Security Daemon for Smart Card Authentication State Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on (SSO) solutions, such as enterprise SSO, struggle to operate in secure enterprise systems that use multiple login methods like smart cards or biometric systems, as they lack direct access to authentication information, leading to issues with sharing login states and preventing unauthorized access.
Innovation Solution
A method and system that utilize a security daemon to capture and manage the authentication state of a security token, allowing it to represent the authenticated token to other applications through a PKCS #11 interface, ensuring secure access and preventing unauthorized access by locking access to the token.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a user logs on to a secure machine with a smart card and allows sharing of login state with trusted applications, then access convenience to multiple applications is improved, but security risk increases due to potential unauthorized access by other users
Solution Approach 1:
The patent segments the authentication state into application-specific contexts. Each application receives its own authenticated representation from the smart card without sharing the actual authentication credentials. This allows multiple applications to access authentication state independently, preventing one application from accessing another's authentication context while maintaining security.
Solution Approach 2:
The patent introduces an intermediary component that acts as a mediator between the smart card authentication system and multiple applications. This intermediary captures the authentication state and creates authenticated representations that applications can use without directly accessing the smart card or each other's authentication states, thus preventing unauthorized cross-application access.
2Adaptability or versatility
If existing SSO solutions are used in secure enterprise systems with multiple login methods, then interoperability with legacy applications is improved, but compatibility with secure authentication systems like smart cards deteriorates due to lack of direct access to authentication information
Solution Approach 1:
The patent creates a universal authentication representation that can be used across different authentication systems including smart cards and traditional password systems. The authenticated representation serves as a multi-functional interface that works with various login methods while maintaining security, allowing the system to handle multiple authentication types through a unified mechanism.
Solution Approach 2:
The patent creates authenticated representations that are copies of the authentication state without being the actual authentication credentials. These copied representations can be shared with applications in a secure manner, enabling interoperability without exposing the actual authentication information that secure systems like smart cards protect.
3Productivity
If a second user logs into the secure machine with the first user's smart card, then device availability is improved, but unauthorized access risk increases as the second user can pretend to be the first user
Solution Approach 1:
The patent segments authentication contexts by application, so that even if a smart card is physically transferred to another user, the authentication state cannot be shared across different application contexts. Each application maintains its own authenticated representation that is tied to the original user's session, preventing impersonation while allowing the card to be used in different physical locations.
Data Source
AI summary
An embodiment generally relates to a method of accessing a secure computer. The method includes capturing an authentication state of a security token in response to a verification of user authentication information. The method also includes providing the authentication state to at least one application requiring authentication with the security token and accessing the at least one application.


