Voice Authentication Liveness Detection via Challenge Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems face vulnerabilities from spoofing attacks, particularly in voiceprint recognition, where existing liveness detection methods require additional equipment, are inconvenient, and often separate from authentication processes, weakening security and user experience.

Innovation Solution

A voice authentication method that uses a challenge-response mechanism with randomly generated verification codes and styles, allowing users to respond with their voice, which is then validated for liveness and matched against stored patterns without additional devices, integrating liveness detection directly into the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional liveness detection methods are used, then security against spoofing attacks is improved, but device complexity increases due to requirement of additional equipment

Engineering Contradiction:
Improvesecurity against spoofing attacksVSAvoidadditional equipment requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges liveness detection functionality directly into the voice authentication process by integrating challenge-response mechanism with verification code generation and voice pattern analysis. The system combines authentication and liveness detection into a single integrated process, eliminating the need for separate liveness detection devices while maintaining security against spoofing attacks.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The voice authentication system performs multiple functions simultaneously: it authenticates user identity through voice pattern recognition and detects liveness through challenge-response verification. The same voice processing infrastructure handles both authentication and liveness detection, making the system multi-functional without requiring additional specialized equipment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Speed

If liveness detection is separated from authentication process, then authentication speed is improved, but security is weakened due to potential bypasses

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent combines liveness detection and authentication into a single integrated process where the challenge-response mechanism is embedded within the voice authentication flow. The verification code generation, voice pattern analysis, and liveness detection occur simultaneously in one continuous process, ensuring that security is not weakened while maintaining efficient authentication speed.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If complex liveness detection methods are implemented, then security against spoofing is improved, but ease of operation deteriorates due to inconvenient user experience

Engineering Contradiction:
Improvesecurity against spoofingVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs liveness detection automatically during the normal authentication process without requiring users to perform additional actions or awareness of the detection mechanisms. The challenge-response verification and voice pattern analysis occur transparently in the background, maintaining user convenience while ensuring security against spoofing attacks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11283631B2Apparatus, method and computer program product for authentication
Publication Date: 2022.03.22 NOKIA TECHNOLOGIES OY
  • US11283631B2 patent drawing
  • US11283631B2 patent drawing
  • US11283631B2 patent drawing

AI summary

Methods, apparatus, computer program product and computer readable medium are disclosed for authentication. A method comprises: sending an authentication request to a relying party, wherein the authentication request comprises a voice authentication command of a user; receiving from an identity provider at least one first challenge message with respective randomly generated verification code and respective first randomly generated challenge style; and sending at least one voice verification code to the identity provider, wherein the at least one voice verification code is pronounced by the user in the light of the respective randomly generated verification code and the respective first randomly generated challenge style.