Secure Appliance for Physical Security Token Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for encoding physical security tokens, such as access cards and key fobs, are vulnerable to physical theft and security breaches due to the handling and storage of cryptographic keys and user information, which can lead to unauthorized access and identity theft.
Innovation Solution
A secure appliance is used to securely provision physical security tokens by receiving encrypted access information from a remote server, utilizing a secure cryptoprocessor to encrypt the data, and transmitting it via a secured channel to a security token reader for encoding, without storing any encrypted information on the reader, thus minimizing exposure to theft and breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If encoder devices or workstations store cryptographic keys and encoding information locally, then provisioning can be performed independently and efficiently, but security is compromised due to vulnerability to physical theft and security breaches
Solution Approach 1:
The patent extracts the cryptographic keys from local storage devices (encoder devices and workstations) and places them in a remote secure server. This separation allows the provisioning process to remain efficient while eliminating the security vulnerability of local key storage. The encoder device and workstation can still function independently for encoding operations, but the sensitive key material is removed from their storage.
Solution Approach 2:
The patent introduces a secure server as an intermediary between the encoding process and the cryptographic keys. Instead of workstations or encoder devices directly storing and using keys, they communicate with the secure server which acts as a mediator. This intermediary provides the necessary security functions while allowing the original encoding workflow to continue with minimal changes.
2Adaptability or versatility
If encoding information is transmitted through multiple devices (workstation to encoder to token), then provisioning flexibility is improved, but exposure to security breaches increases
Solution Approach 1:
The patent extracts the most sensitive information (cryptographic keys) from the transmission path between workstation and encoder device. By having the workstation communicate directly with the secure server to obtain keys, and the encoder device obtaining keys from the server rather than from the workstation, the transmission path for sensitive data is shortened and secured.
Solution Approach 2:
The patent applies different security qualities to different parts of the system. The secure server implements stringent security controls for key storage and distribution, while the encoder device and workstation can use less restrictive measures for non-key operations. This localized security approach provides strong protection where needed without unnecessarily complicating the entire system.
Data Source
AI summary
A computer-implemented system and methods for provisioning a security token are provided. An example method may include steps of: receiving, at a secure appliance and from a remote server, a command to encode a set of access information into the physical security token; generating, at the secure appliance, encrypted access information, comprising: providing the set of access information to a secure cryptoprocessor; and instructing the secure cryptoprocessor to use a cryptographic key stored in the secure cryptoprocessor to encrypt the set of access information; obtaining, from a security token reader, an indication of a presence of the physical security token being inserted into or presented to the security token reader; and provisioning the physical security token by transmitting, via a secured channel, the encrypted access information from the secure appliance to the security token reader for encoding the physical security token with the encrypted access information.


