CI Pipeline Authorization Key Obfuscation Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile applications are vulnerable to reverse engineering and unpackaging, leading to security hazards due to the complexity of traditional obfuscation tools, which often result in accidental removal or rejection of authorization key obfuscation, exposing sensitive information.

Innovation Solution

A system and method for validating authorization key obfuscation in a continuous integration (CI) pipeline codebase, involving a transceiver, memories, and processors that receive, store, and obfuscate updates, scanning for the presence or absence of authorization keys to ensure secure integration and obfuscation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional obfuscation tools are used, then application security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improveapplication securityVSAvoidobfuscation tool complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authorization key obfuscation validation from the complex traditional obfuscation tools and implements it as a separate, dedicated validation mechanism within the CI pipeline. This validation component independently checks for unobfuscated authorization keys, simplifying the overall process by separating the validation function from the obfuscation tool complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary validation step in the CI pipeline that acts as a mediator between code submission and final deployment. This intermediary automatically validates authorization key obfuscation, reducing the need for designers to directly manage complex obfuscation tools while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional obfuscation tools are used, then application security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveapplication securityVSAvoidobfuscation process ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service validation mechanism where the CI pipeline automatically performs authorization key obfuscation validation without requiring manual intervention from application designers. The system self-checks for unobfuscated keys and provides automated feedback, making the security validation process easy to operate while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms in the CI pipeline that automatically notify designers when authorization keys are improperly obfuscated. This feedback loop enables designers to correct issues easily without needing to understand complex obfuscation tools, improving ease of operation while maintaining security.

Inventive Principle:
Principle #23Feedback

3Device complexity

If authorization key obfuscation is removed or rejected, then device complexity is reduced, but security deteriorates

Engineering Contradiction:
Improveobfuscation process complexityVSAvoidapplication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by preventing the deployment of applications with unobfuscated authorization keys through automated validation in the CI pipeline. This preliminary check stops potential security issues before they reach production, maintaining security without requiring complex manual obfuscation processes.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent performs preliminary obfuscation validation during the CI pipeline build process, before deployment. This preliminary action ensures authorization keys are properly obfuscated early in the development cycle, maintaining security while keeping the deployment process simple and automated.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12086218B2Systems and methods to facilitate authorization key obfuscation validation
Publication Date: 2024.09.10 QUANATA LLC
  • US12086218B2 patent drawing
  • US12086218B2 patent drawing
  • US12086218B2 patent drawing

AI summary

A device for validating authorization key obfuscation in a continuous integration (CI) pipeline codebase is presented. The device includes a transceiver, one or more memories, and one or more processors interfacing with the transceiver and the one or more memories. The one or more processors are configured to receive an update to the CI pipeline codebase. The update may include an authorization key, which the one or more processors store in the one or more memories. The one or more processors may perform a build process to integrate the update into the CI pipeline codebase. The build process may include an obfuscation, which creates an obfuscated CI pipeline codebase. The one or more processors may also scan the obfuscated CI pipeline codebase to determine a presence or an absence of the authorization key.