Room Impulse Response Multi-Factor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication (MFA) methods are inefficient and insecure, particularly in indoor environments, as GPS lacks accuracy and is slow, and internet IP addresses can be easily spoofed, limiting their effectiveness for location-based authentication.

Innovation Solution

A method using room impulse response (RIR) for MFA, which generates a challenge chirp signal, measures the RIR from a terminal and a trusted device, and compares these measurements to verify the location and presence of the trusted device, allowing for fast and secure authentication without pre-installed infrastructure, using commonly available speakers and microphones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If GPS is used for location-based authentication, then location information can be obtained, but accuracy is poor in indoor environments and sensing time is long

Engineering Contradiction:
Improvelocation accuracyVSAvoidsensing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces GPS satellite-based positioning with an acoustic measurement system using microphones and speakers to capture room impulse responses. This substitution enables accurate indoor location fingerprinting by measuring acoustic characteristics of the environment rather than relying on satellite signals that fail indoors.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system uses acoustic vibrations (sound waves) to probe the environment and capture room impulse responses. By analyzing the vibrational characteristics of sound traveling through the room, the system creates location fingerprints that accurately identify indoor positions without requiring long sensing times.

Inventive Principle:
Principle #18Mechanical vibration

2Reliability

If internet IP address is used for location verification, then location information can be obtained, but it is easily spoofed reducing security

Engineering Contradiction:
Improveauthentication securityVSAvoidIP address spoofing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces network-based IP address verification with acoustic environment measurement. By capturing the physical acoustic characteristics of the room through impulse responses, the system creates location fingerprints that cannot be spoofed through network manipulation, significantly improving authentication security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system uses the environment itself (the room's acoustic properties) as the authentication factor. The physical space naturally provides unique acoustic characteristics that serve as inherent security credentials, eliminating the need for external verification infrastructure and making spoofing impossible.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple authentication factors are verified, then security is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines location fingerprinting and device presence verification into a single acoustic measurement process. By capturing the room impulse response, the system simultaneously obtains both the environmental acoustic signature and confirms the device's physical presence in that environment, reducing complexity while maintaining multi-factor security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The acoustic measurement system serves multiple authentication functions simultaneously. The same room impulse response measurement provides both location identification through acoustic fingerprinting and device presence confirmation, making the system universally applicable for multiple authentication factors without requiring separate verification mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach provides fast, secure, and accurate authentication by utilizing RIR for both location fingerprinting and device presence verification, overcoming indoor inaccuracies and IP address spoofing attacks, with minimal hardware requirements and simultaneous verification of multiple factors.

Implementation Method 1

SoundLoc: Accurate room-level indoor localization using acoustic signatures

Methodology Applied
Scientific EffectAcoustic signature: Acoustics

Implementation Method 2

Echolocation refers to a technique, such as that used by bats and dolphins, of using sound to navigate

Methodology Applied
Scientific EffectEcholocation: Echo

Data Source

PatentUS10938833B2Multi-factor authentication based on room impulse response
Publication Date: 2021.03.02 NEC CORP
  • US10938833B2 patent drawing
  • US10938833B2 patent drawing
  • US10938833B2 patent drawing

AI summary

A method of multi-factor authentication includes receiving, by a remote hosting server from a terminal, a request from a user possessing a trusted device to access a remote service. The remote hosting server generates challenge chirp signal information and sends the challenge chirp signal information to the terminal and the device. Measurements are received of a room impulse response taken by each of the terminal and the trusted device using the chirp signal information. It is checked whether a location of the terminal is known based on a measurement of the room impulse response. The measurements of the room impulse response of the terminal and the trusted device are compared. A level of access to the remote service is granted to the user based on whether the location of the terminal is known and whether the trusted device is present at the location of the terminal.