Adaptive SIM Security and Transaction Authentication System and Method Based on Device-Network-Location Triad
Patent Information
- Application Number
- TR202613515
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-08-10
- Publication Date
- 2026-09-21
Smart Images

Figure 00000013_0000
Abstract
Description
1 TARIFF Adaptive SIM Security and Transaction Authentication System Based on Device-Network-Location Triad and Method TECHNICAL FIELD The invention relates to telecommunications network security, digital authentication, and SIM card management. systems used in the field of financial cybersecurity, especially SIM card replacement or line Unauthorized access attempts resulting from transportation operations affect the device, network, and location. 10 Identification through combined evaluation of data and assessment of critical operations according to risk level a SIM security and transaction verification system that enables adaptive verification and It is related to the method. PREVIOUS TECHNIQUE 15 Nowadays, when changing SIM cards or porting phone numbers, banks and Digital platforms usually make this change after the transaction is completed, and in some cases... In some cases, it is noticed with a delay. In current applications, user consent is obtained via SMS. or it can be obtained through a simple verification mechanism, but the user's phone must not be 20 at that moment. remote access, social engineering or similar methods controlled by third parties Whether or not it has been done cannot be analyzed in every case. Furthermore, the physical location of a line cannot be determined in every situation. Information about the device's location and where it was used, password reset, high-value information. Instantaneous and simultaneous operation at the operator level during financial transfers or similar sensitive transactions. These may not be used as security criteria for evaluation. 25 In the current systems, banks can control SIM card changes and mobile operators can control location. They can have access to this information. However, this data is subject to a single real-time security measure. It is not integrated under the protocol. Accordingly, in the current structure, control is carried out after the incident. or notifications can be made, device information, location information and critical operation authorization are all with the same operator 30 Simultaneously evaluated within the network and stopped before the process is completed. It remains limited. In addition, the line's predefined device ID or hardware cryptographically linking the signature and authorizing financial transactions on an unverified device. The absence of a SIM-device anchoring structure to prevent SIM swapping fraud. This creates an additional security need. 35 2 Current validation systems are mostly based on fixed decisions of transaction acceptance or rejection. It utilizes mechanisms such as the user being in a familiar location but on a new device. or in intermediate risk situations such as a familiar device but switching to an unusual location, the risk Depending on your score, instead of SMS, you may receive voice confirmation, biometric verification, a registered secondary line, or The need arises to choose different verification channels, such as video confirmation. These 5 Therefore, device fingerprinting, base station-derived location and behavioral data are critical processes. Information, SIM-device connection, and user consent all come together at the operator level. integrated system that enables dynamic determination of the verification level by evaluation A security structure is needed. As a result of research conducted in the literature, publication number “US10178223B1” and “FRAUDULENT SUBSCRIBER IDENTITY MODULE (SIM) SWAP DETECTION - FRAUDULENT SUBSCRIBER IDENTITY United States patent titled "MODULE (SIM) CHANGE DETECTION" A document was found. This document concerns the mobile device's connection to the cellular network. by evaluating its status, signal level and, in some cases, its geographic location 15 This determines the likelihood that a SIM card change has occurred and notifies the user or the relevant service. It relates to a detection approach that sends a notification to its provider. However, in the document mentioned, Anchoring between the previously registered device fingerprint and the SIM card, base station Creating a routine transaction profile from data received from banks or digital services. 20 critical transaction and one-time password requests simultaneously on the operator's core network. adaptive technology that selects different verification channels based on the audit and resulting risk score. an indication that the verification orchestrator works in an integrated manner with these elements None have been encountered. As a result of research conducted in the literature, publication number “US20190319945A1” and “DYNAMIC 25 MULTI-FACTOR AUTHENTICATION - DYNAMIC MULTI-FACTOR AUTHENTICATION A United States patent application titled "Invention" has been found. The application is based on changes in the risk score relating to the user or device. Multifactor authentication, which dynamically changes the number or type of validation factors. It is related to the verification model. However, in the mentioned application, SIM change or number portability 30 Monitoring of transactions at the mobile operator level, SIM card to predefined device Linking the identity and hardware signature to the base station data creates a routine location profile. creation and processing of critical transaction requests from banks regarding the device-SIM-location Along with the matching process, unauthorized transactions are evaluated within the operator's core network. No evidence of blocking during the communication phase was found. 