System and method of associating communication devices to secure a commercial transaction over a network
Claim Score by NHIP
Abstract
A system and a method for associating communication devices like a computing device and a wireless portable device so as to carry out secure transactions over an untrusted network like the Internet are disclosed. The communication devices are assumed to be independently capable of communicating with an electronic commerce site managing a directory of legitimate users which all possess a token like a smart-card. Whenever a user desires to carry out a secure transaction, the user initially prepares the transaction from a first communication device like a personal computer. When completed with the preparation, a signature of the user is obtained from a second communication device like a mobile phone through which the legitimate user is reachable and which is enabled with the token of the user. When contacted from the electronic commerce site, the second communication device is used to check, validate, sign and transmit the signed secure transaction to the electronic commerce site where final processing of the commercial transaction can be completed.

Term
Term ended
Projected expiry passed 27 February 2021, 5.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
22 claims: 6 independent, 16 dependent
- 1Broadest claimClaim Score 79, broad(NHIP)A method for associating a commerce site, a first communication device, and a second communication device in executing a commercial transaction over a network, said method comprising:operating the first communication device and the commerce site to prepare and approve the commercial transaction;operating the commerce site to provide a signature request to the second communication device upon an approval of the commercial transaction;and operating the second communication device to provide a signature to the commerce site in response to said signature request.
- 3A method for associating a first communication device and a commerce site after a preparation and an approval of a commercial transaction by a second communication device and the commerce site, said method comprising:operating the commerce site to retrieve an identification record corresponding to a user of the first communication device and the second communication device;operating the commerce site to establish a communication link between the first communication device and the commerce site in response to said identification record;and operating the commerce site to provide a signature request to the first communication device upon an establishment of the communication link.
- 7A method for completing a commercial transaction prepared and approved by a first communication device and a commerce site, said method comprising:operating the commerce site to provide a signature request to a second communication device;operating said second communication device to examine said signature request;operating said second communication device to identify a user of the first communication device and the second communication device;and operating said second communication device provide a signature for the commercial transaction in response to an identification of said user.
- 9A system for completing a commercial transaction, said system comprising:a first communication device;a second communication device;and a server running a commerce site, wherein said first communication device and said server are operable to prepare and approve the commercial transaction, wherein said server is further operable to provide a signature request to said second communication device upon an approval of the commercial transaction, and wherein said second communication device is operable to provide a signature to said server in response to said signature request.
- 21A computer program product in a computer usable medium for associating a first communication device and a commerce site after a preparation and an approval of a commercial transaction by a second communication device and the commerce site, said program comprising:a means for retrieving an identification record corresponding to a user of the first communication device and the second communication device;a means for establishing a communication link between the first communication device and the commerce site in response to the identification record;and a means for providing a signature request to the first communication device upon an establishment of the communication link.
- 22A computer program product in a computer usable medium for completing a commercial transaction prepared and approved by a first communication device and a commerce site, said program comprising:a means for examining a signature request from the commerce site;a means for identifying a user of the first communication device;and a means for providing a signature for the commercial transaction in response to an identification of the user.
Independent claims6
34 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
[0001] 1. Field of the Invention
[0002] The present invention relates generally to the electronic commerce and more particularly applies to commercial-like transactions taking place over a network like the Internet that requires confidentiality, authentication, integrity, and non-repudiation.
[0003] 2. Description of the Related Art
[0004] Commerce over the Internet is dramatically expanding. It involves all sorts of transactions implying the movement of electronic money. All of this is taking place over what is, basically, a very unsecured network. Therefore, based on cryptography, numerous techniques and methods have been devised not only ensuring confidentiality of the transactions but also, this is often even more important, authentication, integrity and non-repudiation. Authentication is required to ascertain the origin of a transaction so as no one should be able to masquerade as someone else. Integrity is key to make sure that a transaction has not been modified, unintentionally or maliciously, on its way through the network to a destination, e.g., a server aimed at processing the customer orders. Finally, non-repudiation is essential to make sure that a completed transaction, that may involve a lot of money, may not just be denied later on by any of the participants.
