Mobile Voice Encryption via SMS Whitelist Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile voice communications over IP are vulnerable to security breaches, unauthorized access, and have issues with integration into IT infrastructure due to weak encryption and reliance on pre-shared keys, leading to potential loss of revenue and regulatory non-compliance.

Innovation Solution

A system that establishes secure communication between a mobile device and a server by verifying phone numbers against a whitelist, generating and renewing encryption keys based on administrator policies, and using SMS or MMS messages to authenticate and encrypt voice communications, ensuring end-to-end encryption and secure identification codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard mobile voice communications are used, then ease of operation is improved, but security is worsened due to weak encryption and vulnerability to unauthorized access

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary encryption system that mediates between standard mobile voice communications and secure transmission. The system uses SMS/MMS messages as intermediaries to exchange encryption keys and authenticate communications, thereby enhancing security without requiring changes to the underlying mobile voice communication infrastructure. This allows standard voice calls to continue operating while adding a layer of encrypted protection through the intermediary messaging channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is strengthened to improve security, then reliability is improved, but device complexity is worsened due to key management and authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the mobile device automatically generates, manages, and renewes encryption keys without requiring manual user intervention. The system autonomously handles authentication by verifying phone numbers against whitelists and managing key lifecycle based on administrator policies. This automation reduces the perceived complexity for users while maintaining strong encryption, as the device serves itself in key management tasks.

Inventive Principle:
Principle #25Self-service

3Reliability

If end-to-end encryption is implemented to prevent unauthorized access, then security is improved, but integration into IT infrastructure is worsened due to proprietary policy enforcement difficulties

Engineering Contradiction:
ImprovesecurityVSAvoidintegration capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal encryption system that can operate across multiple mobile phone networks and disparate operating systems. The solution uses standard SMS/MMS messaging protocols that are universally supported, allowing the encryption infrastructure to integrate with existing IT systems without requiring network-specific or device-specific modifications. The system enforces proprietary information policies universally across different platforms while maintaining compatibility with standard communication infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If pre-shared keys are used for encryption, then ease of operation is improved, but security is worsened due to vulnerability to MITM attacks and root certificate exploitation

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-establishing trusted relationships through phone number verification against administrator-approved whitelists before encryption keys are exchanged. This preliminary authentication step prevents man-in-the-middle attacks by ensuring that only authorized devices can participate in the key exchange process. The system performs security verification in advance, eliminating the need for users to manually manage pre-shared keys while maintaining protection against certificate exploitation and MITM attacks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9572033B2Systems and methods for encrypted mobile voice communications
Publication Date: 2017.02.14 CELLTRUST CORP
  • US9572033B2 patent drawing
  • US9572033B2 patent drawing
  • US9572033B2 patent drawing

AI summary

A system for establishing a registration for secure communication between a mobile device and a server includes a server configured to: determine the phone number of the mobile device from which the SMS or MMS message is originated; and verify the phone number of the mobile device originating the SMS or MMS message against a whitelist to authorize a registration between the mobile device and the server. The server can establish an encryption key between the mobile device and the server, which can used to provide or enhance encryption of a voice communication, such as a VoIP communication, made using the mobile device. The server can renew the encryption key based on one or more policies determined by an administrator. The server can be configured to verify a secure identification code that is input at the mobile device and which can be provided to a user of the mobile device before the mobile device is registered with the server.