Secure USB Drive Host-Agent Card-Agent Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current smart card solutions require specialized hardware and software installations on host computers, limiting their deployment due to the need for administrative rights, which hinders mass adoption for desktop applications.

Innovation Solution

A smart card with firmware that automatically installs necessary components on a host computer via a standard peripheral connection, such as USB, allowing secure communication without requiring special hardware or software on the host computer, using a host-agent and card-agent architecture that communicates over the USB mass storage protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smart cards use specialized hardware (card readers) and require driver/middleware installation, then security services can be provided, but device complexity and ease of operation deteriorate due to installation requirements and administrative rights needed

Engineering Contradiction:
Improvesecurity servicesVSAvoidhardware and software infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the smart card functionality with a standard USB flash drive, merging security services with a commonly available device. This eliminates the need for specialized card readers and reduces hardware complexity while maintaining security capabilities through the integrated secure element

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The invention makes the security device universal by using standard USB connectivity that works with any computer without requiring specialized hardware or driver installation. The device can be used across multiple platforms and systems, eliminating the need for system-specific configurations

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If smart cards require driver and middleware installation with administrative rights, then security functionality is achieved, but ease of operation deteriorates due to installation burden

Engineering Contradiction:
Improvesecurity functionalityVSAvoiddeployment simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The USB flash drive with secure element performs self-service by automatically being recognized by the operating system as a standard USB storage device. No driver installation or administrative rights are needed - the device simply works when plugged in, allowing users to deploy security functionality without technical expertise or system administrator access

Inventive Principle:
Principle #25Self-service

3Ease of operation

If smart cards are designed for restricted user-mode accounts without administrative rights, then ease of operation improves, but the ability to install necessary software deteriorates

Engineering Contradiction:
Improveuser-mode account compatibilityVSAvoidsoftware installation capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The invention extracts the software installation requirement from the deployment process. Instead of requiring drivers to be installed on the host system, all necessary functionality is contained within the USB flash drive itself, allowing it to work with restricted user-mode accounts that cannot perform system-wide installations

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2002373B1Providing security services using a secure device
Publication Date: 2017.05.03 THALES DIS FRANCE SA
  • EP2002373B1 patent drawingFigure 1
  • EP2002373B1 patent drawingFigure 2
  • EP2002373B1 patent drawingFigure 3

AI summary

A secure portable electronic device for providing secure services when used in conjunction with a host computer. The secure portable device includes a read-only memory partition, a read/write memory partition, and a secure memory partition. The secure portable device includes instructions stored in the read-only partition including a host agent containing instructions executable by the host computer. The secure portable device also includes instructions stored in the secure memory partition. These instructions include a card agent containing instructions executable by central processing units secure portable electronic device, and includes a card agent communications module for communicating with the host agent; and a security module for accessing private information stored in the secure memory partition. The host agent includes a host agent communications module for communicating with the card agent and at least one function requiring use of private information stored in the secure memory partition of the portable device and operable to transmit a request to the card agent to perform a corresponding function requiring the use of private information stored on the portable device.