IP Library Granted Patent US 12,386,940
Granted Patent B2
US 12,386,940 · App. 18/214,016 · Granted Aug 12, 2025

Two-factor authentication integrating dynamic QR codes

Inventors: Jennifer Sanctis (Charlotte, NC); Taylor Farris (Hoboken, NJ); Vishwas Korde (Matthews, NC)
Assignee: Bank of America Corporation
G06F21/36G06F21/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,940
App. No.
18/214,016
Granted
Aug 12, 2025
Kind
B2
Abstract

A method for authenticating a user into a session on an entity application running on a computing device is provided. The method may include using a mobile device of the user as an authenticator. The method may include capturing by the mobile device, a dynamic quick response (“QR”) code displayed on the computing device. The method may include transmitting the dynamic QR code, pre-authorized user credentials and a facial image of the user captured within a pre-determined time to a central server for authentication. The transmitting may be for verifying the user of the computing device being the user of the mobile device. In response to the verifying, via the central server, the dynamic QR code, the pre-authorized user credentials and the facial image, authenticating the user into the session on the entity application on the computing device.

Claims (57)

1. A method for authenticating into a secure session on an entity application running on a computing device, the authenticating using a mobile device of a user as an authenticator, the computing device and the mobile device in electronic communication with a central server, the method comprising:

generating, via the central server, a dynamic quick response (“QR”) code in response to a request to authenticate user access to the secure session, the dynamic QR code including a graphical display that, when parsed by a QR code reader, identifies a short URL;

displaying the dynamic QR code on a user interface (“UI”) of the computing device;

capturing the dynamic QR code, by the mobile device, within a time period immediately following the generating of the dynamic QR code;

in response to the capturing, parsing the dynamic QR code;

following the parsing, redirecting a web browser of the mobile device to a first website, the first website, when accessed, instructing the central server to authenticate the user to the secure session;

transmitting the instruction to the central server; retrieving, from secure storage on the mobile device: pre-authorized user credentials for authentication of the user into an entity application running on the mobile device; and

a facial image of the user captured within a pre-determined time to the capturing of the dynamic QR code;

transmitting the dynamic QR code, the pre-authorized user credentials and the facial image to the central server, the transmitting for verifying the user of the computing device being the user of the mobile device; and

in response to the verifying of the pre-authorized user credentials and the facial image, and in response to the instruction, authenticating, via the central server, the computing device into the secure session.

2. The method of claim 1 wherein the dynamic QR code, when captured after the time period has lapsed, directs the mobile device to a second website, the second website, when accessed, instructs the central server to deny the request to authenticate the user to the secure session.

3. The method of claim 1 wherein the pre-authorized user credentials are authorized at a first initiation session of the user into the entity application on the mobile device and further stored for authenticating the user into each session on the entity application of the mobile device.

4. The method of claim 3 further comprising, prior to authenticating the user into a session:

capturing the facial image of the user of the mobile device;

tagging the facial image with a timestamp of the time of the capturing; and

confirming that the facial image matches a stored facial image.

5. The method of claim 4 further comprising, in response to the confirming, authenticating the user into the session on the mobile device.

6. The method of claim 4 wherein the verifying by the central server further comprises scanning the timestamp of the facial image to verify the timestamp being within the pre-determined time to the capturing of the dynamic QR code.

7. The method of claim 6 wherein, when the timestamp is outside the pre-determined time, re-capturing by the mobile device the facial image of the user and verifying by the central server that the facial image matches the stored facial image.

8. The method of claim 7 further comprising, when the facial image does not match the stored facial image, denying the user access to the secure session.

9. The method of claim 1 wherein the computing device is a desktop computer.

10. A system for authenticating a user into a secure session on an entity application running on a computing device, the system comprising:

a first entity application running on a first computing device, the first entity application configured to display a dynamic quick response (“QR”) code on a user interface (“UI”) of the first computing device for initiating the session;

a second entity application running on a second computing device, a user of the second computing device being pre-authenticated into a session within the second entity application, a pre-authenticating comprising:

capturing a facial image of the user of the second computing device;

tagging a timestamp to the facial image of a time of the capturing of the facial image; and

confirming that the facial image matches a stored facial image within an account profile of the user of the second computing device;

a central server for operating a functionality of the first entity application and the second entity application;

the second computing device configured to:

capture the dynamic QR code displayed on the first computing device;

store the dynamic QR code at the second computing device; and

transmit the dynamic QR code, pre-authorized user credentials stored on the second computing device and the facial image of the user to the central server for authenticating, the authenticating for enabling initiating the session within the first entity application on the first computing device; and

the central server configured to:

receive the dynamic QR code, the pre-authorized user credentials and the facial image;

verify an authenticity of the pre-authorized user credentials and the facial image;

verify that the timestamp is within a threshold range of time of the capturing of the dynamic QR code;

in response to a verification of the authenticity of the pre-authorized user credentials, the facial image and of the timestamp, confirm that the user of the first computing device is the user of the second computing device; and

initiate the secure session on the first computing device.

