Customizable Voice Authentication in Multi-Tenant Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-tenant online systems face challenges in meeting diverse authentication demands as they typically use a single authentication procedure for all users, failing to accommodate varying levels of security required by different organizations, which may handle sensitive or non-sensitive data.

Innovation Solution

A multi-tenant system implements customizable voice-based user authentication by allowing tenants to specify tenant-specific authentication plans, using phrase types and associated verification methods, and focuses on confirming inaccuracies in user responses through conversations and external services for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single authentication procedure is used for all users, then the system is simple to operate and maintain, but it cannot meet the diverse authentication demands of different organizations with varying security requirements

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system by introducing tenant-specific authentication plans that can be independently configured. Each tenant (organization) can define their own authentication procedures, phrase types, and verification methods, allowing the system to adapt to diverse security requirements without requiring complete system redesign. This segmentation enables different authentication strategies for different tenants while maintaining a unified underlying architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic authentication by allowing authentication plans to be customized and modified per tenant. The system transitions from a static, one-size-fits-all approach to a dynamic model where authentication parameters (phrase types, verification methods, conversation flows) can be adjusted based on organizational needs. This dynamic configuration capability enables the system to adapt to changing security requirements over time.

Inventive Principle:
Principle #15Dynamics

2Reliability

If strong authentication procedures are implemented for all users, then security is improved, but user experience deteriorates and false positives increase for organizations handling non-sensitive data

Engineering Contradiction:
Improveauthentication securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by allowing different authentication strengths for different tenants based on their specific security needs. Organizations handling sensitive data can implement strong authentication with multiple verification methods, while organizations with non-sensitive data can use simpler procedures. This localized customization ensures that security is strengthened only where necessary, preventing unnecessary friction for users of less security-critical systems.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent enables parameter changes by allowing tenants to configure authentication parameters such as phrase types, verification methods, and conversation complexity according to their security requirements. This flexibility allows organizations to adjust the strength of authentication procedures to match their actual security needs, avoiding both over-protection and under-protection scenarios.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If voice-based authentication with conversation and external verification is used, then authentication accuracy is improved, but system complexity and processing time increase

Engineering Contradiction:
Improveverification accuracyVSAvoidauthentication process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing external verifications (such as checking phone numbers, email addresses, or other identifying information) during the authentication conversation itself, rather than as separate post-authentication steps. This integrated approach allows the system to verify user identity through multiple channels while maintaining a cohesive user experience, reducing the need for additional complex verification steps after authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses intermediaries by incorporating external services and data sources that assist in the verification process. These intermediaries (such as phone verification services, email validation services, or database lookups) help confirm user identity without requiring the authentication system to build all verification capabilities internally, thus managing complexity while improving accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11588800B2Customizable voice-based user authentication in a multi-tenant system
Publication Date: 2023.02.21 SALESFORCE INC
  • US11588800B2 patent drawing
  • US11588800B2 patent drawing
  • US11588800B2 patent drawing

AI summary

A system authenticates users using voice-based conversations. The system allows the authentication process to be customized using an authentication plan. For example, the system may be a multi-tenant system that allows customization of the authentication process for each tenant. The authentication plan is represented as an expression of phrase types, each phrase type associated with a phrase verification method. The system authenticates a user by executing the expression of an authentication plan for that user in response to a request from the user. The system performs a conversation with the user according to the authentication plan. The system determines whether to allow or deny the user request based on the result of evaluation of the expression of the authentication plan.