Software Diversification for Mobile Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile software applications are vulnerable to attacks, and existing security measures are not universally effective in preventing large-scale automated circumvention of security protections, as malware can exploit similarities in application deployments across devices.

Innovation Solution

Implementing software diversification techniques to generate and distribute diverse instances of mobile applications, where each device receives a unique implementation of an application, frustrating malware attempts by presenting unpredictable and different targets, akin to polymorphic malware evasion strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software diversification techniques are implemented to generate diverse application instances for each device, then application security is improved by frustrating malware attempts, but device complexity increases due to the need for unique implementation variations across devices

Engineering Contradiction:
Improveapplication securityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by introducing device-specific variations in application implementation. Each device receives a uniquely customized version of the application with modified code sequences, control flow structures, and data arrangements tailored to that specific device's characteristics (processor architecture, memory layout, etc.). This localized customization ensures that malware developed for one device cannot easily compromise other devices, thereby improving security while managing complexity through targeted rather than universal modifications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements parameter changes by systematically varying multiple parameters within the application code for each device instance. These variations include changing instruction sequences, modifying control flow paths, altering data storage locations, and adjusting runtime parameters. By changing these parameters across different device deployments, the application maintains functional equivalence while presenting different targets to potential malware attacks, thus improving security without requiring complete redesign of the application architecture.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If diverse application instances are distributed to various devices through application stores, then security protections become more effective against large-scale automated attacks, but manufacturing precision requirements increase to ensure consistent functionality across diverse implementations

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidapplication consistency
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent applies preliminary action by pre-configuring diversification parameters and security constraints during the application development and compilation phase. Before distribution, the system establishes the framework for generating diverse instances, including predefined variation ranges, mandatory functional requirements, and security-critical code segments that must remain consistent across all device versions. This preliminary setup ensures that subsequent device-specific customizations maintain both security effectiveness and functional consistency without requiring post-deployment adjustments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent manages manufacturing precision through controlled parameter changes. While allowing variations in non-critical parameters (such as code sequencing, data layout, and optional features), the system maintains strict control over critical parameters that affect core functionality and security. This selective parameter management ensures that diverse application instances remain functionally equivalent and meet quality standards while still providing the security benefits of differentiation against malware attacks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12050904B2Secure application distribution systems and methods
Publication Date: 2024.07.30 INTERTRUST TECH CORP
  • US12050904B2 patent drawing
  • US12050904B2 patent drawing
  • US12050904B2 patent drawing

AI summary

Systems and methods are described that use software diversification techniques to improve the security of mobile applications. Embodiments of the disclosed systems and methods may, among other things, facilitate secure application distribution through deployment of diverse of applications in an application distribution channel. Software diversification consistent with certain disclosed embodiments may mitigate large-scale automated circumvention of security protections by presenting attacking malware moving and/or otherwise unpredictable diverse targets.