Identity verification
By decoupling NFC reader operations from decryption and implementing a server-side cryptographic protocol, the method addresses high latency and security issues in NFC-based identity verification, enabling fast and secure remote identity checks on smartphones.
Patent Information
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- IPROOV
- Filing Date
- 2025-09-15
- Publication Date
- 2026-04-22
AI Technical Summary
Existing NFC-based identity verification systems, particularly on smartphones like Apple iPhones, suffer from high read latency, preventing their use in remote and automated identity checks, and are vulnerable to man-in-the-middle attacks, especially when using web apps, which are inherently insecure.
A method that decouples NFC reader operations from decryption processes by implementing a server-side cryptographic protocol, where a server handles resource-intensive data processing and a client acts as a dumb proxy, enabling end-to-end encryption and batched data reading to reduce latency and enhance security.
This approach allows for secure, fast, and reliable remote identity verification using smartphones, minimizing user cost and time, while being immune to man-in-the-middle attacks and supporting a wider range of identity documents without requiring app updates on user devices.
Smart Images

Figure 00000000_0001_ABST 
Figure 00000000_0000_ABST
Abstract
Description
The verification of the true identity of a natural person is becoming essential in an increasing range of contexts. Anti-money laundering regulations require that large transactions, privileged operations and the opening of financial services accounts be attributed to persons whose identities have been adequately established. Security concerns require that persons traveling or entering sensitive installations should not conceal their true identities, so that their past records may first be scrutinized. The most generally accepted source of evidence of the true identity of a person is that issued by governments. In order to issue passports or national identity cards, governments require trusted documentation, adequate corroboration and, if necessary, investigation. In countries where national identity cards do not exist, such as the United States or United Kingdom, reliance is placed on the driving license, and a substantial obligation of due diligence is placed on the Motor Vehicle or Driver administrative bodies that issue driving licenses. Thus, the physical possession of a government-issued identity document (ID) such as a passport, identity card or high-trust driving license is generally considered a trustworthy corroboration of the identity asserted by an individual. In a number of countries, digital identities are being created with the aspiration of being used instead of physical documents. In the European Union, the elDAS Regulations permit the use of compliant digital identities throughout the member states. Normally, to establish an elDAS digital identity in the first place, a person must present themselves together with their government issued identity document, usually in their home member state. The trust vested by the relying party in such a document depends on the document itself being genuine and un-falsified. For this reason, governments have for centuries invested in increasingly sophisticated methods of printing and laminating such documents, in a race to keep ahead of the increasing sophistication of forgers. In the last decade electronic means have been added, with the insertion of microchips into documents complying with the ICAO 9303 standard. Such micro-chips contain the information printed in the document, plus a digital certificate signed by the issuing authority. Under current cryptographic practice, such certificates are considered impossible to forge and hence represent the best possible guarantee of the authenticity of the information contained in the chip, which is readable contactlessly using NFC technology. EP3647977 discloses a method for securely communicating data, comprising initiating a secure communication between a mobile device and a requester using a cryptographic key to verify the user of the mobile device and the requester. At the mobile device, a data store is queried for the requested data attributes and a verification attribute. In response to the request, the requested data attributes and the verification attribute from the data store are provided to the requester, wherein the verification attribute is generated from data items of a physical token such as an identity card, passport or driving licence, the data item including information characterising a biological feature of the user. The verification attribute also indicates that sensor data of a biological feature of the user detected by the mobile device has been matched to the information characterising the biological feature of the user. A distributed ledger, hashgraph or blockchain may be used to store the cryptographic keys and data describing the data attributes. EP3439190 discloses the use of NFC for banking, access control or identification. The NFC-chip contains data verifying the identity of the holder. The data on an NFC-chip is read by an NFC-chip reader, such as a bank terminal, border control gate or access controlled gate comprising an online or stand-alone terminal. Depending on the requirements and environment in which the terminal is operated, this terminal may be trusted or untrusted. If the terminal is trusted, the terminal may require a communication link to a certificate server. If the terminal is untrusted, the terminal requires a link to a server performing all the authentication steps. This server in turn may require a link to a certificate server. To overcome the disadvantage of the conventional NFC-chips and NFC-chip readers in a remote location, EP3539190 discloses a method for communication with an NFC-chip of a user identification document, comprising the steps of: a terminal obtaining protected data from the NFC-chip, wherein obtaining comprises the step of verifying the integrity of the protected data; and a server verifying genuineness of the NFC-chip communicating via the terminal. EP3439190 suffers from the problem that the read latency in such systems is high so that the verification of the NFC chip and the protected data is invariably above 20s. This prevents the use of mobile telephones in the verification process, in particular Apple iPhones, as the verification process will time out in accordance with the design requirements of the iOS operating