US2014372321A1PendingUtilityA1

Secure authentication between multiple parties

Assignee: EBAY INCPriority: Jun 30, 2009Filed: Aug 28, 2014Published: Dec 18, 2014
Est. expiryJun 30, 2029(~2.9 yrs left)· nominal 20-yr term from priority
Inventors:Khurram Khan
G06Q 20/40G06Q 20/4012G06Q 20/385G06Q 20/02G06Q 20/325G06Q 20/10G10L 17/00G06F 21/31
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are disclosed herein to allow a party to a multiple-party transaction to perform authentications using identification information received from another party while allowing the party generating the identification information to maintain confidentiality of information. A user may enter an access code to identify the user to a first party that will be generating identification information to a second party in the transaction. The access code may be entered without requiring the entry of an alphanumeric PIN (Personal Identification Number). The first party may convert the access code to a second code for transmission to the second party so that the access code is not revealed to the second party. The second party may use the second code to authenticate the user, to authenticate a payment transaction or other types of communications from the user or the first party. Thus, parties in a multiple-party transaction may perform authentications while maintaining the confidentiality of information.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A system comprising:
 a non-transitory memory comprising information for an account of a user; and   one or more hardware processors in communication with the non-transitory memory and configured to:
 process an approval request to generate a payment key, wherein the approval request comprises an agreement to make payments from the account of the user to a merchant; 
 communicate the payment key to the merchant and the user; 
 receive login information for the account; 
 receive a personal identification number (PIN) from the user, wherein the PIN authenticates the user during use of the payment key by the merchant; 
 associate the PIN with the payment key using the login information; 
 receive a payment request including the PIN and the payment key from the merchant; 
 verify the PIN and the payment key to authorize the payment request without requiring the login information for the account; and 
 transfer a payment for the payment request from the account of the user to the merchant. 
   
     
     
         2 . The system of  claim 1 , wherein the PIN is generated from an access code entered by the user using a user device. 
     
     
         3 . The system of  claim 2 , wherein the PIN is generated by one of the user device and a merchant device for the merchant. 
     
     
         4 . The system of  claim 1 , wherein the login information is received from a communication device. 
     
     
         5 . The system of  claim 4 , wherein the login information is not provided to the merchant. 
     
     
         6 . The system of  claim 5 , wherein the communication device prevents the login information from being provided to the merchant. 
     
     
         7 . The system of  claim 4 , wherein the payment request is received from the communication device. 
     
     
         8 . The system of  claim 1 , wherein the login information comprises an account identifier and an authorization password. 
     
     
         9 . A method comprising:
 processing, using one or more hardware processors, a payment request to generate a key, wherein the payment request comprises a request to make payments from an account of a user to a merchant;   communicating the key to the merchant and the user;   receiving credential information for the account;   receiving a personal identification number (PIN) from the user, wherein the PIN authenticates the user during use of the key by the merchant;   associating the PIN with the key using the credential information;   receiving a payment authorization including the PIN and the key from the merchant;   verifying the PIN and the key to authorize the payment authorization without requiring the credential information for the account; and   transferring a payment for the payment authorization from the account of the user to the merchant.   
     
     
         10 . The method of  claim 9 , wherein the PIN is derived from an access code entered into a user device for the user. 
     
     
         11 . The method of  claim 10 , wherein the access code comprises a pattern of finger movement of the user entered into the user device. 
     
     
         12 . The method of  claim 10 , wherein the access code comprises biometric information of the user entered into the user device. 
     
     
         13 . The method of  claim 9 , wherein the approval request includes payment constraint information to set limits on the payment request. 
     
     
         14 . The method of  claim 9 , wherein at least one of the approval request and the payment request are received from the user. 
     
     
         15 . The method of  claim 9 , wherein at least one of the approval request and the payment request are received from the merchant. 
     
     
         16 . The method of  claim 9 , wherein the login information is received from the user, and wherein the merchant does not receive the login information. 
     
     
         17 . The method of  claim 9 , wherein the user communicates the login information to a device. 
     
     
         18 . A non-transitory computer-readable medium comprising instructions which, in response to execution by a computer system, cause the computer system to perform a method comprising:
 accessing, using one or more hardware processors, an approval request to generate a payment key, wherein the approval request comprises an agreement to make payments from an account of a user to a merchant;   transmitting the payment key to the merchant and the user;   receiving login information for the account;   receiving a personal identification number (PIN) from the user, wherein the PIN authenticates the user during use of the payment key by the merchant;   associating the PIN with the payment key using the login information;   receiving a payment request including the PIN and the payment key from the merchant;   processing the PIN and the payment key to authorize the payment request without requiring the login information for the account; and   processing a payment for the payment request from the account of the user to the merchant.   
     
     
         19 . The non-transitory computer-readable medium of  claim 18 , wherein the approval request is received from a merchant device acting as a facilitator for transactions with the merchant. 
     
     
         20 . The non-transitory computer-readable medium of  claim 19 , wherein the payment request is received from the merchant device.

Join the waitlist — get patent alerts

Track US2014372321A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.