[0005] Accessing the Internet is mainly achieved nowadays from a personal computer (PC), a workstation (WS) or any other similar computer device capable of running a piece of browser software in order to be able to get on the World-Wide Web (Web). The Web is a ubiquitous application that has accompanied the explosive growth of the Internet in past years. Thus, an Internet commerce site is a particular Web site aimed at handling commercial transactions. A well-known site is located at http://www.amazon.com/. It is a huge virtual bookstore selling also music and videos. The site claims that millions of people from many countries have indeed made online shopping on the site. Although such sites also claim they are completely safe, such sites actually fail to satisfactorily meet confidentiality, authentication, integrity and non-repudiation. To attempt to reach these objectives, a computer device would need to be equipped with a smart card reader and a user would have to carry a token, e.g., an intelligent chip-card or a smart-card, so that authentication based on the knowledge (personal identification number or password) and possession (token) principle can be carried out. Smart-cards are also suitable for securely storing certificates and encryption keys. Smart cards with an integrated crypto-processor can implement cryptographic functions directly on the card so that the keys never leave the smart card. For example, a smart card may implement an encrypted digital signature with a user private key appended to it. A recipient may therefore check the transaction with a user public key and make sure that the transaction has not been altered on its way and has originated by the person possessing the corresponding user private key. This eliminates any possibility of the key falling into the wrong hands.
[0006] However, all of this is only possible if the computer device is indeed equipped with the proper hardware, e.g., a card reader and the corresponding software or device driver to perform the adaptation with the operating system (OS) running on the computer device. This is a new technology and a new type of I/O port to be added to the computer device. This has a cost which does not fit well with the general trend that wants to reduce as much as possible the operational expenses of a private or enterprise network to thereby lower the cost of terminal equipment and total cost of ownership. Thus, in practice, computer devices are still seldom equipped with such card readers. Although a separate chip card reader can always be later added to a particular computer device, separate chip card readers require the installation of corresponding software and device driver(s).
[0007] Another even more explosive market is the one of mobile wireless communications. This market was initially driven by mobile digital cellular phones, but is rapidly evolving to cover other applications in relation with the Internet such as e-mail. It is anticipated that electronic commerce applications such as personal banking, stock trading, gambling, ticket reservations and shopping will soon become commonly available on mobile phones. Hence, the security of data communications over wireless networks has become a major concern to mobile commerce businesses and users. This concern has triggered the development of products to build secure systems that solve the core requirements of confidentiality, authentication, integrity and non-repudiation for electronic commerce security. Also, standards are being put in place to control the development of such products and make sure that they may inter operate. The Wireless Application Protocol (WAP) Forum (http://www.wapforum.org) has thus become the de facto worldwide standard for providing Internet communications and advanced telephony services on digital mobile phones, pagers, personal digital assistants and other wireless terminals. Therefore, all these mobile devices, contrary to computer devices, are promised to be up-front equipped with all necessary features and functions so as to guarantee security of electronic commerce transactions. Nevertheless, mobile phones all have inherent limited display capability and a rudimentary user interface along with limited processing power, battery life and storage capabilities.
[0008] It is desirable therefore to provide a method and a system that combine the display and user interface capabilities of a computer device and the built-in security features of wireless mobile devices to facilitate convenient and secure electronic commerce transactions.
SUMMARY OF THE INVENTION
[0009] A first form of the present invention is a method for associating a commerce site, a first communication device, and a second communication device in executing a commercial transaction over a network. The first communication device and the commerce site are operated to prepare and approve the commercial transaction. The commerce site is operated to provide a signature request to the second communication device upon approval of the commercial transaction. The second communication device is operated to provide a signature to the commerce site in response to the signature request.
[0010] A second form of the present invention is a method for associating a first communication device and a commerce site after a preparation and an approval of a commercial transaction by a second communication device and the commerce site. The commerce site is operated to retrieve an identification record corresponding to a user of the first communication device and the second communication device. The commerce site is operated to establish a communication link between the first communication device and the commerce site in response to the identification record. The commerce site is operated to provide a signature request to the first communication device upon an establishment of the communication link.
