Security Token in UUI Field for Pre-Call Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing call authentication methods, such as whitelist services, are ineffective against caller ID spoofing, allowing fraud calls to reach connected-car systems and other domains by falsifying caller IDs, which traditional methods cannot block.

Innovation Solution

Incorporating a security token within the User-to-User Information (UUI) field of call setup messages, which is authenticated before call establishment, using time-synchronized or hash function-based one-time password methods to generate authentication keys that are valid for a short period, preventing replay attacks and ensuring secure call authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional caller ID validation is used, then calls from whitelisted numbers are allowed, but caller ID spoofing can still bypass this security

Engineering Contradiction:
Improvecall authentication reliabilityVSAvoidcaller ID spoofing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by embedding the security token in the UUI field of the call setup message before the call is established. The authentication key is prepared in advance and included in the initial signaling message, allowing the receiving end to verify the caller's identity before the call connection is fully established, thus preventing spoofed calls from bypassing security checks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism by using a security token containing an authentication key as a mediator between the calling and receiving ends. This token acts as a third-party verification element that proves the caller's identity, bridging the trust gap between parties and enabling reliable authentication beyond simple caller ID matching

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security tokens are authenticated in all calls, then fraud calls are blocked, but call setup time increases

Engineering Contradiction:
Improvefraud call blocking effectivenessVSAvoidcall setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing security token authentication selectively rather than universally. The authentication mechanism can be configured to apply only to specific high-risk call scenarios or domains (such as connected-car systems), while allowing standard calls to proceed with traditional validation, thus achieving fraud blocking without universally increasing call setup time

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent enables skipping by allowing calls with valid security tokens to be authenticated rapidly during the initial call setup phase. The authentication process is integrated into the existing signaling flow, and once the token is verified, the call can proceed without additional delays, effectively rushing through the authentication step for legitimate calls

Inventive Principle:
Principle #21Skipping (Rushing through)

3Object-affected harmful factors

If caller ID filtering is implemented, then unwanted calls are reduced, but spoofed caller IDs cannot be detected

Engineering Contradiction:
Improveunwanted call volumeVSAvoidspoofed caller ID detection capability
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies copying by creating a verifiable copy of the caller's authentication credentials in the security token. Instead of relying on the caller ID string alone, the system creates a cryptographic copy of the authentication key that can be verified by the receiving end, providing a true copy-based verification mechanism that exposes spoofing attempts

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10771453B2User-to-user information (UUI) carrying security token in pre-call authentication
Publication Date: 2020.09.08 CISCO TECHNOLOGY INC
  • US10771453B2 patent drawing
  • US10771453B2 patent drawing
  • US10771453B2 patent drawing

AI summary

In one embodiment, a telecommunication apparatus includes a processor to generate a telephone call set-up message including a user-to-user information (UUI) field, and include a security token in the UUI field of the telephone call set-up message, and a network interface to send the telephone call set-up message to a telephone network. Related apparatus and methods are also described.