Cloud Call Authentication Service for Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current call authentication methods, particularly Knowledge-Based Authentication (KBA), are time-consuming, undesirable for customers, and ineffective in preventing sophisticated fraud attacks such as Account Takeover, Social Engineering, Telephony Denial of Service, Robocalls, and Harassing calls, due to spoofing and lack of effective authentication.

Innovation Solution

A cloud-based Call Authentication Service (CAS) and Customer-Premise Equipment (CPE) solution that uses a combination of proprietary, third-party, and standards-based approaches to provide real-time authentication scores, integrating with existing systems for Multi-Factor Authentication, and leveraging new techniques like STIR/SHAKEN for enhanced security without requiring changes to premise equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Knowledge-Based Authentication (KBA) is used, then authentication can be performed, but it is time-consuming and wastes agent time

Engineering Contradiction:
Improveauthentication effectivenessVSAvoidagent time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication analysis before the call is fully processed by routing calls through an authentication service that evaluates multiple data sources (carrier information, device identifiers, call patterns, blacklist/whitelist databases) in advance, providing an authentication score that enables agents to quickly assess call legitimacy without time-consuming manual verification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An authentication service acts as an intermediary between the contact center and callers, automatically analyzing call data and providing authentication assessments to agents, thereby eliminating the need for agents to manually perform time-consuming verification tasks while maintaining reliable authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional authentication methods are used, then authentication can be performed, but they are not effective in fighting sophisticated fraud attacks

Engineering Contradiction:
Improveauthentication effectivenessVSAvoidfraud attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system combines multiple authentication approaches into a composite solution that integrates carrier-provided data (STIR/SHAKEN verification, device identifiers), device-based authentication (IMEI, serial numbers), call pattern analysis, and blacklist/whitelist databases to create a multi-layered defense against sophisticated fraud attacks including account takeover, social engineering, and robocalls

Inventive Principle:
Principle #40Composite materials

Solution Approach 2:

The system dynamically changes authentication parameters by selecting different verification methods and data sources based on the specific call context, risk level, and available information, allowing flexible adaptation to various fraud types while maintaining effective authentication

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If cloud-based authentication service is implemented, then flexibility and cost-effectiveness improve, but system complexity increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system extracts authentication logic and data processing functions from the contact center infrastructure and relocates them to a cloud-based authentication service, allowing the contact center to maintain simple existing systems while gaining access to sophisticated authentication capabilities through standardized API interfaces

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11647114B2Call authentication service systems and methods
Publication Date: 2023.05.09 SECURELOGIX CORP
  • US11647114B2 patent drawing
  • US11647114B2 patent drawing
  • US11647114B2 patent drawing

AI summary

A system for authenticating the calling device used to place a call to an enterprise call center. The system uses a premise component, a cloud-based Call Authentication Service (CAS), and orchestration between these two components. The premise component includes a number of sub-components including servers and probes. The CAS includes a Decision Engine that utilizes a number and variety of authentication plugins. The disclosed system may be used independently or as part of a multi-factor authentication strategy with other techniques such as reduced Knowledge-Based Authentication or voice biometrics.