IP Library Granted Patent US 9,197,746
Granted Patent B2
US 9,197,746 · App. 12/366,630 · Granted Nov 24, 2015

System, method and apparatus for authenticating calls

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,197,746
App. No.
12/366,630
Granted
Nov 24, 2015
Kind
B2
Abstract

The present invention provides a system, method and apparatus for authenticating calls that is a robust Anti-vishing solution. The present invention can identify Caller ID spoofing, verify dialed number to detect man-in-the middle and verify called party against dialed digits to detect impersonation. This solution can handle calls coming from any phone any where with little impact on user experience. Two separate solutions are tailored for smart phones (communication devices capable of running application software) and traditional phones to reduce the impact to user experience while providing robust verification.

Claims (38)

1. A method for authenticating a calling device comprising the steps of:

receiving a call from the calling device to a called device, at a controller, wherein the controller intercepts the call from the calling device to the called device;

sending a first authentication request for the call from the controller to the calling device;

receiving, at the controller, a first authentication response for the call from the calling device, wherein the first authentication response for the call comprises calling device encrypted data generated by the calling device, wherein the calling device encrypted data includes a hash of a caller identification for the calling device and a called number using a shared secret key;

extracting, by the controller, the caller identification and the called number from the encrypted data using the shared secret encryption key;

determining, by the controller, whether the extracted caller identification and the extracted called number are valid; and

transferring, by the controller, the call to the called device in response to determining that the extracted caller identification and the extracted called number are valid.

2. The method as recited in claim 1 , wherein:

the first authentication request for the call includes a controller generated encryption key;

the first authentication response for the call includes a calling device generated encryption key; and

wherein the calling device encrypted data is generated using the caller identification, a calling number, the called number, the controller generated encryption key, the calling device generated encryption key and the shared secret encryption key.

3. The method as recited in claim 1 , further comprising the steps of:

registering the calling device; and

creating the shared secret encryption key.

4. The method as recited in claim 1 , wherein the messages are exchanged using in-band communication channels, out-of-band communication channels, or a combination thereof.

5. A system for authenticating a calling device comprising:

a controller communicably coupled to a communications network wherein the controller comprises a communications interface communicably coupled to the communications network and a processor communicably coupled to the communications interface, and wherein the processor (a) receives a call from the calling device that is directed to a called device using a called number, wherein the call is intercepted by the controller, (b) sends a first authentication request to the calling device, (c) receives a first authentication response from the calling device, wherein the first authentication response comprises calling device encrypted data generated by the calling device comprising a hash of a caller identification, the called number and a shared secret encryption key, (d) extracts the caller identification and the called number from the encrypted data using the shared secret encryption key, (e) determines whether the extracted caller identification and the extracted called number are valid, and (f) transfers the call to the called device whenever the extracted caller identification and the extracted called number are valid.

6. The system as recited in claim 5 , wherein the calling device further comprises an anti-vishing agent.

7. A method for authenticating a calling device comprising the steps of:

trapping by an agent on the calling device the called number;

receiving a call from the calling device to a called device, at a controller, wherein the controller intercepts the call from the calling device to the called device;

sending a first authentication request for the call from the controller to the calling device;

receiving, at the controller, a first authentication response for the call from the calling device, wherein the first authentication response for the call comprises calling device encrypted data generated by the calling device, wherein the calling device encrypted data includes a hash of a caller identification for the calling device and a called number using a shared secret key;

extracting, by the controller, the caller identification and the called number from the encrypted data using the shared secret encryption key;

determining, by the controller, whether the extracted caller identification and the extracted called number are valid; and

transferring, by the controller, the call to the called device in response to determining that the extracted caller identification and the extracted called number are valid, wherein the step of transferring the call to the called device whenever the extracted caller identification and the extracted called number are valid comprises the steps of:

in response to determining that the extracted caller identification and the extracted called number are valid, sending a second authentication request for the call to the calling device, wherein the second authentication request for the call comprises controller device encrypted data generated by a controller using the calling number, the called number, the controller generated encryption key, the calling device generated encryption key and the shared secret encryption key;

receiving a second authentication response for the call from the calling device;

transferring the call to the called device whenever the second authentication response for the call indicates success; and

terminating the call whenever the second authentication response for the call indicates failure.

8. The method as recited in claim 7 , wherein:

the first authentication request for the call includes a controller generated encryption key;

the first authentication response for the call includes a calling device generated encryption key and the calling device encrypted data; and

wherein the calling device encrypted data is generated using the caller identification, a calling number, the called number, the controller generated encryption key, the calling device generated encryption key and the shared secret encryption key.

9. The method as recited in claim 7 , further comprising the steps of:

registering the calling device; and

creating the shared secret encryption key.

10. The method as recited in claim 7 , wherein the messages are exchanged using in-band communication channels, out-of-band communication channels, or a combination thereof.

Assignments (22)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2024
From: AVAYA LLC
To: ARLINGTON TECHNOLOGIES, LLC
Reel/Frame 067022/0780 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0227 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: CITIBANK, N.A.
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0117 →
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
MERGER Recorded Oct 28, 2011
From: SIPERA SYSTEMS, INC.
To: AVAYA INC.
Reel/Frame 027138/0920 →
RELEASE Recorded Oct 24, 2011
From: SILICON VALLEY BANK
To: SIPERA SYSTEMS, INC.
Reel/Frame 027120/0119 →
RELEASE OF SECURITY INTEREST Recorded Mar 4, 2011
From: COMERICA BANK
To: SIPERA SYSTEMS, INC.
Reel/Frame 025901/0892 →
SECURITY AGREEMENT Recorded Jan 25, 2011
From: SIPERA SYSTEMS, INC.
To: SILICON VALLEY BANK
Reel/Frame 025694/0699 →
SECURITY AGREEMENT Recorded Nov 3, 2010
From: SIPERA SYSTEMS, INC.
To: COMERICA BANK
Reel/Frame 025243/0742 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2009
From: KURAPATI, SRIKRISHNA; MOHAN, RAJESH; SADHASIVAM, KARTHIKEYAN; TYAGI, SATYAM
To: SIPERA SYSTEMS, INC.
Reel/Frame 022465/0082 →