Inbound Call Authentication for Inmate Communication Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Controlled-environment facilities, such as prisons, typically only allow outgoing calls from inmates, making it impractical for inmates to receive inbound calls due to the lack of infrastructure to properly direct and authenticate incoming calls.

Innovation Solution

Implementing an inbound resident call server system that authenticates non-resident callers and connects them to inmate media and communications devices, using a central phone number and multilayer authentication processes, including PIN verification and biometric methods, to ensure secure and authorized communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional communication services only allow outbound calls from inmates, then facility security and operational simplicity are maintained, but communication accessibility and inmate connection to outside world are limited

Engineering Contradiction:
Improvecommunication accessibilityVSAvoidinfrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an inbound calling account system as an intermediary layer between external callers and inmate devices. This mediator handles authentication, call routing, and coordination without requiring direct infrastructure changes in the facility, thus enabling inbound communication while maintaining operational simplicity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the communication process into distinct functional components: external caller interface, authentication server, inmate device interface, and call coordination layer. This segmentation allows each component to operate independently with well-defined interfaces, reducing overall system complexity while enabling versatile inbound calling functionality.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If inbound calling infrastructure is implemented without authentication, then communication accessibility is improved, but facility security and authorization control are compromised

Engineering Contradiction:
Improvecommunication accessibilityVSAvoidsecurity assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication actions before allowing inbound calls to connect to inmate devices. External callers must be verified against authorized contact lists, and authentication credentials are validated in advance. This preliminary security check ensures that only authorized individuals can initiate calls, maintaining security while enabling accessible communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server implements feedback mechanisms where call authorization decisions are communicated back to both the external caller and the inmate device. The system provides real-time feedback on authentication status, call routing decisions, and connection establishment, ensuring that security protocols are properly executed while maintaining communication flow.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple authentication layers are implemented for inbound calls, then security and authorization control are improved, but call setup time and system complexity increase

Engineering Contradiction:
Improvesecurity assuranceVSAvoidcall setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication credentials and authorization data are pre-configured and stored in the authentication server before call attempts. When an inbound call is initiated, the system performs rapid lookups against pre-established authentication rules and authorized contact lists, rather than performing complex real-time verification. This preliminary preparation significantly reduces call setup time while maintaining multiple layers of security verification.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If inbound call routing to specific inmate devices is implemented, then communication precision and inmate privacy are improved, but system complexity and authentication requirements increase

Engineering Contradiction:
Improvecall routing precisionVSAvoidrouting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The authentication server acts as an intelligent intermediary that handles complex call routing logic. Instead of requiring complex routing capabilities at the inmate device level or in the facility's telephony infrastructure, the authentication server receives the inbound call, verifies authorization, and routes the call to the appropriate inmate device based on pre-configured associations between external contacts and inmate devices. This mediator approach enables precise routing while keeping the overall system simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10063698B2Inbound calls to intelligent controlled-environment facility resident media and/or communications devices
Publication Date: 2018.08.28 SECURUS TECH LLC
  • US10063698B2 patent drawing
  • US10063698B2 patent drawing
  • US10063698B2 patent drawing

AI summary

Systems and methods for inbound calls to controlled-environment facility resident media and/or communications devices may receive, via the device, data associated with the resident operating the device. Authentication of the resident operating the device may be verified as associated with an address identifier of the device and it may be confirmed that an inbound calling non-resident is associated with the address identifier. A notification of the inbound call may then be sent to the device, and the same or other data associated with the resident operating the device may be received, via the device. Authentication of the resident operating the device as a resident as associated with an address identifier may be re-verified using the same or other data and the call connected as a result of the verification, confirmation and/or re-verification.