System and method for providing temporary access credentials for accessing a physical location

The system provides secure and efficient temporary access control by using a digital access rights locker and multi-factor authentication to manage and enforce access rights, addressing vulnerabilities in existing systems.

JP7791960B2Active Publication Date: 2025-12-24AXS GROUP LLC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024186925
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-11-07
Filing Date
2024-10-23
Publication Date
2025-12-24
Estimated Expiration
2043-03-24

Smart Images

  • Figure 0007791960000001
    Figure 0007791960000001
  • Figure 0007791960000002
    Figure 0007791960000002
  • Figure 0007791960000003
    Figure 0007791960000003
Patent Text Reader

Abstract

To provide an efficient user access and remove an unauthorized person from a physical location to secure safety of the location in electronic access control to the physical location.SOLUTION: A physical location access control system is configured to receive, via a network interface, a request to provide a temporary access right for a first physical location to a first user, the request providing an indication as to a first time period associated with the temporary access right. In response to determining that a requester has an access right to the first physical location for a second time period including the first time period, a temporary access token corresponding to the first time period is created and the requester's access right to access the first physical location for the first time period is disabled. The temporary access token is transmitted to a device associated with the first user, enabling the first user to access the first physical location during the first time period.SELECTED DRAWING: Figure 1A
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (Incorporation by reference of priority application) Any foreign or domestic priority claim identified in the Application Data Sheet filed with this application All applications filed are hereby incorporated by reference under 37 CFR 1.57. do.

[0002] (Copyright Notice) A portion of the disclosure of this patent document contains material that is subject to copyright protection. Copyright The parties hereto reserve the right to modify, translate, translate and / or translate this patent document and / or patents as they appear in the U.S. Patent and Trademark Office patent files and / or records. or the facsimile reproduction by anyone of the patent disclosure, All other rights reserved.

[0003] The present disclosure generally relates to systems and methods for providing access to physical locations. do. [Background technology]

[0004] Description of Related Art Electronic access control to physical locations provides efficient user access while , in ensuring the security of the place by excluding unauthorized persons from the place. It is becoming increasingly important. Summary of the Invention

[0005] The following presents a simplified version of one or more aspects in order to provide a basic understanding of the invention. A summary is provided. This summary is not an extensive overview of all contemplated aspects, but rather provides a summary of all aspects. To identify key or critical elements or delineate the scope of any or all aspects. Its sole purpose is to provide a preliminary, more detailed explanation of the invention that follows. This is to present some concepts of these aspects in a simplified form.

[0006] One aspect of the present disclosure is to provide a method for providing a first physical location via a network interface. a request from a requester to provide a first user with temporary access rights to a receiving a request from a requester providing instructions regarding a first period associated with the right of access, determining whether the user has access to the first location during a second time period that includes the first time period; The present invention relates to a physical location access control system configured to: In response to determining that the user has access to the first physical location during a second time period that includes: A temporary access token corresponding to a first time period is generated and used at a first physical location during the first time period. The requester's access rights to the site are revoked. a first user at a first physical location during a first time period; allows access.

[0007] One aspect of the present disclosure relates to a physical location access control system, the system comprising: a network interface and at least one processing device, providing a first user with temporary access to a first physical location via an interface A request from an access controller regarding a first period associated with a temporary access right. and receiving a request from the access controller providing instructions to Providing temporary access to a first physical location to a first user for a first period of time and determining whether the access controller is authorized to access the first physical location. determining that the first user is authorized to receive temporary access rights for a first period of time; creating a temporary access record corresponding to the first time period, at least in part in response to the first time period; the access controller's right of access to a first physical location for a first time period; and sends a message corresponding to the temporary access record to a destination associated with the first user. transmitting a first user access to the first physical location for a first time period, optionally At least one operable to allow temporary access rights in the absence of a corresponding token and one processing unit.

[0008] One aspect of the present disclosure relates to a computer-implemented method, the method comprising: In the system, an access right control is transmitted to a computer via a network interface during a first period. a first access right retrievable by a controller to a first user; have a set of access rights, including a retrievable first access right associated with a physical location; receiving a request from the access rights controller; a first access right retrievable to the first user at least in part in response to the request of recording instructions regarding providing the access rights in a database; Disable the ability of the user to utilize the retrievable first access right associated with the first physical location. and receiving a first access from the access right controller via the network. receiving a reclaim request for access rights and determining whether the reclaimable access rights are currently reclaimable; determining whether the reclaimable access rights are currently reclaimable; and, in response at least in part to the request, a database regarding the reclaim of the reclaimable first access right. and the access rights controller records the instructions in the first retrievable access rights associated with the first physical location. and enabling the ability to utilize the access rights of the first physical location. and revoking the first user's ability to utilize the first available access right. .

[0009] One aspect of the present disclosure relates to a non-transitory computer-readable memory that stores instructions, the instructions , when executed by a computer system including one or more computing devices. a computer system for generating a retrievable record for a first physical location for a first event; receiving a request from a requester at a first time to provide access rights to a first user; A person grants retrievable access to a first physical location for a first event to a first user. determine whether the requester is authorized to provide the Authorized to provide a first user with retrievable access to a first physical location. determining that the first event is recoverable; creating an access provision record corresponding to providing the access right to the first user; Revoke the requester's access right to access the first physical location for the event; sending a message corresponding to the access provision record to a destination associated with the first user, and optionally The first access token for the first event without a corresponding retrievable access token. Performing an action including enabling a first user to access a physical location . [Brief explanation of the drawings]

[0010] Embodiments will now be described with reference to the drawings summarized below. These drawings and The related description is provided to illustrate exemplary aspects of the present disclosure and is not intended to limit the scope of the present invention. It is not intended to limit the scope of the [Figure 1A] FIG. 1A is a diagram illustrating an example of a network environment architecture. [Figure 1B] FIG. 1B shows an example of a system architecture. [Figure 2] FIG. 2 shows an example of the process. [Figure 3] FIG. 3 shows an example of the process. [Figure 4] FIG. 4 shows an example of the process. DETAILED DESCRIPTION OF THE INVENTION

[0011] One aspect of the present disclosure is to provide a service that allows users to access a physical location or other location for a specified period and / or for a specified event. and a system for providing dynamic and temporary access to resources. Digital access rights lockers are not linked to physical locations, physical objects, and / or other To store data indicating your access rights to rights and the status of those rights It can be used for.

[0012] A given access right may be a subordinate access right to a physical location, physical object, and / or other rights. For example, the highest level of access may include one or more physical locations / venues. Multiple related events in a season (e.g., multiple events in a season) Providing users with access to multiple concerts or sporting events Subordinate access rights can be granted to a single event within multiple events at a single physical location. Event (e.g., season tickets where the transferor or lender a single sporting event if you have a ticket; and and / or the lower access rights may include one or more events at one or more physical locations. It may also include access rights for a specified period of time (including start and / or stop dates and times). Subordinate access rights may be for part of one event at a physical location. There may be special restricted areas within the physical location for a given event (e.g., a restaurant or It may also be for access rights to the P section.

[0013] A user (sometimes called an access control owner or access controller) has one or more Upper access rights (e.g., top access rights, lower access rights, further lower access rights) (e.g., the recipient) to another user (sometimes called the recipient or receiving user). It may be possible.

[0014] Thus, for example, the transfer or loan of access rights may be recorded in the form of a start time (date and optionally The access time may be associated with a specific start time of the day and an end time. The transfer or lease of rights shall be subject to a start time (which may be a date and, optionally, a specific start time on that date). The access certificate holder may at any time or revoke such assignment in accordance with the specified revocation rules. The award may be a starting event (a specific event in a season, such as a sports season). Events that are part of a Season may be designated as End Events (which may be designated as specific subsequent events in the Season) and End Events (which may be designated as specific subsequent events in the Season) Optionally, transfer or lease Granting multiple access rights to a given event (e.g., by multiple attendees of an event) This may include multiple tickets that can be used together, thus allowing the transfer or rental of specific access rights. The grant may be temporary in nature or may take the form of a loan of access rights. At its discretion, the access control owner may reclaim any loaned rights at any time. Optionally, the access control owner may reclaim specific or any loaned rights. For example, the access right holder may optionally withdraw the access right once it has been lent. However, the recipient of the access rights can return the loaned access rights. The access right holder may choose to reject the request (e.g., upon request from the access right holder).

[0015] As mentioned above, certain access rights may be granted to venues (e.g., stadiums, concert halls, Events, such as ticketed events, at physical locations (such as theaters, fields, etc.) (e.g., musical performances, sporting events, movies, plays, art exhibitions, etc.) Additionally, access rights can be assigned to specific seats (e.g., seat sections, rows, and (associated with seat number) and / or to a specific location within the venue, such as a VIP section However, in addition or alternatively, the right of access may be Or it can be for a physical item such as an article of clothing.

