Movatterモバイル変換


[0]ホーム

URL:


US20120124646A1 - Method and Apparatus for Authenticating Online Transactions Using a Browser - Google Patents

Method and Apparatus for Authenticating Online Transactions Using a Browser
Download PDF

Info

Publication number
US20120124646A1
US20120124646A1US13/358,176US201213358176AUS2012124646A1US 20120124646 A1US20120124646 A1US 20120124646A1US 201213358176 AUS201213358176 AUS 201213358176AUS 2012124646 A1US2012124646 A1US 2012124646A1
Authority
US
United States
Prior art keywords
authentication
service provider
server
provider server
browser
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Abandoned
Application number
US13/358,176
Inventor
Paul Y. Lin
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by IndividualfiledCriticalIndividual
Priority to US13/358,176priorityCriticalpatent/US20120124646A1/en
Publication of US20120124646A1publicationCriticalpatent/US20120124646A1/en
Abandonedlegal-statusCriticalCurrent

Links

Images

Classifications

Definitions

Landscapes

Abstract

A computer-implemented method for authenticating a user using a service provider server and an authentication server, the user communicating with at least one of the service provider server and the authentication server using a user browser. The method includes requesting, using the user browser, the authenticating with the service provider server. The method also includes authenticating, using the user browser, a secure communication channel with the authentication server. The method also includes receiving, using the user browser, a Next Pre-Authentication Anchor (NPAA) value from the authentication server. The method additionally includes temporarily storing the Next Pre-Authentication Anchor (NPAA) value in a user browser cookie associated with the user browser, wherein the Next Pre-Authentication Anchor (NPAA) value is protected by employing Same Origin Policy (SOP).

Description

Claims (5)

US13/358,1762008-12-192012-01-25Method and Apparatus for Authenticating Online Transactions Using a BrowserAbandonedUS20120124646A1 (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
US13/358,176US20120124646A1 (en)2008-12-192012-01-25Method and Apparatus for Authenticating Online Transactions Using a Browser

Applications Claiming Priority (3)

Application NumberPriority DateFiling DateTitle
US13952708P2008-12-192008-12-19
US12/641,156US8245030B2 (en)2008-12-192009-12-17Method for authenticating online transactions using a browser
US13/358,176US20120124646A1 (en)2008-12-192012-01-25Method and Apparatus for Authenticating Online Transactions Using a Browser

Related Parent Applications (1)

Application NumberTitlePriority DateFiling Date
US12/641,156DivisionUS8245030B2 (en)2008-12-192009-12-17Method for authenticating online transactions using a browser

Publications (1)

Publication NumberPublication Date
US20120124646A1true US20120124646A1 (en)2012-05-17

Family

ID=42312466

Family Applications (3)

Application NumberTitlePriority DateFiling Date
US12/641,156Expired - Fee RelatedUS8245030B2 (en)2008-12-192009-12-17Method for authenticating online transactions using a browser
US13/358,176AbandonedUS20120124646A1 (en)2008-12-192012-01-25Method and Apparatus for Authenticating Online Transactions Using a Browser
US13/358,160Expired - Fee RelatedUS8528076B2 (en)2008-12-192012-01-25Method and apparatus for authenticating online transactions using a browser and a secure channel with an authentication server

Family Applications Before (1)

Application NumberTitlePriority DateFiling Date
US12/641,156Expired - Fee RelatedUS8245030B2 (en)2008-12-192009-12-17Method for authenticating online transactions using a browser

Family Applications After (1)

Application NumberTitlePriority DateFiling Date
US13/358,160Expired - Fee RelatedUS8528076B2 (en)2008-12-192012-01-25Method and apparatus for authenticating online transactions using a browser and a secure channel with an authentication server

Country Status (2)

CountryLink
US (3)US8245030B2 (en)
TW (2)TWI436627B (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
WO2013059866A1 (en)*2011-10-252013-05-02Misolutions Pty LtdRemote device authentication system and method
TWI505491B (en)*2013-02-042015-10-21Hon Hai Prec Ind Co Ltd Photoresistance
US9424543B2 (en)2012-09-272016-08-23International Business Machines CorporationAuthenticating a response to a change request
US10142309B2 (en)2014-12-192018-11-27Dropbox, Inc.No password user account access
US20190370790A1 (en)*2018-06-052019-12-05Jpmorgan Chase Bank, N.A.Systems and methods for using a cryptogram lockbox

