Cloud Identity Management via Secure Wireless Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile computing device systems lack efficient methods for securely upgrading user accounts and managing user identities across multiple devices, particularly in financial transactions, while ensuring privacy and security.

Innovation Solution

A cloud-based system for storing and managing user profiles, allowing users to securely consolidate private information and authenticate across devices using a unique identifier and password, with encryption and secure communication protocols, enabling secure financial transactions and device management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user identity and profile data are stored locally on mobile devices, then security and privacy are maintained, but device upgrades and identity management across multiple devices become complex and difficult

Engineering Contradiction:
Improveidentity management securityVSAvoiddevice upgrade process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based identity management service as an intermediary between users and their devices. This service stores encrypted user profiles and device identifiers, enabling seamless identity management across devices without requiring local storage of sensitive data. The cloud service acts as a mediator that facilitates secure device upgrades and multi-device access while maintaining security and privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If user profiles are stored in the cloud, then device upgrades and multi-device access become seamless, but security and privacy risks increase

Engineering Contradiction:
Improveidentity management processVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a cryptographic copying mechanism where the user's identity is represented by multiple device identifiers that can be associated with different devices. The cloud service stores encrypted copies of profile data linked to these identifiers, allowing seamless access across devices without exposing the actual identity data. This copying approach enables ease of operation while maintaining security through encryption and distributed identifier management.

Inventive Principle:
Principle #26Copying

3Reliability

If traditional authentication methods are used for financial transactions, then security is maintained, but transaction speed and user convenience are reduced

Engineering Contradiction:
Improvetransaction securityVSAvoidtransaction processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication by associating device identifiers with user profiles in advance through the cloud-based identity management service. When a financial transaction is initiated, the pre-established trust relationship between the device identifier and user profile enables rapid authentication without requiring traditional multi-step verification processes. This preliminary action maintains security while significantly improving transaction processing speed and user convenience.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2577551B1Identity management via cloud
Publication Date: 2021.11.03 QUALCOMM INC
  • EP2577551B1 patent drawingFigure 1
  • EP2577551B1 patent drawingFigure 2
  • EP2577551B1 patent drawingFigure 3

AI summary

A system and method of maintaining a user profile for a handheld computer in a shared, scalable computing resource is described. The method includes receiving user profile data from the handheld computer at the shared, scalable computing resource, the user profile data comprising a user security factor. The user profile data is received via a secure wireless communication protocol having authentication of an identity of the handheld computer. The method includes storing the user profile data on the shared, scalable computing resource as a portion of a user profile, the user profile further comprising user preference data. The method further includes receiving the user security factor from a second computing device. The user security factor is received via a secure wireless communication protocol having authentication of an identity of the second computing device. The method further includes downloading user preference data to the second computing device.