Next Patent: Periodic software licensing system
Next Patent: Periodic software licensing system
Plaque It!
|
[0001] The present invention relates to a system and a method for payment transaction authentication, and more particularly to a strong authentication of a payment transaction that utilizes personal communication devices and smart cards.
[0002] Payment transactions have evolved from hard currency to checks and credit/debit cards. In the recent years, with the introduction of eCommerce, consumers can purchase goods and services from remote merchants via the Internet, or the telephone. Another way of purchasing goods and services from remote merchants is via mail order from a catalog. Credit cards and debit cards have been the main payment instrument for these eCommerce and mail order transactions.
[0003] Referring to
[0004] Payment card fraud cost businesses and consumers nearly three billion dollars in 2001 and is expected to reach eight billion by 2005, if it remains unchecked. In particular, non-face-to-face or card-not-present (CNP) payment transactions represent the fastest growing segment of payment card fraud. CNP transactions include Internet, telephone, mail order, mail order telephone order (MOTO), television, and mobile orders, i.e., prepaid top-up cards, and orders placed with mobile communication devices. The instances of fraud increase when the customer purchases non-physical or “digital” goods, such as an airline e-ticket or mobile phone airtime credits, because there is no shipment of physical goods to trace back to the customer. Most merchant servers
[0005] In the recent years, traditional credit and debit cards that utilize a magnetic stripe to store cardholder information are being replaced by “smart cards” or “chip cards”. Smart cards are plastic cards that have an embedded Integrated Circuit (IC) computer chip. The computer chip stores information including the card number, expiration date, financial institution code, and cardholder information, among others. The computer chip may also include a personal identification number (PIN), a password, and a biometric signal as additional security features. Examples of biometric signals include a retinal scan, a fingerprint, and a portion of a cardholder's DNA, among others. The use of smart cards as payment instruments is becoming widely accepted as a more secure way for consumers to conduct business with merchants because of the embedded security features. Examples of smart cards used for payment include the American Express Blue Card, the Target Smart Visa, and the oneSMART Card from MasterCard International.
[0006] Several major payment card associations and financial institutions that include among others Europay, MasterCard, Visa, and American Express have agreed to a payment standard for credit/debit payments that utilizes smart cards, i.e., Europay-MaterCard-Visa (EMV). The worldwide rollout of EMV is contributing to the rapid adoption of smart cards by banks, financial institutions and merchants. The use of smart cards for payment transactions has largely been focused on face-to-face consumer/merchant transactions where consumers use smart cards with merchant Point of Sale (POS) smart card readers. The use of smart cards in connection with merchant POS has the potential of reducing fraud for face-to-face payment transactions. However, CNP transactions will not benefit from EMV and smart cards in the current configuration.
[0007] In addition to smart cards with payment capabilities, mobile network operators utilize the strong authentication features of smart cards to authenticate and authorize mobile phones and devices to access their mobile network. The smart cards utilized by mobile network operators are called Subscriber Identity Modules (SIMs). SIMs are significantly smaller than payment smart cards, however, they utilize the same technology as the larger payment smart cards.
[0008] There are several patents that employ smart cards and personal computers to transact with Internet and web merchants. U.S. Pat. No. 6,282,522, entitled “Internet Payment System using Smart Card” and U.S. Pat. No. 6,105,008, entitled “Internet Loading System using Smart Card” describe the use of a smart card in connection with a “card reader attached to a personal computer (PC)” for remote payments on “open networks such as the Internet”. Although this solution can greatly reduce fraud for website purchases, it does not address the problem of using the smart card for remote transactions over private networks such as Wireless Wide Area Networks (WWAN) where mobile operators license the network spectrum (i.e. GSM, TDMA, CDMA, iDEN, Mobitex, DataTac), as well as Wireless Local Area Networks (WLAN) (i.e., 802.11a, 802.11b), and Personal Area Networks (PAN) (i.e., Bluetooth, Infrared) that are unlicensed and private to a small group of users. Additionally, the use of a smart card reader that is attached to the PC restricts the customer in using only one PC or carrying the smart card reader and software with the person at all times.
[0009] There are also several prior art patents relating to payment schemes using mobile devices over private networks. However, there is still a need for a non-repudiatable payment system for non-face-to-face CNP payment transactions that reduces payment card fraud.
