Virtual Smart Card Server Key Management Auditing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional smart cards are susceptible to loss, theft, and unauthorized use, and they hinder auditing processes due to limited visibility and control over private key management in public key infrastructure (PKI) systems, especially when employees leave the organization.
Innovation Solution
A virtual smart card system with a centralized virtual smart card server (VSS) manages and secures private keys, providing controlled access and auditing capabilities, ensuring secure authentication and authorization through user-level and system-level agents, and maintaining secure audit logs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional smart cards are used for authentication and private key storage, then hardware-based security protection is improved, but the system becomes susceptible to loss, theft, and unauthorized use when physical control is lost
Solution Approach 1:
The patent creates a virtual copy of the smart card functionality through software-based virtual smart card agents that run on trusted computing platforms. Instead of relying on a physical token, the system uses virtual representations of smart card capabilities that can be securely managed and revoked remotely, eliminating the risk of physical loss or theft while maintaining authentication and encryption functions.
Solution Approach 2:
The patent introduces a virtual smart card server and trusted platform as intermediaries between the user and the authentication system. The private key never leaves the secure virtual environment, and all operations are mediated through the virtual smart card agent on the trusted platform, providing an additional layer of security control that prevents unauthorized use even when physical access is compromised.
2Reliability
If conventional smart cards are used for authentication, then security control is improved, but auditing capability and visibility of private key usage is worsened
Solution Approach 1:
The patent implements comprehensive logging and auditing mechanisms that provide feedback on all virtual smart card operations. The virtual smart card agent records detailed information about authentication events, private key usage, and system interactions, enabling complete audit trails that enhance visibility and accountability without compromising security.
Solution Approach 2:
The virtual smart card system integrates multiple functions including authentication, encryption, and auditing within a single unified platform. The virtual smart card agent not only performs security functions but also automatically logs all operations, eliminating the need for separate proprietary auditing systems and providing comprehensive visibility across all private key usage.
3Loss of information
If virtual smart card system is implemented with centralized server control, then auditing capability and key management control are improved, but system complexity and infrastructure requirements are worsened
Solution Approach 1:
The patent combines the virtual smart card server, trusted platform modules, and logging infrastructure into an integrated system architecture. By merging these components and leveraging existing trusted computing platform capabilities, the system reduces overall complexity compared to maintaining separate proprietary smart card systems while still providing comprehensive auditing and control.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Virtual smart card system includes a virtual smart card server (VSS) which controls access to content respectively associated with a plurality of virtual smart cards. A remote client computer system includes a system level agent which establishes the client computer machine to the VSS as a trusted computer system. A user level agent at the client computer system responds to a request for a virtual smart card operation by causing the client computer system to obtain user authentication information, negotiate with the system level agent to obtain a cookie, and initiate a request to the VSS for the virtual smart card operation. The VSS will perform the virtual smart card operation provided that a security policy is satisfied and will communicate the results to the user level agent.