EP1218841A2

Electronic commerce with cryptographic authentication

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 20 September 2020, 6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

79 claims: 22 independent, 57 dependent

  1. 1
    Claims of equivalent WO 0122322 A2 WHAT IS CLAIMED IS:1. A method of implementing an authentication transaction related to an electronic transaction between a vendor and a user, the method comprising: receiving a request for an authentication transaction from a vendor, wherein the authentication transaction is related to an electronic transaction involving the vendor and a user, and the authentication transaction includes a transaction identifier (TID);forwarding enrollment authentication data corresponding to the user and the TID to an authentication engine;querying the user for current authentication data and the TID;receiving the current authentication data along with the TID from the user and forwarding the current authentication data and the TID to the authentication engine;matching the enrollment authentication data to the current authentication data through the TID;and comparing the enrollment authentication data to the current authentication data in order to generate an authentication result.
  2. 2
    A method of implementing a cryptographic transaction related to an electronic transaction between a vendor and a user, the method comprising:associating a user from multiple users with one or more keys from a plurality of private cryptographic keys stored on a secure server, wherein the one or more keys are unknown to the user;receiving a request for a cryptographic transaction from a vendor, wherein the cryptographic transaction is related to an electronic transaction involving the vendor and the user and the cryptographic transaction includes a transaction identifier (TID);forwarding enrollment authentication data corresponding to the user and the TID to an authentication engine;querying the user for current authentication data and the TID;receiving the current authentication data along with the TID from the user and forwarding the current authentication data and the TID to the authentication engine;matching the enrollment authentication data to the current authentication data through the TID;comparing the enrollment authentication data to the current authentication data in order to generate an authentication result;and when the authentication result uniquely identifies the user, employing the one or more keys to perform one or more cryptographic functions.
  3. 11
    A method of facilitating a cryptographic function related to an electronic transaction, the method comprising:receiving at a trust engine, data corresponding to a transaction between at least a user and a vendor;receiving at the trust engine, a request from the vendor to obtain the digital signature of the user;and generating the digital signature at the trust engine by using at least one private cryptographic key associated with the user.
  4. 13
    A cryptographic system for performing cryptographic functions, the cryptographic system comprising:data corresponding to a transaction between at least a user and a vendor;a request from the vendor to obtain a digital signature of the user;and a cryptographic handling module which receives the data and the request, and which generates the digital signature by using at least one private cryptographic key associated with the user.
  5. 14
    A method of facilitating a cryptographic function related to an electronic transaction, the method comprising:receiving at a first entity, data about a transaction between at least a second entity and a third entity;receiving at the first entity, a request from the third entity to obtain the digital signature of the second entity;and signing at the first entity the transaction data using at least one private cryptographic key associated with the second entity.
  6. 15
    A method of facilitating a cryptographic function related to an electronic transaction, the method comprising:associating in a trust engine, a user from multiple users with one or more keys from a plurality of private cryptographic keys stored on the trust engine;receiving at a trust engine, transaction data related to a transaction between at least a user and a vendor;receiving at the trust engine, a request to digitally sign the transaction data;and signing the transaction data with the one or more keys associated with the user.
  7. 16
    A cryptographic system for performing cryptographic functions, the cryptographic system comprising:a computer readable storage medium storing a plurality of private cryptographic keys;transaction data related to a transaction between at least a user and a vendor;and a cryptographic handling module which associates the user with one or more keys of the plurality of private cryptographic keys, which receives the request and the transaction data, and which signs the transaction data with the one or more keys associated with the user.
  8. 17
    A method of facilitating a cryptographic function related to an electronic transaction, the method comprising:receiving transaction data that comprises a portion of an agreement between at least a first and second entity;receiving a request for a cryptographic function;and signing the transaction data with at least one private cryptographic key stored on a secure server.
  9. 18
    A method of facilitating a cryptographic transaction related to an electronic transaction between first and second users, the method comprising:receiving authentication data from a first user;receiving transaction data identifying a cryptographic transaction between the first user and a second user;comparing the authentication data to enrollment authentication data corresponding to the first user, thereby verifying the identity of the first user;utilizing at least one private cryptographic key stored on a secure server and unknown to either user to perform cryptographic functions relating to the cryptographic transaction without releasing the at least one private cryptographic key to either user;and upon authentication of the identity of at least the first user, transmitting data related to the cryptographic transaction to one of the first and second users, without including additional cryptographic keys.
  10. 24
    A method of increasing the speed of an authentication process by performing various authentication steps in parallel, the method comprising:receiving a request for a cryptographic function related to an electronic transaction involving a vendor and a user;processing the cryptographic function while awaiting authentication data from the user;receiving the authentication data from the user;and transmitting response related to the cryptographic function when the authentication data from the user uniquely identifies the user.