[0016] Advantageously, such access rights may optionally be determined by the recipient user's device or electronic address (e.g. For example, to an email address, messaging address, or other such address No need to hand over or lend access credentials or keys, or print physical tickets The designated access rights can be transferred or loaned to a receiving user device or electronic access point. Transfer or lend access certificates or keys to the address without the need to transfer or lend them. Therefore, there is no opportunity for the access rights to be intercepted or misused. Significantly improved security.

[0017] Instead, the transfer or loan may be optional and may be subject to data maintained by an access control system. The access rights are recorded in a digital access rights locker, which may be in the form of a base record. Optionally, the access control system may include a synchronized distributed database for storing said records. The database records the access rights holder (e.g., (User who first purchased or owned the Access Rights), and transfer or loan of the Access Rights from the Access Rights Owner. For example, a given access right may include an identifier associated with any recipient of the access right. The right holder has the use of the given access rights or the access rights holder has the given access rights. The access rights may be associated with a logical toggle that indicates whether the access rights are being transferred or loaned to the recipient. If a given access right is transferred or loaned, the corresponding recipient identifier is toggled. In this way, the recipient of the access rights can access the physical or electronic ticket. Even if you do not have an access right token such as a At the same time, the access right holder can activate the ability to gain admission to the access point. This can revoke the ability to use the privilege.

[0018] As discussed above and elsewhere herein, optionally, access rights may be granted. The owner can retrieve certain access rights that he / she has lent to other users. If the access right holder does not retrieve the access right that has been loaned or transferred, The owner of the access rights may be restricted from using the access rights that he / she has loaned or transferred. For example, The access right holder must provide a certificate to access the event to which the corresponding access right has been lent. When a user presents a certificate or biometric, the disclosed system The system can then use the access rights holder record to The right holder's records will be used to determine whether the right has been granted and the event venue's indicators (e.g., (e.g., a display and / or sound emitting device) to deny entry to the access right holder. Optionally, the access right holder may transmit instructions to the user to display an indication that the access right has been loaned. If you withdraw your access rights, the recipient of the loaned access rights may have already used them to enter the venue. A determination can be made as to whether the recipient of the loaned access has already If it is determined that you are using your access rights to access the venue, Those who have access rights may be restricted from retrieving them and may be restricted from entering the event venue.

[0019] For example, if the recipient of the loaned access is still using the access to the event venue, If it is determined that the access rights are not available, the access rights holder will be allowed to reclaim the access rights and The recipient of the loaned access rights may be granted access to the event venue. If it is determined that the access right has been used, the access right holder will be prevented from revoking the access right and the event Entry to the venue may be restricted. As a further example, the loaned access rights may not allow access. If the period prior to the event is determined to be greater than a predetermined threshold period, The person who granted the access rights may be allowed to reclaim the access rights that he / she has granted. If the period prior to the event is determined to be less than a predetermined threshold period, the access right owner This may restrict the collection of loaned access rights and restrict entry to the event venue.

[0020] The revocation of access rights can be recorded via a toggle in the corresponding database record. For recipients of granted (and now revoked) access, the access is revoked. , a notification may be sent indicating that the recipient is no longer available. For example, the notification may an associated electronic address (e.g., email address, messaging service address); and / or in an application configured to provide access rights Furthermore, the recipient may use the loaned access rights to enter the event venue. For example, the system may restrict the access rights from being recorded as having access rights. The system may determine that the recipient has collected the item, and the system may display a message on a display at the event venue indicating that the recipient has collected the item. Instructions may be sent to display a sign that entry is denied.

[0021] To illustrate, attendees and / or devices associated with attendees may be identified by physical location. For example, biometric authentication (e.g., fingerprints, face print data, iris print, etc.), light displayed on the user device, Academic seal (e.g., optical code such as QR code (registered trademark), or other barcode, etc.), an audible indicia generated by a speaker on the attendant device, a radio frequency signal from the attendant device; and / or other means to identify attendees. Wearable computing devices (e.g., smart watches, smart batteries) smart glasses, smart clothing, smart jewelry, etc.), tablet computers , or other portable computing device or token.

[0022] Once attendees are identified, correspondence owned by, transferred to, or loaned to them will be The system searches for permissions, including those that belong to the user, and lists the permissions that are owned, transferred, or loaned ( If so, the attendees will be able to reach the physical location at the current time (e.g., the current event). The right to access the information may be determined by ownership, transfer, or The loaned access rights (if any) allow the attendee to access the current time (e.g., the current event In response to determining that the person in question is entitled to gain access to the physical location, A signal may be generated that allows the seat holder to access the physical location.

[0023] As described elsewhere herein, signals may include visible light indicators, audible tones, and and / or provide a human-perceivable "access granted" indication in the form of haptic feedback Additionally or alternatively, the signal may be used to provide attendees with access to a physical location. The barriers providing access can be unlocked and / or opened.

[0024] Optionally, multi-factor authentication consisting of multiple certificates and geographic location verification is performed by a given attendee. Multi-factor authentication can be used to verify that a user has gained access to a specific physical location. ,access to resources (e.g., entrance to a site such as an event venue) with different types of It provides additional security by requiring two or more certificates. As explained, it is optional. The certificate may include a unique user identifier and a unique user device identifier, to a specific geographic location (e.g., a venue or a specific set of venue entrances, e.g., seating areas) You may need to present it at the entrance.

[0025] You may acquire, transfer, or lend access to an event for one or more attendees, Optionally, in the same manner as above, you may have physical A ticket or a downloaded ticket or access token stored on a user device Instead of providing users with a website, The user's rights may be enforced using multi-factor authentication, which advantageously allows the user to The device does not need to be connected to a network. For example, it can be installed at (or part of) the event venue. User rights to access can be optionally restricted to specific locations (e.g., event venues or venues / seats) This is done by authenticating the user equipment and users at the entrances to the seating area. This can be done.

[0026] For example, an application configured to allow users to access events at a venue. Download the app from an application store (sometimes called an app store) or other source. Optionally, the same application may be used For example, an application can manage fungible electronic tokens. Tokens (sometimes referred to herein as Non-Unique Digital Elements NDE) and Non-Fungible The token (sometimes referred to herein as a unique digital element UDE) is stored in the This may also include access to a wallet (sometimes called a logical storage module) configured in Users are provided with an access control system configured to manage and control event access. You may register an account with the system. A user account is a unique The authentication credentials may include an identifier for the user and / or a unique identifier associated with the user device. The unique identifier associated with the user device may optionally be an identifier other than a telephone number associated with the user device. It may also be an identifier to make it more difficult to imitate. A unique user device identifier, optionally used to perform multi-factor authentication, is provided by the access control system. In some cases, the user equipment may or may not be assigned a specific number.

[0027] For example, the User Equipment Identifier is the International Mobile Equipment Identity (IMEI), a 14-digit number, letters and Unique Device ID (UDID), a 40-digit sequence of numbers, serial number, and advertiser One or more of the following: ID for Google Advertisers (IDFA), Google Advertiser ID for Google (GAID), or Google Advertiser ID for Google (GAID) Optionally, the access control system may include a downloaded application on the user device. Embed a unique identifier in the application, which is then used as a unique device identifier. possible.

[0028] A unique user identifier (optionally used for multi-factor authentication) is provided by the access control system. For example, a user may or may not be assigned a user ID. A user can provide a user ID and the system can search a database of user identifiers. The system may determine that a user identifier is associated with another user or user account. If detected, the user will be prompted by the system to select another user identifier. This process may be repeated until the user specifies what is determined to be a unique user identifier. Optionally, in addition or alternatively, the system may generate a unique user identifier. The user may create a unique user identifier and transmit the assigned unique user identifier to the user device. The provided application utilizes the unique device identifier and performs the authentication / verification described herein. It can be used during the authentication process. Optionally, applications provided on the user device The option provides a unique user device identifier and / or user identifier in a human readable form (alphanumeric or The user may or may not be presented with a text string (using ASCII characters). Thus, the user may be unaware of the actual value of the user device identifier and / or user identifier. There is a match.

[0029] The user enters the venue entrance (which may be the first entrance to the venue building or area, or a VIP to reach a particular seat within a venue, such as an area, or an internal entrance to another area Upon receiving the signal, the user device may optionally encode (e.g., encrypt) the signal from the digital domain to an optical or wireless a unique user device identifier and / or user The user device may present the identifier to the venue scanner (e.g., a unique user device identifier and / or user identifier (through the application provided) and the current time stamp, in a visual indicia (e.g., a QR code or is encoded into a barcode (e.g., a linear barcode) and transmitted as an electronic signal (e.g., Bluetooth via th (registered trademark), Wifi, NFC, etc.) and / or audio signals The timestamp may be used to display the screen of the data submitted by the user. Taking a screenshot or other recording and transferring the screenshot or other recording to another user device and other users attempt to access the event using screenshots or other recordings. This can prevent people from viewing the screenshot or other recording. This is because the timestamp can no longer reflect the current time.

