Multi-factor authentication using wearable devices

A wearable device secures and speeds up multi-factor authentication by displaying codes at corresponding UI elements, addressing inefficiencies and vulnerabilities in conventional methods.

JP2026503191APending Publication Date: 2026-01-28GOOGLE LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025525045
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-11-01
Filing Date
2023-10-27
Publication Date
2026-01-28

AI Technical Summary

Technical Problem

Conventional multi-factor authentication methods, particularly those involving SMS codes, are inefficient and can compromise security due to the need for manual entry of authentication codes, which increases time and vulnerability.

Method used

A wearable device, such as a head-mounted display, receives and displays authentication codes at specific locations corresponding to UI elements on a user's computing device, using optical character recognition or wireless communication, allowing for secure and efficient entry of codes without manual typing.

Benefits of technology

The wearable device enhances security and reduces the time required for multi-factor authentication by anchoring the code to a UI element, maintaining security while streamlining the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026503191000001_ABST
    Figure 2026503191000001_ABST
Patent Text Reader

Abstract

According to one aspect, a method includes receiving, by a head-mounted display device, an authentication code associated with multi-factor authentication; receiving image data from an image camera on the head-mounted display device; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code in a location corresponding to the interface.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Provisional Patent Application No. 63 / 381,868, filed November 1, 2022, the disclosure of which is incorporated herein by reference in its entirety. [Background technology]

[0002] Multi-factor authentication is an electronic authentication method in which a user presents two or more pieces of evidence to an authentication mechanism that, if successful, grants access to computer resources. In some instances, particularly in the case of Short Message Service (SMS) codes, a user may be required to read the code on a mobile phone and enter the code on another device. Summary of the Invention

[0003] The present system provides a technical solution for achieving multi-factor authentication with a wearable device in a secure and reliable manner, and may reduce the time it takes a user to complete the multi-factor authentication while maintaining a relatively high level of security for computer resources protected by the multi-factor authentication. The wearable device may receive an authentication code associated with the multi-factor authentication, determine a location to display the authentication code, and display the authentication code on a display of the wearable device at the determined location. In some examples, the location is determined based on the location of a UI element (e.g., a code entry field) within an interface displayed by the computing device.

[0004] In some aspects, the techniques described herein relate to a computer-implemented method that includes receiving, by a head-mounted display device, an authentication code associated with multi-factor authentication; receiving image data from an image camera on the head-mounted display device; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code in a location corresponding to the interface.

[0005] In some aspects, the techniques described herein relate to a method that includes detecting, by a head-mounted display device, a request for authentication; displaying an interface in response to the request for authentication; receiving, via the interface, a plurality of gestures; determining whether the plurality of gestures corresponds to a stored pattern of gestures; and authenticating the authentication request in response to determining that the plurality of gestures corresponds to the stored gesture pattern.

[0006] The details of one or more implementations are set forth in the accompanying drawings and the description below. Other features will be apparent from the description and drawings, and from the claims. [Brief explanation of the drawings]

[0007] [Figure 1A] 1 illustrates a system for multi-factor authentication using a wearable device according to one aspect. [Figure 1B] 1 illustrates an example of a wearable device displaying an authentication code according to one embodiment. [Figure 1C] 1 illustrates an example of a wearable device displaying an authentication code on an interface of a computing device according to one aspect. [Figure 1D] 1 illustrates an example of an authentication code displayed in a code entry field of an interface of a computing device according to one aspect. [Figure 1E] 1 illustrates an example of an authentication code displayed above a code entry field on an interface of a computing device according to one aspect. [Figure 1F] 1 illustrates an example of a wearable device for determining the font size of an authentication code according to one embodiment. [Figure 2A] 1 illustrates an example of a wearable device displaying a first portion of an authentication code according to one embodiment. [Figure 2B] 1 illustrates an example of a wearable device displaying a second portion of an authentication code according to one embodiment. [Figure 2C] 1 illustrates a first portion of an authentication code aligned with a second portion of the authentication code according to one embodiment. [Figure 3] 1 illustrates an example of a wearable device illustrating a gaze interface for multi-factor authentication according to one aspect. [Figure 4] 1 illustrates an example of a light label being inserted into a web page for multi-factor authentication according to one aspect. [Figure 5A] FIG. 1 illustrates a front view of a head-mounted wearable device according to one embodiment. [Figure 5B] FIG. 1 illustrates a rear view of a head-mounted wearable device according to one embodiment. [Figure 6] 1 illustrates an example operation of a system for multi-factor authentication using a wearable device according to one aspect. DETAILED DESCRIPTION OF THE INVENTION

[0008] The present disclosure relates to a system for multi-factor authentication using a wearable device, where the wearable device can receive an authentication code and display at least a portion of the authentication code. The wearable device can be a head-mounted display device. In some examples, the wearable device displays the authentication code at a position (e.g., a 3D position) corresponding to a position (e.g., a 3D position) of a real-world object (e.g., a UI element on a screen in front of the user). For example, the authentication code is positioned (e.g., attached, anchored) to a particular UI element on an interface displayed by the user device (e.g., the device's interface is in front of the user). For example, the authentication code is anchored to that location regardless of head movement. In some examples, the UI element is a code entry field, and the wearable device displays the authentication code at a position corresponding to (or adjacent to) the position of the code entry field. In some examples, the wearable device includes an augmented reality (AR) display device (e.g., smart glasses). In some examples, the wearable device includes a virtual reality (VR) headset. In some examples, the user can enter the authentication code on the user device while viewing the authentication code on the wearable device.

[0009] In some examples, the wearable device receives the authentication code by detecting it from image data captured by one or more image cameras on the wearable device. The image camera(s) can generate image data about the user's surroundings. In some examples, the wearable device detects the authentication code from the image data using optical text recognition. For example, a user can use a first user device (e.g., a laptop), access a resource protected by multi-factor authentication, and enter login / password information to complete the first verification factor, which then sends an authentication code to a second user device (e.g., the user's smartphone) to complete the second verification factor. In some examples, instead of sending an authentication code, the authentication may be visible from an authentication application on the user's smartphone. While the user is looking at their smartphone, the wearable device can receive image data of the authentication code displayed on the user's smartphone via the image camera(s). The wearable device can extract the authentication code from the image data. A smartphone and a laptop are used as examples of the first and second user devices, but the first and second user devices may be any type of user device, such as a tablet, desktop computer, smartwatch, game console, television, etc.

[0010] In some examples, the wearable device receives an authentication code from a second user device (e.g., a smartphone) via a wireless connection (e.g., a direct Wi-Fi connection, a short-range wireless connection (e.g., a Bluetooth connection), etc.). In some examples, the wearable device receives the authentication code from a central server. In some examples, an operating system of the second user device can detect the authentication code, and the operating system can be associated with a user account linked to other devices, including the wearable device. When the wearable device and the second user device are associated with the same user account, the wearable device can receive the authentication code from the second user device and / or the central server.

[0011] To receive the authentication code, the wearable device can display the authentication code in a location (e.g., a 3D location) that corresponds to a location (e.g., a 3D location) of an interface displayed by the first user device (e.g., a laptop). In some examples, the location of the code is based on the location of a particular UI element (e.g., a code input field, a light label, etc.) in the interface displayed on the first user device. In other words, in some examples, the wearable device can anchor the authentication code to a particular UI element in the interface displayed by the first user device.

[0012] In some examples, the authentication code is fixedly anchored to an object (e.g., a UI element), and as the UI element moves, the authentication code also moves. For example, as a particular UI element moves to a different location within the user's field of view (e.g., the user moves their head), the authentication code remains anchored to the particular UI element (e.g., moves with the particular UI element). In some examples, the wearable device can overlay the authentication code on a code input field of an interface for receiving the authentication code. In some examples, the wearable device can display the authentication code in a location adjacent (e.g., above, below, adjacent, etc.) to the code input field for receiving the authentication code. The user can then use the first user device to input the authentication code into the code input field (e.g., type the code into the code input field). In some examples, the wearable device displays the authentication code in the code input field (e.g., spatially locating the authentication code within a box). In some examples, the wearable device can determine a font size of the authentication code based on a depth (e.g., a depth value) between the wearable device and the first user device (e.g., how far a smartphone is from the wearable device). The user can then use the first user device to enter the authentication code.

[0013] In some examples, each time the user types a new character, the wearable device erases the character. In some examples, each time the user types a new character, the wearable device changes a display characteristic of the character (e.g., changes color, transparency, contrast, etc.). In some examples, if an incorrect character is entered, the wearable device may highlight the character (e.g., highlight it in red). In some examples, instead of overlaying authentication on an interface displayed by the first user device, the wearable device may communicate with a browser application running on the first user device and prompt the user to enter an authentication code into a code entry field.

[0014] In some examples, instead of displaying an authentication code on the wearable device, the wearable device can detect an authentication request for multi-factor authentication, and in response to the authentication request, the wearable device can render a gaze interface. For example, the wearable device can receive multiple gaze gestures via the gaze interface, determine whether the gaze gestures correspond to stored patterns of eye gestures, and in response to determining that the gaze gestures correspond to the stored patterns of eye gestures, the wearable device can authenticate the authentication request, thereby providing access to underlying computer resources protected by multi-factor authentication.

