IP Library › Granted Patent US 12,457,207
Granted Patent B2
US 12,457,207 · App. 17/847,939 · Granted Oct 28, 2025

Systems and methods for phone number certification and verification

Inventors: Benjamin Montgomery (San Diego, CA); William W. Smith (Charlottesville, VA)
Assignee: Just One Technologies LLC
H04L63/0823H04L9/3247H04M3/42042H04M3/436H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,207
App. No.
17/847,939
Granted
Oct 28, 2025
Kind
B2
Abstract

Methods, systems, apparatuses, and computer-readable storage mediums are described for issuing digital certificates to phone numbers and verifying phone numbers based on the digital certificates. For instance, a client may request from a certificate authority a digital certificate to be associated with the client's phone number. The certificate authority issues a phone number challenge to the client to verify that the request did in fact come from the client. The certificate authority signs and issues the digital certificate to the client responsive to a successful challenge. The digital certificates are utilized to exchange messages between a caller and call recipient to determine whether a phone number provided via CLI is accurate or inaccurate. Embodiments described herein determine whether the phone number is accurate using a process referred herein as positive CLI verification and determines whether the phone number is inaccurate using a process referred herein as negative CLI verification.

Claims (72)

1. A method in a server for associating a digital certificate with a phone number associated with a first client, the method comprising:

receiving a request from the first client for a signed digital certificate, the request specifying the phone number associated with the first client and a uniform resource identifier (URI) of a relay server;

determining to utilize a first phone number verification process from a plurality of phone number verification processes based at least on the request;

providing, to the first client, a phone number verification request in accordance with the first phone number verification process, the phone number verification request specifying a first verification code;

responsive to receiving a second verification code, determining whether the second verification code matches the first verification code;

in response to determining that the second verification code matches the first verification code;

causing generation of a signed digital certificate comprising the URI of the relay server, and causing a lookup service to store the signed digital certificate in association with the first client; and

causing a second client to:

obtain the signed digital certificate from the lookup service, and

utilize the signed digital certificate to determine the URI of the relay server and send a message to the first client via at least the relay server, wherein the utilization of the signed digital certificate prevents the relay server from decrypting the message.

2. The method of claim 1 , further comprising:

in response to determining that the second verification code does not match the first verification code or in response to determining that no second verification code is received, denying the request for the signed digital certificate.

3. The method of claim 1 , wherein the lookup service enables the signed digital certificate to be searchable and retrievable by a plurality of requesting entities, the plurality of requesting entities comprising the second client.

4. The method of claim 3 , wherein the signed digital certificate further comprises the phone number associated with the first client.

5. The method of claim 1 , wherein the first phone number verification process comprises a short message service (SMS)-based verification process, and wherein said providing the phone number verification request comprises:

providing, to the first client, the phone number verification request as an SMS-based text message comprising the first verification code via a first communication channel; and

receiving the second verification code via a second communication channel that is different than the first communication channel.

6. The method of claim 1 , wherein the first phone number verification process comprises an audio code-based verification process, and wherein said providing the phone number verification request comprises:

initiating, via a first communication channel, a telephonic communication session with the first client;

responsive to the telephonic communication session being accepted, providing the first verification code as an auditory code via the telephonic communication session; and

receiving the second verification code via a second communication channel that is different than the first communication channel.

7. The method of claim 6 , wherein the request for the signed digital certificate further specifies the first phone number verification process.

8. The method of claim 1 , wherein the server is associated with one or more URIs comprising a first URI and a second URI, the request for the signed digital certificate received via the first URI, the method further comprising:

receiving, via the second URI, another request from the first client for the signed digital certificate, the another request specifying the phone number associated with the first client;

determining to utilize a second phone number verification process from the plurality of phone number verification processes based at least on a mapping of the second URI to the second phone number verification process, the second phone number verification process different from the first phone number verification process; and

providing, to the first client, another phone number verification request in accordance with the second phone number verification process.

