CREATING A CRYPTOGRAPHICALLY SECURED ELECTRONIC IDENTITY
Patent Information
- Application Number
- DE502022004078
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-04-21
- Filing Date
- 2022-04-01
- Publication Date
- 2025-06-18
- Estimated Expiration
- 2042-04-01
AI Technical Summary
Manufacturers and providers of applications for mobile devices face challenges in ensuring the cryptographic security of applications, particularly when these applications manage user electronic identities, as they lack independent control over the security elements embedded in mobile devices.
A method for creating a cryptographically secured electronic identity on a mobile terminal, which involves installing an ID application program with a control component and a provisioning component. The method includes performing a remote security inspection, generating asymmetric key pairs, creating certificates, and personalizing the ID application program using a personalization server over a network.
This solution enables the creation of a cryptographically secured electronic identity on a mobile device, ensuring the cryptographic security of user identities managed by the ID application program, thereby addressing the challenge of independent security assurance for mobile applications.
Description
[0001] The invention relates to a method for creating a cryptographically secured electronic identity of a user on a mobile terminal, as well as to a mobile terminal and a system for carrying out the method.
[0002] Mobile devices, such as smartphones, are ubiquitous. They are used in many areas of life and situations to perform a wide variety of digital tasks or with the aid of digital tools. Accordingly, corresponding mobile devices must be capable of meeting high security requirements. The security of mobile devices, such as smartphones, has therefore become a relevant requirement for device manufacturers, the manufacturers of the programs installed on the devices, and providers of services that can be used with the devices. To ensure the cryptographic security of such mobile devices, the manufacturers equip them with tools, such as security elements, for providing cryptographic procedures and key material. However, these tools are under the exclusive control of the device manufacturers.Manufacturers and providers of applications for such mobile devices therefore face the challenge of how they can independently ensure the cryptographic security of the applications they provide. This challenge is particularly relevant when a corresponding application program is intended to manage the electronic identity of a user of the mobile device as an ID application program.
[0003] US 2019 / 036688 A1 describes a method, system, and device for providing secure communication. The device includes a security element for generating application key pairs. The device comprises a trusted environment that is physically or logically isolated from an untrusted environment. The trusted environment includes one or more processors configured to perform operations of an application. The operations include generating an application key pair. The application key pair includes a private key of the security element and a public key of the security element. The operations include sending an application authentication request, including one or more device identifiers and the public key of the security element, to a server.The operations include obtaining a digital certificate containing the public key of the security element and the one or more device identifiers. The operations include providing the digital certificate to a second device and establishing a secure communication channel between the device and the second device using the digital certificate.
[0004] The invention is based on the object of creating an improved method for creating a cryptographically secured electronic identity on a mobile terminal.
[0005] The object underlying the invention is solved by the features of the independent patent claims. Embodiments of the invention are specified in the dependent patent claims.
[0006] Embodiments include a method for creating a cryptographically secured electronic identity of a user on a mobile terminal, which includes a security element. An ID application program for providing the electronic identity is installed on the mobile terminal. The ID application program includes a control component for controlling the creation of the electronic identity. The ID application program further includes a provisioning component for provisioning the ID application program during the creation of the cryptographically secured electronic identity.
[0007] Provisioning the ID application program includes: In response to a security inspection request from the provisioning component, performing a remote security inspection of the security infrastructure of the mobile terminal using the control component by a personalization server over a network, receiving a result of the remote security inspection from the personalization server, which the control component forwards to the provisioning component, in response to a positive result of the remote security inspection, sending a key generation request from the provisioning component to the control component, which the control component forwards to the security element, in response to the key generation request, generating a first asymmetric key pair associated with the ID application program and a second asymmetric key pair associated with the ID application program by the security element,wherein the first asymmetric key pair comprises a first private cryptographic key and a first public cryptographic key, wherein the second asymmetric key pair comprises a second private cryptographic key and a second public cryptographic key, wherein the security element sends the first and second public cryptographic keys to the control component, which forwards the two public cryptographic keys to the provisioning component upon receipt of the two public cryptographic keys, creating a certificate request by the provisioning component for creating a certificate of the ID application program comprising the first public cryptographic key, wherein the certificate request comprises the first public cryptographic key,Sending the certificate request by the provisioning component over the network to the personalization server, wherein the certificate request includes the first public cryptographic key, wherein the provisioning component sends the second public cryptographic key to the personalization server in response to the certificate request, receiving the certificate created by the personalization server with the first public cryptographic key and a root certificate of a root instance of a PKI by the personalization component, storing the certificate of the ID application program and the root certificate on the mobile terminal. ,
[0008] Embodiments can have the advantage that they enable the creation of a cryptographically secured electronic identity of a user on a mobile device, more precisely in an ID application program. For this purpose, the mobile device provides a security element. Such a security element provides, for example, cryptographic keys and cryptographic algorithms for cryptographically securing the mobile device and the application programs installed thereon. The creation of the cryptographically secured electronic identity comprises, for example, provisioning the ID application program, i.e., providing cryptographic infrastructure, in particular cryptographic keys, which are required for personalization, i.e., incorporating the electronic identity into the ID application program. To carry out the provisioning, the ID application program comprises a provisioning component.Furthermore, the ID application program includes a control component. The corresponding control component is configured, for example, to control the setup of the ID application program and its execution.
[0009] Embodiments can have the advantage that, during provisioning, an external security inspection of the mobile device's security infrastructure is initially performed. Upon a security inspection request from the provisioning component, a personalization server, using the control component, performs a security inspection of the mobile device's security infrastructure for the ID application program over a network. For example, the control component captures or queries characteristics of the security infrastructure and sends them to the personalization server, which checks the provided information. The personalization server sends the result of the remote security inspection to the control component, which forwards it to the provisioning component. Upon a positive result of the remote security inspection, the provisioning component begins the actual provisioning.To do this, the provisioning component sends a key generation request to the control component, which forwards the key generation request to the security element. In response to the key request, the security element generates two asymmetric key pairs for the ID application program. The first asymmetric key pair of the ID application program comprises a private cryptographic key and a first public cryptographic key. The second asymmetric key pair of the ID application program comprises a second private cryptographic key and a second public cryptographic key of the ID application program. In response to the key generation request, the security element provides the two generated public cryptographic keys. These are sent, for example, to the control component, which forwards them to the provisioning component.
[0010] Upon receipt of the two public cryptographic keys, the provisioning component creates a certificate request to create a certificate for the ID application program containing the first public cryptographic key. The provisioning component sends this certificate request containing the first public cryptographic key over the network to the personalization server. In addition to the certificate request, the provisioning component sends the second public cryptographic key to the personalization server. In response to the certification request, the personalization server creates a certificate containing the first public cryptographic key of the ID application program and sends it to the provisioning component. In addition to the created certificate, the personalization server sends a root certificate from a root authority of a PKI.The received certificate from the ID application program and the root certificate are stored on the mobile device. For example, the provisioning component forwards the root certificate to the control component for further use, which stores the root certificate.
[0011] In addition to creating the ID application program's certificate, the personalization server, for example, performs a verification of attestation information for the two public cryptographic keys. Key attestation certifies that cryptographic keys, such as public cryptographic keys, were created in compliance with a predefined set of security requirements and / or that the security element creating the cryptographic keys meets the predefined set of security requirements. For example, attestation information for the two public cryptographic keys is sent with the certificate request. This attestation information certifies that the security element created the two keys and that the security element complies with predefined security requirements when generating the corresponding keys.When verifying this attestation information, it is checked whether the personalization server met the specified requirements when generating the keys. For example, meeting the corresponding requirements is a prerequisite for creating the ID application program's certificate. The generated certificate and the second public cryptographic key are stored on the personalization server.
[0012] The first asymmetric key pair, which the security element possesses and for which a certificate has been issued by the personalization server, enables the ID application program to authenticate itself to other entities. The certificate proves the authenticity of the first public cryptographic key. This first public cryptographic key can be used, for example, as a signature verification key for signatures created with the first private cryptographic key. Thus, an entity that has the certificate with the first public cryptographic key can verify signatures that the security element has created using the first private cryptographic key as the signature key for the ID application program.
[0013] The second asymmetric key pair, whose second public cryptographic key is available to the personalization server, enables authentication of the ID application program to the personalization server. Using the public cryptographic key as a signature verification key, the personalization server can verify signatures created by the security element with the second private cryptographic key for the ID application program. Furthermore, the second public cryptographic key can be used by the personalization server, for example, to calculate a symmetric cryptographic session key for encrypting communication between the personalization server and the ID application program. For this purpose, a Diffie-Hellman method can be used, for example, to calculate the symmetric cryptographic key.
[0014] A mobile device, such as a smartphone, with an ID application program that provides an electronic identity for the user of the mobile device can, for example, serve as proof of identity, authentication, and authorization token in electronic business processes. The user of the mobile device is securely authenticated, for example, by the service they wish to use. For example, attributes of the electronic identity for authentication are read out by an ID provider server of an ID provider service, which then provides the corresponding service with the appropriate attributes for authenticating the user. A device manufacturer, for example, offers methods on the mobile device it produces that enable secure user authentication, e.g., using biometric features.Application developers can utilize this functionality, as well as other functions of a security element provided by the respective device manufacturer on the mobile device, e.g., a hardware-based security element known as a key store, for handling cryptographic key material. This makes it possible to establish a secure connection between the user and the mobile device. An electronic identity of the user linked to the mobile device is created and personalized. The electronic identity created in this way is made available to the user for use by the ID application program.
[0015] To create a cryptographically secured electronic identity for the user of the mobile device, the mobile device is provisioned to bind the user to the corresponding device, and an ID application program is installed on the mobile device to use the electronic identity. During the personalization of the electronic identity on the mobile device, the corresponding user identity is derived from an existing electronic identity, which is provided via an ID token. The personalized electronic identity is used under the control of the previously bound user.
[0016] To provision the device-specific security element, cryptographic key material, such as an asymmetric key pair, is generated in the device-specific security element with a connection to a PIN, in particular a system PIN, and / or biometric characteristics of the user of the mobile device. A system PIN is, for example, a user PIN assigned to the operating system of the corresponding mobile device. Furthermore, a certificate for the key material generated in the device-specific security element is requested from a provisioning service provided by a personalization server via a network. To personalize the ID application program, a connection secured by mutual authentication or a secure transmission channel is established from the mobile device to a personalization service provided by a personalization server via a network.User-side authentication includes, for example, capturing the user's biometric characteristics and / or entering a PIN, in particular a system PIN, of the mobile device by the user. Furthermore, an electronic identity document or ID token of the user is read by the personalization server via the mobile device. This occurs in conjunction with user authentication against the electronic identity document, such as the user entering a document PIN. Information or attributes necessary for personalization are transmitted from the electronic identity document to the personalization server via the previously established secure transmission channel. Furthermore, an end-to-end encrypted channel is established between the ID application program on the mobile device and the personalization server using the established communication channel.During this setup, the ID application program authenticates itself to the personalization server, and the personalization server authenticates itself to the ID application program. Finally, the ID application program installed on the mobile device is personalized by the personalization server using the user data read from the electronic identity document and the necessary cryptographic keys.
[0017] The electronic identity created on the mobile device and derived from the ID token is used by the device-specific security element to provide identity information or attributes of the user. The attributes are provided, for example, to a requesting ID provider server. Such provision includes user authentication to the ID application program, authentication of the ID provider server by the ID application program, authentication of the ID application program to the ID provider server, and transmission of the attributes to the ID provider server.
[0018] The process for provisioning the ID application program installed on a mobile device with the cryptographic keys prepares the mobile device, for example, for subsequent cryptographically secured personalization with identity information or attributes of the mobile device user and their binding to the mobile device. This can be done without the need for external access to the security element of the mobile device and thus, for example, independently of the device manufacturer. It is not necessary to incorporate external key material or software into the security element. A mobile device equipped with a corresponding electronic identity managed by the ID application program enables identification and / or authentication of the user of the mobile device.This enables user authentication to the device manufacturer-independent ID application program using the device manufacturer-dependent security element. The user authenticates himself to this security element, which confirms successful user authentication to the ID application program, for example, the control component included in the ID application program.
[0019] By provisioning and personalizing the ID application program installed on the mobile device, a derived electronic identity is created that is tied to the user of the mobile device and made available for use by the ID application program. The ID application program, which is independent of the device manufacturer, enables identification and / or authentication of the user of the mobile device with the electronic identity managed by the ID application program. This enables user authentication with the ID application program, which is independent of the device manufacturer, using a security element of the mobile device that is dependent on the device manufacturer. The user authenticates themselves with this security element, which is a prerequisite, for example, for the ID application program to use the attributes of the electronic identity.Successful user authentication by the security element is confirmed to the ID application program by the security element. For example, using the attributes requires performing cryptographic operations, such as generating a secret using a cryptographic key, which are assigned to the ID application program and stored on the security element. Using the corresponding cryptographic key, in turn, requires successful user authentication. Providing the result of the corresponding cryptographic operations, such as the secret, by the security element to the ID application program thus at least implicitly confirms that successful user authentication was performed by the security element.
[0020] A security element is a secured element of a mobile device that provides cryptographic means. These cryptographic means are protected against tampering and, for example, are accessible only to authorized services and applications via cryptographic keys. In particular, the cryptographic means can only be introduced, supplemented, modified, and / or deleted in the security element by authorized services and applications. A security element therefore provides a tamper-proof platform, for example, implemented in the form of a secure single-chip microcontroller, on which software and / or confidential and / or cryptographic data can be stored according to predefined rules and security requirements by reliably identified trusted entities and thus made available to authorized application programs and / or operating systems.A security element is, for example, a hardware component embedded in the mobile device, i.e., it cannot be removed non-destructively. A security element can, for example, be implemented in the form of a Secure Element (SE). The security element can, for example, be implemented as a cryptographically secured co-processor, i.e., a Secure Enclave, with a hardware-based key manager, which enables and provides an additional security layer through isolation from a main processor of the mobile device. This co-processor can be used to generate symmetric cryptographic keys and / or asymmetric cryptographic key pairs. The co-processor provides, for example, identifiers with which the cryptographic keys can be identified.Using the identifiers, the secure enclave can be requested to perform cryptographic operations, such as encryption and / or decryption, on behalf of another program, for example, a key management program. For example, elements to be stored can be encrypted and stored on the mobile device using cryptographic keys provided by the coprocessor. For example, the derived or generated cryptographic keys are stored on a security element, i.e., the security element comprises a data vault for cryptographic keys or a "key store." Such a key store or security element can also be implemented as part of the main processor, for example, in a TEE (Trusted Execution Environment). For example, the security element can be implemented using or as a TEE.A TEE provides a secure and trusted runtime environment for applications. Such a TEE can exist, for example, isolated on a separate processor (a coprocessor), directly on the main processor(s) of the mobile device, or in a die of a multiprocessor system or a system-on-chip (SoC). For example, only specifically authorized applications can be executed on such a TEE.
[0021] An application program, also called an application or app for short, is a computer program that provides, supports and / or enables the processing of non-system-technical functionality.
[0022] An operating system is a computer program or a collection of computer programs that provides, supports, and / or enables the processing of system-specific functionalities. An operating system provides system resources. System resources refer to system elements or hardware components of a computer that are required by processes to function correctly.
[0023] A computer or a computer system can be, for example, a stationary computer, such as a personal computer (PC), service terminal, or server, or a mobile portable computer, such as a laptop, tablet, smartphone, or other smart device. The computer can include an interface for connecting to the network, which can be a private or public network, in particular the Internet. Depending on the embodiment, this connection can also be established via a mobile network.
[0024] A "service provider server" or service server is understood here to be a server or computer system on which a server program is executed and which provides the possibility of initiating, using and / or executing an offered service via a network.
[0025] A "personalization server" is a server or computer system on which a server program is executed and which is configured to read attributes from an ID token and insert them into a mobile device.
[0026] An "ID token" is understood here to be a portable electronic device, for example, a so-called USB stick, a chip card, or a document on which a user's attributes are stored. A "document" is understood in particular to be an identification, valuables, or security document, in particular a sovereign document, in particular a paper-based and / or plastic-based document, such as an electronic identification document, in particular a passport, identity card, visa, driver's license, vehicle registration document, vehicle registration document, health card, or a company ID card, or another ID document, a chip card, a means of payment, in particular a banknote, bank card or credit card, a waybill, or other proof of authorization.In particular, the ID token can be a machine-readable travel document, such as that standardized by the International Civil Aviation Organization (ICAO) and / or the Federal Office for Information Security (BSI).
[0027] A "personalization server" is a server or computer system on which a server program is executed and which is configured to read attributes from an ID token and transfer them to a mobile device. Furthermore, the personalization server is configured, for example, to provision the mobile device, in particular with cryptographic keys.
[0028] An "ID provider server" is understood to mean a server or a computer system on which a server program is executed and which is configured to provide attributes of an electronic identity provided by the mobile device to a service provider server and / or to confirm them to the service provider server.
[0029] A "mobile device" is a mobile, portable communication device, such as a smartphone, a tablet or a smartwatch.
[0030] A "program" or "program instructions" is understood here, without limitation, to mean any type of computer program that includes machine-readable instructions for controlling a functionality of the computer.
[0031] A "processor" is understood here and below to mean a logic circuit that serves to execute program instructions. The logic circuit can be implemented on one or more discrete components, in particular on a chip. In particular, a "processor" is understood to mean a microprocessor or a microprocessor system comprising multiple processor cores and / or multiple microprocessors.
[0032] The term "memory" refers here to both volatile and non-volatile electronic memories or digital storage media.
[0033] "Non-volatile memory" is defined here as electronic memory for the permanent storage of data, particularly static cryptographic keys, attributes, or identifiers. Non-volatile memory can be configured as non-modifiable memory, also known as read-only memory (ROM), or as modifiable memory, also known as non-volatile memory (NVM).
[0034] In particular, this can be an EEPROM, for example a Flash EEPROM, or simply Flash. Non-volatile memory is characterized by the fact that the data stored on it is retained even after the power supply is turned off.
[0035] An "interface" or "communication interface" is understood here to be an interface through which data can be received and sent. The communication interface can be configured as contact-based or contactless. A communication interface can, for example, enable communication over a network. Depending on the configuration, a communication interface can, for example, provide wireless communication according to a cellular standard, Bluetooth, RFID, Wi-Fi, and / or NFC standards. Depending on the configuration, a communication interface can, for example, provide cable-based communication. The communication interface can be an internal interface or an external interface.
[0036] Encrypted communication channels, for example, are encrypted end-to-end connections. An "encrypted end-to-end connection" or "encrypted end-to-end transmission channel" is understood here as a connection between a sender and a receiver with end-to-end encryption, in which the data to be transmitted is encrypted by the sender and only decrypted by the receiver. The encryption of transmitted data thus occurs across all transmission stations, so that intermediate stations cannot gain knowledge of the content of the transmitted data due to the encryption. The connection is cryptographically secured by encryption to prevent spying and / or manipulation of the transmission; a so-called secure messaging procedure can be used for this purpose.End-to-end encryption, for example, is based on two symmetric cryptographic keys, with a first symmetric key used to encrypt messages and a second symmetric key used to authenticate the sender of the message, for example, using Message Authentication Code (MAC) algorithms. For example, during the setup of an encrypted communication channel, ephemeral encryption keys are negotiated, which become invalid when the communication channel is terminated. Using different ephemeral keys for different communication channels makes it possible to operate multiple communication channels in parallel.
[0037] An encrypted communication channel can be established, for example, using the Transport Layer Security (TLS) protocol, for example as part of the Hypertext Transfer Protocol Secure (HTTPS) protocol.
[0038] Asymmetric key pairs are used in a variety of cryptosystems and play an important role in the secure transmission of electronic data. An asymmetric key pair consists of a public cryptographic key, which is used to encrypt and / or decrypt data and may be shared with third parties, such as a sender or receiver of data, and a private cryptographic key, which is used for encryption and / or decryption but also for signing data and must generally be kept secret. The public key allows anyone to encrypt data for the owner of the private cryptographic key or to verify digital signatures created with the private cryptographic key.A private key allows its owner to decrypt data encrypted with the public cryptographic key or to create digital signatures of data.
[0039] A digital signature of data includes, for example, creating a check value for the data, such as a hash value, which is encrypted with a private cryptographic key of an asymmetric key pair used as the signature key. In the case of a signature, only the signatory knows the private cryptographic key (i.e., signature key) of the asymmetric key pair used to create the signature. The signature recipient only has the public cryptographic key (i.e., signature verification key) of the asymmetric key pair used for the signature. The signature recipient can therefore verify the signature but cannot calculate it themselves. To verify a signature, the signature recipient calculates, for example, the check value of the signed data and compares this with the result of decrypting the signature using the signature verification key.If the calculated hash value matches the decryption result, the signature is correct. If the authenticity of the signature verification key is also confirmed, for example, by a certificate, especially a PKI certificate, the signature is valid.
[0040] A "certificate" here refers to a digital certificate, also known as a public key certificate (PKI certificate). A certificate is structured data used to assign a public cryptographic key of an asymmetric cryptosystem to an identity, such as a person, institution, or device. For cryptographic security and to prove the authenticity of the certificate data, these are signed by a certificate issuer. PKI certificates, which are based on asymmetric key pairs and, with the exception of a root certificate, are each signed by a certificate issuer with a signature key, the corresponding signature verification key of which is assigned to the certificate issuer by a PKI certificate of the corresponding certificate issuer, create a so-called public key infrastructure (PKI).For example, the certificate can conform to the X.509 standard or another standard. For example, the certificate is a Card Verifiable Certificate (CVC). An authorization certificate contains structured data that additionally defines the rights of the identity.
