Mobile Device Security System for Malicious Code Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices lack effective security measures to detect and mitigate malicious code, making them vulnerable to malware attacks during mobile commerce transactions.

Innovation Solution

A mobile device data security system that establishes a communication link with the device, scans for malicious code in third-party applications, and initiates actions to limit functionalities or remove the threat, including disabling access to affected applications and features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile devices incorporate security protection software, then security against malicious code is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote server as an intermediary that performs the heavy lifting of malicious code detection and analysis. The mobile device only needs to communicate with this server, transferring application data for scanning and receiving control instructions in return. This mediator approach allows the device to gain comprehensive security protection without bearing the full complexity burden locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security system is divided into multiple components distributed across different locations: a lightweight client on the mobile device, a communication module for data exchange, and a comprehensive analysis server that performs the heavy scanning and detection work. This segmentation allows each component to be optimized independently, reducing the complexity burden on the mobile device while maintaining overall system effectiveness.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If security scans are performed on third-party applications, then detection of malicious code is improved, but processing time and user experience are worsened

Engineering Contradiction:
Improvemalicious code detectionVSAvoidscan processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs security scanning in advance, either when applications are installed or before they are executed. By conducting the malicious code detection beforehand rather than during active use, the system ensures thorough scanning without causing delays to the user's workflow. The application is scanned and validated before being allowed to run, preventing time loss during critical usage moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The remote server acts as an intermediary that handles the time-consuming scanning and analysis operations. The mobile device quickly transmits application data to the server, which then performs the comprehensive security check and returns results. This distribution of processing workload to a dedicated server eliminates the time penalty from local scanning while maintaining high detection precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If control signals are transmitted to limit functionalities, then mitigation of malicious code effects is improved, but user convenience is worsened

Engineering Contradiction:
Improvemalicious code mitigationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security control system dynamically adjusts functionality restrictions based on the specific threats detected and the current risk level. Rather than applying fixed, blanket restrictions, the system adapts its control measures to match the actual security needs. When threats are present, functionalities are limited; when the environment is safe, normal operation is restored. This dynamic approach ensures that user convenience is only reduced when absolutely necessary for security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements continuous monitoring and feedback loops that track application behavior and security conditions. When malicious code is detected, control signals are transmitted to limit functionalities. The system then monitors whether the threat persists or has been mitigated, and adjusts controls accordingly. This feedback mechanism ensures that functionality restrictions are temporary and reversible, restoring user convenience once the security threat is resolved.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10002248B2Mobile device data security system
Publication Date: 2018.06.19 BANK OF AMERICA CORP
  • US10002248B2 patent drawing
  • US10002248B2 patent drawing
  • US10002248B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for a mobile device data security system. The present invention is configured to establish a communication link with the mobile device; receive, via the established communication link, information associated with one or more third-party applications stored on the mobile device; initiate a scan, via the established communication link, to determine whether the one or more third-party applications are associated with a malicious code; transmit control signals, via the established communication link, configured to cause the data security application to begin running in the background of the mobile device in response to determining that the one or more third-party applications are associated with the malicious code; and initiate, via the data security application, one or more actions to be executed on the mobile device of the user, wherein the one or more actions limit one or more functionalities of the mobile device.