Digital Identification Validation Using Dynamic Decryption Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Physical identification cards are susceptible to fraud and counterfeiting due to preset security features, and users face inconvenience when their information changes, requiring new cards to be issued.

Innovation Solution

A digital identification system that allows user data validation on a portable electronic device, using proximity-based data exchange protocols, checksum validation, and variable decryption keys, enabling secure access and updates without network connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical identification cards with preset security features are used, then identity verification is enabled, but the system becomes susceptible to fraud and counterfeiting when security features are compromised

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidfraud and counterfeiting vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic security features through time-varying decryption keys that change based on timestamps. The digital identification system uses multiple decryption keys (first decryption key, second decryption key) that are selected based on time conditions, making the security credentials dynamic rather than static. This dynamic approach prevents counterfeiting because the security features continuously change and cannot be replicated from static copies.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes cryptographic parameters by using different decryption keys based on timestamps and conditions. The patent specifies that decryption keys are selected based on time parameters, and the system validates timestamps to ensure the authenticity of digital identifications. This parameter changing approach enhances security by ensuring that security credentials are not static and can be verified against temporal parameters.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If physical identification cards are issued with fixed user information, then identity verification is provided, but users experience inconvenience when information changes requiring new card issuance

Engineering Contradiction:
Improveidentity verificationVSAvoidtime for card reissuance
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a digital copy of physical identification cards that can be stored and accessed on portable electronic devices. The digital identification contains user information in electronic form that can be updated remotely without requiring physical card reissuance. When user information changes, the system can update the digital copy instantly, eliminating the need to wait for physical card production and delivery while maintaining verification reliability through cryptographic validation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary validation by checking timestamps and decryption keys before verifying user information. The patent includes mechanisms to validate the authenticity of digital identifications by verifying timestamps against expected time ranges and using appropriate decryption keys based on time conditions. This preliminary validation ensures that even when information is updated dynamically, the verification process remains secure and reliable.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If digital identification with variable decryption keys is implemented, then security against fraud is enhanced, but device complexity increases

Engineering Contradiction:
Improvefraud preventionVSAvoiddecryption key management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements periodic key selection based on timestamps and time conditions. The system uses a first decryption key for certain time periods and a second decryption key for other time periods, creating a periodic pattern in key usage. This periodic action simplifies key management compared to completely random key selection, as the pattern is predictable and can be implemented through timestamp-based logic rather than complex key management infrastructure.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The digital identification system performs self-validation by including timestamps and decryption key selection logic within the digital identification itself. The portable electronic device can independently validate the authenticity of the digital identification by checking timestamps and selecting appropriate decryption keys based on time conditions, without requiring constant connection to a central authority. This self-service approach reduces device complexity by distributing validation capabilities rather than requiring centralized key management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11509477B1User data validation for digital identifications
Publication Date: 2022.11.22 IDEMIA CIVIL IDENTITY NA LLC
  • US11509477B1 patent drawing
  • US11509477B1 patent drawing
  • US11509477B1 patent drawing

AI summary

In general, one innovative aspect of the subject matter described in this specification may be embodied in methods that may include validating user data pages extracted from a digital identification in circumstances where a user device that includes the digital identification is either unavailable or presently lacks network connectivity. For instance, an authorized device may be used to extract user data pages from the digital identification by either exchanging communications with the user device using a proximity-based data exchange protocol, or by using a physical identification card to identify the digital identification on a user record. The user data pages may then be validated by comparing checksums associated with user data pages against the checksums within the user record, and decrypting the user data pages using a decryption key that is variably designated by a security status assigned to the digital identification.