Multi-factor authentication using wearable devices
By receiving and displaying authentication codes related to multi-factor authentication on wearable devices, the shortcomings of existing multi-factor authentication methods in terms of security and user experience are solved, and a faster and safer authentication process is achieved.
Patent Information
- Application Number
- CN202380075364.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-01
- Filing Date
- 2023-10-27
- Publication Date
- 2025-05-27
AI Technical Summary
The existing multi-factor authentication methods have shortcomings in terms of security and user experience, especially in the use of Short Message Service (SMS) code, where users need to read the code on the mobile phone and enter the code on another device, resulting in cumbersome processes and may affect security.
By receiving the authentication code associated with multi-factor authentication and displaying the location of the authentication code on the display, the user can complete the authentication process without directly entering the code. The wearable device receives image data through an image camera, extracts the authentication code using optical character recognition technology, and displays the authentication code at a position corresponding to the interface.
This method improves the security and user experience of multi-factor authentication, reduces the time for users to complete authentication, and maintains high security of computer resources.
Smart Images

Figure CN120051774A_ABST
Abstract
Description
Cross - Reference to Related Applications
[0001] This application claims priority to U.S. Provisional Patent Application No. 63 / 381,868, filed on November 1, 2022, the disclosure of which is incorporated herein by reference in its entirety. Background Art
[0002] Multi - factor authentication is an electronic authentication method in which a user is authorized to access computer resources after successfully submitting two or more pieces of evidence to an authentication authority. In some examples, especially for short message service (SMS) codes, a user may have to read the code on a mobile phone and enter the code on another device. Summary of the Invention
[0003] The system provides a technical solution for implementing multi - factor authentication in a secure and reliable manner using a wearable device, and can reduce the amount of time it takes for a user to complete multi - factor authentication while maintaining a relatively high level of security for computer resources protected by multi - factor authentication. The wearable device can receive an authentication code associated with multi - factor authentication, determine a location for displaying the authentication code, and display the authentication code at the determined location on a display of the wearable device. In some examples, the location is determined based on the location of a UI element (e.g., a code entry field) in an interface displayed by a computing device.
[0004] In some aspects, the techniques described herein relate to a computer - implemented method that includes: receiving, by a head - mounted display device, an authentication code associated with multi - factor authentication; receiving, from an image camera on the head - mounted display device, image data; detecting, by the head - mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head - mounted display device, the authentication code at a location corresponding to the interface.
[0005] In some aspects, the techniques described herein relate to a method that includes: detecting, by a head - mounted display device, an authentication request; in response to the authentication request, displaying an interface; receiving, via the interface, a plurality of gestures; determining whether the plurality of gestures correspond to a stored gesture pattern; and authenticating, in response to the plurality of gestures being determined to correspond to the stored gesture pattern, the authentication request.
[0006] Details of one or more implementations are set forth in the accompanying drawings and the description below. Other features will be apparent from the description and drawings, and from the claims. Brief Description of the Drawings
[0007] Figure 1A A system for multi - factor authentication using a wearable device is depicted according to one aspect.
[0008] Figure 1BShows an example of a wearable device that displays an authentication code according to one aspect.
[0009] Figure 1C Shows an example of a wearable device that displays an authentication code on the interface of a computing device according to one aspect.
[0010] Figure 1D Shows an example of an authentication code displayed in a code entry field on the interface of a computing device according to one aspect.
[0011] Figure 1E Shows an example of an authentication code displayed above a code entry field on the interface of a computing device according to one aspect.
[0012] Figure 1F Shows an example of a wearable device for determining the font size of an authentication code according to one aspect.
[0013] Figure 2A Shows an example of a wearable device that displays the first part of an authentication code according to one aspect.
[0014] Figure 2B Shows an example of a wearable device that displays the second part of an authentication code according to one aspect.
[0015] Figure 2C Shows that the first part of the authentication code is aligned with the second part of the authentication code according to one aspect.
[0016] Figure 3 Shows an example of a wearable device that depicts a gaze interface for multi-factor authentication according to one aspect.
[0017] Figure 4 Shows an example of an optical tag inserted into a web page for multi-factor authentication according to one aspect.
[0018] Figure 5A Shows a front view of a head-mounted wearable device according to one aspect.
[0019] Figure 5B Shows a rear view of a head-mounted wearable device according to one aspect.
[0020] Figure 6 Shows an example operation of a system for multi-factor authentication using a wearable device according to one aspect. Detailed Description
[0021] The present disclosure relates to a system for multi-factor authentication using a wearable device, where the wearable device can receive an authentication code and display at least a portion of the authentication code. The wearable device can be a head-mounted display device. In some examples, the wearable device displays the authentication code at a location (e.g., 3D location) corresponding to the positioning (e.g., 3D positioning) of a real-world object (e.g., a UI element on a screen in front of the user). For example, the authentication code is positioned (e.g., attached, anchored) to a specific UI element on the interface displayed by the user device (e.g., the interface of the device is in front of the user). For example, the authentication code is anchored to that location regardless of head movement. In some examples, the UI element is a code entry field, and the wearable device displays the authentication code at a location corresponding to (or adjacent to) the positioning of the code entry field. In some examples, the wearable device includes an augmented reality (AR) display device (e.g., smart glasses). In some examples, the wearable device includes a virtual reality (VR) head-mounted headset. In some examples, when viewing the authentication code on the wearable device, the user can enter the authentication code on the user device.
[0022] In some examples, the wearable device receives the authentication code by detecting the authentication code from image data captured by one or more image cameras on the wearable device. The image cameras can generate image data about the user's surrounding environment. In some examples, the wearable device uses optical text recognition to detect the authentication code from the image data. For example, a user can use a first user device (e.g., a laptop computer) to navigate to a resource protected by multi-factor authentication and enter their login / password information to complete the first authentication factor, which can trigger the transmission of an authentication code to a second user device (e.g., the user's smartphone) to complete the second authentication factor. In some examples, instead of transmitting the authentication code, the authentication can be viewable from an authenticator application on the user's smartphone. While the user is looking at their smartphone, the wearable device can receive image data of the authentication code displayed on the user's smartphone via the image camera. The wearable device can extract the authentication code from the image data. Although a smartphone and a laptop computer are used as examples of the first user device and the second user device, the first user device and the second user device can be any type of user device, such as a tablet computer, a desktop computer, a smartwatch, a gaming console, a television device, etc.
[0023] In some examples, the wearable device receives an authentication code from a second user device (e.g., a smartphone) via a wireless connection (e.g., a direct Wi-Fi connection, a short-range wireless connection such as a Bluetooth connection, etc.). In some examples, the wearable device receives the authentication code from a central server. In some examples, the operating system of the second user device can detect the authentication code, and the operating system can be associated with a user account linked to other devices including the wearable device. When the wearable device and the second user device are associated with the same user account, the wearable device can receive the authentication code from the second user device and / or the central server.
[0024] The wearable device can display the authentication code at a location (e.g., a 3D location) corresponding to the location (e.g., a 3D location) of an interface for receiving the authentication code displayed by a first user device (e.g., a laptop computer). In some examples, the location of the code is based on the location of a specific UI element (e.g., a code entry field, an optical tag, etc.) in the interface displayed on the first user device. In other words, in some examples, the wearable device can anchor the authentication code to a specific UI element in the interface displayed by the first user device.
[0025] In some examples, the authentication code is fixedly anchored to an object (e.g., a UI element), where when the UI element moves, the authentication code also moves. For example, when a specific UI element moves to a different position in the user's field of view (e.g., the user moves their head), the authentication code remains fixed to the specific UI element (e.g., moves with the specific UI element). In some examples, the wearable device can overlay the authentication code in the code entry field of the interface for receiving the authentication code. In some examples, the wearable device can display the authentication code at a location near the code entry field for receiving the authentication code (e.g., above the code entry field, below the code entry field, adjacent to the code entry field, etc.). Then, the user can use the first user device to enter the authentication code in the code entry field (e.g., type the code into the code entry field). In some examples, the wearable device displays the authentication code in the code entry field (e.g., spatially locates the authentication code within a box). In some examples, the wearable device can determine the font size of the authentication code based on the depth (e.g., a depth value) between the wearable device and the first user device (e.g., how far the smartphone is from the wearable device). Then, the user can use the first user device to enter the authentication code.
[0026] In some examples, whenever a user types a new character, the wearable device causes the character to disappear. In some examples, whenever a user types a new character, the wearable device causes a change in the display characteristics of the character (e.g., changing color, transparency, contrast, etc.). In some examples, if an incorrect character is entered, the wearable device can highlight the character (e.g., highlight it in red). In some examples, instead of overlaying the authentication on the interface displayed by the first user device, the wearable device can communicate with a browser application running on the first user device to enter the authentication code into a code entry field.
[0027] In some examples, instead of displaying the authentication code on the wearable device, the wearable device can detect an authentication request for multi-factor authentication, and in response to the authentication request, the wearable device can render a gaze interface. For example, the wearable device can receive a plurality of gaze gestures via the gaze interface, determine whether the gaze gesture corresponds to a stored eye gesture pattern, and in response to the gaze gesture being determined to correspond to the stored eye gesture pattern, the wearable device can authenticate the authentication request, thereby granting access to underlying computer resources protected by multi-factor authorization.
