IP Library › Granted Patent US 12,530,688
Granted Patent B2
US 12,530,688 · App. 18/202,676 · Granted Jan 20, 2026

Methods and systems for leveraging transactions to dynamically authenticate a user

Inventors: Debashis Ghosh (Charlotte, NC); Randy Shuken (Westport, CT)
Assignee: MASTERCARD INTERNATIONAL INCOPORATED
G06Q20/4014G06F21/31G06F21/316H04L9/3271H04L63/0876G06F2221/2149H04L9/3213H04L9/3226H04L9/3273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,530,688
App. No.
18/202,676
Granted
Jan 20, 2026
Kind
B2
Abstract

A system and method for authenticating a candidate user accessing a host computing device as an authentic user is provided. The host computing device is in communication with an authenticating computing device. The method includes receiving, by the authenticating computing device, a request to authenticate the candidate user as an authentic user. The authentication request includes a user identifier. The method also includes retrieving, by the authenticating computing device, transaction data including payment transactions performed by the authentic user based on the user identifier. The method also includes generating, by the authenticating computing device, a challenge question and a correct answer based on the transaction data associated with the authentic user, and transmitting the challenge question for display on a candidate user computing device used by the candidate user.

Claims (41)

1 . A computing device comprising at least one processor coupled to a memory device and in communication with a first database and a second database, the at least one processor configured to:

receive, from a user computing device associated with a candidate user, a request to authenticate the candidate user as an authentic user for accessing secure data stored in the second database by the candidate user, the request including device data for identifying the user computing device used in a previous interaction;

access, using the device data, user data of the authentic user stored in the first database, the user data including data known to the authentic user;

generate, before receiving the request to authenticate the candidate user, a challenge question based on the user data stored in the first database and a predetermined level of security associated with accessing the secure data stored in the second database, wherein the challenge question and at least a portion of the user data are associated with at least one transaction of the authentic user that was received during a predetermined period of time;

generate, after receiving the request to authenticate the candidate user and based on the predetermined level of security, a correct answer to the challenge question;

transmit the challenge question to the user computing device;

cause to display on the user computing device the challenge question;

receive, from the user computing device, an answer to the challenge question;

compare the received answer to the generated correct answer; and

in response to the received answer matching at least one portion of the generated correct answer, authenticate the candidate user as the authentic user to enable access to the candidate user to the data stored in the second database.

2 . The computing device of claim 1 , wherein the challenge question includes a plurality of images, and wherein one of the plurality of images includes a correct answer to the challenge question.

3 . The computing device of claim 1 , wherein the second database is associated with a host computing device, wherein the first database is associated with an authenticating computing device, and wherein the host computing device and the authenticating computing device are different and separate computing devices.

4 . The computing device of claim 1 , wherein the challenge question includes a plurality of answers, and wherein one of the plurality of answers is a correct answer that matches the at least one portion of the user data stored in the first database.

5 . A computer-implemented method using a computing device including at least one processor coupled to a memory device and in communication with a first database and a second database, the method comprising:

receiving, from a user computing device associated with a candidate user, a request to authenticate the candidate user as an authentic user for accessing secure data stored in the second database by the candidate user, the request including device data for identifying the user computing device used in a previous interaction;

accessing, using the device data, user data of the authentic user stored in the first database, the user data including data known to the authentic user;

generating, before receiving the request to authenticate the candidate user, a challenge question based on the user data stored in the first database and a predetermined level of security associated with accessing the secure data stored in the second database, wherein the challenge question and at least a portion of the user data are associated with at least one transaction of the authentic user that was received during a predetermined period of time;

generating, after receiving the request to authenticate the candidate user and based on the predetermined level of security, a correct answer to the challenge question;

transmitting the challenge question to the user computing device a;

causing to display on the user computing device the challenge question;

receiving, from the user computing device, an answer to the challenge question;

comparing the received answer to the generated correct answer; and

in response to the received answer matching at least one portion of the generated correct answer, authenticating the candidate user as the authentic user to enable access to the candidate user to the data stored in the second database.

6 . The method of claim 5 , wherein the challenge question includes a plurality of images, and wherein one of the plurality of images includes a correct answer to the challenge question.

