Mobile App Signature Authentication With Dynamic Forgery Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile application forgery detection technologies require registering all signatures in advance, leading to normal applications being incorrectly identified as forged if not properly registered, and lack flexibility in real-time authentication decisions.
Innovation Solution
A method and system that allows a client to deliver app signature authentication information and user identifiers to a server, enabling the server to dynamically allow or block application execution based on business situations, using a whitelist and blacklist managed by the application operator.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all signature types are pre-registered in the whitelist, then forgery detection accuracy is improved, but device complexity and operational burden increase
Solution Approach 1:
The patent applies preliminary action by pre-registering only a representative signature (e.g., distribution signature) in the whitelist before service provision, rather than registering all possible signature types. This reduces the operational burden of maintaining comprehensive whitelists while still enabling effective forgery detection through dynamic signature verification against the pre-registered baseline.
2Measurement precision
If all signature types are pre-registered in the whitelist, then detection precision is improved, but ease of operation deteriorates
Solution Approach 1:
The patent performs preliminary registration of a representative signature in advance, eliminating the need for ongoing manual registration of multiple signature types. This maintains verification precision while significantly improving ease of operation by reducing whitelist maintenance to a one-time setup process.
Solution Approach 2:
The system enables self-service by automatically managing signature verification using the pre-registered representative signature. The server autonomously compares application signatures against the registered baseline without requiring manual intervention for each signature type, thereby improving operational ease while maintaining detection precision.
3Device complexity
If normal signature information is not registered in advance, then device complexity is reduced, but reliability deteriorates causing false identification
Solution Approach 1:
The patent applies preliminary action by registering at least one representative signature (such as a distribution signature) before service provision. This single pre-registration maintains system simplicity while preventing false identification of normal applications, as the server can verify signatures against this baseline without requiring comprehensive registration of all signature types.
Solution Approach 2:
The pre-registered representative signature serves multiple functions: it acts as a baseline for verifying distribution signatures, development signatures, and QA signatures. This universal reference point enables reliable authentication of various application types without increasing system complexity or requiring separate registration for each signature category.
Data Source
AI summary
A client transmits signature information for an application and a user's identifier (for example, user ID) to a server, and the server allows an application operator to decide whether to allow or block application authentication according to the business circumstances, and thus, forgery of a mobile application can be flexibly detected without registering all signatures in advance.