9. A computing device for associating a digital certificate with a phone number associated with a first client, comprising:

at least one processor circuit; and

at least one memory that stores program code configured to perform a method when executed by the at least one processor circuit, the method comprising:

receiving a request from the first client for a signed digital certificate, the request specifying the phone number associated with the first client;

determining a phone number verification process from a plurality of phone number verification processes based on the request;

providing, to the first client, a phone number verification request in accordance with the determined phone number verification process, the phone number verification request specifying a first verification code;

responsive to receiving a second verification code, determining whether the second verification code matches the first verification code;

in response to determining that the second verification code matches the first verification code, providing the signed digital certificate to the first client, the signed digital certificate comprising a uniform resource identifier (URI) associated with a relay server configured to send messages between the first client and another device;

causing a lookup service to store the signed digital certificate in association with the first client; and

causing a second client to:

obtain the signed digital certificate from the lookup service, and

utilize the signed digital certificate to send an encrypted message to the first client via at least the relay server, wherein utilization of the signed digital certificate prevents the relay server from decrypting the encrypted message.

10. The computing device of claim 9 , the method further comprising:

in response to determining that the second verification code does not match the first verification code or in response to determining that no second verification code is received, denying the request for the signed digital certificate.

11. The computing device of claim 9 , wherein the lookup service that enables the signed digital certificate to be searchable and retrievable by a plurality of requesting entities, the plurality of requesting entities comprising the second client.

12. The computing device of claim 11 , wherein the signed digital certificate further comprises the phone number associated with the first client.

13. The computing device of claim 9 , wherein the phone number verification process comprises a short message service (SMS)-based verification process, and wherein said providing the phone number verification request comprises:

providing, to the first client, the phone number verification request as an SMS-based text message comprising the first verification code via a first communication channel; and

receiving the second verification code via a second communication channel that is different than the first communication channel.

14. The computing device of claim 9 , wherein the phone number verification process comprises an audio code-based verification process, and wherein said providing the phone number verification request comprises:

initiating, via a first communication channel, a telephonic communication session with the first client;

responsive to the telephonic communication session being accepted, providing the first verification code as an auditory code via the telephonic communication session; and

receiving the second verification code via a second communication channel that is different than the first communication channel.

15. The computing device of claim 14 , wherein the request for the signed digital certificate further specifies the phone number verification process.

16. A computer-readable storage medium having program instructions recorded thereon that, when executed by at least one processor, perform a method for associating a digital certificate with a phone number associated with a client, the method comprising:

receiving a request from the client for a signed digital certificate, the request specifying the phone number associated with the client;

determining a phone number verification process from a plurality of phone number verification processes based on the request;

providing, to the client, a phone number verification request in accordance with the determined phone number verification process, the phone number verification request specifying a first verification code;

responsive to receiving a second verification code, determining whether the second verification code matches the first verification code;

in response to determining that the second verification code matches the first verification code:

generating the digital certificate, the digital certificate comprising a uniform resource identifier (URI) associated with a relay server configured to send messages between the client and another device,

signing the digital certificate, and

causing a lookup service to store the signed digital certificate in association with the phone number associated with the client, the lookup service configured to enable the signed digital certificate to be searchable based at least on the phone number associated with the client and retrievable by a requesting entity, the lookup service executing on a server separate from a client device associated with the client and corresponding to the phone number; and

causing the requesting entity to:

obtain the signed digital certificate from the lookup service based at least on the phone number associated with the client, and

utilize the signed digital certificate to send a message to the client via the relay server, wherein the utilization of the signed digital certificate prevents the relay server from decrypting the message.

17. The computer-readable storage medium of claim 16 , the method further comprising:

in response to determining that the second verification code does not match the first verification code or in response to determining that no second verification code is received, denying the request for the signed digital certificate.

18. The computer-readable storage medium of claim 16 , wherein the phone number verification process comprises a short message service (SMS)-based verification process, and wherein said providing the phone number verification request comprises:

providing, to the client, the phone number verification request as an SMS-based text message comprising the first verification code via a first communication channel; and

receiving the second verification code via a second communication channel that is different than the first communication channel.

