Audio Code Authentication for Mobile User Localization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for websites are cumbersome, as users struggle to remember multiple usernames and passwords, and lack a direct link to a person's real identity, with existing solutions like Single Sign-On and 2-factor authentication being costly or limited in scale.
Innovation Solution
A method and apparatus that uses an authentication server to receive an authentication request from a mobile user, generates a code associated with the user, and verifies it through an audio signal received from the user, linking the user's identity to a trusted entity's location, utilizing low-cost mobile handsets for secure authentication and localization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional username and password authentication is used for each website, then user identity can be authenticated, but users must remember multiple usernames and passwords which is cumbersome
Solution Approach 1:
The patent introduces a trusted entity (such as a mobile phone or authentication device) as an intermediary between the user and the authentication server. This trusted entity stores authentication credentials and communicates with the server to verify user identity, eliminating the need for users to directly manage multiple usernames and passwords while maintaining security.
2Reliability
If 2-factor authentication using physical tokens or smartcards is implemented, then authentication security is improved, but distribution cost to users becomes high limiting scale
Solution Approach 1:
The patent makes the trusted entity universal by allowing common devices like mobile phones to serve as authentication tools. The system is designed to work with standard mobile phones that already possess communication capabilities, eliminating the need for specialized expensive tokens or smartcards. This enables widespread adoption without high distribution costs while maintaining 2-factor authentication security.
3Measurement precision
If location verification is added to authentication, then user localization accuracy is improved, but system complexity increases
Solution Approach 1:
The trusted entity (mobile phone) automatically provides location information to the authentication server using its built-in GPS or network location capabilities. The user does not need to manually input location data, and the system leverages existing self-service capabilities of mobile devices to obtain location information, adding precision without proportionally increasing complexity.
Data Source
Figure 1
Figure 2
AI summary
In a method for authenticating and localizing a mobile user, an authentication server receives from a mobile user an authentication request and an identifier associated with a trusted entity, the location of the trusted entity being ascertainable by the server. The server produces a code associated with the mobile user in response to the authentication request and sends the code to the trusted entity for the trusted entity to provide the code to the mobile user. The server receives an audio signal from the mobile user and compares the audio signal received from the mobile user with the code. The server authenticates the mobile user when the audio signal comprises the code and localizes the mobile user based on the location of the trusted entity.