发明名称 System and method for partner key management
摘要 A system and method for implementing an interoperable credential management protocol for processing online transactions. The protocol, referred to as the Partner Key Management (PKM) protocol provides an improved alternative to traditional public key infrastructure (PKI), particularly for use in high-value commercial transactions which require additional controls on the use of credentials for authentication and authorization. According to the PKM protocol, a user may take advantage of credential interoperability by using the same credential at a plurality of different financial institutions for authentication or digital signatures. Additionally, the credential interoperability achieved according to the PKM protocol allows the user to employ the same credential at a plurality of financial institutions for the purpose of digital or electronic signatures.
申请公布号 US9608826(B2) 申请公布日期 2017.03.28
申请号 US201012826311 申请日期 2010.06.29
申请人 JPMorgan Chase Bank, N.A. 发明人 Benson Glenn Stuart;Croston Sean
分类号 H04L9/32;G06Q20/38;G06Q20/40;G06Q40/00 主分类号 H04L9/32
代理机构 Goodwin Procter LLP 代理人 Goodwin Procter LLP
主权项 1. A method comprising: storing, by an institution computer of a first institution, a file comprising a stored policy statement mutually agreed upon by the first institution and a user, wherein the stored policy statement comprises security procedures governing transactions between the first institution and the user; generating a credential to execute a plurality of online transactions with the first institution and a second institution; generating a digital signature with the credential using Portable Security Transaction Protocol; receiving, by the institution computer, a request from the user for registration of the credential; examining, by the institution computer, the request for registration of the credential; determining whether the request for registration of the credential complies with registration requirements established by the first institution; in response to determining that the request for registration of the credential complies with the registration requirements established by the first institution, registering, by the institution computer, the credential to represent the user with regard to a plurality of online transactions with the first institution; receiving, from the user, a request for an online transaction comprising a received policy statement and the digital signature, wherein the received policy statement comprises security procedures governing transactions between the first institution and the user; verifying the identity of the user by examining the digital signature; determining whether the received policy statement complies with the stored policy statement; and in response to verifying the identity of the user and determining that the received policy statement complies with the stored policy statement, authorizing, by the institution computer, the requested online transaction; and executing the requested online transaction.
地址 New York NY US