Voice-Verified Authentication Using Dynamic Token Secrets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems are vulnerable to attacks, particularly when tokens are unattended or stolen, as attackers can analyze their methods of operation and secrets, leading to the generation of valid authentication codes for unauthorized access.
Innovation Solution
A method and system that uses a shared secret between a verifier and a user authentication device, where a first voice sample is recorded and dynamic authentication information is generated, with the user responding to presented authentication information, and both voice samples and responses are compared to verify identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dynamic authentication codes are generated using a shared secret and time-based variables, then predictability of authentication codes is reduced, but vulnerability to sophisticated analysis attacks on the token remains
Solution Approach 1:
The authentication system is divided into two separate components: a token that generates authentication codes and a voice verification system that provides an additional authentication layer. This segmentation ensures that even if the token is compromised, attackers cannot fully authenticate without also passing voice verification, thereby reducing the harmful effects of token attacks while maintaining authentication reliability
Solution Approach 2:
Voice verification acts as an intermediary authentication mechanism between the token and the final authentication decision. The system requires both token-based authentication codes and voice sample verification to grant access, creating a mediator layer that prevents direct authentication even if the token is stolen or analyzed, thus reducing attack vulnerability while preserving security
2Reliability
If voice-based verification is added to the authentication system, then authentication strength is improved, but system complexity increases
Solution Approach 1:
The voice verification functionality is merged with the existing token authentication system into a unified authentication process. The verifier combines both authentication code verification and voice sample comparison in a single system, allowing the dual-factor authentication to operate as an integrated process rather than separate systems, thereby improving authentication strength while minimizing the increase in system complexity
Data Source
AI summary
There is disclosed method and system for authenticating user in authentication system comprising verifier and authentication device configured such that verifier and device comprise secret. A first voice sample of user recorded in verifier. Authentication information is generated in device. The device configured such that information generated is dynamic information based on secret. The information generated in device presented to user. An input signal received in verifier comprising a second voice sample of user and response by user to information. The input signal received in verifier in response to user responding to information by voicing response to information. The first and second samples compared in verifier. The information generated by device and response by user to information compared in verifier. An authentication result generated in verifier based on comparison of first and second samples and comparison of information and response. The result used for authenticating user.


