ID Token Attribute Reading via Time-Based Password

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management methods, such as Microsoft Windows CardSpace and OPENID, face issues with user manipulation and central storage of digital identities, leading to data protection concerns and lack of trustworthiness.

Innovation Solution

A method for reading attributes from an ID token, which involves user and system authentication, generating a time-based one-time password using the ID token, and transmitting attributes securely over a network, ensuring data protection and trustworthiness without central storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If digital identities are stored centrally in a server-based system like OPENID, then user authentication can be managed efficiently, but data protection is compromised and user behavior can be recorded

Engineering Contradiction:
Improveauthentication management efficiencyVSAvoiddata protection and trustworthiness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the digital identity system by distributing identity attributes across multiple decentralized ID tokens rather than storing them centrally. Each ID token contains specific attributes that can be selectively disclosed, eliminating the single point of failure and surveillance risk inherent in centralized systems while maintaining authentication efficiency through standardized verification protocols

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces selective disclosure mechanisms and cryptographic protocols as intermediaries between the user's ID tokens and verification systems. These intermediaries enable efficient authentication by allowing verifiers to authenticate user identities without accessing complete personal data, thus maintaining productivity while protecting privacy and preventing unauthorized recording of user behavior

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If user digital identity can be manipulated in a client-based system like Microsoft Windows CardSpace, then user control over identity presentation is improved, but trustworthiness and data protection are compromised

Engineering Contradiction:
Improveuser control over identityVSAvoidtrustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic attribute disclosure where users can selectively reveal only the necessary attributes for each authentication context. The ID tokens contain cryptographically secured attributes that can be dynamically disclosed or withheld based on verification requirements, providing user control without manipulation while maintaining trustworthiness through cryptographic proof of attribute validity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the state of identity attributes from static, user-editable data in client-based systems to cryptographically signed, immutable attributes stored in secure ID tokens. This parameter change ensures that attributes cannot be manipulated while still allowing users to control which attributes are disclosed and to whom, balancing ease of operation with reliability

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If multiple attributes are read from ID token, then comprehensive user information is obtained, but data protection and security risks increase

Engineering Contradiction:
Improvecompleteness of user informationVSAvoidsecurity risks and data exposure
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by enabling different levels of attribute disclosure for different verification contexts. Instead of reading all attributes uniformly, the system allows selective disclosure where only the specific attributes required for each authentication purpose are accessed and transmitted. This reduces security risks and data exposure while obtaining the necessary information for each local context

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3261011B1Method for reading attributes from an id token
Publication Date: 2020.11.04 BUNDESDRUCKEREI GMBH
  • EP3261011B1 patent drawingFigure 1
  • EP3261011B1 patent drawingFigure 2
  • EP3261011B1 patent drawingFigure 3~3a

AI summary

The invention relates to a method for reading at least one attribute stored in an ID token (106, 106'), wherein the ID token is assigned to a user (102), comprising the following steps: - authentication of the user to the ID token, - authentication of a first computer system (136) to the ID token, - after successful authentication of the user and the first computer system to the ID token, transmission of a timestamp from the first computer system to the ID token for the generation of a password using the timestamp from the ID token, read access of the first computer system to the at least one attribute stored in the ID token for the transmission of the at least one attribute after its signing to a second computer system (150).