[0015] In some examples, the wearable device receives a first portion of the authentication code and displays the first portion of the authentication code on a display of the wearable device. A second portion of the authentication code may be displayed on the first user device. In some examples, the authentication code may be visible to the user when the first portion is aligned with the second portion. These and other features are further described with reference to the drawings.

[0016] 1A-1F illustrate a system 100 for multi-factor authentication using a wearable device 102 according to various aspects. The wearable device 102 can obtain an authentication code 122 associated with the multi-factor authentication (e.g., two-factor authentication, three-factor authentication, or more than three-factor authentication, etc.), determine a location 120 at which to display the authentication code 122, and, in some examples, display the authentication code 122 on a display 118 of the wearable device 102 at the location 120.

[0017] Multi-factor authentication is an authentication method that requires a user to provide two or more verification factors to gain access to a computer resource, such as an application, online account, or virtual private network. In some examples, the verification factors may include receiving a user's authentication credentials (e.g., username, account identifier, password, etc.), receiving a user's biometric(s) (e.g., fingerprint, facial recognition, iris recognition, voice recognition, etc.), receiving an authentication code 122, and / or information indicative of the presence of a physical token or smart card. In some examples, the authentication code 122 is generated in response to successful authentication of the first verification factor (e.g., the user enters the correct username / password, enters the correct PIN, etc.).

[0018] In some examples, authentication code 122 is generated by a computer resource, such as a web resource (e.g., a web page visited by a user) or an application (e.g., application 104 or application 134) running on a user device (e.g., computing device 130 or computing device 152). In some examples, authentication code 122 is sent to the user via a message (e.g., a text message or email message). For example, a user may provide their email address or phone number associated with a particular computer resource that has multi-factor authentication, and upon successful completion of the first verification factor, a text message or email (containing authentication code 122) arrives at the user's device (e.g., computing device 130 or computing device 152).

[0019] In some examples, authentication code 122 is generated by an authentication application. Separate instances of the authentication application are represented by authentication application 106 (executing on wearable device 102), authentication application 136 (executing on computing device 130), and / or authentication application 158 (executing on computing device 152). The authentication application (e.g., 106, 136, 158) can periodically (over time) update authentication code 122, and in some examples, a user can view authentication code 122 from the authentication application's user interface. For example, when the authentication application is launched, the authentication application can display authentication code 122 associated with a particular computer resource that has multi-factor authentication.

[0020] In some examples, the underlying computing device (e.g., operating system) can communicate with an authentication application (e.g., via inter-process communication (IPC)) to obtain authentication code 122, which can be provided to other devices (e.g., devices having operating systems associated with the same user account 172), including wearable device 102. For example, wearable device 102 can obtain authentication code 122 from authentication application 106. In some examples, wearable device 102 can obtain authentication code 122 from authentication application 136 of computing device 130 when the operating system of wearable device 102 and operating system 132 of computing device 130 are associated with the same user account 172. In some examples, wearable device 102 can obtain authentication code 122 from authentication application 158 of computing device 152 when the operating system of wearable device 102 and operating system 154 of computing device 152 are associated with the same user account 172.

[0021] The authentication code 122 may include a combination of characters (e.g., numbers, symbols, letters, etc.) used to verify the identity of a user. In some examples, the authentication code 122 includes a first character, a second character, a third character, etc. In some examples, the authentication code 122 is associated with a sequence of characters (e.g., the second character must be positioned after the first character).

[0022] More specifically, when a user gains access to a computer resource associated with multi-factor authentication (e.g., an online account on a web page), the user can use their computing device (e.g., computing device 152) to provide their authentication credentials (e.g., username, password) on the interface of the computer resource, which may be considered a first verification factor in multi-factor authentication. In some examples, a second verification factor is required to gain access to the computer resource. In some conventional approaches, an email or text message is sent to the user, and the email or text message includes an authentication code 122. In some examples, the authentication code 122 is generated by the computer resource (e.g., a web page) that hosts the online account. In some examples, the authentication code 122 is generated and displayed by an authentication application (e.g., authentication application 136) running on a mobile device. The user then verifies the authentication code 122 and enters the authentication code 122 on the web page of the online account.

[0023] As described herein, system 100 provides a technical solution for achieving multi-factor authentication in a secure and reliable manner using wearable device 102. In some examples, system 100 can reduce the time it takes a user to complete multi-factor authentication while maintaining a relatively high level of security for computer resources protected by the multi-factor authentication.

[0024] The wearable device 102 may include a head-mounted display (HMD) device, such as an optical head-mounted display (OHMD) device, a transparent head-up display (HUD) device, an augmented reality (AR) device, a virtual reality (VR) device, or other devices, such as goggles or a headset, having sensors, a display, and computing capabilities. In some examples, the wearable device includes an AR device. In some examples, the wearable device includes smart glasses. Smart glasses are optical head-mounted display devices designed in the shape of glasses. Smart glasses may be glasses that add information (e.g., project a display 118) in addition to what the wearer sees through the glasses (e.g., the wearer can see an interface 164 for receiving the authentication code 122 through the glasses). Smart glasses may allow a user to see (e.g., through the lenses) physical items in the real world and content rendered in the display 118 (e.g., the authentication code 122, digital images, user interface elements, virtual content, etc.).

[0025] In some examples, the wearable device 102 includes a VR device that provides a partially (or fully) immersive VR environment. The VR device is a head-mounted display (HMD) that creates a simulated environment for the user. The AR device can be eyewear or a handheld device that uses cameras and sensors to track the user's surroundings. AR devices can display digital information, such as route guidance, product information, or virtual characters and objects, over the real world. VR devices are typically headsets that completely block out the real world and replace it with a virtual world. However, VR devices may include image camera(s) 116 that capture image data 101 in front of the user (or around the user, or partial surroundings). The VR device uses sensors to track the user's head movement and adjust the virtual environment accordingly. An augmented reality (XR) device may include a VR device and an AR device. In some examples, the XR device has two screens for each eye. The screens display slightly different images, creating the illusion of depth. The XR device also has sensors that track the user's head movement, allowing the virtual environment to move with the user's head.

[0026] The wearable device 102 may include one or more processors 103 and one or more memory devices 105. The processor(s) 103 may be formed on a substrate configured to execute one or more machine-executable instructions or portions of software, firmware, or combinations thereof (e.g., to perform any of the operations described herein for the wearable device 102). The processor(s) 103 may be semiconductor-based, i.e., the processor may include semiconductor material capable of executing digital logic. The memory device(s) 105 may include a non-transitory computer-readable medium that stores executable instructions that cause the processor(s) 103 to perform the operations described herein for the wearable device 102. In some examples, the memory device(s) 105 may include a main memory that stores information in a format that can be read and / or executed by the processor(s) 103. The memory device(s) 105 may store applications 104 that, when executed by the processor(s) 103, perform certain operations.

[0027] In some examples, the application 104 includes an authentication application 106. The authentication application 106 can periodically generate an authentication code 122. For example, the authentication application 106 can be enabled for a particular computer resource that performs multi-factor authentication, and in some examples, the authentication application 106 can periodically update the authentication code 122 (e.g., change the authentication code 122 every predetermined period) for that particular computer resource.

[0028] The wearable device 102 may include a display device 110 configured to project a display 118 into the user's field of view. In some examples, the display device 110 may be configured to project light from a display light source onto a portion of teleprompter glass mounted at an angle (e.g., 30-45 degrees) that acts as a beam splitter. The beam splitter may have reflectance and transmittance values ​​that partially reflect the light from the display light source and transmit the remaining light. Such an optical design allows the user to view content generated by the display device 110 (e.g., authentication code 122, digital images, user interface elements, virtual content, authentication code 122, etc.) adjacent to (or superimposed on) a physical item in the real world, for example, as seen through a lens (e.g., an interface 164 displayed on another computing device, such as computing device 152).

[0029] Wearable device 102 includes one or more image cameras 116. Image camera(s) 116 generate image data 101 of a physical scene within the camera's field of view. In some examples, for AR devices, the user's field of view (as seen through glasses) may correspond to the camera's field of view. In some examples, for AR devices, the camera's field of view is wider or smaller than the user's field of view. Image camera(s) 116 can capture what is displayed by computing device 130 or computing device 152 when the display screen of the computing device is within the image camera's field of view. Image camera(s) 116 can include cameras such as forward-facing, outward-facing, or world-facing cameras that can capture still and / or moving images of the wearable device's 102 external environment. In some examples, wearable device 102 is a VR device, and image camera 116 can capture the world in front of the user, including what is displayed by computing device 130 or computing device 152. In some examples, wearable device 102 can generate and display a computer-generated representation of a user device (e.g., computing device 130, computing device 152) when the user device is within the field of view of the image camera, including computer-generated graphics corresponding to what is displayed on the display screen.

[0030] The wearable device 102 may include other sensors, such as one or more position / orientation sensor(s) (e.g., an inertial measurement unit, an accelerometer, a gyroscope, and / or a magnetometer, etc.), one or more audio sensors capable of detecting audio input, one or more touch input sensors capable of detecting touch input, and other such sensors. In some examples, the wearable device 102 includes an eye-tracking device 117 that detects and tracks gaze direction and movement. Data captured by the eye-tracking device 117 may be processed to detect and track gaze direction and movement as user input.

