Trust Broker Authentication for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile devices lack effective mechanisms to manage user privacy preferences during authentication processes, often requiring users to share extensive sensor data without adequate control over what information is shared with authenticating entities.

Innovation Solution

A mobile device system that includes a processor configured to receive authentication requests, determine if they align with user-defined privacy preferences, and form a trust vector from sensor data to securely transmit only authorized information to authenticating entities, using a local trust broker to negotiate and manage privacy and trust vectors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the mobile device transmits comprehensive sensor data for authentication, then the authentication reliability is improved, but the user privacy control deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser privacy control
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments sensor data into multiple categories (biometric data, contextual data, device data) and applies different privacy policies to each category. The trust broker evaluates and selectively transmits only the necessary segments required for authentication, rather than transmitting all sensor data comprehensively. This segmentation allows the system to maintain authentication reliability by including essential data while preserving user privacy control by excluding unnecessary data segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trust broker as an intermediary component that mediates between the sensor data sources and the authentication system. The trust broker evaluates privacy policies, determines which sensor data should be transmitted, and controls the authentication process. This intermediary enables the system to achieve both authentication reliability (by ensuring proper verification) and user privacy control (by filtering data transmission according to user-defined policies).

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the mobile device shares extensive sensor data with authenticating entities, then the authentication accuracy is improved, but the data security deteriorates

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddata security
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements partial action by transmitting only the specific sensor data subsets that are necessary for authentication, rather than transmitting all available sensor data. The trust broker determines the minimum required data set based on privacy policies and authentication requirements. This partial transmission approach maintains authentication accuracy by including essential verification data while improving data security by limiting exposure of unnecessary sensitive information.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If the mobile device implements strict privacy policies for data sharing, then the user privacy control is improved, but the authentication reliability deteriorates

Engineering Contradiction:
Improveuser privacy controlVSAvoidauthentication reliability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent implements dynamic privacy policy evaluation where the trust broker assesses privacy policies in real-time based on the authentication context, user preferences, and required data types. The system dynamically adjusts which sensor data to transmit based on this evaluation, rather than applying static restrictive policies. This dynamic approach allows the system to maintain user privacy control through enforceable policies while preserving authentication reliability by adapting data transmission to meet verification requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3108397B1Trust broker authentication method for mobile devices
Publication Date: 2019.03.20 QUALCOMM INC
  • EP3108397B1 patent drawingFigure 1
  • EP3108397B1 patent drawingFigure 2
  • EP3108397B1 patent drawingFigure 3

AI summary

A mobile device may perform authentication with an authenticating entity. The mobile device may comprise a plurality of sensors and a processor. The processor may be configured to: receive an authentication request from the authenticating entity requesting authentication information; and determine if the authentication request satisfies predefined user privacy preferences. If so, the processor may be configured to: retrieve the authentication information from at least one sensor to form a trust vector in response to the authentication request and to command transmission of the trust vector to the authenticating entity for authentication.