IP Library Granted Patent US 12,387,201
Granted Patent B2
US 12,387,201 · App. 17/856,097 · Granted Aug 12, 2025

Multi-factor user authentication using blockchain tokens

Inventors: Harish Tammaji Kulkarni (Singapore, SG); Kumudini Choyal (Tung Chung, HK); Min Cao (Singapore, SG); Nhat Minh Nguyen (Singapore, SG); Ra Uf Ridzuan Bin Ma Arof (Singapore, SG); Surendran Surendran (Singapore, SG)
Assignee: Bank of America Corporation
G06Q20/3823G06Q20/3827G06Q20/389G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,387,201
App. No.
17/856,097
Granted
Aug 12, 2025
Kind
B2
Abstract

Aspects of the disclosure relate to multi-factor user authentication for card-based payment transactions using blockchain tokens. An computing platform may receive, from a computing device, transaction details associated with a card-based payment transaction corresponding to a user, wherein the transaction details comprise a card number of a payment card. The computing platform may determine, based on the card number, a user device associated with the user. The computing platform may send, to the user device, a one-time passcode (OTP). After sending the OTP, the computing platform may receive a security key. The security key may be generated based on the sent OTP and a blockchain token hash. The computing platform may, based on the received security key, send, to the computing device, a message indicating whether the transaction is approved or declined.

Claims (55)

1. A computing platform, comprising:

one or more processors;

a communication interface communicatively coupled to the one or more processors; and

memory storing computer-readable instructions that, when executed by the one or more processors, cause the computing platform to:

receive, from a user device associated with a user, a blockchain token hash;

receive, from a computing device, transaction details associated with a card-based payment transaction corresponding to the user, wherein the transaction details comprise a card number of a payment card;

determine, based on the card number, the user device associated with the user;

send, to the user device, a one-time passcode (OTP);

after sending the OTP, receive a security key including the OTP and blockchain token hash and having a pattern placing characters of the OTP and the blockchain token hash based on one or more predefined rules identifying the pattern and set at a time of the card-based payment transaction associated with the transaction details, wherein the security key is generated by the user device associated with the user;

extract, from the security key, the OTP and blockchain token hash;

validate the extracted OTP and blockchain token hash; and

based on validating both the extracted OTP and the blockchain token hash, send, to the computing device, a message indicating whether the card-based payment transaction associated with the transaction details is approved or declined.

2. The computing platform of claim 1 , wherein the blockchain token hash is generated based on information associated with: the user, the user device, and the payment card.

3. The computing platform of claim 1 , wherein the one or more rules are set by a payment gateway device.

4. The computing platform of claim 3 , wherein the pattern placing the characters of the OTP and blockchain token hash to generate the security key includes interleaving the OTP and the blockchain token hash.

5. The computing platform of claim 1 , wherein the placing the characters of the OTP and blockchain token hash to generate the security key includes appending the blockchain token hash to the OTP.

6. The computing platform of claim 1 , wherein the pattern placing the characters of the OTP and blockchain token hash to generate the security key includes prepending the blockchain token hash to the OTP.

7. The computing platform of claim 1 , wherein the message indicates that the transaction is approved based on:

the OTP provided in the security key matching the sent OTP, and

the blockchain token hash provided in the security key matching a blockchain token hash, corresponding to the user, stored at a predetermined number of nodes associated with a plurality of card networks.

8. The computing platform of claim 1 , wherein the message indicates that the transaction is declined based on one or more of:

the OTP provided in the security key not matching the sent OTP; or

the blockchain token hash provided in the security key not matching a blockchain token hash, corresponding to the user, stored at a predetermined number of nodes associated with a plurality of card networks.

9. The computing platform of claim 1 , wherein the payment card is a credit card or a debit card.

10. The computing platform of claim 1 , wherein the user device is a mobile communication device.

11. The computing platform of claim 1 , wherein receiving the security key comprises receiving the security key via the user device.

12. A method comprising:

receiving, from a user device associated with a user, a blockchain token hash;

receiving, from a computing device, transaction details associated with a card-based payment transaction corresponding to the user, wherein the transaction details comprise a card number of a payment card;

determining, based on the card number, the user device associated with the user;

sending, to the user device, a one-time passcode (OTP);

after sending the OTP, receiving a security key including the OTP and blockchain token hash and having a pattern placing characters of the OTP and the blockchain token hash based on one or more predefined rules identifying the pattern and set at a time of the card-based payment transaction associated with the transaction details, wherein the security key is generated by the user device associated with the user;

extract, from the security key, the OTP and blockchain token hash;

validate the extracted OTP and blockchain token hash; and

based on validating both the extracted OTP and the blockchain token hash, sending, to the computing device, a message indicating whether the card-based payment transaction associated with the transaction details is approved or declined.

13. The method of claim 12 , wherein the blockchain token hash is generated based on information associated with: the user, the user device, and the payment card.

14. The method of claim 12 , wherein the one or more rules are set by a payment gateway device.

15. The method of claim 14 , wherein the pattern placing the characters of the OTP and blockchain token hash to generate the security key includes interleaving the OTP and the blockchain token hash.

16. The method of claim 12 , wherein the pattern placing the characters of the OTP and blockchain token hash to generate the security key includes appending the blockchain token hash to the OTP.

17. The method of claim 12 , wherein the pattern placing the characters of the OTP and blockchain token hash to generate the security key includes prepending the blockchain token hash to the OTP.

18. The method of claim 12 , wherein the message indicates that the transaction is approved based on:

the OTP provided in the security key matching the sent OTP, and

the blockchain token hash provided in the security key matching a blockchain token hash, corresponding to the user, stored at a predetermined number of nodes associated with a plurality of card networks.

