US2009228370A1PendingUtilityA1

Systems and methods for identification and authentication of a user

Assignee: VERIENT INCPriority: Nov 21, 2006Filed: May 21, 2009Published: Sep 10, 2009
Est. expiryNov 21, 2026(~0.3 yrs left)· nominal 20-yr term from priority
G06Q 20/341G06Q 30/0185G06Q 20/40G06Q 20/40975G06Q 40/00G07F 7/1008G07F 7/1025G06Q 30/0601G06Q 30/06G06Q 20/401
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention generally relates to a computer security system for use in the identification and authentication of a user prior to an on-line transaction. In one aspect, a method for facilitating a secure transaction over a network is provided. The method includes collecting a username and password associated with a user of the machine. The method further includes verifying that the username and password matches a previously collected username and password in an identity profile. The method also includes collecting device data from a user machine to uniquely identify the machine. Additionally, the method includes verifying that the device data matches previously collected device data in the identity profile. In another aspect, a computer-readable medium including a set of instructions that when executed by a processor cause the processor to facilitate a secure transaction over a network is provided. In yet a further aspect, a system for facilitating a secure transaction is provided.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method for performing a payment transaction, the method comprising:
 creating a one-time use personal account number for a transaction with a merchant;   replacing the one-time personal account number with a user real personal account number; and   sending the user real personal account number and details associated with the transaction to a financial institution server for approval.   
     
     
         2 . The method of  claim 1 , wherein the user real personal account number is associated with a user account held at a financial institution. 
     
     
         3 . The method of  claim 1 , further comprising the step of obtaining payment type information from the financial institution server. 
     
     
         4 . The method of  claim 1 , further comprising the step of prompting a user to select a payment type to be used for paying the merchant. 
     
     
         5 . The method of  claim 1 , wherein the merchant is an on-line merchant. 
     
     
         6 . The method of  claim 5 , further comprising the step of transmitting the one-time use personal account number to the on-line merchant through a merchant webpage. 
     
     
         7 . The method of  claim 6 , further comprising the step of sending the one-time personal account number and the details associated with the transaction to a server machine. 
     
     
         8 . The method of  claim 1 , further comprising the steps of:
 receiving a first username and a first password input into a computer system by a user;   accessing a database that stores a user profile associated with the user that includes a second username and a second password previously collected from the user when the user enrolled a user account;   verifying that the first username matches the second username included in the user profile and that the first password matches the second password included in the user profile; and   allowing the user to access the user account from the computer system to purchase a product or a service from the merchant.   
     
     
         9 . The method of  claim 1 , further comprising the steps of collecting first biometric data from a user and verifying that the first biometric data matches second biometric data previously collected from the user and included in a user profile. 
     
     
         10 . The method of  claim 9 , wherein the first biometric data includes typing patterns of the user, fingerprint data, or iris pattern data. 
     
     
         11 . The method of  claim 1 , further comprising the step of allowing a user to access a user account without providing sensitive personal data. 
     
     
         12 . The method of  claim 11 , further comprising the step of detecting a webpage related to the user attempting to access the user account. 
     
     
         13 . The method of  claim 12 , wherein the step of detecting comprises reading a source code of the webpage or detecting a trigger included in the webpage. 
     
     
         14 . The method of  claim 12 , wherein the step of detecting comprises reading HTML for key words including expiration date or card verification value. 
     
     
         15 . A computer-readable medium including a set of instructions that, when executed by a processor, cause the processor to perform a payment transaction, by performing the steps of:
 creating a one-time use personal account number for a transaction with a merchant;   replacing the one-time personal account number with a user real personal account number; and   sending the user real personal account number and details associated with the transaction to a financial institution server for approval.   
     
     
         16 . The computer-readable medium of  claim 15 , wherein the user real personal account number is associated with a user account held at a financial institution. 
     
     
         17 . The computer-readable medium of  claim 15 , further comprising the step of obtaining payment type information from the financial institution server. 
     
     
         18 . The computer-readable medium of  claim 15 , further comprising the step of prompting a user to select a payment type to be used for paying the merchant. 
     
     
         19 . The computer-readable medium of  claim 15 , wherein the merchant is an on-line merchant. 
     
