Systems and methods for password managers

US12216757B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12216757-B2
Application numberUS-202418425019-A
CountryUS
Kind codeB2
Filing dateJan 29, 2024
Priority dateJan 27, 2020
Publication dateFeb 4, 2025
Grant dateFeb 4, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An authentication system comprises a browser extension and a password manager application. The browser extension can be configured for execution on a first user device. The browser extension can be configured to display a response code and receive a login credential from a server. The response code can comprise a unique session identifier identifying the browser extension and a user browsing session. The password manager application can be configured for execution on a second user device. The second user device can have a scanner configured to scan the response code. The password manager application can be configured to extract the unique session identifier, parse the unique session identifier into session identifier content, send a portion of the session identifier content to the server, receive an approval from a user of the second user device, and send a notification to the server.

First claim

Opening claim text (preview).

What is claimed is: 1. A system, comprising a first user device including a browser extension and a second user device including a password manager application, wherein: the browser extension is configured to: display a code comprising metadata, the metadata including a unique session identifier, a security question, a device identifier, and a browser type identifier; and receive login credentials from a server; and the password manager application is configured to: receive the code; establish a handshake with the server based on the metadata; parse the unique session identifier into session identifier content; send the security question and a portion of the session identifier content to the server; and receive an approval from the server. 2. The system of claim 1 , wherein the browser extension is further configured to encrypt the received login credentials with a private key. 3. The system of claim 1 , wherein the password manager application is further configured to extract the unique session identifier and the security question. 4. The system of claim 1 , wherein the password manager application is further configured to receive a security question answer from the server, and send a notification to the server, wherein the notification includes the unique session identifier and the login credentials. 5. The system of claim 1 , wherein the unique session identifier identifies the browser extension and a user browsing session, and the browser extension is further configured to perform the login using the credentials. 6. The system of claim 1 , wherein the approval comprises a personal identification number (PIN) or a biometric. 7. The system of claim 1 , wherein the code comprises a bar code or a quick response code. 8. A method, comprising: receiving a secure login option for a login associated with a website, wherein the website is displayed on a first user device; generating a unique session identifier and sending the unique session identifier to a server; displaying a code on the first user device, wherein the code includes metadata comprising the unique session identifier, a security question, a device identifier, a browser type identifier, and a time zone identifier; establishing a handshake with the server based on the metadata; receiving credentials for the login associated with the unique session identifier from the server; and performing the login using the credentials. 9. The method of claim 8 , wherein the login is secured through a password manager application on a second user device. 10. The method of claim 9 , wherein the code is scannable by the second user device. 11. The method of claim 8 , further comprising encrypting the credentials using a private key. 12. The method of claim 8 , further comprising transmitting the metadata to the server to establish the handshake. 13. The method of claim 8 , further comprising receiving a security question answer from the server, wherein the security question answer is associated with a password manager application. 14. The method of claim 8 , wherein the unique session identifier identifies a browser extension and a user browsing session. 15. The method of claim 14 , wherein the second user device includes a scanner configured to scan the code. 16. The method of claim 8 , further comprising receiving a whitelist from the server, wherein the secure login option is available for the website because it is a member of the whitelist. 17. The method of claim 8 , wherein the metadata includes at least one selected from the group of an IP address and a time stamp. 18. A non-transitory computer-accessible medium having stored thereon computer-executable instructions that, when executed by a computer arrangement, cause the computer arrangement to perform procedures comprising: receiving a secure login option for a login associated with a website, wherein the website is displayed on a first user device; generating a unique session identifier and sending the unique session identifier to a server; displaying a code on the first user device, wherein the code includes metadata comprising the unique session identifier, a security question, a device identifier, a browser type identifier, and a time zone identifier; establishing a handshake with the server based on the metadata; receiving credentials for the login associated with the unique session identifier from the server; and performing the login using the credentials. 19. The non-transitory computer-accessible medium of claim 18 , the procedures further comprise receiving an approval, wherein the approval comprises a two-factor authentication. 20. The non-transitory computer-accessible medium of claim 18 , the procedures further comprise receiving a security question answer and sending a notification to a server, wherein the notification includes the unique session identifier and the login credentials. 21. The method of claim 8 , wherein establishing a handshake with the server is performed on a second user device.

Assignees

Inventors

Classifications

  • using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title

  • Providing cryptographic facilities or services · CPC title

  • Access control lists [ACL] · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12216757B2 cover?
An authentication system comprises a browser extension and a password manager application. The browser extension can be configured for execution on a first user device. The browser extension can be configured to display a response code and receive a login credential from a server. The response code can comprise a unique session identifier identifying the browser extension and a user browsing se…
Who is the assignee on this patent?
Capital One Services Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/45. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 04 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).