READING LOCALLY STORED ENCRYPTED IDENTITY ATTRIBUTES
Patent Information
- Application Number
- DE502022003868
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-02-19
- Filing Date
- 2022-02-17
- Publication Date
- 2025-05-22
- Estimated Expiration
- 2042-02-17
AI Technical Summary
Existing technologies face challenges in implementing a cryptographically secured procedure for reading identity attributes from diverse mobile devices with varying hardware and software configurations.
A procedure that involves encrypting identity attributes on a mobile device using a first cryptographic key from a distant safety element, and an additional encryption using a second cryptographic key from the mobile device, allowing selective decryption and forwarding of identity attributes to a server for further processing.
This approach ensures the cryptographic protection and sovereignty of identity attributes, allowing for secure reading and provision of identity attributes while maintaining user control and preventing unauthorized access.
Description
[0001] The invention relates to a method for reading one or more identity attributes of an electronic identity stored on a mobile device. Furthermore, the invention relates to a mobile device and a distributed system with a corresponding mobile device for reading one or more identity attributes of a corresponding electronic identity.
[0002] Mobile devices, such as smartphones, are ubiquitous. They are used in many areas of life and situations to perform a wide variety of digital tasks. Mobile devices are also used as proof of identity and as authentication and authorization tokens, for example, in electronic business processes. However, these devices differ greatly in their hardware configuration as well as in the operating systems they use, including their variants and versions. It is therefore difficult to establish a common basis for the cryptographic protection of electronic identities provided on these devices or the identity attributes contained in the corresponding electronic identities. In particular, it is difficult to implement a cryptographically secure procedure for reading the identity attributes.
[0003] DE 10 2019 100335 A1 describes a method for securely providing a personalized electronic identity on a terminal device, which can be used by a user for identification when using an online service. In the method, an identification application, a personalization application, and an identity provider application are executed on the terminal device in a system with data processing devices and a terminal device assigned to a user. The method comprises the following: transmitting a request for transmitting an identity attribute assigned to the user from the personalization application to the identity provider application; transmitting the identity attribute from the identity provider application to the personalization application after the identity provider application has received consent from the user to transmit the identity attribute;Generating an asymmetric key pair with a public and a private key by the identification application on the terminal device; transmitting the public key from the identification application on the terminal device to the personalization application; generating an electronic certificate for the public key by the personalization application and storing the electronic certificate in a first public key infrastructure of the personalization application in a data store, further comprising: generating a hash value for the identity attribute and incorporating the hash value into the electronic certificate. The identity attribute is encrypted and transmitted together with the electronic certificate from the personalization application to the identification application on the terminal device. Both are stored there in a local storage device of the terminal device.
[0004] The invention is based on the object of creating an improved method for reading identity attributes.
[0005] The object underlying the invention is achieved by the features of the independent patent claims. Embodiments of the invention are specified in the dependent patent claims.
[0006] Embodiments include a method for reading one or more identity attributes of an electronic identity. The electronic identity is stored on a mobile device and is managed by an application installed on the mobile device. A remote security element is provided for the electronic identity on a server. The server communicates with the mobile device via a network.
[0007] The electronic identity comprises a first set of identity attributes stored on the mobile device, which comprises one or more identity attributes. The identity attributes in the first set of identity attributes are each individually encrypted using a first cryptographic key of the remote security element. An attribute identifier is each assigned to the identity attributes in the first set of identity attributes. The identity attributes of the first set of identity attributes encrypted using the first cryptographic key are further encrypted using a second cryptographic key of the mobile device.
[0008] The process includes the application on the mobile device: Receiving a read request from a reading computer system, which attribute identifiers comprise one or more identity attributes to be read out, selecting the identity attributes to be read out from the first set of identity attributes, wherein in the course of the selection, the encryption created using the second cryptographic key is at least partially decrypted while the encryption created using the first cryptographic key is maintained, creating a second set of identity attributes, which comprises the selected identity attributes to be read out, which are encrypted using the first cryptographic key, sending the second set of identity attributes to the server in response to the sending of the second set of identity attributes,Receiving the second set of identity attributes encrypted using a third cryptographic key of the reading computer system from the server, wherein the encryption of the selected identity attributes to be read out in the received second set of identity attributes created using the first cryptographic key was decrypted by the remote security element before encryption with the third cryptographic key, forwarding the second set of identity attributes encrypted using the third cryptographic key to the reading computer system.
[0009] Embodiments can have the advantage of enabling cryptographic protection of readable identity attributes of an electronic identity stored on the mobile device using a remote security element. For example, the mobile device has control over the identity attributes, while the cryptographic protection of the identity attributes or the provision of the corresponding identity attributes is ensured by the remote security element.
[0010] Embodiments may have the advantage that identity attributes of an electronic identity can be provided locally on a mobile device. Through local provision, control over the use of the corresponding identity lies locally with the mobile device or an authorized user of the mobile device. At the same time, however, the identity attributes are provided locally only in encrypted form, i.e., encrypted using the first cryptographic key of the remote security element. Thus, the identity attributes can also be stored locally in an insecure environment, since the remote security element is necessary for accessing the identity attributes, i.e., for decrypting the identity attributes.In addition to cryptographically securing the local storage on the mobile device, this has the advantage of allowing the encrypted identity attributes to be bound to the remote security element. This binding can, for example, ensure that the remote security element, with its cryptographic keys and cryptographic means, is always involved in reading the locally stored identity attributes.
[0011] Furthermore, embodiments can have the advantage that identity attributes to be read out can be identified and selected based on the attribute identifiers, even if the identity attributes are available locally only in encrypted form. For example, the first set comprises identity attributes that specify, for example, a first name, a last name, a street, a house number, a postal code, a place of residence, a date of birth, a place of birth, and / or a nationality of the user of a mobile terminal in encrypted form. Based on the attribute identifiers, it can be identified, for example, which of the encrypted data values specifies the first name, last name, street, house number, postal code, place of residence, date of birth, place of birth, or nationality of the user of a mobile terminal.Thus, for example, the encrypted data value of the user's date of birth can be selected by the application or mobile device from the first set of identity attributes as the identity attribute to be read, without the application or mobile device having or obtaining knowledge of the date of birth. As a result, not even the authorized user of the mobile device itself gains access to the identity attributes of the first set of identity attributes in unencrypted form. While they can use the identity attributes and make them available to computer systems in response to read requests, they cannot access the identity attributes themselves.This ensures that even an unauthorized third party who gains unauthorized access to the mobile device and the set of identity attributes stored on it cannot access the identity attributes in unencrypted form. This effectively prevents such an unauthorized third party from gaining knowledge of the specific content of the identity attributes.
[0012] For example, the first set of identity attributes can have a data structure in the form of a table. The data structure can be row-oriented or column-oriented, for example. For example, the first set of identity attributes is provided in the form of a table, which includes a first column or row with the attribute identifiers, such as attribute names, and a corresponding second column or row with encrypted attribute values, i.e., with the identity attribute in encrypted form that the respective attribute identifier identifies.
[0013] Encryption of identity attributes using the first cryptographic key of the remote security element is an encryption that cannot be decrypted locally on the mobile device, but can only be decrypted on the server's security element, for example.
[0014] The additional encryption using the second cryptographic key of the mobile device can have the advantage that the mobile device's contribution to decrypting the identity attributes is necessary. For example, in addition to being encrypted using the first cryptographic key of the remote security element, the individual identity attributes are also encrypted using the second cryptographic key of the mobile device. Alternatively, the first set of identity attributes, for example in the form of a table, can be encrypted as a whole using the second cryptographic key of the mobile device.In both cases, the encryption must first be decrypted by the mobile device using the second cryptographic key to enable the remote security element to finally decrypt the selected identity attributes. Final decryption here means that the identity attributes are available in plaintext. For transmission to the reading computer system, the identity attributes can be encrypted in plaintext using the third cryptographic key of the reading computer system. This ensures that the mobile device must actively contribute to providing selected identity attributes to the reading computer system by decrypting the encryption created using the second cryptographic key.For example, this can prevent the first set of identity attributes from being sent virtually bypassing the user of the mobile device. The first set of identity attributes would be impossible to decrypt, for example, according to the security element's design.
[0015] Re-encryption of the selected identity attributes of the second set of identity attributes, wherein the encryption created using the first cryptographic key is decrypted and the identity attributes are encrypted in plain text with the third cryptographic key, can ensure that the re-encrypted second set of identity attributes can be decrypted, for example, only by the receiving reading computer system and not by the forwarding mobile terminal.
[0016] Embodiments may have the advantage of providing the possibility of using a remote security element, i.e., a remote security element, to provide cryptographic functions for an application installed on a mobile device. A corresponding security element comprises, for example, cryptographic keys for completing cryptographic protocols, such as encryption, decryption, and / or signatures. A corresponding security element therefore does not have to be implemented on the mobile device itself, but can be provided for the mobile device by a server that communicates with the mobile device via a network.
[0017] For example, the remote security element can be used for encrypted communication between the application installed on the mobile device and the reading computer system. For example, one or more electronic identities are stored on the mobile device. The electronic identities each comprise one or more identity attributes. The corresponding identity attributes are stored, for example, in encrypted form on the mobile devices. For example, the mobile device does not have one or more cryptographic keys for decrypting the encrypted identity attributes. For example, the identity attributes of different electronic identities are encrypted with different cryptographic keys. The cryptographic key(s) for decrypting the identity attributes are stored, for example, in the remote security element.Thus, the mobile device, and thus the user of the mobile device, has control over the identity attributes, while their cryptographic security is performed by the remote security element. Thus, on the one hand, the cryptographic security of the identity attributes can be outsourced to a remote server, while the user still retains control over the identity attributes. This means that the user can decide which identity attributes are made available to which computer system for reading. Without involving the mobile device, and thus the user of the mobile device, no identity attributes can be made available.
[0018] If identity attributes are to be read, the server receives the corresponding identity attributes from the application installed on the mobile device that manages the associated electronic identity. The server's remote security element decrypts the identity attributes to be read using a cryptographic key assigned to the electronic identity. The cryptographic key is, for example, a symmetric cryptographic key stored in the remote security element. For example, the security module is implemented in the form of a hardware security module (HSM) of the server. The corresponding security element can, for example, comprise an applet assigned to the corresponding application.For example, the corresponding cryptographic key for decrypting the identity attributes is stored in a sub-security domain of the security element assigned to the electronic identity. The decrypted identity attributes to be read are encrypted by the security element using an ephemeral symmetric key. The corresponding ephemeral symmetric cryptographic key was generated, for example, during the establishment of a cryptographically secured communication channel between the remote security element and the reading computer system. The corresponding ephemeral symmetric cryptographic key is stored in the remote security elements, for example, to secure communication with the reading computer system. Communication between the remote security element and the reading computer system is encrypted.The connection between the server on the one hand and the reading computer system on the other hand takes place, for example, via the application or the mobile device. The server sends encrypted identity attributes to the reading computer system using the ephemeral symmetric key.
[0019] Embodiments can have the advantage that hardware-based security of electronic identities can be provided on hardware independent of the mobile device, i.e., using the remote secure element, independent of the hardware and software configuration of the mobile device itself. For example, integrity, authenticity, and accountability of the electronic identities can be provided, for example, through authentication using the remote security element. Furthermore, decentralized storage of identity data on the mobile device can be enabled, whereby the user of the mobile device retains control over the identity attributes of their electronic identities. Furthermore, secure verification of the electronic identities on the mobile device can be ensured using suitable cryptographic methods.Finally, a variable and interchangeable use of authentication methods can be enabled.
[0020] Authentication refers to the verification of a claimed property of an entity, such as a user of a mobile device. During authentication, for example, the corresponding proof provided by the user is verified. The entity performs authentication through its contribution to the authentication process, i.e., by providing appropriate proof such as authentication data or authentication factors for verification.
[0021] Authentication of the user regarding the claimed property of authenticity, for example, the authenticity of their person or identity, allows the authenticated user to perform further actions. For example, the user is granted access rights. A successfully authenticated user is considered authentic. Final confirmation of authentication may include authorization.
[0022] The user can authenticate themselves in various ways. For example, they can provide proof of knowledge, such as a PIN or password, proof of possession, such as a cryptographic key, a certificate, or an electronic device, and / or proof of their own personal characteristics, such as biometric or behavioral characteristics. For example, the corresponding proof is captured by an authentication sensor on the mobile device in the form of the user's authentication data and compared by a security element on the mobile device with one or more stored reference values. The security element that evaluates the captured authentication data is, for example, a security element of the mobile device's operating system.If there is a sufficient match between the captured authentication data and the stored reference values, the security element confirms successful user authentication. For example, confirmation of successful user authentication involves executing a challenge-response procedure by the confirming security element. For example, upon successful user authentication, the confirming security element confirms this successful authentication to another security element, such as the remote security element, by issuing a correct response to a challenge from the remote security element.
[0023] A mobile device is a mobile, portable communication device, such as a smartphone, a tablet or a smartwatch.