[0010] In general, in one aspect, the invention features an electronic payment system utilized by a customer to pay for the purchase of a good and/or a service with a payment card. The payment system includes a merchant server, a payment server, an authentication server and a communication device. The merchant server is in connection with a first network, and is adapted to receive a purchase order by the customer for the purchase of the good and/or service and to create a digital order including purchase order information. The payment server is also in connection with the first network, and is adapted to receive the digital order from the merchant server over the first network and to further route the digital order. The authentication server is in connection with the first network, and is adapted to receive the digital order from the payment server over the first network, format the digital order into a first message and route the first message over a second network. The communication device includes identification information of the payment card, and is adapted to receive the first message from the authentication server over the second network, display the first message to the customer, request and receive authorization for payment from the customer, retrieve payment card identification information, request and receive payment card security information from the customer, and route the authorization result and in case of a positive authorization result the payment card identification and security information to the authentication server over the second network. The authorization result and payment card identification and security information are routed from the authentication server to the payment server over the first network and from the payment server to a financial institution over the first network system. The financial institution is the issuer of the payment card and is asked to approve and execute the requested payment and to route the payment approval result through the payment server to the merchant server and to the authentication server.
[0011] Implementations of this aspect of the invention may include one or more of the following features. The authentication server may further route the payment approval result to the communication device. The merchant server may be further adapted to receive identification information for the communication device and the authentication server may be adapted to access the communication device via the communication device identification information over the second network. The communication device may further include an authentication client application. The authentication client application includes instructions for receiving the first message from the authentication server over the second network, displaying the first message to the customer, requesting and receiving authorization for payment for the purchase order with the payment card from the customer, retrieving payment card identification number, requesting and receiving payment card security information from the customer, routing the authorization result and in case of a positive authorization result the payment card identification and security information to the authentication server over the second network, and receiving the payment approval result and creating a record. The merchant server upon receiving a positive approval result may fulfill the purchase order. The authentication server may include an authentication server application. The authentication server application includes instructions for receiving the digital order from the payment server over the first network, formatting the digital order into a first message, routing the first message over a second network to the communication device, receiving the authorization result and payment card identification and security information from the communication device, routing the authorization result and payment card identification and security information to the payment server, receiving the payment approval result from the payment server, formatting the payment approval result into a second message and routing the second message to the communication device. The communication device may be a mobile wireless device and the second network may be a wireless network. The mobile wireless device may be a mobile phone, a personal digital assistant, a pager, a wireless laptop computer, a personal computer, a television remote control, or combinations thereof. The second network may be a wireless wide area network (WWAN), a wireless local area network (WLAN) or a wireless personal area network (PAN). The communication device may also be a wired communication device and the second network may be a wired network. The wired communication device may be a telephone or a computer and the wired network may be a telecommunications network or the Internet, respectively. The first network may be the Internet or a telecommunication network. The communication device may include identification information for a plurality of payment cards issued by a plurality of financial institutions. The communication device may include a first Subscriber Identification Module (SIM) card and the first SIM card may be adapted to store communication device and subscriber information. The first SIM card may be adapted to further store the payment card identification information and/or the authentication client application. The communication device may further include a second SIM card, and the second SIM card may be adapted to store the payment card identification information and/or the authentication client application. The communication device may further include an attachment adapted to receive an external payment card and route the external payment card identification information through the communication device to the authentication server. The first or second SIM cards may be Universal Subscriber Identification Module (USIM) cards that can support third-generation (3G) network requirements. The payment card may be a credit card, a debit card, a stored-value card, a coupon card, a reward card, an electronic cash card, loyalty card, or an identification card. The merchant may receive the purchase order via the Internet, telephone connection, mail order form, fax, e-mail, voice recognition system, shot message service, interactive voice recording (IVR), or face-to-face interaction with the customer. The purchase order information may include at least one of price, currency indicator, product identification, product description, quantity, delivery method, delivery date, shipping and billing information, merchant identification, payment method, communication device identification information, and transaction number. The format for the first message may be Short Message Service (SMS), General Packet Radio Service (GPRS), Transmission Control Protocol/Internet Protocol (TCP/IP), User Datagram Protocol (UPD), Simple Mail Transmission Protocol (SMTP), Simple Network Management Protocol (SNMP), or a proprietary message format. The identification information of the payment card may include at least one of payment card number, payment card expiration date, cardholder's name, cardholder's contact information, cardholder's account information, issuer financial institution identification, issuer financial institution contact information, and security information for the authentication of the cardholder. The security information may include at least one of a personal identification number (PIN), password, biometric signal, fingerprint, retinal scan, voice signal, digital signature, and encrypted signature, username and password combinations, identity certificate such as X.509, public and private keys to support Public Key Infrastructure (PKI), a Universal Card Authentication Field (UCAF), or combinations thereof. The security information of the payment card may be entered by the customer via the communication device.
