Method of one-time caller authentication passwords

GB2618414BActive Publication Date: 2025-05-07HENRY MCGUIRE +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
GB2023002924
Authority / Receiving Office
GB · GB
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-03-04
Filing Date
2023-02-28
Publication Date
2025-05-07
Estimated Expiration
2043-02-28

AI Technical Summary

Technical Problem

Current caller authentication methods are one-sided, leaving consumers vulnerable to fraudulent activities as they lack the means to verify the identity of corporate, commercial, or institutional callers, especially in telephone and doorstep interactions.

Method used

A method utilizing time-based one-time passwords (TOTP) that allows consumers to authenticate the identity of callers across multiple accounts by generating and validating one-time passwords, providing control over access and presentation, and incorporating additional identification information for enhanced security.

Benefits of technology

This solution enhances security by enabling consumers to verify the identity of callers before answering, reducing vulnerabilities and providing a flexible, user-controlled authentication process that adapts to various communication systems, ensuring safer interactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_0000
    Figure 00000001_0000
  • Figure 00000002_0000
    Figure 00000002_0000
  • Figure 00000003_0000
    Figure 00000003_0000
Patent Text Reader

Abstract

A method of identity authentication for telephone, internet and doorstep calling wherein a called party 1 can authenticate the identity of a caller in real time using a range of time-based one-time pa
Need to check novelty before this filing date? Find Prior Art