[0041] The PKI provides a system for issuing, distributing, and verifying digital certificates. In an asymmetric cryptosystem, a digital certificate can confirm the authenticity of a public cryptographic key and its permissible scope of use and validity. The digital certificate itself is protected by a digital signature, the authenticity of which can be verified using the public cryptographic key of the certificate issuer. A digital certificate is used to verify the authenticity of the issuer key. In this way, a chain of digital certificates can be established, each of which confirms the authenticity of the public cryptographic key, which can be used to verify the previous certificate. Such a chain of certificates forms a so-called validation path or certification path.For example, PKI participants must be able to rely on the authenticity of the last certificate, the so-called root certificate, and the key certified by it, without requiring any additional certificates. The root certificate is managed by a so-called root certification authority, whose assumed authenticity underlies the authenticity of all PKI certificates.
[0042] Digital certificates, for example, are validated by an independent, trustworthy authority (certification service provider / CSP or trust service provider / TSP), i.e., the certification authority that issued the certificate. Certificates can be made available to a wide range of people to enable them to verify electronic signatures for authenticity and validity. A certificate can be associated with an electronic signature and provide a signature verification key in the form of the public cryptographic key if the private key associated with the signature verification key was used as the signature key.By making a certificate in association with a public cryptographic key available to the public, a CDA / VDA enables users of asymmetric cryptosystems to assign the public cryptographic key to an identity, for example a person, an organization, or a computer system.
[0043] Authentication refers to the verification of a claimed property of an entity, such as a user of a mobile device. During authentication, for example, corresponding evidence provided by the user is verified. The entity performs authentication through its contribution to the authentication process, i.e., by providing appropriate evidence such as authentication data or authentication factors for verification.
[0044] Authentication of the user regarding the claimed property of authenticity, for example, the authenticity of their person or identity, allows the authenticated user to perform further actions. For example, the user is granted access rights. A successfully authenticated user is considered authentic. Final confirmation of an authentication may include authorization.
[0045] The user can authenticate themselves in various ways. For example, they can provide proof of knowledge, such as a PIN or password, proof of possession, such as a cryptographic key, a certificate, or an electronic device, and / or proof of their own personal characteristics, such as biometric or behavioral characteristics. For example, the corresponding proof is captured by an authentication sensor on the mobile device in the form of the user's authentication data and compared by a security element on the mobile device with one or more stored reference values. The security element that evaluates the captured authentication data is, for example, a security element of the mobile device's operating system.If there is a sufficient match between the recorded authentication data and the stored reference values, the security element confirms successful user authentication. For example, confirmation of successful user authentication involves executing a challenge-response procedure by the confirming security element. For example, upon successful user authentication, the confirming security element confirms this successful authentication to the ID application program installed on the mobile device, for example, to the control component of the ID application program, by issuing a correct response to a challenge from the installed ID application program.
[0046] An authentication sensor is understood to be a sensor for capturing authentication data of the user of the mobile device. The authentication data can, for example, comprise biometric data of the user. The authentication sensor can be configured to capture biometric data of the user. Biometric data can, for example, comprise: fingerprint data, body geometry data / anthropometric data, such as facial, hand, or ear geometry data, hand line structure data, vein structure data, such as palm vein structure data, iris data, retina data, voice recognition data, and nail bed patterns. The authentication sensor can, for example, comprise a camera of the mobile device. The authentication data can, for example, comprise user knowledge, such as a PIN or password. The authentication sensor can comprise an input device for entering authentication data, such as a PIN or password.The input device may, for example, comprise a keyboard and / or a touchscreen.
[0047] A challenge-response method represents a secure authentication method between a first instance and a second instance based on knowledge. For example, an authenticating security element of a mobile device, such as a security element of the mobile device's operating system, is authenticated by another authenticating security element of the mobile device using a challenge-response method. At the same time, the response represents confirmation of successful user authentication if the response is only generated under the condition of successful user authentication by the authenticating security element.Thus, in the case of a successful challenge-response procedure, the authenticating security element not only knows that the user authentication has been confirmed, but also that it has been confirmed by the authenticating security element and is therefore valid.
[0048] In the course of a challenge-response procedure, a first instance presents a task ("challenge") to a second instance, for which the second instance must provide a correct answer ("response").
[0049] For example, the first instance generates a random value ("nonce") and sends it to the second instance. The second instance uses a shared secret to cryptographically transform the nonce and sends the result as a response to the first instance for the purpose of authenticating the second instance. For example, the nonce is combined with the shared secret and a cryptographic hash function or encryption is applied to this combination. Alternatively, the shared secret, such as a symmetric cryptographic key, can be used to encrypt the nonce. The first instance, which knows both the nonce and the shared secret, can, for example, perform the same computation as the second instance and / or perform an inverse computation, e.g., decrypt the encrypted nonce using the shared secret.If the result of the calculation by the first instance matches the result of the calculation by the second instance or the challenge, the challenge-response procedure is successful and the second instance is successfully authenticated.
[0050] Furthermore, a challenge-response procedure can also be based on an asymmetric cryptosystem and serve to prove to the first instance that the second instance possesses a private and thus secret cryptographic key. In this case, only the second instance knows the corresponding private cryptographic key, which it uses for a cryptographic transformation of the challenge, e.g., a nonce. The corresponding cryptographic transformation can, for example, be a digital signature. The first instance can use a public cryptographic key associated with the private cryptographic key to check the response to determine whether the second instance actually has knowledge of the private cryptographic key, without the first instance itself gaining knowledge of the private cryptographic key during the verification process.
[0051] According to embodiments, the personalization component forwards the root certificate to the control component for storage.
[0052] Embodiments may have the advantage that the root certificate is available to the control component, which can use the root certificate to verify certificate chains. For example, if the control component receives a certificate chain from an external entity or server, it can verify the signature of the root entity on which the certificate chain depends using the root certificate.
[0053] According to embodiments, the mobile device further comprises one or more authentication sensors for detecting one or more authentication factors of the user. The user is registered on the mobile device, and one or more reference values of the registered user are stored in the security element for verifying at least one detected authentication factor of the registered user. The security element is configured such that a prerequisite for generating the first asymmetric key pair is successful authentication of the user to the security element. By authenticating, the user consents to the generation of the first asymmetric key pair.The security element is further configured so that the use of the first private cryptographic key by the security element is subject to further successful authentication of the user to the security element. With each further authentication, the user consents to the corresponding use of the first private cryptographic key.
[0054] Embodiments may have the advantage that both the generation of the first asymmetric key pair and the use of the first private cryptographic key can be tied to the user of the mobile terminal. This also ties the ID application program to the user of the mobile terminal, since cryptographically secured use of the ID application program or an electronic identity managed by it, i.e., use of the first asymmetric key pair, is only possible under the condition of successful user authentication to the mobile terminal or the security element of the mobile terminal.This ensures that the user is prompted for authentication each time the ID application program is used, which involves the use of the first private cryptographic key of the ID application program, and that by providing the appropriate authentication he or she consents to the use of the first private cryptographic key.
[0055] According to embodiments, the security element is a device-specific security element. A device-specific security element is understood here to be a security element to which no device-independent or device-manufacturer-independent external access is possible. The security element is configured, for example, such that the personalization server cannot access the security element and introduce external key material or software. Thus, it is not possible for the personalization server to introduce external cryptographic key material or software, such as cryptographic functions, during personalization. Embodiments can have the advantage of enabling provisioning even if the security element is a device-specific security element.
[0056] According to embodiments, the method further comprises personalizing the ID application program on the mobile terminal using an ID token. The ID application program further comprises a personalization component for personalizing the ID application program. The personalization comprises: Establishing a first encrypted communication channel between the mobile terminal and the personalization server via the network, wherein the personalization component is used to establish the first encrypted communication channel, Establishing a first encrypted subchannel between the ID token and the personalization server within the first encrypted communication channel via the mobile terminal, wherein the personalization component is used to establish the first encrypted subchannel, Reading one or more of the attributes from the ID token by the personalization server via the first encrypted subchannel within the first encrypted communication channel, Establishing a second encrypted subchannel between the control component and the personalization server within the first encrypted communication channel,wherein the personalization component is used to establish the second encrypted subchannel, receiving the read attributes by the control component from the personalization server via the second encrypted subchannel within the first encrypted communication channel, storing the received attributes by the control component on the mobile terminal, wherein the ID application program is configured to use the attributes to prove the identity of the user to another computer system.
[0057] Embodiments may have the advantage that the ID application program provisioned with the two asymmetric cryptographic key pairs can be further personalized. Personalization here refers to the incorporation of an electronic identity in the form of attributes into the ID application program. This incorporation of the attributes, as well as the use of the attributes, is cryptographically secured using the two asymmetric key pairs.
[0058] The ID application program is configured to verify the identity of the user of the mobile device. To do this, the ID application program can use attributes of the user that identify the corresponding user. These attributes represent an electronic identity of the user. The corresponding attributes and thus the electronic identity of the user is provided, for example, by an ID token, i.e., an electronic identity document. During the personalization of the ID application program, attributes are read from the electronic identity document and stored on the mobile device under the management of the ID application program. The resulting electronic identity of the user, which the mobile device provides, is therefore a derived identity derived from the electronic identity document.The corresponding electronic identity document may in particular be a sovereign identity document, such as an electronic identity card or an electronic passport.
[0059] Furthermore, during personalization, the security element can be used to generate additional cryptographic keys, for example, attribute-specific or identity-specific keys. The corresponding key material is generated, for example, on the security element of the mobile device and made available to the ID application program. Cryptographic keys and / or intermediate results of cryptographic operations, such as secrets calculated using corresponding cryptographic keys, can be output by the security element to the ID application program for further use. Furthermore, corresponding cryptographic keys can be stored on the security element for the ID application program.To perform cryptographic operations with the corresponding cryptographic keys, the ID application program sends a corresponding request to the security element, which executes the requested cryptographic operation using the cryptographic keys and makes the result available to the ID application program for further use. The corresponding cryptographic operations can be both cryptographic calculations and verifications of cryptographic values.
[0060] Embodiments can have the advantage that, during such derivation, it can be ensured that the derived identity in the form of the stored attributes is actually stored on the device linked to the user. For example, the attributes can be stored in encrypted form on the mobile device. For example, the attributes are encrypted with a cryptographic key that is generated in the security element during personalization.
[0061] Embodiments can have the advantage that a binding of the corresponding attributes to the actual owner of the corresponding attributes can be ensured via a binding of the security element to the user of the mobile terminal. Since, on the one hand, the owner of the attributes or of the ID token authenticates himself to the ID token during personalization, i.e. when setting up the first sub-channel, and, on the other hand, the user of the mobile terminal authenticates himself to the mobile terminal or the security element during the establishment of the encrypted communication channel and / or the second sub-channel, a binding is implemented between the owner of the attributes and the user of the mobile terminal. Both the first and the second sub-channel are each set up within the encrypted communication channel and are therefore cryptographically entangled with it.This also interlinks the authentication of the attribute owner and the user of the mobile device. This is especially true if the attribute owner's authentication against the ID token occurs via the mobile device, for example, via the personalization component of the ID application program.
[0062] Channel interleaving ensures that the attributes are read via the same mobile device into which they are inserted during personalization.
[0063] This can, for example, prevent an unauthorized user from gaining access to another user's attributes and using them to identify themselves with a forged electronic identity. When verifying identity using a mobile device, it is advantageously possible to ensure that the attributes presented with the identity verification are actually attributes of the identified user. To this end, the transmission path for reading the corresponding attributes, i.e., the electronic identity of an identity document, is secured with a transmission path for personalizing the derived identity, i.e., incorporating the read attributes into a security element of a mobile device using cryptographic means.This ensures that the mobile device used to read the attributes is the same mobile device whose security elements are personalized with the read attributes.
[0064] For example, when reading the ID token using the mobile device, the user must authenticate themselves to the ID token. This ensures that the user initiating or confirming the reading is actually the owner of the corresponding ID document. Furthermore, when personalizing the security element of the mobile device, i.e. when entering the read attributes, the user must authenticate themselves to the mobile device. This ensures that the user initiating or confirming the personalization is actually the owner of the mobile device or the user registered on this mobile device. By additionally providing the transmission paths for reading the attributes and for entering the attributes orFor personalization purposes, if the mobile devices are linked together using cryptographic means, it can be ensured that the same mobile device is used when reading and entering the attributes and is assigned to the same user.
[0065] If the user must authenticate themselves to both the mobile device and the ID token when reading the attributes, it can be ensured, for example, that the holder of the ID token is the same person who also owns the mobile device. At the very least, it can be ensured that the holder of the ID token must give their consent together with the owner of the mobile device during the reading process, and that at least the consent of the owner of the same mobile device is necessary for the inclusion of the corresponding attributes. This prevents the mobile device used from being replaced during the reading and inclusion of attributes, and that the corresponding attributes could thus fall under the control of another, especially an unauthorized, user. This effectively prevents misuse.To cryptographically link the transmission path for reading the attributes to the transmission path for personalizing or inserting the attributes, an encrypted communication channel is established between the mobile device and a personalization server that performs the personalization. This communication channel is encrypted to ensure that communication via it is actually only possible between the two participants who initially established the corresponding communication channel, i.e., the mobile device and the personalization server. End-to-end encryption can be used for this purpose. For example, encryption on the mobile device side is carried out using the security element of the mobile device, which is assigned, for example, to an operating system of the mobile device and is configured to establish encrypted communication channels.
[0066] The reading from the ID token, on the one hand, and the insertion of the read attributes into the mobile device during personalization for use by the ID application program to be personalized, on the other hand, are each carried out via a separate encrypted subchannel of the encrypted communication channel. The encrypted subchannels ensure that only participants who have established the corresponding subchannel and have the corresponding cryptographic keys can communicate with each other. In the case of the first encrypted subchannel between the ID token and the personalization server, these are the corresponding ID token and the personalization server.In the case of the second encrypted subchannel between the ID application program to be personalized and the personalization server, these are the corresponding ID application program to be personalized, for example, the personalization component of the ID application program, and the personalization server. The subchannels are encrypted subchannels within the encrypted communication channel. The transmitted data is encrypted twice in each case. Firstly, the corresponding data is encrypted by the ID token during the reading from the ID token using a channel-specific ephemeral symmetric cryptographic session key assigned to the corresponding encrypted subchannel.During the transmission of the corresponding encrypted data between the mobile device and the personalization server, the mobile device additionally encrypts the data a second time using a channel-specific ephemeral symmetric cryptographic session key of the encrypted communication channel. The receiving personalization server must therefore first decrypt the encryption of the communication channel and then the encryption of the corresponding subchannel to gain access to the transmitted data.
[0067] During personalization, the personalization server consistently uses the same encrypted communication channel. This means that the attributes used for personalization are encrypted with the channel-specific ephemeral symmetric cryptographic session key of the encrypted communication channel. Since only the mobile device already used to read the attributes, for example, its security element or the personalization component of the ID application program, possesses the same channel-specific ephemeral symmetric cryptographic session key, only the same mobile device is capable of decrypting the attributes to be used for personalization. This ensures that the same mobile device is used for personalization that was previously used to read the corresponding attributes.To ensure secure transmission of the attributes to be used for personalization to the ID application program of the mobile device to be personalized, an additional encrypted subchannel within the encrypted communication channel is used to transmit the attributes. In other words, the corresponding attributes are first encrypted with an ephemeral symmetric cryptographic session key of the corresponding subchannel and then with the channel-specific ephemeral symmetric cryptographic session key of the encrypted communication channel. The attributes thus doubly encrypted are first decrypted by the mobile device forming the endpoint of the encrypted communication channel, for example, by a security element of the device that manages the necessary ephemeral cryptographic session key.The data resulting from this first decryption is provided to the ID application program to be personalized, for example, a personalization component of the ID application program. The ID application program has the cryptographic session key, which is assigned to the corresponding subchannel, whose endpoint, for example, the ID application program forms. This cryptographic session key can also be used to decrypt the second encryption of the transmitted data, which can then be used for personalization by the security element to be personalized.
[0068] For example, a secure connection in the form of an encrypted communication channel is first established from the mobile device to the personalization server. This connection is secured, for example, by mutual authentication, which allows the participants to verify who they are communicating with. Authentication on the part of the mobile device may require authentication of the user of the mobile device to the mobile device. This not only ensures that communication takes place in the communication channel with or via the mobile device, but also that the communication takes place with the consent of the user of the mobile device. For this purpose, the corresponding user provides, for example, an authentication factor, such as a biometric feature or a PIN, in particular a system PIN.The corresponding authentication factor is recorded, for example, by an authentication sensor on the mobile device in the form of authentication data. This can be a biometric sensor, such as a finger scanner or a camera for detecting the user. For example, the corresponding authentication sensor can also be an input device on the mobile device via which the user can enter their PIN, such as a keyboard or a touchscreen. A system PIN, for example, is a user PIN assigned to the operating system of the corresponding mobile device. In order to read attributes from the ID token, i.e. the user's electronic identity document, authentication of the user with the ID token is also necessary during the setup of the subchannel.For this purpose, the user can, for example, provide a corresponding authentication factor via the authentication sensor of the mobile device. Alternatively, the corresponding authentication factor can also be provided directly to the ID token if the ID token has the authentication sensor for detecting the corresponding authentication factor. As before, the corresponding authentication factor can be, for example, biometric characteristics of the user or, in particular, a document PIN. A corresponding document PIN is a PIN that is assigned to the corresponding ID token or electronic identity document. To transmit the attributes read from the ID token to the personalization server, an encrypted subchannel of the encrypted communication channel is established. The corresponding establishment takes place, for example, via the encrypted communication channel.The attributes to be read are then transferred from the personalization server to the mobile device or the ID application program to be personalized, secured with double encryption.
[0069] To personalize the ID application program, a second subchannel is established within the encrypted communication channel. During the establishment, for example, authentication of the user with respect to the security element to be personalized is necessary. Authentication takes place, for example, using the security element of the mobile device, which is, for example, a security element assigned to the operating system of the mobile device. The user authenticates himself with respect to the corresponding security element or is successfully authenticated by the corresponding security element. The security element communicates the successful authentication of the user to the ID application program to be personalized directly or indirectly. For example, the security element calculates for the ID application program orFor the control component of the ID application program, a secret for generating the ephemeral symmetric session key for encrypting the second subchannel is only available under the condition of successful user authentication. By providing the corresponding secret, the ID application program can, for example, conclude that the user has successfully authenticated through the security element.
[0070] The encrypted subchannel, which is established between the ID application program to be personalized or the control component of the ID application program and the personalization server via the encrypted communication channel, uses an end-to-end encrypted subchannel, for example. The previously read data, i.e., attributes, from the ID token are then transmitted via the second subchannel within the communication channel to the ID application program to be personalized. The attributes are introduced into the mobile device, for example, in the form of a binary compact data format, such as a CBOR structure ("Concise Binary Object Representation"), i.e., a binary compact data format for serialization. Other formats, such as ASN.1, JSON, XML, protoBuf, etc., can also be used to introduce the attributes.Furthermore, further cryptographic elements, such as root signature verification keys, can also be transmitted via the corresponding sub-channel. The root signature verification keys are, for example, CVCA keys from a Country Verifying Certificate Authority, i.e. a national certificate authority for verification. These further cryptographic elements can, for example, also be part of the CBOR structure with the attributes. Furthermore, the generation of attribute-specific and thus identity-specific cryptographic keys on the security element can be initiated via the corresponding sub-channel, which are assigned to the derived electronic identity of the user of the mobile device stored on the mobile device during personalization. For example, a third asymmetric cryptographic key pair is generated by the security element, which corresponds to the introduced attributes oris assigned to the created identity. For example, the third public cryptographic key is stored together with attributes or with the electronic identity. This public cryptographic key can be used, for example, to verify attribute-specific or identity-specific signatures created using the third public cryptographic key as a signature key.
[0071] During the provisioning of the mobile device or the ID application program, embodiments enable preparation for subsequent secure personalization with a user's identity information and their binding to the device. Embodiments can have the advantage of enabling secure management of digital or electronic identities using a mobile device. For this purpose, the ID application program for managing electronic identities or identity attributes belonging to or defining electronic identities is installed on the mobile device.
[0072] The mobile device with the electronic identities managed by the ID application program can be used, for example, for identification and authentication, for transmitting identity data and for supporting declarations of intent in the mobile context.
[0073] According to embodiments, the electronic identity may comprise an officially recognized identity, such as an electronic identity created on the basis of an official identification document, such as an identity card or passport.
[0074] A user's electronic identity is unambiguous, meaning it is unique and unmistakable. It is defined based on characteristics, so-called identity attributes. An electronic identity includes, for example, personal data. Personal data refers to data that enables the identification of a person or can be assigned to a person to whom the personal data relates.
[0075] A user may have multiple different, application-specific electronic identities. These electronic identities may meet different security requirements. The ID application program may be configured to manage multiple electronic identities.
