AppSuit KeypadBlock input-data hijacking at the source,
secure input protection with AppSuit Keypad
A security solution that transforms and encrypts input data in real time across mobile app and web environments, based on a virtual keypad
Password input without a secure keypad is handed straight to attackers
Mobile security isn't complete with servers and networks alone. If the moment users enter their accounts, verification codes, and payment details isn't protected, the data can be hijacked as-is, before it is ever encrypted.
Sensitive input data
Input data such as passwords, account details, and verification values is the most sensitive information in a mobile service.
Diverse attack techniques
Input data such as passwords, account details, and verification values is the most sensitive information in a mobile service.
Directly tied to business risk
Input data such as passwords, account details, and verification values is the most sensitive information in a mobile service.
A secure keypad: not a choice, but an essential security requirement
Across financial, public, and personal-data services, protecting the input stage is a fundamental security element specified in regulations and guidelines.
| Application area | Relevant authority | Key regulation | Required security item |
|---|---|---|---|
| Finance / Payment | Financial Services Commission | Electronic Financial Supervisory Regulation Article 15 | Keyboard hacking prevention program |
| Finance / Payment | Financial Security Institute | Smartphone Electronic Financial Service Security Guide | Use of a virtual keypad |
| Public / Administration | Ministry of the Interior and Safety | Mobile e-Government Service Management Guidelines | Application of a secure keypad |
| General / Personal data | Personal Information Protection Commission | Personal Information Protection Act Article 29 | Personal data protection safeguards |
Application area
- Finance / Payment
- Finance / Payment
- Public / Administration
- General / Personal data
Relevant authority
- Finance / Payment
- Financial Services Commission
- Finance / Payment
- Financial Security Institute
- Public / Administration
- Ministry of the Interior and Safety
- General / Personal data
- Personal Information Protection Commission
Key regulation
- Finance / Payment
- Electronic Financial Supervisory Regulation Article 15
- Finance / Payment
- Smartphone Electronic Financial Service Security Guide
- Public / Administration
- Mobile e-Government Service Management Guidelines
- General / Personal data
- Personal Information Protection Act Article 29
Required security item
- Finance / Payment
- Keyboard hacking prevention program
- Finance / Payment
- Use of a virtual keypad
- Public / Administration
- Application of a secure keypad
- General / Personal data
- Personal data protection safeguards
* Input-stage security is not a user-experience nicety, but the starting point of regulatory compliance.
An input-security module that conceals and encrypts user input
A virtual-keypad-based security solution that protects user input — a single-function module dedicated to input-data protection.
Conceal
Transforms input so it is never exposed
The moment a user presses the keypad, the touch coordinates are transformed so that even identical input is processed as a different value every time. It blocks direct exposure of input values and keylogging- and screen-based hijacking at the source.
Encrypt
Encryption of input and transmitted data
From the moment of key entry through to the network transmission segment, data is double-protected so it is never exposed in plaintext. Both inside the device and in transit, it is delivered safely without decryption.
Conceal
A random keypad that neutralizes input patterns
By dynamically changing the keypad layout, it blocks input-pattern analysis and automated attacks. Sequential, random, and blank layouts can be configured to match your policy.
A security operation structure that protects input data
AppSuit Keypad designs a protection structure so that data is never exposed from the moment of input through to transmission.
Input protection stage
Blocking input-data hijacking
The moment a user enters input, the touch position is transformed so that even identical input is processed as a different value.
- Prevents direct exposure of input values
- Blocks keylogging and screen-based hijacking
Processing security stage
Encrypting input data
Entered values are encrypted instantly and protected so they are not decrypted within the device or in the transmission segment.
- Real-time encryption of input values
- Data protection in the network segment
Attack response stage
Real-time attack response
By dynamically changing the keypad layout, it blocks input-pattern analysis and automated attacks. Responding to pattern-analysis attacks
- Supports random / sequential layouts
- Responds to pattern-analysis attacks
Convenience for users and developers
It resolves the usability concerns that arise when adopting a security solution.
Customization flexibility
The UI and color features can be freely changed to match your brand image.
Various keyboard types
It provides layouts suited to diverse service needs, such as numeric/PIN and Korean (Qwerty).
Accessibility support
It includes accessibility features for the visually impaired, considering convenience for all users.
Multi-platform support
It supports Android, iOS, and hybrid apps, and provides full coverage in JavaScript web environments.
Product application method
Not a mere UI, but a 'security infrastructure structure'
Not a mere UI, but a 'security infrastructure structure'
The client library and the WAS server module operate as a pair to protect input values end-to-end.
- 01
Connect
Deliver client and server libraries, samples, and guide documents to the customer
STEALIEN - 02
Add library + install server
Add the library to the development environment and install the keypad server module on the WAS server
Developer - 03
Develop with the guide
Refer to the guide documents and samples to develop keypad integration within the app and web
Developer - 04
Customize, then deploy
Customize features and layout, and more, then deploy to the production environment
Developer
Server integration architecture
A dedicated server module in library (Jar) form supports decryption of encrypted data and the original-text extraction process.
- CLIENTKey/Token generationClient ↔ server exchange
- CLIENTEncrypted data transmissionApp → server
- SERVERData refinementServer module
- SERVERDecryptionServer module
- SERVEROriginal-text extractionDelivered to business logic
Quality certifications and intellectual property
Our keypad security capabilities have been verified through accredited certifications and proprietary technology.
GS (Good Software) Certification Level 1
The highest grade of software quality certification awarded by the Telecommunications Technology Association (TTA). As a nationally accredited certification, the stability and reliability of the keypad module have been officially verified.
Patent registered — virtual secure keypad generation technology
Holds a patent for virtual secure keypad generation technology using noise-based random number generation. By making input patterns hard to predict, it effectively blocks keylogging and input-pattern analysis attacks.
Frequently asked questions
Considering adopting AppSuit Keypad?
We provide technical consultations for adopting the input-security module. POC requests, material requests, and technical inquiries are all welcome.