Terminal and method for determining personal data using an identity document
Patent Information
- Application Number
- EP2021152470
- Authority / Receiving Office
- EP · EP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-01-30
- Filing Date
- 2021-01-20
- Publication Date
- 2026-09-09
- Estimated Expiration
- 2041-01-20
Smart Images

Figure IMGF0001 
Figure IMGF0002 
Figure IMGF0003
Abstract
Description
[0001] The present invention relates to a method for determining personal data using an identity document. The personal data is assigned to the holder of the identity document and includes, for example, the holder's residential address. Furthermore, the invention relates to an end device with computer functionality, which is configured for data transmission to a server and, together with the server, for executing the method according to the invention. The end device with computer functionality is preferably mobile and can, for example, be a smartphone.
[0002] From WO 2012 / 083469 A1, a device for authenticating documents marked with photochromic systems is known. The photochromic security feature exhibits a color change and / or a shape change under the influence of a flash of light. It is further described that the security feature is based on a retinal protein.
[0003] WO 2013 / 034471 A1 describes a device for detecting a document that has a phosphor-based security feature with wavelength conversion properties. This device includes a light-generating device, such as an LED flash unit, which illuminates the security feature with excitation light, and an image-capturing device, such as a digital camera of a mobile communication device, which captures the light emitted by the security feature.
[0004] WO 2013 / 034603 A1 describes a method for verifying a security document with a security feature in the form of a fluorescent printed element. The method involves stimulating the printed element with a light source, causing it to emit electromagnetic radiation that can be detected by a sensor. The detected data is then evaluated by comparing it to predefined data. Specifically, the method is intended to be performed using a smartphone, with the smartphone's flash module serving as the excitation source and the smartphone's camera sensor as the detection unit.
[0005] From EP 2 786 318 B1, an identification document is known which has data arranged in a machine-readable zone and a barcode. The barcode provides a duplicate of the data arranged in the machine-readable zone.
[0006] German patent application DE 10 2013 201 027 A1 discloses a method for authenticating a user to a vending machine. In this method, the vending machine generates a challenge in which a first pattern is encoded. The first pattern is displayed on a screen of the vending machine and optically captured by a user device. The user device then generates a response to the challenge. Additionally, a second pattern, in which the response is encoded, is generated by the user device, displayed, and optically captured by the vending machine for verification.
[0007] German patent DE 103 34 012 A1 describes a data carrier for the identification of persons and documents. All of a person's data is linked to their biometric characteristics for identification purposes, compressed, and stored on the data carrier in an encrypted two-dimensional barcode. The personal data is digitally pre-processed using the pixels of a digital photograph, the person's biometric data, and their signature. This data is then compressed, encrypted, and stored in a character format as a two-dimensional barcode printed on the data carrier. Data retrieval is performed using separate software. Each data record can be stored in a central database and accessed by authorized personnel in special cases, such as a name change.
[0008] German patent application DE 10 2016 103 694 A1 describes a security document, which could be, for example, an identity card. The security document has a first security element comprising visually recognizable and machine-readable information. This first piece of information includes personalized data relating to the holder of the security document. A second security element of the security document comprises machine-readable information that can be used to verify the first piece of information. This second piece of information is, in particular, a key for decoding the first piece of information or a password for database access. The second security element is preferably designed as a two-dimensional barcode. To authenticate the security document, the first piece of information is read from the first security element, and the second piece of information is read from the second security element.The first piece of information is verified using the second piece of information.
[0009] The Federal Republic of Germany uses identity cards as official documents for proving the identity of German citizens. The identity card states the cardholder's residential address. If the cardholder's residential address changes, a sticker with the updated address is usually affixed to the identity card. This procedure is cumbersome and could compromise confidence in the integrity of the identity card. One objective of the present invention, building on the prior art, is to enable the reliable identification of personal data using an identity document, even after changes to the data.
[0010] The aforementioned problem is solved by a method according to the attached claim 1.
[0011] The method according to the invention serves to determine personal data using an identity document. A person requesting the personal data receives the personal data provided they have the original identity document in their possession, whereby the receipt of the personal data may be subject to further conditions. The personal data is assigned to the holder of the identity document. Thus, the personal data relates to the holder of the identity document.
[0012] In one step of the process, a security feature on the identity document, consisting of a fluorescent material, is checked to verify its authenticity. This check determines whether the requester has received the original document. The check will fail if the requester only has a copy or if the document is a forgery. The security feature can be checked by a machine. The check is performed using a testing device, such as a smartphone equipped with a suitable application (app). All necessary temporary device settings are configured by this app and reset after the check is complete.
