Call Authentication System Using Shared Secret Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Caller ID spoofing and man-in-the-middle attacks are prevalent in IP Telephony, making it difficult to authenticate callers and verify their identity, particularly in financial and banking sectors, where attacks like 'Vishing' can lead to theft of financial assets.
Innovation Solution
A system and method for authenticating calls using a shared secret encryption key to verify the caller identification and called number, combined with voice biometric authentication to ensure the legitimacy of the caller, which can be implemented on both smartphones and traditional phones, reducing user experience impact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Caller ID is delivered by telecommunication operators in traditional phone systems, then Caller ID authenticity is maintained and spoofing is difficult, but with IP Telephony, Caller ID can be easily spoofed using freely available tools and techniques
Solution Approach 1:
The patent introduces an intermediary authentication system that acts as a mediator between the calling device and the called device. This intermediary verifies the authenticity of the Caller ID by checking it against authenticated caller information stored in the system, thereby preventing spoofing without requiring complex changes to the existing telecommunication infrastructure.
Solution Approach 2:
The system performs preliminary authentication of caller information before the call is connected. Caller information is authenticated and stored in advance, and this pre-authenticated information is then used to verify the Caller ID during the actual call, preventing spoofing attacks before they can succeed.
2Adaptability or versatility
If Caller ID spoofing and man-in-the-middle attacks are allowed in IP Telephony, then geographic independence and accessibility are improved, but financial security and caller verification are compromised
Solution Approach 1:
The system implements feedback mechanisms where the authentication status of caller information is continuously verified and communicated. The intermediary system checks Caller ID against authenticated information and provides feedback to the called device about the authenticity of the caller, enabling informed decisions about call acceptance while maintaining geographic independence.
Solution Approach 2:
The patent segments the authentication process into separate components: an intermediary authentication system, local authentication databases, and verification protocols at the called device. This segmentation allows the system to maintain security controls without restricting geographic accessibility, as each component operates independently but cooperatively.
3Measurement precision
If robust authentication systems are implemented to prevent Caller ID spoofing, then caller verification accuracy is improved, but user experience and call setup time may be degraded
Solution Approach 1:
The system performs authentication actions in advance by pre-authenticating caller information and storing it in the intermediary system. When a call is initiated, the verification process is streamlined by comparing the Caller ID against this pre-authenticated information, maintaining high verification accuracy while minimizing the time added to call setup.
Solution Approach 2:
The patent implements partial authentication where the system verifies only the critical elements of caller identity (Caller ID against authenticated caller information) rather than performing exhaustive verification of all possible identity attributes. This partial action maintains sufficient verification accuracy while reducing the time penalty for authentication.
Data Source
AI summary
The present invention provides a system, method and apparatus for authenticating calls that is a robust Anti-vishing solution. The present invention can identify Caller ID spoofing, verify dialed number to detect man-in-the middle and verify called party against dialed digits to detect impersonation. This solution can handle calls coming from any phone any where with little impact on user experience. Two separate solutions are tailored for smart phones (communication devices capable of running application software) and traditional phones to reduce the impact to user experience while providing robust verification.


