IP Library › Patent Application 10346732
Patent Application
App. No. 10/346,732

Systems and methods for authentication of electronic transactions

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/346,732
Abstract

An online transaction system configured to implement authentication methods that allow for strong multi-factor authentication in online environments. The authentication methods can be combined with strong security methods to further ensure that the authentication process is secure. Further, the strong multi-factor authentication can be implemented with zero adoption dependencies through the implementation of automated enrollment methods.

Claims (97)

1 . A method for authenticating an electronic transaction; comprising:

receiving a request to transact;

verifying the presence of a token in a terminal; and

authenticating the electronic transaction based at least in part on successful verifying the presence of the token in the terminal.

2 . The method of claim 1 , further comprising verifying a plurality of factors in response to the received request to transact, wherein the presence of the token is just one of the plurality of factors.

3 . The method of claim 2 , wherein the plurality of factors includes an account identifier.

4 . The method of claim 2 , wherein the plurality of factors includes a personal identifier.

5 . The method of claim 4 , wherein the personal identifier is linked with a user profile.

6 . The method of claim 2 , wherein the plurality of factors includes a biometric.

7 . The method of claim 2 , wherein the plurality of factors includes an electronic signature.

8 . The method of claim 2 , further comprising decoding received, encoded messages comprising information related to one or more of the plurality of factors.

9 . The method of claim 1 , wherein receiving a request to transact, comprises:

receiving a request to verify enrollment in an authentication program of a token identifier associated with the token;

verifying enrollment of the token identifier in the authentication program; and

transmitting a response based on the verification.

10 . The method of claim 1 , further comprising storing information related to the authentication of the electronic transaction.

11 . A transaction authentication system comprising an authentication authority, the authentication authority configured to:

receive a request to transact;

verify the presence of a token in a terminal; and

authenticate the electronic transaction based at least in part on successful verifying the presence of the token in the terminal.

12 . The authentication system of claim 11 , wherein the authentication authority is further configured to verify a plurality of factors in response to the received request to transact, wherein the presence of the token is just one of the plurality of factors.

13 . The authentication system of claim 12 , wherein the plurality of factors includes an account identifier.

14 . The authentication system of claim 12 , wherein the plurality of factors includes a personal identifier.

15 . The authentication system of claim 14 , wherein the personal identifier is linked with a user profile.

16 . The authentication system of claim 12 , wherein the plurality of factors includes a biometric.

17 . The authentication system of claim 12 , wherein the plurality of factors includes an electronic signature.

18 . The authentication system of claim 12 , wherein the authentication authority is further configured to decode received, encoded messages comprising information related to one or more of the plurality of factors.

19 . The authentication system of claim 11 , wherein the authentication authority is further configured to:

receive a request to verify enrollment in an authentication program of an token identifier associated with the token;

verify enrollment of the token identifier in the authentication program; and

transmit a response based on the verification.

20 . The authentication system of claim 11 , wherein the authentication authority is further configured to store information related to the authentication of the token transaction.

21 . A method for authenticating an electronic transaction, comprising:

issuing a token configured to be used in the electronic transaction;

issuing a personal identifier to be used in conjunction with the issued token in the electronic transaction;

receiving a request to authorize the electronic transaction; and

verifying the presence of the token in a terminal and the personal identifier in response to the authentication request.

22 . The method of claim 21 , further comprising authorizing the electronic transaction if the verification of the presence of the token and the personal identifier was successful.

23 . The method of claim 21 , further comprising storing information related to the electronic transaction authentication.

24 . The method of claim 21 , wherein issuing a personal identifier comprises issuing a public key-private key combination, and wherein verifying the personnel identifier comprises using the public key to verify the personnel identifier.

25 . The method of claim 21 , further comprising registering the token in an authentication program.

26 . A method for authorizing an electronic transaction, comprising receiving information related to the electronic transaction, the information comprising verification of the presence of a token in a terminal; and storing the received information.

27 . The method of claim 26 , further comprising:

receiving an enrollment inquiry related to the token;

acquiring the enrollment status of the token; and

forwarding the acquired enrollment status.

28 . The method of claim 27 , wherein acquiring the enrollment status comprises:

receiving a token identifier;

sending a request to an issuer to verify the enrollment status based on the token identifier; and

receiving the enrollment status of the token from the issuer in response to the enrollment request.

29 . The method of claim 28 , wherein acquiring the enrollment status further comprises verifying that the token identifier is within a certain range of identifiers.

30 . The method of claim 25 , further comprising receiving information related to the electronic transaction, and storing the received information.

31 . A transaction authentication system comprising a directory server, the directory server configured to:

receive information related to an electronic transaction, the information comprising verification of the presence of a token in a terminal; and

store the received information.

