Person Authentication via Mobile Device and Identification Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods are inefficient and inflexible, particularly due to the large and fixed nature of terminals used for authentication, limiting their application.
Innovation Solution
A method utilizing an electronically readable identification document that establishes communication connections between a device, the identification document, and a server to read and compare electronic identifications for authentication, employing protocols like PACE and TLS for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional authentication terminals are used, then authentication can be performed, but the terminals are large and fixed, limiting flexibility and portability
Solution Approach 1:
The patent replaces the mechanical/physical authentication terminal with a software-based authentication application running on mobile communication devices. The authentication functionality is implemented through software modules that communicate via electronic signals, eliminating the need for large fixed terminals while maintaining authentication capabilities.
Solution Approach 2:
The authentication system is designed to work across multiple types of communication devices (smartphones, tablets, computers) and support various authentication methods (password, biometric, token-based). This universal approach allows the same authentication mechanism to be deployed across different platforms and devices, greatly enhancing flexibility.
2Adaptability or versatility
If traditional authentication terminals are used, then authentication can be performed, but the terminals are fixed in location, limiting portability
Solution Approach 1:
The patent introduces an authentication server as an intermediary that centralizes security management and credential verification. The mobile device acts as a mediator between the user and the authentication system, running secure authentication protocols while the server provides centralized security policies and credential storage, maintaining reliability despite portability.
Solution Approach 2:
The physical fixed terminal is replaced with a software-based authentication system that runs on mobile devices with secure enclaves or trusted execution environments. These software-based security mechanisms provide comparable or superior security to physical terminals while enabling portability through wireless communication.
3Adaptability or versatility
If mobile communication devices are used for authentication, then portability and flexibility are improved, but secure communication channels must be established between multiple components
Solution Approach 1:
The authentication application establishes secure communication channels in advance before actual authentication occurs. SSL/TLS certificates are pre-configured, and secure sockets are established before sensitive data transmission, simplifying the authentication process while maintaining security despite the complexity of mobile communication environments.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method (100) for authenticating a person using an electronically readable identification document, comprising: establishing (101) a first communication link between a communication device and the identification document; establishing (103) a second communication link between an identification server and the communication device; reading (105) an electronic identification from the identification document by the identification server via the first communication link and the second communication link; and comparing (107) the read electronic identification with a pre-stored electronic identification to authenticate the person.