AUTHENTICATION USING A PLURALITY OF ELECTRONIC IDENTITIES
Patent Information
- Application Number
- DE502022004243
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-02-19
- Filing Date
- 2022-02-17
- Publication Date
- 2025-07-03
- Estimated Expiration
- 2042-02-17
AI Technical Summary
Existing methods for releasing identity attributes of electronic identities stored on mobile devices are complicated and time-consuming, often requiring separate procedures for each application context or electronic identity.
A method for releasing identity attributes involves successful authentication of a reading computer system, which includes receiving a read request with a read certificate, validating the signature of the read certificate using a root certificate, and determining the relevant electronic identities with read rights, thereby confirming the reading rights to the corresponding applications.
This method enables efficient and secure provision of multiple electronic identities on a mobile device, allowing for centralized authentication and authorization verification, thus simplifying the process of reading identity attributes while ensuring cryptographic security.
Description
[0001] The invention relates to a method for releasing one or more identity attributes of one or more electronic identities stored on a mobile terminal to a reading computer system. Furthermore, the invention relates to a corresponding mobile terminal.
[0002] Mobile devices, such as smartphones, are ubiquitous. They are used in many areas of life and situations to perform a wide variety of digital tasks. Mobile devices are also used as proof of identity, authentication, and authorization tokens, for example, in electronic business processes. There are usually separate procedures for releasing identity attributes for each application context or each electronic identity, which quickly makes their use complicated and time-consuming.
[0003] DE 10 2019 100335 A1 describes a method for securely providing a personalized electronic identity on a terminal device, which can be used by a user for identification when using an online service. In the method, an identification application, a personalization application, and an identity provider application are executed on the terminal device in a system with data processing devices and a terminal device assigned to a user. The method comprises the following: transmitting a request for transmitting an identity attribute assigned to the user from the personalization application to the identity provider application; transmitting the identity attribute from the identity provider application to the personalization application after the identity provider application has received consent from the user to transmit the identity attribute;Generating an asymmetric key pair with a public and a private key by the identification application on the terminal device; transmitting the public key from the identification application on the terminal device to the personalization application; generating an electronic certificate for the public key by the personalization application and storing the electronic certificate in a first public key infrastructure of the personalization application in a data store, further comprising: generating a hash value for the identity attribute and incorporating the hash value into the electronic certificate. The identity attribute is encrypted and transmitted together with the electronic certificate from the personalization application to the identification application on the terminal device. Both are stored there in a local storage device of the terminal device.
[0004] The invention is based on the object of creating an improved method for releasing identity attributes.
[0005] The object underlying the invention is solved by the features of the independent patent claims. Embodiments of the invention are specified in the dependent patent claims.
[0006] Embodiments include a method for releasing one or more identity attributes of one or more electronic identities stored on a mobile device to a reading computer system. A plurality of electronic identities are stored on the mobile device. Releasing the identity attributes requires successful authentication of the reading computer system. Authenticating the reading computer system comprises: Receiving a read request from the reading computer system for reading one or more identity attributes of one or more types of electronic identities to be read out, together with a read certificate of the reading computer system, wherein the read certificate defines read rights of the reading computer system to identity attributes of a plurality of different types of electronic identities. Centrally executing the authentication of the reading computer system, wherein the authentication comprises validating a signature of the read certificate using a root certificate stored on the mobile terminal, upon successful authentication of the reading computer system. Determining a group of one or more electronic identities with those electronic identities stored on the mobile terminal that belong to one of the types of electronic identities for which the read certificate defines read rights.Identifying one or more electronic identities within the specific group of electronic identities that belong to one of the types of electronic identities to be read according to the read request, sending authentication confirmations to one or more applications installed on the mobile device, each of which manages one or more of the identified electronic identities, thereby confirming the reading rights of the reading computer system to the corresponding electronic identities.
[0007] Embodiments can have the advantage that they enable the provision of a plurality of electronic identities on a mobile device. The corresponding electronic identities are, for example, each managed by an application installed on the mobile device. For cryptographically securing the corresponding electronic identities, in particular for the secure storage of catalyst keys assigned to the corresponding identities, the mobile device comprises one or more security elements. For example, a security element is provided for each of the electronic identities. For example, several electronic identities share a common security element, although each of the electronic identities is assigned an individual sub-security domain, i.e. a secure storage area, of the security element.For example, a separate application is installed on the mobile device for each of the electronic identities provided by the mobile device. For example, an application installed on the mobile device manages multiple electronic identities.
[0008] Embodiments may further have the advantage that a centralized execution of authentication and authorization verification of a reading computer system can be implemented. This makes it possible, for example, that when reading identity attributes originating from a plurality of electronic identities, the authentication of the reading computer system and the verification of the reading authorization of the corresponding reading computer system for the corresponding identity attributes or the corresponding plurality of electronic identities only need to be performed once.
[0009] First, the mobile device receives a read request from the reading computer system to read one or more identity attributes of one or more reading types of electronic identities. Different types of electronic identities comprise different types of identity attributes. This means, for example, that one and the same user can be assigned multiple electronic identities, each of which comprises a different set of identity attributes of the corresponding user. For example, only these electronic identities of different types are stored on the mobile device.If a reading computer system wants to read a specific combination of identity attributes that does not comprise one type of electronic identity, it is necessary to read a plurality of electronic identities that together provide the desired combination of identity attributes.
[0010] The read request also includes a read certificate, which defines or verifies the reading rights of the reading computer system to identity attributes. During the authentication of the reading computer system, the validity of the read certificate is carried out by a signature check. During the signature verification, a route certificate stored in the mobile device is used. The read certificate has a signature, i.e. it is signed with a signature key, which is a private cryptographic key of an asymmetric signature key pair. This signature can, for example, be verified with a signature verification key, which is, for example, a public cryptographic key of the asymmetric signature key pair. The signature verification key is provided either by the root certificate or by a certificate in a certificate chain that ends with the root certificate.The corresponding additional certificates in the certificate chain besides the root certificate are received, for example, together with the read certificate. Alternatively, the corresponding certificates can be retrieved by the mobile device via a network, or the corresponding certificates can be stored on the mobile device, for example, together with the root certificate.
[0011] In order for the read certificate to constitute valid proof of authorization for the read request, it must demonstrate read rights of the reading computer system for all types of electronic identities to be read. Upon successful authentication of the reading computer system, it is determined for which of the electronic identities stored on the mobile device the read certificate defines read rights. Within this specific group of electronic identities, those electronic identities are identified that belong to a type of electronic identity to be read according to the read request. The correspondingly identified electronic identities orAuthentication statements are sent to the applications managing the corresponding electronic identities, confirming successful authentication and authorization verification of the reading computer system for reading the corresponding electronic identities. In other words, the authentication confirmation not only confirms successful authentication of the reading computer system but also confirms the reading computer system's existing read rights to the corresponding electronic identities.
[0012] Authentication refers to the verification of a claimed property of an entity, such as a user of a mobile device. During authentication, for example, corresponding evidence provided by the user is verified. The entity performs authentication through its contribution to the authentication process, i.e., by providing appropriate evidence such as authentication data or authentication factors for verification.
[0013] Authentication of the user regarding the claimed property of authenticity, for example, the authenticity of their person or identity, allows the authenticated user to perform further actions. For example, the user is granted access rights. A successfully authenticated user is considered authentic. Final confirmation of an authentication may include authorization.
[0014] The user can authenticate themselves in various ways. For example, they can provide proof of knowledge, such as a PIN or password, proof of possession, such as a cryptographic key, a certificate, or an electronic device, and / or proof of their own personal characteristics, such as biometric or behavioral characteristics. For example, the corresponding proof is captured by an authentication sensor on the mobile device in the form of the user's authentication data and compared by a security element on the mobile device with one or more stored reference values. The security element that evaluates the captured authentication data is, for example, a security element of the mobile device's operating system.If there is a sufficient match between the captured authentication data and the stored reference values, the security element confirms successful user authentication. For example, confirming successful user authentication involves executing a challenge-response procedure by the confirming security element.
[0015] A mobile device is a mobile, portable communication device, such as a smartphone, a tablet or a smartwatch.