[0011] A third form of the present invention is a method for completing a commercial transaction prepared and approved by a first communication device and a commerce site. A second communication device is operated to examine a signature request from the commerce site. The second communication device is operated to identify a user of the first communication device. The second communication device is operated to provide a signature for the commercial transaction in response to an identification of the user.
[0012] A fourth form of the present invention is a system for executing a commercial transaction. The system comprises a first communication device, a second communication device, and a server running a commerce site. The first communication device and the server are operable to prepare and approve the commercial transaction. The server is further operable to provide a signature request to the second communication device upon an approval of the commercial transaction. The second communication device is operable to provide a signature to the server in response to the signature request.
[0013] A fifth form of the present invention is a computer program product in a computer usable medium for associating a first communication device and a commerce site after a preparation and an approval of a commercial transaction by a second communication device and the commerce site. The program includes the following means. A means for retrieving an identification record corresponding to a user of the first communication device and the second communication device. A means for establishing a communication link between the first communication device and the commerce site in response to the identification record. And, a means for providing a signature request to the first communication device upon an establishment of the communication link.
[0014] A sixth form of the present invention is a method a computer program product in a computer usable medium for completing a commercial transaction prepared and approved by a first communication device and a commerce site. The program includes the following means. A means for examining a signature request from the commerce site. A means for identifying a user of the first communication device. And, a means for providing a signature for the commercial transaction in response to an identification of the user.
[0015] Further forms, objects, features and advantages of the present invention will become apparent to the ones skilled in the art upon examination of the following description in reference to the accompanying drawings. It is intended that any additional advantages are incorporated herein.
BRIEF DESCRIPTION OF THE DRAWINGS
[0016]FIG. 1 illustrates one embodiment of a computer device and one embodiment of a wireless portable device in accordance with the present invention;
[0017]FIG. 2 is a data flow chart of one embodiment of a commercial transaction in accordance with the present invention;
[0018]FIG. 3 is an exemplary correlation table of identification records in accordance with the present invention; and
[0019]FIG. 4 illustrates one embodiment of a secured system in accordance with the present invention.
DETAILED DESCRIPTION OF PREFERRED EMBODIMENT
[0020] Referring to FIG. 1, a computing device in the form of a personal computer <b>110</b> (hereinafter “PC <b>110</b>”) and a wireless portable device in the form of a mobile telephone <b>140</b> are shown. PC <b>110</b> provides a user <b>100</b> with access to a commercial Internet Web site to perform a transaction, e.g., the AMAZON.COM virtual bookstore at http://www.amazon.com to perform a transaction such as buying a book. This can be done by having a communication link <b>130</b> from PC <b>110</b> to a network <b>135</b> such as the Internet and running a browser on PC <b>110</b> that is capable of conveniently displaying pages from the Web site whereby user <b>100</b> can gather all necessary information on what user <b>100</b> is buying. PC <b>110</b> is equipped with a display monitor <b>120</b> preferably having at least a 5-inch wide screen (diagonal) capable of displaying 800×600 pixels or more. PC <b>110</b> is also equipped with an input device in the form of a keyboard <b>121</b> preferably having at least 100 keys and a pointing device in the form of a mouse <b>122</b>.
[0021] User <b>100</b> can also establish a communication link <b>165</b> from mobile telephone <b>140</b> to network <b>116</b>. Mobile telephone <b>140</b> is personalized to user <b>100</b> with a token in the form of a smart card <b>155</b> whereby user <b>100</b> may be uniquely identified. As compared to PC <b>110</b>, mobile telephone <b>140</b> includes a display <b>160</b> that is limited to a few lines of a few characters, and a rudimentary numeric keyboard <b>150</b>.
