Trusted Device Proxy for Smart Card Secret Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computing systems, the use of smart cards for transactions and complex processes can be inefficient due to the need for multiple communications and the slower processing speed of smart card processors compared to device processors, leading to slow and time-consuming operations.

Innovation Solution

A computing system comprising a token reader and a trusted device that is physically and logically protected, which communicates with a security token to validate information and receive a secret for use within the system, acting as a proxy for the smart card to facilitate faster and more efficient transactions and processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smart cards are used for transactions and complex processes in distributed computing systems, then security and user identification are ensured, but operational speed and processing efficiency deteriorate due to slower smart card processors and multiple communication requirements

Engineering Contradiction:
ImprovesecurityVSAvoidoperational speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a trusted device as an intermediary between the smart card and the distributed computing system. The trusted device contains a copy of the smart card's secret and performs cryptographic operations locally, eliminating the need for multiple slow communications with the smart card while maintaining security through the trusted device's protected environment

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates security functions into two parts: the smart card retains the secret in its protected environment for secure storage and initial authentication, while the trusted device holds a copy of the secret for performing cryptographic operations. This segmentation allows the smart card to be used less frequently while maintaining security

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple communications with smart card are performed in a single transaction, then complex processes and transactions can be completed, but time consumption increases due to additional communication legs and slower smart card processing

Engineering Contradiction:
Improveprocess complexityVSAvoidtime consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The trusted device is pre-configured with a copy of the smart card's secret before transactions occur. This preliminary setup allows the trusted device to perform multiple cryptographic operations independently during transactions without needing to communicate with the smart card for each operation, significantly reducing time consumption while maintaining process complexity

Inventive Principle:
Principle #10Preliminary action

3Reliability

If smart card processor is used for all cryptographic operations, then security is maintained through centralized secret management, but processing speed deteriorates due to the slower smart card processor compared to device processor

Engineering Contradiction:
Improvesecret managementVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The trusted device acts as an intermediary that performs cryptographic operations using a copy of the smart card's secret. This allows fast processing on the device processor while the smart card's secret remains protected in its secure environment, with the trusted device bridging the gap between security requirements and processing speed needs

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7779267B2Method and apparatus for using a secret in a distributed computing system
Publication Date: 2010.08.17 LIONRA TECH LTD
  • US7779267B2 patent drawing
  • US7779267B2 patent drawing
  • US7779267B2 patent drawing

AI summary

There are many times when a secret needs to be used in a distributed computing system—these are often held in security tokens, such as smart cards. It may be desirable for another device, such as a computer platform, to act in place of the security token as the repository of a secret, particularly for operations within a distributed computing system. Within the distributed computing system there is located a trusted entity, physically and logically resistant to unauthorized modification—this may be a trusted device located within a specific computing platform. This contains validation information which can be communicated to the security token. The security token then carries out a validation process on this validation information—if successful, the security token then provides a secret to the trusted device for use within the distributed computing system. The trusted device may be required to use this secret only for a specified period of time, or for a specific purpose or task.