Centralized electronic commerce card transactions
Abstract
A central transaction server in electronic commerce card authorization system enables the electronic commerce card association to manage and monitor the authentication system. The central transaction server acts as an intermediary for all communications between the access control server used for authentication. If any portion of the authentication system fails, the central transaction server compensates by providing appropriate responses to other portions of the system. The centralized transaction server translates all incoming traffic into a format compatible with the intended recipient, enabling portions of the system to be upgraded without breaking compatibility with the non-upgraded portions. The centralized transaction server also enables the integration of formally separate portions of the authentication system into a single unit. The directory and the authentication history servers can be integrated into the central transaction server, and the central transaction server can initiate charges to the electronic commerce card automatically, bypassing the card acquirer.
Claims
exact text as granted — not AI-modified1 .- 31 . (canceled)
32 . A central transaction server having a processor and a computer-readable non-transitory medium coupled to the processor, the computer-readable medium comprising code that when executed by the processor causes the processor to perform a method comprising:
receiving an authentication request from a cardholder system; forwarding the authentication request to an access control server; evaluating a response from the access control server, wherein the response is either an unintelligible response, or a non-response from the access control server in response to the forwarded authentication request; based on the evaluation, generating an attempted authentication response when the access control server does not reply or provides the unintelligible response, wherein:
the central transaction server generates the attempted authentication response independently of the access control server,
the attempted authentication response includes an indication of the determination regarding the no reply or the unintelligible response,
the attempted authentication response includes a uniform resource locator (URL) associated with the central transaction server instead of a URL associated with the access control server, and
forwarding the attempted authentication response to the cardholder system.
33 . The central transaction server of claim 32 , wherein the attempted authentication response is adapted to be analyzed by a networked system, and wherein the networked system that analyzes the attempted authentication response is a merchant system.
34 . The central transaction server of claim 32 , wherein the central transaction server is further adapted to receive a verifying enrollment request from a directory server, and to send a verifying enrollment response to the directory server.
35 . The central transaction server of claim 34 , does not forward the verifying enrollment request to the access control server.
36 . The central transaction server of claim 32 , wherein a pseudonym is included in a verifying enrollment response.
37 . The central transaction server of claim 36 , wherein the pseudonym was previously created by a merchant system.
38 . The central transaction server of claim 32 , further configured to initiate a charge request via a card association network in response to generating the attempted authentication response.
39 . The central transaction server of claim 32 wherein a cardholder initiates an online purchase before a verifying enrollment request is received at the central transaction server associated with the authentication request.
40 . A method of authenticating electronic commerce card information provided by a cardholder, the method comprising:
receiving an authentication request from a cardholder system; forwarding the authentication request to an access control server; evaluating a response from the access control server, wherein the response is either an unintelligible response, or a non-response from the access control server in response to the forwarded authentication request; based on the evaluation, generating an attempted authentication response when the access control server does not reply or provides the unintelligible response, wherein:
a central transaction server generates the attempted authentication response independently of the access control server,
the attempted authentication response includes an indication of the determination regarding the no reply or the unintelligible response,
the attempted authentication response includes a uniform resource locator (URL) associated with the central transaction server instead of a URL associated with the access control server, and
forwarding the attempted authentication response to the cardholder system.
41 . The method of claim 40 , wherein the attempted authentication response is adapted to be analyzed by a networked system, and wherein the networked system that analyzes the attempted authentication response is a merchant system.
42 . The method of claim 40 , wherein the central transaction server is adapted to receive a verifying enrollment request from a directory server, and to send a verifying enrollment response to the directory server.
43 . The method of claim 42 , wherein a pseudonym is included in the verifying enrollment response.
44 . The method of claim 43 , wherein the pseudonym is created by a merchant system.
45 . The method of claim 40 further comprising: initiating a charge request via a card association network in response to generating the attempted authentication response.
46 . The method of claim 40 , wherein the attempted authentication response is adapted to be analyzed by a networked system, and wherein the networked system is a merchant computer that receives a card number and expiration date from the cardholder.
47 . A method comprising:
transmitting, by a cardholder system, an account number and an expiration date to a merchant system; receiving, by the cardholder system, an authentication request from the merchant system; transmitting, by the cardholder system, the authentication request to a central transaction server, the central transaction server configured to receive the authentication request from the cardholder system; forward the authentication request to an access control server; evaluate a response from the access control server, wherein the response is either an unintelligible response, or a non-response from the access control server in response to the forwarded authentication request; based on the evaluation, generate an attempted authentication response when the access control server does not reply or provides the unintelligible response, wherein:
the central transaction server generates the attempted authentication response independently of the access control server,
the attempted authentication response includes an indication of the determination regarding the no reply or the unintelligible response,
the attempted authentication response includes a uniform resource locator (URL) associated with the central transaction server instead of a URL associated with the access control server, and
forward the attempted authentication response to the cardholder system; and receiving the attempted authentication response from the central transaction server.
48 . The method of claim 47 , wherein the central transaction server is also configured to receive an authentication response from the access control server.
49 . The method of claim 48 , wherein the central transaction server is also configured to forward the authentication response to the cardholder system.
50 . The method of claim 47 , wherein the non-response from the access control server is determined if an authentication response is not received from the access control server within a predetermined period of time.
51 . The method of claim 47 , further comprising:
forwarding, by the cardholder system, the attempted authentication response to the merchant system.Join the waitlist — get patent alerts
Track US2017270520A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.