US 12,238,525 B2
SIM swap scam protection via passive monitoring
Christopher Daumer, Rennes (FR); and Christophe Gay, Rennes (FR)
Assigned to EXFO Solutions SAS, Saint-Jacques-de-la-Lande (FR)
Filed by EXFO Solutions SAS, Saint-Jacques-de-la-Lande (FR)
Filed on Oct. 26, 2021, as Appl. No. 17/510,460.
Claims priority of provisional application 63/107,592, filed on Oct. 30, 2020.
Prior Publication US 2022/0141669 A1, May 5, 2022
Int. Cl. H04W 12/72 (2021.01); H04W 4/14 (2009.01); H04W 12/121 (2021.01)
CPC H04W 12/72 (2021.01) [H04W 4/14 (2013.01); H04W 12/121 (2021.01)] 18 Claims
OG exemplary drawing
 
1. A method comprising steps of:
receiving wireless network data based on passive monitoring of a wireless network, wherein the passive monitoring includes capturing data packets from the wireless network at specific points;
identifying a subscriber identity module (SIM) card change in user equipment (UE) based on changes in identifiers in the captured data packets, wherein the SIM card change is identified based on i) international mobile subscriber identity (IMSI) or subscription permanent identifier (SUPI) and ii) Mobile Subscriber Integrated Services Digital Network (ISDN) Number (MSISDN) changes detected in the wireless network data, wherein the i) IMSI or SUPI and ii) in the MSISDN are stored as a pair in a database, and wherein the SIM card change is identified based on comparing extracted IMSI or SUPI and MSISDN contents to IMSI or SUPI and MSISDN pairs in the database;
identifying a commercial user communication with the UE after the SIM card change, wherein the commercial user communication is determined to be commercial based on any of i) a short message service, SMS, communication including any of a short code number and an alphanumeric sender identifier and ii) detection of an identifier of the commercial user in packet data to the UE, in the captured data packets, wherein the specific points are located separate from the UE and the commercial user such that the UE and the commercial user are unaware of the passive monitoring; and
detecting potentially fraudulent activity for the UE based on a combination of the SIM card change, the commercial user communication, and the length of a time period between the SIM card change and the commercial user communication.