Current embodiments provide for 
authorization and 
payment of an online commercial transaction between a purchaser and a merchant including 
verification of an identity of the purchaser and 
verification of an ability of the purchaser to pay for the transaction, where the 
identity provider and the 
payment provider are often different network entities. Other embodiments also provide for protocols, 
computing systems, and other mechanisms that allow for identity and 
payment authentication using a mobile module, which establishes single or 
multilevel security over an untrusted network (e.g., 
the Internet). Still other embodiments also provide for a three-way 
secure communication between a merchant, 
consumer, and payment provider such that sensitive account information is opaque to the merchant, yet the merchant is sufficiently confident of the 
consumer's ability to pay for requested purchases. In yet another embodiment, 
electronic billing information is used for 
authorization, auditing, payment federation, and other purposes.