Families Citing this family (46)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
EP1779216A1 (en)*2004-08-202007-05-02Rhoderick John Kennedy PughServer authentication
CN102332977A (en)*2010-07-132012-01-25F2威尔股份有限公司Use ISP's server and certificate server authentication user's method
US9071616B2 (en)2010-11-182015-06-30Microsoft Technology Licensing, LlcSecuring partner-enabled web service
US20120215658A1 (en)*2011-02-232012-08-23dBay Inc.Pin-based payment confirmation
US8789154B2 (en)*2011-06-302014-07-22Qualcomm IncorporatedAnti-shoulder surfing authentication method
US9609000B2 (en)*2012-06-062017-03-28Nec CorporationMethod and system for executing a secure application on an untrusted user equipment
US9716691B2 (en)2012-06-072017-07-25Early Warning Services, LlcEnhanced 2CHK authentication security with query transactions
US10025920B2 (en)2012-06-072018-07-17Early Warning Services, LlcEnterprise triggered 2CHK association
US9887983B2 (en)2013-10-292018-02-06Nok Nok Labs, Inc.Apparatus and method for implementing composite authenticators
US10270748B2 (en)2013-03-222019-04-23Nok Nok Labs, Inc.Advanced authentication techniques and applications
US9396320B2 (en)2013-03-222016-07-19Nok Nok Labs, Inc.System and method for non-intrusive, privacy-preserving authentication
AU2014268112A1 (en)*2013-05-142015-11-12Touch Networks Australia Pty LtdMethod of processing a transaction request
US9961077B2 (en)2013-05-302018-05-01Nok Nok Labs, Inc.System and method for biometric authentication with device attestation
CN104518876B (en)*2013-09-292019-01-04腾讯科技(深圳)有限公司Service login method and device
US9577999B1 (en)2014-05-022017-02-21Nok Nok Labs, Inc.Enhanced security for registration of authentication devices
US9654469B1 (en)2014-05-022017-05-16Nok Nok Labs, Inc.Web-based user authentication techniques and applications
US9413533B1 (en)2014-05-022016-08-09Nok Nok Labs, Inc.System and method for authorizing a new authenticator
US9875347B2 (en)2014-07-312018-01-23Nok Nok Labs, Inc.System and method for performing authentication using data analytics
US9749131B2 (en)2014-07-312017-08-29Nok Nok Labs, Inc.System and method for implementing a one-time-password using asymmetric cryptography
US10148630B2 (en)2014-07-312018-12-04Nok Nok Labs, Inc.System and method for implementing a hosted authentication service
US9455979B2 (en)2014-07-312016-09-27Nok Nok Labs, Inc.System and method for establishing trust using secure transmission protocols
US9736154B2 (en)2014-09-162017-08-15Nok Nok Labs, Inc.System and method for integrating an authentication service within a network architecture
US9059985B1 (en)*2014-12-082015-06-16Fmr LlcMethods for fraud detection
CN105991514B (en)*2015-01-282019-10-01阿里巴巴集团控股有限公司A kind of service request authentication method and device
US10341342B2 (en)2015-02-052019-07-02Carrier CorporationConfiguration data based fingerprinting for access to a resource
RU2015115352A (en)*2015-04-242016-11-20Закрытое акционерное общество "Лаборатория Касперского" The way to launch the browser in protected mode
AU2016340025B2 (en)*2015-10-162021-12-09Kasada Pty LtdDynamic Cryptographic Polymorphism (DCP) system and method
RU2635276C1 (en)*2016-06-242017-11-09Акционерное общество "Лаборатория Касперского"Safe authentication with login and password in internet network using additional two-factor authentication
US10769635B2 (en)2016-08-052020-09-08Nok Nok Labs, Inc.Authentication techniques including speech and/or lip movement analysis
US10637853B2 (en)2016-08-052020-04-28Nok Nok Labs, Inc.Authentication techniques including speech and/or lip movement analysis
US10237070B2 (en)2016-12-312019-03-19Nok Nok Labs, Inc.System and method for sharing keys across authenticators
US10091195B2 (en)2016-12-312018-10-02Nok Nok Labs, Inc.System and method for bootstrapping a user binding
US11868995B2 (en)2017-11-272024-01-09Nok Nok Labs, Inc.Extending a secure key storage for transaction confirmation and cryptocurrency
US11831409B2 (en)2018-01-122023-11-28Nok Nok Labs, Inc.System and method for binding verifiable claims
CN109104456A (en)*2018-06-072018-12-28北京本邦科技股份有限公司A kind of user tracking based on browser fingerprint and propagating statistics analysis method
EP3588347B1 (en)2018-06-292021-01-13AO Kaspersky LabSystems and methods for identifying unknown attributes of web data fragments when launching a web page in a browser
RU2697960C1 (en)2018-06-292019-08-21Акционерное общество "Лаборатория Касперского"Method of determining unknown attributes of web data fragments when launching a web page in a browser
US12041039B2 (en)2019-02-282024-07-16Nok Nok Labs, Inc.System and method for endorsing a new authenticator
US11792024B2 (en)2019-03-292023-10-17Nok Nok Labs, Inc.System and method for efficient challenge-response authentication
US11200548B2 (en)2019-12-092021-12-14Evan Chase RoseGraphical user interface and operator console management system for distributed terminal network
US10873578B1 (en)*2019-12-092020-12-22Evan Chase RoseBiometric authentication, decentralized learning framework, and adaptive security protocols in distributed terminal network
US11113665B1 (en)2020-03-122021-09-07Evan Chase RoseDistributed terminals network management, systems, interfaces and workflows
US10902705B1 (en)2019-12-092021-01-26Evan Chase RoseBiometric authentication, decentralized learning framework, and adaptive security protocols in distributed terminal network
US12238101B2 (en)*2021-03-092025-02-25Oracle International CorporationCustomizing authentication and handling pre and post authentication in identity cloud service
US12126613B2 (en)2021-09-172024-10-22Nok Nok Labs, Inc.System and method for pre-registration of FIDO authenticators
TWI845063B (en)*2022-12-132024-06-11臺灣網路認證股份有限公司System and method for providing server to sign calculation data generated from article to be sign

