Processor-Specific Obfuscated Virtual Machines for Secure Element Cloning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software-based secure elements in mobile devices are vulnerable to cloning and lack adequate security measures, particularly when storing sensitive data like cryptographic keys or user credentials, as they are not as secure as hardware-based elements and can be exposed to hostile environments.
Innovation Solution
A method is developed to generate a structure comprising obfuscated virtual machines by obfuscating source code, associating processor and user-specific identifiers, and compiling them to create processor- and user-specific obfuscated virtual machines, which are integrated into a tree of trust and secured with a monotonic counter to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software-based secure elements are used to store sensitive data in mobile devices, then integration and functionality are improved, but security level deteriorates due to exposure to hostile environments and vulnerability to cloning
Solution Approach 1:
The system segments the secure element functionality into multiple virtual machines (VMs) that are further divided into processor-specific instances. Each VM is compiled with unique processor identifiers, creating segmented security domains that isolate sensitive operations and data, thereby maintaining security even in software-based implementations.
Solution Approach 2:
The patent applies local quality by making each virtual machine instance unique to a specific processor through compilation with processor identifiers. This creates locally optimized and secured VM instances that are tailored to their specific execution environment, enhancing security at the local level while maintaining overall system integration.
2Adaptability or versatility
If virtual machines are used in software-based secure elements, then flexibility and adaptability are improved, but vulnerability to cloning and reverse engineering increases
Solution Approach 1:
The system introduces asymmetry by compiling virtual machines with unique processor identifiers and secret identifiers that are specific to each processor instance. This creates asymmetric VM instances that are not identical copies, making cloning ineffective since each VM is uniquely bound to its processor through asymmetric compilation parameters.
Solution Approach 2:
The patent changes parameters by incorporating processor identifiers and secret identifiers into the VM compilation process. These parameter changes create unique VM instances that are sensitive to their specific compilation parameters, thereby preventing cloning since copied VMs would lack the correct processor-specific parameters required for execution.
3Reliability
If processor-specific identifiers are associated with virtual machine source code, then security against cloning is improved, but device complexity increases
Solution Approach 1:
The system applies preliminary action by pre-compiling virtual machines with processor identifiers and secret identifiers before deployment. This preliminary compilation step binds the VMs to specific processors in advance, creating security bindings that prevent cloning without requiring complex runtime verification mechanisms.
Solution Approach 2:
The patent uses copying in a controlled manner by allowing VM source code to be copied and distributed, but the compilation process with processor-specific identifiers ensures that only authorized copies can be executed. The copying principle is applied to distribute VMs while the compilation step prevents unauthorized execution of copied instances.
4Reliability
If multiple security measures are implemented in software-based secure elements, then security level is improved, but ease of manufacture and deployment deteriorates
Solution Approach 1:
The system achieves universality by creating a multi-functional compilation process that handles multiple security requirements in a single step. The VM compiler simultaneously processes obfuscation, processor identifier association, and secret identifier integration, thereby implementing multiple security measures without proportionally increasing deployment complexity.
Data Source
AI summary
Disclosed is a method of generating a structure comprising at least one virtual machine, the method comprising: obfuscating a first virtual machine source code, thereby yielding a first obfuscated virtual machine (OVM) source code; associating a processor identifier with the first OVM source code, thereby yielding a processor-specific first OVM source code; compiling the processor-specific first OVM source code, thereby yielding a processor-specific first OVM. Furthermore, a structure generated by said method is disclosed.


