Systems and methods for authentication of electronic transactions
An online transaction system configured to implement authentication methods that allow for strong multi-factor authentication in online environments. The authentication methods can be combined with strong security methods to further ensure that the authentication process is secure. Further, the strong multi-factor authentication can be implemented with zero adoption dependencies through the implementation of automated enrollment methods.
1 . A method for authenticating an electronic transaction; comprising:
receiving a request to transact;
verifying the presence of a token in a terminal; and
authenticating the electronic transaction based at least in part on successful verifying the presence of the token in the terminal.
2 . The method of claim 1 , further comprising verifying a plurality of factors in response to the received request to transact, wherein the presence of the token is just one of the plurality of factors.
3 . The method of claim 2 , wherein the plurality of factors includes an account identifier.
4 . The method of claim 2 , wherein the plurality of factors includes a personal identifier.
5 . The method of claim 4 , wherein the personal identifier is linked with a user profile.
6 . The method of claim 2 , wherein the plurality of factors includes a biometric.
7 . The method of claim 2 , wherein the plurality of factors includes an electronic signature.
8 . The method of claim 2 , further comprising decoding received, encoded messages comprising information related to one or more of the plurality of factors.
9 . The method of claim 1 , wherein receiving a request to transact, comprises:
receiving a request to verify enrollment in an authentication program of a token identifier associated with the token;
verifying enrollment of the token identifier in the authentication program; and
transmitting a response based on the verification.
10 . The method of claim 1 , further comprising storing information related to the authentication of the electronic transaction.
11 . A transaction authentication system comprising an authentication authority, the authentication authority configured to:
receive a request to transact;
verify the presence of a token in a terminal; and
authenticate the electronic transaction based at least in part on successful verifying the presence of the token in the terminal.
12 . The authentication system of claim 11 , wherein the authentication authority is further configured to verify a plurality of factors in response to the received request to transact, wherein the presence of the token is just one of the plurality of factors.
13 . The authentication system of claim 12 , wherein the plurality of factors includes an account identifier.
14 . The authentication system of claim 12 , wherein the plurality of factors includes a personal identifier.
15 . The authentication system of claim 14 , wherein the personal identifier is linked with a user profile.
16 . The authentication system of claim 12 , wherein the plurality of factors includes a biometric.
17 . The authentication system of claim 12 , wherein the plurality of factors includes an electronic signature.
18 . The authentication system of claim 12 , wherein the authentication authority is further configured to decode received, encoded messages comprising information related to one or more of the plurality of factors.
19 . The authentication system of claim 11 , wherein the authentication authority is further configured to:
receive a request to verify enrollment in an authentication program of an token identifier associated with the token;
verify enrollment of the token identifier in the authentication program; and
transmit a response based on the verification.
20 . The authentication system of claim 11 , wherein the authentication authority is further configured to store information related to the authentication of the token transaction.
21 . A method for authenticating an electronic transaction, comprising:
issuing a token configured to be used in the electronic transaction;
issuing a personal identifier to be used in conjunction with the issued token in the electronic transaction;
receiving a request to authorize the electronic transaction; and
verifying the presence of the token in a terminal and the personal identifier in response to the authentication request.
22 . The method of claim 21 , further comprising authorizing the electronic transaction if the verification of the presence of the token and the personal identifier was successful.
23 . The method of claim 21 , further comprising storing information related to the electronic transaction authentication.
24 . The method of claim 21 , wherein issuing a personal identifier comprises issuing a public key-private key combination, and wherein verifying the personnel identifier comprises using the public key to verify the personnel identifier.
25 . The method of claim 21 , further comprising registering the token in an authentication program.
26 . A method for authorizing an electronic transaction, comprising receiving information related to the electronic transaction, the information comprising verification of the presence of a token in a terminal; and storing the received information.
27 . The method of claim 26 , further comprising:
receiving an enrollment inquiry related to the token;
acquiring the enrollment status of the token; and
forwarding the acquired enrollment status.
28 . The method of claim 27 , wherein acquiring the enrollment status comprises:
receiving a token identifier;
sending a request to an issuer to verify the enrollment status based on the token identifier; and
receiving the enrollment status of the token from the issuer in response to the enrollment request.
29 . The method of claim 28 , wherein acquiring the enrollment status further comprises verifying that the token identifier is within a certain range of identifiers.
30 . The method of claim 25 , further comprising receiving information related to the electronic transaction, and storing the received information.
31 . A transaction authentication system comprising a directory server, the directory server configured to:
receive information related to an electronic transaction, the information comprising verification of the presence of a token in a terminal; and
store the received information.
