Mobile Device Enrollment via Smart Card Credential Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of Personal Identity Verification (PIV) and Common Access Card (CAC) cards for secure authentication on mobile devices is challenging due to the lack of integrated smart card readers, leading to cumbersome user experiences and security risks in Bring Your Own Device (BYOD) environments, where enterprises face difficulties in managing and controlling remote access to resources.

Innovation Solution

A computer system comprising a smart card reader, a credential management system (CMS) server, and an enrollment server, which authenticates a smart card and generates secure credentials stored on the mobile device, enabling secure enrollment and access to enterprise resources without the need for frequent card insertion, using a one-time password (OTP) displayed on a connected display.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PIV or CAC cards are used for authentication on mobile devices, then security is improved through two-factor authentication, but device complexity increases due to the need for separate card readers

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary enrollment server that facilitates credential extraction from the smart card without requiring the mobile device to have integrated card reading capabilities. The enrollment server acts as a mediator between the smart card and the mobile device, enabling secure credential transfer through a controlled enrollment process that resolves the contradiction between maintaining security and reducing device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct components: the smart card reader (separate device), the enrollment server (intermediary system), and the mobile device (endpoint). This segmentation allows the mobile device to remain simple while security functions are distributed to specialized components, resolving the contradiction by separating authentication security requirements from device complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If users must insert their PIV or CAC card every time they need to access enterprise resources, then authentication security is maintained, but ease of operation deteriorates due to cumbersome user experience

Engineering Contradiction:
Improveauthentication securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by extracting and storing authentication credentials from the smart card during an initial enrollment process. Once enrolled, users can access enterprise resources without repeatedly inserting their physical cards, as the credentials are already provisioned on their mobile devices. This maintains security through cryptographic credentials while dramatically improving ease of operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates cryptographic copies of the authentication credentials from the smart card and stores them on the mobile device. These credential copies enable authentication without requiring the physical card to be present, resolving the contradiction between maintaining authentication security and improving user convenience

Inventive Principle:
Principle #26Copying

3Reliability

If enterprises implement strict password policies, then security is improved, but ease of operation deteriorates due to user resistance and password management issues

Engineering Contradiction:
Improvenetwork securityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the password management burden from the user by using smart card-based authentication. Instead of requiring users to create, remember, and regularly change complex passwords, the system uses the smart card and PIN as the primary authentication mechanism. This maintains strong security while eliminating password management issues, resolving the contradiction between network security and ease of operation

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If enterprises allow BYOD environments, then ease of operation is improved by allowing personal devices, but security deteriorates due to lack of control over employee-provided devices

Engineering Contradiction:
Improvedevice accessibilityVSAvoidenterprise security control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The enrollment server acts as an intermediary that enables secure enrollment of personal devices without requiring the enterprise to have direct control over the device hardware. The server mediates the credential extraction and storage process, allowing employees to use their own devices while maintaining enterprise security controls through the enrollment mechanism, thus resolving the contradiction between device accessibility and security control

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10397778B2Computer network providing secure mobile device enrollment features and related methods
Publication Date: 2019.08.27 CITRIX SYSTEMS INC
  • US10397778B2 patent drawing
  • US10397778B2 patent drawing
  • US10397778B2 patent drawing

AI summary

A computer system may include a smart card reader, a credential management system (CMS) server, an enrollment server connected with the CMS server on an internal LAN, and a mobile device associated with a user and configured to initiate enrollment with the enrollment server via an internal enrollment port inaccessible outside of the internal LAN. The CMS server may cooperate with the smart card reader to authenticate a smart card associated with the user, and generate a secure credential(s) that is stored on the mobile device based upon authentication of the smart card. The enrollment server may collect the secure credential(s) from the mobile device via the internal enrollment port, cooperate with the CMS server to verify the secure credential(s), and enroll the mobile device to access the enrollment server from outside of the internal LAN based upon verification of the secure credential(s).