Proximity-Based SIM Authentication Token Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing use of SMS for multi-factor authentication (MFA) in mobile devices exposes sensitive accounts to security vulnerabilities, such as SIM-swapping, where adversaries can intercept MFA codes and gain unauthorized access.
Innovation Solution
Implementing proximity-based SIM card subscriber authentication, where a new SIM card is activated in a locked state until successful verification using a token from a physical authentication device within proximity to the subscriber's mobile device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If SMS is used for multi-factor authentication, then ease of operation is improved, but security reliability deteriorates due to SIM-swapping vulnerabilities
Solution Approach 1:
The patent introduces a proximity-based authentication device as an intermediary between the user and the authentication process. This physical device must be in close proximity to the mobile device to authorize SIM card changes, adding a new layer of security without completely replacing the existing SMS-based MFA process. The intermediary device verifies physical presence and authorization before allowing SIM card activation.
Solution Approach 2:
The authentication process is segmented into multiple independent verification steps: first verifying subscriber identity through existing channels, then requiring physical proximity authentication through a separate authentication device, and finally activating the SIM card. This segmentation allows each component to be optimized independently while collectively providing enhanced security.
2Reliability
If proximity-based authentication is added to SIM card activation, then security reliability is improved, but device complexity increases
Solution Approach 1:
The authentication device serves as a dedicated intermediary component that handles the complexity of proximity-based verification. By separating this functionality into a standalone device, the mobile device itself doesn't need to incorporate complex authentication hardware, thus limiting the increase in device complexity to only the authentication device rather than the entire mobile ecosystem.
3Reliability
If SIM card activation requires proximity authentication, then security reliability is improved, but loss of time increases due to additional verification steps
Solution Approach 1:
The authentication device performs preliminary verification of the subscriber's identity and authorization status before the SIM card activation process begins. By completing these verification steps in advance and maintaining authentication tokens, the system reduces the time required during actual SIM card activation, as the physical presence verification is already established.
Data Source
AI summary
Examples of the present disclosure describe systems and methods for preventing unauthorized Subscriber Identity Module (SIM) card swapping by implementing proximity-based SIM card subscriber authentication. In examples, when a communications service provider receives a request to move a subscriber phone number to a new SIM card, the new SIM card is activated in a locked state. In the locked state, certain features (e.g., receiving calls and text messages/texts) are disabled until the subscriber's identity is confirmed using proximity-based authentication. In examples, proximity-based SIM card subscriber authentication is performed using a token provided by a physical authentication device within proximity to a subscriber mobile device including the new SIM card. Upon successful proximity-based SIM card subscriber authentication, the new SIM card is activated in an unlocked state.


