Nova Patents
EP2368339B2

Secure transaction authentication

Abstract

This record has no abstract on file.

EP2368339B2, drawing sheet 1
Sheet 1 of 2

Term

Projected expiry 3 December 2029.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Projected expiry

15 claims: 8 independent, 7 dependent

  1. 1
    A method for authentication of a secure transaction to be conducted between a secure transaction host (15) and a transacting user (9), the method to be carried out at an authentication service provider and comprising the steps of:receiving an authentication request from the secure transaction host (15);receiving a digital identifier (13) containing a hardware identifier comprising an International Mobile Equipment Identity (IMEI) number and an International Mobile Subscriber Identity (IMSI) number from a mobile communications device (7) associated with the transacting user (9) whereby the mobile communications device may be uniquely identified, the digital identifier (13) having been created automatically, without user intervention, by an authentication application (59) installed on the mobile communications device as a function of the IMEI and the IMSI numbers of the hardware identifier and a random number created by the authentication application such that the digital identifier (13) cannot be re-created without the mobile communications device of the user (9) and thereby establishing a one-to-one association between the digital identifier and the mobile communications device (7) of the user (9), the digital identifier (13) being stored in a secure storage location (65) on the mobile communications device from where it is retrievable only by authorized applications including the authentication application (59);comparing the digital identifier (13) with a list of digital identifiers associated with mobile communications devices of pre-enrolled users stored on a database (5) associated with the authentication service provider;upon initiating of a secure communications link from the authentication application (59) on the mobile communications device (7), allowing a secure communications link to be established between the mobile communications device (7) of the transacting user (9) and the authentication service provider if the received digital identifier (13) corresponds to a digital identifier stored on the database (5);transmitting a transaction confirmation request to the mobile communications device (7) of the transacting user (9) over the secure communications link, the request requiring the user (9) to confirm or deny its intended performance of the secure transaction;receiving a confirmation or denial result from the mobile communications device (7) over the secure communications link;in response to a confirmation result, transmitting a positive authentication result to the secure transaction host (15);and in response to a denial result, transmitting a negative authentication result to the secure transaction host (15).
  2. 4
    A system (1) for authenticating a secure transaction conducted between a transacting user (9) and a secure transaction host (15), the system comprising:a mobile communications device authentication application (59) configured to be installed on a mobile communications device (7), to create automatically, without user intervention, a digital identifier (13) containing a hardware identifier comprising an International Mobile Equipment Identity (IMEI) number and an International Mobile Subscriber Identity (IMSI) number from the mobile communications device and the digital identifier being created as a function of the IMEI and IMSI numbers of the hardware identifier and a random number created by the authentication application such that the digital identifier cannot be re-created without the mobile communications device of the user (9), so as to establish a one-to-one association between the digital identifier and the mobile communications device (7) of the user (9) and whereby the mobile communications device (7) on which the authentication applications (59) is installed may be uniquely identified, and to store and retrieve the digital identifier (13) in and from a secure storage location (65) on the mobile communications device (7), wherein the digital identifier (13) is only retrievable from the secure storage location (65) by authorized applications including the authentication application (59);and an authentication service provider including at least one authentication server (3) and an authentication database (5) associated therewith;wherein the authentication server (3) is configured to enrol users by registering at least digital identifiers (13) created by the authentication application (59) installed on their mobile communications devices in the authentication database (5), each digital identifier (13) being uniquely capable of identifying the mobile communications device on which it was created;to receive an authentication request from the secure transaction host (15);to receive a digital identifier (13) from a mobile communications device (7) of the transacting user (9);to compare the received digital identifier (13) with a list of digital identifiers associated with mobile communications devices of pre-enrolled users stored in the database (5);upon initiating of a secure communications link from the authentication application (59) on the mobile communications device (7), to allow establishment of a secure communications link between the mobile communications device (7) of the transacting user (9) and the authentication server (3) if the received digital identifier (13) corresponds to a digital identifier stored on the database (5);to transmit a transaction confirmation request to the mobile communications device (7) of the transacting user (9) over the secure communications link, requesting the user (9) to confirm or deny its intended performance of the secure transaction;to receive a confirmation or denial result from the mobile communications device (7) of the transacting user (9) over the secure communications link;and to transmit a positive authentication result to the secure transaction host (15) in response to a confirmation result and a negative authentication result in response to a denial result.
  3. 7
    A system as claimed in any one of claims 4 to 6 in which the storage location (65) on the mobile communications device (7) is secure and accessible by the application (59) by means of Digital Rights Management features of an operating system operating on the mobile communications device (7).
  4. 9
    A system as claimed in any one of claims 4 to 8 in which the application (59) is configured to periodically create a new digital identifier using the IMEI number of the mobile communications device, the IMSI number of the SIM card being used in the mobile communications device and a newly generated random number.
  5. 11
    A system as claimed in any one of claims 4 to 10 in which an enrolment pass key is created and assigned to a user (9) when the application (59) is downloaded to its mobile communications device (7), the enrolment pass key entitling the user to enrol with the authentication server (3).
  6. 12
    A system as claimed in any one of claims 4 to 11 which includes an authentication web server (21) by means of which clients or client applications may interface with the authentication server (3).
  7. 13
    A system as claimed in any one of claims 4 to 12 in which the application (59) is configured to initiate a suitable alarm and pop-up that appears on the screen of the mobile communications device (7) of the transacting user (9) in response to the confirmation or denial request from the authentication server (3), the pop-up requesting the user (9) to confirm or deny its intended performance of the secure transaction by means of a key press.
  8. 15
    A system as claimed in any one of claims 4 to 13 in which the authentication service provider includes a plurality of authentication servers (3) driven by a load balancing server (29) that assigns servers to mobile communications devices of transacting users according to the loads on the respective servers.