METHOD FOR PERSONALIZING AN ID DOCUMENT, PERSONALIZED ID DOCUMENT AND METHOD FOR AUTHENTICATING A PERSONALIZED ID DOCUMENT

DE502021009327D1Active Publication Date: 2025-12-24BUNDESDRUCKEREI GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502021009327
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-10-22
Filing Date
2021-10-20
Publication Date
2025-12-24
Estimated Expiration
2041-10-20

AI Technical Summary

Technical Problem

Existing ID documents face limitations in storage capacity for digital signatures, which restricts the amount of personalized data that can be securely stored and verified, and there is a need for enhanced security measures to ensure data integrity.

Method used

The method involves storing at least part of the digital signature outside the electronic chip in a computer network, using network retrieval information to access it, allowing for additional personalized data storage and enhanced security through multiple cryptographic algorithms and hash tree data structures.

Benefits of technology

This approach optimizes storage capacity by utilizing off-chip digital signatures, enabling more data to be stored and enhances security by providing robust integrity verification, adaptable to quantum-computer-safe cryptographic methods.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for personalizing an ID document, a personalized ID document, and a method for authenticating a personalized ID document. background

[0002] Personalized ID documents, meaning documents that can be used to verify a person's identity, typically consist of a document body and personalized data displayed on that body, providing information about the individual. ID documents are known to have an electronic chip embedded in the document body, for example, in the form of a plastic card with an electronic chip. This allows personalized data to be stored electronically on the chip, either as a supplement to or exclusively as electronic data. This personalized data is then available, for example, for personal identification, as it can be read and analyzed from the electronic chip using a suitable reader.

[0003] In one form, the ID document can be a machine-readable travel document. The International Civil Aviation Organization (ICAO) has developed standards for the standardization of such ID documents. International Civil Aviation Organization For example, the ICAO standard DOC 9303 was adopted. This standard includes, among other things, passive authentication of the machine-readable travel document. Passive authentication serves to verify the integrity of personalized data on the ID document. A hash value is determined for each data group or object using a hash function. This is called a Document Security Object (SOD). Document Security ObjectThe SOD summarizes the hash values. The SOD is stored in the electronic chip of the ID document. Furthermore, a digital signature is determined for the SOD and also stored in the electronic chip. The information used to verify the integrity of the data groups or objects is thus stored together in the electronic chip.

[0004] According to document DE 10 2015 220 244 A1, a procedure is provided for verifying a document, in particular a valuable or security document, wherein personal and / or document-specific data is stored on the document in machine-readable form, and wherein a random value is stored on the document in machine-readable form. The document may contain a memory or chip in which a signature is stored.

[0005] Document DE 102 96 626 T5 describes a method for electronically and / or digitally signing data using a first signature device employing an electronic signature system. Document US 2019 / 205413 A1 discloses methods for preventing file duplication in cloud storage. Document DE 10 2006 049 442 A1 concerns a method for activating a first smart card for use with a data processing system using a second smart card.

[0006] Document DE 10 2018 115 350 concerns a method for the tamper-proof issuance and storage of multiple electronic documents using a blockchain. The method comprises: receiving a data record for entry by a blockchain server of a blockchain network, wherein the data record contains data of an electronic document to be issued according to a specification of a sovereign institution; executing program instructions of a blockchain program module, wherein the program module is configured to issue electronic documents according to the specification; the execution of the program instructions includes checking whether the data record meets the specification; if the data record meets the specification, adding the data record to an additional block of the blockchain. Summary

[0007] The object of the invention is to provide a method for personalizing an ID document and a personalized ID document itself, thereby expanding the application possibilities for personalized ID documents and enabling increased security. A method for authenticating such a personalized ID document is also to be provided.

[0008] To solve this problem, a method for personalizing an ID document and a system according to independent claims 1 and 12 are provided. Furthermore, a method for authenticating a personalized ID document according to dependent claim 13 is provided. Further embodiments are the subject of dependent subclaims.

[0009] According to one aspect, a method for personalizing an ID document is created, in which an ID document is provided with an electronic chip embedded in the document body. Before and / or after embedding the electronic chip in the document body, the following steps are provided for personalizing the ID document: storing personalized data in the electronic chip; calculating an initial digital signature for the personalized data using an initial signature procedure; storing the initial digital signature for the personalized data, at least partially, outside the electronic chip in a computer network, such that the initial digital signature is at least partially retrievable in the computer network using initial network retrieval information; and storing initial retrieval data indicating the initial network retrieval information on the document body and / or in the electronic chip.

