Native Dialer Verification for SIM Swapping Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SIM jacking and SIM swapping attacks allow malicious actors to fraudulently transfer a Subscriber Identity Module (SIM) associated with a mobile device to another device without authorization, enabling them to intercept calls, messages, and authentication codes, leading to identity theft and financial fraud.
Innovation Solution
A unified communications service maintains data records mapping subscriber identifiers to device identifiers, verifying that the device identifier of the mobile computing device matches the subscriber identifier during call requests, and employs synthetic call hand-offs and authentication processes to ensure only authorized devices can access the SIM-associated phone number.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SIM cards are made removable and portable, then user mobility and flexibility are improved, but vulnerability to SIM jacking and swapping attacks increases
Solution Approach 1:
The patent introduces a unified communications service as an intermediary layer between the user and the SIM card. This service maintains device identifiers and call routing information independently of the SIM card's physical location, allowing calls to be routed to the legitimate device even when the SIM is physically present in a different device. The intermediary service verifies device identity through authentication processes and synthetic call hand-offs, preventing malicious devices from intercepting calls simply by possessing the SIM card.
2Device complexity
If traditional call routing based on SIM phone numbers is used, then network simplicity is maintained, but security against unauthorized SIM usage deteriorates
Solution Approach 1:
The patent implements preliminary authentication actions before call routing occurs. The unified communications service performs synthetic call hand-offs and device verification processes in advance to establish and verify the legitimate device identifier associated with a SIM phone number. This preliminary verification ensures that only authorized devices can receive calls routed through the traditional phone number system, adding security without fundamentally changing the call routing infrastructure.
Solution Approach 2:
The system implements feedback mechanisms where the unified communications service continuously monitors and verifies device-SIM associations through synthetic call tests and authentication processes. When a device presents a SIM card, the service verifies whether the device identifier matches the expected identifier for that SIM's phone number. This feedback loop provides ongoing security verification while maintaining compatibility with traditional call routing based on phone numbers.
Data Source
AI summary
A method for detecting fraudulent SIM swapping on a mobile device is provided. A server of a communications service receives a call request from a mobile device and obtains an identifier unique to the device. The obtained identifier is compared to a stored identifier and if different, the call request is held in a temporary state, pending authentication. To authenticate, a message with authentication instructions is sent via a messaging service of the communications service. The message provides instructions for the user to transmit a specific code from the mobile device's native messaging application to a server. Upon receiving the code, the device is authenticated before further call processing. Alternatively, a client application initiates a synthetic call which is then handed off to the native dialer application. If the handoff fails due to the native dialer's lack of mobile network connectivity, the device is then suspected of being compromised, such that additional authentication is required. The server thus provides enhanced security by leveraging the native dialer and messaging application.


