Ephemeral Device Transfer Token for Secure Cloud Ownership

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security methods for transferring device ownership in cloud computing environments are insecure, as they rely on user authentication and device attributes that can be spoofed or compromised, making it difficult to manage ownership changes between entities in a secure and reliable manner.

Innovation Solution

The use of an elliptic-curve Diffie-Hellman cryptographic function to generate ephemeral device transfer tokens, which are valid for a limited time, allows secure transfer of ownership by modifying device ownership records upon receipt of these tokens, ensuring only authorized transfers occur.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user authentication and device attributes are used for ownership transfer, then the transfer process is simple and easy to operate, but the security is compromised because these methods can be spoofed

Engineering Contradiction:
Improveownership transfer processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism using cryptographic tokens and trusted authority verification. Instead of directly relying on user-provided credentials that can be spoofed, the system uses an intermediary verification process where a trusted authority generates cryptographic proofs that mediate between the user and the ownership transfer system, ensuring security without complicating the user interface

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/authentication-based system (usernames, passwords, device attributes) with a cryptographic system based on mathematical proofs. The authentication mechanism is substituted from checking user-provided credentials to verifying cryptographic signatures and token validity, which cannot be spoofed if implemented correctly

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If cryptographic token verification is implemented, then security and reliability of ownership transfer are improved, but the system complexity increases

Engineering Contradiction:
Improveownership transfer securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct modular components: token generation by the trusted authority, token transmission through the interface, token verification by the ownership transfer system, and ownership record updating. Each component handles a specific aspect of the cryptographic verification, making the overall complex system manageable through clear separation of concerns

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptographic system is designed to be self-verifying through mathematical proofs. The tokens contain embedded cryptographic evidence that automatically proves authenticity without requiring manual verification steps. The system serves itself by using cryptographic mathematics to inherently validate authentication, reducing the need for complex manual security procedures

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11190346B2Secure device ownership transfer using an ephemeral device transfer token generated using elliptic curve cryptography
Publication Date: 2021.11.30 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US11190346B2 patent drawing
  • US11190346B2 patent drawing
  • US11190346B2 patent drawing

AI summary

One or more device(s) is identified for which ownership of the device(s) is to be transferred from an identified transferor system to an identified transferee system. An ephemeral device transfer token is generated for the transferor using an elliptic-curve Diffie-Hellman cryptographic function, wherein the ephemeral device transfer token is only valid over a limited period of time to authorize a transfer of ownership of the device from the transferor to the transferee. The transferor then delivers the ephemeral device transfer token to the transferee. A device ownership record may be modified to transfer ownership of the device from the transferor to the transferee in response to receiving the ephemeral device transfer token from the transferee during the limited time period.