×

Authenticating remote transactions using a mobile device

  • US 10,521,794 B2
  • Filed: 12/10/2013
  • Issued: 12/31/2019
  • Est. Priority Date: 12/10/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving transaction details comprising a transaction amount at an authentication server computer, wherein the transaction details are for a transaction conducted by a consumer using an account associated with an issuer;

    initiating, by the authentication server computer, an authentication request message to a mobile device operated by the consumer;

    receiving, by the authentication server computer, a personal identifier from the mobile device,wherein the personal identifier is an encrypted personal identifier and wherein the mobile device encrypts the personal identifier using a first transport key stored in the mobile device before the personal identifier is received from the mobile device, and wherein the method further comprises;

    decrypting, by the authentication server computer, the received encrypted personal identifier using a second transport key;

    determining, by the authentication server computer, that the personal identifier matches a previously stored personal identifier for the consumer;

    generating, by the authentication server computer, an authentication indicator indicating a positive authentication result;

    generating, by the authentication server computer, a digital certificate using a key provided by the issuer;

    after decrypting the encrypted personal identifier with the second transport key, encrypting the personal identifier with a first issuer key that is unique to the transaction and that is derived using a master key and an algorithm supplied by the issuer to form a re-encrypted personal identifier; and

    in response to determining that the personal identifier matches the previously stored personal identifier for the consumer, sending the authentication indicator and the digital certificate to the wallet provider computer, the wallet provider computer subsequently sending an authorization request message comprising the transaction amount, an account identifier associated with the account, the re-encrypted personal identifier and the digital certificate to an issuer computer associated with the issuer, the issuer computer subsequently decrypting the re-encrypted personal identifier with a second issuer key that is unique to the transaction, and is also derived from the master key and the algorithm, wherein the issuer computer determines whether or not to authorize the transaction based on the transaction amount, the account identifier, the personal identifier and the digital certificate, andwherein the wallet provider computer generates the authorization request message in response to receiving the authentication indicator indicating the positive authentication result.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×