IP Library Granted Patent US 12,388,813
Granted Patent B2
US 12,388,813 · App. 18/137,459 · Granted Aug 12, 2025

Enhanced security with multiple factor authentication at devices using partitions

Inventors: Maharaj Mukherjee (Poughkeepsie, NY); George Albero (Charlotte, NC)
Assignee: Bank of America Corporation
H04L63/0838H04L63/0861H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,813
App. No.
18/137,459
Granted
Aug 12, 2025
Kind
B2
Abstract

A computing device may configure a plurality of device partitions. The computing device may send, to a one time password (OTP) server and via an interface of a first partition of the plurality of device partitions, a login request. The computing device may receive, at a second partition of the plurality of device partitions, an OTP. The computing device may access, by validating authentication credentials corresponding to the second partition of the plurality of device partitions, the OTP. The computing device may send, to the OTP server, the OTP. The computing device may access, upon receiving confirmation of validation of the OTP, services hosted by the OTP server.

Claims (50)

1. A computing device comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

configure a plurality of device partitions;

send, to a one time password (OTP) server and via an interface of a first partition of the plurality of device partitions, a login request;

receive, from the OTP server, a notification indicating a decoy OTP, wherein the notification identifies characteristics of an interface, to be displayed based on the login request, to warn of the decoy OTP, and wherein the decoy OTP is selectively sent in response to a portion of login requests, wherein the characteristics comprise one or more of: an indication that a particular number of decoy OTPs will be sent in advance of a valid OTP, an indication that OTPs may be sent for only a portion of login attempts, or an indication of how to distinguish between valid and decoy OTPs;

receive, at a second partition of the plurality of device partitions, an OTP;

access, by validating authentication credentials corresponding to the second partition of the plurality of device partitions, the OTP;

send, to the OTP server, the OTP; and

access, upon receiving confirmation of validation of the OTP, services hosted by the OTP server.

2. The computing device of claim 1 , wherein the plurality of device partitions include: one or more hardware partitions and one or more virtual partitions.

3. The computing device of claim 1 , wherein receiving, at the second partition of the plurality of device partitions, the OTP comprises receiving a first portion of the OTP, wherein a second portion of the OTP is received at a third partition of the plurality of device partitions.

4. The computing device of claim 3 , wherein the memory stores additional computer readable instructions that, when executed by the at least one processor, cause the computing device to:

automatically assemble, after validating authentication credentials corresponding to the third partition of the plurality of device partitions, the OTP using the first portion and the second portion.

5. The computing device of claim 4 , wherein the authentication credentials corresponding to the second partition of the plurality of device partitions are different than the authentication credentials corresponding to the third partition of the plurality of device partitions.

6. The computing device of claim 1 , wherein accessing the OTP comprises accessing a decoy OTP prior to accessing the OTP.

7. The computing device of claim 6 , wherein the memory stores additional computer readable instructions that, when executed by the at least one processor, cause the computing device to:

enroll, prior to sending the login request, with the OTP server.

8. The computing device of claim 6 , wherein the OTP server is configured to:

identify use of the decoy OTP by a different computing device, and

initiate, based on identification of the decoy OTP by the different computing device, one or more security actions.

9. The computing device of claim 8 , wherein the one or more security actions comprise one or more of:

tracing the different computing device, wiping the computing device, locking at least one of the plurality of device partitions, prompting for entry of a code at the computing device, or notifying an authority.

10. The computing device of claim 1 , wherein the authentication credentials comprise biometric credentials.

11. The computing device of claim 1 , wherein the OTP is sent to a randomly selected partition of the plurality of device partitions each time a login request is received.

12. The computing device of claim 1 , wherein the indication comprises a natural language indication to distinguish between valid and decoy OTPs, and wherein the natural language indication indicates a particular phrase indicating that a subsequently received OTP will be a valid OTP.

13. The computing device of claim 1 , wherein the indication comprises a numeric value displayed within the interface, wherein the numeric value indicates which OTP of a series of received OTPs is valid.

14. The computing device of claim 1 , wherein a position of the indication within the interface indicates which OTP of a series of received OTPs is valid.

15. The computing device of claim 1 , wherein a position of the indication within the interface indicates a numeric value corresponding to a correct partition for use in accessing the OTP.

16. The computing device of claim 1 , wherein the second partition is accessed based on detection of a swipe input during access of the first partition.

17. The computing device of claim 1 , wherein the first partition is configured only for receipt of OTPs, and wherein the second partition is configured to perform all other functions of the computing device.

18. The computing device of claim 1 , wherein authentication credentials for the first partition comprise a single finger biometric scan and wherein authentication credentials for the second partition comprise a multi-finger biometric scan.

