Personal Data Verification With Time-Bound Key Publication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing personal data verification systems face challenges in ensuring data confidentiality and reducing technical and bureaucratic hurdles, as digital signatures can be easily reused and stored by service providers, leading to unauthorized data sharing and increased complexity.

Innovation Solution

A method involving a secure element to digitally sign personal data with a timestamp, where the cryptographic private key is published upon a predefined criterion, ensuring authenticity during communication and rendering the signature useless after a specific time, thus eliminating the need for intermediaries and simplifying the verification process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal data is provided with a digital signature to prove authenticity, then the authenticity of the data is improved, but the data can be easily reused and stored by service providers, leading to unauthorized data sharing

Engineering Contradiction:
Improveauthenticity of personal dataVSAvoidunauthorized data sharing and reuse
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by publishing the private key in advance before the signature verification occurs. The private key is published with a timestamp, and any signature created after this timestamp becomes invalid. This prevents service providers from storing and reusing signatures because the validation key changes over time, rendering previously stored signatures useless.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by making the private key dynamic and time-dependent rather than static. The private key is published at specific timestamps, and its validity changes over time. This dynamic approach ensures that signatures cannot be reused indefinitely, as the cryptographic validation key evolves, thereby preventing unauthorized data sharing while maintaining authenticity.

Inventive Principle:
Principle #15Dynamics

2Reliability

If an intermediary personal data service is introduced to verify digital signatures, then data security is improved, but the complexity of the verification process increases

Engineering Contradiction:
Improvedata securityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the intermediary verification service from the system and replaces it with a direct verification mechanism. Service providers can independently verify signatures by obtaining the current private key from the public authority's publication list, eliminating the need for complex intermediary services while maintaining security through the time-dependent key publication mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If service providers are given direct access to digital signatures, then verification efficiency is improved, but the risk of unauthorized data transmission to third parties increases

Engineering Contradiction:
Improveverification efficiencyVSAvoidunauthorized data transmission
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-publishing private keys with timestamps before verification occurs. Service providers receive efficient direct access to signatures, but the pre-published keys with time limits prevent unauthorized third-party transmission, as any signature created after the key's publication time becomes invalid.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses dynamics by implementing time-dependent private key publication. Service providers can efficiently verify signatures directly, but the dynamic nature of key publication ensures that signatures cannot be legitimately used for unauthorized third-party transmission, as the validation key changes over time, rendering old signatures useless.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4425820B1A method and a system for verifying personal data
Publication Date: 2025.09.17 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP4425820B1 patent drawingFigure 1
  • EP4425820B1 patent drawingFigure 2
  • EP4425820B1 patent drawingFigure 3a~4

AI summary

The invention relates to a method and a system for verifying personal data, wherein a cryptographic private key used for digitally signing the personal data is published when a publication criterion is fulfilled.