[0016] An authentication sensor is understood to be a sensor for capturing authentication data of the user of the mobile device. The authentication data can, for example, comprise biometric data of the user. The authentication sensor can be configured to capture biometric data of the user. Biometric data can, for example, comprise: fingerprint data, body geometry data / anthropometric data, such as facial, hand, or ear geometry data, hand line structure data, vein structure data, such as palm vein structure data, iris data, retina data, voice recognition data, and nail bed patterns. The authentication sensor can, for example, comprise a camera of the mobile device. The authentication data can, for example, comprise user knowledge, such as a PIN or password. The authentication sensor can comprise an input device for entering authentication data, such as a PIN or password.The input device may, for example, comprise a keyboard and / or a touchscreen.
[0017] A challenge-response procedure represents a secure authentication procedure between a first instance and a second instance based on knowledge. For example, the first security element is authenticated by the security applet of the second security element using a challenge-response procedure. At the same time, the response represents confirmation of successful user authentication if the response is only generated under the condition of successful user authentication by the first security element. Thus, in the case of a successful challenge-response procedure, the security applet not only knows that the user authentication has been confirmed, but also that it has been confirmed by the first security element and is therefore valid.
[0018] In the course of a challenge-response procedure, a first instance presents a task ("challenge") to a second instance, for which the second instance must provide a correct answer ("response").
[0019] For example, the first instance generates a random number ("nonce") and sends it to the second instance. The second instance uses a shared secret to cryptographically transform the nonce and sends the result as a response to the first instance for the purpose of authenticating the second instance. For example, the nonce is combined with the shared secret and a cryptographic hash function or encryption is applied to this combination. Alternatively, the shared secret, such as a symmetric cryptographic key, can be used to encrypt the nonce. The first instance, which knows both the nonce and the shared secret, can, for example, perform the same computation as the second instance and / or perform an inverse computation, e.g., decrypt the encrypted nonce using the shared secret.If the result of the calculation by the first instance matches the result of the calculation by the second instance or the challenge, the challenge-response procedure is successful and the second instance is successfully authenticated.
[0020] Furthermore, a challenge-response procedure can also be based on an asymmetric cryptosystem and serve to prove to the first instance that the second instance is in possession of a private and thus secret cryptographic key. In this case, only the second instance knows the corresponding private cryptographic key, which it uses for a cryptographic transformation of the challenge, e.g. a nonce. The corresponding cryptographic transformation can be, for example, a digital signature. The first instance can use a public cryptographic key associated with the private cryptographic key to check the response to determine whether the second instance actually has knowledge of the private cryptographic key, without the first instance itself gaining knowledge of the private cryptographic key during the check.
[0021] A security element, also called a "secure element" or "SE," is a secured element of a mobile device that provides cryptographic means. These cryptographic means are protected against manipulation and are accessible, for example, via cryptographic keys, only to authorized services and applications. In particular, the cryptographic means can only be inserted, added to, modified, and / or deleted in the security element by authorized services and applications.A security element therefore provides a tamper-proof platform, for example, implemented in the form of a secure single-chip microcontroller, on which applets and / or confidential and / or cryptographic data can be stored according to predefined rules and security requirements by reliably identified trusted entities and thus made available to authorized application programs and / or operating systems. A security element can be embedded or integrated, for example, non-destructively removable or permanently attached, i.e., not non-destructively removable. The security element can, for example, comprise a SIM, UICC, SmartMicroSD, smart card, eSE, eSIM, or eUICC. For example, cryptographic keys are stored on a security element, i.e., the security element comprises a data safe for cryptographic keys or a "key store." Such a key store orThe security element can also be implemented as part of the main processor, for example, in a TEE (Trusted Execution Environment). For example, the first security element can be implemented using a TEE. Security elements are implemented, for example, as hardware and / or firmware. According to embodiments, security elements or key stores can also be implemented as software. Two security elements are independent of each other, for example, if there is no common instance that has access rights for both security elements.
[0022] An application program, also called an application or app for short, is a computer program that provides, supports and / or enables the processing of non-system-technical functionality.
[0023] An applet is a computer program that is not run as a standalone application. The term "applet" is derived from the words "application" and "snippet."
[0024] An operating system is a computer program or a collection of computer programs that provides, supports, and / or enables the processing of system-specific functionalities. An operating system provides system resources. System resources refer to system elements or hardware components of a computer that are required by processes to function correctly.
[0025] A computer or a computer system can be, for example, a stationary computer, such as a personal computer (PC), service terminal, or server, or a mobile portable computer, such as a laptop, tablet, smartphone, or other smart device. The computer can include an interface for connecting to the network, which can be a private or public network, in particular the Internet. Depending on the embodiment, this connection can also be established via a mobile network.
[0026] A "user computer system" is defined here as a computer system to which the user has access. This can be, for example, a desktop computer (PC), a service terminal, or a mobile portable communications device such as a laptop, tablet, smartphone, or other smart device.
[0027] A "service server" is understood here to be a server or computer system on which a server program is executed and which provides the possibility of initiating, using and / or executing an offered service via a network.
[0028] A "program" or "program instructions" is understood here, without limitation, to mean any type of computer program that includes machine-readable instructions for controlling a functionality of the computer.
[0029] A "processor" is understood here and below to mean a logic circuit that serves to execute program instructions. The logic circuit can be implemented on one or more discrete components, in particular on a chip. In particular, a "processor" is understood to mean a microprocessor or a microprocessor system comprising multiple processor cores and / or multiple microprocessors.
[0030] The term "memory" refers here to both volatile and non-volatile electronic memories or digital storage media.
[0031] "Non-volatile memory" is defined here as an electronic memory for the permanent storage of data, in particular static cryptographic keys, attributes, or identifiers. Non-volatile memory can be configured as non-modifiable memory, also known as read-only memory (ROM), or as modifiable memory, also known as non-volatile memory (NVM). In particular, this can be an EEPROM, for example, a flash EEPROM, also known as flash. Non-volatile memory is characterized by the fact that the data stored on it is retained even after the power supply is switched off.
[0032] An "interface" or "communication interface" is understood here to be an interface through which data can be received and sent. The communication interface can be configured as contact-based or contactless. A communication interface can, for example, enable communication over a network. Depending on the configuration, a communication interface can, for example, provide wireless communication according to a cellular standard, Bluetooth, RFID, Wi-Fi, and / or NFC standards. Depending on the configuration, a communication interface can, for example, provide cable-based communication. The communication interface can be an internal interface or an external interface.
[0033] Encrypted communication channels, for example, are encrypted end-to-end connections. An "encrypted end-to-end connection" or "encrypted end-to-end transmission channel" is understood here as a connection between a sender and a receiver with end-to-end encryption, in which the data to be transmitted is encrypted by the sender and only decrypted by the receiver. The encryption of transmitted data thus occurs across all transmission stations, so that intermediate stations cannot gain knowledge of the content of the transmitted data due to the encryption. The connection is cryptographically secured by encryption to prevent spying and / or manipulation of the transmission. A so-called secure messaging procedure can be used for this purpose.End-to-end encryption, for example, is based on two symmetric cryptographic keys, with a first symmetric key used to encrypt messages and a second symmetric key used to authenticate the sender of the message, for example, using Message Authentication Code (MAC) algorithms. For example, during the setup of an encrypted communication channel, ephemeral encryption keys are negotiated, which become invalid when the communication channel is terminated. Using different ephemeral keys for different communication channels makes it possible to operate multiple communication channels in parallel.
[0034] An encrypted communication channel can be established, for example, using the Transport Layer Security (TLS) protocol, for example as part of the Hypertext Transfer Protocol Secure (HTTP) protocol.
[0035] Asymmetric key pairs are used in a variety of cryptosystems and play an important role in the secure transmission of electronic data. An asymmetric key pair consists of a public key, which is used to encrypt and / or decrypt data and may be passed on to third parties, such as a sender or receiver of data, and a private key, which is used for encryption and / or decryption but also for signing data and must generally be kept secret. The public key allows anyone to encrypt data for the owner of the private key or to verify digital signatures created with the private key. A private key allows its owner to decrypt data encrypted with the public key or to create digital signatures for data.
