SIM Authentication via Cryptographic Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a method to independently verify that a Subscriber Identity Module (SIM) on a mobile device has not been swapped or forged, which can lead to unauthorized use of mobile communications.

Innovation Solution

Implementing cryptographic metadata and software during manufacturing and SIM activation processes to verify the SIM on a mobile device is the same one activated for that device, using a network environment with components like OEM and MNO platforms to generate and validate unique authentication codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SIM card systems are used without additional verification mechanisms, then device simplicity is maintained, but security against SIM swapping and forgery is compromised

Engineering Contradiction:
ImproveSIM authentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by embedding cryptographic metadata and authentication software during the manufacturing and SIM activation processes. This pre-configuration enables automatic verification of SIM authenticity before actual use, preventing SIM swapping and forgery attacks without requiring complex runtime interventions or user actions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic metadata as an intermediary element that mediates between the SIM card and the mobile device. This metadata serves as a trusted third-party verification mechanism, allowing the system to authenticate SIM identity without direct human intervention or complex procedural steps, thereby enhancing security while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic verification methods are implemented, then SIM authentication reliability is improved, but computational requirements increase

Engineering Contradiction:
ImproveSIM authentication securityVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent reduces computational energy consumption by performing cryptographic operations preliminarily during manufacturing and SIM activation. The authentication software and cryptographic metadata are pre-configured, enabling fast verification during actual use without requiring intensive real-time computational resources or significant energy expenditure.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If verification systems are scaled to accommodate large numbers of devices, then system versatility is improved, but complexity of management increases

Engineering Contradiction:
Improvescalability to large device numbersVSAvoidsystem management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent achieves scalability by designing a universal cryptographic verification system that can accommodate any number of devices through a standardized authentication protocol. The system uses consistent metadata structures and verification procedures across all devices, allowing seamless expansion without increasing management complexity or requiring device-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10924928B1System and method for providing authenticated identity of mobile phones
Publication Date: 2021.02.16 VERIZON PATENT & LICENSING INC
  • US10924928B1 patent drawing
  • US10924928B1 patent drawing
  • US10924928B1 patent drawing

AI summary

Systems and methods validate that subscriber identity module (SIM) number of an end device connected to a network is the same number that was activated for that device. A network device in a network obtains a SIM number and a universal identifier (UID) for the end device during an activation procedure. The network device generates a unique SIM authentication code based on the SIM number, the UID, and a master key. The network device sends the unique SIM authentication code to the end device as part of the activation procedure. After activation, the network device receives, from the end device, an authentication message that includes a first one-time password (OTP), the UID, a time value, the SIM number, and the SIM authentication code. The network device generates a second OTP based on the UID, the time value, the SIM number, and the master key and validates a pairing of the end device and the SIM number when the two OTPs match.