ID Token Attribute Reading via Dual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation in client-based systems and inadequate data protection in server-based systems, with central storage of digital identities leading to security concerns.

Innovation Solution

A method for reading attributes from an ID token, where user authentication and system authentication are required to establish a secure connection, allowing for trusted attribute transmission between systems without central storage, using certificates for authorization and end-to-end encryption for secure data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If client-based digital identity system is used, then user can communicate digital identity to online services, but user can manipulate his digital identity

Engineering Contradiction:
Improvedigital identity communication capabilityVSAvoiddigital identity authenticity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an ID token as an intermediary device that stores digital identity attributes. The ID token acts as a mediator between the user and online services, preventing direct manipulation by the user while enabling communication of identity information. The token's secure storage mechanism and controlled access protocols ensure that identity data cannot be arbitrarily modified by the user, thus resolving the contradiction between versatility and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If server-based digital identity system is used, then digital identities are stored centrally, but data protection is inadequate and user behavior can be recorded

Engineering Contradiction:
Improvecentralized storage structureVSAvoiddata protection vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized identity storage into distributed ID tokens held by individual users. Instead of a single central database, identity attributes are distributed across multiple independent tokens. This segmentation eliminates the single point of failure and reduces the risk of mass data breaches, as each token contains only the specific identity data it protects, not a comprehensive central repository.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts identity data from centralized server storage and places it directly into user-held ID tokens. This extraction removes the vulnerable central storage infrastructure and places control directly with the user. The identity information is taken out of the potentially insecure central environment and stored in a decentralized manner, improving data protection while maintaining the ability to present identity to services as needed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If user registration is required, then digital identity management is established, but prior registration step is needed which reduces convenience

Engineering Contradiction:
Improveidentity management structureVSAvoiduser registration requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-loading identity attributes into the ID token during its creation phase, before the user needs to present it to any service. The token is prepared in advance with all necessary identity information securely stored and signed. This eliminates the need for on-the-spot registration or data entry, as the identity data is already in place and ready for immediate use, thus improving ease of operation while maintaining reliability through pre-established security measures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10142324B2Method for reading attributes from an ID token
Publication Date: 2018.11.27 BUNDESDRUCKEREI GMBH
  • US10142324B2 patent drawing
  • US10142324B2 patent drawing
  • US10142324B2 patent drawing

AI summary

The invention relates to a method for reading at least one attribute stored in an ID token, wherein the ID token is assigned to a user, comprising the following steps: authenticating the user with respect to the ID token, authenticating a first computer system with respect to the ID token, after successful authentication of the user and the first computer system with respect to the ID token, read-access by the first computer system to the at least one attribute stored in the ID token for transfer of the at least one attribute to a second computer system.