Secure Portable Device Host Agent Card Agent Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current smart card solutions require specialized hardware and software installations on host computers, limiting their deployment for desktop applications due to the need for administrative rights, which hinders mass adoption for providing security services over the Internet.

Innovation Solution

A secure portable electronic device that connects to a host computer via a standard interface, such as USB, using firmware to provide security services without the need for additional hardware or software installations, with a host agent and card agent communicating securely over a mass storage protocol to manage and access private information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized hardware and software infrastructure is installed on host computers to support smart cards, then security services can be provided, but device complexity and ease of operation deteriorate due to requiring administrative rights and specialized installations

Engineering Contradiction:
Improvesecurity servicesVSAvoidhardware and software infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex infrastructure requirements from the host computer and relocates them to the smart card itself. The smart card contains embedded drivers, middleware, and network stack that were traditionally required to be installed on the host system. This extraction eliminates the need for host-side installations while maintaining security services.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card provides self-service capability by including all necessary software components (drivers, middleware, network stack) embedded within the card itself. When connected to a host computer, the card automatically initiates communication and establishes secure connections without requiring any installation or configuration on the host side, thereby simplifying operation.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If specialized card readers and middleware applications are installed on host computers, then smart card functionality is enabled, but ease of operation worsens due to requiring administrative privileges

Engineering Contradiction:
Improvesmart card functionalityVSAvoidinstallation and configuration
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent extracts all middleware and card reader functionality from the host computer and embeds them directly into the smart card. This allows the card to function independently on any standard computer without requiring specialized hardware or software installations on the host system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card performs self-service by automatically initiating communication with the host computer and establishing secure connections without requiring user intervention or administrative privileges. The embedded network stack enables the card to autonomously navigate network protocols and establish secure communications.

Inventive Principle:
Principle #25Self-service

3Device complexity

If standard peripheral connectors are used to avoid special card readers, then device complexity is reduced, but adaptability worsens because the cards still require driver and middleware installation on host computers

Engineering Contradiction:
Improvehardware connectorsVSAvoidhost computer compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent makes the smart card universal by embedding all necessary communication and security functionality within the card itself. The card can connect to any standard peripheral interface (USB, serial, parallel) and automatically adapt to the host computer's architecture, eliminating the need for specialized card readers while maintaining broad compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent extracts host-dependent components (drivers, middleware, network stack) from the host computer and relocates them to the smart card. This extraction allows the card to function with standard peripheral connectors on any host system without requiring additional installation or configuration.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If network capabilities are added to smart cards, then adaptability improves, but device complexity worsens due to requiring software installation and configuration on interface computers

Engineering Contradiction:
Improvenetwork capabilitiesVSAvoidsoftware installation and configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the network stack and communication protocols from the host computer and embeds them within the smart card. This includes TCP/IP implementation, DNS resolution, and secure communication protocols, all of which are traditionally required to be installed on the host system. By moving these components to the card, the patent enables network capabilities without increasing host-side complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9092635B2Method and system of providing security services using a secure device
Publication Date: 2015.07.28 THALES DIS FRANCE SA
  • US9092635B2 patent drawing
  • US9092635B2 patent drawing
  • US9092635B2 patent drawing

AI summary

A secure portable electronic device for providing secure services when used in conjunction with a host computer. The secure portable device includes a read-only memory partition, a read/write memory partition, and a secure memory partition. The secure portable device includes instructions stored in the read-only partition including a host agent containing instructions executable by the host computer. The secure portable device also includes instructions stored in the secure memory partition. These instructions include a card agent containing instructions executable by central processing units secure portable electronic device, and includes a card agent communications module for communicating with the host agent; and a security module for accessing private information stored in the secure memory partition. The host agent includes a host agent communications module for communicating with the card agent and at least one function requiring use of private information stored in the secure memory partition of the portable device and operable to transmit a request to the card agent to perform a corresponding function requiring the use of private information stored on the portable device.