Telecommunications Authentication Using ID Token Soft Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management methods face issues such as user manipulation, centralization leading to data protection concerns, and the need for registration, which compromise security and privacy.

Innovation Solution

A telecommunications method involving ID tokens with end-to-end encryption, where attributes are read from an ID token, used to generate soft tokens with time specifications, ensuring secure and trustworthy transmission and storage, and allowing for secure online updates without central storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital identities are stored centrally in a server-based system, then user authentication can be managed, but data protection is compromised and user behavior can be recorded

Engineering Contradiction:
Improveauthentication managementVSAvoiddata protection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the digital identity data from centralized servers and stores it in distributed ID tokens on user devices. The identity attributes are read locally from the ID token and transmitted only when needed, eliminating the need for centralized storage and preventing behavior recording.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the digital identity management into separate components: the ID token stored on the user device containing identity attributes, the reader that reads these attributes, and the service system that receives them. This segmentation distributes control and eliminates centralized storage vulnerabilities.

Inventive Principle:
Principle #1Segmentation

2Reliability

If user registration is required for digital identity management, then identity verification can be performed, but the process becomes complex and time-consuming

Engineering Contradiction:
Improveidentity verificationVSAvoidregistration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The ID token is pre-loaded with identity attributes before the user needs them. This preliminary action eliminates the need for registration at the point of use, as the identity data is already available in the ID token on the user's device.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of requiring users to register and create digital identities in a centralized system, the patent uses copies of official identity documents stored in ID tokens. These copies can be read and verified without requiring registration in the service system.

Inventive Principle:
Principle #26Copying

3Ease of operation

If digital identity data is transmitted over networks, then service access is enabled, but manipulation and replay attacks become possible

Engineering Contradiction:
Improveservice accessVSAvoidmanipulation and replay attacks
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent implements time-limited validity for transmitted identity attributes by including timestamp information and validity periods in the data structure. This periodic action ensures that captured data cannot be replayed after expiration, preventing replay attacks while enabling network transmission for service access.

Inventive Principle:
Principle #19Periodic action

4Ease of operation

If attributes are read from ID token without time specification, then authentication is simple, but replay attacks cannot be prevented

Engineering Contradiction:
Improveauthentication simplicityVSAvoidreplay attack prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent preliminarily embeds time specification data (timestamps and validity periods) into the identity attributes within the ID token before transmission. This preliminary action maintains authentication simplicity while enabling replay attack prevention through automatic time-based validation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2338255B1Method, computer program product and system for authenticating a user of a telecommunications network
Publication Date: 2017.04.05 BUNDESDRUCKEREI GMBH
  • EP2338255B1 patent drawingFigure 1
  • EP2338255B1 patent drawingFigure 1
  • EP2338255B1 patent drawingFigure 2

AI summary

The invention relates to a telecommunication method with the following steps: establishing a first connection (101) between a first ID-token (106) and a first computer system (136) via a second computer system (100) for reading out at least a first attribute from the first ID-token, generating a first soft-token, wherein the first Soft-Token comprises at least a first attribute and a time stamp and the first soft-token is signed by the first computer system, transmitting the first soft-token from the first computer system to a third computer system (150), wherein the first connection is a connection with end-to-end encoding.