Mobile Device Voice Channel Authentication via Data-Generated Tones
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for mobile devices over voice channels are insecure, prone to eavesdropping, and lack confidence in identifying devices accessing voice services, particularly in corporate settings where sensitive information and toll charges are at risk.
Innovation Solution
A system where a mobile device requests an authentication token over a data channel, which is then presented as a series of audible tones on the voice channel for authentication, using a database of issued tokens to verify authenticity, ensuring conditional access to voice services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If caller ID information is used for authentication over voice channels, then device identification is simplified, but security is compromised due to spoofing and unavailability
Solution Approach 1:
The patent introduces an authentication token as an intermediary element that bridges the gap between voice channel communication and secure authentication. The token is generated over a secure data channel and then transmitted over the voice channel, serving as a mediator that provides both security and compatibility with voice communication limitations
Solution Approach 2:
The authentication token is generated and prepared in advance over a secure data channel before being used for voice channel authentication. This preliminary action ensures that the authentication credentials are established through a secure pathway before being deployed in the less secure voice environment
2Adaptability or versatility
If voice channels are used for authentication, then compatibility with existing voice services is maintained, but security is weakened due to eavesdropping and interception risks
Solution Approach 1:
The authentication process is segmented into two distinct phases: secure token generation over a data channel and token verification over the voice channel. This segmentation allows each phase to operate in its optimal security environment while maintaining overall system compatibility
Solution Approach 2:
The authentication token serves as a secure intermediary that carries authentication credentials through the insecure voice channel without exposing sensitive information. The token encapsulates necessary authentication data in a form that is secure for voice transmission
3Ease of operation
If conference call numbers are distributed with meeting invitations, then user access is simplified, but unauthorized access increases due to interception and capture
Solution Approach 1:
The authentication token is generated and distributed in advance through secure data channels before the voice conference takes place. This preliminary secure distribution ensures that only authorized participants receive valid tokens, preventing later interception and unauthorized access
Solution Approach 2:
The authentication mechanism changes the parameter of access control from static conference numbers to dynamic authentication tokens. This parameter change transforms the security model from vulnerable number-based access to secure token-based verification
Data Source
AI summary
Mobile devices are authorized to access PBX-based voice services through presentation of audible tones on a voice channel, which are determined based on a code received over a separate data channel. The device can request a code over a data channel from a server in communication with the PBX. The server provides data representative of the code over the data channel to the device, and arranges for local storage of the code. The device makes a connection with the PBX over a separate voice channel. The mobile device presents the received code as a sequence of audio tones (e.g., DTMF tones). The audio tones are used to generate data that can be compared with stored codes by an authentication module. The authorization module can indicate to the PBX that the code is valid; services can be provided by the PBX in response. The valid codes can be maintained, such as by removing used codes from code storage.


