IP Library Granted Patent US 9,215,331
Granted Patent B2
US 9,215,331 · App. 12/572,321 · Granted Dec 15, 2015

Dual layer authentication for electronic payment request in online transactions

Inventors: Barbara Febonio (Rome, IT); Sandro Piccinini (Campano, IT)
Assignee: International Business Machines Corporation
H04M15/00G06Q20/105G06Q20/12G06Q20/327G06Q20/40G06Q20/425G06Q30/0603H04M15/47H04M15/48H04M15/8005H04M15/85H04M15/851H04M15/858H04M17/00H04W4/24H04M2215/0148H04M2215/0156H04M2215/815H04M2215/8183
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,215,331
App. No.
12/572,321
Granted
Dec 15, 2015
Kind
B2
Abstract

Increasing the security of online payment requests by introducing a dual-layer authentication system for accessing the funds and/or credit through payment cards is described. An additional check regarding the identity of a card user to be included within a traditional security protocols for these cards, wherein the additional check is based on an authentication channel which is external to the user's card. A device owned by the legitimate card owner certifies that the user of the card at any given instant is the legitimate owner of the card and not someone else. To process this additional information, a connection by means of a proximity based device is established.

Claims (38)

1. A method for an additional authorization of an electronic payment information, the method comprising:

a computer configuring a payment card with information associated with at least one device wherein the information includes one or more uniform resource locator (URL) addresses designated as a friend URL for which the additional authorization is not required, a price threshold requiring the additional authorization, and a type of object threshold requiring the additional authorization;

the computer receiving the electronic payment information from the payment card at a browser running on the computer, wherein the browser requires the additional authorization for the payment card in addition to a main authorization process when a uniform resource locator address associated with the browser has not been designated as the friend URL, and one of the price threshold and the type of object threshold has been met;

the computer, responsive to determining that the uniform resource locator address associated with the browser has not been designated as the friend URL, and one of the price threshold and the type of object threshold has been met, suspending the main authorization process;

the computer, responsive to suspending the main authorization process, establishing a connection with a cell phone of the user;

the computer, responsive to establishing the connection with the cell phone of the user, retrieving an additional information associated with the electronic payment information, wherein the additional information is an identifier associated with both the cell phone and the payment card, and wherein the additional information includes one of the type of object threshold and the threshold of expense;

the computer, responsive to receiving the additional information, using the additional information to complete the additional authorization process; and

the computer, responsive to completing the additional authorization process, completing the main authorization process.

2. The method of claim 1 further including:

refusing the additional authorization in the event the additional authorization process is unsuccessful;

notifying an owner of the card of an unsuccessful additional authorization using personal information of the user and an external device of the user to advise the user of an authentication failure, thereby providing substantially instantaneous warning to the user of a potential breach in a security of the user.

3. The method of claim 1 further including:

refusing the additional authorization in the event the computer does not connect with the cell phone;

notifying an owner of the card of the failed connection.

4. A computer program product for performing an additional authorization of an electronic payment information, the computer program product comprising:

one or more non-transitory computer readable mediums;

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for configuring a payment card with information associated with at least one device wherein the information includes one or more uniform resource locator (URL) addresses designated as a friend URL for which the additional authorization is not required, a price threshold requiring the additional authorization, and a type of object threshold requiring the additional authorization;

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for receiving the electronic payment information from a payment card at a browser running on the computer, wherein the browser requires the secondary authorization for the payment card in addition to the main authorization process when a uniform resource locator address associated with the browser has not been designated as the friend URL, and one of the price threshold and the type of object threshold has been met;

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for, responsive to receiving the electronic payment information, establishing a connection with a cell phone of the user;

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for, responsive to determining that the uniform resource locator address associated with the browser has not been designated as the friend URL, and one of the price threshold and the type of object threshold has been met, suspending the main authorization process;

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for, responsive to suspending the main authorization process, establishing the connection with the cell phone of the user;

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for, responsive to establishing the connection with the cell phone of the user, retrieving the additional information, wherein the additional information is an identifier associated with both the payment card and the cell phone, and wherein the additional information includes a type of object and a threshold of expense;

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for, responsive to receiving the additional information, using the additional information to complete the additional authorization process; and

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for, responsive to completing the additional authorization process, completing the main authorization process.

5. A computer program product of claim 4 , further comprising:

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for refusing the additional authorization in the event the additional authorization process is unsuccessful; and

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for notifying the an owner of the card of an unsuccessful additional authorization using personal information of the user and an external device of the user to advise the user of an authentication failure, thereby providing substantially instantaneous warning to the user of a potential breach in a security of the user.

6. The computer program product of claim 4 , further comprising:

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for refusing the authorization in the event the computer does not connect with the cell phone; and

computer program instructions stored in at least one of the one or more non-transitory computer readable mediums for notifying an owner of the card of a failed detection.

7. A system for providing an additional authorization of an electronic payment information, the system comprising a data processor coupled to a memory having instructions stored therein that are configured to perform the steps of:

configuring a payment card with information associated with at least one device wherein the information includes one or more uniform resource locator (URL) addresses designated as a friend URL for which the additional authorization is not required, a price threshold requiring the additional authorization, and a type of object threshold requiring the additional authorization;

receiving the electronic payment information from the payment card at a browser running on the computer, wherein the browser requires the additional authorization for the payment card in addition to a main authorization process when a uniform resource locator address associated with the browser has not been designated as the friend URL, and one of the price threshold and the type of object threshold has been met;

responsive to determining that the uniform resource locator address associated with the browser has not been designated as the friend URL, and one of the price threshold and the type of object threshold has been met, suspending the main authorization process;

responsive to suspending the main authorization process, establishing a connection with a cell phone of the user;

responsive to establishing the connection with the cell phone of the user, retrieving an additional information associated with the electronic payment information, wherein the additional information is an identifier associated with both the cell phone and the payment card, and wherein the additional information includes one of the type of object threshold and the threshold of expense;

responsive to receiving the additional information, using the additional information to complete the additional authorization process; and

responsive to completing the additional authorization process, completing the main authorization process.

Assignments (5)
SECURITY INTEREST Recorded Mar 28, 2025
From: AVALARA, INC.; EDISON VAULT, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 070671/0097 →
RELEASE OF SECURITY INTEREST Recorded Mar 28, 2025
From: BLUE OWL CREDIT INCOME CORP (F/K/A OWL ROCK CORE INCOME CORP.), AS COLLATERAL AGENT
To: AVALARA, INC.; EDISON VAULT, LLC
Reel/Frame 070671/0486 →
SECURITY INTEREST Recorded Oct 20, 2022
From: AVALARA, INC.; EDISON VAULT, LLC
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 061728/0201 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: EDISON VAULT, LLC
Reel/Frame 057059/0956 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2009
From: FEBONIO, BARBARA; PICCININI, SANDRO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 023317/0462 →
Priority Claims (1)
EP 08165705 · Oct 2, 2008 · regional
Continuity (1)
Related Publication 20100088228A1 · Apr 8, 2010