[0022] Referring additionally to FIG. 4, a secured system <b>101</b> in accordance with the present invention in shown. System <b>101</b> comprises PC <b>110</b>, mobile phone <b>140</b>, network <b>135</b>, and a server <b>200</b>. Server <b>200</b> includes a software and data package <b>201</b> having a business application <b>210</b>, a signature correlation servlet <b>220</b>, and a table <b>300</b> consisting of identification records of people/businesses having authorization to access business application <b>210</b>. A commercial transaction in accordance with the present invention initially involves user <b>100</b> running PC <b>110</b> to access business application <b>210</b> on server <b>200</b> over network <b>135</b> via communication link <b>130</b> and a communication link <b>190</b>. Business application <b>210</b> is a core of a commercial-like site that user <b>100</b> wants to deal with. User <b>100</b> approves the commercial transaction when user <b>100</b> is satisfied with the contents and the objects of the transaction. Upon receipt of the approval, business application <b>210</b> uses table <b>300</b> to identify an identification record of user <b>100</b>. Upon identifying an identification record of user <b>100</b>, servlet <b>220</b> contacts mobile phone <b>140</b> through network <b>135</b>, a gateway <b>175</b>, and a tower <b>170</b> via communication link <b>190</b>, a communication link <b>191</b>, a communication link <b>192</b>, and communication link <b>165</b>. Servlet <b>220</b> then sends a signature request to mobile phone <b>140</b> according to the Wireless Application Protocol (WAP). User <b>100</b> uses a private key of smart card <b>155</b> to sign for the commercial transaction. Business application <b>210</b> and servlet <b>220</b> complete the transaction upon receipt of the signature of user <b>100</b>. Those having ordinary skill in the art will appreciate that the commercial transaction meets all the goals of confidentiality, authentication, integrity and non-repudiation.
[0023] Referring to FIGS. 2 and 4, a more detailed embodiment of a commercial transaction in accordance with the present invention as implemented by user <b>100</b> involving system <b>101</b> will now be described herein. A complete execution of the commercial transaction consists of a preparation phase P<b>1</b>, an approval phase P<b>2</b>, a signature request phase P<b>3</b>, a signature phase P<b>4</b>, and a transaction completion phase P<b>5</b>. In one embodiment, PC <b>110</b> and mobile phone <b>140</b> both include a computer program product within a computer readable medium for performing the applicable acts that are described in FIG. 2. From the following description of FIG. 2, those having ordinary skill in the art will appreciate that the commercial transaction can be implemented by user <b>100</b> involving alternative embodiments of system <b>101</b> that comprise a computing device other than PC <b>110</b> and/or a wireless portable device other than mobile phone <b>140</b>. Those having ordinary skill in the art will also appreciate that the commercial transaction can be implemented by user <b>100</b> involving alternative embodiments of system <b>101</b> that comprise a communication device other than a computing device and/or a wireless portable device.
[0024] The commercial transaction is initiated from PC <b>110</b> during a stage S<b>111</b> when user <b>100</b> utilizes PC <b>100</b> to access business application <b>210</b> on server <b>200</b> over network <b>116</b>. Server <b>200</b> runs business application <b>210</b> for setting up a commerce site for user <b>100</b>. For example, business application <b>210</b> can be for setting up the AMAZON.COM virtual bookstore. During a stage S<b>211</b>, business application <b>210</b> request client authentication from user <b>100</b>. During a stage S<b>112</b>, user <b>100</b> responds to the authentication request by complying with whatever method is in effect in server <b>200</b>. For example, user <b>100</b> can provide credentials to be recognized as a legitimate user. In one embodiment, user <b>100</b> sends a user ID with a password to server <b>200</b>. Other embodiments may require user <b>100</b> and/or server <b>200</b> to send certificates issued by a third party trusted by user <b>100</b> and owners of server <b>200</b>, e.g., a CA (Certificate Authority).