[0028] In some examples, the wearable device receives a first part of the authentication code and displays the first part of the authentication code on a display of the wearable device. A second part of the authentication code can be displayed on the first user device. In some examples, when the first part is aligned with the second part, the authentication code can be visible to the user. These and other features are further explained with reference to the accompanying drawings.
[0029] Figures 1A to 1F A system 100 for multi-factor authentication using a wearable device 102 is shown in accordance with various aspects. The wearable device 102 can obtain an authentication code 122 associated with multi-factor authentication (e.g., two-factor authentication, three-factor authentication, or more than three-factor authentication, etc.), determine a location 120 for displaying the authentication code 122, and in some examples, display the authentication code 122 at the location 120 on a display 118 of the wearable device 102.
[0030] Multi-factor authentication is an authentication method that requires a user to provide two or more verification factors to obtain access to computer resources such as an application, an online account, or a virtual private network. In some examples, the verification factors can include receipt of the user's authentication credentials (e.g., username, account identifier, password, etc.), receipt of the user's biometric characteristics (e.g., fingerprint, facial recognition, iris recognition, voice recognition, etc.), receipt of an authentication code 122, and / or information indicating the presence of a physical token or smart card. In some examples, the authentication code 122 is generated in response to successful authentication of a first verification factor (e.g., the user entered the correct username / password, entered the correct pin, etc.).
[0031] In some examples, the authentication code 122 is generated by a computer resource such as a web resource (e.g., a web page accessed by the user) or an application (e.g., application 104 or application 134) executing on a user device (e.g., computing device 130 or computing device 152). In some examples, the authentication code 122 is transmitted to the user via a message (e.g., a text message or an email message). For example, the user may have provided their email address or phone number associated with a particular computer resource having multi-factor authentication, and in response to a successful first verification factor, receive (including the authentication code 122) a text message or an email at the user's device (e.g., computing device 130 or computing device 152).
[0032] In some examples, the authentication code 122 is generated by an authenticator application. Separate instances of the authenticator application are represented by the authenticator application 106 (executing on the wearable device 102), the authenticator application 136 (executing on the computing device 130), and / or the authenticator application 158 (executing on the computing device 152). The authenticator application (e.g., 106, 136, 158) can periodically update the authentication code 122 (over time), and in some examples, the user can view the authentication code 122 from the user interface of the authenticator application. For example, when the authenticator application is launched, the authenticator application can display the authentication code 122 associated with a particular computer resource having multi-factor authentication.
[0033] In some examples, an underlying computing device (e.g., an operating system) can communicate with an authenticator application to obtain an authentication code 122 (e.g., via inter - process communication (IPC)), where the authentication code 122 can be provided to other devices, including the wearable device 102 (e.g., a device having an operating system associated with the same user account 172). For example, the wearable device 102 can obtain the authentication code 122 from the authenticator application 106. In some examples, when the operating system of the wearable device 102 and the operating system 132 of the computing device 130 are associated with the same user account 172, the wearable device 102 can obtain the authentication code 122 from the authenticator application 136 of the computing device 130. In some examples, when the operating system of the wearable device 102 and the operating system 154 of the computing device 152 are associated with the same user account 172, the wearable device 102 can obtain the authentication code 122 from the authenticator application 158 of the computing device 152.
[0034] The authentication code 122 can include a combination of characters (e.g., numbers, symbols, letters, etc.) for verifying a user's identity. In some examples, the authentication code 122 includes a first character, a second character, a third character, etc. In some examples, the authentication code 122 is associated with the order of the characters (e.g., the second character must be positioned after the first character).
[0035] More specifically, when obtaining access to computer resources associated with multi - factor authentication (e.g., an online account on a web page), a user can use their computing device (e.g., the computing device 152) to provide their authentication credentials (e.g., username, password) on the interface of the computer resource, which can be considered the first verification factor in multi - factor authentication. In some examples, a second verification factor is required to obtain access to the computer resource. In some conventional methods, an email or text message is transmitted to the user, where the email or text message includes the authentication code 122. In some examples, the authentication code 122 is generated by the computer resource (e.g., a web page) hosting the online account. In some examples, the authentication code 122 is generated and displayed by an authenticator application (e.g., the authenticator application 136) executing on a mobile device. The user then views the authentication code 122 and enters the authentication code 122 on the web page of the online account.
[0036] As discussed herein, the system 100 provides a technical solution for using the wearable device 102 to implement multi - factor authentication in a secure and reliable manner. In some examples, the system 100 can reduce the amount of time it takes for a user to complete multi - factor authentication while maintaining a relatively high level of security for the computer resources protected by multi - factor authentication.
[0037] The wearable device 102 may include: a head-mounted display (HMD) device, such as an optical head-mounted display (OHMD) device, a transparent head-up display (HUD) device, an augmented reality (AR) device, a virtual reality (VR) device; or other devices, such as goggles or a head-mounted headset having sensors, a display, and computing capabilities. In some examples, the wearable device includes an AR device. In some examples, the wearable device includes smart glasses. Smart glasses are an optical head-mounted display device designed in the shape of a pair of glasses. Smart glasses can be glasses that add information (e.g., project a display 118) next to what the wearer views through the glasses (e.g., the wearer can view an interface 164 for receiving an authentication code 122 via the glasses). Smart glasses can allow the user to see physical objects in the world (e.g., through the lenses) and content rendered in the display 118 (e.g., the authentication code 122, digital images, user interface elements, virtual content, etc.).
[0038] In some examples, the wearable device 102 includes a VR device that provides a partial (or fully) immersive VR environment. A VR device is a head-mounted display (HMD) that creates a simulated environment for the user. An AR device can be glasses or a handheld device that uses cameras and sensors to track the user's surrounding environment. An AR device can display digital information, such as directions, product information, or even virtual characters and objects, on top of the real world. A VR device is typically a head-mounted headset that completely blocks out the real world and replaces it with a virtual world. However, a VR device can include an image camera 116 that captures image data 101 in front of the user (or around or partially around the user). A VR device uses sensors to track the user's head movements and adjusts the virtual environment accordingly. An extended reality (XR) device can encompass VR devices and AR devices. In some examples, an XR device has two screens, one for each eye. The screens display slightly different images, which creates an illusion of depth. An XR device also has sensors that track the user's head movements so that the virtual environment can move with the user's head.
[0039] The wearable device 102 includes one or more processors 103 and one or more memory devices 105. The processor 103 may be formed in a substrate and configured to execute one or more machine-executable instructions or software components, firmware components, or combinations thereof (e.g., to perform any of the operations discussed herein with respect to the wearable device 102). The processor 103 may be semiconductor-based, that is, the processor may include semiconductor material that can execute digital logic. The memory device 105 may include non-transitory computer-readable media storing executable instructions that cause the processor 103 to perform the operations discussed herein with respect to the wearable device 102. In some examples, the memory device 105 may include a main memory that stores information in a format readable and / or executable by the processor 103. The memory device 105 may store applications 104 that, when executed by the processor 103, perform certain operations.
[0040] In some examples, the application 104 includes an authenticator application 106. The authenticator application 106 may periodically generate an authentication code 122. For example, the authenticator application 106 may be enabled with respect to a particular computer resource implementing multi-factor authentication, and in some examples, the authenticator application 106 may periodically update the authentication code 122 of the particular computer resource (e.g., change the authentication code 122 every predetermined time period).
[0041] The wearable device 102 may include a display device 110 configured to project a display 118 into the user's field of view. In some examples, the display device 110 may be configured to project light from a display source onto a portion of a teleprompter glass acting as a beam splitter disposed at an angle (e.g., 30 - 45 degrees). The beam splitter may allow reflection and transmission values that allow light from the display source to be partially reflected while the remaining light is transmitted through. Such an optical design may allow the user to see content (e.g., the authentication code 122, digital image, user interface elements, virtual content, authentication code 122, etc.) generated by the display device 110 at a location proximate to (or overlaid on) physical items in the world, e.g., seen through lenses (e.g., an interface 164 displayed on another computing device such as the computing device 152).
[0042] The wearable device 102 includes one or more image cameras 116. The image camera 116 generates image data 101 of a physical scene in the field of view of the camera. In some examples, in the case of an AR device, the user's field of view (as seen through glasses) may correspond to the field of view of the camera. In some examples, in the case of an AR device, the field of view of the camera is greater than or less than the user's field of view. When the display screen of the computing device 130 or the computing device 152 is within the field of view of the image camera, the image camera 116 may capture the content displayed by the computing device 130 or the computing device 152. The image camera 116 may include a camera that can capture still and / or moving images of the environment outside the wearable device 102, such as a front-facing camera, an outward-facing camera, or a world-facing camera, etc. In some examples, the wearable device 102 is a VR device, and the image camera 116 may capture the world in front of the user, including the content displayed by the computing device 130 or the computing device 152. In some examples, when the user device is within the field of view of the image camera, the wearable device 102 may generate and display a computer-generated representation of the user device (e.g., the computing device 130, the computing device 152), including computer-generated graphics corresponding to the content displayed on the display screen of the user device.