[0036] A digital signature of data includes, for example, creating a check value for the data, such as a hash value, which is encrypted with a private cryptographic key of an asymmetric key pair used as the signature key. In the case of a signature, only the signatory knows the private cryptographic key (i.e., signature key) of the asymmetric key pair used to create the signature. The signature recipient only has the public key (i.e., signature verification key) of the asymmetric key pair used for the signature. The signature recipient can therefore verify the signature but cannot calculate it themselves. To verify a signature, the signature recipient calculates, for example, the check value of the signed data and compares this with the result of decrypting the signature using the signature verification key.If the calculated hash value matches the decryption result, the signature is correct. If the authenticity of the signature verification key is also confirmed, for example, by a certificate, especially a PKI certificate, the signature is valid.
[0037] A "certificate" here refers to a digital certificate, also known as a public key certificate (PKI certificate). A certificate is structured data used to assign a public key of an asymmetric cryptosystem to an identity, such as a person, institution, or device. For cryptographic security and to prove the authenticity of the certificate data, it is signed by a certificate issuer. PKI certificates, which are based on asymmetric key pairs and, with the exception of a root certificate, are each signed by a certificate issuer with a signature key whose corresponding signature verification key is assigned to the certificate issuer by a PKI certificate of the corresponding certificate issuer, create a so-called Public Key Infrastructure (PKI). For example, the certificate can conform to the X.509 or another standard. For example, the certificate is a Card Verifiable Certificate (CVC). An authorization certificate, such as a read and / or write certificate, includes structured data that additionally defines identity rights, such as read and / or write permissions.
[0038] The PKI provides a system for issuing, distributing, and verifying digital certificates. In an asymmetric cryptosystem, a digital certificate can confirm the authenticity of a public cryptographic key and its permissible scope of use and validity. The digital certificate itself is protected by a digital signature, the authenticity of which can be verified using the public key of the certificate issuer. A digital certificate is used to verify the authenticity of the issuer key. In this way, a chain of digital certificates can be established, each of which confirms the authenticity of the public key with which the previous certificate can be verified. Such a chain of certificates forms a so-called validation path or certification path.For example, PKI participants must be able to rely on the authenticity of the last certificate, the so-called root certificate, and the key certified by it, without requiring any additional certificates. The root certificate is managed by a so-called root certification authority, whose assumed authenticity underlies the authenticity of all PKI certificates.
[0039] Digital certificates, for example, are confirmed by an independent, trustworthy authority (certification service provider / CSP or trust service provider / TSP), i.e. the certification authority that issued the certificate. Certificates can be made available to a wide group of people to enable them to check electronic signatures for authenticity and validity. A certificate can be associated with an electronic signature and provide a signature verification key in the form of the public key if the private key belonging to the signature verification key was used as the signature key. By making a certificate in association with a public key available to the public, a CSP / TSP enables users of asymmetric cryptosystems to assign the public key to an identity, for example, a person, an organization, or a computer system.
[0040] According to embodiments, the electronic identity may comprise an officially recognized identity, such as an electronic identity created on the basis of an official identification document, such as an identity card or passport.
[0041] A user's electronic identity is unambiguous, meaning it is unique and unmistakable. It is defined based on characteristics, so-called identity attributes. An electronic identity includes, for example, personal data. Personal data refers to data that enables the identification of a person or can be assigned to a person to whom the personal data relates.
[0042] A user can have multiple different, application-specific electronic identities. These electronic identities can meet different security requirements.
[0043] According to embodiments, an electronic identity stored on the mobile device and provided or managed by the ID application program can be used to identify and authenticate the user of the mobile device without additional hardware besides the mobile device.
[0044] Identity attributes are requested, for example, by service providers or service providers for online services. According to embodiments, the identity attributes required by a service provider for its online service are transmitted in an encrypted and authentic manner. For example, read certificates are used to regulate who is authorized to access which identity attributes or who has read authorization for them. For example, the required identity attributes are read by an ID provider authorized to do so by means of a read certificate and made available to the requesting service provider. According to embodiments, the ID provider only provides the requesting service provider with confirmation of the requested identity attribute(s).
[0045] The user's consent to the use of identity attributes and / or user authentication takes place, for example, by checking one or more authentication factors, such as password, PIN, fingerprint or facial recognition.
[0046] According to embodiments, the authentication confirmations each comprise an indication of those identity attributes of the identified electronic identities which are managed by the application to which the corresponding authentication confirmation is sent and for which the read certificate defines read rights of the reading computer system.
[0047] Embodiments may have the advantage that if the read certificate for one or more types of electronic identities does not grant read rights to all identity attributes of the corresponding types of electronic identities, for example, if the read certificate only grants read rights to certain identity attributes, this can be defined in the authentication confirmation so that the receiving application that manages the corresponding electronic identity becomes aware of which of the identity attributes of the corresponding electronic identity the reading computer system has read rights for. If the read certificate grants read rights for all identity attributes of the specified types of electronic identities, it is not necessary for the authentication confirmation to list individual identity attributes to which the reading computer system has read rights.
[0048] According to embodiments, the central authentication of the reading computer system is carried out by validating the reading certificate by an operating system installed on the mobile device.
[0049] Embodiments may have the advantage that the operating system has access to a security element in which the root certificate for validating the read certificate can be stored. For example, the root certificate is integrated with the operating system's security elements during the production of the mobile device or during provisioning of the mobile device with the operating system.
[0050] According to embodiments, authentication is performed by the operating system using a security element of the operating system in which the root certificate for validating the read certificate is stored.
[0051] Embodiments may have the advantage that the security element of the operating system can provide a private cryptographic key of an asymmetric key pair associated with the operating system, with which the authentication confirmations can be signed. Thus, the security element of the operating system can provide cryptographic keys for executing cryptographic protocols; in particular, private cryptographic keys can be stored in the security element.
[0052] According to embodiments, the authentication confirmations are signed with a private cryptographic key associated with the operating system, which is stored in the security element of the operating system.
[0053] According to embodiments, the central authentication of the reading computer system is carried out by validating the reading certificate by an application installed on the mobile device.
[0054] Embodiments may have the advantage that central authentication can be performed by an application installed on the mobile device. The corresponding application may, for example, be an application that manages electronic identities or an application intended for authenticating the reading computer system. The corresponding application may, for example, be assigned a security element or a sub-security domain in a security element of the mobile device, which the application can use to authenticate the reading computer system and / or to generate the authentication confirmations.
[0055] According to embodiments, the application is assigned an applet, which is installed in a sub-security domain of a security element of the mobile device assigned to the application. Authentication is performed using the applet. Furthermore, the root certificate for validating the read certificate is stored in the sub-security domain of the security element of the mobile device.
[0056] Embodiments may have the advantage that the root certificate for a signature verification of the read certificate can be stored in a protected form in the sub-security domain of the security element assigned to the application.
[0057] According to embodiments, the mobile device comprises a plurality of security elements. According to embodiments, applets from one or more of the applications are stored on multiple security elements. According to embodiments, the corresponding applications select which of the plurality of applets assigned to them they use for authentication to the reading computer system.
[0058] For example, the security element comprises a plurality of sub-security domains. According to embodiments, applets assigned to different applications are stored on a common security element. For example, the security element comprises only a single sub-security domain. According to embodiments, applets of one or more of the applications are each stored on an application-specific security element.
[0059] According to embodiments, the authentication confirmations are signed with a private cryptographic key assigned to the application, which is stored in the sub-security domain of the security element of the mobile device assigned to the application.
[0060] Embodiments may have the advantage that a private cryptographic key of an asymmetric key pair associated with the application can be securely stored in the sub-security domain of the security element associated with the application. The corresponding private cryptographic key can be used to sign the authentication confirmation.
[0061] According to embodiments, the application includes the root certificate for validating the read certificate. The entire application or a portion of the application including the root certificate has a signature. A prerequisite for performing authentication is a successful integrity check, which includes verifying the signature.
[0062] Embodiments may have the advantage that, if the application does not have a sub-security domain of a security element available to secure the authentication of the reading computer system, the application can, for example, include the root certificate itself. To secure the root certificate, the entire application or at least a part of the application that matches the root certificate can have a signature. For example, a prerequisite for executing authentication is a successful identity verification of the application or of the part of the application that includes the root certificate. A corresponding identity verification includes, for example, a verification of the signature.