7 . The method of claim 5 , wherein the second database is associated with a host computing device, wherein the first database is associated with an authenticating computing device, and wherein the host computing device and the authenticating computing device are different and separate computing devices.

8 . The method of claim 5 , wherein the challenge question includes a plurality of answers, and wherein one of the plurality of answers is a correct answer that matches the at least one portion of the user data stored in the first database.

9 . At least one non-transitory computer-readable medium having computer-executable instructions embodied thereon, wherein when executed by at least one processor of a computing device in communication with a first database and a second database, the computer-executable instructions cause the at least one processor to:

receive, from a user computing device associated with a candidate user, a request to authenticate the candidate user as an authentic user for accessing secure data stored in the second database by the candidate user, the request including device data for identifying the user computing device used in a previous interaction;

access, using the device data, user data of the authentic user stored in the first database, the user data including data known to the authentic user;

generate, before receiving the request to authenticate the candidate user, a challenge question based on the user data stored in the first database and a predetermined level of security associated with accessing the secure data stored in the second database, wherein the challenge question and at least a portion of the user data are associated with at least one transaction of the authentic user that was received during a predetermined period of time;

generate after receiving the request to authenticate the candidate user and based on the predetermined level of security, a correct answer to the challenge question;

transmit the challenge question to the user computing device;

cause to display on the user computing device the challenge question;

receive, from the user computing device, an answer to the challenge question;

compare the received answer to the generated correct answer; and

in response to the received answer matching the generated correct answer, authenticate the candidate user as the authentic user to enable access to the candidate user to the data stored in the second database.

10 . The non-transitory computer-readable medium of claim 9 , wherein the challenge question includes a plurality of images, and wherein one of the plurality of images includes a correct answer to the challenge question.

11 . The non-transitory computer-readable medium of claim 9 , wherein the second database is associated with a host computing device, wherein the first database is associated with an authenticating computing device, and wherein the host computing device and the authenticating computing device are different and separate computing devices.

12 . The non-transitory computer-readable medium of claim 9 , wherein the challenge question includes a plurality of answers, and wherein one of the plurality of answers is a correct answer that matches the at least one portion of the user data stored in the first database.

13 . The computing device of claim 1 , wherein the device data includes at least one of a media access control (MAC) address or an Internet protocol (IP) address of the user computing device.