[0025] During a stage S<b>212</b>, server <b>200</b> authenticates user <b>100</b> unless user <b>100</b> fails to timely and satisfactorily response to the authentication request of stage S<b>211</b> in which case the transaction is aborted by server <b>200</b>. All of this can actually be implemented from various well-known methods known by those skilled in the art. Many variants exist. In one embodiment, certificates could be X.509 certificates as described in RFC2459 of the Request For Comments of the Internet Engineering Task Force used by the Web browsers supporting Secure Socket Layer protocol which is being standardized under the name of Transport Layer Security protocol in RFC2246. As far as server <b>200</b> is concerned, the only other assumption is that it is capable of generating static and dynamic Hyper Text Markup Language pages that can be viewed from PC <b>110</b> by user <b>100</b>.
[0026] When user <b>100</b> has been recognized as a legitimate user by server <b>200</b>, user <b>100</b> is then permitted during a stage S<b>113</b> to browse the HTML pages of business application <b>210</b> so as to gather all the necessary information regarding the commercial transaction user <b>100</b> wants to perform. This assumes that multiple exchanges may have to take place between PC <b>100</b> and server <b>200</b> during stage S<b>113</b> and a stage S<b>213</b>, and generally requires that user <b>100</b> fill virtual forms during a stage S<b>114</b> such as dynamic HTML pages formatted by server <b>200</b> during a stage S<b>214</b>. Server <b>200</b> interprets the content of the virtual forms so as to determine what user <b>100</b> intends to do. For example, when the business application <b>210</b> is for AMAZON.COM, a virtual shopping cart is filled with that which user <b>100</b> desires to acquire. While filling the virtual shopping cart, user <b>100</b> has the option of returning to stage S<b>113</b> to review and consult all of the information and data provided by server <b>200</b> during stage S<b>213</b> that relates to the commercial transaction before proceeding to a virtual cash register.
[0027] Upon being satisfied with the contents of the transaction, user <b>100</b> uses PC <b>110</b> to approve the commercial transaction during a stage S<b>115</b>. For example, user <b>100</b> can proceed to stage S<b>115</b> when user <b>100</b> has finished filling the virtual shopping cart at AMAZON.COM. Also by example, user <b>100</b> can proceed to stage S<b>115</b> when user <b>100</b> has finalized a list of shares he wants to sell or buy through a preferred broker. Obviously, although not explicitly shown, user <b>100</b> always has the freedom of aborting the commercial transaction any time before completion. Also, the commercial transaction may be aborted due to any malfunction of PC <b>110</b>, network <b>135</b>, and/or server <b>200</b> such as an interruption of communication link <b>115</b> and/or communication link <b>190</b>. However, normally, the transaction is approved by user <b>100</b> from PC <b>110</b>.
[0028] During a stage S<b>216</b>, server <b>200</b> desires to obtain a signature of user <b>100</b>. In one embodiment, server <b>200</b> manages table <b>300</b> for cross-referencing an user identification (ID) of user <b>100</b> along with a corresponding mobile device ID of mobile phone <b>140</b> and a public key that is encrypted on smart card <b>155</b>. An example of table <b>300</b> is shown in FIG. 3. Referring to FIG. 3, table <b>300</b> lists users IDs in a column <b>310</b> that are recognized by server <b>200</b> as being legitimate users authorized to deal with business application <b>220</b>. For each registered user, table <b>300</b> lists a corresponding mobile device ID number in column <b>320</b> and a corresponding user public key in column <b>330</b>. Each row of user ID, mobile device ID, and user public key constitutes an identification record of the corresponding user such as identification record <b>340</b>. The precise form under which table <b>300</b> is actually implemented and the way it is searched when interrogated is beyond the scope of the invention. Those having ordinary skilled in the art will recognize that numerous alternate ways are feasible, e.g., tailored to favor performance or memory size required. As an example, table <b>300</b> could be implemented to obey the specifications of a Lightweight Directory Access Protocol (LDAP). LDAP is a protocol for accessing on-line directory services defined by the Internet Engineering Task Force in Request For Comments (RFC), especially RFC <b>777</b>. LDAP defines a relatively simple protocol for updating and searching directories running over the Internet suite of protocols (TCP/IP). An LDAP directory entry is a collection of attributes with a name, called a distinguished name (DN). The DN refers to the entry unambiguously. Each of the entry's attributes has a type and one or more values.