[0076] According to embodiments, an electronic identity stored on the mobile terminal and provided or managed by the ID application program can be used to identify and authenticate the user of the mobile portable device without additional hardware besides the mobile terminal.
[0077] Identity attributes are requested, for example, by service providers or service providers for online services. According to embodiments, the identity attributes required by a service provider for its online service are transmitted in an encrypted and authentic manner. For example, authorization certificates are used to regulate who is authorized to access which identity attributes or who has read authorization for them. For example, the required identity attributes are read by an ID provider authorized to do so by means of an authorization certificate and made available by this provider to the requesting service provider. According to embodiments, the ID provider only provides the requesting service provider with confirmation of the requested identity attribute(s).For example, the service provider queries whether the requested identity attributes have one or more characteristics, which is checked by the ID provider server based on the read identity attributes and either confirmed or denied to the service provider.
[0078] The user's consent to the use of identity attributes and / or user authentication takes place, for example, by checking one or more authentication factors, such as password, PIN, fingerprint or facial recognition.
[0079] According to embodiments, the ID application program controls the establishment of the encrypted communication channel between the mobile terminal and the personalization server. For example, the ID application program comprises a personalization component that controls the personalization on the mobile terminal side. For example, the personalization component of the ID application program controls the establishment of the encrypted communication channel on the mobile terminal side, as well as the establishment of the first encrypted subchannel and the second encrypted subchannel, mediated by the mobile terminal.
[0080] For example, the received attributes are stored on the mobile device by the control component of the ID application program. For example, the attributes are stored in a memory area of the mobile device assigned to the control component and / or the ID application program. For example, the attributes are stored in encrypted form. For example, the attributes are stored unencrypted.
[0081] According to embodiments, the first encrypted communication channel is encrypted with a first channel-specific ephemeral symmetric cryptographic session key. The first encrypted subchannel is encrypted with a second channel-specific ephemeral symmetric cryptographic session key. The second encrypted subchannel is encrypted with a third channel-specific ephemeral symmetric cryptographic session key.
[0082] Embodiments may have the advantage that the encryption in the communication channel and in the two encrypted subchannels are each assigned channel-specific ephemeral symmetric cryptographic session keys. Thus, the subchannels can each be combined with the communication channel or executed within it by using double encryption through the cryptographic session keys assigned to the corresponding channels.
[0083] According to embodiments, the first channel-specific ephemeral symmetric cryptographic session key, the second channel-specific ephemeral symmetric cryptographic session key, and the third channel-specific ephemeral symmetric cryptographic session key are each independent of one another.
[0084] For example, a channel-specific ephemeral symmetric cryptographic authentication key is further assigned to each of the first and second encrypted subchannels for authenticating data transmitted via the respective first and second encrypted subchannels. For example, a MAC is generated for the corresponding data using the respective channel-specific ephemeral symmetric cryptographic authentication key. The corresponding authentication keys are, for example, cryptographic keys for generating the corresponding MAC.
[0085] A MAC, for example, is calculated using a MAC algorithm that receives the data to be protected, e.g., identity attributes, and a cryptographic key, e.g., a symmetric cryptographic key, as input data. Using this input data, the MAC algorithm calculates a checksum, which serves as the MAC. Block ciphers or hash functions, for example, can be used to calculate MACs. An HMAC (Keyed-Hash Message Authentication Code), for example, can be used as a MAC. A cryptographic hash function, such as the Secure Hash Algorithm (SHA), and a secret cryptographic key, e.g., a symmetric cryptographic key, are used to construct this code.
[0086] To secure a data transmission, for example, the transmission of identity attributes, a cryptographic key, such as a symmetric cryptographic key, is agreed upon between the sender (e.g., the ID token) and the receiver (e.g., a personalization server). The sender uses this cryptographic key to calculate a MAC for the data to be transmitted and sends the calculated MAC along with the data to be transmitted to the receiver. The receiver, in turn, calculates a MAC for the received data using the cryptographic key and compares the result with the received MAC. If the calculated MAC matches the received MAC, the integrity check is successful, and the received data is considered authentic.
[0087] In the case of a MAC, both sender and receiver must know the cryptographic key used, unlike when using pure hash functions or signatures. In the case of pure hash functions, for example, no cryptographic keys are used. If the hash functions are public, anyone can calculate the hash value, especially for manipulated messages. In the case of a signature, only the signer knows the private cryptographic key (i.e., signature key) of an asymmetric key pair used to create the signature. The signature recipient only has the public cryptographic key (i.e., signature verification key) of the asymmetric key pair used for the signature. The signature recipient can therefore verify the signature using the signature verification key, but cannot calculate it themselves.
[0088] According to embodiments, the encryption of the first encrypted communication channel is end-to-end encryption between the mobile device and the personalization server.
[0089] Embodiments can have the advantage of ensuring that the same mobile device always forms an endpoint of the encrypted communication channel. Thus, as long as communication is carried out via the same encrypted communication channel, the personalization server knows that it is communicating with the same mobile device. Thus, it can be ensured that the mobile device via which the ID token is read is the same mobile device that is personalized with the read data, i.e., attributes of the ID token.
[0090] According to embodiments, the encrypted communication channel is encrypted by the mobile device using a security element of the mobile device, which is associated, for example, with an operating system of the mobile device. The security element provides, for example, cryptographic keys and / or cryptographic protocols for the operating system.
[0091] According to embodiments, the encryption of the first encrypted subchannel is end-to-end encryption between the ID token and the personalization server.
[0092] Embodiments can have the advantage that the data transmitted in encrypted form between the ID token and the personalization server can be transmitted at least between the mobile device and the personalization server within the encrypted communication channel. At the same time, the mobile device does not yet gain access to the data transmitted via the encrypted subchannel at this point. This ensures that access to the corresponding data occurs exclusively through the personalization server during personalization. This can thus prevent misuse or unauthorized reading of attributes. Rather, the corresponding reading and use of the attributes for personalization can occur exclusively via a trusted entity in the form of the personalization server.
[0093] According to embodiments, the encryption of the second encrypted subchannel is end-to-end encryption between the ID application program on the mobile terminal, for example the control component of the ID application program, and the personalization server.
[0094] Embodiments may have the advantage that the end-to-end encryption between the ID application program, for example, the control component of the ID application program, and the personalization server can ensure that the ID application program of the mobile terminal to be personalized is actually personalized and that the data used for personalization is made available exclusively to the ID application program. This can prevent, for example, unauthorized access to the corresponding personalization data.
[0095] Depending on the embodiment, personalization further includes: Generating a third asymmetric key pair associated with the ID application program by the security element, wherein the third asymmetric key pair comprises a third private cryptographic key and a third public cryptographic key, wherein the third asymmetric key pair serves to authenticate the ID application program when using the attributes,
[0096] According to embodiments, the security element sends the third public cryptographic key of the ID application program from the security element to the personalization server using the control component via the second encrypted subchannel within the first encrypted communication channel.
[0097] Embodiments may have the advantage that an individual asymmetric key pair for the individual ID application program can be generated by the security element and made available for use by the ID application program. The public cryptographic key of the corresponding asymmetric key pair is transmitted via the encrypted subchannel between the ID application program and the personalization server in the encrypted communication channel. Thus, the corresponding public cryptographic key, which is generated on the personalized security element during personalization, is made available to the personalization server. The personalization server can make the corresponding public cryptographic key available to other instances, for example, as a signature verification key.The corresponding signature verification key can be used to ensure that data signed with the associated private cryptographic key actually originates from the personalized security element. For example, the personalization server can issue a certificate for or with the corresponding public cryptographic key. Using the corresponding certificate, which could be, for example, a certificate from a certificate chain, particularly a PKI, the personalization server can confirm the authenticity of the corresponding public cryptographic key or its assignment to the personalized security element and thus to the corresponding personalized ID application program.
[0098] For example, to initiate the generation of the asymmetric cryptographic key pair associated with the ID application program, the personalization server sends a request to the security element requesting the security element to generate the asymmetric cryptographic key pair associated with the ID application program.
[0099] Depending on the embodiment, personalization further includes: Receiving one or more root signature verification keys by the control component from the personalization server via the second encrypted subchannel within the first encrypted communication channel, storing the received root signature verification keys by the control component on the mobile terminal, wherein the ID application program is configured to use the root signature verification keys to verify certificate signatures of one or more root instances which have certificates which are each used in the course of reading out the attributes for authenticating a reading computer system to the ID application program.
[0100] Embodiments can have the advantage that, during personalization, root signature verification keys can be stored on the mobile device for use by the ID application program. The corresponding root signature verification keys enable the ID application program to verify signatures from root authorities, in particular certificate signatures from root authorities. A certificate chain is presented to the ID application program for authenticating a computer system, for example, an ID provider server, which wishes to access the attributes read out and stored in the personalized security element to prove the identity of the user of the mobile device. For example, the root signature verification key can be used to verify a first initial certificate of the corresponding certificate chain issued within the certificate chain.If the corresponding initial certificate proves to be authentic, the authenticity of the entire certificate chain can be successively checked and verified. For example, each certificate in the certificate chain is signed using a private cryptographic key of an issuing authority as the signature key. The corresponding signature can be verified, for example, using a corresponding public cryptographic key provided by the preceding certificate as the signature verification key. Only the initial certificate, which is not preceded by a certificate, is signed with a root signature key of a root authority. This root signature can be checked and verified using a corresponding root signature verification key stored in the personalized security element.
[0101] Depending on the embodiment, personalization further includes: Receiving a signature of the attributes from the personalization server by the control component via the second encrypted subchannel within the first encrypted communication channel, wherein the signature serves as proof of authenticity of the attributes, storing the received signature of the attributes by the control component on the mobile terminal.
[0102] Embodiments can have the advantage that the authenticity of the attributes can be verified using the corresponding signature. Thus, the mobile device, which includes a corresponding signature of the attributes used for personalization, can also be used offline to prove the identity of the user of the mobile device. To this end, the mobile device displays the corresponding attributes, including the signature, for example, on a display device, for example in the form of a one- or two-dimensional readable machine code, such as a QR code. The corresponding attributes with the signature can then be captured, for example, by a reader and verified using the signature. Furthermore, a contactless transmission of the corresponding attributes with the signature to another computer system, such as another mobile device, would be possible for example to prove the identity of the user of the mobile device.In this case, too, the authenticity of the corresponding attributes and thus the identity of the user of the mobile device could be proven using the signature.
[0103] According to embodiments, establishing the first encrypted communication channel comprises negotiating the first channel-specific ephemeral symmetric cryptographic session key.
[0104] According to embodiments, negotiating the first channel-specific ephemeral symmetric cryptographic session key comprises: Generating a first random value by the mobile terminal, generating the first channel-specific ephemeral symmetric cryptographic session key using the first random value by the mobile terminal, receiving a first certificate of the personalization server with a fourth public cryptographic key of a fourth asymmetric cryptographic key pair of the personalization server by the mobile terminal from the personalization server, encrypting the first random value using the received first public cryptographic key of the personalization server by the mobile terminal, sending the encrypted first random value to the personalization server by the mobile terminal for generating the first channel-specific ephemeral symmetric cryptographic session key by the personalization server.
[0105] Embodiments may have the advantage that a secure method for providing the first channel-specific ephemeral symmetric cryptographic session key for encrypting the communication channel between the mobile terminal and the personalization server can be provided. For example, a first initial random value is first generated by the mobile terminal and sent to the personalization server. After receiving the corresponding first initial random value, the personalization server generates a second initial random value, which it sends to the mobile terminal. Thus, both participants, the mobile terminal and the personalization server, have both initial random values. Furthermore, the server sends, for example, its certificate to the mobile terminal and receives a certificate of the mobile terminal from the mobile terminal after successfully verifying the corresponding certificate.The mobile device certificate, for example, is a certificate associated with the ID application program. The mobile device certificate received by the personalization server is also verified. Both certificates each contain a public cryptographic key, i.e., the personalization server certificate contains a public cryptographic key of an asymmetric key pair of the personalization server, and the mobile device certificate contains a public cryptographic key of an asymmetric key pair of the mobile device.
[0106] Thus, both participants now each have the other party's cryptographic key, the authenticity of which is verified by a certificate. The mobile device then generates, for example, the first random value, which it sends to the personalization server. Thus, both participants in the communication now each have three random values, from which, for example, the channel-specific ephemeral symmetric cryptographic session key can be calculated. Furthermore, the mobile device sends, for example, a signature of one, several, or all previous messages exchanged during channel establishment to the personalization server. By verifying the corresponding signature using the public cryptographic key provided by the mobile device's certificate as the signature verification key, the personalization server can authenticate the mobile device.This could be, for example, the first public cryptographic key of the ID application program if the certificate of the mobile device is the certificate assigned to the ID application program with the first public cryptographic key of the ID application program. If the personalization server subsequently sends a message encrypted with the first channel-specific ephemeral symmetric cryptographic session key to the mobile device, this also authenticates the personalization server to the mobile device. The personalization server can only calculate the first channel-specific ephemeral symmetric cryptographic session key if it has a private cryptographic key with which it can decrypt the first random value received from the mobile device.Thus, only the personalization server in possession of the corresponding private cryptographic key, to which the personalization server certificate is assigned, is capable of encrypted communication via the encrypted communication channel.
[0107] According to embodiments, establishing the first encrypted communication channel further comprises mutually authenticating the ID application program of the mobile terminal and the personalization server.
[0108] Embodiments can have the advantage that mutual authentication can ensure which participants are communicating with each other and, thus, between which participants the encrypted communication channel is established. In particular, this can be used to determine the identity of the mobile device and to ensure which device the user's electronic identity is assigned to or which mobile device is personalized.
[0109] According to embodiments, the security element is configured such that the prerequisite for authenticating the ID application program of the mobile device with the personalization server is successful authentication of the user with the security element. By authenticating, the user consents to the personalization of the ID application program.
[0110] This ensures that a registered user consents to the use of the mobile device to personalize the ID application. For example, authenticating the ID application involves the security element signing a challenge from the personalization server with the ID application's first private cryptographic key, which requires successful user authentication by the registered user.
[0111] According to embodiments, the mobile terminal sends the certificate with the first public cryptographic key of the ID application program to the personalization server for authentication. For authentication, the mobile terminal further sends a message signed by the security element with the first private cryptographic key of the ID application program to the personalization server.
[0112] According to embodiments, the message is a challenge received by the personalization component from the personalization server in the course of a challenge-response procedure.
[0113] According to embodiments, establishing the first encrypted subchannel comprises authenticating the user to the ID token via the mobile device.
[0114] Embodiments may have the advantage that, when reading the ID token, it can be ensured that the corresponding reading is authorized by the owner of the ID token. For example, the user is authenticated to the ID token using the mobile device.
[0115] According to embodiments, authenticating the user to the ID token includes: Receiving a further user authentication factor detected by the one or more authentication sensors by the personalization component, generating a symmetric cryptographic key using the received further authentication factor, receiving an encrypted second random value by the personalization component from the ID token, wherein the encrypted second random value is encrypted using the symmetric cryptographic key, which the ID token generates using a further reference value of the registered user stored in the ID token for verifying the further authentication factor, decrypting the received encrypted second value using the generated symmetric cryptographic key, generating a first ephemeral asymmetric cryptographic key pair of the ID application program by the security element,which comprises a first ephemeral private cryptographic key and a first ephemeral public cryptographic key of the ID application program, sending the first ephemeral public cryptographic key of the ID application program to the ID token, receiving an ephemeral public cryptographic key of the ID token, generating a first secret shared with the ID token by the security element using the decrypted second random value, the first ephemeral private cryptographic key of the ID application program, and the ephemeral public cryptographic key of the ID token, receiving the shared first secret by the control component, generating a first common authentication key for mutually authenticating the ID application program and the ID token by the control component using the shared first secret,Generating a first authentication token using the first authentication key and the first ephemeral public cryptographic key of the ID token by the control component, Sending the first authentication token generated by the control component to the ID token by the personalization component, Receiving a second authentication token from the ID token by the personalization component, which forwards the second authentication token to the control component, Verifying the received second authentication token by the control component using the first authentication key and the first ephemeral public cryptographic key of the ID application program.
[0116] For example, an ephemeral symmetric cryptographic key is derived using a recorded user authentication factor. The ephemeral symmetric cryptographic key is derived, for example, by the security element of the mobile device. The authentication factor recorded by the mobile device and a reference value stored on the ID token each serve as a shared password for mutually deriving the ephemeral symmetric cryptographic key. The mobile device receives a random value from the ID token, which is encrypted with the same ephemeral symmetric cryptographic key.The ID token derives the corresponding ephemeral symmetric cryptographic key, for example, from a reference value for the authentication factor, or the correspondingly derived ephemeral symmetric cryptographic key is stored on the ID token. If the mobile device is able to correctly decrypt the received encrypted random value, this constitutes proof that the mobile device has the correct authentication factor. The mobile device generates an ephemeral asymmetric key pair, whose public cryptographic key the mobile device sends to the ID token. In return, the mobile device receives the public cryptographic key of the ID token. At this point in the process, therefore, no static cryptographic keys are necessary; only randomly generated ephemeral asymmetric key pairs can be used.The mobile device generates a secret shared with the ID token using the decrypted random value, the ephemeral private cryptographic key of the ID application program, and the ephemeral public cryptographic key of the ID token. The ID token is also capable of calculating the corresponding secret using the random value it generated, the ephemeral private cryptographic key of the ID token, and the ephemeral public cryptographic key of the mobile device received from the mobile device.
[0117] The mobile device can then use the shared secret thus generated to calculate a common authentication key for mutually authenticating the ID application program and the ID token. For example, the mobile device can generate a first authentication token using the corresponding authentication key and the ephemeral public cryptographic key of the ID token. The corresponding authentication token can be sent from the mobile device to the ID token, which can verify the received authentication token using the shared authentication key and the ephemeral private cryptographic key of the ID token. Thus, the mobile device can authenticate itself to the ID token. Likewise, the ID token can send an authentication token to the mobile device.The mobile device receives the authentication token, which is generated, for example, using the shared secret and the mobile device's ephemeral public cryptographic key. The authentication token can be verified using the authentication key and the public cryptographic key of the ID application program.
[0118] According to embodiments, an application domain identifier of an application domain of the ID token is further used to generate the shared first secret, wherein the application domain identifier is received together with the encrypted second random value from the ID token by the ID application program.
[0119] According to embodiments, the first authentication key is a cryptographic key for generating a message authentication code, wherein the first authentication token is a first MAC of the first ephemeral public cryptographic key of the ID application program generated using the first authentication key.
[0120] According to embodiments, the security element further generates a fifth ephemeral symmetric cryptographic key using the shared first secret for encrypting the communication between the mobile terminal and the ID token.
[0121] Embodiments may have the advantage that an ephemeral symmetric cryptographic key can be provided, with which the communication between the mobile terminal and the ID token can be encrypted. Thus, for example, the further communication between the IT token and the mobile terminal, the ID token communicating with the personalization server during the establishment of the second subchannel, can be encrypted. For example, the communication is encrypted with the corresponding ephemeral symmetric cryptographic key until the encrypted subchannel between the ID token and the personalization server is established, which enables end-to-end encryption between the ID token and the personalization server.
[0122] According to embodiments, establishing the first encrypted subchannel comprises authenticating the personalization server by the ID token via the mobile terminal.
[0123] Embodiments can have the advantage that the participants establishing the encrypted subchannel can be sure with whom they are communicating. In particular, the ID token can thus be sure with whom it is communicating. For example, a corresponding authentication method is used to authenticate the personalization server using the ID token.
[0124] According to embodiments, authenticating the personalization server by the ID token comprises: Receiving a second certificate from the personalization server, which comprises a second public cryptographic key of a second asymmetric cryptographic key pair of the personalization server, via the first encrypted communication channel, verifying a signature of the received second certificate of the personalization server, generating a third random value using the ID token, sending the third random value as a challenge to the personalization server via the first encrypted communication channel, receiving a first signature of the challenge as a response from the personalization server via the first encrypted communication channel, wherein the challenge is signed using a second private cryptographic key of the personalization server,Verifying the received first signature using the second public cryptographic key of the personalization server and the sent third random value.
[0125] According to embodiments, a second ephemeral public cryptographic key of the personalization server, for example in compressed form, is further received by the ID token via the encrypted communication channel.
[0126] According to embodiments, to generate the response, a first data combination is signed, which includes the challenge. For example, the first data combination includes, in addition to the third random value sent as a challenge, the second ephemeral public cryptographic key of the personalization server, for example in compressed form.
[0127] Embodiments may have the advantage that the personalization server can be authenticated by the ID token in a cryptographically secure manner. For this purpose, the ID token receives, for example, a certificate from the personalization server, which provides a public cryptographic key of the personalization server for authentication. The ID token verifies the signature of the received certificate. For example, the corresponding certificate is received as part of a certificate chain, for the verification of which corresponding signature verification keys, in particular root signature verification keys, are stored on the ID token. Thus, the ID token can verify the authenticity of the provided certificate based on the certificate chain, for example, a PKI. Furthermore, the ID token receives, for example, an ephemeral public cryptographic key of the personalization server.For example, the ID token receives the personalization server's ephemeral public cryptographic key in compressed form. In return for receiving the personalization server's certificate, the ID token generates a random value, which it sends to the personalization server as a challenge via the encrypted communication channel. The personalization server creates a signature of the challenge as a response to the challenge using a private cryptographic key that forms an asymmetric key pair with the public cryptographic key of the previously provided certificate. For example, to generate the response, a data combination is signed that includes the random value as a challenge and the personalization server's ephemeral public cryptographic key, for example, in compressed form.The ID token receives the corresponding signature via the encrypted communication channel and verifies it using the previously received public cryptographic key of the personalization server as the signature verification key. For this purpose, the ID token also uses, for example, the random value previously sent as a challenge and the previously received ephemeral public cryptographic key of the personalization server.
