IP Library Granted Patent US 12,658,192
Granted Patent B1
US 12,658,192 · App. 19/174,905 · Granted Jun 16, 2026

Systems and methods for user-to-user authentication

Inventors: Jassem Shakil (New York, NY); Christian Adam (New York, NY); David Pollino (New York, NY)
Assignee: The Bank of New York Mellon
G10L17/24H04L9/3231
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,658,192
App. No.
19/174,905
Granted
Jun 16, 2026
Kind
B1
Abstract

Systems and method for user-to-user authentication for secured communications are described. For example, the system may receive, from a first user, a first user request to identify a second user, wherein the first user request indicates a first network action requiring an identify confirmation of the second user. The system may, in response to the first user request, determine a first identifier for the second user based on user information for the second user, determine a first secured token, wherein the first secured token comprises a first secured token type of a plurality of secured token types, determine a first secured token requirement for the first secured token based on the first secured token type, wherein the first secured token requirement comprises a playback characteristic of the first secured token, and compare the first secured token to the first secured token requirement.

Claims (77)

1 . A system for user-to-user authentication for cryptographically secured communications across encrypted computer networks, the system comprising:

one or more processors; and

one or more non-transitory, computer-readable media, comprising instructions that, when executed by the one or more processors, cause operations comprising:

generating a first cryptographically secured session between a first user and a second user;

during the first cryptographically secured session, receiving, from the first user, a first user request to identify the second user, wherein the first user request indicates a first network action requiring an identify confirmation of the second user;

in response to the first user request:

determining a first identifier for the second user based on user information for the second user;

determining a first secured token, wherein the first secured token comprises a first secured token type of a plurality of secured token types;

determining a first secured token requirement for the first secured token based on the first secured token type; and

comparing the first secured token to the first secured token requirement; and

in response to comparing the first secured token to the first secured token requirement, generating a first encrypted communication package for transmitting to the second user based on the first identifier and the first secured token, wherein the first encrypted communication package identifies the second user by:

generating a prompt requesting the second user regenerate the first secured token;

causing the second user to submit a second secured token comprising a required playback characteristic in response to the prompt; and

generating a second encrypted communication package for transmission, via the first cryptographically secured session, to the first user comprising the second secured token.

2 . A method for user-to-user authentication for secured communications, the method comprising:

receiving, from a first user, a first user request to identify a second user, wherein the first user request indicates a first network action requiring an identify confirmation of the second user;

in response to the first user request:

determining a first identifier for the second user based on user information for the second user;

determining a first secured token, wherein the first secured token comprises a first secured token type of a plurality of secured token types;

determining a first secured token requirement for the first secured token based on the first secured token type, wherein the first secured token requirement comprises a playback characteristic of the first secured token; and

comparing the first secured token to the first secured token requirement; and

in response to comparing the first secured token to the first secured token requirement, generating a first communication package for transmitting to the second user based on the first identifier and the first secured token, wherein the first communication package identifies the second user by:

generating a prompt requesting the second user regenerate the first secured token;

causing the second user to submit a second secured token comprising a required playback characteristic in response to the prompt; and

generating a second communication package for transmission to the first user comprising the second secured token.

3 . The method of claim 2 , wherein the first communication package identifies the second user by:

comparing the first secured token to the second secured token.

4 . The method of claim 2 , wherein determining the first identifier for the second user based on the user information for the second user further comprises:

receiving the user information in the first user request; and

extracting the user information from the first user request.

5 . The method of claim 2 , wherein determining the first identifier for the second user based on the user information for the second user further comprises:

accessing a user profile for the second user; and

extracting the user information from the user profile.

6 . The method of claim 2 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required number of pitch variations to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining a number of pitch variations in the passphrase; and

comparing the number of pitch variations to the required number of pitch variations.

7 . The method of claim 2 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required timbre characteristic to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining a timbre characteristic for the passphrase; and

comparing the timbre characteristic to the required timbre characteristic.