[0012] In general, in another aspect, the invention features an electronic payment system utilized by a customer to pay for the purchase of a good and/or a service with a payment card. The payment system includes a merchant server, an authentication server, and a communication device. The merchant server is in connection with a first network, and is adapted to receive a purchase order by the customer for the purchase of the good and/or service and to create a digital order comprising purchase order information. The authentication server is in connection with the first network, and is adapted to receive the digital order from the merchant server over the first network, format the digital order into a first message and route the first message over a second network. The communication device includes identification information of the payment card, and is adapted to receive the first message from the authentication server over the second network, display the first message to the customer, request and receive authorization for payment for the purchase order with the payment card from the customer, retrieve payment card identification information, request and receive payment card security information from the customer, and route the authorization result and in case of a positive authorization result the payment card identification and security information to the authentication server over the second network. The authorization result and payment card identification and security information are routed from the authentication server to the financial institution over the first network system. The financial institution is the issuer of the payment card and is asked to approve and execute the requested payment and to route the payment approval result through the authentication server to the merchant server and to the communication device.
[0013] In general, in another aspect, the invention features an electronic payment system utilized by a customer to pay for a purchase of a good and/or a service with a payment card. The payment system includes a merchant server, a financial institution authentication server and a communication device. The merchant server is in connection with a first network, and is adapted to receive a purchase order by the customer for the purchase of the good and/or service and to create a digital order comprising purchase order information. The financial institution authentication server is in connection with the first network, and is adapted to receive the digital order from the merchant server over the first network, format the digital order into a first message and route the first message over a second network. The communication device includes identification information of the payment card, and is adapted to receive the first message from the financial institution authentication server over the second network, display the first message to the customer, request and receive authorization for payment for the purchase order with the payment card from the customer, retrieve payment card identification information, request and receive payment card security information from the customer, and route the authorization result and in case of a positive authorization result the payment card identification and security information to the financial institution authentication server over the second network. The financial institution authentication server is asked to approve and execute the requested payment and to route the approval result to the merchant server and to the communication device.
[0014] In general, in another aspect, the invention features a payment authentication system for authenticating the identity of a customer and the presence of a payment card in a non-face-to-face payment transaction for the purchase of a good and/or a service from a merchant server. The payment authentication system includes a payment server, an authentication server, and a communication device. The payment server is in connection with a first network, and is adapted to receive a digital order from the merchant server over the first network and to further route the digital order. The authentication server is in connection with the first network, and is adapted to receive the digital order from the payment server over the first network, format the digital order into a first message and route the first message over a second network. The communication device includes identification information of the payment card, and is adapted to receive the first message from the authentication server over the second network, display the first message to the customer, request and receive authorization for payment for the purchase order with the payment card from the customer, retrieve payment card identification information, request and receive payment card security information from the customer, and route the authorization result and in case of a positive authorization result the payment card identification and security information to the authentication server over the second network. The authorization result and payment card identification and security information are routed from the authentication server to the payment server over the first network and from the payment server to a financial institution over the first network system. The financial institution is the issuer of the payment card and is asked to approve and execute the requested payment and to route the payment approval result through the payment server to the merchant server and to the authentication server.
[0015] In general, in another aspect, the invention features a payment authentication system for authenticating the identity of a customer and the presence of a payment card in a non-face-to-face payment transaction for the purchase of a good and/or a service from a merchant server. The payment authentication system includes an authentication server, and a communication device. The authentication server is in connection with a first network, and is adapted to receive a digital order from the merchant server over the first network, format the digital order into a first message and route the first message over a second network. The communication device includes identification information of the payment card, and is adapted to receive the first message from the authentication server over the second network, display the first message to the customer, request and receive authorization for payment for the purchase order with the payment card from the customer, retrieve payment card identification information, request and receive payment card security information from the customer, and route the authorization result and in case of a positive authorization result the payment card identification and security information to the authentication server over the second network. The authorization result and payment card identification and security information are routed from the authentication server to a financial institution over the first network system, wherein the financial institution is the issuer of the payment card and is asked to approve and execute the requested payment and to route the payment approval result through the authentication server to the merchant server and to the communication device.