system with respect to NFC processes. For some countries, fingerprint information is stored in passports in the so-called datagroup 3 area, in which reading is protected by Extended Access Control (EAC). EAC is optional and can only be currently used by EU member states to read biometric data (fingerprint or iris), so that fingerprints in passports can only be read by EU member states. The service that reads fingerprints therefore needs to be operated and controlled by a member state and not a private company. There is, however, an increasing requirement to check the identity of an individual remotely and automatically. Organizations able to permit users to prove their identity remotely, preferably on their now-ubiquitous smartphones, gain an immediate competitive advantage. However, the use of smartphones and similar devices has a number of technical problems. For example, when delivering an SDK to read NFC a lot of crypto libraries are needed due to the number of different NFC implementations for identity documents. It is inherently hard to maintain and secure all platforms. The standard approach in the field of using mobile apps and web apps is inherently insecure and cannot be trusted. It is, for example, possible to read data in the browser debugger for known solutions. There is therefore still a need to provide means to assess the authenticity of an identity document remotely, using the devices available to members of the public alone, in an automated, reliable and fast way in order to minimize cost, in particular to the user being identified, minimize the time required, and maximize the reliability of the result. This is a particular problem with the advent of the “EuroWallet” or EUDI wallet ecosystem in which the PID consists only of name, surname and date of birth, which is insufficient for many purposes for which identification is required. Large scale adoption of biometric applications in border checks is also resource intensive and subject to Al powered frauds. According to the invention there is provided a method of reading encrypted data on an NFC enabled identity document, wherein a key pair is derived by a server using an access control algorithm and data is read from the identity document by a NFC reader using an authentication code, the data being read in batches, with each batch being given a sequence number, wherein the method comprises determining how many bytes of data the NFC enabled identity document returns with each reading call, the server generating a batch of encrypted calls in dependence of the number of bytes and sending the encrypted calls to NFC reader, wherein the reader executes the calls in sequence, the encrypted data being returned in batches for decryption server side to thereby enable authentication of the identity document. Preferred aspects of the invention can be found in the sub-claims. The invention splits the NFC reader protocol into a separate server and a client component. The server component does the resource intensive data processing and handles the cryptographic processes. The client component can then be a dumb proxy that only sends commands to the NFC chip. The solution of the invention provides a solution for a web based NFC to read passports and other identity documents. Although WebNFC is known, it can currently only deal with simple tags. The approach of the invention provides a protocol where security relies on the server. This can then be certified for authentication purposes, which enables a wider number of use cases than the simple EuroWallet basic case. When a service provider encounters a new document using a new twisted cryptographic solution, the approach of the invention requires only change in one place, i.e. on the server, rather than an app on the user’s device. The solution of the invention can be advantageously immune to man in the middle type attacks as the communication can be end-to-end encrypted. This advantageously provides a smoother or easier check in process for passengers. It also advantageously enables remote verification, securely binding the fingerprint to the identity (and the face). An exemplary embodiment of the invention will now be described in greater detail with reference to the drawing in which: Fig. 1 shows a sequence diagram Fig. 2 shows a second sequence diagram. Verifiable credentials are a digital representation of a person’s identity and credentials, such as their name, date of birth, educational qualifications, work experience, and more. Unlike traditional identity documents like passports or a driver’s licence, verifiable credentials are stored digitally and can be easily accessed and verified online. They are designed to be tamper-proof and secure, making it difficult for fraudsters to falsify or alter them. There are three fundamental roles when it comes to utilizing verifiable credentials: the Issuer, which is a person or organization that issues verifiable credentials such as a government department issuing a national ID or a college issuing a diploma to a person; a holder: which is a person or organization that owns or holds the verifiable credential in their digital wallet and a verifier, who is the person or organization validating or authenticating the credential like a security agent at the airport checking your passport. The digital wallet can be stored on a user’s smartphone or other handheld device such as a tablet or, alternatively, it would be possible to hold the information in a web wallet. A digital or web wallet is an app or secured storage which contains data, protected biometrically or by other access features of the platform, that can enable a user to interact with other services, in which the app is the only app that can access the data within the app. Many identity documents are provided with an NFC readable chip on which the verifiable credentials are stored in an encrypted manner. The encryption tends to be implemented by the document provider and so there are a very large number of implementations. Smartphones, smart watches and tablets are now routinely NFC enabled. This enables them to exchange small bits of data with other devices and read NFC-equipped cards over relatively short distances, the most common application being payments. Figure 1 shows an exemplary sequence diagram showing the communication sequence the chip containing the verifiable credentials, the NFC reader, which can be an NFC enabled smart phone or device, and the server. The algorithm to read NFC has two parts: the first comprises authentication using an access control protocol. Examples