ID Token Attribute Retrieval for Secure E-Commerce Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic transaction methods for e-commerce and e-government applications lack a secure, flexible, and user-friendly solution for financial transactions, as they often require sharing sensitive payment information and do not ensure maximum security and trustworthiness in attribute retrieval from ID tokens.
Innovation Solution
A computer-implemented payment method utilizing an ID token with secure authentication processes, where user and ID provider system authentication is mandatory, and attributes are read using a SAML request-response protocol with end-to-end encryption, ensuring secure and trustworthy transactions without revealing sensitive information to the service computer system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard payment methods are used for electronic transactions, then payment processing can be performed, but sensitive payment information must be shared and security is compromised
Solution Approach 1:
The invention extracts and separates sensitive payment information from the transaction process. Instead of sharing actual payment details, the system uses attributed data (public keys, certificates, and encrypted references) that can verify payment capability without exposing the underlying sensitive information. This extraction principle resolves the contradiction by removing the need to disclose payment information while maintaining transaction security.
Solution Approach 2:
The invention introduces an intermediary layer consisting of attribute data structures, certificates, and encrypted references that mediate between the payment system and the service computer system. This intermediary mechanism allows verification of payment information without direct exposure of sensitive data, thus resolving the contradiction between enabling transactions and protecting information security.
2Ease of operation
If payment information is shared for transaction processing, then transactions can be executed, but trustworthiness and maximum security cannot be ensured
Solution Approach 1:
The invention creates verified copies of payment information in the form of attribute data structures and certificates. These copies contain all necessary verification data (public keys, encrypted references, metadata) to execute transactions without requiring access to the original sensitive payment information. This copying mechanism enables easy transaction execution while maintaining trustworthiness through cryptographic verification.
Solution Approach 2:
The invention performs preliminary actions by pre-establishing encrypted references, generating certificates, and creating attribute data structures before transactions occur. This preliminary setup includes generating key pairs, encrypting payment information references, and establishing verification mechanisms in advance, which enables seamless transaction execution while ensuring trustworthiness through pre-verified cryptographic proofs.
3Adaptability or versatility
If existing electronic payment methods are used, then transactions can be processed, but a secure and flexible solution for all applications is lacking
Solution Approach 1:
The invention creates a universal payment verification system using standardized attribute data structures, certificates, and encrypted references that can be applied across different applications (e-commerce, e-government, mobile payments). This multi-functional approach provides consistent security mechanisms (cryptographic verification, encrypted references, certificate-based authentication) that adapt to various transaction types while maintaining security consistency, thus resolving the contradiction between versatility and security reliability.
Data Source
AI summary
The invention relates to an electronic transaction method using an ID token (106) that is associated with a user (102), wherein the ID token has an electronic memory (118) with a protected memory area (124) that stores one or more attributes, wherein access to the protected memory area is possible only via a processor (128) of the ID token, and wherein the ID token has a communication interface (108) for communication with a reader of a user computer system (100), having the following steps: set-up of a first session (201) between an application program (112), particularly an Internet browser of the user computer system, and a service computer system (150) via a network (116), – reception of a transaction request (158) concerning the first session from the application program (112) by the service computer system, – production of a request (166) by the service computer system on the basis of the reception of the transaction request, the request being signed by the service computer system and the request containing attribute specification, for the attributes that are to be read from the ID token for performing the transaction, transaction data for specifying the transaction, an identifier (180) of the request, a URL of an ID provider computer system and a URL of the service computer system, – transmission of a web page (160) and of the request concerning the first session from the service computer system to the user computer system, the web page having an input field (162) for the input of supplementary information (168) for performing the transaction, – display of the web page by the application program and input of the supplementary information into the input field by the user, – set-up of a second session (202) between the application program (112) and the ID provider computer system via the network using the URL of the ID provider computer system, the second session being set up with a secure transport layer, – forwarding of the request and of the supplementary information from the application program to the ID provider computer system via the second session, – on the basis of reception of the request, production of a session ID for a third session (203) by the ID provider computer system and storage of the request and of the supplementary information by the ID provider computer system, – transmission of a message from the ID provider computer system to the application program (112) with the session ID of the third session and a logical address, particularly a URL, via the second session, – set-up of the third session between a program (113) of the user computer system and the ID provider computer system via the secure transport layer of the second session, the program being able to be different from the application program (112), – transmission of at least one certificate (144) from the ID provider computer system to the program (113), the certificate containing a statement of reading rights for the ID provider computer system to read one or more of the attributes stored in the ID token, with the certificate being transmitted via the third session, – checking by the program (113) to determine whether the reading rights indicated on the certificate are sufficient to permit read access by the ID provider computer system to the attribute(s) to be read on the basis of the attribute specification, – production of a response (174) that contains the read attribute(s) and at least the identifier (180) of the request, and that is signed by the ID provider computer system, – storage of the response for retrieval using the logical address, – reading of the response from the ID provider computer system by the user computer system by retrieving the response from the logical address via the network by means of a read command , – forwarding of the response to the service computer system by the user computer system via the first session, – association of the response with the request by the service computer system using the identifier that the response contains, – performance of the transaction by the ID provider computer system using the response.