IVR Voice Authentication for Secure Web Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for user ID verification in restricted areas like Internet banking lack robustness, as they rely on single-use passwords that can be compromised via SMS or mobile devices, and current IVR systems are not effectively adapted for web-based high-security access.
Innovation Solution
An interactive voice response system (IVR) that authenticates user IDs by controlling phone numbers and utilizing speech synthesis, recognition, and voice verification, allowing users to verify their identities through recorded phone numbers, security questions, and voice signatures, with the IVR either initiating or receiving calls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OTP is sent via SMS, then user authentication is provided, but SMS sending cost is incurred
Solution Approach 1:
The patent replaces the SMS-based OTP delivery system with a voice-based IVR system. Instead of sending text messages via SMS infrastructure, the system uses voice calls through the IVR platform to deliver authentication codes. This substitution eliminates SMS costs while maintaining authentication reliability, as the IVR system can deliver OTPs through voice prompts and DTMF input without incurring SMS messaging fees.
2Reliability
If A5/x standard is used for OTP sent via SMS, then authentication is provided, but risk of exploitation by malicious people exists
Solution Approach 1:
The patent introduces the IVR system as an intermediary between the user and the authentication process. Instead of directly sending OTPs via SMS which can be intercepted through A5/x vulnerabilities, the IVR system acts as a mediator that delivers authentication codes through voice calls. This intermediary layer bypasses the vulnerable SMS protocol entirely, using voice communication and DTMF tones which are not susceptible to the same exploitation risks.
3Reliability
If OTP is generated via mobile phone, then authentication is provided, but risk of lost or stolen mobile phone exists
Solution Approach 1:
The patent creates a backup authentication pathway by implementing server-side OTP generation capability. Instead of relying solely on the mobile device to generate OTPs (which risks loss if the phone is stolen), the system maintains the ability to generate and deliver OTPs through the IVR system via voice calls. This copying of the authentication function to a different platform ensures that users can still authenticate even if their mobile device is lost or stolen.
4Reliability
If personal OTP devices are used, then authentication is provided, but risk of unauthorized access similar to mobile phone exists
Solution Approach 1:
The patent implements a universal authentication system that works across multiple platforms and devices without requiring specialized OTP hardware. The IVR-based system can deliver authentication codes to any phone capable of receiving voice calls, eliminating the need for proprietary OTP devices. This multi-functionality approach reduces the security risks associated with dedicated hardware while maintaining authentication reliability across diverse user devices.
5Reliability
If IVR system is used for call center database protection, then unauthorized access is prevented, but web-based restricted area access is not covered
Solution Approach 1:
The patent extends the IVR system's functionality from solely protecting call center databases to also securing web-based restricted areas. By integrating the IVR authentication mechanism into the web access flow, the system provides universal protection across both telephony and web platforms. The same voice-based OTP delivery mechanism serves dual purposes: protecting traditional call center resources and securing modern web applications, thereby achieving versatility without compromising security.
Data Source
AI summary
A user ID authentication method, wherein it comprises the process step of realization of a call between the phone number recorded previously in the customer information database (5), and the interactive voice response system (IVR) (1) in the case where a user logs over a web browser (4) into a restricted access system requiring high security such as Internet banking.


