IP Library Granted Patent US 12,282,950
Granted Patent B2
US 12,282,950 · App. 17/093,497 · Granted Apr 22, 2025

Credential provisioning for an electronic device

Inventors: David T. Haggerty (Cupertino, CA); George R. Dicker (Sunnyvale, CA); Joakim Linde (Cupertino, CA); Ahmer A. Khan (Cupertino, CA); Timothy S. Hurley (Cupertino, CA)
Assignee: Apple Inc.
G06Q40/02G06F21/42G06Q20/3255G06Q20/3278G06Q20/354G06Q20/3821G06Q20/425G06Q30/0185H04L9/3215H04L63/0876G06Q2220/00H04L2101/37H04L2209/56H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,950
App. No.
17/093,497
Granted
Apr 22, 2025
Kind
B2
Abstract

Systems, methods, and computer-readable media for provisioning credentials on an electronic device are provided. In one example embodiment, a secure platform system may be in communication with an electronic device and a financial institution subsystem. The secure platform system may be configured to, inter alia, detect a selection of a particular commerce credential, access communication mechanism data indicative of at least one communication mechanism of the device, where the at least one mechanism is configured to receive a communication on the device, transmit information to the financial subsystem, where the information includes the mechanism data and the selection of the particular commerce credential, and instruct the financial subsystem to provision the particular commerce credential in a disabled state on the device and communicate credential enablement data to the device using a particular communication mechanism of the at least one communication mechanism indicated by the communication mechanism data.

Claims (45)

1. A system comprising:

a memory; and

at least one processor configured to:

detect a selection of a particular commerce credential to be enabled on an electronic device, the particular commerce credential corresponding to a financial institution subsystem;

access communication mechanism data indicative of at least two communication techniques of the electronic device, wherein each of the at least two communication techniques is configured to receive a communication on the electronic device;

generate a ranking of the at least two communication techniques;

transmit information to the financial institution subsystem, wherein the information comprises the communication mechanism data and the selection of the particular commerce credential, and the generated ranking;

instruct the financial institution subsystem to provision the particular commerce credential in a disabled state as an applet of a supplemental security domain (“SSD”) on a secure element of the electronic device;

responsive to the instructing, obtain credential enablement data associated with the particular commerce credential; and

communicate the credential enablement data via an out-of-band communication channel to the electronic device using a particular communication technique of the at least two communication techniques indicated by the communication mechanism data, wherein the communicated credential enablement data is configured to cause the secure element of the electronic device to execute a script to update the applet of the SSD for the provisioned particular commerce credential from the disabled state on the secure element of the electronic device to an enabled state on the secure element of the electronic device.

2. The system of claim 1 , wherein the at least one processor is further configured to access the communication mechanism data from the electronic device.

3. The system of claim 1 , wherein the at least one processor is further configured to access the communication mechanism data from a data source that is not the electronic device.

4. The system of claim 1 , wherein the accessed communication mechanism data is indicative of the at least two communication techniques of the electronic device.

5. The system of claim 4 , wherein the at least one processor is further configured to instruct the financial institution subsystem to run a comparison with a list of verified communication techniques associated with the particular commerce credential to determine the particular communication technique of the at least two communication techniques indicated by the transmitted information.

6. The system of claim 1 , wherein the communication mechanism data comprises at least one of a text messaging address and an e-mail messaging address.

7. The system of claim 1 , wherein the at least one processor is further configured to:

run a fraud check on the particular commerce credential; and

access the communication mechanism data and transmit the information when a result of the fraud check does not meet a particular standard.

8. The system of claim 1 , wherein the at least one processor is configured to access the communication mechanism data transparently to a user of the electronic device.

9. The system of claim 1 , wherein the credential enablement data is configured to update the particular commerce credential on the electronic device from the disabled state to the enabled state transparently to a user of the electronic device.

10. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving a selection of a particular commerce credential to be enabled on an electronic device;

receiving communication mechanism data indicative of at least two communication techniques of the electronic device;

identifying at least a particular communication technique of the at least two communication technique indicated by the received communication mechanism data that matches a verified communication technique associated with the particular credential; and

transmitting credential enablement data associated with the particular commerce credential to the electronic device via an out-of-band communication channel using the particular communication technique, wherein the transmitted credential enablement data is configured to cause a secure element of the electronic device to execute a script to update an applet of supplemental security domain (“SSD”) on the secure element corresponding to the particular commerce credential from a disabled state on the secure element to an enabled state on the secure element.

