Audio One-Time Password Encoding for Secure Voice Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Audio interface devices, such as smart home devices, face security concerns due to the inability to perform high-confidence authentications and data safety risks when using voice commands for payment transactions, as traditional authentication methods require direct interaction and may compromise password security.

Innovation Solution

An authentication system that generates and verifies an audio transmission including a one-time password encoded with primary and secondary security artifacts, allowing secure authentication without requiring direct user interaction with the device, using an authentication server and a verified user computing device to ensure secure communication and transaction authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional biometric or passcode authentication is used on audio interface devices, then security is improved, but ease of operation deteriorates because direct user interaction is required

Engineering Contradiction:
Improveauthentication securityVSAvoidremote operation capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a verified user computing device as an intermediary between the audio interface device and the authentication server. This intermediary device receives the audio transmission containing the one-time password and verifies it, allowing the audio interface device to perform authentication remotely without requiring direct user interaction with the audio device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical biometric authentication systems with an acoustic field-based system. Instead of requiring physical fingerprints or facial recognition, the system uses audio transmissions containing encoded one-time passwords that can be verified remotely through acoustic communication between devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If voice commands are used for authentication, then ease of operation is improved, but security deteriorates because passwords become audible and can be overheard

Engineering Contradiction:
Improvevoice command usabilityVSAvoidpassword security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into distinct components: the audio interface device generates and transmits the audio signal, the verified user computing device receives and verifies it, and the authentication server validates the transaction. This segmentation allows the one-time password to be encoded in the audio transmission without being directly spoken, reducing the risk of overheard authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameters of the audio transmission by encoding the one-time password within the acoustic signal characteristics rather than using audible speech. The audio transmission includes modified acoustic parameters that convey authentication information without making the password directly audible to listeners.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If one-time password encoding in audio transmissions is implemented, then security is improved, but device complexity increases due to additional authentication components

Engineering Contradiction:
Improvetransaction authenticationVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the verified user computing device serve multiple functions: it acts as both a communication endpoint for receiving audio transmissions and as a verification device for validating the audio content. This multi-functionality reduces the need for separate dedicated authentication hardware, thereby limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system performs self-verification through the comparison of audio transmissions between the audio interface device and the verified user computing device. The system automatically validates the one-time password encoding without requiring manual intervention or complex external verification mechanisms, simplifying the overall system architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11836719B2Encoding one-time passwords as audio transmissions including security artifacts
Publication Date: 2023.12.05 MASTERCARD INT INC
  • US11836719B2 patent drawing
  • US11836719B2 patent drawing
  • US11836719B2 patent drawing

AI summary

An authentication server computing device is provided. The authentication server computing device is configured to receive a transaction request from an audio interface device, generate a first audio file including a first audio transmission, wherein the first audio transmission includes a primary security artifact and at least one secondary security artifact and the primary security artifact is an encoding of a one-time password, store a reference data file including the first audio transmission, transmit the first audio file to a verified user computing device associated with the account identifier, receive a second audio file from the audio interface device, wherein the second audio file includes a second audio transmission, verify the second audio transmission by comparing the second audio transmission to the reference data file including the primary security artifact and the at least one secondary security artifact, and authorize the transaction based on verifying the second audio transmission.