Communication network with data channel

The communication network addresses the challenge of abuse prevention in ISDN telephony by using a parallel data channel as an authentication network with limited input and output data, achieving efficient and secure authentication with minimal computational load.

DE102023134091A1Inactive Publication Date: 2025-06-12OCULEUS GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102023134091
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-06
Publication Date
2025-06-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing communication networks face challenges in providing compatible and adaptable interfaces while preventing abuse, especially in ISDN telephony, where the D channel is often shut down due to cost-avoiding communication and lack of efficient abuse prevention.

Method used

A communication network with a parallel data channel that functions as an authentication network with multiple interfaces, where only a data packet containing a caller ID and call number can be input, and responses are limited to a few bits, ensuring secure and efficient authentication without additional data payload.

Benefits of technology

This solution provides a high degree of redundancy and efficiency in authenticating caller IDs and call numbers, minimizing computational load and data volume, while effectively preventing abuse and ensuring reliable communication.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

Despite good approaches in the field of ISDN technology, no practical method for authenticating caller ID has yet been established. The increasing use of digital communication over data networks has, in fact, increased the number of compromised interfaces and manipulated data. The task is to meet the long-standing need for a fail-safe device that consumes as little data capacity as possible, while effectively enabling the authentication of a caller ID and the associated phone number on the recipient side. Based on the good approaches in the field of ISDN technology, the solution is a data channel, designed as a parallel, strictly assigned authentication network consisting of a plurality of interfaces, which, apart from the purpose of authentication, does not provide any additional data payload.By consistently limiting the number of receivable data packets to a few bytes and the number of output responses to a few bits, a high degree of redundancy is possible and allows implementation as a system-relevant security component. This surprisingly efficient authentication of caller ID and phone number, using the simplest of devices, is now possible for the first time in a secure, encrypted, fast, adaptable, amnesic authentication network with high reliability, before network operators have to activate channels for user data or user communication. The required data capacity is minimal, and common fraud strategies can thus be highly effectively prevented. This significantly improves the reliability and efficiency of phone number-based communication, both ecologically and economically.
Need to check novelty before this filing date? Find Prior Art

