Network Core Subscriber Authentication for SIM Swap Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telecommunication networks face vulnerabilities where bad actors can manipulate subscriber account changes through methods like SIM swapping and social engineering, compromising user accounts due to lack of robust authentication within the network core.

Innovation Solution

Implementing a subscriber authentication system within the network core that generates authentication codes, verifies user input, and requires approval from the subscriber before applying account changes, using mechanisms like two-factor authentication and secure elements on SIM cards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional account change methods are used without robust authentication, then account changes can be made quickly and easily, but security is compromised and unauthorized access occurs

Engineering Contradiction:
Improveaccount securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system generates and presents authentication information to the subscriber before the account change is finalized. The subscriber must approve the change after seeing the authentication information, ensuring verification occurs in advance of the actual account modification. This preliminary authentication step prevents unauthorized changes while maintaining a manageable process flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication information (such as one-time codes or verification tokens) that mediates between the subscriber's request and the account change execution. This intermediary element verifies the subscriber's identity and intent without requiring complex direct authentication protocols, thus enhancing security while keeping the system relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication methods are implemented, then unauthorized access is prevented, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication information is generated and presented to the subscriber before the account change is executed. The subscriber has a brief window to review and approve or reject the change. This preliminary presentation reduces authentication time by avoiding iterative verification steps, while still ensuring reliable authentication through the approval mechanism.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables the subscriber to self-verify their own authentication information and make the approval decision directly. Rather than requiring multiple external verification steps or customer service intervention, the subscriber independently completes the authentication process by reviewing the presented information and confirming approval, thereby reducing overall authentication time while maintaining reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12495303B2Systems and methods for authenticating a subscriber within the network core
Publication Date: 2025.12.09 BOOST SUBSCRIBERCO LLC
  • US12495303B2 patent drawing
  • US12495303B2 patent drawing
  • US12495303B2 patent drawing

AI summary

A subscriber authentication system prevents a change from being applied to a subscriber account until the subscriber approves of the change at the network core. The subscriber authentication system identifies one or more subscriber accounts for a network, each subscriber account being associated with a subscriber. The subscriber authentication system receives an indication that a change is requested for a subscriber account. The subscriber authentication system receives, within a network core, authentication information and data indicating whether the change is to be made to the subscriber account. The subscriber authentication system authenticates, within the network core, that the data was received from the subscriber based on the authentication information. The subscriber authentication system causes the change to be made based on the data indicating whether the change is to be made and the result of the authentication.