ID Token Attribute Reading via Secure Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity management systems face issues such as user manipulation, lack of data protection, and centralization of user behavior records, as well as limitations in securely reading and writing attributes from ID tokens.
Innovation Solution
A method for reading attributes from an ID token that involves a secure communication protocol between the ID token, an ID provider module, and attribute provider computer systems, ensuring protected access and transmission using end-to-end encryption, with mutual authentication and authorization checks to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital identities are stored centrally in a server-based system, then data protection is improved through centralized control, but user privacy deteriorates due to centralized recording of user behavior
Solution Approach 1:
The patent segments the digital identity system by separating the identity token from the attribute data. The identity token is stored in a secure element on the user's device, while attribute data is distributed across multiple attribute provider systems. This segmentation prevents centralized storage of complete user profiles, thereby protecting user privacy while maintaining data protection through cryptographic security.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the secure element acts as a mediator between the user and attribute providers. The secure element contains cryptographic credentials that enable authentication without exposing sensitive attribute data. This intermediary layer protects user privacy by preventing direct access to attribute data while maintaining system reliability through secure authentication.
2Ease of operation
If attributes are read directly from ID token without additional authentication, then ease of operation is improved, but security deteriorates due to potential unauthorized access
Solution Approach 1:
The patent implements preliminary authentication actions before attribute reading. The secure element must first authenticate the attribute provider using cryptographic credentials stored in the secure element. Only after successful authentication is the attribute data released. This preliminary authentication step maintains ease of operation for authorized users while ensuring security against unauthorized access.
3Ease of operation
If user computer system has access to attribute specification for service requests, then ease of operation is improved, but security deteriorates by exposing sensitive information
Solution Approach 1:
The patent extracts the attribute specification from the user computer system and places it directly into the secure element. The secure element then uses this extracted specification to authenticate with attribute providers and retrieve only the necessary attributes. This extraction eliminates the need for the user computer system to handle sensitive attribute specifications, thereby maintaining ease of operation while preventing information exposure.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
The invention relates to a method for reading attributes from an ID token (106) assigned to a user (102). The method includes: - sending a service request (103) from the user computer system (100) to a service computer system (150); - sending a first attribute specification (105) from the service computer system to the ID provider module; - mutual authentication of the ID provider module and the ID token; - writing the first attribute specification (105) to a protected memory area of the ID token; - sending one or more class identifiers (702) to an attribute provider directory computer system (199), wherein the attribute provider directory computer system is neither authorized to read the first attribute specification from the ID token nor to write attributes to the ID token;- Receipt of one or more identifiers (704) by the user computer system (100), wherein each of the identifiers (704) identifies an attribute provider computer system (172, 1722, 1723, 173, 174) which is trained to provide user-related attributes of the attribute class identified by the class identifier;