IP Library › Granted Patent US 12,689,622
Granted Patent B2
US 12,689,622 · App. 18/444,105 · Granted Jul 21, 2026

Enhanced one-time passcode devices

Inventor: Weston Thackeray Thompson (Claremont, CA)
Assignee: Wells Fargo Bank, N.A.
H04L63/0838H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,689,622
App. No.
18/444,105
Filed
Feb 16, 2024
Granted
Jul 21, 2026
Kind
B2
Art Unit
2497
USPC
726/7
Abstract

A third verification factor is introduced into the two-factor authentication process, thereby establishing a robust three-factor authentication system. Specifically, a One-Time Password (OTP) that is typically generated for authentication purposes undergoes an additional layer of security by utilizing the OTP in a data authentication scheme of a user's chip-enabled credit, debit, banking, or similar card. An enhanced OTP generator sends the OTP to the card, which encrypts either the OTP or a value derived from the OTP (e.g., such as a hash of the OTP) with a cryptographic key associated with the card to create an encrypted authentication token. The encrypted authentication token is then provided to the authenticating party. Also described is an enhanced OTP generation device in the form of a passbook.

Claims (56)

1 . An authentication method, comprising:

using a hardware processor of a first computing device:

generating a one-time passcode using a shared secret value, the shared secret value shared between the first computing device and a second computing device, the second computing device providing a network-based service;

detecting a Near Field Communications (NFC) enabled card using an NFC reader communicatively coupled to the hardware processor;

transmitting the one-time passcode to the NFC enabled card;

receiving an encrypted token from the NFC enabled card, the encrypted token generated by the NFC enabled card using the one-time passcode and a cryptographic key of the NFC enabled card;

outputting a value based upon the encrypted token on a display of the first computing device; and

providing login credentials input by a user and the value as separate authentication factors to the second computing device to authenticate the user of the first computing device to the second computing device to access an account of the user on the network-based service.

2 . The authentication method of claim 1 , further comprising:

using a second hardware processor of the second computing device:

generating a second one-time passcode using the shared secret value;

receiving, as part of an authentication of the user, the encrypted token;

decrypting the encrypted token using a cryptographic key corresponding to the cryptographic key of the NFC enabled card to generate decrypted data;

determining whether the decrypted data corresponds to the second one-time passcode; and

responsive to determining whether the decrypted data corresponds to the second one-time passcode, granting access to the network-based service or operation of the network-based service.

3 . The authentication method of claim 2 , wherein the decrypted data comprises card specified data and wherein determining whether the decrypted data corresponds to the second one-time passcode comprises:

utilizing a cryptographic hash of the second one-time passcode and the card specified data and comparing the cryptographic bash with a portion of the decrypted data.

4 . The method of claim 1 , wherein the NFC enabled card is a bank card issued by a financial institution and wherein the network-based service is a banking application providing access to a financial account of the user.

5 . The method of claim 1 , wherein the one-time passcode is a time-based one-time-passcode (TOTP).

6 . An authentication device, comprising:

a hardware processor configured to perform operations comprising:

generating a one-time passcode using a shared secret value, the shared secret value shared between the authentication device and a second computing device, the second computing device providing a network-based service;

detecting a Near Field Communications (NFC) enabled card using an NFC reader communicatively coupled to the hardware processor;

transmitting the one-time passcode to the NFC enabled card;

receiving an encrypted token from the NFC enabled card, the encrypted token generated by the NFC enabled card using the one-time passcode and a cryptographic key of the NFC enabled card;

outputting a value based upon the encrypted token on a display of the authentication device; and

providing login credentials input by a user and the value as separate authentication factors to the second computing device to authenticate the user of the authentication device to the second computing device to access an account of the user on the network-based service.

7 . The authentication device of claim 6 , wherein the operations further comprise:

using a second hardware processor of the second computing device:

generating a second one-time passcode using the shared secret value;

receiving, as part of an authentication of the user, the encrypted token;

decrypting the encrypted token using a cryptographic key corresponding to the cryptographic key of the NFC enabled card to generate decrypted data;

determining whether the decrypted data corresponds to the second one-time passcode; and

responsive to determining whether the decrypted data corresponds to the second one-time passcode, granting access to the network-based service or operation of the network-based service.

