IP Library Granted Patent US 10,447,481
Granted Patent B2
US 10,447,481 · App. 15/459,597 · Granted Oct 15, 2019

Systems and methods for authenticating caller identity and call request header information for outbound telephony communications

Inventors: Huahong Tu (Tempe, AZ); Adam Doupe (Tempe, AZ); Gail-Joon Ahn (Phoenix, AZ); Ziming Zhao (Chandler, AZ)
Assignee: Arizona Board of Regents on Behalf of Arizona State University
H04L9/3247H04L9/3263H04L9/3268H04M3/42042H04M2203/6045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,481
App. No.
15/459,597
Granted
Oct 15, 2019
Kind
B2
Abstract

Various embodiments of a system and method for authenticating a call request header including identity information that is lightweight and deployable in VoIP and PSTN systems are disclosed.

Claims (36)

1. A method for authenticated communication, the method comprising:

receiving a key pair including a public key and a private key at a registrar, the key pair generated by a caller device, the caller device in communication with the registrar over a network;

receiving a routing address from the caller device at a registrar;

generating a nonce for the caller device using the registrar, the nonce encrypted with the public key;

sending the nonce encrypted with the public key to the routing address;

receiving the nonce at the registrar from the caller device, the nonce decrypted by the caller device using the public key; and

generating an identity certificate for the caller device using the registrar, the identity certificate including the routing address and the public key each signed by the registrar.

2. The method of claim 1 , further comprising:

sending the identity certificate to the caller device for generating an authenticated communication request header.

3. The method of claim of claim 2 , wherein the communication request header is used by the caller device to initiate a communication with a recipient device, the communication being at least one of a call, a short message service (SMS) message, or a multimedia messaging service (MMS) message.

4. The method of claim 1 , wherein the nonce is a randomly generated.

5. The method of claim 1 , wherein the registrar generates a signature for the nonce prior to sending the nonce encrypted with the public key to the routing address.

6. The method of claim 5 , wherein the caller device verifies an authenticity of the nonce using the signature prior to decrypting the nonce.

7. The method of claim 1 , wherein the identity certificate further includes an expiration time.

8. The method of claim 1 , further comprising:

revoking any previous identity signatures associated with the routing address.

9. The method of claim 1 , wherein the identity certificate further includes identity information associated with the caller device.

10. A method for authenticated communication, the method comprising:

receiving a communication session token at a recipient device from a caller device over a network in connection with a request for communication, the communication session token generated by the caller device using a timestamp and a recipient routing address each signed with a private key for the caller device;

obtaining an identity certificate for the caller device at the recipient device, the identity certificate including a caller routing address and a public key corresponding to the private key for the caller device, the caller routing address and the public key each authenticated by a registrar;

determining a validity of the communication session token by verifying the timestamp is within a valid duration and by matching the recipient routing address to a known routing address for the recipient device; and

generating an authentication of the request for communication based on the validity of the communication session token and the identity certificate.

11. The method of claim 10 , wherein the communication session token and the identity certificate are received at the recipient device as a set of fields in a communication request header with the request for communication.

12. The method of claim 11 , wherein the set of fields are included as an extension to the communication request header.

13. The method of claim 10 , wherein the identity certificate is obtained by the recipient device from at least one of a public database, the registrar, or a previous communication with the caller device.

14. The method of claim 10 , further comprising:

displaying the authentication of the request for communication with a delivery of the request for communication to the recipient device.

15. The method of claim 10 , wherein the caller device is a calling terminal or an origination switch and the recipient device is a receiving terminal or a termination switch.

16. A system for authenticated communication, the system comprising:

a caller device having a caller routing address and a key pair, the key pair including a public key and a private key;

a registrar in communication with the caller device, the registrar generating an identity certificate for the caller device following a verification of the caller routing address and the key pair, the identity certificate including a signed routing address and a signed public key for the caller device; and

a recipient device authenticating a request for communication received from the caller device over a network, the recipient device authenticating the request for communication using the identity certificate.

17. The system of claim 16 , wherein the request for communication includes a communication session token signed by the caller device using the private key.

18. The system of claim 17 , wherein the communication session token includes a timestamp for the request for communication and a recipient routing address.

19. The system of claim 18 , wherein the recipient device further authenticates the request for communication by verifying the timestamp is within a valid duration and by matching the recipient routing address to a known routing address for the recipient device.

20. The system of claim 16 , wherein the caller device is a calling terminal or an origination switch and the recipient device is a receiving terminal or a termination switch.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2017
From: TU, HUAHONG; DOUPE, ADAM; AHN, GAIL-JOON; ZHAO, ZIMING
To: ARIZONA BOARD OF REGENTS ON BEHALF OF ARIZONA STATE UNIVERSITY
Reel/Frame 042184/0982 →
Continuity (2)
Provisional Application 62308105 · Mar 14, 2016
Related Publication 20170264443A1 · Sep 14, 2017