Reader device and method of configuring the same
By simulating virtual tokens in the reader device, the problem of reader device configuration management in the prior art is solved, realizing remote configuration without user interaction and non-standard settings, and supporting secure centralized management and configuration.
Patent Information
- Application Number
- CN202180019615.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-12-29
- Filing Date
- 2021-12-22
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2041-12-22
AI Technical Summary
In existing systems, the configuration and management of reader devices are difficult to perform without a physical token connection, especially in networked systems with multiple reader devices and a central management device, which require user interaction or non-standard settings, making remote or centralized management difficult.
By simulating a virtual token in the reader device and communicating with the management device using standard communication protocols, remote configuration management of the reader can be achieved. This includes simulating a virtual token and sending a corresponding message when the physical token is detected to be missing, and modifying the configuration data in the memory.
It enables remote configuration and management of reader devices without user interaction or non-standard settings, supports secure centralized management and configuration, and is suitable for unified management of multiple reader devices.
Smart Images

Figure CN115280310B_ABST
Abstract
Description
[0001] Priority application
[0002] This application claims priority to European Patent Application Serial No. 20217596.4, filed on December 29, 2020, the disclosure of which is incorporated herein by reference in its entirety. Technical Field
[0003] This disclosure generally relates to reader devices for reading and writing data stored on tokens (e.g., smart cards), and particularly to methods for configuring such reader devices. Background Technology
[0004] Typically, readers such as smart card readers are used in a variety of applications. For example, such readers can be used to read data from security tokens to allow access to resources such as physical facilities, computers, or networks. Other known applications include online banking applications and use as credit card terminals. As a concrete example, HID Global's... A reader is used in desktop applications, mobile computers, and multifunction devices such as printers. Such a reader can be configured as an easy-to-install USB device suitable for all contact or contactless smart card operations, such as access to resources, online banking, or digital signature applications as described above.
[0005] The aforementioned reader can be a standalone device or integrated into, for example, a desktop computer. Furthermore, such readers typically support all major operating systems and allow for high-speed data transfer between the reader and the host device connected to it.
[0006] In some applications, multiple readers can be set up in different locations, such as within an organization or building, and can be connected to a central management device that manages different aspects of the multiple readers.
[0007] US 7,971,238 B2 discloses an information processing system including a processor, system memory, and a remote access resource, the remote access resource including a virtual card reader capable of establishing a communication channel between the remote access resource and the remote card reader to transmit smart card reader access requests and responses between them.
[0008] This disclosure relates, at least in part, to one or more aspects of improving or overcoming existing systems. Summary of the Invention
[0009] According to one aspect of this disclosure, a reader device includes a memory storing configuration data configuring the reader device. The reader device further includes: a first interface configured to connect the reader device to a host device; a second interface configured to connect a physical token to the reader device; and a controller configured to access the memory to read data from and write data to the memory, communicate with the host device via the first interface, and communicate with the physical token via the second interface. Additionally, the controller is configured to, in response to detecting that no physical token is connected to the reader device, simulate a virtual token and send a first message indicating that the virtual token is connected to the reader device to the host device. In response to receiving at least one command from the host device addressing the virtual token, the controller is further configured to modify the configuration data stored in the memory according to the at least one command.
[0010] In another aspect, this disclosure relates to a system for managing multiple reader devices. The system includes a central management device, multiple host devices, and multiple reader devices according to the foregoing aspects, each of which is connected to the multiple host devices. The management device is configured to receive a first message from an associated host device indicating that a virtual token has been connected, and to send at least one command to the associated host device to configure the reader device connected to the associated host device.
[0011] In another aspect, this disclosure relates to a method for configuring a reader device, the reader device comprising: a memory storing configuration data; a first interface configured to connect the reader device to a host device; a second interface configured to connect a physical token to the reader device; and a controller configured to communicate with the host device via the first interface and to access the memory to read data from and write data to the memory. The method includes, in response to detecting that no physical token is connected to the reader device, simulating a virtual token and sending a first message indicating that the virtual token is connected to the reader device to the host device. Furthermore, the method includes receiving at least one command from the host device addressing the virtual token, and modifying the configuration data stored in the memory according to the at least one command.
