Dynamic Key Cryptography Using Device Minutiae for Mobile Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptography systems face challenges in securely managing and distributing cryptographic keys, particularly on mobile devices, where static keys are vulnerable to attacks and difficult to manage due to the limitations of touch keypads and the inability to alter apps post-installation, leading to inadequate protection of user data and identity verification.
Innovation Solution
Dynamic key cryptography systems utilize a wide range of minutiae such as computer hardware, firmware, software, user secrets, and biometrics to generate cryptographic keys, which are never transmitted and are based on changing device characteristics, providing a more secure and reliable authentication method.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static cryptographic keys are used on mobile devices, then key management is simplified, but security is compromised due to vulnerability to attacks and inability to update keys
Solution Approach 1:
The patent transforms static cryptographic keys into dynamic keys that automatically change over time based on device characteristics and time parameters. This allows the system to maintain security by continuously updating keys without requiring manual intervention or complex key management processes, thus resolving the contradiction between security and complexity.
Solution Approach 2:
The system enables devices to autonomously generate and update their own cryptographic keys using inherent device characteristics (hardware identifiers, software versions, configuration data) without external intervention. This self-service mechanism eliminates the need for complex key distribution and management infrastructure while maintaining strong security.
2Ease of operation
If cryptographic keys are transmitted for distribution, then authentication can be established, but security is compromised due to potential key exposure and interception
Solution Approach 1:
The patent extracts the cryptographic key material directly from device characteristics and time parameters at the point of use, rather than transmitting pre-established keys. This extraction approach eliminates key transmission entirely, allowing authentication to proceed without exposing keys to interception or exposure risks.
Solution Approach 2:
The system introduces time and device characteristics as intermediaries between authentication parties. Instead of directly transmitting keys, these intermediaries mediate the authentication process by serving as the basis for generating equivalent keys on both sides, enabling secure authentication without key exposure.
3Reliability
If complex passwords are used for authentication, then security is improved, but ease of operation deteriorates due to difficulty in entry and memory requirements
Solution Approach 1:
The system replaces manual password creation and memorization with automated key generation based on device characteristics. The device itself serves as the password repository, automatically providing authentication credentials without requiring user memory or complex input, thus resolving the contradiction between security and convenience.
Solution Approach 2:
The patent replaces the mechanical process of manual password entry with automated electronic key generation and verification. This substitution eliminates the need for users to type complex passwords or remember them, while maintaining strong security through cryptographic key-based authentication.
Data Source
AI summary
Dynamic key cryptography validates mobile device users to cloud services by uniquely identifying the user's electronic device using a very wide range of hardware, firmware, and software minutiae, user secrets, and user biometric values found in or collected by the device. Processes for uniquely identifying and validating the device include: selecting a subset of minutia from a plurality of minutia types; computing a challenge from which the user device can form a response based on the selected combination of minutia; computing a set of pre-processed responses that covers a range of all actual responses possible to be received from the device if the combination of the particular device with the device's collected actual values of minutia is valid; receiving an actual response to the challenge from the device; determining whether the actual response matches any of the pre-processed responses; and providing validation, enabling authentication, data protection, and digital signatures.