[0128] According to embodiments, the first and second certificates of the personalization server are different certificates with different public cryptographic keys of the personalization server. Thus, in this case, the first and second public cryptographic keys of the personalization server are, for example, different public cryptographic keys of different asymmetric cryptographic key pairs.
[0129] According to embodiments, the first and second certificates of the personalization server are the same certificate with the same public cryptographic key of the personalization server. Thus, in this case, the first and second public cryptographic keys of the personalization server are, for example, the same public cryptographic key of the same asymmetric cryptographic key pair.
[0130] According to embodiments, the second certificate of the personalization server is a read certificate, which proves that the personalization server has the right to read the attributes to be read from the ID token.
[0131] Embodiments may have the advantage that the personalization server can use the corresponding certificate to prove read authorization to read the attributes to be read from the ID token.
[0132] According to embodiments, the second certificate of the personalization server is received as part of a certificate chain, wherein verifying the signature of the received certificate comprises checking a signature chain of the certificates of the certificate chain. According to embodiments, the certificate chain begins with an initial certificate signed by a root authority whose signature is verifiable with a root signature verification key stored in the ID token. According to embodiments, the certificate chain ends with the certificate of the personalization server.
[0133] According to embodiments, the combination further comprises an identifier of the ID token, wherein the identifier of the ID token is further used to verify the received signature.
[0134] According to embodiments, the identifier of the ID token is generated, for example, using the ephemeral public cryptographic key of the ID token. For example, the identifier of the ID token is the compressed first ephemeral public cryptographic key of the ID token.
[0135] Embodiments may have the advantage that the ID token can be identified using the identifier. For example, an ephemeral public cryptographic key of the ID token can be used as the identifier of the ID token, which key was previously generated, for example, during the user's authentication using the ID token. The corresponding ID token can, for example, be forwarded from the mobile device to the personalization server. Thus, the personalization server receives access to the corresponding ephemeral public cryptographic key and can use this as an identifier to ensure that the ID token with which it is authenticating is the same ID token with which the user of the mobile device previously authenticated.
[0136] According to embodiments, establishing the first encrypted subchannel comprises authenticating the ID token to the personalization server via the mobile terminal.
[0137] Embodiments may have the advantage that mutual authentication between ID token and personalization server takes place during the establishment of the encrypted subchannel.
[0138] According to embodiments, authenticating the ID token to personalization servers includes: Sending the ID token's public cryptographic key from the ID token to the personalization server via the first encrypted communication channel, receiving the second ephemeral public cryptographic key of the personalization server by the ID token from the personalization server via the first encrypted communication channel, generating a second secret shared with the personalization server by the ID token using the ID token's private cryptographic key and the second ephemeral public cryptographic key of the personalization server, generating a fourth random value by the ID token, generating a second shared authentication key for authenticating data sent via the first encrypted subchannel by the ID token,wherein the second shared authentication key is generated using the shared second secret and the fourth random value, generating a third authentication token by the ID token using the second authentication key and the second ephemeral public cryptographic key of the personalization server to authenticate the ID token to the personalization server, sending the fourth random value together with the third authentication token to authenticate the ID token by the ID token to the personalization server via the first encrypted communication channel.
[0139] Embodiments may have the advantage that the ID token can authenticate itself to the personalization server in a cryptographically secure manner. To do so, the ID token sends a public cryptographic key to the personalization server. This occurs via the encrypted communication channel. In return, the ID token receives an ephemeral public cryptographic key from the personalization server via the encrypted communication channel. The ID token calculates a shared secret with the personalization server using the private cryptographic key of the ID token and the received ephemeral public cryptographic key of the personalization server. The personalization server can calculate the same shared secret using the public cryptographic key of the ID token and the ephemeral private cryptographic key of the personalization server.The ID token generates a random value, which it uses to calculate a shared authentication key. The authentication key is used to authenticate data sent over the encrypted subchannel. The ID token generates the corresponding shared authentication key using the random value and the shared secret. Furthermore, the ID token generates an authentication token using the corresponding authentication key and the ephemeral key of the personalization server. The ID token sends the authentication token thus generated, along with the random value, to the personalization server in the communication channel. Upon receipt of the random value, the personalization server is also able to calculate the authentication key using the shared secret.Using this shared authentication key and the personalization server's ephemeral public cryptographic key, the personalization server can verify the received authentication token. If the verification is successful, the ID token is also successfully authenticated to the personalization server, and successful mutual authentication of the ID token and the personalization server is achieved. Furthermore, the shared authentication key calculated in this way can be used to authenticate data exchanged between the ID token and the personalization server via the encrypted subchannel.
[0140] According to embodiments, the ephemeral public cryptographic key of the personalization server received during the authentication of the personalization server, for example in compressed form, is compared with the ephemeral public cryptographic key of the personalization server received during the authentication of the ID token, wherein a match between both ephemeral public cryptographic keys of the personalization server is a prerequisite for generating the shared second secret. For example, the ephemeral public cryptographic key of the personalization server received during the authentication of the ID token is compressed for the purpose of comparison.
[0141] Embodiments may have the advantage that a binding can be established between the personalization server and the authentication server with which communication takes place during the authentication of the ID token.
[0142] According to embodiments, an application domain identifier of an application domain of the ID token is further used to generate the shared second secret, wherein the application domain identifier is sent from the ID token to the personalization server together with the public cryptographic key of the ID token.
[0143] Embodiments may have the advantage that the ID token can be assigned to a specific application area.
[0144] According to embodiments, the second authentication key is a cryptographic key for generating a message authentication code, wherein the second authentication token is a second MAC of the second ephemeral public cryptographic key of the personalization server generated using the second authentication key.
[0145] According to embodiments, the ID token further generates the second channel-specific ephemeral symmetric cryptographic session key using the shared second secret and fourth random value.
[0146] Embodiments may have the advantage that a channel-specific, ephemeral, symmetric cryptographic session key can be provided for the subchannel in a cryptographically secured manner, which is known only to the ID token and the personalization server. Thus, end-to-end encryption can be enabled via the encrypted subchannel between the ID token and the personalization server.
[0147] The mobile device can serve, for example, as an authentication token, authorization token, and / or as proof of identity, i.e., ID token, for example in electronic business processes. For this purpose, the user can be securely authenticated by the mobile device. According to embodiments, the local authentication of the user by the device can serve as the basis for further authentication of the user using identity attributes, for example, stored on the mobile device, for further authentication by an ID provider service.
[0148] The mobile device is configured for secure user authentication using the authentication sensor and the operating system or security element. Authentication can, for example, be based on capturing and evaluating the user's biometric characteristics.
[0149] Embodiments may have the advantage that manufacturers of ID application programs or the corresponding ID application programs can utilize the authentication functionality of the mobile terminal for user authentication. The authentication functionality of the terminal using the authentication sensor and the security element implements a secure binding of the user to the terminal.
[0150] The security element, which may be, for example, a hardware-based security element from the device manufacturer, provides cryptographic means, such as cryptographic key material and protocols, which can be used to securely make the authentication results of the user of the mobile device available to an ID application program installed on the mobile device. Thus, the security element, for example, ensures the cryptographic security of the operating system or provides the operating system with cryptographic security functionality. According to embodiments, the security element may also be, for example, a hardware-based security element from the device manufacturer. Furthermore, the security element provides cryptographic key material that is assigned to the ID application program.
[0151] According to embodiments, establishing the second encrypted subchannel further comprises authenticating the personalization server by the control component.
[0152] Embodiments may have the advantage that a prerequisite for establishing the second encrypted subchannel is successful authentication of the personalization server by the security element. Thus, the security element can be certain not only that the personalization is performed by the same personalization server that read the attributes from the ID token, but also that the corresponding server is authorized to personalize the corresponding security element.
[0153] According to embodiments, authenticating the personalization server by the control component comprises: Sending a challenge from the control component to the personalization server via the first encrypted communication channel, receiving a response from the personalization server by the control component, the response being a signature of the challenge created using a third private cryptographic key of a third asymmetric key pair of the personalization server, receiving a third ephemeral public cryptographic key of the personalization server by the control component, verifying the received response using a third public cryptographic key of the third asymmetric key pair of the personalization server and the sent challenge, storing the third ephemeral public cryptographic key of the personalization server by the control component on the mobile terminal.
[0154] Depending on the embodiment, the challenge is a random value.
[0155] According to embodiments, a third ephemeral public cryptographic key of the personalization server, for example in compressed form, is further received by the control component via the encrypted communication channel.
[0156] According to embodiments, a second data combination comprising the challenge is signed to generate the response. For example, the second data combination includes the fifth random value sent as a challenge and the third ephemeral public cryptographic key of the personalization server, for example in compressed form.
[0157] Embodiments may have the advantage that the ID application program to be personalized first receives a certificate from the personalization server via the encrypted communication channel. The corresponding certificate can be verified by the security element. For example, the corresponding certificate is provided as part of a certificate chain, which the security element can verify using stored root signature verification keys. Thus, the ID token can verify the authenticity of the provided certificate using the certificate chain, for example, a PKI. Furthermore, the security element receives an ephemeral public cryptographic key from the personalization server. For example, the security element receives the ephemeral public cryptographic key of the personalization server in compressed form.In return for receiving the certificate from the personalization server, the security element generates a random value and sends the corresponding random value as a challenge to the personalization server. In response to sending the random value as a challenge, the security element receives a signature of the challenge as a response from the personalization server via the encrypted communication channel. To create the signature, the private cryptographic key of the personalization server is used, which forms an asymmetric key pair with the public cryptographic key of the previously provided certificate. For example, to generate the response, a data combination is signed. The corresponding data combination includes, for example, the random value previously sent as a challenge and the ephemeral public cryptographic key of the personalization server, e.g., in compressed form.The security element can verify the corresponding signature using the previously received public cryptographic key of the personalization server as the signature verification key. To do this, the security element can, for example, also use the ephemeral public cryptographic key of the personalization server and the random value previously sent as a challenge. If the signature verification is successful, the personalization server is considered successfully authenticated.
[0158] According to embodiments, authenticating the personalization server by the control component further comprises receiving a third certificate of the personalization server, which comprises the third public cryptographic key of the personalization server, by the control component via the first encrypted communication channel.
[0159] According to embodiments, the first, second, and / or third certificates of the personalization server are different certificates with different public cryptographic keys of the personalization server. Thus, in this case, the first, second, and / or third public cryptographic keys of the personalization server are, for example, different public cryptographic keys of different asymmetric cryptographic key pairs.
[0160] According to embodiments, the first, second, and / or third certificate of the personalization server is the same certificate with the same public cryptographic key of the personalization server. Thus, in this case, the first, second, and / or third public cryptographic key of the personalization server is, for example, the same public cryptographic key of the same asymmetric cryptographic key pair.
[0161] According to embodiments, the certificate is received as part of a certificate chain, wherein verifying the signature of the received certificate comprises checking a signature chain of the certificates in the certificate chain. According to embodiments, the certificate chain begins with a first certificate signed by a root authority whose signature is verifiable with a root signature verification key to which the ID application program has access. According to embodiments, the certificate chain ends with the certificate of the personalization server.
[0162] According to embodiments, establishing the second encrypted subchannel further comprises authenticating the control component to the personalization server.
[0163] Embodiments may have the advantage of performing authentication of the control component with the personalization server. Thus, for example, mutual authentication can be implemented between the control component or the ID application program and the personalization server.
[0164] According to embodiments, authenticating the ID application program by the control component to the personalization server comprises: Sending a request to generate a third shared secret with the personalization server from the control component to the security element, where the request includes the third ephemeral public cryptographic key of the personalization server. In response to the request, receiving the third shared secret generated by the security element by the control component, where the generation of the third shared secret by the security element is performed using the second private cryptographic key of the ID application program and the third ephemeral public cryptographic key of the personalization server. Generating a sixth random value by the control component. Generating a third common authentication key by the control component to authenticate data sent over the second encrypted sub-channel.wherein the third shared authentication key is generated using the shared third secret and the sixth random value, generating a fourth authentication token by the control component using the third authentication key and the third ephemeral public cryptographic key of the personalization server to authenticate the ID application program to the personalization server, sending the sixth random value together with the fourth authentication token to authenticate the ID application program by the control component to the personalization server via the first encrypted communication channel.
[0165] Embodiments can have the advantage that the not-yet-personalized ID application program can authenticate itself to the personalization server. To do this, the corresponding ID application program to be personalized first uses a stored initial key of the security element. The corresponding initial key is stored on the security element, for example, during provisioning of the security element. To authenticate the security element, the corresponding security element first receives, for example, an ephemeral public cryptographic key generated for the purpose of authentication from the personalization server. The personalization server generates the corresponding public cryptographic key, for example, for the authentication of the security element to be personalized.The security element receives the cryptographic key, for example, via the encrypted communication channel. The security element calculates a shared secret using the security element's initial private cryptographic key and the received ephemeral public cryptographic key of the personalization server. The ID application program to be personalized generates a random value. The ID application program to be personalized uses the corresponding random value to generate a shared authentication key. The shared secret is also used to generate the corresponding shared authentication key. The security element also generates an authentication token.The security element generates the corresponding authentication token using the previously received public cryptographic key from the personalization server and the previously generated shared authentication key. The ID application program to be personalized sends this authentication token, along with the random value, to the personalization server via the encrypted communication channel. The personalization server can also initially calculate the shared secret. To do this, the personalization server uses an initial public cryptographic key of the security element, which is known to the personalization server. For example, the corresponding initialization key was generated during provisioning of the security element to be personalized and made available to the personalization server.Furthermore, the personalization server uses the personalization server's ephemeral private cryptographic key to calculate the shared secret. With the corresponding shared secret, the personalization server is able to calculate the shared authentication key. To do so, the personalization server uses the received random value and the previously calculated shared secret. The personalization server can then verify the received authentication token using the shared authentication key and the personalization server's ephemeral public cryptographic key.
[0166] This allows the ID application program to be personalized to be authenticated. This can have the advantage, for example, that the participants in the encrypted subchannel between the security element to be personalized and the personalization server know who they are communicating with, or they can ensure that they are communicating with the correct participant. Furthermore, the shared authentication key can be used to authenticate data exchanged over the second encrypted subchannel between the security element to be personalized and the personalization server.
[0167] According to embodiments, the ephemeral public cryptographic key of the personalization server received during the authentication of the personalization server, for example in compressed form, is compared with the ephemeral public cryptographic key of the personalization server received during the authentication of the ID application program, for example in compressed form, wherein a match between both ephemeral public cryptographic keys of the personalization server is a prerequisite for generating the shared secret.
[0168] According to embodiments, the third authentication key is a cryptographic key for generating a message authentication code, wherein the third authentication token is a third MAC of the third ephemeral public cryptographic key of the personalization server generated using the third authentication key.
[0169] According to embodiments, the security element is configured such that the prerequisite for generating the shared third secret by the security element is successful authentication of the user to the security element. By authenticating, the user consents to the establishment of the second encrypted subchannel.
[0170] This ensures that a registered user consents to the authentication of the control component or ID application program with the personalization server and thus to the establishment of the second encrypted subchannel. For example, generating the shared third secret requires the use of the ID application program's second private cryptographic key, which is tied, for example, to successful user authentication of the registered user.
[0171] According to embodiments, the control component further generates the third channel-specific ephemeral symmetric cryptographic session key using the shared third secret and the sixth random value.
[0172] Embodiments may have the advantage that a channel-specific ephemeral symmetric cryptographic session key can be provided for the ID application program to be personalized and the personalization server, by means of which the second subchannel can be encrypted. In particular, end-to-end encryption can thus be realized between the endpoints of the corresponding subchannel, i.e., the security element to be personalized and the personalization server.
[0173] According to embodiments, a plurality of ID tokens are used for personalization.
[0174] According to embodiments, a second ID token is further used for personalization. The personalization further includes: Establishing a third encrypted subchannel between the second ID token and the personalization server within the encrypted communication channel via the mobile terminal, wherein the ID application program is used to establish the third encrypted subchannel; Reading one or more of the second attributes from the second ID token by the personalization server via the third encrypted subchannel within the encrypted communication channel; Establishing a fourth encrypted subchannel between the control component and the personalization server within the encrypted communication channel, wherein the ID application program is used to establish the fourth encrypted subchannel; Receiving the read second attributes by the control component from the personalization server via the fourth encrypted subchannel within the encrypted communication channel;Storing the received second attributes by the control component, wherein the ID application program is configured to use the second attributes to prove the identity of the user to another computer system.
[0175] Embodiments can have the advantage that attributes can be read from different ID tokens and, during personalization, stored in the security element of the mobile device to be personalized. Thus, the mobile device can store not only digital identities that reflect identities provided by an ID token, i.e., an electronic identity document, but also identities that represent combinations of attributes of corresponding ID tokens. For example, the attributes from different ID tokens are read via the same encrypted communication channel.
[0176] For example, attributes from different ID tokens are read via different encrypted communication channels. According to embodiments, a third encrypted communication channel is established between the mobile device and the personalization server via the network, within which a third and fourth encrypted subchannel are established.
[0177] For example, the ID application program is configured to use the second attributes in combination with the first attributes to prove the identity of the user to another computer system, for example an ID provider server.
[0178] According to embodiments, the method further comprises using the cryptographically secured electronic identity. One or more of the contributed attributes are provided to an ID provider server. The use comprises: Establishing a second encrypted communication channel between the mobile terminal and the ID provider server via the network, receiving a read request from an ID provider server to read one or more of the attributes of the electronic identity, authenticating the ID provider server by the ID application program using the control component, authenticating the ID application program to the ID provider server by the security element using the control component, reading the attributes to be read from the mobile terminal by the ID provider server via the network using the control component.
[0179] Embodiments can have the advantage that the cryptographically secured electronic identity created during personalization or incorporated into the ID application program can be used to verify the identity of the user of the mobile device. Thus, the mobile device with the ID application program can be used as a portable electronic identification document. For example, the mobile device is a smartphone that, with the ID application program, has an ID function. To use the electronic identity, attributes of the corresponding electronic identity are read from the mobile device by an ID provider server in a cryptographically secured manner and made available, for example, to a service provider.Reading the attributes through an ID provider server can have the advantage of ensuring that only an authorized entity that can prove the corresponding authorization, for example by means of a certificate, can read attributes from the mobile device in a cryptographically secured manner.
[0180] When using the electronic identity, an encrypted communication channel is first established between the mobile device and the ID provider server. The mobile device or the ID application program receives a read request from the ID provider to read one or more attributes of the electronic identity. For example, the read request identifies the attributes to be read. The read request also specifies, for example, who is requesting the corresponding attributes, i.e., to whom the ID provider server will forward the corresponding attributes, as well as their intended use. The information provided by the read request is displayed, for example, on a display device on the mobile device for the user to review the corresponding information.Furthermore, the user of the mobile device can be offered the possibility to select which of the requested attributes should actually be made available to the ID provider server and / or to select further attributes which should additionally be made available to the ID provider server.
[0181] To cryptographically secure the reading of the attributes, the ID application program authenticates the ID provider server, and the ID application program authenticates the ID provider server. To authenticate the ID application program against the ID provider server, the mobile device or the ID application program uses the mobile device's security element, which manages the ID application program's private cryptographic keys. Following successful mutual authentication, the ID provider server reads the attributes to be read from the mobile device over the network. The ID provider server can then, for example, sign the read attributes and make them available to a requesting service provider. The service provider can verify the authenticity of the attributes provided to it using the ID provider server's signature.
[0182] Embodiments may have the advantage that communication via the second communication channel can be carried out in an encrypted and thus cryptographically secured manner.
[0183] In the course of negotiating the channel-specific ephemeral symmetric cryptographic session key for encrypting the second communication channel, for example, a random value generated by the mobile device, such as the control component, is first provided. This random value is used to generate a channel-specific ephemeral symmetric cryptographic session key for encrypting the communication via the second communication channel. Input parameters, for example, are used to generate the channel-specific ephemeral symmetric cryptographic session key. For example, the mobile device receives another random value from the ID provider server. For example, the mobile device calculates another random value.
[0184] The mobile device also receives a certificate from the ID provider server. This certificate from the ID provider server provides a public cryptographic key of an asymmetric cryptographic key pair of the ID provider server. The mobile device encrypts the previously calculated random value using the ID provider server's public cryptographic key provided by the certificate and sends this encrypted random value to the ID provider server. The ID provider server receives the encrypted random value, can decrypt it, and also use it to calculate the channel-specific ephemeral symmetric cryptographic session key.
[0185] According to embodiments, the second encrypted communication channel is encrypted with a fourth channel-specific ephemeral symmetric cryptographic session key.
[0186] According to embodiments, the encryption of the second encrypted communication channel is end-to-end encryption between the mobile device and the ID provider server.
[0187] According to embodiments, establishing the second encrypted communication channel comprises negotiating the fourth channel-specific ephemeral symmetric cryptographic session key.
