IP Library Patent Application 13524867
Patent Application
App. No. 13/524,867

METHODS AND APPARATUS FOR CONDUCTING ELECTRONIC TRANSACTIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/524,867
Abstract

A system and method for conducting electronic commerce are disclosed. In various embodiments, the electronic transaction is a purchase transaction. A user is provided with an intelligent token, such as a smartcard containing a digital certificate. The intelligent token suitably authenticates with a server on a network that conducts all or portions of the transaction on behalf of the user. In various embodiments a wallet server interacts with a security server to provide enhanced reliability and confidence in the transaction. In various embodiments, the wallet server includes a toolbar. In various embodiments, the digital wallet pre-fills forms. Forms may be pre-filled using an auto-remember component.

Claims (58)

1 . A method comprising:

receiving, by a wallet server comprising a processor and a memory, a transaction request from a user device;

sending, by the wallet server, an authentication request to a security server, wherein the security server formats a challenge message;

receiving, by the wallet server and from the security server, the challenge message;

sending, by the wallet server and to the user device, a signature request based on the challenge message, wherein the user device creates a signature response message;

receiving, by the wallet server, the signature response message from the user device;

creating, by the wallet server, a validity check message based upon the signature response message and a security token;

sending, by the wallet server, the validity check message to the security server, wherein the security server verifies a match between security token and security information accessible by the security server; and

receiving, by the wallet server, a validity acceptance from the security server, wherein a transaction associated with the transaction request proceeds, in response to the receiving the validity acceptance.

2 . The method of claim 1 , wherein the challenge message comprises random data.

3 . The method of claim 1 , wherein the security token is stored by the wallet server.

4 . The method of claim 1 , herein the security token is at least one of created and enabled based upon a logon process.

5 . The method of claim 1 , wherein the security server performs the at least one of the creating and the enabling the security token.

6 . The method of claim 1 , wherein the user device is configured with a software application and wherein the software application processes the signature request.

7 . The method of claim 6 , wherein the software application formats a signature request block.

8 . The method of claim 6 , wherein the software application formats the signature request block as a Public-Key Cryptography Standards (PKCS) block.

9 . The method of claim 7 , wherein the software application makes the signature request block available to at least one of a signature module.

10 . The method of claim 9 , wherein a smart card comprises the signature module.

11 . The method of claim 9 , wherein a memory of the user device stores the signature module.

12 . The method of claim 11 , wherein the signature module signs the signature Hock and provides a copy of a security certificate.

13 . The method of claim 12 , wherein the signature response message comprises the signature block and the security certificate.

14 . The method of claim 1 , wherein the security token comprises at least one of an authentication token and a user identification (“user ID”).

15 . The method of claim 1 , further comprising:

scanning, by the wallet server, a third party request, the scanning identifying executable commands, wherein the executable commands are associated with a programming language; and

at least one of editing and removing, by the wallet server, at least a portion of the executable commands.

16 . The method of claim 15 , wherein the at least one of editing and removing comprises at least one of:

rendering the executable commands unexecutable by the user device by removing a character of the executable commands, and

rendering the executable commands unexecutable by the user device by replacing particular characters within the executable commands.

17 . The method of claim 1 , wherein the security server:

scans a third party request to identify executable commands, wherein the executable commands are associated with a programming language; and

at least one of edits and removes at least a portion of the executable commands, wherein the at least one of editing and removing comprises at least one of:

rendering the executable commands unexecutable by the user device by removing a character of the executable commands, and

rendering the executable commands unexecutable by the user device by replacing particular characters within the executable commands.

18 . The method of claim 1 , wherein the user device is configured with wallet client software, wherein the wallet client software:

scans a third party request to identify executable commands, wherein the executable commands are associated with a programming language; and

at least one of edits and removes at least a portion of the executable commands, wherein the at least one of editing and removing comprises at least one of:

rendering the executable commands unexecutable by the user device by removing a character of the executable commands, and

rendering the executable commands unexecutable by the user device by replacing particular characters within the executable commands.

19 . An article of manufacture including a non-transitory computer readable medium having instructions stored thereon that, in response to execution by a wallet server, cause the wallet server to perform operations comprising:

receiving, by the wallet server, a transaction request from a user device;

sending, by the wallet server, an authentication request to a security server, wherein the security server formats a challenge message;

receiving, by the wallet server and from the security server, the challenge message;

sending, by the wallet server and to the user device, a signature request based on the challenge message, wherein the user device creates a signature response message;

receiving, by the wallet server, the signature response message from the user device;

creating, by the wallet server, a validity check message based upon the signature response message and a security token;

sending, by the wallet server, the validity check message to the security server, wherein the security server verifies a match between security token and security information accessible by the security server; and

receiving, by the wallet server, a validity acceptance from the security server, wherein a transaction associated with the transaction request proceeds, in response to the receiving the validity acceptance.

20 . A system comprising:

a non-transitory memory communicating with a wallet server comprising a processor,

the memory having instructions stored thereon that, in response to execution by the processor, cause the processor to perform operations comprising:

receiving, by the processor, a transaction request from a user device;

sending, by the processor, an authentication request to a security server, wherein the security server formats a challenge message;

receiving, by the processor and from the security server, the challenge message;

sending, by the processor and to the user device, a signature request based on the challenge message, wherein the user device creates a signature response message;

receiving, by the processor, the signature response message from the user device;

creating, by the processor, a validity check message based upon the signature response message and a security token;

sending, by the processor, the validity check message to the security server, wherein the security server verifies a match between security token and security information accessible by the security server; and

receiving, by the processor, a validity acceptance from the security server, wherein a transaction associated with the transaction request proceeds, in response to the receiving the validity acceptance.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2018
From: INTELLECTUAL VENTURES ASSETS 66 LLC
To: LIBERTY PEAK VENTURES, LLC
Reel/Frame 045610/0409 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2018
From: GULA CONSULTING LIMITED LIABILITY COMPANY
To: INTELLECTUAL VENTURES ASSETS 66 LLC
Reel/Frame 045417/0042 →
MERGER Recorded Dec 18, 2015
From: LEAD CORE FUND, L.L.C.
To: GULA CONSULTING LIMITED LIABILITY COMPANY
Reel/Frame 037331/0239 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2013
From: SORA APPLICATIONS LLC
To: LEAD CORE FUND, L.L.C.
Reel/Frame 030350/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2012
From: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
To: SORA APPLICATIONS LLC
Reel/Frame 029270/0235 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2012
From: JOHNSON, MICHAEL G.; ROYER, COBY; SWIFT, NICK
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 028387/0611 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2012
From: SIMKIN, MARVIN
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 028387/0553 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2012
From: BISHOP, FRED ALAN; GLAZER, ELLIOTT HAROLD; GORGOL, ZYGMUNT STEVEN; HOHLE, WILLIAM G.; JOHNSTONE, DAVID E.; LAKE, WALTER DONALD; WHITE, DIRK B.; BENNETT, RUSSELL
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 028387/0524 →