IP Library Granted Patent US 12,093,945
Granted Patent B2
US 12,093,945 · App. 17/554,348 · Granted Sep 17, 2024

Multi-factor user authentication

Inventors: Ra Uf Ridzuan Bin Ma Arof (Singapore, SG); Harish Tammaji Kulkarni (Singapore, SG); Kumudini Choyal (Tung Chung, HK); Nhat Minh Nguyen (Singapore, SG); Surendran Surendran (Singapore, SG)
Assignee: Bank of America Corporation
G06Q20/385G06Q20/382G06Q20/4016G06Q20/407
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,093,945
App. No.
17/554,348
Granted
Sep 17, 2024
Kind
B2
Abstract

A system for multi-factor user authentication for payment card-based transactions are described. The multifactor authentication may be based on a one-time passcode/password (OTP) as sent by an authentication server. A user device may, based on receiving the OTP, send an authentication code. The authentication code may be generated/determined based on the OTP. The authentication code may be augmented biometric identifier (ID) of a user associated with the user device. The authentication server may validate a transaction based on the authentication code.

Claims (55)

1. An apparatus comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the apparatus to:

receive an authentication request for a user, wherein the authentication request comprises a user identifier associated with the user;

determine, based on the user identifier, a user device associated with the user;

send, to the user device, a one-time passcode (OTP);

send, to the user device, a character mapping, associated with the user, for a dynamic digital keypad interface that maps user input characters to encoded characters, wherein:

the dynamic digital keypad interface corresponds to a graphical user interface (GUI) comprising a plurality of buttons arranged in a grid,

each button, of the plurality of buttons, represents a corresponding user input character,

each button, of the plurality of buttons, is associated with a corresponding encoded character based on:

the character mapping associated with the user, and

a row and a column, in the grid, associated with the user input character, and

the character mapping is periodically refreshed;

after sending the OTP, receive an authentication code, wherein the authentication code is generated based on user input via the dynamic digital keypad interface;

generate, based on the OTP and the character mapping associated with the user, a validation code; and

based on comparing the validation code and the authentication code, send an authorization response indicating whether the authentication request is approved or declined.

2. The apparatus of claim 1 , wherein the authorization response indicates that the authentication request is approved based on the validation code matching the authentication code.

3. The apparatus of claim 1 , wherein the authorization response indicates that the authentication request is declined based on the validation code not matching the authentication code.

4. The apparatus of claim 1 , wherein the instructions, when executed by the one or more processors, cause the apparatus to send the OTP via at least one of:

a short messaging service (SMS) message; or

an electronic mail.

5. The apparatus of claim 1 , wherein the user device is a mobile communication device.

6. The apparatus of claim 1 , wherein the instructions, when executed by the one or more processors, cause the apparatus to:

send the OTP via a first communication channel, and

receive the authentication code via a second communication channel.

7. A method for multi-factor user authentication, the method comprising:

receiving an authentication request for a user, wherein the authentication request comprises a user identifier associated with the user;

determining, based on the user identifier, a user device associated with the user;

sending, to the user device, a one-time passcode (OTP);

sending, to the user device, a character mapping, associated with the user, for a dynamic digital keypad interface that maps user input characters to encoded characters, wherein:

the dynamic digital keypad interface corresponds to a graphical user interface (GUI) comprising a plurality of buttons arranged in a grid,

each button, of the plurality of buttons, represents a corresponding user input character,

each button, of the plurality of buttons, is associated with a corresponding encoded character based on:

the character mapping associated with the user, and

a row and a column, in the grid, associated with the user input character, and

the character mapping is periodically refreshed;

after sending the OTP, receiving an authentication code, wherein the authentication code is generated based on user input via the dynamic digital keypad interface;

generating, based on the OTP and the character mapping associated with the user, a validation code; and

based on comparing the validation code and the authentication code, sending an authorization response indicating whether the authentication request is approved or declined.

8. The method of claim 7 , wherein the authorization response indicates that the authentication request is approved based on the validation code matching the authentication code.

9. The method of claim 7 , wherein the authorization response indicates that the authentication request is declined based on the validation code not matching the authentication code.

10. A non-transitory computer readable medium storing instructions that, when executed, cause an authentication platform to:

receive an authentication request for a user, wherein the authentication request comprises a user identifier associated with the user;

determine, based on the user identifier, a user device associated with the user;

send, to the user device, a one-time passcode (OTP);

send, to the user device, a character mapping, associated with the user, for a dynamic digital keypad interface that maps user input characters to encoded characters, wherein:

the dynamic digital keypad interface corresponds to a graphical user interface (GUI) comprising a plurality of buttons arranged in a grid,

each button, of the plurality of buttons, represents a corresponding user input character,

each button, of the plurality of buttons, is associated with a corresponding encoded character based on:

the character mapping associated with the user, and

a row and a column, in the grid, associated with the user input character, and

the character mapping is periodically refreshed;

after sending the OTP, receive an authentication code, wherein the authentication code is generated based on user input via the dynamic digital keypad interface;

generate, based on the OTP and the character mapping associated with the user, a validation code; and

based on comparing the validation code and the authentication code, send an authorization response indicating whether the authentication request is approved or declined.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2021
From: RIDZUAN BIN MA AROF, RA UF; KULKARNI, HARISH TAMMAJI; CHOYAL, KUMUDINI; NGUYEN, NHAT MINH; SURENDRAN, SURENDRAN
To: BANK OF AMERICA CORPORATION
Reel/Frame 058417/0855 →
Continuity (1)
Related Publication 20230196349A1 · Jun 22, 2023
Cited By (1)
US 12,432,203