8 . The authentication device of claim 7 , wherein the decrypted data comprises card specified data and wherein the operations of determining whether the decrypted data corresponds to the second one-time passcode comprises:

utilizing a cryptographic hash of the second one-time passcode and the card specified data and comparing the cryptographic hash with a portion of the decrypted data.

9 . The authentication device of claim 6 , wherein the NFC enabled card is a bank card issued by a financial institution and wherein the network-based service is a banking application providing access to a financial account of the user.

10 . The authentication device of claim 6 , wherein the one-time passcode is a time-based one-time-passcode (TOTP).

11 . A non-transitory, machine-readable medium, storing instructions, which when performed by an authentication device, causes the authentication device to perform operations comprising:

generating a one-time passcode using a shared secret value, the shared secret value shared between the authentication device and a second computing device, the second computing device providing a network-based service;

detecting a Near Field Communications (NFC) enabled card using an NFC reader communicatively coupled to the authentication device;

transmitting the one-time passcode to the NFC enabled card;

receiving an encrypted token from the NFC enabled card, the encrypted token generated by the NFC enabled card using the one-time passcode and a cryptographic key of the NFC enabled card;

outputting a value based upon the encrypted token on a display of the authentication device; and

providing login credentials input by a user and the value as separate authentication factors to the second computing device to authenticate the user to the second computing device to access an account of the user on the network-based service.

12 . The non-transitory, machine-readable medium of claim 11 , wherein the operations further comprise:

using a second hardware processor of the second computing device:

generating a second one-time passcode using the shared secret value;

receiving, as part of an authentication of the user, the encrypted token;

decrypting the encrypted token using a cryptographic key corresponding to the cryptographic key of the NFC enabled card to generate decrypted data;

determining whether the decrypted data corresponds to the second one-time passcode; and

responsive to determining whether the decrypted data corresponds to the second one-time passcode, granting access to the network-based service or operation of the network-based service.

13 . The non-transitory, machine-readable medium of claim 12 , wherein the decrypted data comprises card specified data and wherein the operations of determining whether the decrypted data corresponds to the second one-time passcode comprises:

utilizing a cryptographic hash of the second one-time passcode and the card specified data and comparing the cryptographic hash with a portion of the decrypted data.

14 . The non-transitory machine-readable medium of claim 12 , wherein the NFC enabled card is a bank card issued by a financial institution and wherein the network-based service is a banking application providing access to a financial account of the user.

