ID Token Foreign Attribute Expansion via Cryptographic Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for digital identities do not provide a means to supplement attributes stored in ID tokens with attributes not directly secured by the trust of the ID provider, limiting the expansion of attributes and anonymous or pseudonymous transactions.
Innovation Solution
A method for expanding attributes in the memory of an ID token within a hierarchy of digitally encoded trust relationships by allowing foreign attributes to be written and read through cryptographic protocols, using an external interface for authentication and secure access, enabling pseudonymous transactions and anonymous assurances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If attributes are stored only with direct trust from the ID provider, then security and trust integrity are maintained, but the ability to expand attributes with foreign providers is limited
Solution Approach 1:
The patent introduces a foreign attribute provider as an intermediary entity that can write attributes to the ID token without having direct trust from the ID provider. The ID provider acts as a mediator that facilitates the writing process through cryptographic protocols, allowing foreign attributes to be stored while maintaining the trust hierarchy. This resolves the contradiction by enabling attribute expansion through intermediaries while preserving the original trust relationships.
Solution Approach 2:
The patent segments the trust relationship into multiple layers: the ID provider maintains trust over the ID token structure and authentication, while foreign attribute providers can contribute specific attributes through cryptographic verification. This segmentation allows different entities to have different levels of access and trust, enabling attribute expansion without compromising overall system security and trust integrity.
2Reliability
If cryptographic protocols are implemented for foreign attribute access, then security is enhanced, but system complexity increases
Solution Approach 1:
The ID token is equipped with self-service capabilities to perform cryptographic verification of foreign attributes independently. The token can autonomously verify the authenticity of foreign attributes using public key cryptography and digital signatures, without requiring constant intervention from the ID provider. This self-service approach enhances security while reducing the operational complexity of managing foreign attribute access.
Solution Approach 2:
The patent replaces manual or centralized cryptographic verification mechanisms with automated cryptographic protocols embedded in the ID token hardware. Instead of requiring the ID provider to manually verify and approve each foreign attribute, the system uses mathematical cryptography (digital signatures, public-key infrastructure) to automatically verify attribute authenticity, reducing human intervention and simplifying system operations despite the cryptographic complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
What is proposed is a method for extending attributes in the memory of an ID token within a hierarchy of digitally coded trust settings by providing the ID token, wherein the ID token is equipped with a memory, an external interface, devices for authentication via the external interface and devices for read- and write-protected access to the memory via the external interface, by steps for the communication of a digitally coded trust setting for writing a foreign attribute to the memory of the ID token by means of an ID provider computer to a foreign attribute provider computer, for carrying out a cryptographic protocol for authenticating the ID token in relation to the foreign attribute provider computer and for verifying the digitally coded trust setting for writing access to the memory of the ID token and for writing a foreign attribute to the memory of the ID token via the external interface thereof by means of the foreign attribute provider computer.