Mobile App Mediator for IVR Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Interactive Voice Response (IVR) systems face challenges in securely authenticating customer identities, particularly when sensitive information is required, leading to cumbersome and insecure processes that can reduce confidence in the authenticity of the information provider.
Innovation Solution
Implementing an application on the user's device for secure authentication, which includes a user device, a third-party server, and an IVR system, where the user device initiates an application session, authenticates credentials, and receives a second credential for secure communication with the IVR system, thereby reducing man-in-the-middle attacks and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional IVR authentication methods are used where customers provide sensitive information directly to the IVR system, then the authentication process is simple to implement, but security is compromised and customer confidence is reduced
Solution Approach 1:
The patent introduces a mobile device as an intermediary between the customer and the IVR system. The mobile device application authenticates the customer locally and then establishes a secure communication channel to the IVR system, acting as a trusted mediator that enhances security without requiring the IVR system to directly handle sensitive customer information
Solution Approach 2:
The authentication process is segmented into distinct phases: local authentication via mobile device application, secure channel establishment, and IVR system verification. This segmentation allows each component to perform its specific function securely, reducing the overall system complexity while maintaining high security standards
2Ease of operation
If customers are required to provide sensitive information through traditional IVR methods, then the authentication process can be completed, but the process becomes cumbersome and insecure
Solution Approach 1:
The mobile device application performs local authentication of the customer using stored credentials and biometric data, enabling self-service authentication without requiring the customer to verbally provide sensitive information to the IVR system. This maintains ease of operation while significantly improving information authenticity
Solution Approach 2:
The patent replaces the mechanical process of verbal information provision with electronic authentication mechanisms including biometric verification and encrypted digital credentials. This substitution eliminates the security vulnerabilities of traditional voice-based authentication while maintaining user convenience
3Reliability
If traditional IVR communication channels are used without additional security measures, then the system is easy to operate, but it is vulnerable to man-in-the-middle attacks
Solution Approach 1:
The mobile device application performs preliminary authentication and establishes security credentials before the IVR communication begins. This preliminary action includes generating secure tokens and establishing encrypted channels in advance, which prevents man-in-the-middle attacks without adding significant time to the overall authentication process
Data Source
AI summary
A device can receive, from an interactive voice response (IVR) system, a set of instructions to initiate an application session of an application and to provide an authentication interface for display. The device can receive, via the authentication interface and during the application session, a first credential from a user of the device. The device can authenticate, during the application session, the first credential. The device can receive, from a third-party server device and during the application session, a second credential. The device can cause, during the application session, a communication session to be established with the IVR system to request the account information. The communication session can include a telephone call established between the application and the IVR system. The device can receive the account information from the IVR system via the application session. The device can provide the account information for display via a display of the device.


