Communication network with data channel
By designing a multi-interface authentication network in the communication network, requiring only the caller ID and phone number to be entered, and combining encryption and redundant storage, the problems of misuse and insufficient security in ISDN networks are solved, achieving efficient and secure communication authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- OCULUS LLC
- Filing Date
- 2023-11-09
- Publication Date
- 2026-05-29
AI Technical Summary
While existing communication networks offer broad compatibility and fast interfaces, they struggle to effectively prevent misuse, especially in the D channel of ISDN networks. This results in excessive data volume and increased costs, as well as insufficient security and fault tolerance.
Design a data channel that uses an authentication network consisting of multiple interfaces to perform strict security queries on data packets containing only the caller ID and phone number, ensuring minimal data volume. Enhance security and fault tolerance through measures such as encryption, redundant storage, and timestamps.
It achieves efficient prevention of misuse with minimal data volume, improves the security and fault tolerance of communication networks, reduces data load, and enhances system fault safety and communication reliability.
Abstract
Description
Technical Field
[0001] This invention belongs to the field of computer-implemented inventions. Simple methods or algorithms have long been used as both hardware and software implementations, as well as hybrid combinations. For example, JP 06201782A, published in 1994, discloses a chipset that includes a shift register with linear feedback as part of a test circuit; further information on this can be found in JP10207695 A and JP 10301492 A from the 1990s. US 6,091,821 A discloses how hash algorithms can be implemented at the hardware level; US 6,289,023 B discloses a more efficient checksum generator; and US 6,348,881 B1 discloses a hardware-implemented compression algorithm. KR 10 2003 005 111 1A discloses a hardware-implemented AES encryption; KR 10 2005 0005 054 A discloses a hardware white noise generator. Therefore, methods and products for implementing established, simple programs for data processing via hardware modules are considered known. Measures such as AND operations, XOR operations, encryption, compression, signatures, checksum verification, cross-correlation, and the creation of internal correlation identifiers are considered to be established in both software and hardware and can be implemented in both. For particularly fast and efficient hardware, block-based parallel processing is used, as described, for example, in DE 10 2005 018 248 B4. In this context, the subject matter defined in this invention describes both hardware and software that can be configured in the same manner, as well as hybrid models in which the functions of the invention can be partially implemented and combined to provide the claimed subject matter. Background Technology
[0002] This invention relates to communication networks according to the preamble of the independent claims. A fundamental problem with communication networks operating using multiple data layers and parallel data channels is, on the one hand, providing the most widely compatible and adaptable interface possible, and on the other hand, preventing misuse. US 4,031,512 A, published in 1977, describes how a communication network (albeit a single-line structure) can be meaningfully divided and operated as multiple data layers or data channels; in this context, the terms "data layer" and "data channel" can describe both or a combination of assigned lines and assigned data identifiers. US 5,335,227 A describes a communication network capable of progressive reconfiguration, which can be reconstructed as needed while user equipment is still identified and assigned to the user via identifiers. Furthermore, WO 1995024791 A discloses how radio and fixed networks can be better combined and coordinated via parallel control channels, and how the radio and fixed networks can be better operated together by collecting operational data. To enable such and similar communication networks to cooperate, numerous intermediary ports are provided in the switching modules at the software and / or hardware levels; however, this has the disadvantage that data may be manipulated during transmission.
[0003] Specifically, concealing and anonymizing a caller’s identity (hereinafter referred to as caller ID) without permission is a common problem that arises, for example, in identification and billing fraud.
[0004] For example, possible countermeasures for the telecommunications sector are described in the following documents: US 5,495,521 A; US 5,907,602A; US 6,058,301 A; EP 1 076 951 B; KR 10 2001 004 3378 A; US 6,675 153 B1; and US 7,496,345 B1. However, none of the established equipment and measures can achieve widespread global implementation. Maintaining rapid compatibility across a large number of networks when using conventional methods within complex and interconnected data layers leads to excessively high and costly data loads.
