IL149203A

Method and system for secure authenticated payment on a computer network

Abstract

A simple, secure and easy-to-deploy method and system for authenticating credit and debit cardholders at the point-of-sale on a computer network (e.g., the Internet) is disclosed. Cardholders are authenticated using digital signatures on a sales draft, in a manner that does not necessarily require any changes in the transaction flow of the participating financial institutions.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

47 claims: 6 independent, 41 dependent

  1. 1
    13 149203/3 CLAIMS:1. A method for authenticating an electronic payment comprising: receiving from a seller an electronic sales draft including an electronic signature, said electronic sales draft being digitally signed using a private key associated with a public key;receiving from said seller a digital certificate associated with a buyer, said digital certificate including a first verification key and an encrypted version of a personal identification number (PIN), said digital certificate including a binding between at least a portion of said financial account datum and said public key using a second verification key associated with a trusted party performing said binding;using said first verification key to verify that said electronic signature was authorized by said buyer;extracting said encrypted version of said PIN from said digital certificate;decrypting said encrypted version of said PIN using said second verification key or a key associated with said second verification key, thereby verifying said first verification key was bound using said second verification key by said trusted party that performed said binding;generating, using said PIN, an authorization request;sending said authorization request to a financial institution;receiving an approval of said authorization request from said financial institution;and sending said approval to said seller.
  2. 2
    A method for authorizing an electronic purchase in a networked computer environment, comprising the steps of:(a) receiving, from a merchant, a transaction authorization request including a digital certificate passed through said merchant from a user involved in said transaction and a transaction order that was digitally signed by said user using a private key associated with a public key, (i) said digital certificate including a financial account datum associated with said user as well as said public key of said user, (ii) said digital certificate also including a binding between at least a portion of said financial account datum and said public key of said user using a cryptographic verification key associated with a trusted party performing said binding;01387117\25-01 14 149203/3 (b) verifying said binding using said cryptographic verification key or a key associated with said cryptographic verification key, thereby verifying said public key was bound using said cryptographic verification key by said trusted party that performed said binding;and 5 (c) using said financial account datum to authorize said transaction order digitally signed by said user with said private key corresponding to said public key.
  3. 15
    16. A method for providing electronic payment capabilities to a user in a networked computer environment, comprising the steps of:(a) obtaining a financial account datum associated with said user;(b) obtaining a public key associated with said user;(c) obtaining a cryptographically assured binding of said public key to at least a portion of said financial account datum using a cryptographic verification key associated with a trusted party performing said binding, (i) said financial account datum, said public key, and said binding being included in a digital certificate for said user, (ii) said digital certificate being usable by said user to conduct an electronic transaction involving said financial account datum;and (d) transmitting said digital certificate to said user, enabling said user to conduct said electronic transaction involving (i) a merchant, and (ii) a transaction processor capable of verifying said binding using said cryptographic verification key or a key associated with said cryptographic verification key, thereby verifying said public key was bound using said cryptographic verification key by said trusted party that performed said binding.
  4. 34
    37. An apparatus for providing electronic payment capabilities to a user in a networked computer environment, comprising:(a) a processor, 20 (b) a memory connected to said processor storing a program to control the operation of said processor;(c) the processor operable with said program in said memory to: (i) obtain a financial account datum regarding said user, (ii) obtain a public key associated with said user, 25 (iii) obtain a cryptographically assured binding of said public key to at least a portion of said financial account datum using a cryptographic verification key associated with a trusted party performing said binding, (1) said financial account datum, said public key, and said binding being included in a digital certificate for said user, 30 (2) said digital certificate being usable by said user to conduct an electronic transaction involving said financial account datum, and 01387117\25-01 18 149203/3 (iv) transmit said digital certificate to said user, enabling said user to conduct said electronic transaction involving (1) a merchant, and (2) a transaction processor capable of verifying said binding using said cryptographic verification key or a key associated with said cryptographic verification key, 5 thereby verifying said public key was bound using said cryptographic verification key by said trusted party that performed said binding.
  5. 38
    42. A computer-readable storage medium encoded with processing instructions for 15 implementing a method for authorizing an electronic purchase in a networked computer environment, said processing instructions for directing a computer to perform the steps of (a) receiving, from a merchant, a transaction authorization request, said request including a digital certificate passed through said merchant from a user involved 20 in said transaction and a transaction order that was digitally signed by said user using a private key associated with a public key, (i) said digital certificate including a financial account datum associated with said user as well as a public key of said user, (ii) said digital certificate also including a binding between at least a 25 ' portion of said financial account datum and a public key of said user using a cryptographic verification key associated with a trusted party performing said binding;(b) verifying said binding using a cryptographic verification key or a key associated with said cryptographic verification key, thereby verifying said public key 30 was bound using said cryptographic verification key by said trusted party that performed said binding;and 01387117\25-01 19 149203/3 (c) using said financial account datum to authorize said transaction order digitally signed by said user with said private key corresponding to said public key.
  6. 43
    47. A computer-readable storage medium encoded with processing instructions for implementing a method for providing electronic payment capabilities to a user in a networked computer environment, said processing instructions for directing a computer to perform the steps of:(a) obtaining a financial account datum regarding said user;(b) obtaining a public key associated with said user;(c) obtaining a cryptographically assured binding of said public key to at least a portion of said financial account datum using a cryptographic verification key associated with a trusted party performing said binding, (i) said financial account datum, said public key, and said binding being included in a digital certificate for said user, (ii) said digital certificate being usable by said user to conduct an electronic transaction involving said financial account datum;and (d) transmitting said digital certificate to said user, enabling said user to conduct said electronic transaction involving (i) a merchant, and (ii) a transaction processor capable of verifying said binding using aid cryptographic verification key or a key associated with said cryptographic verification key, thereby verifying said public key was bound using said cryptographic verification key by said trusted party that performed said binding.