Token-Based Authentication for Electronic ID Card Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems restrict access to electronic ID cards to only trustworthy institutions due to the requirement of special CV certificates, preventing private individuals or institutions from accessing these documents.
Innovation Solution
A token with a private key corresponding to the CV certificate is used for authentication with the electronic ID card, allowing access only if the identification data matches a stored reference data, enabling limited access to specific documents and shifting the security mechanism to the token.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a CV certificate with private key is issued to a reading device to enable authentication and access to electronic ID cards, then the reading device can perform authentication and access control, but private institutions or individuals cannot access electronic ID cards because the private key cannot be freely distributed
Solution Approach 1:
The system segments the authentication functionality by separating the CV certificate (held by the document) from the authentication capability (provided by the token). The token contains a private key that corresponds to the CV certificate but is restricted to specific documents through identification data matching, allowing selective access without distributing broad authentication rights.
Solution Approach 2:
The token acts as an intermediary between the reading device and the electronic ID card. It holds the private key corresponding to the CV certificate and mediates authentication by verifying identification data, enabling controlled access for private institutions while maintaining security through document-specific restrictions.
2Reliability
If the private key for the CV certificate is restricted to trustworthy institutions only, then high security is maintained, but private individuals or institutions are prevented from accessing electronic ID cards
Solution Approach 1:
The token implements local quality by restricting authentication capability to specific documents through identification data matching. The private key in the token is not universally valid but only works with documents whose identification data matches stored reference data, creating localized access rights for different documents.
Solution Approach 2:
The system changes the parameter of certificate validity from universal (trusted institutions can access any document) to specific (tokens can access only matching documents). This is achieved by adding identification data verification as an additional parameter that must be satisfied alongside cryptographic authentication.
3Adaptability or versatility
If a token with private key is used for authentication, then private individuals can access specific electronic ID cards, but the system must verify identification data to prevent unauthorized access
Solution Approach 1:
The token performs preliminary action by storing reference identification data in advance and automatically verifying it during authentication. This pre-stored reference data enables the token to quickly determine whether a document should be accessible without requiring complex real-time verification procedures.
Solution Approach 2:
The token performs self-service by autonomously verifying identification data against stored reference data and controlling access based on the match result. The reading device simply executes authentication commands; the token independently determines whether to grant access, reducing the complexity burden on the overall system.
Data Source
Figure 1
Figure 2
AI summary
The method involves reading out an identification date (ID) i.e. personal identity number, of a document (E) e.g. electronic pass, by a token (T) via a reading device (L) after successful authentication in relation to a document. The token verifies whether the identification date coincides with a reference date (RD) stored in the token. The token permits reading out of the data of the document via the reading device, during coincidence of the identification date with the reference date. The token prevents reading out of data of the document during non-coincidence of the identification date. The token is utilized as a chip card or a smart card. Independent claims are also included for the following: (1) a computer program product, which is directly loaded in an internal memory of a digital computer (2) a device for accessing a machine readable document.