Dynamic QR Two-Factor Authentication With Facial Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing two-factor authentication methods require manual entry of additional data elements, which are time-consuming.

Innovation Solution

A system that uses a mobile device as an authenticator, leveraging a dynamic QR code and facial recognition to authenticate users into a secure session on computing devices, with optional one-time password (OTP) verification through a smartwatch, eliminating the need for manual data entry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual entry of additional data element is used for two-factor authentication, then security is improved, but time consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical manual entry system with an automated optical recognition system. The mobile device captures an image of the additional data element displayed on the computer screen, and optical character recognition (OCR) technology automatically extracts and transmits the data, eliminating the need for manual typing or input.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service authentication where the mobile device automatically performs data capture, recognition, and transmission without requiring user intervention. The additional data element is automatically read from the screen and sent to the authentication server, allowing the system to serve itself.

Inventive Principle:
Principle #25Self-service

2Reliability

If additional data element transmission is performed substantially contemporaneously with user authentication, then authentication security is improved, but user interaction time increases

Engineering Contradiction:
Improveauthentication securityVSAvoiduser interaction time
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The mobile device application pre-configures authentication parameters and establishes communication channels before the actual authentication process. When authentication is needed, the device already has the necessary protocols ready, allowing rapid capture and transmission of the additional data element without setup delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces sequential manual operations with parallel automated processes. While the user is being authenticated, the mobile device simultaneously captures the additional data element, performs OCR recognition, and transmits it to the server, making the processes occur substantially contemporaneously rather than sequentially.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12386940B2Two-factor authentication integrating dynamic QR codes
Publication Date: 2025.08.12 BANK OF AMERICA CORP
  • US12386940B2 patent drawing
  • US12386940B2 patent drawing
  • US12386940B2 patent drawing

AI summary

A method for authenticating a user into a session on an entity application running on a computing device is provided. The method may include using a mobile device of the user as an authenticator. The method may include capturing by the mobile device, a dynamic quick response (“QR”) code displayed on the computing device. The method may include transmitting the dynamic QR code, pre-authorized user credentials and a facial image of the user captured within a pre-determined time to a central server for authentication. The transmitting may be for verifying the user of the computing device being the user of the mobile device. In response to the verifying, via the central server, the dynamic QR code, the pre-authorized user credentials and the facial image, authenticating the user into the session on the entity application on the computing device.