ID Token Attribute Reading via Secure Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation, lack of data protection, and centralization of user behavior records, as well as limitations in securely reading and writing attributes from ID tokens.

Innovation Solution

A method for reading attributes from an ID token that involves a secure communication protocol between the ID token, an ID provider module, and attribute provider computer systems, ensuring protected access and transmission using end-to-end encryption, with mutual authentication and authorization checks to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital identities are stored centrally in a server-based system, then data protection is improved through centralized control, but user privacy deteriorates due to centralized recording of user behavior

Engineering Contradiction:
Improvedata protectionVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the digital identity system by separating the identity token from the attribute data. The identity token is stored in a secure element on the user's device, while attribute data is distributed across multiple attribute provider systems. This segmentation prevents centralized storage of complete user profiles, thereby protecting user privacy while maintaining data protection through cryptographic security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the secure element acts as a mediator between the user and attribute providers. The secure element contains cryptographic credentials that enable authentication without exposing sensitive attribute data. This intermediary layer protects user privacy by preventing direct access to attribute data while maintaining system reliability through secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If attributes are read directly from ID token without additional authentication, then ease of operation is improved, but security deteriorates due to potential unauthorized access

Engineering Contradiction:
Improveattribute readingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication actions before attribute reading. The secure element must first authenticate the attribute provider using cryptographic credentials stored in the secure element. Only after successful authentication is the attribute data released. This preliminary authentication step maintains ease of operation for authorized users while ensuring security against unauthorized access.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If user computer system has access to attribute specification for service requests, then ease of operation is improved, but security deteriorates by exposing sensitive information

Engineering Contradiction:
Improveservice request processingVSAvoidinformation exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the attribute specification from the user computer system and places it directly into the secure element. The secure element then uses this extracted specification to authenticate with attribute providers and retrieve only the necessary attributes. This extraction eliminates the need for the user computer system to handle sensitive attribute specifications, thereby maintaining ease of operation while preventing information exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3244332B1Method for reading attributes from an id token
Publication Date: 2019.03.06 BUNDESDRUCKEREI GMBH
  • EP3244332B1 patent drawingFigure 1
  • EP3244332B1 patent drawingFigure 2A
  • EP3244332B1 patent drawingFigure 2B

AI summary

The invention relates to a method for reading attributes from an ID token (106) assigned to a user (102). The method includes: - sending a service request (103) from the user computer system (100) to a service computer system (150); - sending a first attribute specification (105) from the service computer system to the ID provider module; - mutual authentication of the ID provider module and the ID token; - writing the first attribute specification (105) to a protected memory area of ​​the ID token; - sending one or more class identifiers (702) to an attribute provider directory computer system (199), wherein the attribute provider directory computer system is neither authorized to read the first attribute specification from the ID token nor to write attributes to the ID token;- Receipt of one or more identifiers (704) by the user computer system (100), wherein each of the identifiers (704) identifies an attribute provider computer system (172, 1722, 1723, 173, 174) which is trained to provide user-related attributes of the attribute class identified by the class identifier;