Co-located Security Device for Communication Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication validation methods, such as STIR/SHAKEN, fail to effectively identify and prevent spoofed communications, including robocalls, as they do not validate the sender's identity or detect impersonation, leading to malicious efforts reaching recipients.
Innovation Solution
A method involving a co-located security device that generates and transmits a security token to authenticate communications, ensuring the recipient can validate the communication's origin, using a system comprising a smart device, security device, authentication server, and recipient device to endorse communications as genuine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing communication validation methods (STIR/SHAKEN) are used, then some communication security is provided, but the sender's identity cannot be validated and spoofed communications cannot be detected
Solution Approach 1:
The patent introduces a co-located security device as an intermediary component that receives a security token from the authentication server and incorporates it into the communication. This security device acts as a mediator between the sender and the communication validation process, enabling identity verification without requiring the sender themselves to perform complex authentication operations. The security token served as the intermediary credential that links the sender's identity to the communication.
Solution Approach 2:
The authentication server performs preliminary action by issuing a security token to the co-located security device before the communication is transmitted. This preliminary authentication step establishes the sender's identity in advance, and the security token is then incorporated into the communication payload. The recipient can validate this pre-established identity, ensuring that only authenticated senders can communicate, thereby preventing spoofed communications.
2Reliability
If a security token is incorporated into the communication for validation, then communication security is improved, but the device complexity increases
Solution Approach 1:
The co-located security device performs self-service by automatically receiving the security token from the authentication server and incorporating it into the communication without requiring manual intervention. The system handles the authentication process autonomously, with the security device managing its own token acquisition and integration. This self-service approach simplifies the user experience while maintaining security.
Solution Approach 2:
The patent merges the security token functionality with the existing communication transmission process. The security token is incorporated into the communication payload as an integrated component rather than a separate process. This merging of authentication and communication functions reduces overall system complexity by eliminating the need for separate authentication channels and processes.
3Reliability
If a co-located security device is used to receive and transmit security tokens, then communication validation is enhanced, but the ease of operation decreases
Solution Approach 1:
The co-located security device performs self-service operations by automatically receiving security tokens from the authentication server and incorporating them into communications without requiring user intervention. The system handles the complex authentication process autonomously, making the user experience simple while maintaining enhanced validation capabilities.
Solution Approach 2:
The patent replaces manual authentication mechanisms with an automated electronic system. Instead of requiring users to manually verify identities or enter authentication codes, the system uses electronic security tokens and automated validation processes. This substitution of mechanical/manual operations with electronic automation enhances validation reliability while simplifying user operations.
Data Source
AI summary
A method, a computer program product, and a computer system transmit an authenticated communication. The method being performed by a sending device includes transmitting a request to an authentication server indicating that the authenticated communication is to be transmitted. The method includes receiving a security token from a security device that is co-located with the sending device. The security token is received by the security device from the authentication server. The method includes generating the authenticated communication by incorporating the security token in a communication. The method includes transmitting the authenticated communication to a recipient device.


