Subscriber Information Verification via SS7 Hardware ID Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online security systems are vulnerable to 'man-in-the-middle' attacks due to spoofing of subscriber identifiers, which undermines additional layers of verification device-based security.
Innovation Solution
A system and method that authenticates a verification device by using subscriber information provided by a user and comparing it with hardware identifiers obtained from a communication network, ensuring that the device used is a trusted verification device associated with the user account, thereby enhancing security without requiring further user interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional username and password checks are used, then ease of operation is maintained, but security reliability is insufficient
Solution Approach 1:
The authentication process is segmented into multiple independent verification stages: initial username/password authentication, followed by device-based verification using hardware identifiers, and optionally biometric verification. Each segment provides a layer of security without requiring the user to manually participate in all stages, thus maintaining ease of operation while significantly improving security reliability.
Solution Approach 2:
The system performs preliminary device verification by obtaining and storing hardware identifiers (such as device IDs, IMEI, or MAC addresses) before actual account access is attempted. This preliminary action establishes a trusted device profile that enables automatic verification during subsequent login attempts, enhancing security without adding operational burden during the actual authentication moment.
2Reliability
If verification device-based security is implemented, then security reliability is improved, but vulnerability to spoofing attacks increases
Solution Approach 1:
The system implements feedback mechanisms by continuously monitoring and comparing device hardware identifiers against stored profiles. During each authentication attempt, the system verifies that the presenting device's hardware ID matches the previously registered identifier for that user account. This feedback loop detects spoofing attempts by identifying mismatches between claimed and actual device identities, thereby neutralizing the harmful effect of spoofing attacks.
Solution Approach 2:
The patent introduces hardware identifiers as an intermediary verification element between the user and the online service. Instead of directly trusting user-provided verification device information, the system uses immutable hardware identifiers (device ID, IMEI, MAC address) as a mediator to prove device authenticity. This intermediary layer prevents spoofing because hardware identifiers are difficult to replicate or forge, adding a trusted verification step that blocks spoofing attacks.
3Reliability
If hardware identifier verification is performed, then reliability against spoofing is improved, but device complexity increases
Solution Approach 1:
The verification system leverages self-service capabilities by automatically collecting hardware identifiers from the user's device without requiring manual input or configuration. The system autonomously retrieves device IDs, IMEI numbers, or MAC addresses through standard device APIs and performs verification comparisons automatically. This self-service approach maintains high reliability against spoofing while minimizing the perceived complexity for users, as the entire process occurs transparently in the background.
Data Source
AI summary
A subscriber information authentication system that compares network-obtained and device-obtained information to verify that a device being used in connection with a user account is authenticated for that account. Certain subscriber information may be associated with the account during a registration process. In subsequent attempts to access the account, the registered subscriber information may be used in conjunction with information obtained from a telecommunication network and from a device to verify that the device is authorized. The information from the telecommunication network may be queried using Signaling System No. 7 (“SS7”) protocols. The device authorization may be performed, for example, to ensure that a device being used for device-based verification is the device a user purports it to be.


