Mobile Identification Credential Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity verification methods, such as in-person identification and password-protected accounts, are prone to human error, fraud, and hacking, compromising the security and privacy of medical records and other sensitive information.

Innovation Solution

A permission-based system and network utilizing mobile identification credentials (MICs) for at-distance communication, allowing secure verification of user identity through mobile devices before granting access to medical records or services, using secure local connections and liveness checks to ensure authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If in-person identification methods are used to verify identity, then access control can be implemented, but the system is prone to human error, fraud, and hacking

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidfraud and hacking risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces manual in-person identification processes with automated mobile identification credential verification. The system uses digital credentials stored on mobile devices and verified through automated authentication protocols, eliminating human error and fraud associated with manual ID checking. The verification process uses cryptographic signatures and secure element technology to ensure authenticity without human intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary verification system that acts as a trusted third party between the user and the service provider. The mobile identification credential system serves as an intermediary that cryptographically verifies identity without requiring direct human interaction or physical document inspection. This intermediary layer prevents fraud by using secure authentication protocols rather than relying on human judgment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If password-protected accounts are used for electronic access to medical records, then remote access is enabled, but the accounts can be hacked or accessed by unauthorized persons

Engineering Contradiction:
Improveelectronic record access convenienceVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces password-based authentication with mobile identification credential verification. Instead of relying on users to remember and protect passwords, the system uses cryptographic credentials stored in secure elements of mobile devices. This substitution eliminates the security vulnerabilities of password systems while maintaining convenient remote access through automated authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent uses cryptographic copies of identity credentials that can be securely transmitted and verified electronically. The mobile identification credential creates a digital copy of the user's identity that can be shared securely with authorized parties without exposing the original credential. This allows convenient electronic access while maintaining security through cryptographic verification rather than password sharing.

Inventive Principle:
Principle #26Copying

3Reliability

If conventional identity verification methods are used, then access control is achieved, but security breaches and privacy compromises occur

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidprivacy breach risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces mobile identification credentials as an intermediary that protects user privacy while enabling access control. The credential system acts as a mediator between the user and service providers, allowing verification of identity without exposing sensitive personal information. The secure element in the mobile device serves as a trusted intermediary that cryptographically proves identity without revealing underlying personal data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces conventional identity verification methods that require sharing personal information with cryptographic credential verification. Instead of exposing sensitive personal data during verification, the system uses cryptographic signatures and secure element technology to prove identity without revealing underlying information. This substitution eliminates privacy breaches while maintaining effective access control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11601816B2Permission-based system and network for access control using mobile identification credential including mobile passport
Publication Date: 2023.03.07 THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SEC OF HOMELAND SECURITY
  • US11601816B2 patent drawing
  • US11601816B2 patent drawing
  • US11601816B2 patent drawing

AI summary

A provider system is connected to readers disposed at distances from the provider system. A secure local connection is established between the client device and the provider system via one of the readers. Before the client reaches an access touchpoint, the provider system receives from the client device a request for client access, the provider system sends to the client device a request for identification information of the client, and the client device sends client information associated with a first mobile identification credential (MIC) which the client device received from an authorizing party system (APS), the client having consented to release the client information to the provider system, and the client information having been verified. The provider system uses the verified client information associated with the first MIC to verify or not verify the identity of the client before granting or denying the request to the client.