[0030] The user device application may periodically (e.g., every 5, 10, 15, or 30 seconds) (in the example) may update the presentation data and update the timestamp to approximately the current time. The user device identifier and / or user identifier (and optionally a timestamp) are hashed using code, using symmetric encryption, using asymmetric encryption, or in any other way It can be encrypted.

[0031] For example, a symmetric encryption algorithm encrypts a fixed block of data (128 bits) at a time. The algorithm is AES (Advanced Encryption Standard ) can be used. AES uses a substitution network and has a fixed block size (e.g. For example, 128 bits) and a key size of 128, 192, or 256 bits.

[0032] As a further example, RSA (Rivest-Shamir-Adleman) encryption / RSA is a public key cryptosystem, where the encryption key is public and the decryption key is The encryption key is kept secret. RSA users have a public key (based on a large prime number and a complementary value) The data can be created and published using the public key (primes are kept private / secret). Anyone can encrypt it, but only someone who knows the secret key (a prime number) can decrypt it. Triple DES (Data Encryption Standard) encryption / decryption Triple DES is a block encryption technology that can be used (optionally in conjunction with AES). The cryptographic algorithm is applied to each data block three times. Each block is a 64-bit data block. The three keys are used as a bundle key with 56 bits per key. In some forms of ES, all keys were independent, or two out of three keys were independent. Or all three keys are the same (Triple DES). The key length for Triple DES is The security of the key can be 112 bits. For example, a hash function may be used. A hash is generated by applying a hash function. , the plaintext or key is converted to a hashed value. Optionally, the input length is greater than the output hash value. hashes are small in size. The hash value can be reverse engineered to find the original plaintext or It provides a one-way encryption process so that the key cannot be derived.

[0033] Therefore, venue scanners can be cameras, laser scanners, radio frequency receivers, palm scanners, etc. Scanner, microphone device, and / or receiver of a unique user device identifier and / or user identifier The device may include other devices for receiving the signal.

[0034] The timestamp may also be a unique user device identifier and / or user identifier, and a timestamp. When the stamp is received by the venue scanner and / or access control system, may be generated by venue scanners and / or access control systems (or other systems) Venue scanners are encrypted, either directly or through an access control system (or other system). Decrypting the encrypted unique user device user identifier and / or timestamp and Time stamps received from the device and generated by the venue scanner and / or system The timestamps match (for example, exactly, or within a range of 1-15 seconds, etc.). If the authentication fails (match within a specified time range), the venue scanner or system may indicate a failed authentication. do.

[0035] If the timestamps are determined to match, the venue scanner will then issue a direct or access control a unique user device and / or user identifier (or a hash thereof) via the system; A unique user device and / or user identifier (e.g., a unique user ID) may be compared with those in a user database. If the user account's password (or its hash) matches that of the user account, the user account is A determination can be made as to whether the access rights are relevant to one or more access rights to the object. If a hash is used, the hash may be, for example, MD5, SHA-1, or SHA-256. This can be a hash of the user device using a public key associated with the system. If the user device and / or user identifier is encrypted (if asymmetric encryption is used), The private key may be used to decrypt the user device and / or the user identifier. If the user identifier is encrypted using symmetric encryption, the The key may be used to perform the decryption.

[0036] The transferred or loaned access rights may be encoded in a token. Data identifying the access rights controller lending the access rights, the rights transferred or lent Events, locations, associated start times, associated end times, and / or associated data identifying the access rights (e.g., the period of access rights), the status of the access rights (e.g., transfer, loan, return) The access rights data may include data indicative of the recipient's access rights (e.g., receipt), and / or data indicative of the recipient user. The data can be encrypted using a public key, such as the keys discussed elsewhere in this specification. , can be decrypted using the private key.

[0037] As described elsewhere herein, by way of example, transferred or loaned access rights can be used to search for a specific event, all events within a specified period, or events beginning at a specified start time. All events, or the first event and the specified event, until the access right is revoked For subsequent events and all events between the first and subsequent events Therefore, the user and / or the user device may be located in a physical location. Once identified, the user and / or user device is currently at the identified physical location. Does this event correspond to access rights specifically transferred or loaned to the current event? or the access rights are within the period of the transfer or loan to the user, or This applies to the period after the access rights have been transferred or loaned to the user and before the access rights have been reclaimed. or the first specified event or a subsequent specified event or the first specified event A determination can then be made as to whether the event falls within a specific event. do.

[0038] A user account has one or more access rights to an event (e.g., as discussed herein). access rights (such as those transferred or loaned by other users) In this case, the event will be handled through devices at the venue entrance (e.g., display devices, sound generators, opening gates, etc.). For example, authentication / verification displays may be provided to allow users to access the event venue. The authentication success indication may be a light of a specific color (e.g., green) or a text (e.g., "Authentication approved"). "You've been selected"), graphic (e.g., a thumbs-up symbol), and / or sound (e.g., a bell) Optionally, the number of access rights a user has may be displayed via a display at the venue. For example, a user may present access rights for the user and specific friends of the user. Optionally, upon successful authentication / verification, the solenoid, stepper motor, A motor, or other electrical or electromechanical device, is activated to unlock / open the barrier and allow the user ( and one or more other users) into the venue.

[0039] The user account has one or more access rights to the event (e.g., purchased rights, transfers, or loaned access rights), if it is determined that the (e.g., a display, a sound emitting device, a gate that is closing or remains closed, etc.) For example, authentication / validation failure indications can be provided for specific Color (e.g., red) light, text (e.g., "Authentication failed"), graphics The text may include a check mark (e.g., a prohibition sign), and / or a sound (e.g., a booming sound).

[0040] Optionally, authenticating the user as having access to the event or a given venue entrance For a determination to be made that the event is / is verified, the identifier associated with the event venue scanner must be It must be received and verified (eg, in conjunction with a user identifier and a user device identifier). For example, the access rights of a user stored by the system may be determined by which venue entrance the user passed through. (and indicate which venue entrances the user is not entitled to pass through) Therefore, the user identifier, user device identifier, and Even if the timestamp and password are verified, the user device may not be able to access the venue entrance where it was scanned. If the User does not have access rights, a corresponding notice will be sent to the Venue Operator and / or the User at their discretion. Optionally, the notice may be provided to the user to inform them of the access rights they have. This can optionally indicate the entrance to a venue that the user has permission to access. Access to specific seating areas at the event venue is provided, and users have access to Ensure that no one is permitted access to entrances that provide entry to seating areas that they are not authorized to access. I testify.

[0041] Optionally, one or more of the above authentication technologies (e.g., assigned to or authorized by the user) the unique user identifier, unique device identifier, and / or venue authentication scanner identifier provided by the In addition to or instead of a personal identification number (using a unique identifier), biometric authentication may be provided. A camera may be utilized to capture an image of the user device that may be used to authenticate the user. As a further example, a fingerprint reader is used to read a user's fingerprint for authentication purposes. As yet another example, an iris reader may be used to capture a user's iris for authentication. As yet another example, infrared or near-infrared radiation may be used to detect the vein pattern of a user. A palm scanner configured to capture a biometric read of the user may be utilized. The readings can be associated with the stored user readings (corresponding user and device identifiers). If they do not match, a verification failure indication is provided, as described above. possible.

[0042] Thus, a user can be authenticated using any multi-factor authentication, and the user device If the user device does not have a downloaded ticket or the like and the user device is not Even if you don't have internet access at the venue, you can still access the event through your user device. The venue can determine the user's right to access the site. Multi-factor authentication can be used to The user's unique user identifier, unique user identifier, timestamp, and biometric read The information may include two or more of the following: a unique user identifier, a unique address, a unique address value, or a geographic location (e.g., User identifiers, biometric readings, and / or timestamps are stored in a specific location, i.e. (If you need to check at the event venue).

[0043] Optionally, the transfer or loan of access rights from one user to another may be made using tamper-resistant or It may be recorded in a tamper-resistant database. Optionally, the database may be made publicly available. Optionally, a record of the transfer or loan of access rights may be kept on file. A distributed database that is synchronized and available across different sites and geographies by the number of attendees The records may be stored on a distributed digital ledger such as a blockchain. , the user identifier and the current state of the access rights (e.g., whether it was loaned and for how long) It can include (such as whether it was given or not).

[0044] Optionally, the transfer or lending of access rights may be carried out on a distributed digital ledger (e.g., a synchronous distributed ledger). in the form of computer code executable on a synchronous distributed database It can be stored in the form of a smart contract. Transactions can be processed by a synchronous distributed database, This can only occur if the conditions specified in the contract are met. For example, a smart contract is an "if / when...then..." statement written in code on the blockchain. A network of computer systems may include a statement that, under certain conditions, When the conditions are met and verified, an action can be executed. Transaction records are encrypted, making it extremely difficult for hackers to use such records. It can be difficult.