Citations (6)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20020138561A1 (en)*2001-02-162002-09-26Gemini Networks, Inc.System, method, and computer program product for an end-user of an open access network to select a new service provider following a discontinuance of a business relationship between their current service provider and the operator of the open access network
US20040003287A1 (en)*2002-06-282004-01-01Zissimopoulos Vasileios BillMethod for authenticating kerberos users from common web browsers
US20080166994A1 (en)*2007-01-042008-07-10Bernard KuMethods and apparatus to implement an internet multimedia sub-system (IMS) terminal
US7720997B1 (en)*2001-12-192010-05-18Cisco Technology, Inc.Path selection system
US8065417B1 (en)*2008-11-172011-11-22Amazon Technologies, Inc.Service provider registration by a content broker
US8074259B1 (en)*2005-04-282011-12-06Sonicwall, Inc.Authentication mark-up data of multiple local area networks

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US6041411A (en)*1997-03-282000-03-21Wyatt; Stuart AlanMethod for defining and verifying user access rights to a computer information
US6148407A (en)*1997-09-302000-11-14Intel CorporationMethod and apparatus for producing computer platform fingerprints
US7885899B1 (en)*2000-02-082011-02-08Ipass Inc.System and method for secure network purchasing
US7272728B2 (en)*2004-06-142007-09-18Iovation, Inc.Network security and fraud detection system and method
CN101682439B (en)*2007-04-232012-07-04Lg电子株式会社 Methods of using content, methods of sharing content, and devices based on security levels
US20110202982A1 (en)*2007-09-172011-08-18Vidoop, LlcMethods And Systems For Management Of Image-Based Password Accounts
WO2009065135A1 (en)*2007-11-172009-05-22Uniloc CorporationSystem and method for adjustable licensing of digital products
EP2291745B1 (en)*2008-04-152013-07-03Foresee ResultsMethod and medium for remote tracking of user interaction with a webpage
US9633183B2 (en)*2009-06-192017-04-25Uniloc Luxembourg S.A.Modular software protection
US20100333213A1 (en)*2009-06-242010-12-30Craig Stephen EtchegoyenSystems and Methods for Determining Authorization to Operate Licensed Software Based on a Client Device Fingerprint
US20100332400A1 (en)*2009-06-242010-12-30Craig Stephen EtchegoyenUse of Fingerprint with an On-Line or Networked Payment Authorization System
US8733732B2 (en)*2010-05-242014-05-27Eaton CorporationPressurized o-ring pole piece seal for a manifold
US8656456B2 (en)*2010-07-222014-02-18Front Porch, Inc.Privacy preferences management system

