Mobile Device Key Generation via Biometric Entropy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices lack effective methods for generating secure keys and protecting sensitive assets, as existing PIN- or passcode-based authentication systems have low entropy, making them vulnerable to attacks and lacking hardware-based security measures like a hardware root of trust.
Innovation Solution
A method that generates and processes cryptographic information by incorporating interface manipulation measures, such as directionality and velocity, to enhance the entropy of key generation on mobile devices, learning patterns over multiple iterations to update and secure the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If PIN- or passcode-based authentication is used on mobile devices, then ease of operation is improved, but security reliability deteriorates due to low entropy
Solution Approach 1:
The patent transforms the authentication process by changing parameters from simple static PIN/passcode entry to dynamic biometric data collection. The system captures multiple biometric parameters (facial features, iris patterns, voice characteristics) and combines them with interface manipulation measures (swipe directionality, tap velocity, press duration) to generate high-entropy cryptographic keys, thereby dramatically improving security while maintaining ease of operation through natural biometric authentication.
Solution Approach 2:
The patent creates a composite authentication system that combines multiple previously separate security elements: biometric data (facial recognition, iris scanning, voice authentication), interface manipulation measures (user interaction patterns), and cryptographic processing. This composite approach integrates diverse data sources with different security characteristics to produce a unified authentication mechanism with substantially higher entropy and security strength than any single component alone.
2Reliability
If hardware security modules are implemented, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent enables the mobile device to generate its own cryptographic keys using built-in sensors and processors without requiring external hardware security modules. The system leverages existing biometric sensors (camera, microphone, touch screen) and the device's own cryptographic processing capabilities to perform key generation, making the security system self-sufficient and eliminating the need for additional hardware components.
Solution Approach 2:
The patent replaces the mechanical hardware-based security module with a software-based cryptographic system that uses biometric data and interface manipulation measures as input entropy sources. Instead of relying on physical hardware tokens or secure elements, the system substitutes these with computational methods that derive cryptographic keys from behavioral and biometric patterns captured through the device's existing sensors and interface.
3Stability of the object's composition
If stable system values like IMSI are used for key generation, then key stability is improved, but adaptability deteriorates as they are isolated from developers
Solution Approach 1:
The patent creates a universal key generation system that can serve multiple applications and developers while maintaining stability. The biometric-based cryptographic module provides a common platform that generates consistent keys for various apps and services, yet remains accessible to developers through standardized interfaces and APIs, enabling them to integrate secure authentication without requiring isolated system values.
Data Source
AI summary
Methods, apparatus and articles of manufacture for adding entropy to key generation on a mobile device are provided herein. A method includes generating a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device; processing input cryptographic information entered via the computing device interface in response to the prompt against a pre-determined set of cryptographic information, wherein said pre-determined set of cryptographic information comprises one or more input elements and one or more interface manipulation measures associated with the one or more input elements; and resolving the authentication request based on said processing.


