ID Token Secure Memory for Electronic Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic transaction methods in e-commerce and e-government applications lack a secure and user-friendly solution for authenticating users and accessing payment information, often compromising privacy and security.

Innovation Solution

A computer-implemented payment method utilizing an ID token with a secure memory area, where user authentication and ID provider system authentication are both required, ensuring secure transactions by reading attributes from the ID token only for authorized purposes, using a multi-session protocol with encryption and mutual authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard payment methods are used for electronic transactions, then ease of operation is improved, but security and privacy protection deteriorate

Engineering Contradiction:
Improveease of transactionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an ID token as an intermediary device that mediates between the user and the service provider. The ID token contains secure memory areas with user attributes and cryptographic keys, acting as a trusted intermediary that enables secure authentication and attribute disclosure without requiring the user to directly manage complex security protocols or share sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the user's identity and payment information into multiple attributes stored in different secure memory areas within the ID token. This segmentation allows selective disclosure of only necessary attributes for each transaction, improving security by minimizing exposed information while maintaining ease of operation through automated attribute selection.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If user authentication data is stored in accessible memory, then ease of operation is improved, but security deteriorates due to unauthorized access

Engineering Contradiction:
Improveaccessibility of authentication dataVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by creating different security zones within the ID token's memory structure. Certain memory areas are marked as secure and require specific authentication procedures for access, while other areas are more accessible. This allows the system to provide ease of operation for legitimate users while maintaining strong security against unauthorized access through differentiated access controls.

Inventive Principle:
Principle #3Local quality

3Reliability

If the ID provider system has full access to transaction data, then transaction security is improved, but user privacy deteriorates

Engineering Contradiction:
Improvetransaction securityVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies partial action by enabling the ID token to disclose only the specific attributes necessary for each transaction, rather than providing full access to all user information. The ID provider system receives only the attributes required for authentication and transaction validation, maintaining security while preserving user privacy through minimal necessary disclosure.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If multiple authentication protocols are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the ID token to autonomously manage multiple authentication protocols and cryptographic operations. The token automatically selects and executes appropriate authentication methods based on the service provider's requirements, shielding users from the complexity of multiple protocols while maintaining high security through automated protocol selection and execution.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2879073B1Electronic transaction method and computer system
Publication Date: 2018.06.27 BUNDESDRUCKEREI GMBH
  • EP2879073B1 patent drawingFigure 1
  • EP2879073B1 patent drawingFigure 2

AI summary

The invention relates to an electronic transaction method using an ID token (106) assigned to a user (102), wherein the ID token has an electronic memory (118) with a protected memory area (124) in which one or more attributes are stored, wherein access to the protected memory area is only possible via a processor (128) of the ID token, and wherein the ID token has a communication interface (108) for communication with a reader (196) of a user computer system (100).