US2014351146A1PendingUtilityA1

Authentication for a commercial transaction using a mobile module

Assignee: MICROSOFT CORPPriority: Apr 19, 2005Filed: Aug 12, 2014Published: Nov 27, 2014
Est. expiryApr 19, 2025(expired)· nominal 20-yr term from priority
G06Q 20/12G06Q 20/4014G06Q 20/40G06Q 20/425G06Q 20/3829G06Q 30/0601G06Q 30/02G06Q 20/3229G06Q 20/3227G06Q 20/322G06Q 20/02G06Q 20/32
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Current embodiments provide for authorization and payment of an online commercial transaction between a purchaser and a merchant including verification of an identity of the purchaser and verification of an ability of the purchaser to pay for the transaction, where the identity provider and the payment provider are often different network entities. Other embodiments also provide for protocols, computing systems, and other mechanisms that allow for identity and payment authentication using a mobile module, which establishes single or multilevel security over an untrusted network (e.g., the Internet). Still other embodiments also provide for a three-way secure communication between a merchant, consumer, and payment provider such that sensitive account information is opaque to the merchant, yet the merchant is sufficiently confident of the consumer's ability to pay for requested purchases. In yet another embodiment, electronic billing information is used for authorization, auditing, payment federation, and other purposes.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . At a first computing device in a distributed network environment, a method of authenticating the first computing device to a second computing device using a mobile module of a third computing device which is connected to the first computing device, the method, which is performed by the first computing device, comprising:
 obtaining a network security token to establish transport level secure communication between the first computing device and a second computing device by performing the following:
 sending a request for the network security token to the mobile infrastructure via the second computing device; 
 obtaining at the first computing device a response from the mobile module in response to a network level challenge that is issued for the request; 
 the first computing device using the response from the mobile module to generate and send a request security token response from the first computing device to the mobile infrastructure; 
 receiving at the first computing device a network security token corresponding to the request security token response which include encrypted session keys; 
 sending from the first computing device the encrypted session keys to the mobile module; 
 receiving at the first computing device unencrypted session keys from the mobile module; and 
 the first computing device using the network security token to obtain a user security token which is subsequently used to obtain a service token. 
   
     
     
         2 . The method recited in  claim 1 , wherein the first computing device using the network security token to obtain the user security token includes:
 sending a request for a user security token to the mobile infrastructure via the second computing device;   receiving at the first computing device a challenge from the mobile infrastructure;   sending from the first computing device the received challenge to a mobile module of the third computing device;   receiving at the first computing device a request for user credentials from the mobile module;   at the first computing device prompting the user for and receiving the credentials;   sending from the first computing device the credentials to the mobile module;   receiving at the first computing device a challenge response sent from the mobile module;   in response to the challenge, creating at the first computing device a request user security token response, and signing or encrypting the response with the network security token;   sending the request user security token response from the first computing device to the mobile infrastructure;   receiving at the first computing device a user security token from the mobile infrastructure that includes new encrypted user keys;   sending from the first computing device the new encrypted user keys to the mobile module; and   receiving at the first computing device new unencrypted user keys from the mobile module, which correspond to the user security token.   
     
     
         3 . The method recited in  claim 2 , wherein the first computing device uses the user security token to obtain the service token by performing the following:
 at the first computing device, signing or encrypting one or more requests for a service token with the new unencrypted user keys of the user security token;   sending the one or more requests signed or encrypted with the new unencrypted user keys from the first computing device to a computing device containing the service token;   in response to the one or more requests, the first computing device receiving the service token from the computing device containing the service token.   
     
     
         4 . The method of  claim 3 , wherein the second computing device is the computing device containing the service token. 
     
     
         5 . The method of  claim 4 , wherein the method further includes the first computing device using the service token to obtain one or more goods or services. 
     
     
         6 . The method of  claim 2 , wherein the method further includes sending the credentials to the mobile module after first signing the credentials with the unencrypted session keys corresponding to the network security token. 
     
     
         7 . The method of  claim 1 , wherein the method further includes sending the request security token response only after it is first signed by the mobile module. 
     
     
         8 . The method of  claim 1 , wherein the mobile module is a subscriber identity module (SIM) card. 
     
     
         9 . The method of  claim 1 , wherein at least one of the one or more service tokens includes information that identifies the mobile module. 
     
