Sound-Based User Authentication Using Type-A and Type-B Sound Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telephone-based user authentication methods are vulnerable to eavesdropping, as they rely on oral password transmission, which can be easily intercepted and exploited.

Innovation Solution

A method where users select and designate personal sounds as 'type-A' and other sounds as 'type-B', with the enterprise combining these sounds randomly and asking authentication questions that only the user can answer, making it difficult for eavesdroppers to impersonate the user.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If oral password authentication is used via telephone, then user authentication can be performed simply and quickly, but the system becomes vulnerable to eavesdropping and security breaches

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct phases: a registration phase where the user designates type-A sounds, and an authentication phase where the user answers questions about type-A sounds. This segmentation allows the system to establish secure credentials upfront while maintaining simple authentication later.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by having the user designate type-A sounds during registration before the actual authentication occurs. This preliminary designation creates a secure reference that can be used later without requiring the user to remember complex passwords.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If traditional oral password methods are used, then authentication is fast and requires minimal resources, but eavesdroppers can easily intercept and exploit the passwords

Engineering Contradiction:
Improveauthentication speedVSAvoideavesdropping vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system converts the potential harm of eavesdropping into a benefit by designing an authentication method where even if sounds are intercepted, the type-A sound designations remain secure because they are based on user-specific references (personal sounds, memories, associations) that cannot be derived from intercepted audio alone.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The type-A sound designations act as an intermediary between the user and the authentication system. Instead of directly transmitting passwords, the system uses these designations as a secure reference point that mediates the authentication process, preventing direct exposure of sensitive credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system uses user-designated type-A sounds for authentication, then security against eavesdropping is improved, but the device complexity and setup time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses self-service by having the user themselves create their own authentication credentials by designating type-A sounds based on personal references. This eliminates the need for complex key management infrastructure, cryptographic protocols, or specialized security hardware, as the user's own knowledge and associations become the security mechanism.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If random type-A and type-B sounds are combined and presented to the user, then it becomes difficult for eavesdroppers to identify type-A sounds, but the authentication process becomes more complex

Engineering Contradiction:
Improveeavesdropper's ability to impersonate userVSAvoidauthentication process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system applies asymmetry by creating an uneven distribution of meaningful versus meaningless sounds. Type-A sounds have special significance to the user based on personal associations, while type-B sounds are ordinary distractors. This asymmetric design makes it computationally infeasible for eavesdroppers to identify type-A sounds without the user's specific knowledge.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS8238530B2Authenticating a user based on the user's ability to distinguish type-A from type-B sounds
Publication Date: 2012.08.07 AVAYA INC
  • US8238530B2 patent drawing
  • US8238530B2 patent drawing
  • US8238530B2 patent drawing

AI summary

A method of authentication is disclosed. When a user registers with an enterprise, the enterprise instructs the user to select sounds from a selection of sounds. Any sound that the user selects is designated as a “type-A” sound and any sound that is not so designated is deemed a “type-B” sound. To authenticate the user, the enterprise combines type-A sounds and type-B sounds into a temporal series of sounds and constructs questions about the series that can only be answered by someone who can recognize and distinguish type-A sounds from type-B sounds. The series of sounds and the questions are then transmitted to the user. If the user is able to answer the questions, then he or she is authenticated, and if not, then he or she is not authenticated.