IP Library › Granted Patent US 12,695,743
Granted Patent B2
US 12,695,743 · App. 18/784,410 · Granted Jul 28, 2026

Method and system for detecting two-factor authentication

Inventors: Michael Mossoba (Great Falls, VA); Joshua Edwards (Carrollton, TX); Jason Ji (Reston, VA); Ljubica Chatman (New York, NY); Carlos Eduardo Rodriguez (Fairfield, CT)
Assignee: Capital One Services, LLC
H04L63/083G06F9/547
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,695,743
App. No.
18/784,410
Filed
Jul 25, 2024
Granted
Jul 28, 2026
Kind
B2
Examiner
LI, MENG
Art Unit
2437
USPC
726/6
Abstract

Embodiments disclosed herein generally related to a system and method for assessing a fraud risk. In one embodiment, a method for assessing a fraud risk is disclosed herein. A web browser extension executing on the computing device identifies an account associated with the computing device. The web browser extension detects that the computing device navigated to a web page hosted by a third party server. The web browser extension determines that the third party server prompted the computing device to opt into two-factor authentication functionality. The web browser extension determines that the computing device did not opt into the two-factor authentication functionality. The web browser extension prompts, via an application programming interface (API), an organization computing system to update a fraud metric associated with the account.

Claims (70)

1 . A method comprising:

identifying, by a web browser extension executing on a client device, an account associated with the client device, wherein the account is managed by an organization computing system;

detecting, by the web browser extension, that the client device visited a web page hosted by a third party web server;

injecting, by the web browser extension and after detecting that the client device visited the web page, code into a script of the web page to enable the web browser extension to monitor whether the client device is engaged in multi-factor authentication, wherein the injected code runs side-by-side with the code in the script of the web page;

monitoring, by the web browser extension and via the injected code, the web page to identify one or more components of the web page;

detecting, by the web browser extension, one or more identifiers, on the one or more components of the web page, associated with the multi-factor authentication;

based on the detecting, determining, by the web browser extension, that the client device does not have a multi-factor authentication functionality enabled with the third party web server; and

prompting, by the web browser extension and via an application programming interface, the organization computing system to update a fraud metric associated with the account based on the determination that the client device does not have the multi-factor authentication functionality enabled with the third party web server, wherein the update to the fraud metric includes increasing a sensitivity of a fraud algorithm configured to analyze one or more transactions between the account and the third party web server to detect potentially fraudulent activity.

2 . The method of claim 1 , wherein increasing the sensitivity of the fraud algorithm associated with the account, comprises:

determining, by the web browser extension, that a type of website is a website associated with a financial institution; and

increasing, by the web browser extension, the sensitivity of the fraud algorithm associated with the account by a first amount.

3 . The method of claim 1 , wherein increasing the sensitivity of the fraud algorithm associated with the account, comprises:

determining, by the web browser extension, that a type of website is a website not associated with a financial institution; and

prompting, by the web browser extension, the organization computing system to increase the sensitivity of the fraud algorithm with the account by a first amount that is less than an amount associated with a financial institution website.

4 . The method of claim 1 , further comprising:

receiving, at the web browser extension, a message from the organization computing system to be transmitted to the client device, the message comprising a suggestion to opt into the multi-factor authentication functionality; and

prompting, by the web browser extension, a user of the client device to opt into the multi-factor authentication functionality.

5 . The method of claim 4 , further comprising:

detecting, by the web browser extension, that the client device has opted into the multi-factor authentication functionality following receipt of the message; and

prompting, by the web browser extension, the organization computing system to further update the fraud metric associated with the account.

6 . The method of claim 5 , wherein, prompting, by the web browser extension, the organization computing system to further update the fraud metric associated with the account, comprises:

decreasing the sensitivity of the fraud algorithm associated with the account.

7 . The method of claim 1 , wherein determining, by the web browser extension, that the client device does not have the multi-factor authentication functionality enabled comprises:

analyzing the script of the web page for one or more fields associated with a multi-factor authentication protocol.

