ID Token Foreign Attribute Expansion via Cryptographic Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for digital identities do not provide a means to supplement attributes stored in ID tokens with attributes not directly secured by the trust of the ID provider, limiting the expansion of attributes and anonymous or pseudonymous transactions.

Innovation Solution

A method for expanding attributes in the memory of an ID token within a hierarchy of digitally encoded trust relationships by allowing foreign attributes to be written and read through cryptographic protocols, using an external interface for authentication and secure access, enabling pseudonymous transactions and anonymous assurances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If attributes are stored only with direct trust from the ID provider, then security and trust integrity are maintained, but the ability to expand attributes with foreign providers is limited

Engineering Contradiction:
Improveattribute expansion capabilityVSAvoidtrust relationship integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a foreign attribute provider as an intermediary entity that can write attributes to the ID token without having direct trust from the ID provider. The ID provider acts as a mediator that facilitates the writing process through cryptographic protocols, allowing foreign attributes to be stored while maintaining the trust hierarchy. This resolves the contradiction by enabling attribute expansion through intermediaries while preserving the original trust relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the trust relationship into multiple layers: the ID provider maintains trust over the ID token structure and authentication, while foreign attribute providers can contribute specific attributes through cryptographic verification. This segmentation allows different entities to have different levels of access and trust, enabling attribute expansion without compromising overall system security and trust integrity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic protocols are implemented for foreign attribute access, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The ID token is equipped with self-service capabilities to perform cryptographic verification of foreign attributes independently. The token can autonomously verify the authenticity of foreign attributes using public key cryptography and digital signatures, without requiring constant intervention from the ID provider. This self-service approach enhances security while reducing the operational complexity of managing foreign attribute access.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual or centralized cryptographic verification mechanisms with automated cryptographic protocols embedded in the ID token hardware. Instead of requiring the ID provider to manually verify and approve each foreign attribute, the system uses mathematical cryptography (digital signatures, public-key infrastructure) to automatically verify attribute authenticity, reducing human intervention and simplifying system operations despite the cryptographic complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3180729B1Digital identities with foreign attributes
Publication Date: 2021.06.16 BUNDESDRUCKEREI GMBH
  • EP3180729B1 patent drawingFigure 1
  • EP3180729B1 patent drawingFigure 2
  • EP3180729B1 patent drawingFigure 3

AI summary

What is proposed is a method for extending attributes in the memory of an ID token within a hierarchy of digitally coded trust settings by providing the ID token, wherein the ID token is equipped with a memory, an external interface, devices for authentication via the external interface and devices for read- and write-protected access to the memory via the external interface, by steps for the communication of a digitally coded trust setting for writing a foreign attribute to the memory of the ID token by means of an ID provider computer to a foreign attribute provider computer, for carrying out a cryptographic protocol for authenticating the ID token in relation to the foreign attribute provider computer and for verifying the digitally coded trust setting for writing access to the memory of the ID token and for writing a foreign attribute to the memory of the ID token via the external interface thereof by means of the foreign attribute provider computer.