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20020138561A1 (en)*2001-02-162002-09-26Gemini Networks, Inc.System, method, and computer program product for an end-user of an open access network to select a new service provider following a discontinuance of a business relationship between their current service provider and the operator of the open access network
US7720997B1 (en)*2001-12-192010-05-18Cisco Technology, Inc.Path selection system
US20040003287A1 (en)*2002-06-282004-01-01Zissimopoulos Vasileios BillMethod for authenticating kerberos users from common web browsers
US8074259B1 (en)*2005-04-282011-12-06Sonicwall, Inc.Authentication mark-up data of multiple local area networks
US20080166994A1 (en)*2007-01-042008-07-10Bernard KuMethods and apparatus to implement an internet multimedia sub-system (IMS) terminal
US8065417B1 (en)*2008-11-172011-11-22Amazon Technologies, Inc.Service provider registration by a content broker

Cited By (8)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
WO2013059866A1 (en)*2011-10-252013-05-02Misolutions Pty LtdRemote device authentication system and method
US9424543B2 (en)2012-09-272016-08-23International Business Machines CorporationAuthenticating a response to a change request
TWI505491B (en)*2013-02-042015-10-21Hon Hai Prec Ind Co Ltd Photoresistance
US10142309B2 (en)2014-12-192018-11-27Dropbox, Inc.No password user account access
US20190370790A1 (en)*2018-06-052019-12-05Jpmorgan Chase Bank, N.A.Systems and methods for using a cryptogram lockbox
WO2019236718A1 (en)*2018-06-052019-12-12Jpmorgan Chase Bank, N.A.Systems and methods for using a cryptogram lockbox
US12008548B2 (en)*2018-06-052024-06-11Jpmorgan Chase Bank , N.A.Systems and methods for using a cryptogram lockbox
US20240273517A1 (en)*2018-06-052024-08-15Jpmorgan Chase Bank, N.A.Systems and methods for using a cryptogram lockbox

Also Published As

Publication numberPublication date
US8528076B2 (en)2013-09-03
US8245030B2 (en)2012-08-14
TW201424316A (en)2014-06-16
TWI436627B (en)2014-05-01
TWI543574B (en)2016-07-21
US20120131332A1 (en)2012-05-24
US20100174900A1 (en)2010-07-08
TW201036388A (en)2010-10-01

Similar Documents

PublicationPublication DateTitle
US8528076B2 (en)Method and apparatus for authenticating online transactions using a browser and a secure channel with an authentication server
US8156335B2 (en)IP address secure multi-channel authentication for online transactions
CN103944900B (en)It is a kind of that attack prevention method and its device are asked across station based on encryption
JP4861417B2 (en) Extended one-time password method and apparatus
US9294288B2 (en)Facilitating secure online transactions
CN101803272B (en)Authentication system and method
US8209744B2 (en)Mobile device assisted secure computer network communication
CN104767731B (en)A kind of Restful move transactions system identity certification means of defence
US20080022085A1 (en)Server-client computer network system for carrying out cryptographic operations, and method of carrying out cryptographic operations in such a computer network system
CN101449548A (en)Secure internet transaction method and device
US7565538B2 (en)Flow token
JP5186648B2 (en) System and method for facilitating secure online transactions
Badra et al.Phishing attacks and solutions
Li et al.Mitigating csrf attacks on oauth 2.0 systems
Deeptha et al.Extending OpenID connect towards mission critical applications
WO2010070456A2 (en)Method and apparatus for authenticating online transactions using a browser
Ellison et al.Security and privacy concerns of internet single sign-on
Beshiri et al.Security issues in the RESTful API (service) using OAuth 2.0 for authentication and authorization
KuacharoenSingle Password Authentication Protocol
TWI394420B (en)Ip address secure multi-channel authentication for online transactions
CN102332977A (en)Use ISP's server and certificate server authentication user's method
Choukse et al.An intelligent anti-phishing solution: password-transaction secure window
Choubey et al.Improving banking authentication using hybrid cryptographic technique
Lakshmeeswari et al.Anti-Phishing Frame-Work applying Visual Cryptography Mechanism
Oppliger et al.PROTECTING ECOMMENCE AGAINST THE MAN-IN-THE-MIDDLE

Legal Events

DateCodeTitleDescription
STCBInformation on status: application discontinuation

Free format text:ABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTION


[8]ページ先頭

©2009-2025 Movatter.jp