Browser Extension for Smart Card Security via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart cards are vulnerable to security threats such as phishing, DNS cache poisoning, Man-in-the-Middle attacks, and keystroke logging when accessed via the internet, due to inadequate security measures in existing systems, which can lead to unauthorized access and data breaches.

Innovation Solution

A web-browser extension provides a secure interface between web applications and smart cards, ensuring only authorized access by validating SSL certificates and using connection keys to authenticate and authorize web applications, thereby preventing malicious interactions and ensuring secure communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a smart card access browser extension is used to enable web applications to access smart cards over the Internet, then accessibility and convenience are improved, but security vulnerabilities increase due to exposure to phishing, DNS cache poisoning, Man-in-the-Middle attacks, and malicious websites

Engineering Contradiction:
Improveaccessibility of smart card via web browserVSAvoidsecurity threats from phishing, DNS cache poisoning, MITM attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a server as an intermediary between the web application and the smart card. The server validates the web application's authorization credentials and establishes a secure communication channel, mediating the interaction to prevent direct exposure to security threats. This intermediary architecture allows web applications to access smart cards conveniently while protecting against phishing, DNS cache poisoning, and Man-in-the-Middle attacks by controlling and monitoring all communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SSL certificate validation and connection keys are implemented to authenticate web applications, then security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity of smart card accessVSAvoidcomplexity of authentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by requiring web applications to obtain authorization credentials from the server before accessing the smart card. The server pre-validates the web application's identity and permissions, and this authorization information is carried throughout the interaction. This preliminary authentication step simplifies the overall security model by establishing trust upfront, rather than requiring complex continuous verification mechanisms during smart card operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8713644B2System and method for providing security in browser-based access to smart cards
Publication Date: 2014.04.29 THALES DIS FRANCE SA
  • US8713644B2 patent drawing
  • US8713644B2 patent drawing
  • US8713644B2 patent drawing

AI summary

A method of operating a host computer having a web-browser with the capability of executing at least one web-browser add-on to provide a web application access to a smart card to protect the smart card from security threats associated with being connected to the Internet. Prior to establishing a connection between a web application executing in the web browser, verifying that the web application has been authorized to connect to a smart care using the web-browser add-on to provide a web application access to a smart card.