IP Library › Granted Patent US 12,417,582
Granted Patent B2
US 12,417,582 · App. 18/473,798 · Granted Sep 16, 2025

System and method for verifying user interactions in an extended reality environment

Inventor: Vijay Kumar Yarabolu (Hyderabad, IN)
Assignee: Bank of America Corporation
G06T17/00G06F3/012G06F3/013G06F3/014H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,582
App. No.
18/473,798
Filed
Sep 25, 2023
Granted
Sep 16, 2025
Kind
B2
Art Unit
2621
USPC
345/419
Abstract

A method includes rendering, on displays of an extended reality (XR) device, an XR environment, detecting a sequence of user interactions with an XR application, and identifying, based on the sequence of user interactions with the XR application and the user identification, a historical user interaction data associated with a user. The method further includes generating a first trust token based on the identified historical user interaction data, and receiving an interaction to finalize execution of the sequence of user interactions. In response, the method includes accessing a second trust token associated with the XR application, comparing the first trust token with the second trust token, validating the second trust token based on the comparison, validating each user interaction of the sequence of user interactions based on the identified historical user interaction data, and finalizing execution of the sequence of user interactions in response to the validations.

Claims (65)

1. A system, comprising:

a memory configured to store a user identification for a user, image data utilized to render an extended reality (XR) environment on an XR device associated with the user, and a plurality of XR applications executable within the XR environment; and

one or more processors operably coupled to the memory and configured to:

render, on one or more displays of the XR device, the XR environment, wherein the XR environment is configured to facilitate user interactions with the plurality of XR applications while executing within the XR environment;

detect, based on sensor data obtained from one or more sensors of the XR device, a sequence of user interactions with at least one XR application of the plurality of XR applications;

identify, based at least in part upon the sequence of user interactions with the at least one XR application and the user identification, a historical user interaction data associated with the user;

generate a first trust token based on the identified historical user interaction data; and

receive an interaction to finalize execution of the sequence of user interactions, and, in response:

access a second trust token associated with the at least one XR application;

compare the first trust token with the second trust token;

validate the second trust token based at least in part upon the comparison of the first trust token with the second trust token;

validate each user interaction of the sequence of user interactions based at least in part upon the identified historical user interaction data; and

in response to validating the second trust token and the user interactions of the sequence of user interactions, finalize execution of the sequence of user interactions.

2. The system of claim 1 , wherein the one or more processors are configured to identify the historical user interaction data by deriving a relational graph based on the sequence of user interactions with the at least one XR application and the user identification.

3. The system of claim 2 , wherein the derived relational graph comprises a plurality of nodes each corresponding to a respective one of the sequence of user interactions with the at least one XR application, and wherein a final node of the derived relational graph corresponds to the interaction to finalize execution of the sequence of user interactions.

4. The system of claim 1 , wherein the one or more processors are further configured to:

determine, based on the sensor data, one or more device-specific patterns associated with the XR device; and

generate the first trust token based on the identified historical user interaction data and the one or more device-specific patterns.

5. The system of claim 1 , wherein the one or more processors are further configured to:

receive, from the at least one XR application, the second trust token, wherein the second trust token comprises an access token configured to permit access to an application programming interface (API) associated with the at least one XR application; and

validate the second trust token based at least in part upon whether the first trust token matches to the second trust token.

6. The system of claim 1 , wherein the one or more processors are configured to finalize execution of the sequence of user interactions by causing the at least one XR application to execute a predetermined action.

7. The system of claim 1 , wherein the identified historical user interaction data comprises one or more of a head pose pattern of the user, an eye gaze pattern of the user, a hand gesture pattern of the user, a body movement pattern of the user, or a clickstream of the user.

8. A method, comprising:

rendering, on one or more displays of an extended reality (XR) device associated with a user, an XR environment, wherein the XR environment is configured to facilitate user interactions with a plurality of XR applications while executing within the XR environment;

detecting, based on sensor data obtained from one or more sensors of the XR device, a sequence of user interactions with at least one XR application of the plurality of XR applications;

identifying, based at least in part upon the sequence of user interactions with the at least one XR application and a user identification, a historical user interaction data associated with the user;

generating a first trust token based on the identified historical user interaction data; and

receiving an interaction to finalize execution of the sequence of user interactions, and, in response:

accessing a second trust token associated with the at least one XR application;

comparing the first trust token with the second trust token;

validating the second trust token based at least in part upon the comparison of the first trust token with the second trust token;

validating each user interaction of the sequence of user interactions based at least in part upon the identified historical user interaction data; and

in response to validating the second trust token and the user interactions of the sequence of user interactions, finalizing execution of the sequence of user interactions.

9. The method of claim 8 , wherein identifying the historical user interaction data comprises deriving a relational graph based on the sequence of user interactions with the at least one XR application and the user identification.

10. The method of claim 9 , wherein the derived relational graph comprises a plurality of nodes each corresponding to a respective one of the sequence of user interactions with the at least one XR application, and wherein a final node of the derived relational graph corresponds to the interaction to finalize execution of the sequence of user interactions.

11. The method of claim 8 , further comprising:

determining, based on the sensor data, one or more device-specific patterns associated with the XR device; and

generating the first trust token based on the identified historical user interaction data and the one or more device-specific patterns.

12. The method of claim 8 , further comprising:

receiving, from the at least one XR application, the second trust token, wherein the second trust token comprises an access token configured to permit access to an application programming interface (API) associated with the at least one XR application; and

validating the second trust token based at least in part upon whether the first trust token matches to the second trust token.

