US2003212642A1PendingUtilityA1

Online payer authentication service

Assignee: VISA INT SERVICE ASSPriority: Apr 24, 2000Filed: Mar 11, 2003Published: Nov 13, 2003
Est. expiryApr 24, 2020(expired)· nominal 20-yr term from priority
G07F 7/1008G06Q 20/027G06Q 20/0855G07F 7/1016G06Q 20/4014G06Q 20/4012G06Q 20/355G06Q 20/3829G06Q 20/341G06Q 20/382G06Q 20/02G06Q 20/3674G06Q 20/40G06Q 20/12G06Q 20/367G06Q 20/04
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A payment authentication service authenticates the identity of a payer during online transactions. The authentication service of the present invention allows a card issuer to verify a cardholder's identity using a variety of authentication methods, such as the use of passwords. Also, the only system participant requiring a certificate is the issuing financial institution. One embodiment of the invention for authenticating the identity of a cardholder during an online transaction involves querying an access control server to determine if a cardholder is enrolled in the payment authentication service, requests a password from the cardholder, verifies the password, and notifies a merchant whether the cardholder's authenticity has been verified. In another aspect of the invention, a chip card and the authentication service independently generate cryptograms that must match in order for the service to verify that the correct chip card is being used by the cardholder.

Claims

exact text as granted — not AI-modified
We claim:  
     
         1 . A method for authenticating the identity of a cardholder during an online transaction comprising: 
 querying an access control server to determine if said cardholder is enrolled in a payment authentication service;    requesting a password from said cardholder;    verifying said password; and    notifying a merchant of the authenticity of the cardholder if the password entered by said cardholder is verified.    
     
     
         2 . A method for authenticating the identity of a cardholder utilizing a chip card comprising: 
 verifying that said cardholder client device includes a chip card reader;    prompting said cardholder to enter said chip card into said chip card reader;    receiving a chip card cryptogram that was generated by said chip card based upon information in said chip card;    receiving a password entered by said cardholder;    independently generating a second cryptogram based upon information in said chip card;    comparing the chip card cryptogram to the second cryptogram to determine the authenticity of the chip card; and    verifying said password to authenticate the identity of said cardholder.

Join the waitlist — get patent alerts

Track US2003212642A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.