[0043] The wearable device 102 may include other sensors, such as one or more positioning / orientation sensors (e.g., inertial measurement unit, accelerometer, gyroscope, and / or magnetometer, etc.), one or more audio sensors that can detect audio input, one or more touch input sensors that can detect touch input, and other such sensors. In some examples, the wearable device 102 includes a gaze tracking device 117 for detecting and tracking the gaze direction and movement of the eyes. The data captured by the gaze tracking device 117 can be processed to detect and track the gaze direction and movement as user input.
[0044] The computing device 152 can be a laptop computer. In some examples, the operating system 154 of the computing device 152 is a desktop operating system. In some examples, the operating system 154 of the computing device 152 is a mobile operating system. However, the computing device 152 can be any type of user device, such as a smart phone, a tablet computer, a desktop computer, a game console, another wearable device, etc. The computing device 152 is configured to execute applications 156. The applications 156 can include an authenticator application 158 and a browser application 160. However, the applications 156 can include various applications, such as native applications (e.g., installable on the operating system 154), web applications (e.g., executable at least in part by the browser application 160), mobile applications (e.g., executable in a mobile environment), and desktop applications (e.g., executable in a desktop environment), etc. The authenticator application 158 and the browser application 160 can be separate instances of the authenticator application 106 and the browser application 108, respectively, and thus can include any of the details discussed with reference to those components.
[0045] The user can use the computing device 152 to access computer resources associated with (e.g., protected by) multi-factor authentication. In some examples, the computer resource is one of the applications 156. In some examples, the computer resource can be accessed via the browser application 160. In some examples, the computer resource is a web page, an online account, or a web application. In some examples, in the first authentication factor, the user can provide their authentication credentials (e.g., submit their username / password), which triggers the activation of the second authentication factor. In some examples, the second authentication factor includes notifying the user of an authentication code 122, where the authentication code 122 is submitted via a code entry field 168 of an interface 164 on a display 162 of the computing device 152.
[0046] As Figure 1A shown, in some examples, the authentication code 122 can be displayed on a display 140 of another computing device (e.g., the computing device 130). In some examples, the computing device 130 is a user device linked to a computer resource protected by multi-factor authentication. In some examples, the computing device 130 is a user device configured to generate or receive the authentication code 122 when the user uses the computing device 152 to properly supply their authentication credentials. The computing device 130 can be a mobile device, such as a smart phone or a tablet computer. In some examples, the operating system 132 of the computing device 130 is a mobile operating system.
[0047] However, the computing device 130 can be any type of user device, such as a laptop computer, a desktop computer, a gaming console, another wearable device, etc. The computing device 130 is configured to execute an application 134. The application 134 can include an authenticator application 136 and a browser application 138. However, the application 134 can include various applications, such as native applications (e.g., installable on the operating system 132), web applications (e.g., executable at least in part by the browser application 138), mobile applications (e.g., executable in a mobile environment), and desktop applications (e.g., executable in a desktop environment), etc. The authenticator application 136 and the browser application 138 can be separate instances of the authenticator application 106 and the browser application 108, respectively, and thus can include any of the details discussed with reference to those components.
[0048] In some examples, the computing device 130 receives a message (e.g., a text message or an email), where the message includes an authentication code 122. The authentication code 122 can be generated by a computer resource protected by multi-factor authentication. For example, in response to a successful first verification factor, the computing device 130 can receive and display the authentication code 122. In some examples, in response to a successful first verification factor, the user can use the computing device 130 to launch the authenticator application 136, which displays the authentication code 122 on the display 140 of the computing device 130. In some examples, the authenticator application 136 is a native (e.g., mobile) application installed on the operating system 132 of the computing device 130.
[0049] In some examples, the wearable device 102 may receive image data 101 of the authentication code 122 via the image camera 116. For example, the user may move the wearable device 102 such that the authentication code 122 displayed on the display 140 of the computing device 130 is within the field of view of the image camera 116. The wearable device 102 may include an optical character recognition (OCR) scanner 114 configured to extract the authentication code 122 from the image data 101 using OCR technology. The OCR scanner 114 is configured to recognize text (e.g., the authentication code 122) within the image data 101 captured by the image camera 116. In some examples, the OCR scanner 114 is configured to recognize and detect the authentication code 122 (e.g., as opposed to other text information that may be captured by the image camera 116). When the authentication code 122 is displayed (e.g., via a text message, an email, or by the authenticator application 136), the user with the wearable device 102 may turn towards the computing device 130, causing the display 140 of the computing device to be within the field of view of the image camera 116. The wearable device 102 may use other image detection and recognition techniques for detecting the authentication code 122. In some examples, the wearable device 102 includes a machine learning (ML) model (e.g., a neural network model). The ML model may be configured to identify and extract the authentication code 122 from the image data 101.
[0050] In some examples, rather than using text recognition from the image data 101, the wearable device 102 may receive the authentication code 122 from the computing device 130 via a wireless connection between the wearable device 102 and the computing device 130. In some examples, the wearable device 102 and the computing device 130 may be wirelessly connected. In some examples, the wireless connection is a direct Wi-Fi connection or a short-range communication link such as a near field communication (NFC) connection or a Bluetooth connection. The wearable device 102 and the computing device 130 may exchange information via the wireless connection. In some examples, the wireless connection defines an application layer protocol that is implemented using protocol buffers with message types for drawing graphical primitives, configuring sensors and peripherals, and changing device modes. In some examples, when a message (e.g., a text message) is received at the computing device 130, the message is transmitted to the wearable device 102 via the application layer protocol. In some examples, the wearable device 102 and the computing device 130 are devices associated with the same user account 172 (e.g., a browser application, an operating system account, an authentication account, or other type of user account 172). In some examples, the wearable device 102 may receive the authentication code 122 from the computing device 130 via a central server 170.
[0051] If the authentication code 122 is received or generated by the computing device 152, the wearable device 102 may obtain the authentication code 122 from the computing device 152 in the same manner as interpreted by the reference computing device 130. For example, the computing device 130 may receive a message (e.g., text or email) from a computer resource protected by multi-factor authentication and display the authentication code 122 on the display 162, where the wearable device 102 obtains the authentication code 122 via OCR scanning. In some examples, the authenticator application 158 may generate and display the authentication code 122, where the wearable device 102 obtains the authentication code 122 via OCR scanning. In some examples, the computing device 152 and the wearable device 102 are connected via a wireless connection, and the wearable device 102 obtains the authentication code 122 via the wireless connection.
[0052] In some examples, the wearable device 102 may receive the authentication code 122 from a central server 170 (e.g., also referred to as a server or server computer). In some examples, the wearable device 102, the computing device 152, and / or the computing device 130 are connected to each other via a network (e.g., the Internet). In some examples, the operating system 154 (and / or the browser application 160) may be associated with a user account 172, and the wearable device 102 and / or the computing device 130 may be devices linked to the user account 172 (e.g., devices identified in the user account 172). In some examples, if the computer resource protected by multi-factor authentication is managed or owned by an entity that manages or owns the operating system 154 (and / or the browser application 160), the wearable device 102 may obtain the authentication code 122 from the central server 170. In some examples, if the computer resource protected by multi-factor authentication is managed or owned by an entity that manages or owns the operating system 132 (and / or the browser application 138), the wearable device 102 may obtain the authentication code 122 from the central server 170.
[0053] Reference Figure 1B, in response to detecting the authentication code 122, in some examples, the wearable device 102 may display the authentication code 122 in the display 118 of the wearable device 102. In some examples, the location 120 depends on the image data 101 generated by the image camera 116 (e.g., viewed through the lens) (e.g., an object in front of the user). In some examples, the wearable device 102 may display the authentication code 122 at a location 120 that does not depend on the information in front of the user (e.g., captured by the image data 101). In some examples, the wearable device 102 determines the location 120 for displaying the authentication code 122 and displays the authentication code 122 at the location 120. In some examples, the location 120 includes two-dimensional coordinates (e.g., x, y). In some examples, the location 120 includes three-dimensional coordinates (e.g., x, y, z). In some examples, the location is a predetermined location, such as a positioning in the top (or bottom) portion of the display 118. In some examples, the location 120 is a positioning in the left (or right) portion of the display 118. In some examples, the location 120 is a positioning in the central portion of the display 118. In some examples, the location 120 is based on the location (or positioning) of an object in the image data 101.
[0054] In some examples, the location 120 is fixed in the display 118 (e.g., does not change). In some examples, the location 120 in the display 118 may change (e.g., move), depending on the image data 101 in the field of view of the image camera. In some examples, the location 120 is based on which content is currently projected by the display device 110 (e.g., other computer-generated elements displayed in the display 118). In some examples, the location 120 is not determined based on the currently displayed content.
[0055] In some examples, the wearable device 102 may display an authentication code 122 at a location 120 in the display 118, where the location 120 is based on an interface 164 for receiving the authentication code 122. In some examples, the location 120 is a specific object (e.g., a UI element) in the image data 101. In some examples, the authentication code 122 is anchored or coupled to the specific object. In some examples, the location 120 is based on the position of a specific UI element 166 in the interface 164. In some examples, the wearable device 102 may anchor (e.g., fixedly couple) the authentication code 122 to a specific UI element 166 in the display 162 of the computing device 152. In other words, the authentication code 122 may remain fixed to the specific UI element 166 regardless of head movement. The wearable device 102 may include one or more inertial measurement units (IMUs) configured to track the movement of the wearable device 102, and the one or more IMUs may be used to align the authentication code 122 with the UI element 166. In some examples, in response to a successful first authentication factor, the computing device 152 may render an interface 164 for receiving the authentication code 122.
