Portable Data Carrier Dynamic Identity Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data carriers require increased storage, processor power, and data management capabilities with each new service provider application, limiting their flexibility and resource efficiency in transaction systems.
Innovation Solution
A portable data carrier with a security identity that can be dynamically associated with multiple application identities across various service providers, using a cryptographically secured security marking for authentication, allowing the same data carrier to be used across different applications and service providers without the need for separate identities or significant resource upgrades.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a data carrier is equipped with multiple independent applications or identities for different service providers, then the versatility and usability of the data carrier is improved, but the device complexity and resource requirements (storage, processor power, data management) increase
Solution Approach 1:
The system segments the identity management functionality by separating the security identity (stored in the data carrier) from the application-specific identities (managed by the authentication server). This allows the data carrier to remain simple while the server handles the complexity of multiple identities and applications.
Solution Approach 2:
The authentication server acts as an intermediary between the data carrier and service providers. It receives the security identity from the data carrier, manages the association with multiple application identities, and facilitates transactions without requiring the data carrier itself to contain multiple identities or complex management logic.
2Device complexity
If a data carrier is designed for a single application or identity, then the device complexity is reduced, but the adaptability and usability across different service providers is limited
Solution Approach 1:
The security identity in the data carrier is designed as a universal identifier that can be associated with multiple application identities on the authentication server. This allows a single simple data carrier to function across multiple applications and service providers, achieving multi-functionality without increasing the complexity of the data carrier itself.
Solution Approach 2:
The system moves the complexity from the data carrier dimension to the authentication server dimension. The data carrier remains in a simple state while the server provides the extended functionality through dynamic identity association, effectively adding a dimension of flexibility to the system architecture.
3Speed
If authentication information is stored and processed locally in the data carrier for each service provider, then the transaction speed is improved, but the storage requirements and data management complexity increase
Solution Approach 1:
The system extracts the storage of multiple application identities and association data from the data carrier and places it on the authentication server. The data carrier only needs to store a single security identity, significantly reducing storage requirements while the server provides fast authentication by maintaining ready-accessible identity associations.
Data Source
AI summary
A method for managing portable data carriers in a system having at least one portable data carrier, an authentication server, and several service providers systems each including reading devices and a service provider unit. The reading devices may request an authentication information item of the data carrier and relay the authentication information item to the authentication server. The authentication server may authenticate the data carrier on the basis of the authentication information item and establish an application identity associated with the data carrier in the service provider system with the help of the security identity The established application identity associated with the data carrier may be transmitted from the authentication server to the reading device of the service provider system.


