Centralized Authentication for Multiple Electronic Identities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for releasing identity attributes of electronic identities stored on mobile devices are complicated and time-consuming, often requiring separate procedures for each application context or electronic identity.

Innovation Solution

A method for releasing identity attributes involves successful authentication of a reading computer system, which includes receiving a read request with a read certificate, validating the signature of the read certificate using a root certificate, and determining the relevant electronic identities with read rights, thereby confirming the reading rights to the corresponding applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate procedures are used for releasing identity attributes for each application context or electronic identity, then cryptographic security is maintained, but the process becomes complicated and time-consuming

Engineering Contradiction:
Improvecryptographic securityVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate authentication procedures into a single centralized authentication process. The reading computer system authenticates once with its certificate, and the mobile terminal determines read rights for multiple electronic identities in that single authentication event, rather than requiring separate procedures for each identity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal authentication mechanism where a single read certificate from the reading computer system can authorize access to multiple different types of electronic identities simultaneously. The authentication confirmation message can contain authorization information for various identity types, making the authentication process multi-functional.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate procedures are used for releasing identity attributes for each application context or electronic identity, then individual authorization is ensured, but the process becomes time-consuming

Engineering Contradiction:
Improveauthorization accuracyVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary determination of read rights during the centralized authentication process. The mobile terminal determines which electronic identities the reading computer system is authorized to access as part of the initial authentication, before any actual identity attribute release occurs. This preliminary action prevents the need for subsequent separate authorization steps for each identity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges multiple authorization checks into a single authentication confirmation message. Instead of performing separate authorization verifications for each electronic identity, the system combines all authorization determinations into one comprehensive authentication process, significantly reducing the time required.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple electronic identities are stored on a mobile device with separate security elements, then cryptographic security is enhanced, but the authentication process becomes more complex

Engineering Contradiction:
Improvecryptographic securityVSAvoidauthentication ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary centralized authentication mechanism that mediates between multiple security elements storing different electronic identities. Instead of requiring direct interaction with each security element separately, the reading computer system presents a single read certificate that the mobile terminal validates centrally, simplifying the user experience while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal authentication interface that works across multiple different types of electronic identities stored in different security elements. The centralized authentication process and authentication confirmation messages provide a unified method for authorizing access to various identity types, making the system easier to operate despite the underlying complexity of multiple security elements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4295533B1Authentication by means of a plurality of electronic identities
Publication Date: 2025.06.11 BUNDESDRUCKEREI GMBH
  • EP4295533B1 patent drawingFigure 1
  • EP4295533B1 patent drawingFigure 2
  • EP4295533B1 patent drawingFigure 3

AI summary

The invention relates to a method for unlocking, for a reading computer system (200), one or more identity attributes of one or more electronic identities (113) stored on a mobile terminal (100). Authentication of the reading computer system (200) comprises: * receiving a read request from the reading computer system (200) with a read certificate (246), * centrally executing the authentication of the reading computer system (200), * determining a group of one or more electronic identities (113) having those electronic identities (113) stored on the mobile terminal (100) which belong to one of the types of electronic identities for which the read certificate (246) defines read permissions, * identifying, within the determined group of electronic identities (113), one or more electronic identities which, according to the read request, belong to one of the types of electronic identities to be read, * sending authentication confirmations to one or more applications (108, 109) installed on the mobile terminal (100) which manage identified electronic identities (113).