Soft Token Generation via ID Token Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems face issues such as user manipulation, central storage of digital identities leading to data protection concerns, and the need for user registration, which compromise security and privacy.

Innovation Solution

A method for generating a soft token by authenticating a user and a computer system against an ID token, allowing secure transmission of attributes over a network, with end-to-end encryption and trusted certificates to ensure data protection and trustworthiness, without central storage of user attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital identities are stored centrally in a server-based system, then user authentication can be managed, but data protection is compromised and user behavior can be recorded

Engineering Contradiction:
Improveauthentication managementVSAvoiddata protection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the digital identity data from centralized server storage and places it directly on the user's device (smartphone, tablet, or computer). The ID token containing encrypted identity information resides locally on the user's device rather than being stored centrally, eliminating the risk of centralized data breaches while maintaining authentication capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the authentication process into multiple components: the ID token stored on the user's device, the encrypted identity information, and the authentication verification process. This segmentation allows the identity data to be distributed across the user's device rather than concentrated in a central server, improving data protection while maintaining system reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If user registration is required for digital identity management, then identities can be managed, but the process becomes more complex and time-consuming

Engineering Contradiction:
Improveidentity managementVSAvoidregistration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables users to self-generate their own ID tokens without requiring registration with a central authority. Users can create their own encrypted identity information and store it locally on their devices, eliminating the need for complex registration processes while maintaining reliable identity management.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If all user attributes are transmitted to computer systems, then complete user information is available, but data protection is compromised

Engineering Contradiction:
Improveinformation availabilityVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements local quality by allowing different levels of attribute disclosure based on the specific authentication context. The ID token can selectively reveal only the necessary attributes for a given authentication scenario while keeping other attributes encrypted and hidden, providing both ease of operation and data protection.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2454700B1Process to create a soft-token
Publication Date: 2018.01.24 BUNDESDRUCKEREI GMBH
  • EP2454700B1 patent drawingFigure 1
  • EP2454700B1 patent drawingFigure 2
  • EP2454700B1 patent drawingFigure 3

AI summary

The invention relates to a method for reading at least one attribute stored in an ID token (106, 106'), said ID token being associated with a user (102). The method comprises the following steps: authenticating the user relative to the ID token, authenticating a first computer system (136) relative to the ID token, once the user and the first computer have been successfully authenticated relative to the ID token, read access of the first computer system to the at least one attribute stored in the ID token, producing a first soft token by the first computer system signing the at least one attribute read out from the ID token, and transmitting the first soft token to a device.