15 . The non-transitory machine-readable medium of claim 12 , wherein the one-time passcode is a time-based one-time-passcode (TOTP).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2024
From: THOMPSON, WESTON THACKERAY
To: WELLS FARGO BANK, N.A.
Reel/Frame 067214/0770 →
Continuity (1)
Related Publication 20250267144A1 · Aug 21, 2025
References Cited (49)
US 5444768A · Lemaire et al. · 1995 [cited by applicant]
US 6542623B1 · Kahn · 2003 [cited by applicant]
US 7194620B1 · Hayes · 2007 [cited by applicant]
US 8769624B2 · Cotterill · 2014 [cited by applicant]
US 9047473B2 · Samuelsson et al. · 2015 [cited by applicant]
US 9092643B2 · Keoh · 2015 [cited by examiner]
US 9537661B2 · Khalil et al. · 2017 [cited by applicant]
US 9769157B2 · Ibrahim et al. · 2017 [cited by applicant]
US 10299118B1 · Karachiwala et al. · 2019 [cited by applicant]
US 20020073045A1 · Rubin · 2002 [cited by examiner]
US 20030051083A1 · Striemer · 2003 [cited by applicant]
US 20040243856A1 · Shatford · 2004 [cited by applicant]
US 20060094401A1 · Eastlake, III · 2006 [cited by examiner]
US 20070005963A1 · Eldar et al. · 2007 [cited by applicant]
US 20070117553A1 · Arnos · 2007 [cited by applicant]
US 20070174904A1 · Park · 2007 [cited by applicant]
US 20070203850A1 · Singh et al. · 2007 [cited by applicant]
US 20080072303A1 · Syed · 2008 [cited by applicant]
US 20140236834A1 · Appalsamy · 2014 [cited by examiner]
US 20150281227A1 · Fox Ivey · 2015 [cited by examiner]
US 20190392417A1 · Li · 2019 [cited by examiner]
US 20200050749A1 · Barboi · 2020 [cited by applicant]
US 20210366309A1 · Kolar et al. · 2021 [cited by applicant]
US 20210377260A1 · Phillips · 2021 [cited by examiner]
US 20220148378A1 · Verschoor · 2022 [cited by examiner]
US 20220261147A1 · Welch et al. · 2022 [cited by applicant]
US 20240289798A1 · Koshy · 2024 [cited by examiner]
US 20250267004A1 · Ulrich · 2025 [cited by applicant]
CN 106782572 · 2020 [cited by applicant]
CN 112805967 · 2023 [cited by applicant]
KR 20100136339 · 2010 [cited by applicant]
KR 20100136367 · 2010 [cited by applicant]
KR 101499906 · 2015 [cited by applicant]
KR 101561499 · 2015 [cited by applicant]
KR 102157344 · 2020 [cited by applicant]
WO 2010101476 · 2010 [cited by applicant]
WO 2018113526 · 2018 [cited by applicant]
“YubiKey Bio Series”, [Online]. Retrieved from the Internet: URL: https: www.yubico.com products yubikey-bio-series , (Accessed on Nov. 19, 2023), 13 pgs. [cited by applicant]
“U.S. Appl. No. 18/581,144, Non Final Office Action mailed Jul. 2, 2025”, 12 pgs. [cited by applicant]
“EMV—Integrated Circuit Card Specifications for Payment Systems”, Book 1, Version 4.3, (Nov. 2011), 189 pgs. [cited by applicant]
“EMV—Integrated Circuit Card Specifications for Payment Systems”, Book 2, Version 4.3, (Nov. 2011), 174 pgs. [cited by applicant]
“EMV—Integrated Circuit Card Specifications for Payment Systems”, Book 3, Version 4.3, (Nov. 2011), 230 pgs. [cited by applicant]
“U.S. Appl. No. 18/581,144, Response filed Oct. 2, 2025 to Non Final Office Action mailed Jul. 2, 2025”, 13 pgs. [cited by applicant]
Banerjee, “Tap Based User Authentication on Smartphones for Visually Impaired People”, 9th International Conference on Computing, Communication and Networking Technologies (ICCCNT), Bengaluru, India, (2018), 1-7. [cited by applicant]
Farghaly, Ahmed Hemdan, “EMV Application Specification :: Offline Data Authentication (ODA)—part I”, [Online]. Retrieved from the Internet: URL: https: www.linkedin.com pulse emv-application-specification-offline-data-o… [cited by applicant]
Farghaly, Ahmed Hemdan, “EMV Application Specification :: Offline Data Authentication (ODA)—part II”, [Online]. Retrieved from the Internet: URL: https: www.linkedin.com pulse emv-application-specification-offline-data-… [cited by applicant]
Fuglerud, “Secure and Inclusive Authentication with a Talking Mobile One-Time-Password Client”, IEEE Security and Privacy, vol. 9, No. 2, (Mar.-Apr. 2011), 27-34. [cited by applicant]
Henwyn, “An Effective Approach to Speech-Based Email Assistance for Visually Impaired People”, 8th International Conference on Trends in Electronics and Informatics (ICOEI), Tirunelveli, India, (2025), 627-632. [cited by applicant]
Patil, “NetraAadhaar: A Deep Learning-Driven Aadhaar Verification Platform for the Aid of Visually Impaired”, IEEE Access, vol. 13, (2025), 74229-74251. [cited by applicant]