Personalized Mobile App Security via Unique Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device software applications lack personalized security protection, making them vulnerable to attacks as the same security measures are applied to all replicas, increasing the incentive for attackers to crack one instance to access multiple user devices.

Innovation Solution

A method to automatically generate and personalize mobile software applications with unique security parameters and obfuscation rules for each user and device, ensuring that even if one instance is compromised, others remain secure, and implementing a registration process with time limits to restrict service access until proper activation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If the same security protection is applied to all replicas of a mobile software application, then the implementation is simple and consistent, but the incentive for attackers to crack one instance to access multiple user devices increases

Engineering Contradiction:
Improveease of security implementationVSAvoidincentive for attackers
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by personalizing security parameters for each user replica of the mobile software application. Each replica receives unique security configurations including personalized secret keys, obfuscation rules, and security tokens that are specific to that user's device and identity. This transforms the uniform security approach into a localized, user-specific security regime that maintains ease of implementation through automated generation while dramatically reducing the incentive for attackers since compromising one replica does not provide access to other user instances.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If unique security parameters are generated for each user replica, then the incentive for attackers to target multiple devices is reduced, but the system complexity and personalization requirements increase

Engineering Contradiction:
Improveincentive for attackersVSAvoidsecurity personalization complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the system to automatically generate and distribute personalized security parameters to each user replica without requiring manual configuration. The server automatically creates unique secret keys, obfuscation rules, and security tokens for each user based on their device identifiers and user profiles. This automation eliminates the need for complex manual personalization processes while maintaining high levels of security customization, thereby reducing attacker incentives without proportionally increasing system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting security parameters such as secret keys, obfuscation algorithms, and encryption methods for each user replica. Instead of using fixed security configurations, the system varies multiple security parameters across different user instances, creating a diverse security landscape that is difficult for attackers to compromise. This parameter variation is achieved through automated generation processes that adapt security settings based on user-specific information while maintaining manageable system complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security personalization is implemented for each user, then security protection is enhanced, but the time and resources required for deployment and management increase

Engineering Contradiction:
Improvesecurity protection levelVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating and distributing personalized security parameters to user devices before the software application is fully deployed or activated. The server creates unique security configurations for each user in advance, storing them securely on the user's device. This preliminary personalization ensures that when the application is deployed, security protection is already in place, eliminating the need for time-consuming security configuration during or after deployment. This approach enhances security reliability while minimizing deployment time by performing security personalization beforehand through automated processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3120280B1Automated and personalized protection system for mobile applications
Publication Date: 2019.11.13 SEGLAN
  • EP3120280B1 patent drawingFigure 1~1a
  • EP3120280B1 patent drawingFigure 2~2.b
  • EP3120280B1 patent drawingFigure 3~3.c

AI summary

This invention relates to a method and a system to automatically generate mobile device software applications, where each one is differently personalized in terms of security parameters and/or obfuscation rules, by using a set of input registries from a first entity, each input registry containing at least a unique identifier and is used to generate an output personalization registry, that is different than another output registry. A second entity uses at least part of the data of the output registry, a generic replica of the mobile device software application and obfuscation software to generate a protected mobile software application that is associated to the output registry and to the at least one unique identifier. A user requests a replica of the mobile software application to the first entity and a protected mobile software application is downloaded to a user mobile device.