[0016] In general, in yet another aspect, the invention features a payment authentication system for authenticating the identity of a customer and the presence of a payment card in a non-face-to-face payment transaction for the purchase of a good and/or a service from a merchant. The payment authentication system includes an authentication server and a communication device. The authentication server is in connection with a first network, and is adapted to receive a digital order from the merchant server over the first network, format the digital order into a first message and route the first message over a second network. The communication device is adapted to receive the first message from the authentication server over the second network, display the first message to the customer, request and receive authorization for payment for the purchase order with the payment card by the customer, request and receive payment card identification information and security information from the customer, and route the authorization result and in case of a positive authorization result the payment card identification and security information to the authentication server over the second network. The authorization result and payment card identification and security information are routed from the authentication server to a financial institution over the first network system. The financial institution is the issuer of the payment card and is asked to approve and execute the requested payment and to route the payment approval result through the authentication server to the merchant server and to the communication device.
[0017] In general, in yet another aspect, the invention features an electronic payment method utilized by a customer for paying with a payment card for the purchase of a good and/or a service. The payment method includes the following. First providing a merchant server that offers a good and/or a service with identification information for a communication device. The communication device includes identification information of the payment card. Next creating a digital order that includes purchase order information and communication device identification number by the merchant server and routing the digital order to an authentication server via a first network. Next, formatting the digital order into a first message that is adapted to be transmitted over a second network, and routing the first message over the second network to the communication device. Next, displaying the first message on the communication device, requesting and receiving authorization of payment from the customer via the communication device, retrieving payment card identification information from the communication device and requesting and receiving payment card security information from the customer via the communication device. Next, routing the authorization result and payment card identification and security information to the authentication server and from the authorization server a financial institution, that is the issuer of the payment card. Finally approving and executing the payment at the financial institution. The method may further include before providing the merchant server with the communication device identification information, placing a purchase order with the merchant server for the good and/or a service, and choosing to pay via the communication device. The method may also include sending notification of the approval and execution of payment to the merchant server and the communication device and fulfilling the purchase order by the merchant server.
[0018] Among the advantages of this invention may be one or more of the following. From the customer's viewpoint, the process is similar to that of using a smart card or credit card with a merchant's Point Of Sale (POS) device or a bank's Automated Teller Machine (ATM). The invention has the advantage that the customer is using a personal, trusted mobile communication device to interact remotely with an authentication system and a payment server. The invention may be used for both non-face-to-face and face-to-face transactions. The presence of the payment card and the identity of the cardholder are strongly authenticated. The embedded IC chip in the payment card cannot be easily counterfeited, as is the case with the magnetic strip payment cards. The signature of a cardholder can be easily forged. However, a security feature such as a digital encrypted signature, PIN, password or biometric signal is difficult to copy. The invention offers a CNP payment transaction with a Personal Point of Sale (PPOS™). The combination of a Personal POS with the strong authentication of a smart card offers a dramatic decrease in payment card fraud. It is a convenient method of payment and easy to use for both the customer and the merchant.
[0019] The details of one or more embodiments of the invention are set forth in the accompanying drawings and description below. Other features, objects and advantages of the invention will be apparent from the following description of the preferred embodiments, the drawings and from the claims.
[0020] Referring to the figures, wherein like numerals represent like parts throughout the several views:
[0021]
[0022]
[0023]
[0024]
[0025]
[0026]
[0027]
[0028]
[0029]
[0030]
[0031]
[0032]
[0033]
[0034]
[0035]
[0036]
[0037] The present invention describes a strong authentication system for non face-to-face payment transactions. The strong authentication system involves smart cards and mobile communication devices. Referring to
[0038] Merchant server
[0039] The merchant server
[0040] The message routing
[0041] In the embodiment of
[0042] In the embodiment of
[0043] Referring to
[0044] Referring to
[0045] Referring to
[0046] Referring to
[0047] Referring to
[0048] Referring to
[0049] Referring to
[0050] Referring to
[0051] Referring to
[0052] Other embodiments are within the scope of the following claims. For example, the mobile phone identification information may be an Internet Protocol (IP) address. The communication networks
[0053] Several embodiments of the present invention have been described. Nevertheless, it will be understood that various modifications may be made without departing from the spirit and scope of the invention. Accordingly, other embodiments are within the scope of the following claims.