Virtual Certificate Authentication for Mobile Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile device data is vulnerable to unauthorized access and distribution due to the lack of effective security measures in cloud computing environments, where data is transmitted and stored using e-commerce and Internet applications.

Innovation Solution

A system and method using virtual certificates at a computer processor to secure mobile devices by electronically receiving a request for access, generating and comparing hash parameters based on security key fragments, and transmitting a session security key for network access, while maintaining a verifier key fragment confidentially on the server processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices transmit data over cloud networks using e-commerce and Internet applications, then connectivity and functionality are improved, but data security and protection from unauthorized access deteriorate

Engineering Contradiction:
ImproveconnectivityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The security key is divided into multiple fragments (first security key fragment, second security key fragment, third security key fragment) that are distributed across different locations (mobile device, server, and derived on-demand). No single fragment alone can reconstruct the full key, providing segmented security protection while enabling cloud connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A conditional seed key fragment acts as an intermediary that enables the server to dynamically generate additional security key fragments on-demand. This intermediary mechanism allows secure key reconstruction only when authorized, mediating between connectivity needs and security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional password-based authentication is used for network access, then ease of operation is improved, but security reliability deteriorates due to vulnerabilities to unauthorized access

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system uses segmented key fragments instead of traditional passwords. The mobile device contains a first security key fragment, while the server holds verification data including a second and third security key fragment. This segmentation maintains user-friendly authentication while dramatically improving security against unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security key fragments are pre-distributed and stored in secure locations before authentication is needed. The mobile device is pre-configured with the first security key fragment, and the server is pre-configured with verification data, enabling secure authentication without requiring complex real-time security measures.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If cloud computing resources are used to perform computations, then processing capability is improved, but data vulnerability to unauthorized distribution increases

Engineering Contradiction:
Improveprocessing capabilityVSAvoidunauthorized distribution
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

By segmenting the security key into multiple fragments distributed between the mobile device and server, the system enables cloud-based processing while preventing unauthorized data distribution. The segmented key structure ensures that even if cloud resources are compromised, the full security key cannot be reconstructed without all fragments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication system uses hash parameter comparison as a feedback mechanism to verify security key fragments. The server generates a hash parameter from the second and third security key fragments and compares it with a received hash parameter, providing feedback that confirms secure authentication before allowing cloud resource access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9531542B2Secure remote password
Publication Date: 2016.12.27 BANK OF AMERICA CORP
  • US9531542B2 patent drawing
  • US9531542B2 patent drawing
  • US9531542B2 patent drawing

AI summary

Aspects of the present disclosure pertain to system and method of securing mobile devices using virtual certificates at a computer processor. A method may include receiving a request for access to a computer network associated with a computing device to an application associated with a network connected server processor; electronically receiving, at the server processor, a first security key fragment from the computing device; the first security key fragment being paired with a verifier key fragment unknown to the computing device; generating a conditional seed key fragment at the server processor associated with the verifier key fragment; comparing a first hash parameter to a second hash parameter at the server processor; transmitting, at the server processor, a session security key for enabling network access to the application associated with the server processor.