Behavioral Data-Based SIM Card Security System

TR202614808A2Pending Publication Date: 2026-09-21TURK TELEKOMUNIKASYON A S
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TR202614808
Authority / Receiving Office
TR · TR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-08-31
Publication Date
2026-09-21

Smart Images

  • Figure 00000010_0000
    Figure 00000010_0000
Patent Text Reader

Abstract

This invention relates to a behavioral data-based SIM card security system (1) used to strengthen SIM card authentication in telecommunications infrastructure. In the system (1), a small behavioral code generated from the speed of the user's touch on the screen is recorded on the SIM card and compared with the new code generated by the mobile device (2) during each mobile network (8) connection, such as connecting, initiating a call, or logging into a data session. Thus, security threats such as SIM cloning, mobile device (2) theft, counterfeit mobile device (2) connection, and unauthorized access are transformed into a second layer of authentication with the user-specific finger speed behavior. In addition, it is guaranteed at the telecommunications level that the mobile device (2) connected to the mobile network (8) actually belongs to its owner.
Need to check novelty before this filing date? Find Prior Art

Description

1 TARIFF Behavioral Data-Based SIM Card Security System Technical Area This invention relates to SIM - Subscriber Identity Module - in telecommunications infrastructure. The Identity Module is used to strengthen card authentication, and includes behavioral data. It relates to a SIM card security system based on... State of the Art Current SIM card security relies primarily on a fixed secret key – Ki – inside the SIM card. It relies on cryptographic verification performed between the operator's core network. However, this Because the method doesn't take user behavior into account at all, the SIM card is physically handled. 10 When the attacker is transferred or cloned, the network cannot distinguish them from the real user. These structures are used for mobile device theft, SIM swap fraud, IMSI snatchers, and counterfeit products. Threats such as base stations and fake mobile devices connecting to the network with cloned IMEIs The current system only checks "is the password correct?". But these systems use a SIM card. who is using it, whether the phone is with its actual owner, or mobile 15 There is no indication as to whether the device's behavior aligns with that of a legitimate user. No verification is performed. Therefore, the telecommunications infrastructure operates as long as the passwords are correct. a single-factor, behaviorless, and static system that attackers can easily connect to It operates with a verification model. This gap is particularly evident in the increasing number of mobile devices in the 5G era. Its diversity and attack surface make it even more critical. 20 Patent application number TR2025 / 015286, which is included in the prior art. The document states that IMEI verification is performed based on the initial network signal during SIM card changes. The fraud prevention system and method are explained in the relevant application document. There is no mention of a SIM card security infrastructure based on behavioral data. In conclusion, the solutions that will meet the needs described above are among the 25 on the subject. Due to its shortcomings, it has become necessary to make improvements in the relevant technical field. Brief Description of the Invention The invention was created by drawing inspiration from existing situations and overcoming the aforementioned drawbacks. It aims to solve the problem. 2 The aim of this invention is to improve SIM card authentication in telecommunications infrastructure. a SIM card security system based on behavioral data used to strengthen It is the presentation of the matter. The SIM system uses a small behavioral code generated from the speed at which the user touches the screen. saved to the card and every mobile 5 in the form of connecting, initiating a call, data session The SIM code is compared with the new code generated by the mobile device during network connection. cloning, mobile device theft, connecting fake mobile devices, and unauthorized access, etc. Security threats require a second verification with user-specific finger speed behavior. It is converted to a layer. Also, the mobile device that connects to the mobile network actually... Whether it belongs to its owner is guaranteed at the telecommunications level. 10 The structural and characteristic features and all the advantages of the invention are given in the figure below. Thanks to the detailed explanation written with references to the diagram, it becomes clearer. This will be understood, and therefore the evaluation should also take this detailed explanation into account. It must be done by taking it. Figure 15 to Help Understand the Invention Figure 1 is a schematic representation of the system that is the subject of the invention. Explanation of Part References 1. System 2. Mobile device 3. User interaction module 20 4. Behavioral data collection and processing module 5. Behavioral signature generation module 6. SIM / eSIM secure area module 7. Base station 8. Mobile network 25 9. Subscriber identity database 3 110. Behavioral profile database 11. Authentication server 12. Access permission module 13. Additional verification module 14. Rejection module 5 Detailed Description of the Invention In this detailed description, the preferred configurations of the system (1) that is the subject of the invention are only This is explained to facilitate a better understanding of the subject. This invention enhances SIM card authentication in telecommunications infrastructure. This relates to a SIM card security system (1) based on behavioral data, used for. 10 In the system (1) a small behavioral code is generated from the speed at which the user touches the screen SIM It is saved to the card and every mobile device can connect, initiate a call, or log in to the data session. In the network (8) connection, the new code generated by the mobile device (2) is compared. Thus SIM cloning, mobile device (2) theft, fake mobile device (2) connection and unauthorized Security threats such as access control are mitigated by user-specific finger speed behavior, creating a second 15 It is converted into a verification layer. Also, the mobile device connected to the mobile network (8) (2) whether it actually belongs to its owner is guaranteed at the telecommunications level It will be received. The system, schematically shown in Figure 1 (1);  20 portable and handheld devices that connect to the internet via wireless networks mobile device (2),  the touch, swipe, press duration of the user on the mobile device (2) screen and User interaction module that collects behavioral data in the form of interaction rhythm (3),  Receiving user interaction data from the user interaction module (3), this raw 25 This filters and analyzes the data and converts it into a suitable format for verification. This allows us to extract behavioral characteristics and determine user-specific core behaviors. Behavioral data collection and processing module that forms the parameters (4), 4  from the behavioral data processed in the behavioral data collection and processing module (4) Generating a user-specific unique behavioral identity signature and displaying the generated signature a behavioral signature that creates a numerical profile unique to the user creation module (5),  Secure the behavior signature created in the behavior signature creation module (5) 5 SIM / eSIM secure area module (6) which stores SIM or eSIM space in this way,  If the mobile device (2) requests access, from the mobile device (2) base station (7) that receives and transmits incoming authentication data,  Receiving verification requests transmitted from the base station (7), authentication mobile network (8), 10 which distributes data between mobile device (2) and core network  Subscriber who stores and manages the user's subscription and authentication information identity database (9),  Stores the user's registered behavior profiles and is referenced during verification. Behavioral profile database that enables its use as (10),  If the mobile device (2) requests access to the mobile network (8) 15 authentication data from mobile device (2) to base station (7) and mobile Classic SIM, located