Single Sign-On via Virtual Smart Card for Mobile Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience due to the need for separate authentication processes for local and remote secure applications, often requiring re-authentication even when using the same or similar credentialing mechanisms.

Innovation Solution

A single sign-on mechanism that leverages a mobile device with a virtual smart card to authenticate users across multiple secure applications, using a local wireless connection and public-private key pair for seamless access to remote secure applications without requiring user involvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication processes are used for local and remote secure applications, then security requirements are met, but user convenience deteriorates due to repeated authentication

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the authentication processes for local and remote secure applications into a unified single sign-on mechanism. The mobile device acts as a central authentication authority that coordinates between the local computing system and remote application server, allowing a single authentication event to grant access to both local and remote resources without requiring separate authentication processes.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile device with virtual smart card technology serves multiple functions: it authenticates the user to the local computing system, issues authentication credentials to the remote application server, and manages the single sign-on process across different platforms and applications, replacing multiple specialized authentication mechanisms with a universal solution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication mechanisms are implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device serves as an intermediary that simplifies the overall system architecture. Instead of implementing complex authentication protocols between the local computing system and remote application server, the mobile device mediates the authentication process by issuing credentials and coordinating verification, thereby reducing the complexity of direct system-to-system authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If re-authentication is required for remote applications, then security is maintained, but time efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication through the mobile device before accessing remote applications. The mobile device pre-issues authentication credentials and establishes trust relationships in advance, so that when the user needs to access a remote application, the authentication has already been performed or can be quickly validated without requiring the user to re-enter credentials.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240348596A1Single sign-on using smart credential
Publication Date: 2024.10.17 ENTRUST CORP
  • US20240348596A1 patent drawing
  • US20240348596A1 patent drawing
  • US20240348596A1 patent drawing

AI summary

Methods and systems for facilitating authentication of a user with a plurality of applications are described. One method includes authenticating a user with a first secure application based on information received from a smart credential stored on a mobile device via a local wireless connection. The method includes obtaining a remote challenge from a remote authentication service and a mobile challenge, signing the mobile challenge with a private key, and transmitting a signed version of the mobile challenge, the remote challenge, and a public key to the mobile device. The method further includes receiving a signed version of the remote challenge and a certificate indicating validation of the mobile challenge, and transmitting the signed version of the remote challenge to the remote authentication service. Based on receiving an authentication result from the remote authentication service, access is granted to a remote secure application via the browser.