Mobile Voice Authentication via Concurrent Data Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile device communications, there is no guarantee that the caller is who they claim to be, leading to security concerns when sensitive information is requested, and it is difficult for callers to verify the identity of the person answering the call.

Innovation Solution

An authentication server is used to authenticate users by sending an encrypted and signed authentication request over a data channel concurrent with a voice channel connection, utilizing public key infrastructure (PKI) or symmetric key encryption, to verify the identity of both parties and ensure message integrity and privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional voice channel communication is used without authentication, then communication simplicity is maintained, but security and identity verification are compromised

Engineering Contradiction:
Improveidentity verificationVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary between users to verify identities. The server receives authentication requests, validates credentials, and provides verification results, thereby enabling secure communication without requiring complex authentication mechanisms in each user device

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into separate functional components: user devices for initiating authentication, an authentication server for processing verification, and integration with both voice and data channels. This segmentation allows the authentication functionality to be added without redesigning the entire communication system

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication requests are sent over data channels concurrent with voice channels, then identity verification is improved, but network resource usage and system complexity increase

Engineering Contradiction:
Improvemessage integrityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges the authentication process with the existing voice call setup procedure. The authentication request is sent concurrently with voice channel establishment using available data channels, combining identity verification with the normal call setup flow to avoid separate authentication procedures

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system utilizes existing data channels and network infrastructure to carry authentication requests, rather than requiring dedicated authentication resources. The authentication leverages the already-established communication pathways between devices

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9848328B2User authentication in a mobile environment
Publication Date: 2017.12.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9848328B2 patent drawing
  • US9848328B2 patent drawing
  • US9848328B2 patent drawing

AI summary

A data channel transmission can be used to authenticate a voice channel transmission. An authentication server can authenticate the identity of one or more parties to a call where at least one of the parties to the call is using a mobile device. A PKI authentication methodology or other symmetric or asymmetric encryption/decryption methodology can be used in a mobile network environment to identify and authenticate a first user to a second user. The authentication request sent to the third party trusted server can be encrypted, signed and transmitted over a data channel (such as an internet connection or SMS or MMS connection), concurrent with the voice channel transmission. In response to validation by the third party trusted server, the third party trusted server can send an authentication indication to the second user's device, which can display identification information and other (optional) data associated with the first user.