[go: up one dir, main page]
More Web Proxy on the site http://driver.im/

TWI516082B - Communication secure authentication system and method - Google Patents

Communication secure authentication system and method Download PDF

Info

Publication number
TWI516082B
TWI516082B TW100136240A TW100136240A TWI516082B TW I516082 B TWI516082 B TW I516082B TW 100136240 A TW100136240 A TW 100136240A TW 100136240 A TW100136240 A TW 100136240A TW I516082 B TWI516082 B TW I516082B
Authority
TW
Taiwan
Prior art keywords
security level
call
security
level code
representative number
Prior art date
Application number
TW100136240A
Other languages
Chinese (zh)
Other versions
TW201316743A (en
Inventor
陳脩德
劉雅蘭
Original Assignee
財團法人電信技術中心
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 財團法人電信技術中心 filed Critical 財團法人電信技術中心
Priority to TW100136240A priority Critical patent/TWI516082B/en
Publication of TW201316743A publication Critical patent/TW201316743A/en
Application granted granted Critical
Publication of TWI516082B publication Critical patent/TWI516082B/en

Links

Landscapes

  • Telephonic Communication Services (AREA)

Description

受話安全認證系統與方法Received security authentication system and method

本申請案是有關於一種受話系統與方法,且特別是有關於一種受話安全認證系統與方法。The present application relates to a system and method for receiving a call, and in particular to a system and method for authenticating a call.

隨著語音傳輸技術之進步,使得愈來愈多電子裝置使用資料傳輸線路來傳送語音訊號,進而漸漸取代傳統語音傳輸之方式。舉例來說,例如是Google Voice、學術網路之VOIP、WiMAX、Face Time以及Skype等。然而,此種依據資料線路所傳送的語音訊號極易被有心人士從中竊取資料訊號進而達到竊聽之目的。With the advancement of voice transmission technology, more and more electronic devices use data transmission lines to transmit voice signals, and gradually replace the traditional voice transmission mode. For example, Google Voice, VOIP for academic networks, WiMAX, Face Time, and Skype. However, the voice signal transmitted by the data line can be easily intercepted by the interested person to achieve the purpose of eavesdropping.

所以,存在一種需求,如何能夠安心的使用以資料傳輸之方式所傳送的語音封包來進行語音通訊,且能夠了解未知顯示來電是否為一危險電話號碼,實為目前研究發展之一重要方向。Therefore, there is a need for how to use voice packets transmitted by means of data transmission for voice communication, and to know whether an unknown display call is a dangerous telephone number, which is an important direction of current research and development.

本申請案係有關於一種受話安全認證系統與方法,其可藉由額外的認證伺服器來使得發話端與收話端能以加密之型式進行通話;此外,更可藉由認證伺服器來控管未知來電,以杜絕任何騷擾或是詐騙電話。The present application relates to a system and method for receiving a secure call, which can enable an utterer and a caller to communicate in an encrypted form by using an additional authentication server; in addition, it can be controlled by an authentication server. Manage unknown calls to prevent any harassment or fraudulent calls.

根據本發明之一方面,提出一種受話安全認證系統,包括一認證伺服器。此認證伺服器係連接一第一網路並經由該第一網路與一受話端通訊。該認證伺服器並接收來自該受話端的一發話確認要求,該發話確認要求包含一代表號。具有該代表號的一發話端經一第二網路撥接給該受話端,該認證伺服器回覆一安全等級碼予該受話端。According to an aspect of the present invention, a call security authentication system is provided, including an authentication server. The authentication server is connected to a first network and communicates with a receiver via the first network. The authentication server receives an acknowledgment request from the called end, and the utterance confirmation request includes a representative number. A caller having the representative number is dialed to the callee via a second network, and the authentication server replies with a security level code to the callee.

根據本發明另一方面,提出一種受話安全認證方法,包括下列步驟:經由一第一網路接收來自一受話端的一發話確認要求,該發話確認要求包含一代表號,而一具有該代表號的發話端經一第二網路撥接給該受話端;查詢關於該代表號之相關訊息,以決定一安全等級碼,且該安全等級碼對應一安全等級訊息;以及回覆該安全等級碼予該受話端,俾使該受話端將該安全等級碼對應的安全等級訊息顯示出來。According to another aspect of the present invention, a method for authenticating a call security is provided, comprising the steps of: receiving a call confirmation request from a callee via a first network, the call confirmation request including a representative number, and a call with the representative number The calling end is dialed to the receiving end via a second network; the related information about the representative number is queried to determine a security level code, and the security level code corresponds to a security level message; and the security level code is replied to the At the receiving end, the receiving end displays the security level information corresponding to the security level code.

根據本發明再一方面,提出一種受話安全認證方法,適用於一受話端,包括下列步驟:下載一應用程式,該應用程式經由一第一網路建立該受話端與一認證伺服器通訊;經由一第二網路接收一發話端的一通話請求後,發出一發話確認要求至該認證伺服器,該發話確認要求包含該發話端的一代表號;接收來自該認證伺服器所回覆的一安全等級碼,且該安全等級碼對應一安全等級訊息;以及將該安全等級碼對應的安全等級訊息顯示於該受話端。According to still another aspect of the present invention, a method for authenticating a call security is provided, which is applicable to a call end, and includes the following steps: downloading an application, the application establishes the call end to communicate with an authentication server via a first network; After receiving a call request from a caller, the second network sends a call confirmation request to the authentication server, the call confirmation request includes a representative number of the caller; and receives a security level code replied from the authentication server. And the security level code corresponds to a security level message; and the security level information corresponding to the security level code is displayed on the receiving end.