[0056] The interface 164 may be a user interface of an application 156 executing on the computing device 152. In some examples, the interface 164 is an interface of a browser application 160. In some examples, the interface 164 includes a web page displayed by the browser application 160. The interface 164 may include one or more UI elements 166. The UI elements 166 may include field entry fields (e.g., a code entry field 168 for receiving the authentication code 122), optical tags 142, menu items, user control elements, boundaries of the interface, navigation panels, etc. In some examples, the authentication code 122 is displayed in or near the UI element 166, and the authentication code may remain displayed in or near the UI element 166 even though the UI element 166 moves to a different area in the display 118. For example, the UI element 166 may be located in the right portion of the display 118, and the user may move their head to the right (or move the computing device 152 to the left), which shifts the UI element 166 to the left portion of the display 118. Even though the UI element moves in the display 118, the authentication code 122 may remain fixed to the UI element 166.
[0057] In some examples, the wearable device 102 may display a computer-generated representation of the computing device 130 at a position in the display 118 corresponding to the position of the computing device 130 in front of the user. Moreover, the wearable device 102 may generate and display content corresponding to the content displayed on the display screen of the computing device 130 (e.g., VR content), including the display of the authentication code 122 (which may be displayed via a text message, email, or authenticator application 136). In some examples, the wearable device 102 may display an interface 164 for receiving the authentication code 122. In some examples, the user may interact with the authentication code 122 (e.g., pinch the authentication code 122) and drag it to the interface 164.
[0058] The wearable device 102 may determine a position 120 for displaying the authentication code 122 in the display 118 of the wearable device 102 based on the interface 164 (e.g., the structure of the interface 164 and / or the positioning of the UI elements 166 of the interface 164). In some examples, the position 120 is based on the position of a particular UI element 166 (e.g., the code entry field 168, the optical tag 142) in the interface 164. In other words, in some examples, the wearable device 102 may associate (e.g., anchor, attach) the position 120 of the authentication code 122 to a particular UI element 166 in the display 162 of the computing device 152.
[0059] In some examples, the wearable device 102 may detect that the image data 101 includes a UI element 166 (e.g., the code entry field 168). In some examples, the UI element 166 refers to an interface for receiving the authentication code 122. For example, the wearable device 102 may include an image detection and recognition engine configured to detect a particular type of physical object (e.g., the UI element 166) based on the image data 101. In some examples, the wearable device 102 includes one or more ML models configured to detect the UI element 166. The wearable device 102 may include a 3D estimation engine configured to determine the positioning of the UI element 166 in 3D space (e.g., 3D positioning) based on the image data 101. In some examples, the image data 101 includes a pair of stereo images, and the 3D estimation engine may use the pair of stereo images to estimate the 3D positioning of the UI element 166 (e.g., by calculating the disparity between the UI elements 166 in the stereo images). In some examples, the 3D estimation engine may use a depth sensor to calculate the depth and position of an object in front of the user.
[0060] The wearable device 102 can identify a specific UI element (e.g., the code entry field 168) from the image data 101 or by inspecting the optical tag 142, and can determine the location 120 based on the location of the UI element. In some examples, the computing device 152 displays an optical tag 142 (e.g., a QR code) corresponding to the interface 164. An optical tag is a machine-readable tag that can be read by a computing device and is used to store a resource locator (e.g., a URL) of a web resource. In some examples, the optical tag 142 includes a bar code (e.g., a two-dimensional bar code). In some examples, the optical tag 142 includes a QR code. In some examples, the optical tag 142 includes a pixel pattern (e.g., a black and white pixel pattern). In some examples, the optical tag 142 includes a machine-readable optical tag. The wearable device 102 can obtain the optical tag 142 corresponding to the interface 164 via the image camera 116. The optical tag 142 can represent a resource locator (e.g., a URL) of a computer resource (e.g., the interface 164). In some examples, when the optical tag 142 is interpreted, the interface 164 is rendered. The wearable device 102 can use the resource locator to obtain information about the UI element 166 (e.g., what UI elements are included, where the UI elements are located, etc.). In some examples, the wearable device 102 can obtain the image data 101 of the UI element 166 on the interface 164 via the image camera 116, and use the image data 101 to determine the location 120 of the authentication code 122.
[0061] Reference Figure 1C and Figure 1D , the wearable device 102 can display the authentication code 122 in the code entry field 168 on the interface 164 displayed by the computing device 152. For example, the wearable device 102 can overlay (e.g., superimpose) the authentication code 122 in the code entry field 168 on the interface 164 displayed by the computing device 152. In other words, the value of the authentication code 122 may not be entered into the code entry field 168, but the wearable device 102 projects the authentication code 122 at a location above the code entry field 168. Then, the user can enter (e.g., manually enter) the authentication code 122 in the code entry field 168 using the computing device 152. In some examples, the wearable device 102 renders the interface 164 on the display 118, and the wearable device 102 displays the characters of the authentication code 122 in the code entry field 168. In some examples, the interface 164 is not displayed on the display 118, and the wearable device 102 sends the authentication code 122 to the underlying resource to authenticate the user.
[0062] Reference Figure 1E, the wearable device 102 can display the authentication code 122 at the location 120 outside the code entry field 168. In some examples, the authentication code 122 is anchored to the optical tag 142, where the authentication code 122 is overlaid (e.g., superimposed) on the optical tag 142, and the optical tag can be close to the code entry field 168 (but outside the boundary of the code entry field). In some examples, the authentication code 122 can be displayed at the location 120 above the code entry field 168 in the display 118. Then, the user can use the computing device 152 to enter the authentication code 122 into the code entry field 168. In some examples, whenever the user types a new character, the wearable device 102 causes the character to disappear. In some examples, when the user correctly types a new character, the display characteristics of the character change (e.g., color, transparency, color, etc.). In some examples, if an incorrect character is entered, the wearable device 102 can highlight the character (e.g., highlight it in red).
[0063] The wearable device 102 can cause the computing device 152 to enter (and in some examples, submit) the authentication code 122 into the code entry field 168, where the user does not have to type the authentication code 122 into the code entry field 168. For example, the wearable device 102 can transmit the authentication code 122 to the browser application 160, where the browser application 160 can render the authentication code 122 in the code entry field 168 on the interface 164. In some examples, the wearable device 102 can transmit the authentication code 122 to the computing device 152, and the computing device 152 can automatically enter the authentication code 122.
[0064] Reference Figure 1E, the wearable device 102 can determine the font size 186 of the authentication code 122 based on the depth (e.g., depth value 182) between a part 121 of the wearable device 102 and a part 123 of the computing device 152. In some examples, the part 121 of the wearable device 102 can be a lens, an image camera 116, or the front part of the wearable device 102. In some examples, the part 123 of the computing device 152 is the display screen (e.g., display 162) of the computing device 152. In some examples, the part 123 is the code entry field 168 on the display 162 of the computing device 152. For example, the wearable device 102 can receive image data 101 of at least a part of the computing device 152 via the image camera 116. The wearable device 102 can include a depth estimator 180 configured to estimate the depth value 182 between the part 121 of the wearable device 102 and the part 123 of the computing device 152. In some examples, the depth estimator 180 can estimate the depth value 182 based on one or more images (e.g., RGB images) of the part 123 of the computing device 152. The wearable device 102 includes a font size identifier 184 configured to identify the font size 186 based on the depth value 182. For example, one or more depth values 182 (or a range of depth values 182) can be associated with a specific font size 186, and one or more depth values (or a range of depth values 182) can be associated with another font size 186. By identifying the depth value 182, the wearable device 102 can select a specific font size 186 for the authentication code 122.
[0065] In some examples, the wearable device 102 can export the authentication code 122 from an authenticator application 106 executed on the wearable device 102, determine the location 120 for displaying the authentication code 122, and display the authentication code 122 at the location 120 on the display 118 of the wearable device 102. For example, the wearable device 102 can detect an authentication request for multi-factor authentication, and in response to the authentication request, the wearable device 102 can start and execute the authenticator application 106, and obtain the authentication code 122 from the authenticator application 106 executed on the wearable device 102. In some examples, the authenticator application 106 can execute in the background of the wearable device 102.
[0066] In some examples, the authentication request is a request to retrieve the authentication code 122. In some examples, the authentication request does not include the authentication code 122, where the authenticator application 106 on the wearable device 102 generates the authentication code 122. In some examples, the authentication request includes the authentication code 122.
[0067] In some examples, the wearable device 102 may receive an authentication request for multi-factor authentication from the computing device 152. In some examples, the computing device 152 may be a user device that initiates a request to access a computer resource protected by multi-factor authentication (e.g., performs a first authentication factor). In some examples, the wearable device 102 and the computing device 152 may be connected to the same network (e.g., the same Wi-Fi network). In some examples, the wearable device 102 and the computing device 152 may be connected via a wireless connection (e.g., a direct Wi-Fi connection, a short-range connection, etc.) or a wired connection. In some examples, if the wearable device 102 and the computing device 152 are connected to each other or on the same Wi-Fi network, the computing device 152 may transmit the authentication request to the wearable device 102.
