Secure Document Personalization via Segmented Key Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The mass production of machine-readable travel documents (MRTDs) faces challenges in efficiently and securely personalizing document blanks using a private key, with existing methods lacking a robust solution for secure key distribution and protection.

Innovation Solution

A method involving the generation of key pairs with public and private keys, where control data is created in a high-security environment and transmitted to a production environment for secure storage in the document's integrated electronic circuit, ensuring the private key is inaccessible externally, and using end-to-end encryption for secure key transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If RFID interfaces are used for document personalization, then communication capability and data access are improved, but security against unauthorized reading deteriorates

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments cryptographic functions into separate modules: key pair generation, data structure creation, and personalization execution are separated into different environments (high-security vs. production). This segmentation allows each module to be optimized for its specific security requirements while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A data structure acts as an intermediary between the private key and the personalization process. The data structure contains public key information and is created in a high-security environment, then transmitted to the production environment where personalization occurs. This intermediary mechanism enables secure key distribution without exposing the private key.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If private keys are distributed for mass production personalization, then personalization efficiency is improved, but key security and protection deteriorates

Engineering Contradiction:
Improvepersonalization efficiencyVSAvoidkey security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The private key is extracted from the production environment entirely and kept only in the high-security environment. The data structure containing public key information is extracted and transmitted to the production environment, allowing personalization to proceed without the private key being present in the production system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The data structure is created in advance in the high-security environment before the personalization process in the production environment. This preliminary action ensures that all cryptographic preparations are completed under strict security conditions, enabling efficient mass production without compromising key security.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If sensitive data is made accessible for security checks, then verification capability is improved, but data protection from unauthorized access deteriorates

Engineering Contradiction:
Improveverification capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Different security levels are applied to different data elements within the document. The data structure contains information with varying access requirements, allowing some data to be more accessible for verification while maintaining stricter protection for sensitive elements through differentiated access control mechanisms.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2070250B1Method for personalizing documents, cryptographic system, personalization system and document
Publication Date: 2017.08.30 BUNDESDRUCKEREI GMBH
  • EP2070250B1 patent drawingFigure 1
  • EP2070250B1 patent drawingFigure 2
  • EP2070250B1 patent drawingFigure 3

AI summary

The invention relates to a method for personalizing documents (132), wherein each of the documents has an integrated electronic circuit (130) comprising the following steps: - receiving input data (110) for the personalization of the documents by means of a computer system (102) of a high-security environment (100), - generating a key pair comprising a public key and a private key (142) for each of the documents, - generating a data structure (140) from the input data and one of the public keys for each of the documents, - generating control data (112) for personalizing the documents with a respective one of the data structures and the private key assigned to the relevant data structure, - transmitting the control data from the computer system to a personalization device (114) of a production environment (101), - transmitting the data structures and the respectively assigned private keys from the personalization device to the documents in accordance with the control data, - storing the data structures in each case in a memory area (138) of the integrated electronic circuit, wherein the storage is effected under an access condition, - storing the private key assigned to the respective data structure in a memory area (138) of the integrated electronic circuit, wherein the storage is effected in such a way that the private key cannot be accessed externally.