[0013] In a further step of the process, a code located on the identity document is read. This machine-readable code represents an identifier for the identity document holder. The identifier allows for a unique assignment to the identity document holder. The identifier is determined from the read code, either directly at the requesting party's location or remotely at a storage location containing personal data. The reading is performed using a reading device, such as the same smartphone used for the previously mentioned verification step.
[0014] In a further step of the process, the personal data of the ID card holder is requested. This request—and preferably also the verification result—is sent to a server on which the ID card holder's personal data is stored. The server can be located remotely from the requesting party. A data connection is established between the server and the requesting party, enabling data exchange between them. To request the personal data, the identifier—preferably together with the verification result—is transmitted to the server. In embodiments of the inventive method, the identifier can be further encrypted within the code, so that the code, for example, an image of the code, is transmitted to the server, and the server then determines the identifier from the extracted code. This request step can again be performed using a smartphone.
[0015] The result of the security feature check must be known to the server. In embodiments of the method according to the invention, the security feature is checked at the requesting party, and the result of the check is transmitted to the server. In other embodiments, the security feature is only partially checked at the requesting party, so that information is transmitted to the server, which then uses this information to perform a final security feature check.
[0016] In a further step of the process, the personal data associated with the identifier is transferred from the server to the requester if the security feature check is successful. If the security feature check fails, the server denies the requester access to the personal data, and the personal data is not transferred from the server to the requester. The transfer of the personal data preferably takes place to a display device, which may also be a smartphone, in particular the same device used for the previously mentioned steps.
[0017] A particular advantage of the method according to the invention is that personal data can be determined from an identity document, even if the data has changed, without the identity document itself being altered or renewed. For example, an identity card can continue to be used even if the personal data, such as a family name, title, or address, has changed. No sticker is required on the identity card.
[0018] The security feature is preferably formed by a pattern. The security feature is preferably made of a different material than the rest of the identification document.
[0019] The machine-readable code and the security feature are preferably arranged side by side on the identification document. Alternatively, the machine-readable code and the security feature are preferably arranged one above the other on the identification document.
[0020] The safety feature comprises or is formed by a phosphor. The phosphor is excitable. Upon excitation, it emits electromagnetic radiation, such as light. The phosphor is preferably formed by a conversion phosphor. The conversion phosphor is excitable by electromagnetic radiation in a first wavelength range. Upon excitation, it emits electromagnetic radiation in a second wavelength range.
[0021] Preferably, the phosphor has a body color similar to the document, so that the security feature is not perceptible in its unexcited state. The security feature can be produced as an invisible part of the machine-readable code, so that a correct code can only be read by activating the phosphor.
[0022] In preferred embodiments of the method according to the invention, the step of checking the security feature on the identification document comprises several sub-steps. In one sub-step, the phosphor is irradiated with electromagnetic radiation to excite it. The phosphor is preferably a conversion phosphor. The excited phosphor then emits radiation, which is received. In a further sub-step, it is checked whether the received radiation has the characteristics that correspond to the specific phosphor excited by the electromagnetic radiation, i.e., whether the received radiation has the characteristics that would be expected when this phosphor is excited with the electromagnetic radiation used.This verifies whether the security feature formed by the fluorescent material is actually present, so that if the test is positive, the authenticity of the identity document can be trusted.
[0023] The step of verifying the security feature on the identification document can be performed partly by the requesting party, who has the document in their possession, and partly by the server. Specifically, the requesting party is irradiated with electromagnetic radiation and the radiation emitted by the excited phosphor is received. A recording of the received radiation is transmitted to the server. The final check to determine whether the received radiation exhibits the characteristics corresponding to the phosphor excited by the electromagnetic radiation is then performed by the server. Alternatively, preferably, the entire verification process is performed by the requesting party, but preferably without the requesting party being able to trace it.
[0024] The characteristics of the received radiation preferably include a temporal profile of the received radiation and / or spectral properties of the received radiation. The temporal profile of the received radiation represents a characteristic behavior of the phosphor and is—especially on shorter timescales—dependent on the temporal profile of the electromagnetic excitation radiation directed at the phosphor. The temporal profile of the electromagnetic radiation directed at the phosphor is preferably specified by the server and is preferably unknown to the requesting party. This prevents manipulation by the requesting party.
