IP Library Granted Patent US 12,340,370
Granted Patent B1
US 12,340,370 · App. 18/639,888 · Granted Jun 24, 2025

Methods and systems for multi-factor authentication

Inventor: Girish Balasubramanian (Fremont, CA)
Assignee: Stripe, Inc.
G06Q20/4014
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,340,370
App. No.
18/639,888
Granted
Jun 24, 2025
Kind
B1
Abstract

Disclosed herein are methods and systems for multi-platform authentication of electronic devices. One method involves a processor monitoring data related to the execution of an initial authentication request for a user via a first electronic platform. Subsequently, the processor receives, via the first platform, a request to complete a second authentication request by a second electronic platform, which corresponds to a multi-factor authentication. Upon receiving a first factor authentication purportedly authenticating the identity of the user, the processor generates second factor authentication information based on the monitored data. A message containing both first and second factor authentication details is then generated and transmitted to the second electronic platform. Upon receiving a positive authentication result from the second electronic platform, confirming the user's identity authentication.

Claims (63)

1. A method for improving speed and reducing network latency associated with multi-factor authentication usage by generating, on behalf of a user device, at least a part of multi-factor authentication information for a current authentication request in accordance with earlier monitored data associated with execution of an earlier authentication request, without requiring user input pertaining to the generated part of multi-factor authentication information to be entered or obtained from the user device across a network, the method comprising:

monitoring, by one or more processors of a server system and at a first time, data associated with execution of a first authentication request for an electronic device,

the first authentication request being the earlier authentication request, and

the user device being the electronic device;

receiving, by the server system and at a second time, a request to complete a second authentication request that is requested for an electronic transaction requested by the electronic device,

the second authentication request being the current authentication request;

determining, by the server system, that the second authentication request is associated with a multi-factor authentication requirement for at least a first factor authentication information associated with a first factor requirement and a second factor authentication information associated with a second factor requirement;

identifying, by the server system, the first factor authentication information received during the electronic transaction;

generating, by the server system, based on determining that the second authentication request is associated with the multi-factor authentication requirement, and based on the monitored data, associated with execution of the first authentication request, being entered during a same browsing session, the second factor authentication information in accordance with the monitored data associated with execution of the first authentication request,

the second factor authentication information satisfying the second factor requirement, and

the second factor authentication information being the generated part of multi-factor authentication information;

generating an expiring universal resource locator (URL) that expires after a period of time has passed;

storing the second factor authentication information in a storage location accessible by the expiring URL; and

transmitting, by the server system and in connection with the second authentication request, an electronic message comprising:

the first factor authentication information, and

the expiring URL for retrieval of the second factor authentication information from the storage location.

2. The method of claim 1 , wherein the expiring URL is transmitted within one or more input fields.

3. The method of claim 1 , further comprising:

encrypting the second factor authentication information; and

transmitting an encryption key for decrypting of the second factor authentication information.

4. The method of claim 1 , wherein the first factor authentication information comprises a card number, a personal identification number, a card security code, an expiration data, a username and password, or a combination thereof.

5. The method of claim 1 , wherein the second factor authentication information comprises a transaction history of a user of the user device, a device identification of the user, a passcode received from the user in association with a prior transaction, or a combination thereof.

6. The method of claim 5 , wherein the passcode received from the user comprises a one-time password.

7. The method of claim 1 , wherein the multi-factor authentication requirement comprises a three-dimensional secure (3DS) protocol.

8. One or more non-transitory computer-readable storage media including instructions that, when executed by a processor of a server system, causes the server system to:

monitor, at a first time, data associated with execution of a first authentication request for an electronic device;

receive, at a second time, a request to complete a second authentication request that is requested for an electronic transaction requested by the electronic device;

determine that the second authentication request is associated with a multi-factor authentication requirement for at least a first factor authentication information associated with a first factor requirement and a second factor authentication information associated with a second factor requirement;

identify the first factor authentication information received during the electronic transaction;

generate, based on determining that the second authentication request is associated with the multi-factor authentication requirement and based on the monitored data being entered during a same browsing session, the second factor authentication information in accordance with the monitored data and without requiring user input pertaining to the second factor authentication information to be entered or obtained from across a network, the second factor authentication information satisfying the second factor requirement;

generate an expiring universal resource locator (URL) that expires after a period of time has passed;

store the second factor authentication information in a storage location accessible by the expiring URL; and

transmit, in connection with the second authentication request, an electronic message comprising:

the first factor authentication information, and

the expiring URL for retrieval of the second factor authentication information from the storage location.

