Mobile App Mediator for IVR Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Interactive Voice Response (IVR) systems face challenges in securely authenticating customer identities, particularly when sensitive information is required, leading to cumbersome and insecure processes that can reduce confidence in the authenticity of the information provider.

Innovation Solution

Implementing an application on the user's device for secure authentication, which includes a user device, a third-party server, and an IVR system, where the user device initiates an application session, authenticates credentials, and receives a second credential for secure communication with the IVR system, thereby reducing man-in-the-middle attacks and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IVR authentication methods are used where customers provide sensitive information directly to the IVR system, then the authentication process is simple to implement, but security is compromised and customer confidence is reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mobile device as an intermediary between the customer and the IVR system. The mobile device application authenticates the customer locally and then establishes a secure communication channel to the IVR system, acting as a trusted mediator that enhances security without requiring the IVR system to directly handle sensitive customer information

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct phases: local authentication via mobile device application, secure channel establishment, and IVR system verification. This segmentation allows each component to perform its specific function securely, reducing the overall system complexity while maintaining high security standards

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If customers are required to provide sensitive information through traditional IVR methods, then the authentication process can be completed, but the process becomes cumbersome and insecure

Engineering Contradiction:
Improveauthentication convenienceVSAvoidinformation authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The mobile device application performs local authentication of the customer using stored credentials and biometric data, enabling self-service authentication without requiring the customer to verbally provide sensitive information to the IVR system. This maintains ease of operation while significantly improving information authenticity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical process of verbal information provision with electronic authentication mechanisms including biometric verification and encrypted digital credentials. This substitution eliminates the security vulnerabilities of traditional voice-based authentication while maintaining user convenience

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If traditional IVR communication channels are used without additional security measures, then the system is easy to operate, but it is vulnerable to man-in-the-middle attacks

Engineering Contradiction:
Improvecommunication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The mobile device application performs preliminary authentication and establishes security credentials before the IVR communication begins. This preliminary action includes generating secure tokens and establishing encrypted channels in advance, which prevents man-in-the-middle attacks without adding significant time to the overall authentication process

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10148816B2Interactive voice response (IVR) call authentication
Publication Date: 2018.12.04 VERIZON PATENT & LICENSING INC
  • US10148816B2 patent drawing
  • US10148816B2 patent drawing
  • US10148816B2 patent drawing

AI summary

A device can receive, from an interactive voice response (IVR) system, a set of instructions to initiate an application session of an application and to provide an authentication interface for display. The device can receive, via the authentication interface and during the application session, a first credential from a user of the device. The device can authenticate, during the application session, the first credential. The device can receive, from a third-party server device and during the application session, a second credential. The device can cause, during the application session, a communication session to be established with the IVR system to request the account information. The communication session can include a telephone call established between the application and the IVR system. The device can receive the account information from the IVR system via the application session. The device can provide the account information for display via a display of the device.