IP Library › Granted Patent US 12,248,935
Granted Patent B2
US 12,248,935 · App. 18/393,763 · Granted Mar 11, 2025

Systems and methods for conducting remote user authentication

Inventor: Abel Fletcher (Prosper, TX)
Assignee: CAPITAL ONE SERVICES, LLC
G06Q20/401G06F21/35
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,935
App. No.
18/393,763
Granted
Mar 11, 2025
Kind
B2
Abstract

Disclosed embodiments may include a system that may receive, from a user device associated with a user, authentication rule(s), each authentication rule associated with respective merchant(s) and comprising respective required authentication factor(s) for completing a transaction with the respective merchant(s). The system may identify a user has navigated to a merchant webpage and may determine at least one rule of the authentication rule(s) associated with the merchant. The system may identify first required authentication factor(s) corresponding to the at least one rule, and may cause the user device to display, via a GUI, the first required authentication factor(s). The system may receive, via the user device, authentication information associated with the user. The system may determine whether the authentication information satisfies the first required authentication factor(s). Responsive to making that determination, the system may enable the user to complete a transaction via the merchant webpage.

Claims (56)

1. A system for user authentication comprising:

one or more processors; and

a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to:

determine, via a web browser extension running on a first user device, that a first user has navigated to a webpage associated with a first merchant;

receive, via a graphical user interface (GUI) of the first user device, a request to use a virtual card number associated with the first merchant to complete a first transaction;

determine whether at least one rule of one or more authentication rules is associated with the first merchant, wherein the at least one rule corresponds to a required level of authentication based on a merchant type associated with the first merchant, and wherein the one or more authentication rules comprise one or more respective required authentication factors;

responsive to determining the at least one rule of the one or more authentication rules is associated with the first merchant, identify one or more first required authentication factors corresponding to the at least one rule, wherein the required level of authentication comprises one or more of a type and a total number of the one or more first required authentication factors, and wherein the type and the total number of the one or more first required authentication factors are stored along with the at least one rule;

receive, via the first user device, authentication information associated with the first user;

determine whether the authentication information satisfies the one or more first required authentication factors; and

responsive to determining the authentication information satisfies the one or more first required authentication factors:

direct the first user to the web browser extension to generate the virtual card number, wherein the web browser extension is external to the first merchant and generates the virtual card number;

modify the GUI of the first user device such that a previously greyed out user input object is enabled to receive user input; and

enable the first user to complete the first transaction by entering the generated virtual card number into the enabled user input object.

2. The system of claim 1 , wherein the instructions are further configured to cause the system to:

transmit a notification to a second user device associated with the first user, the notification providing the one or more first required authentication factors.

3. The system of claim 2 , wherein the first user device is a computer and the second user device is a mobile phone.

4. The system of claim 1 , wherein the one or more respective required authentication factors are customizable by the first user.

5. The system of claim 1 , wherein a total number of the one or more respective required authentication factors for completing the first transaction is based on a total dollar amount of the first transaction.

6. A system for user authentication comprising:

one or more processors; and

a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to:

determine, via a web browser extension running on a first user device, that a first user has navigated to a webpage associated with a first merchant, wherein the web browser extension is external to the first merchant;

determine whether at least one rule of one or more authentication rules is associated with the first merchant, wherein the at least one rule corresponds to a required level of authentication based on a merchant type associated with the first merchant, and wherein the one or more authentication rules comprise one or more respective required authentication factors;

responsive to determining the at least one rule of the one or more authentication rules is associated with the first merchant,

identify one or more first required authentication factors corresponding to the at least one rule, wherein the required level of authentication comprises one or more of a type and a total number of the one or more first required authentication factors, and wherein the type and the total number of the one or more first required authentication factors are stored along with the at least one rule;

receive, via the first user device, authentication information associated with the first user;

determine whether the authentication information satisfies the one or more first required authentication factors; and

responsive to determining the authentication information satisfies the first required authentication factors:

modify a graphical user interface (GUI) of the first user device such that a previously greyed out user input object is enabled to receive user input;

direct the first user to the web browser extension to generate a first virtual card number, wherein the web browser extension generates the first virtual card number; and

enable the first user to complete a first transaction by entering the first virtual card number into the enabled user input object.

7. The system of claim 6 , wherein enabling the first user to complete the first transaction via the webpage comprises enabling the first user to generate a new virtual card number associated with the first merchant.

8. The system of claim 6 , wherein enabling the first user to complete the first transaction via the webpage comprises enabling the first user to utilize a virtual card number associated with the first merchant.

9. The system of claim 6 , wherein the instructions are further configured to cause the system to:

transmit a notification to a second user device associated with the first user, the notification providing the one or more first required authentication factors.

10. The system of claim 9 , wherein the first user device is a computer and the second user device is a mobile phone.

11. The system of claim 6 , wherein the one or more respective required authentication factors are customizable by the first user.

