3D Cloud Lock Spatial Authentication for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing architectures face inadequate security measures, particularly in protecting against unauthorized access and data subversion, especially when users access cloud services through powerful browsers that can be exploited by unauthorized users.

Innovation Solution

The 3D Cloud Lock system employs remote rendering of 3D password elements, where users manipulate and authenticate 3D projections of data, ensuring only authorized users can access cloud resources by matching customized 3D projections, thereby enhancing security and reducing the risk of subversion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access cloud services through browsers, then ease of operation is improved, but security is worsened due to browser subversion risks

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a 3D lock intermediary system between the browser and cloud service. This mediator presents 3D password elements that authenticate users without exposing the browser to direct cloud service risks. The intermediary validates 3D manipulations locally before communicating with the cloud, preventing browser subversion from compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from traditional 2D password interfaces to 3D password elements that require spatial manipulation. Users interact with 3D objects that can be rotated, scaled, and positioned in three-dimensional space, creating a higher-dimensional authentication space that is more resistant to subversion while maintaining usability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If cloud providers remove pointers to data as deletion method, then ease of manufacture is improved, but security is worsened as data remains exposed on physical media

Engineering Contradiction:
Improveease of data deletionVSAvoiddata exposure risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive data from direct cloud storage and embeds it within 3D password element structures. By taking data out of traditional storage formats and encoding it within 3D object properties, the system enables secure deletion through 3D model destruction while preventing data recovery even if physical media is accessed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent combines data with 3D geometric structures to create composite information carriers. Data is embedded within the topology, coordinates, or texture mappings of 3D models, creating a composite structure where data recovery requires reconstructing the entire 3D object, thereby preventing simple data extraction from physical media.

Inventive Principle:
Principle #40Composite materials

3Reliability

If 3D password elements are used for authentication, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses 3D model copying and transformation operations as the basis for authentication. Instead of complex cryptographic protocols, the system relies on users manipulating copies of 3D password elements through standard geometric transformations (rotation, translation, scaling), simplifying the underlying mechanism while maintaining security through the complexity of 3D spatial reasoning.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2750351B13D cloud lock
Publication Date: 2018.08.01 DASSAULT SYSTEMES SA
  • EP2750351B1 patent drawingFigure 1
  • EP2750351B1 patent drawingFigure 2
  • EP2750351B1 patent drawingFigure 3A

AI summary

In embodiments, a method of securing access to a computer memory and other computer resources includes authoring a 3D projection of data by a registering user customizing elements in the 3D projection, resulting in a registered 3D projection. The method further includes presenting to a requesting user a representation of the elements of the 3D projection in a randomized fashion. The method additionally includes receiving, from the requesting user, manipulations of the presented elements of the 3D projection toward undoing or solving the randomization. The method includes determining whether the manipulated elements of the 3D projection match the customized elements of the registered 3D projection. Then, the method includes granting, to the registered user, access to the computer memory if the manipulated elements of the 3D projection match the customized elements of the registered 3D projection. The granting may be based on the determination of whether the manipulated elements of the 3D projection match the customized elements of the registered 3D projection in the positive.