Local dialer verification for mobile computing devices
By verifying the mapping of device identifiers and synthesizing the call process in the communication service server, the problems of SIM hijacking and replacement attacks are solved, thereby improving the security of mobile devices and the user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- MICROSOFT TECHNOLOGY LICENSING LLC
- Filing Date
- 2024-10-29
- Publication Date
- 2026-05-01
AI Technical Summary
In existing technologies, SIM hijacking and SIM swapping attacks enable malicious actors to impersonate the victim's phone identity, bypass two-factor authentication, and access the victim's online accounts, leading to identity theft and financial fraud. Furthermore, mobile network communication protocols have technical weaknesses that prevent such attacks from being effectively prevented.
By maintaining a mapping between subscriber and device identifiers in the communication service server, and using synthetic call and authentication processes to verify the matching of device identifiers, it ensures that calls are routed only to authorized devices. Combined with periodic testing and authentication requests from the local dialer, it prevents unauthorized SIM swapping.
Effectively prevents SIM swapping attacks, ensures calls and messages are routed only to authorized devices, prevents identity theft and financial fraud, enhances mobile security, and provides a seamless user experience.
Smart Images

Figure CN121970295A_ABST
Abstract
Description
Local dialer authentication for mobile computing devices Technical Field
[0001] This application relates to the field of data security in online communications, specifically those conducted via mobile networks. More specifically, this application relates to a technique for detecting that a subscriber identity module (SIM) associated with a mobile computing device may have been fraudulently replaced or transferred to another device without proper authorization (such malicious action is commonly referred to as SIM "hijacking" or SIM "replacement"). Background Technology
[0002] A SIM card is a small, removable card that is crucial for operating and identifying mobile devices on a cellular network (often referred to as a mobile network). The SIM card contains an International Mobile Subscriber Identity (IMSI), which uniquely identifies a user (e.g., a subscriber) on the mobile network. The SIM card also stores a Mobile Station International Subscriber Directory Number (MSISDN), more commonly referred to as a telephone number. It also stores authentication keys used to secure communications, as well as other configuration data similar to the Service Provider Name (SPN) used by mobile network operators (also known as mobile network providers).
[0003] eSIMs offer the same overall functionality as regular physical SIM cards, but in an integrated digital form. eSIMs are typically soldered directly onto the device's motherboard, rather than being removable cards. Like SIM cards, eSIMs store the IMSI and authentication keys required to connect to a mobile network. However, eSIM solutions save physical space and eliminate the need for SIM card slots on mobile devices. Furthermore, eSIMs can be remotely reprogrammed to change carriers or plans without replacing the physical SIM card. This makes switching between mobile network providers easier, especially for devices that require frequent network changes.
[0004] Both SIM cards and eSIMs play crucial security roles within mobile devices. They contain unique identifiers that authenticate the device to the mobile network, preventing unauthorized access. SIM / eSIMs also store encryption keys used to protect communications over the mobile network. Furthermore, they associate the device with the user's phone number, essential for making and receiving calls and sending and receiving messages. If a malicious actor compromises a SIM / eSIM, they can impersonate the user's phone number and gain access to user accounts and data protected through SMS-based two-factor authentication. Therefore, SIM / eSIMs are vital for establishing a trusted device identity and protecting mobile devices and associated accounts from fraudulent access. Attached Figure Description
[0005] Embodiments of the invention are illustrated by way of example, not limitation, in the accompanying drawings, wherein: Figure 1 is a diagram illustrating an example of how a mobile network subscriber may lose mobile network connectivity after a SIM card or eSIM has been hijacked by a malicious actor.
[0006] Figure 2 is a diagram illustrating a network environment that can be deployed according to an embodiment of the present invention, wherein the network environment includes a unified communications service that has been integrated to operate seamlessly with a mobile network.
[0007] Figures 3A and 3B are user interface diagrams according to some embodiments, illustrating two examples of authentication requests or authentication messages that can be transmitted to subscribers of a unified communications service for authenticating a local dialer application on a mobile computing device.
[0008] Figure 4A is a diagram illustrating the method operation of a method performed by one or more server computers of a unified communications service to securely transmit an SMS message containing an authentication code, according to some embodiments.
[0009] Figure 4B is a diagram illustrating examples of user interfaces for different messaging applications when an authentication code is transmitted in a manner that combines the method illustrated and described in Figure 4A.
[0010] Figure 5 is a block diagram illustrating a software architecture that can be installed on any computing device in various computing devices to execute the methods described herein.
[0011] Figure 6 is a schematic representation of a machine in the form of a computer system (e.g., a server computer) according to an example embodiment, within which a set of instructions can be executed to cause the machine to perform any one or more of the methods discussed herein. Detailed Implementation
[0012] This document describes methods and systems for authenticating mobile computing devices associated with subscribers of unified communications services, for detecting and preventing attacks resulting from SIM hijacking or SIM replacement. In the following description, numerous specific details are set forth with respect to exemplary embodiments of the invention in order to provide a thorough understanding of various aspects of the different embodiments. However, those skilled in the art will understand that the invention can be practiced without utilizing all the specific details set forth in this specification. Some well-known structures and functions may not be shown or described to avoid obscuring this disclosure.
[0013] SIM hijacking and SIM swapping occur when malicious actors illegally transfer a mobile network operator's subscriber's mobile computing device phone number to a SIM card or eSIM under their control. This unauthorized transfer allows malicious actors to intercept calls and messages (e.g., text messages and SMS messages) intended for use on the victim's device. Malicious actors can also impersonate the victim by making outbound calls, receiving inbound calls, and sending and receiving messages from and from the device using the hijacked phone number. By impersonating the victim, malicious actors can interact with customer service agents or spread false information. Furthermore, malicious actors can bypass multi-factor authentication and access the victim's online accounts using authentication codes, including one-time verification codes sent via SMS, enabling identity theft and financial fraud. Through SIM hijacking and SIM swapping, malicious actors can completely impersonate the victim's telephone identity.
[0014] SIM hijacking and swapping attacks can have serious consequences. By gaining control of a victim's phone number, malicious actors can potentially reset account verification codes and bypass two-factor authentication protected by SMS verification codes. This allows malicious actors to access the victim's online accounts, finances, and personal data. In addition to enabling fraud and identity theft, SIM swapping also compromises the confidentiality of the victim's phone communications. Therefore, SIM hijacking and swapping pose a serious threat to individuals, privacy, accounts, and assets accessed through mobile computing devices.
[0015] Figure 1 illustrates an example of how subscriber 106-A of mobile network 108 might lose mobile network connectivity after their SIM or eSIM is hijacked by a malicious actor 102-A. As shown in Figure 1, the malicious actor 102-A has replaced user 106-A's SIM 104 and is now impersonating the user's phone number on his or her mobile device 102-B. There are multiple ways a malicious actor can hijack, replace, or steal another user's SIM (including eSIM) (such as physically stealing the SIM card, using social engineering to persuade the mobile network operator to reprogram the victim's eSIM, or intercepting the QR code or unique identifier used to activate the eSIM).