8 . The method of claim 2 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required phonetic characteristic to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining a phonetic characteristic for the passphrase; and

comparing the phonetic characteristic to the required phonetic characteristic.

9 . The method of claim 2 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required acoustic characteristic to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining an acoustic characteristic for the passphrase; and

comparing the acoustic characteristic to the required acoustic characteristic.

10 . The method of claim 2 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required audio waveform pattern to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining an audio waveform pattern for the passphrase; and

comparing the audio waveform pattern to the required audio waveform pattern.

11 . The method of claim 2 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required passphrase length to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining a passphrase length for the passphrase; and

comparing the passphrase length to the required passphrase length.

12 . The method of claim 2 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required keyword to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining a keyword for the passphrase; and

comparing the keyword to the required keyword.

13 . The method of claim 2 , wherein determining the first secured token further comprises:

receiving a requested network action in the first user request; and

selecting the first secured token type from the plurality of secured token types based on the requested network action.

14 . One or more non-transitory, computer-readable media, comprising instructions that, when executed by one or more processors, cause operations comprising:

generating a first secured session between a first user and a second user;

during the first secured session, receiving, from the first user, a first communication package for identifying the second user, wherein the first communication package comprises a prompt requesting the second user regenerate a first secured token, wherein the first secured token is a first secured token type of a plurality of secured token types, and wherein the first secured token meets a first secured token requirement for the first secured token type, wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required number of pitch variations to secure the passphrase, and wherein meeting the first secured token requirement comprises:

determining a number of pitch variations in the passphrase; and

comparing the number of pitch variations to the required number of pitch variations;

receiving a user submission of a second secured token in response to the prompt;

generating a second communication package based on the user submission; and

transmitting the second communication package to the first user.

15 . The one or more non-transitory, computer-readable media of claim 14 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required timbre characteristic to secure the passphrase, and wherein meeting the first secured token requirement comprises:

determining a timbre characteristic for the passphrase; and

comparing the timbre characteristic to the required timbre characteristic.

16 . The one or more non-transitory, computer-readable media of claim 14 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required phonetic characteristic to secure the passphrase, and wherein meeting the first secured token requirement comprises:

determining a phonetic characteristic for the passphrase; and

comparing the phonetic characteristic to the required phonetic characteristic.

17 . The one or more non-transitory, computer-readable media of claim 14 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required acoustic characteristic to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining an acoustic characteristic for the passphrase; and

comparing the acoustic characteristic to the required acoustic characteristic.

18 . The one or more non-transitory, computer-readable media of claim 14 , wherein the first secured token is a passphrase required to be spoken by the second user, wherein the first secured token requirement comprises a required audio waveform pattern to secure the passphrase, and wherein comparing the first secured token to the first secured token requirement further comprises:

determining an audio waveform pattern for the passphrase; and

comparing the audio waveform pattern to the required audio waveform pattern.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2026
From: SHAKIL, JASSEM; POLLINO, DAVID; ADAM, CHRISTIAN
To: THE BANK OF NEW YORK MELLON
Reel/Frame 073650/0619 →
References Cited (11)
US 8463705B2 · Joshi et al. · 2013 [cited by applicant]
US 9692758B2 · Zeljkovic et al. · 2017 [cited by applicant]
US 10110608B2 · Dureau · 2018 [cited by applicant]
US 12248545B1 · Bell · 2025 [cited by examiner]
US 20110276323A1 · Seyfetdinov · 2011 [cited by examiner]
US 20160275952A1 · Kashtan · 2016 [cited by examiner]
US 20180308501A1 · Johnson · 2018 [cited by examiner]
US 20190327448A1 · Fu · 2019 [cited by examiner]
US 20220036905A1 · Keith · 2022 [cited by applicant]
US 20220164801A1 · Bruno · 2022 [cited by applicant]
US 20250225520A1 · May · 2025 [cited by examiner]