Description

The invention is well within the scope of computer implemented inventions. Simple methods or algorithms have long been available both as hardware and software implementations and hybrid combinations. Thus, JP 06201782A already discloses a chipset in which a linear feedback shift register is provided as part of a test circuit; further developments thereof can be found in the 1990's documents JP10207695 A and also JP 10301492 A. U.S. Pat. No. 6,091,821 A discloses how a hardware-level hash algorithm can be mapped; U.S. Pat. No. 6,289,023 B discloses a more efficient checksum generator; U.S. Pat. No. 6,348,881 B1 discloses a hardware-implemented compression algorithm. KR 10 2003 005 111 1 A is a hardware-implemented AES encryption; KR 10 2005 0005 054 A is a hardware generator for white noise. Methods and products for implementing simple, established methods can therefore be considered known in data processing via a hardware module. Measures such as AND operation, XOR operation, encryption, compression, signing, checksum validation, intercorrelling and also the creation of inherently correlated characteristic data can be regarded as established and implementable both on the software side and on the hardware side. For particularly fast and efficient hardware, block-based parallel processing is used, as described, for example, in DE 10 2005 018 248 B4. Against this background, the subject matter defined in this invention describes both hardware and the software that can be placed in the same direction, and hybrid models in which the functions of the invention can be implemented proportionally and provided in combination to form the claimed subject matter.GENERAL BACKGROUNDThe present invention relates to a communication network according to the preamble of the independent claims. A basic problem of communication networks operating with many data layers and parallel data channels is the provision of interfaces that are compatible and adaptable as widely as possible on the one hand and the prevention of abuse on the other hand. U.S. Pat. No. 4,031,512 A already describes 1977 how a communication network can be divided and operated reasonably into a plurality of data layers or data channels despite a structure of individual lines; against this background, the terms "data layer" and "data channel" can describe both associated lines and associated data identifiers or combinations thereof. US 5,335,227 A further describes reconfigurable communication networks which can be restructured if needed while user terminals are detected via an identifier and remain assigned to users. In addition, WO 1995024791 A discloses how a radio network and a fixed network can be combined in an improved manner and tuned via a parallel control channel and operated better jointly with the collection of operating data. In order for such and similar communication networks to cooperate, many switching, usable ports are provided in soft and / or hardware level switching modules; however, this has the disadvantage that data can be manipulated during transmission.In particular, obscuring and impermissible anonymizing of a caller identity, referred to hereinafter as the caller ID, is a common problem that arises, for example, in the case of identity and billing fraud.Possible counter-measures for the field of telecommunications are described, for example, in the documents U.S. Pat. No. 5,495,521 a; U.S. Pat. No. 5,907,602 a; U.S. Pat. No. 6,058,301 a; EP 1 076 951 B; KR 10 2001 004 3378 A; U.S. Pat. No. 6,675,153 B1 and U.S. Pat. No. 7,496,345 B1. However, none of the established devices and measures have gained global and broad acceptance. The large number of compatible networks quickly leads to a too high and expensive data load within the complex correlated data layers in the conventional approaches.DESCRIPTION OF THE PRIOR ARTISDN telephony: The present invention builds on the concepts known from ISDN telephony. ISDN devices rely on the aforementioned principle of U.S. Pat. No. 4,031,512 A and initially provide 2 types of data channels: a plurality of B channels, via which user data can be exchanged, and a parallel D channel, which was intended for the coordination of the devices and network functions with one another. JP 620 380 52 A proposes monitoring an ISDN network via the D channel. JP 02246652 A makes it possible to propose using the D channel for parallel data transmission; JP 06188936 A describes, in addition, parallel data transmission via a plurality of B channels. JP 04220857 A proposes restricting the available services via access data or password to ISDN systems. JP 03254261 A proposes subjecting device identifiers to a preparatory register check in order to speed up requests and activations. JP 03270543 A describes a test method in which outgoing start communication of an ISDN device is read along, modified and forwarded for validation; if the modified start communication agrees with a desired value, the line and the device are evaluated as suitable and permitted / activated.U.S. Pat. No. 5,218,680 A discloses an integrated interconnection of ISDN functions and expanding CPU functions on a chip; in the same direction, EP 0 833 529 A2 proposes the operation of an ISDN installation in expansion with a radio network. Finally, U.S. Pat. No. 5,805,570 A from 1998 discloses software with which an ISDN communication node on a PC can be simulated. Against this background, the functions provided in the area 'ISDN' in the 1980's and 1990's essentially via hardware can be provided in the same direction for initiation both as software with modern PCs and as hardware or in suitable part combinations.From JP 0 205 464 5 A it is known to use the D channel for preventing abuse, e.g. by password interrogation.EP 0 817 484 A2 proposes connecting networks for communication, comprising multimedia data streams, to one another via an ISDN installation.Thus, communication networks are known from the prior art in which a parallel D channel can be used for preventing abuse in parallel with a plurality of channels for communication data of the users.A disadvantage of this concept is that the D channel of an ISDN network also provides a data volume for parallel communication. DE 199 37 098 A1 therefore proposes carrying out all preparatory communications without charges before setting up a charged connection. This has regularly resulted in a misbeauded, cost-avoiding communication directly via the D channel in the market, which also corresponds to the sharing as a communication data channel proposed in the Japanese document. In view of this, the network operators regularly shut down the D channel and a reasonable development of an efficient parallel channel for validation of call data and for preventing abuse did not take place.It is an object of the present