Data network security system and method

Multiplex communications – Pathfinding or routing – Combined circuit switching and packet switching

Reexamination Certificate

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

Reexamination Certificate

active

06252869

ABSTRACT:

TECHNICAL FIELD
This invention relates generally to secure communications over data networks, and particularly to a method for secure transactions for information, interactive services, and secure payment for other services and goods that may be purchased over data networks.
BACKGROUND OF THE INVENTION
Currently, a multitude of services are available to users over data networks such as the Internet. These services include information and interactive services deliverable over the network, and goods and services that may be shopped for and ordered over the network but are not deliverable over the network (e.g., clothing, food, etc.). Despite the plethora of available services and the apparent convenience for consumers of virtual shopping from electronic merchants or service providers (SPs), individuals are generally wary of electronic shopping and particularly, are reluctant to send credit card or other sensitive information over the Internet, since it is well publicized that personal credit card information should not be transmitted over a public data network, which may be subject to unauthorized access. It is also well publicized that individuals have cracked security coding mechanisms (e.g., RSA encryption) used in commercial software for secure communications on the Internet. It is therefore possible, for instance, that while en route to a targeted SP, encrypted credit card or other sensitive information may be intercepted at intervening routers by “hackers” or other eavesdroppers, who can decrypt the information.
Some providers of “non-electronically” delivered goods or services (e.g., goods delivered off-line; e.g., food, clothing, etc.) provide an option for avoiding sending sensitive information over the Internet by posting 800 telephone numbers that a user later calls off-line to pay for the goods or services which were ordered (but not paid for) over the Internet. This approach, however, is not only cumbersome, thus negating the appeal and purpose of virtual shopping and on-line purchasing of goods and services, but is also not suited as a payment method for goods and services (including information) which are delivered over the Internet (referred to hereinafter as “electronic goods”), and which are preferably delivered interactively in one session as part of a single transaction.
It may be understood that the lack of a secure transaction mechanism limits the further development of the Internet, the availability of service providers to users, and particularly the viability of smaller SPs. It is known that in addition to providing gateway access to the Internet and the thousands of small service providers around the world, large information service providers such as Prodigy, America Online and Compuserve provide their own information and interactive services. Users may also access the Internet and the thousands of smaller information service providers (ISPs) directly through smaller user-local Internet access providers. Generally, the large information service providers bill their customers on a time-usage basis after a financial payment relationship has been established, with the user/customer receiving a monthly bill which may include additional charges for usage of certain information and services and which is paid via the conventional postage system. Similarly, the smaller user-local Internet access providers usually also base their service charges to their subscribers for access to the Internet on a time-usage basis.
The smaller ISPs, however, currently either do not charge for access to their information and interactive services, or, if they do, also require the user to establish some sort of financial relationship whereby the user subscribes to the ISP and pays a bill via the conventional postage system. A frequent user of a particular established ISP may not be adverse to establishing a financial relationship for payment purposes. Typically, however, and in accordance with a fundamental concept of using the Internet (e.g., “surfing the net” using Web browsers which link websites by hypertext), a user accesses many different ISPs, each on only a casual and often unanticipated basis, and is not likely to want or be able to establish a plethora of financial relationships with so many different providers. ISPs that do or want to charge for access to their information and/or interactive services could do so by requiring the user to input their credit card number before data service is provided. Yet, as discussed above, users are loath to sending credit card information over the Internet, and therefore, would likely eschew such ISPs, who are typically smaller ISPs.
Accordingly, it may be appreciated that from the standpoint of the user/consumer, such a security and privacy risk effectively preempts the ostensible convenience of services available over data networks, and also limits the actual availability of information and interactive services to those which are free of charge or are charged within the purview of existing financial relationships (e.g., information from a user's service provider). From the standpoint of the SPs, the absence of a secure on-line billing mechanism limits the virtual marketplace, and its potential returns. In addition, the lack of a secure payment mechanism limits the number of SPs which can enter this marketplace, thereby limiting competition which would also likely benefit users/consumers.
There is a need, therefore, for improved secure communication methods over data networks, and particularly, for improved methods which provide enhanced security for users to send credit card or other sensitive information to Internet SPs.
SUMMARY OF THE INVENTION
The present invention overcomes the above, and other, prior art limitations by providing a secure communication mechanism which does not require credit card or other sensitive information to be transmitted over the data network (e.g., Internet) to a SP which charges for information and/or services and/or goods (including non-electronically delivered and electronically delivered goods). In accordance with the present invention, for secure or private communication of sensitive information over a data network, a telephone connection is established between the originating server to which the user is connected for access to the data network and the SP to which the sensitive information is directed.
In accordance with an embodiment of the invention, the telephone connection is established for user payment to an ISP for receiving from the ISP information and/or interactive services via the data network such as the Internet (i.e. electronically delivered goods or services) and/or for paying an ISP for non-electronically delivered goods or services ordered over the Internet. Users access a terminating ISP server from an originating access SP server as they usually do on a first connection over the Internet or any other data network via routing point servers, using a technology such as Web client/server technology. Any communications or transactions to a terminating ISP server involving credit card or other sensitive information are effected, however, on a second connection through a telephone call placed to a telephone number of the terminating ISP server. After receiving a call, and by associating such call with the user's request over the Internet for information and/or interactive services, and/or non-electronically deliverable goods or services, the ISP provides the user with the requested information and/or service, or approves delivery of the non-electronically deliverable goods or services. With the arrangement, payment is effected without providing credit card information via the Internet routing servers and without establishing a financial relationship with the ISP. Preferably, the communication of information over the telephone line between the originating server and the terminating ISP server is also subject to encryption.
In one embodiment of the invention when, based on actions of the user accessing the data network via an originating access SP server, if a terminating ISP requ

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Data network security system and method does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Data network security system and method, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Data network security system and method will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-2453286

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.