[0024] An authentication sensor is understood to be a sensor for capturing authentication data of the user of the mobile device. The authentication data can, for example, include biometric data of the user. The authentication sensor can be configured to capture biometric data of the user. Biometric data can, for example, include: fingerprint data, body geometry data / anthropometry data, such as facial, hand, or ear geometry data, hand line structure data, vein structure data, such as palm vein structure data, iris data, retina data, voice recognition data, and nail bed patterns. The authentication sensor can, for example, comprise a camera of the mobile device. The authentication data can, for example, comprise user knowledge, such as a PIN or password. The authentication sensor can comprise an input device for entering authentication data, such as a PIN or password.The input device may, for example, comprise a keyboard and / or a touchscreen.
[0025] A challenge-response method represents a secure authentication method between a first instance and a second instance based on knowledge. For example, a first security element, such as a security element of the operating system of the mobile device, is authenticated by a second security element, such as the remote security element, using a challenge-response method. At the same time, the response represents confirmation of successful user authentication if the response is only generated under the condition of successful user authentication by the first security element. Thus, in the case of a successful challenge-response method, the second security element not only knows that the user authentication has been confirmed, but also that it has been confirmed by the first security element and is therefore valid.
[0026] In the course of a challenge-response procedure, a first instance presents a task ("challenge") to a second instance, for which the second instance must provide a correct answer ("response").
[0027] For example, the first instance generates a random number ("nonce") and sends it to the second instance. The second instance uses a shared secret to cryptographically transform the nonce and sends the result as a response to the first instance for the purpose of authenticating the second instance. For example, the nonce is combined with the shared secret and a cryptographic hash function or encryption is applied to this combination. Alternatively, the shared secret, such as a symmetric cryptographic key, can be used to encrypt the nonce. The first instance, which knows both the nonce and the shared secret, can, for example, perform the same computation as the second instance and / or perform an inverse computation, e.g., decrypt the encrypted nonce using the shared secret.If the result of the calculation by the first instance matches the result of the calculation of the second instance or the challenge, the challenge-response procedure is successful and the second instance is successfully authenticated.
[0028] Furthermore, a challenge-response procedure can also be based on an asymmetric cryptosystem and serve to prove to the first instance that the second instance possesses a private and thus secret cryptographic key. In this case, only the second instance knows the corresponding private cryptographic key, which it uses for a cryptographic transformation of the challenge, e.g., a nonce. The corresponding cryptographic transformation can, for example, be a digital signature. The first instance can use a public cryptographic key associated with the private cryptographic key to check the response to determine whether the second instance actually has knowledge of the private cryptographic key, without the first instance itself gaining knowledge of the private cryptographic key during the verification process.
[0029] A security element, also called a "Secure Element" or "SE," is a secured element of a mobile device that provides cryptographic means. These cryptographic means are protected against manipulation and are accessible only to authorized services and applications, for example, via cryptographic keys. In particular, the cryptographic means can only be inserted, added to, modified, and / or deleted in the security element by authorized services and applications.A security element therefore provides a tamper-proof platform, for example, implemented in the form of a secure single-chip microcontroller, on which applets and / or confidential and / or cryptographic data can be stored according to predefined rules and security requirements by reliably identified trusted entities and thus made available to authorized application programs and / or operating systems. A security element can be embedded or integrated, for example, non-destructively removable or permanently attached, i.e., not non-destructively removable. The security element can, for example, comprise a SIM, UICC, SmartMicroSD, smart card, eSE, eSIM, or eUICC. For example, cryptographic keys are stored on a security element, i.e., the security element comprises a data safe for cryptographic keys or a "key store." Such a key store orThe security element can also be implemented as part of the main processor, for example, in a TEE (Trusted Execution Environment). For example, the first security element can be implemented using a TEE. Security elements are implemented, for example, as hardware and / or firmware. According to embodiments, security elements or key stores can also be implemented as software. Two security elements are independent of each other, for example, if there is no common instance that has access rights for both security elements.
[0030] An application program, also called an application or app for short, is a computer program that provides, supports and / or enables the processing of non-system-technical functionality.
[0031] An applet is a computer program that is not run as a standalone application. The term "applet" is derived from the words "application" and "snippet."
[0032] An operating system is a computer program or a collection of computer programs that provides, supports, and / or enables the processing of system-specific functionalities. An operating system provides system resources. System resources refer to system elements or hardware components of a computer that are required by processes to function correctly.
[0033] A computer or computer system can be, for example, a stationary computer, such as a personal computer (PC), service terminal, or server, or a mobile, portable computer, such as a laptop, tablet, smartphone, or other smart device. The computer can include an interface for connecting to the network, which can be a private or public network, in particular the Internet. Depending on the embodiment, this connection can also be established via a mobile network.
[0034] A "user computer system" is defined here as a computer system to which the user has access. This could be, for example, a desktop computer (PC), a service terminal, or a mobile portable communications device such as a laptop, tablet, smartphone, or other smart device.
[0035] A "service server" is understood here to be a server or computer system on which a server program is executed and which provides the possibility of initiating, using and / or executing an offered service via a network.
[0036] A "program" or "program instructions" is understood here, without limitation, to mean any type of computer program that contains machine-readable instructions for controlling a functionality of the computer.
[0037] A "processor" is understood here and below to mean a logic circuit used to execute program instructions. The logic circuit can be implemented on one or more discrete components, in particular on a chip. In particular, a "processor" is understood to mean a microprocessor or a microprocessor system comprising multiple processor cores and / or multiple microprocessors.
[0038] The term "memory" refers here to both volatile and non-volatile electronic memories or digital storage media.
[0039] "Non-volatile memory" is defined here as an electronic memory for the permanent storage of data, particularly static cryptographic keys, attributes, or identifiers. Non-volatile memory can be configured as non-modifiable memory, also known as read-only memory (ROM), or as modifiable memory, also known as non-volatile memory (NVM). In particular, this can be an EEPROM, for example, a Flash EEPROM, also known as Flash. Non-volatile memory is characterized by the fact that the data stored on it is retained even after the power supply is switched off.
[0040] An "interface" or "communication interface" is understood here as an interface through which data can be received and sent. The communication interface can be configured as contact-based or contactless. A communication interface can, for example, enable communication over a network. Depending on the configuration, a communication interface can, for example, provide wireless communication according to a cellular standard, Bluetooth, RFID, Wi-Fi, and / or NFC standards. Depending on the configuration, a communication interface can, for example, provide cable-based communication. The communication interface can be an internal interface or an external interface.
[0041] Encrypted communication channels, for example, are encrypted end-to-end connections. An "encrypted end-to-end connection" or "encrypted end-to-end transmission channel" is understood here as a connection between a sender and a receiver with end-to-end encryption, in which the data to be transmitted is encrypted by the sender and only decrypted by the receiver. The encryption of transmitted data thus occurs across all transmission stations, so that intermediate stations cannot gain knowledge of the content of the transmitted data due to the encryption. The connection is cryptographically secured by encryption to prevent spying and / or manipulation of the transmission. A so-called secure messaging procedure can be used for this purpose.End-to-end encryption, for example, is based on two symmetric cryptographic keys, with a first symmetric key used to encrypt messages and a second symmetric key used to authenticate the sender of the message, for example, using Message Authentication Code (MAC) algorithms. For example, during the setup of an encrypted communication channel, ephemeral encryption keys are negotiated, which become invalid when the communication channel is terminated. Using different ephemeral keys for different communication channels makes it possible to operate multiple communication channels in parallel.
[0042] An encrypted communication channel can be established using the Transport Layer Security (TLS) protocol, for example as part of the Hypertext Transfer Protocol Secure (HTTPS) protocol.
[0043] Asymmetric key pairs are used in a variety of cryptosystems and play an important role in the secure transmission of electronic data. An asymmetric key pair consists of a public key, which is used to encrypt and / or decrypt data and may be passed on to third parties, such as a sender or receiver of data, and a private key, which is used for encryption and / or decryption but also for signing data and must generally be kept secret. The public key allows anyone to encrypt data for the owner of the private key or to verify digital signatures created with the private key. A private key allows its owner to decrypt data encrypted with the public key or to create digital signatures for data.
[0044] A digital signature of data includes, for example, creating a check value for the data, such as a hash value, which is encrypted with a private cryptographic key of an asymmetric key pair used as the signature key. In the case of a signature, only the signatory knows the private cryptographic key (i.e., signature key) of the asymmetric key pair used to create the signature. The signature recipient only has the public key (i.e., signature verification key) of the asymmetric key pair used for the signature. The signature recipient can therefore verify the signature but cannot calculate it themselves. To verify a signature, the signature recipient calculates, for example, the check value of the signed data and compares this with the result of decrypting the signature using the signature verification key.If the calculated hash value matches the decryption result, the signature is correct. If the authenticity of the signature verification key is also confirmed, for example, by a certificate, especially a PKI certificate, the signature is valid.
[0045] A "certificate" here refers to a digital certificate, also known as a public key certificate (PKI certificate). A certificate is structured data used to assign a public key of an asymmetric cryptosystem to an identity, such as a person, institution, or device. For cryptographic security and to prove the authenticity of the certificate data, these are signed by a certificate issuer. PKI certificates, which are based on asymmetric key pairs and, with the exception of a root certificate, are each signed by a certificate issuer with a signature key whose corresponding signature verification key is assigned to the certificate issuer by a PKI certificate of the corresponding certificate issuer, create a so-called Public Key Infrastructure (PKI). For example, the certificate can conform to the X.509 or another standard. For example, the certificate is a Card Verifiable Certificate (CVC). An authorization certificate includes structured data that additionally defines identity rights.
[0046] The PKI provides a system for issuing, distributing, and verifying digital certificates. In an asymmetric cryptosystem, a digital certificate can confirm the authenticity of a public cryptographic key and its permissible scope of use and validity. The digital certificate itself is protected by a digital signature, the authenticity of which can be verified using the public key of the certificate issuer. A digital certificate is used to verify the authenticity of the issuer key. In this way, a chain of digital certificates can be established, each of which confirms the authenticity of the public key with which the previous certificate can be verified. Such a chain of certificates forms a so-called validation path or certification path.For example, PKI participants must be able to rely on the authenticity of the last certificate, the so-called root certificate, and the key certified by it, without requiring any additional certificates. The root certificate is managed by a so-called root certification authority, whose assumed authenticity underlies the authenticity of all PKI certificates.
[0047] Digital certificates, for example, are confirmed by an independent, trustworthy authority (certification service provider / CSP or trust service provider / TSP), i.e. the certification authority that issued the certificate. Certificates can be made available to a wide group of people to enable them to verify electronic signatures for authenticity and validity. A certificate can be associated with an electronic signature and provide a signature verification key in the form of the public key if the private key associated with the signature verification key was used as the signature key. By making a certificate in association with a public key available to the public, a CSP / TSP enables users of asymmetric cryptosystems to assign the public key to an identity, for example, a person, organization, or computer system.
[0048] According to embodiments, the electronic identity may comprise an officially recognized identity, such as an electronic identity created on the basis of an official identification document, such as an identity card or passport.
[0049] A user's electronic identity is unambiguous, meaning it is unique and unmistakable. It is defined based on characteristics, so-called identity attributes. An electronic identity includes, for example, personal data. Personal data refers to data that enables the identification of a person or can be assigned to a person to whom the personal data relates.
[0050] A user can have multiple different, application-specific electronic identities. These electronic identities can meet different security requirements.
[0051] According to embodiments, an electronic identity stored on the mobile device and provided or managed by the ID application program can be used to identify and authenticate the user of the mobile device without additional hardware besides the mobile device.
[0052] Identity attributes are requested, for example, by service providers or online service providers. According to some embodiments, the identity attributes required by a service provider for its online service are transmitted in an encrypted and authentic manner. For example, authorization certificates are used to regulate who is authorized to access which identity attributes or who has read authorization for them. For example, the required identity attributes are read by an ID provider authorized to do so by means of an authorization certificate and made available to the requesting service provider. According to some embodiments, the ID provider only provides the requesting service provider with confirmation of the requested identity attribute(s).
[0053] The user's consent to the use of identity attributes and / or user authentication occurs, for example, by checking one or more authentication factors, such as password, PIN, fingerprint or facial recognition.
[0054] According to embodiments, the first cryptographic key of the security element is a symmetric cryptographic key associated with the electronic identity, which is stored in the remote security element. Embodiments can have the advantage that the symmetric cryptographic key does not leave the security element, and thus only the security element is capable of decrypting the data using the first cryptographic key in the form of the symmetric cryptographic key of the security element.
[0055] According to embodiments, the first cryptographic key of the security element is a public cryptographic key associated with the electronic identity, to which a private cryptographic key of the electronic identity stored in the remote security element is associated. Embodiments can have the advantage that the private cryptographic key does not leave the security element, and thus only the security element is capable of decrypting the data using the first cryptographic key in the form of the public cryptographic key of the security element.