[0010] According to another aspect, a system with a personalized ID document is created, which has the following: a document body; an electronic chip embedded in the document body; personalized data stored in the electronic chip; and first retrieval data stored on the document body and / or in the electronic chip, indicating or specifying first network retrieval information, which is usable, a first digital signature calculated for the personalized data using a first signature procedure, at least partially retrievable from outside the electronic chip from a computer network of the system.

[0011] From another perspective, a method for authenticating a personalized ID document has been created, which has a document body and an electronic chip embedded therein.The procedure involves the following: reading initial retrieval data stored on the document body and / or in the electronic chip, indicating initial network retrieval information usable to retrieve an initial digital signature in a computer network established outside the electronic chip, wherein the initial digital signature is a digital signature for personalized data stored on the electronic chip during the personalization of the ID document; retrieving the initial electronic signature, at least partially, from the computer network using the initial network retrieval information; and verifying the integrity of the personalized data stored on the electronic chip using the initial digital signature.

[0012] The sequence of the planned steps may vary depending on the specific aspects mentioned above.

[0013] It is intended that, in conjunction with the personalized ID document, the first electronic signature, which is calculated for the personalized data stored on the electronic chip for personalization or a part thereof, will be stored wholly or only partially (partial data structure of the digital signature) outside the ID document and separately from it in a computer network, in such a way that the first digital signature can be retrieved there, at least partially, if desired, for example when authenticating the personalized ID document or other processes.In order for the first digital signature to be partially or fully accessible for retrieval within the computer network, the electronic chip stores the initial retrieval data. This data can be read to determine the first network retrieval information associated with the first digital signature, insofar as this information is stored outside the chip. This information can then be used to retrieve at least part of the first digital signature within the computer network. For example, the first network retrieval information might include a so-called link, which can be used to access the first digital signature for retrieval or download within the computer network.

[0014] By storing at least part of the initial digital signature outside the electronic chip, a storage area that would otherwise be required for this purpose within the chip is saved. Due to the typically limited storage capacity of the ID document's electronic chip, this creates the possibility of storing other electronic data on the chip, such as supplementary personalized data. It also enables the use of digital signatures in conjunction with the ID document for which the storage space on the electronic chip would otherwise be insufficient.In particular, novel and potentially security-enhancing methods for generating digital signatures can create digital signatures with a data volume that, while providing a higher degree of security, does not fit into the storage area of ​​the usual electronic chips of ID documents.

[0015] The calculation of the first digital signature can be performed exclusively by a processor of the electronic chip of the ID document or solely by a processor of a data processing unit separate from the ID document, which may be part of the computer network or separate from it. It is also possible for partial steps to be performed by both the processor of the electronic chip and the processor of the data processing unit. The data processing unit may be configured for electronic data exchange with the electronic chip for this or other processes, using wireless and / or wired data communication. Devices capable of reading and / or writing electronic data to the electronic chip of the ID document are known in various embodiments.

[0016] The initial retrieval data can be stored exclusively in the memory area of ​​the electronic chip. Alternatively, the initial retrieval data can be stored exclusively on the document body, for example as a print, whether encoded or unencoded. A combined storage method is also possible, with some of the initial retrieval data stored on the document body and other parts on the electronic chip.

[0017] After personalization, the ID document is free of at least one partial data structure of the first digital signature, which is therefore not stored on the ID document, at least to the extent of the partial data structure, but outside in the computer network, where it can be retrieved using the first network retrieval information.If the personalized ID document is then to be used, for example for authentication, the first retrieval data, which specifies or displays the first network retrieval information, is used to access the first digital signature stored at least partially outside the chip in the computer network. Using this first digital signature, the integrity of the personalized data in the electronic chip is then verified. This verification can be performed at least partially by the processor of the electronic chip itself or at least partially by a data processing device outside the electronic chip. The data integrity verification described here, using the digital signature stored at least partially outside the electronic chip as an example, is also referred to as passive authentication in connection with machine-readable ID documents, especially travel documents.

[0018] Methods for calculating a digital signature are known in various forms, which is why they will not be explained further here.

[0019] The calculation of the first digital signature can further comprise the following: calculating a hash value for a first data object of the personalized data and a second data object of the personalized data, which is different from the first data object; generating a security data object that includes the hash values ​​for the first and second data objects; and calculating the first digital signature for the security data object using the first signature procedure. The personalized data comprises multiple data objects, blocks, or groups, which may be arranged in a directory structure on the electronic chip. An associated hash value is calculated for each of the different data objects, which can be performed by the processor of the electronic chip and / or the processor of a separate data processing unit.A security data object is then created, containing the respective hash values. The first digital signature for the security data object is calculated using the first signature procedure. This first digital signature is then stored outside the electronic chip and accessible on the computer network. The security data object can, for example, be created according to the Document Security Object (SOD) as defined in ICAO Doc 9303. The security data object is stored on the electronic chip.

