Systems and methods for secure authentication of electronic transactions
An online transaction system configured to implement authentication methods that allow for strong multi-factor authentication in online environments. The authentication methods can be combined with strong security methods to further ensure that the authentication process is secure. Further, the strong multi-factor authentication can be implemented with zero adoption dependencies through the implementation of automated enrollment methods.
1 . A method for secure authentication, comprising:
receiving an authentication request message at a terminal from an authentication authority;
prompting a user to interface a token with the terminal;
extracting unique information from the token once it is interfaced with the terminal;
prompting the user for a personal identifier; and
generating a response to the authentication request message based on the personal identifier and the unique information.
2 . The method of claim 1 , further comprising generating a transactionally unique session key, using the transactionally unique session key to encrypt the response, and transmitting the encrypted response to the authentication authority.
3 . The method of claim 1 , wherein the personal identifier is linked with an account associated with the token.
4 . The method of claim 1 , wherein the unique information comprises a unique serial number.
5 . The method of claim 1 , wherein the unique information comprises a message key.
6 . The method of claim 1 , wherein the unique information comprises random data.
7 . The method of claim 1 , wherein the unique information comprises a network address associated with the authentication authority.
8 . The method of claim 1 , further comprising generating a time stamp and generating the response based on the time stamp.
9 . The method of claim 1 , wherein the authentication request message is encrypted, and wherein the method further comprises decrypting the received authentication request message.
10 . The method of claim 1 , further comprising synchronizing a time associated with the response based at least in part on time information included in the authentication request message.
11 . A method for secure authentication, comprising:
receiving an authentication request comprising transactional information;
generating an authentication request message in response to the authentication request;
transmitting the authentication request message to a terminal; and
receiving a response to the authentication request message from the terminal that is encrypted using a transactionally unique session key.
12 . The method of claim 11 , wherein generating the authentication request message comprises encrypting the authentication request message.
13 . The method of claim 12 , wherein encrypting the authentication message comprises generating a random number.
14 . The method of claim 12 , wherein encrypting the authentication message comprises generating a time stamp.
15 . The method of claim 12 , wherein encrypting the authentication message comprises generating an electronic signature.
16 . The method of claim 12 , wherein encrypting the authentication message comprises retrieving a message key.
17 . The method of claim 11 , further comprising decrypting the received response using the transactionally unique session key.
18 . A terminal configured for secure authentication, the termianl comprising client software configured to allow the terminal to:
receive an authentication request message from an authentication authority;
prompt a user to interface a token with the terminal;
extract unique information from the token once it is interfaced with the terminal;
prompt the user for a personal identifier; and
generate a response to the authentication request message based on the personal identifier and the unique information.
19 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to generate a transactionally unique session key, use the transactionally unique session key to encrypt the response, and transmit the encrypted response to the authentication authority.
20 . The terminal of claim 18 , wherein the personal identifier is linked with an account associated with the token.
21 . The terminal of claim 18 , wherein the unique information comprises a unique serial number.
22 . The terminal of claim 18 , wherein the unique information comprises a message key.
23 . The terminal of claim 18 , wherein the unique information comprises random data.
23 . The terminal of claim 18 , wherein the unique information comprises a network address associated with the authentication authority.
24 . The terminal of claim 23 , wherein the client software is further configured to access the network address and automatically connect with the authentication authority.
25 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to generate a time stamp and generate the response based on the time stamp.
26 . The terminal of claim 18 , wherein the authentication request message is encrypted, and wherein the client software is further configured to allow the terminal to decrypt the received authentication request message.
27 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to associated a time with the response based at least in part on time information included in the authentication request message.