Current embodiments provide for authorization and payment of an online
commercial transaction between a purchaser and a merchant including
verification of an identity of the purchaser and verification of an
ability of the purchaser to pay for the transaction, where the identity
provider and the payment provider are often different network entities.
Other embodiments also provide for protocols, computing systems, and
other mechanisms that allow for identity and payment authentication using
a mobile module, which establishes single or multilevel security over an
untrusted network (e.g., the Internet). Still other embodiments also
provide for a three-way secure communication between a merchant,
consumer, and payment provider such that sensitive account information is
opaque to the merchant, yet the merchant is sufficiently confident of the
consumer's ability to pay for requested purchases. In yet another
embodiment, electronic billing information is used for authorization,
auditing, payment federation, and other purposes.