White-Box Cryptography for Secure Mobile Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile transaction systems require secure hardware, which is not always available or user-friendly, making it difficult to securely use mobile devices for financial transactions without compromising security or requiring complex customization.
Innovation Solution
The method employs white-box cryptographic techniques to create a secure environment on a mobile device, using a generic transaction application that can be downloaded and initialized with a user key, allowing for secure storage and encryption of sensitive data without relying on secure hardware, and can emulate a contactless payment card using NFC technology.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure hardware (secure element) is used to protect sensitive transaction data, then security is improved, but device complexity and user customization requirements increase
Solution Approach 1:
The patent replaces the physical secure element hardware with a software-based white-box cryptographic implementation. Instead of relying on a dedicated secure hardware component, the sensitive transaction data is protected through cryptographic transformations embedded in the application software itself, allowing the same security function to be achieved through software rather than hardware.
Solution Approach 2:
The patent transforms the security model by changing from hardware-based physical protection to software-based cryptographic protection. The white-box cryptographic environment modifies how security is implemented by using cryptographic parameters and transformations that protect keys and sensitive data entirely within the software execution environment, eliminating the need for separate secure hardware infrastructure.
2Reliability
If secure element is used for transaction applications, then security is improved, but ease of operation deteriorates due to customization requirements
Solution Approach 1:
The patent creates a universal white-box cryptographic environment that can be implemented in any mobile device without requiring specific hardware configurations or secure element support. The same application can be deployed across different devices and platforms, providing consistent security and functionality without needing device-specific customization or partnerships with hardware manufacturers.
Solution Approach 2:
The patent effectively copies the security functionality of a secure element into software form. The white-box cryptographic implementation replicates the protective functions of hardware-based security within the application code itself, allowing the security mechanism to be distributed and installed like any other software application without requiring special hardware infrastructure.
3Device complexity
If white-box cryptographic techniques are used instead of secure hardware, then device complexity is reduced, but security may be compromised
Solution Approach 1:
The patent replaces hardware-based security mechanisms with software-based white-box cryptographic mechanisms. The security function is substituted from the hardware domain to the software domain, using cryptographic transformations and obfuscation techniques that protect sensitive data and keys within the software execution environment without requiring secure hardware infrastructure.
Solution Approach 2:
The patent introduces white-box cryptographic transformations as an intermediary layer between the application logic and the sensitive data/keys. This intermediary layer performs cryptographic operations that protect the confidentiality and integrity of transaction data while allowing the application to function normally, bridging the gap between software convenience and security requirements.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
A mobile computing device has a processor and a memory. A mobile transaction application 101 is installed and initialised on the mobile computing device. The memory comprises a local database 102 to hold data items for use by the mobile transaction application 101. In initialisation, the mobile transaction application 101 replaces a generic key with a user key for use as a transport key.