IP Library Granted Patent US 11,004,168
Granted Patent B2
US 11,004,168 · App. 16/370,455 · Granted May 11, 2021

Optical feedback for visual recognition authentication

Inventors: Alex Nayshtut (Gan Yanve, IL); Igor Muttik (Berkhamsted, GB); Oleg Pogorelik (Lapid, IL); Adam Marek (Gdansk, PL)
Assignee: MCAFEE, LLC
G06T1/0021G06K9/00577G06K9/00899G06K9/00906H04L63/08G06K2009/0059
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,004,168
App. No.
16/370,455
Granted
May 11, 2021
Kind
B2
Abstract

Providing optical watermark signals for a visual authentication session by performing at least the following: receive, at an anti-spoof engine, an instruction to perform visual authentication operations for a visual authentication session, generate, with the anti-spoof engine, an optical watermark signal based on receiving the instruction, wherein the optical watermark signal includes at least one optical identifier to authenticate images captured during the visual authentication session, obtain, with the anti-spoof engine, an image source that includes captured images of the visual authentication session, determine, with the anti-spoof engine, whether the image source includes a reflected optical watermark signal, and compare, with the anti-spoof engine, whether the reflected optical watermark signal matches the generated optical watermark signal based on the determination that the image source includes the reflected optical watermark signal.

Claims (34)

1. At least one of a storage device or a storage disk comprising instructions to prevent visual authentication spoofing that, when executed, cause a machine to at least:

select (a) a first data element from candidate data elements to encode into a first watermark during a first time period and (b) a second data element different from the first data element from the candidate data elements to encode into a second watermark during a second time period, the second time period different than the first time period;

encrypt the first and second data elements with a security key;

generate an optical signal for a visual authentication session, the optical signal including the first watermark during the first time period and the optical signal including the second watermark during the second time period; and

determine whether a reflected optical signal matches the optical signal generated for the visual authentication session based on a determination that the reflected optical signal includes (a) the first data element during the first time period and (b) the second data element during the second time period, the first and second data elements decrypted with the security key.

2. The at least one storage device or storage disk of claim 1 , wherein the security key is a shared security key based on a one time password sequence.

3. The at least one storage device or storage disk of claim 1 , wherein the security key is set in a secure factory environment.

4. The at least one storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the machine to generate a first hash value for the first data element and a second hash value for the second data element using the security key.

5. The at least one storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the machine to deny a user access to restricted information based on a determination that the reflected optical signal does not match the optical signal generated for the visual authentication session.

6. The at least one storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the machine to abort the visual authentication session based on a determination that the reflected optical signal does not include (a) the first watermark during the first time period and (b) the second watermark during the second time period.

7. The at least one storage device or storage disk of claim 1 , wherein the instructions, when executed, cause the machine to project at least one of the optical signals at a wavelength of light that is greater than 700 nanometers.

8. A system for preventing spoofing of visual authentication, comprising:

a processor; and

a memory, coupled to the processor, including instructions, that when executed by the processor, cause the system to:

select (a) a first data element from candidate data elements to encode into a first watermark during a first time period and (b) a second data element different from the first data element from the candidate data elements to encode into a second watermark during a second time period, the second time period different than the first time period;

encrypt the first and second data elements with a security key;

generate an optical signal for a visual authentication session, the optical signal including the first watermark during the first time period and the optical signal including the second watermark during the second time period; and

determine whether a reflected optical signal matches the optical signal generated for the visual authentication session based on a determination that the reflected optical signal includes (a) the first data element during the first time period and (b) the second data element during the second time period, the first and second data elements decrypted with the security key.

9. The system of claim 8 , wherein the security key is shared security key based on a one time password sequence.

10. The system of claim 8 , wherein the security key is set in a secure factory environment.

11. The system of claim 8 , wherein the instructions, when executed, cause the system to generate a first hash value for the first data element and a second hash value for the second data element using the security key.

12. The system of claim 8 , wherein the instructions, when executed, cause the system to deny a user access to restricted information based on a determination that the reflected optical signal does not match the optical signal generated for the visual authentication session.

13. The system of claim 8 , wherein the instructions, when executed, cause the system to abort the visual authentication session based on a determination that the reflected optical signal does not include (a) the first watermark during the first time period and (b) the second watermark during the second time period.

14. The system of claim 8 , wherein at least one of the optical signals is projected at a wavelength of light that is greater than 700 nanometers.

15. A method for preventing spoofing of visual authentication, comprising:

selecting, by executing an instruction with at least one processor, (a) a first data element from candidate data elements to encode into a first watermark during a first time period and (b) a second data element different from the first data element from the candidate data elements to encode into a second watermark during a second time period, the second time period different than the first time period;

encrypting, by executing an instruction with the at least one processor, the first and second data elements with a security key;

generating, by executing an instruction with the at least one processor, an optical signal for a visual authentication session, the optical signal including the first watermark during the first time period and the optical signal including the second watermark during the second time period; and

determining, by executing an instruction with the at least one processor, whether a reflected optical signal matches the optical signal generated for the visual authentication session based on a determination that the reflected optical signal includes (a) the first data element during the first time period and (b) the second data element during the second time period, the first and second data elements decrypted with the security key.

16. The method of claim 15 , wherein the security key is shared security key based on a one time password sequence.

17. The method of claim 15 , wherein the security key is set in a secure factory environment.

18. The method of claim 15 , further including generating a first hash value for the first data element and a second hash value for the second data element using the security key.

19. The method of claim 15 , further including denying a user access to restricted information in response to determining that the reflected optical signal does not match the optical signal generated for the visual authentication session.

20. The method of claim 15 , further including aborting the visual authentication session in response to determining that the reflected optical signal does not include (a) the first watermark during the first time period and (b) the second watermark during the second time period.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
CHANGE OF NAME Recorded Oct 4, 2019
From: MCAFEE, INC
To: MCAFEE, LLC
Reel/Frame 050636/0200 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2019
From: NAYSHTUT, ALEX; MUTTIK, IGOR; POGORELIK, OLEG O.; MAREK, ADAM
To: MCAFEE, INC.
Reel/Frame 050496/0605 →
Continuity (2)
Continuation 15348079 · Nov 10, 2016
Related Publication 20190228496A1 · Jul 25, 2019