[0016] Simultaneously, the user's mobile device 106-B is no longer connected to the mobile network 108, and all communication directed to the user's phone number via the mobile network 108 is now routed to the malicious actor's mobile device 102-B. The malicious actor 102-A has effectively hijacked the phone identity of user 106-A. By controlling the user's phone number, the malicious actor 102-A is now able to intercept arbitrary calls and messages intended for use with the user's mobile device 106-B. For example, if another user 116-A uses his or her mobile device 116-B to make a phone call using the phone number of subscriber-user 106-A associated with SIM 104, the mobile network 108 will route the call and connect it to the malicious actor 102-A's mobile device 102-B. Similarly, when user 106-A attempts to log in to web service 114 to access his or her account and user data (e.g., using a WiFi® connection to the Internet 110, or via another computing device), web service 114 may send an SMS message with an authentication request to user 106-A's phone number, meaning that the SMS message will be received by malicious actor 102-A who has already hijacked user 106-A's SIM 104.
[0017] Because other web services, such as social media accounts, email services, and cryptocurrency swapping, often rely on SMS verification codes for two-factor authentication, SIM or eSIM hijacking can lead to serious problems. By hijacking a user's SIM, malicious actor 102-A (now the attacker) can circumvent security measures and gain access to numerous online accounts. Malicious actor 102-A can then continue to steal funds, data, and personal information from the victim. This illustration demonstrates the severity of the SIM swapping threat.
[0018] The threat posed by SIM swapping attacks stems from technical weaknesses in the authentication protocols used by mobile networks, online services, and mobile computing devices. Specifically, the ability of malicious actors to intercept messages, calls, and authentication challenges designed for recipients associated with a specific SIM depends on the technical mechanisms by which mobile networks route communications to devices based on SIM information. Therefore, the authentication protocols used by online services to verify users using SMS codes suffer from technical flaws that cannot prevent exploitation by SIM swappers. The technical components of these systems, including SIM card technology used for device identification, mobile network communication protocols, and online service authentication schemes, need improvement to address the technical vulnerabilities currently exploited by hackers and malicious actors for SIM swapping fraud.
[0019] Embodiments of the present invention provide technical solutions to the technical problems described above. According to some embodiments, a communication service providing unified communications maintains data records for subscribers of the service. Specifically, for each subscriber of the communication service, at least one data record is maintained to map a subscriber identifier representing the subscriber of the communication service to a device identifier representing a mobile computing device (e.g., a mobile phone) that the subscriber uses to access the communication service and its integrated mobile network using a SIM card or eSIM card. When a server computer associated with the communication service receives a call request for a subscriber of the communication service, the server computer verifies whether the device identifier of the mobile computing device matches the subscriber identifier of the device included in the data record for the subscriber.
[0020] As an example, John Doe is a subscriber to a communications service and has a mobile phone with a unique device identifier of “A1B2C3D4E5”. In the communications service’s data records, John Doe’s subscriber account, which contains John Doe’s phone number (123) 456-7890, is mapped to device ID “A1B2C3D4E5”. When John Doe issues or receives a call request referencing his phone number, the server computer processing the call request checks to ensure that the device identifier of the mobile device currently using John Doe’s phone number (e.g., (123) 456-7890) stored on a SIM or eSIM matches the device identifier in the data records, thereby confirming that John Doe is using his intended phone.
[0021] Therefore, when the server computer of a communication service receives a call request that points to a known subscriber's phone number, the communication service obtains a unique identifier for the device associated with that phone number. This unique device identifier can be obtained in one of several different ways, depending on various factors. One method is to include the device identifier as a data field within the call request message itself. The server simply parses the message to extract the device identifier. Another method is to use a call signaling protocol such as SIP. In this case, the server computer sends a SIP request to the device requesting its identifier, and the device returns the identifier in a SIP response. Alternatively, if the user has installed a client communication application for the communication service, the application can transmit the device identifier directly to the server computer via an internet connection. The application can run persistently in the background to enable periodic identifier checks. Thus, various options exist for the server computer to securely obtain the device identifier used for verification.
[0022] Continuing the example, when the server computer receives a call request referencing John Doe's phone number (123) 456-7890, the server computer retrieves the device identifier "A1B2C3D4E5" stored in John's subscriber account for that number. The server then checks whether the device identifier in the call request matches "A1B2C3D4E5". Alternatively, if the device identifier is not included as part of the call request, the server will use the phone number, for example, using SIP signaling or some other network communication protocol, to query the device to obtain the device identifier. If the identifier matches, the server computer allows the call to continue, thereby connecting John Doe's communication device to participate in the call.
[0023] However, if the device identifier in the call request or obtained from the device does not match the stored device identifier "A1B2C3D4E5", the server computer will temporarily suspend the call while performing the authentication process. The mismatched identifier could indicate that John Doe is using a new, unregistered device, or alternatively, that an unauthorized device is attempting to use John Doe's phone number. In the second case, this could mean that John's SIM card has been replaced by a malicious actor with another device.
[0024] To verify John's identity, the server computer initiates an authentication process. For example, a message is sent to John via a client communication application associated with the communication service, prompting him to take action to authenticate, such as sending a verification code to the phone number via a local messaging application on a device using that specific phone number. This authentication process is further secured by accessing a separate authentication scheme required by the messaging service itself. John Doe will not receive authentication prompt messages unless a legitimate user, John Doe, logs into the messaging service. The server computer will only allow the call to proceed if authentication is successful. This authentication process ensures that calls connected by the server are only routed to the subscriber's intended device, thus preventing SIM swapping attacks.
[0025] Alternatively, in some embodiments, the mobile device of a subscriber to the communication service will include a client communication application capable of making calls and a local dialer. In this context, the local dialer is an application on the mobile device that registers the subscriber's phone number with it via a device profile. The client communication application includes functionality similar to the local dialer and is capable of making calls and also seamlessly hand-off calls to be handled by the local dialer. To verify that the local dialer is functioning correctly, using the phone number and device already registered with the communication service, the dialer of the client communication application will periodically make "synthetic" calls to a dedicated phone number associated with the communication service as part of a periodic verification process. This can be done in the background, for example, when the device is not actively used by the user.
[0026] In this context, a synthetic call is a simulated telephone call generated programmatically by the dialer of the client communication application for authentication purposes. The synthetic call does not connect the two parties involved in the actual conversation. Instead, the client communication application initiates the synthetic call by sending a call request to the server computer of the communication service. This call request can be sent via a data connection such as WiFi or via mobile data instead of a regular mobile network.
