ID Provider System for Dynamic Trust Level Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity verification methods fail to balance the service provider's need for secure and trustworthy user data with the user's interest in data protection and anonymity, particularly due to differing reliability requirements across services and the administrative burden of managing multiple identities.

Innovation Solution

A computer-implemented method that calculates and recalcules trust levels for user attribute values using a combination of attribute-independent and attribute-specific functions, allowing for a fine-grained verification of digital identities and reducing the need for multiple verification steps by dynamically generating new identities based on existing trust levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service providers require comprehensive user verification for all attributes, then data reliability is improved, but user privacy protection deteriorates

Engineering Contradiction:
Improvedata reliabilityVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements attribute-specific trust levels where different attributes of a user's digital identity can have different verification qualities. Instead of treating all user attributes uniformly, the system assigns specific trust levels to individual attributes (e.g., name, address, email) based on their verification status, allowing service providers to request only verified attributes while preserving unverified ones for privacy protection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the digital identity into multiple independent attributes, each with its own trust level. This segmentation allows the identity to be partially verified rather than requiring complete verification of all attributes, enabling a fine-grained balance between providing necessary information for service reliability and protecting sensitive information for privacy.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If users manage multiple digital identities for different services, then service adaptability is improved, but system complexity deteriorates

Engineering Contradiction:
Improveservice adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal digital identity structure that can be adapted to multiple services through attribute selection rather than requiring separate identity systems. The same core identity framework supports different service requirements by selectively presenting verified attributes, eliminating the need for users to maintain completely separate identities for each service while still achieving service-specific adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic attribute selection where the presented digital identity adapts to service requirements in real-time. The system dynamically determines which attributes to present and at what trust levels based on the specific service context, rather than using static identity configurations. This dynamic adaptation reduces complexity by providing a single flexible identity system that serves multiple purposes.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If multiple verification steps are performed for each service, then measurement precision is improved, but time consumption deteriorates

Engineering Contradiction:
Improveverification precisionVSAvoidverification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs verification actions in advance, establishing trust levels for user attributes before actual service usage. The identity verification system pre- verifies critical attributes and stores their trust levels, so that when a user accesses a service, the verification results are already available and can be quickly presented without requiring repeated verification steps for each service interaction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where verification results and trust levels are stored and reused across multiple service interactions. The system provides feedback about previously verified attributes to service providers, eliminating the need for redundant verification steps. This feedback loop maintains verification precision while significantly reducing the time required for repeated verifications.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3117360B1Id provider computer system
Publication Date: 2020.09.09 BUNDESDRUCKEREI GMBH
  • EP3117360B1 patent drawingFigure 1~2
  • EP3117360B1 patent drawingFigure 3~4
  • EP3117360B1 patent drawingFigure 5

AI summary

The invention relates to a computer-implemented method for checking a digital identity of a user (102) by a service computer system (150), comprising: - automatic calculation (502) of trust levels (198, L1-L5) for each attribute value (190, V1, V2) of attributes (412, A1, A2) by an ID provider computer system (136) with the aid of a first function (192) in an attribute-independent manner; -automatic execution (504) of one or more second functions (193.1-193.4), wherein each of the second functions is specifically assigned to one or more of the attributes, wherein each execution of the second functions effects a new calculation of the trust levels of the attribute values of those attributes to which the second function is assigned; -receipt (506) of a query (194, 202) to confirm the digital identity of the user by the ID provider computer system (136); -transmission (508) of a response (195, 204) to the service computer system, wherein each response for one or more of the attributes of the query contains an attribute value (V1, V2) associated with the user and the trust level (L1-L4) which has been assigned to this attribute value and which has been newly calculated by means of a second function; - checking (510) of the digital identity of the user by evaluating both the attribute values contained in the response and the trust values associated therewith.