  11. 29
    A method of increasing the speed of an authentication process by performing various authentication steps in parallel, the method comprising:receiving an authentication request from a vendor wherein the authentication request is related to an electronic transaction involving the vendor and a user;retrieving enrollment data associated with the user while awaiting authentication data from the user;and receiving the authentication data from the user and comparing the authentication data to the retrieved enrollment data.
  12. 40
    A method of conducting an authentication transaction to secure an electronic transaction, the method comprising:receiving an authentication request associated with an electronic transaction from a first user;receiving data from a second user, the data comprising authentication data generated by the second user and circumstantial data associated with the generation of the authentication data;determining a level of trust associated with the authentication data, the level of trust based in part upon the circumstantial data;and providing a response to the authentication request to one of the first user and the second user indicating that the second user has been authenticated.
  13. 47
    A method for conducting an authentication transaction to provide security for an electronic transaction, the method comprising:receiving authentication data from a first user, wherein the authentication data is associated with an authentication transaction;obtaining data corresponding to the circumstances surrounding the process of entering the authentication data;determining a reliability for the authentication data based upon the obtained data;comparing the authentication data to previously stored enrollment data;generating a level of trust for the authentication data associated with the authentication transaction;and providing a response for use in the transaction.
  14. 56
    A system for authenticating an electronic transaction between a first user and a second user, comprising:authentication data received from a first user and associated with an authentication transaction;circumstantial data corresponding to the circumstances surrounding the authentication data;reliability data associated with the authentication data and based upon the circumstantial data;enrollment data associated with the first user;and a trust engine which compares the authentication data to the enrollment data and generates a level of trust for the authentication data and provides the level of trust for use authenticating the first user.
  15. 59
    An apparatus that provides cryptographic functions by interconnecting a client-side application programming interface with a network-based trust engine, comprising:a client-side application programming interface that is configured to operate on a client computer;a service provider module that is in communication with the application programming interface and in communication with a network-based trust engine, wherein the service provider module is configured to request cryptographic functions from the network-based trust engine.
  16. 63
    A method for performing security functions with a network-based cryptographic server, comprising:receiving at a user system, a request for a security function from an application programming interface;and routing the request to a network-based cryptographic server.
  17. 67
    An apparatus for making security functions available to a user system from a network based cryptographic server, comprising:a cryptographic service provider module in communication with an application programming interface of a user system, the cryptographic service provider module receiving requests from the applications programming interface of a user system;and a cryptographic server in communication with the cryptographic service provider module across a communication link, the cryptographic server providing responses to requests from the cryptographic service provider module across the communication link.
  18. 70
    A method of providing a cryptographic service with a network accessible server, comprising:receiving a request for a cryptographic service from an application programming interface;preparing a request for cryptographic functions, the cryptographic functions being necessary to provide the requested cryptographic service to the application programming interface;sending the request for cryptographic functions to a server across a communications link;receiving a result based upon the request for cryptographic functions from the server;preparing a response to the request for the cryptographic service based upon the result received from the server;and sending the response to the request for the cryptographic server available to the application programming interface.
  19. 71
    A method of performing cryptographic functions with a network-based cryptographic server, comprising:receiving an authentication request from an application programming interface;and processing the authentication request with a remotely located server.
  20. 75
    A method of performing authentication functions with a network-based trust engine, comprising:receiving at a user computer, a request for an authentication function from an application programming interface;and routing the request to a network-based trust engine.
  21. 78
    A method of interconnecting a cryptographic application programming interface with a network accessible resource, comprising:a cryptographic application programming interface on a client computer;and a cryptographic service provider module that is in communication with the cryptographic application programming interface wherein the cryptographic service provider is configured to perform cryptographic functions via a network accessible resource.
  22. 79
    An apparatus for providing cryptographic functions to a user system from a remote trust engine comprising a cryptographic service provider module in communication with an application programming interface of the user system, the cryptographic service provider module receiving a request for cryptographic functions from the application programming interface, and the cryptographic service provider module connected to a network accessible trust engine via a communication link, the trust engine providing a response to a requests for cryptographic functions from the cryptographic service provider module.
Independent claims22