     
         10 . The method of  claim 1 , wherein at least one of the one or more service tokens includes information regarding an identity of the user. 
     
     
         11 . The method of  claim 1 , wherein at least one of the one or more service tokens includes information that verifies the ability of the user to pay for services provided by a third party server. 
     
     
         12 . One or more computer storage device having stored computer-executable instructions which when executed by a processor perform a method at a first computing device in a distributed network environment, for authenticating the first computing device to a second computing device using a mobile module of a third computing device which is connected to the first computing device, wherein the method includes:
 obtaining a network security token to establish transport level secure communication between the first computing device and a second computing device by performing the following:   sending a request for the network security token to the mobile infrastructure via the second computing device;   obtaining at the first computing device a response from the mobile module in response to a network level challenge that is issued for the request;   the first computing device using the response from the mobile module to generate and send a request security token response from the first computing device to the mobile infrastructure;   receiving at the first computing device a network security token corresponding to the request security token response which include encrypted session keys;   sending from the first computing device the encrypted session keys to the mobile module;   receiving at the first computing device unencrypted session keys from the mobile module; and   the first computing device using the network security token to obtain a user security token which is subsequently used to obtain a service token.   
     
     
         13 . The one or more computer storage device recited in  claim 1 , wherein the first computing device using the network security token to obtain the user security token includes:
 sending a request for a user security token to the mobile infrastructure via the second computing device;   receiving at the first computing device a challenge from the mobile infrastructure;   sending from the first computing device the received challenge to a mobile module of the third computing device;   receiving at the first computing device a request for user credentials from the mobile module;   at the first computing device prompting the user for and receiving the credentials;   sending from the first computing device the credentials to the mobile module;   receiving at the first computing device a challenge response sent from the mobile module;   in response to the challenge, creating at the first computing device a request user security token response, and signing or encrypting the response with the network security token;   sending the request user security token response from the first computing device to the mobile infrastructure;   receiving at the first computing device a user security token from the mobile infrastructure that includes new encrypted user keys;   sending from the first computing device the new encrypted user keys to the mobile module; and   receiving at the first computing device new unencrypted user keys from the mobile module, which correspond to the user security token.   
     
     
         14 . The one or more computer storage device recited in  claim 13 , wherein the first computing device uses the user security token to obtain the service token by performing the following:
 at the first computing device, signing or encrypting one or more requests for a service token with the new unencrypted user keys of the user security token;   sending the one or more requests signed or encrypted with the new unencrypted user keys from the first computing device to a computing device containing the service token;   in response to the one or more requests, the first computing device receiving the service token from the computing device containing the service token.   
     
     
         15 . The one or more computer storage device of  claim 14 , wherein the second computing device is the computing device containing the service token. 
     
     
         16 . The one or more computer storage device of  claim 15 , wherein the method further includes the first computing device using the service token to obtain one or more goods or services. 
     
     
         17 . The one or more computer storage device of  claim 13 , wherein the method further includes sending the credentials to the mobile module after first signing the credentials with the unencrypted session keys corresponding to the network security token. 
     
     
         18 . The one or more computer storage device of  claim 12 , wherein the method further includes sending the request security token response only after it is first signed by the mobile module. 
     
     
         19 . The one or more computer storage device of  claim 12 , wherein the mobile module is a subscriber identity module (SIM) card. 
     
     
         20 . A computing system comprising:
 at least one processor; and   one or more computer storage device having stored computer-executable instructions which when executed by the at least one processor perform a method at the computing system for authenticating the computing system to another computing device using a mobile module of a mobile computing device which is connected to the computing system, wherein the method includes:
 obtaining a network security token to establish transport level secure communication between the computing system and said other computing device by performing the following: 
 sending a request for the network security token to the mobile infrastructure via the other computing device; 
 obtaining at the computing system a response from the mobile module in response to a network level challenge that is issued for the request; 
 the computing system using the response from the mobile module to generate and send a request security token response from the computing system to the mobile infrastructure; 
 receiving at the computing system a network security token corresponding to the request security token response which include encrypted session keys; 
 sending from the computing system the encrypted session keys to the mobile module; 
 receiving at the computing system unencrypted session keys from the mobile module; and 
 the computing system using the network security token to obtain a user security token which is subsequently used to obtain a service token.

Join the waitlist — get patent alerts

Track US2014351146A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.