US2005044385A1PendingUtilityA1
Systems and methods for secure authentication of electronic transactions
Priority: Sep 9, 2002Filed: Jan 7, 2003Published: Feb 24, 2005
Est. expirySep 9, 2022(expired)· nominal 20-yr term from priority
Inventors:John Holdsworth
H04L 9/0869H04L 2209/56G06Q 20/382G06Q 20/40975G06F 21/36G06Q 20/367G06Q 20/108G06F 2221/2117G06Q 20/3821H04L 9/3231G07F 7/1025G07F 7/1016G06Q 20/3672H04L 9/3213G06Q 20/341G07F 7/1008G06Q 20/3674G06F 21/34H04L 9/3271G06Q 20/40
43
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
An online transaction system configured to implement authentication methods that allow for strong multi-factor authentication in online environments. The authentication methods can be combined with strong security methods to further ensure that the authentication process is secure. Further, the strong multi-factor authentication can be implemented with zero adoption dependencies through the implementation of automated enrollment methods.
Claims
exact text as granted — not AI-modified1 . A method for secure authentication, comprising:
receiving an authentication request message at a terminal from an authentication authority; prompting a user to interface a token with the terminal; extracting unique information from the token once it is interfaced with the terminal; prompting the user for a personal identifier; and generating a response to the authentication request message based on the personal identifier and the unique information.
2 . The method of claim 1 , further comprising generating a transactionally unique session key, using the transactionally unique session key to encrypt the response, and transmitting the encrypted response to the authentication authority.
3 . The method of claim 1 , wherein the personal identifier is linked with an account associated with the token.
4 . The method of claim 1 , wherein the unique information comprises a unique serial number.
5 . The method of claim 1 , wherein the unique information comprises a message key.
6 . The method of claim 1 , wherein the unique information comprises random data.
7 . The method of claim 1 , wherein the unique information comprises a network address associated with the authentication authority.
8 . The method of claim 1 , further comprising generating a time stamp and generating the response based on the time stamp.
9 . The method of claim 1 , wherein the authentication request message is encrypted, and wherein the method further comprises decrypting the received authentication request message.
10 . The method of claim 1 , further comprising synchronizing a time associated with the response based at least in part on time information included in the authentication request message.
11 . A method for secure authentication, comprising:
receiving an authentication request comprising transactional information; generating an authentication request message in response to the authentication request; transmitting the authentication request message to a terminal; and receiving a response to the authentication request message from the terminal that is encrypted using a transactionally unique session key.
12 . The method of claim 11 , wherein generating the authentication request message comprises encrypting the authentication request message.
13 . The method of claim 12 , wherein encrypting the authentication message comprises generating a random number.
14 . The method of claim 12 , wherein encrypting the authentication message comprises generating a time stamp.
15 . The method of claim 12 , wherein encrypting the authentication message comprises generating an electronic signature.
16 . The method of claim 12 , wherein encrypting the authentication message comprises retrieving a message key.
17 . The method of claim 11 , further comprising decrypting the received response using the transactionally unique session key.
18 . A terminal configured for secure authentication, the termianl comprising client software configured to allow the terminal to:
receive an authentication request message from an authentication authority; prompt a user to interface a token with the terminal; extract unique information from the token once it is interfaced with the terminal; prompt the user for a personal identifier; and generate a response to the authentication request message based on the personal identifier and the unique information.
19 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to generate a transactionally unique session key, use the transactionally unique session key to encrypt the response, and transmit the encrypted response to the authentication authority.
20 . The terminal of claim 18 , wherein the personal identifier is linked with an account associated with the token.
21 . The terminal of claim 18 , wherein the unique information comprises a unique serial number.
22 . The terminal of claim 18 , wherein the unique information comprises a message key.
23 . The terminal of claim 18 , wherein the unique information comprises random data.
23 . The terminal of claim 18 , wherein the unique information comprises a network address associated with the authentication authority.
24 . The terminal of claim 23 , wherein the client software is further configured to access the network address and automatically connect with the authentication authority.
25 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to generate a time stamp and generate the response based on the time stamp.
26 . The terminal of claim 18 , wherein the authentication request message is encrypted, and wherein the client software is further configured to allow the terminal to decrypt the received authentication request message.
27 . The terminal of claim 18 , wherein the client software is further configured to allow the terminal to associated a time with the response based at least in part on time information included in the authentication request message.Join the waitlist — get patent alerts
Track US2005044385A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.