eID Application Subscription Profile Asymmetric Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for governments to provide users with a secure and easy-to-use application for electronic identification (eID) that can be executed on a user's terminal, utilizing identity data available to mobile network operators or identification services.

Innovation Solution

A method for managing an application for electronic identification of a user in a mobile network, involving the generation of a subscription profile with asymmetric personalization keys, encryption of user identity data, and distribution of the subscription profile and application to a mobile terminal, ensuring secure and compliant data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity data is collected and stored by mobile network operator or identification service, then electronic identification application can be provided to users, but data protection compliance and security requirements increase system complexity

Engineering Contradiction:
Improveease of provision of eID applicationVSAvoidsystem complexity for data protection
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system is segmented into distinct functional components: the mobile network operator collects and stores identity data, the subscription manager generates cryptographic keys and subscription profiles, and the eID application is distributed to users' terminals. This segmentation allows each component to operate independently with clearly defined security responsibilities, reducing overall system complexity while maintaining data protection compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The subscription manager acts as an intermediary between the mobile network operator's identity data and the user's eID application. It generates asymmetric personalization keys and creates encrypted subscription profiles that bridge the gap between raw identity data and the functional eID application, simplifying the security architecture by introducing a specialized security management layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If asymmetric personalization keys are generated and used for encrypting identity data, then data security is enhanced, but computational requirements and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time for key generation and encryption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Asymmetric personalization keys are generated in advance by the subscription manager during the subscription profile creation process, before the eID application is activated on the user's terminal. This preliminary key generation allows the actual eID application to use pre-prepared cryptographic materials, reducing processing time during application activation and use while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If subscription profile with private key is distributed to mobile terminal, then user can securely store and use eID application, but secure distribution and key management complexity increases

Engineering Contradiction:
Improvesecure storage of private keyVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The private asymmetric personalization key is extracted and stored exclusively within the secure environment of the user's mobile terminal, specifically within the eID application or its associated secure element. This extraction isolates the most sensitive cryptographic material from the broader system, requiring it to be managed only by the terminal's security mechanisms rather than by centralized system components, thereby reducing overall key management complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250203377A1Method for managing an application for electronic identification of a user
Publication Date: 2025.06.19 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • US20250203377A1 patent drawing
  • US20250203377A1 patent drawing
  • US20250203377A1 patent drawing

AI summary

A method for managing an application for the electronic identification of a user of a mobile terminal has a subscriber identity module in a mobile network. The method comprises: transmitting a request to generate a subscription profile, with the application, to a subscription manager data preparation (SM-DP+) server of the mobile network; generating a subscription profile with the application for the electronic identification of the user, wherein generating the subscription profile comprises generating a private asymmetric personalization key associated with the subscription profile and a public asymmetric personalization key associated with the subscription profile for the application; transmitting the public asymmetric personalization key to a server of the mobile network operator or to a server of an identification provider; encrypting identity data of the user using the public asymmetric personalization key; and distributing the subscription profile with the application, and the private asymmetric personalization key to the mobile terminal.