in the subscriber identity database (9), over the network (8). Behavioral profiles recorded in the database (10) with verification information mobile during access to the mobile network (8) which evaluates the identity signature together Registered behavior profile with current behavioral data received from the device (2) 20 Identity verification that performs similarity analysis and risk assessment by comparison. server (11),  Behavioral and authentication results of the authentication server (11) If it deems appropriate, it allows access to the mobile network (8) of the mobile device (2). permission module (12), 25  Authentication server (11) risky, suspicious or partial non-compliance status If detected, the additional verification module (13) requests additional verification from the user. And  If the authentication server (11) finds the authentication process to be unsuccessful, the behavior Significant discrepancies were found with the profile, including SIM cloning, SIM swapping, and stolen SIM cards. if mobile device (2) use or the possibility of unauthorized access is determined deny access which prevents the mobile device (2) from accessing the mobile network (8) module (14) It includes. The invention differs from existing telecommunications security infrastructures in that it uses only a SIM card. the traditional structure based on verifying static cryptographic keys within it by bypassing user-specific behavioral biometric data, mobile network (8) verification It provides an additional layer of security that is included in the process. In current configurations, SIM In case the card or verification information is compromised, the mobile network (8), mobile 5 While the device (2) cannot be distinguished from the real user, within the scope of the system (1) the user's screen touch speed, press duration, scrolling characteristics, interaction rhythm, and Behavioral signatures generated from micro-behavioral movements serve as a verification mechanism. is included. Current data generated each time a connection is established to the mobile network (8). Behavioral data is compared with previously recorded user profiles in Mobile 10. It is analyzed whether the device is used by (2) the actual user. Thus SIM cloning, SIM swap fraud, use of stolen mobile devices (2), cloning Attempts to access the mobile network (8) with IMEI, fake base station (7) attacks and Unauthorized access attempts are detected with much higher accuracy compared to current techniques. This is possible. Another advantage of the invention is that it can be used with existing smart devices without requiring additional equipment. thanks to its ability to work via mobile device (2) sensors and user interaction data It can be integrated into operator infrastructures at low cost. In addition, the system (1) only be able to perform behavioral consistency analysis not only at the time of entry, but also throughout the session. Because it can be configured, it offers a dynamic and continuous verification approach, in this respect A more advanced level of security compared to classic one-time authentication methods. 20 This is especially true for 5G and future 6G communication infrastructures, where mobile networks are increasing. Considering the variety of devices (2), IoT connections and the advanced cyberattack surface, system (1) a new generation based on behavioral biometrics at the telecommunications level By offering a security and authentication method, it makes significant contributions to the existing technology. It provides. 25 In the system, the person using the (1) mobile device (2) touch, scroll, screen pressure, typing Behavioral movements such as rhythm and interaction duration User interaction module (3) It is detected by and transferred to the behavior data collection and processing module (4). Behavior In the data collection and processing module (4), raw user data is filtered and analyzed. and user-specific behavioral parameters are extracted. The resulting parameters are used to determine behavior. 30 a unique signature is generated by the signature creation module (5) and is processed by the user. It is converted into a behavioral identity signature. The generated behavioral signature is securely stored. SIM / eSIM is stored in the secure area module (6). The mobile device (2) connects to the mobile network (8) if an access request is made, authentication from the mobile device (2) data is transmitted from the base station (7) to the mobile network (8) and authentication 35 6 is transferred to the server (11). The authentication server (11) has the subscriber identity database. (9) Classic SIM verification information found in the behavior profile database (10) It evaluates the behavioral identity signature together. During access to the mobile network (8) Registered behavior profile with current behavioral data received from mobile device (2) Similarity analysis and risk assessment are performed by comparing them. Access permission 5 If the module (12) yields results consistent with actual user behavior, the mobile module (12) will be used. Access to the system (1) is permitted for the device (2). In case of suspected or partial incompatibility, Additional validation module (13) requests additional validation from the user. Rejection module (14), Significant discrepancies with the behavioral profile were detected; SIM cloning, SIM swapping, theft. If mobile device (2) use or the possibility of unauthorized access is determined, then mobile 10 The system (1) rejects the device's (2) access to the mobile network (8). Thus, the system (1) only accepts static SIM. Unlike existing techniques based on verification, behavioral biometrics-based By creating a dynamic verification mechanism, telecommunication networks become more secure. It implements a continuous and multi-layered authentication principle. The working principle of the system (1) is stated below. 15 User touch, swipe, press duration and interaction rhythm on mobile device (2) Behavioral data such as are collected. The data obtained is processed by the software in the mobile device (2). Behavioral characteristics are extracted by analyzing the data. This allows for the identification of key user-specific traits. Behavioral parameters are established. The collected behavioral data is converted into a behavioral identity signature. The generated signature is 20 It is converted into a digital profile that is unique to the user. This structure is then used in the following process: It is used as reference data in verification processes. The generated behavioral signature is stored on the SIM card, in the eSIM storage area. Alternatively... The behavioral profile is stored in a secure area on the operator's side. This allows for verification. Your data will be protected against unauthorized access. 25 Standard authentication when the mobile device (2) wants to connect to the mobile network (8) The process is initiated. Simultaneously, up-to-date user behavior data is generated and verified. This includes not only SIM verification but also behavioral verification in the process. is carried out. 7 The authentication server (11) on the mobile network (8) side, receives from the mobile device (2) It compares the current behavioral signature with the recorded behavioral profile. The similarity rate and... Behavioral consistency is analyzed. As a result of this process, user identity verification is performed. Based on the comparison results, a risk score is generated by the system (1). Risk Depending on the level, access may be allowed, additional verification may be requested, or access may be restricted to level 5. A decision to reject the request is generated. This ensures dynamic and multi-layered security control. If a discrepancy with the behavioral profile is detected, the system (1) may detect a possible SIM. cloning, SIM-changing, use of stolen mobile device (2) or counterfeit mobile device (2) It identifies situations. Suspicious links are automatically flagged, and security policies are applied. This is implemented. Thus, more advanced threat detection is achieved compared to existing structures. 10 The system (1) ensures behavioral consistency not only at the initial connection but also throughout the session. It can perform the monitoring. By analyzing sudden changes in user behavior. The security level is updated dynamically. This provides additional security based on continuous verification. Protection is provided.

