Voice Biometric Authentication with Out-of-Band PIN Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional voice biometric systems face challenges in scalability, security, and user acceptance due to reliance on speech recognition, cross-channel compatibility issues, and high enrolment loads, leading to increased false rejection rates and inconvenience.
Innovation Solution
A two-factor authentication process that combines voice biometrics with an out-of-band security layer, using a physical ID card with a PIN code and a secret matrix for additional authentication, reducing the reliance on voice biometrics and enabling on-demand enrolment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If voice biometric authentication is used as the only security layer, then user convenience is improved, but security level deteriorates due to high false acceptance rates
Solution Approach 1:
The authentication process is segmented into multiple independent phases: pre-enrolment phase (where voice profile is created but authentication does not occur) and enrolment/verification phases (where actual authentication happens). This segmentation allows the system to separate profile creation from security-critical authentication, enabling better control over security parameters while maintaining user convenience.
Solution Approach 2:
The system performs preliminary actions by creating and storing the user's voice profile during the pre-enrolment phase before actual authentication is needed. This preliminary profile creation allows the system to prepare authentication data in advance, reducing the burden on users during actual authentication while maintaining high security through proper threshold settings.
2Reliability
If the voice authentication threshold is set high to ensure security, then security level is improved, but user acceptance deteriorates due to increased false rejection rates
Solution Approach 1:
The system dynamically adjusts the authentication threshold based on the specific operational context and user profile. Rather than using a fixed high threshold that causes false rejections, the threshold is adapted to balance security requirements with user acceptance, allowing the system to maintain both high security and low false rejection rates simultaneously.
3Adaptability or versatility
If automatic speech recognition is integrated into voice verification, then language support is improved, but system complexity increases and scalability is limited
Solution Approach 1:
The system extracts and removes the complex automatic speech recognition component from the core voice verification process. Instead of integrating ASR into the authentication verification phase, the system handles language-specific processing separately during the pre-enrolment phase, simplifying the main authentication architecture while still providing broad language support.
4Adaptability or versatility
If voice biometric systems are deployed on a huge scale, then user base coverage is improved, but fraudulent attacks increase due to higher probability of successful attacks
Solution Approach 1:
The system performs preliminary authentication checks and voice profile verification before allowing access to the main service. This preliminary action layer prevents fraudulent attacks from reaching the core system, even as the user base expands to millions of users across different languages and regions.
Solution Approach 2:
The system introduces an intermediary verification layer using voice biometrics as a mediator between the user and the main service. This intermediary layer acts as a security barrier that is difficult for attackers to bypass, while remaining convenient for legitimate users, thus protecting the system at scale without significantly impacting user experience.
Data Source
Figure 1
Figure 2A~2B
Figure 3
AI summary
Process for authenticating a user, to control his remote access to a service, data base or data network, wherein, in an enrolment step, an initial voice sample provided by the user is analyzed to obtain an initial user-specific voice profile and, in a later verification step, a current voice sample provided by the user is analyzed to obtain a current voice profile which is compared to the initial voice profile to generate an access control signal in response to the result of the comparison step, wherein additional user-dedicated authenticating means are generated in a pre-enrolment period, the additional authenticating means being used to authenticate the user in the enrolment step and/or in an access control step prior to and independent on the enrolment step, in a provisional or supplementary authentication procedure.