[0188] According to embodiments, negotiating the fourth channel-specific ephemeral symmetric cryptographic session key comprises: Generating a seventh random value by the mobile terminal, generating the fourth channel-specific ephemeral symmetric cryptographic session key using the seventh random value by the mobile terminal, receiving a first certificate of the ID provider server with a fifth public cryptographic key of a fifth asymmetric cryptographic key pair of the ID provider server by the mobile terminal from the ID provider server, encrypting the seventh random value using the received fifth public cryptographic key of the ID provider server by the mobile terminal, sending the encrypted seventh random value to the ID provider server by the mobile terminal for generating the fourth channel-specific ephemeral symmetric cryptographic session key by the ID provider server.
[0189] According to embodiments, the mobile terminal further receives an eighth random value from the ID provider server and generates a ninth random value, wherein the eighth and ninth random values are also used for generating the fourth channel-specific ephemeral symmetric cryptographic session key by the mobile terminal.
[0190] According to embodiments, authenticating the ID provider server using the control component comprises: Sending a challenge from the control component to the ID provider server via the second encrypted communication channel, receiving a response from the ID provider server by the control component, wherein the response is a signature of the challenge created using the private cryptographic key of an asymmetric key pair of the ID provider server, receiving a fourth ephemeral public cryptographic key of an ephemeral key pair of the ID provider server by the control component, verifying the received response using a public cryptographic key of the asymmetric key pair of the ID provider server and the sent challenge, storing the fourth ephemeral public cryptographic key of the ID provider server by the control component on the mobile terminal.
[0191] Embodiments may have the advantage that the authentication of the ID provider server can be carried out, for example, using a challenge-response method. For this purpose, the control component sends a challenge to the ID provider server via the encrypted communication channel. The ID provider server creates a response to the challenge. The response is a signature of the challenge created using a private cryptographic key of an asymmetric key pair of the ID provider server. The ID provider server sends the corresponding response to the mobile terminal, which receives the response. Furthermore, the mobile terminal receives an ephemeral public cryptographic key of an ephemeral cryptographic key pair of the ID provider server.The control component of the ID application program verifies the received response using a public cryptographic key from the asymmetric key pair of the ID provider server and the sent challenge. During the verification process, it is checked whether the response is actually a signature of the sent challenge using the private cryptographic key of the ID provider server. If the verification is successful, i.e., if the ID provider server is successfully authenticated by the ID application program, the mobile device saves the received ephemeral public cryptographic key of the ID provider server.
[0192] According to embodiments, the fourth ephemeral public cryptographic key of the ID provider server is received from the control component, for example, in compressed form. According to embodiments, the fourth ephemeral public cryptographic key of the ID provider server is received, for example, in uncompressed form.
[0193] Depending on the embodiment, the challenge is a random value.
[0194] According to embodiments, authenticating the ID provider server by the control component further comprises receiving a certificate of the ID provider server, which comprises the public cryptographic key of the ID provider server, by the control component via the second encrypted communication channel.
[0195] The corresponding certificate of the ID provider server can, for example, be received together with a certificate chain, the validity of which is verified using a root certificate, as previously stored for the control component on the mobile device.
[0196] According to embodiments, authenticating the ID application program to the ID provider server by the security element using the control component comprises: Sending a request to generate a fourth secret shared with the ID provider server from the control component to the security element, wherein the request includes the fourth ephemeral public cryptographic key of the ID provider server, in response to the request, receiving the shared fourth secret generated by the security element by the control component, wherein the generation of the shared fourth secret by the security element is carried out using the first private cryptographic key of the ID application program and the fourth ephemeral public cryptographic key of the ID provider server, Generating a tenth random value by the control component, Generating a fourth common authentication key for authenticating data to the ID provider server by the control component, wherein the fourth common authentication key is generated using the shared fourth secret and the tenth random value, Generating a fifth authentication token by the control component using the fourth authentication key and the fourth ephemeral public cryptographic key of the ID provider server for authenticating the ID application program to the ID provider server, Sending the tenth random value together with the fifth authentication token for authenticating the ID application program by the control component to the ID provider server via the second encrypted communication channel.
[0197] Embodiments may have the advantage that the ID application program can authenticate itself to the ID provider server in the course of calculating shared symmetric cryptographic keys. To do so, the control component sends, for example, a request to the security element to generate a secret shared with the ID provider server using the ID application program's private cryptographic key. With the request, the control component provides the security element with, for example, the ephemeral public cryptographic key of the ID provider server. The control component has previously received this ephemeral public cryptographic key of the ID provider server, for example, during the authentication of the ID provider server. For example, the control component has received the corresponding public cryptographic key in uncompressed form.Alternatively, the control component can receive the ephemeral public cryptographic key of the ID provider server from the ID provider server during the authentication of the ID application program. For example, the control component receives the ephemeral public cryptographic key of the ID provider server in compressed form during the authentication of the ID provider server, compresses the public cryptographic key of the ID provider server received in uncompressed form during the authentication of the ID application program, and compares the two.
[0198] The security element generates the requested secret using the second private cryptographic key of the ID application program and the ephemeral public cryptographic key of the ID provider server and makes it available to the control component. The control component uses the shared secret to generate a common authentication key for authenticating data exchanged with the ID provider server. The corresponding authentication key is, for example, a symmetric cryptographic key. The control component also uses a random value to generate the authentication key. This random value is generated on the mobile device, for example, by the control component.Using the authentication key and the ephemeral public cryptographic key of the ID provider server, the control component generates an authentication token. The control component sends the authentication token thus generated, along with the random value, to the ID provider server to authenticate the ID application program against the ID provider server. Using the random value received from the ID application program or the control component, the ID provider server can also generate the authentication key. The ID provider server calculates the shared secret required for this, for example, using an ephemeral private cryptographic key of the ephemeral asymmetric key pair of the ID provider server and the public cryptographic key of the ID application program.Using the authentication key and its ephemeral public cryptographic key, the ID provider server can check the received authentication token for validity.
[0199] According to embodiments, the fifth authentication key is a cryptographic key for generating a message authentication code, wherein the fifth authentication token is a fourth MAC of the fourth ephemeral public cryptographic key of the ID application program generated using the fifth authentication key.
[0200] According to embodiments, the security element is configured such that the prerequisite for the authentication of the ID application program of the mobile device to the ID provider server by the security element is successful authentication of the user to the security element. By authenticating, the user consents to the reading of the attributes to be read by the ID provider server.
[0201] Embodiments can have the advantage of ensuring that authentication of the ID application program to the ID provider server, and thus reading attributes from the ID application program, is only possible with the consent of the user of the mobile device. During the authentication of the user of the mobile device, it is ensured that the confirmed user is actually the registered user. To generate the shared fourth secret during the authentication of the ID application program, for example, it is necessary to use the first private cryptographic key of the ID application program, which is tied, for example, to successful user authentication of the registered user.
[0202] According to embodiments, the control component further generates a fourth ephemeral symmetric cryptographic session key using the shared fourth secret and the tenth random value.
[0203] Embodiments may have the advantage that the ephemeral symmetric cryptographic session key can be used to encrypt communication between the ID provider server and the ID application program.
[0204] According to embodiments, the attributes to be read are encrypted using the fourth ephemeral symmetric cryptographic session key and sent to the ID provider server via the second encrypted communication channel.
[0205] Embodiments may have the advantage that the read attributes can be sent to the ID provider server in a cryptographically secured manner.
[0206] Embodiments further comprise a mobile terminal comprising a processor and a memory. An ID application program for providing an electronic identity is stored in the memory. The processor is configured to execute a method for creating a cryptographically secured electronic identity of a user on a mobile terminal. The ID application program comprises a control component for controlling the creation of the electronic identity. The ID application program further comprises a provisioning component for provisioning the ID application program during the creation of the cryptographically secured electronic identity. The mobile terminal further comprises a security element. The mobile terminal further comprises a communication interface for communicating with a personalization server via a network.
[0207] Provisioning the ID application program includes: In response to a security inspection request from the provisioning component, performing a remote security inspection of the security infrastructure of the mobile terminal using the control component by a personalization server over a network, receiving a result of the remote security inspection from the personalization server, which the control component forwards to the provisioning component, in response to a positive result of the remote security inspection, sending a key generation request from the provisioning component to the control component, which the control component forwards to the security element, in response to the key generation request, generating a first asymmetric key pair associated with the ID application program and a second asymmetric key pair associated with the ID application program by the security element,wherein the first asymmetric key pair comprises a first private cryptographic key and a first public cryptographic key, wherein the second asymmetric key pair comprises a second private cryptographic key and a second public cryptographic key, wherein the security element sends the first and second public cryptographic keys to the control component, which forwards the two public cryptographic keys to the provisioning component upon receipt of the two public cryptographic keys, creating a certificate request by the provisioning component for creating a certificate of the ID application program comprising the first public cryptographic key, wherein the certificate request comprises the first public cryptographic key,Sending the certificate request by the provisioning component over the network to the personalization server, wherein the certificate request includes the first public cryptographic key, wherein the provisioning component sends the second public cryptographic key to the personalization server in response to the certificate request, receiving the certificate created by the personalization server with the first public cryptographic key and a root certificate of a root instance of a PKI by the personalization component, storing the certificate of the ID application program and the root certificate on the mobile terminal. ,
[0208] According to embodiments, the mobile terminal is configured to implement each of the above-described embodiments of the method for creating the cryptographically secured electronic identity of the user on the mobile terminal.
[0209] According to embodiments, creating the cryptographically secured electronic identity further comprises personalizing the ID application program on the mobile terminal using an ID token. The ID application program further comprises a personalization component for personalizing the ID application program during the creation of the cryptographically secured electronic identity.
[0210] Personalization includes: Establishing an encrypted communication channel between the mobile terminal and the personalization server via the network, wherein the personalization component is used to establish the encrypted communication channel. Establishing a first encrypted subchannel between the ID token and the personalization server within the encrypted communication channel via the mobile terminal, wherein the personalization component is used to establish the first encrypted subchannel. Reading one or more of the attributes from the ID token by the personalization server via the first encrypted subchannel within the encrypted communication channel. Establishing a second encrypted subchannel between the control component and the personalization server within the encrypted communication channel, wherein the personalization component is used to establish the second encrypted subchannel.Receiving the read attributes by the control component from the personalization server via the second encrypted subchannel within the encrypted communication channel, storing the received attributes by the control component on the mobile terminal, wherein the ID application program is configured to use the attributes to prove the identity of the user to another computer system.
[0211] Embodiments include a system. The system includes a mobile terminal according to one of the previously described embodiments of a mobile terminal and a personalization server. The personalization server is configured to perform a remote security inspection of the security infrastructure of the mobile terminal via the network, to receive the certificate request with the first public cryptographic key generated by the security element of the mobile terminal, to receive the second public cryptographic key generated by the security element of the mobile terminal, to create a certificate with the first public cryptographic key, to provide a root certificate of a root authority of a PKI, and to read attributes from an ID token via the mobile terminal and to personalize the ID application program of the mobile terminal.
[0212] According to embodiments, the system is configured to implement each of the above-described embodiments of the method for creating the cryptographically secured electronic identity of the user on the mobile terminal.
[0213] According to embodiments, the system further comprises the ID token in which the attributes to be read are stored.
[0214] According to embodiments, the system further comprises an ID provider server. The ID provider server is configured to generate a read request for reading one or more of the attributes of the electronic identity provided by the ID application program, to send the read request to the mobile terminal for authentication with the ID application program, to authenticate the ID application program, and to read the attributes to be read from the mobile terminal via the network.
[0215] Embodiments of the invention will be explained in more detail below with reference to the drawings. They show: Figure 1 is a schematic diagram of an exemplary mobile terminal, Figure 2 is a schematic diagram of an exemplary system, Figure 3 is a flowchart of an exemplary method for provisioning an ID application program on the mobile terminal, Figure 4 is a flowchart of an exemplary method for provisioning the ID application program on the mobile terminal, Figure 5 is a flowchart of an exemplary method for personalizing the ID application program on the mobile terminal, Figure 6 is a schematic diagram of exemplary encrypted channels, Figure 7 is a flowchart of an exemplary method for personalizing the ID application program on the mobile terminal, Figure 8 is a flowchart of an exemplary method for reading attributes from the mobile terminal, and Figure 9 is a flowchart of an exemplary method for reading attributes from the mobile terminal.
[0216] Elements of the following embodiments that correspond to one another are identified by the same reference numerals.
[0217] Figure 1shows an exemplary mobile terminal 100, for example a smartphone, which comprises a memory 104 with program instructions executed by a processor 102. The program instructions can, for example, comprise an operating system 106 installed on the mobile terminal 100 and an ID application program 108. The ID application program 108 is configured to manage attributes or identity attributes of a user in a personalized state. These attributes form an electronic identity of the user and are provided by the ID application program 108, for example, to prove the user's identity to another computer system, such as an ID provider server. Furthermore, the ID application program 108 comprises, for example, a control component that controls the creation of the electronic identity by the ID application program 108.In addition, the control component controls, for example, the use of the electronic identity, such as reading the attributes of the electronic identity by an ID provider server. Furthermore, the ID application program 108 comprises, for example, a provisioning component that controls provisioning of the ID application program 108 with cryptographic keys. Furthermore, the ID application program 108 comprises, for example, a personalization component that controls personalization of the ID application program 108, i.e., incorporating attributes into the mobile terminal 100. In particular, the personalization component controls, for example, the establishment of encrypted channels for communication during the course of a corresponding personalization. The corresponding attributes are part of or form an electronic identity of the user managed by the ID application program 108, which the user can use via the mobile terminal 100.Furthermore, the mobile terminal 100 comprises, for example, a security element 110, which is embedded, for example, as a hardware component in the mobile terminal 100. The security element 110 can be implemented, for example, as a cryptographically secured co-processor with a hardware-based key manager, which enables and provides an additional security layer through isolation from the main processor 102 of the mobile terminal. The security element 110 with the co-processor can be used to generate symmetric cryptographic keys and / or asymmetric cryptographic key pairs for the mobile terminal 100, in particular for the application program 108. The security element 110 provides, for example, identifiers with which the generated cryptographic keys can be identified.Using the identifiers, the security element 110 can be requested, for example by the ID application program 108, to perform cryptographic operations, such as encryption and / or decryption, on behalf of the ID application program 108 using the cryptographic keys generated for the ID application program 108. For example, the security element 110 can provide a TEE or Secure Enclave, which provides a secure or trustworthy runtime environment for applications. The security element 110 is, for example, assigned to the operating system 106 and provides cryptographic means for it, such as cryptographic keys, cryptographic functions and / or cryptographic protocols. For example, the security element 110 provides a key store orKey storage is provided for storing cryptographic keys, such as symmetric, public, and / or private cryptographic keys, and certificates, such as read certificates, public key certificates, and / or attribute certificates. The cryptographic means provided by the security element 110 enable the operating system 106, for example, to execute or participate in a challenge-response procedure. Furthermore, the security element 110 provides cryptographic means for the ID application program 108, such as cryptographic keys, cryptographic functions, and / or cryptographic protocols. The cryptographic means provided by the security element 110 enable the ID application program 108, for example, to execute or participate in a challenge-response procedure.
[0218] Furthermore, the mobile terminal 100 comprises a user interface 116, which, for example, comprises a display, in particular a touchscreen. Using the user interface 116, the user can interact with the mobile terminal 100. For example, the user can be prompted to provide authentication factors or authentication features. To capture authentication data of the user's authentication factors, the mobile terminal 100 comprises an authentication sensor 118, which can, for example, be integrated into the user interface 116 or implemented as a standalone component. Finally, the mobile terminal 100 comprises a communication interface or antenna 120, which is configured for wireless communication, for example, via a network.
[0219] Using the communication interface 120, the mobile terminal 100 can, for example, communicate with a personalization server for the purpose of provisioning the ID application program 108. Furthermore, the mobile terminal 100 can communicate with the personalization server using the communication interface 120, for example, for the purpose of personalizing the ID application program 108. Furthermore, the communication interface 120 is configured, for example, for wireless communication with an ID token that provides the user's attributes for the purpose of personalization. For different communication methods, the communication interface 120 comprises, for example, different communication components.
[0220] The mobile terminal 100 with the communication interface 120 can thus, as a transceiver, enable communication between the ID token and the personalization server for the personalization server to read the attributes from the ID token. The mobile terminal 100 establishes an encrypted communication channel to the personalization server via a network using the security element 110. The corresponding communication channel is encrypted, for example, using end-to-end encryption. Within the encrypted communication channel, a first encrypted subchannel is established between the ID token and the personalization server through the mediation of the mobile terminal 100 or a personalization component of the ID application program 108. The corresponding first subchannel is also encrypted, for example, using end-to-end encryption.This first encrypted subchannel is used, for example, for communication between the ID token and the personalization server, for example, for the personalization server to read the attributes provided by the ID token. Furthermore, within the encrypted communication channel, a second encrypted subchannel can be established between the ID application program 108 to be personalized and the personalization server. This establishment is again carried out, for example, via the mediation of the personalization component of the ID application program 108. The corresponding second subchannel is also encrypted, for example, using end-to-end encryption.This second encrypted subchannel is used, for example, for communication between the ID application program 108, such as the personalization component u of the ID application program 108 and the personalization server, for example for personalizing the ID application program 108 with the attributes read from the ID token by the personalization server.
[0221] Figure 2 shows an exemplary system 170 comprising a mobile terminal 100 connected to a personalization server 220 via a network 150, for example, the Internet. Furthermore, the mobile terminal 100 can communicate via the network 150, for example, with an ID provider server 240 and / or a service provider server 260. Furthermore, the mobile terminal 100 can be connected to an ID token 200, for example, via a wireless direct communication link 152. The mobile terminal 100 is configured, for example, as shown in Figure 1described and has the corresponding functionalities.
[0222] The personalization server 220 is configured, for example, to be used in the course of provisioning the mobile terminal 100 or the ID application program 108. The personalization server 220 comprises a processor 222, a memory 224, and a communication interface 230. Program instructions 228 are stored in the memory 224, the execution of which, for example, causes the processor 222 to cause the personalization server 220 to perform an external security inspection. A control component of the ID application program 108, for example, sends a security inspection request to the personalization server 220, for example, to perform an external security inspection or a remote security inspection. The security inspection request is initiated, for example, by a provisioning component of the ID application program 108.This security inspection request is sent, for example, via the control component to the personalization server 220. The control component records, for example, test parameters of the security infrastructure of the mobile terminal 100, which the personalization server 220 evaluates during the external security inspection. The personalization server 220 sends the result of the remote security inspection to the control component of the ID application program 108, which forwards it to the provisioning component of the ID application program 108. The security inspection includes, for example, checking the software and / or hardware of the mobile terminal 100. In this case, the mobile terminal 100 can be checked, for example, for manipulation, modifications, and / or security vulnerabilities.The integrity of the mobile device 100 can be validated to ensure that the mobile device 100 is not compromised and provides a secure environment for creating an electronic identity. In particular, it can be checked, for example, whether the security infrastructure, such as the security element 110 and the security functions implemented by it, such as encryption and / or access restrictions, of the mobile device 100 meets a predefined set of security requirements. Upon a positive result of the remote security inspection, the provisioning component begins the actual provisioning.
[0223] During provisioning, the security element 110 generates, for example, two asymmetric key pairs for the ID application program 108 upon request from the provisioning component of the ID application program 108 and provides the provisioning component with two public cryptographic keys of the two asymmetric key pairs for further use. The associated private cryptographic keys are not issued by the security element 110, for example, but are used by the security element on behalf of the ID application program 108 upon request from the ID application program 108. For example, successful user authentication of a registered user of the mobile terminal 100 by the security element 110 is a necessary prerequisite for generating one and / or both asymmetric key pairs of the ID application program 108.For example, a binding between the registered user and one and / or both asymmetric key pairs can be implemented in this way. For example, the security element 110 is configured such that the use of one and / or both private cryptographic keys of the two asymmetric key pairs of the mobile terminal requires successful user authentication of a registered user of the mobile terminal 100 by the security element 110.
[0224] The personalization server 220 also provides, for example, a certificate comprising a first public cryptographic key of a first asymmetric key pair of the two asymmetric key pairs generated during provisioning. For this purpose, the mobile terminal 100 or the ID application program 108 sends the first public cryptographic key to the personalization server 220. A prerequisite for issuing the certificate is, for example, a key attestation, which certifies that the first public cryptographic key was created in compliance with a predefined set of security requirements and / or that the security element 110 creating the first public cryptographic key meets the predefined set of security requirements.With a certificate request, the mobile terminal 100 sends, for example, attestation information relating to the first public cryptographic key to the personalization server 220 for verification. The attestation information verifies, for example, which security requirements were met by the security element 110 during the generation of the first asymmetric key pair. Furthermore, during the provisioning process, the second public cryptographic key is also sent from the mobile terminal 100 or the ID application program 108 to the personalization server 220. Furthermore, the mobile terminal 100 sends, for example, attestation information relating to the second public cryptographic key to the personalization server 220 for verification.The attestation information documents, for example, which security requirements were met by the security element 110 during the generation of the second asymmetric key pair. Upon successful key attestation by the personalization server 220, the two attested public cryptographic keys of the ID application program 108 are stored, for example, on the personalization server 220. For example, the first public cryptographic key is stored in the form of the certificate generated by the personalization server 220. The certificate is sent by the personalization server 220 in response to the certificate request via the network 150 to the mobile terminal 100 or the ID application program 108. For example, the personalization server 220 also sends one or more root signature verification keys, such as CVCA keys of a Country Verifying Certificate Authority, i.e.a national certificate authority for verification, to the mobile terminal 100 or the ID application program 108. These root signature verification keys are used to verify certificate signatures of one or more root authorities. Furthermore, the personalization server 220 sends, for example, the results of the key attestation to the mobile terminal 100 or the ID application program 108.
