Mobile Biometric Credential Sharing to Replace Manual Checks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure data communication between individuals and organizations are inefficient and require manual identity checks, which are costly in time and resources, and organizations lack a reliable way to verify the authenticity of user data without breaching security protocols.
Innovation Solution
A system and method that utilizes a mobile device to securely store and provide user attributes using a physical token with biometric data, generating verification attributes through biometric matching, and communicating these attributes via a cryptographic key, ensuring data accuracy and authenticity while maintaining user control over their information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual identity checks are performed by organization representatives, then data authenticity can be verified, but time cost and resource consumption increase significantly
Solution Approach 1:
The patent creates digital copies of identity credentials (passport, driving license) stored in a secure data store within the mobile device. These digital copies can be presented and verified electronically without requiring physical inspection by organization representatives, thereby eliminating time-consuming manual checks while maintaining verification reliability through cryptographic authentication of the credential copies.
Solution Approach 2:
The patent replaces the mechanical manual identity verification process (physical inspection of documents by representatives) with an automated electronic verification system. The mobile device automatically presents digital credentials and the organization's system automatically verifies them using cryptographic keys, substituting human manual inspection with automated digital validation that is both faster and equally reliable.
2Ease of operation
If personal data is shared with organizations, then service access is enabled, but security risks and loss of user control increase
Solution Approach 1:
The patent segments personal data into specific attributes (name, address, date of birth, etc.) that can be selectively shared with organizations. Users control which attributes are disclosed through the credential verification process, enabling service access with only the necessary information while maintaining security by not exposing unnecessary personal data. This selective disclosure maintains user control while facilitating convenient service access.
Solution Approach 2:
The patent introduces a mobile device with a secure data store as an intermediary between the user and organizations. This intermediary holds and manages personal data, presenting only verified credentials to organizations through cryptographic authentication. The intermediary enables service access by mediating the interaction while maintaining security through controlled access mechanisms and preventing direct exposure of raw personal data to organizations.
3Reliability
If organizations store personal information for verification, then identity validation is improved, but security vulnerabilities and data protection risks increase
Solution Approach 1:
The patent stores digital copies of identity credentials in a secure data store within the mobile device rather than in centralized organization databases. These copies are cryptographically signed and can be verified without the organization needing to store or access the actual personal information. This approach maintains reliable identity validation through cryptographic verification while eliminating security vulnerabilities associated with storing sensitive personal data in organization systems.
Solution Approach 2:
The patent extracts the verification capability from the personal data itself. Instead of organizations storing personal information to validate identity, the system extracts cryptographic verification mechanisms (digital signatures, hashed credentials) that prove identity without requiring storage of the actual personal data. This extraction enables reliable identity validation while removing the security risk of storing vulnerable personal information in organization databases.
Data Source
AI summary
Method and system for securely communicating data, the method comprising the steps of: initiating a secure communication between a mobile device and a requester using a cryptographic key to verify the user of the mobile device. Receiving, using the secure communication, at a mobile device a request from the requester, the request including an indication of one or more requested data attributes associated with a user of the mobile device. At the mobile device, querying a data store for the requested one or more data attributes and a verification attribute. In response to the request, providing the requester, using the secure communication, with the requested one or more data attributes and the verification attribute from the data store, wherein the verification attribute is generated from one or more data items of a physical token issued to the user, the one or more data items including information characterising a biological feature of the user, the verification attribute also indicating that sensor data of a biological feature of the user detected by the mobile device has been matched to the information characterising the biological feature of the user. At the requester, receiving the verification attribute over the secure communication.