[0056] According to embodiments, the encryption of the identity attributes of the first set of identity attributes encrypted using the first cryptographic key, which is created using the second cryptographic key, is an individual encryption of each of the individual identity attributes. The decryption during the selection process comprises a selective decryption of the encryptions of the selected identity attributes created using the second cryptographic key. Embodiments can have the advantage that, for the selected identity attributes, the encryptions created using the second cryptographic key are decrypted by the mobile terminal. For the identity attributes not selected, the encryptions created using the second cryptographic key remain.Thus, the mobile device and / or an authorized user operating the mobile device can selectively control which identity attributes the encryptions created using the second cryptographic key are decrypted for. Thus, access by the mobile device or the user of the mobile device can be effectively restricted to the selected identity attributes. Access to the attribute identifiers is possible, for example, without decrypting the encryptions created using the second cryptographic key.
[0057] According to embodiments, the encryption of the identity attributes of the first set of identity attributes encrypted using the first cryptographic key, which is created using the second cryptographic key, is an encryption of the first set of identity attributes as a whole. The decryption during the selection process comprises decrypting the encryption of the first set of identity attributes created using the second cryptographic key as a whole. The identity attributes are selected using the resulting decrypted first set of identity attributes. Embodiments may have the advantage that access to the attribute identifiers is possible, for example, only after decrypting the encryption of the first set of identity attributes as a whole, created using the second cryptographic key.Thus, the first set of identity attributes must first be decrypted as a whole before identity attributes can be selected for the second set. Thus, decrypting the encryption created using the second cryptographic key is a necessary prerequisite for making a selection and generating a second set of identity attributes.
[0058] According to embodiments, copies of the identity attributes whose encryption, created using the second cryptographic key, was decrypted during the selection process are deleted from the mobile device. For example, the deletion occurs after the second set of identity attributes has been sent to the server. Embodiments can have the advantage that identity attributes are only present on the mobile device during the creation of a second set of identity attributes without encryption using the second cryptographic key. For example, identity attributes are stored on the mobile device without encryption using the second cryptographic key only as temporary storage in a volatile memory of the mobile device.As a result, it can be ensured that in order to provide an identity attribute on the mobile device without encryption using the second cryptographic key, active decryption of the corresponding identity attributes by the mobile device is always necessary.
[0059] According to embodiments, the second cryptographic key of the mobile terminal is a private cryptographic key of the mobile terminal, which the mobile terminal uses together with a public cryptographic key of the remote security element or a public cryptographic key of a server of a personalization service to calculate a symmetric cryptographic key with which the mobile terminal decrypts the encryption of the identity attributes of the first set of identity attributes created using the second cryptographic key.
[0060] Embodiments can have the advantage of enabling the mobile device to calculate the symmetric cryptographic key for decryption using its private cryptographic key. To do so, the mobile device only requires an additional public key, which by definition is intended to be publicly accessible. The public cryptographic key of the remote security element is provided to the mobile device, for example, by the remote security element. The public cryptographic key of the personalization service server is provided to the mobile device, for example, by the corresponding server. Alternatively, the corresponding public cryptographic key can be part of the application, for example, in the form of a certificate.
[0061] During application personalization, a public cryptographic key of the mobile device is transmitted to the personalization service in the channel between the application and the personalization service. A private cryptographic key associated with this transmitted public cryptographic key is stored on the mobile device. The transmitted public cryptographic key and the associated private cryptographic key belong to the same asymmetric cryptographic key pair. The associated private cryptographic key is stored in a protected memory area on the mobile device. For example, the associated private cryptographic key is protected in a hardware key store, in a Trusted Execution Environment (TEE), or in a Secure Enclave.For example, a certificate can also be provided with the asymmetric key pair, which contains the public cryptographic key of the corresponding asymmetric key pair and is used to log in to the personalization service. For example, the login is performed using mutual Transport Layer Security authentication (mTLS). In this way, the public cryptographic key can be transferred to the personalization service along with the certificate, for example.
[0062] In the case of a symmetric cryptographic key, the encryption key is identical to the decryption key. Furthermore, this enables encryption of the identity attributes using the second cryptographic key when providing the identity attributes or the first set of identity attributes. For example, the corresponding symmetric cryptographic key can be calculated by the remote security element using the private cryptographic key of the remote security element and the public cryptographic key of the mobile device and used for encryption.For example, the corresponding symmetric cryptographic key can be calculated by the personalization service server using a private cryptographic key of the personalization service server and the public cryptographic key of the mobile terminal and used for encryption.
[0063] According to embodiments, the second cryptographic key of the mobile terminal is a public cryptographic key of the mobile terminal. The mobile terminal uses the private cryptographic key of the mobile terminal to decrypt the encryption of the identity attributes of the first set of identity attributes created using the second cryptographic key.
[0064] Embodiments may have the advantage that only the mobile terminal, with its private cryptographic key, is capable of decrypting the encryption created using the second cryptographic key, i.e., the public cryptographic key of the mobile terminal. At the same time, for example, the server of the personalization service or the remote security element is enabled to encrypt the identity attributes with the second cryptographic key.
[0065] According to embodiments, use of the private cryptographic key of the mobile terminal to decrypt the encryption created using the second cryptographic key requires, during the selection process, approval by an authorized user of the mobile terminal, which requires successful authentication of the authorized user by the mobile terminal.
[0066] Embodiments may have the advantage that the use of the mobile device's private cryptographic key, and thus the use of the identity attributes to create the second set of identity attributes, requires approval by an authorized user of the mobile device. The authorized user grants the approval and thus their consent by authenticating themselves to the mobile device. If the user's authentication by the mobile device is successful, the mobile device's private cryptographic key can be used. Such successful authentication is confirmed, for example, by means of a successful challenge-response procedure.
[0067] According to embodiments, the attribute identifiers of the identity attributes to be read, which are included in the read request, are displayed to the user of the mobile device as a selection suggestion on a display device of the mobile device for confirmation. Confirmation includes authenticating the user to the mobile device to authorize the use of the mobile device's private cryptographic key. Embodiments can have the advantage of explicitly displaying to the user which identity attributes are being requested with the read request for reading by the reading computer system. Based on the displayed attribute identifiers, the user can decide whether they actually want to authorize the associated identity attributes or those identified by them for reading.
[0068] According to embodiments, the user can remove attribute identifiers from the selection suggestion, whereby identity attributes whose attribute identifiers have been removed from the selection suggestion are not considered during the selection process. Embodiments can have the advantage that the user can decide whether all or which of the requested identity attributes are made available to the reading computer system.
[0069] According to embodiments, the user can add additional attribute identifiers of additional identity attributes from the first set of identity attributes to the selection suggestion, wherein additional identity attributes whose attribute identifiers were added to the selection suggestion are also taken into account during the selection. Embodiments can have the advantage of allowing the user to provide additional identity attributes to the reading computer system during the reading process.
[0070] According to embodiments, the third cryptographic key of the reading computer system is an ephemeral public cryptographic key of the reading computer system. The second set of identity attributes is encrypted with the ephemeral public cryptographic key of the reading computer system, to which an ephemeral private cryptographic key of the reading computer system is assigned for decryption. Embodiments can have the advantage that only the reading computer system, with its ephemeral private cryptographic key, is able to decrypt the encryption of the second set of identity attributes created using the third cryptographic key. Thus, only the reading computer system can decrypt the identity attributes of the second set of identity attributes and thus use them in plaintext form.
[0071] Alternatively, the second set of identity attributes is encrypted with a first ephemeral symmetric cryptographic key, which is computable using the private cryptographic key of the security element stored in the remote security element in conjunction with the ephemeral public cryptographic key of the reading computer system. The first ephemeral symmetric cryptographic key is further computable for decryption using the ephemeral private cryptographic key of the reading computer system in conjunction with the public cryptographic key of the security element.
[0072] Embodiments may have the advantage that the remote security element, using its private cryptographic key in conjunction with the ephemeral public cryptographic key of the reading computer system, is enabled to calculate the third cryptographic key of the reading computer system in the form of the first ephemeral symmetric cryptographic key and thus to use it to encrypt the second set of identity attributes. The mobile terminal receives the corresponding ephemeral public cryptographic key of the reading computer system, for example, during authentication of the reading computer system to the remote security element.At the same time, the reading computer system is enabled to decrypt the encrypted second set of identity attributes using the ephemeral private cryptographic key of the reading computer system in conjunction with the public cryptographic key of the security element and to provide the corresponding identity attributes in plain text for use.
[0073] According to embodiments, the second set of identity attributes is encrypted by the mobile device using a fourth cryptographic key before being sent to the server. Embodiments may have the advantage that the second set of identity attributes can be additionally secured before being sent, so that, for example, only the remote security element can access it.
[0074] According to embodiments, the fourth cryptographic key is the public cryptographic key of the security element associated with the electronic identity, to which the private cryptographic key of the security element stored in the remote security element is assigned for decryption. Embodiments may have the advantage that access to the second set of identity attributes is possible exclusively with the private cryptographic key of the security element.
[0075] According to embodiments, the fourth cryptographic key is a second ephemeral symmetric cryptographic key, which the mobile terminal calculates using the private cryptographic key of the mobile terminal and the public cryptographic key of the security element associated with the electronic identity. The second ephemeral symmetric cryptographic key can be further calculated for decryption using the public cryptographic key of the mobile terminal and the private cryptographic key of the security element associated with the electronic identity.
[0076] Embodiments may have the advantage that the remote security element, using its private cryptographic key in conjunction with the security element's public cryptographic key associated with the electronic identity, is enabled to calculate the fourth cryptographic key in the form of the second ephemeral symmetric cryptographic key and thus to use it to encrypt the second set of identity attributes. At the same time, the remote security element is enabled to decrypt the encrypted second set of identity attributes using the security element's private cryptographic key associated with the electronic identity in conjunction with the mobile terminal's public cryptographic key.In addition, if the encryption created using the first cryptographic key is decrypted, the corresponding identity attributes can be made available for use in plain text.
[0077] According to embodiments, each of the identity attributes to be read out in the second set of identity attributes is assigned an attribute identifier. Embodiments may have the advantage that the structure of the second set of identity attributes can, for example, be identical to the structure of the first set of identity attributes. For example, the second set of identity attributes represents a subset of the first set of identity attributes. For example, if the first set of identity attributes is provided in the form of a table, the second set of identity attributes can be provided, for example, as an abbreviated table.
[0078] According to embodiments, the first set of identity attributes further comprises the public cryptographic key of the mobile terminal, which is encrypted using the first cryptographic key. The public cryptographic key of the mobile terminal, encrypted using the first cryptographic key, is added to the second set of identity attributes to prove access of the mobile terminal to the first set of identity attributes. Embodiments can have the advantage that the first and second sets of identity attributes can each be additionally bound to the mobile terminal using the encrypted public cryptographic key of the mobile terminal. Furthermore, access of the mobile terminal to the first set of identity attributes can thus be proven. If the mobile terminal does not have the necessary means, iehas the first cryptographic key, it cannot encrypt the public cryptographic key of the mobile device itself, but must extract it from the first set of identity attributes.
[0079] According to embodiments, the mobile device receives the first set of identity attributes from the remote security element during personalization by the personalization service server. The encryption of the identity attributes of the first set is performed using the first and second cryptographic keys by the personalization service server or by the remote security element.
[0080] Embodiments may have the advantage that the first set of identity attributes can be provided in a secure form during personalization. By encrypting the identity attributes with the first cryptographic key, the security of the identity attributes can be ensured even in the case of an insecure environment on the mobile device. If the first cryptographic key is, for example, the public cryptographic key of the remote security element, the encryption can be performed, for example, by the server of the personalization service. If the first cryptographic key is, for example, a symmetric cryptographic key of the remote security element, the encryption can be performed, for example, by the remote security element.
[0081] According to embodiments, the method further comprises authenticating the reading computer system by the application. During the process of authenticating the reading computer system, the application receives the ephemeral public cryptographic key of the reading computer system and forwards the received ephemeral public cryptographic key to the server.
[0082] Embodiments may have the advantage that the authentication of the reading computer system can be carried out by the application, in the course of which a public cryptographic key of the reading computer system for negotiating session keys for encrypting a communication between the remote security element and the reading computer system can be provided to the remote security element through the mediation of the application.
[0083] According to embodiments, the method further comprises authenticating the electronic identity to the reading computer system. Authenticating the electronic identity comprises receiving the public cryptographic key of the remote security element associated with the electronic identity from the server by the application, which forwards the received public cryptographic key of the remote security element to the reading computer system.
[0084] Embodiments may have the advantage that the security element can provide a public cryptographic key of the electronic identity for authenticating the electronic identity to the reading computer system through the mediation of the application or the mobile terminal for the reading computer system.
[0085] According to embodiments, the public cryptographic key is received together with a certificate and forwarded to the reading computer system.
[0086] According to embodiments, authenticating the electronic identity further comprises receiving a first random number generated by the remote security element together with an authentication token generated by the remote security element from the server by the application, which forwards the received random number together with the authentication token to the reading computer system.