[0025] The step of verifying the security feature on the identification document comprises further sub-steps. Parameters of the electromagnetic radiation with which the phosphor is to be irradiated are transmitted. These parameters are transmitted from the server to the requesting party. These parameters are preferably defined individually by the server for each query. The parameters preferably describe a temporal profile of the electromagnetic radiation to be directed at the phosphor and / or spectral properties of the electromagnetic radiation to be directed at the phosphor. The phosphor is irradiated with the electromagnetic radiation containing the parameters in order to excite it. It is then checked whether the received radiation exhibits the characteristics that correspond to the phosphor excited by the electromagnetic radiation containing the parameters.whether the received radiation exhibits the characteristics that are to be expected when the phosphor is excited with the electromagnetic radiation used that has the parameters.
[0026] The electromagnetic radiation with which the phosphor is irradiated is preferably formed by light. The electromagnetic radiation with which the phosphor is irradiated is preferably formed by white light. Alternatively, the electromagnetic radiation with which the phosphor is irradiated preferably comprises visible light, ultraviolet radiation, and / or infrared radiation.
[0027] The parameters preferably describe the temporal progression in the form of a flash sequence of light illuminating the phosphor. The flash sequence preferably represents an irregular sequence of flashes.
[0028] The light used to excite the phosphor is preferably generated by a flash lamp in a smartphone or tablet computer. The phosphor is thus also irradiated by the smartphone or tablet computer. The radiation emitted by the excited phosphor is also preferably received by the smartphone or tablet computer. The radiation emitted by the phosphor is preferably formed by light, ultraviolet radiation, and / or infrared radiation.
[0029] Reading the code on the identity document is also preferably done using a smartphone or tablet computer.
[0030] The identifier is preferably transmitted to the server via smartphone or tablet. Preferably, a recording of the received radiation is also transmitted to the server via smartphone or tablet to verify the security feature.
[0031] The identification of the identifier from the read code is preferably carried out by the smartphone or tablet computer, or alternatively preferably by the server.
[0032] The personal data is preferably transferred from the server to the smartphone or tablet computer. The smartphone or tablet computer is preferably located in the possession of the requesting party.
[0033] Instead of a smartphone or tablet, another mobile device with computer functionality can preferably be used. Alternatively, a stationary device with computer functionality, such as a PC, is preferred.
[0034] In further embodiments, the server also performs the steps of checking the security feature on the identity document, reading the code on the identity document and determining the identifier from the read code.
[0035] The identification document is preferably a national identity card. However, it can also be, for example, a driver's license or a social security card. In addition to the machine-readable code, the identification document preferably also includes information that is readable by humans, such as text and a photograph.
[0036] The code is preferably not cognitively decipherable by humans. The code is preferably a barcode. However, other codes, such as a QR code, can also be used. The code is preferably applied to the identification document by a laser, an inkjet printer, or another type of printer, or integrated into the identification document as a patch.
[0037] Since a particular advantage of the method according to the invention is that the personal data can be determined using the unaltered identity document even if it has changed shortly beforehand, the method according to the invention preferably also includes a step in which, when the identity card holder's personal data changes, the identity card holder's personal data stored on the server is updated. For this update, the security feature is preferably also checked and the identifier transmitted to the server.
[0038] The authorization of the person requesting the update of personal data is also given priority.
[0039] The disclosed terminal device has computer functionality, so that it is, in a broader sense, a computer. The terminal device according to the invention is configured for a data connection with a server, so that data can be exchanged between the terminal device and the server. The terminal device is configured together with the server to execute the method according to the invention. Preferably, the terminal device is configured together with the server to execute one of the described preferred embodiments of the method according to the invention.
[0040] The terminal device with computer functionality is preferably mobile. This terminal device is preferably a smartphone, a tablet computer, or a laptop. Alternatively, the terminal device is preferably stationary. This stationary terminal device is preferably a PC. This stationary terminal device is preferably a self-service terminal where the cardholder can identify themselves.
[0041] The terminal device is preferably equipped with a light source, e.g., an LED to excite the phosphor, and with a camera for recording the emitted radiation. Alternatively, the excitation light can also be emitted by the terminal device itself.
[0042] The light to stimulate the phosphor forming the safety feature is preferably generated by a monitor of the self-service terminal, for example light blue light.
[0043] Furthermore, a unit formed from the terminal device and the server constitutes an object of the invention.