[0020] The security data object can be created using a hash tree data structure, which includes the respective hash values ​​for the first and second data objects. In this embodiment, the hash values ​​of the data objects are integrated into a hash tree data structure encompassed by the security data object. The first digital signature is then calculated for the security data object using this hash tree data structure. A hash tree is generally a tree of hash values ​​from data blocks or objects, such as files. The hash tree data structure can be stored on the electronic chip of the ID document or outside the electronic chip in the computer network.When storing data outside the electronic chip in the computer network, retrieval data associated with the stored hash tree data structure can be stored in the electronic chip, displaying network retrieval information that enables access (retrieval) to the hash tree data structure in the computer network.

[0021] A hash value can be calculated for the initial data retrievals, and the security data object can be comprehensively generated to contain this hash value. The calculation of the hash value for the initial data retrievals can be performed using the processor of the electronic chip and / or the processor of a separate data processing unit. It is possible for the hash tree data structure, for which the first digital signature is calculated, to include the hash value of the security data object.

[0022] To distinguish the first digital signature from other digital signatures on the computer network, an initial identifier can be assigned to it. Initial identifier data, which displays this identifier, can be stored on the document body and / or on the electronic chip. This initial identifier serves to individualize the first digital signature for retrieval on the computer network and thus, in particular, to differentiate it from other digital signatures. In this configuration, the initial retrieval data and the initial identifier data together provide the information necessary to retrieve the first digital signature on the computer network.For the initial identifier data, it may be necessary to calculate an associated hash value, either using the processor of the electronic chip or the processor of the separately implemented data processing unit, and to store the hash value in the electronic chip, for example, in the hash tree data structure. The hash value of the initial identifier data can be included in the calculation of the first digital signature, for example, by including this hash value in the security data object.

[0023] The initial retrieval data and / or the initial identification data can be stored, at least partially, in a machine-readable area of ​​the ID document. This machine-readable area is typically located within the document body. The initial retrieval data and / or the initial identification data can be stored here in plain text (unencoded) or in encoded form.

[0024] One implementation of the procedure may include the following: calculating a second digital signature for the personalized data using a second signature method that differs from the first signature method; storing the second digital signature for the personalized data outside the electronic chip in the computer network, such that the second digital signature can be retrieved in the computer network using second network retrieval information; and storing second retrieval data, which indicates the second network retrieval information, on the document body and / or in the electronic chip. The design options described above in connection with the first digital signature apply accordingly to the second digital signature for the personalized data.In one implementation, the first and second network retrieval information can be identical, so that they point, for example, to one and the same (addressable) storage location in the computer network. The first and second digital signatures can then be distinguished by a respective individualizing (first and second) identifier, whereby the first and second digital signatures are assigned different identifiers.

[0025] In an alternative configuration, the first and second network retrieval information are different, so that the first and second digital signatures can be retrieved individually in the computer network solely due to this difference.

[0026] It may also be provided that different digital signatures are calculated for different data objects, blocks or groups of personalized data, and that corresponding network retrieval information is provided and stored outside the electronic chip in the computer network.

[0027] The first digital signature for personalized data can be calculated using a key from an initial cryptographic key pair. Cryptographic keys are known in various forms. For example, cryptographic key pairs comprise a private and a public key.

[0028] In the various versions, the digital signature(s) can be calculated or determined using at least one cryptographic algorithm or procedure.

[0029] In one embodiment of the method, the following may be provided: storing a key associated with the first cryptographic key pair outside the electronic chip in the computer network, such that the associated key is retrievable using key network retrieval information in the computer network; and storing key retrieval data indicating the key network retrieval information on the document body and / or in the electronic chip. For example, the public key of the first cryptographic key pair may thus be stored outside the electronic chip in a retrievable manner in the computer network.Similar to the preceding explanations in connection with the digital signature, a key identifier can be assigned to the associated key, which is stored outside the electronic chip in the computer network and can be retrieved. This identifier individualizes the key in the computer network to distinguish it from other data objects stored there, such as other keys.

[0030] In one embodiment of the method, the following may be provided: storing an electronic certificate associated with the first cryptographic key pair outside the electronic chip in the computer network, such that the electronic certificate is retrievable in the computer network using certificate network retrieval information; and storing certificate retrieval data indicating the certificate network retrieval information on the document body and / or in the electronic chip. The electronic certificate, which is stored outside the electronic chip and retrievable in the computer network, may be assigned a certificate identifier that distinguishes the electronic certificate from other electronic certificates in the computer network.

