Mobile ID Authentication via Hash Anonymization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile identity authentication methods are either overly complex or fail to comply with GDPR regulations due to the need for secure transmission of personal data, often requiring multiple certificates and increased effort in setting up public key infrastructure.

Innovation Solution

A method using a single Mobile ID certificate that anonymizes personal information using a one-way function, allowing for secure authentication without initially transmitting non-anonymized data, and enabling later verification with user consent, thus ensuring GDPR compliance and simplifying the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional mobile ID authentication methods are used, then security can be maintained, but the implementation becomes highly complex and requires multiple certificates

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication functions into a single mobile ID certificate. Instead of requiring separate certificates for different authentication purposes, the invention integrates identity verification, authentication, and authorization into one unified certificate that can be used across multiple services, thereby reducing complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile ID certificate is designed to be universally applicable across different online services and platforms. A single certificate can be used for authentication with multiple service providers without requiring service-specific certificates, simplifying the authentication process while maintaining robust security through standardized cryptographic mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If personal data is transmitted for authentication, then verification can be performed, but GDPR compliance is compromised due to exposure of personal information

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidGDPR compliance risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential authentication elements from personal data. Instead of transmitting full personal information, the system uses cryptographic techniques to extract and verify specific identity attributes embedded in the mobile ID certificate, enabling accurate verification while minimizing personal data exposure and ensuring GDPR compliance

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile ID certificate acts as an intermediary between the user's personal identity and the authentication system. The certificate contains verified identity attributes that can be presented for verification without exposing the underlying personal data, serving as a mediator that enables accurate identity verification while protecting personal information from direct exposure

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple certificates are used for different services, then service-specific authentication can be achieved, but the setup effort and infrastructure complexity increase

Engineering Contradiction:
Improveservice-specific authentication capabilityVSAvoidpublic key infrastructure setup effort
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The mobile ID certificate is designed with universal applicability across multiple services and platforms. A single certificate can be used for authentication with various service providers without requiring separate service-specific certificates, thereby reducing infrastructure setup effort while maintaining the ability to provide service-specific authentication through the standardized certificate interface

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3840321B1Method and system for authenticating a mobile id using hash values
Publication Date: 2022.11.02 DEUTSCHE TELEKOM AG
  • EP3840321B1 patent drawingFigure 1

AI summary

The invention relates to a method (100) for authenticating a mobile ID, in which the mobile ID is provided on a user's terminal device (1) to a first entity (2), e.g., an online service (2). First, personal information (10) about a user is anonymized (21, 22, 23) using a hash function or a comparable one-way function known to the user and the online service (2) and transmitted to the online service (1) with a single mobile ID certificate (20). Subsequently, this mobile ID certificate (20) is used to identify communication (42) with the online service (2).At a later point, the user will be given the option to authorize (35) the transmission (30) of the personal information in non-anonymized form (31, 32, 33) to the online service (2), and the online service (2) will then use the non-anonymized personal information (30) transmitted to it to perform a verification (50) of its anonymized form (21, 22, 23). Furthermore, a system for authenticating a mobile ID is required.