ID Token Attribute Reading for Decentralized Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity management systems face issues such as user manipulation, central storage of identities leading to data protection concerns, and lack of trustworthiness in identity verification processes.
Innovation Solution
A method for reading attributes from an ID token that involves a user computer system sending a request to a service computer system, specifying attributes, and authenticating with an ID provider computer system to securely read and sign attributes from the ID token, establishing a trustworthy connection without central storage of user data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital identities are stored centrally in a server-based system, then identity verification can be performed, but data protection is compromised and user behavior can be recorded
Solution Approach 1:
The patent extracts the digital identity data from centralized storage and places it directly on the user's portable device (ID token). The service computer system no longer stores user identities centrally, but instead verifies identities by reading attributes directly from the user's device, eliminating the central database that compromises data protection.
Solution Approach 2:
The patent introduces an intermediary verification process where the service computer system acts as a mediator that reads and verifies identity attributes from the user's portable device without storing them. This intermediary role allows identity verification while maintaining data protection, as the system verifies identities without centralizing storage.
2Adaptability or versatility
If a user can manipulate their digital identity, then flexibility is improved, but trustworthiness of the identity system deteriorates
Solution Approach 1:
The patent applies preliminary action by having identity attributes signed and sealed on the portable device before they are presented to the service computer system. The digital signature is created in advance on the user's device, ensuring the identity data has not been manipulated during transmission or verification, thus maintaining trustworthiness while allowing flexible presentation.
Solution Approach 2:
The patent inverts the traditional approach by having the user's portable device sign and verify the identity attributes locally, rather than relying on the service computer system to verify against a central database. This inversion places trust in the user's device and the cryptographic signatures, preventing manipulation while maintaining flexibility.
3Adaptability or versatility
If multiple computer systems need to verify attributes from an ID token, then service capability is improved, but connection complexity increases
Solution Approach 1:
The patent applies universality by creating a standardized attribute specification format and verification process that can be used by any service computer system. The ID token and verification method are designed to be universally applicable across different services and domains, allowing multiple computer systems to verify attributes without requiring complex, service-specific connection protocols.
Data Source
Figure 1
Figure 2
Figure 3~3a
AI summary
The invention relates to a method for reading at least one attribute stored in an ID token (106, 106'), wherein the ID token is assigned to a user (102), comprising the following steps: authenticating the user with respect to the ID token, authenticating a first computer system (136) with respect to the ID token, after successful authentification of the user and the first computer system with respect to the ID token, read-access by the first computer system to the at least one attribute stored in the ID token for transfer of the at least one attribute to a second computer system (150).