Security Token Access Device Multi-Connection Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security token access devices are typically dedicated to a single user device, making them inconvenient for users who need to access multiple devices securely, such as personal computers and mobile communication devices, as they require severing connections between devices to switch between user devices.

Innovation Solution

A method and system for managing connections between a security token access device and multiple user devices over a wireless connection, allowing secure pairing with multiple devices and automatically terminating connections to stale or unauthorized devices by maintaining connection information and implementing a management protocol for handling stale devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a security token access device uses a dedicated connection with a single user device, then security is maintained through secure pairing, but the device cannot be used with multiple user devices simultaneously

Engineering Contradiction:
ImproveAbility to connect with multiple user devicesVSAvoidSecurity of connection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the connection management by maintaining separate connection records for each user device, with each record containing unique security information. This allows the access device to manage multiple secure connections simultaneously by treating each connection as an independent segment with its own security credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access device is designed to perform multiple functions by supporting connections with multiple user devices while maintaining security. The device universally accepts connections from different devices by verifying their security information against stored records, enabling it to serve multiple users securely.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If a security token access device allows connections from multiple user devices, then usability is improved for users with multiple devices, but security risks increase from potential unauthorized access

Engineering Contradiction:
ImproveConvenience of using security token with multiple devicesVSAvoidUnauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security verification by checking whether security information for a connecting user device exists in the connection records before establishing a connection. This preliminary action prevents unauthorized devices from connecting, as they will not have valid security information in the records.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the access device monitors connection status and can identify when a user device is no longer in use. The system provides feedback to users about connection status and enables users to revoke access for devices that are no longer needed, maintaining security while allowing flexible usage.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the access device maintains secure pairing with multiple user devices, then versatility is enhanced, but device complexity increases for managing multiple connections

Engineering Contradiction:
ImproveSupport for multiple simultaneous connectionsVSAvoidConnection management overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access device provides self-service capabilities by automatically managing connection records and security information. The device can autonomously determine whether a user device is no longer in use and facilitate its removal from connection records, reducing the manual management burden on users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary management protocol that handles the complexity of multiple connection management. This intermediary layer abstracts the complexity by providing standardized methods for adding, removing, and managing connections, making the system easier to use despite the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP1881433B1Method and apparatus for the management of multiple connections to a security token access device
Publication Date: 2012.04.18 BLACKBERRY LTD
  • EP1881433B1 patent drawingFigure 1
  • EP1881433B1 patent drawingFigure 2
  • EP1881433B1 patent drawingFigure 3A~3C

AI summary

A system and method for automatically managing a connection between a user device and a security token access device. The access device is adapted to wirelessly communicate with a plurality of user devices and to be securely paired with at least one of the plurality of user devices, and is further adapted to maintain connection information relating to each of the plurality of user devices. The connection information comprises security information for each user device securely paired with the access device. The access device automatically manages a connection by maintaining a store of connection information comprising security information for each of a set of at least one securely paired user devices; determining whether one of the securely paired user devices is a stale device; and if it is determined that one of the securely paired user devices is a stale device, implementing a management protocol for handling the stale device.