Identification Card Cryptographic Certificate Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for providing identification cards with cryptographic certificates are inefficient, requiring complex identification processes and personalization devices, and often involve storing personal data on the card, which is cumbersome and time-consuming.

Innovation Solution

A method where pre-stored personal data is transmitted from a data processing system to an electronic certification server, which generates and transmits a cryptographic certificate to the identification card, eliminating the need for storing data on the card and simplifying the identification process by using a cryptographic secret that can be authenticated electronically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex identification processes and personalization devices are used to provide cryptographic certificates, then security and authentication capability are improved, but device complexity and time consumption increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidpersonalization device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identification card performs self-service by generating its own cryptographic key pair internally. The card's processor creates the public-private key pair without external intervention, and the private key remains securely stored within the card. This eliminates the need for complex external personalization devices to write cryptographic data to the card.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A server acts as an intermediary between the identification card and the certification authority. The server receives the public key from the card, requests the cryptographic certificate from the certification authority, and then provides the certificate back to the card. This simplifies the overall system architecture by centralizing the certificate management function.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cryptographic certificates are provided after optical personalization, then flexibility in timing is improved, but the process requires additional complex identification steps

Engineering Contradiction:
Improvetiming flexibilityVSAvoididentification process simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The identification card is pre-configured with the capability to generate cryptographic key pairs before any personalization or certificate issuance occurs. The card's processor and secure storage are ready in advance, allowing cryptographic functionality to be activated at any later time without requiring additional hardware or complex setup procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

When it is time to issue a certificate, the identification card autonomously generates its public key and transmits it to the server, which then obtains the certificate from the certification authority. The card performs these cryptographic operations independently without requiring the user to undergo complex identification procedures or to be present with specialized equipment.

Inventive Principle:
Principle #25Self-service

3Loss of information

If personal data is stored on the identification card, then data availability is improved, but security risks and storage complexity increase

Engineering Contradiction:
Improvepersonal data availabilityVSAvoiddata storage complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The personal data (public key and cryptographic certificate) is extracted from the identification card and stored externally on a server. The card retains only the essential private key for cryptographic operations. This separation reduces the storage burden and security requirements on the card itself, while maintaining full data availability through the server.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The server serves as an intermediary storage location for the public key and cryptographic certificate. Instead of storing all personal data on the card or requiring complex secure storage infrastructure, the server provides a centralized, secure repository that the card can access when needed for cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3134840B1Method for providing an identification card of a person with a cryptographic certificate
Publication Date: 2020.04.15 BUNDESDRUCKEREI GMBH
  • EP3134840B1 patent drawingFigure 1
  • EP3134840B1 patent drawingFigure 2
  • EP3134840B1 patent drawingFigure 3

AI summary

The invention relates to a method (100) for providing an identification card of a person with a cryptographic certificate, comprising transmitting (101) a pre-stored personal date to an electronic certification server by means of a data-processing system, generating (103) a cryptographic key by means of the identification card, transmitting (105) the generated cryptographic key from the identification card to the electronic certification server, generating (107) the cryptographic certificate by means of the electronic certification server on the basis of the cryptographic key and the personal date, and transmitting (109) the cryptographic certificate to the identification card by means of the electronic certification server in order to provide the identification card with the cryptographic certificate.