[0045] For example, a synchronous distributed database can identify the access rights administrator who is granting the access rights. data identifying the event, the location, the relevant start time, the rights transferred or rented (e.g., data identifying the access rights (access rights for the relevant end time and / or relevant period) Data indicating the status of the access right (e.g., transfer, loan, repossession, etc.) and / or the recipient user A block or reference to a block containing some or all of the data shown can be stored. The access rights data is stored using a public key, such as the keys discussed elsewhere in this specification. It can be encrypted using a private key and decrypted using a private key.

[0046] For example, the access rights held by the access right holder (e.g., event tickets, VIP rights to space, rights to food or goods, etc.) and their current status (e.g., rented are being loaned, withdrawn, transferred, or in default (e.g., loaned, withdrawn, A user interface that lists all the users who have transferred their accounts (e.g., It is a web page that is presented through a dedicated application such as a chat app or through a browser. The access control owner can then present the access control information to the access control owner (via a predefined page). Depending on the access rights selected, various attributes related to the selected access rights are displayed. (e.g. available loan period, sub-rights available for loan, etc.) The user interface allows the access owner to specify the parameters related to the access loan (e.g. For example, start time, end time, other parameters discussed herein, and / or the like. ) can be specified. The access rights are determined according to the parameters specified by the access right owner. You can provide a field where you can specify who you want to grant access to. For example, the recipient of the access right to the data subject by specifying the electronic address associated with the recipient (e.g., email address) You may specify this via your email address, message service address, or other electronic address. do.

[0047] Optionally, which access rights may be granted, when certain access rights may be granted, How long can access rights be loaned? How many access rights can be loaned at a given time? How many access rights can be granted in a given period (e.g., monthly, yearly, etc.)? whether a given access right can be loaned, how often a given access right can be loaned, and for what period of time Access right lending rules that control how many access rights can be reclaimed during a period The access rights and correspondence granted by the access right holder can be implemented in the system. The user interface allows you to select the loan parameters you want to grant, and also allows you to select which access rights are currently being granted. which access rights can be loaned, which access rights cannot currently be loaned, and which loan parameters are available for a given access right. parameters and / or which loan parameters can be selected for a given access right. This can be pre-configured by the system to indicate whether the item is currently available for loan or not. For unauthorised access rights, the system uses the access rights holder's loan history to and / or based on the access rights lending rules, the access rights owner lends the access rights. The system can determine when access rights are granted. the dates and / or other conditions that must be met before the person can loan access rights; The display of the information can be preset in the user interface.

[0048] Optionally, to the Access Holder as a memento or other benefit of the loaned Access. Fungible and / or non-fungible tokens may be provided by the system. For example, a token may contain an image of a ticket for an event to which the loaned access rights correspond, Images, graphics, cryptocurrency or other information of performers at the event to which the access rights grant access Optionally, the granting of tokens is contingent on fulfilling one or more conditions. For example, tokens may be granted virtually immediately upon granting access rights. As a further example, a token may be used to allow a recipient of access rights to use the access rights. In addition, access rights may be granted depending on whether the access rights holder can no longer reclaim them. Tokens may also be awarded in response to a determination that the transaction is not possible.

[0049] Specific embodiments will now be described with reference to the figures.

[0050] FIG. 1A illustrates an exemplary network that may be utilized to implement the exemplary processes herein. The access control system 102 is connected to the network 100 (e.g., Internet, Intranet, cellular network, and / or other networks) via one or more respective venues (or components located at the venues) The system may be in communication with one or more venue systems 104, 106, 108.

[0051] For example, a given venue system may be a venue entrance (an entrance to a venue building, have a corresponding authentication scanner located at the entrance to the building (which may be a building entrance to a restricted area) A given authentication scanner may, for example, identify a user and / or a barcode for authentication purposes. Take an image of the barcode (e.g., 1D or 2D barcode such as QR Code (registered trademark)) a camera configured to acquire a barcode, a barcode scanner (e.g., a laser barcode scanner configured to read and write data from the user device, a radio frequency receiver configured to receive a radio transmission; a user device (e.g., and configured to receive an audible signal containing authentication data from the device (110, 112, 114). microphone, biometric reader (e.g., fingerprint reader, iris reader, palm reader) ), and / or a unique user device and / or other device for receiving a user identifier. A given venue system may include one or more of the following: A network configured to communicate with the authentication system 102 and, optionally, other systems. The network interface may include:

[0052] The access control system 102 may display two-dimensional and / or three-dimensional venue seating charts and event information. For example, the event information may be stored in a given For events, the event date, event name (e.g., performer name, tour name, Sports event team name), event venue, event venue seating / section access Token price, which seat access tokens have been sold and which are available The access control system 102 may store user account information. and may contain some or all of the following: username, user email address, User phone number / SMS / text messaging address, user avatar (user UDE related content that users can select from), geographic information (e.g., physical address, postal code, city, etc.), unique user identifier (e.g., alphanumeric identifier, fingerprint data, data, facial print data, iris print data, etc.), unique user device identifiers, and the access rights ( Event identifier corresponding to the event for which the user has granted access (including subordinate rights), rights (optionally, the loan date, the identification of the event for which the right grants access, the right loan (including identification of the event venue, identification of the event date, and identification of the recipient), Access rights (optionally, loan date, identification of the event for which the access right allows access, (including the identification of the event venue, the event date, and the authorizer) The retrieved loaned access rights (optionally, the date of the retrieved loan, the date the retrieved access rights were Identification of the event for which access is being granted, identification of the event venue for which access is being granted, and identification of the event date user preferences (e.g., favorite performers, favorite venues, favorite Music style, etc.), UDEs assigned to users (UDEs are stored in a synchronous distributed database) (including an identifier that allows the UDE to be placed in a different location), a UDE that the user reassigns to another person, the fees paid to you, your unique UDE / cryptocurrency e-wallet identifier, and / or this Other user-related data disclosed to.

[0053] The access control system 102 may also perform venue authentication, as described elsewhere herein. You can configure the scanner to authenticate users using authentication data scanned by the scanner. For example, the access control system 102 may be configured to handle a variety of factors when identifying and authenticating a user. Authentication may be used.

[0054] The access control system 102 determines which access rights may be granted and provides predetermined access rights. When can a given access right be granted? For how long can a given access right be granted? How many access rights can be granted, for a given period of time (e.g., monthly, yearly, etc.) How many access rights can be granted to a user, and how frequently a given access right can be exercised. How many access rights can be loaned and how many can be recovered in a given period? It can also be configured to implement access rights lending rules that control access rights. The control system 102 may be configured to preconfigure the user interface described herein. It can also be configured.

[0055] The access control system 102 may also be configured as follows: UDE Allocation Rules; User's Right to Sell, Exchange, or Otherwise Transfer UDE rules governing the conversion of non-unique digital elements into unique digital elements; For example, an access control system can be configured to enforce rules that control 102 is configured to implement the rules and allocation processes described elsewhere herein. It is possible.

[0056] The access control system 102 may be implemented using a distributed ledger 116 (e.g., a blockchain or other It can be configured to record UDEs on a synchronous distributed database. The distributed database 116 can be a public or private synchronous distributed database. The UDE provides access rights, images (e.g., photos, videos, graphics, digital art, It may represent a file (such as a network), a sound file, and / or text. Any rights you provide to users in relation to content represented by a license to use, copy, and display such Content Assets, can be used to establish verified public proof of ownership of a property (e.g., the right to exchange a property). Cut.

[0057] FIG. 1B is a block diagram illustrating example components of the access control system 102. The exemplary access control system 102 may be used to implement aspects of the present disclosure. The present invention includes the arrangement of computer hardware and software components that can be used to implement the present invention. The illustrative components may include more (or fewer) components than those depicted in FIG. 1B. It will be understood that the access control system 102 may be a cloud-based computer The system may include a computer system.

[0058] Regarding cloud-based computer systems, The systems are located in different facilities, remotely accessible, and can be delivered quickly when needed. Hosted computing resources include a collection of physical computing resources that can be accessed This may include cloud computing environments (sometimes referred to as "cloud" computing environments). Certain data set out in the subsection shall be made available on an optional, remotely accessible, and promptly available basis. a hosted storage environment that includes a collection of physical data storage devices that can provide It can be stored using a data store (sometimes called "cloud" storage) ).

