Voice Call Authentication via Secure Data Channel Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for mobile devices over voice channels are insecure, prone to eavesdropping, and lack robust identification, allowing unauthorized access to sensitive voice services, particularly in corporate settings where privacy and cost concerns are significant.
Innovation Solution
A system where mobile devices obtain and present authentication tokens over a data channel for voice channel authentication, using a PBX to manage and verify these tokens, ensuring unique, one-time use, and secure access to voice services by encrypting and validating tokens through a secure data channel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (caller ID, conference numbers) are used for voice channels, then ease of operation is maintained, but security and reliability deteriorate due to spoofing and eavesdropping vulnerabilities
Solution Approach 1:
The patent introduces an authentication token as an intermediary element that mediates between the mobile device and the voice service. The token is generated by a server through secure data channel authentication and then used to authenticate the device over the voice channel, effectively decoupling the security-critical authentication logic from the voice channel itself
Solution Approach 2:
The authentication process is segmented into two distinct phases: (1) secure data channel authentication where the server verifies the mobile device and generates an authentication token, and (2) voice channel authentication where the pre-recorded token is presented for verification. This segmentation allows each phase to use appropriate security measures for its specific requirements
2Reliability
If secure data channel authentication is implemented for voice services, then reliability and security improve, but ease of operation deteriorates due to additional authentication steps
Solution Approach 1:
The authentication token is generated and prepared in advance during the data channel authentication phase. This preliminary action stores the authentication result in a reusable format that can be automatically presented during the voice channel authentication, eliminating the need for users to manually perform complex authentication steps during the actual voice service access
3Adaptability or versatility
If voice channels are made accessible to mobile devices, then adaptability and service availability improve, but security deteriorates due to eavesdropping and unauthorized access risks
Solution Approach 1:
The authentication token serves as a secure intermediary that enables voice service access without exposing the voice channel to security risks. The token encapsulates the authentication result and can be verified without transmitting sensitive authentication data over the insecure voice channel
Solution Approach 2:
The authentication result is copied into a pre-recorded token format that can be stored and replayed during voice channel authentication. This copying allows the authentication information to be transmitted in a secure, non-interactive format that cannot be intercepted or modified during the voice call
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Aspects relate to authorizing mobile devices for PBX-based voice services. A mobile device calls a PBX over a voice channel, and phone number identifier information is obtained and matched to identifier information for devices that known (authorizeable) to use the PBX. If there is one incoming call that matches to a given device, and an authentication token provided over a data channel matches an authentication token associated with that device, then the device is authorized for voice services. Where there are multiple matching calls, those devices are instructed to provide authentication tokens over their voice channels. The devices can detect absence of a data channel and provide authentication tokens over the voice channels; the devices also can wait to receive a call connected response and in the absence of such provide their authentication tokens over the voice channel. Tokens can be requested and downloaded for storage at the devices.