Remote Device Unlocking via Server Emulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing client devices with embedded operating systems, such as multifunction peripherals (MFPs), face challenges in authenticating users due to the incompatibility of general-purpose operating systems, which prevents the execution of authentication applications and secure data access.
Innovation Solution
A method is implemented where a server, connected via a network, emulates a general-purpose operating system environment, allowing a USB device with a secured data area and authentication application to be virtually attached, enabling remote unlocking by switching interfaces and using secure applications to unlock the secure data partition.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a device with an embedded operating system is used, then device complexity and resource requirements are reduced, but the device cannot execute authentication applications designed for general-purpose operating systems
Solution Approach 1:
The patent introduces an emulation layer as an intermediary between the embedded operating system and the authentication application. This emulation layer virtualizes the general-purpose operating system environment, allowing the authentication application to execute on the embedded OS without requiring the device to actually run a general-purpose OS. The emulation layer translates application requests into operations that the embedded OS can handle, resolving the incompatibility while maintaining device simplicity.
Solution Approach 2:
The patent creates a virtual copy of a general-purpose operating system environment within the embedded operating system through emulation. Instead of replacing the embedded OS with a general-purpose OS, the system copies the necessary OS functions and interfaces into a virtual environment that the authentication application can interact with. This allows the application to run as if on a general-purpose OS while the physical device continues to use the resource-efficient embedded OS.
2Reliability
If authentication processing is enabled on the device, then user security is improved, but the device requires additional processing capabilities and memory resources
Solution Approach 1:
The emulation layer acts as an intermediary that enables authentication processing without requiring the device to have native general-purpose OS capabilities. By virtualizing the authentication environment, the system provides secure authentication processing while keeping the actual resource requirements aligned with the embedded OS capabilities. The emulation layer handles the complexity of authentication protocols without proportionally increasing device resource demands.
3Ease of operation
If a virtual desktop environment is used, then remote access and security management are enhanced, but the system requires network infrastructure and server resources
Solution Approach 1:
The patent creates a virtual desktop environment that copies the functionality of a full desktop OS into a remote access interface. This virtual environment is delivered through the network infrastructure, allowing users to access authentication and data management capabilities remotely. The virtual desktop copying approach enables remote access without requiring each local device to have full desktop capabilities, distributing the complexity to the server side while keeping client devices simple.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for unlocking a device remotely from a server, where the device is connected locally to a client, and the server is remote to the client and the device, are provided in accordance with various aspects of the subject technology. In one aspect, a system includes a remote unlocking module configured to monitor, at the server, traffic between a secure application and a virtual bus driver for at least one string descriptor request associated with switching an interface of the device from a first interface type to a second interface type, and to intercept the at least one string descriptor request. The system further includes an agent configured to receive the intercepted at least one string descriptor request, and to send the intercepted at least one string descriptor request from the server to the client over a network.