Identity Document Security via Cryptographic Machine Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity document generation systems lack robust security measures to prevent forgery and unauthorized document creation, making it difficult to determine the authenticity of documents such as passports, IDs, and financial cards.

Innovation Solution

A method and apparatus that generate identity documents by combining unique machine data and personalization data, digitally signing this data using a cryptographic engine, and incorporating it into the document, ensuring that only authorized systems can produce valid documents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional identity document generation systems are used, then document creation is simple and fast, but security against forgery and unauthorized creation is insufficient

Engineering Contradiction:
Improvedocument authenticityVSAvoidgeneration system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by obtaining unique machine data from the generation system before document creation, and digitally signs this data in advance. This pre-established cryptographic binding ensures that only the authorized generation system can create valid documents, resolving the security vulnerability without requiring complex runtime verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a cryptographic engine as an intermediary component that digitally signs the unique machine data. This intermediary layer creates a trusted connection between the generation system and the document, providing robust security against forgery while maintaining a relatively simple overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique machine data and digital signatures are incorporated into identity documents, then security against forgery is improved, but the complexity of the generation system increases

Engineering Contradiction:
Improveforgery preventionVSAvoidgeneration system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic engine performs multiple functions: it obtains unique machine data, digitally signs this data, and incorporates the signed data into the identity document. By consolidating these security functions into a single multi-functional component, the system achieves robust forgery prevention without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the unique machine data and personalization data into a single signed data structure that is incorporated into the identity document. This combination simplifies the system architecture by integrating multiple security elements into one unified mechanism, rather than requiring separate systems for each function.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9994054B2Generating an identity document with personalization data and unique machine data
Publication Date: 2018.06.12 ENTRUST CORP
  • US9994054B2 patent drawing
  • US9994054B2 patent drawing
  • US9994054B2 patent drawing

AI summary

An apparatus and methods for generating an identity document obtain unique machine data related to an identity document generation system. The apparatus and methods obtain personalization data related to an intended holder of the identity document. The apparatus and methods generate a unique machine and personalization data object that includes values of the unique machine data and the personalization data. The apparatus and methods digitally sign the unique machine and personalization data object. The apparatus and methods incorporate the signed unique machine and personalization data object into the identity document.