SDK Fraud Prevention via Communicative Isolation Wrapper

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in detecting and mitigating fraudulent or corrupted Software Development Kits (SDKs) on user equipment, which can lead to fraud, corruption, and security vulnerabilities, as these SDKs can communicate directly with operating systems and remote servers, making it difficult to rapidly and accurately identify and address performance issues.

Innovation Solution

A system and method that involves wrapping SDKs in a communicatively isolating wrapper on user equipment, allowing for monitoring and interception of API calls, evaluating these calls against predefined rules, and executing actions such as shutting down or modifying the SDK's functionality to prevent fraudulent activities and ensure secure communication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SDKs are allowed to communicate directly with operating systems and remote servers, then functionality and ease of operation are improved, but security and reliability deteriorate due to fraud and corruption risks

Engineering Contradiction:
ImproveSDK functionalityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a wrapper as an intermediary component that sits between the SDK and the operating system/remote servers. This wrapper monitors and controls API calls, allowing legitimate functionality while blocking fraudulent activities. The wrapper acts as a mediator that enables communication when safe and prevents communication when malicious, thus resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SDKs are monitored and wrapped to prevent fraud, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the SDK functionality by wrapping it in a separate controllable layer. Instead of making the entire SDK complex and hard to manage, the segmentation allows the core SDK to remain simple while the wrapper provides the security functionality. This modular approach improves security without excessively complicating the overall system structure.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If fraudulent SDKs are detected and mitigated, then harmful factors are reduced, but loss of time occurs in monitoring and evaluating API calls

Engineering Contradiction:
Improvefraud preventionVSAvoidAPI call monitoring time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring the wrapper with rules and criteria for evaluating API calls. Instead of analyzing each API call from scratch, the wrapper has pre-established security policies and patterns that allow it to quickly evaluate calls against known fraud indicators. This reduces the time loss associated with monitoring while maintaining effective fraud detection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10623417B1Software development kit (SDK) fraud prevention and detection
Publication Date: 2020.04.14 T MOBILE INNOVATIONS LLC
  • US10623417B1 patent drawing
  • US10623417B1 patent drawing
  • US10623417B1 patent drawing

AI summary

Discussed herein are systems and methods for detecting fraud, corruption, and malfunctions of applications on a user equipment by identifying and separating a software developer kit (SDK) from an application package and encasing the separated SDK in a wrapper to communicatively isolate it from the operating system and other elements of the UE. By monitoring and intercepting API calls from SDKs encased in wrappers, the UE determines what action to take based on an evaluation of the intercepted API calls.