IP Library Granted Patent US 12,353,545
Granted Patent B2
US 12,353,545 · App. 18/330,159 · Granted Jul 8, 2025

System and method for improving security using recursively generated quick response codes

Inventor: Saurabh Gupta (New Delhi, IN)
Assignee: Bank of America Corporation
G06F21/554G06K7/1417G06K19/06037G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,353,545
App. No.
18/330,159
Granted
Jul 8, 2025
Kind
B2
Abstract

A method includes capturing a preliminary quick response (QR) code displayed by a device of a desired service provider. The preliminary QR code has a substantially blank region and comprises an identification feature of the desired service provider. The identification feature is analyzed to determine an identification credential of the desired service provider. In response to determining that the identification credential matches a stored identification credential stored in a server of an interaction provider, a QR code is requested from the server. One or more directed acyclic graphs (DAGs) are generated. A first DAG is received from the server. A first portion of the QR code is generated based on the first DAG and added to the preliminary QR code to generate a first intermediate QR code. One or more recursion operations are performed until all DAGs are received and the QR code is generated from the preliminary QR code.

Claims (125)

1. A system comprising:

a server of an interaction provider, wherein the server comprises:

a first memory configured to store:

identification credentials for a plurality of service providers; and

a first processor communicatively coupled to the first memory, wherein the first processor is configured to:

generate one or more directed acyclic graphs (DAGs), wherein the one or more DAGs comprise information to generate a quick response (QR) code; and

a user device communicatively coupled to the server, wherein the user device comprises:

a second processor configured to:

capture a preliminary quick response (QR) code displayed by a device of a desired service provider, wherein the preliminary QR code has a substantially blank region and comprises an identification feature of the desired service provider, the identification feature configured to identify the desired service provider to the interaction provider;

display the preliminary QR code;

analyze the identification feature to determine a name of a corresponding service provider;

in response to determining that the name of the corresponding service provider matches a name of the desired service provider, analyze the identification feature to determine an identification credential of the desired service provider and information of the interaction provider; and

in response to determining that the identification credential matches a stored identification credential stored in the server of the interaction provider:

request a QR code from the server of the interaction provider to perform an interaction requested by the desired service provider;

receive a first DAG from the server of the interaction provider;

generate a first portion of the QR code based on the first DAG;

add the first portion of the QR code to the preliminary QR code to generate a first intermediate QR code;

display the first intermediate QR code; and

perform one or more recursion operations until the QR code is generated from the preliminary QR code, wherein performing each recursion operation comprises:

 analyzing an identification feature of a current intermediate QR code to determine a new identification credential; and

 in response to determining that the new identification credential matches the stored identification credential:

 receiving a subsequent DAG from the server of the interaction provider;

 generating a subsequent portion of the QR code based on the subsequent DAG;

 adding the subsequent portion of the QR code to the current intermediate QR code to generate a subsequent intermediate QR code; and

 displaying the subsequent intermediate QR code.

2. The system of claim 1 , wherein the second processor is further configured to:

in response to determining that the name of the corresponding service provider does not match the name of the desired service provider:

generate an alert indicating a potential security breach; and

display the alert.

3. The system of claim 1 , wherein the second processor is further configured to:

in response to determining that the identification credential does not match the stored identification credential:

generate an alert indicating a potential security breach; and

display the alert.

4. The system of claim 1 , wherein the second processor is further configured to:

in response to determining that the new identification credential does not match the stored identification credential:

generate an alert indicating a potential security breach; and

display the alert.

5. The system of claim 1 , wherein the second processor is further configured to:

in response to determining that all DAGs are received from the server of the interaction provider:

display the QR code; and

in response to determining that the QR code corresponds to the DAGs received from the server of the interaction provider, perform the interaction based on the QR code.

6. The system of claim 5 , wherein the second processor is further configured to:

in response to determining that the QR code does not correspond to the DAGs received from the server of the interaction provider:

generate an alert indicating a potential security breach; and

display the alert.

7. The system of claim 1 , wherein the first DAG is different from the subsequent DAG.

8. A method comprising:

capturing a preliminary quick response (QR) code displayed by a device of a desired service provider, wherein the preliminary QR code has a substantially blank region and comprises an identification feature of the desired service provider, the identification feature configured to identify the desired service provider to an interaction provider;

displaying the preliminary QR code;

analyzing the identification feature to determine a name of a corresponding service provider;

in response to determining that the name of the corresponding service provider matches a name of the desired service provider, analyzing the identification feature to determine an identification credential of the desired service provider and information of the interaction provider; and

in response to determining that the identification credential matches a stored identification credential stored in a server of the interaction provider:

requesting a QR code from the server of the interaction provider to perform an interaction requested by the desired service provider;

generating one or more directed acyclic graphs (DAGs), wherein the one or more DAGs comprise information to generate the QR code;

receiving a first DAG from the server of the interaction provider;

generating a first portion of the QR code based on the first DAG;

adding the first portion of the QR code to the preliminary QR code to generate a first intermediate QR code;

displaying the first intermediate QR code; and

performing one or more recursion operations until the QR code is generated from the preliminary QR code, wherein performing each recursion operation comprises:

analyzing an identification feature of a current intermediate QR code to determine a new identification credential; and

in response to determining that the new identification credential matches the stored identification credential:

receiving a subsequent DAG from the server of the interaction provider;

generating a subsequent portion of the QR code based on the subsequent DAG;

adding the subsequent portion of the QR code to the current intermediate QR code to generate a subsequent intermediate QR code; and

displaying the subsequent intermediate QR code.

