IP Library › Granted Patent US 12,476,951
Granted Patent B2
US 12,476,951 · App. 18/610,164 · Granted Nov 18, 2025

Delayed user authentication

Inventor: Rahul Nair (Leander, TX)
Assignee: PayPal, Inc.
H04L63/08H04L51/046H04W4/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,951
App. No.
18/610,164
Granted
Nov 18, 2025
Kind
B2
Abstract

Techniques are disclosed relating to a delayed presentation of authentication challenge for users, such as in the context of a chat session. In various embodiments, a server system receives an indication of a request for service initiated by a user in a chat session within an application executed by a client device. The request for service involves an authentication of the user that is dependent on the authentication being successfully completed within a particular time period after the authentication is initiated. The server system delays the initiation of authentication for the request for service until a readiness condition is satisfied. The readiness condition includes the server system being available to process the request for service, as well as subsequently detecting engagement with the user relating to the request for service. In response to the readiness condition being satisfied, the server system initiates the authentication of the user.

Claims (41)

1 . A system, comprising:

a non-transitory memory; and

one or more hardware processors coupled to the non-transitory memory and configured to read instructions from the non-transitory memory to cause the system to perform operations comprising:

receiving an indication of a request for service initiated by a user, wherein the request for service involves an authentication of the user, and wherein the authentication is dependent on an authentication challenge at a computing device of the user being successfully completed within a particular time period after the authentication is initiated;

upon receiving the indication of the request for service, making an initial determination regarding an authentication type to be initiated for authenticating the user; and

upon subsequently detecting engagement of the user, initiating the authentication of the user, within the particular time period, based on the engagement of the user and the authentication type.

2 . The system of claim 1 , wherein the authentication type of the initial determination is a first authentication type corresponding to a first level of strictness.

3 . The system of claim 2 , wherein the operations further comprise:

upon subsequently detecting engagement of the user, making a final determination regarding the authentication type.

4 . The system of claim 3 , wherein the final determination selects a second authentication type distinct from the first authentication type, the second authentication type corresponding to a second level of strictness higher than the first level of strictness.

5 . The system of claim 3 , wherein the operations further comprise:

detecting, at the computing device of the user, an event relating to the user that occurred between the initial determination and the final determination, wherein the detection of the event triggers, at least in part, the making of the final determination regarding the authentication type.

6 . The system of claim 1 , wherein the operations further comprise:

determining a readiness condition for the request for service.

7 . The system of claim 6 , wherein the authentication of the user is initiated at least in part based on the readiness condition for the request for service.

8 . A method, comprising:

receiving, at a user device, an indication of a request for service initiated by a user, wherein the request for service involves an authentication of the user, wherein the authentication is dependent on an authentication factor at the user device being successfully completed within a particular time period after the authentication is initiated;

upon receiving the indication of the request for service, making an initial determination regarding an authentication type to be initiated for authenticating the user; and

upon subsequently detecting engagement of the user, initiating the authentication of the user, within the particular time period, based on the engagement of the user and the authentication type.

9 . The method of claim 8 , wherein the authentication type of the initial determination is a first authentication type corresponding to a first level of strictness.

10 . The method of claim 9 , further comprising:

upon subsequently detecting engagement of the user, making a final determination regarding the authentication type.

11 . The method of claim 10 , wherein the final determination selects a second authentication type distinct from the first authentication type, the second authentication type corresponding to a second level of strictness higher than the first level of strictness.

12 . The method of claim 10 , further comprising:

detecting, at the user device, an event relating to the user that occurred between the initial determination and the final determination, wherein the detection of the event triggers, at least in part, the making of the final determination regarding the authentication type.

13 . The method of claim 8 , further comprising:

determining a readiness condition for an application that received the request for service, and wherein the authentication of the user is initiated at least in part based on the readiness condition for the application.

14 . A non-transitory machine-readable medium having instructions stored thereon that are executed by a computer system to perform operations comprising:

receiving an indication of a request for service initiated by a user, wherein the request for service involves an authentication of the user, and wherein the authentication of the user is dependent on an authentication challenge at a device of the user being successfully completed within a particular time period after the authentication is initiated;

upon receiving the indication of the request for service, making an initial determination regarding an authentication type to be initiated for authenticating the user;

subsequently detecting engagement of the user with the device of the user; and

upon detecting the engagement of the user, initiating the authentication of the user, within the particular time period, based on the engagement of the user and the authentication type.

