IP Library › Granted Patent US 12,293,353
Granted Patent B2
US 12,293,353 · App. 18/618,895 · Granted May 6, 2025

Device provisioning using partial personalization scripts

Inventors: Erick Wong (Vancouver, CA); Oleg Makhotin (Paris, FR)
Assignee: Visa International Service Association
G06Q20/363G06F21/1065G06Q20/3227G06Q20/3278G06Q20/354G06Q20/3552G06Q20/38215G06Q20/3829
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,293,353
App. No.
18/618,895
Granted
May 6, 2025
Kind
B2
Abstract

Embodiments of the invention relate to systems and methods for efficiently provisioning mobile devices with personalization data. For some embodiments, a method is disclosed comprising receiving a request for provisioning comprising device information for a mobile device and user authentication information for a user, generating a partial personalization script, an activation script, and a deletion script using the device information, sending the partial personalization script, the activation script, and the deletion script to an application provider computer, wherein the application provider computer initiates execution of the partial personalization script on the mobile device, authenticating the user authentication information, and sending an activation message to the application provider computer, wherein the application provider computer initiates execution of the activation script.

Claims (50)

1. A method comprising:

sending, by a mobile device, to an application provider computer, a request for provisioning the mobile device, the request including device information for the mobile device, the device information including a secure element identifier and a session identifier, wherein the application provider computer sends the request for provisioning the mobile device to a service provider computer, the service provider computer retrieves a personalization master key associated with the mobile device based on the secure element identifier, generates a personalization session key using a key derivation function, the secure element identifier, the session identifier, and the personalization master key, generates store data commands comprising personalization data, encrypts the store data commands using the personalization session key, generates a partial personalization script using the encrypted store data commands, generates an activation script, encrypts the activation script using the personalization session key, generates a deletion script, and encrypts the deletion script using the personalization session key;

receiving, by the mobile device, from the application provider computer, the partial personalization script, the activation script and the deletion script; and

executing, by the mobile device, the partial personalization script, including:

decrypting the encrypted store data commands using an encryption key that matches the personalization session key; and

executing, by the mobile device, at least one of the activation script and the deletion script, including:

decrypting at least one of the activation script and the deletion script using the encryption key that matches the personalization session key, wherein execution of the activation script enables the mobile device with access to the personalization data and provisions the personalization data onto the mobile device.

2. The method of claim 1 , further comprising:

receiving, by the mobile device, from the application provider computer, an activation message; and

executing, by the mobile device, the activation script prior to initiating a transaction using the personalization data, and including:

decrypting the activation script using the encryption key that matches the personalization session key.

3. The method of claim 1 , further comprising:

receiving, by the mobile device, from the application provider computer, a deletion message; and

executing, by the mobile device, the deletion script to delete the personalization data from the mobile device, and including:

decrypting the deletion script using the encryption key that matches the personalization session key.

4. The method of claim 1 , further comprising:

receiving, by the mobile device, from the application provider computer, the activation script; and

executing, by the mobile device, the activation script, thereby provisioning the personalization data onto the mobile device, and including:

decrypting the activation script using the encryption key that matches the personalization session key.

5. The method of claim 1 , further comprising:

receiving, by the mobile device, from the application provider computer, the deletion script; and

executing, by the mobile device, the deletion script to delete the personalization data from the mobile device, and including:

decrypting the deletion script using the encryption key that matches the personalization session key.

6. The method of claim 1 , wherein the service provider computer determines that the personalization session key is expired, establishes a new session associated with a new personalization session key, and generates a new activation script using the new personalization session key, and further comprising:

receiving, by the mobile device, from the application provider computer, the new activation script.

7. The method of claim 1 , wherein the partial personalization script includes a script operable to store the personalization data on the mobile device in a secured form.

