eID Wallet Namespace Security Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic identification (eID) wallet applications on mobile devices lack uniform communication of namespaces and associated security policies, leading to varying levels of confidence and cumbersome security requirements, which can hinder access to data items.
Innovation Solution
A technology that manages security policies by associating them with each namespace on a mobile device, allowing a reader module to communicate with the device and select a namespace based on verifier confidence, whitelisting, blacklisting, and overhead considerations, and optionally displaying a dialog for user selection, ensuring secure access to data items.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple eID applications with different namespaces are supported on a mobile device, then the versatility and adaptability of the eID wallet are improved, but the complexity of managing security policies and determining which namespace to access increases
Solution Approach 1:
The patent applies parameter changes by introducing a confidence level parameter that verifiers can assign to different namespaces. This allows the system to dynamically select namespaces based on the confidence parameter rather than using a fixed selection mechanism, thereby resolving the complexity of managing multiple namespaces while maintaining versatility
Solution Approach 2:
The patent implements preliminary action by having verifiers pre-configure confidence levels and security policies for different namespaces before actual data access requests. This preliminary configuration eliminates the need for complex real-time decision-making during namespace selection, reducing operational complexity while supporting multiple eID applications
2Reliability
If strict security policy requirements are enforced for accessing eID data, then the reliability and security of data access are improved, but the ease of operation and user experience deteriorate due to cumbersome authentication protocols
Solution Approach 1:
The patent applies partial action by implementing risk-based authentication where not all namespaces require the full suite of security protocols. Verifiers can select namespaces with confidence levels that match the security requirements of the specific access request, applying only the necessary level of security verification rather than uniformly enforcing all security measures
Solution Approach 2:
The patent changes the security parameter from a binary authorized/unauthorized state to a multi-level confidence system. This allows the system to adjust security requirements dynamically based on the confidence level associated with each namespace, improving ease of operation for low-risk accesses while maintaining high security for sensitive data
3Reliability
If cryptographic signatures and authentication protocols are required for namespace access, then the security of the eID wallet is improved, but the overhead and processing time increase
Solution Approach 1:
The patent implements partial action by applying cryptographic verification only when necessary based on the confidence level and security policy of the selected namespace. For high-confidence namespaces with established trust relationships, the system can skip or simplify authentication protocols, reducing overhead while maintaining security for lower-confidence accesses
Data Source
AI summary
A system, mobile device, and method for managing security policies for data items stored in an electronic identification (eID) wallet on the mobile device. Security policies are associated with each of a plurality of supported namespaces on a mobile device and a verifier terminal operates to select a namespace to access a data item stored on the mobile device based on the security policies associated with the plurality of supported namespaces on the mobile device.