[0031] Computing device 152 may be a laptop. In some examples, operating system 154 of computing device 152 is a desktop operating system. In some examples, operating system 154 of computing device 152 is a mobile operating system. However, computing device 152 may be any type of user device, such as a smartphone, tablet, desktop computer, game console, other wearable device, etc. Computing device 152 is configured to execute applications 156. Applications 156 may include authentication application 158 and browser application 160. However, applications 156 may include a variety of applications, such as native applications (e.g., installable on operating system 154), web applications (e.g., executable at least in part by browser application 160), mobile applications (e.g., executable in a mobile environment), and desktop applications (e.g., executable in a desktop environment). Authentication application 158 and browser application 160 may be separate instances of authentication application 106 and browser application 108, respectively, and therefore may include any of the details described with reference to those components.

[0032] A user may use computing device 152 to access a computer resource associated with (e.g., protected by) multi-factor authentication. In some examples, the computer resource is one of applications 156. In some examples, the computer resource is accessible via browser application 160. In some examples, the computer resource is a web page, an online account, or a web application. In some examples, in a first verification factor, the user provides their authentication credentials (e.g., submits a username / password), which initiates a second verification factor. In some examples, the second verification factor includes notifying the user of an authentication code 122, which is submitted via a code entry field 168 of interface 164 on display 162 of computing device 152.

[0033] 1A , in some examples, the authentication code 122 may be displayed on a display 140 of another computing device, such as a computing device 130. In some examples, the computing device 130 is a user device linked to a computer resource protected by multi-factor authentication. In some examples, the computing device 130 is a user device configured to generate or receive the authentication code 122 when a user successfully supplies their authentication credentials using a computing device 152. The computing device 130 may be a mobile device, such as a smartphone or tablet computer. In some examples, the operating system 132 of the computing device 130 is a mobile operating system.

[0034] However, computing device 130 may be any type of user device, such as a laptop, desktop computer, game console, other wearable device, etc. Computing device 130 is configured to execute applications 134. Applications 134 may include authentication application 136 and browser application 138. However, applications 134 may include a variety of applications, such as native applications (e.g., installable on operating system 132), web applications (e.g., executable at least in part by browser application 138), mobile applications (e.g., executable in a mobile environment), and desktop applications (e.g., executable in a desktop environment). Authentication application 136 and browser application 138 may be separate instances of authentication application 106 and browser application 108, respectively, and therefore may include any of the details described with reference to those components.

[0035] In some examples, computing device 130 receives a message (e.g., a text message or email), which includes authentication code 122. Authentication code 122 can be generated by a computer resource protected by multi-factor authentication. For example, in response to a successful first verification factor, computing device 130 can receive and display authentication code 122. In some examples, in response to a successful first verification factor, a user can use computing device 130 to launch authentication application 136, which displays authentication code 122 on display 140 of computing device 130. In some examples, authentication application 136 is a native (e.g., mobile) application installed on operating system 132 of computing device 130.

[0036] In some examples, the wearable device 102 can receive the image data 101 of the authentication code 122 via the image camera(s) 116. For example, a user can move the wearable device 102 so that the authentication code 122 displayed on the display 140 of the computing device 130 is within the field of view of the image camera(s) 116. The wearable device 102 can include an optical character recognition (OCR) scanner 114 configured to extract the authentication code 122 from the image data 101 using OCR technology. The OCR scanner 114 is configured to recognize text (e.g., the authentication code 122) in the image data 101 captured by the image camera(s) 116. In some examples, the OCR scanner 114 is configured to recognize and detect the authentication code 122 (e.g., rather than other text information that may be captured by the image camera 116). When the authentication code 122 is displayed (e.g., via text message, email, or displayed by the authentication application 136), the user wearing the wearable device 102 faces the computing device 130 so that the display 140 of the computing device is within the field of view of the image camera(s) 116. The wearable device 102 can use other image detection and recognition techniques to detect the authentication code 122. In some examples, the wearable device 102 includes a machine learning (ML) model (e.g., a neural network model). The ML model can be configured to identify and extract the authentication code 122 from the image data 101.

[0037] In some examples, instead of using text recognition from image data 101, wearable device 102 can receive authentication code 122 from computing device 130 via a wireless connection between wearable device 102 and computing device 130. In some examples, wearable device 102 and computing device 130 can be connected wirelessly. In some examples, the wireless connection is a direct Wi-Fi connection or a short-range communication link such as a near-field communication (NFC) connection or a Bluetooth connection. Wearable device 102 and computing device 130 can exchange information via the wireless connection. In some examples, the wireless connection defines an application layer protocol implemented using protocol buffers with message types for drawing graphic primitives, configuring sensors and peripherals, and changing device modes. In some examples, when a message (e.g., a text message) is received at computing device 130, the message is forwarded to wearable device 102 via the application layer protocol. In some examples, the wearable device 102 and the computing device 130 are devices associated with the same user account 172, such as a browser application, an operating system account, an authentication account, or other type of user account 172. In some examples, the wearable device 102 can receive the authentication code 122 from the computing device 130 via the central server 170.

[0038] If authentication code 122 is received or generated by computing device 152, wearable device 102 can obtain authentication code 122 from computing device 152 in the same manner as described with respect to computing device 130. For example, computing device 130 can receive a message (e.g., a text or email) from a computer resource protected by multi-factor authentication and display authentication code 122 on display 162, with wearable device 102 obtaining authentication code 122 via OCR scanning. In some examples, authentication application 158 can generate and display authentication code 122, with wearable device 102 obtaining authentication code 122 via OCR scanning. In some examples, computing device 152 and wearable device 102 are connected via a wireless connection, and wearable device 102 obtains authentication code 122 via the wireless connection.

[0039] In some examples, wearable device 102 can receive authentication code 122 from central server 170 (e.g., also referred to as a server or server computer). In some examples, wearable device 102, computing device 152, and / or computing device 130 are connected to each other via a network (e.g., the Internet). In some examples, operating system 154 (and / or browser application 160) can be associated with user account 172, and wearable device 102 and / or computing device 130 can be devices linked to user account 172 (e.g., devices identified in user account 172). In some examples, wearable device 102 can obtain authentication code 122 from central server 170 if the computer resource protected by multi-factor authentication is managed or owned by the entity that manages or owns operating system 154 (and / or browser application 160). In some examples, if the computer resource protected by multi-factor authentication is managed or owned by the entity that manages or owns the operating system 132 (and / or browser application 138), the wearable device 102 can obtain the authentication code 122 from the central server 170.

[0040] 1B , in response to the authentication code 122 being detected, in some examples, the wearable device 102 can display the authentication code 122 within the display 118 of the wearable device 102. In some examples, the location 120 depends on image data 101 (e.g., of an object in front of the user) generated by the image camera(s) 116 (e.g., as seen through the lens). In some examples, the wearable device 102 can display the authentication code 122 at a location 120 that does not depend on information in front of the user (e.g., as captured by the image data 101). In some examples, the wearable device 102 determines a location 120 at which to display the authentication code 122 and displays the authentication code 122 at the location 120. In some examples, the location 120 includes two-dimensional coordinates (e.g., x, y). In some examples, the location 120 includes three-dimensional coordinates (e.g., x, y, z). In some examples, the location is a predetermined location at the top (or bottom) of the display 118. In some examples, location 120 is a position on the left (or right) side of display 118. In some examples, location 120 is a position in the center portion of display 118. In some examples, location 120 is based on the location (or position) of an object in image data 101.

[0041] In some examples, location 120 is fixed (e.g., does not change) within display 118. In some examples, location 120 within display 118 can change (e.g., move), which depends on the image data 101 within the field of view of the image camera. In some examples, location 120 is based on content currently projected by display device 110 (e.g., other computer-generated elements displayed within display 118). In some examples, location 120 is not determined based on currently displayed content.

[0042] In some examples, the wearable device 102 can display the authentication code 122 at a location 120 within the display 118, where the location 120 is based on an interface 164 for receiving the authentication code 122. In some examples, the location 120 is a particular object (e.g., a UI element) within the image data 101. In some examples, the authentication code 122 is anchored or bound to the particular object. In some examples, the location 120 is based on the location of a particular UI element 166 within the interface 164. In some examples, the wearable device 102 can anchor (e.g., fixedly bind) the authentication code 122 to a particular UI element 166 within the display 162 of the computing device 152. In other words, the authentication code 122 can remain fixed to the particular UI element 166 regardless of head movement. The wearable device 102 can include one or more inertial measurement units (IMUs) configured to track movement of the wearable device 102, and the IMUs can be used to align the authentication code 122 with the UI element 166. In some examples, in response to the first verification factor being successful, the computing device 152 may render an interface 164 for receiving the authentication code 122.