35 3 Ultimately, the problems mentioned above, which cannot be solved with current technology, are the subject of this technical analysis. This has made it necessary to make an innovation in the field. A BRIEF DESCRIPTION OF THE INVENTION The present invention aims to eliminate the aforementioned disadvantages and introduce new 5 to the relevant technical field. combining device, network, and location data to bring advantages. It relates to the adaptive SIM security and transaction verification system and method. The main purpose of the invention is to enable a mobile line's critical operation authorization to be granted only by user-entered information. Not based on information or SMS confirmation, but on the line's predefined device ID and hardware signature, base 10 It depends on the simultaneous verification of routine location information originating from the station and the real-time transaction context. to make it so. Another purpose of the invention is to facilitate device-to-line communication during SIM card swapping or line porting attempts. By analyzing deviations in matching and position behavior at the moment the transaction occurs, 15 intervention before unauthorized financial or digital transactions are completed to provide. Another purpose of the invention is to provide verbal confirmation instead of a fixed acceptance or rejection decision based on a risk score. Different types of verification, such as biometric authentication, registered second line verification, or video confirmation, are available. The goal is to provide a validation structure that adaptively triggers the most appropriate of the available methods. Another purpose of the invention is to ensure that the SIM card is only active on defined and secure devices. SIM-device anchoring, which enables the device to be cloned or SIM replaced. The next step is to prevent unauthorized devices from performing critical operations. 25 Another purpose of the invention is mobile banking, cryptocurrency exchange access, and corporate virtual private networks. connection, e-Government access, remote contract approval, and authorized device or region restriction. a central security gateway that can be used in existing Internet of Things applications to provide. 30 All the purposes mentioned above and those that will emerge from the detailed explanation below. The present invention aims to achieve device identification in the mobile operator core network. SIM replacement by simultaneously evaluating location and behavioral data along with critical transaction information. 35 methods for detecting fraudulent attempts originating from various sources and verifying them according to risk level. SIM security and transaction verification system that adaptively selects and stops unauthorized operations. Its characteristic is; 4 the IMEI and hardware signature of the secure devices used by the subscriber's line are sent to the network. The device fingerprint recorder creates a device-line match by recording the device fingerprint. Using base station data, it determines the subscriber's routine movement area and real-time location. a location and behavior analytics engine that analyzes deviations, Instantaneous processing of one-time password and critical transaction requests from banks or digital services. as a critical transaction trigger tracker, even sudden device, location or SIM changes can be assessed as risky. an anomaly detection algorithm that marks these situations, The SIM card should only be authorized to operate on defined and secure devices. SIM-device anchoring protocol, 10 Adaptive validation determines the additional validation method to be applied based on the resulting risk score. orchestrator, In suspicious situations, alternative options such as a registered second line, video confirmation, or biometric verification are available. a user approval interface that obtains user consent through a channel, Immediately halting transactions determined to be unauthorized and notifying the relevant financial institutions or 15 Fraud alert and blocking unit that sends reports to the operator panel. It includes. The best way to utilize the advantages of the existing invention, together with its structure and additional elements. For it to be understood, it must be evaluated together with the figures explained below. 20 BRIEF DESCRIPTION OF THE FIGURES Figure 1 shows the adaptive SIM security and operation based on the device-network-location triad, which is the subject of the invention. This is a representative link representation of the verification system. 25 Figure 2 shows the process flow of the adaptive SIM security and transaction verification method that is the subject of the invention. It is a representative view showing. The drawings do not necessarily need to be scaled and are necessary for understanding the invention. Details that are not present may have been overlooked. Furthermore, at least to a large extent, 30 Elements that are identical or at least have substantially identical functions are numbered the same. It is shown. REFERENCE NUMBERS 35 1. Device fingerprint scanner 2. Location and behavior analytics engine 3. Critical transaction trigger tracker 4. Anomaly detection algorithm 5. SIM-device anchoring protocol 6. Adaptive verification orchestrator 7. User Confirmation Interface 5 8. Fraud warning and blocking unit 1001. The IMEI and hardware signature of the secure devices used by the subscriber's line are transmitted to the network. Verification of device-line matching by recording 1002. Determining the subscriber's routine movement area and real-time location using base station data. 10 analyzing deviations as a risk of fraud 1003. Instantaneous processing of one-time password requests from banks or digital services. being checked and passed through a security filter 1004. Even sudden changes can be flagged as risky by artificial intelligence. 1005. Cryptographic lock that ensures the SIM card can only be activated on defined and secure devices. 15 implementation of the mechanism 1006. Decision to trigger an additional verification method based on the resulting risk score. 1007. Obtaining confirmation from the user through an alternative channel in suspicious situations. 1008. Immediate suspension of transactions found to be unauthorized and related financial actions. 20 sending reports to organizations or operator panels DETAILED DESCRIPTION OF THE INVENTION This detailed description explains the invention, an adaptive SIM based on the device-network-location triad. The security and transaction verification system and method only contribute to a better understanding of the subject. 