EP1209935A1

Fraud detection method for mobile telecommunication networks

Abstract

The present invention provides a fraud detection method for third generation mobile telecommunication systems using data related with unsuccessful authentication procedures, such us access type, authentication re-attempt and server address as secondary fraud indicators. Said data are included in predefined-type fields of the authentication failure report message sent from the Serving Environment back to the Home Environment in said authentication procedures, stored in the Home Location Register and forwarded to the Fraud Detection Systems for processing in conjunction with primary fraud indicators, for fraud detection purposes.

EP1209935A1, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Projected expiry passed 24 November 2020, 5.8 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

8 claims: 5 independent, 3 dependent

  1. 1
    A method for fraud detection in mobile telecommunications systems comprising the steps of:a) obtaining secondary fraud indicators from failures in user authentication procedures due to unsuccessful network authentications or unsuccessful user authentications;b) including said secondary fraud indicators in the authentication failure report message (MAP AFR_req) sent from the Serving Environment (3G MSC/VLR, 3G SGSN) back to the Home Environment (HE HLR) in said authentication procedures, as new parameters of specific types for each of said indicators;andc) storing said messages in the Home Location Register (HLR) for further processing.
  2. 4
    A method according to any of the preceding claims, characterized in that said secondary fraud indicators includes the access type of the communication in which the authentication procedure failed.
  3. 6
    A method according to any of the preceding claims, characterized in that said secondary fraud indicators includes a re-attempt indicator indicating whether the authentication failure was produced in a normal authentication attempt or in a authentication reattempt.
  4. 7
    A method according to any of the preceding claims characterized in that said secondary fraud indicators includes the Visitor Location Register (VLR) or the Serving GPRS Support Node (SGSN) address.
  5. 8
    A method according to any of the preceding claims characterized in that said secondary fraud indicators are included in extension container fields of said authentication failure report message (MAP AFR_req) instead of new parameters of specific types.