WO2018014103A1 - Sistema de provisionamento, assinatura e verificação de documento eletrônico, método de provisionamento e assinatura de documento eletrônico e método de verificação de autenticidade de documento eletrônico - Google Patents
Sistema de provisionamento, assinatura e verificação de documento eletrônico, método de provisionamento e assinatura de documento eletrônico e método de verificação de autenticidade de documento eletrônico Download PDFInfo
- Publication number
- WO2018014103A1 WO2018014103A1 PCT/BR2017/050204 BR2017050204W WO2018014103A1 WO 2018014103 A1 WO2018014103 A1 WO 2018014103A1 BR 2017050204 W BR2017050204 W BR 2017050204W WO 2018014103 A1 WO2018014103 A1 WO 2018014103A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- code
- machine readable
- server
- electronic document
- cbb
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/33—User authentication using certificates
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/34—User authentication involving the use of external additional devices, e.g. dongles or smart cards
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06K—GRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
- G06K19/00—Record carriers for use with machines and with at least a part designed to carry digital markings
- G06K19/06—Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
- G06K19/067—Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0478—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload applying multiple layers of encryption, e.g. nested tunnels or encrypting the content with a first key and then with at least a second key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/409—Device specific authentication in transaction processing
- G06Q20/4097—Device specific authentication in transaction processing using mutual authentication between devices and transaction partners
- G06Q20/40975—Device specific authentication in transaction processing using mutual authentication between devices and transaction partners using encryption therefor
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q2220/00—Business processing using cryptography
- G06Q2220/10—Usage protection of distributed data files
Definitions
- the present invention describes an electronic document provisioning, authentication and verification system, an electronic document provisioning and authentication method and an electronic document authenticity verification method.
- the present invention is in the fields of Information Technology, more specifically in the area of Information Security.
- Modern mobile communication devices such as the mobile phone or the so-called smart mobile phone (smartphone) have become almost ubiquitous in society. Most adults and teens routinely carry these gadgets as well as an increasing number of children. Most nowadays it is easier for the citizen to forget his wallet at home than his cell phone.
- the mobile handset incorporates considerable processing power and sophisticated communications with a powerful display system and built-in sensors.
- the authority carrying the citizen's device for the purpose of verification of validity, may damage the same, suffering consequences due to such adversity and may also have access to confidential information contained in the device, and may even even be charged with invasion of privacy in some cases.
- WO 2015/1 17212 A1 refers to the generation and issuance of security code issued by combining data sent by the customer, and optionally with the issuing agency's geolocation and in which the data set is signed. digitally in the Public Key Infrastructure Standard (PKI) and encrypted with a cryptographic key pair for this purpose.
- PKI Public Key Infrastructure Standard
- WO 2010 / 028903A1 A1 relates to a method of provisioning and surveillance of identification document with optically identifiable data and optical representation of a digital signature of the document.
- the document does not mention participation in the provisioning of the document from an electronic device, and thus does not guarantee the authenticity of the electronic device on which the document could be displayed.
- US 2016/0162898 A1 discloses a two-dimensional code generated from authenticated data that can be displayed on an authentication device. Said code generated on a first device is read and decoded by an authentication application of an authentication device. Then, a second two-dimensional code is generated from the information of the first code in the authentication device.
- the system requires the second code to be generated by an authentication device.
- the method is vulnerable to replication, since obtaining the first code can replicate the method since the second code is generated on the authentication device and does not guarantee that code generation is done on a mobile device. user.
- Document "US 2014/0013106 A1" discloses methods and systems for authenticating electronic identity documents that promote the sending of encrypted and decoded electronic documents from a certification authority to a mobile device.
- the document solution is vulnerable to replication as it does not provide evidence of authenticity of the mobile device on which the document will be displayed.
- the present invention aims at solving the constant problems in the state of the art from the provision and verification of electronic documents comprising the digital signature of data, ensuring the authenticity of the issuance of the electronic document by performing data structure formation on the issuing agency's server, the authenticity of the requesting mobile device and the authenticity of the relationship between the issuing agency and the mobile device by through Machine Readable Codes.
- the present invention provides an electronic document provisioning, signing and verification system comprising at least:
- The. a first device (DM);
- server (S) is associated with first device (DM) and database (BD) via secure communication channels;
- the encryption processor (P) is communicating to the server (S) and comprises authentication cryptographic key generator;
- the device (DM) comprises hidden cryptographic key storage, one-time password and machine readable code generating algorithm.