[0031] The following options may still be included in the personalization process: Computation of the first digital signature for the personalized data using the first signature procedure and a further signature procedure, such that the first digital signature is computed as a first composite digital signature for the personalized data, which is divisible into a first data structure and a second data structure; storage of the first data structure of the first composite digital signature outside the electronic chip in the computer network, such that the first data structure is retrievable in the computer network (9) using first network retrieval information; and storage of the second data structure of the first composite digital signature in the electronic chip.

[0032] Alternatively, it may be possible to store both the first data structure and the second data structure of the first composite digital signature outside the chip in the computer network.

[0033] The first and subsequent signature procedures may, during execution, provide that when calculating the first composite digital signature for the personalized data, a first cryptographic procedure (first cryptographic algorithm) and a further cryptographic procedure (further cryptographic algorithm) are used, which are different from each other, in particular with regard to cryptographic keys that are assigned to the respective cryptographic procedures and are used when generating the first composite digital signature for the personalized data.

[0034] The first composite digital signature, which in this respect forms a total data structure (result data of calculating the first digital signature for the personalized data) generated by applying the first cryptographic procedure and the further cryptographic procedure to the personalized data, is separable or divisible into the first data structure and a second data structure according to a control algorithm.

[0035] The ID document can be provided in accordance with the specifications of ICAO Doc 9303.

[0036] The configurations described above in connection with the procedure for personalizing the ID document can be implemented in conjunction with the procedure for authenticating the personalized ID document. In particular, identifier data can be read and evaluated to retrieve the first digital signature from the computer network. Additionally, it may be possible to retrieve the associated key of the first cryptographic key pair and / or the associated electronic certificate for authenticating the personalized ID document from the computer network using the respective network retrieval information and to use them during the authentication process.

[0037] Verifying the integrity of the personalized data may further include: calculating a respective hash value for a first data object of the personalized data and a second data object of the personalized data that is different from the first data object; and comparing the respective hash value with stored hash values ​​that are stored in the electronic chip for the first and second data objects, respectively.

[0038] Verifying the integrity of the personalized data may further include: calculating a hash value for a hash tree, which includes the respective hash values ​​for the first and second data objects in a data tree structure; and comparing the hash value for the hash tree with a hash value stored for the hash tree in the electronic chip.

[0039] Authentication can be used to check whether the personalized data stored on the personalized ID document is damaged or compressed (lack of data integrity).

[0040] The aforementioned features may be provided for in connection with the personalized ID document. Description of exemplary implementations

[0041] Further examples of implementation are explained below with reference to figures in a drawing. These figures show: Fig. 1 a schematic representation of an arrangement for personalizing an ID document; Fig. 2 a schematic block diagram to explain a method for personalizing an ID document; Fig. 3 a schematic representation of an arrangement for authenticating a personalized ID document; Fig. 4 a schematic block diagram to explain a method for authenticating a personalized ID document; Fig. 5 an exemplary flowchart of an embodiment of a method for calculating the first digital signature for the personalized data and verifying it, using several cryptographic algorithms; Fig. 6 a schematic representation of a first control algorithm and a data structure with the composite cryptographic data generated according to the first control algorithm; Fig.Figure 7 shows a schematic representation of the application of another first control algorithm and a data structure with the composite cryptographic data generated according to it, and Figure 8 shows a schematic representation of the application of a further first control algorithm and a data structure with the composite cryptographic data generated according to it.

[0042] Fig. 1Figure 1 shows a schematic representation of an arrangement for personalizing an ID document 1. The ID document 1 serves as proof of the identity of a person P and is, for example, designed as a so-called chip card. The ID document 1 has a document body 2 and an embedded electronic chip 3, which can receive electronic data from and transmit electronic data to the outside, as is known. A device 4 is provided for writing and / or reading the electronic data, which has a processor 5 for processing electronic data. Via interfaces 6, 7, the device 4, which is, for example, a read / write device, can exchange electronic data on the one hand with the electronic chip 3 and on the other hand with a storage device 8, which is part of a computer network 9.In addition, a separately formed data processing unit 10 is provided, which can exchange electronic data with the device 4 and the computer network 9, whether through wireless and / or wired data communication.

[0043] With reference to Fig. 2 The following describes a procedure for personalizing ID document 1. Personalization can be performed before or after embedding the electronic chip 3 in the document body 2. It is also possible to perform partial steps before and after embedding the electronic chip 3. In step 20, personalized data assigned to person P and usable for identifying that person P is stored in the electronic chip 3, for example, in the form of data blocks or objects that may be stored in a directory structure.

[0044] In step 21, an initial digital signature for the personalized data is determined using a first signature procedure. For example, a hash value can be calculated for each data object, which comprises a portion of the personalized data, using a hash function. The hash values ​​determined in this way can then be aggregated in a hash tree within a data tree structure. Optionally, the first digital signature can be calculated for the hash tree using a private key from a cryptographic key pair.

