STI Proxy Server Certificate Validation for VoIP Fraud Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to nuisance and fraudulent communications, leading to network overload and interoperability challenges due to the integration of new technology standards, which existing solutions fail to adequately address.

Innovation Solution

The implementation of a Secure Telephony Identity (STI) proxy server within the SHAKEN framework, which monitors and verifies the validity of public STI certificates for Public Land Mobile Networks (PLMNs) to authenticate outgoing and verify incoming VoIP communication requests, intercepting fraudulent messages and alleviating network overload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If telecommunication providers deploy technology standards with trusted certificate authority sources to verify calling telephone identity, then network security and legitimacy verification are improved, but device complexity and interoperability challenges increase

Engineering Contradiction:
Improvenetwork securityVSAvoidinteroperability challenges
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an STI proxy server as an intermediary component that mediates between the certificate authority verification system and the telecommunication network. This proxy server handles the complex certificate validation operations, shielding the core network infrastructure from complexity while maintaining security verification. The intermediary absorbs the interoperability challenges and presents a simplified interface to the rest of the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The verification system is segmented into distinct functional components: the STI proxy server handles certificate validation, the trusted certificate authority sources perform verification, and the telecommunication network handles call routing. This segmentation allows each component to be optimized independently, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If telecommunication networks integrate new technology standards for certificate verification, then fraudulent communication detection is improved, but network overload and operational impact worsen

Engineering Contradiction:
Improvefraudulent communication detectionVSAvoidnetwork operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The STI proxy server performs certificate verification in advance, before calls are routed through the network. By validating certificates preemptively and maintaining caches of verified certificate information, the system avoids repeated verification operations during peak traffic periods, preventing network overload while maintaining fraud detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service mechanisms where the STI proxy server automatically manages certificate validation caches and updates without requiring manual intervention or consuming excessive network resources. The proxy server serves itself by maintaining local copies of certificate information, reducing the need for continuous communication with external certificate authorities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10986501B2Secure telephone identity (STI) certificate management system
Publication Date: 2021.04.20 T MOBILE US INC
  • US10986501B2 patent drawing
  • US10986501B2 patent drawing
  • US10986501B2 patent drawing

AI summary

A Secure Telephony Identity (STI) proxy server is described for intercepting incoming Voice over Internet Protocol (VoIP) communication requests for the purpose of mitigating an effect of fraudulent and nuisance VoIP communications. The STI proxy server may facilitate an STI verification server in verifying an authenticity of an originating network associated with an incoming call request. In one example, the STI proxy server may verify that the visited network is permitted to interact with the home network, based on a list of permissible networks. In addition, the STI proxy server may determine whether public STI certificates associated with an originating network have expired or set to expire within a predetermined time interval. In response to an actual o impending expiration, the STI proxy server may facilitate retrieval of a superseding, new public STI certificate for use by an STI authentication server to digitally sign an outgoing SIP INVITE messages.