- the present invention provides an electronic document provisioning and signing method implemented in the system according to the first object, comprising the steps of:
- CBB machine readable base code
- CBB machine readable base code
- LDSA signed structure
- server (S) or first device (DM) is configured for machine readable base code (CBB) generation.
- CBB machine readable base code
- the present invention provides a method for verifying electronic document authenticity comprising at least the steps of:
- The. receiving sender authentication key (CH3) from a server (S) by a second device (DA);
- said electronic document authenticity verification method further comprises at least one of the steps of:
- CBA read machine readable authentication code
- CBI machine readable image code reading per second device
- inventive concept common to all claimed protection contexts is based on the provisioning of an electronic document comprising the generation of codes for verifying the authenticity of the document in relation to the user and the issuer of the document.
- Figure 1 depicts the infrastructure of an electronic document issuing unit unit comprising a secure communication network, server (S), database (BD) and a cryptographic processor (P).
- S server
- BD database
- P cryptographic processor
- Figure 2 represents the mobile device (DM) communicating to the sending server infrastructure server (S) over the secure network.
- Figure 3 shows a schematic of the electronic document request step by a user at the device (DM) comprising the registration number (NM) and document number (ND) sending.
- Figure 4 represents the flow of data sent by the mobile device (DM) to the issuing agency's server (S) at the request stage: registration number (NM), identification number (NI) and document number (ND) ).
- Figure 5 represents the data flow between the issuing agency server (S), the database (BD) and the cryptographic processor (P).
- the database (BD) is searched for the image and data (D) of the electronic document.
- a pair of encryption keys (CH1 and CH2) are sent to server (S).
- Figure 6 represents the data flow between the issuing server (S) and the cryptographic processor (P), where the data structure (LDS) is sent to the cryptographic processor (P) for signature, forming the signed structure (LDSA).
- S issuing server
- P cryptographic processor
- FIG 7a represents an embodiment in which machine-readable base code (CBB) content is generated by the issuing agency's server (S) or the device (DM).
- said base code (CBB) comprises type 1 structure (LDS) composed of data (D), identification number (NI), public key (CH1) and HASH (HF).
- LDS type 1 structure
- D data
- NI identification number
- CH1 public key
- HASH HASH
- FIG. 7b represents one embodiment the machine readable base code (CBB) content is generated by the issuing agency server (S) or the device (DM).
- said base code (CBB) comprises type 2 structure (LDS) composed of data (D), identification number (NI), public key (CH1) and image.
- Figure 8 represents, in one embodiment, the sending by the server (S) of the issuing body of the base code (CBB), the data (D), the image and the private cryptographic key (CH2) to the mobile device ( DM).
- CBB base code
- D data
- CH2 private cryptographic key
- Figure 9 represents the reassembly by the citizen's mobile device (DM) of the identification document image identical to the printed document.
- Figure 10 represents the first machine readable base code (CBB) generated by the identification document issuing server (S) or device (DM) and is displayed on the device screen (DM).
- CBB machine readable base code
- Figure 11 discloses a flowchart of an embodiment of the present invention comprising requesting an electronic document by a first element, searching data (D) in database (BD), sending data (D), from photo. , from the encryption key pair, coming from a dedicated encryption processor (P), and the device identification number (NI) (DM) to a server (S), forming a structure (LDS) on the server (S) ), digital authentication of the LDS framework (LDSA) on a dedicated encryption processor (P) and generation of a machine readable base code (CBB).
- Figure 12 shows a flowchart of an embodiment comprising requesting and provisioning an electronic document by a user of a device (DM), wherein the encryption processor (P) is comprised in the device (DM) and sends the key.
- cryptography CH1 to structure (LDS) on server (S) and issuing body (OE)
- the device (DM) reassembles the document (DM) and generates the machine-readable base code (CBB).
- CBB machine-readable base code
- Figure 13 represents the machine readable authentication code (CBA) which is generated by the citizen's mobile device (DM) being displayed on its screen.
- CBA machine readable authentication code
- Figure 14 represents the machine readable image code (CBI) which is generated by the citizen's mobile device (DM) being displayed on its screen.
- CBI machine readable image code
- Figure 15 represents the content of the machine readable authentication code (CBA) generated by the citizen's mobile device (DM), which comprises the time of its generation (T) and the unique identification number (NI) of the citizen's mobile device (DM).
- CBA machine readable authentication code
- Figure 16 depicts the content of the machine readable image code (CBI) generated by the citizen mobile device (DM) comprising the citizen photo.
- CBI machine readable image code
- Figure 17 shows a flowchart of one embodiment of the identity document authenticity check.