[0027] After initiating the synthetic call, the client communication application attempts to switch the call to the local dialer application. Essentially, the client communication application requests the mobile operating system to redirect the call from itself to the local dialer. If the local dialer application is functioning correctly, meaning the device's SIM card is working, the switch will succeed. The local dialer will then take over the call using a phone number supplied by the mobile network and maintain the active call state. This will be seamlessly detected by the communication service server.
[0028] However, if the local dialer application cannot accept the handover, for example due to a SIM card replacement, the call will time out after a predetermined duration. This failed handover indicates that the local dialer may not have proper mobile network connectivity, meaning the device's SIM card may be compromised. As an additional verification step, the client communication application can temporarily disconnect the device's Wi-Fi connection before attempting a handover. If the handover still fails with Wi-Fi disabled, it confirms a lack of cellular data connectivity and a possible SIM card replacement. In this way, periodic synthetic call handover provides the client communication application with an automated way to work in conjunction with the communication service's server to check the integrity of the local dialer and its associated SIM connection.
[0029] Furthermore, the third hybrid approach combines the on-demand synthetic call process with device identifier comparison. In this approach, when a suspicious change in the device identifier is detected during call processing, the server computer only initiates the synthetic call handover. The target invocation of the verification process aims to balance security, efficiency, and user experience.
[0030] Embodiments of the present invention provide technical solutions to technical problems in the field of mobile security and to prevent SIM swapping attacks. A first embodiment allows the communication service server to proactively verify the device identifier upon receiving a call request. This prevents hackers from using stolen SIM certificates and intercepts calls intended to target victims. A second embodiment enables continuous automated testing of the SIM connectivity of the local dialer in the background. Synthetic call switching technology detects SIM swapping without any visible impact on the user. Together, these two solutions enhance security, providing seamless protection for subscribers and preventing unauthorized use of mobile accounts and credentials. Tight integration between communication services and mobile network operators brings shared value, leveraging their respective technical capabilities for more robust SIM swapping prevention. These embodiments elegantly address pressing technical challenges to significantly improve mobile security. Other aspects and advantages of various embodiments of the invention will be apparent to those skilled in the art from the following description of several figures.
[0031] Figure 2 illustrates a network environment 200 that can be deployed according to an embodiment of the present invention, wherein the network environment 200 includes a unified communications service 206 that has been integrated to operate seamlessly with the mobile network 210. Mobile network operators or MNOs may collaborate with providers of the unified communications service, hereinafter referred to as the communications service, to integrate their respective network and service offerings. For example, this type of integration allows subscribers of the mobile network (who are also subscribers of the communications service) to utilize the robust mobile network 210 while simultaneously accessing a variety of communications services 206 from the communications service provider, such as messaging, audio / video calling, screen sharing, file sharing, and many other services. In many cases, subscribers can use a unified communications client application 212 to access the various communications services of the communications service 206 on various client computing devices, such as mobile computing device 202-B, desktop computer 212-A, tablet computer 212-B, and telephone device 212-C.
[0032] The integration of mobile network 210 with communication service 206 involves the mobile network operator routing telephone calls and text messages (e.g., including SMS messages) destined for subscribers' phone numbers to the server computer of communication service 206, in addition to routing them through its own mobile network. Typically, communication service 206 maintains a database mapping each subscriber's phone number to its corresponding user account. In some cases, the communication service may also maintain a database to track each user or subscriber's registered computing device. Accordingly, when communication service 206 receives a telephone call or text message for a subscriber, it checks the mapping to identify the correct user account.
[0033] Then, the communication service 206 simultaneously routes the incoming communication to all user-registered computing devices or any computing device the user is currently logged into. This includes not only routing to the user's local dialer 204-A via mobile network 210, but also routing to computing devices such as computing devices 212-A, 212-B, and 212-C with the Unified Communications (UC) client application 212 installed via the Internet 208. For example, when a telephone call is dialed to the user's mobile phone number, the communication service 206 routes the call to the user's local dialer 204 to make their mobile phone ring, and also routes the call via IP (Internet Protocol) to make the desktop and tablet computing devices 212-A and 212-B, where the user is logged into the Unified Communications (UC) client application 212, ring.
[0034] This integration allows subscribers to leverage the robustness and ubiquity of the MNO's mobile network while also gaining the flexibility of a unified communications service that synchronizes communication across devices. Users can seamlessly switch calls between their local dialer 204 and the UC client application 212 without interruption. The mobile computing device telephone number serves as a unified endpoint for ringing all user-registered communication devices.
[0035] As explained in further detail below, another advantage of this integration is the ability to authenticate the user's local dialer 204 to ensure that the user is not a victim of SIM hijacking or SIM replacement. According to some embodiments, the numbers "1" through "6" enclosed in circles, as shown in Figure 2, are intended to represent a set of numbered steps corresponding to the operations and communications performed as part of the authentication of the user's local dialer.
[0036] In the example shown in Figure 2, user 202-A is a subscriber to both mobile network 210 and communication service 206. Communication service 206 provides unified communication capabilities, such as audio / video calling, messaging, screen sharing, etc., through a UC client application 212 installed on the user's device. As indicated by the circle "1" (e.g., step one), a call request is directed to mobile network 210 and received there. This call request could be an outbound call originating from the local dialer 204-A of the user's mobile computing device 202-B. Alternatively, the call request could be an inbound call originating from another device (not shown) but directed to the user's telephone number.
[0037] In this example, although the call request is received at mobile network 210, the call request is immediately switched or transferred to communication service 206, as indicated by the closed "2" (e.g., step 2). This is done, for example, because mobile network 210 determines that the phone number associated with the call request is mapped to a subscriber of communication service 206.
[0038] Upon receiving the call request, communication service 206 obtains a unique device identifier associated with the user of the user's mobile computing device 202-B. This is indicated in Figure 2 by a circled "3" (e.g., step 3). Various techniques exist that communication service 206 can use to obtain this unique device identifier. For example, the unique device identifier may be included as a specific data field within the call request message itself, in which case communication service 206 simply extracts the unique device identifier by parsing the appropriate field. Alternatively, the unique device identifier can be obtained via a call signaling protocol such as Session Initiation Protocol (SIP). The SIP protocol can be used to send a request for its unique device identifier from the server computer of communication service 206 to mobile computing device 202-B, which will then return the request in a SIP signaling response. Other protocols can also be used to request the unique device identifier from mobile computing device 202-B.
[0039] In some cases, the unique device identifier will be a hardware-specific value such as a Media Access Control (MAC) address. However, in other cases, the unique device identifier may be a different permanent identifier assigned to the device hardware. Once obtained, the communication service 206 compares the current unique device identifier with a previously stored identifier associated with the user's account, as indicated by the closed "4" (e.g., step 4). A mismatch between the current and stored identifier can indicate one of at least two possible scenarios. First, the mismatch can indicate, for example, an unauthorized SIM replacement by a malicious actor on a new device. Alternatively, the mismatch can also indicate that a legitimate user has simply begun using their SIM card on a new mobile computing device different from the device previously associated with their account, or has moved their SIM card to an eSIM on the same or a different device. In any case, the mismatch triggers the communication service 212 to initiate an authentication process.