     
         20 . The computer-readable medium of  claim 19 , further comprising the step of transmitting the one-time use personal account number to the on-line merchant through a merchant webpage. 
     
     
         21 . The computer-readable medium of  claim 20 , further comprising the step of sending the one-time personal account number and the details associated with the transaction to a server machine. 
     
     
         22 . The computer-readable medium of  claim 15 , further comprising the steps of:
 receiving a first username and a first password input into a computer system by a user;   accessing a database that stores a user profile associated with the user that includes a second username and a second password previously collected from the user when the user enrolled a user account;   verifying that the first username matches the second username included in the user profile and that the first password matches the second password included in the user profile; and   allowing the user to access the user account from the computer system to purchase a product or a service from the merchant.   
     
     
         23 . The computer-readable medium of  claim 15 , further comprising the steps of collecting first biometric data from a user and verifying that the first biometric data matches second biometric data previously collected from the user and included in a user profile. 
     
     
         24 . The computer-readable medium of  claim 23 , wherein the first biometric data includes typing patterns of the user, fingerprint data, or iris pattern data. 
     
     
         25 . The computer-readable medium of  claim 15 , further comprising the step of allowing a user to access a user account without providing sensitive personal data. 
     
     
         26 . The computer-readable medium of  claim 25 , further comprising the step of detecting a webpage related to the user attempting to access the user account. 
     
     
         27 . The computer-readable medium of  claim 26 , wherein the step of detecting comprises reading a source code of the webpage or detecting a trigger included in the webpage. 
     
     
         28 . The computer-readable medium of  claim 26 , wherein the step of detecting comprises reading HTML for key words including expiration date or card verification value. 
     
     
         29 . A system for performing a payment transaction, the system comprising:
 a server that includes a user profiles database and is configured to:
 create a one-time use personal account number for a transaction with a merchant, 
 replace the one-time personal account number with a user real personal account number, and 
 send the user real personal account number and details associated with the transaction to a financial institution server for approval. 
   
     
     
         30 . The system of  claim 29 , wherein the user real personal account number is associated with a user account held at a financial institution. 
     
     
         31 . The system of  claim 29 , wherein the server is further configured to obtain payment type information from the financial institution server. 
     
     
         32 . The system of  claim 29 , wherein the server is further configured to prompt a user to select a payment type to be used for paying the merchant. 
     
     
         33 . The system of  claim 29 , wherein the merchant is an on-line merchant. 
     
     
         34 . The system of  claim 33 , wherein the server is further configured to transmit the one-time use personal account number to the on-line merchant through a merchant webpage. 
     
     
         35 . The system of  claim 29 , further comprising a first computing device having a processor and a memory, wherein the memory includes a security agent configured to collect a first username and a first password input into the first computing device by a user. 
     
     
         36 . The system of  claim 35 , wherein the security agent is further configured to send the one-time personal account number and the details associated with the transaction to the server machine. 
     
     
         37 . The system of  claim 35 , wherein the server is further configured to:
 receive the first username and the first password input into the first computing device by the user;   access the user profiles database that stores a user profile associated with the user that includes a second username and a second password previously collected from the user when the user enrolled a user account;   verify that the first username matches the second username included in the user profile and that the first password matches the second password included in the user profile; and   allow the user to access the user account from the first computing device to purchase a product or a service from the merchant.   
     
     
         38 . The system of  claim 37 , wherein the user accesses the user account without providing sensitive personal data. 
     
     
         39 . The system of  claim 38 , wherein the security agent is further configured to detect a webpage related to the user attempting to access the user account. 
     
     
         40 . The system of  claim 39 , wherein the detecting comprises reading a source code of the webpage or detecting a trigger included in the webpage. 
     
     
         41 . The system of  claim 39 , wherein the detecting comprises reading HTML for key words including expiration date or card verification value. 
     
     
         42 . The system of  claim 35 , wherein the security agent is further configured to collect first biometric data from the user and verify that the first biometric data matches second biometric data previously collected from the user and included in a user profile. 
     
     
         43 . The system of  claim 42 , wherein the first biometric data includes typing patterns of the user, fingerprint data, or iris pattern data. 
     
     
         44 . The system of  claim 29 , wherein the one-time use personal account number has a format associated with a conventional credit card.

Join the waitlist — get patent alerts

Track US2009228370A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.