Trust Broker Authentication for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile devices lack effective mechanisms to manage user privacy preferences during authentication processes, often requiring users to share extensive sensor data without adequate control over what information is shared with authenticating entities.
Innovation Solution
A mobile device system that includes a processor configured to receive authentication requests, determine if they align with user-defined privacy preferences, and form a trust vector from sensor data to securely transmit only authorized information to authenticating entities, using a local trust broker to negotiate and manage privacy and trust vectors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the mobile device transmits comprehensive sensor data for authentication, then the authentication reliability is improved, but the user privacy control deteriorates
Solution Approach 1:
The patent segments sensor data into multiple categories (biometric data, contextual data, device data) and applies different privacy policies to each category. The trust broker evaluates and selectively transmits only the necessary segments required for authentication, rather than transmitting all sensor data comprehensively. This segmentation allows the system to maintain authentication reliability by including essential data while preserving user privacy control by excluding unnecessary data segments.
Solution Approach 2:
The patent introduces a trust broker as an intermediary component that mediates between the sensor data sources and the authentication system. The trust broker evaluates privacy policies, determines which sensor data should be transmitted, and controls the authentication process. This intermediary enables the system to achieve both authentication reliability (by ensuring proper verification) and user privacy control (by filtering data transmission according to user-defined policies).
2Measurement precision
If the mobile device shares extensive sensor data with authenticating entities, then the authentication accuracy is improved, but the data security deteriorates
Solution Approach 1:
The patent implements partial action by transmitting only the specific sensor data subsets that are necessary for authentication, rather than transmitting all available sensor data. The trust broker determines the minimum required data set based on privacy policies and authentication requirements. This partial transmission approach maintains authentication accuracy by including essential verification data while improving data security by limiting exposure of unnecessary sensitive information.
3Loss of information
If the mobile device implements strict privacy policies for data sharing, then the user privacy control is improved, but the authentication reliability deteriorates
Solution Approach 1:
The patent implements dynamic privacy policy evaluation where the trust broker assesses privacy policies in real-time based on the authentication context, user preferences, and required data types. The system dynamically adjusts which sensor data to transmit based on this evaluation, rather than applying static restrictive policies. This dynamic approach allows the system to maintain user privacy control through enforceable policies while preserving authentication reliability by adapting data transmission to meet verification requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A mobile device may perform authentication with an authenticating entity. The mobile device may comprise a plurality of sensors and a processor. The processor may be configured to: receive an authentication request from the authenticating entity requesting authentication information; and determine if the authentication request satisfies predefined user privacy preferences. If so, the processor may be configured to: retrieve the authentication information from at least one sensor to form a trust vector in response to the authentication request and to command transmission of the trust vector to the authenticating entity for authentication.