invention to overcome the disadvantages of the prior art and to design a data channel which, despite the possibility of parallel communication, is able to provide an efficient protection against abuse that is attractive to network operators.This object is achieved according to the features of the independent claims. Advantageous embodiments are evident from the dependent claims and the following description.Another problem is the fact that communication security is a core aspect of modern companies; a system contributing to this should therefore require as little computational load or data volume as possible in order not to decelerate the communication.Another problem is the fact that safety-relevant systems should have an increased level of fail-safe; partial failures should be able to be compensated.The fact that a fundamentally possible communication via a parallel data channel would be available to third parties is also problematic; access to these functions should be restricted in terms of time and / or for users.Another problem is the fact that call data permit conclusions to be drawn about private data and properties of the communication links; data security should be taken into account.Another problem is the fact that system relevant functions should be subjected to continuous monitoring; an important system should be able to detect and compensate for overload or increased demand.SUMMARY OF THE INVENTIONAccording to the invention, the claimed communication network has a data channel. Furthermore, a plurality of channels for user data and user communication are provided. The parallel data channel consists of an authentication network of a plurality of interfaces. It is essential that the data channel is strictly associated with the function of the security query and does not offer a data volume as available payload. For this purpose, only a data packet can be input into the interfaces, which contains a caller ID and a call number; the data packet can be input as a request or as a request.DESCRIPTION OF THE INVENTION AND ADVANTAGEOUS FEATURESAccording to the invention, the claimed communication network has a data channel analogous to a D channel of the ISDN technology.A plurality of channels, analogous to the B channels of ISDN technology or the data layers of established mobile radio networks, are available for user data and user communication.The parallel data channel consists of an authentication network of a plurality of interfaces. It is essential that the data channel is strictly associated with the function of the security query and does not offer a data volume as available payload.For this purpose, only a data packet can be input into the interfaces, which contains a caller ID and a call number.The caller ID and also the call number are information which is checked before connection is set up in the established radio networks in order to ensure the payment of the call. Against this background, the caller ID comprises at least the unambiguously identifiable contract partner recorded with a separate call number and / or the corresponding credit account via which the call is preliminarily released. Thus, the caller ID and the call number form a small data packet of a few bytes. The data packet can be input as a request or as a request. A request is recorded in the data channel and stored for timely matching and a receipt confirmation is sent.In the case of a request, the request data packet is matched to the existing request data packets and confirmed if a match is found or rejected if a match is not found.On the part of the operator of the caller, the above-described concept only requires the forwarding of the caller ID and call number to the respective operator of the call number connection; the parallel data channel strictly oriented for its purpose makes the operator of the call number connection possible with minimal effort a request for the data packet as described above: the received data only have to be fed into the data channel identified as a request. Upon confirmation, the call can then be set up, and upon rejection, the connection is rejected.Preferably, only a few bits long response can be output via the interfaces. If the magnitude of possible responses is significantly smaller than the data packet, then abuse of the data channel as a communication channel becomes very unattractive. A few bits are already sufficient to classify a successful transmission, a checksum or the like. Particularly preferably, the response comprises, as call-related information, exclusively 2 bits for statements comprising statements consisting of the group of statements consisting of 'valid', 'ID invalid', 'call number invalid' and 'invalid'. It is thus sufficiently possible for the operator of the call number to form groups on the basis of the caller ID and the statement, which groups can enable statements about the quality of the communication channels and / or trustworthiness of the caller ID and can be used in established, further measures.The interfaces are preferably configured to allow only an encrypted and / or secured communication. An encrypted communication can provide end-to-end encryption so that input data packets cannot be used by third parties; furthermore, a personal code can be assigned to each user via supplementary, cryptographic tools in order to identify impermissible or counterfeit inputs; furthermore, a protection can comprise a detection of the respective sender ID and the continuous increase of a minimum waiting time in the case of incorrect inputs in order to prevent DOS attacks; furthermore, both hardware and software side-common and possible, simple functions as are known in the scientific field can be provided.The interfaces are preferably configured as a peer-to-peer network with redundant multiple storage of the incoming data. By dividing the data packets into a plurality of interfaces, preferably also physically remote from one another, a high degree of reliability is achieved; preferably, the extent of redundancy for hazardous situations / situations and / or specific user groups can be regulated in order to be able to adapt the reliability of the system in the event of a changed situation and / or increased system relevance of a user group.The interfaces are preferably synchronized via at least one clock. This allows the assignment of passwords or access data with a time-dependent component and / or validity; particularly when compromised access data is suspected, a rapid, time-dependent modulation of the access data and its transmission over different data paths can help identify and switch off the compromised data paths.Preferably, data packets in the authentication network can be provided with a time stamp when they are received. In the case of a request, the data packet is thereby supplemented