[0043] Interface 164 may be a user interface of an application 156 executing on computing device 152. In some examples, interface 164 is an interface of browser application 160. In some examples, interface 164 includes a web page displayed by browser application 160. Interface 164 may include one or more UI elements 166. UI element 166 may include code entry field(s) (e.g., code entry field 168 for receiving authentication code 122), light label 142, menu items, user control elements, interface borders, navigation panels, etc. In some examples, authentication code 122 is displayed within or adjacent to UI element 166 and may remain displayed within or adjacent to UI element 166 even when UI element 166 is moved to another area within display 118. For example, UI element 166 may be located on the right side of display 118, and the user may move their head to the right (or computing device 152 to the left) to shift UI element 166 to the left side of display 118. The authentication code 122 may remain fixed to the UI element 166 even if the UI element is moved within the display 118 .

[0044] In some examples, the wearable device 102 can display a computer-generated representation of the computing device 130 in a location corresponding to the location of the computing device 130 in front of the user within the display 118. The wearable device 102 can also generate and display content (e.g., VR content) corresponding to what is displayed on the display screen of the computing device 130, including a display of the authentication code 122 (which may be displayed via a text message, email, or authentication application 136). In some examples, the wearable device 102 can display an interface 164 for receiving the authentication code 122. In some examples, the user can interact with the authentication code 122 (e.g., pinch the authentication code 122) and drag it to the interface 164.

[0045] The wearable device 102 may determine a location 120 for displaying the authentication code 122 within the display 118 of the wearable device 102 based on the interface 164 (e.g., the structure of the interface 164 and / or the location of UI elements 166 of the interface 164). In some examples, the location 120 is based on the location of a particular UI element 166 (e.g., a code entry field 168, a light label 142) within the interface 164. In other words, in some examples, the wearable device 102 may associate (e.g., anchor, attach) the location 120 of the authentication code 122 with a particular UI element 166 within the display 162 of the computing device 152.

[0046] In some examples, the wearable device 102 can detect that the image data 101 includes a UI element 166 (e.g., a code entry field 168). In some examples, the UI element 166 refers to an interface for receiving the authentication code 122. For example, the wearable device 102 can include an image detection and recognition engine configured to detect a particular type of physical object (e.g., the UI element 166) based on the image data 101. In some examples, the wearable device 102 can include one or more ML models configured to detect the UI element 166. The wearable device 102 can include a 3D estimation engine configured to determine the position (e.g., 3D position) of the UI element 166 in 3D space based on the image data 101. In some examples, the image data 101 includes a pair of stereo images, and the 3D estimation engine can use the pair of stereo images to estimate the 3D position of the UI element 166 (e.g., by calculating the disparity between the UI element 166 in the stereo images). In some examples, the 3D estimation engine can use a depth sensor to calculate the depth and location of objects in front of the user.

[0047] The wearable device 102 can identify a particular UI element (e.g., code entry field 168) from the image data 101 or by examining the light label 142 and can determine the location 120 based on the location of the UI element. In some examples, the computing device 152 displays the light label 142 (e.g., a QR code) corresponding to the interface 164. The light label is a machine-readable label that can be read by the computing device and is used to store a resource locator (e.g., a URL) of a web resource. In some examples, the light label 142 includes a barcode (e.g., a two-dimensional barcode). In some examples, the light label 142 includes a QR code. In some examples, the light label 142 includes a pixel pattern (e.g., a black and white pixel pattern). In some examples, the light label 142 includes a machine-readable light label. The wearable device 102 can acquire the light label 142 corresponding to the interface 164 via the image camera(s) 116. The light label 142 may represent a resource locator (e.g., a URL) of a computer resource (e.g., an interface 164). In some examples, when the light label 142 is interpreted, the interface 164 is rendered. The wearable device 102 may use the resource locator to obtain information about the UI elements 166 (e.g., which UI elements are included, where they are located, etc.). In some examples, the wearable device 102 may obtain image data 101 of the UI elements 166 on the interface 164 via the image camera(s) 116 and use the image data 101 to determine the location 120 of the authentication code 122.

[0048] 1C and 1D , the wearable device 102 may display the authentication code 122 within a code entry field 168 on an interface 164 displayed by the computing device 152. For example, the wearable device 102 may overlay (e.g., superimpose) the authentication code 122 within the code entry field 168 on the interface 164 displayed by the computing device 152. In other words, the value of the authentication code 122 need not be entered into the code entry field 168, but the wearable device 102 projects the authentication code 122 in a location on top of the code entry field 168. The user can then enter (e.g., manually enter) the authentication code 122 into the code entry field 168 using the computing device 152. In some examples, the wearable device 102 renders the interface 164 on the display 118, and the wearable device 102 displays the characters of the authentication code 122 within the code entry field 168. In some examples, the interface 164 is not displayed within the display 118, and the wearable device 102 transmits the authentication code 122 to the underlying resource to authenticate the user.

[0049] 1E , the wearable device 102 may display the authentication code 122 at a location 120 outside the code entry field 168. In some examples, the authentication code 122 is anchored to a light label 142, where the authentication code 122 is superimposed (e.g., overlaid) on the light label 142 near (but outside the boundaries of) the code entry field 168. In some examples, the authentication code 122 may be displayed in the display 118 at a location 120 above the code entry field 168. The user may then enter the authentication code 122 into the code entry field 168 using the computing device 152. In some examples, each time the user types a new character, the wearable device 102 erases the character. In some examples, when the user correctly types a new character, the display characteristics (e.g., color, transparency, color, etc.) of the character change. In some examples, if an incorrect character is entered, the wearable device 102 may highlight the character (e.g., highlight it in red).

[0050] The wearable device 102 can have the computing device 152 enter (and, in some examples, transmit) the authentication code 122 into the code entry field 168, without the user having to type the authentication code 122 into the code entry field 168. For example, the wearable device 102 can transmit the authentication code 122 to the browser application 160, which can render the authentication code 122 in the code entry field 168 on the interface 164. In some examples, the wearable device 102 can transmit the authentication code 122 to the computing device 152, which can automatically enter the authentication code 122.

[0051] 1E , the wearable device 102 can determine a font size 186 of the authentication code 122 based on the depth (e.g., depth value 182) between a portion 121 of the wearable device 102 and a portion 123 of the computing device 152. In some examples, the portion 121 of the wearable device 102 can be a lens, an image camera(s) 116, or a front portion of the wearable device 102. In some examples, the portion 123 of the computing device 152 is a display screen (e.g., display 162) of the computing device 152. In some examples, the portion 123 is a code entry field 168 on the display 162 of the computing device 152. For example, the wearable device 102 can receive image data 101 of at least a portion of the computing device 152 via the image camera(s) 116. The wearable device 102 may include a depth estimator 180 configured to estimate a depth value 182 between the portion 121 of the wearable device 102 and the portion 123 of the computing device 152. In some examples, the depth estimator 180 can estimate the depth value 182 based on one or more images (e.g., RGB images) of the portion 123 of the computing device 152. The wearable device 102 includes a font size identifier 184 configured to identify a font size 186 based on the depth values ​​182. For example, one or more depth values ​​182 (or ranges of depth values ​​182) can be associated with particular font sizes 186, and one or more depth values ​​(or ranges of depth values ​​182) can be associated with other font sizes 186. By identifying the depth values ​​182, the wearable device 102 can select a particular font size 186 for the authentication code 122.

[0052] In some examples, the wearable device 102 can derive the authentication code 122 from an authentication application 106 running on the wearable device 102, can determine a location 120 to display the authentication code 122, and can display the authentication code 122 on the display 118 of the wearable device 102 at the location 120. For example, the wearable device 102 can detect an authentication request for multi-factor authentication, and in response to the authentication request, the wearable device 102 can launch and execute the authentication application 106 and obtain the authentication code 122 from the authentication application 106 running on the wearable device 102. In some examples, the authentication application 106 can run in the background of the wearable device 102.

[0053] In some examples, the authentication request is a request to obtain an authentication code 122. In some examples, the authentication request does not include an authentication code 122, and an authentication application 106 on the wearable device 102 generates the authentication code 122. In some examples, the authentication request includes an authentication code 122.

[0054] In some examples, the wearable device 102 can receive an authentication request for multi-factor authentication from the computing device 152. In some examples, the computing device 152 can be a user device that originates a request to access a computer resource protected by multi-factor authentication (e.g., has performed a first verification factor). In some examples, the wearable device 102 and the computing device 152 can be connected to the same network (e.g., the same Wi-Fi network). In some examples, the wearable device 102 and the computing device 152 can be connected via a wireless connection (e.g., a direct Wi-Fi connection, a short-range connection, etc.) or a wired connection. In some examples, when the wearable device 102 and the computing device 152 are connected to each other or on the same Wi-Fi network, the computing device 152 can send an authentication request to the wearable device 102.

[0055] For example, in response to a successful first verification factor at computing device 152, computing device 152 can send an authentication request to wearable device 102. In some examples, wearable device 102 can receive an authentication request for multi-factor authentication from central server 170 that includes information about a user account 172 associated with one or more linked devices (e.g., computing device 130, computing device 152, and / or wearable device 102). In some examples, user account 172 is a user account for an operating system. In some examples, user account 172 is a user account for a browser application. User account 172 can be associated with settings 174. If user account 172 is associated with an operating system, settings 174 can include network settings, display settings, application settings, multi-factor authentication settings, etc. If user account 172 is associated with a browser application, settings 174 can include multi-factor authentication settings, browser settings, personalization settings, etc.

