Person Authentication via Mobile Device and Identification Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods are inefficient and inflexible, particularly due to the large and fixed nature of terminals used for authentication, limiting their application.

Innovation Solution

A method utilizing an electronically readable identification document that establishes communication connections between a device, the identification document, and a server to read and compare electronic identifications for authentication, employing protocols like PACE and TLS for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional authentication terminals are used, then authentication can be performed, but the terminals are large and fixed, limiting flexibility and portability

Engineering Contradiction:
ImproveflexibilityVSAvoidterminal size
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical authentication terminal with a software-based authentication application running on mobile communication devices. The authentication functionality is implemented through software modules that communicate via electronic signals, eliminating the need for large fixed terminals while maintaining authentication capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system is designed to work across multiple types of communication devices (smartphones, tablets, computers) and support various authentication methods (password, biometric, token-based). This universal approach allows the same authentication mechanism to be deployed across different platforms and devices, greatly enhancing flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If traditional authentication terminals are used, then authentication can be performed, but the terminals are fixed in location, limiting portability

Engineering Contradiction:
ImproveportabilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary that centralizes security management and credential verification. The mobile device acts as a mediator between the user and the authentication system, running secure authentication protocols while the server provides centralized security policies and credential storage, maintaining reliability despite portability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The physical fixed terminal is replaced with a software-based authentication system that runs on mobile devices with secure enclaves or trusted execution environments. These software-based security mechanisms provide comparable or superior security to physical terminals while enabling portability through wireless communication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If mobile communication devices are used for authentication, then portability and flexibility are improved, but secure communication channels must be established between multiple components

Engineering Contradiction:
ImproveflexibilityVSAvoidcommunication protocol
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication application establishes secure communication channels in advance before actual authentication occurs. SSL/TLS certificates are pre-configured, and secure sockets are established before sensitive data transmission, simplifying the authentication process while maintaining security despite the complexity of mobile communication environments.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2881879B1Method for authenticating a person
Publication Date: 2019.02.13 BUNDESDRUCKEREI GMBH
  • EP2881879B1 patent drawingFigure 1
  • EP2881879B1 patent drawingFigure 2
  • EP2881879B1 patent drawingFigure 3

AI summary

The invention relates to a method (100) for authenticating a person using an electronically readable identification document, comprising: establishing (101) a first communication link between a communication device and the identification document; establishing (103) a second communication link between an identification server and the communication device; reading (105) an electronic identification from the identification document by the identification server via the first communication link and the second communication link; and comparing (107) the read electronic identification with a pre-stored electronic identification to authenticate the person.