Mobile Device Voice Authentication via Data Channel Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for mobile devices over voice channels are insecure, prone to eavesdropping, and lack effective identification, allowing unauthorized access to sensitive voice services, particularly in corporate settings where privacy and confidentiality are concerns.

Innovation Solution

A system that uses authentication tokens issued over a data channel for verification on voice channels, ensuring unique tokens are used once and securely transmitted, either through data channels or as audible tones, to authenticate mobile devices accessing PBX services, employing robust encryption and secure data channels to prevent interception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If authentication tokens are transmitted over voice channels as audible tones, then mobile devices can be authenticated without requiring data channel connectivity, but the authentication process becomes vulnerable to eavesdropping and interception

Engineering Contradiction:
Improveauthentication capabilityVSAvoideavesdropping vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication over the secure data channel before voice channel authentication. The mobile device is first authenticated over the data channel, and only after successful authentication are tokens issued for voice channel use. This preliminary secure authentication prevents unauthorized devices from obtaining valid tokens in the first place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication token that bridges the secure data channel and the less secure voice channel. The token acts as a mediator that carries authentication information from the secure channel to the voice channel, allowing the system to leverage the security of the data channel while enabling voice channel functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If caller ID information is used for authentication, then the authentication process is simple and quick, but the information can be spoofed and is sometimes not available

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication over the secure data channel before voice channel authentication. The mobile device is first authenticated over the data channel, and only after successful authentication are tokens issued for voice channel use. This preliminary secure authentication prevents unauthorized devices from obtaining valid tokens in the first place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication token that bridges the secure data channel and the less secure voice channel. The token acts as a mediator that carries authentication information from the secure channel to the voice channel, allowing the system to leverage the security of the data channel while enabling voice channel functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If authentication tokens are issued over data channels, then secure transmission is achieved, but mobile devices without data channel connectivity cannot be authenticated

Engineering Contradiction:
Improveinterception preventionVSAvoiddevice compatibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The authentication process is segmented into two distinct phases: a preliminary authentication phase over the secure data channel, and a subsequent voice channel authentication phase using tokens. This segmentation allows the system to maintain security through the initial data channel authentication while enabling voice channel functionality for devices that may not have continuous data connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication over the secure data channel before voice channel authentication. The mobile device is first authenticated over the data channel, and only after successful authentication are tokens issued for voice channel use. This preliminary secure authentication prevents unauthorized devices from obtaining valid tokens in the first place.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8548432B2Authenticating voice calls from mobile devices
Publication Date: 2013.10.01 MALIKIE INNOVATIONS LTD
  • US8548432B2 patent drawing
  • US8548432B2 patent drawing
  • US8548432B2 patent drawing

AI summary

Aspects relate to authorizing mobile devices for PBX-based voice services. A mobile device calls a PBX over a voice channel, and phone number identifier information is obtained and matched to identifier information for devices that known (authorizeable) to use the PBX. If there is one incoming call that matches to a given device, and an authentication token provided over a data channel matches an authentication token associated with that device, then the device is authorized for voice services. Where there are multiple matching calls, those devices are instructed to provide authentication tokens over their voice channels. The devices can detect absence of a data channel and provide authentication tokens over the voice channels; the devices also can wait to receive a call connected response and in the absence of such provide their authentication tokens over the voice channel. Tokens can be requested and downloaded for storage at the devices.