Mobile Enterprise Smartcard Authentication via Portal Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile devices have limitations in using smart cards for multi-factor authentication into enterprise networks via VPN, restricting the launch of various applications and websites due to the need for specific configuration with smart card readers.
Innovation Solution
The Mobile Enterprise Smartcard Authentication (MESA) system allows users to authenticate with smart cards on mobile devices using native VPN clients, enabling any app to access enterprise networks without requiring specific configuration, leveraging existing enterprise mobility solutions and PKI components for validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If smart card readers are specifically configured for use with smart cards, then multi-factor authentication security is improved, but the number and type of available applications and websites that can access enterprise network resources is limited
Solution Approach 1:
The patent introduces a portal server as an intermediary component that sits between the smart card reader and enterprise network resources. The portal server receives authentication requests from any application or website, validates smart card credentials through a card reader interface, and grants access to enterprise resources. This mediator approach allows unmodified applications to use smart card authentication without requiring specific configuration, resolving the contradiction between security and versatility.
Solution Approach 2:
The portal server is designed as a universal authentication gateway that can handle multiple authentication methods (smart cards, tokens, certificates) and support various applications and websites simultaneously. By creating a single multi-functional authentication platform, the system enables any application to access enterprise network resources using smart card authentication without requiring application-specific modifications, thereby achieving both high security and broad compatibility.
2Reliability
If applications are specifically designed to function with smart cards, then authentication reliability is improved, but the deployment speed and flexibility of applications is reduced
Solution Approach 1:
The portal server acts as an intermediary that handles all smart card authentication logic centrally, allowing applications to access enterprise resources without being specifically designed for smart cards. The portal server translates generic authentication requests into smart card-specific operations, enabling rapid deployment of standard applications while maintaining authentication reliability through the intermediary's specialized handling.
Solution Approach 2:
The authentication system is segmented into separate functional components: the portal server handles authentication logic, the card reader manages physical smart card interaction, and applications provide user access. This segmentation allows applications to remain generic and quickly deployable, while authentication reliability is maintained through the specialized portal server and card reader components that handle smart card-specific operations.
3Reliability
If multiple authentication factors are required for enterprise network access, then security is improved, but the complexity of the authentication process increases
Solution Approach 1:
The portal server merges multiple authentication factors (smart card credentials, PIN codes, biometric data) into a single unified authentication interface. Users interact with one portal that handles all authentication requirements simultaneously, combining what would otherwise be separate authentication steps into a single streamlined process. This merging maintains high security through multi-factor authentication while reducing perceived complexity for users.
Solution Approach 2:
The portal server serves as an intermediary that manages the complexity of multi-factor authentication behind the scenes. It coordinates between different authentication methods (smart card reading, PIN verification, biometric matching) and enterprise resource access, shielding users from the underlying complexity while maintaining strong security through required multi-factor verification.
Data Source
AI summary
Utilities that allow for multi-factor authentication into an enterprise network with a smart card using mobiles devices (e.g., smartphones, tablets, etc.), where almost any application (app) or website that accesses enterprise resources can be launched or executed to automatically establish of a VPN connection with the enterprise network free of necessarily having to specially configure the apps or websites to be useable with smart cards, card readers, etc. Virtually any app can be used and take advantage of the multifactor authentication free or substantially free of modification to the app itself as the disclosed utilities may take advantage of the native VPN clients and capabilities provided with the mobile device operating system (OS) (e.g., Android®, iOS). As a result, a much more flexible solution may be provided that allows the use of commercially available apps (e.g., from an “App Store”) as well as, for instance, enterprise developed apps.


