Secure Identification via Intermediary Proxy and Encrypted Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identification methods face challenges in ensuring secure, privacy-protecting remote identification of individuals, particularly due to issues with data tracking, complex security protocols, and the risk of personal data misuse by service providers, which can lead to centralized systems and lack of proof for identification.

Innovation Solution

A method is established for secure identification using a service provider as a proxy for communication between an identification card and a verification entity, with secure, one-way and mutually authenticated communication channels, ensuring that only encrypted identification data is shared, preventing fingerprinting and maintaining user anonymity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized identification solution is used, then identification can be performed by a central authority, but tracking of online activities and creation of identification histories for each individual becomes possible

Engineering Contradiction:
Improveidentification reliabilityVSAvoidtracking capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The service provider acts as an intermediary that forwards identification requests to the verification authority and receives encrypted identification data without being able to access or track the actual personal data. This mediator architecture allows centralized verification while preventing the service provider from tracking online activities or creating identification histories.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If decentralized certificate-based identification is used, then no central authority is needed, but service providers must verify certificate validity and status, and cross-provider tracking becomes possible through unique serial numbers

Engineering Contradiction:
ImprovedecentralizationVSAvoidcross-provider tracking
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the tracking capability from the identification system by using encrypted identification data that does not contain unique identifiers. The service provider receives only the necessary identification data encrypted with the user's public key, eliminating the ability to track across providers while maintaining decentralized operation.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If the German eID solution with Extended Access Control is used, then decentralized identification without data transmission is enabled, but all relevant communication and security protocols must be implemented by the service provider, making the system complex and error-prone

Engineering Contradiction:
Improvedata protectionVSAvoidprotocol complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The verification authority acts as a specialized intermediary that handles all complex security protocols and verification operations. The service provider simply needs to establish a communication channel with the verification authority and forward identification requests, significantly reducing the complexity burden on the service provider while maintaining strong data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If specialized identification providers are used to handle technical aspects, then identification can be performed securely, but these providers may store personal data and combine datasets from multiple service providers without technical measures to prevent it

Engineering Contradiction:
Improveidentification securityVSAvoidpersonal data storage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personal data from the identification process by using encryption where only the service provider can decrypt the identification data. The verification authority receives encrypted data that appears as random noise without unique identifiers, preventing the verification authority from storing or combining personal data while maintaining identification security.

Inventive Principle:
Principle #2Taking out (Extraction)

5Reliability

If no external identification provider is used, then service providers have no proof that identification has taken place, but using external providers creates risks of data misuse and centralized system characteristics

Engineering Contradiction:
Improveidentification proofVSAvoiddata misuse risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The verification authority serves as a trusted intermediary that provides cryptographic proof of identification without storing personal data. The service provider receives a verification result that confirms identification occurred, while the encrypted nature of the data transmission prevents the verification authority from misusing personal data, thus eliminating the data misuse risk associated with external providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4242890B1Method for secure identification of a person by a verification instance
Publication Date: 2025.01.15 VERIDOS GMBH
  • EP4242890B1 patent drawingFigure 1~2(b)
  • EP4242890B1 patent drawingFigure 2(c)
  • EP4242890B1 patent drawingFigure 2(d)

AI summary

The invention relates to a method for the secure identification of a person with an identification card (10) by a verification instance (14) vis-à-vis a service provider (12), in which a logical communication channel is established between the identification card (10) and the verification instance (14). A first key agreement is established between the verification instance (14) and the identification card (10), and a second key agreement is established between the service provider (12) and the identification card (10) for the encryption and authentication of the required identification data. The identification data is encrypted by the identification card (10) using the second key material and transmitted to the verification instance (14) in encrypted form using the first key material.This transmits the identification data encrypted with the second key material to the service provider (12) and confirms to the provider that the identification data originates from an identification card (10) that has been successfully validated. The service provider (12) decrypts the identification data transmitted by the verification instance (14).