11. The non-transitory computer-readable medium of claim 10 , wherein the operations further comprise:

provisioning data associated with the particular commerce credential on to the electronic device using another communication technique that is different than the particular communication technique.

12. The non-transitory computer-readable medium of claim 11 , wherein the credential enablement data is configured to update the particular commerce credential on the electronic device from the disabled state to the enabled state transparently to a user of the electronic device.

13. The non-transitory computer-readable medium of claim 10 , wherein the operations further comprise accessing the communication mechanism data from the electronic device.

14. The non-transitory computer-readable medium of claim 10 , wherein the operations further comprise accessing the communication mechanism data from a data source that is not the electronic device.

15. The non-transitory computer-readable medium of claim 10 , wherein the communication mechanism data comprises at least one of a text messaging address and an e-mail messaging address.

16. The system of claim 1 , wherein the particular commerce credential is provisioned as the applet of the SSD by a secure mobile platform (“SMP”) trusted services manager (“TSM”).

17. A method comprising:

detecting a selection of a particular commerce credential to be enabled on an electronic device, the particular commerce credential corresponding to a financial institution subsystem;

accessing communication mechanism data indicative of at least two communication techniques of the electronic device, wherein each of the at least two communication techniques is configured to receive a communication on the electronic device;

generating a ranking of the at least two communication techniques;

transmitting information to the financial institution subsystem, wherein the information comprises the communication mechanism data and the selection of the particular commerce credential, and the generated ranking;

instructing the financial institution subsystem to provision the particular commerce credential in a disabled state as an applet of a supplemental security domain (“SSD”) on a secure element of the electronic device;

responsive to the instructing, obtaining credential enablement data associated with the particular commerce credential; and

communicating the credential enablement data via an out-of-band communication channel to the electronic device using a particular communication technique of the at least two communication techniques indicated by the communication mechanism data, wherein the communicated credential enablement data is configured to cause the secure element of the electronic device to execute a script to update the applet of the SSD for the provisioned particular commerce credential from the disabled state on the secure element of the electronic device to an enabled state on the secure element of the electronic device.

18. The method of claim 17 , further comprising:

accessing the communication mechanism data from the electronic device.

19. The method of claim 17 , further comprising:

accessing the communication mechanism data from a data source that is not the electronic device.

20. The method of claim 19 , wherein the accessed communication mechanism data is indicative of the at least two communication techniques of the electronic device.

