IP Library Granted Patent US 9,961,197
Granted Patent B2
US 9,961,197 · App. 14/594,973 · Granted May 1, 2018

System, method and apparatus for authenticating calls

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,961,197
App. No.
14/594,973
Granted
May 1, 2018
Kind
B2
Abstract

The present invention provides a system, method and apparatus for authenticating calls that is a robust Anti-vishing solution. The present invention can identify Caller ID spoofing, verify dialed number to detect man-in-the middle and verify called party against dialed digits to detect impersonation. This solution can handle calls coming from any phone any where with little impact on user experience. Two separate solutions are tailored for smart phones (communication devices capable of running application software) and traditional phones to reduce the impact to user experience while providing robust verification.

Claims (55)

1. A method for authenticating a user of a calling device comprising:

receiving a first call from the calling device;

providing a notification to the calling device prior to terminating the first call, wherein the notification tells the user that an authentication process will begin following the termination of the first call;

in response to receiving the first call from the calling device, terminating the first call;

placing a second call to the calling device;

in the second call, prompting the user to speak one or more words and depress one or more keys on the calling device;

receiving, in the second call, the spoken words and one or more signals associated with the depressed keys;

comparing one or more biometric parameters of the received spoken words with a stored voice biometric template for the user, the received spoken words with the prompted words, and the received signals with the signals associated with the prompted keys; and

transferring the second call to a called device whenever the user is authenticated as a result of the comparison.

2. The method as recited in claim 1 , further comprising: playing a stored message to the user to authenticate the called device, wherein the stored message was previously recorded by the user during a registration process.

3. The method as recited in claim 2 , wherein the registration process comprises:

prompting the user to speak a message;

recording and storing the message; and

creating and storing the voice biometric template based on the user's voice.

4. The method as recited in claim 2 , wherein the registration process comprises periodically changing the stored message by prompting the user to speak a new message, recording the new message, and replacing the stored message with the new message.

5. The method as recited in claim 2 , wherein the stored message is not played to the user until the user is authenticated.

6. The method as recited in claim 1 , further comprising:

terminating the second call whenever the user is not authenticated; or

providing one or more notifications to the called device whenever the user is not authenticated.

7. The method as recited in claim 1 , wherein the authentication method prevents caller ID spoofing, man-in-the-middle attacks, record and replay attacks, called device impersonation, or a combination thereof.

8. The method as recited in claim 1 , wherein at least one of:

the one or more words and the one or more keys are randomly generated;

the one or more keys are selected from one or more digits of a telephone number of the called device; and

the one or more keys are selected from 0-9, * and # keys.

9. The method as recited in claim 1 , wherein:

the authentication method is an automated process executed by a controller operated by the called device, a network provider, a service provider, a facility provider or a call center;

the controller comprises a computer, a server, a switch, a PBX, or a gateway; and

the calling device comprises a phone, a computer, a PDA or other communications device.

10. An apparatus for authenticating a user of a calling device comprising:

a communications interface; and

a processor communicably coupled to the communications interface, wherein the processor: receives a first call from the calling device via the communications interface, provides a notification to the calling device prior to terminating the first call, wherein the notification tells the user that an authentication process will begin following the termination of the first call, terminates the first call in response to receiving the first call, places a second call to the calling device via the communications interface, prompts, in the second call, the user to speak one or more words and depress one or more keys on the calling device, receives, in the second call, the spoken words and one or more signals associated with the depressed keys via the communication interface, authenticates the user by comparing one or more biometric parameters of the received spoken words with a stored voice biometric template for the user, the received spoken words with the prompted words, and the received signals with the signals associated with the prompted keys, and transfers the second call to a called device whenever the user is authenticated.

11. The apparatus as recited in claim 10 , further comprising the operation of the processor playing a stored message to the user to authenticate the called device, wherein the stored message was previously recorded by the user during a registration process, and wherein the registration process comprises the operations of:

the processor prompting the user to speak a message;

the processor recording and storing the message; and

the processor creating and storing the voice biometric template based on the user's voice.

12. The apparatus as recited in claim 10 , further comprising the operation of the processor playing a stored message to the user to authenticate the called device, wherein the stored message was previously recorded by the user during a registration process, and wherein the registration process comprises periodically changing the stored message by prompting the user to speak a new message, recording the new message, and replacing the stored message with the new message.

13. The apparatus as recited in claim 10 , further comprising the operation of the processor playing a stored message to the user to authenticate the called device, wherein the stored message was previously recorded by the user during a registration process, and wherein the stored message is not played to the user until the user is authenticated.

14. The apparatus as recited in claim 10 , further comprising:

terminating the second call whenever the user is not authenticated; or

providing one or more notifications to the called device whenever the user is not authenticated.

15. The apparatus as recited in claim 10 , wherein the authentication method prevents caller ID spoofing, man-in-the-middle attacks, record and replay attacks, called device impersonation, or a combination thereof.

16. The apparatus as recited in claim 10 , wherein at least one of:

the one or more words and the one or more keys are randomly generated;

the one or more keys are selected from one or more digits of a telephone number of the called device; and

the one or more keys are selected from the 0-9, * and # keys.

17. The apparatus as recited in claim 16 , wherein the one or more words and the one or more keys are randomly generated.

18. The apparatus as recited in claim 16 , wherein the one or more keys are selected from the one or more digits of a telephone number of the called device.

19. The apparatus as recited in claim 10 , wherein:

the authentication method is an automated process executed by a controller operated by the called device, a network provider, a service provider, a facility provider or a call center;

the controller comprises a computer, a server, a switch, a PBX, or a gateway; and

the calling device comprises a phone, a computer, a PDA or other communications device.

20. A system for authenticating a user of a calling device comprising:

a communications network communicably coupled to the calling device;

a controller communicably coupled to the communications network wherein the controller comprises a communications interface communicably coupled to the communications network and a processor communicably coupled to the communications interface; and

wherein the processor: receives a first call from the calling device via the communications interface, provides a notification to the calling device prior to terminating the first call, wherein the notification tells the user that an authentication process will begin following the termination of the first call, terminates the first call in response to receiving the first call, places a second call to the calling device via the communications interface, prompts, in the second call, the user to speak one or more words and depress one or more keys on the calling device, receives, in the second call, the spoken words and one or more signals associated with the depressed keys via the communication interface, authenticates the user by comparing one or more biometric parameters of the received spoken words with a stored voice biometric template for the user, the received spoken words with the prompted words, and the received signals with the signals associated with the prompted keys, and transfers the second call to a called device whenever the user is authenticated.

Assignments (18)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2024
From: AVAYA LLC
To: ARLINGTON TECHNOLOGIES, LLC
Reel/Frame 067022/0780 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: CITIBANK, N.A.
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0117 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0227 →
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2016
From: KURAPATI, SRIKRISHNA; MOHAN, RAJESH; SADHASIVAM, KARTHIKEYAN; TYAGI, SATYAM
To: SIPERA SYSTEMS, INC.
Reel/Frame 039004/0489 →
MERGER Recorded Jun 24, 2016
From: SIPERA SYSTEMS, INC.
To: AVAYA INC.
Reel/Frame 039004/0566 →