Secure Mobile App Compilation via Encrypted Source and Certificate Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in securely managing and deploying mobile applications, particularly for corporations, where the separation of source code and digital certificates is necessary to prevent unauthorized access and exposure, while ensuring the security and privacy of both the appliance and the network, especially in the context of complex software modifications and bespoke development.

Innovation Solution

A system and method that allows the source code and digital certificate to be encrypted and remitted separately to a server for temporary storage before combination in the compiler, with decryption occurring only during compilation and access being restricted to prevent exposure, ensuring secure data handling and protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If source code and digital certificate are combined in a single development environment, then application development is simplified, but security is compromised due to unauthorized access and exposure risks

Engineering Contradiction:
Improveapplication development processVSAvoidsecurity of sensitive information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the development process into separate secure environments: one for source code and another for digital certificate. This segmentation prevents both sensitive elements from being exposed to the same potential security threats, allowing simplified development while maintaining security through environmental separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure server as an intermediary that receives encrypted source code and digital certificates separately, stores them securely, and facilitates their combination only in controlled circumstances. This intermediary mechanism enables development simplification while maintaining security through centralized, protected mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If corporations use internal distribution mechanisms for customized software, then brand differentiation is achieved, but security exposure increases due to broader access requirements

Engineering Contradiction:
Improvesoftware customization capabilityVSAvoidsecurity exposure to malicious interference
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary encryption to source code and digital certificates before they are transmitted or stored in the internal distribution system. This pre-securing action allows corporations to implement customized software distribution while maintaining security, as the sensitive elements are protected before exposure to the distribution network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements location-specific security measures where source code and digital certificates are stored and processed in different secure environments with access controls tailored to their specific security requirements. This localized security approach enables customization while minimizing overall security exposure.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If digital certificate is shared with external contractors for application development, then bespoke software development is enabled, but security risk increases due to potential certificate compromise

Engineering Contradiction:
Improveexternal development capabilityVSAvoiddigital certificate security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the digital certificate from the external development environment and keeps it secured in a separate, controlled environment. External contractors can access and use the source code for development, but the certificate remains isolated and protected, enabling external development capability while maintaining certificate security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses a secure server as an intermediary that manages the digital certificate and controls its usage. The server facilitates external development by allowing contractors to work with source code while maintaining secure, controlled access to the certificate, thus enabling collaboration while protecting against certificate compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9135434B2System and method for third party creation of applications for mobile appliances
Publication Date: 2015.09.15 MALIKIE INNOVATIONS LTD
  • US9135434B2 patent drawing
  • US9135434B2 patent drawing
  • US9135434B2 patent drawing

AI summary

The creation of an application for any mobile appliance, for example Apple's iPhone, requires several elements to be present at compile time. In the Apple example of an enterprise application where an entity wishes to develop applications internally for its staff, two of these elements are the source code and a digital certificate. These must be combined in the compiler so that the application may be properly authorized to run in the appliance. Where the owner of the source code and the owner of the digital certificate are not the same, serious concerns arise because each element must be secured. An intermediating system and method are described that allows each party to cooperate securely through a third party escrow service to produce the complied application while leaving no unwanted residue of the independent parts.