Smart Card Reader Emulating USB Mass Storage for Secure Digital Signing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing remote access to computers and applications over public networks, such as those using static passwords and PKI smart cards, are cumbersome due to the need for specific hardware and software installations on general-purpose computing devices, which can lead to complicated setups and unreliable systems.

Innovation Solution

A device that presents itself as a USB Mass Storage Device to a host computer, allowing for cryptographic processing and digital signature generation without requiring the installation of specific hardware and software, using a communication interface to exchange files and perform cryptographic operations with a private key, and optionally interacting with external removable key storage devices like smart cards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI smart cards and USB smart card readers are used for digital signing, then security is improved, but device complexity and installation requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidinstallation requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the smart card reader multi-functional by enabling it to operate in two modes: traditional cryptographic operation mode and mass storage emulation mode. This allows the same device to serve both security functions and file transfer functions, eliminating the need for separate software installations on the host computer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a host-independent cryptographic library that runs on the smart card reader itself rather than on the host computer. This intermediary layer handles all cryptographic operations locally, mediating between the smart card and the host computer without requiring the host to have specific cryptographic software installed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cryptographic libraries and USB drivers are installed on the host computer, then digital signing functionality is enabled, but ease of operation deteriorates

Engineering Contradiction:
Improvedigital signing functionalityVSAvoidsetup complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The smart card reader performs self-service by containing its own cryptographic library and executing cryptographic operations locally. This eliminates the need for the host computer to provide cryptographic services, making the system independent of the host's software environment and much easier to operate.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of having the host computer provide cryptographic services to the smart card reader, the patent inverts the relationship by having the smart card reader provide cryptographic services independently. The reader becomes the active provider of cryptographic functionality rather than a passive recipient of host services.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If USB smart card readers are used, then secure cryptographic operations are possible, but compatibility with standard USB interfaces is reduced

Engineering Contradiction:
Improvecryptographic securityVSAvoidUSB interface compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the smart card reader dynamic by enabling it to switch between two operational modes: traditional cryptographic mode for secure operations and USB mass storage emulation mode for file transfer. This dynamic adaptability allows the device to maintain cryptographic security while also being compatible with standard USB mass storage interfaces.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3090504B1Electronic signing methods, systems and apparatus
Publication Date: 2020.04.29 ONESPAN INT GMBH
  • EP3090504B1 patent drawingFigure 1
  • EP3090504B1 patent drawingFigure 2
  • EP3090504B1 patent drawingFigure 3

AI summary

Methods, apparatus, and systems for generating digital signatures are disclosed. An apparatus may present itself to a host computer as a mass storage device to provide cryptographic processing results through a standard mass storage access mechanism for exchanging files.