ONLINE AUTHORIZATION SYSTEM
A computer-implemented technique may secure an online transaction by reading embedded identification information from a machine-readable government-issued official identification document at a user device. The user device may generate control characters and an encryption key based on transformation rules applied to at least a portion of the embedded identification information, and may encrypt transaction details to form an encrypted transaction packet. The user device may transmit the encrypted transaction packet, unencrypted account identification information, and the control characters to an online organization for forwarding to a financial institution associated with the unencrypted account identification information. The financial institution may reproduce the transformation rules from the control characters using a rule generating algorithm, reconstruct a decryption key based on stored account holder identification information, decrypt the encrypted transaction packet, determine whether decrypted identification information matches the stored account holder identification information, and transmit an approval or rejection.
1 . A computer-implemented method for securing an online transaction, comprising:
reading, by a user device, embedded identification information from a machine-readable government-issued official identification document;
generating, by the user device, control characters for selecting or generating transformation rules for a dynamic key;
generating, by the user device, an encryption key by transforming at least a portion of the embedded identification information in accordance with the transformation rules;
encrypting, by the user device, transaction details and at least a portion of the embedded identification information using the encryption key to form an encrypted transaction packet;
transmitting, by the user device to an online organization, the encrypted transaction packet, unencrypted account identification information, and the control characters;
forwarding, by the online organization, the encrypted transaction packet, the unencrypted account identification information, and the control characters to a financial institution associated with the unencrypted account identification information;
reproducing, by the financial institution, the transformation rules based on the control characters and a rule generating algorithm;
reconstructing, by the financial institution, a decryption key based on account holder identification information stored by the financial institution for an account identified by the unencrypted account identification information and based on the transformation rules;
decrypting, by the financial institution, the encrypted transaction packet using the decryption key;
determining, by the financial institution, whether the embedded identification information obtained from the decrypted encrypted transaction packet matches the account holder identification information stored by the financial institution; and
transmitting an approval or rejection of the online transaction to the online organization, based on at least the determining.
2 . The computer-implemented method of claim 1 , wherein the machine-readable government-issued identification document comprises a driver's license, passport, or national identification card having embedded identification information encoded in a magnetic stripe, barcode, RFID chip, or smart card chip.
3 . The computer-implemented method of claim 1 , wherein the embedded identification information comprises at least one of: a name, date of birth, government-assigned identification number, photograph data, biometric data, address, or document issuance information.
4 . The computer-implemented method of claim 1 , wherein generating the control characters comprises randomly producing the control characters as an input to the rule generating algorithm to generate the transformation rules.
5 . The computer-implemented method of claim 1 , wherein generating the control characters comprises generating a random number and transmitting the random number as at least a portion of the control characters.
6 . The computer-implemented method of claim 1 , wherein the financial institution transmits the approval or the rejection based on whether a status of the account permits the online transaction.
7 . The computer-implemented method of claim 1 , wherein determining whether the embedded identification information matches the account holder identification information comprises comparing at least one of a name, a date of birth, an identification number, or an address.
8 . The computer-implemented method of claim 1 , wherein reproducing the transformation rules comprises applying the rule generating algorithm to the control characters to generate a set of transformation rules corresponding to the control characters.
9 . The computer-implemented method of claim 1 , wherein the user device comprises a cell phone, personal digital assistant, or personal computer.
10 . The computer-implemented method of claim 1 , further comprising receiving, by the user device, user-entered information comprising at least one of a password, a personal identification number, or a social security number, wherein generating the encryption key is further based on at least a portion of the user-entered information.
11 . A system comprising:
a user device;
an online organization system; and
a financial institution system;
wherein the user device is configured to read embedded identification information from a machine-readable government-issued official identification document, generate control characters for selecting or generating transformation rules for a dynamic key, generate an encryption key by transforming at least a portion of the embedded identification information in accordance with the transformation rules, encrypt transaction details and at least a portion of the embedded identification information using the encryption key to form an encrypted transaction packet, and transmit the encrypted transaction packet, unencrypted account identification information, and the control characters to the online organization system;
wherein the online organization system is configured to forward the encrypted transaction packet, the unencrypted account identification information, and the control characters to the financial institution system associated with the unencrypted account identification information; and
wherein the financial institution system is configured to reproduce the transformation rules based on the control characters and a rule generating algorithm, reconstruct a decryption key based on account holder identification information stored for an account identified by the unencrypted account identification information and based on the transformation rules, decrypt the encrypted transaction packet using the decryption key, determine whether embedded identification information obtained from the decrypted encrypted transaction packet matches the account holder identification information, and transmit an approval or rejection of the online transaction to the online organization system based on at least the determination.
12 . The system of claim 11 , wherein the machine-readable government-issued identification document comprises a driver's license, passport, or national identification card having embedded identification information encoded in a magnetic stripe, barcode, RFID chip, or smart card chip.
13 . The system of claim 11 , wherein the embedded identification information comprises at least one of: a name, date of birth, government-assigned identification number, photograph data, biometric data, address, or document issuance information.
14 . The system of claim 11 , wherein generating the control characters comprises randomly producing the control characters as an input to the rule generating algorithm to generate the transformation rules.
15 . The system of claim 11 , wherein generating the control characters comprises generating a random number and transmitting the random number as at least a portion of the control characters.
16 . The system of claim 11 , wherein the financial institution system is configured to transmit an approval or rejection based on whether a status of an account permits the online transaction.
17 . The system of claim 11 , wherein the financial institution system is configured to determine whether the embedded identification information matches account holder identification information by comparing at least one of a name, a date of birth, an identification number, or an address.
18 . The system of claim 11 , wherein reproducing the transformation rules comprises applying the rule generating algorithm to the control characters to generate a set of transformation rules corresponding to the control characters.
19 . The system of claim 11 , wherein the user device comprises a cell phone, personal digital assistant, or personal computer.
20 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause a system to:
read, by a user device, embedded identification information from a machine-readable government-issued official identification document;
generate, by the user device, control characters for selecting or generating transformation rules for a dynamic key;
generate, by the user device, an encryption key by transforming at least a portion of the embedded identification information in accordance with the transformation rules;
encrypt, by the user device, transaction details and at least a portion of the embedded identification information using the encryption key to form an encrypted transaction packet;
transmit, by the user device to an online organization system, the encrypted transaction packet, unencrypted account identification information, and the control characters;
forward, by the online organization system, the encrypted transaction packet, the unencrypted account identification information, and the control characters to a financial institution system associated with the unencrypted account identification information; reproduce, by the financial institution system, the transformation rules based on the control characters and a rule generating algorithm;
reconstruct, by the financial institution system, a decryption key based on account holder identification information stored for an account identified by the unencrypted account identification information and based on the transformation rules;
decrypt, by the financial institution system, the encrypted transaction packet using the decryption key;
determine, by the financial institution system, whether embedded identification information obtained from the decrypted encrypted transaction packet matches the account holder identification information; and
transmit, by the financial institution system, an approval or rejection of the online transaction to the online organization system based on at least the determination.