Mobile Device Backup OS for Denial of Service Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to denial of service (DOS) attacks, which can temporarily or permanently render them unusable due to malicious software blocking access to authentication services, and existing solutions either require network changes or only delay the attack without effectively preventing malware from rendering the SIM card useless.

Innovation Solution

A method and protection unit for mobile devices that utilize a backup operating system stored in ROM, which can be replaced with the active operating system if malware is detected, using signals from authentication failures and comparisons with a backup OS to identify and remove malicious code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a predetermined delay is introduced after authentication failures to prevent DOS attacks, then the attack is temporarily delayed, but the user experience deteriorates and the device remains vulnerable if the delay is not noticed

Engineering Contradiction:
ImproveDOS attack preventionVSAvoidUser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A backup operating system is pre-loaded into the mobile device's memory during manufacturing or initial setup. This backup OS serves as a pre-prepared rescue environment that can be immediately activated when malware is detected, eliminating the need for network downloads or external intervention during the crisis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A complete copy of the operating system is maintained in the device's memory as a backup. This copy is identical to the original OS and can replace the infected active OS, ensuring the device can be restored to a functional state without requiring external resources or user intervention.

Inventive Principle:
Principle #26Copying

2Reliability

If network changes are implemented to improve channel assignment and prevent DOS attacks, then DOS resistance is improved, but the complexity of network implementation increases

Engineering Contradiction:
ImproveDOS resistanceVSAvoidNetwork implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The DOS protection capability is extracted from the network infrastructure and embedded directly into the mobile device itself. The backup OS and malware detection mechanisms are stored locally in the device's memory, making the protection self-contained and independent of network modifications or external systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device performs self-diagnosis and self-recovery when malware is detected. The device autonomously detects authentication failures, activates the backup OS, and restores functionality without requiring network intervention, administrator action, or external assistance.

Inventive Principle:
Principle #25Self-service

3Speed

If malware detection and OS replacement is automated, then response time is improved, but the device complexity increases

Engineering Contradiction:
ImproveMalware response timeVSAvoidProtection mechanism complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The mobile device autonomously monitors authentication attempts, detects malware behavior, and triggers backup OS activation without external intervention. The system self-diagnoses the infection and self-repairs by switching to the clean backup environment, eliminating the need for user action or network coordination.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors authentication failure patterns and feeds this information back to the control logic. When a threshold of failures is detected, the system automatically triggers the backup OS activation, creating a closed-loop protection mechanism that responds dynamically to threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2297993B1Protecting a mobile device against a denial of service attack
Publication Date: 2019.08.07 KONINK KPN NV
  • EP2297993B1 patent drawingFigure 1
  • EP2297993B1 patent drawingFigure 2

AI summary

A method of protecting a mobile device against malware is described. The mobile device comprises a backup operating system, the backup operating system being stored, preferably in a ROM, in the mobile device separately from the active operating system. The method comprises the steps of: providing a signal indicative of the possible presence of malware in the mobile device; and, replacing in response to the signal the active operating system with the backup operating system.