Mobile Device Key Generation via Biometric Entropy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices lack effective methods for generating secure keys and protecting sensitive assets, as existing PIN- or passcode-based authentication systems have low entropy, making them vulnerable to attacks and lacking hardware-based security measures like a hardware root of trust.

Innovation Solution

A method that generates and processes cryptographic information by incorporating interface manipulation measures, such as directionality and velocity, to enhance the entropy of key generation on mobile devices, learning patterns over multiple iterations to update and secure the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If PIN- or passcode-based authentication is used on mobile devices, then ease of operation is improved, but security reliability deteriorates due to low entropy

Engineering Contradiction:
Improveauthentication usabilityVSAvoidsecurity strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms the authentication process by changing parameters from simple static PIN/passcode entry to dynamic biometric data collection. The system captures multiple biometric parameters (facial features, iris patterns, voice characteristics) and combines them with interface manipulation measures (swipe directionality, tap velocity, press duration) to generate high-entropy cryptographic keys, thereby dramatically improving security while maintaining ease of operation through natural biometric authentication.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a composite authentication system that combines multiple previously separate security elements: biometric data (facial recognition, iris scanning, voice authentication), interface manipulation measures (user interaction patterns), and cryptographic processing. This composite approach integrates diverse data sources with different security characteristics to produce a unified authentication mechanism with substantially higher entropy and security strength than any single component alone.

Inventive Principle:
Principle #40Composite materials

2Reliability

If hardware security modules are implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvehardware-based securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the mobile device to generate its own cryptographic keys using built-in sensors and processors without requiring external hardware security modules. The system leverages existing biometric sensors (camera, microphone, touch screen) and the device's own cryptographic processing capabilities to perform key generation, making the security system self-sufficient and eliminating the need for additional hardware components.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical hardware-based security module with a software-based cryptographic system that uses biometric data and interface manipulation measures as input entropy sources. Instead of relying on physical hardware tokens or secure elements, the system substitutes these with computational methods that derive cryptographic keys from behavioral and biometric patterns captured through the device's existing sensors and interface.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Stability of the object's composition

If stable system values like IMSI are used for key generation, then key stability is improved, but adaptability deteriorates as they are isolated from developers

Engineering Contradiction:
Improvekey consistencyVSAvoiddeveloper access
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal key generation system that can serve multiple applications and developers while maintaining stability. The biometric-based cryptographic module provides a common platform that generates consistent keys for various apps and services, yet remains accessible to developers through standardized interfaces and APIs, enabling them to integrate secure authentication without requiring isolated system values.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9407441B1Adding entropy to key generation on a mobile device
Publication Date: 2016.08.02 RSA SECURITY USA LLC
  • US9407441B1 patent drawing
  • US9407441B1 patent drawing
  • US9407441B1 patent drawing

AI summary

Methods, apparatus and articles of manufacture for adding entropy to key generation on a mobile device are provided herein. A method includes generating a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device; processing input cryptographic information entered via the computing device interface in response to the prompt against a pre-determined set of cryptographic information, wherein said pre-determined set of cryptographic information comprises one or more input elements and one or more interface manipulation measures associated with the one or more input elements; and resolving the authentication request based on said processing.