- the present invention provides an electronic document provisioning, authentication and verification system comprising at least: a first device (DM), a database (BD), a server (S) and a processor encryption (P).
- DM first device
- BD database
- S server
- P processor encryption
- Server (S) is associated with device (DM) and database (BD) via secure communication channels.
- the server (S) comprises machine readable code generator.
- Machine readable code means machine readable code. Codes generated by encoding data that are readable by a device include means for reading and / or scanning codes, such as QR (Quick Response) codes, bar codes, motion QR-Codes, or any other machine readable code. .
- server (S) is a computing system comprising data processing. In one embodiment, server (S) comprises Machine Readable Codes generator.
- the device (DM) is an electronic device capable of connecting to wireless or wired communication networks, with or without internet access, for example, a smartphone, tablet, notebook or computer.
- the first device (DM) comprises readable code generation means for verifying the authenticity of the electronic document.
- the device (DM) comprises provisioned electronic document display interface.
- the device (DM) comprises hidden cryptographic key storage, that is, the cryptographic keys stored on said device are not available and / or accessible to a user, so as to prevent a malicious person from modifying any key or improperly collecting information attempting to misuse or steal data.
- the device (DM) comprises a one-time password generator algorithm, that is, the device is capable of generating a password that is discarded after its use.
- said one-time password generator algorithm is an OTP (One Time Password) generator algorithm.
- the encryption processor (P) is communicating to the server (S) and comprises authentication cryptographic key generator.
- the encryption processor (P) is a processor dedicated to this function and capable of managing and protecting digital keys for authentication and execution of encryption processing, such as a Hardware Security Module (HSM).
- HSM Hardware Security Module
- the encryption processor (P) is comprised of the first device (DM) and is communicating to the server (S) via secure communication channels.
- the cryptographic processor (P) may be implemented in the device master processor (DM) or be a processor dedicated to the generation of cryptographic codes, integrated into the device architecture (DM) and capable of communicating with the master processor (DM) via, for example, a conventional data bus.
- the encryption processor (P) comprises authentication cryptographic key generator.
- Said cryptographic key generator in one embodiment, is an elliptic curve key generation algorithm, quantum cryptography, or any other asymmetric key generator algorithm.
- the database is a system comprising a set of files that refer to records related to citizen identification documents. For example: biographical data and photos relating to ID cards, work cards, national driver's licenses, individual records, passports, electoral titles and / or civil identity records.
- Said secure communication channels comprise infrastructure that promotes data exchange between server (S), device (DM) and database (BD), such as secure ethernet or wireless communication networks, eg, Wifi
- the system operates in the secure environment of a document issuing agency, where a citizen requests the provisioning and digital personalization of their identification document and in which employees enter their registration numbers (Figure 3).
- the system operates in a secure environment, such as in a document issuing body comprising protected communications networks ( Figures 1 and 2).
- the system comprises a second device (DA) comprising machine readable code reading means and issuing body encryption key (CH3).
- the second device (DA) is able to verify the authenticity of a code generated by the first device (DM).
- the machine readable code reading medium is a CCD reader, a two-dimensional image scanner, a pen-type reader or any device comprising image processing means.
- the encryption key of the issuing agency corresponds with a digital signature for verifying the authenticity of the signature performed at an issuing agency or any other location comprising digital signature means of a data structure.
- the system comprises the calculation of image HASH (HF) to increase the security in the authenticity of the electronic document.
- a HASH (HF) calculator algorithm is implemented on the server (S) and / or the first device (DM) and / or the second device (DA).
- the electronic document is an electronic identification document (EID), such as a driver's license, general registration (RG), individual registration (CPF), passport, employee identification card. Further, said document may be a vehicle registration certificate (CRV), event ticket or any other electronic document.
- EID electronic identification document
- RG general registration
- CPF vehicle registration certificate
- event ticket event ticket
- the present invention provides an electronic document provisioning and signing method implemented in the first object system and comprising the steps of: first device (DM) electronic document request to a server (S); search for data (D) in database (BD) by server (S); sending data (D) from the database (BD) to the server (S); structure formation (LDS) on server (S) based on data (D) from the previous step; digital signature of the frame (LDS) on the encryption processor (P); and generating a machine readable base code (CBB).
- first device (DM) electronic document request to a server (S) search for data (D) in database (BD) by server (S); sending data (D) from the database (BD) to the server (S); structure formation (LDS) on server (S) based on data (D) from the previous step; digital signature of the frame (LDS) on the encryption processor (P); and generating a machine readable base code (CBB).
