ID Token Attribute Reading via Dual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation, lack of data protection, and central storage of user identities, which compromise security and privacy.

Innovation Solution

A method for reading attributes from an ID token, which involves user and system authentication, secure connection establishment, and transmission of attributes to a second system, ensuring secure and trustworthy handling of digital identity information without central storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital identities are stored centrally in a server-based system, then user identity management is simplified, but data protection is compromised and user behavior can be recorded

Engineering Contradiction:
Improveidentity managementVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the digital identity data from centralized server storage and places it directly on the user's mobile device in the form of an ID token. This extraction eliminates the centralized database that compromises data protection, while the tokenized format maintains the ability to manage digital identities securely at the user level.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication system that uses cryptographic protocols to verify user identity without exposing the actual identity data. The system acts as a mediator between the user and service providers, allowing identity verification while preserving data protection through secure token-based authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users can manipulate their digital identity, then flexibility is improved, but security is compromised

Engineering Contradiction:
Improveidentity flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-authenticating the user to the ID token before any attribute access occurs. The user must authenticate once, and this authentication state is maintained for subsequent attribute readings, allowing flexible access to different attributes without repeated authentication while maintaining security through the pre-established trusted relationship.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by allowing the ID token to dynamically control attribute access based on the authenticated user's permissions. The token can selectively provide different attributes to different service providers based on the user's consent and the service provider's requirements, providing flexibility while maintaining security through dynamic access control.

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple authentication steps are required, then security is improved, but operation complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple authentication steps into a single user authentication action. When the user authenticates to the ID token, this single authentication event establishes trust for both the user and the first computer system, eliminating the need for separate authentication steps and simplifying the overall operation while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2454703B1Method for reading attributes from an id token
Publication Date: 2019.11.20 BUNDESDRUCKEREI GMBH
  • EP2454703B1 patent drawingFigure 1
  • EP2454703B1 patent drawingFigure 2
  • EP2454703B1 patent drawingFigure 3~3a

AI summary

The invention relates to a method for reading at least one attribute stored in an ID token (106, 106'), said ID token being associated with a user (102). The method comprises the following steps: authenticating the user relative to the ID token, authenticating a first computer system (136) relative to the ID token, once the user and the first computer have been successfully authenticated relative to the ID token, read access of the first computer system to the at least one attribute stored in the ID token for transmitting the at least one attribute to a second computer system (150), and generation of a time indication for the at least one attribute by the first computer system.