[0044] Further details, advantages, and developments of the invention will become apparent from the following description of preferred embodiments of the invention, with reference to the drawing. The drawing shows: Fig. 1 a schematic representation of the reverse side of an identity card to be used according to a preferred embodiment of a method according to the invention; Fig. 2 a flowchart of a preferred embodiment of the method according to the invention; Fig. 3 a flowchart of a variation of the Fig. 1 embodiment shown; Fig. 4 a flowchart of a further modification of the one shown in Fig. 1 embodiment shown; Fig. 5 a time course of a according to the in Fig. 4 Fig. 6 shows a sequence of flashes to be generated in the embodiment shown; Fig. 6 shows a flowchart of an authenticity check in a preferred embodiment of the method according to the invention; Fig. 7 shows a flowchart of an address determination in a preferred embodiment of the method according to the invention; Fig. 8 shows a flowchart of a preferred embodiment of the method according to the invention; Fig. 9 shows a flowchart of a modification of the in Fig. 8 embodiment shown; and Fig. 10 a flowchart of a further modification of the one shown in Fig. 8 embodiment shown.
[0045] Fig. 1 Figure 1 shows a schematic representation of the reverse side of an identity card to be used according to a preferred embodiment of a method according to the invention. The identity card is an identification document of the cardholder. The identity card includes, among other things, a passport photo (not shown) of the cardholder and written information (not shown) relating to their identity. According to the invention, the identity card also has a barcode 01 in which a unique identifier of the cardholder is encoded. The identifier is preferably a number. However, the identifier can also be alphanumeric. The barcode 01 replaces the written information regarding the cardholder's residential address. According to the invention, the identity card also has a security feature 02 in the form of a fluorescent material. The security feature 02 is concealed.The phosphor forming the safety feature 02 emits radiation in a specific wavelength range when excited by light.
[0046] Fig. 2 shows a flowchart of a preferred embodiment of the method according to the invention. According to this embodiment, the following is carried out based on the Fig. 1 The identity card shown determines the residential address of the cardholder by a third party if the cardholder identifies themselves with their identity card in front of the third party. The Fig. 1 The displayed identity card is exposed to a series of flashes, preferably using a smartphone (not shown). This process scans the security feature 02 (shown in Fig. 1 ) excited, causing it to emit radiation. This radiation, as well as the barcode 01 (shown in Fig. 1 These are recorded as videos, preferably using a smartphone (not shown). An analysis reveals that the security feature 02 (shown in Fig. 1 If the security feature 02 (shown in the video) is not recognized, the process is stopped. Fig. 1 If the barcode is recognized in the recorded video and verified as genuine, the identifier is taken from the recorded barcode 01 (shown in Fig. 1 The ID is read. Using the identifier, a third party sends a query to a central database stored on a remote server. This is preferably done via a smartphone (not shown), for which a data connection is established between the smartphone and the server. The database contains a link between the identifier and the ID card holder's residential address. The residential address is then transmitted to the third party's smartphone.
[0047] Fig. 3 shows a flowchart of a variation of the in Fig. 1 as shown in the embodiment. After the identifier has been read, the security feature 02 is additionally read (shown in Fig. 1 ) checked for authenticity.
[0048] Fig. 4 shows a flowchart of another variation of the in Fig. 1 in the illustrated embodiment. After the identifier has been read and the request has been transmitted to the database, the server performs a check of security feature 02 (shown in Fig. 1 ) initiated in the form of a challenge. Since the server is verifying security feature 02 (shown in Fig. 1 By defining this, the server prevents third parties from falsifying the authentication process. The server defines the verification of security feature 02 (shown in Fig. 1 ) in particular by showing a flash sequence (shown in Fig. 5 ) defines which light is to be used to illuminate the security feature. Thus, security feature 02 (shown in Fig. 1 ) Radiation according to the excitation by the flash sequence (shown in Fig. 5 ), making manipulation by a third party more difficult.
[0049] Fig. 5 shows a temporal progression of the according to the in Fig. 4 The illustrated embodiment generates a flash sequence. The course of the flash sequence is selected randomly.
[0050] Fig. 6 Figure 1 shows a flowchart for an authenticity check in a preferred embodiment of the method according to the invention. First, it is checked whether images of barcode 01 (shown in Figure 1) are present. Fig. 1 ) and security feature 02 (shown in Fig. 1 ) are available. If these images are not yet available, the recording area may be detected and the images of barcode 01 (shown in Fig. 1 ) and security feature 02 (shown in Fig. 1 ). If the identity card has a personalized feature, the identifier or other personalized characteristic must first be determined. Feature extraction and verification then take place. If necessary, further properties of the identity card are verified. Finally, the verification result is available.
