Layered Mobile Application Security System Using Code Obfuscation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ad-hoc wireless networks with mobile applications are vulnerable to security breaches due to their dynamic nature, lacking a clear line of defense against maliciously designed applications that can compromise network integrity.
Innovation Solution
A layered security approach combining code obfuscation, multiple code signatures, limited application lifetime, and control value verification using hash functions to protect the integrity of mobile applications, including the use of 'dead code' and periodic signature changes, along with a voting mechanism to identify and isolate invalid applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile applications are used in ad-hoc wireless networks, then network mobility and flexibility are improved, but network security and integrity deteriorate due to vulnerability to malicious applications
Solution Approach 1:
The patent segments security protection into multiple independent layers: code obfuscation, code signing, time-limited execution, and control value verification. Each layer provides independent security protection, so if one layer is compromised, other layers continue to protect the system. This segmented approach resolves the contradiction by maintaining security reliability while allowing mobile application flexibility.
Solution Approach 2:
The patent applies preliminary security actions before mobile applications execute: code is obfuscated and signed in advance, execution time limits are predetermined, and control values are pre-calculated. These preliminary measures ensure security is embedded before potential attacks can occur, allowing mobile applications to operate freely within predetermined security boundaries.
2Object-affected harmful factors
If code obfuscation techniques are applied to mobile applications, then reverse engineering difficulty increases, but application execution complexity increases
Solution Approach 1:
The patent applies local quality by obfuscating only critical portions of the code (identifiers, control structures) while leaving functional logic intact. This selective obfuscation increases reverse engineering difficulty for attackers who need to understand code structure, while maintaining relatively simple execution for legitimate applications that have the proper deobfuscation keys.
Solution Approach 2:
The patent introduces an intermediary verification mechanism that mediates between obfuscated code and execution. The control value verification system acts as an intermediary that checks whether obfuscated code has been properly authenticated before execution, simplifying the execution process for legitimate applications while maintaining high resistance to reverse engineering.
3Reliability
If multiple security techniques are layered together, then overall security reliability improves, but system complexity increases
Solution Approach 1:
The patent segments the security system into four distinct, independently implementable layers: code obfuscation, code signing, time-limited execution, and control value verification. Each layer can be implemented and verified separately, making the complex security system manageable through modular segmentation while maintaining high overall reliability.
Solution Approach 2:
The patent merges multiple security techniques into a unified security framework where all layers work together synergistically. The obfuscated and signed code executes within time limits and undergoes control value verification, creating a combined security effect greater than the sum of individual techniques while providing a streamlined implementation approach.
4Object-affected harmful factors
If mobile applications have limited useful lifetime, then the window for malicious activity is reduced, but application availability decreases
Solution Approach 1:
The patent implements periodic action by automatically renewing mobile applications before their time limits expire. The system periodically checks application lifetimes and triggers renewal processes, ensuring continuous availability of legitimate applications while maintaining the security benefit of limited execution windows that reduce malicious activity opportunities.
Solution Approach 2:
The patent uses feedback mechanisms where the system monitors application execution time and provides feedback when applications approach their time limits. This feedback triggers automated renewal or replacement processes, ensuring that application availability is maintained through continuous monitoring and proactive renewal while preserving the security advantage of time-limited execution.
Data Source
AI summary
A wireless communication network (20) including mobile applications (56-62) includes a security approach that uses a combination of at least two techniques (42, 50, 54, 72). One disclosed example includes a combination of all four techniques. The combined, layered approach greatly reduces the probability that an unauthorized individual will be able to masquerade as a valid application within the network so that network security is improved. Disclosed techniques include obfuscating software code of a mobile application, providing a mobile application with a plurality of code signatures for generating a corresponding plurality of unique control values, limiting the useful lifetime of a mobile application and determining that a control value of a mobile application corresponds to the control value of another application before the two applications are allowed to interact in a manner that could compromise either application or the network.