[0012] In another aspect, this disclosure relates to a computer program including computer-executable instructions that, when executed by a controller of a reader device, cause the controller to perform the following steps: in response to detecting that no physical token is connected to the reader device, simulating a virtual token and sending a first message indicating that the virtual token is connected to the reader device to a host device connected to the reader device; and in response to receiving at least one command from the host device addressing the virtual token, modifying configuration data stored in the memory of the reader device according to the at least one command.
[0013] In another aspect, this disclosure relates to a computer program product that stores computer programs for the above-mentioned aspects.
[0014] Other features and aspects of this disclosure will become apparent from the following description and accompanying drawings. Attached Figure Description
[0015] Figure 1 The reader device is shown when a physical token is connected to a reader device according to this disclosure;
[0016] Figure 2 This shows what happens when the virtual token is emulated by a reader device. Figure 1 Reader devices; and
[0017] Figure 3 A system for managing multiple reader devices according to this disclosure is shown. Detailed Implementation
[0018] The following is a detailed description of exemplary embodiments of this disclosure. The exemplary embodiments described herein are intended to teach the principles of this disclosure, enabling those skilled in the art to implement and use this disclosure in many different environments and for many different applications. Therefore, the exemplary embodiments are not intended and should not be considered as a limiting description of the scope of protection. Rather, the scope of protection should be defined by the appended claims.
[0019] This disclosure is based, at least in part, on the understanding that in many currently used systems, such as networked systems including multiple reader devices connected to a central management device, reader configuration management needs to support different non-standard settings in the operating system, or even require user interaction to connect to the reader. This can hinder remote or centralized management of smart card readers as a whole. For example, when a reader device is connected to a host device that includes an operating system (which may also be a local management device), a management application may attempt to access the reader device using special commands that do not correspond to standard settings for the protocol used to communicate with a token (e.g., a smart card) connected to the reader. In particular, access of any kind can be simply denied when no token is connected to the reader. Therefore, it may be necessary to first connect a token to the reader in order to configure the reader. Additionally, it may be necessary to change standard settings (e.g., operating system and / or reader settings) to be able to send appropriate configuration commands that cause the reader to update its configuration.
[0020] Furthermore, especially when a central management device manages multiple readers connected to different host devices, the remote connection between the central management device and each host device must support any special commands necessary for remotely configuring each reader. However, this is not guaranteed in many applications, even when using a local management device. Therefore, in known systems, management, particularly the configuration of reader devices, may be impossible.
[0021] As disclosed herein, it has been recognized that the aforementioned drawbacks can be overcome by configuring readers to emulate tokens (virtual tokens). Specifically, this emulation can occur when a physical token is not present at the reader. Based on such emulated tokens, all token-specific security mechanisms can be used, and secure (remote) configuration management of the reader is permitted. No user interaction is required, and centralized configuration can be performed without any special settings for the token subsystem, or even at the operating system level of the host device to which the reader is connected.
[0022] When a reader emulates such a virtual token (e.g., a virtual smart card), this virtual token can be addressed using standard commands and methods typically used to communicate with such tokens. For example, this allows a central management device to communicate with each reader using the PC / SC standard without requiring any special configuration or setup. In other words, the (central) management device communicates with the reader in the same way it communicates with physical smart cards. Therefore, any security mechanisms introduced for, for example, smart cards (e.g., secure communication, man-in-the-middle attack detection, etc.) can be used to access the reader configuration as part of any card command or memory structure.
[0023] Furthermore, it has been recognized that the emulated card can also present reader-specific information, such as the reader's firmware version or reader serial number, to the central management device to facilitate configuration or management processes. This can be done in addition to presenting standard required values (such as ATR responses). In this way, management applications on the management device can also distinguish between physical and virtual tokens and appropriately address virtual tokens to configure readers emulating said virtual tokens. In some implementations, the local or central management device can request reader-specific information by sending appropriate commands to the reader, and the reader's controller can then be configured to read configuration data or other data including reader-specific information based on the request and forward it to the management device.
