IP Library › Granted Patent US 12,598,470
Granted Patent B2
US 12,598,470 · App. 18/801,586 · Granted Apr 7, 2026

Using subscriber identity module (SIM) card as a security key for SIM swap fraud prevention

Inventors: Hugh Tyler Amick (Seattle, WA); Sean Patrick Hoelzle (Collegeville, PA); Deepak Jaiswal (Redmond, WA)
Assignee: T-Mobile Innovations LLC
H04W12/72H04W12/068H04W12/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,470
App. No.
18/801,586
Granted
Apr 7, 2026
Kind
B2
Abstract

A method of utilizing a SIM card as a security key for subscriber identity module (SIM) swap prevention is described. The method includes receiving, from a service provider, an initial one-time password (OTP) delivery request comprising an OTP message, a mobile station international subscriber directory number (MSISDN) destined to receive the OTP message, and a SIM indicator associated with the MSISDN; determining, based on the OTP delivery request, a current international mobile subscriber identity (IMSI) associated with the MSISDN; obtaining, from a datastore based on the SIM indicator associated with the MSISDN, an IMSI of record for the MSISDN; comparing the current IMSI associated with the MSISDN and the IMSI of record for the MSISDN; and determining, based on the comparing, whether to deliver the OTP message to the MSISDN or block delivery of the OTP message to the MSISDN.

Claims (80)

1 . A communications system to provide datastore management for SIM swap fraud prevention that utilizes a subscriber identity module (SIM) card at a user device as a security key, the system comprising:

a datastore to store a SIM indicator in association with a first international mobile subscriber identity (IMSI) recorded for a mobile station international subscriber directory number (MSISDN) registered for 2FA with a service provider, wherein the first IMSI is associated with a first SIM card; and

a first network node comprising:

at least one processor;

at least one non-transitory memory; and

a SIM management application comprising instructions stored at the at least one non-transitory memory, which when executed by the at least one processor, causes the SIM management application to:

receive, from a second network node, a first risk score for a first SIM change associated with the MSISDN, wherein the first SIM change is associated with a second IMSI of a second SIM card different than the first SIM card;

update, based on the first risk score associated with the first SIM change satisfying a first criterion, the datastore to associate the SIM indicator with the second IMSI after an expiry of a first predetermined amount of time;

receive, from the second network node, a second risk score for a second SIM change associated with the MSISDN, wherein the second SIM change is associated with a third IMSI of a third SIM card different than the first SIM card; and

update, based on the second risk score associated with the second SIM change satisfying a second criterion but failing to satisfy the first criterion, the datastore to associate the SIM indicator with the third IMSI after an expiry of a second predetermined amount of time greater than the first predetermined amount of time.

2 . The system of claim 1 , wherein the first criterion comprises a first threshold, and wherein the second criterion comprises a second threshold lower than the first threshold.

3 . The system of claim 1 , wherein the SIM management application is further caused to:

receive, from the second network node, a third risk score for a third SIM change associated with the MSISDN, wherein the third SIM change is associated with a fourth IMSI of a fourth SIM card different than the first SIM card; and

block, based on the third risk score associated with the third SIM change failing to satisfy the first criterion and the second criterion, updating the association between the SIM indicator and the first IMSI in the datastore.

4 . The system of claim 1 , wherein the SIM management application is further caused to:

receive, from a third network node, an indication of the first SIM change associated with the MSISDN;

transmit, to a fourth network node, an analysis request for the first SIM change associated with the MSISDN; and

receive, from the fourth network node, the first risk score.

5 . The system of claim 1 , further comprising:

a second datastore to store the MSISDN in association with the first IMSI of the first SIM card,

wherein the SIM management application is further caused to:

update, based on the first risk score associated with the first SIM change satisfying the first criterion, the second datastore to associate the MSISDN with the second IMSI; and

update, based on the second risk score associated with the second SIM change satisfying the second criterion, the second datastore to associate the MSISDN with the third IMSI.

