IP Library › Granted Patent US 12,317,076
Granted Patent B2
US 12,317,076 · App. 18/139,244 · Granted May 27, 2025

Authenticated secure audio calling and digitally signed metadata for integrity verification

Inventors: Nagendra Kumar Nainar (Morrisville, NC); David John Zacks (Vancouver, CA); Vinay Saini (Bangalore, IN)
Assignee: Cisco Technology, Inc.
H04W12/065H04L9/3213H04M3/42034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,317,076
App. No.
18/139,244
Filed
Apr 25, 2023
Granted
May 27, 2025
Kind
B2
Art Unit
2408
USPC
726/5
Abstract

Techniques are described for providing secure audio calls between a calling party and a receiving party. Upon receiving a call request from a call initiating party, a notification is sent to the intended call recipient. The call recipient can send a request for a secure call. Upon receiving the request for a secure call, a bi-directional multifactor authentication is performed to authenticate the identity of both the call initiating party and the call receiving party. In response to successfully authenticating both parties, a secure call between the parties is established. One or more secure key tokens or other metadata can be embedded in the call to ensure security of the call.

Claims (71)

1. A method for secure audio communication between parties, the method comprising:

receiving, at a network-based security service, a call request from a calling party;

sending, at the network-based security service, a call notification to a receiving party;

receiving, at the network-based security service, a request for call authentication from the receiving party;

performing, by the network-based security service, a multifactor authentication of the calling party;

performing, by the network-based security service, a multifactor authentication of the receiving party;

establishing, by the network-based security service, a secure call between the calling party and the receiving party;

assigning a first token key to the receiving party, the first token key being unique to the receiving party;

embedding metadata in the secure call using the first token key and in a time series, wherein:

individual instances of the metadata embedded in the secure call include respective time stamps indicating respective times at which respective call data was generated or received; and

the individual instances of the metadata include the first token key that verifies that the respective times indicated by the respective time stamps at which the respective call data was generated or received are authentic.

2. The method as in claim 1 , the method as in claim 1 further comprising:

in response to authenticating the calling party via the multifactor authentication, assigning a second token key to the calling party, wherein

the first token key is assigned to the receiving party in response to authenticating the receiving party via the multifactor authentication.

3. The method as in claim 1 , wherein the method is performed by a third-party security service, and wherein the calling party and the receiving party are registered with the third-party security service.

4. The method as in claim 1 , wherein the call request from the calling party includes an indication that a secure call is requested.

5. The method as in claim 1 , wherein at least one of the multifactor authentication of the calling party and multifactor authentication of the receiving party includes biometric authentication.

6. The method as in claim 1 , further comprising:

storing a recording of the secure call;

upon receiving a request for access to the recording from a requesting party, performing a multifactor factor authentication of the requesting party; and

in response to authenticating the requesting party, allowing access to the recording of the secure call.

7. The method as in claim 6 , wherein the requesting party is either of the calling party and the receiving party and the multifactor authentication is in addition to the multifactor authentication performed to establish the secure call.

8. A system for providing secure telephonic communication, the system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving a call request from a calling party;

sending a call notification to a receiving party;

receiving a request for call authentication from the receiving party;

performing a multifactor authentication of the calling party;

performing a multifactor authentication of the receiving party;

establishing a secure call between the calling party and the receiving party;

assigning a first token key to the receiving party, the first token key being unique to the receiving party;

embedding metadata in the secure call using the first token key and in a time series, wherein:

individual instances of the metadata embedded in the secure call include respective time stamps indicating respective times at which respective call data was generated or received; and

the individual instances of the metadata include the first token key that verifies that the respective times indicated by the respective time stamps at which the respective call data was generated or received are authentic.

9. The system as in claim 8 , operations further comprising:

in response to authenticating the calling party via the multifactor authentication, assigning a second token key to the calling party, wherein

the first token key is assigned to the receiving party in response to authenticating the receiving party via the multifactor authentication.

10. The system as in claim 8 , wherein the operations are performed by a third-party security service, and wherein the calling party and the receiving party are registered with the third-party security service.

11. The system as in claim 8 , wherein the call request from the calling party includes an indication that a secure call is requested.