Description

The present invention relates to the field of telecommunications. In particular, it discloses a method whereby a consumer can authenticate the identity of a telephone, internet or doorstep caller from a corporate, commercial, organisation or institution. Currently when a corporate, commercial, organisation or institution phones a customer or account holder or a customer or account holder calls a corporate, commercial, organisation or institution it is the consumer who must authenticate their identity by various means such as correctly answering specific personal or account questions or by correctly verifying a code generated and supplied by the corporate, commercial, organisation or institution. This process is one sided and leaves a consumer at a distinct disadvantage and vulnerable to criminal and other unwanted activity with no means of authenticating the identity of a corporate, commercial, organisation or institution caller to their personal satisfaction. Similar consumer disadvantages and vulnerabilities apply to doorstep calls from a corporate, commercial, organisation or institution. One-time passwords (OTP) and time-based one-time password (TOTP) are an automatically generated numeric or alphanumeric string of characters that authenticate a user for a single transaction or login session. One-time passwords (OTP) and time-based one-time passwords (TOTP) are more secure than static passwords, especially user-created passwords, which can be weak and or reused across multiple accounts. Currently time-based one-time password (TOTP) services are commonly used within the area of internet technology to replace static passwords as authentication for a login session or transaction and may be used as an additional layer of security. For example, with the introduction of online banking and other online accounts one-time passwords are used as two-factor authentication that is sent to consumers by email or SMS to further verify their identity when making an online payment. The limitations of much of the prior art systems are readily apparent. For example, one-time passwords (OTP) and time-based one-time passwords (TOTP) are limited by being one sided and generated solely by or on behalf of commercial, corporate, organisation or institutions and sent to a consumer via email, SMS or proprietary tokens for one-time use to validate the identity of an account. Currently utility companies operate a system whereby a customer has a shared secret with each utility company in order to identify a doorstep caller from a particular company. Limitations of this prior art is also readily apparent due to a customer of multiple utility companies having to remember multiple shared secrets and passwords. With the further development of telecommunications, intercom and doorbell systems it is now possible to incorporate or integrate existing and developing intercom and doorbell systems with or within a consumer centric one-time password (OTP) caller authentication system. It is an object of the present invention to provide a method of time-based one-time passwords (TOTP) caller authentication within telephone, internet and doorstep calling systems for use across multiple accounts to enable a consumer to authenticate the identity of corporate, commercial, organisation or institution callers . It is a further object of the present invention to provide a method of time-based one-time passwords (TOTP) caller authentication within telephone, internet and doorstep calling systems to enable a corporate, commercial, organisation or institution to authenticate the identity of known or unknown callers prior to or after answering a call. It is a further object of the present invention to provide each user with or with access to at least one one-time password generator. It is a further object of the present invention to provide each user with or with access to at least one one-time password validator. It is a further object of the present invention to provide each user with or with access to at least one one-time password display. It is a further object of the present invention to provide a method whereby each user has control over who has access to their one-time password information. According to the present invention there is provided a method of authenticating the identity of telephone, internet and doorstep callers using a range of time-based one-time passwords (TOTP) across multiple accounts, the method comprising the steps of: 1) Caller selects party to be called. 2) Prior to or after call being initiated by caller system generates delivers and presents a one-time password on device of caller or devices of caller and selected party. 3) Caller initiates call to selected party. 4) Prior to or after call being answered or access being gained system or called party requests caller to authenticate their identity by accurately providing a one-time password to system or called party within set timescale. 5) On requested one-time password being received presented to and verified by system or called party called party answers call or rejects call or continues with call or discontinues call or allows access or denies access. Preferably a call comprises mobile, landline, internet, nearfield, intercom or doorbell or door knock call. Preferably a call further comprises voice, video, access, rhetorical, face to face calls or real-time electronic messaging or other real-time communication systems or methods . Preferably a caller comprises a corporate, commercial, organisation, institution representative or agent or a consumer or hardware or software or machine. Preferably a called party comprises a consumer or a corporate, commercial, organisation, institution representative or agent or hardware or software or machine . Preferably a one-time password is time-based (TOTP). Preferably a one-time password is not time-based (OTP). Preferably method consists one-time password generators. Preferably method consists one-time password validators. Preferably a one-time password timing is system or user controlled. Preferably a one-time password comprises for example, numeric, alpha-numeric (including; post, zip or area codes), graphics, coloured characters, colour blocks or QR codes or biometrics or any combination of. Preferably a one-time password comprises a shared secret or unique ID code or secure key or any combination of. Preferably a one-time password is presented to caller or called party or caller and called party. Preferably a one-time password presentation is in for example, visual, audio, text, graphical, verbal or sign language form or in any combination of. Preferably a one-time password presentation is presented on screen or audio output or screen and audio output of for example, mobile phone, pc, laptop, tablet, games console, intercom, doorbell or handheld OTP or other device of called party or