Identity Account Registration via Document Reader Terminal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for recording user identity data at a point of sale lack secure data collection and adequate security measures, which can lead to potential fraud and unauthorized access.
Innovation Solution
A system and method that utilizes a terminal with a document reader at the point of sale to securely collect personal data from identity documents, employing a two-tiered security system where personal data and identifiers are transmitted to an identity service provider's server, with the option to upgrade security levels for expanded application usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If personal data is collected at a point of sale using traditional methods, then data collection is simple and quick, but security is insufficient and vulnerable to fraud
Solution Approach 1:
The patent introduces an identity service provider as an intermediary between the point of sale and the user's identity data. The ISP verifies identity documents, performs background checks, and issues identity accounts, thereby enhancing security without requiring the point of sale system to handle sensitive data directly. This mediator approach resolves the contradiction by outsourcing complex security verification to a specialized service.
Solution Approach 2:
The system divides the identity verification process into separate modules: document reading at the terminal, data transmission to the identity service provider, background check processing, and identity account issuance. This segmentation allows each component to be optimized independently, maintaining operational simplicity while achieving high security through specialized processing at each stage.
2Reliability
If traditional identity verification methods are used, then the process is fast and straightforward, but fraud prevention capabilities are weak
Solution Approach 1:
The identity service provider performs background checks and verifies identity documents in advance before issuing the identity account. This preliminary verification ensures that when the user makes purchases online, the fraud prevention measures are already in place, preventing fraud without adding time to the actual transaction process.
Solution Approach 2:
The system automatically reads identity documents using document readers, transmits data to the identity service provider, and processes verification without requiring manual intervention for each step. This automated self-service approach maintains speed while implementing comprehensive fraud prevention through systematic data verification.
3Reliability
If basic security measures are implemented for identity accounts, then ease of use is maintained, but security levels are insufficient for expanded applications
Solution Approach 1:
The identity account system implements dynamic security levels that can be adjusted based on the specific application or transaction type. The identity service provider can raise or lower security requirements depending on the risk assessment of the service being accessed, allowing basic ease of use for low-risk operations while enabling enhanced security for high-value or sensitive applications.
Solution Approach 2:
The system changes security parameters (such as verification requirements, authentication methods, and monitoring intensity) based on the application context. For routine purchases, basic verification suffices, but for expanded applications like credit services or high-value transactions, the system automatically adjusts parameters to implement stricter security measures without requiring users to manually configure settings.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method for capturing user identity data for an identity account at a point of sale, the method comprising the following steps: creating an identity account for a person, which can be used for online identity verification, in a server facility (10) of an identity service provider; providing an identifier for the identity account; establishing a data communication connection (11) between a chip (6) of a personal identity document (7), which is assigned to the person and contains personal data of the person in a memory of the chip (6), and a document reader (5) of a terminal (4) at a point of sale (1); capturing an access code (8) printed on the personal identity document (7) in the document reader (5); executing a password-based authentication and key agreement procedure for the personal identity document (7) and the document reader (5);Reading the personal data using the document reader (5); capturing the identifier for the identity account in the terminal (4) at the point of sale (1); transmitting the read personal data and the captured identifier from the terminal (4) at the point of sale (1) to the server facility (10) of the identity service provider and storing an electronic association between the personal data and the identity account in the server facility (10) of the identity service provider. Furthermore, a system for capturing user identity data for an identity account at a point of sale is provided with a server facility (10) of an identity service provider and a terminal (4) with a document reader (5) at a point of sale (1). (Fig. 1);