為讓本發明之上述內容能更明顯易懂,下文特舉一較佳實施例,並配合所附圖式,作詳細說明如下:In order to make the above-mentioned contents of the present invention more comprehensible, a preferred embodiment will be described below, and in conjunction with the drawings, a detailed description is as follows:

雖然本發明將參閱含有本發明較佳實施例之所附圖式予以充份描述,但在此描述之前應瞭解熟悉本行之人士可修改在本文中所描述之發明,同時獲致本發明之功效。因此,須瞭解以下之描述對熟悉本行技藝之人士而言為一廣泛之揭示,且其內容不在於限制本發明。Although the invention will be fully described with reference to the preferred embodiments of the invention, it should be understood that those skilled in the art can modify the invention described herein while achieving the effect of the invention. . Therefore, it is to be understood that the following description is a broad disclosure of those skilled in the art and is not intended to limit the invention.

請參照第一圖,其繪示本發明之受話安全認證系統100之示意圖。在本發明的實施例中,受話安全認證系統100至少包括一認證伺服器110。於一實施例中,受話安全認證系統100可更包括受話端120、發話端130與一資料庫140。Please refer to the first figure, which shows a schematic diagram of the called security authentication system 100 of the present invention. In the embodiment of the present invention, the called security authentication system 100 includes at least one authentication server 110. In an embodiment, the received security authentication system 100 may further include a receiving end 120, a calling end 130, and a database 140.

認證伺服器110,舉例來說,例如是一具有網路能力的數據處理庫,可依據由網路所傳送進來之資料進行資料處理,並依據不同的要求各別加以回應。於一實施例中,認證伺服器110可包括一ENUMBER資料庫,其存有各類電話號碼、e-mail、網址、任何足以識別發話端130或受話端120的資訊。The authentication server 110 is, for example, a network-capable data processing library, which can perform data processing according to data transmitted from the network, and responds according to different requirements. In an embodiment, the authentication server 110 may include an ENUMBER database storing various types of phone numbers, e-mails, web addresses, and any information sufficient to identify the sender 130 or the receiver 120.

受話端120與發話端130,例如是具有有線/無線傳輸功能的手持式電子裝置、電腦、遊戲主機、家電等任何電子裝置,其具備基本的操作系統與傳輸功能,可藉由網路與其它電子裝置進行溝通。The receiving end 120 and the calling end 130 are, for example, any electronic device such as a handheld electronic device with a wired/wireless transmission function, a computer, a game console, a home appliance, etc., which have basic operating system and transmission functions, and can be connected by network and others. Electronic devices communicate.

資料庫140,可設置於認證伺服器110之內及/或外,舉例來說,可為設置於認證伺服器110內之儲存裝置,其儲存有各種資料可供認證伺服器110取用,此些資料例如是用戶之黑名單等。然此資料庫140也可為設置於外部之資料庫,例如是警政署之資料庫。認證伺服器110可經由網路連結至外部之資料庫140以取得所需之資料,例如是警政與相關單位公告之詐騙電話號碼資料等。該資料庫記錄曾經被檢舉為惡意電話,或警政署與相關單位公告之詐騙電話號碼。The data library 140 can be disposed in and/or outside the authentication server 110. For example, it can be a storage device disposed in the authentication server 110, and stores various materials for the authentication server 110 to use. Some of the information is, for example, a blacklist of users. However, the database 140 can also be an externally located database, such as a database of the police department. The authentication server 110 can be connected to the external database 140 via the network to obtain the required information, such as fraudulent telephone number information announced by the police and relevant units. The database records fraudulent telephone numbers that have been reported as malicious calls or announced by the Police Department and relevant units.

此認證伺服器110可連接一第一網路N1,並經由此第一網路N1與受話端120通訊。其中,認證伺服器110係接收來自該受話端120的一發話確認要求,此發話確認要求至少包括一代表號,而具有此代表號的一發話端130經第二網路N2撥接給受話端120。認證伺服器110並依據此發話確認要求中的代表號回覆一安全等級碼予受話端120。其中,第一網路例如是網際網路,此第二網路例如為電信通訊網路;代表號例如是電話號碼、e-mail、網址、或任何足以識別發話端的資訊。The authentication server 110 can be connected to a first network N1 and communicate with the receiver 120 via the first network N1. The authentication server 110 receives an acknowledgment request from the receiver 120. The acknowledgment request includes at least one representative number, and a utterance 130 having the representative number is dialed to the receiver via the second network N2. 120. The authentication server 110 replies a security level code to the receiving terminal 120 according to the representative number in the acknowledgment request. The first network is, for example, the Internet, and the second network is, for example, a telecommunications communication network; the representative number is, for example, a phone number, an e-mail, a web address, or any information sufficient to identify the originating end.

