Voice Assistant Authentication via Passphrase Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Voice assistant devices lack the capability to easily authenticate users with service endpoints, especially in shared environments where multiple individuals may access the device, and existing solutions are cumbersome or lack enterprise control over the authentication process.
Innovation Solution
Implementing a network environment with an identity manager, assistant connection service, and authentication service that enables persistent authentication of users with a single sign-on (SSO) portal or service endpoints through a voice assistant device, allowing users to easily associate and dissociate their accounts using a passphrase for secure and controlled access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication credentials are permanently linked to the assistant device through APIs, then the user can access services through the assistant, but the user cannot easily dissociate accounts and enterprise control is lost
Solution Approach 1:
The authentication system transitions from static permanent linking to dynamic temporary association. Authentication credentials are linked to the assistant device temporarily for a specific session or purpose, allowing easy dissociation when the session ends. This enables the system to adapt between maintaining secure access and allowing flexible account management based on operational context.
Solution Approach 2:
The enterprise pre-configures authentication credentials and policies before the user needs to access services. The identity provider service is set up in advance with predefined authentication methods and authorization rules, eliminating the need for users to perform cumbersome linking procedures during actual service access.
2Ease of operation
If the authentication process is controlled by the assistant ecosystem provider, then the assistant can access services easily, but the enterprise loses control over the authentication process
Solution Approach 1:
An identity provider service acts as an intermediary between the assistant device and service endpoints. This intermediary maintains enterprise control over authentication credentials and authorization policies while enabling seamless authentication. The identity provider verifies user identity and manages credential distribution, ensuring enterprise oversight without complicating the user experience.
3Reliability
If users perform the cumbersome process of linking and unlinking service accounts, then enterprise control is maintained, but user convenience is reduced
Solution Approach 1:
The enterprise pre-configures authentication credentials and authorization policies before users need to access services. The identity provider service is set up in advance with predefined authentication methods, eliminating the need for users to perform time-consuming linking procedures during actual service access.
Solution Approach 2:
The system enables users to authenticate themselves automatically through the identity provider service without requiring manual account linking. Users present their identity credentials, and the system automatically establishes the necessary authentication context, reducing both user effort and time investment while maintaining enterprise control.
Data Source
AI summary
Disclosed are various approaches for authenticating a user through a voice assistant device and creating an association between the device and a user account. The request is associated with a network or federated service. The user can use a client device, such as a smartphone, to initiate an authentication flow. A passphrase is provided to the client device can captured by the client device and a voice assistant device. Audio captured by the client device and voice assistant device can be sent to an assistant connection service. The passphrase and an audio signature calculated from the audio can be validated. An association between the user account and the voice assistant device can then be created.