[0024] It is also recognized that the reader enters token emulation mode whenever a physical token is absent (e.g., when it is detected that a physical token has been removed). In this way, the reader can be remotely configured whenever it is not currently in use. In this regard, it is also recognized that signaling to the management device that a physical token has been presented to the reader and terminating the emulation of the virtual token is also advantageous. In this way, the administrator can identify when the reader's configuration is currently unavailable.
[0025] Furthermore, it has been recognized that the following would be advantageous when the emulation of the virtual token can be turned on and off by the client or the installed device. In this way, clients or installed devices that do not require or do not wish to use the methods described herein can prevent remote configuration of the corresponding reader.
[0026] Figure 1 An example of a reader device 10 according to this disclosure is shown. Figure 1 As shown, the reader device 10 includes a memory 14 that stores configuration data for configuring the reader device 10. It should be understood that the memory 14 can be any type of known non-volatile memory (ROM, EEPROM, flash memory, etc.) that can store data permanently (i.e., regardless of whether the reader device 10 is connected to a power source), or a volatile memory that stores data as long as the reader device 10 is connected to a power source. Those skilled in the art will readily recognize that, depending on the application for which the reader device 10 is used (e.g., for identification purposes, online banking, etc.), the configuration data stored in the memory 14 may include, for example, firmware controlling the operation of the reader device 10, various settings for the operation of the reader device 10, security data such as encryption keys, PIN numbers, user IDs, compatibility settings for connecting the reader device 10 to different operating systems and / or different devices, etc.
[0027] Similarly, Figure 1As shown, the reader device 10 also includes a first interface 16 configured to connect the reader device 10 to the host device 12. For example, the first interface 16 may be a USB interface, which includes a USB connector configured to connect to a USB port on the host device 12. As previously mentioned, the host device 12 may be, for example, a desktop computer or a mobile computer such as a laptop computer. It should be understood that the host device 12 typically includes an operating system that controls the operation of the host device 12 and also facilitates communication between the host device 12 and the reader device 10 via the first interface 16. In some applications, the host device 12 may be a computer including an operating system that supports the CCID standard and may use a corresponding CCID driver to connect to the reader device 10, for example, via a USB connection. However, it should be understood that such a USB connection is merely an example and does not limit the first interface 16 to a USB interface. For example, the reader device 10 may also be integrated with the host device 12 and connected to the host device 12 via internal circuitry. Furthermore, in some applications, there may be no wired connection between the reader device 10 and the host device 12, and instead, a wireless interface may form the first interface 16.
[0028] The reader device 10 also includes a controller 22 configured to communicate with the host device 12 via a first interface 16. The controller can be any type of processor or hardware configured to execute instructions, access memory 14, etc., such as a microcontroller. Furthermore, the controller 22 can be operatively coupled to the first interface 16 to send messages to and receive messages (including one or more commands) from the reader device 12. In some embodiments, a dedicated communication unit can be connected to the first interface 16 and forward messages between the first interface 16 and the controller 22. In other embodiments, such a communication unit or circuitry can be integrated with the controller 22.
[0029] Additionally, reader device 10 includes a second interface 18 configured to connect a physical token 20 (e.g., a contact smart card) to reader device 10. Controller 22 is configured to communicate with the physical token 20 via the second interface 18. For example, reader device 10 may be a smart card reader for use with any compatible contact smart card. Thus, reader device 10 may include a receptacle for the physical token 20 (e.g., a smart card) and may be electrically connected to the physical token 20 via the second interface 18 in a known manner. Furthermore, it is noted in this respect that in other applications, the second interface 18 may be a contactless interface, and the physical token 20 may be, for example, an RFID smart card, which is wirelessly connected to reader device 10 in a known manner.
[0030] Controller 22 is configured to enable communication between physical token 20 and host device 12, such as by receiving data from physical token 20 and forwarding it to host device 12, and by receiving commands from host device 12, according to communication protocols such as the PC / SC standard. These commands may be, for example, read / write commands forwarded from reader device 10 to physical token 20. Details of such operation are known to those skilled in the art and will not be described herein.
[0031] like Figure 1 As shown, management device 30, such as a central management device, can be connected to host device 12 and can be used to configure reader device 10 in a manner that will be described in more detail below. Here, it is readily understood that management device 30 can be any suitable computer system or server connected to host device 12 wirelessly and / or via wired means, such as via the Internet.