如此一來,由於受話端120可藉由第一網路與認證伺服器110通訊,其中第一網路不同於第二網路,使得受話端120可不需經由第二網路來與認證伺服器通訊,避免受話端120同時經由第二網路傳送,導致第二網路雍塞。In this way, since the receiving end 120 can communicate with the authentication server 110 through the first network, wherein the first network is different from the second network, the receiving end 120 can be connected to the authentication server via the second network. Communication prevents the receiving end 120 from being simultaneously transmitted via the second network, causing the second network to be blocked.

舉例來說,當具有此代表號的發話端130經第二網路N2發出通話要求至受話端120時,發話端120想確認此代表號,例如是電話號碼、一特定e-mail位址等任何可用以代表身分之串列,是否為一詐騙電話號碼或是危險電話號碼,則受話端120可經由第一網路N1發出具有此代表號的發話確認要求至認證伺服器110。其中,第一網路不相同於第二網路。而認證伺服器110則依據此發話確認要求中的代表號回傳對應此代表號的安全等級碼予受話端120。For example, when the calling terminal 130 having the representative number sends a call request to the receiving terminal 120 via the second network N2, the calling terminal 120 wants to confirm the representative number, such as a telephone number, a specific e-mail address, and the like. Any string that can be used to represent the identity, whether it is a fraudulent telephone number or a dangerous telephone number, the receiving terminal 120 can issue an acknowledgment request with the representative number to the authentication server 110 via the first network N1. The first network is different from the second network. The authentication server 110 returns the security level code corresponding to the representative number to the receiving end 120 according to the representative number in the acknowledgment request.

於一實施例中,發話端130於經第二網路N2撥接給受話端120時,發話端130並經第一網路N1發出一包含代表號的發話通知給認證伺服器110。而此認證伺服器110則註冊此代表號以供受話端120的確認要求之使用。In an embodiment, when the calling terminal 130 is dialed to the receiving terminal 120 via the second network N2, the calling terminal 130 sends a call notification including the representative number to the authentication server 110 via the first network N1. The authentication server 110 registers this representative number for use by the confirmation request of the receiving terminal 120.

再者,於另一實施例中,當發話端130經過第一網路N1發出包含發話端130的代表號與所欲撥接之受話端120的代表號之發話通知至認證伺服器110時,認證伺服器110除註冊發話端130的代表號外,更依據發話端130與受話端120各別的代表號產生一即時金鑰,並將此即時金鑰傳送至發話端130。而待受話端120經由第一網路N1發出一發話確認要求至認證伺服器110時,認證伺服器110即回覆此即時金鑰至受話端120。如此一來,藉由認證伺服器110所產生之即時金鑰,發話端130與受話端120可依據即時金鑰進行加密通訊。Furthermore, in another embodiment, when the calling terminal 130 sends a call notification including the representative number of the calling terminal 130 and the representative number of the called terminal 120 to be sent to the authentication server 110 via the first network N1, The authentication server 110 generates an instant key according to the representative number of the calling terminal 130 and the receiving terminal 120, and transmits the instant key to the calling terminal 130. When the to-be-received terminal 120 sends an acknowledgment request to the authentication server 110 via the first network N1, the authentication server 110 replies to the instant key to the receiving terminal 120. In this way, by authenticating the instant key generated by the server 110, the calling terminal 130 and the receiving end 120 can perform encrypted communication according to the instant key.

前述之安全等級碼,舉例來說,請參照第二圖,其繪示將安全等級碼分為六個等級之個別對應情形。For the foregoing security level code, for example, please refer to the second figure, which illustrates an individual corresponding situation in which the security level code is divided into six levels.

若發話端130的代表號係經過身分認證,且雙方通話係於語音加密之情況下所進行,則安全等級碼設定為「安全加密」。舉例來說,若發話端130與受話端120之操作環境係在VoIP,則首先由發話端130透過第一網路N1向認證伺服器110要求一即時金鑰作為語音加密用,並依據此即時金鑰透過第二網路N2,例如是電信業者的SIP Server,嘗試發話。而當電信業者的SIP Server驗證發話端130的合法金鑰後,即通知受話端120。並由SIP Server通知收話端120向認證伺服器110要求一即時金鑰作為語音加密用,並透過SIP Server加以回應。SIP Server驗證受話端120的即時金鑰後,通知發話端130。此時受話端120與發話端130即可以金鑰加密而透過電信業者的Media Gateway進行通話。上述流程完成後即表示發話端130與受話端120之間係以身分認證與語音加密之方式進行通訊,故安全等級碼設為「安全加密」。If the representative number of the calling terminal 130 is authenticated by the identity and the two parties are engaged in voice encryption, the security level code is set to "secure encryption". For example, if the operating environment of the calling terminal 130 and the receiving end 120 is in VoIP, the calling terminal 130 first requests an instant key to the authentication server 110 through the first network N1 for voice encryption, and according to the instant. The key attempts to speak through the second network N2, such as the carrier's SIP Server. When the SIP server of the carrier verifies the legal key of the sender 130, the receiver 120 is notified. The SIP server notifies the receiving terminal 120 to request an instant key to the authentication server 110 for voice encryption, and responds through the SIP Server. After the SIP Server verifies the instant key of the called terminal 120, it notifies the calling terminal 130. At this time, the receiving terminal 120 and the calling terminal 130 can be encrypted by the key and communicated through the carrier's Media Gateway. After the above process is completed, it means that the identity end 130 and the receiving end 120 communicate by means of identity authentication and voice encryption, so the security level code is set to "secure encryption".