[0040] According to some embodiments, the authentication process involves communication service 206 sending a message including an authentication request via a messaging service that is part of the service provision of communication service 206. This is illustrated in Figure 2 by a line diagram associated with a circled "5" (e.g., step 5). The message may be sent to one or more registered computing devices of the user, where the user is currently logged into the messaging service. In some examples, the authentication request is a prompt instructing the user to send a specific verification code or string to a designated phone number associated with the communication service using a local messaging application (e.g., an application configured to use a phone number assigned to the user's SIM card). Successful receipt of the verification code authenticates the user.
[0041] Alternatively, in some embodiments, the authentication request may include a Quick Response (QR) code, which is transmitted via a messaging service to one or more computing devices in the user's computing device. The prompt instructs the user to scan the QR code using a mobile computing device 202-B associated with their account and to derive a verification code based on the scanning process. The user must then send the derived verification code via a local messaging application to a phone number associated with the communication service, which authenticates the user upon receipt. In some cases, alternatively, the authentication request may be provided via an audio prompt played during a voice call via the UC client application 212, or sent as a notification to the UC client application 212, rather than via text-based or QR code-based messaging interaction.
[0042] In Figure 2, the authentication response indicated by the dashed line associated with the circled "6" (step 6) is shown as a local messaging application 204-B from mobile computing device 202-B. Local dialer 204-A and local messaging application 204-B are applications provided by default on the mobile operating system (e.g., Android, iOS) included on mobile computing device 202-B. Both applications are configured to use the phone number assigned to SIM card 104 as the address for sending and receiving calls and text messages (including SMS messages), respectively.
[0043] Specifically, the local dialer 204-A allows users to make and receive phone calls using the phone number associated with their SIM card. The local messaging application 204-B is also capable of sending and receiving text messages (including SMS messages) to and from the SIM card's phone number. Both system applications are integrated with the mobile network 210 and use the SIM card to identify the device used for communication over the mobile network infrastructure. Therefore, any call made or any text sent by the local dialer or messaging application will be recognized by the mobile network 210 and the communication service 206 as originating from the user's SIM phone number.
[0044] As described in conjunction with Figure 2, in some embodiments, the authentication process proceeds immediately after a mismatch is detected between the obtained device identifier (e.g., step 3) and the stored device identifier, leaving the original call request pending or in an intermediate state until it is fully processed after the user successfully authenticates (e.g., within a predetermined time period such as 2 minutes). However, in alternative embodiments, the call request can be fully processed to connect the telephone call, while the authentication process is performed in parallel or shortly after the call is connected. In these cases, the authentication may be required within a specific time window after the call is connected (e.g., within the next 30 minutes, 4 hours, 24 hours, etc.). By allowing the call connection while performing authentication in parallel, this alternative prioritizes call completion and continuity while still ensuring that the user is authenticated for a reasonable period after the call connection to verify that they are authorized to have the device associated with their subscriber account and phone number.
[0045] As illustrated above in conjunction with Figure 2, one example of a unique device identifier that can be used according to some embodiments is a MAC address. Those skilled in the art will recognize that various other identifiers can be used as unique device identifiers, including any one or more of the following, or various combinations thereof: • IMEI (International Mobile Equipment Identity) – an A15-17 numeric code that uniquely identifies a mobile device. It is assigned to the device hardware itself rather than the SIM card.
[0046] • MEID (Mobile Equipment Identifier) - A 56-bit identifier assigned to a CDMA mobile device. It identifies the physical device, not the subscriber.
[0047] • UUID (Universally Unique Identifier) - A standardized 128-bit number generated and assigned to a device by its operating system. It is unique across all device hardware and software.
[0048] • UDID (Unique Device Identifier) - A sequence of 40 letters and numbers specific to iOS devices. It is associated with hardware components.
[0049] • Serial number - A unique serial number is embedded in the hardware of a device by the manufacturer to identify a specific device unit.
[0050] • Wi-Fi MAC address - Separate from the network interface MAC address, this identifies the device's Wi-Fi radio hardware.
[0051] • Bluetooth MAC address - Identifies the device's Bluetooth radio and is unique across all Bluetooth devices.
[0052] • CPU ID - Identifiers such as CPU serial numbers or chipset models can also be used to identify hardware components in a device.
[0053] Figure 3A illustrates a user interface 300 of a messaging application associated with a communication service according to some embodiments, wherein an authentication request relates to a message for the user containing a prompt to text-transmit a specific verification code using a local messaging application on a mobile computing device. In this example, the user has a UC client application installed on a computing device such as a desktop computer 302. The UC client application provides access to various unified communications services (including messaging) provided by the provider. The user logs into the messaging service via the UC client application.
[0054] When the communication service detects a mismatch in the device identifier used for authentication, it sends a message to the user's UC client application. This message contains instructions prompting the user to enter a specific verification code (e.g., "12345678") into a designated phone number (e.g., "800-123-4567") using the local messaging application of the mobile computing device associated with their subscriber account and SIM.
[0055] The local messaging application is the default text messaging application provided by the mobile operating system and is configured to send text using the phone number assigned to the SIM card in the device. By requesting a verification code to be sent via the local messaging application, this ensures that the device sending the code has proper connectivity over the mobile network when using the intended SIM card associated with the user's account. Once the user follows the instructions and sends the verification code text from the phone number associated with the SIM to the designated number, the communication service receives the verification code. Because the verification code is received from the SIM's phone number, this indicates that the user has access to the intended SIM card and has mobile network connectivity over the SIM. The communication service can authenticate the user when verifying the received code. At this point, the identity of the given device and the subscriber account have been verified through the messaging-based authentication process, and pending call requests can proceed.
[0056] After authenticating a user via a message-based verification code process, a follow-up message can be sent to the user, requesting confirmation that the SIM is now known to be associated with a new device. This follow-up message prompts the user to verify whether they have recently switched devices or received a new SIM card linked to their subscriber account. If the user provides confirmation indicating their awareness of the device change, the communication service can update its internal user data records to reflect the new, unique device identifier (e.g., MAC address) now associated with the user's SIM and account. This allows the communication service to maintain an accurate device profile for each user in its system for future authentication needs. However, if the user indicates they have not authorized or expect a SIM card or device change, the service can take additional fraud prevention measures, such as temporarily suspending the account, reverting to an older device identifier profile, or requiring further in-person verification.
[0057] Figure 3B illustrates a user interface 302 of a messaging application associated with a communication service according to some embodiments, wherein the authentication request relates to a message for the user containing a prompt to scan a QR code. In this example, the user logs into the messaging service of a communication provider via a UC client application on a desktop computer. When the communication service detects a mismatch in the device identifier, a message containing a unique QR code is sent to the desktop application.
