Secure Interface Filter for Mobile Device Malware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to malware infections due to the increasing complexity and frequency of electronic attacks, leading to disruptions and loss of confidential information, necessitating a secure interface to monitor and block malicious transmissions.

Innovation Solution

A secure interface for mobile communications devices featuring output communications circuitry, private network communications circuitry, and an input/output filter that separates and filters incoming and outgoing information packets based on programmed criteria, using one-way links and servers to prevent malware and unauthorized data transmission, while enabling communication through mobile or Wi-Fi networks with encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure interface with filtering is implemented, then protection against malware and data leakage is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against malwareVSAvoidinterface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary secure interface device positioned between the mobile device and external networks. This intermediary contains filtering logic and maintains communication tables to monitor and control data packets, effectively protecting the mobile device without requiring complex security implementations within the device itself. The intermediary handles the complexity of malware detection and filtering externally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all incoming and outgoing information is monitored and filtered, then security against malware is improved, but communication speed decreases

Engineering Contradiction:
Improvesecurity against malwareVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The secure interface pre-establishes communication tables containing authorized communication partners and protocols before actual data transmission occurs. By having filtering criteria and trusted entity information ready in advance, the system can quickly match incoming packets against pre-defined rules rather than performing complex analysis on each packet, thereby maintaining communication speed while ensuring security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If device identity is hidden to protect security, then protection against targeted attacks is improved, but ability to receive targeted communications decreases

Engineering Contradiction:
Improveprotection against targeted attacksVSAvoidreceiving targeted communications
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the communication identification function by separating device identity from communication routing. Instead of hiding all device identifiers, the system uses the secure interface to translate between external communication addresses and internal device identifiers. This allows targeted communications to reach the device through the intermediary without exposing the actual device identity to external networks, thus maintaining both security and targeted communication capability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10142289B1Secure interface for a mobile communications device
Publication Date: 2018.11.27 OWL CYBER DEFENSE SOLUTIONS LLC
  • US10142289B1 patent drawing
  • US10142289B1 patent drawing
  • US10142289B1 patent drawing

AI summary

A secure interface for a mobile communications device has output communications circuitry operable to communicate with an external network, private network communications circuitry operable to communicate with a mobile communications device, and an input/output filter connected between the output communications circuitry and the private network communications circuitry. The input/output filter separately filters, based on programmed stored criteria, externally-received information packets from the external network via the output communications circuitry and internally-received information packets from the mobile communications device via the private network communications circuitry. The input/output filter passes the filtered externally-received information packets to an internal connection of the private network communications circuitry for transmission to the mobile communications device and passes the filtered internally-received information packets to an internal connection of the output communications circuitry for transmission to the external network.