19. The computer-readable storage medium of claim 16 , wherein the phone number verification process comprises an audio code-based verification process, and wherein said providing the phone number verification request comprises:

initiating, via a first communication channel, a telephonic communication session with the client;

responsive to the telephonic communication session being accepted, providing the first verification code as an auditory code via the telephonic communication session; and

receiving the second verification code via a second communication channel that is different than the first communication channel.

20. The computer-readable storage medium of claim 19 , wherein the request for the signed digital certificate further specifies the phone number verification process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2022
From: MONTGOMERY, BENJAMIN; SMITH, WILLIAM W.
To: JUST ONE TECHNOLOGIES LLC
Reel/Frame 060295/0752 →
Continuity (2)
Division 17001421 · Aug 24, 2020
Related Publication 20220337580A1 · Oct 20, 2022
References Cited (32)
US 6792531B2 · Heiden et al. · 2004 [cited by applicant]
US 7779250B2 · Song et al. · 2010 [cited by applicant]
US 8228902B2 · Mehmood et al. · 2012 [cited by applicant]
US 8681783B2 · Carney et al. · 2014 [cited by applicant]
US 9332119B1 · Danis · 2016 [cited by examiner]
US 10149156B1 · Tiku et al. · 2018 [cited by applicant]
US 10374809B1 · Dasarakothapalli · 2019 [cited by examiner]
US 20020065828A1 · Goodspeed · 2002 [cited by examiner]
US 20060002556A1 · Paul · 2006 [cited by applicant]
US 20070106612A1 · O'Brien · 2007 [cited by examiner]
US 20070162742A1 · Song · 2007 [cited by examiner]
US 20090046839A1 · Chow et al. · 2009 [cited by applicant]
US 20100278322A1 · Krantz · 2010 [cited by examiner]
US 20150188712A1 · Teuwen · 2015 [cited by examiner]
US 20170041463A1 · Yaung · 2017 [cited by examiner]
US 20180192290A1 · Soulez · 2018 [cited by examiner]
US 20180343251A1 · Voth · 2018 [cited by examiner]
US 20190036688A1 · Wasily · 2019 [cited by examiner]
US 20190213317A1 · Fujikawa · 2019 [cited by examiner]
US 20190220583A1 · Douglas · 2019 [cited by examiner]
US 20200028690A1 · Barakat · 2020 [cited by examiner]
US 20200145528A1 · Lee · 2020 [cited by examiner]
US 20200389552A1 · Trim · 2020 [cited by examiner]
US 20210075907A1 · Murphy et al. · 2021 [cited by applicant]
US 20220060467A1 · Montgomery et al. · 2022 [cited by applicant]
Ivan Torroledo et al., Hunting Malicious TLS Certificates with Deep Neural Networks, Jan. 15, 2018, ACM, pp. 64-73. (Year: 2018). [cited by examiner]
Arun Venkataramani et al., Design Requirements of a Global Name Service for a Mobility-Centric, Trustworthy Internetwork, Feb. 21, 2013, IEEE, pp. 1-9. (Year: 2013). [cited by examiner]
Ahmad Sghaier Omar et al., Decentralized Identifiers and Verifiable Credentials for Smartphone Anticounterfeiting and Decentralized IMEI Database, Aug. 11, 2020, IEEE, vol. 43, Issue: 3, pp. 174-180. (Year: 2020). [cited by examiner]
Lein Harn et al., Generalized Digital Certificate for User Authentication and Key Establishment for Secure Communications, Jul. 2011, IEEE, vol. 10, Issue: 7, pp. 2372-2379. (Year: 2011). [cited by examiner]
Elwell, J., “Connected Identity in the Session Initiation Protocol (SIP)”, RFC 4916, Jun. 2007, 24 pages. [cited by applicant]
Reaves, et al., “AuthentiCall: Efficient Identity and Content Authentication for Phone Calls”, Proceedings of the 26th USENIX Security Symposium, Aug. 16-18, 2017, pp. 575-592. [cited by applicant]
Tu, et al., “Toward Standardization of Authenticated Caller ID Transmission”, ITU Kaleidoscope, IEEE Communications Standards Magazine, Sep. 2017, pp. 30-36. [cited by applicant]