若發話端130的代表號係經過發話者認證,則安全等級碼設為「安全」。舉例來說,若發話端130與受話端120之操作環境係在3G網路,則於發話端130經第一網路N1發出包含代表號的發話通知至認證伺服器110時,認證伺服器110會註冊此代表號。待受話端120發送一發話確認要求至認證伺服器110時,認證伺服器110可檢查此代表號之發話端130是否符於一特定規則,例如是於前10秒內撥號。上述流程完成後即表示發話端130與受話端120之間係以發話者認證之方式進行通訊,故安全等級碼設為「安全」。If the representative number of the calling terminal 130 is authenticated by the caller, the security level code is set to "secure". For example, if the operating environment of the calling terminal 130 and the receiving terminal 120 is in the 3G network, the authentication server 110 is sent when the calling terminal 130 sends a call notification including the representative number to the authentication server 110 via the first network N1. This representative number will be registered. When the receiving end 120 sends an acknowledgment request to the authentication server 110, the authentication server 110 can check whether the utterance end 130 of the representative number is in a specific rule, for example, dialing within the first 10 seconds. After the above process is completed, it means that the sender 130 and the receiver 120 communicate by means of the sender authentication, so the security level code is set to "safe".

此外,若經檢查確認代表號存於受話端120的電話簿內,則設定安全等級碼為「風險」。若代表號存在於受話端120的撥號記錄內,則設定安全等級碼為「威脅」。若代表號經檢查曾被檢舉為惡意電話,且並非為安全加密、安全、或風險等級,則安全等級碼設為「危險」。若代表號經檢查係警政署與相關單位公告之詐騙電話號碼,且並非為安全加密、安全、風險、或危險等級,則安全等級碼設為「嚴重危險」。In addition, if it is checked that the representative number is stored in the phone book of the receiving terminal 120, the security level code is set to "risk". If the representative number exists in the dialing record of the receiving end 120, the security level code is set to "threat". If the representative number has been reported as a malicious call and is not securely encrypted, secure, or risk level, the security level code is set to "dangerous". If the representative number is checked by the Police Department and the relevant unit for the fraudulent telephone number and is not for security encryption, security, risk, or hazard level, the security level code is set to “serious danger”.

其中,上述之安全等級碼可為由認證伺服器110依據代表號來編輯,或是由受話端120之內部程式所編輯。而各安全等級碼各別對應一安全等級訊息,此安全等級訊息可於受話端120之螢幕上顯示,以提醒使用者。舉例來說,受話端120從認證伺服器110接收安全等級碼後,受話端120將此安全等級碼對應的安全等級訊息顯示出來。The security level code may be edited by the authentication server 110 according to the representative number or edited by the internal program of the receiver 120. Each security level code corresponds to a security level message, and the security level information can be displayed on the screen of the receiving end 120 to remind the user. For example, after the receiving end 120 receives the security level code from the authentication server 110, the receiving end 120 displays the security level information corresponding to the security level code.

此外,如前所述,上述之安全等級碼可為由受話端120依據代表號來編輯。舉例來說,受話端120從認證伺服器110接收該安全等級碼後,根據受話端120的來電記錄或撥號記錄或是否曾經被檢舉為惡意電話或警政署與相關單位公告之詐騙電話號碼來編輯該安全等級碼,受話端120並將編輯後之安全等級碼對應的安全等級訊息顯示出來。In addition, as described above, the security level code described above may be edited by the receiving terminal 120 based on the representative number. For example, after the receiving terminal 120 receives the security level code from the authentication server 110, according to the incoming call record or the dialing record of the receiving terminal 120 or whether it has been reported as a malicious phone or a fraudulent telephone number announced by the police department and the relevant unit. The security level code is edited, and the receiving terminal 120 displays the security level information corresponding to the edited security level code.

總結來說,安全等級碼是根據發話端130是否認證,或是否存在於受話端120的電話簿內,或是否存在於受話端120的撥號記錄內,或是否存在於受話端120的來電記錄內,或是否曾經被檢舉為惡意電話,或是否警政署與相關單位公告之詐騙電話號碼來編輯。In summary, the security level code is based on whether the calling terminal 130 authenticates, whether it exists in the phone book of the receiving terminal 120, or whether it exists in the dialing record of the receiving end 120, or whether it exists in the incoming call record of the receiving end 120. , or whether it has been reported as a malicious call, or whether the police department and the relevant unit announced the fraud phone number to edit.

除此之外,受話端120可內建一程式,受話端120之使用者於接聽一電話號碼後,發覺此電話號碼之持有者為詐騙集團等之危險電話號碼,則可逕行由受話端120之一應用程式上之一軟體或硬體按鈕,上傳此電話號碼為危險號碼之訊息至認證伺服器110。若對應此電話號碼之所上傳的危險訊息超過一臨界值,則此認證伺服器110可逕行判斷此電話號碼為危險號碼,並將此訊息傳送至資料庫140,以新增此電話號碼至資料庫140。In addition, the receiving terminal 120 can have a built-in program. After the user of the receiving terminal 120 answers a telephone number and finds that the holder of the telephone number is a dangerous telephone number such as a fraud group, the user can go through the receiving end. One of the software or hardware buttons on one of the applications 120 uploads the message with the phone number as a dangerous number to the authentication server 110. If the dangerous message uploaded corresponding to the phone number exceeds a threshold, the authentication server 110 can determine that the phone number is a dangerous number and transmit the message to the database 140 to add the phone number to the data. Library 140.

