White Box SDK Obfuscation for Mobile Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices without secure hardware components are vulnerable to hacker attacks and tampering, as they lack protection for sensitive data and applications stored in regular memory.
Innovation Solution
The implementation of a white box software development kit (SDK) that provides obfuscation and cryptography to secure sensitive data and applications on mobile devices, including re-obfuscation at predetermined intervals to prevent decryption by hackers, using cryptographic processes and a trusted application manager server to update and re-encrypt data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If sensitive data is stored in regular memory elements of mobile devices, then storage capacity and accessibility are improved, but security against hacker attacks and tampering deteriorates
Solution Approach 1:
The patent introduces a white box software development kit (SDK) as an intermediary layer between the sensitive data and the regular memory elements. This SDK provides obfuscation and cryptography functions that protect the data during storage and access, allowing the system to use regular memory while maintaining security through the mediating protective layer.
Solution Approach 2:
The patent applies parameter changes by transforming the sensitive data into obfuscated form using cryptographic processes. The data is encrypted and its parameters (such as readability, structure) are changed so that it becomes inaccessible to hackers while remaining accessible to authorized applications through the white box SDK.
2Reliability
If obfuscation and cryptography are applied to protect sensitive data, then security is improved, but device complexity increases
Solution Approach 1:
The white box SDK is designed as a universal solution that provides multiple security functions (obfuscation, encryption, anti-tampering) within a single software package. This multi-functional approach consolidates various security mechanisms into one integrated component, reducing the overall complexity that would result from implementing separate security solutions.
Solution Approach 2:
The obfuscation and cryptography processes are automatically applied by the white box SDK without requiring manual intervention from developers or users. The SDK self-manages the security operations, including automatic encryption of sensitive data and protection against tampering, thereby reducing the operational complexity despite the sophisticated security measures employed.
3Reliability
If re-obfuscation is performed at predetermined intervals, then security against decryption attacks is improved, but processing time and energy consumption increase
Solution Approach 1:
The patent implements periodic re-obfuscation at predetermined intervals to refresh the cryptographic protection of sensitive data. This periodic action ensures that even if hackers are attempting decryption, the data will be re-encrypted at scheduled times, rendering their efforts obsolete. The interval is optimized to balance security needs with processing overhead.
Solution Approach 2:
The re-obfuscation process is planned and scheduled in advance at predetermined intervals, allowing the system to prepare for security refreshes without causing unexpected disruptions. This preliminary planning enables efficient resource allocation and minimizes the impact on processing time by spreading the re-obfuscation operations across scheduled time slots rather than concentrating them.
Data Source
AI summary
Methods and systems for protecting sensitive data and applications on a mobile device. In an embodiment, a mobile device processor of a mobile device downloads, from a digital wallet server computer, a mobile wallet application including a white box software development kit (SDK) which includes code protection processes, then obfuscates, by running the code protection processes of the white box SDK, consumer financial data and consumer authentication data and stores the obfuscated consumer financial data and consumer authentication data in a regular memory of the mobile device. The process also includes protecting, by the mobile device processor running the white box SDK, sensitive applications stored in the regular memory which execute during a transaction from attack, and re-obfuscating, by the mobile device processor, at least one of the consumer financial data and the consumer authentication data according to a predetermined time interval.


