White Box SDK Obfuscation for Mobile Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices without secure hardware components are vulnerable to hacker attacks and tampering, as they lack protection for sensitive data and applications stored in regular memory.

Innovation Solution

The implementation of a white box software development kit (SDK) that provides obfuscation and cryptography to secure sensitive data and applications on mobile devices, including re-obfuscation at predetermined intervals to prevent decryption by hackers, using cryptographic processes and a trusted application manager server to update and re-encrypt data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If sensitive data is stored in regular memory elements of mobile devices, then storage capacity and accessibility are improved, but security against hacker attacks and tampering deteriorates

Engineering Contradiction:
Improvestorage capacityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a white box software development kit (SDK) as an intermediary layer between the sensitive data and the regular memory elements. This SDK provides obfuscation and cryptography functions that protect the data during storage and access, allowing the system to use regular memory while maintaining security through the mediating protective layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by transforming the sensitive data into obfuscated form using cryptographic processes. The data is encrypted and its parameters (such as readability, structure) are changed so that it becomes inaccessible to hackers while remaining accessible to authorized applications through the white box SDK.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If obfuscation and cryptography are applied to protect sensitive data, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The white box SDK is designed as a universal solution that provides multiple security functions (obfuscation, encryption, anti-tampering) within a single software package. This multi-functional approach consolidates various security mechanisms into one integrated component, reducing the overall complexity that would result from implementing separate security solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The obfuscation and cryptography processes are automatically applied by the white box SDK without requiring manual intervention from developers or users. The SDK self-manages the security operations, including automatic encryption of sensitive data and protection against tampering, thereby reducing the operational complexity despite the sophisticated security measures employed.

Inventive Principle:
Principle #25Self-service

3Reliability

If re-obfuscation is performed at predetermined intervals, then security against decryption attacks is improved, but processing time and energy consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic re-obfuscation at predetermined intervals to refresh the cryptographic protection of sensitive data. This periodic action ensures that even if hackers are attempting decryption, the data will be re-encrypted at scheduled times, rendering their efforts obsolete. The interval is optimized to balance security needs with processing overhead.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The re-obfuscation process is planned and scheduled in advance at predetermined intervals, allowing the system to prepare for security refreshes without causing unexpected disruptions. This preliminary planning enables efficient resource allocation and minimizes the impact on processing time by spreading the re-obfuscation operations across scheduled time slots rather than concentrating them.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11238139B2Methods for securely storing sensitive data on mobile device
Publication Date: 2022.02.01 MASTERCARD INT INC
  • US11238139B2 patent drawing
  • US11238139B2 patent drawing
  • US11238139B2 patent drawing

AI summary

Methods and systems for protecting sensitive data and applications on a mobile device. In an embodiment, a mobile device processor of a mobile device downloads, from a digital wallet server computer, a mobile wallet application including a white box software development kit (SDK) which includes code protection processes, then obfuscates, by running the code protection processes of the white box SDK, consumer financial data and consumer authentication data and stores the obfuscated consumer financial data and consumer authentication data in a regular memory of the mobile device. The process also includes protecting, by the mobile device processor running the white box SDK, sensitive applications stored in the regular memory which execute during a transaction from attack, and re-obfuscating, by the mobile device processor, at least one of the consumer financial data and the consumer authentication data according to a predetermined time interval.