Network SIM Secure Device for Unauthorized Access Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Physical SIMs in wireless communication systems pose security risks as they can be easily transferred to unauthorized devices, allowing access to network services and private resources without proper authorization.
Innovation Solution
Implementing a Network SIM Secure (NSS) device controlled by the service provider, which determines whether a UE device is authorized to access the network independently of the SIM or UE device, using equipment identity checks and subscriber identity verification to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a physical SIM is used to provide flexibility for device upgrades, then ease of operation is improved, but network security deteriorates due to the risk of SIM extraction and unauthorized access
Solution Approach 1:
The patent introduces an NSS (Network SIM Secure) device as an intermediary component that mediates between the physical SIM and the network. The NSS device verifies the authenticity of the SIM and the authorized relationship between the SIM and the wireless device before allowing network access. This intermediary layer prevents unauthorized access even if the physical SIM is extracted from an authorized device or inserted into an unauthorized device, thus resolving the security vulnerability while preserving the flexibility of physical SIM usage.
2Ease of operation
If SIM authorization is used to enable device access to the network, then ease of operation is improved, but security against compromised SIMs deteriorates
Solution Approach 1:
The patent implements preliminary anti-action by having the NSS device perform security verification before the SIM authorization takes effect. The NSS device checks whether the SIM is compromised or unauthorized before allowing it to grant network access to the wireless device. This pre-emptive security check prevents compromised SIMs from successfully authorizing unauthorized devices, thereby eliminating attack scenarios while maintaining ease of operation for legitimate users.
Data Source
AI summary
A method may include receiving an attach request that includes an international mobile equipment identity (IMEI) and an international mobile subscriber identity (IMSI), and determining whether the IMEI is associated with a user device that is not allowed to attach to the network. The method may also include determining whether the IMSI included in the attach request is stored in a database, and determining whether an IMEI associated with the IMSI is stored in the database. The method may further include determining whether the IMEI stored in the database matches the IMEI included in the attach request and denying the attach request in response to determining that the IMEI stored in the database does not match the IMEI included in the attach request.


