IP Library Granted Patent US 9,171,307
Granted Patent B2
US 9,171,307 · App. 14/179,468 · Granted Oct 27, 2015

Using successive levels of authentication in online commerce

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,171,307
App. No.
14/179,468
Granted
Oct 27, 2015
Kind
B2
Abstract

A method comprising performing following acts on a network server: receiving a communication from a client terminal operated by a client; performing a first authentication of the client terminal or client; in response to the first authentication, delivering a first service to the client; after delivering the first service, sending an offer for a second service to the client terminal; receiving an acceptance message for the second service from the client terminal; performing a second authentication of the client terminal and/or the client; in response to receiving the acceptance message for the second service from the client terminal and to the second authentication being successful, delivering a second service to the client; wherein the first authentication and the second authentication use different authentication techniques. Other aspects include a programmed data processing apparatus for carrying out the method and a tangible program carrier instructing the apparatus to perform the acts.

Claims (101)

1. A method comprising:

performing following acts on a network server:

receiving a communication from a mobile terminal operated by a client;

performing a first authentication of the mobile terminal and/or the client;

in response to the first authentication being successful, delivering a first service to the client;

after delivering the first service to the client, sending an offer for a second service to the mobile terminal;

receiving an acceptance message for the second service from the mobile terminal;

performing a second authentication of the mobile terminal and/or the client;

in response to receiving the acceptance message for the second service from the mobile terminal and to the second authentication being successful, delivering the second service to the client;

wherein the first authentication and the second authentication use different authentication techniques;

wherein the second authentication comprise:

randomly selecting one of a finite number of telecommunication addresses by which the network server is accessible;

using the randomly selected telecommunication address in an offer message from the network server to the mobile terminal;

authenticating the mobile terminal and/or the client if a reply message to the offer message is received from the mobile terminal at the randomly selected telecommunication address.

2. The method according to claim 1 , wherein the first authentication and the second authentication utilize automatic detection of one or more telecommunication addresses used in communication between the network server and the mobile terminal.

3. The method according to claim 2 , wherein the telecommunication addresses are selected from a list that comprise a terminal identifier in a mobile cellular network, an e-mail address and a social network identity.

4. The method according to claim 1 , wherein the second service comprises setting up an online wallet for the client, and wherein the network server receives instructions to debit the online wallet for future services to the client.

5. The method according to claim 1 , wherein the second service comprises products delivered from one or more vending machines, and wherein the first service comprises a limited number of one or more products delivered from the one or more vending machines.

6. The method according to claim 5 , wherein the limited number is not more than 10.

7. The method according to claim 1 , wherein the second service comprises resources needed for transportation and/or accommodation, and wherein the first service comprises one or more advisory services related to the needed resources.

8. The method according to claim 1 , wherein the second service differs from the first service with respect to one or more of nature, quantity, unit value, method of payment, service provider, time of delivery, method of delivery, and user.

9. A method comprising:

performing following acts on a network server:

receiving a communication from a mobile terminal operated by a client;

performing a first authentication of the mobile terminal and/or the client;

in response to the first authentication being successful, delivering a first service to the client;

after delivering the first service to the client, sending an offer for a second service to the mobile terminal;

receiving an acceptance message for the second service from the mobile terminal;

performing a second authentication of the mobile terminal and/or the client;

in response to receiving the acceptance message for the second service from the mobile terminal and to the second authentication being successful, delivering a second service to the client;

wherein the first authentication and the second authentication use different authentication techniques,

wherein the second service comprises content delivered from an online content repository, and

wherein the content delivered from an online content repository is associated with user interface elements for recommending the delivered content to other users.

10. The method according to claim 9 , wherein the second service differs from the first service with respect to one or more of nature, quantity, unit value, method of payment, service provider, time of delivery, method of delivery, and user.