[0059] The access control system 102 includes one or more processing units 120B (e.g., general-purpose processors). processor and / or high-speed graphics processor) and one or more network interfaces interface 122B, a non-transitory computer-readable medium drive 124B, and an input / output device and a device interface 126B, all of which communicate with each other via one or more communication buses. The network interface 122B can communicate with one or more networks or computing systems (e.g., venue systems, user devices, distributed ledgers, event The systems described herein have connectivity to systems such as event promoters, seating chart visualization systems, etc. Therefore, the processing unit 120B can communicate with other Receiving information (e.g., access tokens) from a computing device, system, or service Receive and respond to requests and instructions (such as purchases, verification / authentication data, and verification / authentication requests) The processing unit 120B can provide data and / or execute instructions. 4B and further output information via input / output device interface 126B. The input / output device interface 126B may provide a keyboard, mouse, digital It receives input from one or more input devices such as a pen, touch screen, microphone, or camera. It can be included.

[0060] The memory 128B may be configured to allow the processing unit 120B to implement one or more aspects of the present disclosure. The memory 128B may include RAM, , ROM (and variations thereof such as EEPROM) and / or other permanent or non-transitory computer The memory 128B includes a computer-readable storage medium. In the general management and operation of processing unit 120B and its included components Operating system 13 that provides computer program instructions for use by 2B can be stored.

[0061] The memory 128B stores the user name, user email address, user phone number / SMS / Text messaging addresses, other electronic destinations, geographic information (e.g., physical addresses) , postal code, city, etc.), unique user identifiers (e.g., alphanumeric identifiers, fingerprint data, face fingerprint data, iris print data, etc.), a unique user device identifier, and the information to which the user has access. A hash of the event identifier, user device and / or user identifier corresponding to the event ,user preferences (e.g., favorite performers, favorite venues, favorite music styles, etc.) payment device data, and / or other user data as described herein. It may store user accounts including:

[0062] The memory 128B stores events, access tokens, and other information as discussed elsewhere herein. The memory 128B may also store the identity of the access rights granted by the user. Information (optionally, loan date, identification of the event for which the access right grants access, access right loan (including identification of the event venue, identification of the event date, and recipient information), the access rights granted (optionally the loan date, identification of the event for which the access rights grant access, (including the identification of the event venue, the event date, and the identity of the person granting the access right), Recovered loaned access rights (optionally, the date of reclaiming the loan, the date the reclaimed access rights were granted, Identification of the event for which access is being granted, identification of the event venue for which access is being granted, and the date of the event The identity of the recipient, including the identity of the recipient, may be stored in the user record and / or elsewhere.

[0063] Some or all of the data and content discussed herein may optionally be relational database, SQL database, NOSQL database, or other database type Content elements can be stored in a variety of types, which are difficult to handle in traditional databases. BLOB (binary) files such as large images (e.g., still images, videos, multi-layer graphics) It may contain a large object, so it may contain parts of a content element (e.g., a BLOB ) or store everything in a file and store the corresponding reference in a database Optionally, memory 128B may be connected to one or more third-party cloud-based storage systems. It can include

[0064] The authentication and electronic asset management module 134B provides a graphical user interface. A GUI component that generates and / or pre-configures and processes user input, and a search component (search (which may include a search engine used to search for ticketed events) The authentication and electronic asset management module 134B is also configured to authenticate users. As noted above, authentication may involve a unique user identifier and A hash of the unique device identifier generated by the event access system 102 As a further example, authentication can be performed by comparing a unique user data including the user identifier and unique device identifier (e.g., a private key or and decrypts the data using the key used to access the event. This can also be done by comparing the stored data with that stored in the other Optionally, a fixed block (128 bits) of data can be encrypted at a time, similar to what was explained in the previous section. AES (Advanced Encryption Standard), a symmetric encryption algorithm that encrypts For example, RSA (R It is also possible to use the (Burst-Shamir-Adleman) encryption / decryption technology. As yet another example, optional triple DES (Data Encryption Standards Standard encryption / decryption technology can also be used. A hash function may be used. Optionally, biometric measurements of the user may also be used. Authentication may be performed using

[0065] The access rights verification component verifies that an authenticated user has access to the venue (and / or part of the event venue). ) whether you have the relevant rights to access the event and the access rights rules the rule engine (e.g., which access rights may be granted, when a given access right is granted, etc.) How long a given access right can be granted, how much access can be granted at a given time, How many access rights can be granted and for how long in a given period (e.g., monthly, yearly, etc.)? How many access rights can be granted and how frequently a given access right can be granted how many access loans can be redeemed in a given period, and / or similar The method may be configured to determine the following:

[0066] The ticketing module 136B allows users to view information about ticketed events. and use the Event Venue seating chart, view available and unavailable Event Venue seats. View the view from a given seat, view the price of access tokens, viewing the user account (optionally, some of the user account information discussed herein); creating, purchasing or otherwise accessing one or more Events The user acquires the access rights (e.g., access token) that the user has acquired (e.g., Stores an indication of the access rights (purchased by the user, transferred to the user, loaned to the user) storing a representation of the access rights that the user has transferred to others and / or Recommending events (e.g., user preferences, access token acquisition history, geographic location) It can be configured to allow for the use of .

[0067] The image analysis and processing module 138B may also process the image data (e.g., by encoding the encrypted authentication data). Image analysis (for optical indicia) is performed to enhance contrast, deblur, and / or Image rotation is performed to thereby The image decoding and decryption method may be configured to enhance the decoding and decryption of the image (code).

[0068] The memory 128B may include an interface module 130B. The sensor module 130B allows compatible computing devices to perform authentication and electronic asset management. transmit data and content to module 134B and ticketing module 136B; or It can be easily configured to generate one or more interfaces that can be received from can.

[0069] Referring now to Figure 2, an example of an authentication / verification process is shown. This process is described elsewhere in this specification. access control systems, venue systems, and / or other systems, such as those described in In the following example, the user device and the user equipment Although the present document discusses encryption of authentication data presented to Optionally, the user device may transmit the information in unencrypted form (e.g., via a barcode) ) authentication data, the scanner reads the authentication data and encrypts the authentication (e.g. using key encryption or hashing), and optionally by other systems described herein. Encryption may be performed.

[0070] In block 202, a venue authentication scanner is used to access the encrypted authentication data. As mentioned above, the user device scans the encrypted optical via optical codes, via encrypted radio frequency signals, and / or encrypted voice The signal may present a unique user identifier and / or a unique device identifier. For example, the scanner may include a camera, a laser scanner, a radio frequency receiver, or a microphone. It can be seen.

[0071] The scanned authentication data can be compressed. For example, to take an image of the authentication data, If you use a camera to get the best results, compress the image to reduce the file size and The memory required to store the image and the network required to transmit the image are required. Compression can be lossless or lossy. For example, when using lossy compression, a transform code can be used to perform the compression. When lossless compression is used, the Length coding, entropy coding, predictive coding may be used. The data can be decompressed using a decompression module that corresponds to the encryption format.

[0072] Optionally, timestamps generated by applications provided on the user device. The timestamp may or may not be encrypted. Keys embedded in applications (e.g., access control systems or other systems that perform decryption) This can be done using the public key of the system. Optionally, authentication data (e.g. A hash may be applied to the unique user ID and / or unique device ID. Additionally or alternatively, a biometric scanner may be used to capture biometric characteristics of the user (e.g., face print, Fingerprints, iris images, etc.) may also be read.

[0073] In block 204, the encrypted authentication data is decrypted (e.g., the system that performs the decryption Optionally, the received authentication data is hashed (using a decryption key, such as a private key associated with the system). If the authentication data is encrypted, the system does not perform any decryption operations. Optionally, encrypted authentication data can be used to generate a timestamp for the venue authentication. The certificate may be transmitted from the scanner to a remote system that performs the decoding.

[0074] Optionally, performing image analysis and processing on the image of the optical indicium to enhance its readability; Thus, increasing the accuracy in decoding and decryption. The QR code (or other barcode) is black and appears to be set against a dark background on the user device. or on the image, in response to detecting insufficient contrast (e.g. , by not detecting clear edges), contrast enhancement may be performed. Edge boundaries in an image of an optical display, such as the edge between a bar code and a background of contrasting color Identifying boundaries and enhancing image contrast in areas immediately adjacent to detected edges A filter may be used.

[0075] Furthermore, if the optical code is unclear, it is difficult to accurately decode and decode the optical code. Therefore, a deblurring process and / or a noise reduction process may be performed. The deblurring process may include applying a convolution filter to the image of the optical code. The image processing and denoising can be performed using deep learning convolutional neural networks. A convolutional neural network can optionally include a neural network input layer, One or more neural network hidden layers, a neural network pooling layer, and It may include a neural network output layer. Other learning engines may also be used. Neural networks also perform image classification, recognition, localization, and / or object detection. It can be used to optionally convert low-resolution images to high-resolution images. To do this, we can use an autoencoder.

[0076] Optionally, the optical indicia image may be used to further facilitate decoding and decrypting the encoded authentication data. To achieve this, the device can be rotated to match the desired orientation.