[0056] In some examples, the wearable device 102 can receive image data 101 via the image camera(s) 116, where the image data 101 includes an optical label 142 (e.g., a barcode, a QR code, etc.) associated with multiple authentication authorities. In some examples, in response to detecting the optical label 142 in the image data 101, the wearable device 102 can detect an authentication request.

[0057] In some examples, applications 104 include a browser application 108. Browser application 108 may be a web browser configured to access information on the internet. In some examples, browser application 108 is a separate application from the operating system of wearable device 102, where browser application 108 is installable on (and executable by) the operating system. In some examples, browser application 108 is the device's operating system (or is included as part of the device's operating system). Browser application 108 may launch one or more browser tabs in the context of one or more browser windows on display 118 of wearable device 102.

[0058] In some examples, in response to wearable device 102 receiving authentication code 122, wearable device 102 can render an interface (e.g., interface 164) on display 118 using browser application 108 and can place authentication code 122 within a code entry field (e.g., code entry field 168) on the interface. A user can interact with wearable device 102 (e.g., manipulate one or more controls on wearable device 102) to accept authentication code 122. In some examples, no user interaction is required on wearable device 102, and in response to receiving authentication code 122, wearable device 102 can submit authentication code 122 to a computer resource (e.g., via browser application 108). Wearable device 102 can generate and send information to computing device 152 indicating that the second verification factor was successful, thereby causing computing device 152 to provide access to the computer resource protected by multi-factor authentication. In some examples, the wearable device 102 may render access to a computer resource (e.g., a web page, an application 104, etc.) by displaying the computer resource within the display 118 of the wearable device 102.

[0059] 2A-2C illustrate an example of a system 200 for multi-factor authentication using a wearable device 202 according to another embodiment. The system 200 may be an example of the system 100 of FIGS. 1A-1F and may include any of the details described with reference to those figures. In some examples, the system 200 may display a first portion 222a of an authentication code 222 on a display 218 of the wearable device 202 and a second portion 222b of the authentication code 222 on a display 262 of the computing device 252. When the first portion 222a is aligned with the second portion 222b, the authentication code 222 may be revealed (e.g., made visible to a user). In some examples, the wearable device 202 receives the first portion 222a and the second portion 222b from different sources. In some examples, aligning the first portion 222a with the second portion 222b includes positioning the first portion 222a and the second portion 222b adjacent to one another. In some examples, aligning the first portion 222a with the second portion 222b includes superimposing the first portion 222a onto the second portion 222b (or vice versa). In some examples, the actual text cannot be determined when viewing the first portion 222a and the second portion 222b separately, but when the first portion 222a is placed over the second portion 222b, the authentication code 222 becomes visible to a user.

[0060] The wearable device 202 may receive only the first portion 222a of the authentication code 222. The first portion 222a may be detected according to any of the techniques discussed herein for detecting an authentication code. In some examples, the wearable device 202 may receive the first portion 222a from a central server. In some examples, the wearable device 202 may receive the first portion 222a from a computing device 252. In some examples, the wearable device 202 may receive the first portion 222a from an authentication application running on the wearable device 202. In some examples, the wearable device 202 may receive the first portion 222a from a computer resource protected by multi-factor authentication.

[0061] The wearable device 202 can project the first portion 222a on the display 218. The computing device 252 can receive the second portion 222b and display the second portion 222b of the authentication code 222 on the interface 264. In some examples, the computing device 252 can receive the second portion 222b from a central server. In some examples, the computing device 252 can receive the second portion 222b from a computer resource protected by multi-factor authentication. In some examples, the central server detects an authentication request for multi-factor authentication, generates the first portion 222a and the second portion 222b, and transmits the first portion 222a and the second portion 222b to the wearable device 202 and the computing device 252, respectively. In some examples, the wearable device 202 receives the authentication code 222 (e.g., according to any of the techniques discussed herein), generates the first portion 222a and the second portion 222b, and transmits the second portion 222b to the computing device 252.

[0062] The first portion 222a can represent at least a portion of the authentication code 222. The second portion 222b can represent at least a portion of the authentication code 222. In some examples, both the first portion 222a and the second portion 222b are required to recover the authentication code 222. In some examples, if the first portion 222a is not aligned within the second portion 222b, the authentication code 222 remains indiscernible (e.g., hidden) to the user. In some examples, the first portion 222a includes a portion of the character value of the authentication code 222, and the second portion 222b includes the other value of the authentication code 222. In some examples, first portion 222a includes a plurality of characters (e.g., arranged in a line, grid, or matrix) and / or character receptors (e.g., boxes, underlines, etc.), and second portion 222b includes a plurality of characters and / or character receptors (e.g., boxes, underlines, etc.), and at least a portion of first portion 222a must be properly aligned with at least a portion of second portion 222b (e.g., for the code 3359, first portion 222a can be "_35_" and second portion 222b can be "3__9"). In some examples, first portion 222a includes authentication code 222 (or a portion thereof) configured in a first display format, and second portion 222b includes authentication code 222 (or a portion thereof) configured in a second display format.

[0063] In some examples, the first portion 222a and the second portion 222b have different transparencies (e.g., transparency values). For example, a first transparency level (e.g., opaque) may indicate that the display of a portion of the authentication code 222 is opaque (e.g., the background image is not visible through the image data), and a second transparency level (e.g., fully transparent) may indicate that the display of a portion of the authentication code 222 is fully transparent (e.g., hidden, allowing the background image to be visible through the image data). In some examples, each of the first portion 222a and the second portion 222b has a transparency value between the first transparency level and the second transparency level. In other words, the first portion 222a and the second portion 222b may have different semi-transparent levels.

[0064] Authentication reveals the code 222 when the user moves the wearable device 202 to align the first portion 222a (e.g., displayed on the display 218 of the wearable device 202) with the second portion 222b (e.g., displayed on the display 262 of the computing device 252). In some examples, aligning the first portion 222a with the second portion 222b includes positioning the first portion 222a adjacent to the second portion 222b. In some examples, aligning the first portion 222a with the second portion 222b includes positioning the first portion 222a above the second portion 222b (e.g., at least partially (or completely) overlapping each other). In some examples, the user does not need to move the wearable device 202 to align the first portion 222a with the second portion 222b. For example, the wearable device 202 can detect where to display the first portion 222a within the display 262 by analyzing the image data 101 of the second portion 222b or by analyzing the light label 142, and can display the first portion 222a in the correct location to align with the second portion 222b, thereby revealing the authentication code 222.

[0065] FIG. 3 illustrates an example of a system 300 for multi-factor authentication using a wearable device 302 according to one aspect. The system 300 may be an example of the system 100 of FIGS. 1A-1F and may include any of the details described with reference to those drawings. In some examples, the wearable device 302 may detect an authentication request 303 and, in response to the authentication request 303, display a line-of-sight interface 305 on a display 318 of the wearable device 302. In some examples, the authentication request 303 may correspond to a second verification factor of multi-factor authentication. In some examples, the authentication request 303 is sent to the wearable device 302 in response to a successful first verification factor. In some examples, the first verification factor is performed on the wearable device 302. In some examples, the first verification factor is performed on another computing device (e.g., computing device 130 or computing device 152 of FIGS. 1A-1F). In some examples, the authentication request 303 may correspond to a first verification factor, which, if authenticated (e.g., the gaze gesture matches a stored pattern), causes a second verification factor to be executed, in which an authentication code 322 is generated and then displayed / entered into the interface.

[0066] In some examples, the wearable device 302 can receive the authentication request 303 from another computing device (e.g., computing device 130 or computing device 152 of FIGS. 1A-1F). In some examples, the wearable device 302 can receive the authentication request 303 from a central server (e.g., central server 170 of FIGS. 1A-1F). In some examples, the wearable device 302 can receive image data via image camera(s), where the image data includes an optical label (e.g., a barcode, a QR code, etc.) associated with multiple authentication authorities. In some examples, in response to detecting the optical label in the image data, the wearable device 302 can detect the authentication request 303. In some examples, the wearable device 302 can detect an authentication code according to any of the techniques described with reference to the previous description, including OCR scanning. In some examples, instead of displaying the authentication code, the wearable device 302 can display a gaze interface 305.

[0067] The wearable device 302 can track eye movement trajectories (e.g., unistrokes), and if the trajectory matches a certain percentage of pre-encoded eye gestures (e.g., stored eye gesture patterns 393), the wearable device 302 can verify the second verification factor, thereby providing the user with access to underlying computer resources associated with multi-factor authentication. For example, the wearable device 302 can receive multiple gaze gestures 391 via the eye gaze interface 305 and determine whether the gaze gestures 391 correspond to the stored eye gesture patterns 393, and in response to determining that the gaze gestures 391 correspond to the stored eye gesture patterns 393, the wearable device 302 can authenticate the authentication request 303, thereby providing access to the underlying computer resources protected by multi-factor authentication. In some examples, head gestures may be used instead of gaze gestures. For example, the wearable device 302 may receive multiple gestures (e.g., eye gestures or head gestures) via the interface, may determine whether the gestures correspond to a stored gesture pattern (e.g., eye gestures or head gestures), and in response to determining that the gestures correspond to the stored gesture pattern, the wearable device 302 may authenticate the authentication request 303, thereby providing access to underlying computer resources protected by multi-factor authentication.