[0045] In step 22, the digital signature is stored outside the electronic chip 3 in the storage device 8 of the computer network 9, such that the digital signature can be retrieved using network retrieval information within the computer network 9, for example, by device 4. In step 23, retrieval data is stored in the electronic chip 3 and / or on the document body 2, which displays and can be read from the first network retrieval information. The ID document 1 therefore does not itself contain the digital signature for the personalized data. Rather, the digital signature is stored separately from the ID document 1 in the storage device 8 of the computer network, so that it can be retrieved there by evaluating the retrieval data, which is itself stored in the electronic chip 3, for example, to authenticate the ID document, as illustrated below with reference to the Fig. 3 and 4(as explained).

[0046] Fig. 3 Figure 1 shows a schematic representation of an arrangement for authenticating the personalized ID document. The same reference symbols are used for identical attributes as in [reference missing]. Fig. 1 used. With reference to Fig. 4 An example implementation of the authentication method is described below.

[0047] In step 40, retrieval data stored on the document body 2 and / or in the electronic chip 3 is read using a read device 30. The read device 30, which has a processor 5 for data processing, extracts the network retrieval information for the digital signature from the retrieval data and then retrieves it from the storage device 8 of the computer network 9 using this network retrieval information (step 41). In step 42, the retrieved digital signature is used to verify the integrity of the personalized data stored on the electronic chip 3.In one embodiment, it can be provided that, to check the data integrity of several data objects, each comprising a portion of the personalized data and stored in the electronic chip 3, a hash value is determined and compared with hash values ​​for the data objects stored in the electronic chip 3 at the time of personalization. If the hash values ​​match, the integrity of the checked personalized data can be established. Otherwise, the personalized data on the ID document 1 is compromised.

[0048] Alternatively, it may be possible to retrieve the public key of the cryptographic key pair, which is associated with the private key used to calculate the digital signature, and / or an associated electronic certificate from computer network 9. The public key and electronic certificate can be stored in computer network 9 in a manner similar to the digital signature, with the corresponding network retrieval information stored in electronic chip 3.

[0049] In one implementation, several data objects are read from ID document 1, and a hash value is determined for each data object. This could, for example, involve name and date of birth information. The hash values ​​determined in this way are compared with corresponding hash values ​​on ID document 1, which were applied / stored there during personalization. Optionally, this can be performed for data objects in a hash tree data structure. The digital signature can then be retrieved from storage device 8 of computer network 9 using the network retrieval information to compare it with the digital signature determined for the hash values ​​of the data objects / hash tree data structure. Furthermore, it can be provided to verify associated certificates and, optionally, certificate chains from a certificate issuer.

[0050] Fig. 5Figure 1 shows an exemplary flowchart of an embodiment of a method for calculating the first digital signature for the personalized data using at least one first and one further signature method for personalizing the ID document 1 and for authenticating the personalized ID document 1. In the embodiment, the use of a respective cryptographic algorithm is provided for the at least two signature methods, wherein the cryptographic algorithms of the signature methods differ, in particular with regard to the cryptographic keys used in each case.

[0051] The exemplary embodiment according to Fig. 5 This can have the particular advantage of supporting great agility in the use of cryptographic algorithms, which allows for the use of multiple cryptographic algorithms to improve security.

[0052] In step 50, the personalized data is provided. In step 51, not just a single cryptographic algorithm is applied to the personalized data (or iteratively to the outputs of other cryptographic algorithms), but two or more cryptographic algorithms. The cryptographic algorithms used here are also referred to as "first cryptographic algorithms." A larger number of cryptographic algorithms may be implemented than are actually used to generate composite cryptographic data (first digital signature) from the personalized data, whether in chip 3 and / or computer network 9. The selection of these cryptographic algorithms and / or the way in which they are combined may be specified in a first control algorithm.This can be implemented, for example, by passing algorithm identifiers, each identifying at least one of the first cryptographic algorithms, as well as optionally some component parameters and / or control parameters, to the first control algorithm as arguments, whereby the first control algorithm executes the individual cryptographic algorithms in such a way that the component parameters belonging to them are passed as arguments.

[0053] In step 52, the composite cryptographic data calculated from the personalized data using several initial cryptographic algorithms—that is, the composite first digital signature (total data structure)—is subdivided or separated into at least two sub-data structures, so that a first and a second (sub-)data structure exist separately and can be stored separately. In various implementations, it is provided that the first and / or the second data structure is stored outside of chip 3 in the computer network 9 and can be retrieved there, as described previously. If both the first and the second data structures are stored outside of chip 3 in the computer network 9, they can be retrieved together in the computer network 9 according to the first network retrieval information.Alternatively, it can be provided that the first and second data structures are stored separately and can be retrieved in computer network 9 according to different network retrieval information.

