Authentication using a conversational user interface
A one-time passphrase is transmitted from an authentication system to a personal communication device of a user. The one-time passphrase includes common but incongruous words. The user is prompted to verbalize the one-time passphrase to a processor-implemented, conversational user interface. Utterances from the user are received by a conversational user interface, and the utterances are communicated from the conversational user interface to the authentication system via a trusted communication channel. The authentication system determines, using speech recognition, presence or non-presence of the one-time passphrase within the received utterances. The authentication system authenticates the user in response to detecting presence of the one-time passphrase within the received utterances.
1 . A method comprising:
receiving an open credential from a user;
determining, based on the open credential, an address of a personal communication device of the user;
sending a one-time passphrase transmitted from an authentication system to the address of the personal communication device;
prompting the user to verbalize the one-time passphrase via utterances to a processor-implemented, conversational user interface;
determining, by the authentication system using speech recognition, presence or non-presence of the one-time passphrase within the utterances;
in response to detecting the presence of the one-time passphrase within the utterances, authenticating the user to a session; and
during the session, re-authenticating the user by:
prompting the user to provide subsequent utterances, which include a subsequent one-time passphrase different from the one-time passphrase; and
determining presence or non-presence of the subsequent one-time passphrase within the subsequent utterances.
2 . The method of claim 1 , wherein the personal communication device communicates the one-time passphrase to the user via a non-textual, graphical representation of common but incongruous words.
3 . The method of claim 1 , wherein the session provides the user access to a protected resource, wherein the re-authenticating further comprises:
determining an initial voiceprint of the user based on the utterance;
determining subsequent voiceprints of the user based on the subsequent utterances;
determining a match between the subsequent and initial voiceprints exceeding a predetermined confidence threshold; and
revoking access rights of the user to the protected resources in response to a mismatch between the subsequent and initial voiceprints.
4 . The method of claim 1 , further comprising receiving via the conversational user interface, a command from the user to terminate the session.
5 . The method of claim 1 , further comprising, during the session:
storing change commands involving protected resources in response to verbal input by the user;
and executing the stored change commands in response to the re-authenticating of the user.
6 . The method of claim 1 , wherein the utterances from the user include common but incongruous words that are selected to be easily pronounced and detected with high confidence by a voice recognition system.
7 . The method of claim 1 , wherein the utterances from the user include common but incongruous words embedded with other conversational verbiage generated by the user.
8 . The method of claim 1 , wherein the personal communication device communicates the one-time passphrase to the user via a tactile representation of common but incongruous words.
9 . The method of claim 1 , wherein the open credential is received via the conversational user interface.
10 . A method comprising:
receiving an open credential from a user;
determining, based on the open credential, an address of a personal communication device of the user;
sending a one-time passphrase transmitted from an authentication system to the address of the personal communication device, the one-time passphrase comprising common but incongruous words;
prompting the user to verbalize the one-time passphrase to a processor-implemented, conversational user interface;
receiving, by the conversational user interface, utterances from the user and communicating the utterances from the conversational user interface to the authentication system via a trusted communication channel;
determining, by the authentication system using speech recognition, the presence or non-presence of the one-time passphrase within the received utterances;
authenticating, by the authentication system, the user in response to detecting the presence of the one-time passphrase within the received utterances;
after authenticating the user, storing change commands involving protected resources in response to verbal input by the user;
prior to executing the stored change commands:
prompting the user to verbalize a second one-time passphrase to the conversational user interface via the personal communication device;
determining, by the authentication system using speech recognition, presence or non-presence of the second one-time passphrase within second utterances communicated from the conversational user interface to the authentication system; and
re-authenticating the user in response to detecting presence of the second one-time passphrase within the second utterances; and
executing the stored change commands in response to successfully re-authenticating the user.
11 . A system comprising:
an authentication system operable to:
receive an open credential from a user of the system;
determine, based on the open credential, an address of a personal communication device of the user;
transmit a one-time passphrase to the address of the personal communication device, the personal communication device prompting the user to verbalize the one-time passphrase; and
a processor-implemented, conversational user interface operable to:
receive utterances from the user in response to the prompting; and
communicate the received utterances to the authentication system;
wherein the authentication system is operable to:
determine, using speech recognition, presence or non-presence of the one-time passphrase within the received utterances;
authenticate the user to a session in response to detecting presence of the one-time passphrase within the received utterances; and
during the session, re-authenticate the user by:
prompting the user to provide subsequent utterances, which include a subsequent one-time passphrase different from the one-time passphrase; and
determining presence or non-presence of the subsequent one-time passphrase within the subsequent utterances.
12 . The system of claim 11 , wherein the personal communication device communicates the one-time passphrase to the user via a non-textual, graphical representation of common but incongruous words.
13 . The system of claim 11 , wherein the session provides the user access to a protected resource and, wherein the re-authenticating further comprises:
determining initial voiceprints of the user based on the utterances;
determining subsequent voiceprints of the user based on the subsequent utterances;
determining a match between the subsequent and initial voiceprints exceeding a predetermined threshold; and
revoking access rights of the user to the protected resource in response to a mismatch between the subsequent and initial voiceprints.
14 . The system of claim 11 , wherein the system is further operable to receive a command from the user via the conversational user interface to terminate the session.
15 . The system of claim 11 , wherein the utterances from the user include common but incongruous words that are selected to be easily pronounced and detected with high confidence by a voice recognition system.
16 . The system of claim 11 , wherein the utterances from the user include common but incongruous words embedded with other conversational verbiage generated by the user.
17 . The system of claim 11 , wherein the personal communication device communicates the one-time passphrase to the user via a tactile representation of common but incongruous words.