[0068] In some examples, instead of a gaze interface, the wearable device 302 can display an interface through which an authentication code can be entered based on head movement. For example, the wearable device 302 can track head movement using a camera or sensor, and data from the head tracking device can be used to calculate a head gaze. The user can move their head to select different regions that correspond to different character values ​​(e.g., the character values ​​can be selected when a head gaze is detected within a particular region for a predetermined period of time or in response to further user selection (e.g., pressing a button on the wearable device 302)). The user can use head movement to enter an authentication code into the interface. In some examples, the authentication code can be received by the wearable device 302 according to any of the techniques described herein. In some examples, the authentication code is a pre-stored code (e.g., previously determined by the user) and, in some examples, stored on the wearable device 302. When the user enters this code into the interface, the user can be authenticated.

[0069] 4 illustrates an example of a system 400 for multi-factor authentication using a wearable device 402 according to another aspect. System 400 may be an example of system 100 of FIGS. 1A-1F, system 200 of FIGS. 2A-2C, and / or system 300 of FIG. 3, and may include any of the details described with reference to those figures.

[0070] In some examples, web page 411 may be displayed on another computing device (e.g., computing device 130 or computing device 152 of FIGS. 1A-1F). In response to verifying a first verification factor (e.g., the user provided the correct username / password), web page 411 may transiently display light label 442 in a manner that is invisible to the user but detectable from image data captured by image camera(s) of wearable device 402. For example, light label 442 is displayed on the computing device for a time interval above a non-perceptibility threshold such that light label 442 is invisible to the person but detectable by wearable device 402.

[0071] In some examples, the non-perceptibility threshold is the critical flicker frequency (CFF). The human visual system has limited ability to detect time-varying variations in light intensity. If the change exceeds the CFF, the human visual system cannot detect the change (e.g., only averaged luminance is perceived). Therefore, by inserting a light label 442 (e.g., a QR code, a barcode, etc.) into the web page 411 at a time interval that exceeds the non-perceptibility threshold (e.g., CFF), the wearable device 402 can detect the light label 442 such that the light label 442 is not visible to the user. Upon detecting the light label 442, the wearable device 402 can obtain the authentication code 422 according to any of the techniques described herein. In some examples, the wearable device 402 can display the authentication code 422 on the display 418 of the wearable device 402. In some examples, in response to detecting the light label 442, the wearable device 402 may display an interface for receiving the authentication code 422, and the wearable device 402 may receive and display the authentication code 422 within the interface in accordance with any of the techniques described herein.

[0072] 5A and 5B show an example of a wearable device 502. The wearable device 502 may be an example of the wearable device 102 of FIGS. 1A-1F, the wearable device 202 of FIGS. 2A-2B, the wearable device 302 of FIG. 3, and / or the wearable device 402 of FIG. 4, and may include any of the details described with reference to these figures. The wearable device 502 may be a head-mounted wearable device, such as smart glasses or augmented reality glasses. The wearable device 502 may include display functionality, computing / processing functionality, and object tracking functionality. FIG. 5A is a front view of the wearable device 502, and FIG. 5B is a rear view of the wearable device 502. It should be noted that while FIGS. 5A and 5B show an AR device, the techniques discussed herein may also be applied to VR devices.

[0073] The wearable device 502 includes a frame 510. The frame 510 includes a front frame portion 520 and a pair of arm portions 530 rotatably coupled to the front frame portion 520 by respective hinge portions 540. The front frame portion 520 includes edge portions 523 that surround respective optics in the form of lenses 527, the edge portions 523 being connected by a bridge portion 529. The arm portions 530 are coupled, e.g., pivotally or rotatably coupled, to the front frame portion 520 around the periphery of the respective edge portions 523. In some examples, the lenses 527 are corrective / prescription lenses. In some examples, the lenses 527 are optical materials that include glass and / or plastic portions that do not necessarily include corrective / prescription parameters.

[0074] In some examples, the wearable device 502 includes a display device 504 that can output visual content, for example, on a display 505 (e.g., an output coupler), thereby making the visual content visible to a user. The display device 504 may be provided on one of the two arm portions 530, for purposes of explanation and illustration only. A display device 504 may be provided on each of the two arm portions 530 to provide binocular output of content. In some examples, the display device 504 may be a see-through near-eye display. In some examples, the display device 504 may be configured to project light from a display light source onto a portion of teleprompter glass that acts as a beam splitter mounted at an angle (e.g., 30-45 degrees). The beam splitter may have a reflectance and a transmittance such that it partially reflects light from the display light source and transmits the remaining light. Such an optical design allows a user to, for example, view real objects through lens 527 while simultaneously viewing content (e.g., authentication codes, digital images, user interface elements, virtual content, etc.) output by display device 504. In some implementations, waveguide optics may be used to render content on display device 504.

[0075] In some examples, the wearable device 502 includes one or more audio output devices 506 (e.g., one or more speakers, etc.), a lighting device 508, a sensing system 511, a control system 512, at least one processor 514, and an outward-facing image sensor 516 (e.g., a camera). In some examples, the sensing system 511 may include various sensing devices, and the control system 512 may include various control system devices, including, for example, one or more processors 514 operably coupled to components of the control system 512. In some examples, the control system 512 may include a communications module that provides for communication and exchange of information between the wearable device 502 and other external devices (e.g., computing device 130, central server 170, computing device 152 of FIG. 1A ).

[0076] In some examples, the wearable device 502 includes an eye-gaze tracking device 515 that detects and tracks gaze direction and movement. Data captured by the eye-gaze tracking device 515 can be processed to detect and track gaze direction and movement as user input. The eye-gaze tracking device 515 is provided on one of the two arm portions 530 solely for purposes of explanation and illustration. In some examples, the eye-gaze tracking device 515 is provided on the same arm portion 530 as the display device 504, so that the user's gaze can be tracked not only relative to objects in the physical environment but also relative to content output displayed by the display device 504. In some examples, the eye-gaze tracking device 515 can be provided on each of the two arm portions 530 to provide eye-gaze tracking for each of the user's eyes. In some examples, the display device 504 can be provided on each of the two arm portions 530 to provide binocular display of visual content. In some examples, the wearable device 502 includes a head-gaze tracking device configured to calculate a head gaze based on head orientation or head movement. Head viewpoint is the point in space where a person's head is pointing. Head viewpoint can be defined as the intersection of the lines of sight of both eyes. Head viewpoint can be used to track where a person is looking and infer what they are attending to. Wearable device 502 can use cameras and / or sensors to track head movement. Data from the cameras and / or sensors can be used to calculate head viewpoint.

[0077] FIG. 6 shows a flowchart 600 illustrating an example operation of a system for multi-factor authentication using a wearable device. While flowchart 600 is described with reference to system 100 of FIGS. 1A-1F, flowchart 600 may be applicable to any of the implementations described herein. While flowchart 600 of FIG. 6 depicts operations in sequence, it will be recognized that this is merely an example and that additional or alternative operations may be included. Additionally, the operations of FIG. 6 and related operations may be performed in an order different from that depicted, or may be performed in a parallel or overlapping manner.

[0078] Operation 602 includes receiving, by the wearable device 102, an authentication code 122 associated with the multi-factor authentication. Operation 604 includes determining, by the wearable device 102, a location 120 at which to display the authentication code 122. Operation 606 includes displaying, by the wearable device 102, the authentication code 122 on the display 118 of the wearable device 102 at the location 120.

[0079] According to some aspects, obtaining an authentication code associated with the multi-factor authentication includes receiving image data via an image camera of the wearable device and extracting the authentication code from the image data using optical character recognition. In some examples, obtaining an authentication code associated with the multi-factor authentication includes receiving the authentication code from a computing device communicatively coupled to the wearable device. In some examples, obtaining an authentication code associated with the multi-factor authentication includes receiving the authentication code from a central server. In some examples, the operation may include executing, by the wearable device, an authentication application to obtain the authentication code. A location to display the authentication code may be determined based on a user interface (UI) element within an interface for receiving the authentication code.

[0080] The operations may include receiving a light label displayed on the computing device via an image camera of the wearable device and identifying a UI element using the light label, where a location of the authentication code is determined based on a position of the UI element within the interface. The light label is displayed on the computing device for a time interval above a non-perceptibility threshold such that the light label is invisible to a person. The operations may include receiving image data of at least a portion of an interface displayed by the computing device via an image camera of the wearable device and identifying a UI element using the image data, where a location of the authentication code is determined based on a position of the UI element within the interface. The operations may include determining, by the wearable device, a depth value between a portion of the wearable device and a portion of the computing device and determining, by the wearable device, a font size of the authentication code, where the authentication code is displayed in this font size. The authentication code may include a first portion and a second portion, and the operations may include displaying the first portion of the authentication code on a display of the wearable device and aligning, using the wearable device, the first portion of the authentication code with the second portion of the authentication code displayed by the computing device.