[0032] As previously mentioned, host device 12 may be a computer running a general-purpose, multi-program operating system, such as... or MacOS Furthermore, it should be understood that although the reader device 10 is called a reader device, it is not only able to read data from, for example, the physical token 20, but also able to write data to it.
[0033] In some cases, it may be necessary or desirable to update the configuration of reader device 10, particularly the configuration data stored in memory 14. To do this, an administrator can launch the appropriate management application on management device 30 (or, in the case of purely local configuration, host device 12) and forward the corresponding configuration commands to reader device 10 via host device 12. However, depending on the application, it may be necessary to use non-standard settings for communicating with reader device 10 and / or physical token 20 to forward configuration commands. In one example, when using the known PC / SC standard, a special set of PC / SC commands must be used to directly address reader device 10 instead of addressing physical token 20. However, configuration of reader device 10 is impossible if no physical token 20 is connected to reader device 10, and / or the connection between management device 30 and host device 12 (and / or the connection between host device 12 and reader device 10) does not support such non-standard settings. Therefore, the administrator will need to access local host device 12 to change operating system settings to perform configuration, or must insert a physical smart card, etc., into reader device 10.
[0034] To overcome this drawback, according to this disclosure, controller 22 is configured to simulate virtual token 26 and, upon detecting that no physical token 20 is connected to reader device 10, send a first message instructing virtual token 26 to connect to reader device 10. For example, controller 22 or a dedicated detection unit connected to it can be configured to detect that physical token 20 has been removed (in the case of a physical connection) and / or disconnected from reader device 10. It is readily understood that various possibilities exist for detecting a disconnection of physical token 20 (mechanical switch, timeout response of wirelessly connected token 20, specific messages received from token 20, etc.). In any case, after detecting that no physical token is connected to reader device 10, controller 22 begins simulating virtual token 26. This... Figure 2 As shown in the image.
[0035] exist Figure 2 In the example shown, controller 22 emulates virtual token 26 by sending a first message instructing reader device 10 to connect virtual token 26 to host device 12. In this way, reader device 10 "mimics" the token. Therefore, virtual token 26 is perceived as being connected to host device 12 via reader device 10, and information about the connection of virtual token 26 can be forwarded from host device 12 to management device 30. Thus, at management device 30, it appears that virtual token 26 has been connected to host device 12.
[0036] The management device 30 can now send one or more configuration commands for the reader device 10 as commands addressing at least one virtual token 26. Optionally, the management device can, for example, send an initial command requesting reader information (e.g., specifying the current configuration of the reader device 10). Based on this, another command for updating the configuration can then be sent to the reader device 10. The at least one command is forwarded to the reader device 10 by the host device 12 via the first interface 16. In response to receiving the at least one command, the controller 22 of the reader device 10 can then read or modify the configuration data stored in the memory 14 according to the at least one command. For example, the at least one command can address the virtual memory 28 of the virtual token 26, which may include at least a portion of the memory 14 storing the configuration data. In this way, standard commands typically used to write data to the physical token 20 can be replaced with commands to write data to the virtual memory 28 of the virtual token 26, which corresponds to a portion (or, in some embodiments, all) of the memory 14 storing the configuration data.
[0037] To facilitate the configuration of reader device 10, a first message instructing virtual token 26 to connect to reader device 10 may include reader information indicating at least one attribute of reader device 10, such as the serial number of the reader device, the firmware version of the firmware installed on the reader device, etc. Additionally, the first message may include information related to the memory structure of the reader device 10's memory 14 (and / or virtual memory 28), and the management device 30 may use this information to appropriately address the virtual memory 28 of virtual token 26. For example, the first message may include information specifying the memory address or memory region where configuration data (e.g., an updated encryption key, a new firmware revision, etc.) will be written. In some embodiments, the first message may be sent by reader device 10 upon receiving a corresponding request from host device 12.
