Remote Device Unlocking via Server Emulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing client devices with embedded operating systems, such as multifunction peripherals (MFPs), face challenges in authenticating users due to the incompatibility of general-purpose operating systems, which prevents the execution of authentication applications and secure data access.

Innovation Solution

A method is implemented where a server, connected via a network, emulates a general-purpose operating system environment, allowing a USB device with a secured data area and authentication application to be virtually attached, enabling remote unlocking by switching interfaces and using secure applications to unlock the secure data partition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a device with an embedded operating system is used, then device complexity and resource requirements are reduced, but the device cannot execute authentication applications designed for general-purpose operating systems

Engineering Contradiction:
Improvedevice complexityVSAvoidoperating system compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an emulation layer as an intermediary between the embedded operating system and the authentication application. This emulation layer virtualizes the general-purpose operating system environment, allowing the authentication application to execute on the embedded OS without requiring the device to actually run a general-purpose OS. The emulation layer translates application requests into operations that the embedded OS can handle, resolving the incompatibility while maintaining device simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of a general-purpose operating system environment within the embedded operating system through emulation. Instead of replacing the embedded OS with a general-purpose OS, the system copies the necessary OS functions and interfaces into a virtual environment that the authentication application can interact with. This allows the application to run as if on a general-purpose OS while the physical device continues to use the resource-efficient embedded OS.

Inventive Principle:
Principle #26Copying

2Reliability

If authentication processing is enabled on the device, then user security is improved, but the device requires additional processing capabilities and memory resources

Engineering Contradiction:
Improveuser authentication securityVSAvoidmemory and processor resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The emulation layer acts as an intermediary that enables authentication processing without requiring the device to have native general-purpose OS capabilities. By virtualizing the authentication environment, the system provides secure authentication processing while keeping the actual resource requirements aligned with the embedded OS capabilities. The emulation layer handles the complexity of authentication protocols without proportionally increasing device resource demands.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a virtual desktop environment is used, then remote access and security management are enhanced, but the system requires network infrastructure and server resources

Engineering Contradiction:
Improveremote access capabilityVSAvoidnetwork infrastructure requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a virtual desktop environment that copies the functionality of a full desktop OS into a remote access interface. This virtual environment is delivered through the network infrastructure, allowing users to access authentication and data management capabilities remotely. The virtual desktop copying approach enables remote access without requiring each local device to have full desktop capabilities, distributing the complexity to the server side while keeping client devices simple.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2678781B1Apparatus and method for unlocking a device remotely from a server
Publication Date: 2017.09.13 WYSE TECHNOLOGY INC
  • EP2678781B1 patent drawingFigure 1
  • EP2678781B1 patent drawingFigure 2
  • EP2678781B1 patent drawingFigure 3

AI summary

Systems and methods for unlocking a device remotely from a server, where the device is connected locally to a client, and the server is remote to the client and the device, are provided in accordance with various aspects of the subject technology. In one aspect, a system includes a remote unlocking module configured to monitor, at the server, traffic between a secure application and a virtual bus driver for at least one string descriptor request associated with switching an interface of the device from a first interface type to a second interface type, and to intercept the at least one string descriptor request. The system further includes an agent configured to receive the intercepted at least one string descriptor request, and to send the intercepted at least one string descriptor request from the server to the client over a network.