[0063] According to embodiments, the authentication confirmations are sent unsigned by the application to one or more applications installed on the mobile device, each of which manages one or more of the identified electronic identities. In this case, for example, the authentication confirmations are sent unsigned to the applications managing the identified electronic identities.
[0064] According to embodiments, the read certificate comprises a first public cryptographic key of a first asymmetric key pair of the reading computer system. Authentication further comprises: Extracting the first public cryptographic key of the reading computer system from the read certificate, generating a random challenge, sending the random challenge to the reading computer system, receiving a response from the reading computer system, wherein the response comprises a signature of the challenge created using a first private cryptographic key of the first asymmetric key pair of the reading computer system, validating the signature of the challenge using the challenge and the extracted first public cryptographic key.
[0065] Embodiments may have the advantage that the corresponding challenge-response method can be used to check whether the reading computer system has the first private cryptographic key. If this is the case, the reading computer system is actually the identity to which the read certificate is assigned. Thus, the reading computer system is authenticated.
[0066] According to embodiments, one or more applets are assigned to each receiving application, each of which is installed in a sub-security domain of a security element of the mobile device assigned to the application. One or more of the receiving applications authenticate themselves to the reading computer system. Authentication includes: Sending a public cryptographic key of an asymmetric key pair assigned to the application to the reading computer system, wherein a private cryptographic key of the asymmetric key pair is stored in the sub-security domain assigned to the application; Calculating a secret shared with the reading computer system by the applet assigned to the application using the private cryptographic key of the application and an ephemeral second public cryptographic key of the reading computer system received from the reading computer system; Generating a random number by the applet; Generating a common authentication key for authenticating information during communication between the application using the applet and the reading computer system using the shared secret and the generated random number;Generating an authentication token by the applet using the authentication key and the ephemeral second public cryptographic key of the reading computer system to authenticate the application using the applet to the reading computer system, sending the random number together with the authentication token for authentication by the reading computer system.
[0067] Embodiments can have the advantage that, using the applets of the applications managing the electronic identities installed in the security elements, the corresponding applications or the electronic identities managed by them can be authenticated to the reading computer system. The reading computer system receives the public cryptographic key in the application and can also calculate the shared secret using this public cryptographic key and an ephemeral second private cryptographic key of the asymmetric key pair comprising the ephemeral second public cryptographic key. Upon receiving the random number, the reading computer system can also calculate the shared authentication key.Using the authentication key calculated in this way and the ephemeral second private cryptographic key, the reading computer system can also validate the received authentication token. For example, if an authentication token calculated by the reading computer system using the calculated authentication key and the received random number matches the received authentication token, the reading computer system demonstrates that the application actually possesses the corresponding private cryptographic key of the asymmetric key pair assigned to the application. Thus, the application or the electronic identity managed by it is authenticated.
[0068] According to embodiments, the authentication confirmations each comprise the ephemeral second public cryptographic key of the reading computer system.
[0069] Embodiments may have the advantage that an ephemeral second public cryptographic key can also be provided for session-dependent encryption of the communication between the reading computer system and the applications managing the electronic identities.
[0070] According to embodiments, the public cryptographic key is sent to the reading computer system along with a certificate. According to embodiments, the reading computer system has access to the certificate; for example, the certificate is stored in a memory of the reading computer system or the certificate is retrievable from an online-accessible registry.
[0071] According to embodiments, in response to the reading computer system sending the public cryptographic key associated with the application, the application using the applet receives a second copy of the reading computer system's ephemeral second public cryptographic key, which the application compares with the first copy of the reading computer system's ephemeral second public cryptographic key from the authentication confirmations. A match between the two copies is a prerequisite for calculating the shared secret.
[0072] Embodiments may have the advantage that the application can check, based on the received second copy of the ephemeral public cryptographic key of the reading computer system, whether the communication during the authentication of the application actually takes place with the already authenticated reading computer system.
[0073] According to embodiments, the calculated authentication key is an identity-specific authentication key.
[0074] Embodiments may have the advantage that, if the application manages a plurality of electronic identities, identity-specific authentication keys can be created for each of the electronic identities. In other words, in this case, an individual authentication of the application to the reading computer system takes place for each of the electronic identities. An identity-specific authentication key is created for each of the electronic identities. Thus, an individual ephemeral encryption can be implemented for each of the electronic identities for transmitting identity attributes of the corresponding electronic identity.
[0075] According to embodiments, each of the applications manages exactly one electronic identity.
[0076] According to embodiments, the calculated random number is an identity-specific random number.
[0077] According to embodiments, an identifier of the type of electronic identity managed by the application is also used to calculate the authentication key. The identifier is sent to the reading computer system together with the public cryptographic key.
[0078] Embodiments may have the advantage that the identifier of the type of electronic identity can be used to implement individualization of the authentication for the corresponding electronic identity or the corresponding type of electronic identity.
[0079] According to embodiments, one or more of the applications each manage a plurality of electronic identities of different types.
[0080] According to embodiments, an identifier of the type of electronic identity managed by the application is used to calculate the authentication key if one of the applications uses a plurality of electronic identities of different types.
[0081] According to embodiments, an identifier of the type of electronic identity managed by the application is further used to calculate the random number.
[0082] According to embodiments, an identifier of the type of electronic identity managed by the application is used to calculate the random number if one of the applications uses a plurality of electronic identities of different types.
[0083] According to embodiments, the authentication key is a key for generating a message authentication code. The authentication token is a MAC code of the random number generated using the authentication key.
[0084] The authenticity of the transmitted identity attributes can be ensured, for example, by using a Message Authentication Code (MAC). A MAC is calculated, for example, using a MAC algorithm to which the data to be protected, i.e. the identity attributes, and a cryptographic key, for example a symmetric cryptographic key, are provided as input data. Using this input data, the MAC algorithm calculates a checksum, which serves as the MAC. Block ciphers or hash functions, for example, can be used to calculate MACs. An HMAC (Keyed-Hash Message Authentication Code), for example, can be used as a MAC. For example, a cryptographic hash function, such as the Secure Hash Algorithm (SHA), and a secret cryptographic key, for example a symmetric cryptographic key, are used for its construction.
[0085] To secure a data transmission, for example the transmission of identity attributes, a cryptographic key, for example a symmetric cryptographic key, is agreed between the sender, for example the applet, and the receiver, for example a reading computer system. The sender uses this cryptographic key to calculate a MAC of the data to be transmitted and sends the calculated MAC along with the data to be transmitted to the receiver. The receiver, in turn, calculates a MAC for the received data using the cryptographic key and compares the result with the received MAC. If there is a match between the calculated MAC and the received MAC, the integrity check is successful and the received data is considered authentic.
[0086] In the case of a MAC, both sender and receiver must know the cryptographic key used, unlike when using pure hash functions or signatures. In the case of pure hash functions, for example, no cryptographic keys are used. If the hash functions are public, anyone can calculate the hash value, especially for manipulated messages. In the case of a signature, only the signer knows the private cryptographic key used to create the signature (i.e., the signature key) of an asymmetric key pair used for the signature. The signature recipient only has the public key (i.e., the signature verification key) of the asymmetric key pair used for the signature. The signature recipient can therefore verify the signature using the signature verification key, but cannot calculate it themselves.
[0087] According to embodiments, the applet further generates a symmetric cryptographic key using the shared secret and the random number to encrypt the communication between the application using the applet and the reading computer system.
[0088] Embodiments may have the advantage that the symmetric cryptographic key enables encryption of the communication between the application and the reading computer system. This symmetric cryptographic key can be used, for example, to encrypt identity attributes of the electronic identity managed by the corresponding application for transmission to a reading computer system. Thus, application-specific encryption can be provided between the corresponding application and the reading computer system.
[0089] According to embodiments, the symmetric cryptographic key is calculated by the applet together with the shared authentication key.
[0090] According to embodiments, the calculated symmetric cryptographic key is an identity-specific symmetric cryptographic key.
[0091] Embodiments may have the advantage that identity-specific encryption can be implemented. For example, the identity attributes of the individual electronic identities or types of electronic identities are each encrypted with their own symmetric cryptographic key. This can be advantageous if an application manages a plurality of electronic identities. If each application manages exactly one electronic identity, application-specific encryption already represents identity-specific encryption.