12. The system of claim 6 , wherein a total number of the one or more respective required authentication factors for completing the first transaction is based on a total dollar amount of the first transaction.

13. A system for user authentication comprising:

one or more processors; and

a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to:

determine, via a web browser extension running on a first user device, that a first user has navigated to a webpage associated with a first merchant, wherein the web browser extension is external to the first merchant;

determine whether at least one rule of one or more stored authentication rules is associated with the first merchant, wherein the at least one rule corresponds to a required level of authentication based on a merchant type associated with the first merchant, and wherein the one or more stored authentication rules comprise one or more respective required authentication factors;

responsive to determining the at least one rule of the one or more stored authentication rules is associated with the first merchant, identify one or more first required authentication factors corresponding to the at least one rule;

receive, via the first user device, one or more first user inputs corresponding to the one or more first required authentication factors, wherein the required level of authentication comprises one or more of a type and a total number of the one or more first required authentication factors, and wherein the type and the total number of the one or more first required authentication factors are stored along with the at least one rule;

determine whether the one or more first user inputs satisfy the one or more first required authentication factors; and

responsive to determining the one or more first user inputs satisfy the one or more first required authentication factors:

modify a graphical user interface (GUI) of the first user device such that a previously disabled user input object is enabled to receive user input;

direct the first user to the web browser extension to generate a virtual card number, wherein the web browser extension generates the virtual card number; and

enable the first user to complete a first transaction via the webpage by entering the generated virtual card number into the enabled user input object.

14. The system of claim 13 , wherein the one or more respective required authentication factors comprise one or more of a personal identification number (PIN), a physical token, a facial recognition, a thumbprint image, a retina scan, or combinations thereof.

15. The system of claim 13 , wherein enabling the first user to complete the first transaction via the webpage comprises enabling the first user to generate a new virtual card number associated with the first merchant.

16. The system of claim 13 , wherein enabling the first user to complete the first transaction via the webpage comprises enabling the first user to utilize a virtual card number associated with the first merchant.

17. The system of claim 13 , wherein the instructions are further configured to cause the system to:

transmit a notification to a second user device associated with the first user, the notification providing the one or more first required authentication factors.

18. The system of claim 13 , wherein a total number of the one or more respective required authentication factors for completing the first transaction is based on a total dollar amount of the first transaction.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2023
From: FLETCHER, ABEL
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 065938/0671 →
Continuity (2)
Continuation 17494737 · Oct 5, 2021
Related Publication 20240202720A1 · Jun 20, 2024
References Cited (22)
US 9807610B2 · Rasheed et al. · 2017 [cited by applicant]
US 10296897B1 · Wu · 2019 [cited by examiner]
US 10313341B2 · Stoops et al. · 2019 [cited by applicant]
US 10681547B1 · Yang · 2020 [cited by applicant]
US 20110117999A1 · Anderson et al. · 2011 [cited by applicant]
US 20120179558A1 · Fischer · 2012 [cited by examiner]
US 20150127530A1 · Wick · 2015 [cited by examiner]
US 20180047018A1 · De Ganon · 2018 [cited by examiner]
US 20180375659A1 · Kozma et al. · 2018 [cited by applicant]
US 20200143375A1 · Gurunathan · 2020 [cited by examiner]
US 20200193443A1 · Piel · 2020 [cited by examiner]
US 20200288315A1 · Hanley et al. · 2020 [cited by applicant]
US 20210125262A1 · Corrieri et al. · 2021 [cited by applicant]
US 20210272115A1 · Muchang · 2021 [cited by examiner]
CN 110661800A · 2020 [cited by applicant]
SG 10202101039T · 2021 [cited by applicant]
“How can I make a browser extension payments systems?” Stack Overflow, dated Jun. 2021 https://stackoverflow.com/questions/64007559/how-can-i-make-a-browser-extension-payments-system (Year: 2021). [cited by examiner]
“Multifactor authentication methods, use cases and products” TechTarget, dated Jan. 2019 https://www.techtarget.com/searchsecurity/feature/The-fundamentals-of-MFA-Procuring-multifactor-authentication?Offer=abt_pubpro_AI… [cited by examiner]
“Why E-Commerce Retailers Need to Start Thinking About MFA,” Medium, dated Mar. 12, 2019 https://medium.com/bidipass/why-e-commerce-retailers-need-to-start-thinking-about-mfa-bd7cb34336e (Year: 2019). [cited by examiner]
Anonymous: “Multi-factor authentication—Wikipedia,” pp. 1-12, retrieved from URL: https://en.wikipedia.org/w/index.php?title=Multi-factor_authentication&oldid=1042568913 (Sep. 5, 2021). [cited by applicant]
Extended European Search Report in related EP Application No. EP22199415.5, mailed Feb. 28, 2023. [cited by applicant]
“How can I make a browser extension payments system?” Stack Overflow, dated Jun. 2021 https://stackoverflow.com/questions/64007559/how-can-i-make-a-browser-extension-payments-system (Year: 2021). [cited by applicant]