11. A method comprising:

performing following acts on a network server:

receiving a communication from a mobile terminal operated by a client;

performing a first authentication of the mobile terminal and/or the client;

in response to the first authentication being successful, delivering a first service to the client;

after delivering the first service to the client, sending an offer for a second service to the mobile terminal;

receiving an acceptance message for the second service from the mobile terminal;

performing a second authentication of the mobile terminal and/or the client;

in response to receiving the acceptance message for the second service from the mobile terminal and to the second authentication being successful, delivering a second service to the client;

wherein the first authentication and the second authentication use different authentication techniques, wherein the second service comprises content delivered from an online content repository, and

wherein the content delivered from an online content repository is associated with user interface elements for making a user-selectable donation to a publisher of the delivered content.

12. The method according to claim 11 , wherein the second service differs from the first service with respect to one or more of nature, quantity, unit value, method of payment, service provider, time of delivery, method of delivery, and user.

13. A data processing system comprising:

a memory system that stores program code instructions and data;

a processing system including at least one processing unit, wherein the processing system executes at least a portion of the program code instructions and processes the data;

a set of network interfaces for acting as a node and for communicating with other nodes in one or more telecommunication networks;

wherein the memory system comprises program code instructions executable by the processing system, wherein execution of the program code instructions causes the processing system to:

receive a communication from a mobile terminal operated by a client;

perform a first authentication of the mobile terminal and/or the client;

in response to the first authentication being successful, deliver a first service to the client;

after delivering the first service to the client, send an offer for a second service to the mobile terminal;

receive an acceptance message for the second service from the mobile terminal;

perform a second authentication of the mobile terminal and/or the client;

in response to receiving the acceptance message for the second service from the mobile terminal and to the second authentication being successful, deliver a second service to the client;

wherein the first authentication and the second authentication use different authentication techniques;

wherein the second authentication comprises:

randomly selecting one of a finite number of telecommunication addresses by which the network server is accessible;

using the randomly selected telecommunication address in an offer message from the network server to the mobile terminal;

authenticating the mobile terminal and/or the client if a reply message to the offer message is received from the mobile terminal at the randomly selected telecommunication address.

14. The data processing system according to claim 12 , wherein the first authentication and the second authentication utilize automatic detection of one or more telecommunication addresses used in communication between the network server and the mobile terminal.

15. The data processing system according to claim 14 , wherein the telecommunication addresses are selected from a list that comprise a terminal identifier in a mobile cellular network, an e-mail address and a social network identity.

16. The data processing system according to claim 13 , wherein the second service comprises setting up an online wallet for the client, and wherein the network server receives instructions to debit the online wallet for future services to the client.

17. The data processing system according to claim 13 , wherein the second service comprises products delivered from one or more vending machines, and wherein the first service comprises a limited number of one or more products delivered from the one or more vending machines.

18. The data processing system according to claim 17 , wherein the limited number is not more than 10.

19. The data processing system according to claim 13 , wherein the second service comprises resources needed for transportation and/or accommodation, and wherein the first service comprises one or more advisory services related to the needed resources.

20. The data processing system according to claim 13 , wherein the second service differs from the first service with respect to one or more of nature, quantity, unit value, method of payment, service provider, time of delivery, method of delivery, and user.

21. A data processing system comprising:

a memory system that stores program code instructions and data;

a processing system including at least one processing unit, wherein the processing system executes at least a portion of the program code instructions and processes the data;

a set of network interface for acting as a node and for communicating with other nodes in one or more telecommunication networks;

wherein the memory system comprises program code instructions executable by the processing system, wherein execution of the program code instructions causes the processing system to:

receive a communication from a mobile terminal operated by a client;

perform a first authentication of the mobile terminal and/or the client;

in response to the first authentication being successful, deliver a first service to the client;

after delivering the first service to the client, send an offer for a second service to the mobile terminal;

receive an acceptance message for the second service from the mobile terminal;

perform a second authentication of the mobile terminal and/or the client;

in response to receiving the acceptance message for the second service from the mobile terminal and to the second authentication being successful, deliver a second service to the client;

wherein the first authentication and the second authentication use different authentication techniques; and

wherein the content delivered from an online content repository is associated with user interface elements for recommending the delivered content to other users.

