ID Token Attribute Reading via Time-Based Password
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity management methods, such as Microsoft Windows CardSpace and OPENID, face issues with user manipulation and central storage of digital identities, leading to data protection concerns and lack of trustworthiness.
Innovation Solution
A method for reading attributes from an ID token, which involves user and system authentication, generating a time-based one-time password using the ID token, and transmitting attributes securely over a network, ensuring data protection and trustworthiness without central storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If digital identities are stored centrally in a server-based system like OPENID, then user authentication can be managed efficiently, but data protection is compromised and user behavior can be recorded
Solution Approach 1:
The patent segments the digital identity system by distributing identity attributes across multiple decentralized ID tokens rather than storing them centrally. Each ID token contains specific attributes that can be selectively disclosed, eliminating the single point of failure and surveillance risk inherent in centralized systems while maintaining authentication efficiency through standardized verification protocols
Solution Approach 2:
The patent introduces selective disclosure mechanisms and cryptographic protocols as intermediaries between the user's ID tokens and verification systems. These intermediaries enable efficient authentication by allowing verifiers to authenticate user identities without accessing complete personal data, thus maintaining productivity while protecting privacy and preventing unauthorized recording of user behavior
2Ease of operation
If user digital identity can be manipulated in a client-based system like Microsoft Windows CardSpace, then user control over identity presentation is improved, but trustworthiness and data protection are compromised
Solution Approach 1:
The patent implements dynamic attribute disclosure where users can selectively reveal only the necessary attributes for each authentication context. The ID tokens contain cryptographically secured attributes that can be dynamically disclosed or withheld based on verification requirements, providing user control without manipulation while maintaining trustworthiness through cryptographic proof of attribute validity
Solution Approach 2:
The patent changes the state of identity attributes from static, user-editable data in client-based systems to cryptographically signed, immutable attributes stored in secure ID tokens. This parameter change ensures that attributes cannot be manipulated while still allowing users to control which attributes are disclosed and to whom, balancing ease of operation with reliability
3Loss of information
If multiple attributes are read from ID token, then comprehensive user information is obtained, but data protection and security risks increase
Solution Approach 1:
The patent applies local quality by enabling different levels of attribute disclosure for different verification contexts. Instead of reading all attributes uniformly, the system allows selective disclosure where only the specific attributes required for each authentication purpose are accessed and transmitted. This reduces security risks and data exposure while obtaining the necessary information for each local context
Data Source
Figure 1
Figure 2
Figure 3~3a
AI summary
The invention relates to a method for reading at least one attribute stored in an ID token (106, 106'), wherein the ID token is assigned to a user (102), comprising the following steps: - authentication of the user to the ID token, - authentication of a first computer system (136) to the ID token, - after successful authentication of the user and the first computer system to the ID token, transmission of a timestamp from the first computer system to the ID token for the generation of a password using the timestamp from the ID token, read access of the first computer system to the at least one attribute stored in the ID token for the transmission of the at least one attribute after its signing to a second computer system (150).