ID Token Attribute Reading with Signed Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation, lack of data protection, and central storage of user identities, which compromise security and privacy.

Innovation Solution

A method for reading attributes from an ID token that involves user and system authentication, establishing a secure connection, and transmitting signed attributes with timestamps, ensuring data protection and preventing manipulation through end-to-end encryption and tamper-proof mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital identities are stored centrally in a server-based system, then user authentication can be managed, but data protection is compromised and user behavior can be recorded

Engineering Contradiction:
Improveauthentication managementVSAvoiddata protection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the digital identity data from centralized storage and places it in a distributed token system. The ID token contains all necessary authentication data locally, eliminating the need for centralized identity storage while maintaining authentication functionality. This extraction resolves the contradiction by removing the central vulnerability point while preserving authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication system is segmented into multiple independent components: the ID token, the client application, and the service provider. Each component operates independently with the ID token holding authentication data locally. This segmentation eliminates centralized storage while maintaining distributed authentication capability, resolving the data protection issue.

Inventive Principle:
Principle #1Segmentation

2Reliability

If user registration is required for digital identity management, then identities can be managed, but the system complexity and user burden increase

Engineering Contradiction:
Improveidentity managementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The ID token is prepared in advance with all necessary authentication data and cryptographic credentials embedded. This preliminary configuration eliminates the need for runtime registration or setup procedures. Users simply present the pre-configured token for authentication, reducing system complexity while maintaining reliable identity management.

Inventive Principle:
Principle #10Preliminary action

3Speed

If attributes are transmitted without signing and timestamping, then transmission speed is faster, but manipulation and trustworthiness increase

Engineering Contradiction:
Improvetransmission speedVSAvoiddata trustworthiness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent changes the parameter of data integrity from unsigned to signed, and adds timestamp parameters to each attribute transmission. These parameter changes enable verification of data authenticity and timing without significantly impacting transmission speed. The digital signature and timestamp provide cryptographic proof of trustworthiness while maintaining efficient communication.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2454704B1Method to read attributes from an id-token
Publication Date: 2018.05.02 BUNDESDRUCKEREI GMBH
  • EP2454704B1 patent drawingFigure 1
  • EP2454704B1 patent drawingFigure 2
  • EP2454704B1 patent drawingFigure 3

AI summary

The invention relates to a method for reading at least one attribute stored in an ID token (106, 106'), wherein the ID is associated with a user (102), having the following steps: authenticating the user with respect to the ID token, authenticating a first computer system (136) with respect to the ID token by means of a first network (116), accessing the at least one attribute store in the ID token for reading by the first computer system after successfully authenticating the user, signing the at least one attribute read from the ID token by the first computer system, transferring the signed attribute from the first computer system to a second computer system (150) by means of a second network (172). La présente invention concerne un procédé pour lire au moins un attribut enregistré dans un jeton d'identification (106, 106'), le jeton d'identification étant attribué à un utilisateur (102). Le procédé comporte les étapes consistant à : authentifier l'utilisateur par rapport au jeton d'identification, authentifier un premier système informatique (136) par rapport au jeton d'identification par le biais d'un premier réseau (116), après une authentification réussie de l'utilisateur et du premier système informatique par rapport au jeton d'identification, permettre au premier système informatique d'accéder en lecture au ou aux attributs enregistrés dans le jeton d'identification, signer le ou les attributs lus à partir du jeton d'identification, transmettre via le premier système informatique l'attribut signé à un deuxième système informatique (150) par le biais d'un deuxième réseau (172).