Dynamic Key Cryptography for Mobile Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptography systems face challenges in securely managing and distributing cryptographic keys, particularly on mobile devices, where static keys can be easily compromised, leading to inadequate protection of user data and identity verification.
Innovation Solution
Dynamic key cryptography systems utilize a wide range of minutiae such as computer hardware, firmware, software, user secrets, and biometrics to generate cryptographic keys, which are never transmitted and are based on changing device characteristics, providing a more secure and reliable authentication method.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static cryptographic keys are used for authentication, then the authentication process is simple, but the security is inadequate and keys can be easily compromised
Solution Approach 1:
The patent transforms static cryptographic keys into dynamic keys that automatically change over time based on device characteristics and time parameters. This dynamic key generation resolves the contradiction by providing continuously evolving security (improving reliability) while the automation of key changes eliminates manual key management complexity (maintaining ease of operation).
Solution Approach 2:
The system implements self-service through automated key generation and rotation based on device-specific characteristics and time parameters. The cryptographic keys are automatically updated without user intervention, resolving the contradiction by enhancing security through continuous key evolution while eliminating the burden of manual key management.
2Ease of operation
If cryptographic keys are distributed and stored on client computers, then authentication can be performed, but the keys become vulnerable to copying and impersonation
Solution Approach 1:
The patent implements dynamic keys that are valid only for specific time periods and are tied to specific device characteristics. This temporal and contextual binding resolves the contradiction by enabling authentication functionality while preventing key copying and impersonation, as compromised keys become invalid after their time period expires or when device characteristics change.
Solution Approach 2:
The system changes key parameters over time and based on device characteristics, transforming static keys into time-limited, context-dependent credentials. This resolves the contradiction by maintaining authentication capability while eliminating the risk of long-term key compromise and impersonation.
3Reliability
If traditional two-factor authentication with PIN and secure element is used, then access control is improved, but there is no implicit binding between the key and the user
Solution Approach 1:
The patent merges multiple identification factors (device characteristics, time parameters, user behavior patterns) into a single dynamic key that inherently binds the cryptographic credential to the specific user and device combination. This resolves the contradiction by maintaining strong access control while establishing implicit user-key binding through the integrated multi-factor key generation process.
Solution Approach 2:
The dynamic key functions as a composite credential combining multiple identification elements (hardware characteristics, software identifiers, temporal data, behavioral patterns). This composite structure resolves the contradiction by providing both security through multi-factor integration and implicit user binding through the unique combination of characteristics that change over time.
4Reliability
If certificates are used to bind user identity with cryptographic key, then identity verification is enabled, but the key remains a random number with no relation to the user
Solution Approach 1:
The patent transforms random cryptographic keys into meaningful keys derived from actual device characteristics and user-specific parameters. This resolves the contradiction by enabling identity verification through keys that inherently contain user-related information, eliminating the need for separate certificate binding mechanisms.
Solution Approach 2:
Instead of using random keys that require certificate binding, the system creates keys that are natural copies or representations of device and user characteristics. This resolves the contradiction by making the cryptographic key itself meaningful and directly related to user identity, eliminating the need for separate identity binding infrastructure.
Data Source
AI summary
Dynamic key cryptography validates mobile device users to cloud services by uniquely identifying the user's electronic device using a very wide range of hardware, firmware, and software minutiae, user secrets, and user biometric values found in or collected by the device. Processes for uniquely identifying and validating the device include: selecting a subset of minutia from a plurality of minutia types; computing a challenge from which the user device can form a response based on the selected combination of minutia; computing a set of pre-processed responses that covers a range of all actual responses possible to be received from the device if the combination of the particular device with the device's collected actual values of minutia is valid; receiving an actual response to the challenge from the device; determining whether the actual response matches any of the pre-processed responses; and providing validation, enabling authentication, data protection, and digital signatures.


