Derived Credential Certificate for Mobile CAC/PIV Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users with CAC/PIV cards face challenges accessing secure web resources on devices without CAC/PIV card readers, such as mobile devices, without requiring rooting or special configurations.

Innovation Solution

A system and method to generate and validate 'CAC/PIV-like' derived credentials, which allow mobile devices to access secure resources by receiving a CAC/PIV certificate, authenticating the user, issuing a passcode, generating a new key pair, and obtaining a signed derived credential certificate from a certificate authority for storage on the target device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CAC/PIV card authentication is required to access secure web resources, then security is improved, but device compatibility deteriorates because mobile devices without CAC/PIV card readers cannot access these resources

Engineering Contradiction:
ImprovesecurityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a derived credential certificate that copies the essential authentication functionality of the CAC/PIV certificate. This derived certificate contains a public key that can be validated by the same certificate chain, allowing mobile devices to present credentials that are functionally equivalent to CAC/PIV cards without requiring the physical card or specialized hardware readers.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary process where a trusted authority generates a derived credential certificate based on the original CAC/PIV certificate. This intermediary certificate acts as a bridge, allowing authentication on devices that cannot directly use CAC/PIV cards while maintaining the security model through certificate chain validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If derived credentials are generated to enable mobile device access, then device compatibility is improved, but system complexity increases due to additional certificate generation and validation steps

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The derived credential certificate is generated in advance through a trusted authority before the mobile device needs to access secure resources. This preliminary generation eliminates the need for complex real-time certificate creation on the mobile device, reducing system complexity while maintaining compatibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The derived credential certificate replicates the structure and validation requirements of standard X.509 certificates, allowing existing certificate validation infrastructure to be reused without significant modification. This copying approach minimizes the addition of complex validation logic while enabling mobile device access.

Inventive Principle:
Principle #26Copying

3Reliability

If CAC/PIV card readers are required for authentication, then authentication security is improved, but ease of operation deteriorates because users cannot access secure resources on mobile devices

Engineering Contradiction:
Improveauthentication securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The derived credential certificate provides a copy of the authentication capability that works with standard mobile device browsers and operating systems. Users can access secure resources on their mobile devices using the derived certificate without needing to physically insert a CAC/PIV card into a specialized reader, greatly improving ease of operation while maintaining security through certificate validation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical CAC/PIV card reader insertion process with a digital certificate-based authentication system that works through standard web browsers. This substitution eliminates the need for physical card readers and manual card insertion, allowing users to authenticate seamlessly on mobile devices while maintaining the security model.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9992189B2Generation and validation of derived credentials
Publication Date: 2018.06.05 SECUREAUTH CORP
  • US9992189B2 patent drawing
  • US9992189B2 patent drawing
  • US9992189B2 patent drawing

AI summary

A CAC/PIV certificate associated with a HSPD-12 identity is used to generate a derived credential for storage on a device, such as a mobile device, that lacks a CAC/PIV card reader. The derived credential (which is distinct from the original CAC/PIV certificate) may then be used to grant the device access to secure resources that may otherwise require a CAC/PIV certificate. Embodiments of the present disclosure also relate to systems and methods for authenticating or validating a derived credential stored on a mobile device.