Mobile Device Authentication via Provisioned Cryptographic Nonces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptography protocols for mobile devices fail to effectively verify the identity of the legitimate owner, leading to potential unauthorized access and misuse, particularly in applications where authentication is crucial for secure transactions and data exchange.
Innovation Solution
The implementation of a cryptographic protocol that utilizes provisioning keys, tokens, and nonces, combined with biometric data, to establish secure communication channels between mobile devices and access points, ensuring that only the legitimate owner can authenticate and authorize transactions, through a process involving key exchanges, encryption, and biometric verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used for portable devices, then the system is simple and easy to operate, but the security and reliability of identity verification is insufficient
Solution Approach 1:
The patent implements preliminary provisioning of cryptographic keys and credentials to portable devices before actual authentication occurs. During device provisioning, unique identifiers, public keys, and cryptographic credentials are pre-configured in the device's secure element. This preliminary setup enables rapid, secure authentication during actual use without requiring complex real-time key exchange or credential verification procedures, thus improving reliability while maintaining operational simplicity.
Solution Approach 2:
The patent introduces cryptographic protocols and secure authentication intermediaries that mediate between the portable device and the authentication system. Instead of direct trust relationships, cryptographic keys, digital signatures, and secure tokens act as intermediaries to verify device identity and authorization. This intermediary layer enhances verification reliability through cryptographic proof while abstracting the complexity from end users, allowing them to interact with simple authentication interfaces.
2Reliability
If cryptographic verification is implemented to verify legitimate device ownership, then security and authentication reliability improve, but the complexity of the authentication system increases
Solution Approach 1:
The patent implements self-service authentication mechanisms where the portable device autonomously performs cryptographic verification operations using its embedded secure element and pre-provisioned credentials. The device automatically generates digital signatures, verifies authentication tokens, and manages cryptographic keys without requiring user intervention for complex cryptographic operations. This self-service capability maintains high security through cryptographic verification while preserving ease of operation, as users simply need to present the device for automatic authentication.
Solution Approach 2:
Complex cryptographic credentials, key pairs, and authentication certificates are pre-configured in the device during manufacturing or initial provisioning. This preliminary setup eliminates the need for users to manually manage cryptographic materials or understand complex authentication protocols during operation. The device automatically utilizes these pre-configured credentials for secure verification, thereby maintaining authentication security while simplifying user interaction to basic device presentation.
3Reliability
If biometric data and cryptographic keys are combined for authentication, then the reliability of owner verification is significantly improved, but the computational requirements and energy consumption increase
Solution Approach 1:
The patent segments the authentication system into distinct functional components: biometric data collection and processing, cryptographic key generation and storage, and authentication verification. Biometric templates are stored in secure hardware, while cryptographic operations are performed separately using pre-provisioned keys. This segmentation allows the system to leverage hardware-accelerated biometric matching for reliable verification while minimizing computational overhead for cryptographic operations, thereby improving owner verification reliability while controlling energy consumption through efficient resource utilization.
Solution Approach 2:
The patent replaces computationally intensive cryptographic operations with hardware-based secure element operations and optimized algorithms. Instead of performing full cryptographic key exchanges or complex mathematical computations, the system utilizes hardware-accelerated biometric matching and pre-computed cryptographic signatures stored in the device's secure element. This substitution of mechanical/computational processes with hardware-based operations significantly reduces energy consumption while maintaining high verification reliability through accurate biometric and cryptographic validation.
Data Source
AI summary
Embodiments are directed towards communicating using a mobile device that performs actions including. A mobile device may be provisioned with an access point such that a provisioning key and a provisioning token for each of the provisioned access points may be stored on the mobile device. The mobile device may be determined to be in the presence of a provisioned access point based on the provisioning key and an advertising nonce. The advertising nonce may be encrypted with the provisioning key. A communication channel between the mobile device and the access point may be established based on a session nonce, the advertising nonce, and the provisioning key. A session key may be generated based in part on the advertising nonce and a message counter. And, encrypted message packets that include a message and a message authentication tag may be communicated to the access point.


