Smart Card Access Rights Partitioning and Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems limit smart cards to exclusive association with a single communication device, preventing flexible and secure transfer of access rights to network services and applications across multiple devices and smart cards.

Innovation Solution

The method involves pairing communication devices with smart cards and establishing associations between owner and borrower smart cards, allowing for the partitioning and bundling of access rights, which can be transferred securely between devices and smart cards using encryption and key management techniques, enabling access rights to be retained or transferred based on user preferences and network provider controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smart cards are exclusively associated with a single communication device, then security is maintained, but flexibility and adaptability are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access rights into two distinct types: portable access rights that remain with the smart card when removed from a device, and device-specific access rights that are transferred to the communication device. This segmentation allows the smart card to maintain security through device-specific credentials while simultaneously providing flexibility through portable access rights that can be used across multiple devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the smart card acts as a mediator between the network provider and multiple communication devices. The card enables device-specific access rights to be transferred securely to authorized devices while maintaining the ability to port access rights to other devices, thus serving as a flexible intermediary that balances security requirements with adaptability needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access rights are completely transferred to a communication device, then ease of operation is improved, but security and control are reduced

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access rights management where access rights can be selectively transferred to communication devices on demand. The smart card maintains the ability to grant or revoke device-specific access rights as needed, creating a dynamic system that provides ease of operation when access is granted while maintaining security control through the ability to revoke or limit access as circumstances change.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If multiple smart cards are allowed in a single communication device, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvemulti-device supportVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs copying mechanisms where device-specific access rights can be securely copied from one communication device to another through the smart card intermediary. Rather than requiring physical duplication of smart cards or complex multi-card configurations, the system allows authorized copying of access rights, simplifying the overall system architecture while maintaining multi-device adaptability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7689250B2Method, apparatus and system for partitioning and bundling access to network services and applications
Publication Date: 2010.03.30 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US7689250B2 patent drawing
  • US7689250B2 patent drawing
  • US7689250B2 patent drawing

AI summary

A method (30) and apparatus (10) for bundling and partitioning access rights to network services and applications. The method includes providing communication devices and paired smart cards that are configured to access network services and applications when a smart card paired with a communication device is inserted in or coupled to the communication device. The method also includes transferring a portion of access rights to authorized network services and applications between associated owner smart cards and borrower smart cards using one or more paired communication devices. The method also includes transferring a portion of network service and application access rights between communication devices using one or more paired smart cards. The use of access rights can be limited by duration or in such a way that only one device/smart card pair can access the associated service or application at a given time.