[0092] According to embodiments, an identifier of the type of electronic identity managed by the application is further used to calculate the symmetric cryptographic key.
[0093] Embodiments may have the advantage that using the identifier of the type of electronic identity managed by the application, calculation of an identity-specific symmetric cryptographic key may be enabled in an effective and efficient manner.
[0094] According to embodiments, the identifier was sent to the reading computer system together with the public cryptographic key.
[0095] According to embodiments, an identifier of the type of electronic identity managed by the application is used to calculate the symmetric cryptographic key if one of the applications uses a plurality of electronic identities of different types.
[0096] According to embodiments, the reading computer system is a server that communicates with the mobile device via a network.
[0097] Embodiments may have the advantage that identity attributes of electronic identities can be provided via a network, such as an intranet or the Internet, using the mobile terminal. This may be advantageous, for example, if a service is to be used via the network using the mobile terminal, the provision of which requires one or more identity attributes.
[0098] According to embodiments, the reading computer system is a local computer system that communicates with the mobile terminal via a contactless radio connection between a communication interface of the local computer system and a communication interface of the mobile terminal.
[0099] Embodiments may have the advantage of enabling local reading of identity attributes by a local computer system, i.e., a terminal. Thus, for example, identity attributes can be provided locally if they are needed, for example, to provide a service on-site.
[0100] Embodiments further include a mobile terminal comprising a processor, a memory, and a communication interface. A plurality of electronic identities are stored on the mobile terminal. The processor is configured to execute a method for releasing one or more identity attributes of one or more of the electronic identities stored on the mobile terminal for a reading computer system. Releasing the identity attributes requires successful authentication of the reading computer system. Authenticating the reading computer system comprises: Receiving a read request from the reading computer system for reading one or more identity attributes of one or more types of electronic identities to be read out, together with a read certificate of the reading computer system, wherein the read certificate defines read rights of the reading computer system to identity attributes of a plurality of different types of electronic identities. Centrally executing the authentication of the reading computer system, wherein the authentication comprises validating a signature of the read certificate using a root certificate stored on the mobile terminal, upon successful authentication of the reading computer system. Determining a group of one or more electronic identities with those electronic identities stored on the mobile terminal that belong to one of the types of electronic identities for which the read certificate defines read rights.Identifying one or more electronic identities within the specific group of electronic identities that belong to one of the types of electronic identities to be read according to the read request, sending authentication confirmations to one or more applications installed on the mobile device, each of which manages one or more of the identified electronic identities, thereby confirming the reading rights of the reading computer system to the corresponding electronic identities.
[0101] According to embodiments, the mobile terminal is configured to perform any of the previously described embodiments of the method for releasing one or more identity attributes.
[0102] Embodiments of the invention will be explained in more detail below with reference to the drawings. They show: Figure 1 is a schematic diagram of an exemplary mobile terminal, Figure 2 is a flowchart of an exemplary method, Figure 3 is a flowchart of an exemplary central authentication of a reading computer system, Figure 4 is a flowchart of an exemplary authentication of a security applet, Figure 5 is a schematic diagram of an exemplary mobile terminal, and Figure 6 is a schematic diagram of an exemplary system.
[0103] Elements of the following embodiments that correspond to one another are identified by the same reference numerals.
[0104] Figure 1shows an exemplary mobile device 100, for example a smartphone, which comprises a memory 104 with program instructions that are executed by a processor 102. The program instructions can, for example, comprise an operating system 106 installed on the mobile device 100 and one or more applications or application programs 108. For example, the mobile device 100 comprises a security element 110 that is assigned to the operating system 106 and provides cryptographic means for it, such as cryptographic keys, cryptographic functions and / or cryptographic protocols. The security element 110 of the operating system 106 represents, for example, a key store orKey storage is provided for storing cryptographic keys, such as symmetric, public, and / or private cryptographic keys, and certificates, such as read certificates, public key certificates, and / or attribute certificates. The cryptographic means provided by the first security element 110 enable the operating system 106, for example, to encrypt and / or decrypt data, as well as to create and / or verify signatures. For example, the cryptographic means provided by the first security element 110 enable the operating system 106 to execute or participate in a challenge-response procedure.
[0105] For example, the mobile terminal 100 further comprises a security element 112, which comprises one or more sub-security domains 114, 116. Each of these sub-security domains 114, 116 is, for example, assigned to an electronic identity stored on the mobile terminal 100. For example, one or more of the electronic identities are each managed by one of the applications 108, 109. For example, one of the applications 108, 109 can also manage a plurality of electronic identities. Each sub-security domain 114, 116 comprises, for example, an individual applet or security applet 115, 117, which is assigned to the electronic identities of the corresponding sub-security domains 114, 116. The applets 115, 117 enable the applications 108, 109 to provide identity-specific cryptographic means for the electronic identities they manage.Applets 115, 117 provide the corresponding identity-specific cryptographic means for the application managing the respective electronic identity. For example, the identity-specific cryptographic means include cryptographic keys, cryptographic functions, and / or cryptographic protocols.
[0106] The applets 115, 117 or the memory areas of the security element 112 assigned to the corresponding applets 115, 117 each provide, for example, a key store for storing cryptographic keys for the individual electronic identities, such as symmetric, public, and / or private cryptographic keys, and certificates, such as read certificates, public key certificates, and / or attribute certificates. The cryptographic means provided by the sub-security domain 114, 116 of the security element 112 enable the applications 108, 109, for example, to encrypt and / or decrypt data for the electronic identities they manage, as well as to create and / or verify signatures.For example, the cryptographic means provided by the sub-security domain 114, 116 of the security element 112 enable the applications 108, 109 to execute or participate in a challenge-response procedure for the electronic identities they manage. The security elements 110, 112 can, for example, each be implemented as an eSim and / or eUICC.
[0107] Furthermore, the mobile terminal 100 comprises a user interface 118, which, for example, comprises a display, in particular a touchscreen. Using the user interface 118, the user can interact with the mobile terminal 100. For example, the user can be prompted to provide authentication data or authentication features. To capture the user's authentication data, the mobile terminal 100 comprises a sensor or authentication sensor 120, which can, for example, be integrated into the user interface 118 or implemented as a standalone component. The authentication data can, for example, comprise the user's biometric data, such as: fingerprint data, body geometry data / anthropometric data, such as facial, hand, or ear geometry data, hand line structure data, vein structure data, such as hand vein structure data, iris data, retina data, voice recognition data, and nail bed patterns.The authentication data can, for example, include user knowledge, such as a PIN or password. Furthermore, the authentication data can, for example, include behavioral characteristics or behavioral data of the user, such as movement data of the mobile terminal 100, which are caused by gross and / or fine motor movements of the user when the user carries and / or uses the mobile terminal 100. Appropriate authentication of the user can, for example, be a prerequisite for releasing identity attributes of the electronic identities for reading by a reading computer system. Appropriate user authentication can, on the one hand, ensure that the mobile terminal 100 is being used by an authorized user.Secondly, the provision of authentication data by the user can represent the user's consent to the reading of the identity attributes of the electronic identities by the reading computer system. Finally, the mobile terminal 100 comprises a communication interface 122, such as an antenna, which is configured for contactless or contact-based communication, for example, with the reading computer system. For example, communication with the reading computer system can take place via a network, such as an intranet or the Internet.
[0108] Figure 2shows an exemplary method for releasing one or more identity attributes of one or more electronic identities stored on a mobile device for a reading computer system. A plurality of electronic identities is stored on the mobile device. The prerequisite for releasing the identity attributes is successful authentication of the reading computer system. In block 300, the mobile device receives a read request from the reading computer system for reading one or more identity attributes of one or more types of electronic identities to be read, together with a read certificate from the reading computer system. The read certificate defines read rights of the reading computer system to identity attributes of a plurality of different types of electronic identities. In block 302, a central authentication of the reading computer system takes place.This authentication includes validating a signature of the read certificate using a root certificate stored on the mobile device.