Claims

8 REQUESTS 1. Portable and handheld devices that connect to the internet via wireless networks. SIM card identity in telecommunication infrastructure, having a mobile device (2) a SIM card used to strengthen its verification, based on behavioral data security system (1) and its feature is; 5  the touch, swipe, press duration of the user on the mobile device (2) screen and User interaction that collects behavioral data in the form of interaction rhythm module (3),  Receiving user interaction data from the user interaction module (3), this raw filtering and analyzing data and converting it into a suitable format for verification, 10 This allows us to extract behavioral characteristics and determine key user-specific behaviors. Behavioral data collection and processing module that forms the parameters (4),  Behavior processed in the behavior data collection and processing module (4) Generating a user-specific unique behavioral identity signature from data and 15 that converts the signature it produces into a digital profile unique to the user Behavior signature generation module (5),  the behavior signature created in the behavior signature creation module (5) SIM / eSIM secure area that securely stores SIM or eSIM data. module (6),  If the mobile device (2) requests access, the mobile device (2) 20 base station (7) that receives and transmits incoming authentication data,  Receiving verification requests transmitted from the base station (7), authentication mobile network (8) which distributes data between mobile device (2) and core network,  Stores and manages user subscription and authentication information. Subscriber ID database (9), 25  stores the user's registered behavior profiles and during verification Behavioral profile database that enables its use as a reference (10),  if the mobile device (2) requests access to the mobile network (8) authentication data from the mobile device (2) to the base station (7) and 30 located in the subscriber identity database (9) via mobile network (8). Classic SIM verification information and behavior profile are registered in the database (10) together with the behavioral identity signature, mobile network (8) recorded with current behavioral data received from the mobile device (2) during access 9 Similarity analysis and risk assessment by comparing behavioral profiles. authentication server (11),  Behavioral and authentication results of the authentication server (11) if it deems it appropriate, the mobile device (2) allows access to the mobile network (8) access permission module (12), 5  authentication server (11) risky, suspicious or partial nonconformity If it detects this, it will request additional verification from the user. module (13) and  If the authentication server (11) finds the authentication process to be unsuccessful, Significant discrepancies detected with the behavioral profile, SIM cloning, SIM-10 change, use of stolen mobile device (2) or possibility of unauthorized access if determined, the mobile device (2) prevents access to the mobile network (8). access denial module (14) It includes.