IP Library › Patent Application 10338822
Patent Application
App. No. 10/338,822

Systems and methods for secure authentication of electronic transactions

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/338,822
Abstract

An online transaction system configured to implement authentication methods that allow for strong multi-factor authentication in online environments. The authentication methods can be combined with strong security methods to further ensure that the authentication process is secure. Further, the strong multi-factor authentication can be implemented with zero adoption dependencies through the implementation of automated enrollment methods.

Claims (42)

1 . A method for secure authentication, comprising:

receiving an authentication request message at a terminal from an authentication authority;

prompting a user to interface a token with the terminal;

extracting unique information from the token once it is interfaced with the terminal;

prompting the user for a personal identifier; and

generating a response to the authentication request message based on the personal identifier and the unique information.

2 . The method of claim 1 , further comprising generating a transactionally unique session key, using the transactionally unique session key to encrypt the response, and transmitting the encrypted response to the authentication authority.

3 . The method of claim 1 , wherein the personal identifier is linked with an account associated with the token.

4 . The method of claim 1 , wherein the unique information comprises a unique serial number.

5 . The method of claim 1 , wherein the unique information comprises a message key.

6 . The method of claim 1 , wherein the unique information comprises random data.

7 . The method of claim 1 , wherein the unique information comprises a network address associated with the authentication authority.

8 . The method of claim 1 , further comprising generating a time stamp and generating the response based on the time stamp.

9 . The method of claim 1 , wherein the authentication request message is encrypted, and wherein the method further comprises decrypting the received authentication request message.

10 . The method of claim 1 , further comprising synchronizing a time associated with the response based at least in part on time information included in the authentication request message.

11 . A method for secure authentication, comprising:

receiving an authentication request comprising transactional information;

generating an authentication request message in response to the authentication request;

transmitting the authentication request message to a terminal; and

receiving a response to the authentication request message from the terminal that is encrypted using a transactionally unique session key.

12 . The method of claim 11 , wherein generating the authentication request message comprises encrypting the authentication request message.

13 . The method of claim 12 , wherein encrypting the authentication message comprises generating a random number.

14 . The method of claim 12 , wherein encrypting the authentication message comprises generating a time stamp.

15 . The method of claim 12 , wherein encrypting the authentication message comprises generating an electronic signature.

16 . The method of claim 12 , wherein encrypting the authentication message comprises retrieving a message key.

17 . The method of claim 11 , further comprising decrypting the received response using the transactionally unique session key.

18 . A terminal configured for secure authentication, the termianl comprising client software configured to allow the terminal to:

receive an authentication request message from an authentication authority;

prompt a user to interface a token with the terminal;

extract unique information from the token once it is interfaced with the terminal;

prompt the user for a personal identifier; and

generate a response to the authentication request message based on the personal identifier and the unique information.

19 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to generate a transactionally unique session key, use the transactionally unique session key to encrypt the response, and transmit the encrypted response to the authentication authority.

20 . The terminal of claim 18 , wherein the personal identifier is linked with an account associated with the token.

21 . The terminal of claim 18 , wherein the unique information comprises a unique serial number.

22 . The terminal of claim 18 , wherein the unique information comprises a message key.

23 . The terminal of claim 18 , wherein the unique information comprises random data.

23 . The terminal of claim 18 , wherein the unique information comprises a network address associated with the authentication authority.

24 . The terminal of claim 23 , wherein the client software is further configured to access the network address and automatically connect with the authentication authority.

25 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to generate a time stamp and generate the response based on the time stamp.

26 . The terminal of claim 18 , wherein the authentication request message is encrypted, and wherein the client software is further configured to allow the terminal to decrypt the received authentication request message.

27 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to associated a time with the response based at least in part on time information included in the authentication request message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2003
From: HOLDSWORTH, JOHN
To: U.S. ENCODE CORPORATION
Reel/Frame 014018/0782 →