Tokenized Wearable Authentication via TSP Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wearable devices face security and provisioning limitations, particularly in regards to external communication and data transfer, making them vulnerable to attacks and difficult to provision for various services due to limited communication capabilities.
Innovation Solution
A token-based transaction authentication system that utilizes a server and tokenization service provider to manage security tokens on wearable devices, enabling secure transactional activities by verifying device status and account authorization through a communication module and processor, and updating device databases to ensure only active devices can perform transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wearable devices are equipped with integrated RFID or NFC chips for wireless peer-to-peer communication, then the portability and convenience of use are improved, but the devices become exposed to third-party attacks such as message injection and eavesdropping
Solution Approach 1:
The patent introduces a tokenization service provider as an intermediary between the wearable device and external systems. The TSP issues tokens that replace sensitive account information, acting as a mediator that enables secure communication without exposing the device to direct security risks. The token serves as an intermediary credential that can be verified by merchants without revealing underlying account details.
Solution Approach 2:
The patent creates a copy of account information in the form of a token that can be used for transactions without exposing the original sensitive data. The token is a representative copy that contains sufficient information for transaction verification while eliminating the security risks associated with storing or transmitting actual account credentials on the wearable device.
2Adaptability or versatility
If wearable devices are equipped with short-range communication capabilities such as NFC, then the device functionality for contactless payment is improved, but the provisioning of such devices becomes difficult due to lack of long-range communication capabilities
Solution Approach 1:
The patent implements preliminary action by pre-provisioning wearable devices with tokens during manufacturing or initial setup, before the devices need to be used for transactions. The tokenization service provider issues tokens in advance and loads them onto the devices, eliminating the need for complex provisioning procedures later. This allows devices to be readily activated for contactless payment without requiring long-range communication capabilities for provisioning.
Data Source
AI summary
A method for authenticating a wearable device is disclosed. The method includes: receiving, from a tokenization service provider (TSP), a signal representing a first code derived by the TSP from decrypting a security token previously provisioned in the computing device, wherein the security token was received at a terminal from the computing device and transmitted to the TSP; obtaining, based on the received signal representing the first code, a device identifier of the computing device and an identifier of an account; querying a device database to verify that the computing device is associated with a first status; verifying that the account is enabled for an operation initiated using the computing device; and transmitting an authorization message to the terminal, the authorization message authorizing the operation.