[0068] For example, in response to a successful first authentication factor on the computing device 152, the computing device 152 may transmit an authentication request to the wearable device 102. In some examples, the wearable device 102 may receive an authentication request for multi-factor authentication from the central server 170, the authentication request including information about a user account 172 associated with one or more linked devices (e.g., the computing device 130, the computing device 152, and / or the wearable device 102). In some examples, the user account 172 is a user account of an operating system. In some examples, the user account 172 is a user account of a browser application. The user account 172 may be associated with settings 174. If the user account 172 is associated with an operating system, the settings 174 may include network settings, display settings, application settings, multi-factor authentication settings, etc. If the user account 172 is associated with a browser application, the settings 174 may include multi-factor authentication settings, browser settings, personalization settings, etc.
[0069] In some examples, the wearable device 102 may receive image data 101 via the image camera 116, where the image data 101 includes an optical tag 142 (e.g., a barcode, a QR code, etc.) associated with a multi-authentication authority. In some examples, in response to detecting the optical tag 142 in the image data 101, the wearable device 102 may detect an authentication request.
[0070] In some examples, application 104 includes browser application 108. Browser application 108 can be a web browser configured to access information on the Internet. In some examples, browser application 108 is an application separate from the operating system of wearable device 102, where browser application 108 can be installed on the operating system (and executed by the operating system). In some examples, browser application 108 is the operating system of the device (or is included as part of the operating system of the device). Browser application 108 can launch one or more browser tabs in the context of one or more browser windows on display 118 of wearable device 102.
[0071] In some examples, in response to wearable device 102 receiving authentication code 122, wearable device 102 can use browser application 108 to render an interface (e.g., interface 164) on display 118 and position authentication code 122 in a code entry field (e.g., code entry field 168) on the interface. A user can operate wearable device 102 (e.g., manipulate one or more controls on wearable device 102) to accept authentication code 122. In some examples, no user interaction is required on wearable device 102, where in response to receiving authentication code 122, wearable device 102 can submit authentication code 122 to a computer resource (e.g., via browser application 108). Wearable device 102 can generate information indicating the success of the second authentication factor and transmit the information to computing device 152, which causes computing device 152 to provide access to computer resources protected by multi-factor authentication. In some examples, wearable device 102 can render access to a computer resource (e.g., a web page, application 104, etc.) by displaying the computer resource in display 118 of wearable device 102.
[0072] Figures 2A to 2C An example of a system 200 for multi-factor authentication using a wearable device 202 is shown according to another aspect. System 200 can be Figures 1A to 1FAn example of system 100, and may include any of the details discussed with reference to those figures. In some examples, system 200 may display a first portion 222a of authentication code 222 on display 218 of wearable device 202, and display a second portion 222b of authentication code 222 on display 262 of computing device 252. When the first portion 222a is aligned with the second portion 222b, the authentication code 222 may be rendered (e.g., visible to the user). In some examples, wearable device 202 receives the first portion 222a and the second portion 222b from different sources. In some examples, aligning the first portion 222a with the second portion 222b includes arranging the first portion 222a and the second portion 222b adjacent to each other. In some examples, aligning the first portion 222a with the second portion 222b includes superimposing the first portion 22a on the second portion 222b (and vice versa). In some examples, viewing the first portion 222a and the second portion 222b separately does not render the actual string, however, when the first portion 222a is set on top of the second portion 222b, the authentication code 222 can be discerned by the user.
[0073] Wearable device 202 may receive only the first portion 222a of authentication code 222. The first portion 222a may be detected according to any of the techniques for detecting authentication codes discussed herein. In some examples, wearable device 202 may receive the first portion 222a from a central server. In some examples, wearable device 202 may receive the first portion 222a from computing device 252. In some examples, wearable device 202 may receive the first portion 222a from an authenticator application executing on wearable device 202. In some examples, wearable device 202 may receive the first portion 222a from a computer resource protected by multi-factor authentication.
[0074] Wearable device 202 may project the first portion 222a onto display 218. Computing device 252 may receive the second portion 222b and display the second portion 222b of authentication code 222 on interface 264. In some examples, computing device 252 may receive the second portion 222b from a central server. In some examples, computing device 252 may receive the second portion 222b from a computer resource protected by multi-factor authentication. In some examples, the central server detects an authentication request for multi-factor authentication, generates the first portion 222a and the second portion 222b, and transmits the first portion 222a and the second portion 222b to wearable device 202 and computing device 252, respectively. In some examples, wearable device 202 receives authentication code 222 (e.g., according to any of the techniques discussed herein) and generates the first portion 222a and the second portion 222b, and transmits the second portion 222b to computing device 252.
[0075] The first portion 222a may represent at least a portion of the authentication code 222. The second portion 222b may represent at least a portion of the authentication code 222. In some examples, both the first portion 222a and the second portion 222b are required to recover the authentication code 222. In some examples, when the first portion 222a is not aligned with the second portion 222b, the authentication code 222 is not distinguishable by the user (e.g., remains hidden). In some examples, the first portion 222a includes some of the values of the characters of the authentication code 222, and the second portion 222b includes other values of the authentication code 222. In some examples, the first portion 222a includes a plurality of characters (e.g., arranged in a row, grid, or matrix) and / or character receivers (e.g., boxes, underlines, etc.) and the second portion 222b includes a plurality of characters and / or character receivers (e.g., boxes, underlines, etc.), wherein at least a portion of the first portion 222a will have to be correctly aligned with at least a portion of the second portion 222b (e.g., for the code 3359, the first portion 222a may be "_35_", and the second portion 222b may be "3__9"). In some examples, the first portion 222a includes the authentication code 222 (or a portion thereof) configured in a first display format, and the second portion 222b includes the authentication code 222 (or a portion thereof) configured in a second display format.
[0076] In some examples, the first portion 222a and the second portion 222b have different transparencies (e.g., transparency values). For example, a first transparency level (e.g., opaque) may indicate that illumination of a portion of the authentication code 222 is not transparent (e.g., the background image is not shown through the image data), and a second transparency level (e.g., fully transparent) may indicate that illumination of a portion of the authentication code 222 is completely transparent (e.g., hidden, where the background image is shown through the image data). In some examples, each of the first portion 222a and the second portion 222b has a transparency value between the first transparency level and the second transparency level. In other words, the first portion 222a and the second portion 222b may have different partial transparency levels.
[0077] When the user moves the wearable device 202 to align the first portion 222a (e.g., as displayed in the display 218 of the wearable device 202) with the second portion 222b (e.g., as displayed in the display 262 of the computing device 252), the authentication code 222 is presented. In some examples, aligning the first portion 222a with the second portion 222b includes positioning the first portion 222a in a location proximate to the second portion 222b. In some examples, aligning the first portion 222a with the second portion 222b includes positioning the first portion 222a in a location above the second portion 222b (e.g., at least partially overlapping (or fully overlapping) on top of each other). In some examples, the user does not have to move the wearable device 202 to align the first portion 222a with the second portion 222b. For example, the wearable device 202 can detect the location for displaying the first portion 222a in the display 262 by examining the image data 101 of the second portion 222b or by examining the optical tag 142, and can display the first portion 222a in the correct location aligned with the second portion 222b such that the authentication code 222 is presented.
[0078] Figure 3 An example of a system 300 for multi-factor authentication using a wearable device 302 in accordance with one aspect is shown. System 300 can be Figures 1A to 1F an example of system 100 and can include any of the details discussed with reference to those figures. In some examples, the wearable device 302 can detect an authentication request 303 and, in response to the authentication request 303, can display a gaze interface 305 on the display 318 of the wearable device 302. In some examples, the authentication request 303 can correspond to a second verification factor for multi-factor authentication. In some examples, in response to a successful first verification factor, the authentication request 303 is sent to the wearable device 302. In some examples, the first verification factor is performed on the wearable device 302. In some examples, the first verification factor is performed on another computing device (e.g., Figures 1A to 1F computing device 130 or computing device 152 of
[0079] In some examples, the wearable device 302 can receive the authentication request 303 from another computing device (e.g., Figures 1A to 1F computing device 130 or computing device 152 of Figures 1A to 1FThe central server 170) receives an authentication request 303. In some examples, the wearable device 302 may receive image data via an image camera, where the image data includes an optical tag (e.g., barcode, QR code, etc.) associated with a multi-factor authentication agency. In some examples, in response to detecting an optical tag in the image data, the wearable device 302 may detect the authentication request 303. In some examples, the wearable device 302 may detect an authentication code according to any of the techniques previously described including OCR scanning. In some examples, instead of displaying the authentication code, the wearable device 302 may display a gaze interface 305.
