Multi-Level Secure Access Control for VoIP Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IP telephones using Internet Protocol (VoIP) lack sufficient security and remote access control, making them vulnerable to unauthorized access, which is a concern for secure voice, data, and video stream communications.

Innovation Solution

A secure service point system that employs physical, logical, and biometric authentication methods, utilizing a Secure Personal Authentication Reader (SPAR) device with various authentication types (smart card, biometric, RFID) to securely access and control IP telephones, ensuring multi-level security and remote management of communication terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IP telephones use Internet Protocol for communication, then cost-effectiveness and flexibility are improved, but security and remote access control deteriorate

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent authentication methods (physical token, biometric, logical credentials) that work together. Each authentication factor is a separate module that can be individually implemented and managed, allowing the system to maintain flexibility while achieving enhanced security through layered authentication requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines multiple authentication mechanisms (physical tokens, biometric sensors, logical credentials) into a composite authentication system. This composite approach integrates different security layers to create a robust security framework that maintains the flexibility of IP telephony while addressing security concerns through multi-factor authentication.

Inventive Principle:
Principle #40Composite materials

2Reliability

If multiple authentication methods are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is designed with universal components that can handle multiple authentication types through a unified framework. The authentication server and terminal are multi-functional, capable of processing physical tokens, biometric data, and logical credentials through the same infrastructure, thereby reducing overall system complexity despite supporting multiple authentication methods.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an authentication server as an intermediary that mediates between the authentication terminal and the IP telephone system. This intermediary handles the complexity of multiple authentication methods centrally, simplifying the terminal design and providing a manageable interface while maintaining robust multi-factor authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If remote access control is implemented, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication terminal provides self-service capabilities by automatically collecting biometric data, reading physical tokens, and verifying logical credentials without requiring manual intervention. The system autonomously manages the authentication process, making remote access control secure while maintaining ease of operation through automated credential verification and user-friendly interfaces.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP1811740B1Method and system for multi-level secure personal profile management and access control to the enterprise multi-modal communication environment in heterogeneous convergent communication networks
Publication Date: 2019.06.26 PASSBAN
  • EP1811740B1 patent drawingFigure 1(a)~1(d)
  • EP1811740B1 patent drawingFigure 2
  • EP1811740B1 patent drawingFigure 3

AI summary

A method and apparatus, in accordance with an embodiment of the present invention, is presented for securely accessing a voice-enabled communication terminal using Internet Protocol by performing physical authentication, performing biometric authentication, performing logical authentication, performing confirmation of a user and upon successful confirmation of the user, allowing access to the communication terminal.