IP Library › Granted Patent US 12,216,757
Granted Patent B2
US 12,216,757 · App. 18/425,019 · Granted Feb 4, 2025

Systems and methods for password managers

Inventors: Rajko Ilincic (Annandale, VA); Jeffrey Rule (Chevy Chase, MD)
Assignee: CAPITAL ONE SERVICES, LLC
G06F21/45G06F21/602H04L63/083H04L63/0853H04L63/0861H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,216,757
App. No.
18/425,019
Granted
Feb 4, 2025
Kind
B2
Abstract

An authentication system comprises a browser extension and a password manager application. The browser extension can be configured for execution on a first user device. The browser extension can be configured to display a response code and receive a login credential from a server. The response code can comprise a unique session identifier identifying the browser extension and a user browsing session. The password manager application can be configured for execution on a second user device. The second user device can have a scanner configured to scan the response code. The password manager application can be configured to extract the unique session identifier, parse the unique session identifier into session identifier content, send a portion of the session identifier content to the server, receive an approval from a user of the second user device, and send a notification to the server.

Claims (42)

1. A system, comprising a first user device including a browser extension and a second user device including a password manager application, wherein:

the browser extension is configured to:

display a code comprising metadata, the metadata including a unique session identifier, a security question, a device identifier, and a browser type identifier; and

receive login credentials from a server; and

the password manager application is configured to:

receive the code;

establish a handshake with the server based on the metadata;

parse the unique session identifier into session identifier content;

send the security question and a portion of the session identifier content to the server; and

receive an approval from the server.

2. The system of claim 1 , wherein the browser extension is further configured to encrypt the received login credentials with a private key.

3. The system of claim 1 , wherein the password manager application is further configured to extract the unique session identifier and the security question.

4. The system of claim 1 , wherein the password manager application is further configured to receive a security question answer from the server, and send a notification to the server, wherein the notification includes the unique session identifier and the login credentials.

5. The system of claim 1 , wherein the unique session identifier identifies the browser extension and a user browsing session, and the browser extension is further configured to perform the login using the credentials.

6. The system of claim 1 , wherein the approval comprises a personal identification number (PIN) or a biometric.

7. The system of claim 1 , wherein the code comprises a bar code or a quick response code.

8. A method, comprising:

receiving a secure login option for a login associated with a website, wherein the website is displayed on a first user device;

generating a unique session identifier and sending the unique session identifier to a server;

displaying a code on the first user device, wherein the code includes metadata comprising the unique session identifier, a security question, a device identifier, a browser type identifier, and a time zone identifier;

establishing a handshake with the server based on the metadata;

receiving credentials for the login associated with the unique session identifier from the server; and

performing the login using the credentials.

9. The method of claim 8 , wherein the login is secured through a password manager application on a second user device.

10. The method of claim 9 , wherein the code is scannable by the second user device.

11. The method of claim 8 , further comprising encrypting the credentials using a private key.

12. The method of claim 8 , further comprising transmitting the metadata to the server to establish the handshake.

13. The method of claim 8 , further comprising receiving a security question answer from the server, wherein the security question answer is associated with a password manager application.

14. The method of claim 8 , wherein the unique session identifier identifies a browser extension and a user browsing session.

15. The method of claim 14 , wherein the second user device includes a scanner configured to scan the code.

16. The method of claim 8 , further comprising receiving a whitelist from the server, wherein the secure login option is available for the website because it is a member of the whitelist.

17. The method of claim 8 , wherein the metadata includes at least one selected from the group of an IP address and a time stamp.

18. A non-transitory computer-accessible medium having stored thereon computer-executable instructions that, when executed by a computer arrangement, cause the computer arrangement to perform procedures comprising:

receiving a secure login option for a login associated with a website, wherein the website is displayed on a first user device;

generating a unique session identifier and sending the unique session identifier to a server;

displaying a code on the first user device, wherein the code includes metadata comprising the unique session identifier, a security question, a device identifier, a browser type identifier, and a time zone identifier;

establishing a handshake with the server based on the metadata;

receiving credentials for the login associated with the unique session identifier from the server; and

performing the login using the credentials.

19. The non-transitory computer-accessible medium of claim 18 , the procedures further comprise receiving an approval, wherein the approval comprises a two-factor authentication.

20. The non-transitory computer-accessible medium of claim 18 , the procedures further comprise receiving a security question answer and sending a notification to a server, wherein the notification includes the unique session identifier and the login credentials.

