METHODS AND APPARATUS FOR CONDUCTING ELECTRONIC TRANSACTIONS
A system and method for conducting electronic commerce are disclosed. In various embodiments, the electronic transaction is a purchase transaction. A user is provided with an intelligent token, such as a smartcard containing a digital certificate. The intelligent token suitably authenticates with a server on a network that conducts all or portions of the transaction on behalf of the user. In various embodiments a wallet server interacts with a security server to provide enhanced reliability and confidence in the transaction. In various embodiments, the wallet server includes a toolbar. In various embodiments, the digital wallet pre-fills forms. Forms may be pre-filled using an auto-remember component.
1 . A method comprising:
accessing, by a user device, user information from at least one of a memory cache of the user device and a wallet server, wherein the user device is configured with an activator software module;
receiving, by the user device, the user information;
monitoring, by the user device, a uniform resource locator (URL) accessed by an internet client of the user device;
determining, by the user device and based upon the user information, that the URL is associated with a check-out page of a supported web site; and
enabling, by the user device, a check-out process of the web site, wherein said check-out process comprises authentication of the user device with a security server.
2 . The method of claim 1 , further comprising requesting the user information from the wallet server.
3 . The method of claim 1 , further comprising updating the memory cache with the user information.
4 . The method of claim 1 , wherein the user information comprises at least one of web sites, domain names and URLs.
5 . The method of claim 2 , wherein the requesting the user information occurs on a predetermined schedule.
6 . The method of claim 1 , wherein the enabling the check.-out process comprises initiating wallet software.
7 . The method of claim 1 , wherein the enabling a check-out process comprises enabling an authentication process with the security server.
8 . The method of claim 7 , wherein the enabling the authentication process comprises:
sending, by the user device, a logon request to the security server, wherein the security server replies to the logon request with a challenge;
receiving, by the user device, the challenge, wherein an intelligent token generates a challenge response based on the challenge;
sending, by the user device, the challenge response to the security server, wherein the security server verifies the intelligent token based upon the challenge response and assembles credentials associated with the user, wherein the credentials comprise a key; and
receiving, by the user device, at least a portion of the assembled credentials.
9 . The method of claim 8 , further comprising sending an authentication request, wherein the security server authorizes a transaction session based upon the authentication request and the assembled credentials.
10 . The method of claim 9 , further comprising
receiving, by the user device, an authentication challenge message, wherein in response to the authentication request, the security server creates the authentication challenge message; and
sending, by the user device, an authentication challenge response, the authentication challenge response comprising a signed signature block and a security certificate.
11 . The method of claim 10 , wherein the security server verifies the authentication challenge response against the assembled credentials.
12 . The method of claim 1 , wherein in response to the receiving the authentication challenge message, the wallet server creates the signature block based on the authentication challenge message, wherein the user device is configured with the wallet server and, wherein the wallet server signs the signature block and provides a security certificate.
13 . The method of claim 1 , wherein the sending a logon request by the user device to the security server comprises sending via at least one of wallet client software and the wallet server.
14 . The method of claim 1 , wherein the transaction session is associated with at least one of a session on wallet client software of the user device and a session on the wallet server.
15 . The method of claim 1 , further comprising:
scanning, by wallet client software associated with the user device, a third party request, the scanning identifying executable commands, wherein the executable commands are associated with a programming language; and,
at least one of editing and removing, by the user device, at least a portion of the executable commands.
16 . The method of claim 15 , wherein the at least one of editing and removing comprises at least one of:
rendering the executable commands unexecutable by the user device by removing a character of the executable commands, and
rendering the executable commands unexecutable by the user device by replacing particular characters within the executable commands.
17 . The method of claim 1 , wherein the wallet server:
scans a third party request to identify executable commands, wherein the executable commands are associated with a programming language; and
at least one of edits and removes at least a portion of the executable commands, wherein the at least one of editing and removing comprises at least one of:
rendering the executable commands unexecutable by the user device by removing a character of the executable commands, and
rendering the executable commands unexecutable by the user device by replacing particular characters within the executable commands.
18 . The method of claim 1 , wherein the wallet server facilitates the authentication of the user device with the security server, and wherein the wallet server:
scans a third party request to identify executable commands, wherein the executable commands are associated with a programming language; and
at least one of edits and removes at least a portion of the executable commands, wherein the at least one of editing and removing comprises at least one of:
rendering the executable commands unexecutable by the user device by removing a character of the executable commands, and
rendering the executable commands unexecutable by the user device by replacing particular characters within the executable commands.
19 . An article of manufacture including a non-transitory computer readable medium having instructions stored thereon that, in response to execution by a user device, cause the user device to perform operations comprising:
sending, by the user device and to a security server, a logon request, wherein the security server replies to the logon request with a challenge;
receiving, by the user device, the challenge, wherein an intelligent token generates a challenge response based on the challenge;
sending, by the user device, the challenge response to the security server, wherein the security server verifies the intelligent token based upon the challenge response and assembles credentials associated with the user, wherein the credentials comprise a key;
receiving, by the user device, at least a portion of the assembled credentials;
sending, by the user device, an authentication request, wherein the security server authorizes a transaction session based upon the authentication request and the assembled credentials.
20 . A user device comprising:
a non-transitory memory communicating with a processor,
the memory having instructions stored thereon that, in response to execution by the processor, cause the processor to perform operations comprising:
sending, by the processor and to a security server, a logon request, wherein the security server replies to the logon request with a challenge;
receiving, by the processor, the challenge, wherein an intelligent token generates a challenge response based on the challenge;
sending, by the processor, the challenge response to the security server, wherein the security server verifies the intelligent token based upon the challenge response and assembles credentials associated with the user, wherein the credentials comprise a key;
receiving, by the processor, at least a portion of the assembled credentials;
sending, by the processor, an authentication request, wherein the security server authorizes a transaction session based upon the authentication request and the assembled credentials.