[0080] The wearable device 302 may track the trajectory of eye movement (e.g., a single stroke), and if the trajectory matches a certain percentage of a pre-coded eye pose (e.g., a stored pattern 393 of eye poses), the wearable device 302 may verify a second verification factor, thereby granting user access to the underlying computer resources associated with multi-factor authentication. For example, the wearable device 302 may receive a plurality of gaze poses 391 via the gaze interface 305, determine whether the gaze poses 391 correspond to the stored eye pose pattern 393, and in response to the gaze poses 391 being determined to correspond to the stored eye pose pattern 393, the wearable device 302 may authenticate the authentication request 303, thereby granting access to the underlying computer resources protected by multi-factor authorization. In some examples, instead of using eye gaze poses, head poses may be used. For example, the wearable device 302 may receive a plurality of poses (e.g., eye poses or head poses) via the interface, determine whether the poses correspond to the stored pose pattern (e.g., eye poses or head poses), and in response to the poses being determined to correspond to the stored pose pattern, the wearable device 302 may authenticate the authentication request 303, thereby granting access to the underlying computer resources protected by multi-factor authorization.
[0081] In some examples, instead of displaying an eye gaze interface, the wearable device 302 can display an interface that can receive an authentication code based on head movement. For example, the wearable device 302 can use a camera or sensor to track head movement, and data from the head tracking device can be used to calculate the head gaze point. The user can move their head to select different regions corresponding to different character values (e.g., when a head gaze point is detected within a specific region during a predetermined time period, or in response to a further user selection (e.g., pressing a button on the wearable device 302), the character value can be selected). Using head movement, the user can enter an authentication code in the interface. In some examples, the authentication code can be received by the wearable device 302 according to any of the techniques discussed herein. In some examples, the authentication code is a pre-stored code (e.g., previously determined by the user and, in some examples, stored at the wearable device 302). When the user enters the code in the interface, the user can be authenticated.
[0082] Figure 4 An example of a system 400 for multi-factor authentication using a wearable device 402 is shown according to another aspect. The system 400 can be Figures 1A to 1F system 100 of Figures 2A to 2C system 200 of, and / or Figure 3 an example of system 300 of, and can include any of the details discussed with reference to those figures.
[0083] In some examples, the web page 411 can be displayed on another computing device (e.g., Figures 1A to 1F computing device 130 or computing device 152 of
[0084] In some examples, the non-perception threshold is the critical flicker frequency (CFF). The human visual system has a limited ability to detect time-varying fluctuations in light intensity. When the variation is above the CFF, the human visual system cannot detect the variation (e.g., only perceives the average brightness). Thus, by inserting the optical tag 442 (e.g., QR code, barcode, etc.) on the web page 411 during a time interval greater than the non-perception threshold (e.g., CFF), the wearable device 402 can detect the optical tag 442 without the user seeing the optical tag 442. Detecting the optical tag 442 can cause the wearable device 402 to obtain the authentication code 422 according to any of the techniques discussed herein. In some examples, the wearable device 402 can display the authentication code 422 on the display 418 of the wearable device 402. In some examples, in response to detecting the optical tag 442, the wearable device 402 can display an interface for receiving the authentication code 422, and the wearable device 402 can receive and display the authentication code 422 in the interface according to any of the techniques discussed herein.
[0085] Figure 5A and Figure 5B shows an example of a wearable device 502. The wearable device 502 can be Figures 1A to 1F the wearable device 102 of Figure 2A and Figure 2B the wearable device 202 of Figure 3 the wearable device 302 of and / or Figure 4 the wearable device 402 of, and can include any of the details discussed with reference to those figures. The wearable device 502 can be a head-mounted wearable device, such as smart glasses or augmented reality glasses. The wearable device 502 can include display capabilities, computing / processing capabilities, and object tracking capabilities. Figure 5A is a front view of the wearable device 502, and Figure 5B is a rear view of the wearable device 502. Although an AR device is depicted in Figure 5A and Figure 5B , it should be noted that the techniques discussed herein can also be applied to VR devices.
[0086] The wearable device 502 includes a frame 510. The frame 510 includes a front frame portion 520 and a pair of temple portions 530 that are rotatably coupled to the front frame portion 520 via respective hinge portions 540. The front frame portion 520 includes an edge portion 523 surrounding a respective optical portion in the form of a lens 527, wherein a bridge portion 529 connects the edge portions 523. The temple portions 530 are coupled to the front frame portion 520 at an outer peripheral portion of the respective edge portions 523, e.g., pivotally or rotatably coupled to the front frame portion. In some examples, the lens 527 is a corrective / prescription lens. In some examples, the lens 527 is an optical material including glass and / or plastic portions that do not necessarily contain corrective / prescription parameters.
[0087] In some examples, the wearable device 502 includes a display device 504 that can output visual content, e.g., at a display 505 (e.g., an output coupler), such that the visual content is visible to the user. For discussion and illustration purposes only, the display device 504 can be disposed in one of the two temple portions 530. The display device 504 can be disposed in each of the two temple portions 530 to provide a binocular output of the content. In some examples, the display device 504 can be a see-through near-eye display. In some examples, the display device 504 can be configured to project light from a display source onto a portion of a teleprompter glass that serves as a beam splitter and is disposed at an angle (e.g., 30 - 45 degrees). The beam splitter can allow reflection and transmission values that allow light from the display source to be partially reflected while the remaining light is transmitted through. Such an optical design can allow the user to see two physical items in the world, e.g., through the lens 527, in proximity to the content output by the display device 504 (e.g., authentication codes, digital images, user interface elements, virtual content, etc.). In some implementations, waveguide optics can be used to depict content on the display device 504.
[0088] In some examples, the wearable device 502 includes one or more audio output devices 506 (such as, e.g., one or more speakers), a lighting device 508, a sensing system 511, a control system 512, at least one processor 514, and a face-facing external image sensor 516 (e.g., a camera). In some examples, the sensing system 511 can include various sensing devices, and the control system 512 can include various control system devices that include, e.g., one or more processors 514 operatively coupled to components of the control system 512. In some examples, the control system 512 can include a communication module that provides communication and information exchange between the wearable device 502 and other external devices (e.g., Figure 1A computing device 130, central server 170, computing device 152).
[0089] In some examples, the wearable device 502 includes a gaze tracking device 515 for detecting and tracking the direction and movement of eye gaze. The data captured by the gaze tracking device 515 can be processed to detect and track the direction and movement of the gaze as user input. For purposes of discussion and illustration only, the gaze tracking device 515 is disposed in one of the two temple portions 530. In some examples, the gaze tracking device 515 is disposed in the same temple portion 530 as the display device 504, such that the user's eye gaze can be tracked not only with respect to objects in the physical environment, but also with respect to the content being output for display by the display device 504. In some examples, the gaze tracking device 515 can be disposed in each of the two temple portions 530 to provide gaze tracking for each of the user's two eyes. In some examples, the display device 504 can be disposed in each of the two temple portions 530 to provide a binocular display of visual content. In some examples, the wearable device 502 includes a head gaze point tracking device configured to calculate a head gaze point based on head orientation or head movement. The head gaze point is a point in space that a person looks at with their head. The head gaze point can be defined as the intersection of the lines of sight of the two eyes. The head gaze point can be used to track where a person is looking and to infer their attention. The wearable device 502 can use a camera and / or sensors to track the movement of the head. Data from the camera and / or sensors can be used to calculate the head gaze point.
[0090] Figure 6 A flowchart 600 depicting an example operation of a system for multi-factor authentication using a wearable device is shown. Although the flowchart 600 is described with reference to Figures 1A to 1F system 100, the flowchart 600 can be applicable to any implementation among the implementations disclosed herein. Although Figure 6 the flowchart 600 of Figure 6 shows these operations in an ordered sequence, it should be understood that this is merely an example and can include additional or alternative operations. Further,
[0091] Operation 602 includes receiving, by the wearable device 102, an authentication code 122 associated with multi-factor authentication. Operation 604 includes determining, by the wearable device 102, a location 120 for displaying the authentication code 122. Operation 606 includes displaying, by the wearable device 102, the authentication code 122 at the location 120 on the display 118 of the wearable device 102.
[0092] According to some aspects, obtaining an authentication code associated with multi-factor authentication includes receiving image data via an image camera of a wearable device and using optical character recognition to extract the authentication code from the image data. In some examples, obtaining an authentication code associated with multi-factor authentication includes receiving the authentication code from a computing device communicatively coupled to the wearable device. In some examples, obtaining an authentication code associated with multi-factor authentication includes receiving the authentication code from a central server. In some examples, the operation may include executing an authenticator application by the wearable device to obtain the authentication code. The location for displaying the authentication code may be determined based on a user interface (UI) element in the interface for receiving the authentication code.
[0093] The operation may include receiving an optical tag displayed on a computing device via an image camera of the wearable device and using the optical tag to identify the UI element, wherein the location of the authentication code is determined based on the positioning of the UI element in the interface. The optical tag is displayed on the computing device for a time interval greater than a non-perceptible threshold such that the optical tag is invisible to a person. The operation may include receiving image data of at least a portion of the interface displayed by the computing device via the image camera of the wearable device and using the image data to identify the UI element, wherein the location of the authentication code is determined based on the positioning of the UI element in the interface. The operation may include the wearable device determining a depth value between a portion of the wearable device and a portion of the computing device and the wearable device determining a font size of the authentication code, wherein the authentication code is displayed in the font size. The authentication code may include a first portion and a second portion, and the operation may include displaying the first portion of the authentication code on a display of the wearable device and using the wearable device to align the first portion of the authentication code displayed by the computing device with the second portion of the authentication code.
