Wireless Terminal Biometric Authentication for Fraudulent SIM-Swap Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security-critical applications rely on the assumption that the current operator of a mobile phone is identical to the pre-registered user, which can be compromised by fraudulent SIM swaps, allowing unauthorized individuals to access sensitive information.

Innovation Solution

Implement biometric authentication methods to verify the identity of the SIM operator by comparing entered biometric data with pre-stored data in a subscriber database, using fingerprints, retina features, or voice samples, and integrating this process into SIM authentication procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric authentication is implemented to verify SIM operator identity, then security against fraudulent SIM swaps is improved, but device complexity and authentication process time increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a biometric authentication intermediary layer between the SIM card and the terminal device. The biometric sensor captures physiological data (fingerprint, retina, voice), which is then processed by a comparison unit against stored biometric templates associated with the SIM's IMSI. This intermediary verification mechanism ensures that only the legitimate SIM owner can access the device, preventing fraudulent SIM swaps while maintaining a structured authentication flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary biometric verification during the SIM authentication process. Before the terminal device fully accesses network services or applications, the biometric data is captured and compared with the pre-stored biometric template in the subscriber database. This preliminary action ensures security is established upfront, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If biometric data is collected and stored in subscriber database, then authentication accuracy is improved, but privacy concerns and data security risks increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidprivacy risks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential biometric verification function from the terminal device and relocates it to the network side. The biometric template is stored in the subscriber database (HSS/UDM) rather than the terminal device, and the comparison operation is performed by the network node (MME/AMF). This extraction reduces the privacy risks associated with storing sensitive biometric data in mobile devices while maintaining high authentication accuracy through centralized secure storage and processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4140112B1Technique for authenticating operators of wireless terminal devices
Publication Date: 2025.10.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4140112B1 patent drawingFigure 1
  • EP4140112B1 patent drawingFigure 2
  • EP4140112B1 patent drawingFigure 3

AI summary

A technique of authenticating an operator of a wireless terminal device is presented, wherein the first terminal device comprises a subscriber identity module (SIM) and wherein a subscription identifier is stored in the SIM. A method aspect of this technique comprises receiving the subscription identifier or a temporary identifier associated with the subscription identifier. The method aspect also comprises receiving a first set of biometric data of the operator, wherein the first set of biometric data has been entered by the operator at the terminal device, and sending a database request towards a subscriber database in a core network domain of a wireless communication system, the database request including the subscription identifier or the temporary identifier. The method further comprises receiving, in response to the database request, a second set of biometric data associated in the subscriber database with the subscription identifier or the temporary identifier, and authenticating the first set of biometric data on the basis of the second set of biometric data so as to obtain a first authentication result.