Dynamic Key Cryptography for Mobile Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptography systems face challenges in securely managing and distributing cryptographic keys, particularly on mobile devices, where static keys can be easily compromised, leading to inadequate protection of user data and identity verification.

Innovation Solution

Dynamic key cryptography systems utilize a wide range of minutiae such as computer hardware, firmware, software, user secrets, and biometrics to generate cryptographic keys, which are never transmitted and are based on changing device characteristics, providing a more secure and reliable authentication method.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static cryptographic keys are used for authentication, then the authentication process is simple, but the security is inadequate and keys can be easily compromised

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static cryptographic keys into dynamic keys that automatically change over time based on device characteristics and time parameters. This dynamic key generation resolves the contradiction by providing continuously evolving security (improving reliability) while the automation of key changes eliminates manual key management complexity (maintaining ease of operation).

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements self-service through automated key generation and rotation based on device-specific characteristics and time parameters. The cryptographic keys are automatically updated without user intervention, resolving the contradiction by enhancing security through continuous key evolution while eliminating the burden of manual key management.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If cryptographic keys are distributed and stored on client computers, then authentication can be performed, but the keys become vulnerable to copying and impersonation

Engineering Contradiction:
Improveauthentication capabilityVSAvoidkey compromise risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic keys that are valid only for specific time periods and are tied to specific device characteristics. This temporal and contextual binding resolves the contradiction by enabling authentication functionality while preventing key copying and impersonation, as compromised keys become invalid after their time period expires or when device characteristics change.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes key parameters over time and based on device characteristics, transforming static keys into time-limited, context-dependent credentials. This resolves the contradiction by maintaining authentication capability while eliminating the risk of long-term key compromise and impersonation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional two-factor authentication with PIN and secure element is used, then access control is improved, but there is no implicit binding between the key and the user

Engineering Contradiction:
Improveaccess control securityVSAvoiduser identity binding
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges multiple identification factors (device characteristics, time parameters, user behavior patterns) into a single dynamic key that inherently binds the cryptographic credential to the specific user and device combination. This resolves the contradiction by maintaining strong access control while establishing implicit user-key binding through the integrated multi-factor key generation process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The dynamic key functions as a composite credential combining multiple identification elements (hardware characteristics, software identifiers, temporal data, behavioral patterns). This composite structure resolves the contradiction by providing both security through multi-factor integration and implicit user binding through the unique combination of characteristics that change over time.

Inventive Principle:
Principle #40Composite materials

4Reliability

If certificates are used to bind user identity with cryptographic key, then identity verification is enabled, but the key remains a random number with no relation to the user

Engineering Contradiction:
Improveidentity verificationVSAvoidkey material meaningfulness
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms random cryptographic keys into meaningful keys derived from actual device characteristics and user-specific parameters. This resolves the contradiction by enabling identity verification through keys that inherently contain user-related information, eliminating the need for separate certificate binding mechanisms.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of using random keys that require certificate binding, the system creates keys that are natural copies or representations of device and user characteristics. This resolves the contradiction by making the cryptographic key itself meaningful and directly related to user identity, eliminating the need for separate identity binding infrastructure.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10178076B2Cryptographic security functions based on anticipated changes in dynamic minutiae
Publication Date: 2019.01.08 MSIGNIA
  • US10178076B2 patent drawing
  • US10178076B2 patent drawing
  • US10178076B2 patent drawing

AI summary

Dynamic key cryptography validates mobile device users to cloud services by uniquely identifying the user's electronic device using a very wide range of hardware, firmware, and software minutiae, user secrets, and user biometric values found in or collected by the device. Processes for uniquely identifying and validating the device include: selecting a subset of minutia from a plurality of minutia types; computing a challenge from which the user device can form a response based on the selected combination of minutia; computing a set of pre-processed responses that covers a range of all actual responses possible to be received from the device if the combination of the particular device with the device's collected actual values of minutia is valid; receiving an actual response to the challenge from the device; determining whether the actual response matches any of the pre-processed responses; and providing validation, enabling authentication, data protection, and digital signatures.