PSTN Identity Assertion via Parallel IP Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity assertion mechanisms in the Publicly Switched Telephone Network (PSTN), such as Caller ID and ANI, are easily falsifiable and lack cryptographic security, leading to unreliable identity verification.

Innovation Solution

An authentication scheme that uses Internet Protocol (IP) communications to provide additional authentication of PSTN identity assertions, optionally using cryptographically secure techniques, by sending network identity assertions in parallel with PSTN calls, making it more difficult to falsify the identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Caller ID or ANI mechanisms are used for identity assertion in PSTN, then identity verification is provided, but the reliability of identity verification deteriorates because these mechanisms are easily falsifiable and lack cryptographic security

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the identity verification process into two independent channels: PSTN channel (Caller ID/ANI) and IP channel (cryptographically authenticated identity assertion). By dividing the authentication process across these separate channels, the system achieves both simplicity (using existing PSTN mechanisms) and reliability (adding cryptographic verification through IP communications)

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using IP communications that mediates between the PSTN call and the identity verification process. The IP-based cryptographic authentication acts as a mediator that validates the PSTN identity assertion without replacing the existing PSTN infrastructure, thus maintaining ease of operation while improving reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic authentication is added to PSTN identity assertions, then identity verification reliability improves, but device complexity increases due to the need for additional authentication mechanisms

Engineering Contradiction:
Improveidentity assertion securityVSAvoidauthentication scheme complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the communication device multi-functional by enabling it to operate in both PSTN mode (traditional voice calls with Caller ID/ANI) and IP mode (cryptographically authenticated communications). This universality allows the device to provide both simple PSTN functionality and secure cryptographic authentication without requiring separate dedicated systems, thereby improving security while managing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary cryptographic authentication through IP communications before or during the PSTN call establishment. By pre-authenticating the identity assertion through the more secure IP channel, the system ensures reliable identity verification is already in place before the PSTN call proceeds, reducing the need for complex real-time verification mechanisms during the call

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8953771B2Method and apparatus to provide cryptographic identity assertion for the PSTN
Publication Date: 2015.02.10 CISCO TECHNOLOGY INC
  • US8953771B2 patent drawing
  • US8953771B2 patent drawing
  • US8953771B2 patent drawing

AI summary

The present application provides an authentication scheme that allows a device to provide additional authentication of a Publicly Switched Telephone Network (PSTN) identity assertion made in a PSTN call by also sending an Internet Protocol (IP) communication. The device sends the IP communication generally in parallel with the PSTN call. The IP communication includes a network identity assertion, which optionally may be authenticated using a cryptographically secure technique. The network identity assertion, being more difficult to falsify, provides additional authentication of the PSTN identity assertion.