8. The method of claim 1 , wherein the session identifier is a nonce value.

9. The method of claim 1 , wherein the personalization master key is a symmetric encryption key.

10. A mobile device comprising:

a processor;

a non-transitory computer-readable medium comprising code executable by the processor for implementing operations including:

sending, to an application provider computer, a request for provisioning the mobile device, the request including device information for the mobile device, the device information including a secure element identifier and a session identifier, wherein the application provider computer sends the request for provisioning the mobile device to a service provider computer, the service provider computer retrieves a personalization master key associated with the mobile device based on the secure element identifier, generates a personalization session key using a key derivation function, the secure element identifier, the session identifier, and the personalization master key, generates store data commands comprising personalization data, encrypts the store data commands using the personalization session key, generates a partial personalization script using the encrypted store data commands, generates an activation script, encrypts the activation script using the personalization session key, generates a deletion script, and encrypts the deletion script using the personalization session key;

receiving, from the application provider computer, the partial personalization script, the activation script and the deletion script; and

executing the partial personalization script, including:

decrypting the encrypted store data commands using an encryption key that matches the personalization session key, and

executing at least one of the activation script and the deletion script, including:

decrypting at least one of the activation script and the deletion script using the encryption key that matches the personalization session key, wherein execution of the activation script enables the mobile device with access to the personalization data and provisions the personalization data onto the mobile device.

11. The mobile device of claim 10 , further comprising:

receiving, from the application provider computer, an activation message; and

executing the activation script prior to initiating a transaction using the personalization data, and including:

decrypting the activation script using the encryption key that matches the personalization session key.

12. The mobile device of claim 10 , wherein the executing the partial personalization script further includes:

storing the personalization data in a secured form.

13. The mobile device of claim 10 , wherein the session identifier is a nonce value.

14. The mobile device of claim 10 , wherein the personalization master key is a symmetric encryption key.

15. The mobile device of claim 10 , further comprising:

generating a device cryptogram using the encryption key that matches the personalization session key, wherein the device information further includes the device cryptogram, and wherein the service provider computer authenticates a user of the mobile device by validating the device cryptogram using the personalization session key.

16. The mobile device of claim 10 , wherein the request further includes user authentication information for a user of the mobile device, wherein the user authentication information includes an account identifier, and wherein the personalization data includes a token that represents the account identifier.

17. The mobile device of claim 10 , wherein the request does not include the personalization master key, and wherein the personalization master key is not sent between the mobile device and the service provider computer.

18. The mobile device of claim 10 , wherein the personalization master key is associated with an issuer of a user account or a manufacturer of a secure element associated with the secure element identifier.

Continuity (7)
Continuation 17232079 · Apr 15, 2021
Continuation 16255559 · Jan 23, 2019
Continuation 15658897 · Jul 25, 2017
Continuation 14275404 · May 12, 2014
Provisional Application 61898428 · Oct 31, 2013
Provisional Application 61822271 · May 10, 2013
Related Publication 20240242203A1 · Jul 18, 2024
References Cited (20)
US 7469151B2 · Khan et al. · 2008 [cited by applicant]
US 9195984B1 · Spector · 2015 [cited by examiner]
US 9760886B2 · Wong et al. · 2017 [cited by applicant]
US 10235670B2 · Wong et al. · 2019 [cited by applicant]
US 20050044393A1 · Holdsworth · 2005 [cited by applicant]
US 20090298468A1 · Hsu · 2009 [cited by applicant]
US 20120078735A1 · Bauer et al. · 2012 [cited by applicant]
US 20120143772A1 · Abadir · 2012 [cited by examiner]
US 20120202462A1 · Sudhakar · 2012 [cited by examiner]
US 20130054474A1 · Yeager · 2013 [cited by applicant]
US 20130111599A1 · Gargiulo · 2013 [cited by applicant]
US 20130151400A1 · Makhotin et al. · 2013 [cited by applicant]
US 20130232083A1 · Smith · 2013 [cited by examiner]
US 20130262302A1 · Lettow et al. · 2013 [cited by applicant]
US 20170323290A1 · Wong et al. · 2017 [cited by applicant]
U.S. Appl. No. 14/275,404 , Non-Final Office Action, Mailed On Jan. 12, 2017, 19 pages. [cited by applicant]
U.S. Appl. No. 14/275,404 , Notice of Allowance, Mailed On Apr. 25, 2017, 15 Pages. [cited by applicant]
U.S. Appl. No. 15/658,897 , Notice of Allowance, Mailed On Oct. 24, 2018, 13 pages. [cited by applicant]
U.S. Appl. No. 16/255,559 , Non-Final Office Action, Mailed On Aug. 5, 2020, 17 pages. [cited by applicant]
U.S. Appl. No. 16/255,559 , Notice of Allowance, Mailed On Jan. 27, 2021, 13 pages. [cited by applicant]