[0225] To personalize the ID application program 108, for example, attributes 206 provided by an ID token 200 are used. The ID token 200 comprises a processor 202 and a memory 204. The attributes 206, which are identity attributes of the owner of the ID token 200, are stored in a protected memory area 205 of the memory 204. Furthermore, program instructions 208 are stored in the memory 204, the execution of which by the processor 202 causes the processor to enable the reading of the attributes 206 by an authorized entity, such as the personalization server 220. For this purpose, the ID token 200, for example using its communication interface 210, establishes a wireless direct connection 152 with the mobile terminal 100, via which the personalization server 220 can read the attributes 206.
[0226] When executing the program instructions 228 stored in the memory 204 of the personalization server 220, the processor 222 controls the personalization server 220 to establish encrypted channels with the mobile terminal 100, the ID token 200 via the mobile terminal 100, and with the ID application program 108 of the mobile terminal 100. The personalization server 220 uses these channels to read attributes 206 from the ID token 200 and to insert the read attributes 206 into the mobile terminal 100 for use by the ID application program 108 during personalization. To verify read authorization for the attributes 206 from the ID token 200 and write authorization for writing the read attributes 206 to the mobile terminal 100, the personalization server 220 uses, for example, corresponding certificates 226.
[0227] The system further comprises, for example, a service provider server 260. The service provider server 260 comprises a processor 262, a memory 264, and a communication interface 270. Program instructions 268 are stored in the memory 264. When executed, the processor 262 controls the service provider server 260 to provide services that can be requested and / or used, for example, by the mobile terminal 100 via the network 150. Using services from the service provider server 260 requires, for example, the provision and / or verification of one or more identity attributes of the user. Upon a request for a service from the service provider server 260 by the mobile terminal 100, the service provider server 260 sends an identity attribute request for identity attributes of the user of the mobile terminal 100 to an ID provider server 240.The identity attribute request can be sent from the service provider server 260 to the ID provider server 240, for example, directly or via the mobile terminal 100.
[0228] The ID provider server 240 comprises a processor 242, a memory 244, and a communication interface 250. Memory 244 stores program instructions 248, which, when executed, cause the processor 242 to instruct the service provider server 240 to read the identity attributes specified in the identity attribute request from a memory of the mobile terminal 100. To this end, the ID provider server 240 establishes a cryptographically secured communication channel with the mobile terminal 100. The cryptographically secured communication channel can, for example, be an end-to-end encrypted communication channel. For example, this requires mutual authentication of the ID provider server 240 and the mobile terminal 100. For read access to the identity attributes, the ID provider server 240 uses an ID application program 108 on the mobile terminal 100, which manages the identity attributes.The ID provider server 240 verifies read authorization to read the identity attributes specified in the identity attribute request, for example, using the read certificate 248. Furthermore, read access by the ID provider server 240 to the identity attributes specified in the identity attribute request requires consent from the user of the mobile terminal 100. To do this, the user must successfully authenticate themselves to the ID application program 108. For example, a display device of the user interface 116 shows the user which identity attributes are to be sent to the ID provider server 240, and the user can edit this selection. For example, the user can select which of the requested identity attributes are actually sent.Upon successful verification of read authorization and successful user authentication, the released identity attributes are sent to the ID provider server 240. The ID provider server 240 signs the received identity attributes, for example, and sends them to the service provider server 260.
[0229] Figure 3shows an exemplary method for provisioning an ID application program installed on a mobile device. The ID application program comprises, for example, a provisioning component that controls the provisioning on the mobile device side, as well as a control component that is configured to control the creation and / or use of the electronic identity managed by the ID application program. The mobile device comprises a security element that provides cryptographic functions and / or cryptographic keys. In block 300, in response to a security inspection request from the provisioning component, a remote security inspection of the security infrastructure of the mobile device is carried out by a personalization server via a network. For this purpose, the control component of the ID application program is used, for example.For example, the control component captures test parameters from the mobile device's security infrastructure and sends them to the personalization server. The personalization server evaluates the received test parameters during the external security inspection and sends the results of the remote security inspection to the control component of the ID application program, which forwards them to the provisioning component. The security inspection includes, for example, checking the software and / or hardware of the mobile device. This can include checking the mobile device for tampering, modifications, and / or security vulnerabilities. The integrity of the mobile device can be validated to ensure that the mobile device is not compromised and provides a secure environment for creating an electronic identity.In particular, it can be checked, for example, whether the security infrastructure of the mobile device, such as the security element and the security functions implemented by it, such as encryption and / or access restrictions, meet a predefined set of security requirements. Upon a positive result of the remote security inspection, the provisioning component begins the actual provisioning. In block 302, the provisioning component sends a key generation request to the control component. The control component then requests that the security element generate a first asymmetric key pair for the ID application program. Furthermore, the control component requests that the security element generate a second asymmetric key pair for the ID application program.In response to the key generation requests, the security element generates two asymmetric key pairs for the ID application program. The security element generates a first asymmetric key pair associated with the ID application program and a second asymmetric key pair associated with the ID application program. The first asymmetric key pair comprises a first private cryptographic key and a first public cryptographic key. Likewise, the second asymmetric key pair comprises a second private cryptographic key and a second public cryptographic key. The mobile terminal further comprises one or more authentication sensors for detecting one or more authentication factors of a user of the mobile terminal.A prerequisite for generating the first asymmetric key pair in block 302 is, for example, successful authentication of the user to the security element. By authenticating, the user consents to the generation of the first asymmetric key pair. At the same time, the use of a first private cryptographic key of the first asymmetric key pair is tied, for example, to successful authentication of the user and thus the user of the mobile device. In block 304, the control component receives the public cryptographic keys of the requested key pairs from the security element. These public cryptographic keys are forwarded by the control component to the provisioning component.
[0230] In block 306, the provisioning component receives a certificate of the ID application program issued by the personalization server in response to a certificate issuance request sent over a network to a personalization server. This certificate includes the first public cryptographic key. This can be, for example, an X.509 certificate. For example, a prerequisite for generation is successful key attestation. For example, with the certificate issuance request, the provisioning component sends the two public cryptographic keys of the ID application program as well as attestation information about the two public cryptographic keys to the personalization server for verification. The attestation information documents, for example, which security requirements were met by the security element during the generation of the two asymmetric key pairs.Following successful key attestation by the personalization server, the two attested public cryptographic keys of the ID application program are stored, for example, on the personalization server. For example, the first public cryptographic key is stored in the form of the certificate generated by the personalization server. Along with the ID application program's certificate, the personalization server also sends one or more root signature verification keys, such as CVCA keys from a Country Verifying Certificate Authority, i.e., a national certificate authority for verification, to the provisioning component. These root signature verification keys are used to verify certificate signatures from one or more root authorities.Furthermore, the personalization server sends, for example, the results of the key attestation to the provisioning component of the ID application program.
[0231] Figure 4shows an exemplary method for provisioning an ID application program 108 installed on a mobile terminal 100 with cryptographic keys. The ID application program 108 comprises, for example, a provisioning component 107 for controlling the provisioning on the mobile terminal side and a control component 109 for controlling the creation and / or use of the electronic identities managed by the ID application program 108. For example, the provisioning component 107 is configured to perform an initial compatibility check, in which it is verified whether the mobile terminal 100 comprises the system components necessary for carrying out the provisioning and / or the further method. The necessary system components include, for example, security element 110 and communication interfaces, for example for communication with the external personalization server 220.In step 400, a request for a security inspection of the security infrastructure of the mobile terminal 100 is sent from the provisioning component 107 to the control component 109. In step 402, the control component 109 sends a security inspection request to the personalization server 220 to perform a remote security inspection. In step 404, the personalization server 220 performs a remote security inspection. The security inspection includes, for example, checking the software and / or hardware of the mobile terminal 100. The mobile terminal 100 can be checked for tampering, modifications, and / or security vulnerabilities, for example. The integrity of the mobile terminal 100 can be validated to ensure that the mobile terminal 100 is not compromised and provides a secure environment for creating an electronic identity.In particular, it can be checked, for example, whether the security infrastructure, such as the security element and the security functions implemented by it, such as encryption and / or access restrictions, of the mobile terminal 100 meets a predefined set of security requirements. The control component 109, for example, captures test parameters of the security infrastructure of the mobile terminal 100 and sends them to the personalization server 220. The personalization server 220 evaluates the received test parameters during the remote security inspection and, in step 406, sends a result of the remote security inspection to the control component 109 of the ID application program 108, which forwards the result to the provisioning component 107 in step 408.
[0232] Upon a positive result of the remote security inspection, the provisioning component 107 sends a key generation request to the control component 109 in step 410 to generate two asymmetric key pairs for the ID application program 108. In step 412, the control component 109 requests, for example, a first asymmetric key pair for the ID application program 108 from the security element 110. In step 414, the security element 110 generates a first asymmetric key pair associated with the ID application program 108, comprising a first public cryptographic key PuK App and a first private cryptographic key PrK App . The mobile terminal 100 further comprises, for example, one or more authentication sensors for detecting one or more authentication factors of a user of the mobile terminal 100.A prerequisite for generating the first asymmetric key pair PuK App , PrK App in step 414 is, for example, successful authentication of the user to the security element 110. With the authentication, the user consents to the generation of the first asymmetric key pair. At the same time, use of a first private cryptographic key PrK App of the first asymmetric key pair is tied, for example, to successful authentication of the user and thus the user of the mobile terminal 100. The first asymmetric key pair thus serves, for example, to confirm user authentication of a user of the mobile terminal 100 by the security element 110 or consent of the user of the mobile terminal 100 in the course of using the ID application program 108.In step 416, the security element 110 sends the first public cryptographic key PuK app of the first asymmetric key pair to the control component 109.
[0233] In step 418, the control component 109 requests, for example, a second asymmetric key pair for the ID application program 108 from the security element 110. In step 420, the security element 110 generates a second asymmetric key pair assigned to the ID application program 108, comprising a second public cryptographic key PuK CA and a first private cryptographic key PrK CA . The second asymmetric key pair serves, for example, as the asymmetric key pair of the ID application program 108 for authenticating the ID application program 108 to other computer systems, such as the personalization server 220. In step 422, the security element 110 sends the second public cryptographic key PuK CA of the second asymmetric key pair to the control component 109.In step 424, the control component forwarded the two public cryptographic keys PuK App , PuK CA received from the security element 110 to the provisioning component 107.
[0234] In step 426, the provisioning component 107 of the ID application program 108 sends a certificate issuance request to the personalization server 220 via a network to issue a certificate with the first public cryptographic key PuK App . Communication with the personalization server 220 takes place, for example, via an encrypted communication connection, for example an HTTPS connection. The certificate issuance request includes, for example, the first public cryptographic key PuK App and attestation information relating to the first public cryptographic key PuK App .The attestation information certifies that the first public cryptographic key PuK App was created in compliance with a predefined set of security requirements and / or that the security element 110 creating the first public cryptographic key PuK App meets the predefined set of security requirements. In addition, the provisioning component 107 sends, for example, the second public cryptographic key PuK CA as well as attestation information about the second public cryptographic key PuK CA to the personalization server 220.The attestation information relating to the second public cryptographic key PuK CA certifies that the second public cryptographic key PuK CA was created in compliance with a predefined set of security requirements and / or that the security element 110 creating the second public cryptographic key PuK CA meets the predefined set of security requirements. In step 428, the personalization server 220 checks the attestation information relating to the first public cryptographic key PuK App and, upon a successful check, generates a certificate Cert App for the ID application program 108 with the first public cryptographic key PuK App . The certificate Cert App is, for example, an X.509 certificate. The certificate Cert App is stored by the personalization server 220.Furthermore, the personalization server 220 checks the attestation information for the second public cryptographic key PuK CA and, upon successful verification, stores the second public cryptographic key PuK CA together with the certificate Cert App . In step 430, the personalization server 220 sends the certificate Cert App to the provisioning component 107. Furthermore, the personalization server 220 sends, for example, the results of the verification of the attestation information for the two public cryptographic keys PuK App and PuK CA to the provisioning component 107. In addition, the personalization server 220 sends, for example, a root signature verification key, such as a CVCA key of a Country Verifying Certificate Authority, i.e., a national certificate authority for verification, as part of a root certificate Cert Root to the provisioning component 107.The root signature verification key of the root certificate Cert Root can be used, for example, to verify signatures, in particular certificate signatures, of a root instance to which the root certificate Cert Root is assigned. Finally, in step 432, the root certificate Cert Root is forwarded from the provisioning component 107 to the control component 109 for storage. Furthermore, the method can include validating the received certificate Cert App, wherein the ID application program 108 or the provisioning component 107 of the ID application program 108 authenticates itself to the personalization server 220 using the certificate Cert App or the first public cryptographic key PuK App included in the certificate Cert App.During this authentication, the provisioning component 107 sends, for example, a signature created using the first private cryptographic key PrK App, such as a response to a challenge from the personalization server 220, to the personalization server 220. A signature with the first private cryptographic key PrK App is created, for example, by the security element 110 for the provisioning component 107, possibly with the mediation of the control component 109.
[0235] Figure 5shows an exemplary method for personalizing an ID application program. The ID application program to be personalized is installed on a mobile device with a security element. Personalization is performed using an ID token on which a user's attributes are stored, and a personalization server that has authorization to read the attributes from the ID token and imports the read attributes into the mobile device for the purpose of personalizing the ID application program or creating an electronic identity managed by the ID application program. The personalization server verifies the corresponding authorizations using a certificate and / or the possession and use of certain cryptographic keys.
[0236] In block 500, personalization comprises establishing an encrypted communication channel between the mobile device and the personalization server via a network. For example, the ID application program or a personalization component of the ID application program is used to control the establishment. During the establishment, mutual authentication of the mobile device and the personalization server takes place, for example, using challenge-response methods. Furthermore, a first channel-specific ephemeral symmetric cryptographic session key is negotiated for encrypting the communication channel between the mobile device and the personalization server.
[0237] In block 502, a first encrypted subchannel is established between the ID token and the personalization server within the encrypted communication channel via the mobile device. For example, the ID application program or a personalization component of the ID application program is used to control the establishment. During the establishment, mutual authentication of the ID token and the personalization server takes place, for example, using challenge-response methods. Furthermore, a second channel-specific ephemeral symmetric cryptographic session key for encrypting the first subchannel is negotiated between the ID token and the personalization server. In block 504, one or more of the attributes from the ID token are read by the personalization server via the first encrypted subchannel within the encrypted communication channel.
[0238] Furthermore, in block 506, a second encrypted subchannel is established between the control component of the ID application program and the personalization server within the encrypted communication channel. For example, the personalization component of the ID application program is used to control the establishment. During the establishment, mutual authentication of the ID application program or the control component of the ID application program and the personalization server takes place, for example, using challenge-response methods. Furthermore, a third channel-specific ephemeral symmetric cryptographic session key for encrypting the second subchannel is negotiated between the control component and the personalization server.
[0239] In block 508, the control component receives the read attributes from the personalization server via the second encrypted subchannel within the encrypted communication channel. The attributes are introduced into the mobile device, for example, as a CBOR structure. Furthermore, additional cryptographic elements, such as root signature verification keys, can also be transmitted via the second encrypted subchannel. The root signature verification keys are, for example, CVCA keys. These additional cryptographic elements can, for example, also be part of the CBOR structure with the attributes.Furthermore, the second encrypted subchannel can be used to initiate the generation of attribute-specific and thus identity-specific cryptographic keys on the security element, which are assigned to the derived electronic identity of the user of the mobile device stored on the mobile device during personalization. For example, a third asymmetric cryptographic key pair is generated by the security element, which is assigned to the introduced attributes or the created identity. For example, the third public cryptographic key is stored together with attributes or with the electronic identity. This public cryptographic key can be used, for example, to verify attribute-specific or identity-specific signatures created with the third public cryptographic key as a signature key.
[0240] In block 510, the control component stores the received attributes, with which the ID application program is assigned or personalized to the corresponding user. For example, the attributes are stored in encrypted form on the mobile device for use by the ID application program, possibly using the security element. The ID application program is configured to use the stored attributes to prove the electronic identity of the corresponding user to another computer system, such as an ID provider server.
[0241] Figure 6shows exemplary encrypted channels 160, 162, 164, which are established during the personalization of the ID application program 108 on the mobile terminal 100. An encrypted communication channel 160 is established between the mobile terminal 100 and the personalization server 220. This serves to secure the communication between the mobile terminal 100 and the personalization server 220. At the same time, this channel links the mobile terminal 100 to the personalization server 220 during the communication. The personalization server 220 can thus ensure that all communication via the encrypted communication channel 160 takes place via the same mobile terminal 100. For example, the same mobile terminal 100 is used to read attributes from the ID token, which is subsequently personalized with the read attributes.
[0242] During further personalization, communication between the mobile terminal 100 and the personalization server 220 takes place via an encrypted communication channel 160. This also includes communication between the personalization server 220 and the ID token 200, which takes place via the mobile terminal 100. The encrypted communication channel 160 is encrypted, for example, using end-to-end encryption. The encryption and decryption of the communication takes place on the side of the mobile terminal 100, for example, using the security element of the operating system of the mobile terminal 100. Within the encrypted communication channel 160, a first encrypted subchannel 162 is also established between the ID token 200 and the personalization server 220, mediated by the mobile terminal 100 or a personalization component of the ID application program.This first encrypted subchannel 162 is used, for example, for communication between the ID token 200 and the personalization server 220, for example, for the personalization server 220 to read the attributes provided by the ID token 200. The corresponding first subchannel 162 is also encrypted, for example, using end-to-end encryption. The data transmission between the mobile device 100 and the personalization server 220 takes place, for example, via a network, while the data transmission between the mobile device 100 and the ID token 200 takes place, for example, via a direct radio connection.
[0243] In this context, subchannel means that data to be transmitted via the corresponding subchannel is first encrypted using a cryptographic session key of the corresponding subchannel. For example, an additional MAC of the data is generated using a cryptographic authentication key of the corresponding subchannel and transmitted together with the encrypted data. In addition, the data to be transmitted is encrypted using another cryptographic session key of the communication channel that is higher than the subchannel. For example, an additional MAC of the data is generated using another cryptographic authentication key of the corresponding communication channel and transmitted together with the encrypted data. When the transmitted data reaches the end of the communication channel, the encryption of the communication channel is first decrypted.When the transmitted data reaches the end of the subchannel, the subchannel's encryption is also decrypted. Transmission over an encrypted subchannel within an encrypted communication channel therefore involves double encryption with two independent session keys. The session keys are independent in the sense that access to one of the two session keys does not automatically result in access to the other session key.
[0244] Within the encrypted communication channel 160, a second encrypted subchannel 164 is also established between the ID application program 108 of the mobile terminal 100 and the personalization server 220, mediated by the personalization component of the ID application program. The corresponding second subchannel 164 is also encrypted, for example, using end-to-end encryption. This second encrypted subchannel 164 serves, for example, for communication between the ID application program 108, for example a control component of the ID application program 108, and the personalization server 220, for example for personalizing the ID application program 108 with the attributes read from the ID token 200 by the personalization server 220.
[0245] Figure 7shows an exemplary method for personalizing an ID application program 108 on a mobile device. First, in step 600, a user of the mobile device authenticates themselves against a security element 110 of the mobile device 100 configured for this purpose. For example, reference values for one or more authentication factors, such as biometric features or a PIN, of a user registered on the mobile device are stored in the security element 110. During user authentication, one or more authentication factors of the user are recorded and compared with the reference values. If there is a match, the user is considered to have been successfully authenticated. In step 602, an encrypted communication channel is established between the mobile device, for example, the security element 110, and the personalization server 220.This includes, for example, mutual authentication of mobile devices and
[0246] Security element 110 and personalization server 220, for example by means of a challenge-response method, and negotiating a cryptographic key, for example a channel-specific ephemeral symmetric cryptographic session key, for encrypting the communication channel.
