US2016132317A1PendingUtilityA1

Secure Application Distribution Systems and Methods

Assignee: INTERTRUST TECH CORPPriority: Nov 6, 2014Filed: Nov 6, 2015Published: May 12, 2016
Est. expiryNov 6, 2034(~8.3 yrs left)· nominal 20-yr term from priority
G06F 8/71H04W 4/003G06F 8/65H04W 4/60G06F 21/125G06F 8/60
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are described that use software diversification techniques to improve the security of mobile applications. Embodiments of the disclosed systems and methods may, among other things, facilitate secure application distribution through deployment of diverse of applications in an application distribution channel. Software diversification consistent with certain disclosed embodiments may mitigate large-scale automated circumvention of security protections by presenting attacking malware moving and/or otherwise unpredictable diverse targets.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for generating and distributing diverse application instances performed by a system comprising a processor and a non-transitory computer-readable storage medium storing instructions that, when executed, cause the system to perform the method, the method comprising:
 generating a first instance of an application;   transmitting the first instance of the application to an application store system for distribution to one or more user devices;   generating a second instance of the application, the second instance of the application being different, at least in part, than the first instance of the application;   accessing a policy associated with a release of the second instance of the application to the application store system; and   transmitting the second instance of the application to the application store system at a time determined based on the accessed policy, the second instance of the application being configured to replace the first instance of the application in the application store system for distribution to the one or more user devices.   
     
     
         2 . The method of  claim 1 , wherein generating the first instance of the application comprises embedding code in the application unique to the first instance of the application. 
     
     
         3 . The method of  claim 2 , wherein the code is embedded in a subcomponent of the application. 
     
     
         4 . The method of  claim 1 , wherein generating the first instance of the application comprises embedding data in the application unique to the first instance of the application. 
     
     
         5 . The method of  claim 4 , wherein the data is embedded in a subcomponent of the application. 
     
     
         6 . The method of  claim 4 , wherein the embedded data comprises at least one of a key, a nonce, and random salt data. 
     
     
         7 . The method of  claim 1 , wherein generating the second instance of the application comprises embedding code in the application unique to the second instance of the application. 
     
     
         8 . The method of  claim 7 , wherein the code is embedded in a subcomponent of the application. 
     
     
         9 . The method of  claim 1 , wherein generating the second instance of the application comprises embedding data in the application unique to the second instance of the application. 
     
     
         10 . The method of  claim 9 , wherein the data is embedded in a subcomponent of the application. 
     
     
         11 . The method of  claim 9 , wherein the embedded data comprises at least one of a key, a nonce, and random salt data. 
     
     
         12 . The method of  claim 1 , wherein the policy associated with the release of the second instance of the application specifies an instance release time period following transmission of the first instance of the application to the application store system and the determined time is based on the instance release time period. 
     
     
         13 . The method of  claim 1 , wherein the policy associated with the release of the second instance of the application specifies a randomly determined release time period and the determined time is randomly determined.

Join the waitlist — get patent alerts

Track US2016132317A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.