Mobile Terminal IMEI Blocking for Malware Damage Limitation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for limiting damage from malware-infected mobile devices, such as smartphones, often restrict the use of SIM cards, causing inconvenience and allowing temporary use of infected devices to send harmful messages, while not effectively preventing integration into botnets.

Innovation Solution

Implement a method and system that block data traffic for infected mobile devices based on their IMEI, allowing the SIM card to be used across multiple devices without restriction, and provide zero-rated services for cleaning the malware, while maintaining service availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If SMS-MO blocking is implemented on infected devices, then malware propagation is prevented, but legitimate user communication is restricted

Engineering Contradiction:
Improvemalware propagationVSAvoidlegitimate user communication
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent segments the blocking mechanism by introducing a whitelist of allowed destinations. Instead of a complete SMS-MO block, only communications to non-whitelisted numbers are prevented. This allows legitimate user communication (to whitelisted contacts) to continue while blocking malware propagation to unknown destinations, thus resolving the contradiction between preventing harm and maintaining ease of operation.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If complete SIM blocking is implemented, then malware integration into botnets is prevented, but legitimate services are unavailable to users

Engineering Contradiction:
Improvebotnet integrationVSAvoidservice availability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies local quality by implementing selective blocking rather than complete SIM blocking. The system differentiates between legitimate communications (to whitelisted destinations) and malicious communications (to non-whitelisted destinations). This localized approach prevents botnet integration while maintaining service availability for legitimate purposes, resolving the contradiction between preventing harm and ensuring reliability.

Inventive Principle:
Principle #3Local quality

3Difficulty of detecting and measuring

If data traffic monitoring is implemented to detect malware, then infection detection capability is improved, but network resource consumption increases

Engineering Contradiction:
Improveinfection detection capabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of energy

Solution Approach 1:

The patent applies partial action by monitoring only specific data traffic patterns indicative of malware behavior rather than analyzing all data traffic comprehensively. The system focuses on detecting unusual communication patterns, high-volume data transfers, and connections to known malicious IPs. This selective monitoring approach improves infection detection capability while minimizing network resource consumption compared to comprehensive traffic analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4425829B1Damage limitation after malware infection of a mobile terminal capable of being mobile
Publication Date: 2026.05.06 DEUTSCHE TELEKOM AG
  • EP4425829B1 patent drawingFigure 1a~1f

AI summary

The invention relates to a solution for damage limitation after the infection of a mobile communication-enabled terminal equipped with computer functionalities, namely a Mobile Terminal MT (1), with malware. An infection of the MT (1) with malware is detected by specially designed network facilities (2) of the mobile network operator, for whose use a subscriber identification module (SIM) used with the MT (1) authorizes the user of the MT (1). In the event that an infection has been detected in an MT (1), data traffic is blocked for the MT (1) affected by the malware infection, according to the proposed solution, by using the International Mobile Device Identification Number (IMEI) determined for this MT (1) by the network facilities (2) of the network operator.This means that for this MT (1) an IMEI-based blocking of outgoing and incoming data traffic takes place, namely the data traffic bound to an available data volume.