NFC Verification Bypass System and Method
Patent Information
- Application Number
- JP2024515699
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-02-06
- Filing Date
- 2022-09-13
- Publication Date
- 2026-08-27
- Estimated Expiration
- 2042-09-13
Smart Images

Figure 0007912061000001 
Figure 0007912061000002 
Figure 0007912061000003
Abstract
Description
Technical Field
[0001] Related Applications
[0001] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 267,606, filed Feb. 6, 2022, and U.S. Provisional Patent Application No. 63 / 277,104, filed Nov. 8, 2021, and this application is a continuation of U.S. patent application Ser. No. 17 / 447,499, filed Sep. 13, 2021, U.S. patent application Ser. No. 17 / 447,528, filed Sep. 13, 2021, and U.S. patent application Ser. No. 17 / 447,530, filed Sep. 13, 2021, each of which is hereby incorporated by reference in its entirety.
[0002]
[0002] This application relates to the field of controlled dispensing machines, and more particularly to systems for restricting the purchase and use of controlled products to authorized individuals who use them.
Background Art
[0003]
[0003] Selling age-restricted products presents certain problems and requires the deployment of effective systems to prevent sales to potential consumers who are minors. Since youths often attempt to evade age verification checks and find ways to obtain age-restricted products, the sale of such products has traditionally required a physical person at the point of sale to require valid age verification to confirm that the purchaser is over the minimum age for buying the product in question.
[0004]
[0004] In the case of online or remote sales, retailers may require purchasers of age-restricted products to register their details or set up an account for future purchases, meaning that age verification checks may only be required for the initial account setup or for the first purchase from the website. However, at the time of product delivery or pickup, a real person is still required to perform identity verification to ensure that the person receiving the age-restricted product matches the identity of the person who set up the account used to purchase the product.
[0005]
[0005] Even if a seller of an age-restricted product can successfully verify the age and identity of the purchaser when the product is received, the purchaser may still allow a minor to use the product, and the seller will have no way of knowing when or how often this is happening.
[0006]
[0006] Failure to restrict the purchase and use of such products to authorized individuals may result in adverse consequences for sellers and manufacturers, including lawsuits, sanctions (e.g., geographical restrictions on sales), positive legislative and regulatory restrictions, fines, and even imprisonment. Therefore, sellers and manufacturers of age-restricted products are interested in ensuring that such products are purchased, released, and used only by authorized individuals. [Overview of the project]
[0007]
[0007] A controlled supply system for restricting the purchase, transfer, and use of controlled products to authorized users is disclosed herein. Exemplary controlled products are products whose use is controlled by age restrictions (e.g., tobacco, tobacco products, cannabis products, cannabidiol (CBD), vaping products, e-liquids, e-cigarettes, nicotine pouches, nicotine gum, nutritional supplements, alcohol, lottery tickets, guns, etc.). Exemplary controlled products may be subject to additional or alternative types of restrictions, such as security restrictions (e.g., inventory-controlled products that are relatively prone to theft, such as contraceptives, razor blades, spray paint, infant formula, telephone cards, cough syrup, pharmaceutical products, etc.), identity restrictions (e.g., products authorized for a designated individual, such as prescription drugs or other pharmaceutical products), and / or quantity restrictions (e.g., products limited to a certain number of purchases or items to a consumer within any given time period).
