Mobile App Signature Authentication With Dynamic Forgery Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile application forgery detection technologies require registering all signatures in advance, leading to normal applications being incorrectly identified as forged if not properly registered, and lack flexibility in real-time authentication decisions.

Innovation Solution

A method and system that allows a client to deliver app signature authentication information and user identifiers to a server, enabling the server to dynamically allow or block application execution based on business situations, using a whitelist and blacklist managed by the application operator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all signature types are pre-registered in the whitelist, then forgery detection accuracy is improved, but device complexity and operational burden increase

Engineering Contradiction:
Improveforgery detection accuracyVSAvoidwhitelist management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-registering only a representative signature (e.g., distribution signature) in the whitelist before service provision, rather than registering all possible signature types. This reduces the operational burden of maintaining comprehensive whitelists while still enabling effective forgery detection through dynamic signature verification against the pre-registered baseline.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If all signature types are pre-registered in the whitelist, then detection precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesignature verification precisionVSAvoidwhitelist maintenance ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent performs preliminary registration of a representative signature in advance, eliminating the need for ongoing manual registration of multiple signature types. This maintains verification precision while significantly improving ease of operation by reducing whitelist maintenance to a one-time setup process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by automatically managing signature verification using the pre-registered representative signature. The server autonomously compares application signatures against the registered baseline without requiring manual intervention for each signature type, thereby improving operational ease while maintaining detection precision.

Inventive Principle:
Principle #25Self-service

3Device complexity

If normal signature information is not registered in advance, then device complexity is reduced, but reliability deteriorates causing false identification

Engineering Contradiction:
Improvesystem complexityVSAvoidapplication authentication reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by registering at least one representative signature (such as a distribution signature) before service provision. This single pre-registration maintains system simplicity while preventing false identification of normal applications, as the server can verify signatures against this baseline without requiring comprehensive registration of all signature types.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The pre-registered representative signature serves multiple functions: it acts as a baseline for verifying distribution signatures, development signatures, and QA signatures. This universal reference point enables reliable authentication of various application types without increasing system complexity or requiring separate registration for each signature category.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12632603B2Method and system for detecting forgery of mobile application by using user identifier and signature collection
Publication Date: 2026.05.19 NAVER CLOUD CORP
  • US12632603B2 patent drawing
  • US12632603B2 patent drawing
  • US12632603B2 patent drawing

AI summary

A client transmits signature information for an application and a user's identifier (for example, user ID) to a server, and the server allows an application operator to decide whether to allow or block application authentication according to the business circumstances, and thus, forgery of a mobile application can be flexibly detected without registering all signatures in advance.