Cryptographic security functions based on anticipated changes in dynamic minutiae
Abstract
Dynamic key cryptography validates mobile device users to cloud services by uniquely identifying the user's electronic device using a very wide range of hardware, firmware, and software minutiae, user secrets, and user biometric values found in or collected by the device. Processes for uniquely identifying and validating the device include: selecting a subset of minutia from a plurality of minutia types; computing a challenge from which the user device can form a response based on the selected combination of minutia; computing a set of pre-processed responses that covers a range of all actual responses possible to be received from the device if the combination of the particular device with the device's collected actual values of minutia is valid; receiving an actual response to the challenge from the device; determining whether the actual response matches any of the pre-processed responses; and providing validation, enabling authentication, data protection, and digital signatures.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system comprising:
a non-transitory memory storing information associated with a plurality of identities, wherein the information stored for each identity includes a plurality of identity validation objects comprising an attribute type, an attribute value associated with the attribute type, and information related to anticipated changes that modify the attribute value, wherein the plurality of identity validation objects includes objects representing at least two different non-static characteristics associated with the identity selected from the group of non-static characteristics comprising: user added data, calling application data, software component data, network connection data, and geo-location data; and one or more hardware processors in communication with the non-transitory memory and configured to execute instructions to cause the system to perform operations comprising:
receiving, from a first device over a network, a message based on a first data value and a second data value from the first device corresponding to a first attribute type and a second attribute type, respectively, wherein the first and second data values serves purposes for the first device other than a security purpose;
retrieving identity validation objects associated with the first attribute type and identity validation objects associated with the second attribute type by accessing the information associated with the plurality of identities;
determining, for each identity in the plurality of identities, whether the first data value and the second data value used to create the message are acceptable for the identity using a first attribute value and first information stored in a first validation object associated with the identity and the first attribute type, and a second attribute value and second information stored in a second validation object associated with the identity and the second attribute type; and
in response to determining that the first data value and the second data value are acceptable for a first identity among the plurality of identities, associating the first device with the first identity.
2 . The system of claim 1 , wherein the operations further comprise:
receiving, from the first device, a request to access a service based on a second identity different from the first identity; and denying the first device access to the service based on the first identity associated with the first device being different from the second identity.
3 . The system of claim 2 , wherein the operations further comprise dissociating the first device from the second identity.
4 . The system of claim 1 , wherein the operations further comprise providing the first device access to a service based on the first identity.
5 . The system of claim 4 , wherein providing the first device access to the service comprises enabling the first device to access a first user account associated with the first identity.
6 . The system of claim 4 , wherein providing the first device access to the service comprises providing access to a physical space.
7 . The system of claim 1 , wherein determining whether the first data value from the first device is acceptable for the identity comprises:
generating, for the identity, a set of possible attribute values corresponding to the first attribute type by applying the first information to the first attribute value; determining at least one anticipated change from the first information that generates a possible attribute value corresponding to the first data value from the first device; and computing, for the first data value from the first device, a score indicating a likelihood that the first data value from the first device is associated with the first identity based on the one anticipated change; and determining whether the computed score passes a predetermined threshold.
8 . The system of claim 1 , wherein the group of non-static characteristics further comprise entertainment data, user contact data, email data, sensor data, and frequently called phone numbers, and wherein the plurality of identity validation objects includes objects representing at least three different non-static characteristics associated with the identity selected from the group of non-static characteristics.
9 . The system of claim 1 , wherein the plurality of identity validation objects associated with each identity includes objects representing at least three different non-static characteristics associated with the identity selected from the group of non-static characteristics.
10 . The system of claim 1 , wherein the first identity validation object and the second identity validation object represent the at least two different non-static characteristic.
11 . The system of claim 1 , wherein the operations further comprise updating, for the first identity, the first identity validation object and the second identity validation object by incorporating the first data value and the second data value into the first identity validation object and the second identity validation object, respectively.
12 . A method comprising:
storing information associated with a plurality of identities, wherein the information stored for each identity includes a plurality of identity validation objects comprising an attribute type, an attribute value associated with the attribute type, and information related to anticipated changes for modifying the attribute value, wherein the plurality of identity validation objects includes objects representing at least two different non-static characteristics associated with the identity selected from the group of non-static characteristics comprising: user added data, calling application data, software component data, network connection data, and geo-location data; receiving, from a first device over a network, a message based on a first data value and a second data value from the first device corresponding to a first attribute type and a second attribute type, respectively, wherein the first and second data values serves purposes for the first device other than a security purpose; retrieving identity validation objects associated with the first attribute type and identity validation objects associated with the second attribute type by accessing the information associated with the plurality of identities; determining, for each identity in the plurality of identities, whether the first data value and the second data value used to create the message are acceptable for the identity using a first attribute value and first information stored in a first validation object associated with the identity and the first attribute type, and a second attribute value and second information stored in a second validation object associated with the identity and the second attribute type; and in response to determining that the first data value and the second data value are acceptable for a first identity among the plurality of identities, associating the first device with the first identity.
13 . The method of claim 12 , further comprising:
receiving, from the first device, a request to access a service based on a second identity different from the first identity; and denying the first device access to the service based on the first identity associated with the first device being different from the second identity.
14 . The method of claim 13 , further comprising dissociating the first device from the second identity.
15 . The method of claim 12 , further comprising providing the first device access to a service based on the first identity.
16 . The method of claim 15 , wherein providing the first device access to the service comprises enabling the first device to access a first user account associated with the first identity.
17 . The method of claim 15 , wherein providing the first device access to the service comprises providing access to a physical space.
18 . The method of claim 12 , wherein determining whether the first data value from the first device is acceptable for the identity comprises:
generating, for the identity, a set of possible attribute values corresponding to the first attribute type by applying the first information to the first attribute value; determining at least one anticipated change from the first information that generates a possible attribute value corresponding to the first data value from the first device; and computing, for the first data value from the first device, a score indicating a likelihood that the first data value from the first device is associated with the first identity based on the one anticipated change; and determining whether the computed score passes a predetermined threshold.
19 . The method of claim 12 , wherein the group of non-static characteristics further comprise entertainment data, user contact data, email data, sensor data, and frequently called phone numbers, and wherein the plurality of identity validation objects includes objects representing at least three different non-static characteristics associated with the identity selected from the group of non-static characteristics.
20 . The method of claim 12 , wherein the plurality of identity validation objects associated with each identity includes objects representing at least three different non-static characteristics associated with the identity selected from the group of non-static characteristics.Join the waitlist — get patent alerts
Track US2019158471A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.