with a time stamp; a comparison of the input time and the query time or response time allows an estimation of the current load of the data channel. The latter can be used to increase the number of available interfaces by generating and / or connecting further interfaces or by deleting and / or switching off interfaces in the event of a load change in order to ensure a continuous minimum performance of the data channel in the sense of an optimized efficiency and ecobalance.The authentication network is preferably of an amnesic design, wherein at least received data packets cannot be permanently stored; by periodic clearing of the data packets, abuse / compromise of the data packets is additionally prevented. Preferably, data packets have a maximum storage time of 300 seconds; 5 minutes maximum storage time were sufficient in practical testing even for extremely unstable line sections with multiple request and redirection to establish a connection; preferably, data packets are deleted after 50 to 150 seconds, which was always a sufficiently long storage time for normal connections; particularly preferably, data packets are deleted after 70 to 120 seconds, which was just sufficient for national calls in areas with average, uniform network coverage. In principle, a shorter minimum storage time correspondingly reduces the load in the data channel. Against this background, a user- and situation-related control of the minimum storage time is particularly attractive in order to also be able to achieve an optimum between customer satisfaction and energy consumption in terms of energy.Preferably, the network operator can store the call-related information at the user data level for further analysis and abuse prevention according to known devices and measures. As explained in the introduction, various approaches and concepts are known with which further steps and preventive measures can be initiated in a communication network when forgery or fraud attempts are detected.Further advantages result from the exemplary embodiments. The features and advantages described above and the exemplary embodiments below should not be interpreted-unless epxliticite is described as such-as final combinations of features. Additional, advantageous features and additional combinations of features, as explained in the description and established according to the cited documents and the references referenced therein, can be implemented in the claimed subject matter, both individually and combined in a different manner, within the scope of the independent claims, without departing from the scope of the invention.DETAILED EXPLANATION OF THE INVENTION BY WAY OF EXAMPLEIn an advantageous embodiment according to the invention, a communication network with data channel has a plurality of channels for user data and user communication. The parallel data channel consists of an authentication network of a plurality of interfaces. Only a data packet containing a caller ID and a call number can be input into the interfaces as a request or as a request. Only a few bits long response can be output via the interfaces, wherein the response comprises only 2 bits for statements as call-related information. The statements can be selected from the group of statements consisting of 'valid', 'ID invalid', 'call number invalid' and 'invalid'. The interfaces are designed to allow only an encrypted and / or secured communication. Furthermore, the interfaces are configured as a peer-to-peer network with redundant multiple storage of the incoming data and are synchronized via at least one clock. The data packets can be provided with a time stamp in the authentication network when they are received. The authentication network is of an amnesic design, wherein at least received data packets cannot be permanently stored, but rather have a maximum storage time of 300 seconds, preferably 50 to 150 seconds, particularly preferably 70 to 120 seconds.When a call is initiated, the caller is legitimised beforehand via the network operator of the caller, inquiring for his caller ID and bonus. The data packet is created by the network operator of the caller, identified as a request, encrypted and transmitted as a request to the data channel after establishing a secure, admissible connection. The request is time stamped and its complete receipt confirmed. The carrier of the call number is contacted and caller ID and call number are transmitted. The network operator of the call number in turn generates a data packet and sends this data packet to the data channel as a request according to the connection set-up as described above. The receipt of the completely and efficiently received request is confirmed. In the authentication network, the request is matched to the present requests. The corresponding response information is created and sent back to the network operator of the call number. Only with the reply information 'valid' is the call set up. For all other responses, the establishment of a call is aborted.INDUSTRIAL APPLICABILITYDespite good approaches in the field of ISDN technology, no reasonable method for authenticating a caller ID and the dialed call number has been used to date. As digital communications over data networks have become increasingly used, the number of compromised interfaces and manipulatable data has increased.The task is to meet the long-standing demand for a fail-safe device that consumes as little data capacity as possible, and this should effectively allow the authentication of a caller ID and associated call number on the part of the receiver.Proceeding from the good approaches from the field of ISDN technology, the solution takes place by means of a data channel, designed as a parallel, strictly assigned authentication network comprising a plurality of interfaces, which not only provides any additional data payload for the purpose of authentication. Due to the consistent restriction of the receivable data packets to a few bytes and the outputable responses to a few bits, a high degree of redundancy is possible and allows implementation as a system-relevant security component. The authentication of the caller ID and the call number which is thus surprisingly efficient with the simplest devices is thus carried out for the first time in a secured, encrypted, fast, adaptable, American authentication network with high reliability before the network operators would have to actively switch channels for user data or user communication. The necessary data capacity is minimal and the usual fraud strategies can be suppressed so efficiently. Both environmentally and economically, this greatly improves the reliability and efficiency of directory number-based communication.References included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Patent Literature citedJP 06201782A

