发明名称 Secure identity authentication in an electronic transaction
摘要 An approach is provided for securely authenticating an identity of a user participating in an electronic transaction. A request is received from a mobile device to initiate the electronic transaction. Attributes of the user and request are received. A request is selected for a biometric identifier or a security question to authenticate the identity of the user. The request for the biometric identifier or security question is converted to a complete Quick Response (QR) code. Based on the user and request attributes, the complete QR code is disassembled into first and second portions by employing a disassembly algorithm. The first portion, but not the second portion, is sent to the mobile device, which prevents an entity other than the user and the enterprise from obtaining the request for the biometric identifier or security question by capturing network traffic that includes the electronic transaction.
申请公布号 US9413757(B1) 申请公布日期 2016.08.09
申请号 US201514597827 申请日期 2015.01.15
申请人 International Business Machines Corporation 发明人 Sadacharam Saravanan;Viswanathan Ram
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Schmeiser, Olsen & Watts 代理人 Schmeiser, Olsen & Watts ;Pivnichny John
主权项 1. A method of securely authenticating an identity of a user participating in an electronic transaction with an enterprise, the method comprising the steps of: a computer receiving a request from a mobile device of the user to initiate the electronic transaction and receiving information that specifies attributes of the user and the request; the computer selecting a request for a biometric identifier or a security question to authenticate the identity of the user; the computer converting the selected request for the biometric identifier or the security question to a first complete Quick Response (QR) code; based on the information that specifies the attributes of the user and the request, the computer disassembling the first complete QR code into first and second portions of the first complete QR code, the first portion of the first complete QR code selected by a QR code disassembly algorithm, and the first and second portions of the first complete QR code not having an element in common; the computer sending to the mobile device the first portion of the first complete QR code, but not the second portion of the first complete QR code, which prevents an entity other than the user and the enterprise from obtaining the request for the biometric identifier or the security question by capturing network traffic that includes the electronic transaction; in response to a scan of the first portion of the first complete QR code by the mobile device, a reassembly of the first complete QR code by the mobile device which employs the first portion of the first complete QR code and a QR code assembly algorithm, a display by the mobile device of the request for the biometric identifier or the security question, a receipt by the mobile device of the biometric identifier or an answer to the security question, a conversion of the biometric identifier or the answer to the security question to a second complete QR code, a disassembly of the second complete QR code into first and second portions of the second complete QR code by employing the QR code disassembly algorithm, and a transmission of the first portion of the second complete QR code from the mobile device to the computer, the computer reassembling the second complete QR code by employing the QR code assembly algorithm and the first portion of the second complete QR code, which prevents the entity other than the user and the enterprise from obtaining the biometric identifier or the answer to the security question by capturing the network traffic that includes the electronic transaction; the computer extracting the biometric identifier or the answer to the security question from the second complete QR code; the computer determining whether the extracted biometric identifier or the answer to the security question matches a record in a data repository that includes biometric identifiers or answers to security questions; and if the extracted biometric identifier or the extracted answer to the security question matches the record in the data repository, the computer authorizing the electronic transaction or if the extracted biometric identifier or the extracted answer to the security question does not match any record in the data repository, the computer indicating the electronic transaction is not authorized.
地址 Armonk NY US
您可能感兴趣的专利