[0005] Description of existing technology ISDN Telephone: This invention is based on concepts known from ISDN telephones. ISDN devices rely on the aforementioned principles of US 4,031,512 A and initially provide two types of data channels: multiple B channels through which user data can be exchanged; and parallel D channels designed to coordinate device and network functions with each other. JP 620 38052 A proposes monitoring ISDN networks via D channels. The suggestion to use D channels for parallel data transmission is derived from JP02246652 A; JP 06188936 A additionally describes parallel data transmission via multiple B channels. JP04220857 A proposes restricting available services on an ISDN system via access data or passwords. JP 03254261 A proposes subjecting device identifiers to pre-registration checks to accelerate lookup and activation. JP 03270543 A describes a test procedure in which the output startup communication of an ISDN device is read, modified, and forwarded for verification; if the modified startup communication matches the target value, the line and device are evaluated as suitable and approved / activated.
[0006] US 5,218,680 A discloses a chip-integrated combination of ISDN functionality and extended CPU functionality; similarly, EP 0833 529 A2 proposes the operation of extending ISDN systems together with radio networks. Finally, as known from US 5,805,570 A in 1998, software can emulate ISDN communication nodes on a PC. In this context, the functionality in the "ISDN" domain, which was primarily provided via hardware in the 1980s and 1990s, can now be provided via modern PCs either in software, hardware, or in a suitable combination of components.
[0007] The suggestion to use the D channel to prevent misuse (e.g., via password authentication) is known from JP 0 205 464 5 A.
[0008] EP 0 817 484 A2 proposes connecting communication networks, including multimedia data streams, via the ISDN system.
[0009] Therefore, communication networks are known from the prior art, in which, in addition to multiple channels for user communication data, parallel D channels can be used to prevent misuse.
[0010] The drawback of this concept is that the D-channel of ISDN networks also provides a large amount of data for parallel communication. Therefore, DE 19937 098 A1 proposes that all preparatory communication should be free before a paid connection is established. This often leads to abuse and cost-avoidance communication directly via the D-channel in the market, which corresponds to the shared use as a communication data channel proposed in the Japanese application. In this context, network operators periodically shut down the D-channel, and there has been no meaningful further development of efficient parallel channels for verifying call data and preventing abuse.
[0011] Therefore, the object of the present invention is to overcome the shortcomings of the prior art and to design a data channel that can provide network operators with efficient and attractive protection against misuse despite the possibility of parallel communication.
[0012] This problem is addressed by the features of the independent claims. Advantageous embodiments arise from the dependent claims and the following description.
[0013] Another issue is the fact that communication security is a core aspect of modern society; therefore, systems that contribute to this should require as little computing power or data as possible so as not to slow down communication.
[0014] Another issue is the fact that safety-related systems should have a high degree of fault tolerance; this should be able to compensate for some failures.
[0015] Furthermore, communication via parallel data channels presents a problem due to the fact that it may be possible for third parties in principle; access to these functions should be subject to time and / or user restrictions.
[0016] Another issue is the fact that call data allows for inferences about the communicator's private data and characteristics; data security should be considered.
[0017] Another issue is the fact that system-related functions should be continuously monitored; critical systems should be able to detect and compensate for overload or increased demand. Summary of the Invention
[0018] According to the present invention, the claimed communication network has a data channel. Furthermore, multiple channels exist for user data and user communication. The parallel data channel consists of an authentication network comprising multiple interfaces. It is crucial that the data channel is strictly assigned to a secure query function and that no data volume is provided as available bandwidth. Therefore, only data packets containing the caller ID and telephone number can be input into the interface; the data packets can be input as requests or queries.
[0019] Description and Advantages of the Invention According to the present invention, the claimed communication network has a data channel similar to the D channel in ISDN technology.
[0020] Similar to the B channel of ISDN technology or the data layer of established mobile networks, multiple channels can be used for user data and user communication.
[0021] The parallel data channel consists of an authentication network with multiple interfaces. It is crucial that the data channel is strictly assigned to the secure query function and does not provide any data volume as available bandwidth.
[0022] Therefore, you can simply input a data packet containing the caller ID and phone number into the interface.
[0023] The caller ID and phone number are multiple pieces of information that are checked within the established radio network before a connection is established to ensure payment for the call. In this context, the caller ID includes at least a uniquely identifiable contractual partner with their own phone number and / or corresponding credit account, through which the call is pre-authorized. Therefore, the caller ID and phone number form a small data packet of only a few bytes. This data packet can be entered as a request or a query. Requests are received and stored in the data channel for rapid verification, and a receipt confirmation is transmitted.
