| Unprecedented
advances in the wireless industry have brought new subscribers to the customer
base, and with them, rising opportunities for cloners to eat away at company profits.
Cloners challenge the industry to develop sophisticated fraud containment methods
which will end fraud without putting an undue burden on the carrier's resources,
or inconveniencing the subscriber. Synacom, the industry leader in fraud
prevention technology, meets the challenge with the SAMS, a comprehensive
system that stops over-the-air fraud as well as security leaks at the system center.
With its unmatched fraud prevention technology, and robust, efficient service
activation features, SAMS strikes the perfect balance between high security,
low cost and network impact.
| Fraud
prevention system integration | As
the most crucial value in the authentication method, the A-Key must be guarded
against all security breaches as it is distributed throughout a wireless network.
This is where the SAMS excels, especially when used in concert with the
rest of Synacom's fraud prevention product line: The
CloneSafe Validator interfaces
between the SAMS and the mobile station, electronically programming A-Keys
and other service parameters into the mobile station's NAM. Validators can
be deployed at the point of manufacture, warehousing, or sale, or at fulfillment
or logistics centers. The CloneSafe
Secure Authentication Center (SAC) provides the ANSI-41 network authentication
function using only the Shared Secret Data (SSD) derived from the A-Key, rather
than the A-Key itself, to improve security. When
combined with Synacom's RoamFree®
Gateway interworking solution, cloning fraud is prevented even while roaming
from GSM to ANSI-41 networks. These products comprise the most advanced
and cost-effective cloning fraud prevention system available in the industry today
for ANSI-41 based networks, regardless of the network technology employed. All
CloneSafe products support AMPS, TDMA, and CDMA cellular and PCS networks
and operate without any subscriber interaction or inconvenience.
Figures below shows the interconnection of these products
as well as the various sources of bulk loaded A-Keys.
| | CloneSafe
product overview with Synacom's SAC |
| | CloneSafe
Product Overview with other vendors Authentication Center |
The versatile SAMS offers the
following features which allow easy integration into an existing system:
The AC can be either stand-alone or integrated
with a Home Location Register (HLR) or a switch.
A-Keys are generated and stored in the SAMS, or pre-programmed. A-Keys can
be obtained either using Electronic Data Interchange (EDI) transactions for carriers
with an installed base of authentication-capable mobile stations (in operation
or in inventory) or bulk loaded from distribution media. The
SAMS securely transfers A-Keys directly to the AC or through the carrier's
Provisioning System.
The Provisioning System can request
real-time delivery of an A-Key from the SAMS.
No matter how they are obtained, A-Keys are always stored
in encrypted form so that they are completely secure.
| Automatic
A-Key Programming |
Manually programming A-Keys into mobile stations can be time
consuming, subject to human error, and worse, the weak link
if the programming agent has access to the A-Key.
The SAMS automatic A-Key programming feature addresses
these concerns by using the Validator to deliver the
A-Key directly from the SAMS to the mobile station so
that no one has visual or electronic access to the A-Key and
no human error can cause a mismatch with the A-Key stored
in the SAMS.
| Other
service activation parameters |
The SAMS automatic programming
feature provisions other service activation parameters through
the Validator into the NAM, including the Home System
Identification (Home SID), other SIDs, and the Mobile Identification
Number (MIN). MINs are stored on the SAMS.
The Validator agent does not need to learn how to
program the various makes and models of mobile stations.
| CloneSafe
SAMS features |
The CloneSafe Secure A-Key
Management System (SAMS) is a toolbox providing a
variety of utilities for manipulating A-Keys. It is a versatile
and flexible system, designed to meet the differing business
needs and operating methods of individual carriers. SAMS
offers the following features and function:
Secure A-Key
generation, storage, and distribution A-Key loading
via Electronic Data Interchange (EDI) from mobile station manufacturer databases
Loading pre-programmed A-Keys from disk, diskette
and tape file Automatic aging of A-Keys
A-Key programming via CloneSafe
Validators
Service Activation parameter programming
via CloneSafe Validators
Support for GlobalStar networks using SMID-based
A-Keys SSD generation for the CloneSafe
Secure Authentication Center (SAC) Interface
to Provisioning Systems for A-Key and MIN distribution Graphical
user interface (GUI) Comprehensive activity logging
and reporting User access control, printer setup,
and software configuration Secure backup, restore,
and recovery Hardware and software fault management
High-availability configuration
Documentation
and training
| | CloneSafe
Product Overview with other vendors Authentication Center |
The CloneSafe SAMS hardware
uses the Sun Microsystems computer system, and the Cisco
Systems or 3Com modem bank for dial-up connections to the
CloneSafe Validators. The SAMS is based on a
Sun Ultra Enterprise computing platform running the
Sun Solaris UNIX Operating System and the Oracle®
Relational Database Management System.
The SAMS is available on the Ultra Enterprise 2 and
the Enterprise 3500 platform, which is optimal for running the larger SAMS applications.
Two SAMS configurations are available. The Standard Configuration provides one
computer system. The High Availability Configuration provides two, allowing immediate
cutover if one system should experience a failure. The High Availability Configuration
also provides additional storage capacity.
| CloneSafe
SAMS System Software |
The following third party software
supports the SAMS application.
Sun
Solaris UNIX Operating System Sun StorEdge
Volume Manager Oracle8 Enterprise Edition
Relational Database Management System Veritas
File System Qualix HA+ High Availability
software |