6 . A communications system to provide subscriber identity module (SIM) swap fraud prevention without a two-factor authentication (2FA) re-registration upon a legitimate SIM change, the system comprising:

a datastore to store a SIM indicator in association with a first international mobile subscriber identity (IMSI) recorded for a mobile station international subscriber directory number (MSISDN), wherein the first IMSI is associated with a first SIM card, wherein the SIM indicator and the MSISDN are associated with a 2FA registration with a service provider;

a first network node comprising:

at least one first processor;

at least one first non-transitory memory; and

a SIM management application comprising instructions stored at the at least one first non-transitory memory, which when executed by the at least one first processor, causes the SIM management application to:

determine that a level of risk for a SIM change associated with the MSISDN satisfies a threshold, wherein the SIM change is further associated with a second IMSI of a second SIM card different than the first SIM card; and

update, based on the determining, the datastore to associate the SIM indicator with the second IMSI,

a second network node comprising:

at least one second processor;

at least one second non-transitory memory; and

a SIM secure application comprising instructions stored at the at least one second non-transitory memory, which when executed by the at least one second processor, causes the SIM secure application to:

receive, from the service provider after the datastore is updated, an OTP delivery request comprising an OTP message, the MSISDN destined to receive the OTP message, and the SIM indicator associated with the MSISDN, wherein the OTP delivery request is associated with the same 2FA registration with the service provider;

determine, based on the OTP delivery request, a current IMSI associated with the MSISDN destined to receive the OTP message;

obtain, from the updated datastore, based on the SIM indicator in the OTP delivery request, the second IMSI; and

deliver, based on a match between the current IMSI associated with the MSISDN destined to receive the OTP message and the second IMSI obtained from the updated datastore, the OTP message to a user device associated with the MSISDN.

7 . The system of claim 6 , wherein the SIM management application is further caused to:

transmit, to a third network node, an analysis request for the SIM change associated with the MSISDN; and

receive, from the third network node in response to the analysis request, an indication of the level of risk for the SIM change associated with the MSISDN.

8 . The system of claim 6 , wherein the delivering the OTP message to the user device associated with the MSISDN comprises:

transmitting, to a third network node, a request to deliver the OTP message to the MSISDN.

9 . The system of claim 6 , further comprising

a second datastore to store the MSISDN in association with the first IMSI of the first SIM card,

wherein the SIM management application is further caused to update, based on the level of risk for the SIM change associated with the MSISDN satisfying the threshold, the second datastore to associate the MSISDN with the second IMSIS of the second SIM card, and

wherein the determining the IMSI associated with the MSISDN destined to receive the OTP message is based on the updated second datastore that associates the MSISDN with the second IMSI of the second SIM card.

10 . The system of claim 6 , wherein the SIM management application is further caused to:

generate the SIM indicator based on an absence of a SIM indicator associated with the first IMSI at the datastore; and

store, at the datastore, the SIM indicator in association with the first IMSI.

11 . The system of claim 6 , wherein the first network node comprises a service delivery gateway (SDG).

12 . A method implemented in a communications system to utilize a subscriber identity module (SIM) card at a user device as a security key for SIM swap fraud prevention, the method comprising:

receiving, by a SIM secure application at a computing system comprising a service delivery gateway (SDG) of the communications system, from a service provider, an initial one-time password (OTP) delivery request comprising an initial OTP message, a mobile station international subscriber directory number (MSISDN) destined to receive the initial OTP message, and a request for a SIM indicator associated with the MSISDN, wherein the initial OTP delivery request is based on a registration of the MSISDN for second factor authentication (2FA) with the service provider;

delivering, by the SIM secure application, the initial OTP message to a user device associated with the MSISDN;

determining, by the SIM secure application based on the delivering, an international mobile subscriber identity (IMSI) of a SIM card in the user device associated with the MSISDN;

obtaining, by the SIM secure application, based on the determined IMSI, from a datastore comprising a plurality of SIM indicators, each in association with an IMSI of record for a respective MSISDN, a first SIM indicator of the plurality of SIM indicators;

transmitting, by the SIM secure application to the service provider, a delivery report including the first SIM indicator and an indication of a successful delivery of the initial OTP message;

receiving, by the SIM secure application from the service provider, a subsequent OTP delivery request comprising a subsequent OTP message, the MSISDN destined to receive the subsequent OTP message, and the first SIM indicator;

determining, by the SIM secure application based on the subsequent OTP delivery request, a current IMSI associated with the MSISDN destined to receive the subsequent OTP message;

obtaining, by the SIM secure application, from the datastore based on the first SIM indicator in the subsequent OTP delivery request, an IMSI of record for the MSISDN destined to receive the subsequent OTP message;

comparing, by the SIM secure application, the current IMSI associated with the MSISDN destined to receive the subsequent OTP message and the IMSI of record for the MSISDN destined to receive the subsequent OTP message; and

determining, by the SIM secure application, based on the comparing, whether to deliver the subsequent OTP message to the MSISDN or block delivery of the subsequent OTP message to the MSISDN.