[0087] Embodiments may have the advantage that an authentication token, together with a random number for authenticating the electronic identity, can be provided to the reading computer system via the application or mobile device. Using the authentication token and the corresponding random number, the reading computer system is enabled, for example, to authenticate the electronic identity, i.e., to check whether the corresponding electronic identity has access to a private cryptographic key associated with the corresponding electronic identity.
[0088] According to embodiments, upon forwarding the public cryptographic key of the security element from the reading computer system, the application receives a second copy of the ephemeral public cryptographic key of the reading computer system, which the application forwards to the server for comparison with the first copy of the ephemeral public cryptographic key of the reading computer system.
[0089] Embodiments may have the advantage that the second copy of the ephemeral public cryptographic key can be used to check whether the reading computer system against which the electronic identity is authenticated is the same one from this computer system that was previously authenticated by the application of the mobile terminal.
[0090] According to embodiments, the application receives the second set of identity attributes encrypted using the third cryptographic key together with a verification code of the second set of identity attributes, which the application forwards to the reading computer system.
[0091] Embodiments may have the advantage that the authenticity of the encrypted second set of identity attributes can be verified by the reading computer system, which receives the corresponding reading computer system from the remote security element, based on the verification code.
[0092] According to embodiments, the authentication of the electronic identity to the reading computer system also requires a successful authentication of the application to the server.
[0093] Embodiments may have the advantage that the application proves to the server through successful authentication an authorization, i.e. an authorization to use the remote security element or a sub-security domain of the remote security element which is assigned to the electronic identity.
[0094] Depending on the embodiment, authenticating the application to the server includes: Sending a challenge request to the server, receiving a second random number generated by the remote security element as a challenge from the server in response to the challenge request, generating a response, wherein the received challenge is encrypted by a security element of the operating system of the mobile terminal using a cryptographic key associated with the electronic identity, wherein the cryptographic key associated with the electronic identity is stored in the security element of the operating system of the mobile terminal, sending the generated response to the server in response to the challenge.
[0095] Embodiments may have the advantage that the corresponding challenge-response procedure enables the application to authenticate to the server in an effective and efficient manner.
[0096] According to embodiments, the cryptographic key assigned to the electronic identity is a symmetric cryptographic key, which is used to generate the response. In this case, the response can be verified for correctness on the recipient side, for example, using the symmetric cryptographic key.
[0097] According to embodiments, the cryptographic key assigned to the electronic identity is a private cryptographic key with which the response is generated. For example, the generated response includes a signature of the challenge with the private cryptographic key as the signature key. For example, the challenge or a hash value of the challenge is encrypted using the private cryptographic key. In this case, the response can be verified for correctness on the recipient side, for example, using the associated public cryptographic key as the signature verification key.
[0098] According to embodiments, the generation of the response by the application requires successful authentication of the user by the mobile device.
[0099] Embodiments can have the advantage that, by requiring successful user authentication, it can be ensured that an authorized user is actually using the mobile device to provide the identity attributes, which is cryptographically linked to the electronic identity or identity attributes. On the other hand, it can be ensured that the user actually consents to the provision of the identity attributes.
[0100] According to embodiments, the server with the removed security element performs, for example, a method comprising: Receiving the second set of identity attributes from the application, decrypting the encryption of the selected identity attributes to be read out in the received second set of identity attributes created using the first cryptographic key by the remote security element, encrypting the second set of identity attributes with the decrypted identity attributes to be read out using the third cryptographic key by the remote security element, sending the second set of identity attributes encrypted using the third cryptographic key to the mobile terminal for forwarding to the reading computer system.
[0101] According to embodiments, sending the identity attributes to be read out, encrypted using the ephemeral symmetric cryptographic key, to the reading computer system comprises sending them to the application for forwarding to the reading computer system.
[0102] Embodiments may have the advantage that communication between the server and the reading computer system takes place via the application or the mobile device. The mobile device or the application forwards messages between the reading computer system and the server. If the corresponding messages include, for example, encrypted identity attributes encrypted using an ephemeral cryptographic key known only to the server or the security element provided by the server, on the one hand, and the reading computer system, on the other, end-to-end encryption can be implemented between the server and the reading computer system.
[0103] According to embodiments, the cryptographic key associated with the electronic identity is a symmetric cryptographic key stored in the remote security element.
[0104] According to embodiments, the cryptographic key associated with the electronic identity is a public cryptographic key of an asymmetric key pair. A private key of the asymmetric key pair is stored in the remote security element.
[0105] Embodiments can have the advantage that symmetric encryption enables efficient and effective encryption. If the symmetric cryptographic key(s) is / are stored in security elements, these can be efficiently and effectively protected from unauthorized access.
[0106] According to embodiments, the method further comprises generating the ephemeral symmetric cryptographic key shared with the reading computer system.
[0107] Embodiments may have the advantage that the server or the remote security element provided by the server can generate the ephemeral symmetric cryptographic key required for encrypted communication with the reading computer system. The ephemeral symmetric cryptographic key is, for example, a session-specific symmetric cryptographic key assigned to a session. If a new session is to be started, a new ephemeral cryptographic key must be generated, for example.
[0108] According to embodiments, the remote security element generates the ephemeral symmetric cryptographic key using a secret shared with the reading computer system and a first random number.
[0109] Embodiments may have the advantage of providing an effective and efficient method for generating the ephemeral symmetric cryptographic key. Since the generation of the ephemeral symmetric cryptographic key is based on a secret shared with the reading computer system, the corresponding cryptographic key can be effectively and efficiently protected from access by unauthorized third parties, for example. Knowledge of the shared secret is necessary to generate the corresponding key.
[0110] According to embodiments, generating the ephemeral symmetric cryptographic key shared with the reading computer system requires successful authentication of the electronic identity to the reading computer system using the remote security element.
[0111] Embodiments can have the advantage that by authenticating the electronic identity to the reading computer system, it can be ensured that the corresponding identity attributes of the correct electronic identity are read. Authentication is performed using the remote security element provided by the server. For example, a private cryptographic key of an asymmetric key pair associated with the electronic identity is stored on the remote security element. This private cryptographic key is used, for example, to authenticate the electronic identity to the reading computer system.
[0112] According to embodiments, the authentication of the electronic identity to the reading computer system by the server comprises: Sending a public cryptographic key of an asymmetric key pair associated with the electronic identity to the reading computer system, wherein a private cryptographic key of the asymmetric key pair is stored in the remote security element; Calculating the secret shared with the reading computer system by the remote security element using the private cryptographic key of the electronic identity and an ephemeral public cryptographic key of the reading computer system; Generating the first random number by the remote security element; Generating a common ephemeral authentication key for authenticating information during communications with the reading computer system using the shared secret and the generated first random number;Generating an authentication token by the remote security element using the ephemeral authentication key and the ephemeral public cryptographic key of the reading computer system to authenticate the electronic identity to the reading computer system, sending the first random number together with the authentication token to authenticate the electronic identity to the reading computer system to the computer system to be read.
[0113] Embodiments may have the advantage that the corresponding applications can be authenticated to the reading computer system, for example, using the applets of the applications installed in the security elements that manage the electronic identities. The reading computer system receives the public cryptographic key in the application and can also calculate the shared secret using this public cryptographic key and an ephemeral second private cryptographic key of the asymmetric key pair comprising the ephemeral second public cryptographic key. Upon receiving the random number, the reading computer system can also calculate the shared authentication key.Using the authentication key calculated in this way and the received random number, the reading computer system can validate the received authentication token. For example, if an authentication token calculated by the reading computer system using the calculated authentication key and the received random number matches the received authentication token, the reading computer system indicates that the application is actually in possession of the corresponding private cryptographic key of the asymmetric key pair assigned to the application. The application is therefore authenticated.
[0114] The remote security element manages the private cryptographic key for the electronic identity or securely stores it. Using the private cryptographic key of the electronic identity stored by the remote security element, the authentication token is generated and made available to the reading computer system for authenticating the electronic identity. Using the authentication token, the reading computer system can verify whether the electronic identity has the corresponding private cryptographic key or has access to it. If so, the electronic identity is considered authenticated.
[0115] According to embodiments, the ephemeral symmetric cryptographic key is calculated by the remote security element together with the ephemeral authentication key.
[0116] According to embodiments, sending the public cryptographic key of the electronic identity to the reading computer system comprises sending it to the application for forwarding to the reading computer system.
[0117] Embodiments may have the advantage that communication between the server and the reading computer system takes place via the mobile device. The mobile device or the application forwards messages between the reading computer system and the server. If the corresponding messages include, for example, encrypted identity attributes encrypted using an ephemeral cryptographic key known only to the server or the security element provided by the server, on the one hand, and the reading computer system, on the other, end-to-end encryption can be implemented between the server and the reading computer system.
[0118] Embodiments can have the advantage that communication between the server and the reading computer system takes place via the application or the mobile device. The mobile device or the application forwards messages between the reading computer system and the server. During this communication, for example, the public cryptographic key of the electronic identity is sent from the server or the remote security element to the reading computer system via the application or the mobile device. Only the corresponding public cryptographic key enables the reading computer system to authenticate the electronic identity.
[0119] According to some embodiments, the public cryptographic key is sent to the reading computer system along with a certificate. According to some embodiments, the reading computer system has access to a certificate, for example, the certificate is stored in a memory of the reading computer system or the certificate is retrievable from an online registry.
[0120] According to embodiments, sending the first random number together with the authentication token to the reading computer system comprises sending it to the application for forwarding to the reading computer system.
[0121] Embodiments may have the advantage that communication between the server and the reading computer system takes place via the application or the mobile device. The mobile device or application forwards messages between the reading computer system and the server. For example, the first random number, together with the authentication token for authenticating the electronic identity, is sent to the reading computer system via the application or the mobile device.
[0122] According to embodiments, the authentication of the electronic identity to the reading computer system requires successful authentication of the reading computer system by the application.
[0123] Embodiments can have the advantage that authentication of the reading computer system can be carried out by the application, i.e., the mobile device. By authenticating the reading computer system, the reading computer system can be authenticated, on the one hand, and access rights of the reading computer system to the identity attributes to be read can be validated, on the other hand. If the reading computer system is successfully authenticated, this means that it has, for example, the authorization to read requested identity attributes. During the authentication of the reading computer system, for example, the ephemeral public cryptographic key of the reading computer system is received by the mobile device and made available to the server or remote security element.
[0124] According to embodiments, the server receives the ephemeral public cryptographic key of the reading computer system from the application, which receives the ephemeral public cryptographic key in the course of authenticating the reading computer system and forwards it to the server.
[0125] Embodiments may have the advantage that the application or the mobile device provides the ephemeral public cryptographic key to the server.
[0126] According to embodiments, in response to the sending of the public cryptographic key associated with the electronic identity from the reading computer system, the server receives a second copy of the ephemeral public cryptographic key of the reading computer system, which the server compares with the first copy of the ephemeral public cryptographic key of the reading computer system, which the application received during the authentication of the reading computer system and forwarded to the server. A match between the two copies is a prerequisite for calculating the shared secret.
[0127] Embodiments may have the advantage that, using the second copy of the ephemeral public cryptographic key of the reading computer system, the server can check whether the reading computer system against which the authentication of the electronic identity is carried out is the same reading computer system that was previously authenticated by the application or the mobile terminal.
[0128] According to embodiments, the method further comprises calculating a verification code of the decrypted identity attributes to be read out using the ephemeral authentication key, which is sent to the reading computer system together with the identity attributes to be read out encrypted using the ephemeral symmetric cryptographic key.
[0129] Embodiments can have the advantage that the authenticity of the encrypted identity attributes to be read can be verified for the reading computer system using the verification code. This is because the executing computer system also has the corresponding ephemeral authentication key, for example, with which the verification code can be validated.
[0130] According to embodiments, the ephemeral authentication key is a key for generating a message authentication code. The verification code is a MAC code of the identity attributes to be read, generated using the ephemeral authentication key.
[0131] The authenticity of the transmitted identity attributes can be ensured, for example, by using a Message Authentication Code (MAC). A MAC is calculated, for example, using a MAC algorithm to which the data to be protected, i.e. the identity attributes, and a cryptographic key, for example a symmetric cryptographic key, are provided as input data. Using this input data, the MAC algorithm calculates a checksum, which serves as the MAC. Block ciphers or hash functions, for example, can be used to calculate MACs. An HMAC (Keyed-Hash Message Authentication Code), for example, can be used as a MAC. For example, a cryptographic hash function, such as the Secure Hash Algorithm (SHA), and a secret cryptographic key, for example a symmetric cryptographic key, are used for its construction.
[0132] To secure a data transmission, for example the transmission of identity attributes, a cryptographic key, for example a symmetric cryptographic key, is agreed between the sender, for example the applet, and the receiver, for example a reading computer system. The sender uses this cryptographic key to calculate a MAC of the data to be transmitted and sends the calculated MAC along with the data to be transmitted to the receiver. The receiver, in turn, calculates a MAC for the received data using the cryptographic key and compares the result with the received MAC. If there is a match between the calculated MAC and the received MAC, the integrity check is successful and the received data is considered authentic.
