Nova Patents
WO0062214A1

Credit card security technique

Abstract

A technique for secure electronic commerce is disclosed wherein a transaction initiator (26) has a primary identifier and a list of secondary identifiers stored therein, each of which is valid for a single transaction. An identification center (36) receives the primary and secondary verification numbers and verifies that the primary number is valid and that the secondary number is appropriate for a current transaction using the primary number. The transaction initiator comprises an enhanced monetary card, such as a credit card or a stored value card, which includes an embedded processor, and which provides the secondary number for each transaction. The secondary numbers are stored in a lookup table, which is also available to the identification center. The values in the lookup table are indexed according to a transaction counter and are preferably communicated to the identification center without encryption or challenge. In some embodiments the transaction initiator comprises other types of hardware such as a personal computer in conjunction with secondary memory such as a CDr for storing secondary numbers and software.

WO0062214A1, drawing sheet 1
Sheet 1 of 13

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

63 claims: 5 independent, 58 dependent

  1. 1
    Claims 1. A method for verifying by an identification center permissibility of a remote transaction, comprising:selecting a variable secondary identification from a list carried by a remote party, said party being remote from said identification center, responsive to a predetermined rule;transferring said secondary identification together with a primary identification of a transaction initiator to said identification center;wherein said secondary identification is transferred to said identification center in an unencrypted format;and verifying at said identification center that said secondary identification is a permissible identification for performing said transaction.
  2. 16
    A method for verifying by an identification center permissibility of a remote transaction, comprising:causing a remote party to initiate a communication link with an identification center, wherein said remote party is remote from said identification center;at said remote party, selecting a variable secondary identification from a list carried by said remote party, responsive to a predetermined rule;transferring said secondary identification together with a constant primary identification of a transaction initiator to said identification center;and verifying at said identification center that said secondary identification is a permissible identification for performing said transaction.
  3. 31
    A method for verifying by an identification center permissibility of a remote transaction, comprising:selecting a variable identification from a list carried by a remote party, said remote party being remote from said identification center, responsive to a predetermined rule;transferring said variable identification to said identification center;wherein said variable identification is transferred to said identification center in an unencrypted format;and verifying at said identification center that said variable identification is a permissible identification for performing said transaction.
  4. 46
    A transaction card for performing transactions with a verifying center, comprising:a primary memory which stores a primary permanent identification;and an embedded unit having a secondary memory disposed in said transaction card which provides according to a predetermined rule a secondary varying identification which is at least partially based on information non-related to any details of said transaction;wherein said secondary varying identification is selected from a plurality of memorized identifiers in said secondary memory.
  5. 50
    A method of performing a remote transaction, comprising the steps of:initiating a first communication link between a first party and a second party, said first party having a fixed primary identification;at said first party, selecting a variable secondary identification from a list carried by said first party, responsive to a predetermined rule;transferring said secondary identification from said first party to said second party via said first communication link;establishing a second communications link between said second party and an authentication center, and communicating said secondary identification from said second party to said authentication center via said second communications link, wherein said authentication center is aware of said fixed primary identification of said first party;verifying at said authentication center that said secondary identification is a permissible identification for performing said transaction;establishing a third communications link between said authentication center and a payment processing agent;and communicating said fixed primary identification from said authentication center to said payment processing agent via said third communications link.