[0109] The central authentication of the reading computer system is carried out, for example, by an operating system of the mobile device. The operating system has, for example, access to a security element of the mobile device in which the root certificate for validating the read certificate is stored. For example, the central authentication of the reading computer system is carried out by an application installed on the mobile device. The authenticating application, for example, does not have access to a security element of the mobile device. In this case, the application includes, for example, the root certificate for validating the read certificate. Furthermore, the entire application or at least a part of the application comprising the root certificate is signed. A prerequisite for carrying out central authentication by the corresponding application is, for example, a successful integrity check of the root certificate.This can be done, for example, by verifying the corresponding signature. For example, the authenticating application can have access to a security element of the mobile device. For example, the application can be assigned an applet that is installed in a sub-security domain of the corresponding security element of the mobile device. The application can use the applet during the authentication of the reading computer system. For example, the root certificate for validating the reading certificate is stored in the sub-security domain of the corresponding security element.
[0110] For example, the read certificate includes a public cryptographic key of an asymmetric key pair of the reading computer system. This public cryptographic key of the reading computer system is extracted from the read certificate during central authentication. A random challenge, for example in the form of a random number, is generated. This random challenge is sent to the reading computer system, and a response is received from the reading computer system in response to the challenge. This response includes, for example, a signature of the previously sent challenge, which was created by the reading computer system using a private cryptographic key of the asymmetric key pair of the reading computer system, which belongs to the extracted public cryptographic key, as the signature key.The mobile device validates the challenge signature provided as a response, using the previously sent challenge as a reference value and the extracted public cryptographic key as the signature verification key. For example, the mobile device decrypts the response or the signed challenge using the extracted public cryptographic key and compares the result with a hash value of the previously sent challenge.
[0111] In block 304, the mobile device or the element of the mobile device performing the central authentication determines a group of electronic identities comprising those electronic identities stored on the mobile device that belong to one of the types of electronic identities for which the read certificate defines read rights. This group therefore includes, for example, all electronic identities of the mobile device for which the reading computer system has read rights. In block 306, those electronic identities within the group determined in block 304 that belong to one of the types of electronic identities to be read according to the read request are identified. Thus, for example, all electronic identities of the mobile device that are to be read and for which the reading computer system simultaneously has or can prove read rights can be identified.In block 308, the element of the mobile device executing the central authentication of the reading computer system sends, upon successful authentication, an authentication confirmation to all applications of the mobile device that manage an identified electronic identity. This confirms the reading rights of the reading computer system to the corresponding electronic identities to the corresponding applications or the corresponding applications or the electronic identities managed by the corresponding applications. In the case of central authentication by an element, such as the operating system or an application, that has access to a security element, the authentication confirmations are signed, for example, by the authenticating element. A corresponding signature key, e.g.A private cryptographic key, for example, is made available to the authenticating element by the corresponding security element.
[0112] In block 310, the applications that receive the authentication confirmations from the central authentication, for example, perform an authentication of the corresponding electronic identity for each of the identified electronic identities using a sub-security domain of the corresponding electronic identity on a security element of the mobile device. During the authentication process, for example, a public cryptographic key of an asymmetric key pair assigned to the application or the electronic identity is sent to the reading computer system. A private cryptographic key of the asymmetric key pair is stored in the sub-security domain assigned to the application or the electronic identity.Using an applet installed in the sub-security domain, a secret shared with the reading computer system is calculated using the private cryptographic key of the application or electronic identity and an ephemeral public cryptographic key received from the reading computer system. For example, a first copy of the corresponding ephemeral public cryptographic key was already received by the reading computer system during the central authentication of the reading computer system by the authenticating element of the mobile device. For example, in response to the reading computer system sending the public cryptographic key assigned to the application, the application using the applet receives a second copy of the ephemeral public cryptographic key. These two copies are compared.For example, to create the shared secret, a match between both copies is necessary.
[0113] By receiving the public cryptographic key of the asymmetric key pair assigned to the application or electronic identity, the reading computer system is also enabled to calculate the shared secret. To do this, the reading computer system uses, for example, the corresponding public cryptographic key and an ephemeral private cryptographic key of the reading computer system that corresponds to the ephemeral public key.
[0114] Furthermore, the applet generates, for example, a random number. This random number is used together with the shared secret, for example, to calculate an authentication key, such as a key for generating a message authentication code, to secure the authenticity of data exchanged during communication between the application using the applet and the reading computer system. Furthermore, the shared secret is used, for example, to calculate a symmetric cryptographic key, which can be used to encrypt the data exchanged during communication between the application using the applet and the reading computer system. In particular, the authentication key and the symmetric cryptographic key can be used to cryptographically secure the identity attributes to be read.
[0115] The applet further generates an authentication token using the authentication key and the ephemeral second public cryptographic key of the reading computer system. This authentication token is sent to the reading computer system along with the random number. The reading computer system can use the received random number to also calculate the authentication key and the symmetric cryptographic key. Using the thus calculated authentication key and the ephemeral second public cryptographic key, the reading computer system can validate the received authentication token. For example, the reading computer system can calculate the authentication token itself and compare the result with the received authentication token. If there is a match, the authentication token and the random number are considered validated.
[0116] Finally, in block 312, the individual applications managing electronic identities from which identity attributes were requested can cryptographically secure the requested identity attributes using the respective authentication key and the symmetric cryptographic key for the corresponding electronic identity, i.e., calculate and encrypt a MAC code. The corresponding, for example, identity-specific, authentication keys and symmetric cryptographic keys are each provided by the applet associated with the corresponding electronic identity. The identity attributes thus cryptographically secured are sent to the reading computer system, which can validate the sent identity attributes using the also calculated, for example, identity-specific, authentication keys and symmetric cryptographic keys.Using the symmetric cryptographic keys, the identity attributes can be decrypted and verified for authenticity using the authentication keys.
[0117] Figure 3shows an exemplary method for centrally authenticating a reading computer system 200 by an authenticating element 111 of a mobile terminal. The authenticating element 111 can be, for example, the operating system of the mobile terminal, which has access to a security element, or an application of the mobile terminal, which has access to a security element. Alternatively, the authenticating element 111 can also be, for example, an application of the mobile terminal, which does not have access to a security element. In step 400, the read request of the reading computer system 200 is received with a read certificate. In step 402, a public cryptographic key of the reading computer system 200 is extracted from the read certificate.The validity of the public cryptographic key is verified by the validity of the read certificate, which can be verified using a root certificate. In step 404, a challenge is generated for the reading computer system 200, which is, for example, a random number. In step 406, the challenge is sent to the reading computer system 200, which generates a response using the challenge in step 408. For example, the reading computer system 200 generates a signature of the received challenge with a private cryptographic key. The signature can include, for example, additional variables, such as an additional random number sent by the authenticating element 111. In step 410, the authenticating element 111 receives the response from the reading computer system 200. In step 412, the authenticating element 111 validates the response.For example, the signature is verified using the cryptographic key extracted in step 402 as the signature verification key. If additional variables have been included in the signature, such as an additional random number, these are also used. If the signature verification is successful, the reading computer system 200 is considered authenticated. In step 414, the authenticating element 111 generates authentication confirmations for all applications 108, 109 of the mobile terminal, each of which manages an electronic identity for which identity attributes are requested and for which the reading computer system 200 has read permission. In step 416, the authentication confirmations are sent to the corresponding applications 108, 109.