19. A method comprising:

at a computing device comprising at least one processor, a communication interface, and memory:

configuring a plurality of device partitions;

sending, to a one time password (OTP) server and via an interface of a first partition of the plurality of device partitions, a login request;

receiving, from the OTP server, a notification indicating a decoy OTP, wherein the notification identifies characteristics of an interface, to be displayed based on the login request, to warn of the decoy OTP, and wherein the decoy OTP is selectively sent in response to a portion of login requests, wherein the characteristics comprise one or more of: an indication that a particular number of decoy OTPs will be sent in advance of a valid OTP, an indication that OTPs may be sent for only a portion of login attempts, or an indication of how to distinguish between valid and decoy OTPs;

receiving, at a second partition of the plurality of device partitions, an OTP;

accessing, by validating authentication credentials corresponding to the second partition of the plurality of device partitions, the OTP;

sending, to the OTP server, the OTP; and

accessing, upon receiving confirmation of validation of the OTP, services hosted by the OTP server.

20. One or more non-transitory computer-readable media storing instructions that, when executed by a computing device comprising at least one processor, a communication interface, and memory, cause the computing device to:

configure a plurality of device partitions;

send, to a one time password (OTP) server and via an interface of a first partition of the plurality of device partitions, a login request;

receive, from the OTP server, a notification indicating a decoy OTP, wherein the notification identifies characteristics of an interface, to be displayed based on the login request, to warn of the decoy OTP, and wherein the decoy OTP is selectively sent in response to a portion of login requests, wherein the characteristics comprise one or more of: an indication that a particular number of decoy OTPs will be sent in advance of a valid OTP, an indication that OTPs may be sent for only a portion of login attempts, or an indication of how to distinguish between valid and decoy OTPs;

receive, at a second partition of the plurality of device partitions, an OTP;

access, by validating authentication credentials corresponding to the second partition of the plurality of device partitions, the OTP;

send, to the OTP server, the OTP; and

access, upon receiving confirmation of validation of the OTP, services hosted by the OTP server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2023
From: MUKHERJEE, MAHARAJ; ALBERO, GEORGE
To: BANK OF AMERICA CORPORATION
Reel/Frame 063396/0258 →
Continuity (1)
Related Publication 20240356914A1 · Oct 24, 2024
References Cited (27)
US 6330653B1 · Murray et al. · 2001 [cited by applicant]
US 7516336B2 · Rothman et al. · 2009 [cited by applicant]
US 8572684B1 · Sama · 2013 [cited by examiner]
US 8939492B2 · Gaudig et al. · 2015 [cited by applicant]
US 9202035B1 · Manusov · 2015 [cited by examiner]
US 11240230B2 · Cho · 2022 [cited by examiner]
US 11429396B1 · Suryanarayana et al. · 2022 [cited by applicant]
US 20030039507A1 · Liu · 2003 [cited by applicant]
US 20070130453A1 · Lewites · 2007 [cited by applicant]
US 20110125977A1 · Karr et al. · 2011 [cited by applicant]
US 20110181499A1 · Ueno · 2011 [cited by applicant]
US 20120084866A1 · Stolfo · 2012 [cited by examiner]
US 20140075360A1 · Wang · 2014 [cited by applicant]
US 20140208091A1 · Koning et al. · 2014 [cited by applicant]
US 20150350251A1 · Brander et al. · 2015 [cited by applicant]
US 20180034822A1 · Mistry · 2018 [cited by examiner]
US 20190244370A1 · Jaroch · 2019 [cited by applicant]
US 20190286355A1 · Bhagwat et al. · 2019 [cited by applicant]
US 20220107743A1 · Yang et al. · 2022 [cited by applicant]
US 20220216990A1 · Mukherjee et al. · 2022 [cited by applicant]
US 20220309506A1 · Yassibas et al. · 2022 [cited by applicant]
US 20220360448A1 · Sahni · 2022 [cited by applicant]
US 20220407851A1 · Marzorati et al. · 2022 [cited by applicant]
US 20230029152A1 · Zaloum et al. · 2023 [cited by applicant]
US 20230093143A1 · Kaidi et al. · 2023 [cited by applicant]
WO WO2007091872A2 · 2007 [cited by examiner]
Zixuan Ding; Ding Wang; “HTOTP: Honey Time-Based One-Time Passwords”; IEEE Transactions on Information Forensics and Security; Year: Mar. 2025 | vol. 20 | Journal Article | Publisher: IEEE; pp. 4438-4453 (Year: 2025). [cited by examiner]