Identification Card Cryptographic Certificate Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for providing identification cards with cryptographic certificates are inefficient, requiring complex identification processes and personalization devices, and often involve storing personal data on the card, which is cumbersome and time-consuming.
Innovation Solution
A method where pre-stored personal data is transmitted from a data processing system to an electronic certification server, which generates and transmits a cryptographic certificate to the identification card, eliminating the need for storing data on the card and simplifying the identification process by using a cryptographic secret that can be authenticated electronically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex identification processes and personalization devices are used to provide cryptographic certificates, then security and authentication capability are improved, but device complexity and time consumption increase
Solution Approach 1:
The identification card performs self-service by generating its own cryptographic key pair internally. The card's processor creates the public-private key pair without external intervention, and the private key remains securely stored within the card. This eliminates the need for complex external personalization devices to write cryptographic data to the card.
Solution Approach 2:
A server acts as an intermediary between the identification card and the certification authority. The server receives the public key from the card, requests the cryptographic certificate from the certification authority, and then provides the certificate back to the card. This simplifies the overall system architecture by centralizing the certificate management function.
2Adaptability or versatility
If cryptographic certificates are provided after optical personalization, then flexibility in timing is improved, but the process requires additional complex identification steps
Solution Approach 1:
The identification card is pre-configured with the capability to generate cryptographic key pairs before any personalization or certificate issuance occurs. The card's processor and secure storage are ready in advance, allowing cryptographic functionality to be activated at any later time without requiring additional hardware or complex setup procedures.
Solution Approach 2:
When it is time to issue a certificate, the identification card autonomously generates its public key and transmits it to the server, which then obtains the certificate from the certification authority. The card performs these cryptographic operations independently without requiring the user to undergo complex identification procedures or to be present with specialized equipment.
3Loss of information
If personal data is stored on the identification card, then data availability is improved, but security risks and storage complexity increase
Solution Approach 1:
The personal data (public key and cryptographic certificate) is extracted from the identification card and stored externally on a server. The card retains only the essential private key for cryptographic operations. This separation reduces the storage burden and security requirements on the card itself, while maintaining full data availability through the server.
Solution Approach 2:
The server serves as an intermediary storage location for the public key and cryptographic certificate. Instead of storing all personal data on the card or requiring complex secure storage infrastructure, the server provides a centralized, secure repository that the card can access when needed for cryptographic operations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method (100) for providing an identification card of a person with a cryptographic certificate, comprising transmitting (101) a pre-stored personal date to an electronic certification server by means of a data-processing system, generating (103) a cryptographic key by means of the identification card, transmitting (105) the generated cryptographic key from the identification card to the electronic certification server, generating (107) the cryptographic certificate by means of the electronic certification server on the basis of the cryptographic key and the personal date, and transmitting (109) the cryptographic certificate to the identification card by means of the electronic certification server in order to provide the identification card with the cryptographic certificate.