UE Visual Authentication With Liveness Checks Against SIM Swap Fraud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SIM swap scams exploit weaknesses in two-factor authentication, particularly when the second factor is an SMS or call, by porting a phone number to a different device, compromising user accounts.
Innovation Solution
Implement a visual authentication method using a unique identifier, such as an international mobile subscriber identity (IMSI) or phone number, combined with facial recognition and liveness checks to verify the user's identity, ensuring the presented ID is live and matches stored records.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional two-factor authentication using SMS or call is used, then ease of operation is improved, but security is worsened due to SIM swap scam vulnerabilities
Solution Approach 1:
The patent replaces the traditional SMS-based mechanical authentication system with a biometric-based optical recognition system. The facial recognition technology captures and analyzes facial features to verify user identity, substituting the vulnerable SMS channel with a more secure biometric verification mechanism that is not susceptible to SIM swap attacks.
Solution Approach 2:
The patent introduces an intermediary liveness detection mechanism between the user and the authentication system. This intermediary layer analyzes facial characteristics to determine whether the presented face is from a live person or a static image/recording, adding an intermediate verification step that prevents automated attacks using stolen photos or videos.
2Ease of operation
If facial recognition without liveness check is used, then ease of operation is improved, but security is worsened due to susceptibility to photo or video attacks
Solution Approach 1:
The patent introduces an intermediary liveness detection mechanism between the user and the authentication system. This intermediary layer analyzes facial characteristics to determine whether the presented face is from a live person or a static image/recording, adding an intermediate verification step that prevents automated attacks using stolen photos or videos.
Solution Approach 2:
The patent implements feedback through active liveness detection challenges where the system requests specific user actions (such as blinking, turning head, or smiling) and verifies the responses. This feedback mechanism provides real-time verification that the subject is a live person capable of performing actions, rather than a static image or pre-recorded video.
3Reliability
If visual authentication with liveness check is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent leverages the existing camera and processor components of modern mobile devices, which already possess the necessary functionality for facial recognition. By utilizing these existing multi-functional components for authentication purposes, the system avoids adding dedicated hardware and keeps the implementation within the capabilities of standard smartphones.
Solution Approach 2:
The patent implements self-service authentication where the user's own facial features serve as the authentication credential. The system uses the user's face, which is always available and requires no additional physical tokens or external devices, enabling the authentication function to serve itself using the user's inherent biological characteristics.
Data Source
AI summary
The system receives an indication of a sensitive operation. The system obtains a unique ID of a user's UE. Based on the unique ID of the UE, the system retrieves a visual authentication method including a visual ID. The system records the visual ID, and retrieves a corresponding stored visual ID. The system performs a liveness check associated with the visual ID, to determine whether the visual ID is a recording or a live version of the visual ID. Upon determining that the visual ID is the recording, the system refuses to authenticate the user. Upon determining that the visual ID is the live version of the visual ID, the system compares the visual ID and the corresponding stored visual ID to determine whether the visual ID and the corresponding stored visual ID match. Upon determining that the visual ID and the corresponding stored visual ID match, the system authenticates the user.


