Network Enforcer for Mobile Device Malware Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile telecommunications devices infected with malware pose a vulnerability to telecommunications networks, as existing methods rely on self-policing by the device, which may not be trustworthy if compromised.

Innovation Solution

A system where the telecommunications network controls mobile devices through an 'enforcer' module, allowing it to independently manage and restrict malicious behavior by signaling instructions directly to the device, thereby reducing reliance on the device's internal state and operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If the mobile device uses self-policing methods to detect and control malicious behavior, then device autonomy and internal control capability are improved, but reliability deteriorates because an infected device cannot be trusted to police itself

Engineering Contradiction:
Improvedevice self-control capabilityVSAvoidtrustworthiness of control mechanism
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent introduces a base station as an intermediary between the mobile device and the network. The base station runs an enforcer that monitors device behavior and executes control decisions, acting as a trusted mediator that neither the device nor the core network must fully trust. This resolves the contradiction by providing automated control (principle 38) through an external intermediary (principle 24) that maintains reliability even when the device is compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of having the device police itself (internal control), the patent inverts the control architecture by placing the enforcement mechanism in the base station. The device generates behavior logs that are analyzed externally, and control decisions are pushed down to the device rather than being generated by the device itself. This inversion resolves the trust issue while maintaining automated response capabilities.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If the network implements comprehensive monitoring and control of mobile devices, then network security is improved, but device complexity increases due to additional control mechanisms

Engineering Contradiction:
Improvenetwork securityVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The base station enforcer acts as an intermediary that centralizes the complex monitoring and control functions. Rather than distributing complexity across multiple network elements or embedding complex control logic in each device, the enforcer consolidates these functions at the base station level, simplifying the overall system architecture while maintaining comprehensive security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback loop where the device continuously logs its behavior, the base station enforcer analyzes these logs against security policies, and control decisions are pushed back to the device for execution. This automated feedback mechanism enables comprehensive security monitoring without requiring complex manual intervention or device-side decision-making logic.

Inventive Principle:
Principle #23Feedback

3Reliability

If the enforcer is implemented as a separate component in the mobile device, then control independence from the operating system is improved, but device complexity increases

Engineering Contradiction:
Improvecontrol independenceVSAvoidcomponent structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent places the enforcer in the base station rather than as a separate device component, using the base station as an intermediary to provide control independence. This eliminates the need for additional device components while achieving the same goal of OS-independent control, as the base station enforcer operates outside the device's operating system environment entirely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2929670B1System to protect a mobile network
Publication Date: 2019.07.03 KONINK KPN NV
  • EP2929670B1 patent drawingFigure 1
  • EP2929670B1 patent drawingFigure 2
  • EP2929670B1 patent drawingFigure 3

AI summary

A system is described for controlling a mobile telecommunications device, in which the mobile device includes an enforcer which can be controlled by the telecommunications network. The telecommunications network signals the enforcer in order to gain control of the mobile device. The enforcer may be a hardware component within the mobile telecommunications device and in particular is coupled between the baseband and applications processors. The system allows a telecommunications network to gain control of a device in the event that the device is corrupted by rogue or malicious software and behaves in a way deleterious to the network.