Virtual Smart Card Entity for Network Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access security methods in computer networks, particularly those using smart cards, face challenges such as inconvenience in credential management, difficulty in changing security credentials, and delays in physical card delivery, which hinder efficient and secure access to services.

Innovation Solution

A virtual smart card entity is created within a client host to manage credential information, allowing secure access to service provider hosts through a credential management server, with features like ephemeral keys and use restrictions, enabling dynamic and secure access without physical cards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical smart cards are used for access security, then security credentials are securely stored in the circuitry of the smart card, but it is difficult and burdensome to change the credentials of the card and physical card delivery takes too much time

Engineering Contradiction:
Improvesecurity credential storageVSAvoidcredential update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a virtual smart card entity that replicates the security credential storage functionality of physical smart cards in software form. This virtual entity can be instantiated, configured, and updated digitally within the computer network, eliminating the need for physical card delivery and manual credential reprogramming while maintaining secure credential storage capabilities

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/physical smart card system with a software-based virtual smart card entity. Instead of physically distributing and reprogramming smart cards, the system uses digital credential configuration through a credential management server, substituting physical mechanisms with electronic/software mechanisms for credential management

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical smart cards and readers are used for access, then security credentials are securely stored, but a physical chip card and reader at the location where the card is used is needed

Engineering Contradiction:
Improvesecurity credential storageVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The virtual smart card entity replicates the security credential storage and authentication functionality of physical smart cards in software form, allowing credentials to be stored and used within the computer network without requiring physical card readers or hardware tokens at access locations

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a credential management server as an intermediary that handles credential distribution and validation. This server acts as a centralized authority that can issue, manage, and verify credentials for virtual smart card entities, eliminating the need for distributed physical readers while maintaining secure credential verification

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If physical smart cards are delivered to users, then security credentials are provided, but this may take too much time for using some services available over a network

Engineering Contradiction:
Improvesecurity credential provisionVSAvoidservice access speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary credential configuration by pre-establishing the virtual smart card entity framework and credential management infrastructure before actual access is needed. Credentials can be rapidly issued and configured on-demand through the credential management server, eliminating the time required for physical card production and delivery while maintaining secure credential provision

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the physical card delivery mechanism with electronic credential provisioning. Instead of physically shipping cards through logistics channels, the system uses digital credential issuance and configuration through networked computers and servers, dramatically reducing the time from credential request to service access while maintaining security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11095638B2Access security in computer networks
Publication Date: 2021.08.17 SSH COMMUNICATIONS SECURITY
  • US11095638B2 patent drawing
  • US11095638B2 patent drawing
  • US11095638B2 patent drawing

AI summary

A virtual smart card entity enabling a data processing apparatus to request for access to at least one service provider host in the computer network is disclosed. A credential management server provides credential information associated with the virtual smart card entity to the data processing apparatus where after the virtual smart card entity is configured according to the credential information. The data processing apparatus can then send a request for access to at least one service provider host using the configured virtual smart card entity.