Split IO Authentication for SIM Swap Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rise in mobile device fraud, particularly illegitimate SIM swaps, poses a significant challenge for mobile network operators, leading to service disruptions and negative impacts on customer experience and network provider reliability.

Innovation Solution

A split input and output (IO) system is implemented, which includes a backend system that creates separate portions of inputs and outputs or communication channels for trusted and untrusted devices during SIM swap procedures, enabling out-of-band authentication to prevent fraud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SIM swap procedures are used, then the process is simple and quick, but the system is vulnerable to fraud and illegitimate swaps

Engineering Contradiction:
Improvefraud preventionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into two distinct communication channels: a first channel (e.g., cellular network) for delivering the authentication code to the user's mobile device, and a second channel (e.g., internet-based communication) for the computing device to submit the code to the backend system. This segmentation ensures that the same communication channel cannot be used for both delivering and verifying the code, preventing fraud while maintaining procedural simplicity.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If out-of-band authentication is implemented, then fraud resistance increases, but the authentication process becomes more complex

Engineering Contradiction:
Improvefraud resistanceVSAvoidauthentication process simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent introduces a backend system as an intermediary that coordinates the out-of-band authentication process. The backend system receives the SIM swap request, generates and sends the authentication code through the first communication channel, and then verifies the code when submitted through the second channel. This intermediary manages the complexity of the dual-channel process while keeping the user experience simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate communication channels are used for authentication, then security against SIM swap fraud improves, but the number of communication channels increases

Engineering Contradiction:
Improveauthentication securityVSAvoidnumber of communication channels
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent adds a dimensional aspect to authentication by using different types of communication channels rather than just multiple channels of the same type. The first channel uses cellular network communication (voice/SMS capabilities) while the second channel uses internet-based communication (data transmission). This dimensional differentiation provides security through diversity while managing complexity by leveraging existing infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12213211B2Split input and output (IO) for subscriber identity module (SIM) swaps
Publication Date: 2025.01.28 AT&T INTELLECTUAL PROPERTY I L P
  • US12213211B2 patent drawing
  • US12213211B2 patent drawing
  • US12213211B2 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, receiving, from a computing device, a user request to perform a subscriber identity module (SIM) swap for a subscriber, wherein the computing device and a user device are accessible to a user, based on the receiving the user request, generating a code for the SIM swap, resulting in a generated code, providing the generated code to the computing device for presentation, obtaining, from the user device, data associated with the user, the user device, or a combination thereof, facilitating user authentication responsive to the obtaining the data, detecting a transmission of a particular code from the user device, resulting in a detected code, and, based on the detecting the transmission and based on the facilitating the user authentication, performing an action relating to the SIM swap. Other embodiments are disclosed.