Application Management via Device Fingerprint and Server-Side Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a risk of malevolent individuals duplicating software applications from one device to another for fraudulent transactions, highlighting a need to increase protection measures for applications on portable devices that access sensitive data or services.

Innovation Solution

A method involving a device and server communication where the device gets a fingerprint and authenticates the user, sending a request to the server for an additional application part, which generates a ciphered part using user credentials and fingerprint, along with an auto-decrypt program. The device receives and stores these, using them to retrieve and execute the part only upon successful authentication, ensuring secure execution and preventing unauthorized cloning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If application is made accessible on portable devices, then user convenience and service availability are improved, but security risk from unauthorized duplication increases

Engineering Contradiction:
Improveservice availabilityVSAvoidunauthorized duplication
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The application is divided into two distinct parts: a generic part that can be freely distributed and installed, and an additional part that contains sensitive functionality and is protected through encryption. This segmentation allows the application to be widely available while preventing unauthorized duplication of the critical components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication server acts as an intermediary between the device and the additional application part. The server verifies device fingerprints and user credentials before releasing the encrypted additional part, preventing unauthorized duplication while maintaining service availability for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If application protection measures are strengthened, then security against duplication is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex authentication and encryption logic is extracted from the portable device and placed on a remote authentication server. The device only needs to implement simple functions: generating fingerprints, authenticating users, and decrypting the additional part using provided keys. This extraction maintains high security while minimizing device complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication server performs all complex verification operations in advance by checking device fingerprints and user credentials before releasing the additional application part. This preliminary action ensures security requirements are met before the application is deployed to the device, simplifying the device's role to mere execution and decryption.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If device-specific authentication is implemented, then cloning prevention is improved, but authentication process time increases

Engineering Contradiction:
Improvecloning preventionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Device fingerprints are generated and stored in advance during device manufacturing or initial setup. When authentication is needed, the device simply retrieves and transmits the pre-computed fingerprint along with user credentials, avoiding time-consuming complex verification calculations on the device itself while maintaining strong cloning prevention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10939265B2Method of managing an application
Publication Date: 2021.03.02 THALES DIS FRANCE SA
  • US10939265B2 patent drawing
  • US10939265B2 patent drawing
  • US10939265B2 patent drawing

AI summary

The invention is a method for managing an application that includes a generic part and an additional part. The generic part is pre-installed on a device. The device gets a fingerprint of itself and after a user authentication sends to a server a request for getting the additional part. The request comprises credentials associated with the user or a reference of the user, the fingerprint and a reference of the application. The server generates a ciphered part of the additional part using a key based on both the credentials and the fingerprint and builds an auto-decrypt program configured to decipher the ciphered part. The device receives the ciphered part and the auto-decrypt program. It gets the fingerprint and the credentials and retrieves the additional part by running the auto-decrypt program with said fingerprint and credentials as input parameters.