[0058] The message prompts the user to scan the QR code using the mobile computing device associated with their subscriber account and SIM card. When the user scans the QR code using the camera app on their mobile computing device, the camera app decodes the QR code and displays a unique verification code. The user is then prompted to send the decoded verification code to a designated phone number associated with the communication service via a local messaging application on their mobile computing device.
[0059] Similar to the previous example described in conjunction with Figure 3A, a decoded verification code is sent from the local messaging application to prove that the mobile device has the appropriate mobile network connection through the expected SIM associated with the user's account. Once the communication service receives the verification code, it authenticates the user and continues processing the pending call request. Additionally, after authenticating the user, the communication service updates its subscriber account database to record a new device identifier associated with the user's SIM and account. This allows the service to maintain an accurate device profile for each user for future authentication needs. In summary, the QR code authentication scheme leverages the user's mobile device's local scanning and messaging capabilities to verify their identity and authorized use of the SIM associated with their subscriber account.
[0060] If a user is unable to complete the authentication process by providing a valid verification code via a local messaging application, this indicates that the user's SIM card may be compromised. In this situation, the communication service can take measures to protect the user's account and prevent fraudulent activities. For example, the service can temporarily suspend the user's phone number and associated SIM card's ability to send or receive calls and text messages on the mobile network. It can notify the mobile network operator that the SIM card may be compromised. It can also notify the user of the failed authentication attempt via the UC client application, along with information to contact customer support, such as a link to a help page or a dedicated phone number for calling. Other reasonable actions to protect the user's account and compromised SIM card can also be performed, such as requiring in-person verification, reverting to an older device identifier profile if available, prompting the user to obtain a new SIM card from the mobile operator, forcing a verification code reset before the account can be used again, or advising the user to contact law enforcement.
[0061] Figure 4 illustrates an alternative technology for authenticating mobile computing devices (specifically, the device's local dialing application). In this technology, the mobile device includes a local dialer and a UC client application. The UC client application is configured to periodically send synthetic calls to a communication service. The synthetic call is a simulated telephone call generated programmatically by the UC client application for authentication purposes. It does not connect the two parties used for the actual conversation.
[0062] The authentication process works as follows. The UC client application on the mobile device initiates a synthetic call, as indicated by the circle "1" (e.g., step one). This synthetic call can be a VoIP call using Internet data instead of a cellular network. The synthetic call is received and acknowledged by the communication service. After initiating the synthetic call, the UC client application attempts to switch the call to a local dialer application, as indicated by the dashed line associated with the circle "2" (e.g., step two). Essentially, the UC client application requests the mobile operating system to transfer the call from the UC client application to the local dialer application.
[0063] If the local dialer application is operating normally, meaning the device's SIM card is intact, the handover will be successful. The local dialer will take over the call using the mobile number supplied by the MNO and maintain the active call status. This will be seamlessly detected by the communication service. However, if the local dialer application cannot accept the handover, for example due to a replacement of the device's SIM, the call will time out after a predetermined duration. This failed handover indicates that the local dialer may not have proper mobile network connectivity, meaning the device's SIM may be compromised. In this way, periodic synthetic call handover provides an automated way for UC client applications to check the integrity of the local dialer application and its associated SIM connectivity.
[0064] In some embodiments, the local dialing application on the mobile device can be configured to make calls using Wi-Fi. This means that when cellular network connectivity is limited, it can route calls via Wi-Fi data connectivity. However, to effectively test the integrity of the local dialer's SIM connection, the authentication process requires mandatory use of a cellular or mobile network. To address this, according to some embodiments, when the UC client application initiates periodic synthetic calls, it communicates with the mobile operating system to temporarily disable the device's Wi-Fi connection. For example, the UC client application can invoke an API call to turn off the Wi-Fi radio for a short duration of 5-10 seconds.
[0065] During this brief Wi-Fi outage, the UC client application switches the synthesized call to the local dialer. With Wi-Fi disabled, the local dialer must use the cellular network and SIM to maintain the call. If the switch fails within the short window of Wi-Fi downtime, it indicates that the local dialer may lack cellular connectivity or SIM access, suggesting a potential security vulnerability.
[0066] The third embodiment provides an enhanced authentication process by integrating operations from the first two embodiments. In this third approach, the communication service uses a synthetic call to verify the local dialer application, but initiates the synthetic call process only after detecting a potential unauthorized device change—such as a device identifier mismatch.
[0067] For example, during the processing of an inbound or outbound call, the communication service obtains a unique device identifier and compares it with a stored identifier, as described in the first embodiment. If a mismatch indicating anomalies or suspicious changes is detected, the server triggers a synthetic call procedure to authenticate the device.
[0068] In this third embodiment, the synthetic call handover from the UC client application to the local dialer is not performed on a fixed schedule. Instead, the communication service sends a command to the UC client application on the mobile device, instructing it to initiate synthetic call authentication. This on-demand synthetic calling allows for more efficient and targeted verification of the integrity of the local dialer.
[0069] If the synthetic call handover fails within the allocated time, the communication service determines that the device may be compromised. Appropriate notifications, account suspensions, or other security measures can then be implemented.
[0070] By combining on-demand synthetic call processing with identifier comparison, this hybrid approach allows for specific authentication when suspicious activity is detected. It aims to balance security, efficiency, and user experience. The synthetic call handover provides robust verification of the local dialer's connectivity while minimizing unnecessary signaling overhead in the absence of unusual device changes.
[0071] Although the embodiments described in Figures 2 and 4 present the mobile network and communication services as separate entities, in some alternative embodiments, functionality can be provided by a single provider as part of an integrated service offering. For example, a mobile operator could provide its own proprietary unified communications service, including features such as messaging, audio / video calling, and file sharing. In the embodiments described above, the integrated mobile operator could perform functions belonging to both the mobile network and the separate communication services. Specifically, the integrated mobile operator could detect device identifier mismatches on its network, initiate synthetic call handover, and authenticate users within its own infrastructure and platform—all. Such a merged model aims to provide users with seamless mobile communications and robust security through a single mobile service provider, without relying on third-party communication services.
[0072] Figure 5 is a block diagram 500 illustrating a software architecture 502 that can be installed on any computing device in a variety of computing devices to perform methods according to the methods described herein. Figure 5 is merely a non-limiting example of a software architecture, and it will be appreciated that many other architectures can be implemented to facilitate the functionality described herein. In various embodiments, the software architecture 502 is implemented by hardware such as a machine 600 of Figure 6, which includes a processor 610, a memory 630, and an input / output (I / O) component 650. In this example architecture, the software architecture 502 can be conceptualized as a stack of layers, each layer providing specific functionality. For example, the software architecture 502 includes layers such as an operating system 504, a library 506, a framework 508, and an application 510. Operationally, according to some embodiments, the application 510 invokes API call 512 through a software stack and receives message 514 in response to API call 512.