of access control protocols include Supplementary Access Control, which is a set of security features defined by the International Civil Aviation Organisation (ICAO) for protecting data contained in electronic travel documents (e.g. electronic passports) such as BAC (Basic access control) or PACE (Password Authenticated Connection Establishment). Use of the access control protocol enables the server to derive a symmetric key pair. The second part comprises the reading of encrypted data stored on the chip. The encrypted data includes verifiable credentials, which can be used to authenticate the document and enable a user to access properties or services. The NFC reader decouples the reading of the encrypted data from the decryption and so can be a relatively simple application. By batching the data, the latency issues caused by the decryption are overcome. MAC, Message Authentication Code, is used with a sequence number to read the encrypted data. After determination of how many bytes the chip returns when reading, a batch of encrypted calls is generated and sent to the client to execute in sequence. The encrypted data is then returned and decrypted server side. In a first step of an exemplary embodiment, the NFC Reader pings the server to ensure server availability and receives a reply from the server. The NFC Reader then sends a request to the NFC chip to select the master file on the chip and on receipt of a response sends a select request and requests to read the binary code on the chip. When the reader has received the binary code, the information is tagged and provided to the server. The reader then selects the passport application and receives a response and then provides the MRZ (machine readable zone) key to the server. The server then sends a BAC (basic access control) Challenge to the reader, which transmits the Bac Challenge to the Chip and receives its response. The BAC Challenge Response is then forwarded to the Server. The server can then authenticate the BAC Challenge and generate a Mutual Authentication. This is provided via the Reader to the chip, which provides its response, which is then provided to the server. In the event that the response is positive, the server will then generate session keys for this session, which are provided to the NFC Reader. The NFC Reader then requests to read DataGroup COM The server then requests to Read the Header via the NFC Reader to the NFC chip, which then provides its response, which is transmitted to the Server. The Server then requests via the NFC Reader to read the protected binary. The response from the chip is then provided to the server. To reduce latency, websocket can be used to provide the communication protocol between the server and the NFC Reader. These steps are then repeated five times in this example as the data is read in batches on the chip. The number of batches will depend on how many bytes the chip returns in each message as different chips return different numbers of bytes, up to 56 bytes. The server is then able to authenticate the document using the decrypted data and confirm the authentication and provide the document details to the NFC Reader. The solution enables the encrypted verifiable credentials on a passport or other identity document to be read without the data being available in a non secure browser environment. In a further embodiment illustrated in Figure 2, it would be possible to implement protected access (eg fingerprints etc) if the backend server is run by, for example, the passport issuing authority. This authority can in turn use another mechanism to share such data only with certified apps. This protocol would also enable secure issuance of Digital Passports, DTCs by the issuer of the physical passport. In the example in Figure 2, a user wishes to verify their fingerprint, for example for travelling to another country. The fingerprint is preferably scanned using the user’s mobile phone but it would be possible to use other devices. In this case the user’s identity wallet, which will typically be stored on the user’s smart phone, requests verification of the fingerprint from a service provider and sends the request to a service provider server. The service provider sends a request token requesting remote reading to a further server controlled by the State or identity document issuing authority. This further or State server provides a return token to the service provider server, which provides the return token to the identity wallet. The identity wallet then presents the token to the State server to perform a remote fingerprint reading. The State server then establishes an encrypted channel to the identity wallet using the Extended Access Control. The State server then can read the fingerprint stored in the identity wallet in accordance with Extended Access Control and then caches the fingerprint. When the reading is complete a result token is returned. The identity wallet then provides the result token to the service provider server. The service provider server then asks for a comparison of the scanned and read fingerprint and supplies the result token. The State server then provides the result of the comparison to the service provider. The service provider can then enable pre-journey enrolment for border control without exposing sensitive ePassport data. The use of the term verifiable credential includes, but is not limited to, those defined by the Worldwide Web Consortium (W3C), the Internet Engineering Task Force (IETF) and mobile Documents (mDocs) as described in the International Standards Organization (ISO) 18013-5 guidelines. The various components of the system described herein may be implemented as a computer program using a general-purpose computer system. Such a computer system typically includes a main unit connected to both an output device that displays information to an operator and an input device that receives input from an operator. The main unit generally includes a processor connected to a memory system via an interconnection mechanism. The input device and output device also are connected to the processor and memory system via the interconnection mechanism. One or more output devices may be connected to the computer system. Example output devices include, but are not limited to, liquid crystal displays (LCD), plasma displays, OLED displays, various stereoscopic displays including displays requiring viewer glasses and glasses-free displays, cathode ray tubes, video projection systems and other video output devices, loudspeakers, headphones and other audio output