9. The method of claim 8 , further comprising:

in response to determining that the name of the corresponding service provider does not match the name of the desired service provider:

generating an alert indicating a potential security breach; and

displaying the alert.

10. The method of claim 8 , further comprising:

in response to determining that the identification credential does not match the stored identification credential:

generating an alert indicating a potential security breach; and

displaying the alert.

11. The method of claim 8 , further comprising:

in response to determining that the new identification credential does not match the stored identification credential:

generating an alert indicating a potential security breach; and

displaying the alert.

12. The method of claim 8 , further comprising:

in response to determining that all DAGs are received from the server of the interaction provider:

displaying the QR code; and

in response to determining that the QR code corresponds to the DAGs received from the server of the interaction provider, performing the interaction based on the QR code.

13. The method of claim 12 , further comprising:

in response to determining that the QR code does not correspond to the DAGs received from the server of the interaction provider:

generating an alert indicating a potential security breach; and

displaying the alert.

14. The method of claim 8 , wherein the first DAG is different from the subsequent DAG.

15. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

capture a preliminary quick response (QR) code displayed by a device of a desired service provider, wherein the preliminary QR code has a substantially blank region and comprises an identification feature of the desired service provider, the identification feature configured to identify the desired service provider to an interaction provider;

display the preliminary QR code;

analyze the identification feature to determine a name of a corresponding service provider;

in response to determining that the name of the corresponding service provider matches a name of the desired service provider, analyze the identification feature to determine an identification credential of the desired service provider and information of the interaction provider; and

in response to determining that the identification credential matches a stored identification credential stored in a server of the interaction provider:

request a QR code from the server of the interaction provider to perform an interaction requested by the desired service provider;

generate one or more directed acyclic graphs (DAGs), wherein the one or more DAGs comprise information to generate the QR code;

receive a first DAG from the server of the interaction provider;

generate a first portion of the QR code based on the first DAG;

add the first portion of the QR code to the preliminary QR code to generate a first intermediate QR code;

display the first intermediate QR code; and

perform one or more recursion operations until the QR code is generated from the preliminary QR code, wherein performing each recursion operation comprises:

analyzing an identification feature of a current intermediate QR code to determine a new identification credential; and

in response to determining that the new identification credential matches the stored identification credential:

receiving a subsequent DAG from the server of the interaction provider;

generating a subsequent portion of the QR code based on the subsequent DAG;

adding the subsequent portion of the QR code to the current intermediate QR code to generate a subsequent intermediate QR code; and

displaying the subsequent intermediate QR code.

16. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

in response to determining that the name of the corresponding service provider does not match the name of the desired service provider:

generate an alert indicating a potential security breach; and

display the alert.

17. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

in response to determining that the identification credential does not match the stored identification credential:

generate an alert indicating a potential security breach; and

display the alert.

18. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

in response to determining that the new identification credential does not match the stored identification credential:

generate an alert indicating a potential security breach; and

display the alert.

19. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

in response to determining that all DAGs are received from the server of the interaction provider:

display the QR code; and

in response to determining that the QR code corresponds to the DAGs received from the server of the interaction provider, perform the interaction based on the QR code.

20. The non-transitory computer-readable medium of claim 19 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

in response to determining that the QR code does not correspond to the DAGs received from the server of the interaction provider:

generate an alert indicating a potential security breach; and

display the alert.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2023
From: GUPTA, SAURABH
To: BANK OF AMERICA CORPORATION
Reel/Frame 063871/0058 →
Continuity (1)
Related Publication 20240411870A1 · Dec 12, 2024
References Cited (19)
US 8645270B2 · Mallean et al. · 2014 [cited by applicant]
US 9009818B2 · Tuvell et al. · 2015 [cited by applicant]
US 9058607B2 · Ganti et al. · 2015 [cited by applicant]
US 9633325B2 · Bolene et al. · 2017 [cited by applicant]
US 9811848B2 · Reuss et al. · 2017 [cited by applicant]
US 10089606B2 · Ihm et al. · 2018 [cited by applicant]
US 10153906B2 · Sweet et al. · 2018 [cited by applicant]
US 10163137B2 · Hoffberg · 2018 [cited by applicant]
US 10402792B2 · Lin et al. · 2019 [cited by applicant]
US 10762477B2 · Finch et al. · 2020 [cited by applicant]
US 10970274B2 · Bisbee et al. · 2021 [cited by applicant]
US 11074218B2 · Faith et al. · 2021 [cited by applicant]
US 11232452B2 · Ivey et al. · 2022 [cited by applicant]
US 11301554B2 · Law · 2022 [cited by examiner]
US 20170103399A1 · Napsky et al. · 2017 [cited by applicant]
US 20200167620A1 · Lin · 2020 [cited by examiner]
US 20210044976A1 · Avetisov · 2021 [cited by examiner]
US 20220217121A1 · Devarajan et al. · 2022 [cited by applicant]
WO WO2022010369A1 · 2022 [cited by examiner]