发明申请
- 专利标题: METHOD FOR SECURELY PROVIDING A PERSONALIZED ELECTRONIC IDENTITY ON A TERMINAL
-
申请号: US17421079申请日: 2020-01-08
-
公开(公告)号: US20220116230A1公开(公告)日: 2022-04-14
- 发明人: Frank DIETRICH , Marian MARGRAF , Tim OHLENDORF , Matthias SCHWAN
- 申请人: Bundesdruckerei GMBH
- 申请人地址: DE Berlin
- 专利权人: Bundesdruckerei GMBH
- 当前专利权人: Bundesdruckerei GMBH
- 当前专利权人地址: DE Berlin
- 优先权: DE102019100335.0 20190108
- 国际申请: PCT/DE2020/100006 WO 20200108
- 主分类号: H04L9/32
- IPC分类号: H04L9/32 ; H04L9/08 ; H04L9/30
摘要:
The invention relates to a method for securely providing a personalized electronic identity on a terminal (2) which can be used by a user (1) for identification purposes when claiming an online service. In the method, an identification application is ran on a terminal (2), which is assigned to a user (1), in a system comprising data processing devices (9; 10; 11; 12) and said terminal (2), and additionally a personalization application and an identity provider application are ran. The method has the following steps in particular; transmitting a request to transmit an identity attribute assigned to the user (1) front the personalization application to the identity provider application; transmitting the identity attribute from the identity provider application to the personalization application after an agreement to transmit the identity attribute by means of the identity provider application is received from the user (1); generating an asymmetric key pair with a public and a private key on the terminal (2) by means of the identification application; transmitting the public-key from tire identification application on the terminal (2) to the personalization application; and generating an electronic certificate for the public-key by means of tire personalization application and storing the electronic certificate in a data storage device in order to form a first public-key infrastructure of the personalization application, additionally having the steps of: generating a hash value for the identity attribute and recording the hash value onto the electronic certificate. The identity attribute is encoded and transmitted together with the electronic certificate from the personalization application to the identification application (14) on the terminal (2), where both are stored in a local storage device of the terminal (2).
公开/授权文献
信息查询