caller or called party and caller. Preferably one-time password presentation comprises customisation or personalisation. Preferably one-time password presentation comprises customisation or personalisation by user. Preferably one-time password customisation or personalisation presentation comprises for example, numeric, alpha-numeric, multi-media or rich media or any combination of. Preferably one-time password presentation comprises customisation and personalisation containing for example, additional consumer, corporate, commercial, organisation, institution, representative or agent identification and or other information and or data. Preferably one-time password presentation additional identification or other information or data comprises for example numeric, alpha-numeric, multi-media or rich media or biometric information. Preferably one-time password presentation additional information comprises verified information. Preferably one-time password presentation additional information comprises verifiable information. Preferably one-time password presentation numeric, alphanumeric, multi-media, rich media and additional identification and or other information and or data is editable in real-time. Preferably one-time password presentation is edited in rea-time by a user using screen, keypad and or microphone of a communication device of user. Preferably one-time password presentation is edited in real-time using graphical user interface (GUI) on communicating device of user or from website. Preferably one-time password presentation additional identification and or other information and or data comprises interactive information and or data. Preferably one-time password is combined with or incorporated into existing caller identification or user profile or one-time and single password systems. Preferably method comprises request features. Preferably request is from system or called party or caller requesting one-time password verification or additional identification or other informationor data. Preferably request is prior or after call activation or connection or delivery or answering or access. Preferably request for additional identification or other information or data continues prior to and or beyond answering or access depending on sensitivities or level of security required by system or called party or calling party. Preferably presentation or additional identification or other information and or data is pulled from local or remote databases or internet or cloud or manually input. Alternatively, presentation or additional identification or other information and or data is pushed directly from calling or called or calling and called device. Preferably one-time password system comprises authentication. Preferably one-time password system comprises authentication by system or caller or called party or called party and caller. Preferably one-time password comprises authentication prior to call connection or delivery or answer or access. Preferaly one-time password comprises authentication after connection or delivery or answer or access. Preferably, one-time password comprises authentication continuing beyond connection or delivery or answer or access . Preferably one-time password authentication is in for example, visual or audio or verbal, text or graphical or physical or electronic or automatic form. Preferably on one-time password being authenticated by system or called party called party answers or continues or discontinues or rejects call or allows or denies access . Preferably method comprises presentation generators. Preferably method comprises password creators, scanners and readers. Preferably the method is programmable. Preferably the method is programmed in real-time by a user using screen, keypad and or microphone of a communication device of user. Preferably the method is programmed using graphical user interface (GUI) on communicating device of user or from website . Preferably one-time password is generated using for example, shared secrets or unique ID codes, secure key or verified credentials or any combination of. Preferably one-time password is randomly generated. Preferably one-time password generation comprises algorithms . Preferably method is independent of call processes. Alternatively, method is incorporated within call -L- O '__O O K— uJ • Preferably method is in digital form. Alternatively, method is in analogue form. Preferably method comprises additional features. Preferably additional features comprise for example, permission, contact list, lookup, answering service or call barring or any combination of. Preferably call barring comprises barring of for example, phone numbers, names, usernames, short codes or other contact details. Preferably call barring feature comprises auto-block. Preferably system comprises user control of for example additional features, presentations, displays and call barring. Preferably method comprises corporate, commercial, organisation or institution data stores. Preferably method comprises consumer personal data stores . Preferably method comprises corporate, commercial, organisation or institution one-time permission-based access to consumer personal data stores. Preferably method comprises consumer one time permissionbased access to corporate, commercial, organisation or institutions data stores. Preferably method comprises encryption. Preferably method comprises cross platform technology. Preferably method comprises interoperability. Preferably method comprises in-app, out-app and cross-app features and applications. The method is not restricted to use within any single communication system or method or signalling or device or interface or application. Embodiments of the present invention will now be described, by way of example only, with reference to the accompanying drawings, in which: Figure 1 illustrates a flow chart of steps involved in a method whereby a consumer authenticates the identity of a corporate telephone caller. Figure 2 illustrates a flow chart of steps involved in a method of registration. Figure 3 illustrates a flow chart of steps involved in a method whereby a consumer authenticates the identity of a corporate caller from a call centre. This invention describes a method whereby a called party can authenticate the identity of a telephone or internet or doorstep caller by the system or a called party requesting that a caller verify their identity by accurately supplying the system or a called party with requested time-based one-time password (TOTP) information prior to or after a call being answered or access being granted. On registration a user shares a secret with the system and thereafter the system allocates a unique ID code to each corporate, commercial, organisation or institution or consumer with permission to access one-time passwords of a user. Figure 1 presents a flow chart that