Dynamic Application Code Obfuscation for Mobile Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers face challenges in securing locally deployed applications on vulnerable electronic platforms due to high costs, cumbersome logistics, and lack of interoperability of existing security measures like Public Key Infrastructure and Trusted Computing, which limits the widespread adoption of secure solutions for platforms such as Mobile Banking and IoT.
Innovation Solution
A system and method that utilizes an Apparatus Server to import and transform application source code using obfuscation, removal, PKI, compiler, and distribution mechanisms, along with a Tamper detection and Feedback mechanism to dynamically and unpredictably patch or remove code blocks, employing obfuscation techniques and secure key management to thwart hacking attempts and ensure secure user interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Public Key Infrastructure and Trusted Computing are deployed to protect platforms, then security is improved, but deployment costs increase and logistics become cumbersome
Solution Approach 1:
The patent uses virtualization to create virtual copies of computing environments, allowing security policies and configurations to be replicated and distributed efficiently. This eliminates the need for physical hardware changes at each endpoint, reducing deployment complexity while maintaining security through consistent virtualized security layers.
Solution Approach 2:
The patent introduces a security gateway or intermediary component that mediates between the untrusted network environment and protected resources. This intermediary handles authentication, authorization, and security policy enforcement centrally, eliminating the need for complex distributed PKI infrastructure at each endpoint while maintaining strong security controls.
2Reliability
If traditional security measures are implemented, then security is improved, but interoperability between heterogeneous deployments decreases
Solution Approach 1:
The patent implements a universal security framework that can operate across heterogeneous platforms and networks. The security gateway provides multi-functional capabilities including authentication, encryption, and policy enforcement that work consistently across different devices, networks, and applications, enabling interoperability while maintaining security.
Solution Approach 2:
The patent uses configurable security parameters and policies that can be dynamically adjusted to accommodate different platforms and deployment scenarios. This allows the same security framework to adapt to heterogeneous environments by changing operational parameters rather than requiring different security infrastructures for different platforms.
3Reliability
If code obfuscation and transformation are applied continuously, then security against hacking is improved, but processing time and computational resources increase
Solution Approach 1:
The patent applies code obfuscation and transformation techniques during the application development and deployment phase rather than in real-time during execution. Security-critical code is obfuscated beforehand, and the obfuscated version is deployed to endpoints. This preliminary processing eliminates continuous transformation overhead during runtime while maintaining security through the obfuscated code structure.
Solution Approach 2:
The patent implements dynamic code transformation where the level and type of obfuscation applied can vary based on the execution context, user role, and security requirements. Not all code paths are obfuscated to the same degree, allowing the system to balance security needs against performance constraints by dynamically adjusting transformation intensity.
Data Source
Figure 1
AI summary
The present invention regards a system and a method for securing locally deployed applications running on vulnerable electronic platforms, like mobile phones, tablets, personal computers or any other electronic device running apps. More particularly, a system and a method that enables Service Providers to continuously execute patching or remove code blocks of running applications in a non-predictable way in order to outperform attackers in terms of time and cost of hacking.