Virtual Smart Card Key Management via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure data transmission systems over unprotected networks, such as the Internet, face vulnerabilities due to the handling of private keys in traditional public key infrastructure (PKI) schemes, particularly in multi-purpose electronic devices that lack security, leading to risks of key exposure and unauthorized access.
Innovation Solution
The implementation of a virtual smart card system that uses identifiers to create a virtual wire and manage user-specific virtual smart card objects, ensuring secure authentication and encryption without physical hardware, utilizing multi-factor authentication and central server management to maintain control over private keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional PKI schemes are used with private keys stored on common storage devices in multi-purpose electronic devices, then service availability and convenience are improved, but security is worsened due to vulnerability to attacks and risk of key exposure
Solution Approach 1:
The system segments the private key storage and processing functions by separating the key generation (performed securely on the server) from the key usage (performed on the client device). The private key never resides on the client device, eliminating the security vulnerability while maintaining service availability.
Solution Approach 2:
The patent introduces a cryptographic intermediary mechanism where the server acts as a trusted mediator that generates and manages private keys on behalf of clients. The server uses its own private key to sign challenge-response pairs, allowing clients to authenticate without ever possessing or storing the server's private key.
2Reliability
If private keys are stored on external smart cards, then security is improved, but device complexity and portability are worsened
Solution Approach 1:
The patent creates a virtual copy of smart card functionality that runs entirely in software on the client device. Instead of requiring physical smart cards and readers, the system emulates smart card operations through software-based key management and cryptographic processing, eliminating hardware dependencies.
Solution Approach 2:
The patent replaces the mechanical/physical smart card system with a software-based cryptographic system. The physical smart card reader and card are substituted with software modules that perform identical cryptographic functions, eliminating the need for specialized hardware while maintaining security.
3Reliability
If physical smart cards are used for secure operations, then key control is improved, but ease of operation and accessibility are worsened due to need for specific hardware
Solution Approach 1:
The patent creates a universal authentication system that works across all devices with standard internet connectivity. The cryptographic operations that previously required specialized smart card hardware are now performed by software modules that can run on any device, making the system universally accessible while maintaining key control through secure server-side management.
Data Source
AI summary
A portable data or information carrier in the form of a smart card with partially or fully virtualized components. To maximize the confidentiality of information stored in the carrier, and more specifically to limit the amount of information available to a potential defrauder, electronic components such as circuits, I/O, cryptographic, memory and dummy objects are built, modified or influenced on demand from physical characteristics of an eligible person or device. Digitized unique biometric or hardware identifiers are read upon start-up and runtime of the device and, in case of an eligible person or device, subsequently supply all values necessary for determination of the characteristics of the user specific virtual smart cards objects, their placement and connections. By multi-factor authentication, the end-user or device will retain sole control of its keys and use them for authentication, signature or encryption purposes as if he had a physical smart card in his hand.