- the electronic document request step comprises the beginning of document provisioning.
- the request is performed through secure communication channels.
- a user enters identification data, such as the employee registration number and document information of a citizen who has requested the provisioning of the document.
- the identification data includes the Employee Registration Number (NM), Requested Document Registration Number (ND), and Device Identification Number (NI) (DM) ( Figure 4) .
- the Device Identification Number is a unique code provided for each device (DM) manufactured by a company specializing in the field, for example, the International Mobile Equipment Identity (IMEI) code of the device. .
- IMEI International Mobile Equipment Identity
- the database (BD) comprises data (D) relating to the document to be issued, such as biographical data or registration data and images.
- the database (BD) is comprised of the issuing agency (OE) infrastructure. Also, the database (DB) may be comprised in a cloud, where it is accessed upon receipt of the request.
- the data search is performed according to the requested document registration number (ND).
- ND document registration number
- the database DB
- ND registration number
- D Data submission
- LDS Structure Forming
- LDS LDS on server (S) comprising data (D) is formed for signature.
- a cryptographic key or, in one embodiment, a cryptographic key pair, a public key (CH1) and a private key is sent by the encryption processor (P) to the server (S)
- the key pair is generated in the encryption processor (P) by Elliptic Curves, Quantum Encryption, RSA, or any other asymmetric encryption key generator algorithm.
- the device (DM) receives from the server (S) a private key (CH2) keeping it in hidden storage.
- the encryption processor (P) may be comprised in the device (DM) and digital signature is performed therein, and in this embodiment the private key (CH2) is generated in the device itself
- the structure (LDS) comprises one of: identification data,
- Image HASH (HF), individual image, identification number (NI), and public cryptographic key (CH1).
- the server (S) then receives the biographical data (D) and the photo from the database (BD), as well as the encryption key pair of Active authentication (CH1 and CH2) come from the dedicated encryption processor (P).
- the data (D), the photo HASH, the device identification number (NI) (DM), and a public key (CH1) comprised in the encryption key pair are assembled into a structure ( Logical Data Structure (LDS).
- LDS Logical Data Structure
- the server (S) sends the biographical data (D) and the photo from the database (BD) to the device (DM), and it sends the encryption processor public key (CH1) (P) for the server (s).
- CH1 public key
- the server (S) calculates the HASH (HF) of the image from the database (BD) for frame formation (LDS).
- the device (DM) calculates the HASH (HF) of the frame forming image (LDS).
- said image refers to the image of the individual, which is understood in the data (D), searched in the database (BD).
- LDS Digital Frame Signing
- P Encryption Processor
- LDSA Signed Frame
- the structure (LDS) is sent from the server (S) to the encryption processor (P) where the signed packet formation (LDSA) packet is signed.
- This digital signature can be performed by conventional means, which ensure the security of the information being signed, in this case the structure (LDS).
- the signed structure (LDSA) is then sent to the device (DM), either sent directly by the encryption processor (P) or server (S), so that, for this second option, processor (P) returns the signed structure (LDSA) to the server (S) before it is sent to the device (DM).
- said encryption processor (P) is comprised in the device (DM) or the issuing agency (OE) infrastructure of the document.
- the machine-readable base code is formed by means of the signed structure (LDSA).
- CBB Machine Readable Base Code
- CBB machine readable base code
- Said code (CBB) may comprise information regarding document data (D), user image, user image HASH, device identification number (NI), and public key (CH1), as this information may be composed directly into the signed structure (LDSA) as detailed above.
- the base code (CBB), signed packet (LDSA), photo, and private cryptographic key (CH2) of the encryption key pair are sent to the mobile device (DM) as per the scheme. revealed in Figure 8.
- the base code (CBB) is generated on the server (S) and sent device (DM) for further reading.
- the base code (CBB) is generated at the device (DM) upon receipt of frame (LDS).
- OE issuing agency's infrastructure
- DM device itself
- the present invention comprises the generation of an authentication code (CBA) on the device itself (DM), which, like the base code (CBB), is also a type of code. machine readable.
- the authentication code (CBA) is generated by a one-time password algorithm, such as an OTP (One Time Password) generator algorithm.
- this authentication code (CBA) is digitally signed by the private cryptographic key (CH2) which, as described above, is paired with the public key (CH1).
- CH2 private cryptographic key
- CH1 public key
- the code comprises at least one of the time equivalent to the authentication code generation request (CBA) and the device identification number (NI). This way, the document ensures that the code was generated at that time by that device (DM).
