×

System and method for point of sale payment data credentials management using out-of-band authentication

  • US 9,741,033 B2
  • Filed: 06/26/2016
  • Issued: 08/22/2017
  • Est. Priority Date: 12/31/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method for authentication for accessing payment credentials in a system comprising a merchant, a user, a first channel payment application, a second channel device application, and an authentication server application having a provisioned user database and encrypted payload, wherein the method comprises:

  • providing a login portal for accessing payment credentials by a merchant, said login portal being in communication with said first channel payment application;

    establishing contact between the first channel payment application and the authentication server application wherein a new authentication session is started;

    generating a session identification (“

    ID”

    ) at the authentication server application, wherein the session ID is communicated to the first channel payment application through at least a first communications channel;

    creating a transitory key at the first channel payment application and providing at least one authentication option for publishing the transitory key at a login screen of the login portal;

    starting authentication by entering at least one credential on the second channel portable communications device application, wherein the second channel portable communications device application validates at least one credential and displays at least one authentication option;

    using the second channel portable communications device application to receive a published transitory key and validate the first channel payment application;

    using the second channel portable communications device application to receive the message from the first channel payment application and to validate the first channel payment application;

    finding on the second channel portable communications device application at least one encrypted user credential with an encryption key from the transitory key;

    sending the at least one encrypted credential and session ID from the second channel portable communications device application to the authentication server application via an outbound out-of-band communications channel;

    validating the new authentication session;

    sending an encrypted payload to the first channel payment application;

    decrypting the encrypted payload at the first channel payment application using at least one of encryption key from the transitory key; and

    extracting credentials from the decrypted payload at the first channel payment application.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×