Systems and methods for conducting remote user authentication

US11854008B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11854008-B2
Application numberUS-202117494737-A
CountryUS
Kind codeB2
Filing dateOct 5, 2021
Priority dateOct 5, 2021
Publication dateDec 26, 2023
Grant dateDec 26, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Disclosed embodiments may include a system that may receive, from a user device associated with a user, authentication rule(s), each authentication rule associated with respective merchant(s) and comprising respective required authentication factor(s) for completing a transaction with the respective merchant(s). The system may identify a user has navigated to a merchant webpage and may determine at least one rule of the authentication rule(s) associated with the merchant. The system may identify first required authentication factor(s) corresponding to the at least one rule, and may cause the user device to display, via a GUI, the first required authentication factor(s). The system may receive, via the user device, authentication information associated with the user. The system may determine whether the authentication information satisfies the first required authentication factor(s). Responsive to making that determination, the system may enable the user to complete a transaction via the merchant webpage.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for user authentication comprising: one or more processors; and a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to: receive, from a first user device associated with a first user, one or more authentication rules, wherein each of the one or more authentication rules is associated with one or more respective merchants and comprises (i) one or more respective required authentication factors for completing a transaction with the one or more respective merchants and (ii) a respective indication of whether the first user is permitted to provide additional authentication information when initially provided authentication information does not satisfy the respective authentication rule, and wherein the one or more respective required authentication factors comprise one or more of a personal identification number (PIN), a physical token, a facial recognition, a thumbprint image, a retina scan, or combinations thereof; store the one or more authentication rules comprising the one or more respective required authentication factors and the respective indication; determine, via a web browser extension running on the first user device, that the first user has navigated to a webpage associated with a first merchant; receive, via a graphical user interface (GUI) of the first user device, a request to use a virtual card number associated with the first merchant to complete a first transaction; determine whether at least one rule of the one or more authentication rules is associated with the first merchant; responsive to determining the at least one rule of the one or more authentication rules is associated with the first merchant, identify one or more first required authentication factors corresponding to the at least one rule; cause the first user device to display, via the GUI of the first user device, the one or more first required authentication factors; receive, via the first user device, authentication information associated with the first user; determine whether the authentication information satisfies the one or more first required authentication factors; responsive to determining that the authentication information does not satisfy the one or more first required authentication factors: retrieve the respective indication stored with the at least one rule; responsive to retrieving the respective indication, determine whether the first user is permitted to provide the additional authentication information; responsive to determining the first user is permitted to provide the additional authentication information, transmit, via the GUI of the first user device, a request to provide the additional authentication information; receive, via the GUI of the first user device, the additional authentication information; determine whether the additional authentication information satisfies one or more additional authentication factors, wherein the one or more additional authentication factors are different from the one or more first required authentication factors; and responsive to determining the additional authentication information satisfies the one or more additional authentication factors: direct the first user to the web browser extension to generate the virtual card number, wherein the web browser extension is external to the first merchant and generates the virtual card number; modify the GUI of the first user device such that a previously greyed out user input object is enabled to receive user input; and enable the first user to complete the first transaction by entering the virtual card number that was generated into the enabled user input object; and responsive to determining that the authentication information satisfies the one or more first required authentication factors, enable the first user to complete the first transaction using the virtual card number. 2. The system of claim 1 , wherein the instructions are further configured to cause the system to: transmit a notification to a second user device associated with the first user, the notification providing the one or more first required authentication factors. 3. The system of claim 2 , wherein the first user device is a computer and the second user device is a mobile phone. 4. The system of claim 1 , wherein the one or more respective required authentication factors are customizable by the first user. 5. The system of claim 1 , wherein a total number of the one or more respective required authentication factors for completing the transaction is based on a total dollar amount of the transaction. 6. A system for user authentication comprising: one or more processors; and a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to: receive, from a first user device associated with a first user, one or more authentication rules, wherein each of the one or more authentication rules is associated with one or more respective merchants and comprises one or more respective required authentication factors for completing a transaction with the one or more respective merchants, and wherein the one or more respective required authentication factors comprise one or more of a personal identification number (PIN), a physical token, a facial recognition, a thumbprint image, a retina scan, or combinations thereof; determine, via a web browser extension running on the first user device, that the first user has navigated to a webpage associated with a first merchant, wherein the web browser extension is external to the first merchant; determine whether at least one rule of the one or more authentication rules is associated with the first merchant; responsive to determining the at least one rule of the one or more authentication rules is associated with the first merchant, identify one or more first required authentication factors corresponding to the at least one rule; cause the first user device to display, via a graphical user interface (GUI) of the first user device, the one or more first required authentication factors; receive, via the first user device, authentication information associated with the first user; determine whether the authentication information satisfies the one or more first required authentication factors; responsive to determining that the authentication information does not satisfy the one or more first required authentication factors: determine whether the first user is permitted to provide additional authentication information based on an indication previously stored and associated with the at least one rule of the one or more authentication rules; responsive to determining the first user is permitted to provide the additional authentication information, transmit, via the GUI of the first user device, a request to provide the additional authentication information; receive, via the GUI of the first user device, the additional authentication information; determine whether the additional authentication information satisfies one or more additional authentication factors, wherein the one or more additional authentication factors are different from the one or more first required authentication factors; and responsive to determining the additional authentication information satisfies the one or more additional authentication factors: modify the GUI of the first user device such that a previously greyed out user input object is enabled to receive user input; direct the first user to the web browser extension to generate a first virtual card number, wherein the web browser extension generates the first virtual card number; and enable the first

Assignees

Inventors

Classifications

  • G06Q20/401Primary

    Transaction verification · CPC title

  • communicating wirelessly · CPC title

  • Verifying personal identification numbers [PIN] · CPC title

  • Identity check for transactions · CPC title

  • Biometric identity checks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11854008B2 cover?
Disclosed embodiments may include a system that may receive, from a user device associated with a user, authentication rule(s), each authentication rule associated with respective merchant(s) and comprising respective required authentication factor(s) for completing a transaction with the respective merchant(s). The system may identify a user has navigated to a merchant webpage and may determin…
Who is the assignee on this patent?
Capital One Services Llc
What technology area does this patent fall under?
Primary CPC classification G06Q20/401. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 26 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).