Security Token Access Device Multi-Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security token access devices are typically dedicated to a single user device, making them inconvenient for users who need to access multiple devices for secure operations, such as digitally signing messages, due to the requirement of a dedicated connection.

Innovation Solution

A system and method that allows a security token access device to be used with multiple user devices through wireless communication links, enabling secure pairing and management of connections, including pairing mechanisms and secure pairing keys, to facilitate secure operations across multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security token access device uses a dedicated connection with a single user device, then security and reliability are improved, but adaptability and ease of operation deteriorate because the device cannot be used with multiple user devices

Engineering Contradiction:
ImprovesecurityVSAvoidmulti-device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The access device segments its connection capabilities by maintaining separate secure pairing information for multiple user devices simultaneously. Each user device has its own dedicated secure connection parameters stored in the access device, allowing multiple segmented secure connections to coexist without interfering with each other

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access device is designed with universal functionality to work with multiple types of user devices (computers, mobile devices, tablets) through wireless communication. The device maintains a registry of multiple paired devices and can selectively establish secure connections with any of them, making it multi-functional rather than dedicated to a single device

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If a security token access device establishes secure pairing with multiple user devices, then adaptability and ease of operation are improved, but device complexity increases due to managing multiple connections and pairing information

Engineering Contradiction:
ImproveconvenienceVSAvoidconnection management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The access device automatically manages the complexity of multiple connections through self-service mechanisms. It autonomously maintains pairing information registries, automatically establishes secure connections with paired devices, and handles connection switching without requiring user intervention. The device serves itself by managing its own connection state and security parameters

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access device acts as an intermediary that simplifies interaction between multiple user devices and the security token. It manages the complexity of secure communications by handling pairing information storage, connection establishment, and authentication processes, allowing user devices to interact with the security token through a simplified interface without exposing the underlying complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If a user device needs to connect to a security token access device, then secure operations can be performed, but loss of time occurs due to the need to sever existing connections and establish new pairings

Engineering Contradiction:
Improvesecure operationsVSAvoidreconnection time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The access device performs preliminary actions by pre-establishing secure pairing information with multiple user devices in advance. During the pairing process, the device stores security parameters and establishes authentication credentials before actual secure operations are needed. This preliminary setup eliminates the need for time-consuming reconnection and re-pairing when switching between devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access device maintains continuous secure connections with multiple user devices simultaneously, allowing seamless switching between them. The secure pairing information persists across device connections, enabling continuous useful action without interruption. When a user switches devices, the connection is re-established instantly using pre-stored pairing information rather than requiring a complete re-pairing process

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP1881663B1Management of multiple connections to a security token access device
Publication Date: 2012.12.26 BLACKBERRY LTD
  • EP1881663B1 patent drawingFigure 1
  • EP1881663B1 patent drawingFigure 2
  • EP1881663B1 patent drawingFigure 3

AI summary

A security token access device, a user device such as a computing device or communications device, and a method for managing multiple connections between multiple user devices and the access device. The access device maintains connection information, including security information, for each user device securely paired with the access device. Each time a new user device is paired with the access device, the access device transmits a notification to the user devices already paired to the user device. A user may provide instructions to the access device to terminate a pairing with one of the user devices by overwriting at least a portion of the connection information associated with the designated user device. A user device may further request a listing of all user devices currently paired with the access device.