Telecommunications Authentication Using ID Token Soft Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity management methods face issues such as user manipulation, centralization leading to data protection concerns, and the need for registration, which compromise security and privacy.
Innovation Solution
A telecommunications method involving ID tokens with end-to-end encryption, where attributes are read from an ID token, used to generate soft tokens with time specifications, ensuring secure and trustworthy transmission and storage, and allowing for secure online updates without central storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital identities are stored centrally in a server-based system, then user authentication can be managed, but data protection is compromised and user behavior can be recorded
Solution Approach 1:
The patent extracts the digital identity data from centralized servers and stores it in distributed ID tokens on user devices. The identity attributes are read locally from the ID token and transmitted only when needed, eliminating the need for centralized storage and preventing behavior recording.
Solution Approach 2:
The system segments the digital identity management into separate components: the ID token stored on the user device containing identity attributes, the reader that reads these attributes, and the service system that receives them. This segmentation distributes control and eliminates centralized storage vulnerabilities.
2Reliability
If user registration is required for digital identity management, then identity verification can be performed, but the process becomes complex and time-consuming
Solution Approach 1:
The ID token is pre-loaded with identity attributes before the user needs them. This preliminary action eliminates the need for registration at the point of use, as the identity data is already available in the ID token on the user's device.
Solution Approach 2:
Instead of requiring users to register and create digital identities in a centralized system, the patent uses copies of official identity documents stored in ID tokens. These copies can be read and verified without requiring registration in the service system.
3Ease of operation
If digital identity data is transmitted over networks, then service access is enabled, but manipulation and replay attacks become possible
Solution Approach 1:
The patent implements time-limited validity for transmitted identity attributes by including timestamp information and validity periods in the data structure. This periodic action ensures that captured data cannot be replayed after expiration, preventing replay attacks while enabling network transmission for service access.
4Ease of operation
If attributes are read from ID token without time specification, then authentication is simple, but replay attacks cannot be prevented
Solution Approach 1:
The patent preliminarily embeds time specification data (timestamps and validity periods) into the identity attributes within the ID token before transmission. This preliminary action maintains authentication simplicity while enabling replay attack prevention through automatic time-based validation.
Data Source
Figure 1
Figure 1
Figure 2
AI summary
The invention relates to a telecommunication method with the following steps: establishing a first connection (101) between a first ID-token (106) and a first computer system (136) via a second computer system (100) for reading out at least a first attribute from the first ID-token, generating a first soft-token, wherein the first Soft-Token comprises at least a first attribute and a time stamp and the first soft-token is signed by the first computer system, transmitting the first soft-token from the first computer system to a third computer system (150), wherein the first connection is a connection with end-to-end encoding.