Voicemail Authentication Secure Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional voicemail systems are susceptible to spoofing attacks, where an individual can falsify the caller ID to gain unauthorized access to a voicemail account by exploiting the 'skip passcode' feature, which lacks robust authentication.
Innovation Solution
A method and system where a user equipment (UE) and a network entity exchange a secure key to authenticate with the voicemail server, with the secure key being generated each time access is requested, and used to verify the authenticity of the UE, prompting additional authentication if the keys do not match.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the voicemail server uses telephone number matching for authentication to enable skip passcode access, then ease of operation is improved, but security is worsened due to spoofing vulnerability
Solution Approach 1:
The patent introduces a secure key as an intermediary authentication mechanism between the UE and voicemail server. Instead of directly trusting telephone number matching, the system uses a dynamically generated secure key that must be exchanged between the UE and server through a network entity, preventing spoofing while maintaining convenient access for authorized users
Solution Approach 2:
The patent changes the authentication parameter from static telephone number matching to dynamic secure key exchange. The secure key is generated anew for each access attempt and transmitted through the network entity, making the authentication mechanism adaptive and resistant to spoofing attacks
2Reliability
If the voicemail server requires passcode entry for authentication, then security is improved, but ease of operation is worsened
Solution Approach 1:
The patent implements dynamic authentication where the secure key is generated and transmitted anew for each access attempt. This dynamic mechanism provides strong security without requiring users to manually enter passcodes, as the key exchange happens automatically in the background during the call setup process
3Ease of operation
If the voicemail server uses static authentication keys, then ease of operation is improved, but security is worsened due to key compromise risk
Solution Approach 1:
The patent implements periodic generation of new secure keys for each authentication attempt. Rather than using a single static key, the system generates and transmits a fresh secure key with each access request, ensuring that compromised keys cannot be reused and maintaining both security and operational ease
Data Source
AI summary
Disclosed are methods and systems to authenticate a UE to grant the UE access to a voicemail account. A network entity and a UE may exchange a secure key that may then be used to authenticate the UE with the voicemail server. The exchange of the secure key may be triggered in response to receiving a user request to access a voicemail account at a voicemail server. The UE may then include the received secure key in an origination request seeking to set up a call to the voicemail server, and the voicemail server may authenticate the UE by comparing the secure key received in the origination request with the secure key most recently transmitted to the UE. If the received secure key is the same as the most recently transmitted secure key, the UE is authenticated.


