Proximity Authentication for Voice Assistants

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Voice assistant devices in shared environments, such as offices or hotels, face challenges in authenticating users with their service endpoints due to lack of capability and user hesitation in linking/unlinking accounts, along with enterprise desires for controlled authentication processes.

Innovation Solution

Implementing a proximity-based authentication system using location beacons and an identity provider service that allows users to access enterprise data through voice assistant devices by associating user accounts with the devices based on proximity, enabling single sign-on and secure access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users link their identity with assistant device through API authentication, then user can access enterprise data through voice assistant device, but user must permanently link account which creates security concerns in shared environments

Engineering Contradiction:
Improveaccess to enterprise dataVSAvoiduser identity security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic authentication where the authentication state changes based on device proximity. When the user's device is near the voice assistant, authentication is automatically established; when moved away, authentication is automatically revoked. This dynamic approach eliminates permanent account linking while maintaining secure access.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary authentication actions by establishing security tokens and proximity-based credentials before the user actually needs to access enterprise data. The authentication framework is pre-configured through enterprise identity providers, so when proximity is detected, access is immediately granted without requiring users to manually link accounts at the moment of need.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If users manually link and unlink accounts on assistant device, then authentication can be controlled, but process is cumbersome and time-consuming

Engineering Contradiction:
Improveauthentication controlVSAvoidaccount linking/unlinking time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service authentication where the voice assistant automatically manages the authentication process based on detected device proximity. The enterprise identity provider service automatically establishes and revokes authentication tokens without requiring user intervention for linking or unlinking accounts, eliminating the time-consuming manual processes while maintaining authentication control.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If enterprise relies on assistant ecosystem provider for authentication, then authentication process is simplified, but enterprise loses control over authentication process

Engineering Contradiction:
Improveauthentication processVSAvoidenterprise control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces an enterprise identity provider service as an intermediary between the voice assistant device and user authentication. This mediator allows enterprises to maintain control over authentication processes, security policies, and access management while still enabling simplified user authentication through the voice assistant. The identity provider service bridges the gap between enterprise control requirements and user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11765595B2Proximity based authentication of a user through a voice assistant device
Publication Date: 2023.09.19 OMNISSA LLC
  • US11765595B2 patent drawing
  • US11765595B2 patent drawing
  • US11765595B2 patent drawing

AI summary

Disclosed are various approaches for authenticating a user through a voice assistant device and creating an association between the device and a user account. The request is associated with a network or federated service. A user account can be implicitly authenticated based on proximity of a client device to the voice assistant device. An association between the user account and the voice assistant device can then be created.