IP Library Granted Patent US 8,548,432
Granted Patent B2
US 8,548,432 · App. 13/598,205 · Granted Oct 1, 2013

Authenticating voice calls from mobile devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,548,432
App. No.
13/598,205
Granted
Oct 1, 2013
Kind
B2
Abstract

Aspects relate to authorizing mobile devices for PBX-based voice services. A mobile device calls a PBX over a voice channel, and phone number identifier information is obtained and matched to identifier information for devices that known (authorizeable) to use the PBX. If there is one incoming call that matches to a given device, and an authentication token provided over a data channel matches an authentication token associated with that device, then the device is authorized for voice services. Where there are multiple matching calls, those devices are instructed to provide authentication tokens over their voice channels. The devices can detect absence of a data channel and provide authentication tokens over the voice channels; the devices also can wait to receive a call connected response and in the absence of such provide their authentication tokens over the voice channel. Tokens can be requested and downloaded for storage at the devices.

Claims (47)

1. A method of establishing service over a voice channel, comprising:

accepting a plurality of calls;

requesting identifying information for each accepted call, the identifying information including an encrypted identifying authentication token comprising a series of audible tones;

determining if any of the accepted calls has corresponding identifying information matching identification information corresponding to a first authorizable device;

determining if any of the accepted calls has corresponding identifying information which does not match any stored identification information;

determining if any of the accepted calls is one for which no identifying information was obtained;

for each accepted call which has identifying information which does not match stored identification information and for each accepted call for which no identifying information was obtained, requesting, over data channels of devices initiating those calls, that each such device provide, without a user input, a unique encrypted authentication token over a voice channel corresponding to an accepted call;

for each authentication token received, determining whether such authentication token matches an authentication token previously provided to a second authorizable device;

providing voice service via the voice channel over which the matching authentication token was provided;

requesting over a voice channel, that each device provide an authentication token when a corresponding data channel is not currently operable; and

thereafter removing each authentication token received from a database of issued and valid tokens; and

further comprising determining that the identifying authentication token is valid prior to providing voice service to the call having the corresponding identifying authentication token.

2. The method as recited in claim 1 , further comprising denying voice service when a first authentication token received matches a second authentication token received.

3. The method as recited in claim 1 , wherein requesting identifying information includes securely sending a message over a data channel.

4. The method of claim 1 , wherein the voice service is provided via a private branch exchange.

5. A communications device including a voice network interface, the device comprising:

a microprocessor having a control program associated therewith, the control program being configured to enable the device to:

accept a plurality of calls through the voice network interface;

request identifying information for each accepted call, the identifying information including an encrypted identifying authentication token comprising a series of audible tones;

determine if any of the accepted calls has corresponding identifying information matching identification information corresponding to a first authorizable device;

determine if any of the accepted calls has corresponding identifying information which does not match any stored identification information

determine if any of the accepted calls is one for which no identifying information was obtained;

for each accepted call which has identifying information which does not match stored identification information and for each accepted call for which no identifying information was obtained, request, over data channels of devices initiating those calls, that each such device provide a unique encrypted authentication token over a voice channel corresponding to an accepted call;

for each authentication token received, determine whether such authentication token matches an authentication token previously provided to a second authorizable device;

provide voice service via the voice channel over which the matching authentication token was provided; and

thereafter remove each authentication token received from a database of issued and valid tokens,

the control program further configured to:

enable the communications device to determine that the identifying authentication token is valid prior to providing voice service to the call having the corresponding identifying authentication token; and

enable the communications device to request, over a voice channel, that each device provide an authentication token when a corresponding data channel is not currently operable.

6. The communications device as recited in claim 5 , wherein the control program is further configured to enable the device to deny voice service when a first authentication token received matches a second authentication token received.

7. The communications device as recited in claim 5 , wherein requesting identifying information includes securely sending a message over a data channel.

8. The communications device as recited in claim 5 , wherein the voice service is provided via a private branch exchange.

9. A non-transitory memory storing instructions that, when loaded into a communications device having a voice network interface are executable to control the communications device to:

accept a plurality of calls through the voice network interface;

request identifying information for each accepted call, the identifying information comprising an encrypted authentication token comprising a series of audible tones;

determine if any of the accepted calls has corresponding identifying information matching identification information corresponding to a first authorizable device;

determine if any of the accepted calls has corresponding identifying information which does not match any stored identification information;

determine if any of the accepted calls is one for which no identifying information was obtained;

for each accepted call which has identifying information which does not match stored identification information and for each accepted call for which no identifying information was obtained, request, over data channels of devices initiating those calls, that each such device provide a unique encrypted authentication token over a voice channel corresponding to an accepted call;

for each authentication token received, determine whether such authentication token matches an authentication token previously provided to a second authorizable device;

provide voice service via the voice channel over which the matching authentication token was provided; and

thereafter remove each authentication token received from a database of valid and issued tokens;

the control program further configured to:

enable the communications device to determine that the identifying authentication token is valid prior to providing voice service to the call having the corresponding identifying authentication token; and

enable the communications device to request, over a voice channel, that each device provide an authentication token when a corresponding data channel is not currently operable.

10. The non-transitory memory as recited in claim 9 , storing instructions that when loaded into the communications device are executable to control the device to deny voice service when a first authentication token received matches a second authentication token received.

11. The non-transitory memory as recited in claim 9 , wherein requesting identifying information includes securely sending a message over a data channel.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Aug 16, 2013
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 031031/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 26, 2012
From: KEAST, LIAM JOHN; SPENCER, BRADFORD LAWRENCE; SINGH, MANVINDER
To: RESEARCH IN MOTION LIMITED
Reel/Frame 029526/0263 →