25 This is explained with examples that will not create any limiting effect. The device fingerprint recorder (1) included in the invention, the subscriber's registers the IMEI and hardware signature of the secure devices using its line with the network and It is the unit used to verify device-line matching in subsequent operations. Location 30 and behavior analytics engine (2), using base station data, analyzes subscriber's routine movements determining the area and the deviation of the instantaneous position from the routine movement area in question. It analyzes the risk of fraud. Critical transaction trigger tracker (3), One-time passwords (OTPs) from banks or digital services, Requests for critical transactions such as password reset, high-value transfers, SIM changes, or number porting are handled under Article 35. It monitors in real-time and initiates a security assessment. Anomaly detection. algorithm (4), new device usage, unusual location, unexpected time period 6 by evaluating sudden changes such as line transfer requests using artificial intelligence SIM identifies risky situations and contributes to the creation of a risk score. Device Anchoring Protocol (SIM-Device Anchoring) (5), SIM card only before having active transaction authorization on devices that are defined and considered secure. It creates the cryptographic lock mechanism that provides the adaptive verification orchestrator (6), 5 The penalty will be applied based on a risk score consisting of device, location, behavior, and critical operation data. determining the verification method; allowing standard verification in low-risk situations. when providing verification, in suspicious situations, voice verification, biometric verification, registered secondary line or It triggers additional verification channels such as video confirmation. User approval interface (7), 10 where additional verification is deemed necessary by the adaptive verification orchestrator (6). In these situations, it obtains confirmation from the user through an alternative channel and uses Face ID or Touch ID. or equivalent biometric data with user information registered in the operator's network It mediates the matching process. Fraud Alert and Blocking Unit Blocking Unit (8) stops transactions that are determined to be unauthorized instantly and the relevant financial It sends alerts and reports to their organizations or operator panels. 15 In one implementation of the invention, the system is located on the mobile operator's core network. network), home subscriber server (HSS) and short message service network a security gateway that controls the data flow between the gateway (SMS-Gateway) It functions as a gateway. This security gateway serves banks and other services 20 Application programming interfaces for real-time data sharing with providers It communicates via Application Programming Interface (API). Thus, a critical The transaction or one-time password request is transmitted to the bank or user before the device / line Matching, compatibility of current location with routine movement profile, SIM-device anchoring status and operation. The context can be evaluated together at the same network layer. 25 With this invention, the Zero Trust approach is being applied to the cellular network level; critical For a transaction to be completed, only the correct password or SMS confirmation is required. It is not accepted that the line is located on a known device ID, and the location behavior is It must be compatible with the expected profile and, if necessary, biometric or alternative channel 30 The completion of the verification process is evaluated together. Thanks to this structure, the SIM If the card is copied or the SIM number is transferred to another SIM card, the device Financial transaction authorization may be blocked due to the inability to establish a match; intermediate risk. Instead of being directly rejected at these levels, the transaction is put on hold for additional verification. It is applicable. 35 7 The invention aims to protect mobile banking security and transaction confirmations arising from SIM swapping. as well as cryptocurrency exchange logins, corporate virtual private network (VPN) access, e-Government portal logins and remote contract approval processes It can be used. In addition, Internet of Things (IoT) devices, For example, smart locks or vehicle tracking systems can only be used by authorized devices or within a designated area. 5 It can also be applied to safety scenarios for its operation, provided the conditions are met. The steps involved in the process are as follows: - By registering the IMEI and hardware signature of the secure devices used by the subscriber's line to the network. Verification of device-line matching (1001), 10 - Determining the subscriber's routine movement area and real-time location using base station data. Analysis of deviations as a risk of fraud (1002), - Instant processing of one-time password requests from banks or digital services. monitoring and passing through a security filter (1003), - In fact, sudden changes made are marked as risky by artificial intelligence (1004), 15 - A cryptographic lock that ensures the SIM card can only be activated on identified and secure devices. implementation of the mechanism (1005), - Decision to trigger an additional verification method based on the resulting risk score (1006), - Obtaining confirmation from the user through an alternative channel in suspicious situations (1007), - Transactions found to be unauthorized will be immediately halted, and the relevant financial institutions will be notified within 20 days. or sending a report to the operator panel (1008). The working principle of the invention is generally that the device fingerprint recorder (1) registers the subscriber's fingerprint. Recording the IMEI and hardware signature of secure devices and performing location and behavioral analytics. 25 by generating routine motion profile from base station data by engine (2) It starts. The critical transaction trigger tracker (3) is a single one from banks or digital services. When it detects a password or critical operation request, it retrieves the current device ID, location, and operation. The context is transferred to the security assessment. The anomaly detection algorithm (4), new It flags risky situations by analyzing deviations such as device or unusual location; SIM-device anchoring protocol (5) checks the line matching with the authorized device 30 Adaptive validation orchestrator (6) sets the standard according to the resulting risk score. continue with verification or audio, biometric, registered second line or video confirmation It decides whether to implement additional verification, such as when additional verification is required. User approval is obtained via the user approval interface (7); verification fails. Fraud warning and blocking 35 if the transaction is found to be unauthorized or if the transaction is determined to be unauthorized. unit (8) stops the operation momentarily and notifies the relevant financial institution or operator panel 8 It sends a report. In this way, the operator receives device information, location information, and transaction authorization information. They are integrated within a single security decision-making mechanism at each layer.