21. The method of claim 8 , wherein establishing a handshake with the server is performed on a second user device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2024
From: ILINCIC, RAJKO; RULE, JEFFREY
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 066286/0924 →
Continuity (3)
Continuation 17307819 · May 4, 2021
Continuation 16773023 · Jan 27, 2020
Related Publication 20240241941A1 · Jul 18, 2024
References Cited (57)
US 6907546B1 · Haswell et al. · 2005 [cited by applicant]
US 7100195B1 · Underwood · 2006 [cited by applicant]
US 7519688B2 · Behrens · 2009 [cited by examiner]
US 8056118B2 · Pillouras · 2011 [cited by applicant]
US 8065219B2 · Haynie et al. · 2011 [cited by applicant]
US 8132243B2 · Bychkov · 2012 [cited by examiner]
US 8213906B2 · Chen · 2012 [cited by applicant]
US 8381269B2 · Yue · 2013 [cited by examiner]
US 8590022B2 · Faryna · 2013 [cited by applicant]
US 8613070B1 · Borzycki et al. · 2013 [cited by applicant]
US 8683571B2 · Zapata · 2014 [cited by examiner]
US 8726343B1 · Borzycki et al. · 2014 [cited by applicant]
US 8844003B1 · Jakobsson · 2014 [cited by applicant]
US 8918479B2 · O'Connell · 2014 [cited by examiner]
US 8949938B2 · Sowatskey et al. · 2015 [cited by applicant]
US 8959583B2 · Fadida et al. · 2015 [cited by applicant]
US 8959628B2 · Coppock · 2015 [cited by applicant]
US 8997195B1 · Fadida et al. · 2015 [cited by applicant]
US 9065824B1 · Valdivia · 2015 [cited by applicant]
US 9203824B1 · Nunn · 2015 [cited by examiner]
US 9224003B2 · Andersen · 2015 [cited by examiner]
US 9235696B1 · Nien et al. · 2016 [cited by applicant]
US 9280670B2 · Conte · 2016 [cited by examiner]
US 9412283B2 · Bhatnagar · 2016 [cited by examiner]
US 9419968B1 · Pei et al. · 2016 [cited by applicant]
US 9479499B2 · Wang · 2016 [cited by applicant]
US 9525667B2 · Wang · 2016 [cited by applicant]
US 9825947B2 · Jass et al. · 2017 [cited by applicant]
US 9887979B1 · Pandita et al. · 2018 [cited by applicant]
US 9979725B1 · Liu et al. · 2018 [cited by applicant]
US 10204327B2 · Katzin · 2019 [cited by applicant]
US 10304026B2 · Smith et al. · 2019 [cited by applicant]
US 10491587B2 · Hon et al. · 2019 [cited by applicant]
US 10719602B2 · Fang · 2020 [cited by examiner]
US 20110145150A1 · Onischuk · 2011 [cited by applicant]
US 20130067217A1 · Matzkel et al. · 2013 [cited by applicant]
US 20130167208A1 · Shi · 2013 [cited by applicant]
US 20130198814A1 · Zheng et al. · 2013 [cited by applicant]
US 20140223525A1 · Fadida · 2014 [cited by examiner]
US 20140237563A1 · Zhang · 2014 [cited by applicant]
US 20140250511A1 · Kendall · 2014 [cited by applicant]
US 20150067772A1 · Paek et al. · 2015 [cited by applicant]
US 20150121491A1 · Xia · 2015 [cited by applicant]
US 20150271167A1 · Kalai · 2015 [cited by applicant]
US 20150339788A1 · Dawson · 2015 [cited by applicant]
US 20160006711A1 · Gage et al. · 2016 [cited by applicant]
US 20160020905A1 · Poole et al. · 2016 [cited by applicant]
US 20160173481A1 · Kwon et al. · 2016 [cited by applicant]
US 20160191506A1 · Wang · 2016 [cited by applicant]
US 20160337553A1 · Sato · 2016 [cited by applicant]
US 20170171200A1 · Bao et al. · 2017 [cited by applicant]
US 20170185761A1 · Stanwood et al. · 2017 [cited by applicant]
US 20170230366A1 · Liang et al. · 2017 [cited by applicant]
US 20170237726A1 · Wang · 2017 [cited by applicant]
US 20180004935A1 · Slegrist · 2018 [cited by applicant]
US 20180041508A1 · Jass et al. · 2018 [cited by applicant]
US 20190066063A1 · Jessamine · 2019 [cited by applicant]