[0038] It should be understood that the term "simulation" as used herein should be interpreted broadly. In the example above, it refers to the reader device 10 (its controller 22) identifying itself as a token to the host device 12 and the management device 30. In this case, it may be necessary to include information specifying the token type in the first message forwarded to the management device 30, that is, notifying the management device 30 that a virtual token 26, which allows the reader device 10 to be connected according to the above configuration, is not connected, rather than the physical token 20, which is typically not addressed in the same way as the virtual token 26. However, the controller 22 can also simulate the virtual token 26 by substantially simulating the token connected to the reader device 10, even though there is no physical token 20 connected. For example, the controller 22 can perform a mapping between the virtual memory 28 of such virtual token 26 and the portion of memory 14 storing the configuration settings. The management device 30 can then forward the appropriate write command for writing data to the virtual memory 28 of the virtual token 26, and the data is then written to the appropriate portion of memory 14 using the mapping.
[0039] Advantageously, controller 22 is also configured to send a second message to host device 12 in response to detecting that physical token 20 is connected to reader device 10 while simulating virtual token 26, indicating that virtual token 26 is no longer connected to reader device 10. This message can then be forwarded to management device 30, and the administrator will be informed that reader device 10 cannot be configured at this time. In this situation, the administrator can initiate appropriate measures to allow configuration of reader device 10 if necessary (e.g., notifying field operators or users that physical token 20 should be removed), or plan to update reader device 10 at a later time if the update is not absolutely necessary.
[0040] In some applications, end users or organizations may also wish to selectively activate or deactivate the possibility of remote configuration of reader device 10. For example, suitable inputs or interfaces may be provided that allow selective activation or deactivation based on user selection. This could be, for example, a physical button, or a software configuration setting on host device 12 to deactivate the emulation of virtual token 26 by reader device 10. In some embodiments, configuration data stored in memory 14 may include data indicating such user selections. It should be understood that if emulation has been deactivated and the corresponding configuration data is stored in memory 14, local reconfiguration will be necessary to reactivate the possibility of emulation and remote configuration.
[0041] As described above, in some applications, such as smart card applications, controller 22 can be configured to receive a first set of commands according to a first standard (e.g., PC / SC) via first interface 16, and forward the first set of commands to physical token 20 when physical token 20 is connected via second interface 18. At least one command sent to the virtual token can conform to the first standard and can be executed by controller 22 simulating virtual token 26. In other words, standard commands for addressing smart cards can be modified to address reader device 10 and can be executed by controller 22 instead of continuing to be passed to the physical smart card connected to reader device 10. In this example, controller 22 can also be configured to receive a second set of commands other than the first standard via first interface 16, and execute the second set of commands to modify configuration data stored in memory 14 when physical token 20 is connected via second interface 18. For example, the second set of commands can correspond to extended commands of the PC / SC standard that can be used to directly address reader device 10.
[0042] As previously stated, the reader device 10 described above according to this disclosure can be advantageously used in conjunction with centralized management of multiple reader devices using a central management device 30, such as... Figure 3 As shown.
[0043] Figure 3 An exemplary system 100 for managing multiple reader devices 10 is shown. The system includes a central management device 30, multiple host devices 12, and multiple reader devices 10 according to this disclosure, each connected to one of the host devices 12. As previously described, the management device 30 is configured to receive a first message from an associated host device indicating that a virtual token 26 has been connected, and to send at least one command for configuring the reader devices 10 to the associated host devices.
[0044] like Figure 3As shown, system 100 may further include a management application 32 running on management device 30. Management application 32 may be configured to identify the virtual token 26 and the memory structure of the memory 14 of the reader device 10 simulating the virtual token 26 based on a first message received from the corresponding host device 12 when the virtual token 26 is spoofed. Based on this, management application 32 may generate at least one command for configuring reader device 10 according to the identified memory structure. Alternatively, management application 32 may use reader information included in the first message to identify the memory structure of memory 14 and generate appropriate commands.
[0045] In some implementations, the management device 30 may also be configured to receive a third message instructing the physical token 20 to connect to the associated host device 12, such as... Figure 3 As shown. In response, management device 30 can send a fourth message to the associated host device 12, causing the host device to display a user prompt requesting the user to remove the physical token. For example, the prompt can be displayed on the monitor of host device 12. In this case, when the user recognizes the user prompt and removes the physical token 20, reader device 12 can restart from emulating the virtual token 26, thereby allowing remote configuration of reader device 12.