- Machine Readable Image Code (CBI) Generation Step further, the present invention comprises the generation of a machine readable image code (CBI).
- the image code (CBI) as well as the authentication code (CBA) mentioned above is also generated by the device (DM).
- Said code (CBI) comprises the identification image so that it is possible to verify the authenticity of the image provided by the electronic document.
- Said image for generating said code (CBI) is obtained from the frame (LDS).
- the identification image contained in the frame (LDS) is the image contained in the data (D) fetched from the database (BD) as defined above.
- the present document provisioning method comprises tools for generating a base code (CBB), an authentication code (CBA) and image code (CBI).
- CBB base code
- CBA authentication code
- CBI image code
- the authentication code (CBA) and image (CBI) code generation request occurs after the machine-readable base code (CBB) is displayed and sequentially displayed for full document display. Also, the authentication (CBA) and image (CBI) codes can be displayed independently of each other after the base code (CBB) is displayed.
- the base code (CBB), the authentication code (CBA), the image code (CBI) are displayed on an interface comprised in the device (DM).
- the biographical data (D) and photo are displayed on a device interface (DM).
- DM device interface
- the identifying image contained in the biographical data (D) and the photo are sent to the device (DM) and displayed on the interface of said device (DM).
- the present invention provides a method for verifying the authenticity of an electronic document comprising the minus the steps of receiving sender authentication key (CH3) from a server (S) by a second device (DA) and reading a machine readable base code (CBB) using said second device (DA) .
- CH3 sender authentication key
- S server
- DA second device
- CBB machine readable base code
- the verification method comprises at least one of the steps of reading machine readable authentication code (CBA) by the second device (DA) and reading machine readable image code (CBI) by second device ( GIVES).
- CBA machine readable authentication code
- CBI machine readable image code
- the present verification method allows the reading of the base code (CBB) and, in sequence, the reading of the codes (CBA) and / or (CBI).
- This method may be implemented in the verification of the provisioned and authenticated electronic document in accordance with the previously defined electronic document provisioning and signature method.
- the code reading step (CBB) comprises, in one embodiment, the digital signature verification of the electronic document by means of the sender authentication key (CH3).
- the base code reading (CBB) may comprise verifying the data veracity (D) of the first device (DM) based on the information read from the machine readable base code (CBB).
- this reading step may comprise verifying identification number (NI) veracity of the first device (DM) with identification number read in the machine readable base code (CBB).
- NI identification number
- CBB machine readable base code
- any of the above steps can be performed to analyze the validity of the electronic document.
- all steps can be performed to ensure greater authenticity of document parameters.
- the verifying user analyzes the veracity of the digital signature of the structure (LDS), checking through the authentication key of the issuer (CH3), besides being able to read all the information. entered in said base code (CBB).
- the second device (DA) reads and stores the public key (CH1) contained in the base code (CBB).
- the machine authentication code (CBB) reading step comprises, in one embodiment, verifying the digital signature veracity of the machine readable authentication code (CBA) using the public cryptographic key (CH1) obtained from machine readable base code (CBB).
- CBA machine readable authentication code generation
- it may comprise verifying the identification number (NI) obtained in the machine readable authentication code (CBA) with the identification number (NI) obtained in the machine readable base code (CBB).
- CBA machine readable authentication code
- CBB machine readable base code
- any of said steps can be performed for code validity checking (CBA), whereby performing all the steps described ensures greater reliability in verifying document authenticity.
- CBA code validity checking
- the image code reading (CBI) step comprises the calculation of the identification image HASH read in the image validation code (CBI) and comparison of the calculated HASH to the HASH (HF) read in the readable base code. machine (CBB).
- the method verifies the authenticity of the data referring to the image of the individual.
- the base (CBB), authentication (CBA), and image (CBI) codes are sequentially verified to increase process reliability and fully scan the document.
- CBI image codes
- CBA Authentication
- the second device (DA) is an authority device for performing a citizen's document verification, verifying its validity and authenticity by the method and system previously described.
- the present object allows the use of a large number of mobile communication devices. Verification of the authenticity of documents to be performed between a citizen and an authority can be performed without the need to synchronize the citizen's device with that of the authority. And it can be done offline without access to any remote database and communication signal. This is true since both citizens and authorities have devices with cryptographic keys already stored on their devices, as well as algorithms to prevent fraud.
- the present project proposes a solution for the realization of digital identification of individuals by solving problems related to offline operation, vulnerability to falsification of data as well as identification image, and also proposes a method of verifying the authenticity of document without the need for physical contact from the authority with the device carrying the document to be verified.
