Virtual Smart Card Entity for Network Access Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access security methods in computer networks, particularly those using smart cards, face challenges such as inconvenience in credential management, difficulty in changing security credentials, and delays in physical card delivery, which hinder efficient and secure access to services.
Innovation Solution
A virtual smart card entity is created within a client host to manage credential information, allowing secure access to service provider hosts through a credential management server, with features like ephemeral keys and use restrictions, enabling dynamic and secure access without physical cards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical smart cards are used for access security, then security credentials are securely stored in the circuitry of the smart card, but it is difficult and burdensome to change the credentials of the card and physical card delivery takes too much time
Solution Approach 1:
The patent creates a virtual smart card entity that replicates the security credential storage functionality of physical smart cards in software form. This virtual entity can be instantiated, configured, and updated digitally within the computer network, eliminating the need for physical card delivery and manual credential reprogramming while maintaining secure credential storage capabilities
Solution Approach 2:
The patent replaces the mechanical/physical smart card system with a software-based virtual smart card entity. Instead of physically distributing and reprogramming smart cards, the system uses digital credential configuration through a credential management server, substituting physical mechanisms with electronic/software mechanisms for credential management
2Reliability
If physical smart cards and readers are used for access, then security credentials are securely stored, but a physical chip card and reader at the location where the card is used is needed
Solution Approach 1:
The virtual smart card entity replicates the security credential storage and authentication functionality of physical smart cards in software form, allowing credentials to be stored and used within the computer network without requiring physical card readers or hardware tokens at access locations
Solution Approach 2:
The patent introduces a credential management server as an intermediary that handles credential distribution and validation. This server acts as a centralized authority that can issue, manage, and verify credentials for virtual smart card entities, eliminating the need for distributed physical readers while maintaining secure credential verification
3Reliability
If physical smart cards are delivered to users, then security credentials are provided, but this may take too much time for using some services available over a network
Solution Approach 1:
The system performs preliminary credential configuration by pre-establishing the virtual smart card entity framework and credential management infrastructure before actual access is needed. Credentials can be rapidly issued and configured on-demand through the credential management server, eliminating the time required for physical card production and delivery while maintaining secure credential provision
Solution Approach 2:
The patent replaces the physical card delivery mechanism with electronic credential provisioning. Instead of physically shipping cards through logistics channels, the system uses digital credential issuance and configuration through networked computers and servers, dramatically reducing the time from credential request to service access while maintaining security
Data Source
AI summary
A virtual smart card entity enabling a data processing apparatus to request for access to at least one service provider host in the computer network is disclosed. A credential management server provides credential information associated with the virtual smart card entity to the data processing apparatus where after the virtual smart card entity is configured according to the credential information. The data processing apparatus can then send a request for access to at least one service provider host using the configured virtual smart card entity.


