Dynamic Pin Dual Factor Authentication Using Mobile Device Audio Session
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current two-factor authentication methods for securing financial transactions are costly and vulnerable due to the use of non-encrypted communication for secondary passwords, necessitating a stronger and more cost-efficient solution.
Innovation Solution
A Plug and Play (PnP) architecture for two-factor authentication that initiates actions on the server and receives user input through an audio session, validating credentials and minimizing fraud by comparing a randomly generated code displayed on the portal with the code entered by the user on their registered device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional second level authentication methods are used (secondary password via text/message/email), then authentication security is improved, but cost increases and communication security deteriorates due to non-encrypted means
Solution Approach 1:
The patent replaces traditional text-based authentication mechanisms with voice-based authentication. Instead of sending codes via SMS/email that travel through non-encrypted channels, the system uses voice calls where the authentication code is spoken and captured through the user's mobile device microphone. This substitution of communication medium maintains security while reducing vulnerability to interception.
Solution Approach 2:
The patent introduces the user's mobile device as an intermediary component in the authentication process. The mobile device serves as both the communication channel and the verification mechanism - it receives the voice call, captures the spoken code through its microphone, and validates the input. This intermediary approach eliminates the need for separate text messaging infrastructure and enhances security through the device's existing secure components.
2Reliability
If device-based token generation is used for second level authentication, then authentication security is improved, but device complexity and integration cost increase
Solution Approach 1:
The patent leverages the mobile device's existing self-service capabilities - specifically its telephone function and microphone - for authentication purposes. Rather than requiring specialized authentication hardware or software installation, the system uses the device's built-in communication and audio capture features. This approach eliminates the need for complex token generation software while maintaining strong authentication security.
Solution Approach 2:
The patent makes the mobile device serve multiple functions: it acts as the authentication client, the communication channel, the code input device, and the verification terminal. By utilizing the device's existing multi-functional capabilities (phone, microphone, display), the system avoids introducing separate dedicated authentication hardware or complex software, thereby reducing overall system complexity.
3Reliability
If audio session-based authentication is implemented, then authentication security and cost efficiency are improved, but implementation complexity increases
Solution Approach 1:
The patent segments the authentication process into distinct functional phases: code generation (server-side), audio session establishment (communication phase), code capture (microphone phase), and code verification (validation phase). This segmentation allows each component to be implemented independently using standard technologies, reducing overall implementation complexity while maintaining high security through the coordinated interaction of these segmented functions.
Data Source
AI summary
The present invention provides cost efficient two way authentication method in which the authentication module can be provided as a Plug and Play (PnP) architecture enabling dual layer security with reduced cost where the actions are initiated by a server and user input is received through an audio session for added security. The second level authentication can be carried out with mobile as client device making it cost efficient. The invention can be hosted as an independent service or can be integrated with existing authentication mechanisms, making it elegant for usage.