[0081] According to one aspect, the wearable device includes at least one processor and a non-transitory computer-readable medium storing executable instructions, the executable instructions causing the at least one processor to obtain an authentication code associated with multi-factor authentication, determine a location to display the authentication code, and display the authentication code at a location on a display of the wearable device or a display of the first computing device.

[0082] According to some aspects, the executable instructions include instructions for causing at least one processor to receive, via an image camera of the wearable device, image data of an authentication code displayed by a second computing device and extract the authentication code from the image data using optical character recognition. The executable instructions include instructions for causing the at least one processor to receive the authentication code from the first computing device, the second computing device, or a central server. The executable instructions include instructions for causing the at least one processor to execute an authentication application to obtain the authentication code. The executable instructions include instructions for causing the at least one processor to receive, via the image camera of the wearable device, a light label displayed on the first computing device and use the light label to identify a user interface (UI) element within an interface associated with the light label, wherein the location of the authentication code is determined based on the position of the UI element within the interface.

[0083] The executable instructions include instructions for causing the at least one processor to receive, via an image camera of the wearable device, image data of at least a portion of an interface displayed by the first computing device, and identifying, using the image data, a user interface (UI) element within the interface, wherein a location of the authentication code is determined based on a position of the UI element within the interface. The executable instructions include instructions for causing the at least one processor to send information including the authentication code to the first computing device, the information being configured to cause the first computing device to display the authentication code in a code input field.

[0084] According to one aspect, a non-transitory computer-readable medium storing executable instructions that cause at least one processor to perform operations including: detecting, by a wearable device, an authentication request associated with multi-factor authentication; displaying a gaze interface on a display of the wearable device in response to the authentication request; receiving, via the gaze interface, a plurality of gaze gestures; determining whether the plurality of gaze gestures correspond to a stored pattern of eye gestures; and authenticating the authentication request in response to determining that the plurality of gaze gestures correspond to the stored pattern of eye gestures.

[0085] In some examples, the operations include receiving a light label displayed on the first computing device via an image camera of the wearable device, and detecting an authentication request in response to the light label.

[0086] Clause 1. A computer-implemented method comprising: receiving, by a wearable device, an authentication code associated with multi-factor authentication; determining, by the wearable device, a location to display the authentication code; and displaying, by the wearable device, the authentication code on a display of the wearable device at the location.

[0087] Clause 2. The computer-implemented method of clause 1, wherein receiving the authentication code associated with the multi-factor authentication includes receiving image data via an image camera of the wearable device and extracting the authentication code from the image data using optical character recognition.

[0088] Clause 3. The computer-implemented method of clause 1 or 2, wherein receiving the authentication code associated with the multi-factor authentication includes receiving the authentication code from a computing device communicatively coupled to the wearable device.

[0089] Clause 4. The computer-implemented method of any one of clauses 1-3, wherein receiving the authentication code associated with the multi-factor authentication includes receiving the authentication code from a server.

[0090] Clause 5. The computer-implemented method of any one of clauses 1 to 4, further comprising: executing, by the wearable device, an authentication application; and receiving the authentication code from the authentication application.

[0091] Clause 6. The computer-implemented method of any one of clauses 1 to 5, wherein the location for displaying the authentication code is determined based on a user interface (UI) element within an interface for receiving the authentication code.

[0092] Clause 7. The computer-implemented method of clause 6, further comprising receiving, via an image camera of the wearable device, a light label displayed on a computing device, and identifying the UI element using the light label, wherein the location of the authentication code is determined based on a position of the UI element within the interface.

[0093] Clause 8. The computer-implemented method of clause 7, wherein the light label is displayed on the computing device for a time interval above a non-perceptual threshold such that the light label is not visible to a human.

[0094] Clause 9. The computer-implemented method of Clause 6, further comprising receiving image data of at least a portion of the interface displayed by a computing device via an image camera of the wearable device, and identifying a UI element using the image data, wherein the location of the authentication code is determined based on a position of the UI element in the interface.

[0095] Clause 10. The computer-implemented method of any one of clauses 1 to 9, further comprising: determining, by the wearable device, a depth value between a portion of the wearable device and a portion of a computing device; and determining, by the wearable device, a font size of the authentication code based on the depth value, wherein the authentication code is displayed in the font size.

[0096] Clause 11. The computer-implemented method of any one of clauses 1 to 10, further comprising: displaying a first portion of the authentication code on the display of the wearable device; and aligning the first portion of the authentication code with a second portion of the authentication code displayed by a computing device based on head movement.

[0097] Clause 12. A wearable device including at least one processor and a non-transitory computer-readable medium storing executable instructions, the executable instructions causing the at least one processor to receive an authentication code associated with multi-factor authentication, determine a location to display the authentication code, and display the authentication code at the location on a display of the wearable device or a display of a first computing device.

[0098] Clause 13. The wearable device of Clause 12, wherein the executable instructions include instructions to cause the at least one processor to receive image data of the authentication code displayed by a second computing device via an image camera of the wearable device, and extract the authentication code from the image data using optical character recognition.

[0099] Clause 14. The wearable device of Clause 13, wherein the executable instructions cause the at least one processor to receive the authentication code from the first computing device, the second computing device, or a server.

[0100] Clause 15. A wearable device described in any one of clauses 12 to 14, wherein the executable instructions include instructions for causing the at least one processor to execute an authentication application and receive the authentication code from the authentication application.

[0101] Clause 16. A wearable device described in any one of clauses 12 to 15, wherein the executable instructions include instructions for causing the at least one processor to receive a light label displayed on the first computing device via an image camera of the wearable device and use the light label to identify a user interface (UI) element within an interface associated with the light label, and the location of the identification code is determined based on the position of the UI element within the interface.

[0102] Clause 17. A wearable device described in any one of clauses 12 to 16, wherein the executable instructions include instructions for causing the at least one processor to receive image data of at least a portion of an interface displayed by the first computing device via an image camera of the wearable device, and using the image data to identify a user interface (UI) element within the interface, and the location of the authentication code is determined based on the position of the UI element within the interface.

[0103] Clause 18. A wearable device described in any one of clauses 12 to 17, wherein the executable instructions include instructions to cause the at least one processor to send information including the authentication code to the first computing device, the information being configured to cause the first computing device to display the authentication code within a code input field.

[0104] Clause 19. A non-transitory computer-readable medium storing executable instructions that cause at least one processor to perform operations including: detecting, by a wearable device, an authentication request associated with multi-factor authentication; displaying a gaze interface on a display of the wearable device in response to the authentication request; receiving a plurality of gaze gestures via the gaze interface; determining whether the plurality of gaze gestures correspond to a stored pattern of eye gestures; and authenticating the authentication request in response to determining that the plurality of gaze gestures correspond to the stored pattern of eye gestures.

[0105] Clause 20. The non-transitory computer-readable medium of Clause 19, further comprising receiving, via an image camera of the wearable device, a light label displayed on a first computing device, and detecting the authentication request in response to the light label.

[0106] Clause 21. A computer-implemented method comprising: receiving, by a head-mounted display device, an authentication code associated with multi-factor authentication; receiving image data from an image camera on the head-mounted display device; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code in a location corresponding to the interface.

[0107] Clause 22. The computer-implemented method of clause 21, wherein the image data is first image data, and receiving the authentication code associated with the multi-factor authentication includes detecting the authentication code from second image data received from the image camera.

[0108] Clause 23. The computer-implemented method of clause 21, wherein receiving the authentication code associated with the multi-factor authentication includes receiving the authentication code from a computing device coupled to the head-mounted display device.

[0109] Clause 24. The computer-implemented method of clause 21, wherein receiving the authentication code associated with the multi-factor authentication includes receiving the authentication code from a server computer.

[0110] Clause 25. The computer-implemented method of clause 21, wherein receiving the authentication code associated with the multi-factor authentication includes receiving the authentication code from an authentication application executing on the head-mounted display device.

[0111] Clause 26. The computer-implemented method of any one of clauses 21 to 25, further comprising estimating a position of the interface in three-dimensional (3D) space based on the image data, the authentication code being displayed at said position.

[0112] Clause 27. The computer-implemented method of any one of clauses 21 to 26, wherein the authentication code is configured to be anchored to the location regardless of head movement.

[0113] Clause 28. The computer-implemented method of any one of clauses 21 to 27, wherein the interface includes a code entry field and the authentication code is located at a location outside the code entry field.

[0114] Clause 29. The computer-implemented method of any one of clauses 21 to 28, wherein the image data is first image data, and further comprising: detecting that characters of the authentication code have been entered on the interface based on second image data from the image camera; and adjusting the display appearance of the characters based on whether the characters are accurate.

[0115] Clause 30. The computer-implemented method of any one of clauses 21 to 29, further comprising: determining, by the head-mounted display device, a depth value of the interface; and determining, by the head-mounted display device, a font size of the authentication code based on the depth value, wherein the authentication code is displayed in the font size.

[0116] Clause 31. The computer-implemented method of any one of clauses 21 to 30, further comprising: displaying a first portion of the authentication code on the head-mounted display device; and aligning the first portion of the authentication code with a second portion of the authentication code displayed by a computing device based on head movement.

[0117] Clause 32. A head-mounted display device storing executable instructions that cause at least one processor to perform any one of clauses 21 to 31.