[0008]
[0008] Systems and methods for supplying and activating controlled products, or more specifically, various implementations of systems and methods for restricting the purchase and / or use of controlled products to individuals authorized to use them, based on identity-based and / or age-based restrictions associated with the controlled products. [Brief explanation of the drawing]
[0009] [Figure 1]
[0009] This is a diagram of the management and supply environment in several implementation forms. [Figure 2]
[0010] This is a diagram of a management and supply machine in several implementation configurations. [Figure 3]
[0011] This is a diagram of a management device in several implementation forms. [Figure 4]
[0012] This is a diagram of a mobile device in several different implementation forms. [Figure 5]
[0013] This is a diagram of a server system in several different implementation forms. [Figure 6A]
[0014] This diagram illustrates various associations between identifiers based on several implementation configurations. [Figure 6B] This diagram illustrates various associations between identifiers based on several implementation configurations. [Figure 7]
[0015] This flowchart illustrates several implementation methods for addressing management and supply environments. [Figure 8]
[0016] This flowchart illustrates several implementation methods for addressing management and supply environments. [Figure 9]
[0017] This is a diagram of the product package in several implementation forms. [Figure 10]
[0018] This is a diagram of a dispensing machine row in several implementation configurations. [Figure 11]
[0019] This is a diagram of the product package in several implementation forms. [Figure 12]
[0020] This is a diagram of a supply machine row in several implementation configurations. [Figure 13]
[0021] This is a diagram illustrating the management and supply environment in several implementation forms. [Figure 14]
[0022] This is a flowchart illustrating management and supply methods based on several implementation configurations. [Figure 15]
[0023] This is a flowchart illustrating the verification process for management and supply methods using several implementation configurations. [Figure 16A]
[0024] This is a diagram of a transaction screen for a management and supply machine or placard, in several implementation forms. [Figure 16B] This is a diagram of a transaction screen for a management and supply machine or placard, in several implementation forms. [Figure 17A]
[0025] Diagram of a transaction screen of a user interface associated with product selection according to some implementation forms. [Figure 17B] Diagram of a transaction screen of a user interface associated with product selection according to some implementation forms. [Figure 17C] Diagram of a transaction screen of a user interface associated with product selection according to some implementation forms. [Figure 17D] Diagram of a transaction screen of a user interface associated with product selection according to some implementation forms. [Figure 17E] Diagram of a transaction screen of a user interface associated with product selection according to some implementation forms. [Figure 17F] Diagram of a transaction screen of a user interface associated with product selection according to some implementation forms. [Figure 18A]
[0026] Diagram of a transaction screen of a user interface associated with store clerk authentication according to some implementation forms. [Figure 18B] Diagram of a transaction screen of a user interface associated with store clerk authentication according to some implementation forms. [Figure 19]
[0027] Diagram of a transaction screen of a user interface associated with consumer authentication according to some implementation forms. [Figure 20]
[0028] Diagram of a management supply environment according to some implementation forms. [Figure 21A]
[0029] Diagram of a management supply machine including an internal camera according to some implementation forms. [[ID=3'6]] [Figure 21B] Diagram of a management supply machine including an internal camera according to some implementation forms. [Figure 21C] Diagram of a management supply machine including an internal camera according to some implementation forms. [Figure 21D] This is a diagram of a management and supply machine, including an internal camera, in several implementation configurations. [Figure 22]
[0030] This is a flowchart illustrating remote verification methods on mobile devices, including remote consumer account provisioning and remote product selection, across several implementation forms. [Figure 23]
[0031] This is a flowchart illustrating remote verification methods on mobile devices, including remote consumer account provisioning and local product selection, across several implementation forms. [Figure 24]
[0032] This is a flowchart illustrating remote verification methods in a managed supply system, including remote consumer account provisioning and remote product selection, across several implementation forms. [Figure 25]
[0033] This is a flowchart illustrating remote verification methods in a managed supply system, including remote consumer account provisioning and local product selection, across several implementation forms. [Figure 26]
[0034] This is a block diagram of a management and supply environment using a remote staff support supply system, with several implementation configurations. [Figure 27A]
[0035] This is a flowchart illustrating a management and supply method using a remote staff support supply system, with several implementation configurations. [Figure 27B] This is a flowchart illustrating a management and supply method using a remote staff support supply system, with several implementation configurations. [Figure 27C] This is a flowchart illustrating a management and supply method using a remote staff support supply system, with several implementation configurations. [Figure 27D] This is a flowchart illustrating a management and supply method using a remote staff support supply system, with several implementation configurations. [Figure 27E] This is a flowchart illustrating a management and supply method using a remote staff support supply system, with several implementation configurations. [Figure 28A]
[0036] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28B] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28C] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28D] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28E] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28F] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28G] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28H] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28I] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28J] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28K]This figure shows exemplary user interfaces for a store clerk's computing device using a remote store clerk support supply system, in several implementation configurations. [Figure 28L] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28M] This figure shows exemplary user interfaces for a store clerk's computing device using a remote store clerk support supply system, in several implementation configurations. [Figure 28N] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28O] This figure shows exemplary user interfaces for a store clerk's computing device using a remote store clerk support supply system, in several implementation configurations. [Figure 28P] This figure shows exemplary user interfaces for consumer mobile devices using a remote store clerk assistance supply system in several implementation forms. [Figure 28Q] This figure shows exemplary user interfaces for a store clerk's computing device using a remote store clerk support supply system, in several implementation configurations. [Figure 29]
[0037] This is a system diagram of an age / identity verification platform in several implementation forms. [Figure 30]
[0038] This is a block diagram of the mobile device of the age / identity verification platform in Figure 29, showing several implementation configurations. [Figure 31]
[0039] This is a block diagram of the verification device for the age / identity verification platform shown in Figure 29, with several implementation configurations. [Figure 32]
[0040] This is a block diagram of the server system of the age / identity verification platform shown in Figure 29, with several implementation configurations. [Figure 33]
[0041] Figure 29 shows a flowchart of an age / identity verification method using the age / identity verification platform, with several implementation variations. [Figure 34]
[0042] This figure shows the operation of the age / identity verification method in Figure 33 using the age / identity verification platform in Figure 29, depending on several implementation configurations. [Modes for carrying out the invention]
[0010]
[0043] Similar reference numbers refer to the corresponding parts across several figures in the drawing.
