Application Communication Service on Untrusted Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
On untrusted computing platforms like Android, there is no facility to verify the source of applications, making secure communication between applications challenging due to the use of self-signed digital certificates that can be easily forged, and embedded secret data unreliable.
Innovation Solution
Implementing a communication service that utilizes a whitelist of self-signed certificates to authenticate applications and associates third-party applications with secure keys signed by trusted certificates, enabling secure access and communication between first-party and third-party applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If self-signed digital certificates are used for application signing, then application installation and distribution is simplified, but security and authenticity verification becomes unreliable
Solution Approach 1:
The patent introduces a communication service as an intermediary between applications. This service maintains a whitelist of trusted self-signed certificates and uses them to verify the authenticity of communicating applications. The whitelist acts as a mediator that bridges the simplicity of self-signed certificates with the need for reliable security verification.
Solution Approach 2:
The patent performs preliminary authentication by verifying application signatures against the whitelist of trusted self-signed certificates before establishing communication channels. This preliminary action ensures that only authenticated applications can communicate, resolving the security reliability issue while maintaining ease of installation.
2Adaptability or versatility
If secret data is embedded within applications, then authentication capability is provided, but security is compromised as data can be extracted
Solution Approach 1:
The patent extracts the secret data (whitelist of trusted certificates) from individual applications and centralizes it in a communication service. This extraction prevents the secret data from being embedded in each application where it could be extracted, while still providing authentication capability through the centralized service.
3Ease of operation
If application source verification is not implemented, then platform compatibility and ease of operation is maintained, but secure communication between applications cannot be ensured
Solution Approach 1:
The communication service acts as an intermediary that handles the complexity of source verification. Applications continue to operate with ease on the untrusted platform, while the communication service transparently performs verification against the whitelist of trusted self-signed certificates, ensuring secure communication without compromising ease of operation.
Data Source
AI summary
Disclosed are various embodiments for facilitating secure communication between applications on an untrusted computing platform. It is verified that a first application installed in a computing device has permission to communicate with a second application also installed in the computing device based at least in part on a secure key associated with the first application. The verification may include determining that the secure key has been signed by a predetermined certificate and determining that the secure key includes a platform-specific, tamper-proof identifier of the first application. Alternatively, the verification may include determining that the first application is signed by a predetermined certificate. Communication between the first and second applications is facilitated when the first application has permission to communicate with the second application.


