Secure Notification via Intermediary Server for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware protection systems struggle to effectively alert users to malware infections, especially when the malware is concealed, as it can block notifications and render antivirus mechanisms ineffective.
Innovation Solution
A system and method for securely notifying users of compromised devices by utilizing a detection device to identify compromised devices, a subscriber database to store user information, and a secure signal path to deliver notifications to non-compromised devices associated with the user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If malware is concealed to avoid detection and deletion, then the malware can remain installed and operational longer, but the user cannot be effectively alerted to the infection
Solution Approach 1:
The patent introduces an intermediary notification system that uses a trusted third-party server to deliver security alerts to users through alternative communication channels. When malware infects a device, the detection system sends notifications via a mediator server that can reach the user through other devices or communication methods, bypassing the blocked notification channels on the compromised device.
Solution Approach 2:
The patent transitions notification delivery from a single-device dimension to a multi-device dimension. Instead of attempting to notify users through the compromised device alone, the system expands notification delivery across multiple devices and communication channels associated with the user, such as other smartphones, tablets, or email accounts, thereby operating in an additional spatial dimension of device ecosystem.
2Device complexity
If traditional notification methods are used on compromised devices, then the system structure remains simple, but the notifications are blocked by malware and fail to reach users
Solution Approach 1:
A trusted third-party server acts as a mediator between the detection system and the user's devices. This intermediary receives detection results, looks up associated devices through a subscriber database, and delivers notifications through alternative channels, ensuring reliable delivery without requiring complex changes to the original device's notification infrastructure.
Solution Approach 2:
The notification system is designed to work across multiple device types and communication channels universally. The subscriber database stores diverse contact information (phone numbers, email addresses, device identifiers), and the system can deliver notifications through any of these channels, making the notification mechanism universally applicable regardless of which specific device is compromised.
3Reliability
If a secure alternative notification path is implemented, then notification delivery reliability improves, but the system complexity increases due to additional components and pathways
Solution Approach 1:
The trusted third-party server serves as a centralized intermediary that manages the complexity of multi-channel notification delivery. Instead of implementing complex notification logic in each device or detection system, all complexity is consolidated in the intermediary server, which handles database lookups, channel selection, and delivery coordination, thereby distributing complexity to a dedicated component rather than proliferating it across the system.
Solution Approach 2:
The system implements self-service mechanisms where the subscriber database automatically stores and manages user contact information, and the trusted server autonomously selects appropriate notification channels based on available information. This reduces the need for manual configuration and complex decision-making logic, allowing the system to self-manage the complexity of alternative notification pathways.
Data Source
AI summary
A system, device and method to securely notify a user of a compromise of a device are provided. The system, device and method may include a detection device adapted for determining a compromise of the device communicatively coupled to the first path, a user database including at least information regarding the device and other devices associated with the user, and the secure signal path to at least one of the other devices.

