Caller ID Spoofing Detection via Certification Data Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for filtering unsolicited electronic communications, such as telephone calls, are ineffective due to the ease with which call centers can change their caller identities using virtual numbers, leading to inconveniences for users and reduced turnover for telecommunications operators.

Innovation Solution

A method that determines whether the identifier transmitted during a communication has been usurped by comparing certification data from the signaling protocol with stored certification data, ensuring the caller's identity is authentic and preventing identity theft, which is implemented on a server or device within the communication network, allowing for automated processing without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If call centers use virtual numbers to change caller identities, then it becomes easier to avoid filtering systems, but it becomes more difficult to verify authentic caller identities

Engineering Contradiction:
Improveability to change caller identityVSAvoidcaller identity verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a certification data intermediary that acts as a mediator between the caller and the filtering system. Instead of directly verifying caller identities, the system uses certification data (such as digital certificates or authentication tokens) as an intermediary proof of identity. This intermediary mechanism allows the system to verify authentic identities even when callers use virtual numbers, as the certification data provides a trusted chain of verification that cannot be easily forged or changed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional filtering systems block calls based on blacklisted numbers, then some unwanted calls are filtered, but call centers can easily evade filtering by changing their caller ID

Engineering Contradiction:
Improvecall filtering effectivenessVSAvoidcaller ID changeability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by verifying and certifying caller identities before the actual call takes place. The certification data is obtained and validated in advance, during the call setup phase, rather than relying on post-hoc blacklisting. This preliminary verification ensures that only authenticated callers can establish connections, preventing call centers from evading filters by changing their caller ID during or between calls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring and validating caller certification data throughout the communication process. The filtering system receives feedback about the authenticity of caller identities through certification verification, allowing it to dynamically adjust its filtering decisions. This feedback loop ensures that even if call centers attempt to change their caller ID, the system can detect the lack of valid certification and block the call accordingly.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If users manually configure blacklist lists, then some control over unwanted calls is achieved, but the blacklists become outdated as call centers change their numbers

Engineering Contradiction:
Improveuser control over filteringVSAvoidblacklist currency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service by automating the certification verification process, eliminating the need for users to manually maintain blacklists. The system automatically obtains, validates, and checks certification data for incoming calls without user intervention. This self-service mechanism ensures that the filtering remains reliable and up-to-date, as the system continuously verifies caller identities against current certification data rather than relying on static, manually updated blacklists.

Inventive Principle:
Principle #25Self-service

4Reliability

If voice identification is requested before call connection, then caller verification is improved, but connection time increases and callers may hang up

Engineering Contradiction:
Improvecaller verification accuracyVSAvoidcall connection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing certification verification during the call setup phase, before the actual communication begins. The certification data is obtained and validated in advance, during the signaling exchange, so that by the time the call is connected, verification is already complete. This eliminates the need for post-connection voice identification delays, as the authentication happens automatically and preliminarily during call establishment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3754956B1Method, device and computer program for detecting manipulation of the caller id
Publication Date: 2022.08.24 ORANGE SA
  • EP3754956B1 patent drawingFigure 1~2
  • EP3754956B1 patent drawingFigure 3~4

AI summary

The invention relates to a method for determining the spoofing of at least one identifier, said identifier being intended for use in a means of communication, during communication between a first and a second terminal, said method being implemented by a device for determining the spoofing of at least one identifier, and characterized in that the method comprises: - a step of receiving a communication signaling message from said first terminal to said second terminal comprising said at least one identifier and at least one first certification data point, - a step of obtaining at least one second certification data point based on said at least one identifier received, - a step of comparing said at least one first certification data point with said at least one second certification data point, - a transmission step, based on the result of the comparison.of at least the said message to the said second terminal.