[0073] In various embodiments, operating system 504 manages hardware resources and provides common services. Operating system 504 includes, for example, kernel 520, services 522, and drivers 524. According to some embodiments, kernel 520 acts as an abstraction layer between hardware and other software layers. For example, kernel 520 provides memory management, processor management (e.g., scheduling), component management, networking and security settings, and other functions. Services 522 can provide other common services to other software layers. According to some embodiments, drivers 524 are responsible for controlling or interfacing with the underlying hardware. For example, drivers 524 can include display drivers, camera drivers, Bluetooth® or Bluetooth® Low Energy drivers, flash memory drivers, serial communication drivers (e.g., Universal Serial Bus (USB) drivers), Wi-Fi® drivers, audio drivers, power management drivers, etc.
[0074] In some embodiments, library 506 provides low-level public infrastructure utilized by application 510. Library 506 may include system libraries 530 (e.g., the C standard library) capable of providing functions such as memory allocation, string manipulation, and mathematical functions. Additionally, library 506 may include API libraries 532, such as media libraries (e.g., libraries for supporting the rendering and manipulation of various media formats such as Moving Picture Experts Group-4 (MPEG4), Advanced Video Coding (H.264 or AVC), Moving Picture Experts Group Layer 3 (MP3), Advanced Audio Coding (AAC), Adaptive Multi-Rate (AMR) audio codecs, Joint Picture Experts Group (JPEG or JPG), or Portable Web Graphics (PNG)), graphics libraries (e.g., OpenGL frameworks for rendering in two-dimensional (2D) and three-dimensional (3D) contexts on a display), database libraries (e.g., SQLite for providing various relational database functions), web libraries (e.g., WebKit for providing web browsing functionality), etc. Library 506 may also include a wide variety of other libraries 634 to provide many other APIs to application 510.
[0075] According to some embodiments, framework 508 provides high-level public infrastructure that can be utilized by application 510. For example, framework 508 provides various GUI functions, advanced resource management, advanced location services, etc. Framework 508 can provide a wide range of other APIs that can be utilized by application 510, some of which may be specific to a particular operating system 504 or platform.
[0076] In example embodiments, application 510 includes a home application 550, a contacts application 552, a browser application 554, a book reader application 556, a location application 558, a media application 560, a messaging application 562, a game application 564, and a variety of other applications, such as third-party applications 566. According to some embodiments, application 510 is a program that performs functions defined in a program. One or more applications 610 can be structured in various ways using various programming languages, such as object-oriented programming languages (e.g., Objective-C, Java, or C++) or procedural programming languages (e.g., C or assembly language). In a particular example, third-party application 566 (e.g., an application developed by an entity other than a platform-specific vendor using the Android™ or iOS™ Software Development Kit (SDK)) can be mobile software running on a mobile operating system (such as iOS™, Android™, Windows® Phone, or another mobile operating system). In this example, third-party application 666 is able to invoke API calls 512 provided by operating system 504 to facilitate the functions described herein.
[0077] Figure 6 illustrates a graphical representation of a machine 600 in the form of a computer system according to an exemplary embodiment, within which a set of instructions can be executed to cause the machine to perform any one or more of the methods discussed herein. Specifically, Figure 6 shows a graphical illustration of a machine 600 in the example form of a computer system, within which instructions 616 (e.g., software, programs, applications, applets, or other executable code) can be executed to cause the machine 600 to perform any one or more of the methods discussed herein. For example, instructions 616 can cause the machine 600 to perform any of the methods or algorithmic techniques described herein. Additionally or alternatively, instructions 616 can be implemented in any of the systems described herein. Instructions 616 transform a general-purpose, non-programmable machine 600 into a specific machine 600 programmed to perform the described and illustrated functions in the described manner. In alternative embodiments, machine 600 operates as a standalone device or can be coupled (e.g., networked) to other machines. In a networked deployment, machine 600 can operate as a server machine or client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. Machine 600 may include, but is not limited to: server computers, client computers, PCs, tablet computers, laptop computers, netbooks, set-top boxes (STBs), PDAs, entertainment media systems, cellular phones, smartphones, mobile devices, wearable devices (e.g., smartwatches), smart home devices (e.g., smart appliances), other smart devices, network devices, network routers, network switches, bridges, or any machine capable of sequentially or otherwise executing instructions 616 to specify actions to be taken by machine 600. Furthermore, although only a single machine 600 is illustrated, the term "machine" should also be considered as a collection of machines 600 that individually or collectively execute instructions 916 to perform any one or more of the methods discussed herein.
[0078] Machine 600 may include processor 610, memory 630, and I / O components 650, which may be configured to communicate with each other, such as via bus 602. In an example embodiment, processor 610 (e.g., a central processing unit (CPU), a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a graphics processing unit (GPU), a digital signal processor (DSP), an ASIC, a radio frequency integrated circuit (RFIC), another processor, or any suitable combination thereof) may include, for example, processor 612 and processor 614 capable of executing instructions 616. The term "processor" is intended to include multi-core processors, which may include two or more independent processors (sometimes referred to as "cores") capable of executing instructions simultaneously. Although Figure 6 illustrates multiple processors 610, machine 600 may include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiple cores, or any combination thereof.
[0079] Memory 630 may include main memory 632, static memory 634, and memory cell 636, all of which can access processor 610 via bus 602. Main memory 630, static memory 634, and memory cell 636 store instructions 916 embodying any one or more of the methods or functions described herein. Instructions 916 may also reside wholly or partially in main memory 632, static memory 634, memory cell 636, processor 610 (e.g., within the processor), or any suitable combination thereof during execution by machine 600.
[0080] I / O component 650 may include a wide variety of components to receive input, provide output, generate output, send information, exchange information, capture measurements, and so on. The specific I / O component 650 included in a particular machine will depend on the type of machine. For example, a portable machine such as a mobile phone may include a touch input device or other such input mechanism, while a headless server machine may not include such a touch input device. It will be appreciated that I / O component 650 may include many other components not shown in Figure 6. I / O components 650 are grouped according to their functions only for the purpose of simplifying the discussion below, and the grouping is by no means limiting. In various example embodiments, I / O component 650 may include output component 652 and input component 654. Output component 652 may include visual components (e.g., displays, such as plasma display panels (PDPs), light-emitting diode (LED) displays, liquid crystal displays (LCDs), projectors, or cathode ray tubes (CRTs)), acoustic components (e.g., speakers), haptic components (e.g., vibration motors, resistance mechanisms), other signal generators, and so on. Input component 654 may include alphanumeric input components (e.g., a keyboard, a touchscreen configured to receive alphanumeric input, an optical keyboard, or other alphanumeric input components), point-based input components (e.g., a mouse, touchpad, trackball, joystick, motion sensor, or other pointing instrument), haptic input components (e.g., a physical button, a touchscreen that provides position and / or force for touch or touch gestures, or other haptic input components), audio input components (e.g., a microphone), etc.