14 . The computing device of claim 1 , wherein the previous interaction includes an exchange of data between the user computing device and the computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2023
From: GHOSH, DEBASHIS; SHUKEN, RANDY
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 063776/0409 →
Continuity (6)
Continuation 17354833 · Jun 22, 2021
Continuation 16518737 · Jul 22, 2019
Continuation 15676739 · Aug 14, 2017
Continuation 15243349 · Aug 22, 2016
Continuation 14100789 · Dec 9, 2013
Related Publication 20230298024A1 · Sep 21, 2023
References Cited (128)
US 932915A · Shoup · 1909 [cited by applicant]
US 4528442A · Endo · 1985 [cited by applicant]
US 5177342A · Adams · 1993 [cited by applicant]
US 5708422A · Blonder · 1998 [cited by applicant]
US 5774525A · Kanevsky · 1998 [cited by applicant]
US 5946646A · Schena · 1999 [cited by applicant]
US 6219793B1 · Li · 2001 [cited by applicant]
US 6263447B1 · French · 2001 [cited by applicant]
US 6957900B2 · Hirano · 2005 [cited by applicant]
US 7051002B2 · Keresman, III · 2006 [cited by applicant]
US 7343351B1 · Bishop · 2008 [cited by examiner]
US 7620600B2 · Patil · 2009 [cited by applicant]
US 7707120B2 · Dominguez · 2010 [cited by applicant]
US 7739162B1 · Pettay · 2010 [cited by applicant]
US 7979894B2 · Royyuru · 2011 [cited by examiner]
US 8016185B2 · Modi · 2011 [cited by applicant]
US 8136148B1 · Chayanam · 2012 [cited by applicant]
US 8156246B2 · Short · 2012 [cited by applicant]
US 8156543B2 · Wentker · 2012 [cited by examiner]
US 8239677B2 · Colson · 2012 [cited by applicant]
US 8424061B2 · Rosenoer · 2013 [cited by applicant]
US 8509431B2 · Schmidt · 2013 [cited by examiner]
US 8510795B1 · Gargi · 2013 [cited by applicant]
US 8533118B2 · Weller · 2013 [cited by applicant]
US 8572391B2 · Golan · 2013 [cited by applicant]
US 8732089B1 · Fang · 2014 [cited by examiner]
US 8793760B2 · Raper · 2014 [cited by applicant]
US 8806600B2 · Taratine · 2014 [cited by examiner]
US 8851370B2 · DiMuro · 2014 [cited by examiner]
US 8881227B2 · Rajagopal · 2014 [cited by applicant]
US 8898762B2 · Kang · 2014 [cited by applicant]
US 8904506B1 · Canavor · 2014 [cited by examiner]
US 8957900B2 · Lau · 2015 [cited by applicant]
US 9323915B2 · Perez · 2016 [cited by examiner]
US 9424410B2 · Ghosh · 2016 [cited by examiner]
US 9734500B2 · Ghosh · 2017 [cited by applicant]
US 10373164B2 · Ghosh · 2019 [cited by applicant]
US 11068891B2 · Ghosh · 2021 [cited by applicant]
US 20020128977A1 · Nambiar · 2002 [cited by applicant]
US 20030061566A1 · Rubstein · 2003 [cited by applicant]
US 20030154406A1 · Honarvar · 2003 [cited by applicant]
US 20050097320A1 · Golan · 2005 [cited by applicant]
US 20060156385A1 · Chiviendacz · 2006 [cited by examiner]
US 20060272007A1 · Sweeley · 2006 [cited by applicant]
US 20070094717A1 · Srinivasan · 2007 [cited by applicant]
US 20070192164A1 · Nong · 2007 [cited by applicant]
US 20070250920A1 · Lindsay · 2007 [cited by examiner]
US 20080013972A1 · Matsuda · 2008 [cited by applicant]
US 20080040276A1 · Hammad · 2008 [cited by examiner]
US 20080066165A1 · Rosenoer · 2008 [cited by examiner]
US 20080098464A1 · Mizrah · 2008 [cited by examiner]
US 20080103972A1 · Lanc · 2008 [cited by applicant]
US 20080120507A1 · Shakkarwar · 2008 [cited by applicant]
US 20080134317A1 · Boss · 2008 [cited by applicant]
US 20080168270A1 · Kulakowski · 2008 [cited by examiner]
US 20080275819A1 · Rifai · 2008 [cited by applicant]
US 20080275916A1 · Bohannon · 2008 [cited by examiner]
US 20080319896A1 · Carlson · 2008 [cited by examiner]
US 20090276263A1 · Deb · 2009 [cited by applicant]
US 20100030839A1 · Ceragioli · 2010 [cited by applicant]
US 20100063895A1 · Dominguez · 2010 [cited by applicant]
US 20100070759A1 · Leon Cobos · 2010 [cited by examiner]
US 20100114776A1 · Weller · 2010 [cited by examiner]
US 20100161470A1 · Wiesman · 2010 [cited by applicant]
US 20110026716A1 · Tang · 2011 [cited by applicant]