schematically outlines this method. The initial step of this process is for a caller or system to select a party to be called (1) • The second stage of the process is prior to or after initiating a call to selected party the system verifies that a caller has permission to access the one-time password information of a selected party and thereafter presents one-time password information of a selected party on device of caller by matching the unique ID code of a selected party and unique ID code and one time password information of a caller (2). One-time password information of a called party can be presented to a caller in a variety of ways depending on the communication system or device or method of calling being used, for example, one-time password presentation can be presented in visual, audio, text, graphical, verbal or other form. The next stage of the process is for a caller to initiate a call to selected party (3). Call initiation can be in a variety of ways depending on the communication system or device or method of calling being used, for example, call initiation can be from mobile, landline, internet soft phone or phone plus independent handheld OTP device, intercom or doorbell. The next stage of the process is for a device of a called party to receive incoming call from caller (4) which initiates a ringtone or vibration or buzzer or ringer of a receiving device and thereafter presents caller identification information to called party. The method of receiving a call can be in a variety of ways depending on the communication system or device or method of calling being used, for example, on screen and or audio output of a mobile phone, landline phone, internet soft phone, phone plus independent handheld OTP device, intercom or doorbell. The next stage of the process is prior to or after answering a call is for system or called party to request that a caller authenticate their identity by accurately supplying requested one-time password (OTP) information to system or called party within a set timescale (5). The method of caller authentication can take place in a variety of ways, for example, by one-time password 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 verification and by further requesting and accurately supplying additional identification and or other information and or data. On caller authenticating their identity by accurately supplying requested one-time password information to system or called party within set timescale (6) a called party can then make an informed decision as to whether they wish to answer a call (7) or continue with a call (8) or reject a call (9). The method of a called party responding to a call can be in a variety of ways depending on the communication system or device or method of calling being used. For example, a called party can answer call or reject call or continue with call or discontinue call or allow access or deny access. Figure 2 presents a flow chart that schematically outlines the process wherein a corporate entity and a consumer register to become a user within the method. The initial step of the registration process is for a corporate entity applicant (1) or a consumer applicant (4) to supply system with all requested contact and identity information, documents, data, or other information which is thereafter validated by system (2 and 5) . Validation of contact and identity information, documents, data, or other information supplied by an applicant can also be carried out by an independent third party or by a registered corporate entity when an existing consumer of a specific corporate entity makes their application through that registered corporate entity. The next stage of the registration process is on successful identity validation a corporate entity applicant is thereafter allocated their own unique key (3) and a consumer applicant is thereafter allocated their own unique key (6) which is securely stored within the system. A representative, agent or service provider of a corporate entity can also make calls within the system using the unique key of a specific corporate entity. A registered consumer can then informs the system of each registered corporate entity with whom they are prepared to accept calls from (7) whereafter a combined key is generated (8) which is unique to each corporate entity with permission to call and registered consumer relationship, this combined key is stored securely in the system. A combined key (8) is then utilised for the generation of a unique time-based one-time password (9) each time a permitted corporate entity calls a specific consumer. A representative, agent or service provider of a registered corporate entity can also make a call within the system using the unique key of a permitted corporate entity or can be registered separately with their own unique key which can also be combined with a unique key of a specific corporate entity and or a specific consumer. Figure 3 presents a flow chart that schematically outlines the process wherein a registered corporate entity calls a consumer from a call centre utilising a combined key as generated in (Figure 2 step 8) within this method. The initial step of this process is for a registered corporate entity call centre operator to 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 select or have selected for consumer to call (1) if registered with system call software proceeds with a call them by internal software a selected consumer is not centre operator or internal as normal (16). If selected consumer is registered with system and registered corporate entity has permission to call consumer (Figure 2 step 7) and to access combined key that is securely stored within the system (Figure 2 step 8) call centre software requests time-based one-time password from system (3) on receiving unique time-based one-time password from system call centre software presents unique combined time-based one-time password to call centre software and to call centre operator, call centre operator or software then proceeds to make a call to selected consumer (5). If call receiving device of selected consumer supports inbuilt automatic system functionality (6) call centre software presents combined time-based one-time password in electronic format on device of consumer (7) inbuilt automatic system functionality (6) also presents additional corporate caller identification information on device of consumer and at same time confirms to the consumer that corporate caller is verified and that call is safe to answer (8), a consumer can now answer call safe in the knowledge that corporate caller is exactly who they claim to be (9). Alternatively, if a call receiving device of selected consumer does not support the incorporation of automatic system functionality (6) a manual process can be followed. On answering a call from corporate caller (10) selected consumer