Application Management via Device Fingerprint and Server-Side Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a risk of malevolent individuals duplicating software applications from one device to another for fraudulent transactions, highlighting a need to increase protection measures for applications on portable devices that access sensitive data or services.
Innovation Solution
A method involving a device and server communication where the device gets a fingerprint and authenticates the user, sending a request to the server for an additional application part, which generates a ciphered part using user credentials and fingerprint, along with an auto-decrypt program. The device receives and stores these, using them to retrieve and execute the part only upon successful authentication, ensuring secure execution and preventing unauthorized cloning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If application is made accessible on portable devices, then user convenience and service availability are improved, but security risk from unauthorized duplication increases
Solution Approach 1:
The application is divided into two distinct parts: a generic part that can be freely distributed and installed, and an additional part that contains sensitive functionality and is protected through encryption. This segmentation allows the application to be widely available while preventing unauthorized duplication of the critical components.
Solution Approach 2:
An authentication server acts as an intermediary between the device and the additional application part. The server verifies device fingerprints and user credentials before releasing the encrypted additional part, preventing unauthorized duplication while maintaining service availability for legitimate users.
2Reliability
If application protection measures are strengthened, then security against duplication is improved, but system complexity increases
Solution Approach 1:
The complex authentication and encryption logic is extracted from the portable device and placed on a remote authentication server. The device only needs to implement simple functions: generating fingerprints, authenticating users, and decrypting the additional part using provided keys. This extraction maintains high security while minimizing device complexity.
Solution Approach 2:
The authentication server performs all complex verification operations in advance by checking device fingerprints and user credentials before releasing the additional application part. This preliminary action ensures security requirements are met before the application is deployed to the device, simplifying the device's role to mere execution and decryption.
3Reliability
If device-specific authentication is implemented, then cloning prevention is improved, but authentication process time increases
Solution Approach 1:
Device fingerprints are generated and stored in advance during device manufacturing or initial setup. When authentication is needed, the device simply retrieves and transmits the pre-computed fingerprint along with user credentials, avoiding time-consuming complex verification calculations on the device itself while maintaining strong cloning prevention.
Data Source
AI summary
The invention is a method for managing an application that includes a generic part and an additional part. The generic part is pre-installed on a device. The device gets a fingerprint of itself and after a user authentication sends to a server a request for getting the additional part. The request comprises credentials associated with the user or a reference of the user, the fingerprint and a reference of the application. The server generates a ciphered part of the additional part using a key based on both the credentials and the fingerprint and builds an auto-decrypt program configured to decipher the ciphered part. The device receives the ciphered part and the auto-decrypt program. It gets the fingerprint and the credentials and retrieves the additional part by running the auto-decrypt program with said fingerprint and credentials as input parameters.


