Security Token Dynamic Application Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security tokens face vulnerabilities due to insufficient protection of host computers, which can lead to fraudulent use and attacks on secure applications, despite strong cryptographic algorithms, as attackers can reverse-engineer or hook into secure channels, compromising the security of all tokens with identical applications.

Innovation Solution

A security token with a communication interface and a security module that modifies the content or execution parameters of applications at each connection to a host computer, using encryption-based security features to create a varying and unpredictable execution environment, including obfuscation of code and random selection of execution modules between the token and host computer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the same application is uploaded and executed on multiple host computers, then the application can be widely used and distributed, but the security is compromised because attackers can reverse-engineer or hook into the secure channel

Engineering Contradiction:
Improveapplication distributionVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies dynamics by making the application code mutable rather than static. The security token dynamically modifies the application code before each upload based on connection-specific parameters, ensuring that the same application becomes different binary artifacts for different hosts or even different connections to the same host. This resolves the contradiction by allowing wide distribution while preventing reverse-engineering attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes parameters of the application code including obfuscation level, code structure, and execution flow based on connection parameters from the host computer. By varying these parameters dynamically, the system allows the same application to be distributed widely while each instance has unique characteristics that prevent universal exploitation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If strong cryptographic algorithms are used for the secured channel, then the security is improved, but the security can still be compromised through reverse-engineering or hooking attacks

Engineering Contradiction:
ImprovesecurityVSAvoidattack surface
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary anti-action by modifying the application code before it reaches the host computer, embedding countermeasures against potential attacks in advance. The code is transformed to include anti-debugging, anti-hooking, and anti-reverse-engineering mechanisms as part of the upload process, preventing attackers from exploiting the secure channel even if they attempt reverse-engineering.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of manufacture

If the application code is kept identical across all tokens, then the manufacturing and distribution is simplified, but all tokens become vulnerable to the same attacks

Engineering Contradiction:
Improveapplication deploymentVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing code modification during the upload process rather than during manufacturing. The base application is stored once in the token, and the dynamic modification occurs at connection time, simplifying manufacturing while ensuring each uploaded instance is unique and resistant to attacks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2572308B1Security token for securely executing an application on a host computer
Publication Date: 2017.08.30 THALES DIS FRANCE SA
  • EP2572308B1 patent drawingFigure 1~2
  • EP2572308B1 patent drawingFigure 3~4

AI summary

The invention relates to a security token (ST) comprising: -a communication interface (USB-C, USB-DC) adapted to communicate with a host computer (HC); -a security module (SM), comprising encryption based security features (CR); -a non volatile memory (RO) storing at least an application (OA) to be uploaded and executed in a host computer, said application making use of said security features when executed in a host computer in communication with the communication interface. The security token is adapted (AMM) to modify the content of the application as uploaded or its execution parameters at successive connexions of the security token (ST) to a host computer (HC).