[0029] The types are typically mnemonic strings, like “cn” for common name, or “mail” for e-mail address. LDAP directory entries are arranged in a hierarchical structure that reflects political, geographic, and/or organizational boundaries. Entries representing countries appear at the top of the tree. Below them are entries representing states or national organizations. Below them might be entries representing people, organizational units, printers, documents, or just about anything else. Therefore, cross-referencing table <b>300</b> of the invention can advantageously be implemented under the form of a customized LDAP directory.
[0030] Referring again to FIGS. 2 and 4, during stage S<b>215</b>, server <b>200</b> retrieves a phone number for mobile phone <b>140</b> and a user public key for smart card <b>155</b> from table <b>300</b> that corresponds to user <b>100</b>. During a stage S<b>216</b>, business application <b>210</b> formats the transaction data to provide a signature request to PC <b>110</b>. Business application <b>210</b> optionally signs the signature request using the user smart-card public key and optionally countersigns the signature request with a server private key whereby user <b>100</b> needs to be certain of the origin of the transaction. During a stage S<b>221</b>, servlet <b>220</b> dials mobile phone <b>140</b> using standards for allowing server <b>200</b> to deliver data to a mobile phone <b>140</b> even though mobile phone <b>140</b> has not issued any request for the data. During a stage S<b>222</b>, servlet <b>220</b> awaits a response from mobile device <b>140</b>. In one embodiment, signing servlet <b>220</b> is a Java™ Servlet. While Java™ is, among other things, a popular, simple, object-oriented, distributed and interpreted general-purpose programming language developed by Sun Microsystems (Sun Microsystems, Inc., 90 San Antonio Road, Palo Alto, Calif. 940 USA.), a Java™ Servlet is a small, platform-independent Java™ program that can be used to extend the functionality of server <b>200</b> in a variety of ways. Thus, a Java™ Servlet is convenient to implement the signing function of the invention. Those having ordinary skill in the art of the invention will recognize that, without departing from the spirit of the invention, it may be implemented in many alternate equivalent ways. In one embodiment, signature request phase P<b>3</b> is completely imbedded within business application <b>210</b>.
[0031] Upon an acceptance by user <b>100</b> of an incoming call from server <b>200</b>, during a stage S<b>141</b>, smart-card <b>155</b> checks the generated transaction content that is optionally signed with a user public key and optionally countersigned with a server private key to ascertain its origin if necessary. During a stage S<b>142</b>, user <b>100</b> is prompted to validate the transaction. At this point user <b>100</b> may want to review the content of the transaction received on mobile phone <b>140</b> (which is sufficient in general to be sure what transaction is being signed). In one embodiment, the transaction may be displayed on mobile screen <b>160</b>, preferably in an abridged form for the sake of convenience due to the limited capacity of the display of such devices. In another embodiment, a number associated with the transaction may be displayed on mobile screen <b>160</b>. This is a common practice when dealing with a server such as server <b>200</b> or ordering goods or services over the phone. This transaction number may thus be used as a correlator so user <b>100</b> is made certain of what transaction is being validated.
[0032] During a stage S<b>143</b>, smart-card <b>155</b> requests a form of identification of user <b>100</b>. In one embodiment, smart-card <b>155</b> requests a personal identification number (PIN) from user <b>100</b>. In another embodiment, smart-card <b>155</b> requests biometric data in the form of finger prints or other identifying marks of user <b>100</b> that are recognized through an appropriate sensor placed on smart-card <b>155</b>. This will add definitively to the security hence, better contributing to reach the goals of authentication, integrity and non-repudiation. Smart-card <b>155</b> signs the transaction using a user private key during a stage S<b>144</b> upon receipt of the identification, and sends the signed transaction to server <b>200</b> during a stage S<b>145</b>. At this point, the signature phase P<b>4</b> to carry out signature of the secure transaction in mobile device <b>140</b> is over.
