Virtual Card Reader for Remote Two-Factor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote users cannot log into servers requiring two-factor authentication due to the inability of current systems to communicate with remote smart card readers, making it cumbersome to complete the physical device verification process.
Innovation Solution
A virtual card reader system that establishes a communication channel between a remote access resource and a remotely located smart card reader, enabling remote physical card authentication and supporting console traffic redirection for userid/password authentication, allowing remote users to complete two-factor authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-factor authentication with physical smart card readers is implemented, then security is improved, but remote access capability deteriorates
Solution Approach 1:
The patent creates a virtual copy of the smart card reader functionality that operates over a network. The virtual card reader receives authentication requests, communicates with the physical smart card reader remotely, and presents credentials to the server, thereby copying the physical presence requirement to a remote environment.
Solution Approach 2:
The virtual card reader acts as an intermediary between the remote user and the physical smart card reader. It receives authentication requests from the user's computer, forwards them to the physical reader, receives the credential response, and relays it back to the server, enabling two-factor authentication without physical presence at the server location.
2Reliability
If physical smart card readers are required for authentication, then authentication reliability is improved, but device complexity increases
Solution Approach 1:
The authentication system is segmented into separate functional components: the virtual card reader software layer, the physical smart card reader hardware layer, and the authentication server. This segmentation allows the complex physical authentication process to be distributed across multiple components, making the system more manageable and deployable in remote environments.
Solution Approach 2:
The patent replaces the mechanical requirement of physical presence at a card reader with an electronic/network-based system. The virtual card reader uses software communication protocols to substitute for the physical insertion and reading of smart cards, thereby reducing the need for complex physical infrastructure at remote locations.
3Ease of operation
If console redirection is used for remote access, then ease of operation is improved, but authentication capability deteriorates
Solution Approach 1:
The patent merges the console redirection functionality with the virtual card reader capabilities into a unified remote access system. The virtual card reader is integrated into the console redirection session, allowing users to perform both console access and two-factor authentication through the same remote connection, thereby combining ease of operation with strong authentication capability.
Data Source
AI summary
An information handling system includes a processor, system memory, and a remote access resource that includes a virtual card reader enabled to establish a communication channel between the remote access resource and a remote card reader to communicate smart card reader access requests and response between them. The system may include an authentication module requiring two factor authentication including userid/password authentication and a physical card authentication. The communication channel enables remote physical card authentication. The resource further supports redirection of system console traffic enabling remote userid/password authentication. The virtual card reader is preferably operable to download a virtual card reader client to a remote management station to which the smart card reader is attached. The remote access resource may be operable to direct console traffic of the system to the remote management station to display a system login screen on the remote management station.


