Virtual Certificate Authentication for Mobile Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile device data is vulnerable to unauthorized access and distribution due to the lack of effective security measures in cloud computing environments, where data is transmitted and stored using e-commerce and Internet applications.
Innovation Solution
A system and method using virtual certificates at a computer processor to secure mobile devices by electronically receiving a request for access, generating and comparing hash parameters based on security key fragments, and transmitting a session security key for network access, while maintaining a verifier key fragment confidentially on the server processor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile devices transmit data over cloud networks using e-commerce and Internet applications, then connectivity and functionality are improved, but data security and protection from unauthorized access deteriorate
Solution Approach 1:
The security key is divided into multiple fragments (first security key fragment, second security key fragment, third security key fragment) that are distributed across different locations (mobile device, server, and derived on-demand). No single fragment alone can reconstruct the full key, providing segmented security protection while enabling cloud connectivity.
Solution Approach 2:
A conditional seed key fragment acts as an intermediary that enables the server to dynamically generate additional security key fragments on-demand. This intermediary mechanism allows secure key reconstruction only when authorized, mediating between connectivity needs and security protection.
2Ease of operation
If traditional password-based authentication is used for network access, then ease of operation is improved, but security reliability deteriorates due to vulnerabilities to unauthorized access
Solution Approach 1:
The authentication system uses segmented key fragments instead of traditional passwords. The mobile device contains a first security key fragment, while the server holds verification data including a second and third security key fragment. This segmentation maintains user-friendly authentication while dramatically improving security against unauthorized access.
Solution Approach 2:
Security key fragments are pre-distributed and stored in secure locations before authentication is needed. The mobile device is pre-configured with the first security key fragment, and the server is pre-configured with verification data, enabling secure authentication without requiring complex real-time security measures.
3Productivity
If cloud computing resources are used to perform computations, then processing capability is improved, but data vulnerability to unauthorized distribution increases
Solution Approach 1:
By segmenting the security key into multiple fragments distributed between the mobile device and server, the system enables cloud-based processing while preventing unauthorized data distribution. The segmented key structure ensures that even if cloud resources are compromised, the full security key cannot be reconstructed without all fragments.
Solution Approach 2:
The authentication system uses hash parameter comparison as a feedback mechanism to verify security key fragments. The server generates a hash parameter from the second and third security key fragments and compares it with a received hash parameter, providing feedback that confirms secure authentication before allowing cloud resource access.
Data Source
AI summary
Aspects of the present disclosure pertain to system and method of securing mobile devices using virtual certificates at a computer processor. A method may include receiving a request for access to a computer network associated with a computing device to an application associated with a network connected server processor; electronically receiving, at the server processor, a first security key fragment from the computing device; the first security key fragment being paired with a verifier key fragment unknown to the computing device; generating a conditional seed key fragment at the server processor associated with the verifier key fragment; comparing a first hash parameter to a second hash parameter at the server processor; transmitting, at the server processor, a session security key for enabling network access to the application associated with the server processor.


