Token Profile Framework for Secure Enrollment and Key Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart cards require complex processes for enrollment and key management, making it difficult for users to regain access if their card is lost or compromised, and administrators face substantial tasks to restore access.

Innovation Solution

A method and system for generating credentials using a token and security server, where a subject key pair is created, encrypted, and forwarded to the token, enabling efficient enrollment and key archival for recovery purposes, with a profile framework managing various security policies and requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional smart card enrollment processes are used, then security credentials can be established, but the process becomes complex and difficult to perform

Engineering Contradiction:
Improvesecurity credential establishmentVSAvoidenrollment process complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a key escrow server as an intermediary between the token and the security infrastructure. This server facilitates key archival and recovery operations, simplifying the enrollment process by automatically managing key pairs and their archival without requiring complex manual configuration or intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary key generation and archival actions during the enrollment process. Private keys are generated and archived in advance on the key escrow server, so that when a token needs recovery or replacement, the keys are already prepared and available, eliminating the need for complex real-time key management operations.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If traditional smart card replacement processes are used, then users can regain access to their information, but administrators face substantial tasks to restore access

Engineering Contradiction:
Improveaccess recoveryVSAvoidadministrator workload time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The key escrow server enables self-service key recovery operations. When a token is lost or compromised, the system can automatically retrieve the archived private key from the key escrow server and restore access without requiring administrators to manually perform complex key management tasks, thereby reducing both time and workload.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Private keys are archived in advance on the key escrow server during initial enrollment. This preliminary action ensures that when token replacement is needed, the recovery process is simplified because the keys are already prepared and stored securely, eliminating the need for time-consuming key regeneration or manual retrieval processes.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive key management is implemented, then security is enhanced, but the system complexity increases

Engineering Contradiction:
Improvesecurity managementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management functionality into a dedicated key escrow server that handles key archival and recovery operations separately from the main token management system. This segmentation allows comprehensive security to be implemented in a modular fashion, where the key escrow server handles the complex security operations independently, reducing the overall system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8412927B2Profile framework for token processing system
Publication Date: 2013.04.02 RED HAT INC
  • US8412927B2 patent drawing
  • US8412927B2 patent drawing
  • US8412927B2 patent drawing

AI summary

Embodiments of the present invention provide a profile framework for handling enrollment requests. In particular, when a token processing system receives an enrollment request, it selects an applicable profile based on information in the request. The profile may indicate a variety of parameters for fulfilling the enrollment request, such as the locations of the applicable certificate authority, token key service, and the like. The profile may also indicate items, such as the number of keys to generate on a token, a token label, and connection information to securely communicate with other components and the client making the enrollment request.