13 . The method of claim 12 , further comprising:

delivering, by the SIM secure application, based on a match between the current IMSI associated with the MSISDN and the IMSI of record for the MSISDN, the subsequent OTP message to the user device associated with the MSISDN.

14 . The method of claim 13 , wherein the delivering the subsequent OTP message to the user device associated with the MSISDN comprises:

transmitting, by the SIM secure application to a short message service center (SMSC) of the communications system, a request to deliver the initial OTP message to the MSISDN.

15 . The method of claim 14 , further comprising:

receiving, by the SIM secure application from the SMSC, based on the request to deliver the subsequent OTP message to the MSISDN, an indication of a successful delivery of the subsequent OTP message; and

transmitting, by the SIM secure application to the service provider, a second delivery report including the indication of the successful delivery of the subsequent OTP message.

16 . The method of claim 12 , further comprising:

blocking, by the SIM secure application, based on a mismatch between the current IMSI associated with the MSISDN and IMSI of record for the MSISDN, delivery of the subsequent OTP message to the MSISDN.

17 . The method of claim 16 , further comprising:

transmitting, by the SIM secure application to the service provider based on the blocking, a second delivery report including an indication of a failure to deliver the subsequent OTP message to the MSISDN.

18 . The method of claim 17 , wherein the second delivery report further comprises an indication that the failure to deliver the subsequent OTP message is due to a SIM change associated with the MSISDN.

19 . The method of claim 12 , wherein the obtaining the IMSI of record for the MSISDN destined to receive the subsequent OTP message comprises:

indexing into the datastore using the first SIM indicator.

20 . The method of claim 12 , wherein the obtaining the IMSI of record for the MSISDN destined to receive the subsequent OTP message comprises:

querying, by the SIM secure application, the datastore for an IMSI of record associated with the first SIM indicator in the subsequent OTP delivery request; and

