Security Daemon for Smart Card Authentication State Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on (SSO) solutions, such as enterprise SSO, struggle to operate in secure enterprise systems that use multiple login methods like smart cards or biometric systems, as they lack direct access to authentication information, leading to issues with sharing login states and preventing unauthorized access.

Innovation Solution

A method and system that utilize a security daemon to capture and manage the authentication state of a security token, allowing it to represent the authenticated token to other applications through a PKCS #11 interface, ensuring secure access and preventing unauthorized access by locking access to the token.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a user logs on to a secure machine with a smart card and allows sharing of login state with trusted applications, then access convenience to multiple applications is improved, but security risk increases due to potential unauthorized access by other users

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication state into application-specific contexts. Each application receives its own authenticated representation from the smart card without sharing the actual authentication credentials. This allows multiple applications to access authentication state independently, preventing one application from accessing another's authentication context while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component that acts as a mediator between the smart card authentication system and multiple applications. This intermediary captures the authentication state and creates authenticated representations that applications can use without directly accessing the smart card or each other's authentication states, thus preventing unauthorized cross-application access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If existing SSO solutions are used in secure enterprise systems with multiple login methods, then interoperability with legacy applications is improved, but compatibility with secure authentication systems like smart cards deteriorates due to lack of direct access to authentication information

Engineering Contradiction:
ImproveinteroperabilityVSAvoidcompatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal authentication representation that can be used across different authentication systems including smart cards and traditional password systems. The authenticated representation serves as a multi-functional interface that works with various login methods while maintaining security, allowing the system to handle multiple authentication types through a unified mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates authenticated representations that are copies of the authentication state without being the actual authentication credentials. These copied representations can be shared with applications in a secure manner, enabling interoperability without exposing the actual authentication information that secure systems like smart cards protect.

Inventive Principle:
Principle #26Copying

3Productivity

If a second user logs into the secure machine with the first user's smart card, then device availability is improved, but unauthorized access risk increases as the second user can pretend to be the first user

Engineering Contradiction:
Improvedevice availabilityVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments authentication contexts by application, so that even if a smart card is physically transferred to another user, the authentication state cannot be shared across different application contexts. Each application maintains its own authenticated representation that is tied to the original user's session, preventing impersonation while allowing the card to be used in different physical locations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7992203B2Methods and systems for secure shared smartcard access
Publication Date: 2011.08.02 RED HAT INC
  • US7992203B2 patent drawing
  • US7992203B2 patent drawing
  • US7992203B2 patent drawing

AI summary

An embodiment generally relates to a method of accessing a secure computer. The method includes capturing an authentication state of a security token in response to a verification of user authentication information. The method also includes providing the authentication state to at least one application requiring authentication with the security token and accessing the at least one application.