IMS-Based Mobile Device Locking via SIP Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing mobile devices, such as network-initiated SIM/USIM/ISIM blocking, do not effectively prevent access to locally stored data and can be inconvenient and costly, as they block network services across all associated devices and require new SIM card issuance upon recovery.

Innovation Solution

A method and apparatus that utilize an over-the-air locking instruction via the IP Multimedia Subsystem (IMS) network, allowing users to lock their mobile devices remotely through a SIP Application Server, using IMS registration and authentication to send a Session Initiation Protocol message with an unlocking code, ensuring only authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network-initiated SIM/USIM/ISIM blocking is used to secure mobile devices, then network service access is restricted, but access to locally stored data is not prevented and service access is blocked across all associated devices

Engineering Contradiction:
Improvedata securityVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The invention segments the security control by introducing a device-specific identifier (such as IMEI, MAC address, or serial number) that allows the network to distinguish between different devices associated with the same subscriber. This enables selective locking of individual devices rather than blocking all devices, thus maintaining service accessibility for other devices while securing the lost or stolen device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention applies local quality by implementing device-specific security measures rather than uniform blocking. The network sends targeted locking instructions to specific devices identified by their unique identifiers, allowing different security states for different devices. This ensures that data security is enhanced for the compromised device while other devices continue to function normally.

Inventive Principle:
Principle #3Local quality

2Reliability

If SIM/USIM/ISIM blocking is implemented to prevent device misuse, then network services are blocked, but new SIM card issuance is required upon recovery increasing cost and complexity

Engineering Contradiction:
Improvedevice securityVSAvoidservice recovery process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention implements preliminary action by establishing a reversible locking mechanism that can be activated immediately when a device is reported lost or stolen, and deactivated when the device is recovered. The network maintains a registry of locked devices and their identifiers, allowing rapid activation and deactivation of security measures without requiring physical SIM card replacement or complex service recovery procedures.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If over-the-air locking instructions are sent via IMS network, then selective device locking is achieved, but network impact must be minimized

Engineering Contradiction:
Improveselective device lockingVSAvoidnetwork load
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The invention applies partial action by implementing a lightweight locking mechanism that sends only essential instructions (lock/unlock commands with device identifiers) over the network rather than continuous monitoring or data transmission. The locking state is maintained locally on the device, reducing the need for ongoing network communication and minimizing network load while maintaining selective device locking capability.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2422539B1Mobile device security
Publication Date: 2015.11.25 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2422539B1 patent drawingFigure 1~2
  • EP2422539B1 patent drawingFigure 3
  • EP2422539B1 patent drawingFigure 4

AI summary

A method of securing a mobile wireless telecommunication device to prevent or restrict access to data stored in the device. The method comprises firstly registering the device with a network-based server in respect of a given user. In the event that said user wishes to prevent or restrict access to data stored on the device when the user does not have access to the device but has access to an alternative communication device, the following steps are carried out. The user is authenticated, via said alternative communication device, to an IP Multimedia Subsystem network, and, on the basis of such authentication, the user is allowed to access the server and send to the server an instruction to lock said mobile wireless telecommunication device.