ID Token Attribute Reading via Segmented Memory and Intermediary Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation, lack of data protection, and centralization of user data, which compromises security and privacy.

Innovation Solution

A method for reading attributes from an ID token that utilizes a protected memory area accessible only via a processor, involving an ID provider module, attribute provider computer systems, and a directory system to decentralize attribute storage and access, ensuring secure and anonymous data provision to services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital identities are stored centrally in a server-based system, then user behavior can be recorded and monitored, but data protection and user privacy are compromised

Engineering Contradiction:
Improvedata protectionVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the digital identity system into distributed components: local identity agents on user devices, attribute providers, and service providers. Each component stores and manages specific portions of identity data locally rather than in a central repository, thereby protecting user privacy while maintaining system functionality through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential structure that acts as a mediator between the user's local identity agent and service providers. This credential contains verified attributes that can be selectively disclosed without exposing the underlying identity data, enabling secure verification while preserving privacy

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a protected memory area is implemented in ID tokens, then unauthorized access is prevented, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidID token structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements protected memory areas and authentication mechanisms in advance during ID token initialization. The security infrastructure, including encrypted storage regions and access control protocols, is established beforehand, allowing secure attribute storage without adding operational complexity during actual identity verification processes

Inventive Principle:
Principle #10Preliminary action

3Reliability

If user attributes are decentralized across multiple systems, then data breaches are reduced, but coordination and access management become more difficult

Engineering Contradiction:
Improvedata securityVSAvoidattribute access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal credential structure that can be used across multiple service providers and attribute providers. The standardized credential format and verification protocol enable seamless attribute access across decentralized systems, maintaining ease of operation while distributing data security risks

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3244331B1Method for reading attributes from an id token
Publication Date: 2019.03.06 BUNDESDRUCKEREI GMBH
  • EP3244331B1 patent drawingFigure 1
  • EP3244331B1 patent drawingFigure 2
  • EP3244331B1 patent drawingFigure 3

AI summary

The invention relates to a method for reading attributes from an ID token (106), wherein the method comprises: - sending (302) a service request (103) from a user computer system (100) to a service computer system (150); - sending a first attribute specification (105) from the service computer system to an ID provider module; - writing the first attribute specification (105) to the ID token by the ID provider module; - sending a trigger signal (T1) from the user computer system to an APV computer system (199); - in response to receiving the trigger signal, reading the first attribute specification (AR) from the protected memory area of ​​the ID token by the APV computer system and splitting the read first attribute specification into at least a second (AR1) and a third (AR2) attribute specification by the APV computer system;- Sending the second attribute specification (AR1) and an address (#106) of the ID token from the APV computer system to a first AP computer system (172) and sending the third and each subsequent attribute specification (AR2, ..., ARn) and the address (#106) from the APV computer system to each of the other AP computer systems (173, 174); - Writing the first attribute set (A1) to the ID token and sending an acknowledgment signal (S1) from the first attribute provider computer system to the attribute provider directory computer system (199) to instruct the service computer system to read the written attribute sets.