ID Token Attribute Reading via Dual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity management systems face issues such as user manipulation in client-based systems and inadequate data protection in server-based systems, with central storage of digital identities leading to security concerns.
Innovation Solution
A method for reading attributes from an ID token, where user authentication and system authentication are required to establish a secure connection, allowing for trusted attribute transmission between systems without central storage, using certificates for authorization and end-to-end encryption for secure data transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If client-based digital identity system is used, then user can communicate digital identity to online services, but user can manipulate his digital identity
Solution Approach 1:
The patent introduces an ID token as an intermediary device that stores digital identity attributes. The ID token acts as a mediator between the user and online services, preventing direct manipulation by the user while enabling communication of identity information. The token's secure storage mechanism and controlled access protocols ensure that identity data cannot be arbitrarily modified by the user, thus resolving the contradiction between versatility and reliability.
2Device complexity
If server-based digital identity system is used, then digital identities are stored centrally, but data protection is inadequate and user behavior can be recorded
Solution Approach 1:
The patent segments the centralized identity storage into distributed ID tokens held by individual users. Instead of a single central database, identity attributes are distributed across multiple independent tokens. This segmentation eliminates the single point of failure and reduces the risk of mass data breaches, as each token contains only the specific identity data it protects, not a comprehensive central repository.
Solution Approach 2:
The patent extracts identity data from centralized server storage and places it directly into user-held ID tokens. This extraction removes the vulnerable central storage infrastructure and places control directly with the user. The identity information is taken out of the potentially insecure central environment and stored in a decentralized manner, improving data protection while maintaining the ability to present identity to services as needed.
3Reliability
If user registration is required, then digital identity management is established, but prior registration step is needed which reduces convenience
Solution Approach 1:
The patent implements preliminary action by pre-loading identity attributes into the ID token during its creation phase, before the user needs to present it to any service. The token is prepared in advance with all necessary identity information securely stored and signed. This eliminates the need for on-the-spot registration or data entry, as the identity data is already in place and ready for immediate use, thus improving ease of operation while maintaining reliability through pre-established security measures.
Data Source
AI summary
The invention relates to a method for reading at least one attribute stored in an ID token, wherein the ID token is assigned to a user, comprising the following steps: authenticating the user with respect to the ID token, authenticating a first computer system with respect to the ID token, after successful authentication of the user and the first computer system with respect to the ID token, read-access by the first computer system to the at least one attribute stored in the ID token for transfer of the at least one attribute to a second computer system.