Continuity (3)
Division 14475273 · Sep 2, 2014
Provisional Application 61909717 · Nov 27, 2013
Related Publication 20210174358A1 · Jun 10, 2021
References Cited (81)
US 7290704B1 · Ball · 2007 [cited by applicant]
US 7752292B1 · Katzer · 2010 [cited by examiner]
US 8060449B1 · Zhu · 2011 [cited by examiner]
US 8612522B1 · Sylvain · 2013 [cited by examiner]
US 9286604B2 · Aabye · 2016 [cited by examiner]
US 10055727B2 · Aiglstorfer · 2018 [cited by examiner]
US 11127001B2 · Tang · 2021 [cited by examiner]
US 11195163B2 · Khan · 2021 [cited by examiner]
US 20040137964A1 · Lynch · 2004 [cited by applicant]
US 20050250538A1 · Narasimhan · 2005 [cited by examiner]
US 20060046742A1 · Zhang · 2006 [cited by examiner]
US 20060178133A1 · Kim · 2006 [cited by examiner]
US 20070174904A1 · Park · 2007 [cited by applicant]
US 20070239833A1 · Alperin · 2007 [cited by examiner]
US 20080065425A1 · Giuffre · 2008 [cited by applicant]
US 20080116264A1 · Hammad · 2008 [cited by examiner]
US 20080133716A1 · Rao · 2008 [cited by examiner]
US 20080195545A1 · Motoyama · 2008 [cited by examiner]
US 20080250244A1 · Baentsch et al. · 2008 [cited by applicant]
US 20080306905A1 · Clarkson · 2008 [cited by applicant]
US 20090006230A1 · Lyda · 2009 [cited by examiner]
US 20090006254A1 · Mumm · 2009 [cited by examiner]
US 20090171805A1 · Gould · 2009 [cited by examiner]
US 20090250515A1 · Todd · 2009 [cited by applicant]
US 20100017413A1 · James · 2010 [cited by applicant]
US 20100080383A1 · Vaughan · 2010 [cited by examiner]
US 20100125635A1 · Axelrod et al. · 2010 [cited by applicant]
US 20100144318A1 · Cable · 2010 [cited by examiner]
US 20100211504A1 · Aabye · 2010 [cited by examiner]
US 20100266132A1 · Bablani · 2010 [cited by applicant]
US 20110055047A1 · Fox · 2011 [cited by examiner]
US 20110089233A1 · Locher · 2011 [cited by applicant]
US 20110153496A1 · Royyuru · 2011 [cited by applicant]
US 20110187642A1 · Faith · 2011 [cited by examiner]
US 20110238575A1 · Nightengale · 2011 [cited by examiner]
US 20110251962A1 · Hruska · 2011 [cited by examiner]
US 20110276420A1 · White · 2011 [cited by examiner]
US 20110276495A1 · Varadarajan et al. · 2011 [cited by applicant]
US 20120011007A1 · Blewett · 2012 [cited by examiner]
US 20120011066A1 · Telle · 2012 [cited by applicant]
US 20120054046A1 · Albisu · 2012 [cited by examiner]
US 20120078735A1 · Bauer · 2012 [cited by examiner]
US 20120095852A1 · Bauer · 2012 [cited by examiner]
US 20120116963A1 · Klein · 2012 [cited by examiner]
US 20120149339A1 · Mulampaka · 2012 [cited by examiner]
US 20120253902A1 · Carney, II · 2012 [cited by examiner]
US 20120266220A1 · Brudnicki · 2012 [cited by examiner]
US 20120276872A1 · Knauth · 2012 [cited by examiner]
US 20120324242A1 · Kirsch · 2012 [cited by applicant]
US 20130130669A1 · Xiao · 2013 [cited by applicant]
US 20130151400A1 · Makhotin · 2013 [cited by examiner]
US 20130157711A1 · Lee · 2013 [cited by examiner]
US 20130179242A1 · Kaplan · 2013 [cited by examiner]
US 20130198081A1 · Royyuru · 2013 [cited by examiner]
US 20130260734A1 · Jain · 2013 [cited by applicant]
US 20130297333A1 · Timmons · 2013 [cited by examiner]
US 20130317928A1 · Laracey · 2013 [cited by examiner]
US 20130347128A1 · Cumming · 2013 [cited by examiner]
US 20140019290A1 · Beaver · 2014 [cited by examiner]
US 20140105372A1 · Nowack · 2014 [cited by examiner]
US 20140208112A1 · McDonald · 2014 [cited by applicant]
US 20140222624A1 · Custer · 2014 [cited by applicant]
US 20140236824A1 · Amaya Calvo · 2014 [cited by examiner]
US 20140330660A1 · Glass · 2014 [cited by applicant]
US 20140337207A1 · Zhang · 2014 [cited by examiner]
US 20150019417A1 · Andrews · 2015 [cited by examiner]
US 20150038120A1 · Larkin · 2015 [cited by applicant]
US 20150371221A1 · Wardman · 2015 [cited by applicant]
US 20200410478A1 · Beltramino · 2020 [cited by examiner]
CN 103020822 · 2013 [cited by applicant]
GB 2473952A · 2011 [cited by examiner]
TW 201327455 · 2013 [cited by applicant]
TW 201337821 · 2013 [cited by applicant]
TW 201346614 · 2013 [cited by applicant]
WO WO2007059169 · 2007 [cited by applicant]
WO WO2012091350 · 2012 [cited by applicant]
WO WO2012177812A1 · 2012 [cited by examiner]
Getting Started with Passbook on iOS 6, 9 pages, 2012, retrieved from https://developer.apple.com/passbook/Getting_Started_with_Passbook.pdf on Jan. 14, 2015. [cited by applicant]
Chinese Office Action from Chinese Patent Application No. 201480060789.8, dated Jul. 15, 2019, 6 pages. [cited by applicant]
Chinese Office Action from Chinese Patent Application No. 201480060789.8, dated Dec. 19, 2019, 7 pages including English language translation. [cited by applicant]
German Office Action from German Patent Application No. 112014005379.1, dated May 22, 2023, 21 pages including machine-generated English language translation. [cited by applicant]