requests that caller identifies the corporate entity calling by providing selected consumer with combined time-based one-time password (11) and other corporate information, on receiving combined time-based one-time password and addition information from corporate caller selected consumer validates all information received (12 and 13) using an independent authenticating device and thereafter answers call safe in the knowledge that the caller is who they claim to be (14). Alternatively, if requested time-based one-time password and other corporate information from caller is not validated by independent authenticating device of selected consumer a selected consumer can discontinue a Incorporating additional information within a time-based one-time password method presentation allows a caller to also rate the importance of a call. For example, on reading additional information contained within a onetime password method presentation a called party will immediately know if the call is of a business or personal nature . The choice to send or allow or not to send or allow access to personal information or contact details of a corporate, commercial, organisation, institution or other entity representative or agent or a consumer allows a caller or a called party to maintain a degree of confidentiality if this is required and therefore not compromising their privacy or revealing too much information unnecessarily. The continuous request and real-time editing of additional information and other features contained within the time-based one-time password method enables a caller or called party to adapt their one-time password presentations in an ongoing dynamic fashion. If a called party is away from their device the system can be programmed to instantly or after a pre-determined time interval default to an answering service. On a caller being unable to authenticate their identity to the satisfaction of the system or a called party prior to or after answering, a called party can decide whether to answer call or reject call or continue with call or discontinue call or allow access or deny access. A corporate, commercial, organisation or institution would experience particular benefits from the flexible consumer centric time-based one-time caller authentication password system by the higher degree of security and reassurance that it offers consumers due to their representatives, agents and service providers having the ability to authenticate their corporate, commercial, organisation or institution identity credentials to a consumer when calling, the incorporation of additional data and information within a one-time password presentation would further help in the promotion and advertisement of a corporate, commercial, organisation or institution and further help a consumer identify individual representatives, agents or service providers each time a consumer receives a corporate, commercial, organisation or institution call. 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 The method as outlined above is not restricted to use within any one particular communication system. It may be employed across a wide range of wireless or wired communication systems that employ a variety of signalling and interfaces including fixed-line, mobile or soft phones or phones or phone systems connected to a smart television, computer, laptop, tablet, pager, gaming console, intercom and smart doorbell systems or any other suitable communications device. A scaling facility is also incorporated such that text and graphical displays can be adjusted to fit either the LCD of a phone system or the screen of a computer or television or any other suitable communication device. The system outlined above has been designed to be incorporated into or integrated with or within present and developing digital, analogue, mobile and fixed line communication technology so as to be compatible with broadband, cable, wi-fi, voip, nearfield, p2p, radio, satellite, smart doorbell and intercom systems. Present systems that do not incorporate the time-based one-time caller authentication password system will simply treat a call in the normal fashion. Software or hardware adapter units can be easily incorporated into such systems to enable them to be compatible with one-time password technology. The universal (b2c / c2b / b2b / c2c) system would be ideal for incorporation into corporate, commercial, organisation or institutions own call centres or outsourced to third party call centres where operators can access the onetime passwords of a called party on their own behalf or on behalf of multiple corporate, commercial, 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 organisations or institutions. Alternatively, the system can be adapted for use by consumers to provide a two-factor method wherein a consumer can authenticate the identity of another consumer when receiving personal calls . An advantage of the present invention is that it is user controlled and can be programmed by user to only allow TOTP calls from callers who have prior permission from a called party to access the TOTP information of a called party or allow TOTP calls from all registered callers or allow calls from TOTP registered and unregistered callers or permanently or temporarily bar any caller. The method also allows a called party and a caller to further authenticate the identity of one another by permitting each other access to additional verified or verifiable identification information and or data. A further advantage of the present invention is that it can be used within video calls, group calls or face to face calls or meetings to verify that any person present is exactly who they say they are. An even further advantage of the present invention is that any customisation or personalisation or additional corporate, commercial, organisation, institution or consumer information or data contained within method presentations can be stored locally or remotely, alternatively customisation or personalisation or additional information or data is not required to be prestored within a database accessed by called party as it can also be contained completely within a transmitted information signal depending on communication system being used. A yet further advantage of the present invention is that it is permission based and highly flexible and so can be used with existing or developing systems, for example, it can be combined with present digital systems that incorporate devices that are capable of downloading new software updates and applications or combined with analogue systems that use phones with no software update or application download capabilities by the incorporation or integration of additional plugin or wires free hardware adapter units. Further modifications and improvements may be added without departing from the scope of the invention herein intended.

