Voice Assistant Authentication via Pronounceable Code and Second Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing voice assistant authentication methods are inadequate for real-time authentication in public environments and are not scalable or reliable for cross-vocal assistant and cross-service scenarios, particularly when multiple users interact with different voice assistants.
Innovation Solution
A two-factor authentication method using a user's telephone number and an optional pronounceable password, combined with a pronounceable code, to verify identity and ensure secure access to services across multiple voice assistants and service providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If voice assistant allows any user to execute commands without authentication, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The system performs preliminary authentication actions before allowing command execution. The voice assistant verifies user identity through voice biometrics and cross-checks with a second device before permitting sensitive operations, ensuring security is established in advance rather than reacting to threats
Solution Approach 2:
A second device (mobile phone, tablet, or computer) acts as an intermediary verification layer. The voice assistant does not directly trust voice commands alone but mediates through a second device that confirms authentication, creating a trusted bridge between the user and the system
2Device complexity
If voice assistant uses single-factor authentication, then device complexity is reduced, but reliability deteriorates
Solution Approach 1:
The authentication system is segmented into two independent parts: voice biometric verification performed by the voice assistant, and secondary confirmation performed by a second device. This segmentation allows each component to remain relatively simple while the combination provides strong authentication reliability
Solution Approach 2:
The second device serves multiple functions: it receives authentication requests, verifies user identity through additional methods, and confirms authorization. This multi-functionality reduces the need for dedicated hardware while improving authentication reliability through existing devices users already carry
3Adaptability or versatility
If voice assistant is used in public environments without authentication, then adaptability is improved, but harmful factors increase
Solution Approach 1:
The system applies preliminary anti-action by proactively preventing unauthorized access in public environments. Before allowing any user to execute commands in public settings, the system actively verifies identity through voice biometrics and requires confirmation from a second device, countering potential security risks before they can manifest
Solution Approach 2:
The system implements feedback loops where the voice assistant communicates authentication status and requirements to the user, and the second device provides real-time verification feedback. This continuous feedback ensures that even in public environments, the system maintains security by confirming each authentication step before allowing command execution
Data Source
Figure 1~5'
Figure 2
Figure 3~4
AI summary
Method for authenticating a user, the method being carried out by an Artificial Intelligence, Al, system (100), said Al system (100) being configured to provide voice assistant functionalities, said method comprising: receiving from a user (300) a vocal request for using a service, the service being provided by a service provider, the service provider being associated with a service provider platform (200); vocally receiving a telephone number (TN); cooperating with the service provider platform (200) to verify that the telephone number (TN) corresponds to an active subscription to said service; sending to the telephone number (TN) an authentication message (AM) including a pronounceable code (PC1 ); vocally receiving a pronounced code (PC2) by the user; verifying that the pronounced code (PC2) corresponds to the pronounceable code ( PC1 ); sending a confirmation message (CM) to the service provider platform (200).