15 . The non-transitory machine-readable medium of claim 14 , wherein the authentication type of the initial determination is a first authentication type corresponding to a first level of strictness.

16 . The non-transitory machine-readable medium of claim 15 , wherein the operations further comprise:

upon subsequently detecting engagement of the user, making a final determination regarding the authentication type.

17 . The non-transitory machine-readable medium of claim 16 , wherein the final determination selects a second authentication type distinct from the first authentication type, the second authentication type corresponding to a second level of strictness higher than the first level of strictness.

18 . The non-transitory machine-readable medium of claim 16 , wherein the operations further comprise:

detecting, at the device of the user, an event relating to the user that occurred between the initial determination and the final determination, wherein the detection of the event triggers, at least in part, the making of the final determination regarding the authentication type.

19 . The non-transitory machine-readable medium of claim 14 , wherein the operations further comprise:

determining a readiness condition for an application that received the request for service.

20 . The non-transitory machine-readable medium of claim 19 , wherein the authentication of the user is initiated at least in part based on the readiness condition for the application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: NAIR, RAHUL
To: PAYPAL, INC.
Reel/Frame 067555/0520 →
Continuity (3)
Continuation 18123983 · Mar 21, 2023
Continuation 17066164 · Oct 8, 2020
Related Publication 20240348590A1 · Oct 17, 2024
References Cited (34)
US 8326759B2 · Hammad · 2012 [cited by applicant]
US 8751801B2 · Harris · 2014 [cited by examiner]
US 8973109B2 · Jillings · 2015 [cited by applicant]
US 9392456B2 · Disraeli et al. · 2016 [cited by applicant]
US 9519761B2 · Jakobsson · 2016 [cited by examiner]
US 9525587B2 · Aleksandrov et al. · 2016 [cited by applicant]
US 11063943B2 · Stoops et al. · 2021 [cited by applicant]
US 11533397B1 · Hansen et al. · 2022 [cited by applicant]
US 20070136303A1 · Singhai et al. · 2007 [cited by applicant]
US 20130139235A1 · Counterman · 2013 [cited by examiner]
US 20130268656A1 · Bott · 2013 [cited by applicant]
US 20140173450A1 · Akula · 2014 [cited by examiner]
US 20150193781A1 · Dave · 2015 [cited by examiner]
US 20150227728A1 · Grigg · 2015 [cited by examiner]
US 20150278504A1 · Azim · 2015 [cited by examiner]
US 20160036869A1 · Logan et al. · 2016 [cited by applicant]
US 20160050203A1 · Hefetz · 2016 [cited by applicant]
US 20160050393A1 · Mande et al. · 2016 [cited by applicant]
US 20160099892A1 · Palakovich et al. · 2016 [cited by applicant]
US 20170011393A1 · Hong · 2017 [cited by examiner]
US 20170041296A1 · Ford · 2017 [cited by examiner]
US 20170118223A1 · Mathew · 2017 [cited by examiner]
US 20180302861A1 · Zhao et al. · 2018 [cited by applicant]
US 20190102813A1 · O'Neill et al. · 2019 [cited by applicant]
US 20190141039A1 · Stoops et al. · 2019 [cited by applicant]
US 20200053096A1 · Bendersky et al. · 2020 [cited by applicant]
US 20200169629A1 · Zhao et al. · 2020 [cited by applicant]
US 20200220864A1 · Goodsitt · 2020 [cited by examiner]
US 20200288315A1 · Hanley et al. · 2020 [cited by applicant]
US 20200304542A1 · Ilincic et al. · 2020 [cited by applicant]
US 20230100148A1 · Lee et al. · 2023 [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/US2021/053547 mailed on Apr. 20, 2023, 11 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2021/053547 mailed on Jan. 11, 2022, 16 pages. [cited by applicant]
Extended European Search Report for European Application No. 21878351.2, mailed on Oct. 1, 2024, 9 pages. [cited by applicant]