IP Library Granted Patent US 10,516,690
Granted Patent B2
US 10,516,690 · App. 15/012,323 · Granted Dec 24, 2019

Physical device detection for a mobile application

Inventors: Shreyans Mehta (Fremont, CA); Ameya Talwalkar (Saratoga, CA)
Assignee: Cequence Security, Inc.
H04L63/1433H04L67/02H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,516,690
App. No.
15/012,323
Granted
Dec 24, 2019
Kind
B2
Abstract

Techniques to facilitate detection of whether or not applications are executed on physical devices are disclosed herein. In at least one implementation, a mobile application that generates a web service request is executed on a computing system. The computing system executes a client security component of the mobile application to collect attributes associated with the computing system and an operating environment on which the mobile application is executing, and utilizes a mobile application programming interface to transfer the web service request including the attributes for delivery to a web server. The web server executes a server security component of a web service to extract the attributes from the web service request and process the attributes to determine whether or not the mobile application is being executed on a physical mobile device.

Claims (35)

1. A method of operating a communication system to facilitate detection of whether or not applications are executed on physical devices, the method comprising:

in a computing system:

executing a mobile application that generates a web service request;

executing a client security component of the mobile application to collect attributes associated with the computing system and an operating environment on which the mobile application is executing, wherein the attributes include hardware attributes representative of the physical configuration of the computing system and installed application attributes representative of software applications installed on the computing system, wherein the client security component utilizes hardware detection techniques to detect the presence or absence of physical hardware components in the computing system to determine the hardware attributes representative of the physical configuration of the computing system; and

utilizing a mobile application programming interface to transfer the web service request including the attributes for delivery to a web server; and

in the web server, executing a server security component of a web service to extract the attributes from the web service request and process the attributes to determine whether the mobile application is being executed on a physical mobile device or on an emulated mobile device.

2. The method of claim 1 further comprising, if the server security component of the web service determines that the mobile application is being executed on the physical mobile device, the server security component is configured to use the determination that the mobile application is being executed on the physical mobile device as at least one factor to validate the web service request, and provide the web service request to the web service upon successful validation.

3. The method of claim 2 wherein the server security component configured to provide the web service request to the web service upon successful validation comprises the server security component configured to remove the attributes from the web service request and provide the web service request without the attributes to the web service.

4. The method of claim 1 wherein the computing system comprises the physical mobile device on which the mobile application is being executed.

5. The method of claim 1 wherein the computing system is running the emulated mobile device and wherein the computing system executing the mobile application comprises the computing system executing the mobile application on the emulated mobile device.

6. The method of claim 1 wherein the web server executing the server security component of the web service to process the attributes to determine whether or not the mobile application is being executed on the physical mobile device comprises executing the server security component of the web service to compare a total number of the attributes to a threshold number of attributes to determine whether or not the mobile application is being executed on the physical mobile device.

7. The method of claim 1 wherein the hardware detection techniques utilized by the client security component comprise polling the physical hardware components to determine the presence or absence of the physical hardware components in the computing system.

8. A communication system to facilitate detection of whether or not applications are executed on physical devices, the communication system comprising:

a computing system configured to execute, using a first processor, a mobile application stored in memory of the computing system to generate a web service request and execute a client security component of the mobile application to collect attributes associated with the computing system and an operating environment on which the mobile application is executing and utilize a mobile application programming interface to transfer the web service request including the attributes for delivery to a web server, wherein the attributes include hardware attributes representative of the physical configuration of the computing system and installed application attributes representative of software applications installed on the computing system, wherein the client security component utilizes hardware detection techniques to detect the presence or absence of physical hardware components in the computing system to determine the hardware attributes representative of the physical configuration of the computing system; and

the web server configured to execute, using a second processor, a server security component of a web service to extract the attributes from the web service request and process the attributes to determine whether the mobile application is being executed on a physical mobile device or on an emulated mobile device.

9. The communication system of claim 8 further comprising, if the server security component of the web service determines that the mobile application is being executed on the physical mobile device, the server security component is configured to use the determination that the mobile application is being executed on the physical mobile device as at least one factor to validate the web service request, and provide the web service request to the web service upon successful validation.

10. The communication system of claim 9 wherein the server security component configured to provide the web service request to the web service upon successful validation comprises the server security component configured to remove the attributes from the web service request and provide the web service request without the attributes to the web service.

11. The communication system of claim 8 wherein the computing system comprises the physical mobile device on which the mobile application is being executed.

12. The communication system of claim 8 wherein the computing system is running the emulated mobile device and wherein the computing system configured to execute the mobile application comprises the computing system configured to execute the mobile application on the emulated mobile device.

13. The communication system of claim 8 wherein the web server configured to execute the server security component of the web service to process the attributes to determine whether or not the mobile application is being executed on the physical mobile device comprises the web server configured to execute the server security component of the web service to compare a total number of the attributes to a threshold number of attributes to determine whether or not the mobile application is being executed on the physical mobile device.

14. The communication system of claim 8 wherein the hardware detection techniques utilized by the client security component comprise polling the physical hardware components to determine the presence or absence of the physical hardware components in the computing system.

15. An apparatus comprising:

one or more non-transitory computer-readable storage media; and

first program instructions comprising a client security component of a mobile application, the first program instructions stored on the one or more non-transitory computer-readable storage media that, when executed by a computing system, direct the computing system to at least:

collect attributes associated with the computing system and an operating environment on which the mobile application is executing, wherein the attributes include hardware attributes representative of the physical configuration of the computing system and installed application attributes representative of software applications installed on the computing system, wherein the client security component utilizes hardware detection techniques to detect the presence or absence of physical hardware components in the computing system to determine the hardware attributes representative of the physical configuration of the computing system;

include the attributes in a web service request generated by the mobile application; and

utilize a mobile application programming interface to transfer the web service request including the attributes for delivery to a web server; and

second program instructions comprising a server security component of a web service, the second program instructions stored on the one or more computer-readable storage media that, when executed by the web server, direct the web server to at least:

extract the attributes from the web service request; and

process the attributes to determine whether the mobile application is being executed on a physical mobile device or on an emulated mobile device.

16. The apparatus of claim 15 wherein the computing system is operatively coupled to the one or more non-transitory computer-readable storage media and the computing system reads and executes the first program instructions.

17. The apparatus of claim 15 wherein the web server is operatively coupled to the one or more non-transitory computer-readable storage media and the web server reads and executes the second program instructions.

18. The apparatus of claim 15 wherein the computing system comprises the physical mobile device on which the mobile application is being executed.

19. The apparatus of claim 15 wherein the computing system is running the emulated mobile device and the mobile application is being executed on the emulated mobile device.

20. The apparatus of claim 15 wherein the second program instructions direct the web server to process the attributes to determine whether or not the mobile application is being executed on the physical mobile device by directing the web server to compare a total number of the attributes to a threshold number of attributes to determine whether or not the mobile application is being executed on the physical mobile device.

Assignments (2)
CHANGE OF NAME Recorded Dec 13, 2018
From: STEALTH SECURITY, INC.
To: CEQUENCE SECURITY, INC.
Reel/Frame 047858/0710 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2016
From: MEHTA, SHREYANS; TALWALKAR, AMEYA
To: STEALTH SECURITY, INC.
Reel/Frame 037635/0402 →
Continuity (2)
Provisional Application 62114383 · Feb 10, 2015
Related Publication 20160234244A1 · Aug 11, 2016