US 20110029902A1 · Bailey · 2011 [cited by examiner]
US 20110078778A1 · Gabriel · 2011 [cited by examiner]
US 20110088087A1 · Kalbratt · 2011 [cited by examiner]
US 20110113237A1 · Hird · 2011 [cited by applicant]
US 20110153461A1 · Royyuru · 2011 [cited by examiner]
US 20110197070A1 · Mizrah · 2011 [cited by examiner]
US 20110207434A1 · Rozhkov · 2011 [cited by applicant]
US 20110231225A1 · Winters · 2011 [cited by examiner]
US 20110239281A1 · Sovio · 2011 [cited by applicant]
US 20110247045A1 · Rajagopal · 2011 [cited by applicant]
US 20120018506A1 · Hammad · 2012 [cited by examiner]
US 20120066130A1 · Dominguez · 2012 [cited by applicant]
US 20120066749A1 · Taugbol · 2012 [cited by examiner]
US 20120072975A1 · Labrador · 2012 [cited by examiner]
US 20120116976A1 · Hammad · 2012 [cited by examiner]
US 20120151567A1 · Chayanam · 2012 [cited by applicant]
US 20120210409A1 · Lin · 2012 [cited by examiner]
US 20120214442A1 · Crawford · 2012 [cited by examiner]
US 20120216260A1 · Crawford · 2012 [cited by examiner]
US 20120254940A1 · Raper · 2012 [cited by examiner]
US 20120311151A1 · Paulsen · 2012 [cited by applicant]
US 20130036457A1 · Vandemar · 2013 [cited by applicant]
US 20130046645A1 · Grigg · 2013 [cited by applicant]
US 20130073463A1 · Dimmick · 2013 [cited by applicant]
US 20130081119A1 · Sampas · 2013 [cited by examiner]
US 20130104197A1 · Nandakumar · 2013 [cited by examiner]
US 20130110658A1 · Lyman · 2013 [cited by examiner]
US 20130160098A1 · Carlson · 2013 [cited by examiner]
US 20130173484A1 · Wesby · 2013 [cited by examiner]
US 20130185207A1 · Lyons · 2013 [cited by examiner]
US 20130218765A1 · Hammad · 2013 [cited by examiner]
US 20130275308A1 · Paraskeva · 2013 [cited by examiner]
US 20130318580A1 · Gudlavenkatasiva · 2013 [cited by applicant]
US 20140137203A1 · Castro · 2014 [cited by examiner]
US 20140171039A1 · Bjontegard · 2014 [cited by applicant]
US 20140189808A1 · Mahaffey · 2014 [cited by examiner]
US 20140282974A1 · Maher · 2014 [cited by examiner]
US 20140310183A1 · Weber · 2014 [cited by applicant]
US 20140316984A1 · Schwartz · 2014 [cited by examiner]
US 20140316989A1 · Raper · 2014 [cited by applicant]
US 20140337089A1 · Tavares · 2014 [cited by examiner]
US 20140337090A1 · Tavares · 2014 [cited by examiner]
US 20140358778A1 · Banerjee · 2014 [cited by applicant]
US 20140372252A1 · Raney · 2014 [cited by examiner]
US 20150106216A1 · Kenderov · 2015 [cited by examiner]
US 20150120549A1 · Khalid · 2015 [cited by examiner]
US 20150161366A1 · Ghosh · 2015 [cited by applicant]
US 20150161375A1 · Ghosh · 2015 [cited by applicant]
US 20150220713A1 · Beenau · 2015 [cited by examiner]
US 20150262208A1 · Bjontegard · 2015 [cited by applicant]
US 20160262017A1 · Lavee · 2016 [cited by applicant]
US 20170126690A1 · Ogawa · 2017 [cited by applicant]
US 20170372316A1 · Ghosh · 2017 [cited by applicant]
US 20230298024A1 · Ghosh · 2023 [cited by examiner]
WO WO2024215589A1 · 2024 [cited by examiner]
Angeli et al., VIP: a visual approach to user authentication, .COPYRGT. 2002, ACM, 8 pages. [cited by applicant]
Datta et al., Imagination: A Robust Image-based CAPTCHA Generation System, .COPYRGT. 2005, ACM, 4 pages. [cited by applicant]
Filyanov et al., Uni-directional Trust Path: Transaction Confirmation on Just One Device, .COPYRGT. 2011, IEEE, 12 pages. [cited by applicant]
Khu-smith el al., Using GSM to Enhance E-Commerce Security, .COPYRGT. 2002, ACM, 7 pages. [cited by applicant]
Pasupathinathan et al., Formal Analysis of Card-based Payment System in Mobile devices, .COPYRGT. 2006, AISW-NetSec, 8 pages. [cited by applicant]
Perakslis et al., Social Acceptance of RFID as a Biometric Security Method, .COPYRGT. 2005, IEEE, 10 pages. [cited by applicant]
Schloglhofer et al., Secure and Usable Authentication on Mobile Devices, .COPYRGT. 2012, ACM, 6 pages. [cited by applicant]
Verma, icAuth: Image Color Based Authentication System, .COPYRGT. 2012, ACM, 2 pages. [cited by applicant]