Smart Card Token Enrollment via Web-Based Self-Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributing and initializing smart cards to a large number of geographically diverse users is time-consuming and logistically challenging for system administrators, especially when there are time deadlines, due to the need for secure enrollment.

Innovation Solution

A method where a certificate server initializes tokens, which are then distributed to users with a security client that detects the token's state and connects to a URL to enroll the user through a web-enrollment form, generating certificates and keys to bind the token to the user, thereby simplifying the enrollment process and reducing administrative involvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If smart cards are distributed to a large number of geographically diverse users, then user coverage and system adoption are improved, but the time and logistical complexity of enrollment and initialization increase significantly

Engineering Contradiction:
Improveuser enrollment efficiencyVSAvoidenrollment time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring smart cards with initialization parameters and enrollment information before distribution. The cards are prepared in advance with necessary cryptographic keys and configuration data, so that when users receive them, the enrollment process can be completed quickly through automated online procedures rather than requiring time-consuming manual initialization at centralized locations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by enabling users to enroll and initialize their own smart cards through web-based interfaces without requiring system administrator intervention. Users can independently complete the enrollment process by inserting their cards into readers connected to their computers and following automated online procedures, which dramatically reduces the time and administrative resources needed for large-scale distribution.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual enrollment procedures are used for smart cards, then security control is maintained, but administrative burden and logistical complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a web-based enrollment system that acts as a mediator between the smart card and the user. This automated online system handles the complex cryptographic initialization and certificate enrollment processes securely in the background, while users simply interact with a simplified web interface. This maintains security controls through automated verification and key management while eliminating the need for administrators to manually manage each enrollment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual administrative procedures with automated electronic systems. Instead of administrators physically distributing and initializing cards through manual processes, the system uses automated online enrollment procedures that electronically provision cards through web-based interfaces, substituting mechanical manual operations with automated digital processes that maintain security while reducing complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If centralized initialization is required for smart cards, then security and control are improved, but scalability and geographic flexibility deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidgeographic flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from centralized physical initialization to distributed online enrollment by adding the dimension of network-based communication. Instead of requiring users to physically bring cards to centralized initialization locations, the system enables enrollment through web-based interfaces accessible from any location with internet connectivity, maintaining security controls through automated cryptographic processes while providing geographic flexibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent creates a universal enrollment system that can handle both centralized and distributed scenarios through a single online platform. The web-based enrollment interface can serve users regardless of their geographic location, and the system maintains consistent security controls across all enrollment methods, making the system adaptable to various deployment scenarios without requiring separate initialization processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9038154B2Token Registration
Publication Date: 2015.05.19 RED HAT INC
  • US9038154B2 patent drawing
  • US9038154B2 patent drawing
  • US9038154B2 patent drawing

AI summary

An embodiment relates generally to a method of binding a token to a user. The method includes receiving a token embedded with an address and inserting the token into a computer. The method also includes connecting to the address stored on the token and binding a user to the token based on information from the address.