ID Token Attribute Reading via Mobile Radio Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation, central storage of identities leading to data protection concerns, and the need for user registration, which compromise security and privacy.

Innovation Solution

A method for reading attributes from an ID token using a mobile radio connection, establishing a protected connection, and authenticating the user and computer system to access and transmit signed attributes, ensuring secure and trustworthy digital identity verification without central storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital identities are stored centrally in a database, then user management and authentication become simplified, but data protection and security are compromised

Engineering Contradiction:
Improveuser managementVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized identity management system into distributed components. Each user possesses their own ID token that contains identity attributes, eliminating the need for a central database. The identity information is split between the user's token and the service provider's verification capability, with no central storage point, thus maintaining security while enabling management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries (digital signatures, certificates, and verification protocols) between the user's ID token and service providers. These cryptographic mechanisms enable secure verification of identity attributes without requiring central storage or direct trust relationships, resolving the contradiction between ease of verification and data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user registration is required for digital identity systems, then centralized control and security management are improved, but user convenience and system accessibility are reduced

Engineering Contradiction:
Improvesecurity managementVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-loading identity attributes into the user's ID token before any service interaction. The token is prepared in advance with relevant attributes (e.g., age, nationality, permissions), allowing users to present ready-to-verify credentials without registration or real-time database queries, thus improving convenience while maintaining security through pre-established cryptographic protection.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple attributes are read and transmitted, then service functionality and user verification capabilities are enhanced, but data exposure and security risks increase

Engineering Contradiction:
Improveservice functionalityVSAvoiddata exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by enabling service providers to read and verify only the specific attributes required for a given service, rather than accessing all user attributes. The ID token contains multiple attributes with different access permissions, and the verification process selectively retrieves only necessary information (e.g., age for age-restricted services), thus enhancing service functionality while minimizing data exposure through attribute-level control.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2415228B1Method for reading attributes of a token via a wireless connection
Publication Date: 2016.05.11 BUNDESDRUCKEREI GMBH
  • EP2415228B1 patent drawingFigure 1
  • EP2415228B1 patent drawingFigure 2
  • EP2415228B1 patent drawingFigure 3

AI summary

The invention relates to a method for reading at least one attribute saved in an ID token (106, 106'), wherein the ID token is allocated to a user (102) and wherein the ID token has a first interface, having the following steps: authenticating the user compared to the ID token, establishing a mobile radio connection between a mobile radio device and a first computer system (136), wherein the mobile radio device has a second interface, establishing a secured connection via the mobile radio connection and via the first and second interfaces between the first computer system and the ID token, authenticating the first computer system (136) compared to the ID token via the secured connection, following successful authentication of the user and the first computer system compared to the ID token, read access of the first computer system to the at least one attribute saved in the ID token for transfer of the at least one attribute via a network (116) after signing thereof.