22. The data processing system according to claim 21 , wherein the second service differs from the first service with respect to one or more of nature, quantity, unit value, method of payment, service provider, time of delivery, method of delivery, and user.

23. A data processing system comprising:

a memory system that stores program code instructions and data;

a processing system including at least one processing unit, wherein the processing system executes at least a portion of the program code instructions and processes the data;

a set of network interfaces for acting as a node and for communicating with other nodes in one or more telecommunication networks;

wherein the memory system comprises program code instructions executable by the processing system, wherein execution of the program code instructions causes the processing system to:

receive a communication from a mobile terminal operated by a client;

perform a first authentication of the mobile terminal and/or the client;

in response to the first authentication being successful, deliver a first service to the client;

after delivering the first service to the client, send an offer for a second service to the mobile terminal;

receive an acceptance message for the second service from the mobile terminal;

perform a second authentication of the mobile terminal and/or the client;

in response to receiving the acceptance message for the second service from the mobile terminal and to the second authentication being successful, deliver a second service to the client;

wherein the first authentication and the second authentication use different authentication techniques wherein the second service comprises content delivered from an online content repository; and

wherein the content delivered from an online content repository is associated with user interface elements for making a user-selectable donation to a publisher of the delivered content.

24. The data processing system according to claim 23 , wherein the second service differs from the first service with respect to one or more of nature, quantity, unit value, method of payment, service provider, time of delivery, method of delivery, and user.

25. A non-transitory computer program embodying computer program instructions for instructing an electronic data processing system acting as a network server to carry out the acts recited in claim 1 .

Assignments (13)
CHANGE OF NAME Recorded Jan 14, 2022
From: BOOKIT OY; BOOKIT AJANVARAUSPALVELU
To: SMARTCOM LABS OY
Reel/Frame 058736/0054 →
SECURITY INTEREST Recorded May 6, 2020
From: BOOKIT OY
To: BKI INVERS AB
Reel/Frame 052585/0723 →
SECURITY INTEREST Recorded May 6, 2020
From: BOOKIT OY
To: AUTERE, JUSSI
Reel/Frame 052585/0498 →
SECURITY INTEREST Recorded May 6, 2020
From: BOOKIT OY
To: MPJ YHTYMA OY
Reel/Frame 052587/0814 →
SECURITY INTEREST Recorded May 5, 2020
From: BOOKIT OY
To: RANIN, URSULA; ENTRADA OY
Reel/Frame 052581/0396 →
SECURITY INTEREST Recorded May 5, 2020
From: BOOKIT OY
To: RONNHOLM, RIKU; RAHNASTO, ILKKA
Reel/Frame 052579/0001 →
SECURITY INTEREST Recorded May 5, 2020
From: BOOKIT OY
To: PITKANEN, OLLI
Reel/Frame 052579/0136 →
SECURITY INTEREST Recorded Apr 16, 2020
From: BOOKIT OY
To: DUCK POND INVESTMENTS; GODFREY, PETER
Reel/Frame 052425/0192 →
SECURITY INTEREST Recorded Apr 16, 2020
From: BOOKIT OY
To: LOSMAA, MARITTTI
Reel/Frame 052426/0037 →
SECURITY INTEREST Recorded Apr 16, 2020
From: BOOKIT OY
To: KALONIENI, MARKKU
Reel/Frame 052535/0634 →
SECURITY INTEREST Recorded Apr 15, 2020
From: BOOKIT OY
To: DUCK POND INVESTMENTS; GODFREY, PETER
Reel/Frame 052410/0189 →
CHANGE OF NAME Recorded Jan 12, 2019
From: BOOKIT OY AJANVARAUSPALVELU
To: BOOKIT OY
Reel/Frame 049368/0480 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2014
From: SALONEN, JUKKA
To: BOOKIT OY AJANVARAUSPALVELU
Reel/Frame 032705/0800 →