IP Library Granted Patent US 12,445,486
Granted Patent B2
US 12,445,486 · App. 17/714,261 · Granted Oct 14, 2025

Preventing phishing attempts of one-time passwords

Inventor: Manbinder Pal Singh (Coral Springs, FL)
H04L63/1483H04L63/0838H04L63/126H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,486
App. No.
17/714,261
Granted
Oct 14, 2025
Kind
B2
Abstract

A computer system is provided. The computer system includes a memory and at least one processor coupled to the memory and configured to identify a first domain name associated with a website that served a login form to a web browser. The at least one processor is further configured to identify a one-time password (OTP) entry request served from the website in response to transmitting user credentials to the website. The at least one processor is further configured to identify a second domain name associated with an OTP server that provided an OTP. The at least one processor is further configured to perform a security action in response to determining that the first domain name differs from the second domain name. The security action may include blocking a response to the OTP request from the website, providing a warning, and/or obtaining confirmation for the response to the OTP entry request.

Claims (30)

1. A computer system comprising:

a memory; and

at least one processor coupled to the memory and configured to:

identify a first domain name associated with a website that served a login form for entering user credentials to a web browser;

identify a one-time password (OTP) entry request served from the website in response to transmitting the user credentials to the website;

identify a second domain name associated with an OTP server that provided an OTP corresponding to the OTP entry request;

determine that the first domain name differs from the second domain name; and

perform a security action in response to the determination.

2. The computer system of claim 1 , wherein the security action comprises blocking a response to the OTP entry request from the website.

3. The computer system of claim 1 , wherein the security action comprises providing a warning and obtaining confirmation for the response to the OTP entry request from the website.

4. The computer system of claim 1 , wherein the at least one processor is further configured to receive the OTP from the OTP server through a Short Message Service (SMS) text message.

5. The computer system of claim 1 , wherein the computer system is a first client device and the at least one processor is further configured to receive the OTP from a second client device, wherein the OTP is sent to the second client device as an SMS text message from the OTP server.

6. The computer system of claim 1 , wherein the at least one processor is further configured to receive the OTP through an email from the OTP server.

7. The computer system of claim 1 , wherein the at least one processor is further configured to provide credentials entered into the login form to the to the website to trigger the OTP entry request.

8. The computer system of claim 1 , wherein the at least one processor is further configured to analyze Hypertext Markup Language (HTML) input field labels to detect that the website served the login form and the OTP entry request to the web browser.

9. The computer system of claim 1 , wherein the at least one processor is further configured to perform computer vision analysis to detect that the website served the login form and the OTP entry request to the web browser.

10. A non-transitory computer readable medium storing executable sequences of instructions to provide protection against phishing of one-time passwords (OTPs), the sequences of instructions comprising instructions to:

identify a first domain name associated with a website that served a login form to a web browser for entering user credentials;

identify an OTP entry request served from the website in response to transmitting the user credentials to the website;

identify a second domain name associated with an OTP server that provided an OTP corresponding to the OTP entry request;

determine that the first domain name differs from the second domain name; and

perform a security action in response to the determination.

11. The computer readable medium of claim 10 , wherein the security action comprises blocking a response to the OTP entry request from the website.

12. The computer readable medium of claim 10 , wherein the security action comprises providing a warning and obtaining confirmation for the response to the OTP entry request from the website.

13. The computer readable medium of claim 10 , wherein the sequences of instructions further include instructions to receive the OTP from the OTP server through a Short Message Service (SMS) text message.

14. The computer readable medium of claim 10 , wherein the computer system is a first client device and the sequences of instructions further include instructions to receive the OTP from a second client device, wherein the OTP is sent to the second client device as an SMS text message from the OTP server.

15. The computer readable medium of claim 10 , wherein the sequences of instructions further include instructions to receive the OTP through an email from the OTP server.

16. The computer system of claim 1 , wherein the sequences of instructions further include instructions to provide credentials entered into the login form to the website to trigger the OTP entry request.

17. The computer readable medium of claim 10 , wherein the sequences of instructions further include instructions to analyze Hypertext Markup Language (HTML) input field labels to detect that the website served the login form and the OTP entry request to the web browser.

18. The computer readable medium of claim 10 , wherein the sequences of instructions further include instructions to perform computer vision analysis to detect that the website served the login form and the OTP entry request to the web browser.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2022
From: SINGH, MANBINDER PAL
To: CITRIX SYSTEMS, INC.
Reel/Frame 059587/0441 →
Continuity (2)
Continuation 17501582 · Oct 14, 2021
Related Publication 20230121470A1 · Apr 20, 2023
References Cited (10)
US 8776196B1 · Oliver · 2014 [cited by examiner]
US 8838973B1 · Yung · 2014 [cited by examiner]
US 9002750B1 · Chu · 2015 [cited by examiner]
US 9674213B2 · Oberheide · 2017 [cited by examiner]
US 20070067828A1 · Bychkov · 2007 [cited by applicant]
US 20180343562A1 · Nalukurthy · 2018 [cited by examiner]
US 20210144174A1 · N · 2021 [cited by examiner]
US 20210377300A1 · Devane · 2021 [cited by examiner]
Moholkar et al., An Efficient Approach for Phishing Website Detection using Visual Cryptography (VC) and Quick Response Code (QR Code), International Journal of Computer Applications (0975-8887) vol. 115—No. 12, Apr. 20… [cited by applicant]
Khan, Preventing Phishing Attacks using One Time Password and User Machine Identification, International Journal of Computer Applications (0975-8887) vol. 68—No. 3, Apr. 2013 (Year: 2013) 5 pages. [cited by applicant]