13. The method of claim 8 , wherein finalizing execution of the sequence of user interactions comprises causing the at least one XR application to execute a predetermined action.

14. The method of claim 8 , wherein the identified historical user interaction data comprises one or more of a head pose pattern of the user, an eye gaze pattern of the user, a hand gesture pattern of the user, a body movement pattern of the user, or a clickstream of the user.

15. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a system, cause the one or more processors to:

render, on one or more displays of an extended reality (XR) device associated with a user, an XR environment, wherein the XR environment is configured to facilitate user interactions with a plurality of XR applications while executing within the XR environment;

detect, based on sensor data obtained from one or more sensors of the XR device, a sequence of user interactions with at least one XR application of the plurality of XR applications;

identify, based at least in part upon the sequence of user interactions with the at least one XR application and a user identification, a historical user interaction data associated with the user;

generate a first trust token based on the identified historical user interaction data;

access a second trust token associating with the at least one XR application based at least in part upon; and

receive an interaction to finalize execution of the sequence of user interactions, and, in response:

access a second trust token associated with the at least one XR application;

compare the first trust token with the second trust token;

validate the second trust token based at least in part upon the comparison of the first trust token with the second trust token;

validate each user interaction of the sequence of user interactions based at least in part upon the identified historical user interaction data; and

in response to validating the second trust token and the user interactions of the sequence of user interactions, finalize execution of the sequence of user interactions.

16. The non-transitory computer-readable medium of claim 15 , wherein the instructions to identify the historical user interaction data further cause the one or more processors to derive a relational graph based on the sequence of user interactions with the at least one XR application and the user identification.

17. The non-transitory computer-readable medium of claim 16 , wherein the derived relational graph comprises a plurality of nodes each corresponding to a respective one of the sequence of user interactions with the at least one XR application, and wherein a final node of the derived relational graph corresponds to the interaction to finalize execution of the sequence of user interactions.

18. The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the one or more processors to:

determine, based on the sensor data, one or more device-specific patterns associated with the XR device; and

generate the first trust token based on the identified historical user interaction data and the one or more device-specific patterns.

19. The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the one or more processors to:

receive, from the at least one XR application, the second trust token, wherein the second trust token comprises an access token configured to permit access to an application programming interface (API) associated with the at least one XR application; and

validate the second trust token based at least in part upon whether the first trust token matches to the second trust token.

20. The non-transitory computer-readable medium of claim 15 , wherein the identified historical user interaction data comprises one or more of a head pose pattern of the user, an eye gaze pattern of the user, a hand gesture pattern of the user, a body movement pattern of the user, or a clickstream of the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2023
From: YARABOLU, VIJAY KUMAR
To: BANK OF AMERICA CORPORATION
Reel/Frame 065012/0431 →
Continuity (1)
Related Publication 20250104341A1 · Mar 27, 2025
References Cited (27)
US 8527640B2 · Reisman · 2013 [cited by applicant]
US 10164985B2 · Turgeman · 2018 [cited by applicant]
US 10395018B2 · Turgeman · 2019 [cited by applicant]
US 10586036B2 · Turgeman · 2020 [cited by applicant]
US 10904246B2 · Chari · 2021 [cited by applicant]
US 11049082B2 · Rice · 2021 [cited by applicant]
US 11151234B2 · Kontsevich et al. · 2021 [cited by applicant]
US 11330012B2 · Turgeman · 2022 [cited by applicant]
US 11470161B2 · Senftleber et al. · 2022 [cited by applicant]
US 11546331B2 · Senftleber et al. · 2023 [cited by applicant]
US 11601398B2 · Senftleber et al. · 2023 [cited by applicant]
US 11657815B2 · Tran et al. · 2023 [cited by applicant]
US 20170346851A1 · Drake · 2017 [cited by applicant]
US 20180115551A1 · Cole · 2018 [cited by applicant]
US 20180129276A1 · Nguyen et al. · 2018 [cited by applicant]
US 20210226952A1 · Senftleber et al. · 2021 [cited by applicant]
US 20210279695A1 · Rice · 2021 [cited by applicant]
US 20220050983A1 · Spivack · 2022 [cited by applicant]
US 20220247678A1 · Atwal et al. · 2022 [cited by applicant]
US 20230360007A1 · Krishnaswamy · 2023 [cited by examiner]
US 20230403152A1 · Feijoo · 2023 [cited by examiner]
US 20240143721A1 · Naik · 2024 [cited by examiner]
US 20240211910A1 · Lal · 2024 [cited by examiner]
Deb Radcliff; “The metaverse brings new breed of threats to challenge privacy and security gatekeepers;” CSO; https://www.csoonline.com/article/3686052/the-metaverse-brings-a-new-breed-of-threats-to-challenge-privacy-an… [cited by applicant]
Security; “9 security threats in the metaverse;” https://www.securitymagazine.com/articles/98142-9-security-threats-in-the-metaverse; Aug. 10, 2022. [cited by applicant]
Ashwin Krishnan; “Top metaverse cybersecurity challenges: How to address them;” Tech Target; https://www.techtarget.com/searchsecurity/tip/Top-metaverse-cybersecurity-challenges-to-consider; Nov. 18, 2022. [cited by applicant]
Ramprakash Ramamoorthy, Zoho Corporation; “Why the metaverse is filled with security, privacy and safety issues;” https://venturebeat.com/security/why-the-metaverse-is-filled-with-security-privacy-and-safety-issues/; Se… [cited by applicant]