Telephone Authentication via Call Rejection and Database Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods for data exchange systems, particularly in VPNs, are vulnerable as authentication data is transmitted alongside user data, making them susceptible to attacks, and lack cost-effective, mobile-friendly solutions that utilize available user equipment for enhanced security.
Innovation Solution
A method that uses a user's telephone to authenticate via a secondary network, where the central telephone terminal determines the caller's number and security level, stores the call data temporarily, and verifies it against a database, allowing secure sessions only if matching records exist, without requiring additional devices or altering the registration process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication data is transmitted alongside user data via data networks, then authentication can be performed, but security is compromised due to susceptibility to attacks
Solution Approach 1:
The authentication process is divided into two separate networks: a first network (e.g., public data network) for establishing communication connections, and a second network (e.g., telephone network) for transmitting authentication data. This segmentation isolates authentication data transmission from user data transmission, preventing attackers who compromise the data network from accessing authentication credentials.
Solution Approach 2:
A central telephone terminal acts as an intermediary between the user's telephone terminal and the database. The central telephone terminal receives the dialed number from the user, queries the database for the corresponding authentication data, and provides it to the user. This intermediary architecture separates the authentication data storage (in the database) from the authentication process, adding a security layer that prevents direct access to stored authentication data.
2Reliability
If additional authentication devices or modified registration processes are implemented, then security is enhanced, but device complexity and ease of operation deteriorate
Solution Approach 1:
The system uses the user's existing telephone terminal and telephone network access for authentication, rather than requiring dedicated authentication devices. The telephone terminal serves multiple functions: communication and authentication. The central telephone terminal also performs multiple roles: receiving dialed numbers, querying the database, and providing authentication data. This multi-functionality approach enhances security without requiring users to acquire additional specialized devices.
Solution Approach 2:
The user's own telephone number and existing telephone terminal are used as the authentication basis. The system leverages resources the user already possesses (their telephone service and device) rather than requiring them to obtain new authentication devices. The registration process stores the user's telephone number in the database, enabling future authentication using their existing telephone access.
3Ease of operation
If telephone authentication is implemented without pre-registration, then ease of operation improves, but reliability deteriorates due to lack of verified user data
Solution Approach 1:
A registration process is performed in advance during which the user's telephone number is stored in the database. This preliminary action ensures that when authentication is needed, the system already has verified user data (the registered telephone number) to match against the dialed number. The user does not need to register again during each authentication event, maintaining convenience while ensuring reliability through pre-verified data.
Data Source
Figure 1~2
AI summary
1. Method for telephone authentication of users of private or public networks for data exchange. 2.1 Methods for authenticating users during data exchange have been known for a long time. 2.2 In order to design a method for telephone authentication such that, by taking into account the equipment available to the user, no change to the login process usual for this equipment is necessary and the user can choose between different security levels, it is provided according to claim 1 that the user (U) is previously registered for different security levels by the central telephone terminal equipment (TE) in a registration process, that for telephone authentication of the user (U), after the registration process, in the first step, the user (U) connects to a telephone terminal equipment (T) via a second network (N2) at the lowest security level on a special,The process begins with the user calling the telephone number assigned to the central telephone terminal equipment (TE). In the second step, the central telephone terminal equipment (TE) determines the caller's number and the dialed number and writes this information to a database (DB) via a third network (N3). The telephone connection is then terminated by the central telephone terminal equipment (TE) not accepting the call but rejecting it after verification. In the third step, such a call is stored for a specific period and then deleted from the database (DB) after an expiry period. In the fourth step, the user (U) establishes a connection with the central data terminal equipment (DE) via the first network (N1) using their data terminal equipment (D) by transmitting data that can be uniquely assigned to the user. In the fifth step, the data terminal equipment (DE) checks the database (DB) by means of a database query.whether this data matches that from the registration process and an entry for the user from step three exists, and that in the sixth step, if a corresponding data record is found in the database (DB), communication between the data terminal (D) and the central data facility (DE) is permitted and a secure session is opened, and if no data record could be found or the expiry time for the validity of the authorization has expired, the query of the database (DB) by the data facility (DE) is rejected.