[0118] Figure 4shows a method for authenticating applications of the mobile terminal device which manage an electronic identity for which identity attributes are requested, or of the corresponding electronic identity. Corresponding authentication takes place, for example, for each application 108, 109 or each electronic identity of the mobile terminal device for which identity attributes are requested. In step 500, the applet 115, 117 or the application assigned to the applet 115, 117 sends a public cryptographic key K PU of an asymmetric key pair assigned to the application or to the electronic identity managed by the application to the reading computer system 200. In step 502, the applet 115, 117 calculates a secret S shared with the reading computer system 200 using the private cryptographic key K PR of the application orthe electronic identity managed by the application and an ephemeral public cryptographic key received from the reading computer system 200. K PU ˜ of the reading computer system 200. The corresponding public cryptographic key K PU ˜ of the reading computer system 200 is received, for example, during the authentication of the reading computer system 200. For example, the copy of the ephemeral public cryptographic key received during the authentication K PU ˜ forwarded to the applet. For example, during the authentication of applications 115, 117 or the electronic identities managed by them, a second copy of the ephemeral public cryptographic key K PU ˜ received, which is linked to the copy of the ephemeral public cryptographic key received during the authentication of the reading computer system 200 K PU ˜ In step 504, the reading computer system 200 also calculates the shared secret S. For this purpose, the reading computer system 200 uses, for example, the public cryptographic key K PU sent in step 500 as well as the ephemeral public cryptographic key K PU ˜ belonging ephemeral private cryptographic key K PR ˜ . In step 506, the applet 115, 117 generates a random number RN. In step 508, the applet 115, 117 generates an authentication key K MAC , e.g., a key for generating a MAC code, as well as a symmetric cryptographic key K SYM . The keys K SYM and K MAC serve, for example, to encrypt data sent by the application or applet 115, 117 to the reading computer system, such as identity attributes, and to prove their authenticity, e.g., using a MAC code. In step 510, the applet 115, 117 generates an authentication token T using the authentication key K MAC and the ephemeral public cryptographic key K PU ˜ . In step 512, the authentication token T is sent to the reading computer system 200 together with the random number RN generated in step 506. In step 514, the reading computer system 200 uses the received random number RN together with the shared secret S calculated in step 504 to calculate the authentication key K MAC , e.g., a key for generating a MAC code, as well as the symmetric cryptographic key K SYM . Finally, in step 516, the received authentication token T is encrypted by the reading computer system 200 using the key K MAC and the ephemeral public cryptographic key K PU ˜ validated. For example, the reading computer system 200 also calculates the authentication token T and compares the result with the received authentication token T. If both match, the application or the electronic identity managed by it is successfully authenticated.
[0119] Figure 5shows an exemplary mobile terminal 100 on which one or more application programs 108 are stored, which are, for example, ID application programs. An ID application program 108 manages, for example, one or more electronic identities with identity attributes assigned to the user. For this purpose, it comprises, for example, an ID management module 107 with one or more identities or ID profiles 113. Each of the electronic identities 113 is assigned, for example, an independent security applet 114 in a security element 112 of the mobile terminal 100. Each of the electronic identities 113 is assigned a set of one or more identity attributes. These identity attributes are, for example, each in a sub-security domain, i.e.a memory area of the security element 112, which is assigned to the corresponding security applet 115, and / or stored in encrypted form in a memory of the mobile terminal 100. The cryptographic keys for decrypting the encrypted identity attributes are, in this case, for example, stored in the corresponding security applets 115. The ID application program 108 further comprises, for example, an ID client module 105, via which the ID application program 108 can receive, for example, requests for identity attributes of one of the ID profiles 113 from a reading computer system. In response to the request, for example, via an ID provider service over a network, the ID application program 108 can provide the requested identity attributes after successful central authentication of the reading computer system, provided the user consents.For this purpose, user authentication with the ID application program 108 may be necessary, or proof of successful user authentication by the ID application program 108 using a challenge-response method may be necessary. For this purpose, a security element 110 assigned to the operating system 106 is used. This element, for example, carries out user authentication with an authentication sensor of the mobile terminal 100 and confirms the successful user authentication to the security element 112. This simultaneously counts, for example, as the user's consent to reading the requested identity attributes. For example, the user may have the option of influencing, e.g., changing, the selection of the identity attributes made available for reading via a user interface.
[0120] Figure 6shows an exemplary system 170, which, for example, comprises a mobile terminal 100 connected via a network 150, for example the Internet, to an initialization server 240, a personalization server 220, an ID provider server 200, and / or a service provider server 260. The initialization server 240 comprises a processor 202, a memory 204, and a communication interface 210. Program instructions 208 are stored in the memory 204, and upon execution, the processor 202 controls the initialization server 240 to initialize an applet in the security element 112 of the mobile terminal 100. The applet is assigned, for example, to an application 108, 109 of the mobile terminal 100 or to an electronic identity managed by the corresponding application. For example, to prove write permission to install the applet, the initialization server 240 uses the write certificate 206.
[0121] The personalization server 220 comprises, for example, a processor 222, a memory 224, and a communication interface 230. Program instructions 228 are stored in the memory 224. When executed, the processor 222 controls the personalization server 220 to provide a symmetric key for a challenge-response process between the security elements 110, 112 of the mobile terminal 100. Thus, the initialized applet can be coupled to the security element 110, which performs user authentication using the sensor 120, and thus to the user of the mobile terminal 100. To verify write authorization for writing the symmetric key to a memory area of the security element 112 of the mobile terminal 100 assigned to the applet, i.e., the sub-security domain of the applet, the personalization server 220 uses, for example, the write certificate 226.
[0122] The service provider server 260 comprises, for example, a processor 262, a memory 264, and a communication interface 270. Program instructions 268 are stored in the memory 264. When executed, the processor 262 controls the service provider server 260 to provide services that can be requested and / or used, for example, by the mobile terminal 100 via the network 150. Using services from the service provider server 260 requires, for example, the provision and / or verification of one or more identity attributes of the user. Upon a request for a service from the service provider server 260 by the mobile terminal 100, the service provider server 260 sends an identity attribute request to an ID provider server 200 for reading identity attributes of the user of the mobile terminal 100.The identity attribute request can be sent from the service provider server 260, for example, directly or via the mobile terminal 100 to the ID provider server 200. The identity attributes to be read out are, for example, identity attributes of various electronic identities stored on the mobile terminal 100.
[0123] The ID provider server 200 comprises, for example, a processor 242, a memory 244, and a communication interface 250. Memory 244 stores program instructions 248, which, when executed, cause the processor 242 to instruct the service provider server 260 to read the identity attributes specified in the identity attribute request from a memory of the mobile terminal 100. To this end, the ID provider server 200 establishes a cryptographically secured communication channel with the mobile terminal 100. The cryptographically secured communication channel can, for example, be an end-to-end encrypted communication channel. For example, this requires mutual authentication between the ID provider server 200 as the reading computer system and the applications 108, 109 managing the electronic identities or the corresponding electronic identities.For read access to the identity attributes to be read, the ID provider server 200 uses the applications 108, 109 on the mobile terminal 100, which manage the electronic identities with the identity attributes to be read. The ID provider server 200, as the reading computer system, sends a corresponding read request to the mobile terminal 100. The ID provider server 200 verifies read authorization to read the identity attributes specified in the identity attribute request, for example, with the read certificate 246. The ID provider server 200 sends the read certificate 246, for example, together with the read request. The received read certificate 246 is validated by the mobile terminal 100, for example, during central authentication.Furthermore, read access by the ID provider server 200 to the identity attributes specified in the identity attribute request requires, for example, consent from the user of the mobile terminal 100. To do so, the user must successfully authenticate themselves to the ID application program 108. The mobile terminal 100 authenticates the user, for example, using the sensor 120 and the security element 110 of the operating system 106. The security element 110 confirms the successful authentication of the user to the security element 112 or the applets comprised by it. This can be done, for example, using a challenge-response method. For example, a display device of the user interface 118 shows the user which identity attributes are to be sent to the ID provider server 200, and the user is able to edit this selection.For example, the user can select which of the requested identity attributes are actually sent. Upon successful verification of read authorization or authentication by the ID provider server 200 and successful user authentication, the released identity attributes are sent to the ID provider server 200. For example, the ID provider server 200 signs the received identity attributes and sends them to the service provider server 260. List of reference symbols
[0124] 100 Mobile device 102 Processor 104 Memory 105 ID client 106 Operating system 107 ID management module 108 Application 109 Application 110 Security element 111 Authenticating element 112 Security element 113 Electronic identity 114 Sub-security domain 115 Applet 116 Sub-security domain 117 Applet 118 User interface 120 Authentication sensor 122 Communication interface 150 Network 170 System 200 Initialization server 202 Processor 204 Memory 206 Write certificate 208 Program instructions 210 Communication interface 220 Personalization server 222 Processor 224 Memory 226 Write certificate 228 Program instructions 230 Communication interface 240 ID provider server 242 Processor 244 Memory 246 Read certificate 248 Program instructions 250 Communication interface 260 Service provider server 262 Processor 264 Memory 266 Program instructions 270 Communication interface
Claims
1. A method for releasing one or more identity attributes of one or more electronic identities (113) stored on a mobile terminal (100) for a reading computer system (200), wherein a plurality of electronic identities (113) is stored on the mobile terminal (100), wherein the release of the identity attributes requires successful authentication of the reading computer system (200), wherein the authentication of the reading computer system (200) comprises: • receiving a read request from the reading computer system (200) for reading one or more identity attributes of one or more types of electronic identities to be read, together with a read certificate (246) of the reading computer system (200), wherein the read certificate (246) defines read rights of the reading computer system (200) to identity attributes of a plurality of different types of electronic identities, • centrally performing authentication of the reading computer system (200), wherein the authentication comprises validating a signature of the read certificate (246) using a root certificate stored on the mobile terminal (100), • upon successful authentication of the reading computer system (200), determining a group of one or more electronic identities (113) with those electronic identities (113) stored on the mobile terminal (100) that belong to one of the types of electronic identities for which the read certificate (246) defines read rights, • identifying one or more electronic identities (113) within the particular group of electronic identities (113) belonging to one of the types of electronic identities to be read out according to the read request, • sending authentication confirmations to one or more applications (108, 109) installed on the mobile terminal (100), each of which manages one or more of the identified electronic identities (113), thereby confirming read rights of the reading computer system (200) to the corresponding electronic identities (113).
