Tokenized Wearable Authentication via TSP Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wearable devices face security and provisioning limitations, particularly in regards to external communication and data transfer, making them vulnerable to attacks and difficult to provision for various services due to limited communication capabilities.

Innovation Solution

A token-based transaction authentication system that utilizes a server and tokenization service provider to manage security tokens on wearable devices, enabling secure transactional activities by verifying device status and account authorization through a communication module and processor, and updating device databases to ensure only active devices can perform transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wearable devices are equipped with integrated RFID or NFC chips for wireless peer-to-peer communication, then the portability and convenience of use are improved, but the devices become exposed to third-party attacks such as message injection and eavesdropping

Engineering Contradiction:
Improveportability and convenience of useVSAvoidvulnerability to third-party attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a tokenization service provider as an intermediary between the wearable device and external systems. The TSP issues tokens that replace sensitive account information, acting as a mediator that enables secure communication without exposing the device to direct security risks. The token serves as an intermediary credential that can be verified by merchants without revealing underlying account details.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of account information in the form of a token that can be used for transactions without exposing the original sensitive data. The token is a representative copy that contains sufficient information for transaction verification while eliminating the security risks associated with storing or transmitting actual account credentials on the wearable device.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If wearable devices are equipped with short-range communication capabilities such as NFC, then the device functionality for contactless payment is improved, but the provisioning of such devices becomes difficult due to lack of long-range communication capabilities

Engineering Contradiction:
Improvecontactless payment functionalityVSAvoiddifficulty of provisioning
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements preliminary action by pre-provisioning wearable devices with tokens during manufacturing or initial setup, before the devices need to be used for transactions. The tokenization service provider issues tokens in advance and loads them onto the devices, eliminating the need for complex provisioning procedures later. This allows devices to be readily activated for contactless payment without requiring long-range communication capabilities for provisioning.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11921836B2Systems for enabling tokenized wearable devices
Publication Date: 2024.03.05 THE TORONTO DOMINION BANK
  • US11921836B2 patent drawing
  • US11921836B2 patent drawing
  • US11921836B2 patent drawing

AI summary

A method for authenticating a wearable device is disclosed. The method includes: receiving, from a tokenization service provider (TSP), a signal representing a first code derived by the TSP from decrypting a security token previously provisioned in the computing device, wherein the security token was received at a terminal from the computing device and transmitted to the TSP; obtaining, based on the received signal representing the first code, a device identifier of the computing device and an identifier of an account; querying a device database to verify that the computing device is associated with a first status; verifying that the account is enabled for an operation initiated using the computing device; and transmitting an authorization message to the terminal, the authorization message authorizing the operation.