[0046] Industrial applicability
[0047] By utilizing the aforementioned reader devices and systems for managing multiple such reader devices, efficient and reliable, especially remote, management of reader devices becomes possible.
[0048] An exemplary method for configuring a reader device according to this disclosure will now be described. In a first step, it is detected (e.g., by controller 22) that no physical token 20 is connected to reader device 10. In response, a virtual token 26 is simulated, and a first message indicating that the virtual token 26 is connected to reader device 10 is sent to host device 12. Here, it should be understood that the steps of detecting the lack of a physical token connection, simulating a virtual token, and sending the first message are performed by reader device 10, and in particular by controller 22 of reader device 10.
[0049] In a subsequent step, reader device 10 also receives at least one command addressing virtual token 26 from host device 12. The at least one command is generated, for example, by central management device 30 in the manner described above. Furthermore, the method includes modifying configuration data stored in memory 14 of reader device 10 according to the at least one command. As described above, the modification step is performed by controller 22 of reader device 10 by writing the configuration data to memory 14 in an appropriate manner.
[0050] Although the steps described above are performed by reader device 10, it will be readily understood that any number of additional steps may be performed by host device 12 and management device 30 where appropriate or necessary. For example, it will be readily understood that the method includes forwarding a first message received from reader device 10 to management device 30 via host device 12. Similarly, the method includes the step of generating at least one command by management device 30, particularly management application 32 running on management device 30. This may be done based on reader information received from reader device 10 along with the first message. The generated at least one command will then be forwarded from management device 30 to reader device 10 via host device 12 to the reader device 10 simulating virtual token 26. Of course, it will be readily understood that any number of additional steps may be included based on other aspects of the reader device and system according to this disclosure described above.
[0051] It should also be understood that a computer program including computer-executable instructions is also an advantageous implementation of this disclosure, which, when executed by the controller of the reader device 10, causes the controller to perform at least some of the steps in the methods described above. For example, such a computer program can be configured as a firmware update for an existing reader device 10. In other words, an administrator can, for example, use a firmware update locally to perform the first update of the configuration of the reader device 10, thereby allowing the updated reader device 10 to perform the above-described simulation. Subsequently, any updated reader device can be configured remotely. In this regard, it should also be understood that a computer program product storing the computer program can be distributed to the owner or operator of the existing system to allow the above-described updates and / or configurations.
[0052] It should be understood that the foregoing description provides examples of the disclosed systems and methods. However, it is contemplated that other implementations of this disclosure may differ in detail from the foregoing examples. All references to this disclosure or its examples are intended to refer to the specific example being discussed at the time and are not intended to imply any limitation on the disclosure in general.
[0053] Unless otherwise stated herein, the numerical ranges listed herein are intended only as shorthand for each individual value falling within that range, and each individual value is incorporated into the specification as if it were listed separately herein. Unless otherwise stated or clearly contradicted by the context, all methodological steps described herein may be performed in any suitable order.
[0054] While preferred embodiments of the present disclosure have been described herein, improvements and modifications may be incorporated without departing from the scope of the appended claims.
Claims
1. A reader device (10) comprising: a memory (14) storing configuration data configuring the reader device (10); a first interface (16) configured to connect the reader device (10) to a host device (12); a second interface (18) configured to connect a physical token (20) to the reader device (10); and a controller (22) configured to: - access the memory (14) to read the configuration data from and write the configuration data to the memory (14); - communicate with the host device (12) via the first interface (16); - communicate with the physical token (20) via the second interface (18); - in response to detecting that no physical token (20) is connected to the reader device (10), emulate a virtual token (26) and send a first message to the host device, the first message indicating that the virtual token (26) is connected to the reader device (10); and - in response to receiving at least one command from the host device addressed to the virtual token (26), modify the configuration data stored in the memory (14) according to the at least one command. The first message comprises reader information indicating at least one property of the reader device (10).
2. The reader device of claim 1, wherein, The at least one property of the reader device comprises at least one of a serial number of the reader device or a firmware version of a firmware installed on the reader device.
