EP3244331A1

Method for reading attributes from an id token

Abstract

The invention relates to a method for reading attributes from an ID token (106), the method comprising: - sending (302) a service request (103) from a user computer system (100) to a service computer system (150); - sending a first attribute specification (105) from the service computer system to an ID provider module; Writing the first attribute specification (105) in the ID token by the ID provider module; Sending a trigger signal (T1) from the user computer system to an APV computer system (199); In response to receipt of the trigger signal, reading the first attribute specification (AR) from the protected memory area of ​​the ID token by the APV computer system and dividing the read first attribute specification into at least a second (AR1) and a third (AR2) attribute specification by the APV computer system; Sending the second attribute specification (AR1) and an address (# 106) of the ID token from the APV computer system to a first AP computer system (172) and sending the third and each further attribute specification (AR2, ..., ARn) and the address (# 106) from the APV computer system to each other AP computer system (173, 174); Writing the first attribute set (A1) into the ID token and sending an acknowledgment signal (S1) from the first attribute provider computer system to the attribute provider directory computer system (199) to cause the service computer system to write Read attribute sets.

EP3244331A1, drawing sheet 1
Sheet 1 of 5

Term

10.6 yearsto projected expiry

Projected expiry 9 May 2037, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

17 claims: 7 independent, 10 dependent

  1. c-de-0001
    A method for reading attributes from an ID token (106) associated with a user (102), the ID token comprising a nonvolatile electronic memory (118) having a protected memory area (124), wherein access to the protected Memory area is only possible via a processor (128) of the ID token, with the following steps:- sending (302) a service request (103) of a user from a user computer system (100) to a service computer system (150) coupled to an ID provider module (136);In response to receiving the service request, sending a first attribute specification (105) from the service computer system to the ID provider module, wherein the first attribute specification specifies those attributes that the service computer system provides to provide the service requested with the service request required, and mutual authentication of the ID provider module and ID token;After successful mutual authentication of the ID provider module and the ID token, write the first attribute specification (105) into the protected memory area of ​​the ID token by the ID provider module and send a first message that the first attribute specification is written was, from the service computer system to the user computer system;In response to receiving the first message, sending a trigger signal (T1) from the user computer system to an APV computer system (199), the APV computer system being an attribute provider directory computer system, the first trigger signal being free is included in the first attribute specification (105) and its parts, and an address (# 106) of the ID token (106);In response to receipt of the trigger signal, mutual authentication of the APV computer system (199) and the ID token using the address;After successful mutual authentication of the APV computer system and the ID token, reading the first attribute specification (AR) from the protected memory area of ​​the ID token and dividing the read first attribute specification into at least a second (AR1) and a third (AR2) attribute specification through the APV computer system;Sending the second attribute specification (AR1) and the address (# 106) from the APV computer system to a first AP computer system (172) configured to provide the attributes specified in the second attribute specification, wherein the first AP computer system includes first attribute provider computer system, and sending the third and each further attribute specification (AR2, ..., ARn) and the address (# 106) of the ID token from the APV computer system to each other AP computer system (173 174) each adapted to provide the attributes specified in the third or further attribute specification;In response to receipt of the second attribute specification (AR1) and the address by the first AP computer system, determining a first set (A1) of attributes specified in the second attribute specification, and initializing a mutual authentication of the first AP computer system and the ID token using the address;After the mutual authentication of the first AP computer system and the ID token, write the first attribute set (A1) by the first AP computer system to the protected memory area of ​​the ID token and send an acknowledgment signal (S1) from the first attribute provider Computer system to the attribute provider directory computer system (199);Upon receipt of an acknowledgment signal (S2, S3, ..., Sn) indicating that the respective AP computer system has been able to fully provide the attribute set to be determined by the AP and to write to the protected memory of the ID token, from the first and the second for each of the further AP computer systems, sending a termination signal (SAPV) from the APV computer system to the user computer system;In response to receipt of the termination signal, sending a second (180) message from the user computer system to the service computer system to cause the service computer system to write the written attribute sets (A1, A2, ..., An) Read out from the protected memory area via the first ID provider module.
  2. c-de-0008
    Method according to one of the preceding claims, wherein the ID token has a communication interface (108) for communication with a reading device (101) of the user computer system (100), - wherein the communication interface of the ID token for wireless communication and for the wireless coupling of energy in the ID token by the reader is designed to provide the ID token with the required for its operation electrical energy;and or - wherein the ID token comprises a volatile electronic memory (113) in which the first attribute specification is stored so that the first attribute specification is deleted from the volatile electronic memory when the ID token is removed from the range of the reader, and wherein the first and second sets of attributes stored in the ID token based on the write access of the first and second AP computer systems (172, 173) are stored in the non-volatile electronic memory (118), so that they are subsequently read-only by another Service request can be accessed;or Alternatively, the first attribute specification and the first and second sets of the attributes are stored in the non-volatile memory.
  3. c-de-0009
    Method according to one of the preceding claims, wherein the authentication of the ID provider module with respect to the ID token is performed by means of an authorization certificate (144) of the ID provider module in which reading rights of the ID provider module for reading attributes from the ID token are specified, wherein the ID token for the read access of the ID provider module performs a read authorization of the ID provider module using the authorization certificate;and in the authorization certificate, write authorizations of the ID provider module for writing the first attribute specification in the ID token are specified, wherein the ID token for the write accesses of the ID provider module uses a check of the write authorization of the ID provider module using the authorization certificate.
