Authentication process using search technology
Abstract
Systems and methods are presented for improved authentication and risk analysis processes using search engine technology. In one potential implementation, an authorization request message is received at a payment processing network as part of a transaction between a user and a merchant. The payment processing network analyzes risk based on a search history associated with the user involved in the transaction with the merchant. A response to the authentication request is made based in part on the risk associated with the user search history. In further embodiments, a user registers with a search engine as part of a service for improved authentication, where the user accepts privacy settings allowing storage of search and transaction data by a search engine server. The search engine server passes search and transaction data to a risk analysis server for creation of risk parameters which may be used to authenticate transactions.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
receiving, at a server computer, an authorization request message, wherein the authorization request message was generated in response to a transaction conducted between a user and a merchant; determining a risk associated with the authorization request message, wherein the risk is determined based on user search data; and communicating a response to the authorization request message based on the risk.
2 . The method of claim 1 wherein determining the risk associated with the authorization request comprises generating a risk analysis parameter based an association between the authorization request message and the user search data; and
wherein initiating the response to the authorization request based on the risk comprises sending the risk analysis parameter and the authorization request to an issuer.
3 . The method of claim 2 wherein determining the risk associated with the authorization request message further comprises initiating a request from a payment processing network to a search engine server requesting the user search data from the search engine server and receiving the user search data from the search engine server prior to determining the risk associated with the authorization request message.
4 . The method of claim 3 wherein the user search data comprises identification and classification data for a plurality of websites selected by the user.
5 . The method of claim 3 wherein the user search data comprises a keyword search history, a user transaction history, and a correlation between the keyword search history and the user transaction history.
6 . The method of claim 5 further comprising initiating a communication to the search engine server to communicate details of the transaction between the user and the merchant after initiating the response to the authorization request.
7 . The method of claim 2 wherein the association between the authorization request and the user search data comprises an identification of the merchant in the user search data.
8 . The method of claim 2 wherein the association between the authorization request and the user search data comprises an identification of a service type in the user search data that is associated with the authorization request.
9 . The method of claim 1 further comprising:
receiving at a payment processing network, prior to receipt of the authorization request message, at least one risk parameter from a risk analysis server, wherein the at least one risk parameter is based on the user search data;
wherein the risk associated with the authorization request message is further evaluated using the at least one risk parameter.
10 . The method of claim 1 wherein the user search data comprises a plurality of keyword searches and the method further comprises deleting a first keyword search from the plurality of keyword searches when a privacy and data deletion setting has been reached.
11 . The method of claim 10 wherein the privacy and data deletion setting is dynamically based on a statistical characteristic of the user search data.
12 . A method comprising:
receiving, at a registration server, registration information from a user authorizing storage of user search data for use in transaction authentication; receiving, at a search engine server, a search request from the user updating, in a search engine database, the user search data in response to the search request; receiving at the search engine server, from a server computer; a request for the user search data in response to an authentication request; and communicating, to the payment processing network, the user search data.
13 . The method of claim 12 wherein the registration information comprises an account number associated with the user.
14 . The method of claim 12 wherein the registration information comprises privacy and data deletion settings.
15 . The method of claim 14 wherein the privacy and data deletion setting specify a time limit for storing the search request and a part of the user search data.
16 . The method of claim 12 wherein the search engine database comprises user search data and a user transaction history.
17 . The method of claim 12 further comprising calculating a spending profile and an aggregated user data profile from the user search data and the user transaction history.
18 . The method of claim 17 further comprising calculating a risk parameter from the spending profile and the aggregated user data profile.
19 . A system comprising:
a search engine server comprising a user search history database; and a server computer for receiving an authorization request message to complete a transaction between a user and a merchant, wherein the search engine server and the server computer are in operative communication; wherein the server accesses the user search history database containing user search data; and wherein the server determines whether the authorization request message is associated with any of the searches belonging to the user in the search history.
20 . The system of claim 19 further comprising a risk engine server;
wherein the server computer accesses the user search history databases via the risk engine server;
wherein the server determines whether the authorization request message is associated with any of the searches by correlating information from the authorization request message with a risk score received from the risk engine server; and
wherein the risk score is derived from the user search history data.Join the waitlist — get patent alerts
Track US2014258124A9 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.