Digital ID Proof Issuance With Dual-Access Attribute Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity verification systems lack robust security measures to prevent unauthorized access and misuse of biometric data, particularly digital photographs, which are essential for secure digital identities.
Innovation Solution
A dual-access mechanism is implemented for digital identity verification, requiring successful authentication of the ID token holder and a requesting computer system for the first attribute group, and the use of an access key derived from machine-readable details for the second attribute group, ensuring that both groups of attributes are accessed through different cryptographic protocols and hardware components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If digital photograph is included in the ID token attributes, then the digital identity verification becomes more complete and useful for applications requiring visual identification, but the security risk increases due to the sensitive nature of biometric data
Solution Approach 1:
The patent segments the attributes stored in the ID token into two distinct groups: a first group of attributes accessible through one authentication method, and a second group containing the digital photograph accessible through a different authentication method requiring an access key. This segmentation allows the system to provide comprehensive digital identity information while controlling access to sensitive biometric data, thereby resolving the contradiction between utility and security risk
Solution Approach 2:
The patent applies different security measures to different parts of the attribute storage. The digital photograph in the second group of attributes is protected with higher security requirements (access key derivation from machine-readable details) compared to other attributes. This local quality approach ensures that sensitive biometric data receives enhanced protection while maintaining overall system versatility
2Ease of operation
If a single access method is used for all ID token attributes, then the system operation is simplified, but the security against unauthorized access is weakened
Solution Approach 1:
The patent divides the attribute access mechanism into two separate authentication paths: one for general attributes and another for the digital photograph requiring access key derivation. This segmentation maintains operational simplicity for non-sensitive data while implementing enhanced security for biometric information, resolving the contradiction between ease of operation and security reliability
3Reliability
If multiple authentication methods are implemented for different attribute groups, then the security is enhanced, but the system complexity increases
Solution Approach 1:
The patent implements a segmented authentication architecture where different authentication methods are applied to different attribute groups. The first group uses standard authentication while the second group requires access key derivation from machine-readable details. This segmentation enhances security for sensitive data while keeping the overall system complexity manageable through clear separation of security protocols
Solution Approach 2:
The patent introduces an intermediary mechanism (access key derivation process) that bridges the gap between the machine-readable details and the protected digital photograph. This intermediary adds a security layer without requiring complete redesign of the authentication system, thereby enhancing reliability while controlling the increase in device complexity
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
A method for providing a digital ID proof (224) using an electronic ID token (300) is disclosed. The method comprises receiving several first attributes (220) read from the ID token (300) during a first read operation by a first read access to a first group (312) of attributes, receiving several second attributes (222) read from the ID token (300) during a second read operation by a second read access to a second group (314) of attributes, checking at least one received second identical attribute for a match with a received first identical attribute, and, upon a match, issuing the digital ID proof (224) which comprises the received first and second attributes (220; 222) and is signed using a signature key (212).