Securing a web service for use only from a custom iphone app

I want to create an iphone application that has two parts, the application itself and the server side component.

In a user request, the application sends data to the server, which must be processed by the operator operators.

To prevent abuse by the iphone app user, the iphone ID is sent along with the request and operators can blacklist pranksters to deny them access to the iphone service.

So far so good. Now the problem is this: someone can easily detect the address of the server component and write a script to send bogus requests using multiple IP addresses, etc.

So my question is, how can I protect myself from this?

Captchas for protecting against script attacks or for user registration is not an option for this particular application.

If I had control over the download, I would associate a unique ID with each downloaded app, but obviously this is not an option with the AppStore.

What would be your approach to make a portion of the server more secure?

Edit:

How about a call response scheme where the server sends a token to the client based on the client constructing a new token with an algorithm known to both?

At the very least, it makes it harder for an attacker to reverse engineer the ARM binary. Do you have experience (I have 0) with a similar approach?

+2


a source to share


2 answers


As part of your iPhone app, you can enable registration / registration functions, and during this process, collect the iPhone ID. This way, you will have a list of VALIDs on your server and you can ignore requests from any iPhones not on the list (as well as fake / fake requests).



-1


a source


The iPhone application can digitally sign the enrollment message (containing the device ID) and send it to the web application. Of course, this only works until someone pulls out the key from the iPhone app, but it can last ... let's say half an hour.



Indeed, you cannot. Unfortunately.

-1


a source







All Articles