Processor-Specific Obfuscated Virtual Machines for Secure Element Cloning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-based secure elements in mobile devices are vulnerable to cloning and lack adequate security measures, particularly when storing sensitive data like cryptographic keys or user credentials, as they are not as secure as hardware-based elements and can be exposed to hostile environments.

Innovation Solution

A method is developed to generate a structure comprising obfuscated virtual machines by obfuscating source code, associating processor and user-specific identifiers, and compiling them to create processor- and user-specific obfuscated virtual machines, which are integrated into a tree of trust and secured with a monotonic counter to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-based secure elements are used to store sensitive data in mobile devices, then integration and functionality are improved, but security level deteriorates due to exposure to hostile environments and vulnerability to cloning

Engineering Contradiction:
Improveintegration capabilityVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the secure element functionality into multiple virtual machines (VMs) that are further divided into processor-specific instances. Each VM is compiled with unique processor identifiers, creating segmented security domains that isolate sensitive operations and data, thereby maintaining security even in software-based implementations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making each virtual machine instance unique to a specific processor through compilation with processor identifiers. This creates locally optimized and secured VM instances that are tailored to their specific execution environment, enhancing security at the local level while maintaining overall system integration.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If virtual machines are used in software-based secure elements, then flexibility and adaptability are improved, but vulnerability to cloning and reverse engineering increases

Engineering Contradiction:
ImproveflexibilityVSAvoidcloning vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces asymmetry by compiling virtual machines with unique processor identifiers and secret identifiers that are specific to each processor instance. This creates asymmetric VM instances that are not identical copies, making cloning ineffective since each VM is uniquely bound to its processor through asymmetric compilation parameters.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent changes parameters by incorporating processor identifiers and secret identifiers into the VM compilation process. These parameter changes create unique VM instances that are sensitive to their specific compilation parameters, thereby preventing cloning since copied VMs would lack the correct processor-specific parameters required for execution.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If processor-specific identifiers are associated with virtual machine source code, then security against cloning is improved, but device complexity increases

Engineering Contradiction:
Improveanti-cloning securityVSAvoidcompilation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies preliminary action by pre-compiling virtual machines with processor identifiers and secret identifiers before deployment. This preliminary compilation step binds the VMs to specific processors in advance, creating security bindings that prevent cloning without requiring complex runtime verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying in a controlled manner by allowing VM source code to be copied and distributed, but the compilation process with processor-specific identifiers ensures that only authorized copies can be executed. The copying principle is applied to distribute VMs while the compilation step prevents unauthorized execution of copied instances.

Inventive Principle:
Principle #26Copying

4Reliability

If multiple security measures are implemented in software-based secure elements, then security level is improved, but ease of manufacture and deployment deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoiddeployment simplicity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system achieves universality by creating a multi-functional compilation process that handles multiple security requirements in a single step. The VM compiler simultaneously processes obfuscation, processor identifier association, and secret identifier integration, thereby implementing multiple security measures without proportionally increasing deployment complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9563754B2Method of generating a structure and corresponding structure
Publication Date: 2017.02.07 NXP BV
  • US9563754B2 patent drawing
  • US9563754B2 patent drawing
  • US9563754B2 patent drawing

AI summary

Disclosed is a method of generating a structure comprising at least one virtual machine, the method comprising: obfuscating a first virtual machine source code, thereby yielding a first obfuscated virtual machine (OVM) source code; associating a processor identifier with the first OVM source code, thereby yielding a processor-specific first OVM source code; compiling the processor-specific first OVM source code, thereby yielding a processor-specific first OVM. Furthermore, a structure generated by said method is disclosed.