IP Library Patent Application 15204400
Patent Application
App. No. 15/204,400

DIGITAL SIGNATURE AUTHENTICATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/204,400
Abstract

A systems and methods for authenticating a consumer with a transaction card using digital signatures according to one embodiment of the invention is disclosed. These systems and methods allow consumers to digitally sign transaction information with a private key. The private key may be used to digitally sign the transaction, for example, through a hosted or local system that protects the integrity of the private key. A financial institution may authenticate the consumer by decrypting the digital signature with a public key.

Claims (51)

1 . A method for authenticating an electronic transaction between a consumer and a merchant, wherein the method occurs at a consumer's computer and comprises:

enrolling a debit card for digital signature authentication at a financial institution;

initiating a transaction between the consumer and the merchant over the Internet;

selecting a payment scheme that includes payment using the debit card;

receiving a request for a digital signature from the merchant, wherein the request includes transaction information;

receiving an authentication scheme from the merchant;

accessing the authentication scheme;

gaining access to a private key as determined by the authentication scheme;

creating a digital signature by encrypting the transaction information with the private key; and

sending the digital signature to the merchant.

2 . The method according to claim 1 , wherein the financial institution is selected from the group consisting of an issuer authentication server (IAS) and a cardholder account directory service (CADS).

3 . The method according to claim 1 , wherein the authentication scheme is a URL that points to a plug-in residing on the consumer's computer system, wherein the plug-in provides access to the private key.

4 . The method according to claim 3 , wherein the plug-in is operable to open local software on the consumer's computer that performs encryption using the private key.

5 . The method according to claim 3 , wherein the plug-in is operable to interact with a device selected from the group consisting of a biometric scanner and a smartcard reader.

6 . The method according to claim 1 , wherein the authentication scheme is a URL pointing to a webpage hosted by the IAS, wherein the webpage provides access to the private key.

7 . The method according to claim 1 , wherein encrypting transaction information comprises encrypting the transaction information using an encryption scheme selected from the group consisting of RSA encryption, the digital signature algorithm, Schnorr signature, Pointcheval-Stern signature algorithm, the Rabin signature algorithm, any of the SHA algorithms, the undeniable signature algorithm, ECDSA, DSA, the ECC algorithm, elliptical curve techniques, Paillier cryptosystem, the EIGamal algorithm, and the Diffie-Hellman key exchange.

8 . The method according to claim 1 , wherein the consumer gains access to a private key through the authentication scheme.

9 . The method according to claim 1 , wherein the authentication scheme includes requiring the consumer to enter information selected from the group consisting of an answer to a question, a biometric sample, and a PC scan.

10 . The method according to claim 1 , wherein the transaction information comprises information selected from the group consisting of transaction currency code, transaction amount, transaction ID, transaction reference number, transaction time, transaction ship data, account number, consumer name, and merchant name.

11 . The method according to claim 1 , wherein:

initiating a transaction between the consumer and the merchant over the Internet comprises sending information associated with an account corresponding to the debit card and the account information does not include a passcode or a personal identification number (PIN) for the account;

the authentication scheme comprises a hosted or a local digital signature service; and

the digital signature does not include a passcode or personal identification number (PIN) for the account.

12 . The method according to claim 11 , further comprising receiving a receipt URL from the financial institution.

13 . The method according to claim 11 , wherein the received account information includes a primary account number (PAN) of the debit card.

14 . The method according to claim 4 , wherein the URL sent to the consumer's computer as part of the authentication scheme is configured to automatically direct the consumer's web browser to the URL where the plug-in may be launched.

15 . The method according to claim 14 , wherein the plug-in is configured to interface with a smartcard reader or biometric detector.

16 . A system for authenticating an electronic transaction between a consumer and a merchant, wherein the system comprises:

a merchant system connected to the Internet and accessible by a consumer;

a merchant processor adapted to process transactions for the merchant, wherein the merchant processor is in communication with the merchant;

an issuing authentication server (IAS) adapted to host an Internet based authentication scheme for the consumer with enrolled debit cards;

a cardholder account directory service (CADS), wherein the CADS is adapted to provide enrollment information regarding debit cards; and

a financial network, wherein the financial network is adapted to provide communication between the merchant processor, the IAS and the CADS;

wherein:

the merchant receives a request from a consumer to use a debit card for a transaction between the consumer and the merchant;

the merchant requests enrollment information for the debit card used by the consumer from the CADS through the merchant processor;

if the debit card is enrolled, the CADS requests from the IAS a URL pointing to an Internet based authentication scheme for the debit card; and

the URL pointing to an Internet based authentication scheme is sent to the consumer for authentication of the debit card for the transaction.

17 . The system according to claim 16 , wherein enrollment information comprises information selected from the group consisting of debit card account number and authentication scheme.

18 . The system according to claim 16 , wherein the financial network comprises an EFT network.

19 . The system according to claim 16 , wherein the merchant does not receive a passcode or a personal information number (PIN) for an account associated with the debit card.

20 . A system for authenticating an electronic transaction between a consumer and a merchant, wherein the system comprises a computer-readable medium comprising a plurality of instructions that when executed control a processor to:

receive account information associated with a debit card account from the consumer over the Internet, wherein the consumer accesses the Internet using a consumer's computer, and the account information does not include a passcode or a personal identification number (PIN) for the debit card account;

confirm enrollment of the debit card account for digital signature authentication from a financial institution;

receive consumer specific authentication parameters from the financial institution, wherein the consumer specific authentication parameters comprises an authentication scheme comprising a hosted or a local digital signature service;

send transaction information over the Internet to the consumer's computer for a digital signature;

send the authentication scheme over the Internet to the consumer's computer;

receive a digital signature from the consumer's computer over the Internet, wherein the digital signature does not include a passcode or personal identification number (PIN) for the debit card account, and the digital signature comprises encrypted portions of the transaction information;

send the transaction information and the digital signature comprising encrypted portions of the transaction information to the financial institution;

receive payment authorization from the financial institution; and

send a receipt URL to the financial institution, the receipt URL later sent to the consumer by the financial institution.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION
Reel/Frame 050094/0650 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION
Reel/Frame 050094/0687 →
SECURITY INTEREST Recorded Nov 30, 2016
From: FIRST DATA CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 040471/0246 →
SECURITY INTEREST Recorded Nov 30, 2016
From: FIRST DATA CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 040471/0334 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2016
From: LOOMIS, NANCY; SAVILLE, JULIE
To: FIRST DATA CORPORATION
Reel/Frame 039103/0341 →