Voice Replay Attack Prevention via Dynamic Token Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Voice biometric authentication systems are susceptible to security attacks such as voice replay attacks, and existing methods require biometric-dependent wake-up phrases, which can be inconvenient and insecure.

Innovation Solution

A computing device employs a two-tier login mechanism using a biometric-independent wake-up phrase and a security token, where the user recites a rendered security token to authenticate, with local processing and generation of the token, and comparison to stored voice data for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If voice biometric authentication is used, then authentication speed and convenience are improved, but security against replay attacks deteriorates

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity against replay attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic authentication by generating a unique security token for each authentication attempt. The system transitions from static voiceprint comparison to dynamic token verification, where the expected response changes with each challenge, preventing replay attacks while maintaining voice-based convenience authentication

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter from comparing fixed voiceprints to verifying dynamic security tokens. By modifying what is being authenticated (from static biometric patterns to dynamic challenge-response tokens), the system simultaneously maintains voice-based convenience and achieves security against replay attacks

Inventive Principle:
Principle #35Parameter changes

2Reliability

If biometric-dependent wake-up phrases are used, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process into two independent parts: a biometric-independent wake-up phrase for device activation, and a biometric-dependent security token verification for actual authentication. This segmentation allows each component to be optimized independently, providing convenience where needed and security where required

Inventive Principle:
Principle #1Segmentation

3Productivity

If voice authentication is implemented, then authentication speed is improved, but susceptibility to security attacks worsens

Engineering Contradiction:
Improveauthentication speedVSAvoidvulnerability to security attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security token as an intermediary element between the voice authentication system and the final access decision. The token acts as a mediator that adds a security layer without significantly impacting authentication speed, as the token verification can be performed concurrently with voice processing

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10229256B2Techniques for preventing voice replay attacks
Publication Date: 2019.03.12 INTEL CORP
  • US10229256B2 patent drawing
  • US10229256B2 patent drawing
  • US10229256B2 patent drawing

AI summary

Technologies for authenticated audio login by a user of a computing device include generating a security token having a plurality of token characters. The computing device renders the generated security token to a current user of the computing device on an output device of the computing device. The computing device, receives security token audio input from the current user and retrieves, based on the rendered security token, voice profile data of an authorized user of the computing device from a voice profile database. The voice profile database includes voice data based on the authorized user's prior recitation of each token character of a set of token characters from which the security token may be composed. The computing device compares the received security token audio input and the retrieved voice profile data to verify that the current user is the authenticated user and the current user recited the rendered security token.