Voice Call Authentication via Application Token Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing voice call identification and authentication methods for customer support are insecure and time-consuming, as users are required to provide personal information over the phone, which can be vulnerable to eavesdropping and do not adequately protect user accounts from impersonation.
Innovation Solution
Implementing a secure voice call authentication system using a client device's application, which establishes a cryptographic connection with a call center server, utilizing a short-living authentication token or authentication tokens to authenticate users without requiring them to answer personal questions, by comparing caller identifiers with stored information and using public-private key cryptography for secure token transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users provide personal information over the phone for authentication, then the authentication process can be completed, but security is compromised due to vulnerability to eavesdropping and impersonation
Solution Approach 1:
The patent extracts the authentication information from the voice call channel and moves it to the application channel. The system uses the application to generate and transmit authentication tokens separately from the voice communication, eliminating the security vulnerability of transmitting personal information over the phone while maintaining ease of authentication.
Solution Approach 2:
The patent introduces an authentication token as an intermediary between the user and the support system. Instead of directly sharing personal information, the application generates a token that serves as a secure mediator, allowing authentication without exposing sensitive data during the voice call.
2Reliability
If users answer personal questions for authentication, then identification can be confirmed, but the process becomes time-consuming
Solution Approach 1:
The patent implements preliminary action by having the application generate and store authentication tokens before the support call occurs. During the actual call, the pre-generated token is quickly transmitted and verified, eliminating the need for time-consuming personal questions while maintaining accurate identification.
Solution Approach 2:
The application automatically generates and manages authentication tokens without requiring user input during the support call. The system serves itself by handling the authentication process through automated token generation and verification, reducing both time and manual intervention.
Data Source
AI summary
Systems and methods providing call identification and authentication. In one implementation, a pool of phone numbers is maintained. A request for a phone number for initiating a voice call is received from a client device. A first phone number from the pool of phone numbers is transmitted to the client device. Responsive to receiving, from the client device, the voice call at the first phone number, the client device is declared authenticated.