[0133] In the case of a MAC, both sender and receiver must know the cryptographic key used, in contrast to the use of pure hash functions or signatures. In the case of pure hash functions, for example, no cryptographic keys are used. If the hash functions are public, anyone can calculate the hash value, especially for manipulated messages. In the case of a signature, only the signer knows the private cryptographic key used to create the signature (i.e., the signature key) of an asymmetric key pair used for the signature. The signature recipient only has the public key (i.e., the signature verification key) of the asymmetric key pair used for the signature. The signature recipient can therefore verify the signature using the signature verification key, but cannot calculate it themselves.
[0134] According to embodiments, the authentication token is a MAC code of the first random number generated using the ephemeral authentication key.
[0135] According to embodiments, the authentication of the electronic identity to the reading computer system also requires successful authentication of the application by the server.
[0136] Embodiments may have the advantage that, using the authentication of the application and the server, it can be ensured that the communication is actually with the corresponding application.
[0137] According to embodiments, authentication by the server includes: Receiving a challenge request from the application, generating a second random number as a challenge by the remote security element, sending the generated challenge to the application in response to the challenge request, receiving a response in response to the sending of the challenge, wherein the response is the challenge encrypted using a cryptographic key associated with the electronic identity, validating the response by the remote security element using a further cryptographic key associated with the electronic identity and stored in the remote security element.
[0138] According to embodiments, the cryptographic key and the additional cryptographic key of the electronic identity are the same symmetric cryptographic key. The response is generated using this symmetric cryptographic key. In this case, the response can be verified for correctness on the recipient side, for example, using the same symmetric cryptographic key.
[0139] According to embodiments, the cryptographic key assigned to the electronic identity is a private cryptographic key with which the response is generated. The second cryptographic key assigned to the electronic identity is, for example, a public cryptographic key with which the response is verified. For example, the generated response includes a signature of the challenge with the private cryptographic key as the signature key. For example, the challenge or a hash value of the challenge is encrypted using the private cryptographic key. In this case, the response can be verified for correctness on the recipient side, for example, using the associated public cryptographic key as the signature verification key.
[0140] Embodiments can have the advantage that, using the challenge-response method, it can be ensured that the application is actually the application managing the corresponding electronic identity. The cryptographic key assigned to the electronic identity, which is used by the mobile devices to encrypt the challenge, is, for example, a cryptographic key stored in a security element of the operating system of the mobile device.
[0141] According to embodiments, validating the response comprises decrypting the response by the remote security element using the additional cryptographic key associated with the electronic identity, for example, a symmetric or public cryptographic key, and comparing the result with the sent challenge generated by the remote security element. If there is a match, the validation is successful.
[0142] According to embodiments, validating the response comprises encrypting the sent challenge generated by the remote security element by the remote security element using the symmetric cryptographic key associated with the electronic identity and comparing the result with the response challenge. If there is a match, the validation is successful.
[0143] According to embodiments, the generation of the response by the application requires successful authentication of the user by the mobile device.
[0144] Embodiments can have the advantage that the challenge-response method can be used to authenticate not only the application, but also the user of the mobile device. In other words, it can be ensured that an authorized user is using the mobile device and explicitly consents to the transmission of identity attributes to the reading computer system. For this purpose, for example, authentication data of the current user is captured by one or more sensors of the mobile device. The corresponding authentication data can be, for example, a PIN of the user, biometric data of the user, such as a fingerprint or a facial image, or behavior-based data, such as gross motor movement data of the movements of the mobile device that the user carries with them.The corresponding authentication data is sent to the operating system's security element, which compares it with the stored reference data that was stored in the operating system's security element during the personalization of the mobile device. If there is a sufficient match between the recorded authentication data and the stored reference data, the authentication of the mobile device user is successful. Upon successful authentication of the mobile device user, the previously received challenge is encrypted using the corresponding symmetric or private cryptographic key of the electronic identity, which was stored in the operating system's security element during the setup of the electronic identity on the mobile device.For example, the corresponding symmetric or private cryptographic key was stored during the personalization process in order to bind the user of the mobile device to the electronic identity.
[0145] Embodiments further include a mobile device. An electronic identity is stored on the mobile device and managed by an application installed on the mobile device. The mobile device includes a processor, a memory with executable program instructions, and a communication interface for communicating with a server via a network, which server provides a remote security element for the electronic identity.
[0146] The electronic identity comprises a first set of identity attributes stored on the mobile device, which comprises one or more identity attributes. The identity attributes in the first set of identity attributes are each individually encrypted using a first cryptographic key of the remote security element. An attribute identifier is each assigned to the identity attributes in the first set of identity attributes. The identity attributes of the first set of identity attributes encrypted using the first cryptographic key are further encrypted using a second cryptographic key of the mobile device. The processor is configured, upon execution of the program instructions, to control the mobile device to execute a method for reading one or more identity attributes of the electronic identity.
[0147] The process includes the application on the mobile device: Receiving a read request from a reading computer system, which attribute identifiers comprise one or more identity attributes to be read out, selecting the identity attributes to be read out from the first set of identity attributes, wherein in the course of the selection, the encryption created using the second cryptographic key is at least partially decrypted while the encryption created using the first cryptographic key is maintained, creating a second set of identity attributes, which comprises the selected identity attributes to be read out, which are encrypted using the first cryptographic key, sending the second set of identity attributes to the server in response to the sending of the second set of identity attributes,Receiving the second set of identity attributes encrypted using a third cryptographic key of the reading computer system from the server, wherein the encryption of the selected identity attributes to be read out in the received second set of identity attributes created using the first cryptographic key was decrypted by the remote security element before encryption with the third cryptographic key, forwarding the second set of identity attributes encrypted using the third cryptographic key to the reading computer system.
[0148] According to embodiments, the mobile terminal is configured to carry out each of the above-described embodiments of the method for reading one or more identity attributes.
[0149] Embodiments further include a server that provides the remote security element for the electronic identity stored on a mobile device and managed by the application installed on the mobile device. The server further includes a processor, a memory with executable program instructions, and a communication interface for communicating with the mobile device via a network. Upon execution of the program instructions, the processor is configured to control the server to execute a method for reading one or more identity attributes of the electronic identity. The method includes: Receiving the second set of identity attributes from the application, decrypting the encryption of the selected identity attributes to be read out in the received second set of identity attributes created using the first cryptographic key by the remote security element, encrypting the second set of identity attributes with the decrypted identity attributes to be read out using the third cryptographic key by the remote security element, sending the second set of identity attributes encrypted using the third cryptographic key to the mobile terminal for forwarding to the reading computer system.
[0150] According to embodiments, the server is configured to perform each of the above-described embodiments of the method for reading one or more identity attributes.
[0151] Embodiments further include a distributed system comprising a mobile terminal according to one of the aforementioned embodiments of a mobile terminal. The distributed system further includes a server that provides the remote security element for the electronic identity stored on a mobile terminal and managed by the application installed on the mobile terminal. The server further includes a processor, a memory with executable program instructions, and a communication interface for communicating with the mobile terminal via a network. The processor is configured, upon execution of the program instructions, to control the server to execute a method for reading one or more identity attributes of the electronic identity.
[0152] The procedure includes: Receiving the second set of identity attributes from the application, decrypting the encryption of the selected identity attributes to be read out in the received second set of identity attributes created using the first cryptographic key by the remote security element, encrypting the second set of identity attributes with the decrypted identity attributes to be read out using the third cryptographic key by the remote security element, sending the second set of identity attributes encrypted using the third cryptographic key to the mobile terminal for forwarding to the reading computer system.
[0153] According to embodiments, the system is configured to perform each of the above-described embodiments of the method for reading one or more identity attributes.
[0154] According to embodiments, the distributed system further comprises a personalization service server. The personalization service server further comprises a processor, a memory with executable program instructions, and a communication interface for communicating via the network with the server providing the remote security element for the electronic identity. Upon execution of the program instructions, the processor is configured to control the personalization service server to incorporate the first set of identity attributes into the mobile terminal.
[0155] The introduction includes: Providing the identity attributes of the first set of identity attributes with the attribute identifiers for personalizing the mobile device, proving authorization to incorporate identity attributes into the mobile device, sending the provided identity attributes via the mobile device to the server with the remote security element for forwarding to the mobile device.
[0156] According to embodiments, the personalization service server creates the first set of identity attributes using the provided identity attributes with the attribute identifiers. Creating the first set of identity attributes includes encrypting the provided identity attributes using the first and / or second cryptographic key. The identity attributes are sent in the form of the first set of identity attributes to the server with the removed security element.
[0157] According to embodiments, the security element creates the first set of identity attributes using the identity attributes received from the personalization service server with the attribute identifiers. Creating the first set of identity attributes comprises encrypting the provided identity attributes using the first and / or second cryptographic key. The identity attributes are forwarded to the mobile device in the form of the first set of identity attributes.
[0158] Embodiments of the invention will be explained in more detail below with reference to the drawings. They show: Figure 1 shows a schematic diagram of an exemplary mobile terminal, Figure 2 shows a schematic diagram of an exemplary set of identity attributes, Figure 3 shows a schematic diagram of an exemplary server providing a remote security element, Figure 4 shows a flowchart of an exemplary method for reading identity attributes, Figure 5 shows a flowchart of an exemplary method for reading identity attributes, Figure 6 shows a flowchart of an exemplary method for initializing application-specific cryptographic security functions, Figure 7 shows a flowchart of an exemplary method for initializing application-specific cryptographic security functions, Figure 8 shows a flowchart of an exemplary central authentication of a reading computer system, Figure 9 shows a flowchart of an exemplary authentication of an applet of a remote security element,Figure 10 is a schematic diagram of an exemplary mobile terminal, Figure 11 is a schematic diagram of an exemplary server providing a remote security element, and Figure 12 is a schematic diagram of an exemplary system.
[0159] Elements of the following embodiments that correspond to one another are identified by the same reference numerals.
[0160] Figure 1shows an exemplary mobile device 100, for example a smartphone, which comprises a memory 104 with program instructions that are executed by a processor 102. The program instructions can, for example, comprise an operating system 106 installed on the mobile device 100 and one or more applications or application programs 108. For example, the mobile device 100 comprises a security element 110 that is assigned to the operating system 106 and provides cryptographic means for it, such as cryptographic keys, cryptographic functions and / or cryptographic protocols. The security element 110 of the operating system 106 represents, for example, a key store orKey storage is provided for storing cryptographic keys, such as symmetric, public, and / or private cryptographic keys, and certificates, such as authorization certificates, public key certificates, and / or attribute certificates. The cryptographic means provided by the first security element 110 enable the operating system 106, for example, to encrypt and / or decrypt data, as well as to create and / or verify signatures. For example, the cryptographic means provided by the first security element 110 enable the operating system 106 to execute or participate in a challenge-response procedure.
[0161] Furthermore, the mobile device 100 comprises a user interface 118, which, for example, comprises a display, in particular a touchscreen. Using the user interface 118, the user can interact with the mobile device 100. For example, the user can be prompted to provide authentication data or authentication features. To capture the user's authentication data, the mobile device 100 comprises a sensor or authentication sensor 120, which can, for example, be integrated into the user interface 118 or implemented as a standalone component. The authentication data can, for example, include the user's biometric data, such as: fingerprint data, body geometry data / anthropometry data, such as facial, hand, or ear geometry data, hand line structure data, vein structure data, such as hand vein structure data, iris data, retina data, voice recognition data, and nail bed patterns.The authentication data can, for example, include user knowledge, such as a PIN or password. Furthermore, the authentication data can, for example, include behavioral characteristics or behavioral data of the user, such as movement data of the mobile device 100, which are caused by gross and / or fine motor movements of the user when the user carries and / or uses the mobile device 100. Appropriate authentication of the user can, for example, be a prerequisite for releasing identity attributes of the electronic identity for reading by a reading computer system. Appropriate user authentication can, on the one hand, ensure that the mobile device 100 is being used by an authorized user.Secondly, the provision of authentication data by the user can constitute the user's consent to the reading of the identity attributes of the electronic identity by the reading computer system. Finally, the mobile terminal 100 comprises a communication interface 122, such as an antenna, which is configured for contactless or contact-based communication, for example, with the reading computer system. For example, communication with the reading computer system can take place via a network, such as an intranet or the internet.
