IP Library Granted Patent US 12677152
Granted Patent B2
US 12677152 · App. 18/503,803 · Granted Jul 7, 2026

Systems and methods for tiered authentication

Inventors: John Tilmon (McLean, VA); Kyle G. McKenna (McLean, VA); Nicholas Pulaski (McLean, VA)
Assignee: Capital One Services, LLC
H04W12/08H04W4/14H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12677152
App. No.
18/503,803
Granted
Jul 7, 2026
Kind
B2
Abstract

Methods and systems for managing text messaging-based authentication in absence of a physical authentication token. The system receives, from a mobile device, a first text message, in which the mobile device is operating on a mobile network and associated with a user digital identifier relating to the mobile network, and the first text message indicates a request for access in absence of the physical authentication token. The system performs an account search based on the user digital identifier. In response to locating a user account associated with the user digital identifier, the system performs an assessment based on mobile device information relating to the mobile network and associated with the user digital identifier; selects, from a plurality of candidate authentication protocols, an authentication protocol based on the assessment; and manages, based on the authentication protocol, the request for access in absence of the physical authentication token.

Claims (79)

1 . A system for managing text messaging-based authentication in absence of a physical authentication token, comprising:

one or more processors; and

one or more non-transitory, computer-readable media comprising instructions that, when executed by the one or more processors, cause operations comprising:

receiving, from a mobile device, a first text message addressed to a recipient digital identifier, wherein the mobile device is operating on a mobile network and associated with a user digital identifier relating to the mobile network, and wherein the first text message indicates a request for access and indicates an intention to perform an authentication, for the request for access, without the physical authentication token;

performing an account search based on the user digital identifier;

in response to determining an existence of a user account associated with the user digital identifier, retrieving mobile device information relating to the mobile network and associated with the user digital identifier;

performing an assessment based on the mobile device information;

selecting, from a plurality of candidate authentication protocols, an authentication protocol based on the assessment of the mobile device information, wherein:

according to a first candidate authentication protocol of the plurality of candidate authentication protocols, in response to determining, based on the assessment, that an authentication condition is satisfied,

determining that the request is authenticated without requesting further information regarding the user account; and

according to a second candidate authentication protocol of the plurality of candidate authentication protocols, in response to determining, based on the assessment, that the authentication condition is not satisfied, requesting additional authentication information regarding the user account; and

managing, based on the authentication protocol, the request for access in absence of the physical authentication token.

2 . A method for managing text messaging-based authentication in absence of a physical authentication token, comprising:

receiving, from a mobile device, a text message indicating an intention to perform an authentication, for a request for access, without the physical authentication token, wherein the mobile device is operating on a mobile network and associated with a user digital identifier relating to the mobile network;

performing an account search based on the user digital identifier;

in response to determining an existence of a user account associated with the user digital identifier, retrieving mobile device information relating to the mobile network and associated with the user digital identifier;

performing an assessment based on the mobile device information;

selecting, from a plurality of candidate authentication protocols, an authentication protocol based on the assessment of the mobile device information, wherein:

according to a first candidate authentication protocol of the plurality of candidate authentication protocols, in response to determining, based on the assessment, that an authentication condition is satisfied, determining that the request is authenticated without requesting further information regarding the user account; and

according to a second candidate authentication protocol of the plurality of candidate authentication protocols, in response to determining, based on the assessment, that the authentication condition is not satisfied, requesting additional authentication information regarding the user account; and

managing, based on the authentication protocol, the request for access in absence of the physical authentication token.

3 . The method of claim 2 , further comprising:

transmitting, to the mobile device, a second text message including a link to a webpage for access in absence of the physical authentication token; and

detecting access of the link from the mobile device before retrieval of the mobile device information.

4 . The method of claim 2 , wherein according to the second candidate authentication protocol, the method further comprises:

generating, for transmission to the mobile device, a first notification requesting the additional authentication information.

5 . The method of claim 4 , wherein:

the first notification comprises a prompt configured to allow a submission of the additional authentication information via a webpage configured to allow access of the user account in absence of the physical authentication token, and

the method further comprises:

receiving, from the mobile device, the additional authentication information;

determining whether to authenticate the request based on the additional authentication information; and

in response to determining that the request is authenticated based on the additional authentication information, generating a temporary machine-readable code for transmitting to the mobile device, wherein the temporary machine-readable code is associated with the user account and is valid for a specified period.

6 . The method of claim 4 , further comprising:

receiving information transmitted using a secure protocol, the information corresponding to the additional authentication information.

