Portable Data Carrier Dynamic Identity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data carriers require increased storage, processor power, and data management capabilities with each new service provider application, limiting their flexibility and resource efficiency in transaction systems.

Innovation Solution

A portable data carrier with a security identity that can be dynamically associated with multiple application identities across various service providers, using a cryptographically secured security marking for authentication, allowing the same data carrier to be used across different applications and service providers without the need for separate identities or significant resource upgrades.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a data carrier is equipped with multiple independent applications or identities for different service providers, then the versatility and usability of the data carrier is improved, but the device complexity and resource requirements (storage, processor power, data management) increase

Engineering Contradiction:
ImproveversatilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the identity management functionality by separating the security identity (stored in the data carrier) from the application-specific identities (managed by the authentication server). This allows the data carrier to remain simple while the server handles the complexity of multiple identities and applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication server acts as an intermediary between the data carrier and service providers. It receives the security identity from the data carrier, manages the association with multiple application identities, and facilitates transactions without requiring the data carrier itself to contain multiple identities or complex management logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a data carrier is designed for a single application or identity, then the device complexity is reduced, but the adaptability and usability across different service providers is limited

Engineering Contradiction:
Improvedevice complexityVSAvoidadaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The security identity in the data carrier is designed as a universal identifier that can be associated with multiple application identities on the authentication server. This allows a single simple data carrier to function across multiple applications and service providers, achieving multi-functionality without increasing the complexity of the data carrier itself.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system moves the complexity from the data carrier dimension to the authentication server dimension. The data carrier remains in a simple state while the server provides the extended functionality through dynamic identity association, effectively adding a dimension of flexibility to the system architecture.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Speed

If authentication information is stored and processed locally in the data carrier for each service provider, then the transaction speed is improved, but the storage requirements and data management complexity increase

Engineering Contradiction:
Improvetransaction speedVSAvoidstorage requirements
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The system extracts the storage of multiple application identities and association data from the data carrier and places it on the authentication server. The data carrier only needs to store a single security identity, significantly reducing storage requirements while the server provides fast authentication by maintaining ready-accessible identity associations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11263302B2Transaction system
Publication Date: 2022.03.01 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US11263302B2 patent drawing
  • US11263302B2 patent drawing
  • US11263302B2 patent drawing

AI summary

A method for managing portable data carriers in a system having at least one portable data carrier, an authentication server, and several service providers systems each including reading devices and a service provider unit. The reading devices may request an authentication information item of the data carrier and relay the authentication information item to the authentication server. The authentication server may authenticate the data carrier on the basis of the authentication information item and establish an application identity associated with the data carrier in the service provider system with the help of the security identity The established application identity associated with the data carrier may be transmitted from the authentication server to the reading device of the service provider system.