請參照第三圖,其根據本發明繪示一種受話安全認證方法300之流程圖。請同時參照第一圖。於步驟S310中,認證伺服器110經由一第一網路N1接收來自一受話端120的一發話確認要求,該發話確認要求包含一代表號,而一具有該代表號的發話端130經一第二網路撥接給該受話端120。Please refer to the third figure, which illustrates a flow chart of a method for receiving secure authentication 300 according to the present invention. Please also refer to the first picture. In step S310, the authentication server 110 receives a call confirmation request from a receiving terminal 120 via a first network N1, the call confirmation request includes a representative number, and a call end 130 having the representative number passes through a first The second network is dialed to the receiver 120.

於步驟S320中,查詢關於該代表號之相關訊息,以決定一安全等級碼,且該安全等級碼對應一安全等級訊息。查詢之動作可於認證伺服器110或受話端120中完成。In step S320, the related information about the representative number is queried to determine a security level code, and the security level code corresponds to a security level message. The action of the query can be done in the authentication server 110 or the receiver 120.

於步驟S330中,認證伺服器110回覆安全等級碼予受話端120,俾使受話端120將安全等級碼對應的安全等級訊息顯示出來。In step S330, the authentication server 110 replies the security level code to the receiving end 120, and causes the receiving end 120 to display the security level information corresponding to the security level code.

受話安全認證方法300可更包括下述步驟:經由該第一網路N1接收來自該發話端130發出一包含該代表號的發話通知;以及註冊該代表號以供該受話端120的確認要求。The received security authentication method 300 may further include the steps of: receiving, via the first network N1, a call notification from the originating terminal 130 that includes the representative number; and registering the representative number for the confirmation request of the called terminal 120.

受話安全認證方法300可更包括下述步驟:查詢關於該代表號之相關訊息,是根據該受話端120的來電記錄或撥號記錄或是否曾經被檢舉為惡意電話或警政署與相關單位公告之詐騙電話號碼,並據以編輯該安全等級碼。The method for receiving the security authentication method 300 may further include the following steps: querying the related information about the representative number according to the incoming call record or the dialing record of the called terminal 120 or whether it has been reported as a malicious call or an announcement by the police department and the relevant unit. Fraud the phone number and edit the security level code accordingly.

請參照第四圖,其根據本發明繪示一種受話安全認證方法400之流程圖,其適用於受話端120。請同時參照第一圖。於步驟S410中,下載一應用程式,此應用程式經由一第一網路建立該受話端與一認證伺服器通訊。Please refer to the fourth figure, which is a flowchart of a method for receiving a secure authentication method 400, which is applicable to the receiving end 120. Please also refer to the first picture. In step S410, an application is downloaded, and the application establishes the receiver via a first network to communicate with an authentication server.

於步驟S420中,經由一第二網路N2接收一發話端130的一通話請求後,發出一發話確認要求至該認證伺服器110,該發話確認要求包含該發話端130的一代表號。In step S420, after receiving a call request from a call center 130 via a second network N2, a call confirmation request is sent to the authentication server 110, and the call confirmation request includes a representative number of the call end 130.

於步驟S430中,接收來自該認證伺服器110所回覆的一安全等級碼,且該安全等級碼對應一安全等級訊息。In step S430, a security level code replied from the authentication server 110 is received, and the security level code corresponds to a security level message.

於步驟S440中,將該安全等級碼對應的安全等級訊息顯示於該受話端120。In step S440, the security level information corresponding to the security level code is displayed on the receiving end 120.

於一實施例中,受話安全認證方法400之流程可更包括下列步驟:根據該受話端120的來電記錄或撥號記錄來編輯該安全等級碼,並將該安全等級碼對應的安全等級訊息顯示於該受話端120。In an embodiment, the process of the received security authentication method 400 may further include the steps of: editing the security level code according to the incoming call record or the dialing record of the receiving end 120, and displaying the security level information corresponding to the security level code on the The receiving end 120.

舉例來說,請參照第五A與第五B圖,其各別繪示使用此應用程式撥話與顯示安全等級之示意圖。於一實施例中,使用者可使用安裝於發話端130的應用程式撥打電話,而此應用程式即可與認證伺服器110以背景模式之方式進行通訊。而於另一實施例中,安裝於受話端120的應用程式可依據認證伺服器110或經受話端120處理之後的安全等級碼所對應的安全等級訊息顯示於螢幕上,例如是如第五B圖所示。For example, please refer to the fifth and fifth B diagrams, which respectively illustrate the schematic diagram of using the application to dial and display the security level. In one embodiment, the user can make a call using an application installed on the dispatcher 130, and the application can communicate with the authentication server 110 in the background mode. In another embodiment, the application installed on the receiving end 120 can be displayed on the screen according to the security level information corresponding to the authentication server 110 or the security level code processed by the terminal 120, for example, as the fifth B. The figure shows.