32 . The transaction authentication system of claim 31 , further configured to:

receive an enrollment inquiry related to the token;

acquire the enrollment status of the token; and

forward the acquired enrollment status.

33 . The transaction authentication system of claim 32 , wherein the directory server is further configured to:

receive a token identifier;

send a request to an issuer to verify the enrollment status based on the token identifier; and

receive the enrollment status of the token from the issuer in response to the enrollment request.

34 . The transaction authentication system of claim 33 , wherein the directory server further comprises a directory configured to store token information, and wherein the directory server is further configured to verify that the token identifier is within a certain range of identifiers based on the information stored in the directory.

35 . The transaction authentication system of claim 31 , wherein the directory sever is further configured to receive information related to the electronic transaction, and store the received information.

36 . A method for authenticating an electronic transaction, comprising determining if a token is interfaced with a terminal through a standard input device, acquiring authentication information from the token, and transmitting a message that comprises the authentication information to an authentication authority.

37 . The method of claim 36 , further comprising displaying a prompt on the terminal requesting that the token be interfaced with the terminal when it is determined that the token is not already interfaced with the terminal.

38 . The method of claim 36 , further comprising encrypting the message before transmitting the message to the authentication authority.

39 . The method of claim 36 , wherein the authentication information comprises a unique information.

40 . The method of claim 39 , wherein the unique information comprises a token identifier.

41 . The method of claim 39 , wherein the unique information comprises a message key.

42 . The method of claim 36 , further comprising receiving a personal identifeir.

43 . The method of claim 42 , wherein the personal identifier is linked with a user profile.

44 . The method of claim 36 , further comprising displaying a prompt, the prompt requesting that a personal identifier be entered.

45 . The method of claim 44 , further comprising receiving a personal identifier in response to the prompt and including the received personal identifier in the message transmitted to the authentication authority.

46 . The method of claim 36 , further comprising receiving information related to a plurality of factors and including the received information in the message transmitted to the authentication authority.

47 . The method of claim 46 , wherein the plurality of factors includes a biometric.

48 . A terminal comprising a standard input device, the terminal configured to determine if a token is interfaced with the terminal and transmit a verification message to an authentication authority indicating whether the token is interfaced with the terminal.

49 . The terminal of claim 48 , further comprising a display, and wherein the terminal is further configured to display a message on the terminal requesting that the token be interfaced with the terminal when it is determined that the token is not already interfaced with the terminal.

50 . The terminal of claim 48 , further configured to encrypt the verification message before transmitting the verification message to the authentication authority.

51 . The terminal of claim 50 , further configured to transmit a token identifier associated with the token to a merchant server.

52 . The terminal of claim 51 , further configured to transmit transaction information related to the electronic transaction to the merchant server.

53 . The terminal of claim 48 , further configured to read a token identifier stored in the token and transmit a verification message comprising the token identifier stored in the token.

54 . The terminal of claim 48 , further configured to receive an authentication message in response to the verification message.

55 . The terminal of claim 54 , further configured to forward the authentication response to a merchant server and complete the electronic transaction.

56 . The terminal of claim 48 , further comprising receiving information related to a plurality of factors of which presence of the token is just one, and wherein the verification message further comprises the received information related to the plurality of factors.

57 . The terminal of claim 56 , wherein the terminal further comprises a biometric reader, and wherein the terminal is further configured to receive biometric information through the biometric reader.

58 . The terminal of claim 56 , wherein the terminal further comprises a user interface, and wherein the terminal is further configured to receive information related to a personal identifier through the user interface.

59 . The terminal of claim 56 , wherein the terminal is further configured to generate an electronic signature and include the electronic signature in the verification message.

60 . A method for authenticating an electronic transaction, comprising:

interfacing a token with a terminal through a standard input device;

verifying the presence of the token once it is interfaced with the terminal; and

authorizing the electronic transaction based at least in part on a successful verification.

61 . The method of claim 69 , further comprising inputting a personal identifier, verifying the personal identifier, and authorizing the electronic transaction based at least in part on a successful verification of the personal identifier.

62 . The method of claim 60 , further comprising reading biometric information input into the terminal through a biometric reader, verifying the biometric information, and authorizing the electronic transaction based at least in part on a successful verification of the biometric information.

63 . The method of claim 60 , further comprising verifying an electronic signature generated by the terminal and authorizing the electronic transaction based in part on a successful verification of the electronic signature.

64 . The method of claim 60 , further comprising receiving information related to a plurality of factors, verifying the plurality of factors based on the received information, and authorizing the transaction base on a successful verification of the plurality of factors.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2003
From: HOLDSWORTH, JOHN
To: U.S. ENCODE CORPORATION
Reel/Frame 014018/0782 →