Systems and methods for identification and authentication of a user
Abstract
The present invention generally relates to a computer security system for use in the identification and authentication of a user prior to an on-line transaction. In one aspect, a method for facilitating a secure transaction over a network is provided. The method includes collecting a username and password associated with a user of the machine. The method further includes verifying that the username and password matches a previously collected username and password in an identity profile. The method also includes collecting device data from a user machine to uniquely identify the machine. Additionally, the method includes verifying that the device data matches previously collected device data in the identity profile. In another aspect, a computer-readable medium including a set of instructions that when executed by a processor cause the processor to facilitate a secure transaction over a network is provided. In yet a further aspect, a system for facilitating a secure transaction is provided.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method for performing a payment transaction, the method comprising:
creating a one-time use personal account number for a transaction with a merchant; replacing the one-time personal account number with a user real personal account number; and sending the user real personal account number and details associated with the transaction to a financial institution server for approval.
2 . The method of claim 1 , wherein the user real personal account number is associated with a user account held at a financial institution.
3 . The method of claim 1 , further comprising the step of obtaining payment type information from the financial institution server.
4 . The method of claim 1 , further comprising the step of prompting a user to select a payment type to be used for paying the merchant.
5 . The method of claim 1 , wherein the merchant is an on-line merchant.
6 . The method of claim 5 , further comprising the step of transmitting the one-time use personal account number to the on-line merchant through a merchant webpage.
7 . The method of claim 6 , further comprising the step of sending the one-time personal account number and the details associated with the transaction to a server machine.
8 . The method of claim 1 , further comprising the steps of:
receiving a first username and a first password input into a computer system by a user; accessing a database that stores a user profile associated with the user that includes a second username and a second password previously collected from the user when the user enrolled a user account; verifying that the first username matches the second username included in the user profile and that the first password matches the second password included in the user profile; and allowing the user to access the user account from the computer system to purchase a product or a service from the merchant.
9 . The method of claim 1 , further comprising the steps of collecting first biometric data from a user and verifying that the first biometric data matches second biometric data previously collected from the user and included in a user profile.
10 . The method of claim 9 , wherein the first biometric data includes typing patterns of the user, fingerprint data, or iris pattern data.
11 . The method of claim 1 , further comprising the step of allowing a user to access a user account without providing sensitive personal data.
12 . The method of claim 11 , further comprising the step of detecting a webpage related to the user attempting to access the user account.
13 . The method of claim 12 , wherein the step of detecting comprises reading a source code of the webpage or detecting a trigger included in the webpage.
14 . The method of claim 12 , wherein the step of detecting comprises reading HTML for key words including expiration date or card verification value.
15 . A computer-readable medium including a set of instructions that, when executed by a processor, cause the processor to perform a payment transaction, by performing the steps of:
creating a one-time use personal account number for a transaction with a merchant; replacing the one-time personal account number with a user real personal account number; and sending the user real personal account number and details associated with the transaction to a financial institution server for approval.
16 . The computer-readable medium of claim 15 , wherein the user real personal account number is associated with a user account held at a financial institution.
17 . The computer-readable medium of claim 15 , further comprising the step of obtaining payment type information from the financial institution server.
18 . The computer-readable medium of claim 15 , further comprising the step of prompting a user to select a payment type to be used for paying the merchant.
19 . The computer-readable medium of claim 15 , wherein the merchant is an on-line merchant.
20 . The computer-readable medium of claim 19 , further comprising the step of transmitting the one-time use personal account number to the on-line merchant through a merchant webpage.
21 . The computer-readable medium of claim 20 , further comprising the step of sending the one-time personal account number and the details associated with the transaction to a server machine.
22 . The computer-readable medium of claim 15 , further comprising the steps of:
receiving a first username and a first password input into a computer system by a user; accessing a database that stores a user profile associated with the user that includes a second username and a second password previously collected from the user when the user enrolled a user account; verifying that the first username matches the second username included in the user profile and that the first password matches the second password included in the user profile; and allowing the user to access the user account from the computer system to purchase a product or a service from the merchant.
23 . The computer-readable medium of claim 15 , further comprising the steps of collecting first biometric data from a user and verifying that the first biometric data matches second biometric data previously collected from the user and included in a user profile.
24 . The computer-readable medium of claim 23 , wherein the first biometric data includes typing patterns of the user, fingerprint data, or iris pattern data.
25 . The computer-readable medium of claim 15 , further comprising the step of allowing a user to access a user account without providing sensitive personal data.
26 . The computer-readable medium of claim 25 , further comprising the step of detecting a webpage related to the user attempting to access the user account.
27 . The computer-readable medium of claim 26 , wherein the step of detecting comprises reading a source code of the webpage or detecting a trigger included in the webpage.
28 . The computer-readable medium of claim 26 , wherein the step of detecting comprises reading HTML for key words including expiration date or card verification value.
29 . A system for performing a payment transaction, the system comprising:
a server that includes a user profiles database and is configured to:
create a one-time use personal account number for a transaction with a merchant,
replace the one-time personal account number with a user real personal account number, and
send the user real personal account number and details associated with the transaction to a financial institution server for approval.
30 . The system of claim 29 , wherein the user real personal account number is associated with a user account held at a financial institution.
31 . The system of claim 29 , wherein the server is further configured to obtain payment type information from the financial institution server.
32 . The system of claim 29 , wherein the server is further configured to prompt a user to select a payment type to be used for paying the merchant.
33 . The system of claim 29 , wherein the merchant is an on-line merchant.
34 . The system of claim 33 , wherein the server is further configured to transmit the one-time use personal account number to the on-line merchant through a merchant webpage.
35 . The system of claim 29 , further comprising a first computing device having a processor and a memory, wherein the memory includes a security agent configured to collect a first username and a first password input into the first computing device by a user.
36 . The system of claim 35 , wherein the security agent is further configured to send the one-time personal account number and the details associated with the transaction to the server machine.
37 . The system of claim 35 , wherein the server is further configured to:
receive the first username and the first password input into the first computing device by the user; access the user profiles database that stores a user profile associated with the user that includes a second username and a second password previously collected from the user when the user enrolled a user account; verify that the first username matches the second username included in the user profile and that the first password matches the second password included in the user profile; and allow the user to access the user account from the first computing device to purchase a product or a service from the merchant.
38 . The system of claim 37 , wherein the user accesses the user account without providing sensitive personal data.
39 . The system of claim 38 , wherein the security agent is further configured to detect a webpage related to the user attempting to access the user account.
40 . The system of claim 39 , wherein the detecting comprises reading a source code of the webpage or detecting a trigger included in the webpage.
41 . The system of claim 39 , wherein the detecting comprises reading HTML for key words including expiration date or card verification value.
42 . The system of claim 35 , wherein the security agent is further configured to collect first biometric data from the user and verify that the first biometric data matches second biometric data previously collected from the user and included in a user profile.
43 . The system of claim 42 , wherein the first biometric data includes typing patterns of the user, fingerprint data, or iris pattern data.
44 . The system of claim 29 , wherein the one-time use personal account number has a format associated with a conventional credit card.Join the waitlist — get patent alerts
Track US2009228370A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.