Two-Factor Authentication Using Device IDs and Voiceprints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for e-commerce rely heavily on weak single-factor authentication, such as passwords, which are vulnerable to theft and exploitation, limiting the adoption of two-factor authentication due to requirements for new hardware or software installations.
Innovation Solution
A method that utilizes device IDs and mobile phones as secondary authentication factors, leveraging existing user devices without the need for additional hardware or software, combining password-based authentication with device identification and mobile phone-based verification to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional two-factor authentication is implemented using hardware tokens or software installations, then security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent applies universality by using existing communication devices (mobile phones, computers with microphones) for their primary communication functions while simultaneously enabling authentication. The microphone, already present for voice calls, is repurposed to capture voiceprints for authentication, eliminating the need for separate authentication hardware or software installations.
Solution Approach 2:
The patent implements self-service by utilizing components that users already possess and operate routinely. The mobile phone's microphone and speaker, along with the device's existing communication capabilities, are leveraged to perform authentication without requiring users to acquire or configure additional devices or software.
2Reliability
If traditional two-factor authentication is implemented using hardware tokens or software installations, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent applies universality by using existing communication devices (mobile phones, computers with microphones) for their primary communication functions while simultaneously enabling authentication. The microphone, already present for voice calls, is repurposed to capture voiceprints for authentication, eliminating the need for separate authentication hardware or software installations.
Solution Approach 2:
The patent implements self-service by utilizing components that users already possess and operate routinely. The mobile phone's microphone and speaker, along with the device's existing communication capabilities, are leveraged to perform authentication without requiring users to acquire or configure additional devices or software.
3Ease of operation
If single-factor password authentication is used, then ease of operation is maintained, but security deteriorates due to password theft vulnerabilities
Solution Approach 1:
The patent merges two authentication factors into a single communication interaction: something the user knows (password) and something the user has (voiceprint captured by the device's microphone). This combination occurs during the natural course of a voice call, maintaining simplicity while enhancing security.
Solution Approach 2:
The patent introduces a voiceprint as an intermediary authentication factor that bridges the gap between simple password authentication and complex multi-factor authentication. The voiceprint serves as a biometric mediator that can be captured and verified without adding significant operational complexity to the authentication process.
Data Source
AI summary
A method for authenticating a user based on a plurality of authentication factors includes a step of receiving a first authentication factor from a first communication device of the user. The first authentication factor includes a password. The method includes a step of receiving a second authentication factor. The second authentication factor comprises at least one of at least one device identifier of the first communication device of the user and data transmitted to or received from a second communication device of the user. The method also includes a step of authenticating the user based on at least the received plurality of authentication factors.