[0054] For example, the first control algorithm can specify a selection and / or the type (for example, the order and / or mode sequential or parallel) of which of the first cryptographic algorithms should be combined with each other and how, in order to obtain the composite cryptographic data.

[0055] The composite cryptographic data, or a sub-data structure thereof, can be provided together with an identifier of a second control algorithm and with parameters (algorithm identifiers of the first and, implicitly, also of the second cryptographic algorithm, and optionally also component parameters and / or control parameters of the second control algorithm). These parameters are also referred to as "composite parameters".

[0056] The output of the first control algorithm, the composite cryptographic data and optionally the parameters, can be considered the output of a new algorithm composed of several individual cryptographic algorithms.

[0057] In the verification of the personalized data, the composite cryptographic data (composite first digital signature) is provided in a first step 53, after the (partial) data structure(s) stored outside the chip 3 in the computer network 9 have been retrieved. In a step 54, the composite cryptographic data is processed to obtain result data. The processing of the composite cryptographic data is carried out using one or more secondary cryptographic algorithms. The selection and / or coordination and combination of the one or more secondary cryptographic algorithms is performed by the second control algorithm, which preferably receives the algorithm identifiers of the secondary cryptographic algorithms as an argument. The algorithm identifiers can, for example, be read from the data structure using optionally available control parameters and / or component parameters.

[0058] The second verification algorithm can be specified using an identifier provided along with the composite cryptographic data. It is possible that only a single second cryptographic algorithm is used to process the composite first digital signature, even though multiple first cryptographic algorithms were used to compute the composite cryptographic data.

[0059] The (first) cryptographic algorithms used after the first control algorithm to calculate the composite first digital signature can be the same as the second cryptographic algorithms used after the second control algorithm to check the personalized data (using the composite first digital signature).

[0060] Finally, step 62 determines whether the authentication of the person using the personalized ID document 1 was successful, which requires the correctness of the verification of the personalized data using the composite first digital signature.

[0061] Fig. 6 Figure 1 shows a schematic representation of a first control algorithm and a data structure containing the composite cryptographic data generated according to the first control algorithm. The first control algorithm specifies, for example, an identifier 60 of the first control algorithm and an identifier 61 of the second control algorithm, which is to be used to process the generated composite cryptographic data (composite first digital signature). Identifiers 60 and 61 are typically identical, but can differ in some embodiments.

[0062] The first control algorithm is preferably executed by taking a series of parameters 62, ..., 65 as input and / or outputting them. For example, the parameters 63 include algorithm identifiers of the first cryptographic algorithms to be used to generate the composite cryptographic data, optionally component parameters required by these algorithms (for example, B1, B2 for signing algorithm / signature verification algorithm B, component parameters C1, C2 and C3 for signing algorithm / signature verification algorithm C, signing algorithm / signature verification algorithm D does not require any component parameters), and optionally also control parameters 62, 64 for the first (and possibly also for the functionally corresponding second) control algorithm itself.

[0063] For example, a control parameter 62, 61 in SIGNATURE K-from-N could specify the value K from the set of the first cryptographic algorithms. The value K is a number less than or equal to N and specifies the minimum number of signatures that must be verified as valid for the composite signature check performed by the second control algorithm to conclude that a signed document is valid. In KEY AGREEMENT, for example, the bit length to which the results of the individual algorithms must be truncated or padded can be used as a control parameter. How the first and / or second algorithms are to be combined is specified by the identifier of the first or second control algorithm, for example, AND / OR / AGGREGATE / etc.

[0064] In the Fig. 6In the example shown, N can be 3 and K can be 2. This means that the three digital signing methods B, C, and D, designated by their algorithm names, are each applied to the input data 66, i.e., the personalized data, with algorithms B and C using component parameters B1, B2, C1, C2, and C3. The resulting digital signatures 67, 68, and 69 are concatenated and stored as the composite cryptographic data 70 (composite first digital signature), for example, in a first field 71 of a data structure 72, which here is an X.509 certificate. The identifier 61 of the second control algorithm, as well as several parameters 64 and 65 to be used by it, are stored in a second field 73 of the data structure. The parameters include the algorithm names B, C, and D, the component parameters B1, B2, C1, C2, and C3, and the control parameter K=2.

