Authentication system and method for server-based payments
Abstract
A method of performing a payment transaction employing a two-factor authentication mechanism. In an embodiment, a user device operated by a user during a payment transaction engages in cryptographic processing with a cryptographic function having a secret key encoded therein. The cryptographic function is stored in a storage device of the user device, and the secret key serves as a first authentication factor. The method also includes the user device utilizing a second authentication factor, which was implemented using only software security techniques, in performing the payment transaction.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of performing a payment transaction employing two-factor authentication, the method comprising:
engaging, by a user device operated by a user during a payment transaction, in cryptographic processing with a cryptographic function having a secret key encoded therein, the cryptographic function stored in a storage device of the user device, the secret key serving as a first authentication factor; and utilizing, by the user device, a second authentication factor, implemented using only software security techniques, in performing the payment transaction.
2 . The method of claim 1 , wherein the second authentication factor is a biometric characteristic of the user of the user device.
3 . The method of claim 1 , wherein the second authentication factor is a secret code known to the user of the user device.
4 . The method of claim 3 , wherein the user device comprises one of a mobile telephone, a personal computer, and a tablet computer.
5 . The method of claim 4 , wherein the secret key was encoded in the cryptographic function during initialization of a payment application.
6 . The method of claim 5 , wherein the secret key was randomly generated by the payment application.
7 . The method of claim 5 , wherein the cryptographic processing comprises: receiving, by the user device from a remote server, an encrypted single use-key as part of the payment transaction; and
decrypting, by the user device, the encrypted single use-key by using the secret key.
8 . The method of claim 1 , wherein the user of the user device is permitted, during the payment transaction, to access a digital wallet assigned to the user and hosted in a wallet server.
9 . A user device operable by a user to perform a payment transaction employing two-factor authentication comprising:
a processor; a memory device operably coupled to the processor, wherein the memory device contains program instructions which when executed cause the processor to:
engage in cryptographic processing with a cryptographic function having a secret key encoded therein, the cryptographic function stored in the memory device, the secret key serving as a first authentication factor; and
utilize a second authentication factor which was implemented using only software security techniques in performing the payment transaction.
10 . The user device of claim 9 , further comprising a biometric sensor operably coupled to the processor, and wherein the second authentication factor comprises a biometric characteristic of the user.
11 . The user device of claim 9 , wherein the second authentication factor is a secret code known to the user.
12 . The user device of claim 11 , wherein the user device comprises one of a mobile telephone, a personal computer, and a tablet computer.
13 . The user device of claim 12 , wherein the secret key was encoded in the cryptographic function during initialization of a payment application.
14 . The user device of claim 13 , wherein the secret key was randomly generated by the payment application.
15 . The user device of claim 13 , wherein the memory device contains further program instructions which when executed cause the processor to:
receive an encrypted single use-key as part of the payment transaction from a remote server; and decrypt the encrypted single use-key by using the secret key.
16 . The user device of claim 9 , wherein the memory device contains further program instructions which when executed cause the processor to permit the user of the user device, during the payment transaction, to access a digital wallet assigned to the user and hosted by a wallet server.Join the waitlist — get patent alerts
Track US2021365938A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.