ID Token Attribute Reading via Secure Channel Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation in client-based systems and inadequate data protection in server-based systems, with central storage of user identities and behavior recording.

Innovation Solution

A method for reading attributes from an ID token using a portable electronic device with protected memory and a communication interface, where access is authorized, involving multiple computer systems for authentication and secure data transmission to provide services while ensuring user privacy and data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If client-based digital identity systems are used, then users can manage their own digital identity, but users can manipulate their digital identity

Engineering Contradiction:
Improveuser control over digital identityVSAvoidintegrity of digital identity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted third party (authentication server) that mediates between the user and the service provider. This intermediary verifies the digital identity attributes against a trusted database, preventing user manipulation while maintaining user control over their identity management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If server-based digital identity systems are used, then digital identities are stored centrally, but data protection is inadequate and user behavior can be recorded

Engineering Contradiction:
Improvecentralized identity managementVSAvoiddata protection vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the digital identity storage into distributed components - each service provider maintains its own database of verified attributes rather than a single centralized storage. This segmentation reduces the impact of data breaches and prevents comprehensive user behavior tracking while maintaining centralized verification through the authentication server.

Inventive Principle:
Principle #1Segmentation

3Reliability

If attributes are stored in protected memory areas, then unauthorized access is prevented, but the system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication actions before attribute access. The authentication server pre-verifies the service provider's authorization and the user's identity before allowing any attribute retrieval. This preliminary action simplifies subsequent access control mechanisms by establishing trust beforehand, reducing the need for complex continuous verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3748521B1Method for reading attributes from an id token
Publication Date: 2023.10.18 BUNDESDRUCKEREI GMBH
  • EP3748521B1 patent drawingFigure 1
  • EP3748521B1 patent drawingFigure 2
  • EP3748521B1 patent drawingFigure 3

AI summary

The invention relates to a method for reading attributes from an ID token comprising the following steps: - authentication of the user to the ID token and optional establishment of a secure transmission channel (SM-[PACE]) between the ID token and the user's computer system, - mutual authentication and establishment of a first secure transmission channel (SM-[CA] #1) with end-to-end encryption between the ID token and the ID provider computer system over the network, - execution of a first read access (107) by the ID provider computer system to the ID token to read the attributes according to the first attribute specification from the ID token, - transmission of a first subset of the attributes (109) specified in the first attribute specification, stored in the memory area of ​​the ID token, from the ID token to the ID provider computer system via the first secure transmission channel.- Generation of a second attribute specification (111) of a second subset of the attributes of the first attribute specification, which specifies those attributes which are not included in the first subset, and transmission of the second attribute specification from the ID provider computer system to the ID token via the first secure transmission channel, - Storage of the second attribute specification in the ID token, - Authentication of an attribute provider computer system (172) to the ID token, - Authentication of the ID token to the attribute provider computer system, - Establishment of a second secure transmission channel (SM-[CA] #2) with end-to-end encryption between the attribute provider computer system and the ID token, whereby the first secure transmission channel remains in place, - Transmission of the second attribute specification from the ID token to the attribute provider computer system via the second secure transmission channel,- Execution of a write access (176) by the attribute provider computer system over the second secure transmission channel to store attributes according to the second attribute specification in the ID token, - Optionally, execution of a write access (176) by the attribute provider computer system over the second secure transmission channel to store a third attribute specification in the ID token for attributes not yet written, - Optionally, mutual authentication and establishment of a third secure transmission channel (SM-[CA] #3) with end-to-end encryption between the attribute provider computer system and the ID token, while the first secure transmission channel remains active, transmission of the third attribute specification from the ID token to the attribute provider computer system via the third secure transmission channel,Execution of a write access (176) by the attribute provider computer system over the third secure transmission channel to store attributes according to the third attribute specification in the ID token, - iteration over any number of attribute provider computer systems until the termination condition is met, - execution of a second read access (177) by the ID provider computer system over the first secure transmission channel to read the attributes stored by the attribute provider computer system in the ID token according to the second attribute specification.