Telecommunications Chip Card Mediates Secure Identity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation, inadequate data protection, and central storage of sensitive information, particularly in client-based and server-based systems like Microsoft Windows CardSpace and OPENID, respectively.

Innovation Solution

A method for reading attributes from an ID token using a mobile device, which establishes a protected connection via a telecommunications chip card, enabling token-based authentication on devices with limited hardware resources without requiring special software installation, and allowing central management by mobile network providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If token-based authentication procedures with complex cryptographic algorithms are implemented, then security and data protection are improved, but hardware resource requirements (processor and memory) increase

Engineering Contradiction:
Improvedata protectionVSAvoidhardware resources
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server computer system as an intermediary that performs complex cryptographic operations and authentication procedures. The mobile device communicates with this server, which handles the computationally intensive tasks of token-based authentication, allowing the mobile device to benefit from secure authentication without requiring high hardware resources locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/computational burden of cryptographic operations on the mobile device with a software-based solution that leverages the server's processing power. The complex cryptographic algorithms are executed remotely on the server rather than locally on the mobile device, substituting physical hardware requirements with network-based computational resources.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If special software is installed on mobile devices for protected connection establishment, then authentication security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidsoftware installation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a solution where the mobile network provider automatically manages and configures the authentication software on mobile devices. Users do not need to manually install or configure software; the system automatically provisions the necessary authentication capabilities through the telecommunications chip card, making the secure authentication transparent and effortless for end users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mobile network provider acts as an intermediary that bridges the gap between security requirements and user convenience. The provider's infrastructure handles software deployment and management, shielding users from technical complexity while maintaining strong authentication security through the server-mediated communication channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If digital identities are stored centrally in a database, then ease of access is improved, but data protection deteriorates

Engineering Contradiction:
Improveidentity accessVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts sensitive identity data from centralized databases and stores it in distributed, secure locations such as smart cards and secure elements on mobile devices. This distribution eliminates the single point of failure and reduces the attack surface, as identity information is no longer concentrated in one vulnerable database but scattered across multiple secure storage locations that require authentication to access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the centralized identity management system into distributed components: identity attributes are stored on the ID token, authentication credentials are stored on the mobile device and server, and verification logic is distributed across these components. This segmentation prevents any single point from containing all sensitive information, thereby improving data protection while maintaining accessibility through coordinated verification.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2397960B1Method for reading attributes from an ID token via a telecommunications chip card and a server computer system
Publication Date: 2018.08.08 BUNDESDRUCKEREI GMBH
  • EP2397960B1 patent drawingFigure 1
  • EP2397960B1 patent drawingFigure 2
  • EP2397960B1 patent drawingFigure 3a

AI summary

The method involves performing authentication of a user (102), and assigning a telecommunication smart card (300) with an identifier to the user. A protected connection (172) is provided between an identity-token and an identity provider computer system (136), where the connection is produced by interaction of the smart card with a server computer system (306). The provider computer system is authenticated over the protected connection. A read access of the computer system for the token is provided based on successful authentication of the user and the computer system. Independent claims are also included for the following: (1) a mobile device with a smart card (2) a server-computer system with a processor (3) a computer program product with instructions for performing a method for reading an attribute stored in an identity-token.