Risk of personal identity theft, especially in connection with on-line
commerce, is mitigated by maintaining private data in a secure database
maintained by a trusted third party verification service. To authenticate
the identity of a user or customer, in one embodiment, a knowledge-based
challenge is issued to the user, and the response is compared to stored
data by the verification service. The verification service reports to the
vendor, to authenticate the user identity, capability and or
authorization for the proposed transaction without disclosing private
data to the vendor.