[0001] JP 10207695 A

[0001] JP 10301492 A

[0001] U.S. Pat. No. 6,091,821 A

[0001] U.S. Pat. No. 6,289,023

[0001] U.S. Pat. No. 6,348,881 B1

[0001] KR 10 2003 005 111 1 A

[0001] KR 10 2005 0005 054 A

[0001] DE 10 2005 018 248 B4

[0001] U.S. Pat. No. 4,031,512 A [0002, 0005]U.S. Pat. No. 5,335,227 A

[0002] WO 1995024791 A

[0002] U.S. Pat. No. 5,495,521 A

[0004] U.S. Pat. No. 5,907,602 A

[0004] U.S. Pat. No. 6,058,301 A

[0004] EP 1 076 951

[0004] KR 10 2001 004 3378 A

[0004] U.S. Pat. No. 6,675,153 B1

[0004] U.S. Pat. No. 7,496,345 B1

[0004] JP 620 380 52 A

[0005] JP 02246652 A

[0005] JP 06188936 A

[0005] JP 04220857 A

[0005] JP 03254261 A

[0005] JP 03270543 A

[0005] U.S. Pat. No. 5,218,680 A

[0006] EP 0 833 529 A2

[0006] U.S. Pat. No. 5,805,570 A

[0006] JP 0 205 464 5 A

[0007] EP 0 817 484 A2

[0008] DE 199 37 098 A1

[0010]

Claims

Communication network with data channel, having a plurality of channels for user data and user communication and the parallel data channel, characterized in that - the parallel data channel consists of an authentication network consisting of a plurality of interfaces, wherein - only a data packet containing a caller ID and a call number - can be input into the interfaces as a request or as a request.Communication network according to the preceding claim, characterized in that only a response of a few bits can be issued via the interfaces.Communication network according to the preceding claim, characterized in that the response comprises, as call-related information, exclusively 2 bits for statements comprising statements consisting of the group of statements consisting of 'valid', 'ID invalid', 'call number invalid' and 'invalid'.Communication network according to one of the preceding claims, characterized in that the interfaces are designed to allow only encrypted and / or secured communication.Communication network according to one of the preceding claims, characterized in that the interfaces are configured as a peer-to-peer network with redundant multiple storage of the incoming data.Communication network according to one of the preceding claims, characterized in that the interfaces are synchronized via at least one clock.Communication network according to one of the preceding claims, characterized in that data packets in the authentication network can be provided with a time stamp when they are received.Communication network according to one of the preceding claims, characterized in that the authentication network is of an domestic design, at least received data packets not being permanently storable.Communication network according to the two preceding claims, characterized in that data packets have a maximum storage time of 300 seconds, preferably 50 to 150 seconds, particularly preferably 70 to 120 seconds.A communication network according to any preceding claim.Communication network according to the preceding claim, wherein the call-related information can be stored at the user data level for further analysis and abuse prevention according to known means and measures.

Citation Information

Patent Citations

  • Method for Addressing, Key Exchange, and Secure Data Transmission in Communication Systems

    DE102015106440A1

  • Method for the transmission of data in a packet-oriented data network

    WO2003028335A1