[0094] According to one aspect, a wearable device includes at least one processor and a non-transitory computer-readable medium storing executable instructions that cause the at least one processor to obtain an authentication code associated with multi-factor authentication, determine a location for displaying the authentication code, and display the authentication code at the location on a display of the wearable device or a display of a first computing device.
[0095] According to some aspects, the executable instructions include instructions that cause at least one processor to perform the following operations: receive image data of an authentication code displayed by a second computing device via an image camera of the wearable device, and extract the authentication code from the image data using optical character recognition. The executable instructions include instructions that cause at least one processor to receive the authentication code from a first computing device, a second computing device, or a central server. The executable instructions include instructions that cause at least one processor to execute an authenticator application to obtain the authentication code. The executable instructions include instructions that cause at least one processor to perform the following operations: receive an optical tag displayed on a first computing device via an image camera of the wearable device, and use the optical tag to identify a user interface (UI) element in an interface associated with the optical tag, wherein the position of the authentication code is determined based on the positioning of the UI element in the interface.
[0096] The executable instructions include instructions that cause at least one processor to perform the following operations: receive image data of at least a portion of an interface displayed by a first computing device via an image camera of the wearable device, and use the image data to identify a user interface (UI) element in the interface, wherein the position of the authentication code is determined based on the positioning of the UI element in the interface. The executable instructions include instructions that cause at least one processor to transmit information including the authentication code to the first computing device, the information being configured to cause the first computing device to display the authentication code in a code entry field.
[0097] According to one aspect, a non-transitory computer-readable medium storing executable instructions that cause at least one processor to perform operations, wherein the operations include: detecting, by the wearable device, an authentication request associated with multi-factor authentication; in response to the authentication request, displaying a gaze interface on a display of the wearable device; receiving, via the gaze interface, a plurality of gaze gestures; determining whether the plurality of gaze gestures correspond to a stored eye gesture pattern; and authenticating the authentication request in response to determining that the plurality of gaze gestures correspond to the stored eye gesture pattern.
[0098] In some examples, the operations include receiving, via an image camera of the wearable device, an optical tag displayed on a first computing device, and detecting the authentication request in response to the optical tag.
[0099] Clause 1. A computer-implemented method, comprising: receiving, by a wearable device, an authentication code associated with multi-factor authentication; determining, by the wearable device, a position for displaying the authentication code; and displaying, by the wearable device, the authentication code at the position on a display of the wearable device.
[0100] Clause 2. The computer-implemented method as described in Clause 1, wherein receiving the authentication code associated with the multi-factor authentication comprises: receiving image data via an image camera of the wearable device; and using optical character recognition to extract the authentication code from the image data.
[0101] Clause 3. The computer-implemented method as described in Clause 1 or 2, wherein receiving the authentication code associated with the multi-factor authentication comprises: receiving the authentication code from a computing device communicatively coupled to the wearable device.
[0102] Clause 4. The computer-implemented method as described in any one of Clauses 1 to 3, wherein receiving the authentication code associated with the multi-factor authentication comprises: receiving the authentication code from a server.
[0103] Clause 5. The computer-implemented method as described in any one of Clauses 1 to 4, further comprising: executing an authenticator application by the wearable device; and receiving the authentication code from the authenticator application.
[0104] Clause 6. The computer-implemented method as described in any one of Clauses 1 to 5, wherein the location for displaying the authentication code is determined based on a user interface (UI) element in the interface for receiving the authentication code.
[0105] Clause 7. The computer-implemented method as described in Clause 6, further comprising: receiving an optical tag displayed on a computing device via an image camera of the wearable device; and using the optical tag to identify the UI element, wherein the location of the authentication code is determined based on the positioning of the UI element in the interface.
[0106] Clause 8. The computer-implemented method as described in Clause 7, wherein the optical tag is displayed on the computing device for a time interval greater than a non-perception threshold such that the optical tag is invisible to a person.
[0107] Clause 9. The computer-implemented method as described in Clause 6, further comprising: receiving image data of at least a portion of the interface displayed by a computing device via an image camera of the wearable device; and using the image data to identify the UI element, wherein the location of the authentication code is determined based on the positioning of the UI element in the interface.
[0108] Clause 10. The computer-implemented method as described in any one of Clauses 1 to 9 further includes: determining, by the wearable device, a depth value between a part of the wearable device and a part of the computing device; and determining, by the wearable device, a font size of the authentication code based on the depth value, wherein the authentication code is displayed in the font size.
[0109] Clause 11. The computer-implemented method as described in any one of Clauses 1 to 10 further includes: displaying, on the display of the wearable device, a first part of the authentication code; and aligning, based on head movement, the first part of the authentication code displayed by the computing device with a second part of the authentication code.
[0110] Clause 12. A wearable device includes: at least one processor; and a non-transitory computer-readable medium storing executable instructions that cause the at least one processor to: receive an authentication code associated with multi-factor authentication; determine a position for displaying the authentication code; and display the authentication code at the position on a display of the wearable device or a display of a first computing device.
[0111] Clause 13. The wearable device as described in Clause 12, wherein the executable instructions include instructions that cause the at least one processor to: receive, via an image camera of the wearable device, image data of the authentication code displayed by a second computing device; and extract the authentication code from the image data using optical character recognition.
[0112] Clause 14. The wearable device as described in Clause 13, wherein the executable instructions include instructions that cause the at least one processor to: receive the authentication code from the first computing device, the second computing device, or a server.
[0113] Clause 15. The wearable device as described in any one of Clauses 12 to 14, wherein the executable instructions include instructions that cause the at least one processor to: execute instructions of an authenticator application; and receive the authentication code from the authenticator application.
[0114] Clause 16. The wearable device as described in any one of Clauses 12 to 15, wherein the executable instructions include instructions that cause the at least one processor to: receive, via an image camera of the wearable device, an optical tag displayed on the first computing device; and use the optical tag to identify a user interface (UI) element in an interface associated with the optical tag, wherein the position of the authentication code is determined based on the positioning of the UI element in the interface.
[0115] Clause 17. The wearable device as described in any one of Clauses 12 to 16, wherein the executable instructions include instructions that cause the at least one processor to perform the following operations: receiving, via an image camera of the wearable device, image data of at least a portion of an interface displayed by the first computing device; and using the image data to identify a user interface (UI) element in the interface, wherein the position of the authentication code is determined based on the positioning of the UI element in the interface.
[0116] Clause 18. The wearable device as described in any one of Clauses 12 to 17, wherein the executable instructions include instructions that cause the at least one processor to perform the following operation: transmitting, to the first computing device, information including the authentication code, the information being configured to cause the first computing device to display the authentication code in a code entry field.
[0117] Clause 19. A non-transitory computer-readable medium storing executable instructions that cause at least one processor to perform operations, the operations including: detecting, by a wearable device, an authentication request associated with multi-factor authentication; in response to the authentication request, displaying a gaze interface on a display of the wearable device; receiving, via the gaze interface, a plurality of gaze gestures; determining whether the plurality of gaze gestures correspond to a stored eye gesture pattern; and authenticating the authentication request in response to the plurality of gaze gestures being determined to correspond to the stored eye gesture pattern.
[0118] Clause 20. The non-transitory computer-readable medium as described in Clause 19, further including: receiving, via an image camera of the wearable device, an optical tag displayed on a first computing device; and detecting the authentication request in response to the optical tag.
[0119] Clause 21. A computer-implemented method, including: receiving, by a head-mounted display device, an authentication code associated with multi-factor authentication; receiving, from an image camera on the head-mounted display device, image data; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code at a position corresponding to the interface.
[0120] Clause 22. The computer-implemented method as described in Clause 21, wherein the image data is first image data, and wherein receiving the authentication code associated with the multi-factor authentication includes: detecting the authentication code from second image data received from the image camera.
[0121] Clause 23. The computer-implemented method as described in Clause 21, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from a computing device communicatively coupled to the head-mounted display device.
[0122] Clause 24. The computer-implemented method as described in Clause 21, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from a server computer.
[0123] Clause 25. The computer-implemented method as described in Clause 21, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from an authenticator application executed on the head-mounted display device.
[0124] Clause 26. The computer-implemented method as described in any one of Clauses 21 to 25, further comprising: estimating the positioning of the interface in a three-dimensional (3D) space based on the image data, wherein the authentication code is displayed at the positioning.
[0125] Clause 27. The computer-implemented method as described in any one of Clauses 21 to 26, wherein the authentication code is configured to be anchored to the position regardless of head movement.
[0126] Clause 28. The computer-implemented method as described in any one of Clauses 21 to 27, wherein the interface includes a code entry field, and wherein the authentication code is positioned at a location external to the code entry field.
[0127] Clause 29. The computer-implemented method as described in any one of Clauses 21 to 28, wherein the image data is first image data, and the method further comprises: detecting characters entered for the authentication code on the interface based on second image data from the image camera; and adjusting a display appearance of the characters based on whether the characters are accurate.
[0128] Clause 30. The computer-implemented method as described in any one of Clauses 21 to 29, further comprising: determining, by the head-mounted display device, a depth value of the interface; and determining, by the head-mounted display device, a font size of the authentication code based on the depth value, wherein the authentication code is displayed in the font size.
[0129] Clause 31. The computer-implemented method as described in any one of Claims 21 to 30, further comprising: displaying, on the head-mounted display device, a first portion of the authentication code; and aligning, based on head movement, the first portion of the authentication code displayed by a computing device with a second portion of the authentication code.
