System and Method for Mobile or Web-Based Payment/Credential Process
The present disclosure describes systems and methods directed towards a highly secure and intelligent, end to end provisioning, authentication, and transaction system which creates and/or consolidates user data for a unified profile for the user (e.g., a person, place, organization, object, etc.) to allow for the safe, secure, and verifiable exchange of information.
1 . A method comprising:
receiving credential data at a web server hosting a website, the credential data including a user identifier and a password of a user;
transmitting, from the web server to an authentication server, the credential data, a payment source identifier, a third party identifier of an entity, a web portal identifier associated with the website, and a transaction type identifier corresponding to a requested transaction type;
at the authentication server, authenticating the password and the web portal identifier based on the user identifier and the third party identifier;
transmitting a confirmation request from the authentication server to a device used by the user;
receiving a confirmation message from the user; and
performing a transaction corresponding to the requested transaction type for the user using a payment source corresponding to the payment source identifier.
2 . The method of claim 1 , further comprising:
transmitting a transaction identifier from the web server to the authentication server; and
authenticating the transaction identifier at the authentication server.
3 . The method of claim 1 , wherein the confirmation message includes a personal identification code of the user, the method further including authenticating the personal identification code at the authentication server.
4 . The method of claim 1 , wherein the user is prompted to enter the personal identification code responsive to a determination that a transaction amount for the requested transaction exceeds a predetermined threshold.
5 . The method of claim 1 , wherein the user is prompted to enter the personal identification code responsive to a determination that the device is currently in one of a predetermined set of locations.
6 . The method of claim 1 , further comprising:
transmitting an electronic message from the authentication server to an entity computer of an entity, wherein the electronic message includes a request for data;
at the authentication server, receiving the requested data from the entity computer;
wherein the transaction is performed for the user based on the received data.
7 . The method of claim 1 , further comprising:
transmitting an electronic message from the authentication server to an entity computer of the entity, wherein the electronic message includes a request for authorization of the requested transaction;
at the authentication server, receiving an electronic authorization from the entity computer;
wherein the transaction is performed for the user responsive to the received authorization from the entity computer.
8 . The method of claim 1 , further comprising:
transmitting an electronic message from the authentication server to an entity computer of the entity, wherein the electronic message includes updated transaction data for storage at the entity computer.
9 . The method of claim 1 , further comprising:
transmitting a first electronic message from the authentication server to an entity computer of the entity, wherein the first electronic message includes a notification of the requested transaction;
at the authentication server, receiving a second electronic message from the entity computer, wherein the second electronic message includes update data; and
transmitting the update data to the device used by the user.
10 . A method comprising:
receiving credential data at an application executing on a mobile device of a user, the credential data including a user identifier and a password of the user;
transmitting, from the mobile device to an authentication server, the credential data, a payment source identifier, a third party identifier of an entity, a device identifier associated with the device, and a transaction type identifier corresponding to a requested transaction type;
at the authentication server, authenticating the password and the device identifier based on the user identifier and the third party identifier;
transmitting a confirmation request from the authentication server to the mobile device;
receiving a confirmation from the user; and
performing a transaction for the user corresponding to the requested transaction type.
11 . The method of claim 10 , further comprising:
transmitting a transaction identifier from the mobile device to the authentication server; and
authenticating the transaction identifier at the authentication server.
12 . The method of claim 10 , wherein the confirmation message includes a personal identification code of the user, the method further including authenticating the personal identification code at the authentication server.
13 . The method of claim 10 , wherein the user is prompted to enter the personal identification code responsive to a determination that a transaction amount for the requested transaction exceeds a predetermined threshold.
14 . The method of claim 10 , wherein the user is prompted to enter the personal identification code responsive to a determination that the device is currently in one of a predetermined set of locations.
15 . The method of claim 10 , further comprising:
transmitting an electronic message from the authentication server to an entity computer of an entity, wherein the electronic message includes a request for data;
at the authentication server, receiving the requested data from the entity computer;
wherein the transaction is performed for the user based on the received data.
16 . The method of claim 10 , further comprising:
transmitting an electronic message from the authentication server to an entity computer of an entity, wherein the electronic message includes a request for authorization of the requested transaction;
at the authentication server, receiving an electronic authorization from the entity computer;
wherein the transaction is performed for the user responsive to the received authorization from the entity computer.
17 . The method of claim 10 , further comprising:
transmitting an electronic message from the authentication server to an entity computer of an entity, wherein the electronic message includes updated transaction data for storage at the entity computer.
18 . The method of claim 10 , further comprising:
transmitting a first electronic message from the authentication server to an entity computer of an entity, wherein the first electronic message includes a notification of the requested transaction;
at the authentication server, receiving a second electronic message from the entity computer, wherein the second electronic message includes update data; and
transmitting the update data to the mobile device.
19 . A method comprising:
receiving, at an authentication server, a user identifier, a password of a user, a payment source identifier, a third party identifier of an entity, a login source identifier, and a transaction type identifier corresponding to a requested transaction type;
authenticating the password and the login source identifier based on the user identifier and the third party identifier;
transmitting a confirmation request from the authentication server to a device used by the user;
receiving from the user a confirmation message including a personal identification code;
authenticating the personal identification code at the authentication server; and
performing a transaction corresponding to the requested transaction type for the user using a payment source corresponding to the payment source identifier.
20 . The method of claim 19 , further comprising:
receiving the user identifier and the password at a web server hosting a website; and
transmitting the user identifier and the password from the web server to the authentication server;
wherein the login source identifier is associated with the website.
21 . The method of claim 19 , wherein the device used by the user is a mobile device, the method further comprising:
receiving the user identifier and the password at an application executing on the mobile device; and
transmitting the user identifier and the password from the mobile device to the authentication server;
wherein the login source identifier is associated with the mobile device.