32 . The transaction authentication system of claim 31 , further configured to:
receive an enrollment inquiry related to the token;
acquire the enrollment status of the token; and
forward the acquired enrollment status.
33 . The transaction authentication system of claim 32 , wherein the directory server is further configured to:
receive a token identifier;
send a request to an issuer to verify the enrollment status based on the token identifier; and
receive the enrollment status of the token from the issuer in response to the enrollment request.
34 . The transaction authentication system of claim 33 , wherein the directory server further comprises a directory configured to store token information, and wherein the directory server is further configured to verify that the token identifier is within a certain range of identifiers based on the information stored in the directory.
35 . The transaction authentication system of claim 31 , wherein the directory sever is further configured to receive information related to the electronic transaction, and store the received information.
36 . A method for authenticating an electronic transaction, comprising determining if a token is interfaced with a terminal through a standard input device, acquiring authentication information from the token, and transmitting a message that comprises the authentication information to an authentication authority.
37 . The method of claim 36 , further comprising displaying a prompt on the terminal requesting that the token be interfaced with the terminal when it is determined that the token is not already interfaced with the terminal.
38 . The method of claim 36 , further comprising encrypting the message before transmitting the message to the authentication authority.
39 . The method of claim 36 , wherein the authentication information comprises a unique information.
40 . The method of claim 39 , wherein the unique information comprises a token identifier.
41 . The method of claim 39 , wherein the unique information comprises a message key.
42 . The method of claim 36 , further comprising receiving a personal identifeir.
43 . The method of claim 42 , wherein the personal identifier is linked with a user profile.
44 . The method of claim 36 , further comprising displaying a prompt, the prompt requesting that a personal identifier be entered.
45 . The method of claim 44 , further comprising receiving a personal identifier in response to the prompt and including the received personal identifier in the message transmitted to the authentication authority.
46 . The method of claim 36 , further comprising receiving information related to a plurality of factors and including the received information in the message transmitted to the authentication authority.
47 . The method of claim 46 , wherein the plurality of factors includes a biometric.
48 . A terminal comprising a standard input device, the terminal configured to determine if a token is interfaced with the terminal and transmit a verification message to an authentication authority indicating whether the token is interfaced with the terminal.
49 . The terminal of claim 48 , further comprising a display, and wherein the terminal is further configured to display a message on the terminal requesting that the token be interfaced with the terminal when it is determined that the token is not already interfaced with the terminal.
50 . The terminal of claim 48 , further configured to encrypt the verification message before transmitting the verification message to the authentication authority.
51 . The terminal of claim 50 , further configured to transmit a token identifier associated with the token to a merchant server.
52 . The terminal of claim 51 , further configured to transmit transaction information related to the electronic transaction to the merchant server.
53 . The terminal of claim 48 , further configured to read a token identifier stored in the token and transmit a verification message comprising the token identifier stored in the token.
54 . The terminal of claim 48 , further configured to receive an authentication message in response to the verification message.
55 . The terminal of claim 54 , further configured to forward the authentication response to a merchant server and complete the electronic transaction.
56 . The terminal of claim 48 , further comprising receiving information related to a plurality of factors of which presence of the token is just one, and wherein the verification message further comprises the received information related to the plurality of factors.
57 . The terminal of claim 56 , wherein the terminal further comprises a biometric reader, and wherein the terminal is further configured to receive biometric information through the biometric reader.
58 . The terminal of claim 56 , wherein the terminal further comprises a user interface, and wherein the terminal is further configured to receive information related to a personal identifier through the user interface.
59 . The terminal of claim 56 , wherein the terminal is further configured to generate an electronic signature and include the electronic signature in the verification message.
60 . A method for authenticating an electronic transaction, comprising:
interfacing a token with a terminal through a standard input device;
verifying the presence of the token once it is interfaced with the terminal; and
authorizing the electronic transaction based at least in part on a successful verification.
61 . The method of claim 69 , further comprising inputting a personal identifier, verifying the personal identifier, and authorizing the electronic transaction based at least in part on a successful verification of the personal identifier.
62 . The method of claim 60 , further comprising reading biometric information input into the terminal through a biometric reader, verifying the biometric information, and authorizing the electronic transaction based at least in part on a successful verification of the biometric information.
63 . The method of claim 60 , further comprising verifying an electronic signature generated by the terminal and authorizing the electronic transaction based in part on a successful verification of the electronic signature.
64 . The method of claim 60 , further comprising receiving information related to a plurality of factors, verifying the plurality of factors based on the received information, and authorizing the transaction base on a successful verification of the plurality of factors.