发明名称 ELECTRONIC TRANSACTION SYSTEMS AND METHODS THEREFOR
摘要 <p>A method and apparatus are disclosed for approving a transaction request between an electronic transaction system and a portable electronic authorization device (PEAD) carried by a user using an electronic service authorization token. The method includes the steps of receiving at the PEAD first digital data representing the transaction request. The PEAD provides information to the user regarding an ability to approve the transaction request. When the transaction request is approved by the user, the PEAD receives second digital data representing the electronic service authorization token. In one aspect of the invention, the method and apparatus include a remote agent server that provides a bridge between the electronic transaction system and the PEAD. In an embodiment providing a further level of security, the private key is stored on the portable device, encrypted. The decryption key is stored outside of the device, at a trusted 3rd party location. When the user attempts to make a signature the software sends a request for the decryption key, along with the user's password or pass phrase keyed in at the keyboard of the PDA, smart phone, or cell phone, to a server belonging to the trusted 3rd party. This password is usually, but not always, different than the password stored in the PEAD. The server checks the password or pass phrase and, if it is correct sends the decryption key to the portable device, where it is used once and immediately discarded. In yet another aspect of the invention, the user's password is securely encoded in the method and apparatus and are used at a point-of-sale location. Advantages of the invention include the ability to securely and conveniently perform transactions in a portable device.</p>
申请公布号 WO2002069291(A2) 申请公布日期 2002.09.06
申请号 US2002005701 申请日期 2002.02.22
申请人 发明人
分类号 主分类号
代理机构 代理人
主权项
地址