[0130] Clause 32. A head-mounted display device storing executable instructions that cause at least one processor to execute any one of Clauses 21 to 31.
[0131] Clause 33. A head-mounted display device comprising at least one processor and a non-transitory computer-readable medium storing executable instructions that cause the at least one processor to perform operations including: receiving, by the head-mounted display device, an authentication code associated with multi-factor authentication; receiving, from an image camera on the head-mounted display device, image data; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code at a position corresponding to the interface.
[0132] Clause 34. The head-mounted display device according to Clause 33, wherein the image data is first image data, and wherein receiving the authentication code associated with the multi-factor authentication includes: detecting the authentication code from second image data received from the image camera.
[0133] Clause 35. The head-mounted display device according to Clause 33, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from a computing device communicatively coupled to the head-mounted display device.
[0134] Clause 36. The head-mounted display device according to Clause 33, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from a server computer.
[0135] Clause 37. The head-mounted display device according to Clause 33, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from an authenticator application executing on the head-mounted display device.
[0136] Clause 38. The head-mounted display device according to any one of Clauses 33 to 37, further comprising: estimating, based on the image data, a positioning of the interface in a three-dimensional (3D) space, wherein the authentication code is displayed at the positioning.
[0137] Clause 39. The head-mounted display device according to any one of Clauses 33 to 38, wherein the authentication code is configured to be anchored to the position regardless of head movement.
[0138] Clause 40. The head-mounted display device according to any one of Clauses 33 to 39, wherein the interface includes a code entry field, and wherein the authentication code is positioned at a location external to the code entry field.
[0139] Clause 41. The head-mounted display device as described in any one of Clauses 33 to 40, wherein the image data is first image data, further comprising: detecting characters of the authentication code entered on the interface based on second image data from the image camera; and adjusting a display appearance of the characters based on whether the characters are accurate.
[0140] Clause 42. The head-mounted display device as described in any one of Clauses 33 to 41, further comprising: determining, by the head-mounted display device, a depth value of the interface; and determining, by the head-mounted display device, a font size of the authentication code based on the depth value, wherein the authentication code is displayed in the font size.
[0141] Clause 43. The computer-implemented method as described in any one of Claims 33 to 42, further comprising: displaying, on the head-mounted display device, a first portion of the authentication code; and aligning the first portion of the authentication code with a second portion of the authentication code displayed by a computing device based on head movement.
[0142] Clause 44. A computer program product storing executable instructions that cause at least one processor to execute any one of Clauses 21 to 31.
[0143] Clause 45. A method comprising: detecting, by a head-mounted display device, an authentication request; in response to the authentication request, displaying an interface; receiving, via the interface, a plurality of gestures; determining whether the plurality of gestures correspond to a stored gesture pattern; and authenticating the authentication request in response to the plurality of gestures being determined to correspond to the stored gesture pattern.
[0144] Clause 46. The method as described in Clause 45, wherein the plurality of gestures include eye gestures.
[0145] Clause 47. The method as described in Clause 45, wherein the plurality of gestures include head gestures.
[0146] Clause 48. The method as described in any one of Clauses 45 to 47, wherein detecting the authentication request includes receiving the authentication request from a computing device.
[0147] Clause 49. The method as described in any one of Clauses 45 to 48, further comprising: receiving, from an image camera on the head-mounted display device, image data; detecting that the image data includes an optical tag; and detecting the authentication request in response to the optical tag.
[0148] Clause 50. The method as described in Clause 49, wherein the optical tag is displayed on the computing device during a time interval greater than the non-perception threshold such that the optical tag is invisible to a person.
[0149] Clause 51. A head-mounted display device storing executable instructions, the executable instructions causing at least one processor to execute any one of Clauses 45 to 50.
[0150] Clause 52. A computer program product storing executable instructions, the executable instructions causing at least one processor to execute any one of Clauses 45 to 50.
[0151] Clause 53. A head-mounted display device, comprising at least one processor and a non-transitory computer-readable medium storing executable instructions, the executable instructions causing the at least one processor to perform operations, the operations including: detecting an authentication request by the head-mounted display device; in response to the authentication request, displaying an interface; receiving a plurality of gestures via the interface; determining whether the plurality of gestures correspond to a stored gesture pattern; and authenticating the authentication request in response to the plurality of gestures being determined to correspond to the stored gesture pattern.
[0152] Clause 54. The head-mounted display device as described in Clause 53, wherein the plurality of gestures includes eye gestures.
[0153] Clause 55. The method as described in Clause 53, wherein the plurality of gestures includes head gestures.
[0154] Clause 56. The method as described in any one of Clauses 53 to 55, wherein detecting the authentication request includes receiving the authentication request from a computing device.
[0155] Clause 57. The method as described in any one of Clauses 53 to 56, further comprising: receiving image data from an image camera on the head-mounted display device; detecting that the image data includes an optical tag; and detecting the authentication request in response to the optical tag.
[0156] Clause 58. The method as described in Clause 57, wherein the optical tag is displayed on the computing device during a time interval greater than the non-perception threshold such that the optical tag is invisible to a person.
[0157] Various implementations of the systems and techniques described herein can be implemented in digital electronic circuitry, integrated circuit systems, specially designed ASICs (Application Specific Integrated Circuits), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementations in one or more computer programs executable and / or interpretable on a programmable system including at least one programmable processor which may be special purpose or general purpose and coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device. Additionally, the term "module" can include software and / or hardware.
[0158] These computer programs (also referred to as programs, software, software applications, or code) include machine instructions for a programmable processor and can be implemented using high-level procedural and / or object-oriented programming languages and / or assembly / machine languages. As used herein, the terms "machine-readable medium", "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0159] For providing interaction with a user, the systems and techniques described herein can be implemented on a computer having a display device (e.g., a CRT (Cathode Ray Tube) or LCD (Liquid Crystal Display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
Claims
1. A computer-implemented method, comprising: receiving, by a head-mounted display device, an authentication code associated with multi-factor authentication; receiving, from an image camera on the head-mounted display device, image data; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code at a position corresponding to the interface.
2. The computer-implemented method according to claim 1, wherein the image data is first image data, and receiving the authentication code associated with the multi-factor authentication includes: detecting the authentication code from second image data received from the image camera.
3. The computer-implemented method according to claim 1, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from a computing device communicatively coupled to the head-mounted display device.
4. The computer-implemented method according to claim 1, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from a server computer.
5. The computer-implemented method according to claim 1, wherein receiving the authentication code associated with the multi-factor authentication includes: receiving the authentication code from an authenticator application executed on the head-mounted display device.
6. The computer-implemented method according to any one of claims 1 to 5, further comprising: estimating, based on the image data, the positioning of the interface in three-dimensional (3D) space, wherein the authentication code is displayed at the positioning.
7. The computer-implemented method according to any one of claims 1 to 6, wherein the authentication code is configured to be anchored to the position regardless of head movement.
8. The computer-implemented method according to any one of claims 1 to 7, wherein the interface includes a code entry field, and the authentication code is positioned at a location outside the code entry field.
9. The computer-implemented method according to any one of claims 1 to 8, wherein the image data is first image data, and the method further includes: detecting, based on second image data from the image camera, characters entered for the authentication code on the interface; and adjusting, based on whether the characters are accurate, the display appearance of the characters.
10. The computer-implemented method according to any one of claims 1 to 9, further comprising: determining, by the head-mounted display device, a depth value of the interface; and determining, by the head-mounted display device, a font size of the authentication code based on the depth value, wherein the authentication code is displayed in the font size.
11. The computer-implemented method according to any one of claims 1 to 10, further comprising: displaying, on the head-mounted display device, a first portion of the authentication code; and aligning, based on head movement, the first portion of the authentication code with a second portion of the authentication code displayed by a computing device.
12. A head-mounted display device storing executable instructions, the executable instructions causing at least one processor to execute any one of claims 1 to 11.
13. A computer program product storing executable instructions, the executable instructions causing at least one processor to execute any one of claims 1 to 11.
14. A method, comprising: detecting, by a head-mounted display device, an authentication request; displaying an interface in response to the authentication request; receiving, via the interface, a plurality of gestures; determining whether the plurality of gestures corresponds to a stored gesture pattern; and authenticating the authentication request in response to the plurality of gestures being determined to correspond to the stored gesture pattern.
15. The method according to claim 14, wherein the plurality of gestures includes eye gestures.
16. The method according to claim 14, wherein the plurality of gestures includes head gestures.
17. The method according to any one of claims 14 to 16, wherein detecting the authentication request includes receiving the authentication request from a computing device.
18. The method according to any one of claims 14 to 17, further comprising: receiving image data from an image camera on the head-mounted display device; detecting that the image data includes an optical tag; and detecting the authentication request in response to the optical tag.
19. The method according to claim 18, wherein the optical tag is displayed on the computing device for a time interval greater than a non-perception threshold such that the optical tag is invisible to a person.
20. A head-mounted display device storing executable instructions, the executable instructions causing at least one processor to execute any one of claims 14 to 19.
21. A computer program product storing executable instructions, the executable instructions causing at least one processor to execute any one of claims 14 to 19.