[0247] For example, a first initial random value is first generated by the mobile terminal or the security element 110 and sent to the personalization server 220. After receiving the corresponding first initial random value, the personalization server 220 generates a second initial random value, which it sends to the mobile terminal. Thus, both participants, the mobile terminal and the personalization server 220, have both initial random values. Furthermore, the personalization server 220 sends, for example, its certificate to the mobile terminal and, after successfully verifying the corresponding certificate, receives a certificate of the mobile terminal from the mobile terminal. The certificate of the mobile terminal can, for example, be a certificate assigned to the ID application program, such as a certificate created by the personalization server 220 for the ID application program during provisioning.The certificate of the mobile terminal received by the personalization server 220 is also verified. Both certificates each comprise a public cryptographic key, i.e., the certificate of the personalization server 220 comprises a public cryptographic key of an asymmetric key pair of the personalization server 220, and the certificate of the mobile terminal comprises a public cryptographic key of an asymmetric key pair of the mobile terminal. Thus, both participants now each have public cryptographic keys of the other party, the authenticity of which is verified by a certificate. The mobile terminal then generates, for example, the first random value, which it sends to the personalization server 220.Thus, both participants in the communication now each have three random values, from which, for example, the channel-specific ephemeral symmetric cryptographic session key can be calculated. Furthermore, the mobile device sends, for example, a signature of one, several, or all previous messages exchanged during channel establishment to the personalization server 220. By verifying the corresponding signature using the public cryptographic key provided by the mobile device's certificate as the signature verification key, the personalization server 220 can authenticate the mobile device and / or the ID application program.If the personalization server 220 subsequently sends a message encrypted with the first channel-specific ephemeral symmetric cryptographic session key to the mobile terminal, this also authenticates the personalization server 220 to the mobile terminal. The personalization server 220 can only calculate the first channel-specific ephemeral symmetric cryptographic session key if it has a private cryptographic key with which it can decrypt the first random value received from the mobile terminal. Thus, only the personalization server 220 in possession of the corresponding private cryptographic key, to which the certificate of the personalization server 220 is assigned, is capable of encrypted communication over the encrypted communication channel.
[0248] To enable establishment of a first encrypted subchannel, in step 604, the user of the mobile terminal is authenticated by the ID token 200 using the mobile terminal or the security element 110. For example, the user is authenticated to the ID token 200 using the mobile terminal. For example, an ephemeral symmetric cryptographic key is derived using the user's detected authentication factor. The mobile terminal receives a random value from the ID token 200, which is encrypted with the same ephemeral symmetric cryptographic key. The ID token 200 derives the corresponding ephemeral symmetric cryptographic key, for example, from a reference value for the authentication factor, or the correspondingly derived ephemeral symmetric cryptographic key is stored on the ID token 200.If the mobile device is able to correctly decrypt the received encrypted random value, this constitutes proof that the mobile device has the correct authentication factor. The mobile device generates an ephemeral asymmetric key pair, the public cryptographic key of which the mobile device sends to the ID token 200. In return, the mobile device receives the public cryptographic key of the ID token 200. At this point in the method, therefore, no static cryptographic keys are necessary; instead, only randomly generated ephemeral asymmetric key pairs can be used. Using the decrypted random value, the ephemeral private cryptographic key of the ID application program, and the ephemeral public cryptographic key of the ID token 200, the mobile device generates a secret shared with the ID token 200.The ID token 200 is also capable of calculating the corresponding secret using the random value generated by it, the ephemeral private cryptographic key of the ID token 200, and the ephemeral public cryptographic key of the mobile terminal received from the mobile terminal.
[0249] The mobile terminal can now use the shared secret thus generated to calculate a common authentication key for mutually authenticating the ID application program and the ID token 200. For example, the mobile terminal can generate a first authentication token using the corresponding authentication key and the ephemeral public cryptographic key of the ID token 200. The corresponding authentication token can be sent from the mobile terminal to the ID token 200, which can verify the received authentication token using the shared authentication key and the ephemeral private cryptographic key of the ID token 200. Thus, the mobile terminal can authenticate itself to the ID token 200. Likewise, the ID token 200 can send an authentication token to the mobile terminal.The mobile device receives the authentication token, which is generated, for example, using the shared secret and the mobile device's ephemeral public cryptographic key. The authentication token can be verified using the authentication key and the public cryptographic key of the ID application program.
[0250] In step 606, a first encrypted subchannel is established following successful user authentication in step 604. Establishing the first encrypted subchannel includes, for example, mutual authentication of ID token 200 and personalization server 220, as well as negotiating a cryptographic key for encrypting the corresponding subchannel.
[0251] For example, the personalization server 220 is first authenticated by the ID token 200 in a cryptographically secure manner. For this purpose, the ID token 200 receives, for example, a certificate from the personalization server 220, which provides a public cryptographic key of the personalization server 220 for authentication. The ID token 200 verifies the signature of the received certificate. For example, the corresponding certificate is received as part of a certificate chain, for the verification of which corresponding signature verification keys, in particular root signature verification keys, are stored on the ID token 200. Thus, the ID token 200 can verify the authenticity of the provided certificate based on the certificate chain, for example, a PKI. Furthermore, the ID token 200 receives, for example, an ephemeral public cryptographic key from the personalization server 220.For example, the ID token 200 receives the ephemeral public cryptographic key of the personalization server 220 in compressed form. In return for receiving the certificate from the personalization server 220, the ID token 200 generates a random value, which it sends to the personalization server 220 as a challenge via the encrypted communication channel. The personalization server 220 creates a signature of the challenge as a response to the challenge using a private cryptographic key, which forms an asymmetric key pair with the public cryptographic key of the previously provided certificate. For example, to generate the response, a data combination is signed that includes the random value as a challenge and the ephemeral public cryptographic key of the personalization server 220, for example in compressed form.The ID token 200 receives the corresponding signature via the encrypted communication channel and verifies it using the previously received public cryptographic key of the personalization server 220 as the signature verification key. For this purpose, the ID token 200 further uses, for example, the previously sent random value as well as the ephemeral public cryptographic key of the personalization server 220 previously received as a challenge.
[0252] The ID token 200 then authenticates itself to the personalization server 220 in a cryptographically secure manner. To do so, the ID token 200 sends a public cryptographic key to the personalization server 220. This occurs via the encrypted communication channel. In return, the ID token 200 receives an ephemeral public cryptographic key from the personalization server 220 via the encrypted communication channel. The ID token 200 calculates a secret shared with the personalization server 220 using the private cryptographic key of the ID token 200 and the received ephemeral public cryptographic key of the personalization server 220. The personalization server 220 may calculate the same shared secret using the public cryptographic key of the ID token 200 and the ephemeral private cryptographic key of the personalization server 220.The ID token 200 generates a random value, which it uses to calculate a shared authentication key. The authentication key is used to authenticate data sent over the encrypted subchannel. The ID token 200 generates the corresponding shared authentication key using the random value and the shared secret. Furthermore, the ID token 200 generates an authentication token using the corresponding authentication key and the ephemeral key of the personalization server 220. The ID token 200 sends the authentication token thus generated, along with the random value, to the personalization server 220 in the communication channel. Upon receipt of the random value, the personalization server 220 is enabled to also calculate the authentication key using the shared secret.Using this shared authentication key and the ephemeral public cryptographic key of the personalization server 220, the personalization server 220 can verify the received authentication token. If the verification is successful, the ID token 200 is also successfully authenticated to the personalization server 220, and successful mutual authentication of the ID token 200 and the personalization server 220 is achieved. Furthermore, the shared authentication key calculated in this way can be used to authenticate data exchanged between the ID token 200 and the personalization server 220 via the encrypted subchannel.
[0253] Furthermore, the ID token 200 and the personalization server 220 can each generate, for themselves, the channel-specific ephemeral symmetric cryptographic session key for encrypting the first sub-channel using the shared secret and the random value.
[0254] The personalization server 220 uses the thus established first encrypted sub-channel between the personalization server 220 and the ID token 200 within the encrypted communication channel between the personalization server 220 and the mobile end device or the security element 110 in step 608 to read out the attributes from the ID token 200 via the mobile end device.
[0255] To incorporate the read attributes, a second encrypted subchannel is established between the ID application program 108 and the personalization server 220. In step 610, for example, the user is authenticated by the security element 110. This authentication of the user by the security element 110 is, for example, a prerequisite for using the first public cryptographic key of the ID application program 108 in the course of authenticating the ID application program 108 to the personalization server 220, for example, in the course of a challenge-response procedure.
[0256] In step 612, following successful user authentication in step 610, a second encrypted subchannel is established. For example, the user authentication according to step 608 can be part of the channel establishment according to step 610. The establishment of the second encrypted subchannel includes, for example, mutual authentication of ID application program 108 and personalization server 220, as well as negotiation of a cryptographic key for encrypting the corresponding subchannel. In the course of authenticating ID application program 108, for example, user authentication by security element 110 is necessary.
[0257] First, for example, the personalization server 220 is authenticated in a cryptographically secure manner by a control component of the ID application program 108. To this end, the control component of the ID application program 108 to be personalized first receives a certificate from the personalization server 220 via the encrypted communication channel. The corresponding certificate can be verified by the control component. For example, the corresponding certificate is provided as part of a certificate chain, which the control component can verify using stored root signature verification keys. Thus, the control component can verify the authenticity of the provided certificate based on the certificate chain, for example, a PKI.In return for receiving the certificate from the personalization server, the security element 112 generates a random value and sends the corresponding random value as a challenge to the personalization server 220. In response to sending the random value as a challenge, the security element 112 receives a signature of the challenge as a response from the personalization server 220 via the encrypted communication channel. To create the signature, the private cryptographic key of the personalization server 220 is used, which forms an asymmetric key pair with the public cryptographic key of the previously provided certificate. For example, a data combination is signed to generate the response. The corresponding data combination includes, for example, the random value previously sent as a challenge and the ephemeral public cryptographic key of the personalization server 220, for example in compressed form.The security element 112 can verify the corresponding signature using the previously received public cryptographic key of the personalization server 220 as the signature verification key. For this purpose, the security element 112 further uses, for example, the ephemeral public cryptographic key of the personalization server 220 and the random value previously sent as a challenge. If the signature verification is successful, the personalization server 220 is considered successfully authenticated.
[0258] Furthermore, the control component receives and stores an ephemeral public cryptographic key from the personalization server 220. For example, the security element 112 receives the ephemeral public cryptographic key from the personalization server 220 in compressed form. For example, the security element 112 receives the ephemeral public cryptographic key from the personalization server 220 in uncompressed form.
[0259] The ID application program 108 then authenticates itself to the personalization server 220 in a cryptographically secure manner. To do so, the corresponding ID application program 108 to be personalized first uses the second private cryptographic key of the second asymmetric key pair of the ID application program 108 stored in the security element. The corresponding second private cryptographic key is generated and stored by the security element 110, for example, during the provisioning of the ID application program 108. To authenticate the ID application program 108, the latter uses, for example, the ephemeral public cryptographic key generated by the personalization server 220 for the purpose of authentication.The ID application program 108 sends the previously received ephemeral public cryptographic key of the personalization server 220, stored by the control component, to the security element 110. The security element 110 calculates a shared secret using the second private cryptographic key of the ID application program 108 and the received ephemeral public cryptographic key of the personalization server 220. The security element 110 outputs the shared secret to the control component of the ID application program 108. The control component uses a random value to generate a shared authentication key. The shared secret is further used to generate the corresponding shared authentication key. Furthermore, the control component of the ID application program 108 generates an authentication token.The control component generates the corresponding authentication token using the previously received ephemeral public cryptographic key of the personalization server 220 and the previously generated shared authentication key. The control component of the ID application program 108 to be personalized sends this authentication token, along with the random value, to the personalization server 220 via the encrypted communication channel. The personalization server 220 can also initially calculate the shared secret. To do this, the personalization server 220 uses the second public cryptographic key of the ID application program 108, which is known to the personalization server 220. This key was stored on the personalization server 220, for example, during the provisioning of the ID application program 108.Furthermore, the personalization server 220 uses the ephemeral private cryptographic key of the personalization server 220 to calculate the shared secret. With the corresponding shared secret, the personalization server 220 is able to calculate the shared authentication key. To do so, the personalization server 220 uses the received random value and the previously calculated shared secret. Thus, the personalization server 220 can verify the received authentication token using the shared authentication key and the ephemeral public cryptographic key of the personalization server 220.
[0260] Furthermore, the control component of the ID application program 108 and the personalization server 220 can each independently generate the channel-specific ephemeral symmetric cryptographic session key for encrypting the second subchannel using the shared secret and the random value. The personalization server 220 uses the second encrypted subchannel thus established between the personalization server 220 and the ID application program 108 within the encrypted communication channel in step 614 to incorporate the attributes from the ID token 200 into the mobile terminal for use by the ID application program 108.
[0261] Figure 8shows an exemplary method for reading attributes of a user's electronic identity, managed by an ID application program on a mobile device, by an ID provider server. In the course of using the electronic identity, an encrypted communication channel is first established, for example, between the mobile device and the ID provider server. In block 700, the mobile device or the ID application program receives a read request from the ID provider to read one or more attributes of the electronic identity. For example, the read request identifies the attributes to be read out. Furthermore, the read request specifies, for example, who is requesting the corresponding attributes, i.e., to whom the ID provider server will forward the corresponding attributes, as well as their intended use.The information provided by the read request is displayed, for example, on a display device of the mobile device for the user to review. Furthermore, the user of the mobile device can be offered the option of selecting which of the requested attributes should actually be made available to the ID provider server and / or selecting additional attributes that should also be made available to the ID provider server.
[0262] To cryptographically secure the reading of the attributes, the ID provider server is authenticated by the ID application program in block 702. The ID provider server is authenticated, for example, using a challenge-response method. To do this, the control component sends a challenge, such as a nonce or a random value, to the ID provider server via the encrypted communication channel. The ID provider server creates a response to the challenge. The response is a signature of the challenge created using a private cryptographic key from an asymmetric key pair of the ID provider server. The ID provider server sends the corresponding response to the mobile device, which receives the response.The control component of the ID application program verifies the received response using a public cryptographic key from the asymmetric key pair of the ID provider server and the sent challenge. During the verification process, it is checked whether the response is actually a signature of the sent challenge using the private cryptographic key of the ID provider server. Furthermore, the mobile device receives, for example, an ephemeral public cryptographic key from an ephemeral cryptographic key pair of the ID provider server. If the verification is successful, i.e., the ID provider server is successfully authenticated by the ID application program, the mobile device saves the received ephemeral public cryptographic key of the ID provider server.
[0263] In block 704, the ID application program is authenticated to the ID provider server. To authenticate the ID application program to the ID provider server, a control component of the ID application program uses the security element of the mobile terminal, which manages the private cryptographic keys of the ID application program. The control component sends, for example, a request to the security element to generate a secret shared with the ID provider server using the second private cryptographic key of the ID application program. With the request, the control component provides the security element, for example, with the ephemeral public cryptographic key of the ID provider server. The control component previously received this ephemeral public cryptographic key of the ID provider server, for example, during the authentication of the ID provider server.A prerequisite for using the ID application program's second private cryptographic key and thus authenticating the mobile device's ID application program with the ID provider server via the security element is, for example, successful user authentication with the security element. By authenticating, the user consents to the ID provider server reading the attributes to be read.
[0264] The security element generates the requested secret using the second private cryptographic key of the ID application program and the ephemeral public cryptographic key of the ID provider server and makes it available to the control component. The control component uses the shared secret to generate a common authentication key for authenticating data exchanged with the ID provider server. The corresponding authentication key is, for example, a symmetric cryptographic key. The control component also uses a random value to generate the authentication key. This random value is generated on the mobile device, for example, by the control component.Using the authentication key and the ephemeral public cryptographic key of the ID provider server, the control component generates an authentication token. The authentication key is, for example, a cryptographic key for generating a message authentication code, while the authentication token is a MAC of the ephemeral public cryptographic key of the ID provider server generated using the authentication key.
[0265] Furthermore, the control component generates an ephemeral symmetric cryptographic session key using the shared secret and the random value to encrypt the attributes to be read.
[0266] The control component sends the authentication token thus generated, along with the random value, to the ID provider server to authenticate the ID application program to the ID provider server. Using the random value received from the ID application program or the control component, the ID provider server can also generate the authentication key. The ID provider server calculates the required shared secret, for example, using an ephemeral private cryptographic key from the ephemeral asymmetric key pair of the ID provider server and the public cryptographic key of the ID application program. Using the authentication key and its ephemeral public cryptographic key, the ID provider server can check the validity of the received authentication token.
[0267] Following successful mutual authentication, the ID provider server reads the attributes to be read from the mobile device via the network in block 706. The read request and / or the attributes to be read are encrypted with the generated ephemeral symmetric cryptographic session key. Authentication tokens are generated using the authentication key, which prove the authenticity of the read request and / or the attributes to be read. The ID provider server can then, for example, sign the read attributes and make them available to a requesting service provider. The corresponding service provider can verify the authenticity of the attributes provided to it using the signature of the ID provider server.
[0268] Figure 9shows an exemplary method for reading attributes of a user's electronic identity managed by an ID application program 108 on a mobile terminal 100 by an ID provider server 240. In step 800, ID provider server 240 sends a read request to read one or more attributes of the electronic identity to an identification component 111 of ID application program 108. The read request is sent, for example, via a previously established encrypted communication channel between mobile terminal 100 and ID provider server 240. Furthermore, the read request specifies, for example, who is requesting the corresponding attributes, i.e., to whom ID provider server 240 will forward the corresponding attributes, as well as their intended use.This information, which the read request provides, is displayed, for example, on a display device of the mobile terminal 100 for the user so that the user can check the corresponding information.
[0269] Furthermore, the user of the mobile terminal can be offered the possibility to select which of the requested attributes should actually be made available to the ID provider server 240 and / or to select further attributes which should additionally be made available to the ID provider server.
[0270] In step 802, the identification component 111 sends a request to a control component 109 of the ID application program 108 to initiate authentication of the ID provider server 240. In step 804, the ID provider server 240 is authenticated by the control component 109 of the ID application program 108. The ID provider server 240 is authenticated, for example, using a challenge-response method. For this purpose, the control component 109 sends a challenge, such as a nonce or a random value, to the ID provider server 240 via the encrypted communication channel. The ID provider server 240 creates a response to the challenge. The response is a signature of the challenge created using a private cryptographic key of an asymmetric key pair of the ID provider server 240.The ID provider server 240 sends the corresponding response to the mobile terminal 100, which receives the response. The control component 109 of the ID application program 108 verifies the received response using a public cryptographic key of the asymmetric key pair of the ID provider server 240 and the sent challenge. During the verification process, it is checked whether the response is actually a signature of the sent challenge using the private cryptographic key of the ID provider server 240. Furthermore, the mobile terminal 100 receives, for example, an ephemeral public cryptographic key of an ephemeral cryptographic key pair of the ID provider server 240. If the verification is successful, i.e.the ID provider server 240 is successfully authenticated by the ID application program 108, the mobile terminal 100 stores the received ephemeral public cryptographic key of the ID provider server 240.
[0271] In step 806, the control component 109 sends the result of the authentication of the ID provider server 240 to the identification component 111 of the ID application program 108. If the authentication of the ID provider server 240 was successful, the identification component 111 sends an authentication request to authenticate the application program 108 to the control component 109 in step 808. To authenticate the ID application program 108 to the ID provider server 240, the control component 111 uses the security element 110 of the mobile terminal 100, which manages the private cryptographic keys of the ID application program 108. In step 810, the control component 111 sends a request to the security element 110 to generate a secret shared with the ID provider server 240 using the second private cryptographic key of the ID application program 108.With the request, the control component 111 provides the security element 110 with, for example, the ephemeral public cryptographic key of the ID provider server 240. The control component 111 has previously received this ephemeral public cryptographic key of the ID provider server 240, for example, during the authentication of the ID provider server 240. A prerequisite for using the second private cryptographic key of the ID application program 108 and thus authenticating the ID application program 108 of the mobile terminal 100 to the ID provider server 240 by the security element 110 is, for example, successful authentication of the user to the security element 110. With the authentication, the user declares his consent to the reading of the attributes to be read by the ID provider server 240.
[0272] In step 812, the security element 110 generates the requested secret using the second private cryptographic key of the ID application program 108 and the ephemeral public cryptographic key of the ID provider server 240. In step 814, the security element 110 makes it available to the control component 111. In step 816, the control component 111 uses the shared secret to generate a common authentication key SK mac for authenticating data exchanged with the ID provider server 240. The corresponding authentication key SK mac is, for example, a symmetric cryptographic key. To generate the authentication key SK mac, the control component 111 also uses a random value. This random value is generated on the mobile terminal 110, for example, by the control component 111.Furthermore, the control component 111 generates an ephemeral symmetric cryptographic session key SK enc using the shared secret and the random value to encrypt the attributes to be read.
[0273] In step 818, the control component uses the authentication key SK_mac and the ephemeral public cryptographic key of the ID provider server 240 to generate an authentication token. The authentication key SK_mac is, for example, a cryptographic key for generating a message authentication code, while the authentication token is a MAC of the ephemeral public cryptographic key of the ID provider server generated using the authentication key.
[0274] The control component 111 sends the authentication token thus generated, along with the random value, to the ID provider server 240 for authenticating the ID application program 108 to the ID provider server 240. Using the random value received from the control component 111, the ID provider server 240 can also generate the authentication key SK mac . The ID provider server 240 calculates the shared secret required for this, for example, using an ephemeral private cryptographic key of the ephemeral asymmetric key pair of the ID provider server 240 and the public cryptographic key of the ID application program 108. Using the authentication key and its ephemeral public cryptographic key, the ID provider server 240 can check the validity of the received authentication token.Further, the ID provider server 240 may generate the ephemeral symmetric cryptographic session key SK enc using the shared secret and the random value.
