Mobile eID Provisioning via Remote Security Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manufacturers and providers of mobile device applications face challenges in ensuring cryptographic security, particularly in managing user electronic identities, as they lack control over the security elements provided by device manufacturers.
Innovation Solution
A method for creating a cryptographically secured electronic identity on a mobile device using a security element with a control component and provisioning component, involving remote security inspection, key generation, and certificate issuance, enabling secure authentication and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device manufacturers provide security elements for cryptographic procedures, then cryptographic security of the mobile device is improved, but independence of application programs from device manufacturers deteriorates
Solution Approach 1:
The patent introduces a security inspection server as an intermediary between the application program and the device manufacturer's security element. This server performs security inspections and issues certificates that validate the security element's functionality, allowing application programs to independently verify security without direct reliance on the device manufacturer.
Solution Approach 2:
The application program performs self-provisioning by automatically requesting security inspections and obtaining certificates from the security inspection server. This self-service mechanism enables the application program to independently ensure cryptographic security without manual intervention or reliance on device manufacturer provisioning.
2Adaptability or versatility
If application programs manage electronic identities, then functionality and versatility are improved, but security responsibility and complexity increase
Solution Approach 1:
The patent extracts the complex security inspection and certificate validation logic from the application program and places it in the security inspection server. This separation allows the application program to manage electronic identities with simpler code, while the server handles the complex cryptographic verification and security infrastructure management.
Data Source
AI summary
The method includes performing a remote security inspection of the security infrastructure of a mobile device by a personalization server over a network; receiving a result of the inspection; upon a positive result of the inspection, sending a key generation request of a provisioning component of the ID application program to a security element of the mobile device; in response to the key generation request, generating two asymmetric key pairs assigned to the ID application program by the security element; sending a certificate request by the provisioning component to the personalization server with the public cryptographic keys of the two asymmetric key pairs to the personalization server; receiving a certificate of the ID application program generated by the personalization server with the first public cryptographic key and a root certificate of a root instance of a PKI; and storing the certificate and the root certificate on the mobile device.