總結來說,由於本發明所揭露之受話安全認證系統具有一認證伺服器,使得即使受話端與發話端為不同電信系統或係以資料網路來傳送語音訊息資料,仍可藉由認證伺服器之服務來確認具有一代表號之發話端是否為危險電話號碼或是使用者。此外,更可藉由認證伺服器依據發話端與受話端的代表號產生一即時金鑰,使得該受話端與該發話端可依據此即時金鑰以加密方式進行通訊,避免資料網路易遭有心人士竊取資料進而得知通話內容之缺點。In summary, since the received security authentication system disclosed in the present invention has an authentication server, the authentication server can be authenticated even if the receiving end and the transmitting end are different telecommunication systems or data networks are used to transmit voice message data. The service is to confirm whether the sender with a representative number is a dangerous phone number or a user. In addition, the authentication server can generate an instant key according to the representative numbers of the calling end and the receiving end, so that the receiving end and the calling end can communicate in an encrypted manner according to the instant key, so as to avoid the data network being vulnerable to the interested person. Stealing the data and knowing the shortcomings of the call.

綜上所述,雖然本發明已以一較佳實施例揭露如上,然其並非用以限定本發明。本發明所屬技術領域中具有通常知識者,在不脫離本發明之精神和範圍內,當可作各種之更動與潤飾。因此,本發明之保護範圍當視後附之申請專利範圍所界定者為準。 In view of the above, the present invention has been disclosed in a preferred embodiment, and is not intended to limit the present invention. A person skilled in the art can make various changes and modifications without departing from the spirit and scope of the invention. Therefore, the scope of the invention is defined by the scope of the appended claims.

100‧‧‧受話安全認證系統 100‧‧‧Received Security Certification System

110‧‧‧認證伺服器 110‧‧‧Authentication Server

120‧‧‧受話端 120‧‧‧Terminal

130‧‧‧發話端 130‧‧‧Talker

140‧‧‧資料庫 140‧‧‧Database

S310~S330、S410~S440‧‧‧流程步驟 S310~S330, S410~S440‧‧‧ Process steps

第一圖係繪示本發明之受話安全認證系統之示意圖。 The first figure shows a schematic diagram of the called security authentication system of the present invention.

第二圖係繪示將安全等級碼分為六個等級之個別對應情形。 The second figure shows an individual correspondence case in which the security level code is divided into six levels.

第三圖係繪示根據本發明一種受話安全認證方法之流程圖。 The third figure is a flow chart showing a method for authenticating a call security according to the present invention.

第四圖繪示一種受話安全認證方法之流程圖。 The fourth figure shows a flow chart of a method for receiving security authentication.

第五A圖繪示使用此應用程式撥話之示意圖。 Figure 5A shows a schematic diagram of dialing using this application.

第五B圖繪示顯示安全等級之示意圖。 Figure 5B shows a schematic diagram showing the security level.

100...受話安全認證系統100. . . Received security authentication system

110...認證伺服器110. . . Authentication server

120...受話端120. . . Receiving end

130...發話端130. . . Speaker

140...資料庫140. . . database

Claims (19)

