Mobile Device Authentication via Provisioned Cryptographic Nonces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptography protocols for mobile devices fail to effectively verify the identity of the legitimate owner, leading to potential unauthorized access and misuse, particularly in applications where authentication is crucial for secure transactions and data exchange.

Innovation Solution

The implementation of a cryptographic protocol that utilizes provisioning keys, tokens, and nonces, combined with biometric data, to establish secure communication channels between mobile devices and access points, ensuring that only the legitimate owner can authenticate and authorize transactions, through a process involving key exchanges, encryption, and biometric verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for portable devices, then the system is simple and easy to operate, but the security and reliability of identity verification is insufficient

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary provisioning of cryptographic keys and credentials to portable devices before actual authentication occurs. During device provisioning, unique identifiers, public keys, and cryptographic credentials are pre-configured in the device's secure element. This preliminary setup enables rapid, secure authentication during actual use without requiring complex real-time key exchange or credential verification procedures, thus improving reliability while maintaining operational simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic protocols and secure authentication intermediaries that mediate between the portable device and the authentication system. Instead of direct trust relationships, cryptographic keys, digital signatures, and secure tokens act as intermediaries to verify device identity and authorization. This intermediary layer enhances verification reliability through cryptographic proof while abstracting the complexity from end users, allowing them to interact with simple authentication interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic verification is implemented to verify legitimate device ownership, then security and authentication reliability improve, but the complexity of the authentication system increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication operation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication mechanisms where the portable device autonomously performs cryptographic verification operations using its embedded secure element and pre-provisioned credentials. The device automatically generates digital signatures, verifies authentication tokens, and manages cryptographic keys without requiring user intervention for complex cryptographic operations. This self-service capability maintains high security through cryptographic verification while preserving ease of operation, as users simply need to present the device for automatic authentication.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Complex cryptographic credentials, key pairs, and authentication certificates are pre-configured in the device during manufacturing or initial provisioning. This preliminary setup eliminates the need for users to manually manage cryptographic materials or understand complex authentication protocols during operation. The device automatically utilizes these pre-configured credentials for secure verification, thereby maintaining authentication security while simplifying user interaction to basic device presentation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If biometric data and cryptographic keys are combined for authentication, then the reliability of owner verification is significantly improved, but the computational requirements and energy consumption increase

Engineering Contradiction:
Improveowner verification reliabilityVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the authentication system into distinct functional components: biometric data collection and processing, cryptographic key generation and storage, and authentication verification. Biometric templates are stored in secure hardware, while cryptographic operations are performed separately using pre-provisioned keys. This segmentation allows the system to leverage hardware-accelerated biometric matching for reliable verification while minimizing computational overhead for cryptographic operations, thereby improving owner verification reliability while controlling energy consumption through efficient resource utilization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces computationally intensive cryptographic operations with hardware-based secure element operations and optimized algorithms. Instead of performing full cryptographic key exchanges or complex mathematical computations, the system utilizes hardware-accelerated biometric matching and pre-computed cryptographic signatures stored in the device's secure element. This substitution of mechanical/computational processes with hardware-based operations significantly reduces energy consumption while maintaining high verification reliability through accurate biometric and cryptographic validation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9032501B1Cryptographic protocol for portable devices
Publication Date: 2015.05.12 NYMI
  • US9032501B1 patent drawing
  • US9032501B1 patent drawing
  • US9032501B1 patent drawing

AI summary

Embodiments are directed towards communicating using a mobile device that performs actions including. A mobile device may be provisioned with an access point such that a provisioning key and a provisioning token for each of the provisioned access points may be stored on the mobile device. The mobile device may be determined to be in the presence of a provisioned access point based on the provisioning key and an advertising nonce. The advertising nonce may be encrypted with the provisioning key. A communication channel between the mobile device and the access point may be established based on a session nonce, the advertising nonce, and the provisioning key. A session key may be generated based in part on the advertising nonce and a message counter. And, encrypted message packets that include a message and a message authentication tag may be communicated to the access point.