- Digital document can be customized at issuing agency quickly. Moreover, the previously described methods and systems promote a quick verification of its authenticity, since it is enough to read the codes by an electronic device.
- the encryption processor (P) is comprised of a first device (DM) to which the electronic document is sent.
- the device (DM) requests the document to be provisioned to a server (S) by the secure communication medium provided by the document issuing agency.
- the server (S) fetches the information regarding the user who requested the document from the database (DB) and forms a structure (LDS).
- the frame (LDS) is sent to the device (DM) to be signed on the encryption processor (P), the signed frame (LDSA) is then used for the generation of machine readable base code (CBB).
- CBB machine readable base code
- the encryption processor (P) belongs to the document issuing agency (OE) infrastructure to the first device (DM) to which the electronic document is sent.
- the device (DM) requests the document to be provisioned to a server (S) by the secure communication medium provided by the document issuing agency.
- the server (S) fetches the information regarding the user who requested the document from the database (DB) and forms a structure (LDS).
- the frame (LDS) is sent to the encryption processor (P) to be signed, the The signed structure (LDSA) is sent to the device (DM), and is then used for the generation of machine-readable base code (CBB).
- DB database
- CBB machine-readable base code
- an authority carrying a device comprising Machine Readable Code code means performs verification of the authenticity of the identification document that has been digitally provisioned using the provisioning method previously described.
- Said second element device (DA) comprises an authentication key (CH3) corresponding to the frame signature (LDS) executed at the issuing body (OE).
- the second element then reads the base code (CBB) through the device and verifies the veracity of the digital frame signature (LDS). Also, verifies the veracity of the information obtained by reading the code (CBB) with the data displayed in the document reassembled in the interface of the DM device. Furthermore, in this reading of the base code (CBB), the authority device, or second device (DA), receives information such as: citizen document data (D), user's image HASH and / or the user's own image, user device identification number (NI), or IMEI (DM), and public key (CH1) coming from the encryption processor (P) in the electronic document signing step.
- D citizen document data
- NI user device identification number
- DM IMEI
- CH1 public key coming from the encryption processor (P) in the electronic document signing step.
- an authority requests the generation of the authentication code (CBA) to proceed with performing the authenticity check of the documentation performed in Example III.
- CBA authentication code
- the authority After the authentication code (CBA) has been generated, the authority reads it to verify that the private key (CH2), coming from the encryption processor (P), used by the device (DM) to sign the content of the authentication code (CBA) is the public key pair (CH1) obtained by reading the base code (CBB). The second element then compares the identification number (NI) obtained in the base code (CBB) with the identification number (NI) obtained from the authentication code (CBA) and also verifies that the generated authentication code (CBA) generation time (T) is compatible with the time when the first element executed the generation request Authentication Code (CBA).
- CH2 private key
- P encryption processor
- DM used by the device (DM) to sign the content of the authentication code (CBA) is the public key pair (CH1) obtained by reading the base code (CBB).
- the second element compares the identification number (NI) obtained in the base code (CBB) with the identification number (NI) obtained from the authentication code (CBA) and also verifies that the generated authentication code (CBA) generation
- the authority verifies the authenticity of digital documentation by reading the image code (CBI), in which the user ID image is obtained.
- the second element calculates the HASH of the read image and compares it to the HASH (HF) obtained by reading the base code (CBB) as described in example III.
- the authority passing through the second element, performs the reading according to examples III, IV, and V.
- the authority performs the reading of the document in its entirety.
- the authentication code (CBA) to be read contains information regarding the time (T) it was generated and the identification number (NI) of the document. device (DM), so it is evaluated as authentic if the identification number (NI) read is the same as that sent to the server (S) in the request for provisioning and personalization of electronic identification document, if the time read in the check is the same as the authentication code generation time (T) (CBA) and even if the private active authentication key (CH2) used for authentication code authentication (CBA) is paired with the public active authentication key (CH1).
- your mobile communication device will be connected to a secure network, such as a secure Wi-Fi network, so that it can receive the QR Code (CBB), containing the structure (LDS) digitally signed by the issuing agency. (LDSA), citizen photo, Private Active Authentication Key (CH2), and LDSA structure ( Figure 8).
- CBB QR Code
- LDS structure
- LDSA LDSA
- citizen photo containing the structure
- CH2 Private Active Authentication Key
- Figure 8 Figure 8
- a button also appears on this screen which, when touched, generates a second dynamic authentication QR Code (CBA), which expires after a certain time ( Figure 13).
