Encrypted Token Authentication for SIM Swap Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SIM swap attacks, where malicious actors trick telecommunications network personnel into porting a victim's telephone number to a SIM card they possess, exploit weaknesses in two-factor authentication, leading to financial theft and resource wastage in identification and prosecution efforts.

Innovation Solution

Implementing a system where user devices generate and authenticate encrypted tokens or keys based on personal identifiers, such as PINs or biometrics, to verify SIM swaps between devices, ensuring only legitimate transactions occur and reducing fraudulent activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted token authentication is implemented for SIM swaps, then security against fraudulent SIM swap attacks is improved, but device complexity and authentication process complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication by generating and verifying encrypted tokens before the SIM swap is completed. The tokens are generated in advance using device-specific credentials (IMEI, Android ID, or iOS identifier) and cryptographic keys, and are verified by the provisioning device before allowing the SIM swap to proceed. This preliminary action ensures security is established before the actual swap occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encrypted token acts as an intermediary that mediates between the user device and the provisioning device during SIM swap authentication. Instead of directly trusting device identifiers or user-provided information, the system uses the encrypted token as a secure intermediary credential that proves ownership and authorization without exposing sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual verification of SIM swaps is performed, then security against fraud is improved, but productivity and resource efficiency deteriorate due to increased processing and investigation resources required

Engineering Contradiction:
Improvefraud preventionVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The SIM swap authentication process is designed to be self-service, where the user device automatically generates the encrypted token and the provisioning device automatically verifies it using pre-configured cryptographic keys. This eliminates the need for manual verification by customer service representatives, allowing the system to handle authentication autonomously and efficiently at scale.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical verification processes with automated cryptographic verification. Instead of human operators manually checking identities and authorizing SIM swaps, the system uses automated cryptographic key verification and encrypted token validation, which is both more secure and highly efficient for processing large volumes of requests.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated SIM swap processing is implemented, then productivity is improved, but security against malicious SIM swap attacks deteriorates

Engineering Contradiction:
ImproveSIM swap processing efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication by generating and verifying encrypted tokens before the SIM swap is completed. The tokens are generated in advance using device-specific credentials (IMEI, Android ID, or iOS identifier) and cryptographic keys, and are verified by the provisioning device before allowing the SIM swap to proceed. This preliminary action ensures security is established before the actual swap occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the authentication parameter from simple device identifiers (IMEI, serial numbers) to cryptographic tokens generated using asymmetric key pairs. This parameter change maintains automated processing while significantly enhancing security, as the cryptographic tokens are computationally infeasible to forge or replicate without the private key.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If cryptographic key verification is performed during SIM swaps, then measurement precision of authentication accuracy is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidcryptographic processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication by generating and verifying encrypted tokens before the SIM swap is completed. The tokens are generated in advance using device-specific credentials (IMEI, Android ID, or iOS identifier) and cryptographic keys, and are verified by the provisioning device before allowing the SIM swap to proceed. This preliminary action ensures security is established before the actual swap occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encrypted token acts as an intermediary that mediates between the user device and the provisioning device during SIM swap authentication. Instead of directly trusting device identifiers or user-provided information, the system uses the encrypted token as a secure intermediary credential that proves ownership and authorization without exposing sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11445374B2Systems and methods for authenticating a subscriber identity module swap
Publication Date: 2022.09.13 VERIZON PATENT & LICENSING INC
  • US11445374B2 patent drawing
  • US11445374B2 patent drawing
  • US11445374B2 patent drawing

AI summary

A first user device may provide, to a provisioning device, a request for a subscriber identity module (SIM) swap that causes provisioning data to be provided to a first SIM card of the first user device and from a second SIM card of a second user device. The first user device may generate a first encrypted token based on a first identifier associated with the first SIM card. The first user device may provide, to the provisioning device, the first encrypted token and a user identifier. The first user device may selectively receive the provisioning data when the first encrypted token matches a second encrypted token generated by the second user device based on a second identifier associated with the second SIM card, or receive a message indicating that the first user device cannot be provisioned, when the first encrypted token fails to match the second encrypted token.