NFC Mobile eID Authentication Without a Desktop Card Reader
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods require a card reader connected to a desktop PC for electronic identity card authentication, limiting their usability on devices without such hardware.
Innovation Solution
A method utilizing an NFC-enabled mobile device to establish a secure connection between an electronic identification element and an authentication service, enabling authentication without a card reader by using the mobile device as a communication link.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a card reader connected to a desktop PC is used for electronic identity card authentication, then authentication can be performed with electronic identity cards, but the system requires additional hardware that is not always available and limits usability
Solution Approach 1:
The mobile device serves as an intermediary between the electronic identity card and the authentication service. The mobile device establishes a communication channel that enables the ID card to communicate with the authentication server without requiring a card reader at the stationary device. This mediator approach resolves the contradiction by eliminating the need for additional hardware while maintaining authentication capability.
Solution Approach 2:
The mobile device is utilized for multiple purposes: it acts as both the authentication client and the communication bridge to the ID card. By making the mobile device universal for both functions, the system eliminates the need for separate card reader hardware, thereby improving ease of operation without sacrificing authentication functionality.
2Adaptability or versatility
If a card reader is required for authentication, then secure reading of ID card data is possible, but the system becomes unavailable on devices without card reader hardware
Solution Approach 1:
The mobile device acts as a mediator that bridges the gap between devices without card readers and the electronic identity card. It establishes a communication channel that enables authentication on any device with a mobile operating system, thereby improving adaptability while maintaining reliable authentication through the intermediary's secure connection capabilities.
3Ease of operation
If direct reading of the ID card by the stationary device is used, then authentication is straightforward, but it requires the stationary device to have card reading capability which limits accessibility
Solution Approach 1:
The mobile device serves as an intermediary that enables ID card reading on stationary devices without card readers. The process remains simple for the user - they only need to bring their mobile device and ID card - while the intermediary handles the complex communication protocols, thereby maintaining ease of operation while improving device accessibility.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables user authentication on devices lacking a card reader by leveraging the mobile device to facilitate secure connections, allowing seamless access to services using electronic identity cards.
Implementation Method 1
communication between the ID card and a suitable 'smartphone' (mobile phone with extensive computer functionalities) is also possible via near-field communication (NFC)
Data Source
Figure 1
Figure 2
AI summary
Authenticating a user to a service provider (SP) using an electronic identification element (EI), wherein the user has a stationary user terminal (120) and a mobile user terminal (122), by: establishing a connection (S10) between the stationary user terminal (120) and a server (130) of the service provider and communicating (S20) a contact number of the mobile user terminal (122); generating (S30) a secret (S) and an identifier (ID) on the server (130) and transmitting (S40) together with a hyperlink (URL) to the mobile terminal (122); establishing (S50) a connection between the mobile terminal and an electronic authentication service (eID) using the URL and transmitting the secret (S) and the ID to the eID; establishing a coupling (NFC) between the mobile terminal (122) and the identification element (EI);Performing the authentication process (S55) using a secure channel between the identification element and the authentication service; sending (S60) an authentication confirmation along with the ID from the eID to the server (130); opening (S70) a personalized access for the stationary user terminal (120).