Digital Telephone Authentication Subsystem for UC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unified communications (UC) systems face security risks due to the need for cumbersome security credential installation on devices with limited input options, such as digital telephones, which can compromise the entire framework if a single device is compromised.

Innovation Solution

A digital telephone management subsystem that includes a telephone interface module for receiving security information, a telephone security module for decrypting encrypted credentials, and an authentication module to authenticate the digital telephone using shared security credentials with a computing device, reducing the need for manual input and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security credentials are manually installed on UC devices, then authentication security is improved, but device complexity and ease of operation deteriorate due to cumbersome installation processes on devices with limited input capabilities

Engineering Contradiction:
Improveauthentication securityVSAvoidcredential installation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A computing device acts as an intermediary to provision security credentials to the digital telephone. The computing device receives credentials from the network, encrypts them, and transmits them to the telephone, eliminating the need for manual credential entry on the telephone itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security credentials are pre-provisioned and encrypted on a computing device before being transferred to the digital telephone. This preliminary preparation of credentials resolves the contradiction by ensuring security is established before the device needs to operate independently.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security credentials are stored on UC devices, then authentication capability is improved, but security risk worsens because compromise of a single device exposes the entire UC framework

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risk exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The computing device serves as a secure intermediary that manages credential encryption and decryption. By keeping the decryption key (PIN) on the computing device rather than the telephone, the system reduces the security risk associated with storing credentials on edge devices while maintaining authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different parts of the system have different security roles: the computing device holds the PIN and performs decryption, while the telephone stores encrypted credentials and performs authentication. This distribution of security functions based on local capabilities reduces overall system risk.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If automated authentication is implemented, then ease of operation is improved, but device complexity worsens due to the need for encryption and decryption modules

Engineering Contradiction:
Improveauthentication process automationVSAvoidsecurity module complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional modules: a telephone interface module for receiving PINs, a telephone security module for encryption/decryption operations, and a telephone authentication module for credential verification. This segmentation manages complexity by distributing functions across separate components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The digital telephone autonomously performs authentication operations using its stored encrypted credentials and the PIN from the computing device. The system serves itself by automatically decrypting and using credentials without manual intervention, improving ease of operation while the modular architecture manages the inherent complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8943560B2Techniques to provision and manage a digital telephone to authenticate with a network
Publication Date: 2015.01.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8943560B2 patent drawing
  • US8943560B2 patent drawing
  • US8943560B2 patent drawing

AI summary

Techniques to manage digital telephones are described. An apparatus may comprise a digital telephone management component having a telephone interface module operative to receive security information in the form of a personal identification number (PIN) for an operator or device. The digital telephone management component may also comprise a telephone security module communicatively coupled to the telephone interface module, the telephone security module operative to receive encrypted security credentials from a computing device, and decrypt the encrypted security credentials with the PIN. The digital telephone management component may further comprise a telephone authentication module communicatively coupled to the telephone security module, the telephone authentication module operative to authenticate the digital telephone using the security credentials. Other embodiments are described and claimed.