Co-located Security Device for Communication Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication validation methods, such as STIR/SHAKEN, fail to effectively identify and prevent spoofed communications, including robocalls, as they do not validate the sender's identity or detect impersonation, leading to malicious efforts reaching recipients.

Innovation Solution

A method involving a co-located security device that generates and transmits a security token to authenticate communications, ensuring the recipient can validate the communication's origin, using a system comprising a smart device, security device, authentication server, and recipient device to endorse communications as genuine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing communication validation methods (STIR/SHAKEN) are used, then some communication security is provided, but the sender's identity cannot be validated and spoofed communications cannot be detected

Engineering Contradiction:
Improvecommunication validation reliabilityVSAvoidspoofed communications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a co-located security device as an intermediary component that receives a security token from the authentication server and incorporates it into the communication. This security device acts as a mediator between the sender and the communication validation process, enabling identity verification without requiring the sender themselves to perform complex authentication operations. The security token served as the intermediary credential that links the sender's identity to the communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server performs preliminary action by issuing a security token to the co-located security device before the communication is transmitted. This preliminary authentication step establishes the sender's identity in advance, and the security token is then incorporated into the communication payload. The recipient can validate this pre-established identity, ensuring that only authenticated senders can communicate, thereby preventing spoofed communications.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a security token is incorporated into the communication for validation, then communication security is improved, but the device complexity increases

Engineering Contradiction:
Improvecommunication authenticationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The co-located security device performs self-service by automatically receiving the security token from the authentication server and incorporating it into the communication without requiring manual intervention. The system handles the authentication process autonomously, with the security device managing its own token acquisition and integration. This self-service approach simplifies the user experience while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges the security token functionality with the existing communication transmission process. The security token is incorporated into the communication payload as an integrated component rather than a separate process. This merging of authentication and communication functions reduces overall system complexity by eliminating the need for separate authentication channels and processes.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If a co-located security device is used to receive and transmit security tokens, then communication validation is enhanced, but the ease of operation decreases

Engineering Contradiction:
Improvesender identity validationVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The co-located security device performs self-service operations by automatically receiving security tokens from the authentication server and incorporating them into communications without requiring user intervention. The system handles the complex authentication process autonomously, making the user experience simple while maintaining enhanced validation capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual authentication mechanisms with an automated electronic system. Instead of requiring users to manually verify identities or enter authentication codes, the system uses electronic security tokens and automated validation processes. This substitution of mechanical/manual operations with electronic automation enhances validation reliability while simplifying user operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11658963B2Cooperative communication validation
Publication Date: 2023.05.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11658963B2 patent drawing
  • US11658963B2 patent drawing
  • US11658963B2 patent drawing

AI summary

A method, a computer program product, and a computer system transmit an authenticated communication. The method being performed by a sending device includes transmitting a request to an authentication server indicating that the authenticated communication is to be transmitted. The method includes receiving a security token from a security device that is co-located with the sending device. The security token is received by the security device from the authentication server. The method includes generating the authenticated communication by incorporating the security token in a communication. The method includes transmitting the authenticated communication to a recipient device.