Electronic Signature Creation via Integrated eID Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for creating electronic signatures are time-consuming and inefficient, as they involve a two-step process that separates user identification and certificate creation from signature generation, often requiring redundant authentication mechanisms.

Innovation Solution

A method that seamlessly integrates user identification and authentication using existing electronic means of identification, such as national electronic identity cards or mobile eIDs, to create a transaction certificate for a single-use electronic signature, eliminating the need for additional authentication steps and generating a unique signature certificate for each transaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a two-step process is used for creating electronic signatures (separating user identification and certificate creation from signature generation), then security and authentication are improved, but process time and operational complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsignature creation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the two-step process into a single integrated step by combining user identification, authentication, and signature generation. The electronic identification means performs both identification and signature creation simultaneously, eliminating the separate certificate creation step and reducing overall process time while maintaining security through the use of established electronic identification mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies preliminary action by pre-establishing electronic identification means (such as electronic identity cards or mobile eIDs) that already contain verified identity data and authentication mechanisms. This pre-verification eliminates the need for repeated authentication during the signature process, as the identification means has already performed the necessary security verification in advance.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a two-step process with separate authentication mechanisms is used, then authentication strength is improved, but process complexity and number of authentication steps increase

Engineering Contradiction:
Improveauthentication strengthVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication functions into a single electronic identification means. The eID contains integrated identity data, authentication mechanisms, and signature creation capabilities, allowing all authentication steps to be performed through one unified interface rather than requiring separate systems for each function.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The electronic identification means serves multiple functions simultaneously: it acts as an identification document, provides authentication verification, and enables signature generation. This multi-functional approach eliminates the need for separate authentication mechanisms and reduces overall process complexity while maintaining strong security through the versatile eID.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional signature certificates with limited validity periods are used, then security management is improved, but additional certificate creation steps are required for each transaction

Engineering Contradiction:
Improvecertificate security managementVSAvoidsignature transaction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the signature creation capability directly from the electronic identification means, eliminating the need for separate signature certificates. Instead of relying on external certificates with validity periods, the eID itself contains the necessary cryptographic elements to create signatures, removing the certificate management overhead while maintaining security through the established eID validation framework.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If redundant authentication mechanisms are implemented in the two-step process, then security verification is improved, but time consumption and operational efficiency decrease

Engineering Contradiction:
Improveverification strengthVSAvoidtransaction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by performing all necessary authentication verification in advance during the creation of the electronic identification means. The eID is pre-verified by trusted authorities and contains all necessary authentication data, eliminating the need for repeated verification steps during each signature transaction. This pre-verification maintains strong security while significantly improving transaction efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4224786A1Method and device for creating electronic signatures
Publication Date: 2023.08.09 PRIMESIGN GMBH
  • EP4224786A1 patent drawingFigure 1
  • EP4224786A1 patent drawing
  • EP4224786A1 patent drawing

AI summary

The invention relates to a method for creating electronic signatures based on existing electronic identification means (eIDs). The signature certificate used for the electronic signature is issued on a case-by-case basis and only for this single signature transaction, during and at the time of the signature transaction, and is used only for this single signature transaction. The data of the signature certificate issued during the transaction, i.e., the user's identity data, are directly taken from or derived from the user's existing electronic identification means. The user authentication, and thus the triggering (authorization) of the electronic signature, is also carried out by the existing electronic identification means. The method is therefore seamless and complete in a single step.It includes the identification and authentication of the user, the issuance of the transaction-related certificate, as well as the authorization (triggering) and the subsequent creation of the electronic signature, ensuring consistency based on the electronic identification means.