Derived Credential Certificate for Mobile CAC/PIV Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users with CAC/PIV cards face challenges accessing secure web resources on devices without CAC/PIV card readers, such as mobile devices, without requiring rooting or special configurations.
Innovation Solution
A system and method to generate and validate 'CAC/PIV-like' derived credentials, which allow mobile devices to access secure resources by receiving a CAC/PIV certificate, authenticating the user, issuing a passcode, generating a new key pair, and obtaining a signed derived credential certificate from a certificate authority for storage on the target device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If CAC/PIV card authentication is required to access secure web resources, then security is improved, but device compatibility deteriorates because mobile devices without CAC/PIV card readers cannot access these resources
Solution Approach 1:
The patent creates a derived credential certificate that copies the essential authentication functionality of the CAC/PIV certificate. This derived certificate contains a public key that can be validated by the same certificate chain, allowing mobile devices to present credentials that are functionally equivalent to CAC/PIV cards without requiring the physical card or specialized hardware readers.
Solution Approach 2:
The patent introduces an intermediary process where a trusted authority generates a derived credential certificate based on the original CAC/PIV certificate. This intermediary certificate acts as a bridge, allowing authentication on devices that cannot directly use CAC/PIV cards while maintaining the security model through certificate chain validation.
2Adaptability or versatility
If derived credentials are generated to enable mobile device access, then device compatibility is improved, but system complexity increases due to additional certificate generation and validation steps
Solution Approach 1:
The derived credential certificate is generated in advance through a trusted authority before the mobile device needs to access secure resources. This preliminary generation eliminates the need for complex real-time certificate creation on the mobile device, reducing system complexity while maintaining compatibility.
Solution Approach 2:
The derived credential certificate replicates the structure and validation requirements of standard X.509 certificates, allowing existing certificate validation infrastructure to be reused without significant modification. This copying approach minimizes the addition of complex validation logic while enabling mobile device access.
3Reliability
If CAC/PIV card readers are required for authentication, then authentication security is improved, but ease of operation deteriorates because users cannot access secure resources on mobile devices
Solution Approach 1:
The derived credential certificate provides a copy of the authentication capability that works with standard mobile device browsers and operating systems. Users can access secure resources on their mobile devices using the derived certificate without needing to physically insert a CAC/PIV card into a specialized reader, greatly improving ease of operation while maintaining security through certificate validation.
Solution Approach 2:
The patent replaces the mechanical CAC/PIV card reader insertion process with a digital certificate-based authentication system that works through standard web browsers. This substitution eliminates the need for physical card readers and manual card insertion, allowing users to authenticate seamlessly on mobile devices while maintaining the security model.
Data Source
AI summary
A CAC/PIV certificate associated with a HSPD-12 identity is used to generate a derived credential for storage on a device, such as a mobile device, that lacks a CAC/PIV card reader. The derived credential (which is distinct from the original CAC/PIV certificate) may then be used to grant the device access to secure resources that may otherwise require a CAC/PIV certificate. Embodiments of the present disclosure also relate to systems and methods for authenticating or validating a derived credential stored on a mobile device.


