Terminal-Based Identity Verification for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for verifying user identity, such as those used for accessing banking or medical data, often require dedicated card readers that are not always accessible, especially in emergency situations or when users are on the move, leading to inefficiencies and limitations in secure data transmission.

Innovation Solution

A method that enrolls a user's terminal by reading a security component, transforming authentic identity data with terminal data to create a derived identity, which is stored and used for strong authentication, allowing secure access to services via a communicating terminal like a smartphone or tablet, without the need for additional card readers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated card readers are deployed for verifying user identity, then security verification capability is improved, but device accessibility and portability deteriorate

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies universality by enabling the terminal device to perform multiple functions: it serves as both a communication device and a security verification device. The terminal stores derived identity data and can verify user identity without requiring separate dedicated card readers, thus making the security verification capability universal across different terminal devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent extracts the security verification function from the dedicated card reader hardware and embeds it into the terminal device's software and storage systems. By storing derived identity data directly in the terminal and performing verification algorithms locally, the system removes the need for external dedicated reading terminals.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If multiple dedicated readers are deployed for different services, then service verification capability is improved, but system complexity and cost increase

Engineering Contradiction:
Improveservice verification capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The terminal device is designed to handle multiple service verifications using a single unified approach. It stores derived identity data that can be verified across different services (banking, healthcare, etc.) without requiring service-specific readers, thus reducing system complexity while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple service verification capabilities into a single terminal device. By combining identity storage, derivation, and verification functions into one integrated system, the patent eliminates the need for separate readers for different services, thereby reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If derived identity is stored in terminal for strong authentication, then authentication robustness is improved, but security risk and data storage requirements increase

Engineering Contradiction:
Improveauthentication robustnessVSAvoiddata storage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent transforms the identity data by deriving a condensed representation that maintains authentication robustness while reducing storage requirements. The derived identity data is a transformed version of the original identity information, optimized for efficient storage and quick verification.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2826005B1Securing a data transmission
Publication Date: 2019.04.24 ORANGE SA
  • EP2826005B1 patent drawingFigure 1
  • EP2826005B1 patent drawingFigure 2~3
  • EP2826005B1 patent drawingFigure 4

AI summary

The invention relates to a securing of data transmission by verification of an identity of a user, comprising: a prior step (INIT) of enrolling a terminal of the user, comprising: an association between an authentic identity datum of the user and a datum of a terminal available to the user and communicating via a network, the association being stored with data regarding contact of the terminal via the network, and a determination of an identity derived at least from said information, stored in the memory of the terminal, in correspondence with a datum specific to the user, with a view to a subsequent strong authentication based both on the datum specific to the user and on the derived identity, as well as a current step (VERIF) of verifying the user's identity, comprising: on the basis of the data regarding contact of the terminal, a contact of the terminal via the network so as to launch at the terminal interrogation of a user so as to ask the user to enter the datum specific to the user, as well as a verification of this datum at the terminal, the verification of the user datum being positive, a verification of the derived identity, and, in the case of successful verification of the derived identity, a validation of the verification of identity of the user.