[0065] This allows cryptosystems using X.509 certificates to be prepared and migrated to quantum-computer-safe cryptographic methods. It may be possible to use several quantum-computer-safe cryptographic methods from different mathematical problem classes, as well as one or more conventional cryptographic methods, to generate the composite cryptographic data. This has the advantage that the composite signatures, cipherrates, and / or keys generated based on such a combination of conventional and new cryptographic algorithms can also be used by applications that have not yet implemented quantum-computer-safe cryptographic methods.

[0066] Of the digital signatures 67, 68, 69 calculated for the personalized data, at least one is stored outside the chip 3 in the computer network 9, as explained above. One or at most two of the digital signatures 67, 68, 69 can be stored on the chip 3.

[0067] Fig. 7 shows a schematic representation of the application of another first control algorithm and a data structure with the composite cryptographic data generated according to it.

[0068] While Fig. 6 The parallel application of several first cryptographic algorithms to the input data 66 illustrates, i.e. the personalized data, shows Fig. 7The sequential (iterative) application of several first algorithms to the input data. Here, a first cryptographic algorithm A 80 is initially applied directly to the input data 66 to generate a first ciphertext 81. This, in turn, serves as input for a second cryptographic algorithm B 82, which encrypts the ciphertext 81 to generate a further ciphertext 83. The procedure can be applied iteratively multiple times until the last applied algorithm outputs a ciphertext 83, which is used as composite cryptographic data.

[0069] When iteratively applying the first cryptographic algorithms, the second control algorithm is typically not of the "OR" type, since all second cryptographic algorithms, which are complementary to the iteratively applied first cryptographic algorithms and must be applied when authenticating the personalized ID document 1, in order to reconstruct the input data, i.e., the composite first digital signature. If even one of these second cryptographic algorithms is missing from the chain, the procedure cannot be carried out. Nevertheless, an iterative application of first cryptographic algorithms can also be helpful in the context of transitioning to quantum-computer-safe methods. For example, the three encryption algorithms applied initially could be conventional, non-quantum-safe encryption methods. The mere fact that multiple methods are used increases security.

[0070] The ciphertext 83 represents the composite cryptographic data or a component thereof and is stored in a first field 71 of the predefined data structure 72, which, by default, stores cryptographic data of a single cryptographic algorithm. The identifier 61 of the "DATA ENCRYPTION-ITERATIVE" control algorithm, as well as associated parameters, in particular the algorithm identifiers of the functionally complementary decryption algorithms C, B, and A with their respective required component parameters 84, are stored in a second field 85 of this data structure, which, by default, stores identifiers and parameters of a single cryptographic algorithm.Since the receiving cryptosystem has direct access to the algorithm identifiers of all algorithms A, B, C required for decryption in the second field 85, it can decide not to perform decryption and the corresponding second control algorithm from the outset if it does not support at least one of the required second cryptographic algorithms.

[0071] Fig. 8 Figure 1 shows a schematic representation of the application of another first control algorithm and a data structure containing the composite cryptographic data generated according to this algorithm. The application of this first control algorithm is similar to that described in Figure 2. Fig. 7The described algorithm differs in that the component parameters of the respective encryption algorithms, together with those of the previously calculated ciphertext, are used as input to calculate the ciphertext of the next step in the sequence. In this case, only the algorithm identifier and component parameters of the last executed encryption algorithm 90 C, or of the first executed decryption algorithm, need to be provided as parameters in plaintext along with the combined cryptographic data 70 when authenticating the ID document 1. The algorithm identifiers and component parameters of the other encryption and decryption algorithms B and A are determined during decryption.

[0072] The features disclosed in the foregoing description, the claims and the drawing can be important for the realization of the various embodiments, both individually and in any combination. Reference symbol list

[0073] 1 ID document 2 Document body 3 Electronic chip 4 Device 5 Processor 6, 7 Interface 8 Storage device 9 Computer network 10 Data processing device 20 ... 23 Process steps 30 Read device 40 ... 44 Process steps 50 ... 54 Process steps 60 Indicator of first control algorithm 61 Indicator of second control algorithm 62 ... 65 Parameters, algorithm identifiers and component parameters of the first cryptographic algorithms 66 Input data (personalized data) 67 ... 69 Signature generated by signing algorithm 70 Cryptographic data 71 First field 72 Data structure 73 Second field 80 Cryptographic algorithm A 81 First ciphertext 82 Cryptographic algorithm B 83 Further ciphertext 84 Parameters of the second control algorithm 85 Second field 90 cryptographic algorithm C

Claims

1. A method for personalizing an ID document (1), in which an ID document (1) is provided with an electronic chip (3) embedded in a document body (2), wherein before and / or after embedding the electronic chip (3) in the document body (2) during a personalization the following is provided: - storing personalized data in the electronic chip (3); and - calculating a first digital signature for the personalized data using a first signature method; characterized by - storing the first digital signature for the personalized data at least partly outside the electronic chip (3) in a computer network (9), such that the first digital signature is at least partly retrievable in the computer network (9) using first network retrieval information; and - storing first retrieval data indicating the first network retrieval information on the document body (2) and / or in the electronic chip (3).

