Mobile Enterprise Smartcard Authentication via Portal Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile devices have limitations in using smart cards for multi-factor authentication into enterprise networks via VPN, restricting the launch of various applications and websites due to the need for specific configuration with smart card readers.

Innovation Solution

The Mobile Enterprise Smartcard Authentication (MESA) system allows users to authenticate with smart cards on mobile devices using native VPN clients, enabling any app to access enterprise networks without requiring specific configuration, leveraging existing enterprise mobility solutions and PKI components for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smart card readers are specifically configured for use with smart cards, then multi-factor authentication security is improved, but the number and type of available applications and websites that can access enterprise network resources is limited

Engineering Contradiction:
Improveauthentication securityVSAvoidapplication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a portal server as an intermediary component that sits between the smart card reader and enterprise network resources. The portal server receives authentication requests from any application or website, validates smart card credentials through a card reader interface, and grants access to enterprise resources. This mediator approach allows unmodified applications to use smart card authentication without requiring specific configuration, resolving the contradiction between security and versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The portal server is designed as a universal authentication gateway that can handle multiple authentication methods (smart cards, tokens, certificates) and support various applications and websites simultaneously. By creating a single multi-functional authentication platform, the system enables any application to access enterprise network resources using smart card authentication without requiring application-specific modifications, thereby achieving both high security and broad compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If applications are specifically designed to function with smart cards, then authentication reliability is improved, but the deployment speed and flexibility of applications is reduced

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidapplication deployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The portal server acts as an intermediary that handles all smart card authentication logic centrally, allowing applications to access enterprise resources without being specifically designed for smart cards. The portal server translates generic authentication requests into smart card-specific operations, enabling rapid deployment of standard applications while maintaining authentication reliability through the intermediary's specialized handling.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into separate functional components: the portal server handles authentication logic, the card reader manages physical smart card interaction, and applications provide user access. This segmentation allows applications to remain generic and quickly deployable, while authentication reliability is maintained through the specialized portal server and card reader components that handle smart card-specific operations.

Inventive Principle:
Principle #1Segmentation

3Reliability

If multiple authentication factors are required for enterprise network access, then security is improved, but the complexity of the authentication process increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The portal server merges multiple authentication factors (smart card credentials, PIN codes, biometric data) into a single unified authentication interface. Users interact with one portal that handles all authentication requirements simultaneously, combining what would otherwise be separate authentication steps into a single streamlined process. This merging maintains high security through multi-factor authentication while reducing perceived complexity for users.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The portal server serves as an intermediary that manages the complexity of multi-factor authentication behind the scenes. It coordinates between different authentication methods (smart card reading, PIN verification, biometric matching) and enterprise resource access, shielding users from the underlying complexity while maintaining strong security through required multi-factor verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9083703B2Mobile enterprise smartcard authentication
Publication Date: 2015.07.14 LEIDOS INNOVATIONS TECHNOLOGY INC
  • US9083703B2 patent drawing
  • US9083703B2 patent drawing
  • US9083703B2 patent drawing

AI summary

Utilities that allow for multi-factor authentication into an enterprise network with a smart card using mobiles devices (e.g., smartphones, tablets, etc.), where almost any application (app) or website that accesses enterprise resources can be launched or executed to automatically establish of a VPN connection with the enterprise network free of necessarily having to specially configure the apps or websites to be useable with smart cards, card readers, etc. Virtually any app can be used and take advantage of the multifactor authentication free or substantially free of modification to the app itself as the disclosed utilities may take advantage of the native VPN clients and capabilities provided with the mobile device operating system (OS) (e.g., Android®, iOS). As a result, a much more flexible solution may be provided that allows the use of commercially available apps (e.g., from an “App Store”) as well as, for instance, enterprise developed apps.