Voice Call Authentication via Secure Data Channel Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for mobile devices over voice channels are insecure, prone to eavesdropping, and lack robust identification, allowing unauthorized access to sensitive voice services, particularly in corporate settings where privacy and cost concerns are significant.

Innovation Solution

A system where mobile devices obtain and present authentication tokens over a data channel for voice channel authentication, using a PBX to manage and verify these tokens, ensuring unique, one-time use, and secure access to voice services by encrypting and validating tokens through a secure data channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (caller ID, conference numbers) are used for voice channels, then ease of operation is maintained, but security and reliability deteriorate due to spoofing and eavesdropping vulnerabilities

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication token as an intermediary element that mediates between the mobile device and the voice service. The token is generated by a server through secure data channel authentication and then used to authenticate the device over the voice channel, effectively decoupling the security-critical authentication logic from the voice channel itself

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into two distinct phases: (1) secure data channel authentication where the server verifies the mobile device and generates an authentication token, and (2) voice channel authentication where the pre-recorded token is presented for verification. This segmentation allows each phase to use appropriate security measures for its specific requirements

Inventive Principle:
Principle #1Segmentation

2Reliability

If secure data channel authentication is implemented for voice services, then reliability and security improve, but ease of operation deteriorates due to additional authentication steps

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication token is generated and prepared in advance during the data channel authentication phase. This preliminary action stores the authentication result in a reusable format that can be automatically presented during the voice channel authentication, eliminating the need for users to manually perform complex authentication steps during the actual voice service access

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If voice channels are made accessible to mobile devices, then adaptability and service availability improve, but security deteriorates due to eavesdropping and unauthorized access risks

Engineering Contradiction:
Improvevoice service accessibilityVSAvoideavesdropping and unauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The authentication token serves as a secure intermediary that enables voice service access without exposing the voice channel to security risks. The token encapsulates the authentication result and can be verified without transmitting sensitive authentication data over the insecure voice channel

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication result is copied into a pre-recorded token format that can be stored and replayed during voice channel authentication. This copying allows the authentication information to be transmitted in a secure, non-interactive format that cannot be intercepted or modified during the voice call

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2334110B1Authenticating voice calls from mobile devices
Publication Date: 2019.07.03 BLACKBERRY LTD
  • EP2334110B1 patent drawingFigure 1~2
  • EP2334110B1 patent drawingFigure 3
  • EP2334110B1 patent drawingFigure 4

AI summary

Aspects relate to authorizing mobile devices for PBX-based voice services. A mobile device calls a PBX over a voice channel, and phone number identifier information is obtained and matched to identifier information for devices that known (authorizeable) to use the PBX. If there is one incoming call that matches to a given device, and an authentication token provided over a data channel matches an authentication token associated with that device, then the device is authorized for voice services. Where there are multiple matching calls, those devices are instructed to provide authentication tokens over their voice channels. The devices can detect absence of a data channel and provide authentication tokens over the voice channels; the devices also can wait to receive a call connected response and in the absence of such provide their authentication tokens over the voice channel. Tokens can be requested and downloaded for storage at the devices.