Mobile Device Voice Channel Authentication via Data-Channel Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for mobile devices over voice channels are insecure, prone to eavesdropping, and lack confidence in identifying authorized devices, especially in sensitive corporate voice services like PBX and teleconferences, where unauthorized access can lead to privacy breaches and financial losses.
Innovation Solution
A system where a mobile device requests an authentication token over a secure data channel, which is then presented as a series of audible tones on the voice channel for verification, using a database of issued tokens to ensure one-time use and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication is performed over voice channels using traditional methods, then ease of operation is maintained, but security and reliability deteriorate due to eavesdropping and spoofing vulnerabilities
Solution Approach 1:
The patent introduces a token as an intermediary authentication mechanism. The mobile device first obtains a token over a secure data channel, then presents this token over the voice channel for authentication. This intermediary token resolves the contradiction by providing reliable authentication without exposing the system to eavesdropping and spoofing attacks that plague direct voice channel authentication methods.
Solution Approach 2:
The authentication process is segmented into two distinct phases: (1) token acquisition over a secure data channel, and (2) token presentation over the voice channel. This segmentation allows the system to leverage the security of data channels for authentication while maintaining ease of operation over voice channels, thereby improving reliability without introducing harmful factors.
2Reliability
If caller ID information is used for authentication, then ease of operation is maintained, but reliability deteriorates because the information can be spoofed and is not always available
Solution Approach 1:
The token serves as a more reliable intermediary authentication mechanism compared to caller ID information. While caller ID can be spoofed and may not be available, the token is obtained through a secure data channel authentication process, ensuring its authenticity and eliminating the spoofing vulnerability inherent in voice channel-based authentication methods.
3Reliability
If voice channels are used for authentication, then ease of operation is maintained, but security deteriorates due to the unencrypted nature of voice traffic
Solution Approach 1:
The patent uses a token as an intermediary that bridges secure data channel authentication with voice channel operation. The token is obtained over an encrypted data channel where security is maintained, then presented over the voice channel for authentication purposes. This resolves the contradiction by providing reliable authentication without requiring unencrypted voice traffic.
4Ease of operation
If conference numbers are distributed with meeting invitations, then ease of operation is improved, but security deteriorates as the numbers can be intercepted and reused
Solution Approach 1:
The system performs preliminary authentication by obtaining a token over a secure data channel before allowing access to voice services or conferences. This preliminary action ensures that only authenticated devices can access the conference, preventing unauthorized access while maintaining ease of operation through automated token-based authentication.
Solution Approach 2:
The token acts as an intermediary authentication mechanism that replaces insecure conference number distribution. By obtaining the token over a secure data channel and presenting it for authentication, the system maintains ease of conference access while dramatically improving security against interception and reuse attacks.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Mobile devices are authorized to access PBX-bssed voice services through presentation of audible tones on a voice channel, which are determined based on a code received over a separate data channel, The device can request a code over a data channel from a server in communication with the PBX. The server provides data representative of the code over the data channel to the device, and arranges for local storage of the code. The device makes a connection with the PBX over a separate voice channel. The mobile device presents the received code as a sequence of audio tones (e.g., DTMF tones), The audio tones are used to data that can be compared with stored codes by an authentication module. The authorization module can indicate to the PBX that the code is valid; services can be provided by the PBX in response. The valid codes can be maintained, such as by removing used codes from code storage.