Smart Card Reader with Channel Switch for Multi-Computer Auth

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face discomfort and security concerns when accessing multiple isolated computer systems, as existing methods require multiple smart-card readers or cards, leading to authentication session termination upon removing the card and increased risk of unauthorized access.

Innovation Solution

A secure user interfacing device with at least two computer channels, a smart-card reader function, and a channel select switch allows concurrent authentication across multiple computers while maintaining data isolation, with optional biometric support and tampering detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a user uses one smart-card to authenticate in one of the several smart-card readers, then the authentication device is simplified, but the user cannot simultaneously access multiple networks and must log-off from other networks

Engineering Contradiction:
Improveauthentication deviceVSAvoidsimultaneous access
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The smart-card reader is divided into multiple independent reader functions (first reader function, second reader function) that can operate simultaneously and independently. Each reader function has its own card presence detection and authentication capabilities, allowing the user to authenticate on multiple computers at the same time using a single smart-card.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The smart-card reader is designed with multi-functionality to serve multiple computers simultaneously. It can function as both a first smart-card reader for a first computer and a second smart-card reader for a second computer at the same time, eliminating the need for separate readers for each computer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If a user uses multiple smart-cards - one card for each system, then simultaneous access to multiple networks is enabled, but user responsibility increases and cards may be forgotten or switched unintentionally

Engineering Contradiction:
Improvesimultaneous accessVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The smart-card reader is designed with multi-functionality to serve multiple computers simultaneously. It can function as both a first smart-card reader for a first computer and a second smart-card reader for a second computer at the same time, eliminating the need for separate readers for each computer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple reader functions are merged into a single smart-card reader device. Instead of having separate physical readers for each computer, the invention combines multiple reader functions within one device, allowing all functions to share a common smart-card slot and reducing the number of cards the user needs to manage.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If organizations isolate classified and non-classified networks, then data leakage is prevented, but users must authenticate in front of multiple computers simultaneously

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The smart-card reader is divided into multiple independent reader functions (first reader function, second reader function) that can operate simultaneously and independently. Each reader function has its own card presence detection and authentication capabilities, allowing the user to authenticate on multiple computers at the same time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The smart-card reader acts as an intermediary device between the user's smart-card and multiple isolated computers. It provides a unified interface that manages authentication to multiple computers simultaneously while maintaining the isolation between different networks, reducing the complexity of the authentication system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2698738B1User authentication device having multiple isolated host interfaces
Publication Date: 2017.07.05 HIGH SEC LABS LTD
  • EP2698738B1 patent drawingFigure 1
  • EP2698738B1 patent drawingFigure 2
  • EP2698738B1 patent drawingFigure 3

AI summary

Devices and methods provide for enabling a user to use a single user authentication device such as smart-card reader, such that the user is capable of securely interfacing with two or more isolated computers and enabling the user to authenticate and remain authenticated at multiple computers at the same time. Once the user removes the smart-card from the smart-card reader, the authentication session on all coupled computers is terminated at once. The user authentication device comprises: an authentication module connected via a channel selection switch to one of a plurality of channels, each interfacing with a respective coupled computer.