11. The system of claim 10 wherein the facial image of the user is captured within a pre-determined time to the capturing of the dynamic QR code.

12. The system of claim 10 further comprising a one-time password (“OTP”) application running on a third computing device, the OTP application being operated by the central server.

13. The system of claim 12 wherein the second computing device is in electronic communication with the third computing device.

14. The system of claim 13 wherein when the second computing device captures the dynamic QR code, the second computing device is further configured to transmit an electronic communication to the third computing device, the electronic communication comprising a request for a generation, by the OTP application, an OTP.

15. The system of claim 14 wherein the third computing device is configured to, in response to a receipt of the request, generate, by the OTP application, the OTP and transmit it to the second computing device.

16. The system of claim 14 wherein the OTP is displayed on a face of the third computing device and the second computing device is configured to trigger an input of the OTP.

17. The system of claim 15 wherein, following transmission of the OTP from the third computing device to the second computing device, the second computing device is further configured to transmit the OTP together with the dynamic QR code, the pre-authorized user credentials and the facial image to the central server for verification.

18. The system of claim 17 wherein the first computing device is a desktop computer, the second computing device is a mobile device and the third computing device is a smartwatch.

19. A method for authenticating a user into a secure session on an entity application running on a first computing device, the authenticating using a second computing device of the user as an authenticator, the method comprising:

capturing, by the second computing device, a dynamic quick response (“QR”) code displayed on a first computing device, the dynamic QR code being displayed within a web browser associated with the entity application;

following the capturing, transmitting an electronic communication to a third computing device comprising a request for a generation of a one-time password (“OTP”) by an OTP application running on the third computing device;

in response to a receipt of the request at the third computing device, generating, by the OTP application, the OTP;

transmitting the OTP to the second computing device;

retrieving, via the mobile device, from secure storage on the second computing device:

pre-authorized user credentials for authentication of the user into an entity application running on the second computing device; and

a facial image of the user captured within a pre-determined time to the capturing of the dynamic QR code;

transmitting the dynamic QR code, the pre-authorized user credentials, the facial image and the OTP to a central server, the transmitting for verifying the user of the first computing device being the user of the second computing device and the user of the third computing device; and

in response to the verifying the dynamic QR code, the pre-authorized user credentials, the facial image and the OTP, authenticating the first computing device into the secure session.

