Voice Authentication via Secondary Device Login Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Voice-based services lack adequate security, particularly when users access sensitive information, as they often rely on insecure cloud storage and can be compromised by hackers, and the integration of multiple services creates additional security vulnerabilities.
Innovation Solution
A system for voice authentication through a secondary device, which involves a voice agent, an authentication intermediary service, and a secure service, where the user's login events are validated to ensure secure access by comparing timestamps and providing an indication of successful login, thereby reducing the need to communicate sensitive credentials over insecure channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If voice-based services are integrated with external services to provide additional functionality, then service versatility is improved, but security vulnerabilities increase
Solution Approach 1:
The patent introduces an authentication intermediary service that acts as a mediator between the voice-based service and external services. This intermediary validates authentication attempts by checking login events and timestamps before allowing access to external services, thereby enabling service integration while maintaining security through an additional verification layer
Solution Approach 2:
The authentication process is segmented into separate components: the voice-based service handles voice-to-text conversion, the authentication intermediary handles security validation by checking login events and timestamps, and the external service handles the actual resource access. This segmentation allows each component to perform its specific function securely without compromising the entire system
2Ease of operation
If users speak sensitive information like PINs or passwords through voice services, then ease of operation is improved, but security against eavesdropping deteriorates
Solution Approach 1:
The patent extracts the sensitive credential verification step from the voice-based service. Instead of the voice service directly accepting and processing sensitive information like PINs or passwords, the authentication intermediary extracts and validates authentication events separately by checking login timestamps and events, thereby eliminating the eavesdropping risk associated with speaking sensitive information while maintaining voice-based convenience
Solution Approach 2:
The system uses short-lived authentication tokens and time-based validation mechanisms that expire quickly. The authentication intermediary checks login events within a specific time window and invalidates old authentication attempts, ensuring that even if credentials are exposed, they can only be used for a limited duration, thereby reducing the impact of potential security breaches
3Adaptability or versatility
If cloud storage is used to store user interaction histories, then accessibility is improved, but security against hacking deteriorates
Solution Approach 1:
The authentication intermediary service acts as a mediator between the voice-based service and the cloud storage containing user interaction histories. Before accessing stored histories, the intermediary validates authentication events and timestamps, ensuring that only authorized requests can retrieve sensitive information from the cloud, thereby maintaining accessibility while improving cloud security through an additional verification layer
4Reliability
If traditional Time-Based One Time Password methods are used, then security is improved, but device complexity and user experience deteriorate
Solution Approach 1:
The authentication intermediary service performs self-service by automatically checking login events and timestamps without requiring user intervention. The system autonomously validates authentication attempts, compares timestamps, and makes decisions about access authorization, thereby improving security while reducing the complexity of user interaction compared to traditional TOTP methods that require manual code entry and device coordination
Data Source
AI summary
A user initiates a voice request to perform an operation with an external service and provides a voice credential for the operation. A determination is made as to whether the user has used a separate device from that which is associated with the voice request to log into the external service within a preceding amount of time before the voice request and/or within a succeeding amount of time following the voice request. If the user has such a login with the external service, the voice operation is processed on behalf of the user with the external service using the voice credential; otherwise the voice request is ignored.


