Time-Based Cryptographic Key Generation for Mobile Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security software for mobile devices relies on limited two-factor authentication, making it vulnerable to reverse engineering, password capture, and brute force attacks, leading users to avoid storing sensitive information due to the lack of robust protection.
Innovation Solution
A low-cost software-only three-factor authentication system that uses a time-based cryptographic technique, generating a unique encryption key based on personal date and time of birth, synchronized with user registration, requiring human intervention and secure online authentication to ensure data security on mobile devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-factor authentication is used, then device simplicity is maintained, but security reliability is insufficient
Solution Approach 1:
The patent introduces a biometric template as an intermediary element that bridges the gap between simple password authentication and complex hardware biometric systems. The template is processed locally on the device using cryptographic operations, serving as a mediator that enhances security without requiring expensive external hardware components.
Solution Approach 2:
The patent replaces physical hardware biometric systems with a software-based cryptographic approach. Instead of using complex hardware sensors and processing units for biometric verification, the system uses mathematical operations on biometric templates stored and processed within the existing device software environment, thereby maintaining simplicity while improving security.
2Reliability
If hardware biometric authentication is implemented, then security reliability improves, but device cost increases
Solution Approach 1:
The patent creates a functional copy of hardware biometric authentication capabilities through software. Instead of implementing physical biometric sensors and dedicated hardware processing units, the system copies the essential security function by performing cryptographic operations on biometric templates using the device's existing processor, thereby achieving similar security outcomes without the associated hardware costs.
Solution Approach 2:
The patent uses computationally intensive but temporary cryptographic operations to achieve security equivalent to expensive hardware systems. The biometric template matching is performed as a transient computational process rather than through permanent hardware infrastructure, allowing high security with minimal additional cost to the device.
3Adaptability or versatility
If hardware biometric sensors are added, then authentication capability improves, but device adaptability decreases
Solution Approach 1:
The patent implements a dynamic authentication system where the biometric template can be updated, regenerated, or replaced through software operations. This dynamic approach allows the authentication capability to adapt and improve over time without requiring physical hardware modifications, as the system can flexibly adjust its security parameters through cryptographic operations.
Solution Approach 2:
The patent makes the existing device processor serve multiple functions: it handles both standard application processing and biometric template verification. By designing the authentication mechanism to utilize the device's existing computational resources, the system achieves enhanced authentication capability without adding specialized hardware components, thereby maintaining device versatility and reducing complexity.
Data Source
AI summary
A remote device secure data file storage system and method of securely storing data files at a remote device, includes a host system having a database and a plurality of remote devices, each connected with the host system by a communication network. Each remote device and the host system is programmed with a time-based cryptography system that generates an encryption key (RVK) and initialization vector (IV) for encrypting and decrypting data on the remote device. The time-based cryptography system generates the encryption key (RVK) as a function of a parameter (PDPT) that is a function of a personal date (PD) and personal time (PT) of the user. The personal date and personal time of the user being a function of personal data entered by the user on the remote device. The personal date (PD) is a function of the date of birth (DOB) of the user and the personal time (PT) is a function of the time of birth (TOB) of the user.