[0051] Fig. 7 Figure 1 shows a flowchart for address determination in a preferred embodiment of the method according to the invention. First, it is checked whether the identifier and the recordings of the barcode 01 (shown in Figure 1) are present. Fig. 1 ) and security feature 02 (shown in Fig. 1 ) are already available. If these images are not yet available, the images of barcode 01 (shown in Fig. 1 ) recorded. If the identifier is not yet available, it is determined. The address is then retrieved from the database using the identifier.
[0052] Fig. 8 shows a flowchart of a preferred embodiment of the method according to the invention with reference to the details in the Figuren 6 and 7 The flowcharts shown illustrate the authentication and address verification process. After an address verification request is submitted, the authentication process begins. If the authentication is successful, the address search is conducted, followed by final approval.
[0053] Fig. 9 shows a flowchart of a variation of the in Fig. 8 as shown in the embodiment. In this modification, the authentication check and the address search are performed simultaneously.
[0054] Fig. 10 shows a flowchart of another variation of the in Fig. 8 as shown in the embodiment. In this further modification, the address search is performed first, followed by the authentication check. Bezugszeichenliste
[0055] 01 Barcode 02 Security feature
Claims
1. A method for determining personal data on the basis of an identity document, wherein the personal data are assigned to an identity document holder of the identity document and wherein the method comprises the following steps: - checking a security feature (02) located on the identity document and comprising a luminescent material by means of a checking device, in order to establish the authenticity of the identity document; - reading, by means of a reading device, a machine-readable code (01) located on the identity document, which code represents an identifier for identifying the identity document holder; - requesting personal data of the identity document holder from a server, for which purpose the identifier is transmitted to the server; and - transmitting the personal data assigned to the identifier from the server to a display device, if the result of checking the security feature (02) is positive, characterized in that the step of checking the security feature (02) located on the identity document comprises the following sub-steps: - transmitting to the checking device parameters of electromagnetic radiation with which the luminescent material is to be irradiated, wherein the parameters are transmitted from the server to a requesting party; - irradiating the luminescent material with the electromagnetic radiation having the parameters, in order to excite the luminescent material; - receiving radiation emitted by the excited luminescent material; and - checking whether the received radiation exhibits characteristics corresponding to the luminescent material excited by the electromagnetic radiation exhibiting the parameters.
2. The method according to claim 1, characterized in that, in the step of requesting personal data of the identity document holder, the result of the step of checking the security feature is also transmitted to the server.
3. The method according to claim 1 or 2, characterized in that the characteristics of the received radiation comprise a temporal profile of the received radiation and / or spectral properties of the received radiation.
4. The method according to any one of claims 1 to 3, characterized in that a temporal profile of the electromagnetic radiation directed at the luminescent material is specified by the server.
5. The method according to any one of claims 1 to 4, characterized in that the parameters of the electromagnetic radiation with which the luminescent material is to be irradiated are individually defined by the server for each individual request.
6. The method according to any one of claims 1 to 5, characterized in that the electromagnetic radiation with which the luminescent material is irradiated is formed by light, wherein the light is generated by a flash of a smartphone or tablet computer configured as the checking device.
7. The method according to any one of claims 1 to 6, characterized in that the radiation emitted by the luminescent material is formed by light, ultraviolet radiation and / or infrared radiation and is received by a camera of a smartphone or tablet computer configured as the reading device.
8. The method according to any one of claims 1 to 7, characterized in that the code is formed by a bar code (01) or a QR code.
9. The method according to any one of claims 1 to 8, characterized in that the luminescent material of the security feature constitutes an invisible part of the machine-readable code in the unexcited state, such that the correct code can only be read after excitation of the luminescent material.
10. The method according to any one of claims 1 to 9, characterized in that, when the personal data of the identity document holder are changed, the personal data of the identity document holder stored on the server are updated.
Citation Information
Patent Citations
Method for authenticating a user to a machine
DE102013201027A1
Data carrier for personal identity documents has all personal identification and biometric data compressed and encrypted into two dimensional bar code and microchip
DE10334012A1
Identification document with machine readable zone and document reader
EP2786318B1
Method and device for authenticating documents marked with photochromic systems
WO2012083469A1
Device for the mobile recognition of a document
WO2013034471A1