Mobile Device Voice Channel Authentication via Data-Channel Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for mobile devices over voice channels are insecure, prone to eavesdropping, and lack confidence in identifying authorized devices, especially in sensitive corporate voice services like PBX and teleconferences, where unauthorized access can lead to privacy breaches and financial losses.

Innovation Solution

A system where a mobile device requests an authentication token over a secure data channel, which is then presented as a series of audible tones on the voice channel for verification, using a database of issued tokens to ensure one-time use and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed over voice channels using traditional methods, then ease of operation is maintained, but security and reliability deteriorate due to eavesdropping and spoofing vulnerabilities

Engineering Contradiction:
Improveauthentication securityVSAvoideavesdropping and spoofing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a token as an intermediary authentication mechanism. The mobile device first obtains a token over a secure data channel, then presents this token over the voice channel for authentication. This intermediary token resolves the contradiction by providing reliable authentication without exposing the system to eavesdropping and spoofing attacks that plague direct voice channel authentication methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into two distinct phases: (1) token acquisition over a secure data channel, and (2) token presentation over the voice channel. This segmentation allows the system to leverage the security of data channels for authentication while maintaining ease of operation over voice channels, thereby improving reliability without introducing harmful factors.

Inventive Principle:
Principle #1Segmentation

2Reliability

If caller ID information is used for authentication, then ease of operation is maintained, but reliability deteriorates because the information can be spoofed and is not always available

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidspoofing
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The token serves as a more reliable intermediary authentication mechanism compared to caller ID information. While caller ID can be spoofed and may not be available, the token is obtained through a secure data channel authentication process, ensuring its authenticity and eliminating the spoofing vulnerability inherent in voice channel-based authentication methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If voice channels are used for authentication, then ease of operation is maintained, but security deteriorates due to the unencrypted nature of voice traffic

Engineering Contradiction:
Improveauthentication securityVSAvoidunencrypted voice traffic
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses a token as an intermediary that bridges secure data channel authentication with voice channel operation. The token is obtained over an encrypted data channel where security is maintained, then presented over the voice channel for authentication purposes. This resolves the contradiction by providing reliable authentication without requiring unencrypted voice traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If conference numbers are distributed with meeting invitations, then ease of operation is improved, but security deteriorates as the numbers can be intercepted and reused

Engineering Contradiction:
Improveconference accessVSAvoidconference security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by obtaining a token over a secure data channel before allowing access to voice services or conferences. This preliminary action ensures that only authenticated devices can access the conference, preventing unauthorized access while maintaining ease of operation through automated token-based authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The token acts as an intermediary authentication mechanism that replaces insecure conference number distribution. By obtaining the token over a secure data channel and presenting it for authentication, the system maintains ease of conference access while dramatically improving security against interception and reuse attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2334111B1Authentication of mobile devices over voice channels
Publication Date: 2012.08.01 BLACKBERRY LTD
  • EP2334111B1 patent drawingFigure 1
  • EP2334111B1 patent drawingFigure 2
  • EP2334111B1 patent drawingFigure 3~4

AI summary

Mobile devices are authorized to access PBX-bssed voice services through presentation of audible tones on a voice channel, which are determined based on a code received over a separate data channel, The device can request a code over a data channel from a server in communication with the PBX. The server provides data representative of the code over the data channel to the device, and arranges for local storage of the code. The device makes a connection with the PBX over a separate voice channel. The mobile device presents the received code as a sequence of audio tones (e.g., DTMF tones), The audio tones are used to data that can be compared with stored codes by an authentication module. The authorization module can indicate to the PBX that the code is valid; services can be provided by the PBX in response. The valid codes can be maintained, such as by removing used codes from code storage.