Identity Document Graphic Code Post-Quantum Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity document security features, particularly those relying on electronic chips, face limitations such as wear and tear issues, vulnerability to quantum attacks, and difficulty in updating cryptographic algorithms, while lacking robust post-quantum security and easy interchangeability.
Innovation Solution
Incorporating a machine-readable graphic code with a control code generated using multiple hash functions and a digital key, independent of user data, to provide an additional security layer that is post-quantum secure and easily updatable, complementing existing chip-based security features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If a chip is used for identity verification, then machine-assisted identity verification becomes possible, but the chip is prone to wear and tear and connection errors
Solution Approach 1:
The patent creates a printed copy of the identity verification data in the form of a machine-readable graphic code (QR code or Data Matrix code). This code contains all necessary personal data and control codes that were previously stored only in the electronic chip, allowing verification without physical contact with the chip.
Solution Approach 2:
The patent replaces the electronic chip-based verification system with a printed graphic code system. Instead of using NFC or contact-based chip interfaces that are subject to wear and connection errors, the verification is performed by scanning the printed code with a mobile device camera or scanner.
2Reliability
If cryptographic algorithms are updated in chip passports, then security can be improved, but the process involves enormous effort due to chip architecture limitations
Solution Approach 1:
The patent makes the cryptographic algorithm dynamic and updatable by storing the hash function identification in the printed code. Different hash functions (SHA-256, SHA-384, SHA-512) can be selected and updated without changing the physical document or chip, allowing flexible security updates.
Solution Approach 2:
The patent changes the cryptographic parameters by allowing selection of different hash function types and image spaces (256, 384, or 512 bits) through the printed code configuration, enabling security parameter updates without physical modifications.
3Device complexity
If a single hash function is used for the control code, then the code can be kept simple, but the system becomes vulnerable to quantum attacks
Solution Approach 1:
The patent uses a composite approach by combining multiple hash functions (SHA-2 and SHA-3 families) in the control code generation. This multi-hash approach creates a more quantum-resistant system while maintaining reasonable code structure through systematic integration of the different hash results.
Solution Approach 2:
The patent segments the control code into multiple parts, each generated by a different hash function. The control code contains separate code sections from different hash functions, allowing verification of multiple cryptographic layers simultaneously.
4Reliability
If the chip antenna is damaged, then the identity document becomes unreadable, but damage detection and verification are difficult
Solution Approach 1:
The patent creates a redundant printed copy of all identity verification data in machine-readable graphic code format. This copy is independent of the chip and antenna condition, ensuring that identity verification can proceed even if the chip or antenna is damaged.
Solution Approach 2:
The patent prepares a backup verification mechanism (printed code) in advance that can compensate for potential chip or antenna failures. This cushioning approach ensures continuous operability without requiring damage detection or verification.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Method for securing and authenticating a personal identity document (1) and corresponding system (19) and identity document (1), wherein, in the context of the securing method, the identity document (1) is equipped with a machine-readable graphic code (9) representing a data content (11), wherein the data content (11) comprises user data (12) and control data (13), wherein the user data (12) comprises at least one field content of the identity document (1), wherein, to determine a control code (18), a hash function is applied at least to the user data (12), wherein the control data (13) comprises a digital key (16), and that the control code (18) has at least two code sections (27, 28), wherein, to determine the two code sections (27, 28), different hash functions based on different hash algorithms are applied to the data content (11).