2. The method according to claim 1, wherein the authentication confirmations each comprise an indication of those identity attributes of the identified electronic identities (113) which are managed by the application (108, 109) to which the corresponding authentication confirmation is sent, and for which the read certificate (246) defines read rights of the reading computer system (200).
3. The method according to any one of the preceding claims, wherein the central authentication of the reading computer system (200) is carried out with the validation of the read certificate (246) by an operating system (106) installed on the mobile terminal (100).
4. The method according to claim 3, wherein the authentication is performed by the operating system (106) using a security element (110) of the operating system (106) in which the root certificate for validating the read certificate (246) is stored.
5. The method according to claim 4, wherein the authentication confirmations are signed with a private cryptographic key associated with the operating system (106) and stored in the security element (110) of the operating system (106).
6. The method according to any one of claims 1 to 2, wherein the central authentication of the reading computer system (200) with the validation of the read certificate (246) is performed by an application (108, 109) installed on the mobile terminal (100).
7. The method according to claim 6, wherein applets (115, 117) are associated with the application (108, 109) and are installed in a sub-security domain (114, 116) of a security element (112) of the mobile terminal (100) associated with the application (108, 109), wherein the authentication is performed using the applet (115, 117), wherein further the root certificate for validating the read certificate (246) is stored in the sub-security domain (114, 116) of the security element (112) of the mobile terminal (100), wherein the authentication confirmations are preferably signed with a private cryptographic key assigned to the application (108, 109), which key is stored in the sub-security domain (114, 116) of the security element (112) of the mobile terminal (100) assigned to the application (108, 109), or wherein the application comprises the root certificate for validating the read certificate (246), wherein the entire application or a part of the application comprising the root certificate has a signature, and wherein a prerequisite for performing the authentication is a successful integrity check comprising a check of the signature, wherein the authentication confirmations are sent preferably unsigned by the application to the one or more applications installed on the mobile terminal (100), each of which manages one or more of the identified electronic identities (113).
8. The method according to any one of the preceding claims, wherein the read certificate (246) comprises a first public cryptographic key of a first asymmetric key pair of the reading computer system (200), wherein the authentication further comprises: • extracting the first public cryptographic key of the reading computer system (200) from the read certificate (246), • creating a random challenge, • sending the random challenge to the reading computer system (200), • receiving a response from the reading computer system (200), wherein the response comprises a signature of the challenge created using a first private cryptographic key of the first asymmetric key pair of the reading computer system (200), • validating the signature of the challenge using the challenge and the extracted first public cryptographic key.
9. The method according to claim 8, wherein the receiving applications (108, 109) are each assigned one or more applets (115, 117), which are each installed in a sub-security domain (114, 116) of a security element (112) of the mobile terminal (100) assigned to the application (108, 109), wherein one or more of the receiving applications (108, 109) each authenticate themselves to the reading computer system (200), wherein the authentication comprises: • sending a public cryptographic key of an asymmetric key pair associated with the application (108, 109) to the reading computer system (200), wherein a private cryptographic key of the asymmetric key pair is stored in the sub-security domain (114, 116) associated with the application (108, 109), • calculating a secret shared with the reading computer system (200) by the applet (115, 117) associated with the application (108, 109) using the private cryptographic key of the application (108, 109) and an ephemeral second public cryptographic key of the reading computer system (200) received from the reading computer system (200), • generating a random number by the applet (115, 117), • generating a shared authentication key for authenticating information in the course of communication between the application (108, 109) using the applet (115, 117) and the reading computer system (200) using the shared secret and the generated random number, • generating an authentication token by the applet (115, 117) using the authentication key and the ephemeral second public cryptographic key of the reading computer system (200) to authenticate the application (108, 109) using the applet (115, 117) to the reading computer system (200), • sending the random number together with the authentication token for authentication by the reading computer system (200).
10. The method according to claim 9, wherein the authentication confirmations each comprise the ephemeral second public cryptographic key of the reading computer system (200), and / or wherein the application (108, 109) using the applet (115, 117), in response to the sending of the public cryptographic key associated with the application (108, 109), receives from the reading computer system (200) a second copy of the ephemeral second public cryptographic key of the reading computer system (200), which the application (108, 109) compares with the first copy of the ephemeral second public cryptographic key of the reading computer system (200) from the authentication confirmation, wherein a match of both copies is a prerequisite for calculating the shared secret, and / or wherein the calculated authentication key is an identity-specific authentication key, wherein an identifier of the type of electronic identity (113) managed by the application (108, 109) is preferably further used to calculate the authentication key and the identifier is sent together with the public cryptographic key to the reading computer system (200), and / or wherein the authentication key is a key for generating a message authentication code, wherein the authentication token is a MAC code of the random number generated using the authentication key.
11. The method according to any one of claims 9 to 10, wherein the applet (115, 117) further generates a symmetric cryptographic key using the shared secret and the random number for encrypting the communication between the application (108, 109) using the applet (115, 117) and the reading computer system (200).
12. The method according to claim 11, wherein the calculated symmetric cryptographic key is an identity-specific symmetric cryptographic key.
13. The method according to claim 12, wherein an identifier of the type of electronic identity (113) administered by the application (108, 109) is further used to calculate the symmetric cryptographic key.
14. The method according to any one of the preceding claims, wherein the reading computer system (200) is a server which communicates with the mobile terminal (100) via a network (150), or wherein the reading computer system is a local computer system which communicates with the mobile terminal (100) via a contactless radio link between a communication interface of the local computer system and communication interface of the mobile terminal (100).
15. A mobile terminal (100) comprising a processor (102), a memory (104) and a communication interface (122), wherein a plurality of electronic identities (113) is stored on the mobile terminal (100), wherein the processor (102) is configured to perform a method for releasing one or more identity attributes of one or more of the electronic identities (113) stored on the mobile terminal (100) for a reading computer system (200), wherein the releasing of the identity attributes requires successful authentication of the reading computer system (200), wherein the authentication of the reading computer system (200) comprises: • receiving a read request from the reading computer system (200) for reading one or more identity attributes of one or more types of electronic identities to be read, together with a read certificate (246) of the reading computer system (200), wherein the read certificate (246) defines read rights of the reading computer system (200) to identity attributes of a plurality of different types of electronic identities, • centrally performing the authentication of the reading computer system (200), wherein the authentication comprises validating a signature of the read certificate (246) using a root certificate stored on the mobile terminal (100), • upon successful authentication of the reading computer system (200), determining a group of one or more electronic identities (113) with those electronic identities (113) stored on the mobile terminal (100) that belong to one of the types of electronic identities for which the read certificate (246) defines read rights, • identifying one or more electronic identities (113) within the determined group of electronic identities (113) that belong to one of the types of electronic identities to be read out according to the read request, • sending authentication confirmations to applications (108, 109) managing one or more identified electronic identities (113), whereby read rights of the reading computer system (200) to the corresponding electronic identities (113) are confirmed.