Clientless Two-Factor Authentication for VoIP Phones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication methods are inadequate for IP-based phones, which lack client applications and are vulnerable to theft and abuse due to their portability and internet connectivity, necessitating a clientless solution for secure authentication.

Innovation Solution

A system and method that authenticates IP phones and users using an in-band channel, leveraging control messages and voice prompts to provide two-factor authentication without requiring a client application on the phone or an out-of-band channel, ensuring secure communication and encryption of voice conversations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional two-factor authentication is implemented using client applications and out-of-band channels, then authentication security is improved, but device complexity and ease of operation deteriorate due to requiring additional clients and channels on IP phones

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines device authentication and user authentication into a single integrated process. The authentication server performs both authentication factors sequentially through the same voice call channel, eliminating the need for separate out-of-band channels and reducing system complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The voice call channel serves multiple functions: it is used for both device identification and user passcode verification. The same communication interface handles both authentication factors, eliminating the need for separate clients and channels, thus reducing device complexity while maintaining authentication security

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If IP phones are made portable and mobile for tele-workers and road warriors, then ease of operation and adaptability are improved, but vulnerability to theft and attacks increases

Engineering Contradiction:
Improvephone portabilityVSAvoidtheft and attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The authentication server acts as an intermediary between the IP phone and the network resources. It performs both device authentication (verifying the phone itself) and user authentication (verifying the user's passcode) before granting access. This dual-layer authentication through the intermediary server protects portable phones from theft and attacks by ensuring that even if a phone is stolen, unauthorized users cannot access the network without the correct passcode

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication where the IP phone automatically presents its device credentials and the user provides their passcode through voice prompts. The authentication server independently verifies both factors without requiring additional external verification systems, providing secure protection for portable devices while maintaining ease of use

Inventive Principle:
Principle #25Self-service

3Reliability

If client applications are installed on IP phones for two-factor authentication, then authentication capability is improved, but ease of operation deteriorates due to requiring user interaction and client management

Engineering Contradiction:
Improveauthentication capabilityVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication client functionality from the IP phone and relocates it to the authentication server. The server generates voice prompts and processes passcode verification directly, eliminating the need for separate client applications on the phone. This reduces ease of operation barriers while maintaining authentication capability through the voice-based interface

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8705720B2System, method and apparatus for clientless two factor authentication in VoIP networks
Publication Date: 2014.04.22 AVAYA INC
  • US8705720B2 patent drawing
  • US8705720B2 patent drawing
  • US8705720B2 patent drawing

AI summary

The present invention provides a system, method and apparatus for authenticating an Internet Protocol (IP) phone and a user of the IP phone by determining whether the IP phone is an authorized device, and whenever the IP phone is authorized and a trigger condition occurs, determining whether the user of the IP phone is authorized. The user authorization process initiates a call to the IP phone, sends a request for a passcode to the IP phone, sends a message to disable the IP phone whenever the passcode is invalid, and terminates the call. The user authentication process uses an in-band channel and the IP phone does not run a two factor authentication client application during the authentication process.