IP Library Granted Patent US 6,908,030
Granted Patent B2
US 6,908,030 · App. 10/003,847 · Granted Jun 21, 2005

One-time credit card number generator and single round-trip authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,908,030
App. No.
10/003,847
Granted
Jun 21, 2005
Kind
B2
Abstract

An online transaction is effected between a user system, a merchant system and an issuer system. The user system generates a one-time number (OTN) to use as a card number for a transaction with the merchant. The user system generates the OTN as a function of various parameters and sends the OTN to the issuer and to the merchant. With the issuer communication, the user is first authenticated, so the issuer can associate the received OTN with the user even if the user's identity cannot be fully discerned from the OTN alone. In authenticating the user with the issuer, and possibly other authentications, the user sends the issuer a signed challenge where the challenge is a sequential challenge or a function of a prior challenge provided by the issuer. The issuer responds with an approval/denial message and, in the latter case, includes the next challenge to be used.

Claims (19)

1. A method of authenticating a client to a server comprising:

generating a challenge at the client;

signing the challenge to form a signed challenge;

sending at least the signed challenge to the server, where the authenticity of the server is not in question;

verifying the signature of the challenge at the server; and

if the signature is verified, sending an indication of successful authentication to the client, where the indication of successful authentication is generated employing a single round trip authentication scheme.

2. The method of claim 1 , wherein generating a challenge at the client comprises generating a random number.

3. The method of claim 1 , wherein generating a challenge at the client comprises generating a sequential challenge.

4. The method of claim 1 , wherein generating a challenge at the client comprises generating a challenge based on data received from the server in a prior step.

5. The method of claim 4 , wherein the data received from the server is a challenge returned with a server response to a prior client query.

6. A method of using a one-time use card number for an online transaction, comprising:

generating a one-time use card number at a user system using a random number generator;

authenticating the user system to an issuer system, where the authenticating employs a single round trip authentication scheme;

passing the one-time use card number from the user system to the issuer system;

passing the one-time use card number from the user system to a merchant system, wherein the merchant system is programmed to present the one-time use card number to the issuer system to effect a payment;

verifying the one-time use card number received from the merchant system with the one-time use card number received from the user system; and

if the one-time use card number is verified, approving the transaction.

7. The method of claim 6 , wherein passing the one-time use card number to the issuer includes passing at least one other data element related to the online transaction.

8. The method of claim 7 , wherein the at least one other data element is selected from, or a function of, a user's account number, a user's private key, a transaction time, a transaction amount, or a merchant ID.

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2012
From: ARCOT SYSTEMS, INC.
To: COMPUTER ASSOCIATES THINK, INC.
Reel/Frame 028943/0020 →
MERGER Recorded Sep 12, 2012
From: COMPUTER ASSOCIATES THINK, INC.
To: CA, INC.
Reel/Frame 028943/0463 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2011
From: MVC CAPITAL, INC. (FORMERLY KNOWN AS MEVC DRAPER FISHER JURVETSON FUND I, INC.)
To: ARCOT SYSTEMS, INC.
Reel/Frame 025894/0720 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2011
From: SAND HILL VENTURE DEBT III, L.L.C.
To: ARCOT SYSTEMS, INC.
Reel/Frame 025894/0895 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2011
From: HORIZON TECHNOLOGY FUNDING COMPANY V L.L.C.
To: ARCOT SYSTEMS, INC.
Reel/Frame 025895/0870 →
RELEASE OF SECURITY INTEREST Recorded Aug 2, 2010
From: SAND HILL VENTURE DEBT III, LLC
To: ARCOT SYSTEMS, INC.
Reel/Frame 024767/0935 →
RELEASE OF SECURITY INTEREST Recorded Aug 2, 2010
From: MVC CAPITAL, INC. (F/K/A MEVC DRAPER FISHER JURVETSON FUND I, INC.)
To: ARCOT SYSTEMS, INC.
Reel/Frame 024776/0159 →
SECURITY AGREEMENT Recorded Aug 21, 2006
From: ARCOT SYSTEMS, INC.
To: SAND HILL VENTURE DEBT III, LLC
Reel/Frame 018148/0286 →
SECURITY INTEREST Recorded Jan 23, 2003
From: ARCOT SYSTEMS, INC.
To: MEVC DRAPER FISHER JURVETSON FUND I, INC.
Reel/Frame 013691/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2002
From: MASCHWITZ, STUART T.
To: ORPHANGAGE, INC., THE
Reel/Frame 012783/0688 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2001
From: RAJASEKARAN, SANGUTHEVAR; VARADARAJAN, RAMMOHAN
To: ARCOT SYSTEMS, INC.
Reel/Frame 012361/0656 →