- CBA has content signed by the device active private authentication key (CH2) and containing the time (T) and the IMEI (NI) of the mobile communication device ( Figure 14). This second authentication QR Code is generated each time the document is presented.
- CH2 device active private authentication key
- T time
- NI IMEI
- the authority's mobile communication device reads the two QR Codes displayed on the screen of the citizen's mobile communication device. By signing the issuing agency in CBB, the authority application verifies the validity and integrity of the data contained in the set.
- the use of the second QR Code guarantees the authenticity of the identification presented to the authority by preventing a copy of the identity image and the first QR Code from being displayed and used as true spoofing.
- a third QRCode can optionally be generated by tapping the screen button again ( Figure 14).
- the CBI contains the citizen photo received by the citizen's mobile communication device from the issuing agency's server in a secure environment ( Figure 16).
- the authority's mobile communication device reads the CBI, internally calculates the photo's "HASH” and compares it to the photo's "HASH” that was generated on and signed by the issuing agency's server. This step ensures that the photo being presented in the document on the screen of the citizen's mobile device really is the photo of the citizen holding that biographical data.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Storage Device Security (AREA)
- Computing Systems (AREA)
- Collating Specific Patterns (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| BR112018076405A BR112018076405A2 (pt) | 2016-07-22 | 2017-07-21 | sistema de provisionamento, assinatura e verificação de documento eletrônico, método de provisionamento e assinatura de documento eletrônico e método de verificação de autenticidade de documento eletrônico |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| BR102016017113-0A BR102016017113A2 (pt) | 2016-07-22 | 2016-07-22 | Sistema e método de provisionamento e personalização digital de documentos de identificação eletrônicos (eid) e método de verificação da autenticidade de documento identificação eletrônicos (eid) |
| BR102016017113-0 | 2016-07-22 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2018014103A1 true WO2018014103A1 (pt) | 2018-01-25 |
Family
ID=60991747
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/BR2017/050204 Ceased WO2018014103A1 (pt) | 2016-07-22 | 2017-07-21 | Sistema de provisionamento, assinatura e verificação de documento eletrônico, método de provisionamento e assinatura de documento eletrônico e método de verificação de autenticidade de documento eletrônico |
Country Status (3)
| Country | Link |
|---|---|
| BR (2) | BR102016017113A2 (pt) |
| PE (1) | PE20190481A1 (pt) |
| WO (1) | WO2018014103A1 (pt) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11223470B1 (en) | 2020-03-06 | 2022-01-11 | Wells Fargo Bank, N.A. | Post-quantum cryptography side chain |
| US11995194B1 (en) | 2020-03-06 | 2024-05-28 | Wells Fargo Bank, N.A. | Self-contained encrypted data and decryption application for third party data storage and data dissemination |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20130243266A1 (en) * | 2012-03-16 | 2013-09-19 | L-1 Secure Credentialing, Inc. | iPassport Apparatus and Method |
| US20140089682A1 (en) * | 2012-09-25 | 2014-03-27 | Apple Inc. | Security Enclave Processor for a System on a Chip |
| WO2014080210A1 (en) * | 2012-11-22 | 2014-05-30 | Barclays Bank Plc | Identity information systems and methods |
-
2016
- 2016-07-22 BR BR102016017113-0A patent/BR102016017113A2/pt not_active Application Discontinuation
-
2017
- 2017-07-21 WO PCT/BR2017/050204 patent/WO2018014103A1/pt not_active Ceased
- 2017-07-21 PE PE2019000010A patent/PE20190481A1/es not_active Application Discontinuation
- 2017-07-21 BR BR112018076405A patent/BR112018076405A2/pt not_active IP Right Cessation
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20130243266A1 (en) * | 2012-03-16 | 2013-09-19 | L-1 Secure Credentialing, Inc. | iPassport Apparatus and Method |
