Multi-Factor User Authentication
US-2024394695-A1 · Nov 28, 2024 · US
US2021217022A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2021217022-A1 |
| Application number | US-202016742323-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jan 14, 2020 |
| Priority date | Jan 14, 2020 |
| Publication date | Jul 15, 2021 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods and systems described herein may monitor, by a browser, activity of a user within a web page displayed by the browser. Based on detecting, by the browser, an attempt by the first user to perform a financial transaction with an online vendor and associated with a financial account, biometric information associated with the user may be captured by the browser. Based on the captured biometric information, the browser may determine whether the first user is authorized to perform financial transactions with the online vendor and associated with the financial account. Based on a determination that the user is not authorized to perform the financial transaction, the browser may modify at least one element of the webpage to block the user from performing the financial transaction with the online vendor.
Opening claim text (preview).
1 . A computer-implemented method, comprising: monitoring, by a browser and based on a determination that a first web page is associated with at least one of a plurality of websites or a plurality of online vendors pre-selected for monitoring, activity of a first user within the first web page displayed by the browser; detecting, by the browser and based on the monitoring, an attempt, by the first user, to perform a first financial transaction with an online vendor and associated with a financial account; capturing, by the browser and based on the detecting, biometric information associated with the first user; determining, by the browser and based on the captured biometric information, whether the first user is authorized to perform financial transactions with the online vendor and associated with the financial account; and modifying, by the browser and based on a determination that the first user is not authorized to perform the first financial transaction, a Document Object Model (DOM) representation of the first web page to block the first user from performing the first financial transaction with the online vendor. 2 . The computer-implemented method of claim 1 , further comprising: detecting, by the browser and based on monitoring user activity of a second user, an attempt to perform a second financial transaction, on a second web page, with the online vendor and associated with the financial account; capturing, by the browser and based on the detecting the attempt to perform the second financial transaction, biometric information associated with the second user; determining, by the browser and based on the captured biometric information, whether the second user is authorized to perform financial transactions with the online vendor and associated with the financial account; and modifying, by the browser and based on a determination that the second user is authorized to perform the second financial transaction, at least one element of the second web page to enable the second user to perform the second financial transaction. 3 . The computer-implemented method of claim 1 , further comprising: detecting, by the browser and based on monitoring user activity of a second user, an attempt to perform a second financial transaction with the online vendor and associated with the financial account; capturing, by the browser and based on the detecting the attempt to perform the second financial transaction, biometric information associated with the second user; determining, by the browser and based on the captured biometric information, whether the second user is authorized to perform a financial transaction with the online vendor and associated with the financial account; and allowing, by the browser and based on a determination that the second user is authorized to perform the second transaction, the second financial transaction. 4 . The computer-implemented method of claim 1 , further comprising: modifying at least one element of the first web page by: disabling one or more user selectable options in the first web page; or hiding one or more portions of content of the first web page. 5 . (canceled) 6 . The computer-implemented method of claim 1 , further comprising: sending, by the browser and based on the determination that the first user is not authorized, a notification of the attempt to perform the first financial transaction to an account holder associated with the financial account. 7 . The computer-implemented method of claim 6 , wherein the notification sent to the account holder comprises at least a portion of the captured biometric information. 8 . (canceled) 9 . The computer-implemented method of claim 1 , wherein the captured biometric information comprises at least one of an image of a face of the first user, a voice sample provided by the first user, a retinal scan of the first user, or a fingerprint provided by the first user. 10 . The computer-implemented method of claim 1 , wherein determining whether the first user is authorized is based on the captured biometric information and biometric data associated with one or more users that are pre-authorized to perform one or more financial transactions with the online vendor and associated with the financial account. 11 . The method of claim 1 , further comprising: notifying, by the browser and based on the determination that the first user is not authorized, the first user that the first user is unauthorized to perform the first financial transaction. 12 . The method of claim 1 , wherein the biometric information associated with the first user is captured periodically. 13 . The method of claim 1 , further comprising: disabling a plurality of user interactive features of the first web page. 14 . The method of claim 13 , further comprising: periodically capturing, after modifying the DOM representation of the first web page, biometric information associated with a current user of the browser; determining, by the browser and based on the captured biometric information associated with the current user, whether the first user is continuing to use the browser; and enabling, by the browser and based on a determination that the first user has ceased using the browser, the DOM representation of the first web page. 15 . The method of claim 10 , wherein the biometric data associated with the one or more users pre-authorized to perform one or more financial transactions with the online vendor and associated with the financial account is stored in a memory of a user device executing the browser. 16 . An apparatus, comprising: one or more processors; and memory storing instructions that, when executed by the one or more processors, cause the apparatus to: display, via a browser executing on the apparatus, a web page accessed by a user, wherein the web page is associated with a first online vendor; determine, via the browser executing on the apparatus, whether the first online vendor has been pre-identified for monitoring; capture, via the browser executing on the apparatus and based on a determination that the first online vendor has been pre-identified for monitoring, biometric data associated with the user; determine, based on the captured biometric data, whether the user is authorized to perform a financial transaction with the online vendor; and based on a determination that the user is unauthorized, modify a plurality of elements of the web page associated with performing a financial transaction, wherein the plurality of elements comprises at least one Document Object Model (DOM) representation of the web page. 17 . The apparatus of claim 16 , wherein the captured biometric information associated with the user comprises at least one image of a face of the user. 18 . (canceled) 19 . The apparatus of claim 16 , wherein the instructions, when executed by the one or more processors, cause the apparatus to: based on the determination that the user is unauthorized, notify the user of the browser that the user is unauthorized to perform a financial transaction with the online vendor. 20 . A non-transitory machine-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform steps comprising: monitoring, by a browser and based on a determination that a first web page is associated with at least one of a plurality of websites or a plurality of online vendors pre-identified for monitoring, activity of a first user within the first web page; detect
monitoring of user actions (tracking the activity of the user H04L67/535) · CPC title
Biometric identity checks · CPC title
specially adapted for electronic shopping systems · CPC title
Tree-structured documents (parsing G06F40/205; validation G06F40/226) · CPC title
Browsing; Visualisation therefor (for navigating the web G06F16/954; browsing optimisation for the web G06F16/957) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.