Bi-directional Authentication for Spoofed Voice Calls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective measures to secure and authenticate telephonic audio communications, making them vulnerable to scams and phishing attacks, especially those that spoof trusted voices.

Innovation Solution

A cloud-based telephonic security service that implements bi-directional multifactor authentication for both calling and receiving parties, embedding digital signatures and metadata for contextual awareness and secure call channel establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital signature and metadata embedding are implemented in telephonic communication, then security and authentication are improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based security service as an intermediary between calling and receiving parties. This service handles the complex tasks of generating digital signatures, embedding metadata, and verifying authentication, thereby improving security without significantly increasing the complexity of end-user devices. The security service acts as a mediator that manages the cryptographic operations and protocol enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security-critical functions (digital signature generation, metadata embedding, authentication verification) from the traditional telephony system and places them in a dedicated security service. This separation allows the core telephony system to remain relatively simple while the extracted security functions provide enhanced protection against spoofing and phishing attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If bi-directional multifactor authentication is implemented for both calling and receiving parties, then reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidcalling convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary actions by requiring both parties to authenticate before the call is established. The security service verifies identities, generates digital signatures, and embeds metadata in advance of the actual communication. This preliminary authentication ensures reliability while automating the process to minimize user burden during the actual calling operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback to users about the authentication status and call security. The security service communicates authentication results, digital signature verification status, and metadata validation to both parties, enabling them to make informed decisions about whether to proceed with the call. This feedback mechanism maintains ease of operation by providing clear guidance without requiring users to understand the underlying complex authentication processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12317076B2Authenticated secure audio calling and digitally signed metadata for integrity verification
Publication Date: 2025.05.27 CISCO TECHNOLOGY INC
  • US12317076B2 patent drawing
  • US12317076B2 patent drawing
  • US12317076B2 patent drawing

AI summary

Techniques are described for providing secure audio calls between a calling party and a receiving party. Upon receiving a call request from a call initiating party, a notification is sent to the intended call recipient. The call recipient can send a request for a secure call. Upon receiving the request for a secure call, a bi-directional multifactor authentication is performed to authenticate the identity of both the call initiating party and the call receiving party. In response to successfully authenticating both parties, a secure call between the parties is established. One or more secure key tokens or other metadata can be embedded in the call to ensure security of the call.