US2021365938A1PendingUtilityA1

Authentication system and method for server-based payments

Assignee: MASTERCARD INTERNATIONAL INCPriority: Jul 17, 2015Filed: Aug 5, 2021Published: Nov 25, 2021
Est. expiryJul 17, 2035(~9 yrs left)· nominal 20-yr term from priority
Inventors:Cristian Radu
G06Q 20/326H04W 12/04G06Q 20/3821G06Q 20/363G06Q 20/3674G06Q 20/4012H04L 63/0861H04W 12/35H04L 2463/082G06Q 20/385G06Q 20/388G06Q 20/3829G06Q 20/36G06Q 20/3823G06Q 20/4014G06Q 20/382G06Q 20/40145H04W 12/06G06Q 2220/00G06Q 20/32
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method of performing a payment transaction employing a two-factor authentication mechanism. In an embodiment, a user device operated by a user during a payment transaction engages in cryptographic processing with a cryptographic function having a secret key encoded therein. The cryptographic function is stored in a storage device of the user device, and the secret key serves as a first authentication factor. The method also includes the user device utilizing a second authentication factor, which was implemented using only software security techniques, in performing the payment transaction.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of performing a payment transaction employing two-factor authentication, the method comprising:
 engaging, by a user device operated by a user during a payment transaction, in cryptographic processing with a cryptographic function having a secret key encoded therein, the cryptographic function stored in a storage device of the user device, the secret key serving as a first authentication factor; and   utilizing, by the user device, a second authentication factor, implemented using only software security techniques, in performing the payment transaction.   
     
     
         2 . The method of  claim 1 , wherein the second authentication factor is a biometric characteristic of the user of the user device. 
     
     
         3 . The method of  claim 1 , wherein the second authentication factor is a secret code known to the user of the user device. 
     
     
         4 . The method of  claim 3 , wherein the user device comprises one of a mobile telephone, a personal computer, and a tablet computer. 
     
     
         5 . The method of  claim 4 , wherein the secret key was encoded in the cryptographic function during initialization of a payment application. 
     
     
         6 . The method of  claim 5 , wherein the secret key was randomly generated by the payment application. 
     
     
         7 . The method of  claim 5 , wherein the cryptographic processing comprises: receiving, by the user device from a remote server, an encrypted single use-key as part of the payment transaction; and
 decrypting, by the user device, the encrypted single use-key by using the secret key.   
     
     
         8 . The method of  claim 1 , wherein the user of the user device is permitted, during the payment transaction, to access a digital wallet assigned to the user and hosted in a wallet server. 
     
     
         9 . A user device operable by a user to perform a payment transaction employing two-factor authentication comprising:
 a processor;   a memory device operably coupled to the processor, wherein the memory device contains program instructions which when executed cause the processor to:
 engage in cryptographic processing with a cryptographic function having a secret key encoded therein, the cryptographic function stored in the memory device, the secret key serving as a first authentication factor; and 
 utilize a second authentication factor which was implemented using only software security techniques in performing the payment transaction. 
   
     
     
         10 . The user device of  claim 9 , further comprising a biometric sensor operably coupled to the processor, and wherein the second authentication factor comprises a biometric characteristic of the user. 
     
     
         11 . The user device of  claim 9 , wherein the second authentication factor is a secret code known to the user. 
     
     
         12 . The user device of  claim 11 , wherein the user device comprises one of a mobile telephone, a personal computer, and a tablet computer. 
     
     
         13 . The user device of  claim 12 , wherein the secret key was encoded in the cryptographic function during initialization of a payment application. 
     
     
         14 . The user device of  claim 13 , wherein the secret key was randomly generated by the payment application. 
     
     
         15 . The user device of  claim 13 , wherein the memory device contains further program instructions which when executed cause the processor to:
 receive an encrypted single use-key as part of the payment transaction from a remote server; and   decrypt the encrypted single use-key by using the secret key.   
     
     
         16 . The user device of  claim 9 , wherein the memory device contains further program instructions which when executed cause the processor to permit the user of the user device, during the payment transaction, to access a digital wallet assigned to the user and hosted by a wallet server.

Join the waitlist — get patent alerts

Track US2021365938A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.