Audio Token Multi-Factor Authentication via DTMF Playback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional multi-factor authentication methods are vulnerable to interception and inaccessible to visually impaired individuals and those with limited technology access, as they often require visual passcodes and internet-based submissions.

Innovation Solution

Implementing dual tone multiple frequency (DTMF) tones for multi-factor authentication, where a code is generated, transmitted as an audio file, and verified through playback on a registered playback device, allowing for secure and accessible authentication via telephone or other devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multi-factor authentication uses visual passcodes and internet-based submission, then authentication security is improved, but accessibility for visually impaired individuals and those with limited technology access deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces visual display mechanisms with audio output mechanisms. Instead of showing passcodes on screens, the system generates audio files containing DTMF tones that correspond to the passcode digits, which are then played through speakers or headphones. This substitution makes the authentication system accessible to visually impaired users while maintaining security through the use of encoded audio signals.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Device complexity

If authentication evidence is transmitted over network without encoding or encryption, then transmission simplicity is improved, but security against interception deteriorates

Engineering Contradiction:
Improvetransmission simplicityVSAvoidsecurity against interception
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transforms the passcode from a simple visual string into an encoded audio signal using DTMF (Dual-Tone Multi-Frequency) encoding. Each digit of the passcode is converted into a specific combination of audio frequencies. This parameter transformation ensures that even if the audio transmission is intercepted, the original passcode cannot be easily extracted without specialized decoding equipment, thus providing security while maintaining relatively simple transmission procedures.

Inventive Principle:
Principle #35Parameter changes

3Extent of automation

If multi-factor authentication requires internet access for both authentication factors, then centralized control is improved, but accessibility for users with limited technology access deteriorates

Engineering Contradiction:
Improvecentralized controlVSAvoidaccessibility across different devices
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent enables the authentication system to work across multiple device types including smartphones, tablets, computers, and traditional telephones. By using audio output capabilities that are universally present across these devices and leveraging standard telephone networks for audio transmission, the system maintains centralized control through the authentication server while allowing users to authenticate from any device without requiring internet connectivity for the second factor.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12170660B1Audio tokens for multi-factor authentication
Publication Date: 2024.12.17 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12170660B1 patent drawing
  • US12170660B1 patent drawing
  • US12170660B1 patent drawing

AI summary

Techniques are described for performing multi-factor authentication of a user during a service session, based at least partly on a code conveyed using an audio file. A code is generated that corresponds to the user and/or their user device. A playback device that is registered to the user can be used to output a playback of an audio file that encodes the code. The playback of the audio file is conveyed through the service session by the user device and received by a backend server, which analyzes the playback of the audio file to extract the code. The user can be authenticated based at least partly on verifying the code that is extracted from the playback of the audio file, by comparing the extracted code to the code that was generated and sent to the playback device.