Voice-Verified Authentication Using Dynamic Token Secrets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems are vulnerable to attacks, particularly when tokens are unattended or stolen, as attackers can analyze their methods of operation and secrets, leading to the generation of valid authentication codes for unauthorized access.

Innovation Solution

A method and system that uses a shared secret between a verifier and a user authentication device, where a first voice sample is recorded and dynamic authentication information is generated, with the user responding to presented authentication information, and both voice samples and responses are compared to verify identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dynamic authentication codes are generated using a shared secret and time-based variables, then predictability of authentication codes is reduced, but vulnerability to sophisticated analysis attacks on the token remains

Engineering Contradiction:
Improveauthentication securityVSAvoidattack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is divided into two separate components: a token that generates authentication codes and a voice verification system that provides an additional authentication layer. This segmentation ensures that even if the token is compromised, attackers cannot fully authenticate without also passing voice verification, thereby reducing the harmful effects of token attacks while maintaining authentication reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Voice verification acts as an intermediary authentication mechanism between the token and the final authentication decision. The system requires both token-based authentication codes and voice sample verification to grant access, creating a mediator layer that prevents direct authentication even if the token is stolen or analyzed, thus reducing attack vulnerability while preserving security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If voice-based verification is added to the authentication system, then authentication strength is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication strengthVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The voice verification functionality is merged with the existing token authentication system into a unified authentication process. The verifier combines both authentication code verification and voice sample comparison in a single system, allowing the dual-factor authentication to operate as an integrated process rather than separate systems, thereby improving authentication strength while minimizing the increase in system complexity

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9122857B1Authenticating a user in an authentication system
Publication Date: 2015.09.01 EMC IP HLDG CO LLC
  • US9122857B1 patent drawing
  • US9122857B1 patent drawing
  • US9122857B1 patent drawing

AI summary

There is disclosed method and system for authenticating user in authentication system comprising verifier and authentication device configured such that verifier and device comprise secret. A first voice sample of user recorded in verifier. Authentication information is generated in device. The device configured such that information generated is dynamic information based on secret. The information generated in device presented to user. An input signal received in verifier comprising a second voice sample of user and response by user to information. The input signal received in verifier in response to user responding to information by voicing response to information. The first and second samples compared in verifier. The information generated by device and response by user to information compared in verifier. An authentication result generated in verifier based on comparison of first and second samples and comparison of information and response. The result used for authenticating user.