[0118] Clause 33. A head-mounted display device including at least one processor and a non-transitory computer-readable medium storing executable instructions that cause the at least one processor to perform operations, the operations including receiving, by the head-mounted display device, a code associated with multi-factor authentication; receiving image data from an image camera on the head-mounted display device; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code in a location corresponding to the interface.

[0119] Clause 34. The head-mounted display device of Clause 33, wherein the image data is first image data, and receiving the authentication code associated with the multi-factor authentication includes detecting the authentication code from second image data received from the image camera.

[0120] Clause 35. The head-mounted display device of Clause 33, wherein receiving the authentication code associated with the multi-factor authentication includes receiving the authentication code from a computing device communicatively coupled to the head-mounted display device.

[0121] Clause 36. The head-mounted display device of Clause 33, wherein receiving the authentication code associated with the multi-factor authentication includes receiving the authentication code from a server computer.

[0122] Clause 37. The head-mounted display device of Clause 33, wherein receiving the authentication code associated with the multi-factor authentication includes receiving the authentication code from an authentication application running on the head-mounted display device.

[0123] Clause 38. A head-mounted display device described in any one of clauses 33 to 37, further comprising estimating the position of the interface in three-dimensional (3D) space based on the image data, and the authentication code is displayed at that position.

[0124] Clause 39. A head-mounted display device as described in any one of clauses 33 to 38, wherein the authentication code is configured to be anchored to the location regardless of head movement.

[0125] Clause 40. A head-mounted display device as described in any one of clauses 33 to 39, wherein the interface includes a code input field and the authentication code is located at a location outside the code input field.

[0126] Clause 41. A head-mounted display device as described in any one of clauses 33 to 40, wherein the image data is first image data, and further comprising: detecting that characters of the authentication code have been entered on the interface based on second image data from the image camera; and adjusting the display appearance of the characters based on whether the characters are accurate.

[0127] Clause 42. A head-mounted display device described in any one of Clauses 33 to 41, further comprising: determining a depth value of the interface by the head-mounted display device; and determining a font size of the authentication code based on the depth value by the head-mounted display device, wherein the authentication code is displayed in the font size.

[0128] Clause 43. The computer-implemented method of any one of clauses 33 to 42, further comprising: displaying a first portion of the authentication code on the head-mounted display device; and aligning the first portion of the authentication code with a second portion of the authentication code displayed by a computing device based on head movement.

[0129] Clause 44. A computer program product storing executable instructions for causing at least one processor to perform any one of clauses 21 to 31.

[0130] Clause 45. A method comprising: detecting, by a head-mounted display device, a request for authentication; displaying an interface in response to the authentication request; receiving a plurality of gestures via the interface; determining whether the plurality of gestures correspond to a stored pattern of gestures; and authenticating the authentication request in response to determining that the plurality of gestures correspond to the stored pattern of gestures.

[0131] Clause 46. The method of clause 45, wherein the plurality of gestures includes eye gestures.

[0132] Clause 47. The method of clause 45, wherein the plurality of gestures includes a head gesture.

[0133] Clause 48. The method of any one of clauses 45 to 47, wherein detecting the authentication request includes receiving the authentication request from a computing device.

[0134] Clause 49. A method according to any one of clauses 45 to 48, further comprising receiving image data from an image camera on the head-mounted display device, detecting that the image data includes an optical label, and detecting the authentication request in response to the optical label.

[0135] Clause 50. The method of clause 49, wherein the light label is displayed on the computing device for a time interval above a non-perceptibility threshold such that the light label is not visible to a human.

[0136] Clause 51. A head-mounted display device storing executable instructions that cause at least one processor to perform any one of clauses 45 to 50.

[0137] Clause 52. A computer program product storing executable instructions for causing at least one processor to perform any one of clauses 45 to 50.

[0138] Clause 53. A head-mounted display device including at least one processor and a non-transitory computer-readable medium storing executable instructions that cause the at least one processor to perform operations, the operations including: detecting, by the head-mounted display device, a request for authentication; displaying an interface in response to the authentication request; receiving a plurality of gestures via the interface; determining whether the plurality of gestures correspond to stored gesture patterns; and authenticating the authentication request in response to determining that the plurality of gestures correspond to the stored gesture patterns.

[0139] Clause 54. A head-mounted display device as described in Clause 53, wherein the plurality of gestures includes eye gestures.

[0140] Clause 55. The method of clause 53, wherein the plurality of gestures includes a head gesture.

[0141] Clause 56. The method of any one of clauses 53 to 55, wherein detecting the authentication request includes receiving the authentication request from a computing device.

[0142] Clause 57. A method according to any one of clauses 53 to 56, further comprising receiving image data from an image camera on the head-mounted display device, detecting that the image data includes an optical label, and detecting the authentication request in response to the optical label.

[0143] Clause 58. The method of clause 57, wherein the light label is displayed on a computing device for a time interval above a non-perceptibility threshold such that the light label is not visible to a human.

[0144] Various implementations of the systems and techniques described herein can be realized in digital electronic circuitry, integrated circuits, specially designed ASICs (application-specific integrated circuits), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs, which can be executable and / or interpretable by a programmable system including at least one programmable processor, which can be special-purpose or general-purpose, and which can be coupled to receive and transmit data and instructions from a storage system, at least one input device, and at least one output device. Furthermore, the term "module" can include software and / or hardware.

[0145] These computer programs (also known as programs, software, software applications, or code) include machine instructions for a programmable processor and may be implemented in a high-level procedural programming language, and / or an object-oriented programming language, and / or an assembly / machine language. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., magnetic disk, optical disk, memory, programmable logic device (PLD)) used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives the machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.

[0146] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user, as well as a keyboard and pointing device (e.g., a mouse or trackball) by which the user can provide input to the computer. Other types of devices can also be used to provide interaction with a user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback), and input from the user can be received in any form, such as acoustic, speech, or tactile input.

Claims

1. receiving, by the head mounted display device, an authentication code associated with the multi-factor authentication; receiving image data from an image camera on the head mounted display device; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; displaying the authentication code at a location corresponding to the interface by the head-mounted display device; A computer-implemented method comprising:

2. 2. The computer-implemented method of claim 1, wherein the image data is first image data, and receiving the authentication code associated with the multi-factor authentication includes detecting the authentication code from second image data received from the image camera.

3. 2. The computer-implemented method of claim 1, wherein receiving the authentication code associated with the multi-factor authentication comprises receiving the authentication code from a computing device communicatively coupled to the head-mounted display device.

4. The computer-implemented method of claim 1 , wherein receiving the authentication code associated with the multi-factor authentication comprises receiving the authentication code from a server computer.

5. 2. The computer-implemented method of claim 1, wherein receiving the authentication code associated with the multi-factor authentication comprises receiving the authentication code from an authentication application executing on the head-mounted display device.

6. 6. The computer-implemented method of claim 1, further comprising estimating a position of the interface in three-dimensional (3D) space based on the image data, and the authentication code is displayed at the position.

7. The computer-implemented method of any one of claims 1 to 6, wherein the authentication code is configured to be anchored to the location regardless of head movement.

8. The computer-implemented method of any one of claims 1 to 7, wherein the interface includes a code entry field, and the authentication code is located at a location outside the code entry field.

9. the image data is first image data, Detecting that characters of the authentication code have been entered into the interface based on second image data from the image camera; and adjusting the display appearance of the character based on whether the character is accurate; and The computer-implemented method of any one of claims 1 to 8, further comprising:

10. determining, by the head mounted display device, a depth value of the interface; determining, by the head-mounted display device, a font size of the authentication code based on the depth value; The computer-implemented method of any one of claims 1 to 9, wherein the authentication code is displayed in the font size.

11. displaying a first portion of the authentication code on the head mounted display device; aligning the first portion of the authentication code with a second portion of the authentication code displayed by a computing device based on head movement; The computer-implemented method of any one of claims 1 to 10, further comprising:

12. A head mounted display device storing executable instructions that cause at least one processor to perform any one of claims 1 to 11.

13. A computer program product storing executable instructions for causing at least one processor to carry out any one of claims 1 to 11.

14. Detecting, by the head mounted display device, a request for authentication; displaying an interface in response to the authentication request; receiving a plurality of gestures via the interface; determining whether the plurality of gestures corresponds to a stored gesture pattern; authenticating the authentication request in response to determining that the plurality of gestures corresponds to the stored gesture pattern; A method comprising:

15. The method of claim 14 , wherein the plurality of gestures includes eye gestures.

16. The method of claim 14 , wherein the plurality of gestures includes head gestures.

17. The method of any one of claims 14 to 16, wherein detecting the authentication request comprises receiving the authentication request from a computing device.

18. receiving image data from an image camera on the head mounted display device; Detecting that the image data includes an optical label; detecting the authentication request in response to the optical label; The method of any one of claims 14 to 17, further comprising:

19. 20. The method of claim 18, wherein the light label is displayed on a computing device for a time interval above a non-perceptibility threshold such that the light label is not visible to a human.

20. A head mounted display device storing executable instructions to cause at least one processor to perform any one of claims 14 to 19.

21. A computer program product storing executable instructions for causing at least one processor to carry out any one of claims 14 to 19.