Mobile Device Enrollment via Smart Card Credential Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of Personal Identity Verification (PIV) and Common Access Card (CAC) cards for secure authentication on mobile devices is challenging due to the lack of integrated smart card readers, leading to cumbersome user experiences and security risks in Bring Your Own Device (BYOD) environments, where enterprises face difficulties in managing and controlling remote access to resources.
Innovation Solution
A computer system comprising a smart card reader, a credential management system (CMS) server, and an enrollment server, which authenticates a smart card and generates secure credentials stored on the mobile device, enabling secure enrollment and access to enterprise resources without the need for frequent card insertion, using a one-time password (OTP) displayed on a connected display.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PIV or CAC cards are used for authentication on mobile devices, then security is improved through two-factor authentication, but device complexity increases due to the need for separate card readers
Solution Approach 1:
The patent introduces an intermediary enrollment server that facilitates credential extraction from the smart card without requiring the mobile device to have integrated card reading capabilities. The enrollment server acts as a mediator between the smart card and the mobile device, enabling secure credential transfer through a controlled enrollment process that resolves the contradiction between maintaining security and reducing device complexity
Solution Approach 2:
The authentication system is segmented into distinct components: the smart card reader (separate device), the enrollment server (intermediary system), and the mobile device (endpoint). This segmentation allows the mobile device to remain simple while security functions are distributed to specialized components, resolving the contradiction by separating authentication security requirements from device complexity
2Reliability
If users must insert their PIV or CAC card every time they need to access enterprise resources, then authentication security is maintained, but ease of operation deteriorates due to cumbersome user experience
Solution Approach 1:
The patent implements preliminary action by extracting and storing authentication credentials from the smart card during an initial enrollment process. Once enrolled, users can access enterprise resources without repeatedly inserting their physical cards, as the credentials are already provisioned on their mobile devices. This maintains security through cryptographic credentials while dramatically improving ease of operation
Solution Approach 2:
The system creates cryptographic copies of the authentication credentials from the smart card and stores them on the mobile device. These credential copies enable authentication without requiring the physical card to be present, resolving the contradiction between maintaining authentication security and improving user convenience
3Reliability
If enterprises implement strict password policies, then security is improved, but ease of operation deteriorates due to user resistance and password management issues
Solution Approach 1:
The patent extracts the password management burden from the user by using smart card-based authentication. Instead of requiring users to create, remember, and regularly change complex passwords, the system uses the smart card and PIN as the primary authentication mechanism. This maintains strong security while eliminating password management issues, resolving the contradiction between network security and ease of operation
4Ease of operation
If enterprises allow BYOD environments, then ease of operation is improved by allowing personal devices, but security deteriorates due to lack of control over employee-provided devices
Solution Approach 1:
The enrollment server acts as an intermediary that enables secure enrollment of personal devices without requiring the enterprise to have direct control over the device hardware. The server mediates the credential extraction and storage process, allowing employees to use their own devices while maintaining enterprise security controls through the enrollment mechanism, thus resolving the contradiction between device accessibility and security control
Data Source
AI summary
A computer system may include a smart card reader, a credential management system (CMS) server, an enrollment server connected with the CMS server on an internal LAN, and a mobile device associated with a user and configured to initiate enrollment with the enrollment server via an internal enrollment port inaccessible outside of the internal LAN. The CMS server may cooperate with the smart card reader to authenticate a smart card associated with the user, and generate a secure credential(s) that is stored on the mobile device based upon authentication of the smart card. The enrollment server may collect the secure credential(s) from the mobile device via the internal enrollment port, cooperate with the CMS server to verify the secure credential(s), and enroll the mobile device to access the enrollment server from outside of the internal LAN based upon verification of the secure credential(s).


