SIM Swap Authentication via Risk Scores and Biometrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The convenience of SIM swap services in mobile communication systems has created a security gap that allows fraudulent actors to circumvent multi-factor authentication, enabling them to intercept verification codes and access financial accounts by impersonating users.

Innovation Solution

Assigning a risk score to user accounts based on activity and location history, and requesting biometric signatures to authenticate SIM card transfers, thereby verifying the legitimacy of SIM swap requests and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SIM swap service is made convenient and easy to process, then user experience and service accessibility are improved, but security vulnerability increases allowing fraudulent actors to intercept verification codes

Engineering Contradiction:
ImproveSIM swap service convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary risk assessment and authentication actions before completing the SIM swap process. Risk scores are calculated in advance based on user behavior patterns, device history, and location data. Authentication challenges are sent to the original device before the SIM swap is finalized, ensuring that the user is still present and authorized before the fraudulent actor can complete the transaction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where risk scores are dynamically adjusted based on user interactions and device behavior. The mobile service provider receives feedback about authentication attempts, device locations, and user actions, and uses this information to update risk assessments in real-time. This allows the system to adapt to changing conditions and detect fraudulent patterns as they emerge.

Inventive Principle:
Principle #23Feedback

2Reliability

If multi-factor authentication is implemented with SMS verification, then authentication security is improved, but fraudulent actors can still circumvent the process by intercepting verification codes

Engineering Contradiction:
Improveauthentication securityVSAvoidverification code interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary risk assessment layer between the authentication request and the verification code delivery. Instead of directly sending verification codes to the new SIM card, the system first evaluates the risk score and may require additional authentication steps. This intermediary layer prevents direct interception of verification codes by blocking the delivery path to compromised devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication challenges before delivering verification codes. By sending authentication requests to the original device first and requiring user confirmation, the system ensures that the user is still present and authorized before any verification codes are sent to the new SIM card, preventing fraudulent interception.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If risk-based authentication mechanisms are added to verify SIM swap legitimacy, then security against fraudulent requests is improved, but system complexity increases

Engineering Contradiction:
ImproveSIM swap authenticationVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct modules: risk score calculation module, authentication challenge module, verification code delivery module, and risk adjustment module. Each module handles a specific aspect of the authentication process independently, making the complex system more manageable and maintainable. The risk score calculation, for example, operates separately from the verification code delivery, allowing for independent optimization and failure isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service authentication where the mobile service provider automatically calculates risk scores and sends authentication challenges without requiring manual intervention. The process is automated and handles itself through programmed logic that evaluates risk factors and delivers appropriate authentication steps, reducing the need for complex manual procedures while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

4Stability of the object's composition

If the mobile service provider continues switching wireless service to the first UE during SIM swap, then service continuity is maintained, but the user may be exposed to fraudulent authentication attempts

Engineering Contradiction:
Improvewireless service continuityVSAvoidauthentication protection
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The system performs preliminary authentication challenges while maintaining service continuity. By sending authentication requests to the original device before the SIM swap is completed, the system ensures that the user is still present and authorized while the service switching process continues in the background. This allows both service continuity and authentication protection to coexist.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the authentication process based on real-time conditions. If the risk score indicates high probability of fraud, the system may pause or modify the service switching process to require additional authentication steps. This dynamic adjustment allows the system to maintain service continuity under normal conditions while providing enhanced protection when fraud is detected.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11985507B2Subscriber identification module (SIM) authentication protections
Publication Date: 2024.05.14 T MOBILE INNOVATIONS LLC
  • US11985507B2 patent drawing
  • US11985507B2 patent drawing
  • US11985507B2 patent drawing

AI summary

A method of computer authentication of a user request for a Subscriber Identity Module (SIM) card transfer by a biometric signature from a user equipment (UE) comprising assigning a risk score, by a mobile service provider, to a user account based on user activity in the user account, wherein the user activity includes a SIM card transfer authorization. The mobile service provider then sends a message requesting a biometric signature from an authentication application executing in memory on the UE. The authentication application on the UE then proceeds capturing a biometric signature, encrypting the biometric signature, and sending an encrypted biometric signature to the mobile service provider using a wireless communication protocol. The mobile service provider then compares the biometric signature to an authorized signature and modifies the risk score based on the comparison.