Virtual Smart Card Key Management via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure data transmission systems over unprotected networks, such as the Internet, face vulnerabilities due to the handling of private keys in traditional public key infrastructure (PKI) schemes, particularly in multi-purpose electronic devices that lack security, leading to risks of key exposure and unauthorized access.

Innovation Solution

The implementation of a virtual smart card system that uses identifiers to create a virtual wire and manage user-specific virtual smart card objects, ensuring secure authentication and encryption without physical hardware, utilizing multi-factor authentication and central server management to maintain control over private keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional PKI schemes are used with private keys stored on common storage devices in multi-purpose electronic devices, then service availability and convenience are improved, but security is worsened due to vulnerability to attacks and risk of key exposure

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the private key storage and processing functions by separating the key generation (performed securely on the server) from the key usage (performed on the client device). The private key never resides on the client device, eliminating the security vulnerability while maintaining service availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cryptographic intermediary mechanism where the server acts as a trusted mediator that generates and manages private keys on behalf of clients. The server uses its own private key to sign challenge-response pairs, allowing clients to authenticate without ever possessing or storing the server's private key.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If private keys are stored on external smart cards, then security is improved, but device complexity and portability are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of smart card functionality that runs entirely in software on the client device. Instead of requiring physical smart cards and readers, the system emulates smart card operations through software-based key management and cryptographic processing, eliminating hardware dependencies.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/physical smart card system with a software-based cryptographic system. The physical smart card reader and card are substituted with software modules that perform identical cryptographic functions, eliminating the need for specialized hardware while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If physical smart cards are used for secure operations, then key control is improved, but ease of operation and accessibility are worsened due to need for specific hardware

Engineering Contradiction:
Improvekey controlVSAvoidportability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal authentication system that works across all devices with standard internet connectivity. The cryptographic operations that previously required specialized smart card hardware are now performed by software modules that can run on any device, making the system universally accessible while maintaining key control through secure server-side management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10616215B1Virtual smart card to perform security-critical operations
Publication Date: 2020.04.07 SUSE LLC
  • US10616215B1 patent drawing
  • US10616215B1 patent drawing
  • US10616215B1 patent drawing

AI summary

A portable data or information carrier in the form of a smart card with partially or fully virtualized components. To maximize the confidentiality of information stored in the carrier, and more specifically to limit the amount of information available to a potential defrauder, electronic components such as circuits, I/O, cryptographic, memory and dummy objects are built, modified or influenced on demand from physical characteristics of an eligible person or device. Digitized unique biometric or hardware identifiers are read upon start-up and runtime of the device and, in case of an eligible person or device, subsequently supply all values necessary for determination of the characteristics of the user specific virtual smart cards objects, their placement and connections. By multi-factor authentication, the end-user or device will retain sole control of its keys and use them for authentication, signature or encryption purposes as if he had a physical smart card in his hand.