Multi-SIM Mobile Traffic Screening Before OS Exposure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices integrated in vehicles are vulnerable to attacks through compromised SIM profiles, which can introduce malware via mobile networks, posing risks to the vehicle's operation and data integrity.

Innovation Solution

A mobile device with an operating system and multiple SIM profiles is equipped with an intrusion detection system (IDS) positioned upstream of the operating system to monitor and control network traffic, allowing early detection and response to security threats, and optionally integrated with a firewall downstream for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple SIM profiles are provided in the mobile device, then the versatility and connectivity options are improved, but the security vulnerability increases due to potential malware introduction via compromised SIM profiles

Engineering Contradiction:
Improveconnectivity optionsVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

An intrusion detection system is introduced as an intermediary component between the network interface and the operating system. This IDS monitors network traffic and detects malicious packets attempting to exploit SIM profiles, thereby enabling the device to maintain multiple SIM profiles for versatility while protecting against their security vulnerabilities through active monitoring and threat detection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If the intrusion detection system is positioned downstream of the operating system, then the device complexity is reduced, but the reliability of security protection deteriorates due to delayed detection and potential OS compromise

Engineering Contradiction:
Improvesystem architectureVSAvoidsecurity protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The intrusion detection system is positioned upstream of the operating system in the network traffic flow, enabling preliminary detection of malicious packets before they can compromise the OS. This early detection approach ensures that security threats are identified and blocked proactively, maintaining high reliability of security protection while the modular architecture keeps the overall system complexity manageable

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If deep packet inspection is performed on all network traffic, then the detection precision of malware increases, but the processing time and energy consumption increase

Engineering Contradiction:
Improvemalware detection precisionVSAvoidenergy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The intrusion detection system applies deep packet inspection selectively to traffic from untrusted SIM profiles or traffic exhibiting suspicious patterns, rather than uniformly inspecting all network traffic. This localized inspection approach maintains high malware detection precision for critical threats while reducing overall energy consumption by avoiding unnecessary inspection of trusted traffic

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12587856B2Mobile device, method for operating a mobile device, and vehicle
Publication Date: 2026.03.24 MERCEDES BENZ GROUP AG
  • US12587856B2 patent drawing

AI summary

A mobile device includes an operating system and at least two SIM profiles for providing several independent mobile connections. Network traffic is exchanged via at least one mobile connection with a mobile network and information transmitted with the network traffic is identified. The mobile device includes an intrusion detection system or an intrusion detection and defense system configured to identify at least the information transmitted with the network traffic. The intrusion detection system or the intrusion detection and defense system is arranged in a direction of the information flow of network traffic received from at least one mobile connection upstream of the operating system.