[0081] In another example embodiment, I / O component 650 may include biometric component 656, motion component 658, environmental component 660, or position component 662, as well as various other components. For example, biometric component 656 may include components for detecting expressions (e.g., hand gestures, facial expressions, voice expressions, body posture, or eye tracking), measuring biosignals (e.g., blood pressure, heart rate, body temperature, sweating, or brain waves), and identifying a person (e.g., voice identification, retinal identification, facial identification, fingerprint identification, or EEG-based identification). Motion component 658 may include accelerometer components (e.g., accelerometers), gravity sensor components, rotation sensor components (e.g., gyroscopes), etc. Environmental component 660 may include, for example, a lighting sensor component (e.g., a photometer), a temperature sensor component (e.g., one or more thermometers for detecting ambient temperature), a humidity sensor component, a pressure sensor component (e.g., a barometer), an acoustic sensor component (e.g., one or more microphones for detecting background noise), a proximity sensor component (e.g., an infrared sensor for detecting nearby objects), a gas sensor (e.g., a gas detection sensor for detecting hazardous gas concentrations for safety purposes or for measuring pollutants in the atmosphere), or other components that can provide indications, measurements, or signals corresponding to the surrounding physical environment. Location component 962 may include a location sensor component (e.g., a GPS receiver component), an altitude sensor component (e.g., an altimeter or barometer for detecting air pressure from which its altitude is derived), an orientation sensor component (e.g., a magnetometer), etc.
[0082] A wide variety of technologies can be used to implement communication. I / O component 950 may include communication component 664, operable to couple machine 600 to network 680 or device 670 via coupling 682 and coupling 672, respectively. For example, communication component 664 may include a network interface component or another suitable device to interface with network 680. In further examples, communication component 664 may include wired communication components, wireless communication components, cellular communication components, near field communication (NFC) components, components (e.g., low power), components, and other communication components that provide communication via other modalities. Device 670 may be another machine or any of a wide variety of peripheral devices (e.g., peripheral devices coupled via USB).
[0083] Furthermore, the communication component 664 can detect identifiers or include components operable to detect identifiers. For example, the communication component 664 may include a radio frequency identification (RFID) tag reader component, an NFC smart tag detection component, an optical reader component (e.g., an optical sensor for detecting one-dimensional barcodes such as Universal Product Code (UPC) barcodes, multi-dimensional barcodes such as Quick Response (QR) codes, Aztec codes, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D barcodes, and other optical codes), or an acoustic detection component (e.g., a microphone for identifying tagged audio signals). Additionally, various information can be derived via the communication component 664, such as location via Internet Protocol (IP) geolocation, location via signal triangulation, location via detection of NFC beacon signals that can indicate a specific location, etc.
[0084] Executable instructions and machine storage media: Various memories (i.e., 630, 632, 634 and / or memory of processor (one or more) 610) and / or storage units 636 may store one or more sets of instructions and data structures (e.g., software) embodying or used by any one or more of the methods or functions described herein. These instructions (e.g., instruction 616) cause various operations to implement the disclosed embodiments when executed by processor (one or more) 610.
[0085] As used herein, the terms “machine storage medium,” “device storage medium,” and “computer storage medium” refer to the same thing and may be used interchangeably in this disclosure. The terms refer to one or more storage devices and / or media (e.g., centralized or distributed databases and / or associated caches and servers) that store executable instructions and / or data. Therefore, the terms should be considered to include, but are not limited to: solid-state memory, and optical and magnetic media, including memory internal or external to the processor. Specific examples of machine storage media, computer storage media, and / or device storage media include: non-volatile memory, including, for example, semiconductor memory devices, such as erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), FPGAs, and flash memory devices; disks, such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The terms “machine storage medium,” “computer storage medium,” and “device storage medium” specifically exclude carrier waves, modulated data signals, and other such media, at least some of which are covered under the term “signal medium” discussed below. In various example embodiments, one or more portions of network 680 may be an ad hoc network, intranet, extranet, VPN, LAN, WLAN, WAN, WWAN, MAN, the Internet, a portion of the Internet, a portion of the PSTN, a common old-style telephone service (POTS) network, a cellular telephone network, a wireless network, a network, another type of network, or a combination of two or more such networks. For example, network 680 or a portion of network 680 may include a wireless or cellular network, and coupling 682 may be a Code Division Multiple Access (CDMA) connection, a Global System for Mobile Communications (GSM) connection, or another type of cellular or wireless coupling. In this example, Coupler 682 can implement any of a variety of data transmission technologies, such as Single Carrier Radio Transmission (1xRTT), Evolved Data Optimization (EVDO), General Packet Radio Service (GPRS), Enhanced Data Rate Evolution of GSM (EDGE), 3rd Generation Partnership Project (3GPP) including 3G, 4th Generation Wireless (4G) networks, Universal Mobile Telecommunications System (UMTS), High-Speed Packet Access (HSPA), Global Microwave Access Interoperability (WiMAX), Long Term Evolution (LTE) standards, other standards defined by various standards-setting organizations, other long-range protocols, or other data transmission technologies.
[0086] Instructions 616 can be sent or received on network 680 using a transmission medium via a network interface device (e.g., a network interface component included in communication component 664) and utilizing any of a variety of well-known transport protocols (e.g., HTTP). Similarly, instructions 616 can be sent or received to device 670 via a transmission medium via coupling 672 (e.g., peer-to-peer coupling). The terms "transmission medium" and "signal medium" refer to the same thing and are used interchangeably in this disclosure. The terms "transmission medium" and "signal medium" should be considered to include any intangible medium capable of storing, encoding, or carrying instructions 616 for execution by machine 600, and include digital or analog communication signals or other intangible media to facilitate communication of such software. Therefore, the terms "transmission medium" and "signal medium" should be considered to include any form of modulated data signal, carrier wave, etc. The term "modulated data signal" refers to a signal having one or more of its characteristics set or altered to encode information in the signal. The terms "machine-readable medium," "computer-readable medium," and "device-readable medium" refer to the same thing and are used interchangeably in this disclosure. The term is defined to include both machine storage media and transmission media. Therefore, the term encompasses both storage devices / media and carrier / modulated data signals.
Claims
1. A computer-implemented method for detecting a Subscriber Identity Module (SIM) change at a mobile computing device, the mobile computing device being configured to make and receive telephone calls via a local dialer application using a telephone number assigned to the SIM, the method comprising: At the server computer of the communication service, a request to initiate a telephone call is received from the mobile computing device (Figure 2, 206). Obtain a first value of a first identifier that uniquely identifies the mobile computing device and a second value of a second identifier that uniquely identifies the subscriber of the communication service (Figure 2, 206); compare the first value of the first identifier with a stored value of the first identifier (Figure 2, 206); and when determining the difference between the value of the first identifier and the stored value of the first identifier, keep the request to initiate the telephone call pending while invoking the authentication process to authenticate the subscriber before further processing the request to initiate the telephone call (Figure 2, 206).