[0033] During a stage S<b>223</b>, servlet <b>220</b> receives the signed transaction to complete a signature cycle of the transaction. During a stage S<b>217</b>, business application <b>210</b> performs a checking step in server <b>200</b> utilizing user public key. If the result of the checking step is positive, business application <b>210</b> formats a transaction status indicating an approval of the transaction during a stage S<b>218</b>. User <b>100</b> views the transaction status during a stage S<b>116</b>.
[0034] While the embodiments of the present invention disclosed herein are presently considered to be preferred, various changes and modification can be made without departing from the spirit and scope of the present invention. The scope fo the present invention is indicated in the appended claims, and all changes that come within the meaning and range of equivalents are intended to be embraced therein.
Contents4
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2011080719A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2007134010A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2007521586A | Cited by | Japan | Search report |
| US2011025282A1 | Cited by | United States of America | Pre-grant |
| US11501218B2 | Cited by | United States of America | Search report |
| US7366913B1 | Cited by | United States of America | Search report |
| US9285840B2 | Cited by | United States of America | Applicant |
| WO2011126756A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7004388B2 | Cited by | United States of America | Search report |
| US8312475B2 | Cited by | United States of America | Applicant |
| US2004133784A1 | Cited by | United States of America | Pre-grant |
| US7194438B2 | Cited by | United States of America | Search report |
| US7562813B2 | Cited by | United States of America | Applicant |
| US7178027B2 | Cited by | United States of America | Search report |
| US2008189357A1 | Cited by | United States of America | Pre-grant |
| US2007262134A1 | Cited by | United States of America | Pre-grant |
| US7014107B2 | Cited by | United States of America | Search report |
| US2006016878A1 | Cited by | United States of America | Pre-grant |
| WO2011080719A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2009083763A1 | Cited by | United States of America | Pre-grant |
| FR3015821A1 | Cited by | France | Search report |
| US2015227929A1 | Cited by | United States of America | Search report |
| US2009119364A1 | Cited by | United States of America | Pre-grant |
| US9047603B2 | Cited by | United States of America | Search report |
| US2004188520A1 | Cited by | United States of America | Pre-grant |
| WO2013163233A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US9020859B2 | Cited by | United States of America | Search report |
| EP2301269A4 | Cited by | European Patent Office (EPO) | Search report |
| US2002176583A1 | Cited by | United States of America | Pre-grant |
| US2008077534A1 | Cited by | United States of America | Pre-grant |
| US2004139332A1 | Cited by | United States of America | Pre-grant |
| EP2301269A2 | Cited by | European Patent Office (EPO) | Search report |
| US2005239447A1 | Cited by | United States of America | Pre-grant |
| US9189647B2 | Cited by | United States of America | Search report |
| US2009181644A1 | Cited by | United States of America | Pre-grant |
| CN107222764A | Cited by | China | Search report |
| WO2007134010A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2011143729A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN1954335A | Cited by | China | Search report |
| US9122456B2 | Cited by | United States of America | Applicant |
| FR2923337A1 | Cited by | France | Search report |
| US7922077B2 | Cited by | United States of America | Applicant |
| US2006036855A1 | Cited by | United States of America | Pre-grant |
| US2002144117A1 | Cited by | United States of America | Pre-grant |
| US2015095664A1 | Cited by | United States of America | Pre-grant |
| US7606918B2 | Cited by | United States of America | Applicant |
| US8370220B1 | Cited by | United States of America | Search report |
| US10460316B2 | Cited by | United States of America | Applicant |
| US2005187882A1 | Cited by | United States of America | Pre-grant |