[0024] When a query is performed, the query packet is compared with an existing request packet, and if a match is found, it is confirmed; otherwise, it is rejected.
[0025] From the caller's network operator's perspective, the concept described above only requires forwarding the caller ID and phone number to the appropriate operator for the phone number connection; due to the parallel data channel strictly focused on its purpose, the operator of the phone number connection can request the data packets as described above with minimal effort: the received data only needs to be marked as a query and fed into the data channel. If confirmed, the call can be established; if rejected, the connection is denied.
[0026] Preferably, a short response of only a few bits can be output via the interface. If the possible response size is significantly smaller than the data packet, misusing the data channel as a communication channel becomes very unattractive. A few bits are sufficient to classify successful transmission, checksum, or similar information. The response includes only two bits for claiming call-related information, consisting of a set of claims: “Valid,” “Invalid ID,” “Invalid Phone Number,” and “Invalid.” This is sufficient to allow phone number operators to form groups based on caller ID and claims, which can provide information about the quality of the communication channel and / or the credibility of the caller ID, and can be incorporated into established further measures.
[0027] Preferably, the interface is designed to allow only encrypted and / or secure communication. Encrypted communication may employ end-to-end encryption to prevent third-party access to sent data packets; additionally, supplementary cryptographic tools may assign a personal code to each user to identify unauthorized or forged entries; additional security measures may include recording the sender's ID and continuously increasing the minimum wait time for invalid entries to prevent DDoS attacks; furthermore, standard and feasible simple functions (such as those known in the art) may be implemented on both the hardware and software sides.
[0028] Preferably, the interface is configured as a peer-to-peer network with redundant multiple storage for incoming data. High fault tolerance is achieved by distributing data packets across multiple interfaces (preferably those that are physically separate); preferably, the redundancy level can be controlled for hazardous situations and / or specific user groups to adapt the system to fault tolerance in the event of changing circumstances and / or increased system dependence of user groups.
[0029] Preferably, the interface is synchronized via at least one clock. This allows for the assignment of passwords or access data using time-related components and / or validity; particularly in cases where compromised access data is suspected, the time-related rapid modulation of the access data and its transmission via different data channels can help identify and disable compromised data channels.
[0030] Preferably, data packets in the authentication network are timestamped upon receipt. When a request is made, the timestamp is used to supplement the data packet; comparing the input time with the query or response time allows for an estimate of the current utilization of the data channel. This estimate can be used to increase the number of available interfaces during load changes by creating and / or activating additional interfaces, or to reduce the number of available interfaces by deleting and / or deactivating interfaces, in order to ensure a sustained minimum performance of the data channel in terms of optimizing efficiency and environmental impact.
[0031] Preferably, the authentication network is designed to be forgetful, in which at least received data packets cannot be permanently stored; additionally, misuse / corruption of data packets is prevented by periodically deleting data packets.
[0032] Preferably, the data packet has a maximum storage time of 300 seconds; in actual testing, a maximum storage time of 5 minutes is sufficient to establish a connection, even for extremely unstable line segments with multiple requests and rerouting; preferably, the data packet is deleted after 50 to 150 seconds, which is always long enough for a normal connection; preferably, the data packet is deleted after 70 to 120 seconds, which is sufficient even for domestic calls in areas with average, consistent network coverage. Generally, a shorter minimum storage time correspondingly reduces the load on the data channel. In this context, user-related and situation-related adjustments to the minimum storage time are particularly attractive in order to achieve an optimal balance between customer satisfaction and energy consumption.
[0033] Preferably, call-related information can be stored by the network operator at the user data tier for further analysis based on known equipment and measures to prevent misuse. As explained at the outset, various methods and concepts are known that can be used to initiate additional steps and preventative measures in the communication network upon detection of forgery or fraudulent attempts.
