Virtual Smart Card via PC/SC Interface for Software Cryptography
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Most applications, especially those running on Microsoft Windows or Linux, are unable to access virtual smart cards through the PC/SC interface, limiting their ability to utilize one-time passcodes and digital certificates generated by virtual smart card programs, whereas they can access physical smart cards seamlessly.
Innovation Solution
A technique is developed to simulate a hardware token in software, allowing access to a virtual token through the PC/SC interface, which includes deploying an executable cryptographic agent set on a computer to generate cryptographic codes, perform cryptographic operations, and provide digital certificates and keys, thereby enabling access to applications without the need for physical smart cards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a physical smart card is used, then applications can access cryptographic codes through the PC/SC interface, but the system requires physical hardware tokens which limits portability and convenience
Solution Approach 1:
The patent creates a virtual smart card that is a software copy of the physical smart card functionality. The virtual smart card contains the same cryptographic credentials (private keys, certificates, OTP secrets) and can be accessed through the PC/SC interface by generic applications, eliminating the need for physical hardware while maintaining the same security functionality.
Solution Approach 2:
The patent replaces the mechanical/physical smart card hardware system with a software-based virtual smart card system. The virtual smart card agent running in memory provides all cryptographic functions that were previously only available through physical smart cards, substituting mechanical hardware with software execution.
2Adaptability or versatility
If specialized applications with PKCS #11 libraries are used, then virtual smart cards can be accessed, but generic applications running on Windows or Linux cannot access virtual smart cards through the PC/SC interface
Solution Approach 1:
The patent makes the virtual smart card universally accessible to all PC/SC-compatible applications regardless of whether they use specialized libraries like PKCS #11 or are generic Windows/Linux applications. The virtual smart card agent implements the PC/SC interface standard, allowing any application that supports PC/SC to access virtual smart cards without requiring specialized cryptographic libraries.
Solution Approach 2:
The virtual smart card agent acts as an intermediary layer between the cryptographic credentials and PC/SC applications. It translates requests from generic applications into the appropriate cryptographic operations, mediating between the simple PC/SC interface that applications expect and the complex cryptographic operations that need to be performed.
3Ease of operation
If cryptographic operations are performed outside the smart card, then virtual smart cards can be implemented in software, but security may be compromised compared to hardware-based operations
Solution Approach 1:
The virtual smart card creates a software copy of the secure hardware environment. By implementing the same cryptographic algorithms and security protocols in software that are executed in hardware smart cards, the system maintains cryptographic security while providing the flexibility of software implementation. The security relies on the correctness of the software implementation and protection of private keys in memory.
Data Source
AI summary
A technique of providing a cryptographic service on a computer having a processor includes deploying an executable cryptographic agent set on the computer, each executable cryptographic agent from the executable cryptographic agent set being a set of instructions executed on the processor. The technique also includes activating an executable cryptographic agent on the computer, each executable cryptographic agent being constructed and arranged to generate cryptographic codes which change over time in response to activation of the agent. The technique further includes providing, to an application running on the computer, access to the executable cryptographic agent through a Personal Computer/Smart Card (PC/SC) interface of the computer.


