Mobile Device Voice Authentication via Data Channel Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for mobile devices over voice channels are insecure, prone to eavesdropping, and lack effective identification, allowing unauthorized access to sensitive voice services, particularly in corporate settings where privacy and confidentiality are concerns.
Innovation Solution
A system that uses authentication tokens issued over a data channel for verification on voice channels, ensuring unique tokens are used once and securely transmitted, either through data channels or as audible tones, to authenticate mobile devices accessing PBX services, employing robust encryption and secure data channels to prevent interception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If authentication tokens are transmitted over voice channels as audible tones, then mobile devices can be authenticated without requiring data channel connectivity, but the authentication process becomes vulnerable to eavesdropping and interception
Solution Approach 1:
The system performs preliminary authentication over the secure data channel before voice channel authentication. The mobile device is first authenticated over the data channel, and only after successful authentication are tokens issued for voice channel use. This preliminary secure authentication prevents unauthorized devices from obtaining valid tokens in the first place.
Solution Approach 2:
The patent introduces an intermediary authentication token that bridges the secure data channel and the less secure voice channel. The token acts as a mediator that carries authentication information from the secure channel to the voice channel, allowing the system to leverage the security of the data channel while enabling voice channel functionality.
2Ease of operation
If caller ID information is used for authentication, then the authentication process is simple and quick, but the information can be spoofed and is sometimes not available
Solution Approach 1:
The system performs preliminary authentication over the secure data channel before voice channel authentication. The mobile device is first authenticated over the data channel, and only after successful authentication are tokens issued for voice channel use. This preliminary secure authentication prevents unauthorized devices from obtaining valid tokens in the first place.
Solution Approach 2:
The patent introduces an intermediary authentication token that bridges the secure data channel and the less secure voice channel. The token acts as a mediator that carries authentication information from the secure channel to the voice channel, allowing the system to leverage the security of the data channel while enabling voice channel functionality.
3Object-affected harmful factors
If authentication tokens are issued over data channels, then secure transmission is achieved, but mobile devices without data channel connectivity cannot be authenticated
Solution Approach 1:
The authentication process is segmented into two distinct phases: a preliminary authentication phase over the secure data channel, and a subsequent voice channel authentication phase using tokens. This segmentation allows the system to maintain security through the initial data channel authentication while enabling voice channel functionality for devices that may not have continuous data connectivity.
Solution Approach 2:
The system performs preliminary authentication over the secure data channel before voice channel authentication. The mobile device is first authenticated over the data channel, and only after successful authentication are tokens issued for voice channel use. This preliminary secure authentication prevents unauthorized devices from obtaining valid tokens in the first place.
Data Source
AI summary
Aspects relate to authorizing mobile devices for PBX-based voice services. A mobile device calls a PBX over a voice channel, and phone number identifier information is obtained and matched to identifier information for devices that known (authorizeable) to use the PBX. If there is one incoming call that matches to a given device, and an authentication token provided over a data channel matches an authentication token associated with that device, then the device is authorized for voice services. Where there are multiple matching calls, those devices are instructed to provide authentication tokens over their voice channels. The devices can detect absence of a data channel and provide authentication tokens over the voice channels; the devices also can wait to receive a call connected response and in the absence of such provide their authentication tokens over the voice channel. Tokens can be requested and downloaded for storage at the devices.


