US2019158471A1PendingUtilityA1

Cryptographic security functions based on anticipated changes in dynamic minutiae

Assignee: MSIGNIA INCPriority: Feb 3, 2011Filed: Jan 7, 2019Published: May 23, 2019
Est. expiryFeb 3, 2031(~4.5 yrs left)· nominal 20-yr term from priority
H04L 63/0428H04L 9/16H04L 9/0861H04L 63/0861H04L 9/0872H04L 9/0866H04L 9/3231H04L 63/083H04L 9/3247H04L 63/0457H04L 9/3271H04L 63/0876H04L 63/061H04L 63/08H04L 63/06
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Dynamic key cryptography validates mobile device users to cloud services by uniquely identifying the user's electronic device using a very wide range of hardware, firmware, and software minutiae, user secrets, and user biometric values found in or collected by the device. Processes for uniquely identifying and validating the device include: selecting a subset of minutia from a plurality of minutia types; computing a challenge from which the user device can form a response based on the selected combination of minutia; computing a set of pre-processed responses that covers a range of all actual responses possible to be received from the device if the combination of the particular device with the device's collected actual values of minutia is valid; receiving an actual response to the challenge from the device; determining whether the actual response matches any of the pre-processed responses; and providing validation, enabling authentication, data protection, and digital signatures.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising:
 a non-transitory memory storing information associated with a plurality of identities, wherein the information stored for each identity includes a plurality of identity validation objects comprising an attribute type, an attribute value associated with the attribute type, and information related to anticipated changes that modify the attribute value, wherein the plurality of identity validation objects includes objects representing at least two different non-static characteristics associated with the identity selected from the group of non-static characteristics comprising: user added data, calling application data, software component data, network connection data, and geo-location data; and   one or more hardware processors in communication with the non-transitory memory and configured to execute instructions to cause the system to perform operations comprising:
 receiving, from a first device over a network, a message based on a first data value and a second data value from the first device corresponding to a first attribute type and a second attribute type, respectively, wherein the first and second data values serves purposes for the first device other than a security purpose; 
 retrieving identity validation objects associated with the first attribute type and identity validation objects associated with the second attribute type by accessing the information associated with the plurality of identities; 
 determining, for each identity in the plurality of identities, whether the first data value and the second data value used to create the message are acceptable for the identity using a first attribute value and first information stored in a first validation object associated with the identity and the first attribute type, and a second attribute value and second information stored in a second validation object associated with the identity and the second attribute type; and 
 in response to determining that the first data value and the second data value are acceptable for a first identity among the plurality of identities, associating the first device with the first identity. 
   
     
     
         2 . The system of  claim 1 , wherein the operations further comprise:
 receiving, from the first device, a request to access a service based on a second identity different from the first identity; and   denying the first device access to the service based on the first identity associated with the first device being different from the second identity.   
     
     
         3 . The system of  claim 2 , wherein the operations further comprise dissociating the first device from the second identity. 
     
     
         4 . The system of  claim 1 , wherein the operations further comprise providing the first device access to a service based on the first identity. 
     
     
         5 . The system of  claim 4 , wherein providing the first device access to the service comprises enabling the first device to access a first user account associated with the first identity. 
     
     
         6 . The system of  claim 4 , wherein providing the first device access to the service comprises providing access to a physical space. 
     
     
         7 . The system of  claim 1 , wherein determining whether the first data value from the first device is acceptable for the identity comprises:
 generating, for the identity, a set of possible attribute values corresponding to the first attribute type by applying the first information to the first attribute value;   determining at least one anticipated change from the first information that generates a possible attribute value corresponding to the first data value from the first device; and   computing, for the first data value from the first device, a score indicating a likelihood that the first data value from the first device is associated with the first identity based on the one anticipated change; and   determining whether the computed score passes a predetermined threshold.   
     
     
         8 . The system of  claim 1 , wherein the group of non-static characteristics further comprise entertainment data, user contact data, email data, sensor data, and frequently called phone numbers, and wherein the plurality of identity validation objects includes objects representing at least three different non-static characteristics associated with the identity selected from the group of non-static characteristics. 
     
     
         9 . The system of  claim 1 , wherein the plurality of identity validation objects associated with each identity includes objects representing at least three different non-static characteristics associated with the identity selected from the group of non-static characteristics. 
     
     
         10 . The system of  claim 1 , wherein the first identity validation object and the second identity validation object represent the at least two different non-static characteristic. 
     
     
         11 . The system of  claim 1 , wherein the operations further comprise updating, for the first identity, the first identity validation object and the second identity validation object by incorporating the first data value and the second data value into the first identity validation object and the second identity validation object, respectively. 
     
     
         12 . A method comprising:
 storing information associated with a plurality of identities, wherein the information stored for each identity includes a plurality of identity validation objects comprising an attribute type, an attribute value associated with the attribute type, and information related to anticipated changes for modifying the attribute value, wherein the plurality of identity validation objects includes objects representing at least two different non-static characteristics associated with the identity selected from the group of non-static characteristics comprising: user added data, calling application data, software component data, network connection data, and geo-location data;   receiving, from a first device over a network, a message based on a first data value and a second data value from the first device corresponding to a first attribute type and a second attribute type, respectively, wherein the first and second data values serves purposes for the first device other than a security purpose;   retrieving identity validation objects associated with the first attribute type and identity validation objects associated with the second attribute type by accessing the information associated with the plurality of identities;   determining, for each identity in the plurality of identities, whether the first data value and the second data value used to create the message are acceptable for the identity using a first attribute value and first information stored in a first validation object associated with the identity and the first attribute type, and a second attribute value and second information stored in a second validation object associated with the identity and the second attribute type; and   in response to determining that the first data value and the second data value are acceptable for a first identity among the plurality of identities, associating the first device with the first identity.   
     
     
         13 . The method of  claim 12 , further comprising:
 receiving, from the first device, a request to access a service based on a second identity different from the first identity; and   denying the first device access to the service based on the first identity associated with the first device being different from the second identity.   
     
     
         14 . The method of  claim 13 , further comprising dissociating the first device from the second identity. 
     
     
         15 . The method of  claim 12 , further comprising providing the first device access to a service based on the first identity. 
     
     
         16 . The method of  claim 15 , wherein providing the first device access to the service comprises enabling the first device to access a first user account associated with the first identity. 
     
     
         17 . The method of  claim 15 , wherein providing the first device access to the service comprises providing access to a physical space. 
     
     
         18 . The method of  claim 12 , wherein determining whether the first data value from the first device is acceptable for the identity comprises:
 generating, for the identity, a set of possible attribute values corresponding to the first attribute type by applying the first information to the first attribute value;   determining at least one anticipated change from the first information that generates a possible attribute value corresponding to the first data value from the first device; and   computing, for the first data value from the first device, a score indicating a likelihood that the first data value from the first device is associated with the first identity based on the one anticipated change; and   determining whether the computed score passes a predetermined threshold.   
     
     
         19 . The method of  claim 12 , wherein the group of non-static characteristics further comprise entertainment data, user contact data, email data, sensor data, and frequently called phone numbers, and wherein the plurality of identity validation objects includes objects representing at least three different non-static characteristics associated with the identity selected from the group of non-static characteristics. 
     
     
         20 . The method of  claim 12 , wherein the plurality of identity validation objects associated with each identity includes objects representing at least three different non-static characteristics associated with the identity selected from the group of non-static characteristics.

Join the waitlist — get patent alerts

Track US2019158471A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.