Token-Based Authentication for Electronic ID Card Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems restrict access to electronic ID cards to only trustworthy institutions due to the requirement of special CV certificates, preventing private individuals or institutions from accessing these documents.

Innovation Solution

A token with a private key corresponding to the CV certificate is used for authentication with the electronic ID card, allowing access only if the identification data matches a stored reference data, enabling limited access to specific documents and shifting the security mechanism to the token.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a CV certificate with private key is issued to a reading device to enable authentication and access to electronic ID cards, then the reading device can perform authentication and access control, but private institutions or individuals cannot access electronic ID cards because the private key cannot be freely distributed

Engineering Contradiction:
ImprovesecurityVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the authentication functionality by separating the CV certificate (held by the document) from the authentication capability (provided by the token). The token contains a private key that corresponds to the CV certificate but is restricted to specific documents through identification data matching, allowing selective access without distributing broad authentication rights.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The token acts as an intermediary between the reading device and the electronic ID card. It holds the private key corresponding to the CV certificate and mediates authentication by verifying identification data, enabling controlled access for private institutions while maintaining security through document-specific restrictions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the private key for the CV certificate is restricted to trustworthy institutions only, then high security is maintained, but private individuals or institutions are prevented from accessing electronic ID cards

Engineering Contradiction:
ImprovesecurityVSAvoidaccess ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The token implements local quality by restricting authentication capability to specific documents through identification data matching. The private key in the token is not universally valid but only works with documents whose identification data matches stored reference data, creating localized access rights for different documents.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of certificate validity from universal (trusted institutions can access any document) to specific (tokens can access only matching documents). This is achieved by adding identification data verification as an additional parameter that must be satisfied alongside cryptographic authentication.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If a token with private key is used for authentication, then private individuals can access specific electronic ID cards, but the system must verify identification data to prevent unauthorized access

Engineering Contradiction:
Improveaccess availabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The token performs preliminary action by storing reference identification data in advance and automatically verifying it during authentication. This pre-stored reference data enables the token to quickly determine whether a document should be accessible without requiring complex real-time verification procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The token performs self-service by autonomously verifying identification data against stored reference data and controlling access based on the match result. The reading device simply executes authentication commands; the token independently determines whether to grant access, reducing the complexity burden on the overall system.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2169579B1Method and device for accessing a machine readable document
Publication Date: 2016.06.29 GIESECKEDEVRIENT IP
  • EP2169579B1 patent drawingFigure 1
  • EP2169579B1 patent drawingFigure 2

AI summary

The method involves reading out an identification date (ID) i.e. personal identity number, of a document (E) e.g. electronic pass, by a token (T) via a reading device (L) after successful authentication in relation to a document. The token verifies whether the identification date coincides with a reference date (RD) stored in the token. The token permits reading out of the data of the document via the reading device, during coincidence of the identification date with the reference date. The token prevents reading out of data of the document during non-coincidence of the identification date. The token is utilized as a chip card or a smart card. Independent claims are also included for the following: (1) a computer program product, which is directly loaded in an internal memory of a digital computer (2) a device for accessing a machine readable document.