Mobile App Obfuscation for HCE Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Host Card Emulation (HCE) technology for mobile payments lacks robust security measures, making it susceptible to attacks similar to card-present and card-not-present e-commerce transactions, despite not requiring secure elements.

Innovation Solution

Implementing methods and systems to obfuscate mobile applications by identifying deployment groups based on shared obfuscation parameters, determining customized obfuscation schemes, and applying these schemes to generate obfuscated applications, which are then transmitted to mobile devices, thereby enhancing security against massive attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Host Card Emulation (HCE) technology is used for mobile payments without secure elements, then device complexity is reduced and ease of operation is improved, but security reliability deteriorates making it susceptible to attacks

Engineering Contradiction:
Improvemobile payment operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies parameter changes by transforming the mobile application through obfuscation techniques that modify code structure, control flow, and data representation. This changes the parameters of the application's executable form without altering its functional behavior, thereby enhancing security while maintaining operational ease

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary obfuscation layer between the clear-text mobile application and the executed code. This intermediary transformation process embeds security measures within the application code itself, acting as a mediator that protects against attacks without requiring separate secure element hardware

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If a single obfuscation scheme is applied to all mobile applications, then manufacturing precision is improved through standardization, but adaptability deteriorates as it cannot address diverse security requirements

Engineering Contradiction:
Improveobfuscation consistencyVSAvoidsecurity scheme adaptability
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the mobile application into multiple components including code segments, data segments, and control flow segments. Each segment can be obfuscated independently using appropriate techniques, allowing consistent application of obfuscation principles while adapting to the specific security needs of different application components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by using different obfuscation techniques for different parts of the application based on their security requirements. Critical security functions receive stronger obfuscation while less sensitive areas use lighter techniques, achieving both consistency in methodology and adaptability to local needs

Inventive Principle:
Principle #3Local quality

3Reliability

If obfuscation parameters are customized for each individual mobile device, then security reliability is improved, but device complexity and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-generating obfuscation parameters and schemes before the mobile application is deployed to devices. The obfuscation is applied during the build or distribution phase rather than at runtime, ensuring device-specific security measures are in place without adding processing time to the user's interaction with the application

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11877213B2Methods and systems for asset obfuscation
Publication Date: 2024.01.16 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11877213B2 patent drawing
  • US11877213B2 patent drawing
  • US11877213B2 patent drawing

AI summary

Techniques for obfuscating and deploying digital assets (e.g., mobile applications) are provided to mitigate the risk of unauthorized disclosure. An asset can be received that is to be deployed to a plurality of mobile devices, each of the mobile devices associated with a corresponding account having account attributes. A deployment group of one or more mobile devices for deploying the asset can be identified based on a set of one or more obfuscation parameters, comprising account attributes shared among the one or more mobile devices within the deployment group. A customized obfuscation scheme to be applied to the asset can be determined based at least in part on the set of obfuscation parameters. The customized obfuscation scheme can be applied to the asset to generate an obfuscated asset. The obfuscated asset can be transmitted and/or updated over a network to the one or more mobile devices within the deployment group.