IP Library Patent Application 19216469
Patent Application
App. No. 19/216,469

ONE TIME VOICE PASSPHRASE TO PROTECT AGAINST MAN-IN-THE-MIDDLE ATTACK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/216,469
Abstract

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.

Claims (33)

1 . A computer-implemented method for authentication using a voice-based one-time password (OTP), the method comprising:

transmitting, by a computing device associated with an end-user, a message indicating an operation request to a backend server;

receiving, by the computing device, an OTP request including an OTP prompt having OTP text of an OTP;

displaying, by the computing device, the OTP text of the OTP prompt at a user interface of the computing device of the end-user;

obtaining, by the computing device, an audio signal including a speaker audio signal of the end-user purportedly speaking the OTP;

generating, by the computing device, an OTP response corresponding to the OTP request, the OTP response including the audio signal including the speaker audio signal; and

transmitting, by the computing device, the OTP response to the backend server.

2 . The method according to claim 1 , further comprising receiving, by the computing device, an authentication result for the operation request from the backend server.

3 . The method according to claim 2 , further comprising displaying, by the computing device, the authentication result for the operation request as received from the backend server.

4 . The method according to claim 1 , wherein the OTP response further includes metadata associated with the computing device of the end-user, the metadata including at least one of a user identifier of the end-user or a device identifier of the computing device.

5 . The method according to claim 1 , wherein the OTP response further includes an operation request identifier associated with the operation request.

6 . The method according to claim 1 , wherein the computing device transmits the message indicating the operation request via at least one of a telephony channel or a data channel.

7 . The method according to claim 1 , wherein the computing device receives the OTP request via at least one of a data channel or a telephony channel.

8 . The method according to claim 1 , wherein the computing device transmits the OTP response via at least one of a data channel or a telephony channel.

9 . The method according to claim 1 , wherein the computing device includes and executes a mobile application associated with the backend server, and wherein the computing device receives the OTP request as a push notification for the mobile application.

10 . The method according to claim 1 , wherein the computing device receives the OTP request containing the OTP prompt via at least one of a text message or an email message.

11 . A system for authentication using a voice-based one-time password (OTP), the system comprising:

a computing device associated with an end-user having at least one processor, the computing device configured to:

transmit a message indicating an operation request to a backend server;

receive an OTP request including an OTP prompt having OTP text of an OTP;

display the OTP text of the OTP prompt at a user interface of the computing device of the end-user;

obtain an audio signal including a speaker audio signal of the end-user purportedly speaking the OTP;

generate an OTP response corresponding to the OTP request, the OTP response including the audio signal including the speaker audio signal; and

transmit the OTP response to the backend server.

12 . The system according to claim 11 , wherein the computing device is further configured to receive an authentication result for the operation request from the backend server.

13 . The system according to claim 12 , wherein the computing device is further configured to display the authentication result for the operation request as received from the backend server.

14 . The system according to claim 11 , wherein the OTP response further includes metadata associated with the computing device of the end-user, the metadata including at least one of a user identifier of the end-user or a device identifier of the computing device.

15 . The system according to claim 11 , wherein the OTP response further includes an operation request identifier associated with the operation request.

16 . The system according to claim 11 , wherein the computing device transmits the message indicating the operation request via at least one of a telephony channel or a data channel.

17 . The system according to claim 11 , wherein the computing device receives the OTP request via at least one of a data channel or a telephony channel.

18 . The system according to claim 11 , wherein the computing device transmits the OTP response via at least one of a data channel or a telephony channel.

19 . The system according to claim 11 , wherein the computing device includes and executes a mobile application associated with the backend server, and wherein the computing device receives the OTP request as a push notification for the mobile application.

20 . The system according to claim 11 , wherein the computing device receives the OTP request containing the OTP prompt via at least one of a text message or an email message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2025
From: GUPTA, AMIT; MERCHANT, MOHAMMEDALI; BALASUBRAMANIYAN, VIJAY
To: PINDROP SECURITY, INC.
Reel/Frame 071203/0569 →