Method and apparatus for secure electronic commerce
Abstract
One embodiment of the present invention provides a system that facilitates secure electronic commerce. The system operates by first providing a consumer with a file of security data relating to an account maintained by a financial institution. The consumer then creates a financial transaction with a merchant using security data from the file to protect the financial transaction. This financial transaction is structured to prevent the merchant from knowing the account number for the account. Next, the merchant validates that the financial institution identified by the financial transaction is acceptable using security data from the file. The merchant then requests that the financial institution authorize the financial transaction. Upon receiving authorization to complete the financial transaction, the merchant completes the financial transaction. Finally, the merchant notifies the financial institution that the financial transaction is complete.
Claims
exact text as granted — not AI-modified1 - 24 . (canceled)
25 . A method that facilitates an electronic transaction between a consumer and a merchant without allowing the merchant to know an account number belonging to the consumer, comprising:
sending a receipt for a transaction in electronic form from a merchant to a consumer; receiving a secure digital envelope from the consumer, the consumer having formed the secure digital envelope by encrypting information associated with the receipt and the account number using a public key of a financial institution; and sending the secure digital envelope along with information associated with the receipt to the financial institution, thereby enabling the financial institution to process the transaction without allowing the merchant to know an account number.
26 . The method of claim 25 ,
wherein the consumer forms the digital envelope by,
generating a first hash of the receipt, and
encrypting the receipt, the first hash, and the account number using the public key of the financial institution; and
wherein the merchant sends the secure digital envelope to the financial institution by,
generating a second hash of the receipt; and
sending the secure digital envelope along with the second hash to the financial institution.
27 . The method of claim 26 , wherein the method further comprises processing the transaction at the financial institution by:
using a private key belonging to the financial institution to decrypt the secure digital envelope to obtain the receipt, the first hash, and the account number; and comparing the first hash with the second hash to validate the transaction.
28 . The method of claim 27 , wherein if the second hash matches the first hash, the method further comprises:
authorizing the transaction; and notifying the merchant that the transaction is valid.
29 . The method of claim 25 , wherein the consumer forms the secure digital envelope in a smart card.
30 . The method of claim 29 , wherein the smart card contains:
an identifier for the consumer; an identifier for the financial institution; a private key for the consumer; the public key for the financial institution; the account number; and encryption mechanisms.
31 . The method of claim 25 , wherein prior to sending the receipt from the merchant to the consumer, the method further comprises validating that the consumer has an account with the financial institution by:
receiving a digital certificate belonging to the financial institution from the consumer; determining if the digital certificate of the financial institution is valid by validating that the digital certificate is signed by a recognized certificate authority; if so, transmitting the consumer identifier and the consumer certificate to the financial institution to validate if the consumer has an account with the financial institution; and receiving a validation message from the financial institution if the consumer has an account with the financial institution.
32 . A computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method that facilitates an electronic transaction between a consumer and a merchant without allowing the merchant to know an account number belonging to the consumer, the method comprising:
sending a receipt for a transaction in electronic form from a merchant to a consumer; receiving a secure digital envelope from the consumer, the consumer having formed the secure digital envelope by encrypting information associated with the receipt and the account number using a public key of a financial institution; and sending the secure digital envelope along with information associated with the receipt to the financial institution, thereby enabling the financial institution to process the transaction without allowing the merchant to know an account number.
33 . The computer-readable storage medium of claim 32 ,
wherein the consumer forms the digital envelope by,
generating a first hash of the receipt, and
encrypting the receipt, the first hash, and the account number using the public key of the financial institution; and
wherein the merchant sends the secure digital envelope to the financial institution by,
generating a second hash of the receipt; and
sending the secure digital envelope along with the second hash to the financial institution.
34 . The computer-readable storage medium of claim 33 , wherein the method further comprises processing the transaction at the financial institution by:
using a private key belonging to the financial institution to decrypt the secure digital envelope to obtain the receipt, the first hash, and the account number; and comparing the first hash with the second hash to validate the transaction.
35 . The computer-readable storage medium of claim 34 , wherein if the second hash matches the first hash, the method further comprises:
authorizing the transaction; and notifying the merchant that the transaction is valid.
36 . The computer-readable storage medium of claim 32 , wherein the consumer forms the secure digital envelope in a smart card.
37 . The computer-readable storage medium of claim 36 , wherein the smart card contains:
an identifier for the consumer; an identifier for the financial institution; a private key for the consumer; the public key for the financial institution; the account number; and encryption mechanisms.
38 . The computer-readable storage medium of claim 32 , wherein prior to sending the receipt from the merchant to the consumer, the method further comprises validating that the consumer has an account with the financial institution by:
receiving a digital certificate belonging to the financial institution from the consumer; determining if the digital certificate of the financial institution is valid by validating that the digital certificate is signed by a recognized certificate authority; if so, transmitting the consumer identifier and the consumer certificate to the financial institution to validate if the consumer has an account with the financial institution; and receiving a validation message from the financial institution if the consumer has an account with the financial institution.
39 . An apparatus that facilitates an electronic transaction between a consumer and a merchant without allowing the merchant to know an account number belonging to the consumer, comprising:
a sending mechanism configured to send a receipt for a transaction in electronic form from a merchant to a consumer; a receiving mechanism configured to receive a secure digital envelope from the consumer, the consumer having formed the secure digital envelope by encrypting information associated with the receipt and the account number using a public key of a financial institution; and wherein the sending mechanism is additionally configured to send the secure digital envelope along with information associated with the receipt to the financial institution, thereby enabling the financial institution to process the transaction without allowing the merchant to know an account number.
40 . The apparatus of claim 39 ,
wherein the consumer forms the digital envelope by,
generating a first hash of the receipt, and
encrypting the receipt, the first hash, and the account number using the public key of the financial institution; and
wherein the merchant sends the secure digital envelope to the financial institution by,
generating a second hash of the receipt; and
sending the secure digital envelope along with the second hash to the financial institution.
41 . The apparatus of claim 40 , further comprising a processing mechanism, which is configured to process the transaction at the financial institution by:
using a private key belonging to the financial institution to decrypt the secure digital envelope to obtain the receipt, the first hash, and the account number; and comparing the first hash with the second hash to validate the transaction.
42 . The apparatus of claim 41 , further comprising:
a authorizing mechanism, which is configured to authorize the transaction if the second hash matches the first hash; and a notifying mechanism, which is configured to notify the merchant that the transaction is valid if the second hash matches the first hash.
43 . The apparatus of claim 39 , wherein the consumer forms the secure digital envelope in a smart card.
44 . The apparatus of claim 43 , wherein the smart card contains:
an identifier for the consumer; an identifier for the financial institution; a private key for the consumer; the public key for the financial institution; the account number; and encryption mechanisms.
45 . The apparatus of claim 39 , further comprising a validating mechanism, which is configured to validate that the consumer has an account with the financial institution by:
receiving a digital certificate belonging to the financial institution from the consumer; determining if the digital certificate of the financial institution is valid by validating that the digital certificate is signed by a recognized certificate authority; if so, transmitting the consumer identifier and the consumer certificate to the financial institution to validate if the consumer has an account with the financial institution; and receiving a validation message from the financial institution if the consumer has an account with the financial institution.Join the waitlist — get patent alerts
Track US2006031173A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.