Dynamic Passphrase Voice Biometric Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing voice recognition systems for secure access are vulnerable to spoofing due to static passphrases and lack of robust two-factor authentication, as they rely on user designations that do not confirm the user's identity.
Innovation Solution
A biometric authentication system using a mobile device that generates a random passphrase for voice recognition, linking secure systems with mobile applications through visual identifiers like QR codes, and employing on-boarding and verification processes to ensure the user's identity matches the reference data, thereby reducing spoofing risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static passphrases are used for voice recognition access control, then the system is easier to implement and operate, but the system becomes vulnerable to spoofing attacks
Solution Approach 1:
The system transitions from static passphrases to dynamic passphrases that change with each authentication attempt. The passphrase is generated randomly at the time of authentication request, ensuring that even if captured, it cannot be reused for spoofing attacks. This dynamic approach maintains ease of operation while significantly improving security reliability.
Solution Approach 2:
The system changes the parameter of the passphrase from static to dynamic by introducing randomness and time-variance. Instead of using a fixed passphrase stored in the system, a new random passphrase is generated for each authentication attempt, changing the security parameter to prevent replay attacks while maintaining operational simplicity.
2Ease of operation
If user designations are used for access control, then the system is simpler to operate, but it cannot verify the actual user identity
Solution Approach 1:
The system replaces the mechanical entry of user designations with biometric voice recognition. Instead of relying on users to correctly input usernames or IDs, the system captures and analyzes voice characteristics, substituting manual input with automated biometric verification that accurately identifies the actual user.
Solution Approach 2:
The system introduces voice biometrics as an intermediary between the user designation and authentication verification. The voice print serves as a mediator that links the user's physical presence to their digital identity, enabling accurate identity verification while maintaining ease of operation through natural voice input.
3Reliability
If two-factor authentication with mobile apps is implemented, then security is enhanced, but the system requires additional user-maintained devices
Solution Approach 1:
The system merges the two authentication factors into a single voice-based authentication process. Instead of requiring separate physical tokens and knowledge factors, the voice biometric simultaneously provides both identification and verification, combining multiple security functions into one unified mechanism that reduces device complexity.
Solution Approach 2:
The voice biometric system performs multiple authentication functions universally - it serves as both the identification factor (who the user is) and the verification factor (confirming identity), replacing the need for separate authentication devices and methods while maintaining high security standards.
4Reliability
If dynamic passphrases are used for voice recognition, then spoofing resistance is improved, but the system complexity increases
Solution Approach 1:
The system implements self-service by automatically generating and managing dynamic passphrases without requiring user intervention. The random passphrase generation, voice capture, and authentication verification are all automated processes that occur seamlessly during the authentication attempt, improving spoofing resistance while avoiding additional complexity for the user.
Data Source
AI summary
A process for granting or denying a user access to a system using biometrics is disclosed. The process includes receiving a unique identifier for the system, receiving a unique identifier associated with the user, and verifying that the user is authorized to access the system. A passcode is transmitted to the device in the possession of the user, and a speech sample of the user speaking the passcode is returned. One or more attributes of the speech sample is compared with one or more attributes that are expected to be in a speech sample. Access is granted or denied based upon a correlation between the file's actual attributes and the predicted attributes.