| US2002116608A1 | Cites | United States of America | Pre-grant |
| US5604801A | Cites | United States of America | Pre-grant |
| US5615110A | Cites | United States of America | Pre-grant |
| US5668876A | Cites | United States of America | Pre-grant |
| US5910989A | Cites | United States of America | Pre-grant |
| US6012144A | Cites | United States of America | Pre-grant |
| US6047270A | Cites | United States of America | Pre-grant |
| US6112078A | Cites | United States of America | Pre-grant |
| US6269445B1 | Cites | United States of America | Pre-grant |
| US6377810B1 | Cites | United States of America | Pre-grant |
| US6430407B1 | Cites | United States of America | Pre-grant |
| US6453416B1 | Cites | United States of America | Pre-grant |
| US6463534B1 | Cites | United States of America | Pre-grant |
| US6654754B1 | Cites | United States of America | Pre-grant |
| US6694431B1 | Cites | United States of America | Pre-grant |
| US6707915B1 | Cites | United States of America | Pre-grant |
11 members in 7 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 00480024 | European Patent Office (EPO) | A | |
| 00480024 | European Patent Office (EPO) | A | |
| 004800249 | – | – | – |
| EP20000480024 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| AU7184300A | Australia | A | |
| KR20010085380A | Republic of Korea | A | |
| JP2001325469A | Japan | A | |
| EP1161055A2 | European Patent Office (EPO) | A2 | |
| US2003191721A1 | United States of America | A1 | |
| EP1161055A3 | European Patent Office (EPO) | A3 | |
| AU777912B2 | Australia | B2 | |
| EP1161055B1 | European Patent Office (EPO) | B1 | |
| DE60119221D1 | Germany | D1 | |
| AT325493T | Austria | T | |
| ATE325493T1 | Austria | T1 |
43 transactions on the USPTO file
Abandoned after 2 non-final rejections, 2 final rejections and 1 RCE.
- Non-final rejections
- 2
- Final rejections
- 2
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | |
|---|---|
| Mail Express Abandonment (During Examination)Abandoned | |
| Express Abandonment (during Examination)Abandoned | |
| Letter of Express Abandonment FiledAbandoned | |
| Mail Final Rejection (PTOL - 326)Final rejection | |
| Final RejectionFinal rejection | |
| Date Forwarded to Examiner | |
| Response after Non-Final Action | |
| Case Docketed to Examiner in GAU | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Date Forwarded to Examiner | |
| Disposal for a RCE / CPA / R129 | |
| Request for Continued Examination (RCE) | |
| Request for Extension of Time - Granted | |
| Workflow - Request for RCE - Begin | |
| Mail Advisory Action (PTOL - 303) | |
| Advisory Action (PTOL-303) | |
| Date Forwarded to Examiner | |
| Response after Final Action | |
| Mail Final Rejection (PTOL - 326)Final rejection | |
| Final RejectionFinal rejection | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| IFW TSS Processing by Tech Center Complete | |
| Date Forwarded to Examiner | |
| Response after Non-Final Action | |
| Workflow incoming amendment IFW | |
| Change in Power of Attorney (May Include Associate POA) | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Application Dispatched from OIPE | |
| Application Is Now Complete | |
| Notice Mailed--Application Incomplete--Filing Date Assigned | |
| Correspondence Address Change | |
| IFW Scan & PACR Auto Security Review | |
| Request for Foreign Priority (Priority Papers May Be Included) | |
| Initial Exam Team nn |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationEXPRESSLY ABANDONED -- DURING EXAMINATIONSTCB | STCB | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 2003191721
- Publication, EPODOC
- US2003191721
- Application
- 9794305
- Application, DOCDB
- 79430501
- Application, EPODOC
- US20010794305
Titles
- English
- System and method of associating communication devices to secure a commercial transaction over a network
Classification
- CPC, 14
- G06Q20/04
- G06Q20/40
- G06Q20/32
- G06Q20/3226
- G06Q20/367
- G06Q20/3823
- G06Q20/425
- H04L63/126
- H04L63/18
- H04L67/04
- H04L67/02
- H04L69/329
- G06Q20/3263
- G06Q20/12
- IPC, 9
- G06F15 00
- G06F21 00
- G06F21 32
- G06F21 33
- G06F21 34
- G06Q20 00
- G09C1 00
- H04L29 06
- H04L29 08
- USPC, 1
- 705065000