Invention Grant
- Patent Title: Secure authentication for authorization for transaction processing
- Patent Title (中): 用于事务处理授权的安全认证
-
Application No.: US12361546Application Date: 2009-01-29
-
Publication No.: US08095965B2Publication Date: 2012-01-10
- Inventor: Robert Lennie , Carl Chen , Gabe Dalbec
- Applicant: Robert Lennie , Carl Chen , Gabe Dalbec
- Applicant Address: JP Tokyo
- Assignee: Access Co., Ltd.
- Current Assignee: Access Co., Ltd.
- Current Assignee Address: JP Tokyo
- Agency: Berry & Associates P.C.
- Main IPC: G06F7/04
- IPC: G06F7/04

Abstract:
A method and apparatus for authenticating and authorizing online transactions. An authentication cookie is transmitted to a client system. The authentication cookie includes a user encryption key and an encrypted buffer that contains user identification data and a profile code. Subsequent requests for the particular service use the authentication cookie to generate a query that includes the encrypted buffer and user identification data entered by the user. Portions of the query are encrypted using the user encryption key. Queries received at each authentication and authorization server are authenticated by reconstructing the user encryption key using information transmitted in the clear and decrypting the query using both the reconstructed user encryption key and the secret key. The user identification data entered by the user is then compared with the user identification data in the encrypted buffer for further authentication. The profile code is analyzed for determining authorization. If the query is authenticated and authorized, the authentication and authorization server forwards the request to a server that provides the desired service.
Public/Granted literature
- US20090138722A1 SECURE AUTHENTICATION FOR AUTHORIZATION FOR TRANSACTION PROCESSING Public/Granted day:2009-05-28
Information query