| US20140089682A1 (en) * | 2012-09-25 | 2014-03-27 | Apple Inc. | Security Enclave Processor for a System on a Chip |
| WO2014080210A1 (en) * | 2012-11-22 | 2014-05-30 | Barclays Bank Plc | Identity information systems and methods |
Non-Patent Citations (3)
| Title |
|---|
| "Part 10 - Logical Data Structure (LDS) for Storage of Biometrics and Other Data in the Contactless Integrated Circuit (IC)", INTERNATIONAL CIVIL AVIATION ORGANIZATION. DOC. 9303 - MACHINE READABLE TRAVEL DOCUMENTS, 2015, ISBN: 978-92-9249-799-6, Retrieved from the Internet <URL:https://www.icao.int/publications/Documents/9303_p10cons_en.pdf> [retrieved on 20171114] * |
| "Part 11 - Security Mechanisms for MRTDs", INTERNATIONAL CIVIL AVIATION ORGANIZATION. DOC. 9303 - MACHINE READABLE TRAVEL DOCUMENTS, 2015, pages 8;21;23 - 26, ISBN: 978-92-9249-799-6, Retrieved from the Internet <URL:https://www.icao.int/publications/Documents/9303_p11_cons_en.pdf> [retrieved on 20171114] * |
| "Part 12 - Public Key Infrastructure for MRTDs", INTERNATIONAL CIVIL AVIATION ORGANIZATION. DOC. 9303 - MACHINE READABLE TRAVEL DOCUMENTS, 2015, ISBN: 978-92-9249-799-6, Retrieved from the Internet <URL:https:/7www.icao.int/publications/Documents/9303_pl2_cons_en.pdf> [retrieved on 20171114] * |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11223470B1 (en) | 2020-03-06 | 2022-01-11 | Wells Fargo Bank, N.A. | Post-quantum cryptography side chain |
| US11626973B1 (en) | 2020-03-06 | 2023-04-11 | Wells Fargo Bank, N.A. | Post-quantum cryptography side chain |
| US11995194B1 (en) | 2020-03-06 | 2024-05-28 | Wells Fargo Bank, N.A. | Self-contained encrypted data and decryption application for third party data storage and data dissemination |
| US12200107B1 (en) | 2020-03-06 | 2025-01-14 | Wells Fargo Bank, N.A. | Post-quantum cryptography side chain |
Also Published As
| Publication number | Publication date |
|---|---|
| BR112018076405A2 (pt) | 2019-04-09 |
| PE20190481A1 (es) | 2019-04-05 |
| BR102016017113A2 (pt) | 2018-02-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11664997B2 (en) | Authentication in ubiquitous environment | |
| KR102004829B1 (ko) | 유비쿼터스 환경에서 인증 | |
| EP3416334B1 (en) | Portable biometric identity on a distributed data storage layer | |
| ES2951585T3 (es) | Autenticación de transacciones usando un identificador de dispositivo móvil | |
| CN112468506B (zh) | 获取、下发电子证件的实现方法和装置 | |
| US10237072B2 (en) | Signatures for near field communications | |
| US20130219481A1 (en) | Cyberspace Trusted Identity (CTI) Module | |
| KR101858653B1 (ko) | 블록체인 데이터베이스 및 이와 연동하는 머클 트리 구조를 통해 모바일 아이디를 이용하여 사용자를 인증하는 방법, 단말 및 이를 이용한 서버 | |
| KR101829730B1 (ko) | 블록체인 데이터베이스를 통해 모바일 아이디를 이용하여 사용자를 인증하는 방법, 단말 및 이를 이용한 서버 | |
| CN103259667A (zh) | 移动终端上eID身份认证的方法及系统 | |
| CN109903052A (zh) | 一种区块链签名方法和移动设备 | |
| CN110876144A (zh) | 一种身份凭证的移动应用方法、装置及系统 | |
| BR102020015872A2 (pt) | Sistema e método para autenticação e/ou autorização de usuário | |
| CN104618307A (zh) | 基于可信计算平台的网银交易认证系统 | |
| BRPI0808238A2 (pt) | Aparelho de identificação, sistema de identificação e autenticação e método para identificar uma pessoa" | |
| JP2019004475A (ja) | ユビキタス環境での認証 | |
| BR102016017113A2 (pt) | Sistema e método de provisionamento e personalização digital de documentos de identificação eletrônicos (eid) e método de verificação da autenticidade de documento identificação eletrônicos (eid) | |
| Singh | Multi-factor authentication and their approaches | |
| CN119808038A (zh) | 匿名身份验证的方法、装置、电子设备及存储介质 | |
| KR20050079951A (ko) | 아이씨칩을 탑재한 스마트카드를 이용한 공인인증서 인증시스템 | |
| Bhargav-Spantzel | CERIAS Tech Report 2007-84 Protocols and Systems for Privacy Preserving Protection of Digital Identity |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17830130 Country of ref document: EP Kind code of ref document: A1 |
|
| REG | Reference to national code |
Ref country code: BR Ref legal event code: B01A Ref document number: 112018076405 Country of ref document: BR |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 112018076405 Country of ref document: BR Kind code of ref document: A2 Effective date: 20181218 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17830130 Country of ref document: EP Kind code of ref document: A1 |