Dynamic Pin Dual Factor Authentication Using Mobile Device Audio Session

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication methods for securing financial transactions are costly and vulnerable due to the use of non-encrypted communication for secondary passwords, necessitating a stronger and more cost-efficient solution.

Innovation Solution

A Plug and Play (PnP) architecture for two-factor authentication that initiates actions on the server and receives user input through an audio session, validating credentials and minimizing fraud by comparing a randomly generated code displayed on the portal with the code entered by the user on their registered device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional second level authentication methods are used (secondary password via text/message/email), then authentication security is improved, but cost increases and communication security deteriorates due to non-encrypted means

Engineering Contradiction:
Improveauthentication securityVSAvoidcommunication security vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional text-based authentication mechanisms with voice-based authentication. Instead of sending codes via SMS/email that travel through non-encrypted channels, the system uses voice calls where the authentication code is spoken and captured through the user's mobile device microphone. This substitution of communication medium maintains security while reducing vulnerability to interception.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces the user's mobile device as an intermediary component in the authentication process. The mobile device serves as both the communication channel and the verification mechanism - it receives the voice call, captures the spoken code through its microphone, and validates the input. This intermediary approach eliminates the need for separate text messaging infrastructure and enhances security through the device's existing secure components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device-based token generation is used for second level authentication, then authentication security is improved, but device complexity and integration cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsoftware integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the mobile device's existing self-service capabilities - specifically its telephone function and microphone - for authentication purposes. Rather than requiring specialized authentication hardware or software installation, the system uses the device's built-in communication and audio capture features. This approach eliminates the need for complex token generation software while maintaining strong authentication security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes the mobile device serve multiple functions: it acts as the authentication client, the communication channel, the code input device, and the verification terminal. By utilizing the device's existing multi-functional capabilities (phone, microphone, display), the system avoids introducing separate dedicated authentication hardware or complex software, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If audio session-based authentication is implemented, then authentication security and cost efficiency are improved, but implementation complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct functional phases: code generation (server-side), audio session establishment (communication phase), code capture (microphone phase), and code verification (validation phase). This segmentation allows each component to be implemented independently using standard technologies, reducing overall implementation complexity while maintaining high security through the coordinated interaction of these segmented functions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9009793B2Dynamic pin dual factor authentication using mobile device
Publication Date: 2015.04.14 INFOSYS LTD
  • US9009793B2 patent drawing
  • US9009793B2 patent drawing
  • US9009793B2 patent drawing

AI summary

The present invention provides cost efficient two way authentication method in which the authentication module can be provided as a Plug and Play (PnP) architecture enabling dual layer security with reduced cost where the actions are initiated by a server and user input is received through an audio session for added security. The second level authentication can be carried out with mobile as client device making it cost efficient. The invention can be hosted as an independent service or can be integrated with existing authentication mechanisms, making it elegant for usage.