Telecommunication Network Verification for SIM Hijacking Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing two-factor authentication systems relying on mobile devices are vulnerable to hijacking by attackers who gain possession of the device or its subscriber identity module (SIM), compromising the security of online accounts with sensitive information.

Innovation Solution

A machine learning model within a telecommunication network generates an authenticity score based on network event data associated with a telephone number, using indicators such as identifier matching, anomalous behavior, device location, malware presence, and user-specified preferences to determine the legitimacy of the device possession.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication using mobile devices is implemented, then account security is improved, but the system becomes vulnerable to SIM hijacking and device compromise

Engineering Contradiction:
Improveaccount securityVSAvoidSIM hijacking vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a telecommunication network intermediary that sits between the authentication service and the mobile device. This intermediary monitors network events, analyzes device behavior patterns, and provides authenticity verification without requiring direct interaction with the user's mobile device, thereby adding a security layer that is independent of device possession

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops by monitoring network events related to the telephone number and device identifiers. The machine learning model processes this feedback data to dynamically assess authenticity scores, allowing the system to adapt to changing threat patterns and detect anomalies in real-time

Inventive Principle:
Principle #23Feedback

2Measurement precision

If machine learning analysis of network events is implemented, then detection accuracy of hijacked devices is improved, but system complexity increases

Engineering Contradiction:
Improvedevice authenticity detection accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The telecommunication network performs multiple functions simultaneously: it routes communications, monitors network events, collects data for analysis, and provides authenticity verification. By leveraging existing network infrastructure for these diverse purposes, the system avoids the need for separate dedicated systems for each function, thereby managing complexity while maintaining high detection accuracy

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If additional authentication verification layers are added, then security against unauthorized access is improved, but authentication process time increases

Engineering Contradiction:
Improveauthorization securityVSAvoidauthentication process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of network events and device behavior patterns continuously in the background before authentication is actually needed. The machine learning model pre-processes and stores authenticity indicators, so that when authentication is required, the verification can be completed rapidly by retrieving pre-analyzed data rather than conducting full analysis in real-time

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12425850B2Telecommuncation network verification for two-factor authentication
Publication Date: 2025.09.23 AT&T INTELLECTUAL PROPERTY I L P
  • US12425850B2 patent drawing
  • US12425850B2 patent drawing
  • US12425850B2 patent drawing

AI summary

A processing system may obtain a first network event data set associated with a telephone number, where the first network event data set includes identifier matching data associated with the telephone number. The processing system may next apply an input data set comprising at least the first network event data set to a machine learning model implemented by the processing system to obtain an authenticity score associated with the telephone number, where the machine learning model is configured to generate the authenticity score associated with the telephone number in accordance with the input data set. The processing system may next obtain a request from a first authentication service for the authenticity score associated with the telephone number and may transmit the authenticity score associated with the telephone number to the first authentication service in response to the request.