Soft Token Generation via ID Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity management systems face issues such as user manipulation, central storage of digital identities leading to data protection concerns, and the need for user registration, which compromise security and privacy.
Innovation Solution
A method for generating a soft token by authenticating a user and a computer system against an ID token, allowing secure transmission of attributes over a network, with end-to-end encryption and trusted certificates to ensure data protection and trustworthiness, without central storage of user attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital identities are stored centrally in a server-based system, then user authentication can be managed, but data protection is compromised and user behavior can be recorded
Solution Approach 1:
The patent extracts the digital identity data from centralized server storage and places it directly on the user's device (smartphone, tablet, or computer). The ID token containing encrypted identity information resides locally on the user's device rather than being stored centrally, eliminating the risk of centralized data breaches while maintaining authentication capabilities.
Solution Approach 2:
The system segments the authentication process into multiple components: the ID token stored on the user's device, the encrypted identity information, and the authentication verification process. This segmentation allows the identity data to be distributed across the user's device rather than concentrated in a central server, improving data protection while maintaining system reliability.
2Reliability
If user registration is required for digital identity management, then identities can be managed, but the process becomes more complex and time-consuming
Solution Approach 1:
The system enables users to self-generate their own ID tokens without requiring registration with a central authority. Users can create their own encrypted identity information and store it locally on their devices, eliminating the need for complex registration processes while maintaining reliable identity management.
3Ease of operation
If all user attributes are transmitted to computer systems, then complete user information is available, but data protection is compromised
Solution Approach 1:
The system implements local quality by allowing different levels of attribute disclosure based on the specific authentication context. The ID token can selectively reveal only the necessary attributes for a given authentication scenario while keeping other attributes encrypted and hidden, providing both ease of operation and data protection.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for reading at least one attribute stored in an ID token (106, 106'), said ID token being associated with a user (102). The method comprises the following steps: authenticating the user relative to the ID token, authenticating a first computer system (136) relative to the ID token, once the user and the first computer have been successfully authenticated relative to the ID token, read access of the first computer system to the at least one attribute stored in the ID token, producing a first soft token by the first computer system signing the at least one attribute read out from the ID token, and transmitting the first soft token to a device.