  4. c-de-0010
    Method according to one of the preceding claims, wherein the authentication of the first AP computer system (172) to the ID token is performed using an authentication certificate of the first AP computer system specifying write permissions of the first AP computer system to write the first set of attributes (A1) in the ID token are;and - wherein the ID token performs a write authorization of the first AP computer system using the authorization certificate before the ID token authorizes the first AP computer system to write the first attribute set.
  5. c-de-0012
    ID token associated with a user (102), wherein the ID token comprises an electronic memory (118) having a protected memory area (124) in which attributes are stored, wherein access to the protected memory area is only via a processor (128) of the ID token, the ID token having a communication interface (108) for communicating with a reader of a user computer system (100), the user computer system coupled to an ID provider module via a network and the ID token is configured to perform the following steps:Mutual authentication of the ID provider module and the ID token in interoperation with the ID provider module;Establishing a first protected transmission channel (SM [CA] # 1) with end-to-end encryption between the ID token and the ID provider module over the network;- receiving a first attribute specification (105) from the ID provider module and storing the received first attribute specification in a protected memory area of ​​the ID token, the first attribute specification specifying those attributes that the service computer system requested to provide the service request Service required;Mutual authentication of an APV computer system and the ID token;Upon mutual authentication of the APV computer system and the ID token, examining an APV computer system-specific authentication certificate to determine if the APV computer system is authorized to read the first attribute specification from the protected memory area;If the APV computer system is authorized to read the first attribute specification, permitting read access to read the first attribute specification to allow the APV computer system to split the read first attribute specification into at least a second (AR1) and a third (AR2) attribute specification;Mutual authentication of a first AP computer system configured to provide attributes, the attributes specified in the second attribute specification, and the ID token;After mutual authentication of the first AP computer system and the ID token, checking a first AP computer system-specific authentication certificate to determine if the first AP computer system is authorized to read the first attribute specification from the protected memory area;If the first AP computer system is authorized to write attributes into the protected memory area of ​​the ID token, permission of the write access of the first AP computer system to the protected memory area to store a first attribute set (A1) in the ID token, wherein the first Set of attributes specified in the second attribute specification and determined by the first attribute provider computer system.
  6. c-de-0014
    AP computer system (172, 1722, 173, 174) having a network interface (138) for accessing an ID token (106) over a network (116), the AP computer system being an attribute provider computer system and is configured to perform the following steps:Receiving, from an APV computer system, a second attribute specification (AR1) which is a subset of the attribute specification generated in a first attribute specification generated by a service computer system, the APV computer system being an attribute provider directory computer system for partitioning the first attribute specification is formed in the second and further attribute specifications, and receiving an address (# 106) of the ID token from the APV computer system;In response to receipt of the second attribute specification and the address, determining a first set (A1) of attributes specified in the second attribute specification, and initializing a mutual authentication of the AP computer system and the ID token using the address;After mutual authentication of the AP computer system and the ID token, establishment of a protected communication channel (SM [CA] # 3), writing of the first attribute set (A1) by the AP computer system over the protected communication channel to the protected memory area of ​​the ID tokens;and Sending an acknowledgment signal (S2, S3, ..., Sn) indicating whether the AP computer system was able to fully provide the first set of attributes and write to the protected memory of the ID token from the AP computer system to the APV computer system ,
  7. c-de-0016
    An APV computer system connected via a network to a user computer system, a first AP computer system and a second AP computer system, the user computer system being coupled via a reader to an ID token comprising a non-volatile electronic memory ( 118) having a protected memory area (124), wherein access to the protected memory area is only possible via a processor (128) of the ID token, the APV computer system is an attribute provider directory computer system and is configured for :- receiving a trigger signal (T1) from the user computer system, wherein the first trigger signal is free of a first attribute specification (105) and parts thereof and an address (# 106) of the ID token (106), the first attribute specification specifies user-related attributes that a service requested by a user of the user computer system requires to provide it;In response to receipt of the trigger signal, mutual authentication of the APV computer system (199) and the ID token using the address;After successful mutual authentication of the APV computer system and the ID token, reading the first attribute specification (AR) from the protected memory area of ​​the ID token and dividing the read first attribute specification into at least a second (AR1) and a third (AR2) attribute specification through the APV computer system;Sending the second attribute specification (AR1) and the address (# 106) from the APV computer system to a first AP computer system (172) configured to provide the attributes specified in the second attribute specification, wherein the first AP computer system includes first attribute provider computer system, and sending the third attribute specification (AR2) and the address (# 106) of the ID token from the APV computer system to the second AP computer system (173) adapted to be in the third Provide attribute specification specified attributes;In response to receipt of acknowledgment signals (S2, S3, ..., Sn) indicating that the first, second, and each further AP computer system that has received from the APV computer system a subset of the first attribute specification, the has been completely provided by this AP computer system to be determined attribute set and written in the protected memory of the ID token, sending a termination signal (SAPV) to the user computer system.