一種受話安全認證系統,包括:一認證伺服器,連接一第一網路並經由該第一網路與一受話端通訊;其中,該認證伺服器接收來自該受話端的一發話確認要求,該發話確認要求包含一代表號,而具有該代表號的一發話端經一第二網路撥接給該受話端,該認證伺服器回覆一安全等級碼予該受話端;其中,該代表號係與識別該發話端身份有關的資訊,該安全等級碼係關聯於該代表號。 A call security authentication system, comprising: an authentication server, connected to a first network and communicating with a receiver via the first network; wherein the authentication server receives an acknowledgment request from the receiver, the utterance The confirmation request includes a representative number, and a calling terminal having the representative number is dialed to the receiving end via a second network, and the authentication server returns a security level code to the receiving end; wherein the representative number is Information related to the identity of the utterance is identified, and the security level code is associated with the representative number. 如申請專利範圍第1項所述之受話安全認證系統,其中該發話端經該第二網路撥接給該受話端時,該發話端經該第一網路發出一包含該代表號的發話通知給該認證伺服器,且該認證伺服器註冊該代表號以供該受話端的確認要求。 The call security authentication system of claim 1, wherein the caller sends a call containing the representative number via the first network when the caller is dialed to the callee by the second network. The authentication server is notified, and the authentication server registers the representative number for the confirmation request of the called party. 如申請專利範圍第1項所述之受話安全認證系統,進一步包含一資料庫,該資料庫記錄曾經被檢舉為惡意電話,或警政署與相關單位公告之詐騙電話號碼。 The system for receiving security authentication as described in claim 1 further includes a database for recording fraudulent telephone numbers that have been reported as malicious calls or announced by the police department and relevant units. 如申請專利範圍第1項所述之受話安全認證系統,其中該第一網路為網際網路,該第二網路為電信通訊網路。 The system for receiving a security authentication according to claim 1, wherein the first network is an internet network, and the second network is a telecommunication communication network. 如申請專利範圍第1項所述之受話安全認證系統,其中該認證伺服器根據該代表號編輯該安全等級碼,且該安全等級碼對應一安全等級訊息。 The system for claiming security according to claim 1, wherein the authentication server edits the security level code according to the representative number, and the security level code corresponds to a security level message. 如申請專利範圍第5項所述之受話安全認證系統,其中該受話端從該認證伺服器接收並處理該安全等級碼 後,該受話端將該安全等級碼對應的安全等級訊息顯示出來。 The system for receiving a security authentication according to claim 5, wherein the receiving terminal receives and processes the security level code from the authentication server. After that, the receiving end displays the security level information corresponding to the security level code. 如申請專利範圍第5項所述之受話安全認證系統,其中該受話端從該認證伺服器接收該安全等級碼後,根據該受話端的來電記錄或撥號記錄或是否曾經被檢舉為惡意電話或警政署與相關單位公告之詐騙電話號碼來編輯該安全等級碼,該受話端將該編輯後之安全等級碼對應的安全等級訊息顯示出來。 The system for receiving a security authentication according to claim 5, wherein the receiving terminal receives the security level code from the authentication server, according to the incoming call record or the dialing record of the receiving end or whether it has been reported as a malicious call or police The security phone number is announced by the government department and the relevant unit to edit the security level code, and the received party displays the security level message corresponding to the edited security level code. 如申請專利範圍第1項所述之受話安全認證系統,其中該安全等級碼是根據該發話端是否認證,或是否存在於該受話端的電話簿內,或是否存在於該受話端的撥號記錄內,或是否存在於該受話端的來電記錄內,或是否曾經被檢舉為惡意電話,或是否警政署與相關單位公告之詐騙電話號碼來編輯。 The security authentication system of claim 1, wherein the security level code is based on whether the terminal is authenticated, or is present in a phone book of the called end, or is present in a dialing record of the receiving end, Whether it exists in the caller's record of the called party, or whether it has been reported as a malicious call, or whether the police department and the relevant unit announced the fraudulent phone number to edit. 如申請專利範圍第2項所述之受話安全認證系統,其中該發話通知更包括該受話端的代表號,該認證伺服器更依據該受話端的代表號與該代表號產生一即時金鑰,該認證伺服器更回覆該即時金鑰予該發話端與該受話端,使得該發話端與該受話端可依據該即時金鑰進行加密通訊。 The call security authentication system of claim 2, wherein the call notification further includes a representative number of the called end, and the authentication server generates an instant key according to the representative number of the called end and the representative number, the authentication The server further replies the instant key to the calling terminal and the receiving end, so that the calling terminal and the receiving end can perform encrypted communication according to the instant key. 如申請專利範圍第1項所述之受話安全認證系統,其中該代表號係電話號碼、e-mail address、或足以識別發話端的資訊。 The system for receiving a security authentication according to claim 1, wherein the representative number is a telephone number, an e-mail address, or information sufficient to identify the sender. 一種受話安全認證方法,包括:經由一第一網路接收來自一受話端的一發話確認要求,該發話確認要求包含一代表號,而一具有該代表號的 發話端經一第二網路撥接給該受話端;查詢關於該代表號之相關訊息,以決定一安全等級碼,且該安全等級碼對應一安全等級訊息;以及回覆該安全等級碼予該受話端,俾使該受話端處理並將該安全等級碼對應的安全等級訊息顯示出來;其中,該代表號係與識別該發話端身份有關的資訊,該安全等級碼係關聯於該代表號。 A method for authenticating a call security includes: receiving, by a first network, a call confirmation request from a call end, the call confirmation request including a representative number, and a call with the representative number The calling end is dialed to the receiving end via a second network; the related information about the representative number is queried to determine a security level code, and the security level code corresponds to a security level message; and the security level code is replied to the Receiving, the receiving end processing and displaying the security level information corresponding to the security level code; wherein the representative number is related to the information identifying the identity of the calling terminal, and the security level code is associated with the representative number. 如申請專利範圍第11項所述之受話安全認證方法,進一步包含:經由該第一網路接收來自該發話端發出一包含該代表號的發話通知;以及註冊該代表號以供該受話端的確認要求。 The method for claiming security authentication according to claim 11, further comprising: receiving, via the first network, a call notification from the caller that includes the representative number; and registering the representative number for confirmation by the callee Claim. 如申請專利範圍第11項所述之受話安全認證方法,進一步包含:查詢關於該代表號之相關訊息,是根據該受話端的來電記錄或撥號記錄或是否曾經被檢舉為惡意電話或警政署與相關單位公告之詐騙電話號碼,並據以編輯該安全等級碼。 The method for authenticating a security according to claim 11 further includes: querying the relevant information about the representative number according to the incoming call record or the dialing record of the called party or whether it has been reported as a malicious call or the police department and The relevant unit announces the fraudulent phone number and edits the security level code accordingly. 如申請專利範圍第11項所述之受話安全認證方法,其中該安全等級碼是根據發話者是否認證,或是否存在於受話端的電話簿內,或是否存在於受話端的撥號記錄內,或是否存在於受話端的來電記錄內,或是否曾經被檢舉為惡意電話,或是否為警政署與相關單位公告之詐騙電話號碼來編輯。 The method for claiming security authentication according to claim 11, wherein the security level code is based on whether the utterer authenticates, or exists in a phone book of the receiving end, or exists in a dialing record of the receiving end, or exists In the call record of the receiver, whether it has been reported as a malicious call, or whether it is edited by the police department and the relevant unit to announce the fraud phone number. 如申請專利範圍第11項所述之受話安全認證方 法,其中該代表號係電話號碼、e-mail address、或足以識別發話端的資訊。 As claimed in the scope of claim 11 Method, wherein the representative number is a telephone number, an e-mail address, or information sufficient to identify the sender. 一種受話安全認證方法,適用於一受話端,包含:下載一應用程式,該應用程式經由一第一網路建立該受話端與一認證伺服器通訊;經由一第二網路接收一發話端的一通話請求後,發出一發話確認要求至該認證伺服器,該發話確認要求包含該發話端的一代表號;接收來自該認證伺服器所回覆的一安全等級碼,且該安全等級碼對應一安全等級訊息;以及處理並將該安全等級碼對應的安全等級訊息顯示於該受話端;其中,該代表號係與識別該發話端身份有關的資訊,該安全等級碼係關聯於該代表號。 A method for authenticating a call, which is applicable to a call end, comprising: downloading an application, the application establishes the call end to communicate with an authentication server via a first network; and receives a call end via a second network After the call request, an acknowledgment request is sent to the authentication server, the acknowledgment request includes a representative number of the utterance end; a security level code replied from the authentication server is received, and the security level code corresponds to a security level And processing the security level information corresponding to the security level code on the receiving end; wherein the representative number is related to identifying the identity of the calling end, and the security level code is associated with the representative number. 如申請專利範圍第16項所述之受話安全認證方法,進一步包含:根據該受話端的來電記錄或撥號記錄來編輯該安全等級碼,並將該安全等級碼對應的安全等級訊息顯示於該受話端。 The method for authenticating the received security according to claim 16 of the patent application, further comprising: editing the security level code according to the incoming call record or the dialing record of the called end, and displaying the security level information corresponding to the security level code on the receiving end . 如申請專利範圍第16項所述之受話安全認證方法,其中該安全等級碼是根據發話者是否認證,或是否存在於受話端的電話簿內,或是否存在於受話端的撥號記錄內,或是否存在於受話端的來電記錄內,或是否曾經被檢舉為惡意電話,或是否為警政署與相關單位公告之詐騙電話號碼來編輯。 The method for claiming security authentication according to claim 16, wherein the security level code is based on whether the utterer authenticates, or exists in the phone book of the receiving end, or exists in the dialing record of the receiving end, or exists In the call record of the receiver, whether it has been reported as a malicious call, or whether it is edited by the police department and the relevant unit to announce the fraud phone number. 如申請專利範圍第16項所述之受話安全認證方法,其中該代表號係電話號碼、e-mail address、或足以識別發話端的資訊。 The method for claiming security authentication according to claim 16, wherein the representative number is a telephone number, an e-mail address, or information sufficient to identify the sender.
TW100136240A 2011-10-06 2011-10-06 Communication secure authentication system and method TWI516082B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW100136240A TWI516082B (en) 2011-10-06 2011-10-06 Communication secure authentication system and method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW100136240A TWI516082B (en) 2011-10-06 2011-10-06 Communication secure authentication system and method