2. The method according to claim 1, characterized in that calculating the first digital signature further comprises: - calculating a respective hash value for a first data object of the personalized data and a second data object of the personalized data different from the first data object; - generating a security data object comprising the respective hash value for the first and second data objects; and - calculating the first digital signature for the security data object using the first signature method.

3. The method according to claim 2, characterized in that the security data object is generated with a hash tree data structure comprising the respective hash value for the first data object and the second data object.

4. The method according to claim 2 or 3, characterized in that a hash value is calculated for the first retrieval data and the security data object is generated comprising the hash value for the first retrieval data.

5. The method according to at least one of the preceding claims, characterized in that a first ordering feature is assigned to the first digital signature for distinguishing from other digital signatures in the computer network (9), and first ordering feature data indicating the first ordering feature are stored on the document body (2) and / or in the electronic chip (3).

6. The method according to at least one of the preceding claims, characterized in that the first retrieval data and / or the first ordering feature data are stored at least partly in a machine-readable area of the ID document (1).

7. The method according to at least one of the preceding claims, characterized by - calculating a second digital signature for the personalized data using a second signature method different from the first signature method; - storing the second digital signature for the personalized data outside the electronic chip (3) in the computer network (9), such that the second digital signature is retrievable in the computer network (9) using second network retrieval information; and - storing second retrieval data indicating the second network retrieval information on the document body (2) and / or in the electronic chip (3).

8. The method according to at least one of the preceding claims, characterized in that the first digital signature for the personalized data is calculated using a key of a first cryptographic key pair.

9. The method according to claim 8, characterized by - storing a key of the first cryptographic key pair assigned to the key outside the electronic chip (3) in the computer network (9), such that the assigned key is retrievable in the computer network (9) using key network retrieval information; and - storing key retrieval data indicating the key network retrieval information on the document body (2) and / or in the electronic chip (3).

10. The method according to claim 8 or 9, characterized by - storing an electronic certificate assigned to the first cryptographic key pair outside the electronic chip (3) in the computer network (9), such that the electronic certificate is retrievable in the computer network (9) using certificate network retrieval information; and - storing certificate retrieval data indicating the certificate network retrieval information on the document body (2) and / or in the electronic chip (3).

11. The method according to at least one of the preceding claims, characterized in that during the personalization the following is further provided: - calculating the first digital signature for the personalized data using the first signature method and a further signature method, such that the first digital signature is calculated as a first composite digital signature for the personalized data, which is divisible into a first data structure and a second data structure; - storing the first data structure of the first composite digital signature outside the electronic chip (3) in the computer network (9), such that the first data structure is retrievable in the computer network (9) using first network retrieval information; and - storing the second data structure of the first composite digital signature in the electronic chip (3).

12. A system, comprising - a personalized ID document, comprising - a document body (2); - an electronic chip (3) embedded in the document body (2); and - personalized data stored in the electronic chip (3); characterized in that the personalized ID document further comprises: - first retrieval data stored on the document body (2) and / or in the electronic chip (3) and indicating first network retrieval information; and by a computer network (9) in which a first digital signature calculated for the personalized data using a first signature method is at least partly stored, such that the first digital signature is at least partly retrievable in the computer network (9) using the first network retrieval information.

13. A method for authenticating a personalized ID document (1) comprising a document body (2) and an electronic chip (3) embedded therein, wherein in the method the following is provided: - reading out first retrieval data stored on the document body (2) and / or in the electronic chip (3) and indicating first network retrieval information usable to retrieve a first digital signature at least partly in a computer network (9) formed outside the electronic chip (3), wherein the first digital signature is a digital signature for personalized data stored on the electronic chip (3) during personalization of the ID document (1); - retrieving the first electronic signature at least partly from the computer network (9) using the first network retrieval information; and - checking the integrity of the personalized data stored on the electronic chip (3) using the first digital signature.

14. The method according to claim 13, characterized in that checking the integrity of the personalized data further comprises: - calculating a respective hash value for a first data object of the personalized data and a second data object of the personalized data different from the first data object; and - comparing the respective hash value with stored hash values respectively stored for the first and second data objects in the electronic chip (3).

15. The method according to claim 14, characterized in that checking the integrity of the personalized data further comprises: - calculating a hash value for a hash tree comprising the respective hash value for the first and second data objects in a data tree structure; and - comparing the hash value for the hash tree with a hash value stored for the hash tree in the electronic chip (3).