Application Signing Apparatus for Authenticating API Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The application market faces challenges in managing and controlling applications, particularly in preventing unauthorized modifications and ensuring the authenticity and authority of application program interface (API) use, leading to issues with modulated applications and potential security risks.
Innovation Solution
A signature apparatus and method that involves generating and verifying authentication notes and signature information using application identification information, encrypting hash values, and inserting these into applications to ensure authenticity and control API use authority, thereby preventing unauthorized modifications and ensuring secure application execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If applications are freely circulated in the application market, then application availability and user access are improved, but application security and authenticity cannot be guaranteed
Solution Approach 1:
The patent implements preliminary signing actions by the signature apparatus and authentication note issuance before applications are circulated. The market server receives signature requests, verifies application authenticity, and attaches authentication notes in advance, ensuring that applications are pre-validated before entering the circulation channel.
Solution Approach 2:
The patent introduces the market server as an intermediary between application developers and users. The market server acts as a mediator that receives applications, collaborates with the signature apparatus to verify authenticity, attaches authentication notes, and then distributes applications to terminals, thereby ensuring application security while maintaining circulation.
2Reliability
If application execution authority is controlled through authentication, then API use authority and terminal control are improved, but application distribution complexity increases
Solution Approach 1:
The patent implements a universal authentication note system that serves multiple functions: it verifies application authenticity, controls API use authority, manages terminal execution permissions, and enables secure distribution. This multi-functional approach consolidates multiple control mechanisms into a single authentication framework.
Solution Approach 2:
The patent changes the parameter of application distribution from direct file transfer to authenticated distribution with embedded authentication notes. The system transforms the distribution process by incorporating authentication verification, signature attachment, and authority control parameters into the distribution workflow.
3Reliability
If signature verification is performed for all applications, then application security and modulation prevention are improved, but processing time and system overhead increase
Solution Approach 1:
The patent performs signature verification and authentication note issuance in advance before application circulation. The signature apparatus signs applications and the market server attaches authentication notes during the distribution preparation phase, so that terminal devices receive pre-verified applications without requiring time-consuming verification during installation or execution.
Data Source
AI summary
When a signature apparatus cooperating with a market server receives signature request information for an optional application from the market server to sign an application, the signature apparatus determines whether an authentication note has been issued corresponding to application identification information included in the signature request information based on the application identification information. When the authentication note has not been issued; the signature apparatus issues the authentication note using the application identification information, generates signature information for the to application using the application identification information, and signs the application including the authentication note and the signature information.