Claims
9 REQUESTS 1. Device ID, location, and behavior data, along with critical data, on the mobile operator's core network. By simultaneously evaluating transaction information, unauthorized transactions resulting from SIM card changes can be detected. Adaptive SIM security and transaction verification 5 developed for verification and blocking. It is a system, and its feature is; • the IMEI and hardware signature of the secure devices used by the subscriber's line are sent to the network. Device fingerprinting, which creates device ID data relating to device-line matching by recording it. recorder (1), • device ID data generated by the device fingerprint recorder (1) 10 base station data to be evaluated to determine the subscriber's routine movement area. a position and behavior analytics engine that determines and analyzes instantaneous position deviations (2), • one-time password and critical transaction requests from banks or digital services Critical process trigger tracker (3) that triggers security assessment by detecting, • device fingerprint recorder (1), location and behavior analytics engine (2) and critical process 15 By evaluating the data provided by the trigger tracker (3), the sudden device, location or Anomaly detection algorithm that marks SIM changes as risky (4), • The SIM card is only authorized to operate on pre-defined and secure devices. SIM-device anchoring protocol (5) which enables this, • Risk status determined by the anomaly detection algorithm (4) and SIM-device anchor 20 Device-SIM matching provided by the (binding) protocol (5) Adaptive validation determines the validation method to be applied based on the risk score by evaluating the situation. verification orchestrator (6), • if an additional verification decision is made by the adaptive verification orchestrator (6) User consent interface (7), 25 that receives approval from the user via an alternative channel • provided by the adaptive validation orchestrator (6) and user confirmation interface (7) Based on the verification result, unauthorized transactions are immediately halted and the relevant financial transactions are addressed. Fraud alert and blocking unit that sends reports to organizations or operator panels (8) It includes. 30 2. The system is compliant with Request 1 and its feature is that the device fingerprint recorder (1) registers the subscriber's line. by registering the IMEI information and hardware signature of the secure devices it uses with the network, then... It is a recording unit that creates device-line mappings for use in critical operations. 35 3. The system is compliant with claim 1 and its feature is that the position and behavior analytics engine (2) is based on Determining the subscriber's routine movement patterns and current location from station data. an analysis that considers deviations from the routine course of action as a risk of fraud It is a unit.
4. The system is compliant with claim 1 and its feature is that the anomaly detection algorithm (4) can detect anomalies, even if they occur. Sudden device changes, location changes, or line porting requests are handled by artificial intelligence. 5 It is an algorithm that evaluates and marks items as risky.
5. The system is compliant with Claim 1 and its feature is; SIM-device anchoring protocol (5), SIM The card should only be authorized to process transactions on pre-defined and secure devices. It is a protocol that includes a cryptographic lock mechanism. 10 6. The system compliant with claim 1, and its feature is that the adaptive verification orchestrator (6) adapts to the different devices. based on the risk score generated if the situation occurs or if the location deviates from its routine area of operation one that triggers at least one of the voice verification or biometric verification methods It is a verification unit. 15 7. The system complies with Request 1 and its feature is that the user approval interface (7) is available in case of suspicious situations. User confirmation is obtained via a registered secondary line or video confirmation, and biometric data is provided. It is an interface that transfers data to the verification process on the operator network.
8. The system complies with Claim 1, and its characteristic is; home subscriber on the mobile operator core network. a security measure that monitors the data flow between the server and the short message service gateway It is configured as a gateway and provides real-time communication with banks and service providers. It includes application programming interfaces for data sharing.
9. Adaptive systems based on device-network-location triad implemented in the mobile operator core network. SIM is a security and transaction verification method; its function is: • By registering the IMEI and hardware signature of the secure devices used by the subscriber's line to the network. Verification of device-line matching (1001), • Determining the subscriber's routine movement area and real-time location using base station data. 30 Analysis of deviations as a risk of fraud (1002), • Instant processing of one-time password requests from banks or digital services monitoring and passing through a security filter (1003), • In fact, sudden changes can be marked as risky by artificial intelligence (1004), • Cryptographic lock that ensures the SIM card can only be activated on defined and secure devices. 35 implementation of the mechanism (1005), • Decision to trigger an additional verification method based on the resulting risk score (1006), 11 • Obtaining confirmation from the user through an alternative channel in suspicious situations (1007), • Immediately halting transactions found to be unauthorized and notifying the relevant financial institutions. or sending a report to the operator panel (1008), It includes the steps of the process.