19. The method of claim 12 , wherein the message indicates that the transaction is declined based on one or more of:

the OTP provided in the security key not matching the sent OTP; or

the blockchain token hash provided in the security key not matching a blockchain token hash, corresponding to the user, stored at a predetermined number of nodes associated with a plurality of card networks.

20. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

receive, from a user device associated with a user, a blockchain token hash;

receive, from a computing device, transaction details associated with a card-based payment transaction corresponding to the user, wherein the transaction details comprise a card number of a payment card;

determine, based on the card number, the user device associated with the user;

send, to the user device, a one-time passcode (OTP);

after sending the OTP, receive a security key including the OTP and blockchain token hash and having a pattern placing characters of the OTP and the blockchain token hash based on one or more predefined rules identifying the pattern and set at a time of the card-based payment transaction associated with the transaction details, wherein the security key is generated by the user device associated with the user;

extract, from the security key, the OTP and blockchain token hash;

validate the extracted OTP and blockchain token hash; and

based on validating both the extracted OTP and the blockchain token hash, send, to the computing device, a message indicating whether the card-based payment transaction associated with the transaction details is approved or declined.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: KULKARNI, HARISH TAMMAJI; CHOYAL, KUMUDINI; CAO, MIN; NGUYEN, NHAT MINH; RIDZUAN BIN MA AROF, RA UF; SURENDRAN, SURENDRAN
To: BANK OF AMERICA CORPORATION
Reel/Frame 060422/0080 →
Continuity (1)
Related Publication 20240005312A1 · Jan 4, 2024
References Cited (43)
US 9137228B1 · Newstadt · 2015 [cited by examiner]
US 9172698B1 · Evans · 2015 [cited by examiner]
US 10043174B1 · Chikkanna · 2018 [cited by examiner]
US 10148629B1 · Roth · 2018 [cited by examiner]
US 11310052B1 · Keogh · 2022 [cited by examiner]
US 20150324789A1 · Dvorak et al. · 2015 [cited by applicant]
US 20160261411A1 · Yau · 2016 [cited by examiner]
US 20180047014A1 · Maus et al. · 2018 [cited by applicant]
US 20180176222A1 · Bhaskar · 2018 [cited by examiner]
US 20180219861A1 · Schultz et al. · 2018 [cited by applicant]
US 20190034612A1 · Smales · 2019 [cited by examiner]
US 20190044942A1 · Gordon et al. · 2019 [cited by applicant]
US 20190140844A1 · Brown et al. · 2019 [cited by applicant]
US 20200014528A1 · Nandakumar et al. · 2020 [cited by applicant]
US 20200026834A1 · Vimadalal et al. · 2020 [cited by applicant]
US 20200052899A1 · Finlow-Bates · 2020 [cited by applicant]
US 20200058021A1 · Mittal · 2020 [cited by examiner]
US 20200084018A1 · Pande · 2020 [cited by examiner]
US 20200127813A1 · Millar et al. · 2020 [cited by applicant]
US 20200195437A1 · Gallagher et al. · 2020 [cited by applicant]
US 20200244441A1 · Madineni · 2020 [cited by examiner]
US 20200244652A1 · Iyer et al. · 2020 [cited by applicant]
US 20200279235A1 · Booth et al. · 2020 [cited by applicant]
US 20200364711A1 · Sarin · 2020 [cited by examiner]
US 20200366671A1 · Larson et al. · 2020 [cited by applicant]
US 20210014064A1 · Channa et al. · 2021 [cited by applicant]
US 20210105271A1 · Nitturkar et al. · 2021 [cited by applicant]
US 20210133750A1 · Leddy, III · 2021 [cited by applicant]
US 20210241270A1 · Raevsky et al. · 2021 [cited by applicant]
US 20210256511A1 · Peacemaker et al. · 2021 [cited by applicant]
US 20210314143A1 · Conner · 2021 [cited by examiner]
US 20210344502A1 · Purves · 2021 [cited by applicant]
US 20210399894A1 · Gallagher et al. · 2021 [cited by applicant]
US 20210409195A1 · Kim · 2021 [cited by examiner]
US 20220114245A1 · Krishan · 2022 [cited by applicant]
WO WO2012005744A1 · 2012 [cited by examiner]
WO WO2017080755A1 · 2017 [cited by examiner]
WO WO2022154051A1 · 2022 [cited by examiner]
Schneier, Bruce “Applied Cryptography Second Edition : protocols, algorithms, and source code in C” ISBN 0-471-12845-7, pp. 34-41 (Year: 1996). [cited by examiner]
Buccafurri et al., “Securing MQTT by Blockchain-Based OTP Authentication,” Sensors (Basel), Apr. 3, 2020;20(7):2002. doi: 10.3390/s20072002. PMID: 32260049; PMCID: PMC7180730. (Year: 2020). [cited by examiner]
M. Zhang, L. Wang and J. Yang, “A Blockchain-Based Authentication Method with One-Time Password,” 2019 IEEE 38th International Performance Computing and Communications Conference (IPCCC), London, UK, 2019, pp. 1-9, doi:… [cited by examiner]
W.-S. Park, D.-Y. Hwang and K.-H. Kim, ““A TOTP-Based Two Factor Authentication Scheme for Hyperledger Fabric Blockchain,”” 2018 Tenth International Conference on Ubiquitous and Future Networks (ICUFN), Prague, Czech Re… [cited by examiner]
Machine Translation of Foreign Patent Document WO2022154051A1 (Year: 2022). [cited by examiner]
Cited By (1)
US 12,585,740