IP Library Granted Patent US 7,908,227
Granted Patent B2
US 7,908,227 · App. 11/623,033 · Granted Mar 15, 2011

Method and apparatus for secure online transactions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,908,227
App. No.
11/623,033
Granted
Mar 15, 2011
Kind
B2
Abstract

A method and apparatus for performing secure online transactions provides a user interface that is intuitive and easily to understand. The invention integrates an online wallet service with credit card issuers that provide online credit card authentication services. The method provides a keypad interface for PIN entry, or an interface that resembles an offline transaction receipt. The apparatus that stores personal information and credit card information uses a level-two authentication password to protect the user's credit card information. The invention integrates with the credit card issuer when a personal identification number is required for the user to perform online transactions by the credit card issuer. The embodiments include integrations when the level-two authentication password is equivalent to the personal identification number and that when they or not equivalent.

Claims (39)

1. A computer-implemented method for conducting an online transaction comprising the steps of:

receiving, by a server, a request from a user to checkout a selection of merchandize or services sold by a merchant;

generating, by said server, an extensible HTML page containing:

a transaction message comprising a core specification that describes online transactions and a frame specification, said frame specification embedding said core specification in a web service message, said transaction message represented in a payment markup language that describes payment transactions; and

a request for an authentication password from said user;

transmitting, by said server, said extensible HTML page to a browser;

rendering, by said browser, said extensible HTML page to a graphical interface that resembles a real-world receipt, said graphical interface displaying a sign button;

receiving said authentication password from said user;

authenticating said authentication password;

installing, on said browser and by said user, a certificate of said user by using browser methods, said certificate of said user issued by said user's bank;

signing, by said browser, said core specification in said transaction message with said certificate of said user;

transmitting, by said browser, said signature to said server in response to said user clicking said sign button;

generating, by said server, a complete transaction message including said signature and sending it to a payment gateway; and

verifying, by said payment gateway, said transaction message along with said signature and in response to said verifying, said payment gateway honoring said transaction.

2. The method of claim 1 further comprising:

storing said signature on said server in case of future disputes.

3. The method of claim 1 further comprising:

containing said transaction message in said extensible HTML page, such that said core specification has its own namespace, and wherein said rendering step further comprises:

rendering said transaction message readily contained in said extensible HTML page and said core specification having its own namespace.

4. The method of claim 1 , wherein said certificate of said user is issued by a credit card issuer of said user, said signing step further comprising signing said transaction message with said certificate issued by said credit card issuer of said user to generate a signature.

5. The method of claim 1 further comprising said transaction message containing a unique transaction ID and a date and time that said transaction takes place to provide non-repudiation.

6. A computer-implemented method for conducting an online transaction comprising the steps of:

receiving, by a server, a request from a user to checkout a selection of merchandize or services sold by a merchant;

generating, by said server, an extensible HTML page containing:

a transaction message comprising a core specification that describes online transactions and a frame specification, said frame specification embedding said core specification in a web service message, said transaction message represented in a payment markup language that describes payment transactions and said transaction message containing a unique transaction ID and a date and time that said transaction takes place to provide non-repudiation; and

a request for an authentication password from said user;

transmitting, by said server, said extensible HTML page to a browser;

rendering, by said browser, said extensible HTML page to a graphical interface that resembles a real-world receipt, said graphical interface displaying a sign button;

receiving said authentication password from said user;

authenticating said authentication password;

signing said core specification in said transaction message by a smart card that contains said certificate of said user, said signing with said certificate;

transmitting, by said browser, said signature to said server in response to said user clicking said sign button;

generating, by said server, a complete transaction message including said signature and sending it to a payment gateway;

verifying, by said payment gateway, said transaction message along with said signature and in response to said verifying, said payment gateway honoring said transaction; and

storing said signature on said server in case of future disputes,

wherein said certificate of said user is issued by a credit card issuer of said user, said signing step further comprising signing said core specification in said transaction message with said certificate issued by said credit card issuer of said user to generate a signature.

7. The method of claim 6 further comprising:

containing said transaction message in said extensible HTML page, such that said core specification has its own namespace, and wherein said rendering step further comprises:

rendering said transaction message readily contained in said extensible HTML page and said core specification having its own namespace.

Assignments (9)
CHANGE OF NAME Recorded Dec 20, 2021
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058961/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2012
From: AOL INC.
To: FACEBOOK, INC.
Reel/Frame 028487/0304 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2012
From: ZISSIMOPOULOS, VASILEIOS "BILL"; RAWAT, JAI; MARSHALL, JOHN
To: AMERICA ONLINE, INC.
Reel/Frame 028348/0243 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 16, 2010
From: BANK OF AMERICA, N A
To: AOL INC; AOL ADVERTISING INC; GOING INC; LIGHTNINGCAST LLC; MAPQUEST, INC; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC; TACODA LLC; TRUVEO, INC; YEDDA, INC
Reel/Frame 025323/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2009
From: AOL LLC
To: AOL INC.
Reel/Frame 023750/0210 →
SECURITY AGREEMENT Recorded Dec 14, 2009
From: AOL INC.; AOL ADVERTISING INC.; BEBO, INC.; ICQ LLC; GOING, INC.; LIGHTNINGCAST LLC; MAPQUEST, INC.; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC.; TACODA LLC; TRUVEO, INC.; YEDDA, INC.
To: BANK OF AMERICAN, N.A. AS COLLATERAL AGENT
Reel/Frame 023649/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED ON REEL 019711 FRAME 0316. ASSIGNOR(S) HEREBY CONFIRMS THE NATURE OF CONVEYANCE IS CHANGE OF NAME. Recorded Mar 25, 2009
From: AMERICA ONLINE, INC.
To: AOL LLC, A DELAWARE LIMITED LIABILITY COMPANY
Reel/Frame 022451/0186 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2007
From: AMERICA ONLINE, INC.
To: AOL LLC, A DELAWARE LIMITED LIABILITY COMPANY
Reel/Frame 019711/0316 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2007
From: AMERICA ONLINE, INC.
To: AOL LLC, A DELAWARE LIMITED LIABILITY COMPANY
Reel/Frame 019321/0447 →