Mobile App Call Authentication via Data Channel Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for authenticating callers to call centers are cumbersome, insecure, and susceptible to spoofing and social engineering attacks, particularly due to the untrustworthy nature of telephony channels.
Innovation Solution
A system and method that utilizes a mobile application to authenticate inbound calls to a call center by leveraging the trust built in a data channel, which includes sending requests to a registered device for authentication information and receiving responses through a data channel to authenticate the call.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional caller identification services are used to transmit caller information, then the service is easy to implement, but the information can be easily spoofed and is insecure
Solution Approach 1:
The patent introduces a mobile application as an intermediary component between the caller and the call center system. This mobile app acts as a trusted mediator that generates and transmits authentication tokens through both telephony and data channels, thereby enhancing the reliability of caller identification without significantly increasing system complexity from the call center's perspective.
Solution Approach 2:
The system performs preliminary authentication actions by requiring the caller to interact with the mobile application before the call is connected. The mobile app pre-generates authentication tokens and establishes trust credentials in advance, so that when the call is made, the authentication information is already prepared and verified, improving security without adding complexity during the actual call handling.
2Reliability
If knowledge-based questions are used to authenticate users, then the authentication method is simple to implement, but it is insecure and susceptible to social engineering attacks
Solution Approach 1:
The patent replaces the mechanical system of knowledge-based questions with a digital authentication mechanism using mobile applications and cryptographic tokens. Instead of relying on users to recall and verbalize private information, the system uses automated mobile app-based authentication that generates and verifies digital credentials, significantly improving security while maintaining ease of operation through automated processes.
Solution Approach 2:
The mobile application enables self-service authentication where the user's own mobile device generates and presents authentication credentials without requiring interaction with external authentication servers during the call process. This self-contained approach improves security by keeping sensitive authentication logic on the user's device while maintaining convenience through automated credential presentation.
3Reliability
If a mobile application with data channel communication is used for authentication, then the authentication security is improved, but the device complexity increases
Solution Approach 1:
The mobile application is designed to perform multiple functions: it serves as a communication client, authentication credential generator, and token transmitter. By consolidating these functions into a single universal application, the system improves authentication security without proportionally increasing complexity, as the same application infrastructure supports multiple capabilities.
Solution Approach 2:
The patent merges the authentication functionality with the existing mobile application ecosystem. Instead of creating a separate complex authentication system, the authentication capabilities are integrated into the mobile app that users already have installed, combining communication, authentication, and verification functions into a unified solution that reduces overall system complexity.
Data Source
AI summary
Embodiments described herein provide for automatically authenticating telephone calls to an enterprise call center. The system disclosed herein builds on the trust of a data channel for the telephony channel. Certain types of authentication information can be received through the telephony channel, as well. But the mobile application associated with the call center system may provide additional or alternative forms of data through the data channel. The system may send requests to a mobile application of a device to provide information that can reliably be assumed to be coming from that particular device, such as a state of the device and/or a user's response to push notifications. In some cases, the authentication processes may be based on quantity and quality of matches between certain metadata or attributes expected to be received from a given device as compared to the metadata or attributes received.


