VoIP Call Setup With Voice-Server Identity Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VoIP telephony systems require cumbersome administrator intervention for linking user terminals to public telephone identities, especially when multiple devices share the same identity, and lack a secure, automated method for terminal authentication.
Innovation Solution
A method and device for VoIP networks that authenticate users and terminals through a voice server, providing public telephone identities and authentication data only after successful user and terminal authentication, eliminating the need for administrator intervention and ensuring security against identity spoofing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrator intervention is used to link terminal to public telephone identity, then security is maintained, but operation complexity and time consumption increase
Solution Approach 1:
The terminal automatically performs authentication with the voice server using pre-configured credentials, obtains its public telephone identity without administrator intervention, and configures itself with the identity information. This self-service mechanism eliminates manual linking while maintaining security through automated authentication protocols.
Solution Approach 2:
The terminal is pre-configured with authentication credentials (username, password, or certificate) before deployment. This preliminary setup enables the terminal to autonomously authenticate with the voice server and obtain its public telephone identity without requiring real-time administrator intervention, thus resolving the contradiction between security and operational simplicity.
2Ease of operation
If automated authentication is implemented, then ease of operation improves, but security may be compromised
Solution Approach 1:
The voice server acts as a trusted intermediary between the terminal and the public telephone identity system. It verifies the terminal's authentication credentials, validates the authentication process, and securely provides the public telephone identity. This intermediary mechanism ensures that automated authentication maintains security through centralized verification while enabling ease of operation.
Solution Approach 2:
The manual mechanical process of administrator intervention is replaced with an automated electronic authentication system. The terminal uses digital credentials (username/password or certificate) to authenticate with the voice server, which automatically verifies credentials and provisions the public telephone identity. This substitution maintains security through cryptographic verification while eliminating manual intervention.
3Reliability
If terminal authentication is required before identity provisioning, then security is improved, but call setup time increases
Solution Approach 1:
Authentication credentials are pre-configured in the terminal before deployment, and the authentication with the voice server is performed automatically as the first step in the call setup process. This preliminary preparation of credentials and automated authentication flow minimizes the time penalty by eliminating manual setup steps while maintaining security verification.
Solution Approach 2:
The authentication process is seamlessly integrated into the call setup flow without interruption. The terminal continuously maintains the authentication session with the voice server, and the public telephone identity is provisioned and cached for subsequent use. This continuous action eliminates repeated authentication overhead, reducing time loss while maintaining security.
4Reliability
If hardware identifier access is required for terminal linking, then security is maintained, but device complexity and administrator burden increase
Solution Approach 1:
The physical access mechanism to hardware identifiers is replaced with digital authentication credentials stored in the terminal's software. Instead of requiring administrators to access hardware identifiers through complex administrative interfaces, the terminal uses pre-configured digital credentials (username/password or certificate) for authentication. This substitution reduces device complexity while maintaining security through cryptographic verification.
Solution Approach 2:
The voice server acts as an intermediary that handles the authentication process using digital credentials, eliminating the need for direct hardware identifier access. The terminal presents its digital credentials to the voice server, which verifies them and provisions the public telephone identity without requiring access to hardware identifiers. This intermediary approach simplifies the system architecture while maintaining security.
Data Source
Figure 1~3
Figure 4
AI summary
The processing method comprises, following receipt by the device of the voice over IP network (VoIP) of a message initiating a VoIP call coming from a terminal: - determining (E30, E190) whether the received message contains a public telephone identity allocated to a user by the VoIP network; - if so, triggering (E220) the establishment of the VoIP call with a recipient of the received message following a positive authentication of the terminal; - if not: - establishing (E50) a VoIP channel between the terminal and a voice server hosted by the VoIP network device; - obtaining (E70), by the voice server via this channel, an authentication code of a user of the terminal; - if the code is associated at the VoIP network level with a public telephone identity allocated by same to a user, supplying (E130), to the terminal, the public telephone identity and an item of authentication data associated at the VoIP network level with this public telephone identity, in order to transmit VoIP calls and to be authenticated on the VoIP network.