Caller Authentication Across PSTN and VoIP Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in authenticating callers using public key infrastructure (PKI) when different interfaces or protocols are involved, particularly in scenarios where both Internet and analog telephone networks coexist, limiting the applicability of PKI-based authentication.
Innovation Solution
The method generates identifiers based on identification numbers for both caller and callee terminals, creates digital signatures, encrypts information, and transmits these through a server for authentication, allowing for secure authentication even across different VoIP protocols and networks by using a combination of outgoing and incoming numbers as authentication tags.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PKI-based authentication is applied in VoIP systems, then authentication security is improved, but compatibility across different protocols and interfaces deteriorates
Solution Approach 1:
The patent introduces a gateway as an intermediary component that bridges different communication protocols (PSTN and VoIP). The gateway performs protocol conversion and PKI authentication, allowing terminals using different protocols to authenticate securely without requiring all parties to use the same protocol. This resolves the contradiction by enabling PKI-based security while maintaining multi-protocol compatibility through the gateway's mediation.
Solution Approach 2:
The authentication server is designed to handle multiple authentication scenarios universally - it can authenticate terminals from both PSTN and VoIP networks, support different call types (direct, relayed, conference), and work with various terminal types. This universal authentication mechanism maintains security across diverse protocols while improving adaptability.
2Ease of operation
If authentication procedures are simplified for easier operation, then ease of operation is improved, but authentication reliability deteriorates
Solution Approach 1:
The authentication system operates autonomously without requiring manual intervention. Terminals automatically generate authentication messages containing their identification numbers, the server automatically verifies credentials against stored data, and the system automatically establishes secure connections. This self-service mechanism maintains high authentication reliability through automated verification while improving ease of operation by eliminating manual authentication steps.
3Reliability
If multiple authentication messages are processed to ensure security, then authentication reliability is improved, but processing time increases
Solution Approach 1:
The server pre-stores authentication information (public keys, terminal data) in a database before actual authentication occurs. When authentication is needed, the server retrieves pre-stored data rather than generating it in real-time, and automatically generates authentication messages based on pre-configured protocols. This preliminary preparation reduces processing time during actual authentication while maintaining security through comprehensive verification.
Solution Approach 2:
The authentication system implements feedback mechanisms where terminals receive authentication results and can retransmit messages if needed. The server provides feedback on authentication status, allowing for efficient error handling and retry logic that reduces overall processing time compared to blind retransmission approaches.
Data Source
AI summary
The present disclosure relates to an apparatus and a method for authenticating a caller in a communication system. An operating method of a terminal for authenticating a caller may comprise the steps of: generating an identifier and information corresponding to the identifier, on the basis of an identification number related to the terminal and an identification number related to another terminal; generating a digital signature for the information; encrypting the information; and transmitting, to a server, a message including the identifier, the digital signature, and the encrypted information.


