Proto-script Pre-generation for Contactless Payment Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for provisioning contactless payment functionality to mobile communication devices face significant burdens in real-time data processing and cryptographic key management, requiring substantial resources to generate and encrypt perso-scripts, which can be vulnerable to decryption by Telcos in conventional 'push' models and may necessitate large numbers of data processing resources.
Innovation Solution
The method involves generating a globally unique identifier (GUID) master encryption key, deriving base encryption keys, creating a proto-script to rotate keys, and storing it with reference to the GUID, allowing for pre-provisioning of proto-scripts ahead of requests, reducing real-time processing demands and minimizing the need for extensive data processing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional push models are used for key provisioning, then cryptographic keys can be provided to secure elements, but the perso-scripts become vulnerable to decryption by Telcos and substantial data processing resources are required
Solution Approach 1:
The patent applies preliminary action by pre-generating proto-scripts with placeholder keys before actual provisioning requests. The TSM prepares encrypted key material and proto-script templates in advance, storing them securely. When a provisioning request arrives, the system rapidly completes the perso-script by replacing placeholders with actual keys, dramatically reducing real-time processing demands while maintaining security through pre-established encryption structures.
Solution Approach 2:
The patent segments the key provisioning process into distinct phases: pre-generation of proto-scripts with placeholder keys, secure storage of encrypted key material, and final completion of perso-scripts only when needed. This segmentation allows the system to separate security-critical key generation from resource-intensive encryption operations, reducing both security vulnerabilities and processing resource requirements at any given moment.
2Reliability
If real-time generation of perso-scripts is performed, then security can be maintained, but significant processing resources and time are required
Solution Approach 1:
The system performs preliminary actions by generating proto-scripts with placeholder keys and pre-encrypting key material before provisioning requests arrive. This advance preparation enables rapid completion of perso-scripts when requests are received, as the system only needs to replace placeholders with actual keys rather than generating entire scripts in real-time, thus maintaining security while dramatically improving provisioning speed.
Solution Approach 2:
The patent uses copying by creating template proto-scripts that can be rapidly replicated and customized for different provisioning requests. Instead of generating unique perso-scripts from scratch for each request, the system copies pre-prepared templates and performs minimal customization by inserting actual cryptographic keys, significantly reducing processing time while maintaining the security properties of freshly generated keys.
3Adaptability or versatility
If Telcos can decrypt transmitted key packets, then key rotation becomes possible, but security vulnerabilities arise during transmission
Solution Approach 1:
The patent applies preliminary action by pre-establishing encrypted storage structures and placeholder mechanisms before key transmission occurs. The TSM prepares secure storage locations with pre-computed encryption parameters and placeholder keys. When keys need to be rotated, the system uses these pre-prepared structures to rapidly complete new perso-scripts, minimizing the time keys are vulnerable during transmission while maintaining the ability to rotate keys when needed.
Solution Approach 2:
The patent introduces an intermediary mechanism using placeholder keys and encrypted key material stored in secure locations. Instead of directly transmitting sensitive cryptographic keys through vulnerable channels, the system uses these intermediaries - the placeholders that are already present in proto-scripts and the encrypted key material stored securely - to enable key rotation without exposing actual keys during transmission, thus maintaining security while enabling adaptability.
Data Source
AI summary
Systems and methods for rapidly provisioning functionality to one or more mobile communication devices are disclosed. The method may comprise generating, prior to a request for the functionality, a globally unique identifier (“GUID”) encryption key, wherein the GUID comprises a unique identifier that may be associated with a transaction account customer, generating a value associated with the GUID, deriving, based on the value, a plurality of base encryption keys associated with the value, creating, a perso-script, wherein the perso-script comprises a file associated with data associated with a customer, and/or creating a proto-script, wherein the proto-script comprises the perso-script prepended by a script to rotate the plurality of base encryption keys.


