Portable Data Carrier Activation via Cryptographic Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for activating portable data carriers, such as electronic identity documents, require direct involvement of a central authority and may be vulnerable to misuse, as they often necessitate personal appearance and lack secure, user-friendly activation processes.

Innovation Solution

A method utilizing a first and second portable data carrier to establish a cryptographically secured end-to-end connection for mutual authentication, allowing the second data carrier to activate the first data carrier without a central intermediary, ensuring secure and user-friendly activation, even in a decentralized manner.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central authority is involved in the activation process, then security and authorization are ensured, but the activation process becomes complex and requires direct user involvement

Engineering Contradiction:
ImprovesecurityVSAvoidactivation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the central authority from the activation process, allowing data carriers to activate each other directly through cryptographic authentication. The second data carrier autonomously authenticates the first data carrier using authentication data, eliminating the need for central authority involvement while maintaining security through cryptographic verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The data carriers perform self-authentication and self-activation through cryptographic verification. The second data carrier independently verifies the first data carrier's authenticity using authentication data stored on both carriers, enabling the system to service itself without external intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If personal appearance at a central authority is required, then identity verification is ensured, but user convenience and accessibility are reduced

Engineering Contradiction:
Improveidentity verificationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical system of physical appearance and manual verification with an electronic cryptographic authentication system. The data carriers automatically verify identities through cryptographic protocols, substituting physical presence with digital verification that maintains security while enhancing convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If data is stored on portable data carriers in an active state, then accessibility is improved, but vulnerability to unauthorized access and copying increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-storing authentication data on the data carriers during manufacturing, before the carriers are activated or used. This authentication data is prepared in advance to enable secure cryptographic verification when the carrier is first activated, ensuring security is established before any data access occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the state parameter of the data carrier from inactive to active through a secure activation process. The carrier transitions from a dormant state where data cannot be accessed to an active state where data is accessible, but only after successful cryptographic authentication verifies the carrier's legitimacy.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2473942B1Method to activate a mobile memory
Publication Date: 2019.11.27 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2473942B1 patent drawingFigure 1

AI summary

The invention relates to a method for activating a portable data carrier (1), wherein a user is provided with a first portable data carrier (1) in an inactive state after the user has requested the first data carrier (1) using a second portable data carrier (2) from a central entity, wherein the first and second data carriers (1, 2) have access to authentication data for mutual authentication. In the method according to the invention, a communication connection is established between the first and second data carrier (1, 2), by way of which the first and second data carriers (1, 2) mutually authenticate each other on the basis of the authentication data and establish a cryptographically secure end-to-end connection. Using said end-to-end connection, the second data carrier (2) then activates the first data carrier (1) by transmitting activation data to the first data carrier (1).