CTI Terminal Identity Abstraction for Secure Third-Party Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer telephony integration (CTI) systems, especially in call centers, there is a risk of incorrect association between a communications terminal and a computer terminal, leading to security vulnerabilities when using third-party systems like Microsoft Live Communications Server (LCS), where users can inadvertently or maliciously control the wrong communications equipment due to lack of secure identity management.

Innovation Solution

A method and system for securely registering an association between a computer terminal and a communications terminal by generating an abstract representation of the terminal's identity, which is used within the CTI system but remains unintelligible outside, ensuring only authorized access and control via a third-party system, using a registration server that replaces the actual directory number with a representative value stored securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the actual directory number is stored and transmitted in third-party systems, then the system can directly control the communications terminal, but security is compromised because the third-party system can inadvertently or maliciously change the terminal allocation

Engineering Contradiction:
ImprovesecurityVSAvoididentity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates an abstract representation (a secure copy) of the communications terminal identity that can be stored and transmitted to third-party systems. This copy contains all necessary control information but cannot be reverse-engineered to reveal the actual directory number, thus protecting the original terminal allocation while enabling third-party control functionality.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The abstract representation acts as an intermediary between the CTI system and third-party systems. It transfers control capabilities to third-party systems without exposing the actual terminal identity, serving as a secure mediator that enables communication and control while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If an abstract representation of the terminal identity is generated and stored securely, then security is enhanced by preventing unauthorized changes, but the system requires additional security infrastructure

Engineering Contradiction:
Improvesystem integrityVSAvoidsecurity infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the terminal identity from its original form (actual directory number) into an abstract representation with different parameters - it retains the essential control functionality but changes the form to be unintelligible outside the CTI system, thereby enhancing security without requiring complex additional infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If the third-party system has access to the actual directory number, then control of communications terminal is straightforward, but the system becomes vulnerable to malicious misuse

Engineering Contradiction:
Improveterminal controlVSAvoidmalicious misuse risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The abstract representation serves as a functional copy that enables third-party systems to control communications terminals without exposing the actual directory number. This copy provides all necessary control capabilities while eliminating the risk of malicious misuse associated with having access to real terminal identities.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8842557B2Computer telephony system
Publication Date: 2014.09.23 BRITISH TELECOM PLC
  • US8842557B2 patent drawing
  • US8842557B2 patent drawing
  • US8842557B2 patent drawing

AI summary

A method and apparatus for securely registering an association between a computer terminal and a selected one of a plurality of communications terminals in a computer telephony system. An association is established according to a known technique between the identity of the selected communications terminal and the identity of the computer terminal to allow for control of the communications terminal by a user via the computer terminal. An abstract representation of the identity of the communications terminal is; generated and provided to a third party system accessible by the user. The user can then implement control of the selected communications terminal via the third party system whilst not prejudicing the security of the system.