8 . One or more non-transitory computer readable media comprising one or more sequences of instructions, which, when executed by one or more processors, causes a computing system to perform operations, comprising:

identifying, by a web browser extension executing on a client device, an account associated with the client device;

detecting, by the web browser extension, that the client device visited a web page hosted by a third party web server;

injecting, by the web browser extension and after detecting that the client device visited the web page, code into a script of the web page to enable the web browser extension to monitor whether the client device is engaged in multi-factor authentication;

detecting, by the web browser extension and using the injected code, one or more components, of the web page, associated with the multi-factor authentication;

based on the detecting, determining, by the web browser extension, that the client device does not have a multi-factor authentication functionality enabled with the third party web server; and

prompting, by the web browser extension and via an application programming interface, an organization computing system to update a fraud metric associated with the account based on the determination that the client device does not have the multi-factor authentication functionality enabled with the third party web server, wherein the update to the fraud metric includes increasing a sensitivity of a fraud algorithm associated with the account.

9 . The one or more non-transitory computer readable media of claim 8 , wherein increasing the sensitivity of the fraud algorithm associated with the account, comprises:

determining that a type of website is a website associated with a social media institution; and

increasing the sensitivity of the fraud algorithm associated with the account by a first amount.

10 . The one or more non-transitory computer readable media of claim 8 , wherein increasing the sensitivity of the fraud algorithm associated with the account, comprises:

determining that a type of website is a website not associated with a social media institution; and

increasing the sensitivity of the fraud algorithm with the account by a first amount that is less than an amount associated with a financial institution website.

11 . The one or more non-transitory computer readable media of claim 8 , further comprising:

receiving, at the web browser extension, a message from the organization computing system to be transmitted to the client device, the message comprising a suggestion to opt into the multi-factor authentication functionality; and

prompting, by the web browser extension, a user of the client device to opt into the multi-factor authentication functionality.

12 . The one or more non-transitory computer readable media of claim 11 , further comprising:

detecting, by the web browser extension, that the client device has opted into the multi-factor authentication functionality following receipt of the message; and

prompting, by the web browser extension, the organization computing system to further update the fraud metric associated with the account.

13 . The one or more non-transitory computer readable media of claim 12 , wherein prompting, by the web browser extension, the organization computing system to further update the fraud metric associated with the account, comprises:

decreasing the sensitivity of the fraud algorithm associated with the account.

14 . The one or more non-transitory computer readable media of claim 8 , wherein determining, by the web browser extension, that the client device does not have the multi-factor authentication functionality enabled comprises:

analyzing a document object model of the web page to identify one or more fields associated with a multi-factor authentication protocol.

15 . A system, comprising:

a processor; and

a memory having programming instructions stored thereon, which, when executed by the processor, causes the system to perform operations comprising:

identifying, by a web browser extension executing on a client device, an account associated with the client device;

detecting, by the web browser extension, that the client device visited a web page;

injecting, by the web browser extension, code into a script of the web page to enable the web browser extension to monitor whether the client device is engaged in multi-factor authentication;

detecting, by the web browser extension, one or more identifiers, on the web page, associated with the multi-factor authentication;

based on the detecting, determining, by the web browser extension, that the client device does not have a multi-factor authentication functionality enabled; and

prompting, by the web browser extension and via an application programming interface, an organization computing system to update a fraud metric associated with the account based on the determination that the client device does not have the multi-factor authentication functionality enabled, wherein the update to the fraud metric includes increasing a sensitivity of a fraud algorithm associated with the account.

16 . The system of claim 15 , wherein increasing the sensitivity of the fraud algorithm associated with the account, comprises:

determining that a type of website is a website associated with an email service institution; and

increasing the sensitivity of the fraud algorithm associated with the account by a first amount.

17 . The system of claim 15 , wherein increasing the sensitivity of the fraud algorithm associated with the account, comprises:

determining that a type of website is a website not associated with an email service institution; and

increasing the sensitivity of the fraud algorithm with the account by a first amount that is less than an amount associated with a financial institution website.

18 . The system of claim 15 , wherein the operations further comprise:

receiving, by the web browser extension, a notification from the organization computing system, the notification including a recommendation for the client device to enable the multi-factor authentication functionality; and

displaying, by the web browser extension, the recommendation to the client device via a user interface of the client device.

