Call Center Authentication via Inverted Call Initiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Call centers face challenges in authenticating users and devices during voice calls, as existing methods rely on basic information that can be easily compromised, leading to potential fraud and unauthorized access.
Innovation Solution
Implementing a system where a user's device, under the control of the call center or associated organization, uses an application for authentication, and Voice Over IP (VOIP) calls are configured to provide hardware attributes and IP addresses for verification, with the call center initiating the call to ensure a 'bound' device is used, thereby controlling the call and preventing identity spoofing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the call center uses basic authentication information (account number, phone number, address), then the authentication process is simple and fast, but the security is weak and vulnerable to fraud
Solution Approach 1:
The system performs preliminary authentication by having the caller initiate a call to a verified short code, which pre-establishes the caller's identity and device binding before the actual customer service interaction begins. This preliminary action ensures that only authenticated users can access the call center system.
Solution Approach 2:
The patent introduces an intermediary authentication system that acts as a mediator between the caller and the call center. This intermediary system verifies the caller's identity through multiple factors (device binding, short code verification, biometric authentication) before allowing connection to the call center, thereby enhancing security without compromising the user experience.
2Ease of operation
If the caller initiates the call to the call center, then the caller has control over the call timing, but the call center cannot verify the authenticity of the incoming call
Solution Approach 1:
Instead of the traditional model where the caller initiates the call to the call center, the patent inverts the approach by having the call center initiate the call to a verified short code that the caller controls. This inversion allows the call center to verify authenticity while maintaining caller control over the communication channel.
Solution Approach 2:
The system implements feedback mechanisms where the call center receives verification information from the short code system about the caller's authenticity. This feedback loop allows the call center to make informed decisions about call handling while the caller maintains control through the verified communication channel.
3Reliability
If the system implements strict authentication and call control measures, then security is enhanced, but the device complexity and operational constraints increase
Solution Approach 1:
The system employs self-service mechanisms where the caller's mobile device automatically performs authentication functions through pre-configured short code bindings. The device itself verifies its identity and maintains security credentials, reducing the complexity burden on the call center system while maintaining high security standards.
Solution Approach 2:
The patent creates a universal authentication framework that can be applied across multiple call center systems and platforms. The short code binding mechanism serves multiple functions including authentication, verification, and secure communication establishment, thereby reducing overall system complexity through multi-functionality.
Data Source
AI summary
This disclosure describes techniques for authenticating a person that seeks to engage in a voice call session with a call center agent, an interactive voice response system, or other system. In one example, this disclosure describes a method that includes storing information associating an authorized device with an account; receiving, over a network and from a device operated by a user, authentication credentials for the user; determining, based on the authentication credentials, that the user is authorized to access the account; receiving, over the network and from the device operated by the user, a request to engage in a voice conversation; responsive to receiving the request, accessing the phone number associated with the authorized device; and initiating a voice call session by placing a call, over the network, to the phone number associated with the authorized device.