7 . The method of claim 6 , wherein:

the information comprises encrypted data that represent the additional authentication information or compressed data that represent the additional authentication information, and

the method further comprises obtaining the additional authentication information by decrypting or decompressing the information.

8 . The method of claim 6 , wherein:

the additional authentication information comprises text or an image file, and

the method further comprises causing the text or the image file to be encrypted or compressed before transmission from the mobile device.

9 . The method of claim 4 , further comprising:

transmitting the first notification via a third text message to the mobile device, or

transmitting the first notification for display in a webpage on the mobile device, wherein the webpage is configured to allow access of the user account in absence of the physical authentication token.

10 . The method of claim 2 , further comprising:

in response to failing to determine the existence of the user account, generating, for transmission to the mobile device, a second notification requesting second additional authentication information.

11 . The method of claim 10 , further comprising:

transmitting the second notification via a fourth text message to the mobile device, or

transmitting the second notification for display in a webpage on the mobile device, wherein the webpage is configured to allow access of the user account in absence of the physical authentication token.

12 . The method of claim 10 , wherein the second additional authentication information comprises a second user digital identifier that is different from the user digital identifier associated with the mobile device, the method further comprising:

performing a second account search based on the second user digital identifier.

13 . The method of claim 2 , further comprising:

in response to failing to determine the existence of the user account, refraining from retrieving mobile device information relating to the mobile network and associated with the user digital identifier.

14 . The method of claim 2 , wherein managing the request for access in absence of the physical authentication token comprises: in response to determining that the authentication condition is satisfied,

generating a temporary machine-readable code associated with the user account, wherein the temporary machine-readable code is valid for a specified period; and

transmitting the temporary machine-readable code to the mobile device for display on the mobile device, wherein the temporary machine-readable code is configured to allow a third party to access the user account by scanning, within the specified period, the temporary machine-readable code.

15 . The method of claim 14 , further comprising:

transmitting the temporary machine-readable code via a fourth text message to the mobile device, or

transmitting the temporary machine-readable code for display in a webpage on the mobile device, wherein the webpage is configured to allow access of the user account in absence of the physical authentication token.

16 . The method of claim 14 , wherein:

the user account belongs to an account type associated with the third party,

the text message is addressed to a recipient digital identifier, and

at least one of the account type or the recipient digital identifier is associated with the third party.

17 . One or more non-transitory, computer-readable media for managing authentication in absence of a physical authentication token comprising instructions that, when executed on one or more processors, cause operations comprising:

receiving, from a mobile device, an indication of an intention to perform authentication, for a request for access, without the physical authentication token, wherein the mobile device is operating on a mobile network and associated with a user digital identifier relating to the mobile network;

performing an account search based on the user digital identifier;

in response to determining an existence of a user account associated with the user digital identifier, retrieving mobile device information relating to the mobile network and associated with the user digital identifier;

performing an assessment based on the mobile device information;

selecting, from a plurality of candidate authentication protocols, an authentication protocol based on the assessment of the mobile device information, wherein:

according to a first candidate authentication protocol of the plurality of candidate authentication protocols, in response to determining, based on the assessment, that an authentication condition is satisfied, determining that the request is authenticated without requesting further information regarding the user account; and

according to a second candidate authentication protocol of the plurality of candidate authentication protocols, in response to determining, based on the assessment, that the authentication condition is not satisfied, requesting additional authentication information regarding the user account; and

managing, based on the authentication protocol, the request for access in absence of the physical authentication token.

18 . The one or more non-transitory, computer-readable media of claim 17 , wherein the request is indicated by the mobile device transmitting a text message to a recipient digital identifier, scanning a machine-readable code, or accessing a webpage configured to allow access of the user account in absence of the physical authentication token.

19 . The one or more non-transitory, computer-readable media of claim 17 , wherein managing the request for access in absence of the physical authentication token comprises: in response to determining that the authentication condition is satisfied,

generating a temporary machine-readable code associated with the user account, wherein the temporary machine-readable code is valid for a specified period; and

transmitting the temporary machine-readable code to the mobile device for display on the mobile device, wherein the temporary machine-readable code is configured to allow a third party to access the user account by scanning, within the specified period, the temporary machine-readable code.

20 . The one or more non-transitory, computer-readable media of claim 17 , wherein managing the request for access in absence of the physical authentication token comprises: in response to determining that the authentication condition is not satisfied,

transmitting, to the mobile device, a first notification requesting the additional authentication information, wherein the first notification comprises a prompt configured to allow a submission of the additional authentication information via a webpage configured to allow access of the user account in absence of the physical authentication token;

receiving, from the mobile device, the additional authentication information; and

determining whether to authenticate the request based on the additional authentication information.