20. The method of claim 19 wherein the first computing device is a desktop computer, the second computing device is a mobile device and the third computing device is a smartwatch.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2023
From: SANCTIS, JENNIFER; FARRIS, TAYLOR; KORDE, VISHWAS
To: BANK OF AMERICA CORPORATION
Reel/Frame 064056/0936 →
Continuity (1)
Related Publication 20240427871A1 · Dec 26, 2024
References Cited (78)
US 8281375B2 · von Krogh · 2012 [cited by applicant]
US 8572684B1 · Sama · 2013 [cited by applicant]
US 9106645B1 · Vadlamani · 2015 [cited by applicant]
US 9124433B2 · Marien et al. · 2015 [cited by applicant]
US 9203824B1 · Nunn et al. · 2015 [cited by applicant]
US 9213820B2 · Farraro · 2015 [cited by applicant]
US 9262759B2 · Hanson et al. · 2016 [cited by applicant]
US 9294476B1 · Lurey et al. · 2016 [cited by applicant]
US 9384481B2 · Hanson et al. · 2016 [cited by applicant]
US 9589123B2 · Farraro · 2017 [cited by applicant]
US 9646300B1 · Zhou et al. · 2017 [cited by applicant]
US 9673975B1 · Machani · 2017 [cited by applicant]
US 9768963B2 · Chu et al. · 2017 [cited by applicant]
US 9811818B1 · Xing · 2017 [cited by applicant]
US 9830589B2 · Xing · 2017 [cited by applicant]
US 9832019B2 · Choi · 2017 [cited by applicant]
US 9871785B1 · Triandopoulos et al. · 2018 [cited by applicant]
US 9906524B2 · Shibata et al. · 2018 [cited by applicant]
US 9930034B2 · Ekambaram et al. · 2018 [cited by applicant]
US 10122719B1 · Vltavsky et al. · 2018 [cited by applicant]
US 10158489B2 · Shastri · 2018 [cited by examiner]
US 10587613B2 · Ledesma · 2020 [cited by applicant]
US 11296874B2 · Harris et al. · 2022 [cited by applicant]
US 20060021003A1 · Fisher et al. · 2006 [cited by applicant]
US 20090097459A1 · Jendbro et al. · 2009 [cited by applicant]
US 20090300738A1 · Dewe et al. · 2009 [cited by applicant]
US 20110197266A1 · Chu et al. · 2011 [cited by applicant]
US 20130212286A1 · Krishnakumar et al. · 2013 [cited by applicant]
US 20130219479A1 · DeSoto et al. · 2013 [cited by applicant]
US 20130283397A1 · Griffin · 2013 [cited by applicant]
US 20140129733A1 · Klais · 2014 [cited by applicant]
US 20140173695A1 · Valdivia · 2014 [cited by applicant]
US 20140333415A1 · Kursun · 2014 [cited by examiner]
US 20140351911A1 · Yang et al. · 2014 [cited by applicant]
US 20150041530A1 · Burkhart et al. · 2015 [cited by applicant]
US 20150088760A1 · Meurs · 2015 [cited by applicant]
US 20150234891A1 · Liu · 2015 [cited by applicant]
US 20150261948A1 · Marra et al. · 2015 [cited by applicant]
US 20160057123A1 · Jiang et al. · 2016 [cited by applicant]
US 20160162873A1 · Zhou et al. · 2016 [cited by applicant]
US 20160255161A1 · Lim et al. · 2016 [cited by applicant]
US 20160294817A1 · Tan et al. · 2016 [cited by applicant]
US 20160337346A1 · Momchilov et al. · 2016 [cited by applicant]
US 20170032370A1 · Beltramino et al. · 2017 [cited by applicant]
US 20170083909A1 · Mork et al. · 2017 [cited by applicant]
US 20170249628A1 · Douglas et al. · 2017 [cited by applicant]
US 20170346851A1 · Drake · 2017 [cited by applicant]
US 20180359635A1 · Lerner · 2018 [cited by applicant]
US 20190164167A1 · Embree · 2019 [cited by applicant]
US 20190174304A1 · Tunnell et al. · 2019 [cited by applicant]
US 20190303556A1 · Jain et al. · 2019 [cited by applicant]
US 20200068029A1 · Lim et al. · 2020 [cited by applicant]
US 20200074070A1 · Boodaei · 2020 [cited by applicant]
US 20200092272A1 · Eisen et al. · 2020 [cited by applicant]
US 20200092287A1 · Cano et al. · 2020 [cited by applicant]
US 20200128594A1 · Shantharam et al. · 2020 [cited by applicant]
US 20200143375A1 · Gurunathan et al. · 2020 [cited by applicant]
US 20200233949A1 · Xia et al. · 2020 [cited by applicant]
US 20200351264A1 · Pellizzer et al. · 2020 [cited by applicant]
US 20200404019A1 · Drake · 2020 [cited by applicant]
US 20210073359A1 · Boodaei et al. · 2021 [cited by applicant]
US 20220004617A1 · Irwin, III · 2022 [cited by examiner]
US 20220086134A1 · Xie · 2022 [cited by examiner]
US 20220095006A1 · Seed et al. · 2022 [cited by applicant]
US 20220150237A1 · Canfield et al. · 2022 [cited by applicant]
US 20230169381A1 · Subramanian · 2023 [cited by applicant]
US 20230284013A1 · Schmidt · 2023 [cited by applicant]
US 20230419067A1 · Wu et al. · 2023 [cited by applicant]
CN 109547196 · 2019 [cited by applicant]
WO WO2017039354 · 2017 [cited by applicant]
Alex Perala, “Apple Exploring Face ID for Apple Watch 4,” https://mobileidworld.com/face-id-for-apple-watch-4-904233/, Mobile ID World, Apr. 24, 2018. [cited by applicant]
Eric Weiss, “Apple Patent Could Bring Face ID to Apple Watch,” https://mobileidworld.com/biometrics-news-apple-patent-could-bring-face-id-apple-watch-111906/, Mobile ID World, Nov. 19, 2019. [cited by applicant]
“Apple Patent Points to Face ID coming to Apple Watch along with Band Sensors to Analyze Sports Performance and More,” https://www.patentlyapple.com/patentlyapple/2018/03/apple-patent-points-to-face-id-coming-to-apple-w… [cited by applicant]
Benjamin Mayo, “Rumor: Apple Developing Touch ID fingertip Biometrics for Apple Watch, Series 2 will not Support WatchOS 7,” https://9to5mac.com/2020/03/27/rumor-apple-developing-touch-id-fingerprint-biometrics-for-appl… [cited by applicant]
E. Grosse et al., “Authentication at Scale,” in IEEE Security & Privacy, vol. 11, No. 1, pp. 15-22, Jan.-Feb. 2013. [cited by applicant]
F. Aloul et al., “Two Factor Authentication Using Mobile Phones,” 2009 IEEE/ACS International Conference on Computer Systems and Applications, 2009, pp. 641-644. [cited by applicant]
Shah, Syed W., and Salil S. Kanhere, “Recent Trends in User Authentication—a Survey,” IEEE Access 7 (2019): 112505-112519 (Year: 2019). [cited by applicant]
“How to Scan a QR Code in a Photo Google Lens,” https://seniortechclub.com/nuggets/how-to-scan-a-qr-code-in-a-photo-using-google-lens/, pp. 1-5, 2020. [cited by applicant]