Voice Replay Attack Prevention via Dynamic Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Voice biometric authentication systems are susceptible to security attacks such as voice replay attacks, and existing methods require biometric-dependent wake-up phrases, which can be inconvenient and insecure.
Innovation Solution
A computing device employs a two-tier login mechanism using a biometric-independent wake-up phrase and a security token, where the user recites a rendered security token to authenticate, with local processing and generation of the token, and comparison to stored voice data for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If voice biometric authentication is used, then authentication speed and convenience are improved, but security against replay attacks deteriorates
Solution Approach 1:
The patent implements dynamic authentication by generating a unique security token for each authentication attempt. The system transitions from static voiceprint comparison to dynamic token verification, where the expected response changes with each challenge, preventing replay attacks while maintaining voice-based convenience authentication
Solution Approach 2:
The system changes the authentication parameter from comparing fixed voiceprints to verifying dynamic security tokens. By modifying what is being authenticated (from static biometric patterns to dynamic challenge-response tokens), the system simultaneously maintains voice-based convenience and achieves security against replay attacks
2Reliability
If biometric-dependent wake-up phrases are used, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent segments the authentication process into two independent parts: a biometric-independent wake-up phrase for device activation, and a biometric-dependent security token verification for actual authentication. This segmentation allows each component to be optimized independently, providing convenience where needed and security where required
3Productivity
If voice authentication is implemented, then authentication speed is improved, but susceptibility to security attacks worsens
Solution Approach 1:
The patent introduces a security token as an intermediary element between the voice authentication system and the final access decision. The token acts as a mediator that adds a security layer without significantly impacting authentication speed, as the token verification can be performed concurrently with voice processing
Data Source
AI summary
Technologies for authenticated audio login by a user of a computing device include generating a security token having a plurality of token characters. The computing device renders the generated security token to a current user of the computing device on an output device of the computing device. The computing device, receives security token audio input from the current user and retrieves, based on the rendered security token, voice profile data of an authorized user of the computing device from a voice profile database. The voice profile database includes voice data based on the authorized user's prior recitation of each token character of a set of token characters from which the security token may be composed. The computing device compares the received security token audio input and the retrieved voice profile data to verify that the current user is the authenticated user and the current user recited the rendered security token.


