WO0229666A1

Method of and system for e-commerce security

Abstract

This invention provides a method and system for secure e-commerce transactions by providing a user (120) with tauthentication tools (110) with which a user can verify the trustedness of a merchant website (120).

WO0229666A1, drawing sheet 1
Sheet 1 of 9

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

70 claims: 6 independent, 64 dependent

  1. 1
    CLAIMS What is claimed is:1. A system for allowing a user to verify information about servers on a computer network, comprising: a computer network;an authenticator server connected to said computer network;a first merchant server connected to said computer network;a user device connected to said computer network;said authenticator server being adapted to: receive first identity information from said user device;retrieve second identity information from associated memory;compare said first identity information to said second identity information;and provide said comparison results to user device;said first merchant server being adapted to: display a trigger element on the web pages of its web site;and provide said first identity information to said user device;and said user device being adapted to: obtain said first identity information from said first merchant server;verify the integrity of said first identity;verify ownership of said first identity;provide said first identity information to said authenticator server;■ receive said comparison results from said authenticator server;and display said comparison results.
  2. 9
    A method for allowing a user to verify information about servers on a computer network, comprising the steps of:providing a web page containing a trigger element from a first merchant server to a user device;obtaining first identity information by said user device from said first merchant server;and verifying the integrity of said first identity;verifying ownership of said first identity;providing said first identity information by said user device to an authenticator server;retrieving second identity information from associated memory by said authenticator server;comparing said first identity information to a second identity information by said authenticator server;sending said comparison results by said authenticator server to said user device;and displaying said comparison results by said user device.
  3. 24
    A system for allowing a user to verify information about servers on a computer network, comprising:a computer network;an authenticator server connected to said computer network;a first merchant server connected to said computer network;a user device connected to said computer network;said authenticator server being adapted to imbed extension information into identity information of said first merchant server;said first merchant server being adapted to: display a trigger element on the web pages of its web site;and provide said identity information to said user device;said user device being adapted to: obtain said identity information from said first merchant server;verify the integrity of said identity information;verify ownership of said identity information;extract said extension information from said identity information;and display said extension information.
  4. 32
    A method for allowing a user to verify information about servers on a computer network, comprising the steps of:providing a web page containing a trigger element from a first merchant server to a user device;obtaining identity information by said user device from said first merchant server;verifying the integrity of said identity information;verifying ownership of said identity information- extracting extension information by said user device from said identity information;and displaying said extension information by said user device.
  5. 45
    A system for allowing a user to verify information about servers on a computer network, comprising:a computer network;an authenticator server connected to said computer network;a first merchant server connected to said computer network;a user device connected to said computer network;said authenticator server being adapted to: receive first connection information from said user device;receive second connection information from said first merchant server;compare said first connection information to said second connection information;and provide said comparison results to said user device;said first merchant server being adapted to: display a trigger element on the web pages of its web site;and provide said second connection information to said authenticator server;and said user device being adapted to: provide first connection information to said authenticator server;receive said comparison results from said authenticator server;and display said comparison results.
  6. 56
    A method for allowing a user to verify information about servers on a computer network, comprising the steps of:providing a web page containing a trigger element from said first merchant server to a user device;sending first connection information from said user device to an authenticator server;providing second connection information from said first merchant server to said authenticator server;comparing said first connection information to said second connection information by said authenticator server;sending said comparison results from said authenticator server to said user device;and displaying said comparison results by said user device.
  7. 67
    68. A method according to claim 67 wherein, prior to receiving said computer program, said first merchant server provides registration information to said authenticator server.
  8. 69
    70. A method according to claim 69 wherein, prior to said authenticator server sending said signed identity information to said user device, user device provides registration information to said authenticator server.