Proto-script Pre-generation for Contactless Payment Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for provisioning contactless payment functionality to mobile communication devices face significant burdens in real-time data processing and cryptographic key management, requiring substantial resources to generate and encrypt perso-scripts, which can be vulnerable to decryption by Telcos in conventional 'push' models and may necessitate large numbers of data processing resources.

Innovation Solution

The method involves generating a globally unique identifier (GUID) master encryption key, deriving base encryption keys, creating a proto-script to rotate keys, and storing it with reference to the GUID, allowing for pre-provisioning of proto-scripts ahead of requests, reducing real-time processing demands and minimizing the need for extensive data processing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional push models are used for key provisioning, then cryptographic keys can be provided to secure elements, but the perso-scripts become vulnerable to decryption by Telcos and substantial data processing resources are required

Engineering Contradiction:
Improvesecurity of perso-scriptVSAvoiddata processing resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies preliminary action by pre-generating proto-scripts with placeholder keys before actual provisioning requests. The TSM prepares encrypted key material and proto-script templates in advance, storing them securely. When a provisioning request arrives, the system rapidly completes the perso-script by replacing placeholders with actual keys, dramatically reducing real-time processing demands while maintaining security through pre-established encryption structures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the key provisioning process into distinct phases: pre-generation of proto-scripts with placeholder keys, secure storage of encrypted key material, and final completion of perso-scripts only when needed. This segmentation allows the system to separate security-critical key generation from resource-intensive encryption operations, reducing both security vulnerabilities and processing resource requirements at any given moment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If real-time generation of perso-scripts is performed, then security can be maintained, but significant processing resources and time are required

Engineering Contradiction:
Improvesecurity of key managementVSAvoidprovisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by generating proto-scripts with placeholder keys and pre-encrypting key material before provisioning requests arrive. This advance preparation enables rapid completion of perso-scripts when requests are received, as the system only needs to replace placeholders with actual keys rather than generating entire scripts in real-time, thus maintaining security while dramatically improving provisioning speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating template proto-scripts that can be rapidly replicated and customized for different provisioning requests. Instead of generating unique perso-scripts from scratch for each request, the system copies pre-prepared templates and performs minimal customization by inserting actual cryptographic keys, significantly reducing processing time while maintaining the security properties of freshly generated keys.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If Telcos can decrypt transmitted key packets, then key rotation becomes possible, but security vulnerabilities arise during transmission

Engineering Contradiction:
Improvekey rotation capabilityVSAvoiddecryption vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-establishing encrypted storage structures and placeholder mechanisms before key transmission occurs. The TSM prepares secure storage locations with pre-computed encryption parameters and placeholder keys. When keys need to be rotated, the system uses these pre-prepared structures to rapidly complete new perso-scripts, minimizing the time keys are vulnerable during transmission while maintaining the ability to rotate keys when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism using placeholder keys and encrypted key material stored in secure locations. Instead of directly transmitting sensitive cryptographic keys through vulnerable channels, the system uses these intermediaries - the placeholders that are already present in proto-scripts and the encrypted key material stored securely - to enable key rotation without exposing actual keys during transmission, thus maintaining security while enabling adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10007911B2Methods for rapidly provisioning application functionality to a mobile communication device
Publication Date: 2018.06.26 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US10007911B2 patent drawing
  • US10007911B2 patent drawing
  • US10007911B2 patent drawing

AI summary

Systems and methods for rapidly provisioning functionality to one or more mobile communication devices are disclosed. The method may comprise generating, prior to a request for the functionality, a globally unique identifier (“GUID”) encryption key, wherein the GUID comprises a unique identifier that may be associated with a transaction account customer, generating a value associated with the GUID, deriving, based on the value, a plurality of base encryption keys associated with the value, creating, a perso-script, wherein the perso-script comprises a file associated with data associated with a customer, and/or creating a proto-script, wherein the proto-script comprises the perso-script prepended by a script to rotate the plurality of base encryption keys.