[0077] At block 206, a venue entrance identifier is received. The venue entrance identifier is used to authenticate the This can be done at the entrance to the venue where the scanner is located, and can be accessed by authentication scanners or the venue system. The venue identifier may be an alphanumeric code and may be a descriptive message. It may also include metadata (e.g., entrance 1 on the east side of the venue).

[0078] In block 208, the timestamp received from the user device is converted to a system generated timestamp. Determine whether the timestamps match (e.g., exactly the same). If it determines that the A failure signal may be generated. This signal may be a light of a particular color (e.g., red), a display Present text to the screen (e.g., "Authentication failed"), or a graphic to the display (e.g., The system may display a warning sign (e.g., a prohibition symbol) and / or emit a sound (e.g., a booming sound) through a speaker. It can be used to wake up.

[0079] If it is determined that the timestamps match, processing may proceed to block 210. The device ID value received from the user device is matched to a unique device ID in the user account record (e.g. For example, IMEI, UDID, serial number, IDFA, and / or GAID If it is determined that the received device ID does not match, authentication / verification A failure signal may be generated. This signal may be a light of a particular color (e.g., red), a display Present text to the screen (e.g., "Authentication failed"), or a graphic to the display (e.g., The system may display a warning sign (e.g., a prohibition symbol) and / or emit a sound (e.g., a booming sound) through a speaker. It can be used to wake up.

[0080] If it is determined that the device IDs match, processing continues at block 212. The user ID that matches the received value is used to create a user account that stores the matching unique device ID. A determination is made as to whether the received user ID matches a unique user ID in the record. If a match is determined not to occur, an authentication / verification failure signal may be generated, similar to that described above.

[0081] If it is determined that the user IDs match, processing continues at block 214. will use the user ID and / or device ID to view the events at the venue on the current day. Determine whether a user has access to a device through their user account record. For example, you have purchased access rights, access rights have been transferred to you, or access rights have been transferred to you. In the example where access rights are lent to a user, You can determine whether the granted access rights apply to the current event. Example For example, a user might want to create a series of events (e.g., a sports team's season or a musician's event series) and the loan is valid for the specified start and stop dates. If so, whether the current event belongs to the set of events for which access rights have been granted. Whether the current date is included in the start and end times of the access rights loan, In this example, a determination can be made as to whether the loan has been collected. The account belongs to a set of events for which access rights have been granted, and the specified start and end dates are If the access right loan is not collected, it will be at the event venue on the current day. Determines that the user has access to the current event. If not, It may be determined that a user does not have access to an event at an event venue on a given day. can.

[0082] If you decide that you have access to an event at the venue on the current day, optionally In block 216, the venue authentication scanner ID is used to identify the number of visitors the user has access to. It can be determined whether the entrance corresponds to a different venue (e.g., user account A list of seats assigned to users from the portal and the corresponding entrances to access the assigned seats. (by comparing the ID with the actual ID). The venue authentication scanner ID determines the user's access rights. If it is determined that the venue entrance does not correspond to the venue entrance having the authentication / verification failure signal, similar to that described above, Optionally, it may generate text indicating the entrances to the venues to which the user has access. The user may then proceed to such authorized entrance and The scanning of the certificate process can be repeated.

[0083] Determine if the venue authentication scanner ID corresponds to a venue entrance that the user has access to. If so, an entrance signal may be generated in block 218. The entrance signal may be A light of a certain color (e.g., green), a text (e.g., "Authentication Approved"), triggering visuals (e.g., a thumbs-up symbol), and / or sounds (e.g., a bell) Optionally, the entry signal may indicate the number of access rights the user has. The entrance barrier can be unlocked or opened to allow the user access to the entrance. For example, the signal may be used to control solenoids, stepper motors, and / or pneumatic actuators. Activate to unlock and / or open entrance doors, extend barriers, lock turnstiles, Furthermore, the entry signal may be a signal that allows for the release of a lock and / or rotation. It can be used to determine whether to assign a child element to a user. If the access rights are loaned to you by another user, the loaned access rights are not used. An indication that the item is no longer available for collection can be stored in the database.

[0084] Optionally, rather than comparing the user ID and device ID, the user ID received from the user device is compared. hash of the user ID and / or device ID (e.g., radio frequency signals, optical indicia, audio signals) (via the password) and compare it with a hash of the user ID and / or device ID from the user account If there is a match and the timestamps match, If so, processing may proceed to block 212. Otherwise, authentication / verification may proceed as described above. A failure signal may be generated.

[0085] Referring now to Figure 3, an exemplary process for lending access rights is shown. The process may be performed by the access control system 102, the user device, and / or other devices disclosed herein. The present invention may be implemented in whole or in part using a device or system of the present invention. At step 302, the process detects that an access rights user interface has been requested. The access rights user interface displays the access rights associated with the user and the access rights of such users. It can be configured to display the status of access rights. For example, The interface is provided on the user device (e.g., downloaded from an app store). This can be provided by a dedicated application related to the ticketing provided by the user. In response to the use of the interface (e.g., in response to a request by a user), The application sends the corresponding message to the system via the network. As a further example, the access rights user interface may be It can be accessed from the access control system 102 using the provided browser. The user device may transmit identification data associated with the user to the system. a user identifier and a password associated with a dedicated application provided on the user device; a unique code, a unique identifier associated with the user device, biometric data of the user, and and / or other identifying data.

[0086] In block 304, the identification data is accessed in a database record corresponding to the user. The database records the access rights associated with the user and the corresponding It may contain records of contextual data. For example, database records may contain information about the users to whom they have access. Events (e.g., unique event identifier, event name, event date, event venue, event seating location), whether and when a given access right was granted indication of loan parameters (e.g., start and / or stop dates, start and / or stop times, and to whom a given access right is granted (e.g., other parameters disclosed herein). an indication of which access rights have been revoked (and the associated revocation dates) The access rights data may include, but are not limited to, the access rights information, and / or other access rights data as disclosed herein.

[0087] In block 306, access rights lending rules may be retrieved from a data store. For example, access rights lending rules determine which access rights can be granted and when a given access right can be granted. How long a given access right can be granted, and how much access can be granted at a given time. How many access rights can be granted and for how long for a given period (e.g., monthly, yearly, etc.)? How many access rights can be granted and how often a given access right can be granted? which access rights can be revoked, and when the access rights can be revoked (if any) ), how many access rights loans can be recovered in a given period, etc.

[0088] In block 308, the rules engine uses the access rights rules and the access rights data to What access rights can be granted using the If this is not permitted at the current time, when can such access be granted (if (if any), and / or determine which access rights can or cannot be revoked .

[0089] In block 308, the retrieved access rights, access rights status, and Which access rights can currently be loaned and when they can be loaned (if currently loaned) which access rights can be revoked and when they can be revoked; The user device will display information about whether access rights can be reclaimed (or about access rights that cannot currently be reclaimed). This can be used to send the This can be done.

[0090] In block 310, access rights are granted by the user via an access rights user interface. For example, the access rights specification can be one selected by the user. You can specify these access rights and the corresponding access rights lending and / or reclaim specifications. For example, the access rights specification specifies the access rights that a user controls, the access rights that a user grants, You can specify the recipient, the access loan start state, and / or the access loan end date. As a further example, a reclaim access rights specification can specify the access rights that a user wants to reclaim (e.g. For example, the user can use the retrieved access rights or lend or grant the access rights to another recipient. or transferable), and timing of collection (e.g., immediate or specified date or event) You can specify the time.

[0091] In block 312, the access rights rules are optionally re-executed to determine the appropriate access rights loan / withdrawal. Whether the acquisition specification violates any rules and therefore the access right lending / recovery specification The user can determine whether the access loan / recovery specification is allowed. If not, in block 314, a rejection notice is generated and the user device (e.g., a dedicated (for display by applications, browsers, etc.) and / or electronically associated with the user destination (e.g., email address, short message service address, other electronic It may be sent to a destination.

[0092] If the access right loan / recovery specification is permitted, then in block 316, the corresponding For database records, by setting the database toggle accordingly, etc. , may be updated to record the access rights loan and / or redemption. , the designated recipient of a given access right loan, and the recipient from whom the loan is being reclaimed. Notifications may be sent to followers for display, for example, in dedicated applications, browsers, etc. and / or to an electronic address associated with the recipient (e.g. , email address, short message service address, etc.) .

