Mobile Device Authentication via Digital Signature Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems for mobile electronic devices in medical data exchange are insecure, making it easy for attackers to access unauthorized data, and require high administrative effort, with reduced availability of secure authentication due to complex security infrastructures.

Innovation Solution

An authentication system that uses a central instantiation unit to install an individualized encryption application on mobile devices, generating a digital signature from a device identifier and timestamp, which is then decrypted on a central server to authenticate the device and access medical data repositories securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal access data is stored on mobile electronic devices and transmitted via standardized communication channels, then patient data accessibility is improved, but security is worsened because the data can easily be damaged or compromised and mobile phone connections can be manipulated by attackers

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent components: a first cryptographic module on the mobile device, a second cryptographic module on the server, and a biometric authentication layer. This segmentation ensures that no single point of failure compromises the entire system, and each component can be optimized for its specific function while maintaining overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Cryptographic keys are generated and stored in advance on both the mobile device and server before any data transmission occurs. The mobile device's public key and the server's public key are exchanged and stored securely, enabling immediate encrypted communication without requiring key generation during the authentication process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If backup infrastructure is provided by third parties for secure authentication, then security measures are enhanced, but administrative effort is worsened due to high maintenance requirements

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service authentication where the mobile device automatically performs cryptographic operations and biometric verification without requiring manual intervention from administrators. The device autonomously generates authentication credentials, manages key storage, and executes the authentication protocol with the server, eliminating the need for complex administrative infrastructure management.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If digital data is exchanged freely in medical systems, then data availability and flexibility are improved, but unauthorized access risk is worsened

Engineering Contradiction:
Improvedata availabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Cryptographic keys and biometric authentication data serve as intermediaries between the mobile device and the medical data system. These intermediaries enable secure data exchange by acting as trusted mediators that verify identities and encrypt communications, allowing free data availability while preventing unauthorized access through cryptographic protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2795569B1System for authentication of mobile devices for exchange of medical data
Publication Date: 2018.09.19 SIEMENS HEALTHCARE GMBH
  • EP2795569B1 patent drawingFigure 1~3
  • EP2795569B1 patent drawingFigure 4

AI summary

The invention relates to an authentication system, a mobile electronic device (G), an instantiating unit (I) and a method, as well as a computer program product for the authentication of a patient against a central registry (10) which exchanges data with a repository (12) for the storage of medical data records. An individualised application (V) is loaded and installed on the mobile radio device (G) in order to sign messages to the registry (10) with a signature (SIG). The signature can be triggered in the registry (10) to check the authenticity of the remote patient in order to provide data access.