Invention Grant
- Patent Title: Method for reading an attribute from an ID token
-
Application No.: US14452633Application Date: 2014-08-06
-
Publication No.: US09130931B2Publication Date: 2015-09-08
- Inventor: Carsten Schwarz , Günter Koch
- Applicant: BUNDESDRUCKEREI GMBH
- Applicant Address: DE Berlin
- Assignee: BUNDESDRUCKEREI GmbH
- Current Assignee: BUNDESDRUCKEREI GmbH
- Current Assignee Address: DE Berlin
- Agency: Leveque IP Law, P.C.
- Priority: DE102010028133 20100422
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L29/06 ; G06F21/33 ; G06F21/34 ; G06F21/41

Abstract:
A method for reading at least one attribute stored in an ID token using first, second and third computer systems, wherein the third computer system comprises a browser and a client, and wherein a service certificate is assigned to the second computer system, wherein the service certificate comprises an identifier which is used to identify the second computer system, wherein the ID token is assigned to a user, a first cryptographically protected connection (TLS1) is set up between the browser of the third computer system and the second computer system, wherein the third computer system receives a first certificate, the first certificate is stored by the third computer system, the third computer system receives a signed attribute specification via the first connection, a second cryptographically protected connection (TLS2) is set up between the browser of the third computer system and the first computer system, wherein the third computer system receives a second certificate, the signed attribute specification is forwarded from the third computer system to the first computer system via the second connection, the first computer system accesses an authorization certificate, wherein the authorization certificate comprises the identifier, a third cryptographically protected connection (TLS3) is set up between the first computer system and the client of the third computer system, wherein the third computer system receives the authorization certificate containing the identifier via the third connection, the client of the third computer system checks whether the first certificate comprises the identifier as proof of the fact that the first certificate matches the service certificate, the user is authenticated with respect to the ID token, the first computer system is authenticated with respect to the ID token, a fourth cryptographically protected connection with end-to-end encryption is set up between the ID token and the first computer system, after the user and the first computer system have been successfully authenticated with respect to the ID token, the first computer system has read access to the at least one attribute stored in the ID token via the fourth connection in order to read the one or more attributes specified in the attribute specification from the ID token,—the first computer system transmits the at least one attribute to the second computer system after said attribute has been signed.
Public/Granted literature
- US20150026476A1 METHOD FOR READING AN ATTRIBUTE FROM AN ID TOKEN Public/Granted day:2015-01-22
Information query