Mobile Security App Injection for Malware Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices infected with malware, such as ransomware, often become inaccessible due to reset passcodes or authentication changes, leaving users with no recovery option other than a factory reset, especially if no anti-malware solution is installed.

Innovation Solution

A mobile device security app is injected into the infected device via a third-party service, with instructions transmitted from a clean device using non-handshake communication protocols like NFC, allowing the app to scan, clean, and reset authentication settings, thereby regaining access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a factory reset is performed to recover a malware-infected device, then the device can be restored to a usable state, but all user data and settings are lost

Engineering Contradiction:
Improvedevice recovery capabilityVSAvoiduser data loss
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The security application is installed on the device before malware infection occurs. This preliminary installation ensures that protective and recovery mechanisms are already in place, allowing the app to detect and respond to malware threats without requiring a factory reset, thereby preserving user data while restoring device functionality

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security application acts as an intermediary between the user and the malware-infected system. It provides a recovery mechanism that operates independently of the compromised operating system, enabling data preservation during recovery by mediating the restoration process through its own intact executable code and recovery protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If no anti-malware solution is installed before infection, then the device remains vulnerable to malware, but the recovery process becomes more complex and data loss increases

Engineering Contradiction:
Improvemalware vulnerabilityVSAvoidrecovery process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The security application is installed in advance before any malware infection occurs. This preliminary protective measure ensures that when malware does infect the device, the security app is already present to detect and respond to the threat, simplifying the recovery process and reducing the need for complex manual intervention or factory resets

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security application provides a safety buffer or cushion against malware attacks by being pre-installed on the device. This beforehand protection creates a layer of defense that absorbs the impact of malware infections, enabling easier recovery and reducing the severity of consequences when infections occur

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Ease of operation

If the security app requires user interaction to initiate recovery, then user control is maintained, but recovery cannot proceed if the device is locked by malware

Engineering Contradiction:
Improveuser control during recoveryVSAvoidautomatic recovery capability
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The security application enables the device to recover from malware infection autonomously without requiring user interaction. The app can automatically detect malware presence, initiate recovery protocols, and restore device functionality even when the device is locked or inaccessible to the user, effectively allowing the system to service itself during the recovery process

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security application accelerates the recovery process by using its pre-installed executable code and authentication credentials to rapidly counteract malware effects. The app can quickly restore device access and remove malware without waiting for user input, speeding up the recovery timeline while maintaining effectiveness

Inventive Principle:
Principle #38Strong oxidants (Accelerated oxidation)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables recovery of malware-infected mobile devices without user intervention, allowing users to regain access and remove malware, even if the device is locked or in an inaccessible state.

Implementation Method 1

The signal received from the clean mobile computing device by the malware-infected mobile computing device may be transmitted via a non-handshake communication protocol, such as near field communication (NFC)

Methodology Applied
Scientific EffectNear Field Communication (NFC):

Data Source

PatentUS10963568B1Using security app injection and multi-device licensing to recover device facing denial of access caused by malware infection
Publication Date: 2021.03.30 GEN DIGITAL INC
  • US10963568B1 patent drawing
  • US10963568B1 patent drawing
  • US10963568B1 patent drawing

AI summary

A mobile computing device is infected by malware which blocks access to the infected device by an authorized user. A download and installation request is generated from another device and sent to a third-party service via the internet to allow a first instance of a mobile device security application to be downloaded and installed on the infected device. A second instance of the same mobile device security application is also downloaded and installed on a clean device, with the first and second instances of the mobile device security application being covered under a single license. An instruction is generated on the mobile device security application on the clean device and transmitted to the infected device. Based on the received instruction, the mobile device security app is initiated and at least one access setting is modified on the infected device to enable user access.