[0093] An exemplary retrieval process is now illustrated with reference to Figure 4. By way of example, the process may be performed using access control System 102, user devices, and / or other devices or systems disclosed herein In block 402, the specified Requests to revoke the access rights granted to the access rights holder are sent via the access rights user interface. The access control information is received from a user device associated with the access control user. Similarly, the access rights user interface displays the access rights and privileges associated with the user. For example, the access rights user can be configured to display the status of the access rights. The interface may be installed on the user device (e.g., downloaded from an app store) This can be provided by a dedicated application related to the ticketing provided. In response to the use of the access rights user interface (e.g., in response to a user request), In response, the application sends a corresponding message to the system over the network. As a further example, the access rights user interface may be The access control system 102 can be accessed through a browser provided on the user device. The user device may transmit identification data relating to the user to the system. The identification data is a user identification associated with a dedicated application provided on the user device. password, unique code, unique identifier associated with the user device, biometric information of the user The information may include associated data, and / or other identifying data.

[0094] In block 404, access rights retrieval rules are executed. For example, The collection rules determine which loan access rights can be revoked / recovered and how many over a given period of time. The number of access rights that can be reclaimed or the expiration date / time when a given access right cannot be reclaimed In block 406, the executed rule specifies whether a time period exists. The executed rule determines whether to allow the reclaim of the loaned access rights. If it is determined that the loaned access right is not to be reclaimed, a denial notice is sent in block 412. and displaying the generated information on the user device (for example, a dedicated application, a browser, etc.). for the purpose of providing the service), and / or electronic addresses associated with the user (e.g., email addresses, The email may be sent to a mailing service address, other electronic destination, etc.

[0095] If the executed rules determine that the loan access rights are permitted to be reclaimed, then block 408 In this case, the access rights are retrieved and the corresponding access rights records are updated in the database accordingly. The system updates the transaction to reflect the withdrawal, for example by setting a toggle. To indicate that the access rights have been reclaimed, the recipient of the loaned access rights and the access rights holder must A notification may be sent to a user who controls access rights. For example, the notification may be sent to a dedicated application. and a receiver device and access rights controller for display by a browser, application, or the like. device and / or the electronic address associated with the recipient (e.g., email address, shopping the relevant electronic address of the access rights controller) It can be sent to the address.

[0096] Thus, one aspect of the present disclosure is to provide a method for detecting a specified period and / or a specified event or is a dynamic and optionally recoverable resource, such as a physical location, for a set of events. The present invention relates to a method and system configured to provide digital access. The Access Locker may optionally grant users access to physical locations, physical objects, and / or other rights. may be used to store data indicating the access rights of users and the status of such rights. can.

[0097] The methods and processes described herein may have fewer or additional steps or states. and steps or states may be performed in a different order. The methods and processes described herein do not necessarily require the implementation of one or more general purpose computers. embodied in software code modules executed by a computer, It can be fully or partially automated. Code modules can be used for any type of code. The method may also be stored on a computer-readable medium or other computer storage device. Alternatively, the entire system may be embodied in whole or in part in dedicated computer hardware. The systems described herein may optionally include a display, a user input device, (e.g., touchscreen, keyboard, mouse, voice recognition, etc.), network interface It may include a surface, etc.

[0098] The results of the disclosed methods can be used to store data in volatile and / or non-volatile memory (e.g., magnetic disk storage). Relational storage using (internal storage, optical storage, EEPROM and / or solid-state RAM) Any type of computer data, including databases and flat file systems It can also be stored in a data repository.

[0099] The various exemplary logic blocks, modules, and methods described in connection with the embodiments disclosed herein Rules, routines, and algorithmic steps are implemented using electronic hardware, computer software, and It can be implemented as hardware, software, or a combination of both. To clearly illustrate this interchangeability with the The steps and methods have been generally described above in terms of their functionality. Whether it is implemented as hardware or software depends on the specific application. The functionality described will vary depending on the design constraints imposed on the overall system and on the implementation. The application may be implemented in a variety of ways, and such implementation decisions are beyond the scope of this disclosure. should not be construed as causing deviation from

[0100] Furthermore, various exemplary logic blocks described in connection with the embodiments disclosed herein and modules may be general-purpose processor devices, digital signal processors (DSPs), application-specific Application-Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs) or Other programmable logic devices, discrete gate and transistor logic, discrete hardware components of the device or designed to perform the functions described herein. It may be implemented or executed by any combination of these machines. The processor unit may be a microprocessor, but may alternatively be a The device may be a controller, a microcontroller, or a state machine, or a combination thereof. The processor unit may be configured to process computer-executable instructions. In another embodiment, the processor unit may include electrical circuitry configured to FPGAs or other programmable devices that perform logical operations without processing computer-executable instructions A processor unit includes a combination of computing devices, e.g., a DSP Combined with a microprocessor, multiple microprocessors, and DSP cores Implemented as one or more microprocessors in combination with other processors, or any other such configuration. Although this specification primarily describes digital technology, the processor device may also be It can also contain primarily analog components. A computing environment can be, to name a few, In other words, microprocessor-based computer systems, mainframe computers digital signal processors, portable computing devices, device controllers, or computing engines of any type, including but not limited to those within consumer electronics devices. It may also include a computer system.

[0101] Any method, process, routine, or algorithm described in connection with the embodiments disclosed herein The elements of the algorithm are software modules executed by a processor unit directly in hardware. A software module can be implemented as a , RAM memory, Flash memory, ROM memory, EPROM memory, EEPROM memory memory, registers, hard disk, removable disk, CD-ROM, or other The program may also reside in any form of non-transitory computer-readable storage medium. The processor device can read information from the storage medium and write information to the storage medium. In the alternative, the storage medium may be coupled to the processor. The processor and storage medium can be integrated into the ASIC. The ASIC can be built into the user terminal. The device and the storage medium may reside as discrete components in a user terminal.

[0102] Conditional language used herein, such as, among others, "can," "might," and "may" "may," "could," "might," "could," "for example," etc., unless otherwise specified. Unless otherwise specified, or understood within the context in which it is used, a particular embodiment does not necessarily refer to specific features, elements, and It is generally intended to convey that embodiments include certain aspects and / or steps, and that other embodiments do not. Therefore, such conditional language may be used to describe a feature, element, and / or step that is more than one. It is not necessary in any way to the above embodiments, or one or more embodiments may require other inputs or These features, elements and / or steps may be incorporated into any particular embodiment, whether or not prompted. This implies that the program necessarily contains logic that determines whether the program is included in or should be executed. The terms "including," "having," and the like are synonymous and are inclusive. When used expansively, it does not exclude additional elements, features, acts, actions, etc., and The term "or" is used in an inclusive (and not exclusive) sense, e.g. When used to connect a list of elements, the term "or" refers to the elements in the list. It can mean one, some, or all.

[0103] Disjunctive language such as phrases like "at least one of X, Y, and Z" is used in The term, etc., may be either X, Y, or Z, or any combination thereof (e.g. It is commonly used to indicate that the Such disjunctive language therefore allows certain embodiments to be understood in the context of X At least one of, at least one of Y, or at least one of Z is present. It is not, and should not be, generally intended to require

[0104] The term "click" refers to a user selecting a control, menu choice, etc. may use other user input, such as voice commands, text input, or gestures. User input may also be used. For example, a text input may be used when a user types text. via a text field and / or a menu selection (e.g., the user selects a check box) drop-down menus, lists, or other selections that can be checked or selected in other ways. The interface, such as through other arrangements (e.g., groups of individually selectable icons), When a user provides an input or activates a control, the corresponding The computing system that executes the command can then execute the corresponding action. Any or all of the data, inputs and instructions provided by the (e.g., a database) from which the system can retrieve the data, inputs, and You may access and obtain instructions and notices / reminders as described herein. The user interface can be a web page, a dedicated or non-dedicated phone application, computer applications, Short Message Service messages (e.g., SM S, MMS, etc.), instant messaging, email, push notifications, voice, pop The information may be provided via an interface, a USB cable, and / or other methods.

[0105] The user terminals described herein include mobile communication devices (e.g., mobile phones), laptops, laptops, tablet computers, interactive televisions, game consoles, media streaming devices Wearable devices, head-worn displays, network watches, and other wearables The user terminal may be in the form of a computing device or the like. , user input devices (e.g., touch screen, keyboard, mouse, voice recognition, etc.), It may include a network interface, etc.

[0106] The foregoing detailed description illustrates, describes and points out novel features applicable to various embodiments. However, various omissions, substitutions, and variations in the form and details of the illustrated devices or algorithms may be present. It will be understood that various modifications and variations can be made without departing from the spirit of the present disclosure. As such, some features may be used or practiced separately from other features and ... Certain embodiments may fall within the scope of the present invention and may not provide all of the features and advantages set forth herein. The scope of the specific embodiments disclosed herein may be embodied in any of the foregoing. The meaning and scope of the claims are as follows: and all changes that come within the range of equivalents are to be embraced within their scope.

