ID Token Attribute Access via Zero-Knowledge Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital identity management methods, such as Microsoft Windows CardSpace, are computationally expensive and have long runtime, making them unsuitable for time-critical applications due to the need for cryptographic operations and request-response cycles in establishing secure data transmission channels.

Innovation Solution

A method that determines the availability of a contact-based interface for an ID token and uses a zero-knowledge authentication protocol via a contactless interface if it is not available, allowing for the generation and use of an ID token identifier to authenticate the user and access attributes without the need for computationally expensive protocols when a contact-based interface is present.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic operations and request-response cycles are used to establish secure data transmission channels, then security is improved, but runtime is increased

Engineering Contradiction:
ImprovesecurityVSAvoidruntime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication actions by storing authentication data directly in the ID token before use. The terminal can authenticate the ID token without requiring real-time cryptographic operations or request-response cycles, as the authentication credentials are pre-established and stored locally in the token itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the authentication functionality from the terminal system and embeds it directly into the ID token. By taking out the cryptographic verification process and placing authentication credentials within the token, the system eliminates the need for computationally expensive real-time authentication operations at the terminal.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If contactless interface is used for authentication, then ease of operation is improved, but authentication speed is reduced

Engineering Contradiction:
Improveease of operationVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent prepares authentication credentials in advance and stores them within the ID token during token creation or initialization. This preliminary action allows the terminal to perform fast authentication by simply reading pre-stored credentials via the contactless interface, without requiring time-consuming cryptographic operations during the actual authentication process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2962439B1Reading an attribute from an id token
Publication Date: 2017.08.30 BUNDESDRUCKEREI GMBH
  • EP2962439B1 patent drawingFigure 1~2c
  • EP2962439B1 patent drawingFigure 3
  • EP2962439B1 patent drawingFigure 4

AI summary

The invention relates to a method for reading at least one attribute (130) that is stored in an ID token (104), wherein the ID token is associated with a user (132), having the following steps: establishment (302), by a terminal (102), of whether a contact-based interface (120) of the ID token is existent and can be used for data interchange with the terminal; if the ID token does not have the contact-based interface or the latter cannot be used:• performance (308) of a zero-knowledge authentication protocol via a contactless interface (134, 136) of terminal and ID token; and • derivation (310) of an ID token identifier (400, 500, 604) by the terminal; if the ID token has the contact-based interface and the latter can be used: • authentication (304) of the user to the ID token via the contact-based interface; • access (306) to an ID token identifier (400, 500, 604) by the terminal; transmission (312) of the ID token identifier from the terminal to an ID provider computer (502); use (314) of the ID token identifier by the ID provider computer for authentication of the ID provider computer to the ID token; read access (316) by the ID provider computer to the at least one attribute stored in the ID token.