2. The method according to claim 1, wherein, Invoking the authentication process includes: sending a message including a verification code from the server computer of the communication service to a client messaging application, wherein the subscriber is currently logged into the messaging service of the communication service via the client messaging application (Figure 2, 206); prompting the user of the computing device to send a text message including the verification code to a specific phone number using a local messaging application running on the mobile computing device (Figure 2, 206); and receiving the text message sent by the local messaging application at the server computer of the communication service, wherein successful reception of the text message with the verification code authenticates the subscriber (Figure 2, 204).
3. The method according to claim 2, wherein, The local messaging application is configured to send and receive text messages using the phone number assigned to the SIM (Figure 2, 204).
4. The method according to claim 1, wherein, Invoking the authentication process includes: transmitting a Quick Response (QR) code to a user of the mobile computing device via a client messaging application associated with the messaging service of the communication service, which runs on the computing device (Figure 3, 302); prompting the user via the client messaging application to use the image sensor of the mobile computing device to scan the QR code and sending a text message including a verification code derived from the scanning of the QR code to a specific phone number (Figure 3, 302); wherein successful reception of the text message with the derived code authenticates the subscriber.
5. The method according to claim 1, wherein, The second value of the second identifier is the subscriber's phone number, and the server computer stores data records that associate the stored value of the first identifier with the subscriber's phone number (Figure 2, 206).
6. The method according to claim 1, wherein, The first identifier is the media access control (MAC) address of the mobile computing device, and obtaining the first value of the first identifier includes: extracting the MAC address from a Session Initiation Protocol (SIP) signal received at the server computer in association with the request to initiate the telephone call (Figure 3, 302).
7. The method according to claim 1, wherein, Obtaining the device identifier includes: sending a request from the server computer to the mobile computing device to provide the device identifier; and receiving a response from the mobile computing device at the server computer, the response including the device identifier (Figure 3, 302).
8. A system for detecting subscriber identity module (SIM) replacement at a mobile computing device, the mobile computing device being configured to make and receive telephone calls via a local dialer application using a telephone number assigned to the SIM, the system comprising: One or more processors; A memory storing instructions that, when executed by the one or more processors, cause the system to: receive a request to initiate a telephone call from the mobile computing device (FIG. 2, 206); obtain a first value of a first identifier that uniquely identifies the mobile computing device and a second value of a second identifier that uniquely identifies a subscriber of the communication service (FIG. 2, 206); and compare the first value of the first identifier with a stored value of the first identifier. And when determining the difference between the value of the first identifier and the stored value of the first identifier, the request to initiate the telephone call is kept in a pending state, while the authentication process is invoked to authenticate the subscriber before further processing the request to initiate the telephone call (Figure 2, 206).
9. The system according to claim 8, wherein, Invoking the authentication process includes: sending a message including a verification code to a client messaging application, through which the subscriber is currently logged into the messaging service (Figure 2, 206); prompting the user of the computing device to send a text message including the verification code to a specific phone number using a local messaging application running on the mobile computing device (Figure 2, 206); and receiving the text message sent by the local messaging application, wherein successful reception of the text message containing the verification code authenticates the subscriber (Figure 2, 206).
10. The system according to claim 9, wherein, The local messaging application is configured to send and receive text messages using the phone number assigned to the SIM (Figure 2, 206).
11. The system according to claim 8, wherein, Invoking the authentication process includes: transmitting a Quick Response (QR) code to a user of the mobile computing device via a client messaging application associated with a messaging service, which runs on the computing device; prompting the user via the client messaging application to scan the QR code using the image sensor of the mobile computing device and sending a text message (Figure 2, 206) to a specific phone number including a verification code derived from the scanning of the QR code; wherein successful reception of the text message with the derived code authenticates the subscriber.
12. The system according to claim 8, wherein, The second value of the second identifier is the subscriber's phone number, and the system stores data records that associate the stored value of the first identifier with the subscriber's phone number (Figure 2, 206).
13. The system according to claim 8, wherein, The first identifier is the media access control (MAC) address of the mobile computing device, and obtaining the first value of the first identifier includes: extracting the MAC address from a received Session Initiation Protocol (SIP) signal associated with the request to initiate the telephone call (Figure 2, 206).
14. The system according to claim 8, wherein, Obtaining the device identifier includes: sending a request to the mobile computing device to provide the device identifier; and receiving a response from the mobile computing device, the response including the device identifier (FIG. 2, 206).
15. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform steps for detecting a Subscriber Identity Module (SIM) change at a mobile computing device configured to make and receive telephone calls via a local dialer application using a telephone number assigned to the SIM, the steps comprising (FIG. 2, 206): receiving a request to initiate a telephone call from the mobile computing device; obtaining a first value of a first identifier uniquely identifying the mobile computing device and a second value of a second identifier uniquely identifying a subscriber of a communication service (FIG. 2, 206); comparing the first value of the first identifier with a stored value of the first identifier; and, upon determining a difference between the value of the first identifier and the stored value of the first identifier, holding the request to initiate the telephone call in a pending state while invoking an authentication process to authenticate the subscriber before further processing the request to initiate the telephone call (FIG. 2, 206).
16. The non-transitory computer-readable medium according to claim 15, wherein, Invoking the authentication process includes: sending a message including a verification code to a client messaging application, through which the subscriber is currently logged into the messaging service (Figure 2, 206); prompting the user of the computing device to send a text message including the verification code to a specific phone number using a local messaging application running on the mobile computing device (Figure 2, 206); and receiving the text message sent by the local messaging application, wherein successful reception of the text message containing the verification code authenticates the subscriber (Figure 2, 206).
17. The non-transitory computer-readable medium according to claim 15, wherein, The second value of the second identifier is the subscriber's phone number, and the instruction causes the one or more processors to store a data record that associates the stored value of the first identifier with the subscriber's phone number (Figure 2, 206).
18. The non-transitory computer-readable medium according to claim 15, wherein, The first identifier is the media access control (MAC) address of the mobile computing device, and obtaining the first value of the first identifier includes (Figure 2, 206): extracting the MAC address from the received Session Initiation Protocol (SIP) signal associated with the request to initiate the telephone call (Figure 2, 206).
19. The non-transitory computer-readable medium according to claim 15, wherein, Obtaining the device identifier includes: sending a request to the mobile computing device to provide the device identifier; and receiving a response from the mobile computing device, the response including the device identifier (FIG. 2, 206).
20. The non-transitory computer-readable medium according to claim 15, wherein, The steps further include: upon successful authentication of the subscriber, updating the database to associate the first value of the first identifier with the second value of the second identifier (Figure 2, 206).