devices, printers, devices for communicating over a low or high bandwidth network, including network interface devices, cable modems, and storage devices such as disk, tape, or solid state media including flash memory. One or more input devices may be connected to the computer system. Example input devices include, but are not limited to, a keyboard, keypad, track ball, mouse, pen / stylus and tablet, touchscreen, camera, communication device, and data input devices. The invention is not limited to the particular input or output devices used in combination with the computer system or to those described herein. The computer system may be a general-purpose computer system, which is programmable using a computer programming language, a scripting language or even assembly language. The computer system may also be specially programmed, special purpose hardware. In a general-purpose computer system, the processor is typically a commercially available processor. The general-purpose computer also typically has an operating system, which controls the execution of other computer programs and provides scheduling, debugging, input / output control, accounting, compilation, storage assignment, data management and memory management, and communication control and related services. The computer system may be connected to a local network and / or to a wide area network, such as the Internet. The connected network may transfer to and from the computer system program instructions for execution on the computer, media data such as video data, still image data, or audio data, metadata, review and approval information for a media composition, media annotations, and other data. A memory system typically includes a computer readable medium. The medium may be volatile or nonvolatile, writeable or nonwriteable, and / or rewriteable or not rewriteable. A memory system typically stores data in binary form. Such data may define an application program to be executed by the microprocessor, or information stored on the disk to be processed by the application program. The invention is not limited to a particular memory system. Time-based media may be stored on and input from magnetic, optical, or solid-state drives, which may include an array of local or network attached disks. A system such as described herein may be implemented in software, hardware, firmware, or a combination of the three. The various elements of the system, either individually or in combination may be implemented as one or more computer program products in which computer program instructions are stored on a non-transitory computer readable medium for execution by a computer or transferred to a computer system via a connected local area or wide area network. Various steps of a process may be performed by a computer executing such computer program instructions. The computer system may be a multiprocessor computer system or may include multiple computers connected over a computer network or may be implemented in the cloud. The components described herein may be separate modules of a computer program, or may be separate computer programs, which may be operable on separate computers. The data produced by these components may be stored in a memory system or transmitted between computer systems by means of various communication media such as carrier signals. Having now described an example embodiment, it should be apparent to those skilled in the art that the foregoing is merely illustrative and not limiting, having been presented by way of example only. Numerous modifications and other embodiments are within the scope of one of ordinary skill in the art and are contemplated as falling within the scope of the invention.
Claims
1. A method of authenticating encrypted data on an NFC enabled identity document, wherein a key pair is derived by a server using an access control algorithm and data is read from the identity document by a NFC reader using an authentication code, the data being read in batches, with each batch being given a sequence number, wherein the method comprises determining how many bytes of data the NFC enabled identity document returns with each reading call, the server generating a batch of encrypted calls in dependence on the number of bytes and sending the encrypted calls to the NFC reader, wherein the reader executes the calls in sequence, the encrypted data being returned in batches for decryption server side to thereby enable authentication of the encrypted data.
2. A method according to Claim 1, wherein the NFC reader sends a request to the NFC chip to select a master file on the chip and on receipt of a response sends a select request and requests to read a code on the chip.
3. A method according to Claim 2, wherein when the reader has received the code, the information is tagged and provided to the server.
4. A method according to any one of Claims 1 to 3, wherein the reader then provides a MRZ (machine readable zone) key to the server.
5. A method according to Claim 4, wherein the server then sends a BAC (basic access control) Challenge to the reader, which transmits the BAC Challenge to the Chip and receives its response.
6. A method according to Claim 5, wherein the BAC Challenge Response is then forwarded to the Server.
7. A method according to any one of Claims 4 to 6, wherein the server authenticates the BAC Challenge and generate a mutual authentication, which is provided via the Reader to the chip, which provides its response, which is then provided to the server.
8. A method according to any one of Claims 1 to 7, wherein in the event that the response is positive, the server will then generate session keys for this session, which are provided to the NFC Reader.
9. A method according to any one of Claims 1 to 8, wherein the Server then requests via the NFC Reader to read the protected code and the response from the chip is then provided to the server.
10. A method according to Claim 9, wherein the data is read in batches on the chip.
11. A method according to Claim 9 or Claim 10, wherein the step is repeated a plurality of times.
12. A method according to Claim 11, wherein the step is repeated 5 times.
13. A method according to any one of Claims 1 to 12, wherein the server then authenticates the document using the decrypted data and provides the document details to the NFC Reader.A
Citation Information
Patent Citations
Electronic passport off-line identification system based on mobile phone NFC and identification method thereof
CN115221489A
Method and system for providing of airport automation service
KR1020100001911A