[0162] Furthermore, a set of identity attributes 109 of an electronic identity managed by the application 108 is stored in the memory of the mobile terminal 100, which set comprises one or more identity attributes in encrypted form. Furthermore, the set of identity attributes 109 comprises, for example, attribute identifiers that identify the encrypted identity attributes. In this case, the mobile terminal 100 has, for example, the encrypted identity attributes of the set 109 without being able to decrypt them, while a remote security element provided by a server has, for example, a cryptographic key for decrypting the identity attributes 109. Thus, the cryptographic security of the identity attributes of the set 109 can be outsourced to the server or the remote security element provided by the server, while the mobile terminal 100 orThe user of the mobile terminal 100 retains control over the identity attributes of set 109 and thus their corresponding electronic identity. The mobile terminal 100 is configured, for example, to enable a reading of identity attributes of set 109, which are managed by the application 108, by a reading computer system. For example, the mobile terminal 100 receives a read request from the reading computer system via the communication interface 122 for the identity attributes of set 109 to be read. The read request includes attribute identifiers that identify the identity attributes of set 109 to be read.The mobile terminal 100 selects the identity attributes to be read out from set 109 in encrypted form using the attribute identifiers, creates a second set of identity attributes with the selected encrypted identity attributes from set 109, and sends this second set to the server via the communication interface 122. In response to the transmission of the identity attributes to be read out, the mobile terminal 100 receives the identity attributes 109 to be read out via the communication interface 122 for forwarding to the reading computer system. The identity attributes to be forwarded have been decrypted by the server and re-encrypted using a third cryptographic key, such as an ephemeral symmetric cryptographic key.The remote security element of the server decrypts, for example, the encryption of the selected identity attributes to be read out, created using the first cryptographic key, in the received second set of identity attributes before encrypting them with the third cryptographic key. The mobile terminal 100 forwards the identity attributes 109 to be read out, encrypted using the third cryptographic key, to the reading computer system via the communication interface 122.
[0163] Figure 2shows a schematic diagram of an exemplary set of identity attributes. The set of identity attributes has, for example, a data structure in the form of a table 109. Attribute identifiers, such as attribute names, are stored in a first column 103, which identify the respective associated identity attribute in the second column 105. The identity attributes in the second column 105 are each individually encrypted, for example, with a first cryptographic key. Nevertheless, the unencrypted attribute identifiers in the first column 103 make it possible to identify the respective identity attribute.Although the content of the identity attributes remains unknown, the specific identity attributes to be read, such as a first name, a last name, a street, a house number, a postal code, a place of residence, a date of birth, a place of birth, and / or a nationality, can be selected and made available for reading. For this purpose, for example, the rows of table 109 whose attribute identifiers are included in the read request are selected from the first table 109 and copied, so that a second set of identity attributes is generated in the form of a second table, which is a subset of the rows of table 109. In addition to the encryption using the first cryptographic key, the set of identity attributes in the form of table 109 can be encrypted with a second cryptographic key.This second encryption using the second cryptographic key will be decrypted, for example, during the course of selecting identity attributes from table 109 by the mobile device. For example, the individual identity attributes in column 105 of table 109 are additionally individually encrypted with the second cryptographic key, or table 109 can be encrypted as a whole with the second cryptographic key, for example.
[0164] Figure 3shows an exemplary server 280, which, as a remote server, provides a remote security element 292 for use by a mobile device or for an electronic identity managed by an application of the mobile device via a network. The server 280 further comprises, for example, a processor 282, a memory 284, and a communication interface 296. Program instructions 288 are stored in the memory 284 for reading identity attributes stored on the mobile device, which are managed by the application. The identity attributes to be read are made available to a reading computer system. Upon execution of the program instructions 288, the processor 282 controls the server 280, for example, to receive the identity attributes to be read from the application using the communication interface 296.The identity attributes are encrypted using a first cryptographic key assigned to the electronic identity. The security element 292 has a cryptographic key 285 for decrypting the identity attributes. In the case of symmetric encryption, the cryptographic key 285 is, for example, the corresponding symmetric key. In the case of asymmetric encryption, the identity attributes are encrypted, for example, with a public cryptographic key, the corresponding private cryptographic key of which is stored as the cryptographic key 285 in the remote security element 292. The remote security element 292 decrypts the identity attributes to be read using the cryptographic key 285.Furthermore, the remote security element 292 encrypts the decrypted identity attributes to be read using a cryptographic key 286 stored in the remote security element 292, for example, an ephemeral symmetric cryptographic key. The remote security element 292 shares this ephemeral symmetric cryptographic key 286, for example, with the computer system performing the readout for communication encryption. Finally, the server 280 sends the encrypted identity attributes to be read to the computer system performing the readout using the communication interface 296. For example, the server 280 sends the encrypted identity attributes to be read to the mobile terminal for forwarding to the computer system performing the readout.
[0165] The remote security element 292 comprises, for example, a key ring 294 assigned to the application and / or the electronic identity. The key ring 294 provides the application 108 with identity-specific cryptographic keys for the electronic identity it manages. Furthermore, the remote security element 292 comprises, for example, further cryptographic means, such as cryptographic functions and / or cryptographic protocols, which the remote security element makes available to the application or the electronic identity for use. The key ring 294 is stored, for example, using a key store orA key store is provided for storing cryptographic keys for the individual electronic identity, such as symmetric, public and / or private cryptographic keys, and certificates, such as public key certificates and / or attribute certificates. The cryptographic means provided by the remote security element 292 enable the application 108, using the key ring 294 with the identity-specific cryptographic keys, to, for example, encrypt and / or decrypt data for the electronic identity managed by the application 108, as well as to create and / or verify signatures. For example, the cryptographic means provided by the remote security element 292 enable the application 108 to execute a challenge-response procedure for the electronic identity it manages.to participate in this. The security element 292 can be implemented, for example, as a hardware security module. A hardware security module refers to an internal or external peripheral device that enables efficient and secure execution of cryptographic operations and / or applications. Cryptographic keys used by the security module are stored there, for example, protected both in software and against physical attacks or side-channel attacks.
[0166] For example, the server 280 further comprises a security management program module 290 of a security management service managing the security element 292. For example, the server 280 is a server of the security management service or a standalone server. The security management service provides, for example, the applet 294 for installation in the security element 294. For example, the server 280 comprises a plurality of security elements 292, each managed by an individual security management service. For each of the security elements 292, for example, a security management program module 290 is installed on the server 280. For example, the server 280 comprises exactly one security element 292 or exclusively security elements 292 that are managed by the same security management service.For example, a plurality of servers 280 are provided, which are assigned to different security management services and comprise exclusively security elements 292, which are managed by the same security management service to which the corresponding server 280 is assigned.
[0167] Figure 4shows an exemplary method for reading identity attributes of an electronic identity. The electronic identity is stored on a mobile device and is managed by an application installed on the mobile device. A remote security element is provided for the electronic identity on a server. The server communicates with the mobile device via a network. In block 300, a first set of identity attributes is provided on the mobile device, which includes one or more identity attributes. The electronic identity includes the corresponding first set of identity attributes stored on the mobile device. The identity attributes in the first set of identity attributes are each individually encrypted using a first cryptographic key of the remote security element.Each identity attribute in the first set of identity attributes is assigned an attribute identifier. The identity attributes of the first set of identity attributes, encrypted using the first cryptographic key, are further encrypted using a second cryptographic key of the mobile device. In block 302, the application on the mobile device receives a read request from a reading computer system for identity attributes to be read, which identifies the identity attributes to be read using their attribute identifiers. In block 304, the mobile device selects the identity attributes to be read from the first set of identity attributes.During the selection process, the encryption created using the second cryptographic key is at least partially decrypted, while the encryption created using the first cryptographic key is maintained. Identification of the identity attributes to be read, which are still encrypted, is performed using the attribute identifiers. In block 306, a second set of identity attributes is created, which includes the selected identity attributes to be read, which are encrypted using the first cryptographic key. In block 308, the application sends the identity attributes to be read in their encrypted form, i.e., in the form of the second set of identity attributes, to the server over the network. The sent identity attributes are encrypted using a cryptographic key assigned to the electronic identity.The corresponding key can be, for example, a symmetric cryptographic key or a public cryptographic key of an asymmetric key pair. The remote security element of the server has a cryptographic key for decrypting the identity attributes, e.g., the corresponding symmetric cryptographic key or a private cryptographic key associated with the public cryptographic key. In block 310, the application of the mobile terminal receives, in response to the transmission of the identity attributes to be read, the second set of identity attributes re-encrypted by the security element of the server. The re-encrypted second set of identity attributes is encrypted using a third cryptographic key of the reading computer system.The encryption of the selected identity attributes to be read out, created using the first cryptographic key, in the re-encrypted second set of identity attributes was decrypted by the remote security element before encryption with the third cryptographic key. The identity attributes of the re-encrypted second set of identity attributes are therefore no longer encrypted with the first cryptographic key. In block 312, the application forwards the re-encrypted second set of identity attributes to the reading computer system in response to the read request received in block 300.
[0168] Figure 5shows an exemplary method for reading identity attributes of an electronic identity stored on a mobile device and managed by an application installed on the mobile device using a server. The server provides a remote security element for the electronic identity. The identity attributes to be read are stored in encrypted form on the mobile device. The server communicates with the mobile device via a network. In block 320, the server receives identity attributes to be read via the network from the application of the mobile device that manages the corresponding electronic identity. The received identity attributes are encrypted using a first cryptographic key associated with the electronic identity.The corresponding key can be, for example, a symmetric cryptographic key or a public cryptographic key of an asymmetric key pair. The remote security element of the server has a cryptographic key for decrypting the identity attributes, e.g., the corresponding symmetric cryptographic key or a private cryptographic key associated with the public cryptographic key. In block 322, the remote security element decrypts the identity attributes to be read using the cryptographic key stored in the security element.In block 324, the remote security element encrypts the decrypted identity attributes to be read using a third cryptographic key stored in the remote security element, such as an ephemeral symmetric cryptographic key. The remote security element shares this ephemeral symmetric cryptographic key, for example, with the reading computer system for communication encryption. In block 326, the server sends the re-encrypted identity attributes to be read over the network to the reading computer system. For example, the server sends the re-encrypted identity attributes to be read to the mobile device for forwarding to the reading computer system.
[0169] Figure 6shows an exemplary method for initializing application-specific cryptographic security functions on a remote security element of a server for an application of a mobile device. In block 340, a mobile application is installed on the mobile device. In block 342, an initialization request is sent from the installed application, for example, via a network, to a security management program module of the security management service installed on the server, which manages the remote security element of the server. The initialization request requests implementation of application-specific cryptographic security functions for the application in the remote security element, which is managed by the corresponding security management service. In block 344, the server's security management program module receives the application's initialization request.In block 346, the security management program module sends an initialization request to a server of the selected security management service, requesting that the security management service implement the application-specific cryptographic security functions for the installed application on the remote security element. Alternatively, the server with the remote security element may be a server of the security management service, which could eliminate the second initialization request. In block 348, for example, an encrypted channel is established between the remote security element and the server of the selected security management service. For this purpose, a cryptographic key of the security management service is used, for example.This cryptographic key of the security management service, for example, verifies write access reserved for the security management service to the security element managed by the security management service. In block 350, the application is cryptographically coupled to the remote security element, thereby enabling the application to use the application-specific cryptographic security functions provided by the remote security element. For example, a cryptographic key associated with the electronic identity managed by the application is stored in the remote security element. The corresponding cryptographic key can be, for example, a symmetric cryptographic key or a cryptographic key of an asymmetric key pair, which is stored in the remote security element.The stored cryptographic key can, for example, be generated by the remote security element or received from the security management service managing the remote security element. For example, the cryptographic key is introduced into the remote security element from a server of the security management service via an encrypted channel. In the case of an asymmetric key pair generated by the remote security element, a public cryptographic key of the corresponding asymmetric key pair is made available to the server of the selected security management service via the security management program module of the corresponding security management service.
[0170] Figure 7shows a further exemplary method for initializing application-specific cryptographic security functions for a mobile application on a remote security element of a server for an application of a mobile device. In block 360, the mobile application is installed on the mobile device. In block 362, the installed application determines which remote security elements on servers are available to the mobile device and can be used to provide application-specific cryptographic security functions for the mobile application. In block 364, at least one of the servers with a determined remote security element is selected. For example, multiple servers with a determined security element are selected. The selection can be made automatically. For example, a selection suggestion can also be created and displayed to the user of the mobile device.The user can, for example, agree to the suggestion or change it. According to embodiments, part of the suggestion is mandatory and cannot be changed by the user, while another part is optional and can be changed by the user. The selected remote security elements are each managed by a security management service. For each of these security management services, for example, a security management program module is installed on the server providing the corresponding remote security element. If a security management program module is missing for one of the security management services, it can, for example, be installed on the server during the method. For each of the selected remote security elements, blocks 366 to 374 are executed, which are identical to blocks 344 to 350 of the . Figure 6 .
[0171] Figure 8shows an exemplary method for authenticating the application 108 of the mobile terminal by the server 280 using the remote security element 292. In step 400, the server receives a challenge request sent by the application over a network. In step 402, for example, the security element 292 generates a challenge for the application, which is, for example, a random number. In step 404, the server 280 sends the challenge over the network to the application, which generates a response using the challenge in step 406. For example, the application generates the response using a symmetric cryptographic key associated with the electronic identity. The response is, for example, a signature of the challenge.The cryptographic key used to create the challenge, for example, a symmetric cryptographic key, is provided by a security element of the mobile device's operating system. Use of the corresponding cryptographic key and thus the generation of the response requires, for example, successful authentication of the user by the mobile device. For this purpose, biometric characteristics of the user are captured and compared with reference characteristics stored, for example, in the security element of the operating system. Successful authentication of the user simultaneously represents, for example, the user's consent to read the identity attributes. In step 408, the server 280 receives the application's response and validates it in step 410.For example, the signature is verified using a cryptographic key stored in the remote security element as a signature verification key. If the signature verification is successful, the application and, if applicable, the user are considered authenticated. Furthermore, a successful signature verification represents, for example, confirmation of the user's consent to read the identity attribute.
