Cryptographic security functions based on anticipated changes in dynamic minutiae
Abstract
Dynamic key cryptography validates mobile device users to cloud services by uniquely identifying the user's electronic device using a very wide range of hardware, firmware, and software minutiae, user secrets, and user biometric values found in or collected by the device. Processes for uniquely identifying and validating the device include: selecting a subset of minutia from a plurality of minutia types; computing a challenge from which the user device can form a response based on the selected combination of minutia; computing a set of pre-processed responses that covers a range of all actual responses possible to be received from the device if the combination of the particular device with the device's collected actual values of minutia is valid; receiving an actual response to the challenge from the device; determining whether the actual response matches any of the pre-processed responses; and providing validation, enabling authentication, data protection, and digital signatures.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system comprising:
a non-transitory memory storing (a) data values associated with one or more identities, and (b) information regarding anticipated changes to one or more of the stored data values; and one or more hardware processors in communication with the non-transitory memory and configured to execute instructions to cause the system to perform authentication operations comprising:
receiving, from a device, a message associated with a request for accessing a service associated with a first identity of the one or more identities, wherein the message is based on one or more data values from the device;
determining whether the one or more data values from the device are acceptable for the first identity using a first stored data value associated with the first identity and the stored information regarding anticipated changes to the one or more of the stored data values; and
in response to determining that the one or more data values from the device are acceptable for the first identity, granting the device access to the service.
2 . The system of claim 1 , wherein the first identity is a user identity or a device identity.
3 . The system of claim 1 , wherein the operations further comprise:
receiving the request for accessing the service from the device; and transmitting, to the device, a challenge that prompts a response based on the one or more data values.
4 . The system of claim 1 , wherein the determining whether the one or more data values from the device are acceptable for the first identity comprises determining whether the one or more data values from the device correspond to an acceptable change to the first stored data value based on the stored information regarding anticipated changes.
5 . The system of claim 1 , wherein the determining whether the one or more data values from the device are acceptable for the first identity comprises generating, for the first identity, a set of possible data values corresponding to the first stored data value by applying at least a portion of the stored information related to anticipated changes to the first stored data value.
6 . The system of claim 5 , wherein the determining that the one or more data values from the device are acceptable for the first identity comprises determining that the one or more data values corresponds to at least one possible data value in the set of possible data values.
7 . The system of claim 1 , wherein the operations further comprise:
retrieving, from an external source over a network, at least a portion of the information regarding anticipated changes to the one or more of the stored data values associated with the one or more identities.
8 . The system of claim 1 , wherein the one or more data values from the first device comprises at least one of user added data, entertainment data, user contact data, calling application data, software component data, email data, network connection data, frequently called phone numbers, or geo-location data.
9 . The system of claim 1 , wherein the stored information regarding anticipated changes comprises industry updates to hardware, firmware, or software elements.
10 . The system of claim 1 , wherein the operations further comprise:
in response to determining that the one or more data values from the device are acceptable for the first identity, storing the one or more data values for the first identity.
11 . A method comprising:
receiving, from a device, a message associated with a request for accessing a service associated with a first identity, wherein the message is based on one or more data values from the device; accessing a data storage that stores (a) data values associated with one or more identities including the first identity, and (b) information regarding anticipated changes to one or more of the stored data values; determining whether the one or more data values from the device are acceptable for the first identity using a first stored data value associated with the first identity and the stored information regarding anticipated changes to the one or more of the stored data values; and in response to determining that the one or more data values from the device are acceptable for the first identity, granting the device access to the service.
12 . The method of claim 11 , wherein the first identity is a user identity or a device identity.
13 . The method of claim 11 , further comprising:
receiving the request for accessing the service from the device; and transmitting, to the device, a challenge that prompts a response based on the one or more data values.
14 . The method of claim 11 , wherein the determining whether the one or more data values from the device are acceptable for the first identity comprises determining whether the one or more data values from the device correspond to an acceptable change to the first stored data value based on the stored information regarding anticipated changes.
15 . The method of claim 11 , wherein the determining whether the one or more data values from the device are acceptable for the first identity comprises generating, for the first identity, a set of possible data values corresponding to the first stored data value by applying at least a portion of the stored information related to anticipated changes to the first stored data value.
16 . The method of claim 15 , wherein the determining that the one or more data values from the device are acceptable for the first identity comprises determining that the one or more data values corresponds to at least one possible data value in the set of possible data values.
17 . The method of claim 11 , further comprising:
retrieving, from an external source over a network, at least a portion of the information regarding anticipated changes to the one or more of the stored data values associated with the one or more identities.
18 . The method of claim 11 , wherein the one or more data values from the first device comprises at least one of user added data, entertainment data, user contact data, calling application data, software component data, email data, network connection data, frequently called phone numbers, or geo-location data.
19 . The method of claim 11 , wherein the stored information regarding anticipated changes comprises industry updates to hardware, firmware, or software elements.
20 . The method of claim 11 , further comprising:
in response to determining that the one or more data values from the device are acceptable for the first identity, storing the one or more data values for the first identity.Join the waitlist — get patent alerts
Track US2022094673A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.