9. The one or more non-transitory computer-readable storage media of claim 8 , wherein the expiring URL is transmitted within one or more input fields.

10. The one or more non-transitory computer-readable storage media of claim 8 , wherein the instructions further cause the server system to:

encrypt the second factor authentication information; and

transmit an encryption key for decrypting the second factor authentication information.

11. The one or more non-transitory computer-readable storage media of claim 8 , wherein the first factor authentication information comprises a card number, a personal identification number, a card security code, an expiration data, a username and password, or a combination thereof.

12. The one or more non-transitory computer-readable storage media of claim 8 , wherein the second factor authentication information comprises a transaction history of a user of the electronic device, a device identification of the electronic device, a passcode received from the user in association with a prior transaction, or a combination thereof.

13. The one or more non-transitory computer-readable storage media of claim 12 , wherein the passcode received from the user comprises a one-time password.

14. The one or more non-transitory computer-readable storage media of claim 8 , wherein the multi-factor authentication requirement comprises a three-dimensional secure (3DS) protocol.

15. A computer system comprising:

memory; and

one or more processors, coupled to the memory, configured to:

monitor, at a first time, data associated with execution of a first authentication request for an electronic device;

receive, at a second time, a request to complete a second authentication request that is requested for an electronic transaction requested by the electronic device;

determine that the second authentication request is associated with a multi-factor authentication requirement for at least a first factor authentication information associated with a first factor requirement and a second factor authentication information associated with a second factor requirement;

identify the first factor authentication information received during the electronic transaction;

generate, based on determining that the second authentication request is associated with the multi-factor authentication requirement and based on the first authentication request being entered during a same browsing session, the second factor authentication information in accordance with the monitored data associated with execution of the first authentication request and without requiring user input pertaining to the second factor authentication information to be entered or obtained from across a network, the second factor authentication information satisfying the second factor requirement; and

generate an expiring universal resource locator (URL) that expires after a period of time has passed;

store the second factor authentication information in a storage location accessible by the expiring URL; and

transmit, in connection with the second authentication request, an electronic message comprising:

the first factor authentication information, and

the expiring URL for retrieval of the second factor authentication information from the storage location.

16. The computer system of claim 15 , wherein the expiring URL is transmitted within one or more input fields.

17. The computer system of claim 15 , wherein the first factor authentication information comprises a card number, a personal identification number, a card security code, an expiration data, a username and password, or a combination thereof.

18. The computer system of claim 15 , wherein the second factor authentication information comprises a transaction history of a user, a device identification, a passcode received from the user in association with a prior transaction, or a combination thereof.

19. The computer system of claim 15 , wherein the one or more processors are further configured to:

encrypt the second factor authentication information.

20. The computer system of claim 19 , wherein the one or more processors are further configured to:

transmitting an encryption key for decrypting of the second factor authentication information.

Assignments (2)
CHANGE OF NAME Recorded Jan 7, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 074264/0807 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: BALASUBRAMANIAN, GIRISH
To: STRIPE, INC.
Reel/Frame 071498/0567 →
Continuity (1)
Continuation 16677393 · Nov 7, 2019
References Cited (5)
US 20070022301A1 · Nicholson · 2007 [cited by examiner]
US 20100332832A1 · Wu · 2010 [cited by examiner]
US 20120110341A1 · Beigi · 2012 [cited by examiner]
US 20130179350A1 · Kirillin · 2013 [cited by examiner]
US 20220191198A1 · Piel · 2022 [cited by examiner]