Native Dialer Verification for SIM Swapping Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SIM jacking and SIM swapping attacks allow malicious actors to fraudulently transfer a Subscriber Identity Module (SIM) associated with a mobile device to another device without authorization, enabling them to intercept calls, messages, and authentication codes, leading to identity theft and financial fraud.

Innovation Solution

A unified communications service maintains data records mapping subscriber identifiers to device identifiers, verifying that the device identifier of the mobile computing device matches the subscriber identifier during call requests, and employs synthetic call hand-offs and authentication processes to ensure only authorized devices can access the SIM-associated phone number.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SIM cards are made removable and portable, then user mobility and flexibility are improved, but vulnerability to SIM jacking and swapping attacks increases

Engineering Contradiction:
Improveuser mobilityVSAvoidSIM jacking vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a unified communications service as an intermediary layer between the user and the SIM card. This service maintains device identifiers and call routing information independently of the SIM card's physical location, allowing calls to be routed to the legitimate device even when the SIM is physically present in a different device. The intermediary service verifies device identity through authentication processes and synthetic call hand-offs, preventing malicious devices from intercepting calls simply by possessing the SIM card.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional call routing based on SIM phone numbers is used, then network simplicity is maintained, but security against unauthorized SIM usage deteriorates

Engineering Contradiction:
Improvenetwork simplicityVSAvoidauthorization security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary authentication actions before call routing occurs. The unified communications service performs synthetic call hand-offs and device verification processes in advance to establish and verify the legitimate device identifier associated with a SIM phone number. This preliminary verification ensures that only authorized devices can receive calls routed through the traditional phone number system, adding security without fundamentally changing the call routing infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the unified communications service continuously monitors and verifies device-SIM associations through synthetic call tests and authentication processes. When a device presents a SIM card, the service verifies whether the device identifier matches the expected identifier for that SIM's phone number. This feedback loop provides ongoing security verification while maintaining compatibility with traditional call routing based on phone numbers.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250175802A1Native dialer verification for a mobile computing device
Publication Date: 2025.05.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250175802A1 patent drawing
  • US20250175802A1 patent drawing
  • US20250175802A1 patent drawing

AI summary

A method for detecting fraudulent SIM swapping on a mobile device is provided. A server of a communications service receives a call request from a mobile device and obtains an identifier unique to the device. The obtained identifier is compared to a stored identifier and if different, the call request is held in a temporary state, pending authentication. To authenticate, a message with authentication instructions is sent via a messaging service of the communications service. The message provides instructions for the user to transmit a specific code from the mobile device's native messaging application to a server. Upon receiving the code, the device is authenticated before further call processing. Alternatively, a client application initiates a synthetic call which is then handed off to the native dialer application. If the handoff fails due to the native dialer's lack of mobile network connectivity, the device is then suspected of being compromised, such that additional authentication is required. The server thus provides enhanced security by leveraging the native dialer and messaging application.