receiving, by the SIM secure application, from the datastore, the IMSI of record associated with the first SIM indicator.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2024
From: AMICK, HUGH TYLER; HOELZLE, SEAN PATRICK; JAISWAL, DEEPAK
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 068270/0207 →
Continuity (1)
Related Publication 20260046628A1 · Feb 12, 2026
References Cited (82)
US 8175589B2 · Montaner Gutierrez · 2012 [cited by examiner]
US 8306571B2 · Larsson · 2012 [cited by examiner]
US 8463239B1 · Koller et al. · 2013 [cited by applicant]
US 8467770B1 · Ben Ayed · 2013 [cited by applicant]
US 8954113B2 · Hauck · 2015 [cited by examiner]
US 9369938B2 · Biggs · 2016 [cited by examiner]
US 9532208B2 · Camilleri · 2016 [cited by examiner]
US 9699660B1 · Blatt · 2017 [cited by examiner]
US 9749862B1 · Selvaraj · 2017 [cited by examiner]
US 10075848B2 · Velusamy · 2018 [cited by examiner]
US 10178223B1 · Marimuthu · 2019 [cited by examiner]
US 10277586B1 · Yau · 2019 [cited by examiner]
US 10349267B1 · Chen · 2019 [cited by examiner]
US 10433156B1 · Long · 2019 [cited by examiner]
US 10530756B1 · Youngs et al. · 2020 [cited by applicant]
US 10623961B1 · Manepalli · 2020 [cited by examiner]
US 10715996B1 · Singh · 2020 [cited by examiner]
US 10743181B1 · Selvaraj · 2020 [cited by examiner]
US 10904741B2 · Chen · 2021 [cited by examiner]
US 11076296B1 · Kant · 2021 [cited by examiner]
US 11368849B1 · Reeves · 2022 [cited by examiner]
US 11706629B2 · Reeves · 2023 [cited by examiner]
US 11902786B1 · Sharma · 2024 [cited by examiner]
US 11985507B2 · Reeves et al. · 2024 [cited by applicant]
US 12028933B1 · An · 2024 [cited by examiner]
US 12177751B1 · Hadadi · 2024 [cited by examiner]
US 12238525B2 · Daumer · 2025 [cited by examiner]
US 20030196106A1 · Erfani · 2003 [cited by examiner]
US 20040229601A1 · Zabawskyj · 2004 [cited by examiner]
US 20050063570A1 · Kim · 2005 [cited by applicant]
US 20080312968A1 · Hannon et al. · 2008 [cited by applicant]
US 20090006230A1 · Lyda · 2009 [cited by examiner]
US 20090007275A1 · Gehrmann · 2009 [cited by applicant]
US 20090327398A1 · Campbell · 2009 [cited by examiner]
US 20100210305A1 · Larsson · 2010 [cited by examiner]
US 20110078773A1 · Bhasin · 2011 [cited by examiner]
US 20130288749A1 · Torres · 2013 [cited by examiner]
US 20150038120A1 · Larkin · 2015 [cited by examiner]
US 20160007190A1 · Wane · 2016 [cited by examiner]
US 20160021532A1 · Schenk et al. · 2016 [cited by applicant]
US 20160050554A1 · Ben Shlush · 2016 [cited by examiner]
US 20160307199A1 · Patel et al. · 2016 [cited by applicant]
US 20170094500A1 · Zhong · 2017 [cited by examiner]
US 20170208540A1 · Egner et al. · 2017 [cited by applicant]
US 20170272972A1 · Egner et al. · 2017 [cited by applicant]
US 20180063708A1 · Shi · 2018 [cited by examiner]
US 20180176767A1 · Hjelt · 2018 [cited by examiner]
US 20180302227A1 · Seegebarth · 2018 [cited by applicant]
US 20200236595A1 · Cuevas Ramirez · 2020 [cited by examiner]
US 20200236603A1 · Cuevas Ramirez · 2020 [cited by examiner]
US 20200245142A1 · Manepalli · 2020 [cited by examiner]
US 20210076204A1 · Goyal · 2021 [cited by examiner]
US 20210165426A1 · White · 2021 [cited by applicant]
US 20210195411A1 · Ratnakaram · 2021 [cited by examiner]
US 20220012743A1 · Snell et al. · 2022 [cited by applicant]
US 20220129900A1 · Naujok · 2022 [cited by examiner]
US 20220141669A1 · Daumer · 2022 [cited by examiner]
US 20220167152A1 · Uy · 2022 [cited by examiner]
US 20220248233A1 · Reeves et al. · 2022 [cited by applicant]
US 20220400384A1 · Byrne · 2022 [cited by examiner]
US 20230054006A1 · Naujok · 2023 [cited by examiner]
US 20230284012A1 · Voruganti · 2023 [cited by examiner]
US 20230396980A1 · Kanchiraju · 2023 [cited by examiner]
US 20240015515A1 · Jaiswal · 2024 [cited by examiner]
US 20240040495A1 · Pratt · 2024 [cited by examiner]
US 20240171558A1 · Diffloth · 2024 [cited by examiner]
US 20240323681A1 · Sikes · 2024 [cited by examiner]
US 20240365126A1 · Dunn · 2024 [cited by examiner]
US 20240381093A1 · Murakami · 2024 [cited by examiner]
US 20250024264A1 · Opedal · 2025 [cited by examiner]
US 20250056201A1 · Liang · 2025 [cited by examiner]
US 20250139209A1 · Hassan · 2025 [cited by examiner]
US 20250220567A1 · Pratt · 2025 [cited by examiner]
US 20250247704A1 · Shah · 2025 [cited by examiner]
WO 2016050990A1 · 2016 [cited by applicant]
Ekeh et al., Awareness of BVN, SIM Swap and Clone Frauds: Methods and Controls, Science World Journal, 2022. [cited by examiner]
Restriction Requirement dated Dec. 9, 2021 U.S. Appl. No. 17/081,813, filed Oct. 27, 2020. [cited by applicant]
Notice of Allowance dated Feb. 24, 2022, U.S. Appl. No. 17/081,813, filed Oct. 27, 2020. [cited by applicant]
Restriction Requirement dated Oct. 11, 2022 U.S. Appl. No. 17/725,487, filed Apr. 20, 2022. [cited by applicant]
Office Action dated Dec. 16, 2022 U.S. Appl. No. 17/725,487, filed Apr. 20, 2022. [cited by applicant]
Notice of Allowance dated Mar. 2, 2023 U.S. Appl. No. 17/725,487, filed Apr. 20, 2022. [cited by applicant]
Notice of Allowance dated Jan. 23, 2024 U.S. Appl. No. 18/324,837, filed May 26, 2023. [cited by applicant]