Voice Biometric Authentication for Malware-Resilient Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods are vulnerable to malware and insecure endpoint devices, particularly due to man-in-the-mobile and man-in-the-browser attacks, which compromise transaction security when using various network-connected devices.

Innovation Solution

A 3-step verification process that shifts from user-centric to service-centric authentication, utilizing phone-based, client-less, voice-channel strong authentication with voice biometrics, where the service provider's network is the last node to request authorization, and includes data directly connected with transaction or access details, ensuring security even on potentially compromised endpoint devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (username/password, hardware tokens, biometrics) are used on network-connected devices, then user access can be verified, but the system becomes vulnerable to malware attacks (man-in-the-browser, man-in-the-mobile) and insecure endpoint devices

Engineering Contradiction:
Improveauthentication securityVSAvoidmalware attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication server that mediates between the user's insecure endpoint device and the service provider. The server receives authentication requests, performs verification through multiple channels (voice biometrics, OTP, device fingerprinting), and returns authentication results. This intermediary architecture isolates the service provider from direct exposure to insecure client devices and malware, while still enabling secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into multiple independent verification steps: (1) voice biometrics verification, (2) OTP validation, (3) device fingerprinting analysis, and (4) behavioral pattern recognition. Each segment operates independently and contributes to the overall authentication decision. This segmentation ensures that compromise of one authentication factor does not lead to complete system vulnerability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple authentication factors (username, password, hardware token, biometrics) are required, then authentication strength increases, but user convenience decreases and authentication complexity increases

Engineering Contradiction:
Improveauthentication strengthVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements adaptive authentication that applies multiple verification factors selectively based on risk assessment. For low-risk transactions, only essential verification (such as voice biometrics or OTP) is required. For high-risk transactions or unusual patterns, additional verification steps are automatically triggered. This partial application of authentication factors maintains security while reducing unnecessary user burden for routine operations.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent incorporates device fingerprinting and behavioral pattern recognition that automatically analyze device characteristics, usage patterns, and interaction behaviors without requiring explicit user input. The system self-evaluates risk based on these passive observations and adjusts authentication requirements accordingly, reducing the burden on users while maintaining strong authentication where needed.

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication processes are made more complex to prevent malware attacks, then security improves, but authentication time and processing overhead increase

Engineering Contradiction:
Improvesecurity against malwareVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary device fingerprinting and behavioral baseline establishment during initial device registration or first login. These preliminary actions create a reference profile of legitimate device characteristics and user behavior patterns. During subsequent authentication attempts, the system compares actual data against these pre-established baselines, enabling faster risk assessment without requiring extensive real-time verification for routine operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system continuously monitors and analyzes authentication outcomes, device characteristics, and user behavior patterns, providing feedback to adjust authentication requirements in real-time. When the system detects unusual patterns or potential threats, it automatically increases verification stringency. When patterns are consistent and low-risk, it reduces authentication overhead. This dynamic feedback mechanism optimizes the balance between security and authentication time based on actual system conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10425407B2Secure transaction and access using insecure device
Publication Date: 2019.09.24 TALMOR ELI
  • US10425407B2 patent drawing
  • US10425407B2 patent drawing
  • US10425407B2 patent drawing

AI summary

The present invention enables secure transactions or access using insecure endpoint devices, such as computers, tablets and smart-phones. These insecure devices are potentially compromised with malicious software that may attack the user in every possible way. The present invention does not pretend to prevent malware. Instead, malware attacks against secure transactions and access are made obsolete. The present invention includes data, directly connected to transaction or access request to Relying-Party-Service-Provider, into authentication process of Identity-as-a-Service Provider. The present invention includes user authentication using mobile phone vs. Identity-Management-as-a-Service provider. The present invention also includes entering request for secure transaction or access to Relying-Party-Service-Provider, using insecure device. The present invention also includes two-way communication between Relying-Party-Service-Provider and Identity-Management-as-a-Service. The advantages of the present invention include, without limitation, that it is resilient to malware attack.