Current embodiments provide for
authorization and
payment of an online commercial transaction between a purchaser and a merchant including
verification of an identity of the purchaser and
verification of an ability of the purchaser to pay for the transaction, where the
identity provider and the
payment provider are often different network entities. Other embodiments also provide for protocols,
computing systems, and other mechanisms that allow for identity and
payment authentication using a mobile module, which establishes single or
multilevel security over an untrusted network (e.g.,
the Internet). Still other embodiments also provide for a three-way
secure communication between a merchant,
consumer, and payment provider such that sensitive account information is opaque to the merchant, yet the merchant is sufficiently confident of the
consumer's ability to pay for requested purchases. In yet another embodiment,
electronic billing information is used for
authorization, auditing, payment federation, and other purposes.