Voice-Based Multi-Factor Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multi-factor authentication methods are inconvenient and impractical for public use due to the need for multiple physical items, which hinders widespread adoption, especially in online transactions, and are susceptible to phishing attacks that exploit single-factor authentication.
Innovation Solution
Implementing voice recognition as a factor in multi-factor authentication, where users select a recognizable voice to receive password messages, combining it with existing factors like a device and knowledge-based information, to authenticate both the user and the legitimacy of the website.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication using physical items (USB dongles, smart cards, RFID devices) is implemented, then security is improved, but device complexity and user inconvenience increase
Solution Approach 1:
The patent replaces physical authentication items (USB dongles, smart cards, RFID devices) with voice-based authentication. Instead of requiring users to carry and locate physical tokens, the system uses voice recognition technology to verify user identity, substituting mechanical/physical authentication mechanisms with acoustic field-based authentication.
Solution Approach 2:
The patent introduces a voice message server as an intermediary component that generates and delivers authentication codes via voice messages. This intermediary handles the complex authentication logic and communication protocols, simplifying the user interface while maintaining strong authentication security through multiple factors including voice biometrics.
2Reliability
If traditional multi-factor authentication with physical items is used, then authentication security is improved, but ease of operation deteriorates due to the need to keep and locate multiple physical items
Solution Approach 1:
The patent replaces the need to physically handle and locate authentication items with voice-based interaction. Users simply speak or listen to voice messages for authentication, eliminating the burden of carrying, remembering, and locating multiple physical authentication devices while maintaining strong security through voice biometrics and multi-factor authentication.
3Ease of operation
If single-factor authentication is used, then ease of operation is improved, but reliability deteriorates due to susceptibility to phishing attacks
Solution Approach 1:
The patent implements preliminary voice-based authentication before providing access credentials. Voice messages containing authentication codes are sent to users' devices before they can complete login, creating a preliminary verification step that prevents phishing attacks while maintaining operational simplicity through automated voice delivery.
Solution Approach 2:
The voice message server acts as an intermediary that delivers authentication codes through a controlled channel, preventing direct exposure of credentials to potential phishing sites. This intermediary layer verifies user identity through voice recognition before releasing authentication information, blocking phishing attacks while keeping the user experience simple.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances security by reducing user inconvenience, preventing phishing attacks, and ensuring only authorized users access legitimate websites, while minimizing the need for physical authentication items.
Implementation Method 1
voice recognition as one factor in a multi-factor authentication process
Data Source
AI summary
A multi-factor authentication solution implements a recognizable voice in conjunction with a user address to increase login security and reduce user inconvenience. A user creates an online account, providing an address such as a telephone number or email address to which voice messages may be sent. The user selects a recognizable voice such as the user's own voice or the voice of a famous or well-known figure. When the user attempts to login to the online account, a random passphrase is generated and converted to a voice message employing the user's pre-selected voice and the voice message is sent to the user's address. The user listens to the voice message and if the user recognizes the voice rendering the passphrase the user's login request is granted.