19 . The system of claim 18 , wherein the operations further comprise:

detecting, by the web browser extension, that the client device has enabled the multi-factor authentication functionality in response to the displayed recommendation; and

transmitting, by the web browser extension to the organization computing system, an indication that the client device has enabled the multi-factor authentication functionality.

20 . The system of claim 15 , wherein determining, by the web browser extension, that the client device does not have the multi-factor authentication functionality enabled comprises:

parsing a document object model of the web page to identify one or more elements associated with a multi-factor authentication process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2024
From: MOSSOBA, MICHAEL; EDWARDS, JOSHUA; JI, JASON; CHATMAN, LJUBICA; RODRIGUEZ, CARLOS EDUARDO
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 068086/0882 →
Continuity (4)
Continuation 18052747 · Nov 4, 2022
Continuation 16877605 · May 19, 2020
Continuation 16224334 · Dec 18, 2018
Related Publication 20240388580A1 · Nov 21, 2024
References Cited (45)
US 8281129B1 · Asghari-Kamrani · 2012 [cited by examiner]
US 10075847B1 · Moreton · 2018 [cited by examiner]
US 10142329B1 · Liu · 2018 [cited by applicant]
US 10193844B1 · Conley · 2019 [cited by examiner]
US 10193880B1 · Jiang · 2019 [cited by examiner]
US 10333934B1 · Fox · 2019 [cited by examiner]
US 10360367B1 · Mossoba · 2019 [cited by examiner]
US RE47633E · Karabinis · 2019 [cited by examiner]
US 10904246B2 · Chari · 2021 [cited by examiner]
US 11005851B2 · Kaube · 2021 [cited by examiner]
US 11080385B1 · Angara · 2021 [cited by examiner]
US 20030163739A1 · Armington · 2003 [cited by examiner]
US 20080275748A1 · John · 2008 [cited by examiner]
US 20090157549A1 · Symons · 2009 [cited by examiner]
US 20130068836A1 · Zanzot · 2013 [cited by examiner]
US 20130232541A1 · Kapadia · 2013 [cited by examiner]
US 20150088760A1 · Meurs · 2015 [cited by examiner]
US 20150310196A1 · Turgeman · 2015 [cited by examiner]
US 20160055132A1 · Garrison · 2016 [cited by examiner]
US 20160164880A1 · Colesa · 2016 [cited by examiner]
US 20160212113A1 · Banerjee · 2016 [cited by examiner]
US 20160283941A1 · Andrade · 2016 [cited by examiner]
US 20170063932A1 · Hubbard et al. · 2017 [cited by applicant]
US 20170118215A1 · Varadarajan · 2017 [cited by examiner]
US 20170178124A1 · Havilio · 2017 [cited by examiner]
US 20170180339A1 · Cheng · 2017 [cited by examiner]
US 20170195356A1 · Turgeman · 2017 [cited by examiner]
US 20170214679A1 · Lin · 2017 [cited by examiner]
US 20170223018A1 · Khalil · 2017 [cited by examiner]
US 20170300911A1 · Alnajem · 2017 [cited by examiner]
US 20170346802A1 · Gruskin · 2017 [cited by examiner]
US 20170357799A1 · Fehér · 2017 [cited by examiner]
US 20180083959A1 · Barbosa · 2018 [cited by examiner]
US 20180165115A1 · Fusaro · 2018 [cited by examiner]
US 20180183786A1 · Tardif · 2018 [cited by applicant]
US 20180267847A1 · Smith · 2018 [cited by examiner]
US 20180295128A1 · Drake, II et al. · 2018 [cited by applicant]
US 20180359233A1 · Alexander · 2018 [cited by examiner]
US 20190081975A1 · Iaroshevych · 2019 [cited by examiner]
US 20190304011A1 · Mossoba · 2019 [cited by examiner]
US 20190318100A1 · Bhatia · 2019 [cited by examiner]
US 20200053094A1 · Kaube · 2020 [cited by examiner]
US 20200089848A1 · Abdelaziz · 2020 [cited by examiner]
US 20200195626A1 · Mossoba · 2020 [cited by examiner]
US 20200280555A1 · Mossoba · 2020 [cited by examiner]