Mobile Device Secure Element Authentication Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for mobile devices lack efficiency and convenience in verifying user identity, particularly in scenarios like customs checkpoints or age verification, where traditional identification documents are cumbersome to use.

Innovation Solution

A mobile device system that incorporates a secure element for storing identification information, utilizing near-field communication and a biosensor for authentication, allowing users to present their identity through the device instead of physical documents, and enabling secure storage and verification of information with authorization from the issuing authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional identification documents are used for authentication, then user identity can be verified, but the authentication process becomes cumbersome and inefficient

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidconvenience of identity verification
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent creates a digital copy of the identification document by extracting relevant information (name, date of birth, identification number) and storing it in a secure element within the mobile device. This digital copy can be quickly presented and verified electronically, eliminating the need to physically handle and manually verify traditional paper identification documents, thus significantly improving authentication efficiency and convenience

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical process of physically presenting and manually verifying paper identification documents with an electronic system. The mobile device uses near-field communication (NFC) to wirelessly transmit authentication data to the verification system, substituting the manual mechanical verification process with automated electronic verification, thereby enhancing both efficiency and user convenience

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If identification information is stored in the mobile device, then authentication convenience is improved, but security risks increase

Engineering Contradiction:
Improveconvenience of identity verificationVSAvoidsecurity of user information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the mobile device into separate security zones: the secure element (a isolated hardware component) stores sensitive identification information and biometric data, while the main processor handles application logic. This segmentation ensures that even if the main system is compromised, the critical authentication data remains protected in the isolated secure element, maintaining security while enabling convenient access

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a biometric authentication intermediary layer between the user and the identification information. The biometric sensor verifies the user's identity first, and only after successful biometric authentication does the system release the stored identification information. This intermediary mechanism ensures that stored information is accessed only by the authorized user, mitigating security risks while maintaining convenience

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If biometric authentication is implemented, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improvesecurity of authenticationVSAvoidcomplexity of authentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the biometric authentication functionality directly into the mobile device by integrating a biometric sensor and processing capabilities within the device itself. This consolidation allows the device to perform self-authentication using the user's biometric data stored in the secure element, enhancing security without requiring external authentication systems or complex external infrastructure

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution streamlines the authentication process, providing secure and convenient identity verification, protecting user information while allowing merchants or authorities to confirm necessary attributes without exposing sensitive details, thus enhancing user experience and security.

Implementation Method 1

utilizing near-field communication and a biosensor for authentication

Methodology Applied
Scientific EffectNear-field communication: Electromagnetic Induction

Implementation Method 2

a biosensor for authentication, allowing users to present their identity through the device

Methodology Applied
Scientific EffectBiometric detection:

Data Source

PatentEP4022472B1User authentication framework
Publication Date: 2023.07.26 APPLE INC
  • EP4022472B1 patent drawingFigure 1
  • EP4022472B1 patent drawingFigure 2
  • EP4022472B1 patent drawingFigure 3A

AI summary

Techniques are disclosed relating to authenticating a user with a mobile device. In some embodiments, a computing device stores a first signed attestation indicating an ability of the computing device to securely perform a user authentication. The computing device receives a request to store credential information of an identification document issued by an issuing authority to a user for establishing an identity of the user. In response to the request, the computing device sends, to the issuing authority, a request to store the credential information, the sent request including the first signed attestation to indicate an ability to perform a user authentication prior to permitting access to the credential information. In response to an approval of the sent request based on the first signed attestation, the computing device stores the credential information in a secure element of the computing device.