12. The system as in claim 8 , wherein at least one of the multifactor authentication of the calling party and multifactor authentication of the receiving party includes biometric authentication.

13. The system as in claim 8 , the operations further comprising:

storing a recording of the secure call;

upon receiving a request for access to the recording from a requesting party, performing a multifactor factor authentication of the requesting party; and

in response to authenticating the requesting party, allowing access to the recording of the secure call.

14. The system as in claim 13 , wherein the requesting party either of the calling party and the receiving party and the multifactor authentication is in addition to the multifactor authentication performed to establish the secure call.

15. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving a call request from a calling party;

sending a call notification to a receiving party;

receiving a request for call authentication from the receiving party;

performing a multifactor authentication of the calling party;

performing a multifactor authentication of the receiving party; and

establishing a secure call between the calling party and the receiving party;

assigning a first token key to the receiving party, the first token key being unique to the receiving party;

embedding metadata in the secure call using the first token key and in a time series, wherein:

individual instances of the metadata embedded in the secure call include respective time stamps indicating respective times at which respective call data was generated or received; and

the individual instances of the metadata include the first token key that verifies that the respective times indicated by the respective time stamps at which the respective call data was generated or received are authentic.

16. The one or more non-transitory computer-readable media as in claim 15 , the operations further comprising:

in response to authenticating the calling party via the multifactor authentication, assigning a second token key to the calling party, wherein

the first token key is assigned to the receiving party in response to authenticating the receiving party via the multifactor authentication.

17. The one or more non-transitory computer-readable media as in claim 15 , wherein the operations are performed by a third-party security service, and wherein the calling party and the receiving party are registered with the third-party security service.

18. The one or more non-transitory computer-readable media as in claim 15 , wherein the call request from the calling party includes an indication that a secure call is requested.

19. The one or more non-transitory computer-readable media as in claim 15 wherein at least one of the multifactor authentication of the calling party and multifactor authentication of the receiving party includes biometric authentication.

20. The one or more non-transitory computer-readable media as in claim 15 , the operations further comprising:

storing a recording of the secure call;

upon receiving a request for access to the recording from a requesting party, performing a multifactor factor authentication of the requesting party; and

in response to authenticating the requesting party, allowing access to the recording of the secure call.

21. The method of claim 2 , further comprising:

embedding second metadata in the secure call using the second token key and in a second time series, wherein:

individual instances of the second metadata embedded in the secure call include respective second time stamps indicating respective second times at which respective second call data was second generated by the calling party; and

the individual instances of the second metadata include the second token key that verifies that the respective second times indicated by the respective second time stamps at which the respective second call data was generated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2024
From: NAINAR, NAGENDRA KUMAR; ZACKS, DAVID JOHN; SAINI, VINAY
To: CISCO TECHNOLGY, INC.
Reel/Frame 066190/0631 →
Continuity (1)
Related Publication 20240365118A1 · Oct 31, 2024
References Cited (16)
US 9191817B1 · Paczkowski · 2015 [cited by examiner]
US 9277049B1 · Danis · 2016 [cited by examiner]
US 12143531B2 · Douglas · 2024 [cited by examiner]
US 20070283142A1 · Milstein et al. · 2007 [cited by applicant]
US 20130232335A1 · King · 2013 [cited by examiner]
US 20160162900A1 · Dutt · 2016 [cited by examiner]
US 20170142096A1 · Reddy · 2017 [cited by examiner]
US 20180183925A1 · Gallo · 2018 [cited by applicant]
US 20180241879A1 · Badger · 2018 [cited by examiner]
US 20200034521A1 · Teng et al. · 2020 [cited by applicant]
US 20200336314A1 · Barakat · 2020 [cited by examiner]
US 20220086139A1 · Venkatesh et al. · 2022 [cited by applicant]
US 20230088868A1 · Haltom · 2023 [cited by examiner]
US 20230353569A1 · Zuo · 2023 [cited by examiner]
WO WO2011146533 · 2011 [cited by applicant]
Patel et al., “Continuous User Authentication on Mobile Devices: Recent progress and remaining challenges”, IEEE Signal Processing Magazine, vol. 33, Issue: 4, Jul. 2016. [cited by examiner]