[0172] Figure 9shows a method for authenticating an electronic identity managed by an application on a mobile device against a computer system reading identity attributes of the corresponding identity using a remote security element provided by a server over a network. In step 500, the server 280 or the remote security element sends a public cryptographic key K PU of an asymmetric key pair associated with the electronic identity to the reading computer system 200. In step 502, the remote security element 292 calculates a secret S shared with the reading computer system 200 using a private cryptographic key K PR of the asymmetric key pair associated with the electronic identity and an ephemeral public cryptographic key received from the reading computer system 200. K PU ˜ of the reading computer system 200. The corresponding public cryptographic key K PU ˜ of the reading computer system 200 is received by the application during the authentication of the reading computer system 200 and forwarded to the remote security element. For example, during the authentication of the applications, a second copy of the ephemeral public cryptographic key K PU ˜ received, which is linked to the copy of the ephemeral public cryptographic key received during the authentication of the reading computer system 200 K PU ˜ In step 504, the reading computer system 200 also calculates the shared secret S. For this purpose, the reading computer system 200 uses, for example, the public cryptographic key K PU sent in step 500 as well as the ephemeral public cryptographic key K PU ˜ belonging ephemeral private cryptographic key K PR ˜ . In step 506, the remote security element 292 generates a random number RN. In step 508, the remote security element 292 generates an authentication key K MAC , e.g., a key for generating a MAC code, as well as a symmetric cryptographic key K SYM . The keys K SYM and K MAC serve, for example, to encrypt data sent by the remote security element 292 for the application to the reading computer system 200, such as identity attributes, and to prove their authenticity, e.g., using a MAC code. In step 510, the remote security element 292 generates an authentication token T using the authentication key K MAC and the ephemeral public cryptographic key K PU ˜ . In step 512, the authentication token T is sent to the reading computer system 200 together with the random number RN generated in step 506. In step 514, the reading computer system 200 uses the received random number RN together with the shared secret S calculated in step 504 to calculate the authentication key K MAC , e.g., a key for generating a MAC code, as well as the symmetric cryptographic key K SYM . Finally, in step 516, the received authentication token T is encrypted by the reading computer system 200 using the key K MAC and the ephemeral public cryptographic key K PU ˜ validated. For example, the reading computer system 200 also calculates the authentication token T and compares the result with the received authentication token T. If both match, the application or the electronic identity managed by it is successfully authenticated.
[0173] Figure 10shows an exemplary mobile terminal 100 on which one or more application programs 108 are stored, which are, for example, ID application programs. An ID application program 108 manages, for example, one or more electronic identities assigned to the user with identity attributes. For this purpose, it comprises, for example, an ID management module 107 with one or more identities or ID profiles 113. Each of the electronic identities 113 is, for example, a keychain 294 with one or more of the electronic identities 113 in a remote security element 292 of a server 280, such as the one shown in Figure 11shown server 280. Each of the electronic identities 113 is assigned a set of one or more identity attributes. These identity attributes are stored in encrypted form in a memory of the mobile terminal 100. The cryptographic keys for decrypting the encrypted identity attributes are, in this case, stored, for example, in the corresponding key rings 294 in a remote security element 292. The ID application program 108 further comprises, for example, an ID client module 105, via which the ID application program 108 can receive, for example, requests for identity attributes of one of the ID profiles 113 from a reading computer system.In response to the request, for example, by an ID provider service over a network, the ID application program 108 can provide the requested identity attributes after successful central authentication of the reading computer system, provided the user consents. This may require user authentication to the ID application program 108, or proof of successful user authentication by the ID application program 108 using a challenge-response method may be necessary. For this purpose, a security element 110 assigned to the operating system 106 is used. This security element 110 performs, for example, user authentication with an authentication sensor of the mobile terminal 100 and confirms the successful user authentication to the remote security element 292. The confirmation is also performed, for example, using a challenge-response method.For example, successful user authentication simultaneously constitutes the user's consent to the reading of the requested identity attributes. For example, the user may have the option to influence, e.g., change, the selection of identity attributes made available for reading via a user interface.
[0174] Figure 11 shows an exemplary server 290 comprising a remote security element 292 in which key rings 294 for one or more electronic identities, such as the identities of the profiles 113 of the Figure 10 , are stored. The electronic identities are, for example, stored by one or more mobile devices, such as the mobile device 100 in Figure 10, provided. The identity attributes of the corresponding electronic identities are stored, for example, in encrypted form on the mobile devices. The remote security element 292 or the key rings 294 each comprise a cryptographic key for decrypting the encrypted identity attributes. Furthermore, the remote security element 292 or the key rings 294 each comprise a cryptographic key 286 for encrypting the decrypted identity attributes for a reading computer system, i.e., in such a way that the reading computer system can decrypt the identity attributes.
[0175] Figure 12shows an exemplary system 170, which includes, for example, a mobile terminal 100 connected via a network 150, for example, the Internet, to a server 280 providing a remote security element 292. Furthermore, a security management service server 240, a personalization server 220, an ID provider server 200, and / or a service provider server 260 are connected via the network 150.
[0176] The security management service server 240 manages, for example, the security element 292 provided by the server 280. Alternatively, the server 280 can also be configured as the security management service server 240. For example, a security management program module 290 of the server 280 is assigned to the security management service server 240. If a key ring for the application 108 of the mobile terminal 100 is to be initialized in the security element 292, this is carried out, for example, via the security management program module 290 using the security management service server 240. The security management service server 240 comprises, for example, a processor 202, a memory 204, and a communication interface 210.Program instructions 208 are stored in the memory 204. When executed, the processor 202 controls the security management service server 240 to initialize the keychain 294 in the remote security element 292 of the server 280, which is managed by the corresponding security management service. The keychain 294 is assigned, for example, to the application 108 of the mobile terminal 100 or to an electronic identity managed by the corresponding application. To verify write authorization for installing the keychain 294, the security management service server 240 uses, for example, a security management service-specific cryptographic key 206.
[0177] The personalization server 220 comprises, for example, a processor 222, a memory 224, and a communication interface 230. Program instructions 228 are stored in the memory 224. When executed, the processor 222 controls the personalization server 220 to provide a symmetric key for a challenge-response process between the security elements 110, 292 of the mobile terminal 100 and the server 280. Thus, the initialized key ring 294 can be linked to the security element 110, which performs user authentication using the sensor 120, and thus to the user of the mobile terminal 100. To verify write authorization for adding the symmetric key to the memory area of the remote security element 292 of the server 280 assigned to the key ring 294, the personalization server 220 uses, for example, the authorization certificate 226.
[0178] The service provider server 260 comprises, for example, a processor 262, a memory 264, and a communications interface 270. Program instructions 268 are stored in the memory 264. When executed, the processor 262 controls the service provider server 260 to provide services that can be requested and / or used, for example, by the mobile terminal 100 via the network 150. Using services from the service provider server 260 requires, for example, the provision and / or verification of one or more identity attributes of the user. Upon a request for a service from the service provider server 260 by the mobile terminal 100, the service provider server 260 sends an identity attribute request to an ID provider server 200 for reading identity attributes of the user of the mobile terminal 100.The identity attribute request can be sent from the service provider server 260 to the ID provider server 200, for example, directly or via the mobile terminal 100. The identity attributes to be read out are, for example, identity attributes of various electronic identities stored on the mobile terminal 100.
[0179] The ID provider server 200 comprises, for example, a processor 242, a memory 244, and a communication interface 250. Program instructions 248 are stored in the memory 244. When executed, the processor 242 instructs the service provider server 260 to read the identity attributes specified in the identity attribute request from a memory of the mobile terminal 100. To this end, the ID provider server 200 establishes a cryptographically secured communication channel via the mobile terminal 100 or the application 108 with the remote security element 292 of the server 280. The cryptographically secured communication channel can, for example, be an end-to-end encrypted communication channel. For example, this requires mutual authentication between the ID provider server 200 as the reading computer system and the applications 108 or 108 managing the electronic identities.the corresponding electronic identities by the remote security element 292 of the server 280. For read access to the identity attributes to be read, the ID provider server 200 uses the applications 108 on the mobile terminal 100, which manage the electronic identities with the identity attributes to be read. For secure transmission, the identity attributes to be read are sent unencrypted by the remote security element 292 of the server 280 for the reading computer system 200. The ID provider server 200, as the reading computer system, sends a corresponding access request to the mobile terminal 100. The ID provider server 200 verifies read authorization to read the identity attributes specified in the identity attribute request, for example, with the authorization certificate 246. The ID provider server 200 sends the authorization certificate 246, for example, together with the access request.The received authorization certificate 246 is validated by the mobile terminal 100, for example, during central authentication. Furthermore, read access by the ID provider server 200 to the identity attributes specified in the identity attribute request requires, for example, consent from the user of the mobile terminal 100. To do this, the user must successfully authenticate themselves to the ID application program 108. The mobile terminal 100 authenticates the user, for example, using the sensor 120 and the security element 110 of the operating system 106. The security element 110 confirms the successful user authentication to the remote security element 292 or the key ring 294 encompassed by it. This can be done, for example, using a challenge-response method.For example, a display device of the user interface 118 indicates to the user which identity attributes are to be sent to the ID provider server 200, and allows the user to edit this selection. For example, the user can select which of the requested identity attributes are actually sent. Upon successful proof of read authorization or authentication of the ID provider server 200 and successful user authentication, the released identity attributes are provided or sent to the ID provider server 200 using the remote security element 292. The ID provider server 200, for example, signs the received identity attributes and sends them to the service provider server 260. List of reference symbols
[0180] 100 mobile device 102 processor 103 column 104 memory 105 column 105 ID client 106 operating system 107 ID management module 108 application 109 set of identity attributes 110 security element 113 electronic identity 118 user interface 120 authentication sensor 122 communication interface 150 network 170 system 200 ID provider server 202 processor 204 memory 206 cryptographic key 208 program instructions 210 communication interface 220 personalization server 222 processor 224 memory 226 authorization certificate 228 program instructions 230 communication interface 240 security management service server 242 processor 244 memory 246 authorization certificate 248Program instructions 250Communication interface 260Service provider server 262Processor 264Memory 266Program instructions 270Communication interface 280Server 282Processor 284Memory 285Cryptographic key 286Symmetric key 288Program instructions 290Security management program module292Security element 294Keychain 296Communication interface
Claims
1. A method for personalising a security applet (114) installed on a first security element (112) of a mobile terminal (100), using a first ID token (200) and a personalisation server (220), wherein an ID application program (108) is installed on the mobile terminal (100), to which the security applet (114) is assigned, wherein first attributes (206) of a user are stored in the first ID token (200), wherein the personalisation comprises: • establishing an encrypted communication channel (160) between the mobile terminal (100) and the personalisation server (220) via a network (150), wherein the ID application program (108) is used to establish the encrypted communication channel (160), • establishing a first encrypted subchannel (162) between the first ID token (200) and the personalisation server (220) within the encrypted communication channel (160) via the mobile terminal (100), wherein the ID application program (108) is used to establish the first encrypted subchannel (162), • reading out one or more of the first attributes (206) from the first ID token (200) by the personalisation server (220) via the first encrypted subchannel (162) within the encrypted communication channel (160), • establishing a second encrypted subchannel (164) between the security applet (114) of the first security element (112) and the personalisation server (220) within the encrypted communication channel (160), wherein the ID application program (108) is used to establish the second encrypted subchannel (164), • receiving, by the security applet (114) of the first security element (112), the read-out first attributes (206) from the personalisation server (220) via the second encrypted subchannel (164) within the encrypted communication channel (160), • storing the received first attributes (206) by the security applet (114), wherein the ID application program (108) is configured to use the first attributes (206) to prove an identity of the user to another computer system.
2. The method according to claim 1, wherein the encrypted communication channel (160) is encrypted with a first channel-specific ephemeral symmetric cryptographic session key, wherein the first encrypted subchannel (162) is encrypted with a second channel-specific ephemeral symmetric cryptographic session key, wherein the second encrypted subchannel (162) is encrypted with a third channel-specific ephemeral symmetric cryptographic session key.
3. The method according to any one of the preceding claims, wherein the encryption of the encrypted communication channel (160) is an end-to-end encryption between the mobile terminal (100) and the personalisation server (220), and / or wherein the encryption of the first encrypted subchannel (162) is an end-to-end encryption between the first ID token (200) and the personalisation server (220), and / or wherein the encryption of the second encrypted subchannel (164) is an end-to-end encryption between the security applet (114) and the personalisation server (220).