Claims

1. 1. A physical location access control system, comprising: A network interface; at least one processing device, receiving, via the network interface, a request from an access controller to provide temporary access to a first user to a first physical location, the request from the access controller providing an indication of a first time period associated with the temporary access right; in response at least in part to the request from the access controller to provide temporary access rights to the first user; creating a corresponding temporary access record corresponding to said first time period; Revoke the access right of the access controller to access the first physical location during the first time period; sending a message corresponding to the temporary access record to a destination associated with the first user; enabling the first user to access the first physical location during the first time period; and at least one processing device operable to:

2. The physical location access control system of claim 1 , wherein the temporary access rights are associated with the right to access restricted areas within the venue.

3. The physical location access control system of claim 1 , wherein temporary access rights are associated with rights to access physical items.

4. The physical location access control system of claim 1 , wherein the temporary access rights relate to rights to access groceries and / or clothing items.

5. The system further comprises: utilizing a history of temporary access rights provided by said access controller; determining a number of temporary access rights provided to the user by the access controller over a second period of time; in response at least in part to determining that the number of temporary access rights provided by the access controller over the second time period is less than a first threshold; determining that the access controller is authorized to provide the first user with the temporary access right to the first physical location for the first time period; 10. The physical location access control system of claim 1, configured to:

6. The system further comprises: utilizing a history of temporary access rights provision associated with said access controller; determining the number of temporary access rights currently provided to the user by the access controller; in response at least in part to determining that a number of temporary access rights currently being provided by the access controller is less than a first threshold; determining that the access controller is authorized to provide the first user with the temporary access right to the first physical location for the first time period; 10. The physical location access control system of claim 1, configured to:

7. The system comprises: During the first period of time, receiving a first hash from a device at the first physical location, the first hash including a hash of an identifier identifying a user communication device associated with the first user and an identifier identifying the first user; comparing the first hash, which includes the hash of the identifier identifying the user communication device associated with the first user and the identifier identifying the first user, to a second hash generated using data stored in a database record associated with the first user; utilizing the temporary access record in response at least in part to determining that the first hash and the second hash match; 2. The physical location access control system of claim 1, configured to perform operations including: transmitting a command configured to cause an indicator of the first physical location to provide an access permission indication based at least in part on the utilized temporary access record.

8. The system comprises: During the first period of time, receiving, from a device at the first physical location, first biometric data of a given user acquired at the first physical location; comparing the received first biometric data with data stored in a database record associated with the first user; utilizing the temporary access record in response at least in part to determining that the first biometric data corresponds to data stored in a database record associated with the first user; 2. The physical location access control system of claim 1, configured to perform operations including: transmitting a command configured to cause an indicator of the first physical location to provide an access permission indication based at least in part on the utilized temporary access record.

9. receiving a request from the access controller to revoke the temporary access right to the first physical location; determining whether the temporary access right is currently retrievable; 10. The physical location access control system of claim 1, configured to perform operations including: sending a retrieval failure notification to the access controller in response at least in part to determining that the temporary access right is not currently retrievable.

10. The physical location access control system of claim 1 , wherein the temporary access rights include access rights to a first event of a set of events.

11. The physical location access control system of claim 1 , wherein the temporary access rights include access to a designated area within the first physical location.

12. 10. The physical location access control system of claim 1, configured to perform operations including recording a token in a synchronized distributed database in response at least in part to providing the temporary access right to the first user.

13. 1. A computer-implemented method comprising: receiving, in the computer system, via a network interface, a request from an access rights controller having a set of access rights including a first access right retrievable by the access rights controller for a first time period to a first user; in response at least in part to the request from the access rights controller; recording in a memory instructions regarding providing the retrievable first access right to the first user; Revoke the ability of the access rights controller to utilize the retrievable first access rights associated with the first physical location; receiving a reclaim request for the reclaimable first access right from the access right controller via a network; In response at least in part to said recall request, recording instructions in a memory regarding the reclaiming of the reclaimable first access right and enabling the access rights controller's ability to utilize the reclaimable first access right associated with the first physical location; and revoking the first user's ability to utilize the retrievable first access right associated with the first physical location.

14. The computer-implemented method of claim 13, wherein the retrievable first access right is associated with the right to access a restricted area within a venue.

15. The computer-implemented method of claim 13, wherein the retrievable first access right is associated with the right to access physical items including groceries and / or clothing.

16. determining whether the retrievable first access right is currently retrievable, 14. The computer-implemented method of claim 13, further comprising determining based at least in part on determining whether the first user has utilized the retrievable first access right.

17. determining whether the retrievable first access right is currently retrievable, 14. The computer-implemented method of claim 13, further comprising determining based at least in part on determining whether a current time falls within the first time period.

18. based at least in part on a history of access rights provision associated with the access rights controller, the history including the number of access rights provided to users by the access rights controller over a second time period; 14. The computer-implemented method of claim 13, further comprising determining whether the access rights controller is authorized to provide the retrievable first access rights to the first physical location to the first user.

19. based at least in part on the number of access rights associated with the access rights controller that are currently provided to the user by the access rights controller; 14. The computer-implemented method of claim 13, further comprising determining whether the access rights controller is authorized to provide the retrievable first access rights to the first physical location to the first user.

20. 14. The computer-implemented method of claim 13, wherein the retrievable first access right comprises access to a first event of a set of events.

21. 14. The computer-implemented method of claim 13, wherein the retrievable first access rights include access rights to a specified area within the first physical location.

22. 14. The computer-implemented method of claim 13, further comprising recording a token in a synchronous distributed database at least in part in response to providing the retrievable first access right to the first user.

23. A non-transitory computer-readable memory storing instructions that, when executed by a computer system including one or more computing devices, cause the computer system to: receiving a request from a requestor at a first time to provide a first user with retrievable access rights to a first physical location for a first event; at least in part in response to the request from the requestor to provide the first user with the retrievable access rights to the first physical location for the first event; creating an access provision record corresponding to providing the retrievable access right to the first event to the first user; Revoke the requester's access right to access the first physical location for the first event; sending a message corresponding to the access provision record to a destination associated with the first user; enabling the first user to access the first physical location for the first event; a non-transitory computer-readable memory configured to perform operations including:

24. The non-transitory computer-readable memory of claim 23, wherein the retrievable access right is associated with the right to access a restricted area within a venue.

25. The non-transitory computer-readable memory of claim 23, wherein the retrievable access rights are associated with the right to access physical items including groceries and / or clothing.

26. The operation may further include: utilizing a history of provision of said retrievable access rights associated with said requester; determining a number of retrievable access rights provided to users by the requestor over a second period of time; in response at least in part to determining that the number of retrievable access rights provided by the requester over the second time period is less than a first threshold; determining that the requestor is authorized to provide the first user with the retrievable access right to the first physical location for the first event; 24. The non-transitory computer-readable memory of claim 23, comprising:

27. The operation may further include: utilizing a history of retrievable access rights provision associated with said requester; determining the number of retrievable access rights currently provided to the user by the requester; in response at least in part to determining that the number of retrievable access rights currently provided by the requester is less than a first threshold; determining that the requestor is authorized to provide the first user with the retrievable access right to the first physical location for the first event; 24. The non-transitory computer-readable memory of claim 23, comprising:

28. The operation is receiving a first hash from a device at the first physical location, the first hash including a hash of an identifier identifying a user communication device associated with the first user and an identifier identifying the first user; comparing a first hash including the hash of the identifier identifying the user communication device associated with the first user and the identifier identifying the first user with a second hash generated using data stored in a database record associated with the first user; utilizing the access provision record in response at least in part to determining that the first hash and the second hash correspond; 24. The non-transitory computer-readable memory of claim 23, further comprising an operation of transmitting a command configured to cause an indicator of the first physical location to provide an access permission indication based at least in part on the utilized access provision record.

29. The operation is receiving, from a device at the first physical location, first biometric data of a given user acquired at the first physical location; comparing the received first biometric data with data stored in a database record associated with the first user; utilizing the access provision record in response at least in part to determining that the first biometric data corresponds to data stored in a database record associated with the first user; 24. The non-transitory computer-readable memory of claim 23, further comprising an operation of transmitting a command configured to cause an indicator of the first physical location to provide an access permission indication based at least in part on the utilized access provision record.

30. The operation is receiving a request from the requestor to revoke the access right to the first physical location; determining whether the retrievable access right is currently retrievable; 24. The non-transitory computer-readable memory of claim 23, comprising an operation of sending a reclaim failure notification to an access rights controller in response at least in part to determining that the reclaimable access rights are not currently reclaimable.

31. 24. The non-transitory computer-readable memory of claim 23, wherein the retrievable access rights include access rights to a first event of a set of events.

32. 24. The non-transitory computer-readable memory of claim 23, wherein the retrievable access rights include access rights to a specified area within the first physical location.

33. The operation is 24. The non-transitory computer-readable memory of claim 23, further comprising: recording a token in a synchronous distributed database at least in part in response to providing the retrievable access right to the first user.

Citation Information

Patent Citations

  • Program

    WO2018074504A1