[0011]
[0044] Systems and methods for supplying and activating controlled products, or more specifically, various implementations of systems and methods for restricting the purchase and use of controlled products to individuals authorized to use them, are disclosed herein.
[0012]
[0045] In some implementations, consumers create an account using any electronic device. An age verification step is included in the account setup process to verify the consumer's age and link their identity to the account. A personal electronic device linking step is also included in the account setup process, so that when the account is set up, the consumer's personal electronic device (e.g., a smartphone) is linked to the account.
[0013]
[0046] User account information is stored on the server. When a consumer purchases a managed product, the server obtains a unique product (or category) identifier corresponding to the specific managed product purchased by the consumer. The server may obtain a unique product identifier as a result of the supply machine scanning the purchased product when the purchased product is transferred or before it is transferred to the consumer. Alternatively, the server may obtain a unique product identifier in advance when the product is stocked in the supply machine (prior to the purchase of the product). Alternatively, products in the machine may be categorized as restricted products based on the machine in which the product is stocked or the specific slot in which the product is stocked, without a unique identifier for the product itself.
[0014]
[0047] Using a unique product identifier, the server links the purchased product to the consumer's account. As part of this linking process, the purchased product is associated with the consumer's personal electronic device. In some embodiments, as a result of this association, the purchased device may only be used when it is within the user's personal electronic device sphere.
[0015]
[0048] Therefore, the purchase of a managed device complies with age restriction requirements because the consumer's age is verified during the account setup process. Furthermore, in some embodiments, the use of a managed device complies with age restriction requirements because the functionality of the managed device is only enabled when it is within the scope of the consumer's personal electronic device. In some embodiments, in addition to being within the scope of the consumer's personal electronic device, the consumer must also perform biometric verification (Facial ID or Touch ID) or enter a PIN to activate and / or use the managed device. This prevents the device from operating if the consumer gives the device to a minor or unauthorized individual after the purchase is complete.
[0016]
[0049] Importantly, the technical aspects of this system (e.g., automated linking and activation) allow purchase and usage restrictions to be met as described above without the requirement of a human being (e.g., a store clerk) performing age verification at the point of sale. This technical automation provides a more efficient user experience, ensures compliance with restrictions on managed devices, and allows managed devices to be sold remotely by unstaffed supply devices, thereby providing increased availability of managed devices without sacrificing consumer safety or seller / manufacturer liability.
[0017]
[0050] Figure 1 shows a management and supply environment 100 in several implementation forms. The environment 100 includes a management and supply machine 102, a management device 104, a mobile device 106, and a server system 108. The management and supply machine 102 and the mobile device 106 communicate with the server system 108 via one or more communication networks 110, such as the Internet. The management device 104 communicates with the mobile device 106 using a short-range communication network, such as Bluetooth Low Energy (BLE)®. In some implementation forms, the environment 100 includes retailer machines 112, such as a computing terminal at a checkout counter in a store, which communicate with the server system 108 via one or more communication networks 110.
