Knowledge-Based Authentication for SIM Reissue Fraud Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The conventional SIM reissuing process is vulnerable to fraudulent activities, as a fraudulent subscriber can easily impersonate a genuine subscriber, leading to unauthorized access to the genuine subscriber's accounts, especially when two-factor authentication is employed.
Innovation Solution
Implementing knowledge-based authentication (KBA) by generating questions based on the genuine subscriber's account data, such as call records and billing information, to validate the user requesting a SIM card reissue, thereby requiring familiarity with the account to authenticate the user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional identification methods (picture ID, credit card number, social security number) are used for SIM reissuing, then the process is simple and fast, but fraudulent subscribers can easily impersonate genuine subscribers
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the mobile device vendor and the subscriber. This server performs knowledge-based authentication by generating questions based on account data and verifying answers, thereby enhancing security without requiring the subscriber to directly provide sensitive identification information.
Solution Approach 2:
The patent changes the authentication parameter from static identification data (picture ID, credit card number, social security number) to dynamic knowledge-based responses. The authentication server generates questions based on account data such as call records, billing information, and usage patterns, making the authentication process adaptive and harder to predict for fraudsters.
2Reliability
If two-factor authentication is used for account access, then account security is improved, but fraudulent subscribers can still gain access by intercepting secret codes sent to the mobile device
Solution Approach 1:
The patent extracts the authentication process from the mobile device itself and relocates it to an authentication server. By performing KBA questions on the server using account data, the system eliminates the vulnerability where fraudsters can intercept codes sent to the device, as the authentication no longer depends on device-based secret codes.
Solution Approach 2:
The authentication server performs preliminary authentication actions by verifying knowledge-based answers before allowing any account access. This preliminary verification using account-specific questions (calls, billing, usage patterns) prevents fraudulent access before it can occur, rather than relying on subsequent code verification that can be intercepted.
3Reliability
If knowledge-based authentication questions are generated based on account data, then fraudulent reissuing is significantly reduced, but the authentication process becomes more complex
Solution Approach 1:
The authentication server performs multiple functions: it generates KBA questions based on account data, receives and verifies answers, and makes authentication decisions. This multi-functionality consolidates the authentication process into a single system component, reducing overall system complexity while maintaining high security through diverse authentication criteria.
Data Source
AI summary
An improved technique involves employing knowledge based authentication (KBA) to validate a user trying to reissue a SIM card. Along these lines, when a user goes to a mobile device vendor and requests a reissue of a SIM card, the vendor relays that request to an authentication server which in turn sends KBA questions to the user. The KBA questions are based on data available to the mobile carrier to which the genuine subscriber subscribes. Such data concerns information including calls made and received, amount of minutes and data used in a month, and amount billed in particular months. The vendor honors or denies the request to reissue the SIM card based on the answers submitted by the user to the authentication server.


