IP Library › Granted Patent US 12,301,560
Granted Patent B2
US 12,301,560 · App. 18/409,143 · Granted May 13, 2025

Multi-factor authentication using symbols

Inventor: Vanck Zhu (New York, NY)
Assignee: Capital One Services, LLC
H04L63/083G06F3/0486G06F21/36H04L63/0876H04L63/20H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,560
App. No.
18/409,143
Granted
May 13, 2025
Kind
B2
Abstract

In some implementations, a server device may receive, from a first device, a credential and a request to access a resource. The server device may transmit, to a second device associated with the credential, an image that includes a first symbol composed of a set of elements. The server device may receive, from the first device, information associated with a second symbol formed via user interaction with a user interface of the first device. The second symbol may be formed by dragging elements, presented via the user interface, to an area of the user interface in which the second symbol is to be formed, or drawing elements in the area of the user interface in which the second symbol is to be formed. The server device may grant or denying access to the resource based on the first symbol and the information associated with the second symbol.

Claims (53)

1. A system for authenticating a user for access to a network resource using multi-factor authentication, the system comprising:

memory; and

one or more processors, coupled to the memory, configured to:

transmit, to a user device associated with a request to access the network resource, an image, or a link to the image, wherein the image is composed of a set of visual elements that each have a particular visual attribute;

transmit, to a client device, information to cause the client device to present an interface indicating instructions to recreate the image by inputting one or more visual elements to form an input image of an authentication symbol with reference to the image presented to the user device, the input image being formed via input of a set of one or more visual elements via the interface; and

grant or deny access to the network resource based on comparing information indicative of the input image to authentication symbol information, wherein the authentication symbol information is associated with the authentication symbol.

2. The system of claim 1 , wherein the input image is formed using a drag and drop input mechanism.

3. The system of claim 1 , wherein the one or more processors are further configured to:

receive, from the client device, a login credential and the request to access the network resource, wherein transmitting the image, or the link to the image, is based on receiving the login credential and the request to access the network resource.

4. The system of claim 1 , wherein the one or more processors are further configured to:

receive position information that identifies respective positions of the set of one or more visual elements within the interface,

wherein the one or more processors, when granting or denying access to the network resource, are configured to:

determine whether the set of one or more visual elements match the set of visual elements from which the image is composed; and

determine, based on the position information, whether the respective positions of the set of one or more visual elements satisfy a threshold with respect to positions of the set of visual elements from which the image is composed.

5. The system of claim 1 , wherein the one or more processors, when granting or denying access to the network resource, are configured to:

compare the input image and the image;

calculate a similarity score based on comparing the input image and the image; and

determine whether the similarity score satisfies a threshold.

6. The system of claim 1 , wherein a plurality of visual elements, identified in the information transmitted to the client device, are determined based on the set of visual elements from which the image is composed.

7. The system of claim 1 , wherein a plurality of visual elements, identified in the information transmitted to the client device, include one or more visual elements that are not components of the image.

8. The system of claim 7 , further comprising identifying the one or more visual elements that are not components of the image based on the set of visual elements from which the image is composed and using a data structure that stores information that identifies associations between visual elements.

9. A method for multi-factor authentication, comprising:

transmitting, by a server device and to a first device associated with a request to access a resource, an image, or a link to the image, wherein the image is composed of a set of visual elements that each have a particular visual attribute;

transmitting, by the server device and to a second device, information to cause the second device to present an interface indicating instructions to recreate the image by inputting one or more visual elements to form an input image of an authentication symbol with reference to the image presented to the first device, the input image being formed via input of a set of one or more visual elements via the interface; and

granting or denying access to the resource based on the image and information indicative of the input image.

10. The method of claim 9 , wherein the information causes a plurality of visual elements to be presented via the interface of the second device and enables visual elements, of the plurality of visual elements, to be input to form the input image.

11. The method of claim 9 , wherein the input image is formed via at least one of:

selecting the set of one or more visual elements, presented via the interface, to form the input image, or

drawing the set of one or more visual elements via the interface.

12. The method of claim 9 , wherein the input image is formed via:

separately dragging one or more first visual elements, and

drawing one or more second visual elements.

13. The method of claim 9 , further comprising:

randomly selecting a first visual element to be included in the image; and

identifying a second visual element to be included in the image based on the first visual element.

14. The method of claim 9 , wherein granting or denying access to the resource comprises:

comparing the input image and the image;

calculating a similarity score based on comparing the input image and the image; and

determining whether the similarity score satisfies a threshold.

15. The method of claim 9 , wherein the input image is formed using an input mechanism that enables intersection or overlapping of at least two visual elements of the set of one or more visual elements.

16. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a client device, cause the client device to:

receive, from a server device, information that identifies an interface to be presented by the client device in association with a request to access a network resource;

present, via the interface:

an indication that includes instructions to recreate an image presented to a user device by inputting one or more visual elements to form, with reference to the image presented to the user device, an input image of an authentication symbol via input of a set of one or more visual elements, wherein the image is composed of a set of visual elements that each have a particular visual attribute; and

receive, from the server device, a message indicating whether access to the network resource is granted or denied based on transmitting input symbol information indicative of the input image.

17. The non-transitory computer-readable medium of claim 16 , wherein the input symbol information includes the input image.

18. The non-transitory computer-readable medium of claim 16 , wherein the input symbol information includes at least one of:

the input image,

information that identifies the set of one or more visual elements used to form the input image, or

position information that identifies respective positions of the set of one or more visual elements.

19. The non-transitory computer-readable medium of claim 16 , wherein the input symbol information includes information that identifies a sequence in which the set of one or more visual elements were input to form the input image.

20. The non-transitory computer-readable medium of claim 16 , wherein the input image is formed by drawing or by using a selecting mechanism.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2025
From: ZHU, VANCK
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 070119/0159 →
Continuity (2)
Continuation 17078898 · Oct 23, 2020
Related Publication 20240214374A1 · Jun 27, 2024
References Cited (27)
US 9432366B2 · Apostolos et al. · 2016 [cited by applicant]
US 9613201B1 · Dotan et al. · 2017 [cited by applicant]
US 9686426B2 · Oguma · 2017 [cited by examiner]
US 10057227B1 · Hess et al. · 2018 [cited by applicant]
US 10218506B1 · Bhabbur et al. · 2019 [cited by applicant]
US 20080098464A1 · Mizrah et al. · 2008 [cited by applicant]
US 20100185858A1 · Nishimi · 2010 [cited by examiner]
US 20130097697A1 · Zhu et al. · 2013 [cited by applicant]
US 20170154177A1 · Tsou · 2017 [cited by applicant]
US 20180144654A1 · Olsen, Jr. · 2018 [cited by applicant]
US 20220131850A1 · Zhu · 2022 [cited by applicant]
WO 2008105602A1 · 2008 [cited by applicant]
WO 2017030210A1 · 2017 [cited by applicant]
Enhancement of Educational Institutions Dynamic Websites by Adding Security and Accesibility, Fgee et al., Jul. 2010 (Year: 2010). [cited by examiner]
Chen X., et al., “Mobile Login Methods Help Chinese Users Avoid Password Roadblocks,” Sep. 2, 2018, 13 pages. [cited by applicant]
“Emoji Passwords: Can't Crack This” 7 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2021/056279, mailed on Feb. 8, 2022, 12 pages. [cited by applicant]
Kraus L., et al., “Implications of the Use of Emojis in Mobile Authentication,” Symposium on Usable Privacy and Securih (SOUPS), Jun. 22-24, 2016, 2 pages, Denver, Colorado. [cited by applicant]
Kraus L., et al., “On the Use of Emojis in Mobile Authentication,” 32nd IFIP International Conference on ICT Systems Security and Privacy Protection (SEC), May 2017, pp. 265-280, Rome, Italy. [cited by applicant]
Kutzner T., et al., “User Verification using Safe Handwritten Passwords on Smartphones,” 2015 Eighth International Conference on Contemporary Computing (IC3), Aug. 2015, 6 pages. [cited by applicant]
Limer E., “Your Android Pattern Password is Super Easy to Guess,” Popular Mechanics, Aug. 21, 2015, 4 pages. [cited by applicant]
Naone E., “Handwritten Passwords,” IT Technology Review, Jun. 28, 2007, 3 pages. [cited by applicant]
Onarlioglu K., et al., “Overhaul: Input-Driven Access Control for Better Privacy on Traditional Operating Systems,” Jun. 2016, pp. 443-454. [cited by applicant]
Rajpal et al., “Non-Intrusive Intellectual Gaming CAPTCHA for Optimal Web Security”, International Conference on Advanced Computation and Telecommunication (ICACAT), IEEE, Dec. 28, 2018, pp. 1-7, XP033675360, [retrieved… [cited by applicant]
Schaub F., “Why Emojis might be your Next Password,” The Conversation, May 3, 2017, 3 pages. Retrieved from the Internet [URL:https://theconversation.com/why-emojis-might-be-your-next-password-76973]. [cited by applicant]
Tolosana R., et al., “BioTouchPass: Handwritten Passwords for Touchscreen Biometrics,” Journal of Latex Class Files, Mar. 2016, vol. 13, No. 9, 12 pages. [cited by applicant]
Yao B., et al., “Using Chinese Characters to Generate Text-Based Passwords for Information Security,” Jul. 11, 2019, 59 pages. [cited by applicant]