Mobile Identification Credential Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity verification methods, such as in-person identification and password-protected accounts, are prone to human error, fraud, and hacking, compromising the security and privacy of medical records and other sensitive information.
Innovation Solution
A permission-based system and network utilizing mobile identification credentials (MICs) for at-distance communication, allowing secure verification of user identity through mobile devices before granting access to medical records or services, using secure local connections and liveness checks to ensure authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If in-person identification methods are used to verify identity, then access control can be implemented, but the system is prone to human error, fraud, and hacking
Solution Approach 1:
The patent replaces manual in-person identification processes with automated mobile identification credential verification. The system uses digital credentials stored on mobile devices and verified through automated authentication protocols, eliminating human error and fraud associated with manual ID checking. The verification process uses cryptographic signatures and secure element technology to ensure authenticity without human intervention.
Solution Approach 2:
The patent introduces an intermediary verification system that acts as a trusted third party between the user and the service provider. The mobile identification credential system serves as an intermediary that cryptographically verifies identity without requiring direct human interaction or physical document inspection. This intermediary layer prevents fraud by using secure authentication protocols rather than relying on human judgment.
2Ease of operation
If password-protected accounts are used for electronic access to medical records, then remote access is enabled, but the accounts can be hacked or accessed by unauthorized persons
Solution Approach 1:
The patent replaces password-based authentication with mobile identification credential verification. Instead of relying on users to remember and protect passwords, the system uses cryptographic credentials stored in secure elements of mobile devices. This substitution eliminates the security vulnerabilities of password systems while maintaining convenient remote access through automated authentication.
Solution Approach 2:
The patent uses cryptographic copies of identity credentials that can be securely transmitted and verified electronically. The mobile identification credential creates a digital copy of the user's identity that can be shared securely with authorized parties without exposing the original credential. This allows convenient electronic access while maintaining security through cryptographic verification rather than password sharing.
3Reliability
If conventional identity verification methods are used, then access control is achieved, but security breaches and privacy compromises occur
Solution Approach 1:
The patent introduces mobile identification credentials as an intermediary that protects user privacy while enabling access control. The credential system acts as a mediator between the user and service providers, allowing verification of identity without exposing sensitive personal information. The secure element in the mobile device serves as a trusted intermediary that cryptographically proves identity without revealing underlying personal data.
Solution Approach 2:
The patent replaces conventional identity verification methods that require sharing personal information with cryptographic credential verification. Instead of exposing sensitive personal data during verification, the system uses cryptographic signatures and secure element technology to prove identity without revealing underlying information. This substitution eliminates privacy breaches while maintaining effective access control.
Data Source
AI summary
A provider system is connected to readers disposed at distances from the provider system. A secure local connection is established between the client device and the provider system via one of the readers. Before the client reaches an access touchpoint, the provider system receives from the client device a request for client access, the provider system sends to the client device a request for identification information of the client, and the client device sends client information associated with a first mobile identification credential (MIC) which the client device received from an authorizing party system (APS), the client having consented to release the client information to the provider system, and the client information having been verified. The provider system uses the verified client information associated with the first MIC to verify or not verify the identity of the client before granting or denying the request to the client.