4. The method according to any one of the preceding claims, wherein the personalisation further comprises: • generating an asymmetric cryptographic key pair associated with the ID application program (108) by the security applet (114) of the first security element (112) comprising a private cryptographic key and a public cryptographic key of the ID application program (108), wherein the asymmetric key pair is used to authenticate the ID application program (108) in the course of using the first attributes (206), and / or wherein the personalisation further comprises: • receiving one or more root signature verification keys by the security applet (114) of the first security element (112) from the personalisation server (220) via the second encrypted subchannel (164) within the encrypted communication channel (160), wherein the received root signature verification keys are for verifying certificate signatures of one or more root instances having certificates each used in the course of a readout of the first attributes (206) for authenticating a reading computer system to the ID application program (108), • storing the received root signature verification keys by the security applet (114) in the first security element (112), and / or wherein the personalisation further comprises: • receiving a signature of the first attributes (206) from the personalisation server (220) by the security applet (114) of the first security element (112) via the second encrypted subchannel (164) within the encrypted communication channel (160), wherein the signature serves as proof of authenticity of the first attributes (206), • storing the received signature of the first attributes (206) by the security applet (114) in the first security element (112).
5. The method according to any one of claims 2 to 4, wherein establishing the encrypted communication channel (160) comprises negotiating the first channel-specific ephemeral symmetric cryptographic session key.
6. The method according to claim 5, wherein negotiating the first channel-specific ephemeral symmetric cryptographic session key comprises: • generating a first random value by the mobile terminal (100), • generating the first channel-specific ephemeral symmetric cryptographic session key using the first random value by the mobile terminal (100), • receiving a first certificate (226) of the personalisation server (220) with a first public cryptographic key of a first asymmetric cryptographic key pair of the personalisation server (220) by the mobile terminal (100) from the personalisation server (220), • encrypting the first random value using the received first public cryptographic key of the personalisation server (220) by the mobile terminal (100), • sending the encrypted first random value to the personalisation server (220) by the mobile terminal (100) to generate the first channel-specific ephemeral symmetric cryptographic session key by the personalisation server (220).
7. The method according to claim 6, wherein establishing the encrypted communication channel (160) further comprises a mutual authentication of the ID application program (108) and / or the mobile terminal (100) and the personalisation server (220).
8. The method according to claim 7, wherein the mobile terminal (100) further comprises a second security element (110), wherein the second security element (110) comprises a first initial private cryptographic key of a first initial asymmetric cryptographic key pair of the ID application program (108), wherein the mobile terminal (100) also comprises an initial certificate of the ID application program (108), which comprises the initial public cryptographic key of the initial asymmetric cryptographic key pair of the ID application program (108), wherein, for authentication to the personalisation server (220), the mobile terminal (100) sends, for example, the initial certificate of the ID application program (108) to the personalisation server (220) as well as a message signed by the second security element (110) with the first initial private cryptographic key of the ID application program.
9. The method according to claim 8, wherein the mobile terminal (100) further comprises one or more authentication sensors (118) for detecting one or more authentication factors of the user, wherein an operating system (106) installed on the mobile terminal (100) is configured to control the authentication sensor (118), wherein the second security element (110) is assigned to the operating system (106), wherein the prerequisite for signing with the first initial private cryptographic key of the ID application program (108) is successful authentication of the user to the second security element (110), wherein the user is registered on the mobile terminal (100) and at least one reference value of the registered user is stored in the second security element (110) for verifying at least one detected authentication factor.
10. The method according to any one of the preceding claims, wherein establishing the first encrypted subchannel (162) comprises authenticating the user to the ID token (200) via the mobile terminal (100), wherein authenticating the user to the ID token (200) in particular comprises: • receiving, by the ID application program (108), a further authentication factor of the user detected by the one or more authentication sensors (118), • generating a symmetric cryptographic key by the second security element (110) using the received further authentication factor, • receiving an encrypted second random value by the ID application program (108) from the ID token (200), wherein the encrypted second random value is encrypted using the symmetric cryptographic key generated by the ID token (200) using a further reference value of the registered user stored in the ID token (200) for verifying the further authentication factor, • decrypting the received encrypted second random value by the second security element (110) using the generated symmetric cryptographic key, • generating a first ephemeral asymmetric cryptographic key pair of the ID application program (108) by the second security element (110), which comprises a first ephemeral private cryptographic key and a first ephemeral public cryptographic key of the ID application program (108), • sending the first ephemeral public cryptographic key of the ID application program (108) to the ID token (200), • receiving an ephemeral public cryptographic key of the ID token (200), • generating a first secret shared with the ID token (200) using the decrypted second random value, the first ephemeral private cryptographic key of the ID application program (108) and the ephemeral public cryptographic key of the ID token (200), • generating a first shared authentication key for mutual authentication of the ID application program (108) and ID token (200) by the second security element (110) using the shared first secret, • generating a first authentication token using the first authentication key and the ephemeral public cryptographic key of the ID token (200) by the second security element (110), • sending the first authentication token to the ID token (200) by the second security element (110), • receiving a second authentication token from the ID token (200) by the second security element (110), • verifying the received second authentication token using the first authentication key and the first ephemeral public cryptographic key of the ID application program (108), and / or wherein establishing the first encrypted subchannel (162) comprises authenticating the personalisation server (220) by the ID token (200) via the mobile terminal (100), wherein authenticating the personalisation server (220) by the ID token (200) in particular comprises: • receiving a second certificate (226) of the personalisation server (220), which comprises a second public cryptographic key of a second asymmetric cryptographic key pair of the personalisation server (220), via the encrypted communication channel (160), • verifying a signature of the received second certificate (226) of the personalisation server (220), • generating a third random value by the ID token (200), • sending the third random value as a challenge to the personalisation server (220) via the encrypted communication channel (160), • receiving a first signature of the challenge as a response from the personalisation server (220) via the encrypted communication channel (160), wherein the challenge is signed using a second private cryptographic key of the personalisation server (220), • verifying the received first signature using the second public cryptographic key of the personalisation server (220) and the sent third random value, and / or wherein establishing the first encrypted subchannel (162) comprises authenticating the ID token (200) to the personalisation server (220) via the mobile terminal (100), wherein authenticating the ID token (200) to the personalisation server (220) in particular comprises: • sending the public cryptographic key of the ID token (200) from the ID token (200) to the personalisation server (220) via the encrypted communication channel (160), • receiving the second ephemeral public cryptographic key of the personalisation server (220) by the ID token (200) from the personalisation server (220) via the encrypted communication channel (160), • generating a second secret shared with the personalisation server (220) by the ID token (200) using the private cryptographic key of the ID token (200) and the second ephemeral public cryptographic key of the personalisation server (220), • generating a fourth random value by the ID token (200), • generating a second common authentication key for authenticating data sent over the first encrypted subchannel (162) by the ID token (200), wherein the second common authentication key is generated using the shared second secret and the fourth random value, • generating a third authentication token by the ID token (200) using the second authentication key and the second ephemeral public cryptographic key of the personalisation server (220) to authenticate the ID token (200) to the personalisation server (220), • sending the fourth random value together with the third authentication token to authenticate the ID token (200) by the ID token (200) via the encrypted communication channel (160) to the personalisation server (220), and / or wherein establishing the second encrypted subchannel (164) comprises authenticating the user by the second security element (110), wherein establishing the second encrypted subchannel (164) further comprises executing a challenge-response procedure between the second security element (110) and the first security element (112), wherein a successful execution of the challenge-response procedure confirms a successful authentication of the user by the second security element (110), and / or wherein establishing the second encrypted subchannel (164) further comprises authenticating the personalisation server (220) by the security applet (114) of the first security element (112), wherein authenticating the personalisation server (220) by the security applet (114) of the first security element (112) in particular comprises: • receiving a third certificate (226) of the personalisation server (220), which comprises a third public cryptographic key of the personalisation server (220), by the security applet (114) of the first security element (112) via the encrypted communication channel (160), • verifying a signature of the received third certificate (226) of the personalisation server (220) by the security applet (114) of the first security element (112), • receiving a third ephemeral public cryptographic key of the personalisation server (220) by the security applet (114) of the first security element (112), • generating a fifth random value as a challenge by the security applet (114) of the first security element (112), • sending the fifth random value by the security applet (114) of the first security element (112) to the personalisation server (220) via the encrypted communication channel (160), • receiving a second signature of the challenge as a response from the personalisation server (220), wherein the challenge is signed using a third ephemeral private cryptographic key of the personalisation server (220), • verifying the received second signature using the third public cryptographic key of the personalisation server (220) and the sent fifth random value.
11. The method according to any one of the preceding claims, wherein establishing the second encrypted subchannel (164) further comprises authenticating the security applet (114) of the first security element (112) to the personalisation server (220), wherein authenticating the security applet (114) of the first security element (112) to the personalisation server (220) in particular comprises: • receiving the third ephemeral public cryptographic key of the personalisation server (220) by the security applet (114) of the first security element (112) from the personalisation server (220) via the encrypted communication channel (160), • generating a third secret shared with the personalisation server (220) by the security applet (114) of the first security element (112) using the private cryptographic key of the security applet (114) of the first security element (112) and the ephemeral public cryptographic key of the personalisation server (220), • generating a sixth random value by the security applet (114) of the first security element (112), • generating a third common authentication key for authenticating data sent over the second encrypted subchannel (164), wherein the third common authentication key is generated using the shared third secret and the sixth random value, • generating a fourth authentication token by the security applet (114) of the first security element (112) using the third authentication key and the third ephemeral public cryptographic key of the personalisation server (220) to authenticate the security applet (114) of the first security element (112) to the personalisation server (220), • sending the sixth random value together with the fourth authentication token to authenticate the security applet (114) of the first security element (112) by the security applet (114) of the first security element (112) via the encrypted communication channel (160) to the personalisation server (220), or wherein the third channel-specific ephemeral symmetric cryptographic session key for encrypting the second encrypted subchannel (164) between the security applet (114) of the first security element (112) and the personalisation server (220) is stored in the first security element (112) and in the personalisation server (220) as an initial key for use by the security applet (114), wherein furthermore in particular a channel-specific ephemeral symmetric cryptographic authentication key for authenticating data transmitted via the corresponding second encrypted subchannel (164) is stored in the first security element (112) for use by the security applet (114) and in the personalisation server (220).
12. The method according to any one of the preceding claims, wherein a second ID token is further used for the personalisation, wherein the personalisation further comprises: • establishing a third encrypted subchannel between the second ID token and the personalisation server (220) within the encrypted communication channel (160) via the mobile terminal (100), wherein the ID application program (108) is used to establish the third encrypted subchannel, • reading out one or more of the second attributes from the second ID token by the personalisation server (220) via the third encrypted subchannel within the encrypted communication channel (160), • establishing a fourth encrypted subchannel between the security applet (114) of the first security element (112) and the personalisation server (220) within the encrypted communication channel (160), wherein the ID application program (108) is used to establish the fourth encrypted subchannel, • receiving the read-out second attributes by the security applet (114) of the first security element (112) from the personalisation server (220) via the fourth encrypted subchannel within the encrypted communication channel (160), • storing the received second attributes by the security applet (114), wherein the ID application program (108) is configured to use the second attributes to prove an identity of the user to another computer system.
13. A mobile terminal (100), wherein the mobile terminal (100) comprises a processor (102) and a memory (104), wherein the memory (104) stores an ID application program (108), wherein the mobile terminal (100) further comprises a security element (112) having a security applet (114) associated with the ID application program (108), wherein the processor (102) is configured to carry out a method for personalising the security applet (114) using an ID token (200) and a personalisation server (220), wherein the mobile terminal (100) further comprises a communication interface (120) for contactless communication with the ID token (200) and for communication via a network (150) with the personalisation server (220), wherein the personalisation comprises: • establishing an encrypted communication channel (160) between the mobile terminal (100) and the personalisation server (220) via a network (150), wherein the ID application program (108) is used to establish the encrypted communication channel (160), • establishing a first encrypted subchannel (162) between the first ID token (200) and the personalisation server (220) within the encrypted communication channel (160) via the mobile terminal (100), wherein the ID application program (108) is used to establish the first encrypted subchannel (162), • reading out one or more of the first attributes (206) from the ID token (200) by the personalisation server (220) via the first encrypted subchannel (162) within the encrypted communication channel (160), • establishing a second encrypted subchannel (164) between the security applet (114) of the security element (112) and the personalisation server (220) within the encrypted communication channel (160), wherein the ID application program (108) is used to establish the second encrypted subchannel (164), • receiving the read-out attributes (206) by the security applet (114) of the security element (112) from the personalisation server (220) via the second encrypted subchannel (164) within the encrypted communication channel (160), • storing the received attributes (206) by the security applet (114), wherein the ID application program (108) is configured to use the attributes (206) to prove an identity of the user to another computer system.
14. A system (170), wherein the system (170) comprises a mobile terminal (100) according to claim 13 and a personalisation server (220), wherein the personalisation server (220) is configured to read out attributes (206) from an ID token (200) via the mobile terminal (100) and to personalise the security applet (114) of the mobile terminal (100).
15. The system (170) according to claim 14, wherein the system (170) further comprises the ID token (200) in which the attributes (206) to be read out are stored.