[0034] Other advantages arise from the implementation scheme. Unless explicitly described as such, the features and advantages described above, as well as the exemplary implementation schemes below, should not be considered an exhaustive combination of the features. Additional advantageous features and combinations thereof, as explained in the specification and according to the listed documents and references cited therein, may be realized individually and in different combinations within the scope of the independent claims in the claimed subject matter, without departing from the scope of the invention. Detailed Implementation
[0035] In an advantageous embodiment of the invention, the communication network with data channels has multiple channels for user data and user communication. The parallel data channels consist of an authentication network comprising multiple interfaces. Only data packets containing the caller ID and telephone number can be input into the interfaces as requests or queries. A short response of only a few bits can be output via the interfaces, wherein the response, as call-related information, includes only two bits for a declaration. The declaration can be freely selected from a set of declarations consisting of "valid," "invalid ID," "invalid telephone number," and "invalid." The interfaces are designed to allow only encrypted and / or secure communication. Furthermore, the interfaces are configured as a peer-to-peer network with redundant multiple storage of input data and are synchronized via at least one clock. Data packets can be timestamped upon arrival at the authentication network. The authentication network is designed to be forgetful, wherein at least received data packets cannot be permanently stored but have a maximum storage time of 300 seconds, preferably 50 to 150 seconds, and more preferably 70 to 120 seconds.
[0036] When a call is initiated, the caller's network operator performs initial verification of the caller's identity by checking the caller's caller ID and reputation. A data packet, created by the caller's network operator, is tagged as a request, encrypted, and sent as a request after a secure and valid connection to the data channel has been established. This request is timestamped, and its complete receipt is acknowledged. The network operator of the phone number is contacted, and the caller ID and phone number are sent. As described above, after the connection is established, the phone number's network operator generates a data packet and transmits it as a request to the data channel. Receipt of a complete and valid request is acknowledged. In the authentication network, the request is compared with existing requirements. A corresponding response is generated and sent back to the phone number's network operator. The call is only established if the response is "valid." For all other responses, call establishment is aborted.
[0037] Industrial applicability Despite promising approaches within ISDN technology, a sensible method for authenticating caller IDs and dialed phone numbers has yet to be established. The increased use of digital communications via data networks has, in fact, led to a rise in compromised interfaces and manipulated data.
[0038] The task is to meet the long-term requirement for a fail-safe system that consumes as little data as possible while effectively authenticating the caller ID and associated phone number on the receiver side.
[0039] Based on sound methods in the ISDN technology field, the solution is implemented through a data channel designed as a strictly assigned parallel authentication network consisting of multiple interfaces. This data channel provides no additional data payload beyond authentication purposes. High redundancy is possible and allowed as a system-dependent security component by consistently limiting the received data packets to a few bytes and the emitted responses to a few bits. Therefore, highly efficient authentication of caller IDs and phone numbers using the simplest equipment is achieved for the first time in a highly reliable, secure, encrypted, fast, adaptable, and forgetful authentication network, before network operators must actively activate channels for user data or communication. The necessary data capacity is minimal, and common fraud strategies are effectively prevented. This significantly improves the reliability and efficiency of phone number-based communication in terms of both ecology and economy.
Claims
1. A communication network including data channels, the communication network having multiple channels for user data and user communication, as well as parallel data channels, characterized in that... The parallel data channel consists of an authentication network with multiple interfaces. Only data packets containing caller ID and phone number Can be input The request can be made or the query can be made through the interface.
2. The communication network according to the preceding claim, characterized in that, The interface can only output responses with a length of a few bits.
3. The communication network according to the preceding claim, characterized in that, The response includes only two bits for a declaration as call-related information, the declaration consisting of a set of declarations consisting of "valid", "invalid ID", "invalid phone number" and "invalid".
4. The communication network according to any one of the preceding claims, characterized in that, The interface is designed to allow only encrypted and / or secure communication.
5. The communication network according to any one of the preceding claims, characterized in that, The interface is configured as a peer-to-peer network with redundant multiple storage for incoming data.
6. The communication network according to any one of the preceding claims, characterized in that, The interface is synchronized via at least one clock.
7. The communication network according to any one of the preceding claims, characterized in that, Data packets in the authentication network are timestamped when they are received.
8. The communication network according to any one of the preceding claims, characterized in that, The authentication network is constructed in a forgetful manner, so that at least the received data packets cannot be permanently stored.
9. The communication network according to the preceding two claims, characterized in that, The data packet has a maximum storage time of 300 seconds, preferably 50 to 150 seconds, and particularly preferably 70 to 120 seconds.
10. The communication network according to all the preceding claims.
11. The communication network according to the preceding claim, wherein the call-related information can be stored at the user data level for further analysis based on known devices and measures and to prevent misuse.