Securing SIM Toolkit-Based Mobile Money Applications Against SIM Swap Attacks Using User Location Data
Chepkwony Caldas Cheruyot, Robin Michel Kouame, Hiroyuki Inaba · 2024
The rise of mobile money services has been accompanied by increased Subscriber Identity Module (SIM) swapping attacks, which exploit weaknesses in identity verification processes. This study proposes a novel method to enhance mobile money application security by utilizing user location data for SIM swap request verification. Unlike traditional methods that rely solely on static personal identifiers, the proposed approach calculates the distance between the SIM swap request location and known transaction or connectivity locations using the haversine formula. The speed derived from this distance is then compared against a legal threshold to assess the validity of the request. This approach enhances security by minimizing the chance of unauthorized access through identity theft in situations where personally identifiable information (PII) is compromised. Experimental results demonstrate that the proposed method achieves an average processing time of 0.16 seconds per request, ensuring minimal computational impact while enhancing the security of users’ SIMs, financial assets, and personal data.