Portable Data Carrier Activation via Cryptographic Mutual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for activating portable data carriers, such as electronic identity documents, require direct involvement of a central authority and may be vulnerable to misuse, as they often necessitate personal appearance and lack secure, user-friendly activation processes.
Innovation Solution
A method utilizing a first and second portable data carrier to establish a cryptographically secured end-to-end connection for mutual authentication, allowing the second data carrier to activate the first data carrier without a central intermediary, ensuring secure and user-friendly activation, even in a decentralized manner.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central authority is involved in the activation process, then security and authorization are ensured, but the activation process becomes complex and requires direct user involvement
Solution Approach 1:
The patent extracts the central authority from the activation process, allowing data carriers to activate each other directly through cryptographic authentication. The second data carrier autonomously authenticates the first data carrier using authentication data, eliminating the need for central authority involvement while maintaining security through cryptographic verification.
Solution Approach 2:
The data carriers perform self-authentication and self-activation through cryptographic verification. The second data carrier independently verifies the first data carrier's authenticity using authentication data stored on both carriers, enabling the system to service itself without external intervention.
2Reliability
If personal appearance at a central authority is required, then identity verification is ensured, but user convenience and accessibility are reduced
Solution Approach 1:
The patent replaces the mechanical system of physical appearance and manual verification with an electronic cryptographic authentication system. The data carriers automatically verify identities through cryptographic protocols, substituting physical presence with digital verification that maintains security while enhancing convenience.
3Ease of operation
If data is stored on portable data carriers in an active state, then accessibility is improved, but vulnerability to unauthorized access and copying increases
Solution Approach 1:
The patent applies preliminary action by pre-storing authentication data on the data carriers during manufacturing, before the carriers are activated or used. This authentication data is prepared in advance to enable secure cryptographic verification when the carrier is first activated, ensuring security is established before any data access occurs.
Solution Approach 2:
The patent changes the state parameter of the data carrier from inactive to active through a secure activation process. The carrier transitions from a dormant state where data cannot be accessed to an active state where data is accessible, but only after successful cryptographic authentication verifies the carrier's legitimacy.
Data Source
Figure 1
AI summary
The invention relates to a method for activating a portable data carrier (1), wherein a user is provided with a first portable data carrier (1) in an inactive state after the user has requested the first data carrier (1) using a second portable data carrier (2) from a central entity, wherein the first and second data carriers (1, 2) have access to authentication data for mutual authentication. In the method according to the invention, a communication connection is established between the first and second data carrier (1, 2), by way of which the first and second data carriers (1, 2) mutually authenticate each other on the basis of the authentication data and establish a cryptographically secure end-to-end connection. Using said end-to-end connection, the second data carrier (2) then activates the first data carrier (1) by transmitting activation data to the first data carrier (1).