Claims

1) According to the present invention there is provided a method of authenticating the identity of telephone, internet and doorstep callers using a range of timebased one-time passwords (TOTP) across multiple accounts, the method comprising the steps of:1) Caller selects party to be called.2) Prior to or after call being initiated bycaller system generates delivers and presents a one-time password on device of caller or devices of caller and selected party.3) Caller initiates call to selected party.4) Prior to or after call being answered or access being gained system or called party requests caller to authenticate their identity by accurately providing a one-time password to system or called party within set timescale.5) On requested one-time password being received presented to and verified by system or called party called party answers call or rejects call or continues with call or discontinues call or allows access or denies access.2) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 1, wherein a time-based one-time password (TOTP) comprises a password generated from one or more from a group comprising numeric or alpha-numeric characters, coloured characters, colour blocks, graphics, QR codes or biometrics.3) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 1 and Claim 2, wherein a time-based one-time password further comprises one-time passwords generated for a caller or a called party or a caller and a called party or combined one-time passwords generated for a caller and a called party.4) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 1 to Claim 3, wherein multiple accounts comprise a user holding an account with one or more from a group comprising a corporate, commercial, organisation, institution or other entity.5) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 1 to Claim 4, wherein a call comprises a call from one from a group comprising a call centre, fixed line or mobile telephone, internet soft phone, apps, intercom, doorbell, software or hardware.6) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 5, wherein a call further comprises one from a group comprising a voice, video, audio, rhetorical or face to face calls or real-time electronic messaging.7) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein a caller within a B2C call comprises one from a group comprising a corporate, commercial, organisation, institutionrepresentative, agent or service provide.8) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein a called party within a business to consumer (B2C) call comprises a consumer.9) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 7 and Claim 8, wherein a caller or a called party further comprises participants within one from a group comprising consumer to business (C2B), business to business (B2B) and consumer to consumer(C2C) calls.10) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the step of selecting party to be called comprises selection by system.11) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 10, wherein the step of selecting party to be called further comprises selection by caller.12) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the step of requesting comprises request being made by system.13) Provides a method of authenticating the identity oftelephone, internet and doorstep callers as claimedin Claim 12, wherein the step of requesting further comprises request being made by user.14) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 12 and Claim 13, wherein the step of requesting further comprises requests continuing to be made throughout duration of call.15) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the step of caller identity verification comprises verification by system.16) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 15, wherein the step of caller identity verification further comprises verification user.17) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein one-time password comprises real-time editable presentation.18) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 17, wherein one-time password presentation further comprises additional information.19) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 17 and Claim 18, wherein one-time passwordpresentation additional information comprises one or more from a group comprising further identification information, non-identification information and data.20) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the method comprises additional features.21) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claims 20, wherein additional features comprise one or more from a group comprising permission, contact lists, look up, answering service and call barring.22) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein a user has real-time control over features within the method.23) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 22, wherein real-time user control further comprises control over one or more features from a group comprising called party selection, requests, timescale, verification, one-time password presentations, one-time password displays, customisation and personalisation, additional information and data, interactivity, editing and programming.24) Provides a method of authenticating the identity oftelephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the method comprises permissions.25) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 25, wherein permissions comprise permission from users .26) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein method comprises one or more from a group comprising onetime password generator, validator, scanner or reader.27) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein method comprises one-time password being combined with or incorporated into one or more from the following existing caller identification or user profile or one-time and single password systems.Amendments to the Claims have been filed as follows:Claims1) According to the present invention there is provided a method for authenticating the identity of corporate, commercial, organisation and institution telephone, internet and doorstep callers using time based onetime passwords (TOTP) and additional information requests, the method comprising the steps of:1) Registered caller selects consumer to be called;2) System verifies consumer is registered;3) Prior to or after call being initiated system generates TOTP unique to caller and consumer selected to be called;4) Caller initiates call to consumer;5) Prior to or after call being answered or access being gained consumer or system on behalf of consumer requests caller to authenticate their identity by accurately providing unique TOTP and or additional verified and or verifiable information and or data;6) On requested TOTP and or verified and or verifiable information and or data being received and verified by consumer or system on behalf of consumer consumer answers call or rejects call or continues with call or discontinues call or allows access or denies access .2) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 1, wherein TOTP comprises being generated fromone or more from a group comprising a shared secret or unique ID code or secure key or numeric or alphanumeric characters, coloured characters, graphics, QR codes or biometrics .3) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 1 and Claim 2, wherein TOTP further comprises being generated for caller and called party combined or caller and or called party separately.4) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 1 to Claim 3, wherein access to called party and caller combined or separate TOTP comprises permission being required from called party and or caller or system on behalf of called party and or caller.5) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein TOTP further comprises real-time editable presentations.6) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 5, wherein TOTP real-time editable presentations further comprises additional information from a group comprising identification information and or nonidentification information and or data.7) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the step ofrequesting verified and or verifiable information and or data or other information and or data comprises request being from called party and or caller or from system on behalf of called party and or caller.8) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 7, wherein the step of requesting verified and or verifiable information and or data or other information and or data further comprises requests continuing throughout duration of call.9) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the step of verifying information is carried out by called party and or caller or system on behalf of called party and or caller.10) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the step of accessing verified and or verifiable information and or data comprises one-time permission being required from called party and or caller or system on behalf of called party and or caller.11) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the sending receiving presenting and or verifying of requested information and or data by called party and or caller or system on behalf of called party and or callercontinues throughout the duration of call.12) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein the method comprises additional features.13) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed Claim 12, wherein method further comprises real-time control over additional features by called party and or caller or system on behalf of called party and or caller.14) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 12 and Claim 13, wherein real-time control over additional features by called party and or caller or system on behalf of called party and or caller further comprises control over one or more features from a group comprising called party selection, permissions, contact lists, look ups, answering service and call barring, requests, timescales, verifications, TOTP presentations and displays, customisation and personalisation, information and data selection, security levels, datastore and or database access, editing and programming.15) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in Claim 12 to Claim 14, wherein selected information and or data and or features is interactive.16) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein a caller and or a called party or system on behalf of caller and or called party further comprises participants within one from a group comprising business to business (B2B), consumer to business (C2B), and consumer to consumer(C2C) calls.17) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein a user holds multiple accounts comprising holding one or more accounts with a group comprising corporates, commercials, organisations, institutions or other entities .18) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein method comprises corporate, commercial, organisation, institution and personal data stores and or databases accessible by called party and or caller or system on behalf of called party and or caller.19) Provides a method of authenticating the identity of telephone, internet and doorstep callers as claimed in any of the preceding Claims, wherein method comprises method being combined with or incorporated into one or more from a group comprising existing caller identification, user profile, single password and one-time password systems.

Citation Information

Patent Citations

  • Methods, apparatus and devices for authenticating a call session

    US20180103144A1

  • Method and system for detecting phishing calls using one-time password

    US9942752B1