Validation Entity for Secure Mobile Access Data Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The provisioning of access data to mobile devices is insecure due to the involvement of multiple entities, leading to potential man-in-the-middle attacks and exposure of sensitive authentication data, especially when untrusted applications are used, which can compromise the security of sensitive information.

Innovation Solution

A method involving a validation entity computer that receives an authentication code, decrypts an encrypted portion to obtain access data, and initiates provisioning to a mobile device, ensuring secure transmission and verification through a trusted application, with the authentication code containing an encrypted time data element for validity checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple entities are involved in the provisioning process, then functionality and versatility are improved, but security and reliability deteriorate due to potential man-in-the-middle attacks and exposure of sensitive authentication data

Engineering Contradiction:
Improveprovisioning capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a validation entity computer as an intermediary between the resource provider and the mobile device. This mediator receives the authentication code, validates it independently, and only then initiates provisioning. This intermediary layer prevents direct exposure of sensitive data between multiple entities, addressing the security concern while maintaining the multi-entity provisioning capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If untrusted applications are used to perform functions for resource providers, then ease of operation and versatility are improved, but security deteriorates as resource providers lose control over security features

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The validation entity computer serves as a trusted intermediary that resource providers can rely on when using untrusted applications. The resource provider sends authentication data to the validation entity, which then validates the authentication code and controls the provisioning process. This allows untrusted applications to maintain functionality while the validation entity preserves security control for the resource provider.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The validation entity computer autonomously validates the authentication code and makes the decision to initiate provisioning without requiring direct control from the resource provider or the untrusted application. This self-service validation mechanism ensures security is maintained independently of the application's trustworthiness.

Inventive Principle:
Principle #25Self-service

3Productivity

If sensitive authentication data is passed between multiple entities, then provisioning functionality is improved, but security worsens due to potential hacking and man-in-the-middle attacks

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoiddata exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive authentication data from the provisioning flow and handles it separately through the validation entity computer. The resource provider sends only the authentication code to the validation entity, which validates it and then initiates provisioning with the resource provider. This extraction of sensitive data handling from the main provisioning flow reduces exposure risk while maintaining provisioning efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The validation entity computer acts as a secure intermediary that receives, validates, and forwards authentication data without exposing it to potential attackers. By routing sensitive data through this controlled intermediary rather than direct peer-to-peer transmission between multiple entities, the system maintains provisioning efficiency while reducing data exposure vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3712792B1Method and system for provisioning access data to mobile device
Publication Date: 2022.06.29 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3712792B1 patent drawingFigure 1
  • EP3712792B1 patent drawingFigure 2
  • EP3712792B1 patent drawingFigure 3

AI summary

A method and system for provisioning access data to a mobile device. An authentication code is received by a validation entity computer. The validation entity computer decrypts an encrypted portion of the authentication code to obtain access data and initiates provisioning the access data to the mobile device.