Mobile ID Authentication via Hash Anonymization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile identity authentication methods are either overly complex or fail to comply with GDPR regulations due to the need for secure transmission of personal data, often requiring multiple certificates and increased effort in setting up public key infrastructure.
Innovation Solution
A method using a single Mobile ID certificate that anonymizes personal information using a one-way function, allowing for secure authentication without initially transmitting non-anonymized data, and enabling later verification with user consent, thus ensuring GDPR compliance and simplifying the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional mobile ID authentication methods are used, then security can be maintained, but the implementation becomes highly complex and requires multiple certificates
Solution Approach 1:
The patent combines multiple authentication functions into a single mobile ID certificate. Instead of requiring separate certificates for different authentication purposes, the invention integrates identity verification, authentication, and authorization into one unified certificate that can be used across multiple services, thereby reducing complexity while maintaining security
Solution Approach 2:
The mobile ID certificate is designed to be universally applicable across different online services and platforms. A single certificate can be used for authentication with multiple service providers without requiring service-specific certificates, simplifying the authentication process while maintaining robust security through standardized cryptographic mechanisms
2Measurement precision
If personal data is transmitted for authentication, then verification can be performed, but GDPR compliance is compromised due to exposure of personal information
Solution Approach 1:
The patent extracts only the essential authentication elements from personal data. Instead of transmitting full personal information, the system uses cryptographic techniques to extract and verify specific identity attributes embedded in the mobile ID certificate, enabling accurate verification while minimizing personal data exposure and ensuring GDPR compliance
Solution Approach 2:
The mobile ID certificate acts as an intermediary between the user's personal identity and the authentication system. The certificate contains verified identity attributes that can be presented for verification without exposing the underlying personal data, serving as a mediator that enables accurate identity verification while protecting personal information from direct exposure
3Adaptability or versatility
If multiple certificates are used for different services, then service-specific authentication can be achieved, but the setup effort and infrastructure complexity increase
Solution Approach 1:
The mobile ID certificate is designed with universal applicability across multiple services and platforms. A single certificate can be used for authentication with various service providers without requiring separate service-specific certificates, thereby reducing infrastructure setup effort while maintaining the ability to provide service-specific authentication through the standardized certificate interface
Data Source
Figure 1
AI summary
The invention relates to a method (100) for authenticating a mobile ID, in which the mobile ID is provided on a user's terminal device (1) to a first entity (2), e.g., an online service (2). First, personal information (10) about a user is anonymized (21, 22, 23) using a hash function or a comparable one-way function known to the user and the online service (2) and transmitted to the online service (1) with a single mobile ID certificate (20). Subsequently, this mobile ID certificate (20) is used to identify communication (42) with the online service (2).At a later point, the user will be given the option to authorize (35) the transmission (30) of the personal information in non-anonymized form (31, 32, 33) to the online service (2), and the online service (2) will then use the non-anonymized personal information (30) transmitted to it to perform a verification (50) of its anonymized form (21, 22, 23). Furthermore, a system for authenticating a mobile ID is required.