Digital Fingerprinting for Secure API Traceability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet-based services lack effective mechanisms for traceability and authentication, particularly in open environments, leading to insecure access and unreliable identification of software components, which is incompatible with stringent security requirements.

Innovation Solution

A method for dynamic traceability of exchanges between an operator's infrastructure and a client's device via the Internet/Intranet network, involving the generation and use of digital fingerprints for identifying and authenticating application programming interfaces and software libraries, ensuring secure and contextual access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If declarative-based identification mechanisms (IP address, pseudo) are used for Internet services, then ease of operation and service accessibility are improved, but reliability and security of traceability are worsened

Engineering Contradiction:
Improveservice accessibilityVSAvoidtraceability security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a digital fingerprint as an intermediary element that bridges the gap between easy declarative access and secure traceability. The fingerprint is generated from software component data and serves as a reliable identifier that can be attached to declarative information, allowing both ease of operation and security to coexist

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identification mechanism combines multiple elements into a composite system: declarative information (for ease of access) combined with digitally generated fingerprints (for security). This composite approach allows the system to benefit from both the simplicity of declarative modes and the reliability of cryptographic verification

Inventive Principle:
Principle #40Composite materials

2Reliability

If strong authentication based on dedicated physical devices (SIM card) is used, then reliability and security are improved, but device complexity and ease of operation are worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidphysical device requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical authentication system (SIM cards) with a software-based digital fingerprinting system. The fingerprint is generated algorithmically from software component data, eliminating the need for physical devices while maintaining security through cryptographic verification of the generated fingerprints

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If software components are developed and used in constantly changing environments, then adaptability and productivity are improved, but identification and authentication reliability are worsened

Engineering Contradiction:
Improvedevelopment flexibilityVSAvoidcomponent identification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by generating the digital fingerprint during the software development or deployment phase, before the software component is executed or modified. This pre-generated fingerprint serves as a stable reference that can be used for later authentication and traceability, even as the software evolves in changing environments

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2284751B1Method for traceability and accountability of dynamic exchange in an internet environment
Publication Date: 2021.06.16 SOC FR DU RADIOTELEPHONE SFR
  • EP2284751B1 patent drawingFigure 1
  • EP2284751B1 patent drawingFigure 2
  • EP2284751B1 patent drawingFigure 3

AI summary

The method involves preparing codes for programming interfaces, and installing the interfaces and software libraries on a client apparatus. The impressions representative of installation environment and buying act are injected into the interface. The impressions are associated to generate a contextual activation code representing traceability and accountability of acts, such that the request initiated by a user contains a signature of the interfaces. The request is transferred from a user station to an operator infrastructure, where the transfer operation includes challenge resolution phase.