Audio MFA Session Linking for Shared Public Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional multi-factor authentication methods require users to manually read and input security codes, leading to high error rates, especially for visually impaired users and those using shared devices, which consumes processing resources and network bandwidth.
Innovation Solution
An audio-based multi-factor authentication system where a portable device sends an audio message containing a security code to a public device, which communicates with a backend server to verify authorization, establishing a session that allows the portable device to access and control user accounts on the public device without manual input.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual code entry is used for authentication, then security verification can be performed, but error rates increase and resource consumption increases
Solution Approach 1:
The patent replaces the mechanical manual input system with an automated audio-based system. The portable device automatically captures audio from the public device's speaker, extracts the security code, and transmits it to the backend server without requiring manual typing or visual reading, thereby reducing errors and resource consumption
Solution Approach 2:
The authentication system performs self-service by automatically capturing, processing, and transmitting the security code. The portable device's application autonomously completes the authentication process by listening to the audio message, extracting the code, and submitting it for verification without human intervention
2Reliability
If manual code reading and input is required, then authentication can be verified, but accessibility is reduced for visually impaired users
Solution Approach 1:
The system replaces the visual-mechanical interaction (reading and typing) with an auditory-automated interaction. The public device speaks the security code aloud, and the portable device automatically captures and processes it, making the system accessible to visually impaired users who can hear but not see the code
Solution Approach 2:
The audio message serves as an intermediary that bridges the gap between the public device and the portable device. Instead of requiring direct visual contact with a display, the security code is transmitted through audio, which can be naturally perceived and processed by users with visual impairments
3Reliability
If security codes are displayed on shared devices, then authentication can proceed, but security risks increase due to unauthorized access
Solution Approach 1:
The audio message acts as a secure intermediary that allows the security code to be transmitted without being displayed on the shared public device screen. The code is spoken aloud and automatically captured by the user's portable device, preventing unauthorized users from reading the code from the public device display
Solution Approach 2:
The security code is extracted from the visual display domain and transferred to the audio domain. By speaking the code instead of displaying it, the system removes the code from the public device's visual interface where it could be compromised, and places it in an audio channel that is directly captured by the authenticated user's device
Data Source
AI summary
Techniques are described for accessing an account on a public device. In some implementations, an audio message is received from a portable computing device, requesting to establish an account access session between the portable computing device and the public device. A first communication based on the audio message is sent from the public device to a backend server. The backend server analyzes the first communication to determine whether the portable computing device is authorized to establish the account access session. A second communication is received from the backend server, indicating that the portable computing device is authorized. In response, the account access session is established between the portable computing device and the public device, wherein the account access session is employed by an application executing on the portable computing device to access account information associated with an account of a user of the portable computing device.


