Virtual Modem Baseband Security Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for mobile networks are inadequate in protecting the infrastructure from attacks originating from hijacked mobile devices, and existing solutions require complex and costly hardware certifications and modifications.

Innovation Solution

A virtual modem running on the application processor exclusively controls the baseband, providing a secure interface for data exchange and filtering unauthorized access without altering the baseband hardware or software, using a control command filter and IP filter to manage and secure the signaling and data channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a virtual modem is introduced to control baseband access exclusively, then security against infrastructure attacks is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual modem as an intermediary layer between the operating system and the baseband. This virtual modem runs as a user-space application and exclusively controls access to the baseband, filtering control commands before they reach the hardware. This mediator architecture improves security by preventing direct OS-access to baseband while managing complexity through software-based control rather than hardware modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If control command filtering is implemented in the virtual modem, then protection against malware attacks is improved, but processing time increases

Engineering Contradiction:
Improveprotection against attacksVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The virtual modem performs preliminary filtering of control commands before they are processed by the baseband or transmitted over the network. By pre-screening AT commands and signaling messages for malicious patterns, the system blocks harmful commands early in the processing chain, preventing them from consuming additional processing time in downstream components.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The virtual modem creates a software-based copy of modem functionality that operates in user space. This virtual representation allows the system to intercept and filter commands without modifying the actual baseband hardware or its critical processing paths, thereby maintaining fast processing while adding security checks.

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If the virtual modem runs entirely on the application processor, then hardware certification requirements are reduced, but the application processor's workload increases

Engineering Contradiction:
Improvecertification requirementsVSAvoidprocessor workload
Core Design Contradiction:
Ease of manufactureVSUse of energy by moving object

Solution Approach 1:

The patent replaces hardware-based security mechanisms with a software-based virtual modem implementation. Instead of requiring hardware certification and specialized secure modules, the security functionality is implemented as a user-space application that emulates modem control. This substitution eliminates complex hardware certification requirements while the application processor handles the additional workload through efficient software-based command filtering.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2767112B1Method and device for monitoring a mobile radio interface on mobile terminals
Publication Date: 2017.11.22 DEUTSCHE TELEKOM AG
  • EP2767112B1 patent drawingFigure 1
  • EP2767112B1 patent drawingFigure 2

AI summary

The invention relates to a method and to a device for monitoring a mobile radio interface on a mobile terminal. The mobile terminal has a baseband and an application processor. The method comprises the following steps: executing an operating system on the application processor; executing a virtual modem on the application processor, which modem performs only the data exchange between the operating system and the base band and provides the functionality of the baseband in order to thereby gain access to data and in order to thereby filter out unpermitted data.