Virtual Smart Card Mapping via IAM Client Injection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Microsoft Windows 10's Virtual Smart Card system is limited by a hard cap of ten virtual smart cards per personal computer, leading to performance issues and an inability to efficiently map virtual smart cards to multiple users.
Innovation Solution
Implementing an Identity and Access Management (IAM) client on personal computers to securely inject usernames and virtual smart card identities into Kerberos communications with Active Directory, allowing a single master virtual smart card to be mapped to multiple users, leveraging biometric authentication and trusted platform module (TPM) technology.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a hard cap of ten virtual smart cards is imposed per personal computer, then system performance and security are maintained, but the ability to map virtual smart cards to multiple users is limited
Solution Approach 1:
The patent segments the virtual smart card mapping function by introducing a separate IAM client component that handles user identity injection into Kerberos communications. This allows the core virtual smart card storage (limited to 10 cards) to be separated from the user mapping functionality, enabling one virtual smart card to serve multiple users through identity injection rather than creating multiple virtual smart card entries.
Solution Approach 2:
The IAM client acts as an intermediary between the virtual smart card storage system and the Kerberos authentication system. It receives the limited set of virtual smart cards, authenticates users, and then injects user identities into Kerberos communications, enabling the system to overcome the hard cap by mediating between the limited card storage and unlimited user mapping requirements.
2Productivity
If multiple virtual smart cards are stored on a personal computer, then more users can be supported, but performance issues arise due to the hard cap limitation
Solution Approach 1:
The patent extracts the user identity injection functionality from the core virtual smart card storage mechanism. By separating the IAM client component that handles identity injection into Kerberos communications, the system can maintain a limited set of virtual smart cards in the TPM while still supporting multiple users, thus preserving performance stability while improving user support capacity.
Solution Approach 2:
The system changes the parameter of identity representation by injecting user identities dynamically into Kerberos communications rather than storing multiple virtual smart card entries. This parameter change allows the system to maintain a fixed number of virtual smart cards while supporting variable numbers of users, resolving the performance-reliability contradiction.
3Adaptability or versatility
If a single virtual smart card is mapped to multiple users, then user scalability is improved, but security risks increase due to shared credentials
Solution Approach 1:
Instead of creating multiple virtual smart cards for multiple users (traditional approach), the patent inverts the approach by using a single virtual smart card with multiple user identities injected into Kerberos communications. This inversion allows one card to serve multiple users while maintaining security through proper identity injection mechanisms that preserve user distinction during authentication.
Solution Approach 2:
The IAM client serves as a security intermediary that controls how user identities are injected into Kerberos communications. It ensures that while a single virtual smart card is used, each user's identity is properly represented and authenticated, preventing security vulnerabilities that would arise from improper shared credential handling.
Data Source
AI summary
A method, a non-transitory computer readable medium, and a personal computer for mapping a virtual smart card to a plurality of users. The method includes hosting, on a personal computer, an identity and access management (IAM) client, the IAM client configured to store a master virtual smart card for the plurality of users on the personal computer; authenticating, on the personal computer, a first user of the plurality of users; injecting, by the IAM client on the personal computer, an identity of the first user of the plurality of users and a personal identification number of the virtual smart card into a Kerberos communication application programming interface (API) with an Active Directory (AD), the Active Directory (AD) including the plurality of users; and mapping, on the personal computer, the master virtual smart card to the first user of the plurality of users.


