Call Authentication System Using Shared Secret Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Caller ID spoofing and man-in-the-middle attacks are prevalent in IP Telephony, making it difficult to authenticate callers and verify their identity, particularly in financial and banking sectors, where attacks like 'Vishing' can lead to theft of financial assets.

Innovation Solution

A system and method for authenticating calls using a shared secret encryption key to verify the caller identification and called number, combined with voice biometric authentication to ensure the legitimacy of the caller, which can be implemented on both smartphones and traditional phones, reducing user experience impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Caller ID is delivered by telecommunication operators in traditional phone systems, then Caller ID authenticity is maintained and spoofing is difficult, but with IP Telephony, Caller ID can be easily spoofed using freely available tools and techniques

Engineering Contradiction:
ImproveCaller ID authenticityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication system that acts as a mediator between the calling device and the called device. This intermediary verifies the authenticity of the Caller ID by checking it against authenticated caller information stored in the system, thereby preventing spoofing without requiring complex changes to the existing telecommunication infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication of caller information before the call is connected. Caller information is authenticated and stored in advance, and this pre-authenticated information is then used to verify the Caller ID during the actual call, preventing spoofing attacks before they can succeed.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If Caller ID spoofing and man-in-the-middle attacks are allowed in IP Telephony, then geographic independence and accessibility are improved, but financial security and caller verification are compromised

Engineering Contradiction:
Improvegeographic independenceVSAvoidfinancial security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback mechanisms where the authentication status of caller information is continuously verified and communicated. The intermediary system checks Caller ID against authenticated information and provides feedback to the called device about the authenticity of the caller, enabling informed decisions about call acceptance while maintaining geographic independence.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent segments the authentication process into separate components: an intermediary authentication system, local authentication databases, and verification protocols at the called device. This segmentation allows the system to maintain security controls without restricting geographic accessibility, as each component operates independently but cooperatively.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If robust authentication systems are implemented to prevent Caller ID spoofing, then caller verification accuracy is improved, but user experience and call setup time may be degraded

Engineering Contradiction:
Improvecaller verification accuracyVSAvoidcall setup time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs authentication actions in advance by pre-authenticating caller information and storing it in the intermediary system. When a call is initiated, the verification process is streamlined by comparing the Caller ID against this pre-authenticated information, maintaining high verification accuracy while minimizing the time added to call setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial authentication where the system verifies only the critical elements of caller identity (Caller ID against authenticated caller information) rather than performing exhaustive verification of all possible identity attributes. This partial action maintains sufficient verification accuracy while reducing the time penalty for authentication.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9961197B2System, method and apparatus for authenticating calls
Publication Date: 2018.05.01 ARLINGTON TECHNOLOGIES LLC
  • US9961197B2 patent drawing
  • US9961197B2 patent drawing
  • US9961197B2 patent drawing

AI summary

The present invention provides a system, method and apparatus for authenticating calls that is a robust Anti-vishing solution. The present invention can identify Caller ID spoofing, verify dialed number to detect man-in-the middle and verify called party against dialed digits to detect impersonation. This solution can handle calls coming from any phone any where with little impact on user experience. Two separate solutions are tailored for smart phones (communication devices capable of running application software) and traditional phones to reduce the impact to user experience while providing robust verification.