Automated Token Enrollment for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart cards require complex processes for enrollment and management, making it difficult for users to access secured information, especially if the card is lost or replaced, and administrators must perform numerous tasks to regain access.

Innovation Solution

An automated process where a security client detects the token, notifies the enterprise security system, and performs profile lookups to authorize its use, allowing users to enroll and access secured information with minimal user input, including key updates and applet upgrades, and key archival for recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual enrollment and authentication processes are used for smart cards, then security management is thorough and controlled, but user operation complexity increases and enrollment time extends

Engineering Contradiction:
Improvesecurity managementVSAvoiduser operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service enrollment where the smart card automatically enrolls itself when inserted into the reader. The card's embedded processor handles key generation, certificate requests, and profile matching without requiring user intervention for these technical steps, thus maintaining security while simplifying user operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring security profiles and criteria in the database before enrollment. When a card is inserted, the system automatically matches the card's unique identifier against pre-defined profiles and pre-generates necessary security credentials, eliminating the need for manual step-by-step enrollment procedures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual enrollment processes are used for smart cards, then security credentials are properly established, but enrollment time and administrative burden increase

Engineering Contradiction:
Improvesecurity credential establishmentVSAvoidenrollment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The smart card performs self-enrollment by automatically generating cryptographic keys, requesting certificates, and registering with the security system when inserted into the reader. This automated self-service process maintains proper security credential establishment while reducing enrollment time from multiple manual steps to a single insertion action.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-prepares enrollment profiles, security policies, and certificate templates in the database before actual enrollment occurs. When a card is inserted, the system quickly matches the card ID against pre-configured profiles and automatically applies the appropriate security credentials, significantly reducing enrollment time while maintaining security integrity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If replacement smart cards require substantial administrative tasks, then security access is restored, but user convenience deteriorates during card replacement

Engineering Contradiction:
Improvesecurity access restorationVSAvoidcard replacement process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

When a replacement card is issued, the system automatically enrolls it by reading the card's unique identifier, matching it against the user's profile in the database, and provisioning the same security credentials as the original card. This self-service replacement process restores security access while requiring minimal administrative intervention and providing convenience to the user.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9769158B2Guided enrollment and login for token users
Publication Date: 2017.09.19 RED HAT INC
  • US9769158B2 patent drawing
  • US9769158B2 patent drawing
  • US9769158B2 patent drawing

AI summary

Embodiments of the present invention provide an automated process for enrolling and logging in with a token. In particular, a security client detects when the user has inserted their token. In response, the security client then notifies the enterprise security system and provides information about the token. The enterprise security system performs a profile lookup and authorizes use of the token.