Mobile App Debugging Inhibition via Security Sensitivity Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile device applications face security risks due to debugging mechanisms that can expose sensitive information, allowing malicious access and compromising security controls, especially in financial applications where debugging can lead to fraud or identity theft.

Innovation Solution

A computer-implemented method in a mobile computing system that inhibits debugging environments by determining if a debugging environment is active and taking actions to prevent its operation, such as setting invalid parameters or creating a parallel thread to interfere with debugging processes, thereby ensuring the application remains non-debuggable and tamper-resistant.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If debugging capability is provided to application developers, then application development and testing is facilitated, but security-sensitive applications are vulnerable to malicious access and information exposure

Engineering Contradiction:
Improveapplication development and testingVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by enabling debugging capability selectively based on application type. Security-sensitive applications (e.g., banking, financial apps) are identified and excluded from debugging access, while non-sensitive applications retain full debugging capability. This is achieved through checking security sensitivity attributes of the application package and conditionally allowing debugging operations only for non-sensitive apps.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent inverts the conventional approach by defaulting to denying debugging access for security-sensitive applications and only allowing it for non-sensitive ones. Instead of universally enabling debugging and restricting specific cases, the system proactively identifies security-sensitive applications and blocks debugging by default, then permits debugging for applications that pass security checks.

Inventive Principle:
Principle #13The other way round (Inversion)

2Ease of repair

If debugging mechanisms are allowed in released applications, then post-release debugging and monitoring is possible, but security controls are compromised and sensitive information can be exposed

Engineering Contradiction:
Improvepost-release debuggingVSAvoidsecurity control integrity
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The patent implements preliminary action by performing security sensitivity checks on applications before allowing debugging operations. The system checks the application package for security-sensitive attributes (e.g., banking, financial keywords) and pre-determines whether debugging should be permitted. This prevents security-sensitive applications from being debugged in the first place, eliminating the risk of post-release security compromises.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by proactively preventing debugging operations on security-sensitive applications before they can compromise security controls. The system identifies security-sensitive applications and blocks debugging access in advance, countering potential security threats before they materialize. This includes preventing access to internal application data, state information, and sensitive parameters.

Inventive Principle:
Principle #9Preliminary anti-action

3Measurement precision

If application debugging is enabled for all applications, then comprehensive testing and error detection is achieved, but malicious software can attack security-sensitive applications and obtain private information

Engineering Contradiction:
Improveerror detection capabilityVSAvoidmalicious attack risk
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by differentiating debugging access based on application security sensitivity. Non-sensitive applications receive full debugging capability for comprehensive error detection, while security-sensitive applications are excluded from debugging entirely. This selective approach maintains error detection precision for appropriate applications while eliminating malicious attack vectors for security-sensitive ones.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8925077B2Mobile devices with inhibited application debugging and methods of operation
Publication Date: 2014.12.30 LOOKOUT INC
  • US8925077B2 patent drawing
  • US8925077B2 patent drawing
  • US8925077B2 patent drawing

AI summary

Applications that have the ability to be debugged also provide an access to violate the security of the application. The present invention provides a means to ensure that the debugging aspects of an application can be defeated after development and other test procedures, to keep persons or other applications from starting a debugging procedure that can lead to the discovery of secured or sensitive information and data. The application of the present invention is greatly automated such that anyone beginning a debugging program against the application in a device will be stymied by the application shutting down the debugging before data or other sensitive information can be released.