Publications (2)

Publication Number Publication Date
TW201316743A TW201316743A (en) 2013-04-16
TWI516082B true TWI516082B (en) 2016-01-01

Family

ID=48803186

Family Applications (1)

Application Number Title Priority Date Filing Date
TW100136240A TWI516082B (en) 2011-10-06 2011-10-06 Communication secure authentication system and method

Country Status (1)

Country Link
TW (1) TWI516082B (en)

Also Published As

Publication number Publication date
TW201316743A (en) 2013-04-16

Similar Documents

Publication Publication Date Title
US9060057B1 (en) Systems and methods for caller ID authentication, spoof detection and list based call handling
US8457290B2 (en) Method, apparatus, and computer program products for providing dynamic replacement communication identification service
TWI672073B (en) Communication, communication access/call method, device and system between mobile terminals
US20090025075A1 (en) On-demand authentication of call session party information during a telephone call
US20080192918A1 (en) Method and system for establishing a telephone connection
US9247389B2 (en) Systems, methods, devices and arrangements for emergency call services
US20110211682A1 (en) Telephony fraud prevention
US8422986B1 (en) Systems, methods, devices and arrangements for emergency call services using non-traditional endpoint devices
US8681783B2 (en) Prevention of call spoofing in a Voice over Internet Protocol (VoIP) network
US11917098B2 (en) Communication system for mitigating incoming spoofed callers using social media
US8711738B2 (en) Methods, systems, and computer-readable media for providing an event alert
EP2051495A1 (en) Method and system for establishing a telephone connection
JP5477379B2 (en) Rogue call detection device, rogue call detection method, and rogue call detection program
Mustafa et al. End-to-end detection of caller ID spoofing attacks
US8843999B1 (en) VOIP identification systems and methods
JP5882963B2 (en) COMMUNICATION SYSTEM, COMMUNICATION METHOD, AND COMPUTER PROGRAM
US20160197921A1 (en) Secure Data Transmission System
EP2385688B1 (en) Method and system for improved communication security
US9407748B2 (en) System and method for providing broadband notification
Wang et al. Spoofing Against Spoofing: Toward Caller ID Verification in Heterogeneous Telecommunication Systems
TWI516082B (en) Communication secure authentication system and method
US20130171966A1 (en) Method and Apparatus for Facilitating Communication Between a Finder of a Misplaced Wireless Terminal and an Authorized User
KR100385860B1 (en) Caller Identification Method Using Public CA In The PC-To-Phone Environment
KR101542829B1 (en) Method of authenticating the sender using the server
CN103220438B (en) Method and communication device for exchanging information in a voice communication system