Method for securing electronic transactions
Abstract
A method for securing electronic transactions includes associating a mobile electronic device with a first user. A first computer system retrievably stores registration data relating to the first user, including a device identifier that is unique to the mobile electronic device. A security application that supports in-application push notifications is installed on the mobile electronic device. The first computer system sends a push notification to the mobile electronic device, the push notification prompting the first user to provide a confirmation reply via a user interface of the security application for activating the mobile electronic device as a security token. The mobile electronic device is activated as a security token for the first user in response to receiving at the first computer system, from the mobile electronic device, the confirmation reply from the first user.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
associating a mobile electronic device with a first user; retrievably storing, by a first computer system, registration data relating to the first user and including a device identifier that is unique to the mobile electronic device associated with the first user; sending, by the first computer system, a push notification to the mobile electronic device, the push notification prompting the first user to provide a confirmation reply via a user interface of a security application for activating the mobile electronic device as a security token; and activating the mobile electronic device as a security token for the first user in response to receiving at the first computer system, from the mobile electronic device, the confirmation reply from the first user.
2 . The method of claim 1 wherein retrievably storing the registration data includes retrievably storing first authentication data for use in authenticating the first user to the first computer system.
3 . The method of claim 2 wherein the push notification is for prompting the first user to provide second authentication data, and further comprising receiving from the mobile electronic device the second authentication data at the first computer system.
4 . The method of claim 2 wherein the push notification is for prompting the first user to provide second authentication data including a biometric input, and further comprising receiving from the mobile electronic device the second authentication data at the first computer system.
5 . The method of claim 3 wherein activating the mobile electronic device as a security token for the first user comprises assigning the security token to one of a plurality of different security levels in dependence upon a result of comparing the second authentication data to the first authentication data.
6 . The method of claim 1 wherein the mobile electronic device is a smartphone.
7 . The method of claim 1 comprising:
providing from the first user to a second computer system an electronic transaction request;
prior to completing the requested electronic transaction, sending an authorization request from the second computer system to the first computer system;
sending, by the first computer system, a push notification to the mobile electronic device, the push notification prompting the first user to provide a response for authorizing the requested electronic transaction;
receiving, from the mobile electronic device, the response at the first computer system;
in response upon receiving the response at the first computer system, providing to the second computer system an authorization message; and
in response to receiving the authorization message at the second computer system, completing the electronic transaction for the first user.
8 . The method of claim 1 comprising:
associating the security token with a specific authorized service, the service for being authenticated in reliance upon the security token.
9 . The method of claim 1 wherein the security token comprises tokenization data uniquely associated with the smart phone such that copying of the tokenization data to another smartphone other than results in a valid token.
10 . A method comprising:
registering by a first system a first user, comprising retrievably storing authentication data for use in authenticating the first user to the first system; registering by a second system the first user, comprising associating a uniquely identifiable mobile electronic device with the first user; requesting by the first user to the first system an electronic transaction requiring authentication of the first user by the first system; authenticating the first user by the first system based on the retrievably stored authentication data and based on data provide by the first user in response to an authentication challenge by the first system; subsequent to authenticating the first user, requesting by the first system to the second system a secondary authentication of the first user; sending from the second system to the uniquely identifiable mobile electronic device a push notification prompting the first user to provide a secondary authentication response via the uniquely identifiable mobile electronic device; receiving by the second system from the uniquely identifiable mobile electronic device the secondary authentication response provided by the first user; providing the secondary authentication of the first user from the second system to the first system based on the secondary authentication response; and subsequent to receiving the secondary authentication of the first user, performing by the first system the requested electronic transaction for the first user.
11 . The method of claim 10 wherein associating a uniquely identifiable mobile electronic device with the first user comprises installing a security application on said device.
12 . The method of claim 10 wherein the secondary authentication response provided by the first user comprises at least one of a password and a username.
13 . The method of claim 10 wherein the secondary authentication response provided by the first user comprises biometric data.
14 . A method comprising:
associating a mobile electronic device with a first user; installing on the mobile electronic device a security application that supports in-application push notifications; registering, by a security computer, the mobile electronic device as a security token for use by the first user for authorizing electronic transactions; receiving at the security computer, from a first transaction system, a first request for authorization to complete a first electronic transaction; receiving at the security computer, from a second transaction system, a second request for authorization to complete a second electronic transaction; sending from the security computer to the mobile electronic device a first push notification prompting the first user to provide a first response authorizing the first electronic transaction; sending from the security computer to the mobile electronic device a second push notification prompting the first user to provide a second response authorizing the second electronic transaction; and providing from the security computer:
a first authorization to the first transaction system in dependence upon receiving the first response from the first user authorizing the first electronic transaction; and
a second authorization to the second transaction system in dependence upon receiving the second response from the first user authorizing the second electronic transaction.
15 . The method of claim 14 wherein the first response from the first user comprises first authentication information required for a first security level, and the second response from the first user comprises second authentication information required for a second security level different than the first security level.
16 . The method of claim 14 wherein the first transaction system is associated with a first entity and the second transaction system is associated with a second entity different than the first entity.
17 . The method according to 14 wherein the first transaction system authenticates the first user prior to the security computer providing the first authorization.
18 . The method according to claim 14 wherein the first transaction system relates to a first service and the second transaction system relates to a second different service.
19 . A method comprising:
associating a mobile electronic device with a first user; installing on the mobile electronic device a security application that supports in-application push notifications; registering, by a first computer system, the mobile electronic device as a security token for use by the first user for authorizing electronic transactions; receiving an electronic transaction request from the first user, the electronic transaction request associated with a security level of a plurality of different security levels; transmitting via at least a push notification a request for N responses each including different authentication information, wherein the number N is greater than 1 and is determined based on the security level that is associated with the electronic transaction request; and in dependence upon receiving at the first computer system an expected response from the first user for each of the N responses, via the mobile electronic device, authorizing the electronic response by the first computer system.
20 . A method according to claim 19 wherein the different authentication information comprises multi-factor authentication information.Join the waitlist — get patent alerts
Track US2015025874A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.