[0275] In step 820, the control component 109 sends the result of the authentication of the ID application program 108 with the ID provider server 240 to the identification component 111 of the ID application program 108. If the authentication of the ID application program 108 was successful, the attributes to be read are read from the mobile terminal 100 by the ID provider server 240 in step 822. The read request and / or the attributes to be read are encrypted with the generated ephemeral symmetric cryptographic session key SK_enc. Authentication tokens are generated with the authentication key SK_mac, which prove the authenticity of the read request and / or the attributes to be read. For example, the read request is sent in the form of an APDU ("Application Protocol Data Unit").
[0276] The ID provider server 240 can, for example, sign the read attributes and make them available to a requesting service provider. The corresponding service provider can verify the authenticity of the attributes provided to it using the signature of the ID provider server 240. List of reference symbols
[0277] 100 Mobile device 102 Processor 104 Memory 106 Operating system 107 Provisioning component 108 ID application program 109 Control component 110 Security element 111 Identification component 116 User interface 118 Authentication sensor 120 Communication interface 150 Network 160 Encrypted communication channel 162 Encrypted subchannel 164 Encrypted subchannel 170 System 200 ID token 202 Processor 204 Memory 205 Protected memory area 206 Attributes 208 Program instructions 210 Communication interface 220 Personalization server 222 Processor 224 Memory 226 Certificate 228 Program instructions 230 Communication interface 240 ID provider server 242 Processor 244 Memory 246 Certificate 248 Program instructions 250Communication interface 260Service provider server 262Processor 264Memory 266Program instructions 270Communication interface
Claims
1. Method for creating a cryptographically secured electronic identity of a user on a mobile device (100) which comprises a security element (110), wherein an ID application program (108) for providing the electronic identity is installed on the mobile device (100), wherein the ID application program (108) comprises a control component (109) for controlling the creation of the electronic identity, wherein the ID application program (108) further comprises a provisioning component (107) for executing a provisioning of the ID application program (108) in the course of the creation of the cryptographically secured electronic identity, wherein the provisioning of the ID application program (108) comprises: • in response to a security inspection request from the provisioning component (107), performing a remote security inspection of the security infrastructure of the mobile device (100) using the control component (109) by a personalization server (220) over a network (150), • receiving a result of the remote security inspection of the personalization server (220), which the control component (109) forwards to the provisioning component (107), • upon a positive result of the remote security inspection, sending a key generation request from the provisioning component (107) to the control component (109), which forwards the control component (109) to the security element (110), • in response to the key generation request, generating by the security element (110) a first asymmetric key pair associated with the ID application program (108) and a second asymmetric key pair associated with the ID application program (108), wherein the first asymmetric key pair comprises a first private cryptographic key and a first public cryptographic key, wherein the second asymmetric key pair comprises a second private cryptographic key and a second public cryptographic key, wherein the security element (110) sends the first and second public cryptographic keys to the control component (109), which forwards the two public cryptographic keys to the provisioning component (107), • upon receipt of the two public cryptographic keys, generating a certificate request by the provisioning component (107) for generating a certificate of the ID application program (108) comprising the first public cryptographic key, wherein the certificate request comprises the first public cryptographic key, • sending the certificate request by the provisioning component (107) over the network (150) to the personalization server (220), wherein the certificate request comprises the first public cryptographic key, wherein the provisioning component (107) sends the second public cryptographic key to the personalization server (220) in addition to the certificate request, • in response to the certificate request, receiving the certificate generated by the personalization server (220) with the first public cryptographic key and a root certificate of a root instance of a PKI by the personalization component, • storing the certificate of the ID application program (108) and the root certificate on the mobile device (100), wherein the method further comprises personalizing the ID application program (108) on the mobile device (100) using an ID token (200), wherein the ID application program (108) further comprises a personalization component for personalizing the ID application program (108), wherein the personalizing comprises: • establishing a first encrypted communication channel (160) between the mobile device (100) and the personalization server (220) over the network (150), wherein the personalization component is used to establish the first encrypted communication channel (160), • establishing a first encrypted sub-channel (162) between the ID token (200) and the personalization server (220) within the first encrypted communication channel (160) via the mobile device (100), wherein the personalization component is used to establish the first encrypted sub-channel (162) • reading one or more of the attributes (206) from the ID token (200) by the personalization server (220) via the first encrypted sub-channel (162) within the first encrypted communication channel (160), • establishing a second encrypted sub-channel (164) between the control component (109) and the personalization server (220) within the first encrypted communication channel (160), wherein the personalization component is used to establish the second encrypted sub-channel (164), • receiving the read attributes (206) by the control component (109) from the personalization server (220) via the second encrypted sub-channel (164) within the first encrypted communication channel (160), • storing the received attributes (206) by the control component (109) on the mobile device (100), wherein the ID application program (108) is configured to use the attributes (206) to prove an identity of the user to another computer system.
2. Method according to claim 1, wherein the personalization component forwards the root certificate to the control component (109) for storage, and / or wherein the mobile device (100) further comprises one or more authentication sensors (118) for detecting one or more authentication factors of the user, wherein the user is registered on the mobile device (100) and one or more reference values of the registered user are stored in the security element (110) for verifying at least one detected authentication factor of the registered user, wherein the security element (110) is configured such that a prerequisite for the generation of the first asymmetric key pair is a successful authentication of the user to the security element (110), wherein the user declares consent to the generation of the first asymmetric key pair with the authentication, wherein the security element (110) is further configured so that a prerequisite for use of the first private cryptographic key by the security element (110) is in each case a further successful authentication of the user to the security element (110), wherein the user declares in each case with the further authentications consent to the corresponding use of the first private cryptographic key, and / or wherein the security element (110) is a device-specific security element (110), and / or wherein the first encrypted communication channel (160) is encrypted with a first channel-specific ephemeral symmetric cryptographic session key, wherein the first encrypted sub-channel (162) is encrypted with a second channel-specific ephemeral symmetric cryptographic session key, wherein the second encrypted sub-channel (164) is encrypted with a third channel-specific ephemeral symmetric cryptographic session key, and / or wherein the personalizing further comprises: • generating, by the security element (110), a third asymmetric key pair associated with the ID application program (108), wherein the third asymmetric key pair comprises a third private cryptographic key and a third public cryptographic key, wherein the third asymmetric key pair is for authenticating the ID application program (108) in the course of using the attributes (206), and / or wherein the personalizing further comprises: • receiving, by the control component (109), one or more root signature verification keys from the personalization server (220) via the second encrypted sub-channel (164) within the first encrypted communication channel (160), • storing the received root signature verification keys by the control component (109) on the mobile device (100), wherein the ID application program (108) is configured to use the root signature verification keys for verifying certificate signatures of one or more root instances having certificates each used in the course of a readout of the attributes (206) for authenticating a readout computer system to the ID application program (108), and / or wherein the personalizing further comprises: • receiving a signature of the attributes (206) from the personalization server (220) by the control component (109) via the second encrypted sub-channel (164) within the first encrypted communication channel (160), wherein the signature serves as proof of authenticity of the attributes (206), • storing the received signature of the attributes (206) by the control component (109) on the mobile device (100).
3. Method according to any one of the preceding claims, wherein establishing the first encrypted communication channel (160) comprises negotiating the first channel-specific ephemeral symmetric cryptographic session key.
4. Method according to claim 3, wherein negotiating the first channel-specific ephemeral symmetric cryptographic session key comprises: • generating a first random value by the mobile device (100), • generating the first channel-specific ephemeral symmetric cryptographic session key using the first random value by the mobile device (100), • receiving a first certificate of the personalization server (220) with a fourth public cryptographic key of a fourth asymmetric cryptographic key pair of the personalization server (220) by the mobile device (100) from the personalization server (220), • encrypting the first random value using the received first public cryptographic key of the personalization server (220) by the mobile device (100), • sending the encrypted first random value to the personalization server (220) by the mobile device (100) for generating the first channel-specific ephemeral symmetric cryptographic session key by the personalization server (220).
5. Method according to claim 4, wherein establishing the first encrypted communication channel (160) further comprises a mutual authentication of the ID application program (108) of the mobile device (100) and the personalization server (220), wherein the security element (110) is configured in particular such that a prerequisite for authenticating the ID application program (108) of the mobile device (100) to the personalization server (220) is a successful authentication of the user to the security element (110), wherein the user declares consent to the personalization of the ID application program (108) with the authentication, and / or wherein the mobile device (100) for authenticating to the personalization server (220) sends in particular the certificate with the first public cryptographic key of the ID application program (108) and a message signed by the security element (110) with the first private cryptographic key of the ID application program (108) to the personalization server (220).
6. Method according to any one of the preceding claims, wherein establishing the first encrypted sub-channel (162) comprises authenticating the user to the ID token (200) via the mobile device (100), wherein authenticating the user to the ID token (200) in particular comprises: • receiving, by the personalization component, a further authentication factor of the user detected by the one or more authentication sensors (118), • generating a symmetric cryptographic key using the received further authentication factor, • receiving an encrypted second random value by the personalization component from the ID token (200), wherein the encrypted second random value is encrypted using the symmetric cryptographic key generated by the ID token (200) using a further reference value of the registered user stored in the ID token (200) for verifying the further authentication factor, • decrypting the received encrypted second random value using the generated symmetric cryptographic key, • generating a first ephemeral asymmetric cryptographic key pair of the ID application program (108) by the security element (110) comprising a first ephemeral private cryptographic key and a first ephemeral public cryptographic key of the ID application program (108), • sending the first ephemeral public cryptographic key of the ID application program (108) to the ID token (200), • receiving an ephemeral public cryptographic key of the ID token (200), • generating a first secret shared with the ID token (200) by the security element (110) using the decrypted second random value, the first ephemeral private cryptographic key of the ID application program (108) and the ephemeral public cryptographic key of the ID token (200), • receiving the shared first secret by the control component (109), • generating a first shared authentication key for mutually authenticating the ID application program (108) and the ID token (200) by the control component (109) using the shared first secret, • generating a first authentication token using the first authentication key and the first ephemeral public cryptographic key of the ID token (200) by the control component (109), • sending the first authentication token generated by the control component (109) to the ID token (200) by the personalization component, • receiving a second authentication token from the ID token (200) by the personalization component, which forwards the second authentication token to the control component (109), • verifying the received second authentication token by the control component (109) using the first authentication key and the first ephemeral public cryptographic key of the ID application program (108).
7. Method according to any one of the preceding claims, wherein establishing the first encrypted sub-channel (162) comprises authenticating the personalization server (220) by the ID token (200) via the mobile device (100), wherein authenticating the personalization server (220) by the ID token (200) in particular comprises: • receiving a second certificate of the personalization server (220), comprising a second public cryptographic key of a second asymmetric cryptographic key pair of the personalization server (220), via the first encrypted communication channel (160), • verifying a signature of the received second certificate of the personalization server (220), • generating a third random value by the ID token (200), • sending the third random value as a challenge to the personalization server (220) via the first encrypted communication channel (160), • receiving a first signature of the challenge as a response from the personalization server (220) via the first encrypted communication channel (160), wherein the challenge is signed using a second private cryptographic key of the personalization server (220), • verifying the received first signature using the second public cryptographic key of the personalization server (220) and the sent third random value.
8. Method according to any one of the preceding claims, wherein establishing the first encrypted sub-channel (162) comprises authenticating the ID token (200) to the personalization server (220) via the mobile device (100), wherein authenticating the ID token (200) to the personalization server (220) in particular comprises: • sending the public cryptographic key of the ID token (200) from the ID token (200) to the personalization server (220) via the first encrypted communication channel (160), • receiving the second ephemeral public cryptographic key of the personalization server (220) by the ID token (200) from the personalization server (220) via the first encrypted communication channel (160), • generating a second secret shared with the personalization server (220) by the ID token (200) using the private cryptographic key of the ID token (200) and the second ephemeral public cryptographic key of the personalization server (220), • generating a fourth random value by the ID token (200), • generating a second shared authentication key for authenticating data sent over the first encrypted sub-channel (162) by the ID token (200), wherein the second shared authentication key is generated using the shared second secret and the fourth random value, • generating a third authentication token by the ID token (200) using the second authentication key and the second ephemeral public cryptographic key of the personalization server (220) to authenticate the ID token (200) to the personalization server (220), • sending the fourth random value together with the third authentication token for authenticating the ID token (200) by the ID token (200) to the personalization server (220) via the first encrypted communication channel (160).
9. Method according to any one of the preceding claims, wherein establishing the second encrypted sub-channel (164) further comprises authenticating the personalization server (220) by the control component (109), wherein authenticating the personalization server (220) by the control component (109) in particular comprises: • sending a challenge from the control component (109) to the personalization server (220) via the first encrypted communication channel (160), • receiving a response from the personalization server (220) by the control component (109), wherein the response is a signature of the challenge created using a third private cryptographic key of a third asymmetric key pair of the personalization server (220), • receiving a third ephemeral public cryptographic key of the personalization server (220) by the control component (109), • verifying the received response using a third public cryptographic key of the third asymmetric key pair of the personalization server (220) and the sent challenge, • storing the third ephemeral public cryptographic key of the personalization server (220) by the control component (109) on the mobile device (100).
10. Method according to any one of the preceding claims, wherein establishing the second encrypted sub-channel (164) further comprises authenticating the control component (109) to the personalization server (220), wherein authenticating the ID application program (108) by the control component (109) to the personalization server (220) in particular comprises: • sending, from the control component (109) to the security element (110), a request to generate a third secret shared with the personalization server (220), wherein the request comprises the third ephemeral public cryptographic key of the personalization server (220), • in response to the request, receiving by the control component (109) the shared third secret generated by the security element (110), wherein the generation of the shared third secret by the security element (110) is performed using the second private cryptographic key of the ID application program (108) and the third ephemeral public cryptographic key of the personalization server (220), • generating a sixth random value by the control component (109), • generating a third shared authentication key for authenticating data sent over the second encrypted sub-channel (164) by the control component (109), wherein the third shared authentication key is generated using the shared third secret and the sixth random value, • generating a fourth authentication token by the control component (109) using the third authentication key and the third ephemeral public cryptographic key of the personalization server (220) to authenticate the ID application program (108) to the personalization server (220), • sending the sixth random value together with the fourth authentication token for authenticating the ID application program (108) by the control component (109) to the personalization server (220) via the first encrypted communication channel (160).
11. Method according to any one of the preceding claims, wherein the method further comprises using the cryptographically secured electronic identity, wherein one or more of the contributed attributes (206) are provided to an ID provider server (240), wherein the using comprises: • establishing a second encrypted communication channel between the mobile device (100) and the ID provider server (240) over the network (150), • receiving a read request from an ID provider server (240) to read one or more of the attributes (206) of the electronic identity, • authenticating the ID provider server (240) by the ID application program (108) using the control component (109), • authenticating the ID application program (108) to the ID provider server (240) by the security element (110) using the control component (109), • reading out the attributes (206) to be read from the mobile device (100) by the ID provider server (240) via the network (150) using the control component (109).
12. Method according to claim 11, wherein authenticating the ID provider server (240) using the control component (109) comprises: • sending a challenge from the control component (109) to the ID provider server (240) via the second encrypted communication channel, • receiving a response from the ID provider server (240) by the control component (109), wherein the response is a signature of the challenge created using the private cryptographic key of an asymmetric key pair of the ID provider server (240), • receiving a fourth ephemeral public cryptographic key of an ephemeral key pair of the ID provider server (240) by the control component (109), • verifying the received response using a public cryptographic key of the asymmetric key pair of the ID provider server (240) and the sent challenge, • storing the fourth ephemeral public cryptographic key of the ID provider server (240) by the control component (109) on the mobile device (100), and / or wherein authenticating the ID application program (108) to the ID provider server (240) by the security element (110) using the control component (109) comprises: • sending a request to generate a fourth secret shared with the ID provider server (240) from the control component (109) to the security element (110), wherein the request comprises the fourth ephemeral public cryptographic key of the ID provider server (240), • in response to the request, receiving by the control component (109) the shared fourth secret generated by the security element (110), wherein the generation of the shared fourth secret by the security element (110) is performed using the first private cryptographic key of the ID application program (108) and the fourth ephemeral public cryptographic key of the ID provider server (240), • generating a tenth random value by the control component (109), • generating a fourth shared authentication key for authenticating data to the ID provider server (240) by the control component (109), wherein the fourth shared authentication key is generated using the shared fourth secret and the tenth random value, • generating a fifth authentication token by the control component (109) using the fourth authentication key and the fourth ephemeral public cryptographic key of the ID provider server (240) to authenticate the ID application program (108) to the ID provider server (240), • sending the tenth random value together with the fifth authentication token for authenticating the ID application program (108) by the control component (109) to the ID provider server (240) via the second encrypted communication channel, and / or wherein the security element (110) is configured such that a successful authentication of the user to the security element (110) is a prerequisite for the authentication of the ID application program (108) of the mobile device (100) to the ID provider server (240) by the security element (110), wherein the user declares consent to the reading of the attributes (206) to be read by the ID provider server (240) with the authentication.
13. Mobile device (100), wherein the mobile device (100) comprises a processor (102) and a memory (104), wherein the memory (104) stores an ID application program (108) for providing an electronic identity, wherein the processor (102) is configured to execute a method for creating a cryptographically secured electronic identity of a user on a mobile device (100), wherein the ID application program (108) comprises a control component (109) for controlling the creation of the electronic identity, wherein the ID application program (108) further comprises a provisioning component (107) for executing provisioning of the ID application program (108) in the course of creating the cryptographically secured electronic identity, wherein the mobile device (100) further comprises a security element (110), wherein the mobile device (100) further comprises a communication interface (120) for communicating via a network (150) with a personalization server (220), wherein provisioning the ID application program (108) comprises: • in response to a security inspection request from the provisioning component (107), performing a remote security inspection of the security infrastructure of the mobile device (100) using the control component (109) by a personalization server (220) over a network (150), • receiving a result of the remote security inspection of the personalization server (220), which the control component (109) forwards to the provisioning component (107), • in response to a positive result of the remote security inspection, sending a key generation request from the provisioning component (107) to the control component (109), which the control component (109) forwards to the security element (110), • in response to the key generation request, generating by the security element (110) a first asymmetric key pair associated with the ID application program (108) and a second asymmetric key pair associated with the ID application program (108), wherein the first asymmetric key pair comprises a first private cryptographic key and a first public cryptographic key, wherein the second asymmetric key pair comprises a second private cryptographic key and a second public cryptographic key, wherein the security element (110) sends the first and second public cryptographic keys to the control component (109), which forwards the two public cryptographic keys to the provisioning component (107), • upon receipt of the two public cryptographic keys, generating a certificate request by the provisioning component (107) for generating a certificate of the ID application program (108) comprising the first public cryptographic key, wherein the certificate request comprises the first public cryptographic key, • sending the certificate request by the provisioning component (107) over the network (150) to the personalization server (220), wherein the certificate request comprises the first public cryptographic key, wherein the provisioning component (107) sends the second public cryptographic key to the personalization server (220) in addition to the certificate request, • in response to the certificate request, receiving the certificate generated by the personalization server (220) with the first public cryptographic key and a root certificate of a root instance of a PKI by the personalization component, • storing the certificate of the ID application program (108) and the root certificate on the mobile device (100), wherein creating the cryptographically secured electronic identity further comprises personalizing the ID application program (108) on the mobile device (100) using an ID token (200), wherein the ID application program (108) further comprises a personalization component for performing personalization of the ID application program (108) in the course of creating the cryptographically secured electronic identity, wherein the personalizing comprises: • establishing an encrypted communication channel (160) between the mobile device (100) and the personalization server (220) over the network (150), wherein the personalization component is used to establish the encrypted communication channel (160), • establishing a first encrypted sub-channel (162) between the ID token (200) and the personalization server (220) within the encrypted communication channel (160) via the mobile device (100), wherein the personalization component is used to establish the first encrypted sub-channel (162) • reading one or more of the attributes (206) from the ID token (200) by the personalization server (220) via the first encrypted sub-channel (164) within the encrypted communication channel (160), • establishing a second encrypted sub-channel (164) between the control component (109) and the personalization server (220) within the encrypted communication channel, wherein the personalization component is used to establish the second encrypted sub-channel (164), • receiving the read attributes (206) by the control component (109) from the personalization server (220) via the second encrypted sub-channel (164) within the encrypted communication channel (160), • storing the received attributes (206) by the control component (109) on the mobile device (100), wherein the ID application program (108) is configured to use the attributes (206) to prove an identity of the user to another computer system.
14. System (170), wherein the system (170) comprises a mobile device (100) according to claim 13 and a personalization server (220), wherein the personalization server (220) is configured to perform a remote security inspection of the security infrastructure of the mobile device (100) via the network (150), to receive the certificate request with the first public cryptographic key generated by the security element (110) of the mobile device (100), for receiving the second public cryptographic key generated by the security element (110) of the mobile device (100), for creating a certificate with the first public cryptographic key, for providing a root certificate of a root instance of a PKI, and for reading attributes (206) from an ID token (200) via the mobile device (100) and for personalizing the ID application program (108) of the mobile device (100).
15. System (170) according to claim 14, wherein the system (170) further comprises the ID token (200) in which the attributes (206) to be read are stored, and / or wherein the system (170) further comprises an ID provider server (240), wherein the ID provider server (240) is configured for creating a read request for reading one or more of the attributes (206) of the electronic identity provided by the ID application program (108), for sending the read request to the mobile device (100) for authenticating to the ID application program (108), for authenticating the ID application program (108), and for reading the attributes (206) to be read from the mobile device (100) via the network (150).