3. The reader device of claim 2, wherein, The controller (22) is configured to send a second message to the host device indicating that the virtual token (26) is no longer connected to the reader device (10) in response to detecting that a physical token (20) is connected to the reader device (10) while emulating the virtual token (26).
4. The reader device of claim 1, wherein, 5. The reader device of claim 1, further comprising means for selectively activating or deactivating the emulation of the virtual token (26) based on a user selection. The configuration data stored in the memory (14) comprises data indicating the user selection.
6. The reader device of claim 5, wherein, The virtual token (26) comprises a virtual memory (28) comprising at least a portion of the memory (14) storing the configuration data, the virtual memory (28) being addressed by the at least one command received from the host device (12).
7. The reader device of claim 1, wherein, The controller (22) is configured to receive a first set of commands via the first interface (16) according to a first standard and to forward the first set of commands to the physical token (20) when the physical token (20) is connected via the second interface (18), and wherein the at least one command complies with the first standard and is executed by the controller (22).
8. The reader device of claim 1, wherein, 9. The reader device of claim 8, wherein, The controller (22) is configured to receive, via the first interface (16), a second set of commands outside the first standard and, when the physical token (20) is connected via the second interface (18), to execute the second set of commands to modify the configuration data stored in the memory (14).
10. A system (100) for managing a plurality of reader devices (10), the system comprising: a central management device (30); a plurality of host devices (12); and a plurality of reader devices (10) according to any one of claims 1 to 8, respectively connected to the plurality of host devices (12); wherein the central management device (30) is configured to receive, from an associated host device, a first message indicating that the virtual token (26) is connected to a respective reader device connected to the associated host device, and to send at least one command to the associated host device (12) to configure the respective reader device (10).
11. The system of claim 10, wherein, The central management device (30) is further configured to receive a third message indicating that the physical token (20) is connected to the respective reader device, and to send a fourth message to the associated host device (12) causing the associated host device to display a user prompt requesting a user to remove the physical token (20).
12. The system of claim 10, wherein the plurality of host devices (12) are configured as a plurality of desktop computers or laptop computers.
13. The system of claim 12, wherein, the plurality of desktop computers or laptop computers comprise a plurality of different operating systems.
14. The system of claim 10, wherein, the plurality of reader devices are configured as a plurality of contact or contactless smart card readers.
15. The system of claim 12, wherein, the plurality of reader devices are configured as a plurality of contact or contactless smart card readers.
16. The system of claim 10, further comprising a management application (32) running on the central management device (30), the management application being configured to identify, based on the first message, a memory structure of a memory (14) of the respective reader device (10) emulating the virtual token (26), and to generate the at least one command according to the identified memory structure.
17. A method of configuring a reader device (10), the reader device comprising: a memory (14) storing configuration data; a first interface (16) configured to connect the reader device (10) to a host device (12); a second interface (18) configured to connect a physical token (20) to the reader device (10); and a controller (22) configured to communicate with the host device (12) via the first interface (16) and to access the memory (14) to read and write the configuration data, the method comprising: - in response to detecting that no physical token (20) is connected to the reader device (10), simulating a virtual token (26) and sending a first message to the host device, the first message indicating that the virtual token (26) is connected to the reader device (10); - receiving at least one command from the host device, the at least one command being addressed to the virtual token (26); and - modifying the configuration data stored in the memory (14) according to the at least one command.
18. A computer program product comprising computer executable instructions that, when executed by a controller (22) of a reader device (10), cause the controller to perform the following steps: in response to detecting that no physical token (20) is connected to the reader device (10), simulating a virtual token (26) and sending a first message to a host device connected to the reader device (10), the first message indicating that the virtual token (26) is connected to the reader device (10); and in response to receiving at least one command from the host device, the at least one command being addressed to the virtual token (26), modifying configuration data stored in a memory (14) of the reader device (10) according to the at least one command.
Citation Information
Patent Citations
Two-factor authentication of a remote administrator
US7971238B2
A smart card reader with a secure logging feature
CN104040555A
Mobile communication device and cloud computer system
CN106372898A