[0018]
[0051] The managed supply machine 102 is a machine configured to store multiple managed products, such as items 124 or managed devices 104, and to transfer them to consumers. The machine 102 may be a vending machine or any other device that stores products or services and dispenses them as a result of transactions involving consumers. The machine 102 may be a wall-mounted vending machine or may be placed on the ground. The machine 102 may have a glass (or otherwise transparent) front panel so that items 124 are visible (or may not have a front panel), or the machine 102 may have a digital display screen 114 on which a representation of items 124 is presented, or the machine 102 may have any other type of opaque front panel (such as metal or plastic) on which items 124 are not directly visible and are instead represented in an analog form, such as using decals, pictures, or labels. In some implementations, machine 102 does not accept cash, coins, or credit cards, but instead operates based on instructions received from server system 108 (for example, as a result of a consumer selecting item 124 using mobile device 106). Machine 102 stocked with age-restricted management devices may be located in adult-only places such as bars, convention centers, hotels, airports, and clubs. Each product is associated with a unique product identifier (e.g., a serial number). The unique product identifier may be placed on a label 126 of item 124 or printed on the packaging of item 124. Machine 102 includes multiple storage locations, sometimes referred to as slots 122. Slots may be arranged across one or more rows and / or columns of machine 102. Machine 102 is associated with a unique machine identifier. The unique machine identifier may be placed on a label 120 (e.g., a quick response (QR) code or barcode that can be scanned by mobile device 106). Machine 102 is connected to a server system 108 via (one or more) networks 110 in a communicative manner.In some implementations, the managed supply machine 102 includes an onboard scanner 118 configured to scan ID cards (e.g., a consumer's driver's license or a retail employee's employee identification card). Alternatively, the managed supply machine 102 may communicate with an external scanning device 116 configured to scan ID cards via a short-range communication protocol (e.g., Bluetooth®). The scanning device 116 may communicate with the retail machine 112 via a short-range communication protocol (e.g., Bluetooth) (for example, to communicate data associated with the scanned ID card).
[0019]
[0052] Control device 104 is any product associated with a usage restriction. An example usage restriction is an age restriction (e.g., can only be used by people who are 18 years of age or older, 21 years of age or older, or of a case-specific age). Control device 104 may be restricted in other ways, such as by identity (e.g., can only be used by a specific individual), by quantity or use, or by any other type of attribute associated with one or more individuals. An example control device 104 includes electronic cigarettes (e-cig), electronic vaporizers (vaping pens or vape pens), or any other product containing controlled substances such as tobacco, nicotine, alcohol, or marijuana. Control device 104 may be a product configured to interface with any of the example products described above. For example, control device 104 may be a vaping accessory that may or may not contain a controlled substance. Control device 104 may be associated with a drug or any other type of age-restricted substance. The managed device 104 may include products not associated with legal restrictions but which need to be tracked by the seller or manufacturer, or the transaction itself needs to be tracked by the seller or manufacturer (for example, for compliance purposes), and which may be for an individual. For example, the managed device 104 may include communication devices (phones, SIM cards, etc.) intended to be sold only to adults or to individuals whose transactions need to be tracked.
[0020]
[0053] Mobile device 106 is a personal electronic device associated with a consumer (e.g., the consumer's smartphone). Mobile device 106 includes, but is not limited to, a smartphone, a tablet or laptop computer, or a personal digital assistant (PDA), a smart card, or a voice assistance device (such as Alexa®), or other known or undiscovered technologies (e.g., combinations of hardware and software) having a similar structure and / or capabilities to the mobile devices described herein. Mobile device 106 includes long-range communication capabilities (e.g., modems, transceivers, etc.) for communicating through (one or more) networks 110, and short-range communication capabilities (e.g., BLE) for communicating with management device 104 and other devices within the range of the mobile device 106's short-range radio (e.g., a Bluetooth radio). Communication between the mobile device 106 and the management device 104 is carried out using short-range communication technologies or protocols (e.g., Bluetooth (such as Bluetooth 4.0, Bluetooth Smart, Bluetooth Low Energy (BLE)), near-field communication (NFC), ultra-wideband (UWB), radio frequency identification (RFID), infrared wireless, inductive wireless, Wi-Fi®, or any wired or wireless technology that may be used to communicate over small distances known or yet undiscovered (e.g., about 100 feet or closer)). The communication technologies described herein may be replaced by alternative communication technologies, and therefore, no particular communication technology is limited. For example, Wi-Fi technology may be replaced by another long-range communication technology.
[0021]
[0054] The server system 108 communicates with the machine 102, the mobile device 106, and the retail machine 112 through one or more communication networks 110. The server system 108 stores user accounts associated with consumers of the management device 104 and links various identifiers associated with the management device 104 and the mobile device 106 to their respective user accounts, as will be described in more detail below with reference to Figures 6-8. The server system 108 includes one or more host processing servers, which may be operated by a company associated with the seller of the management device 104. For each consumer, the server system 108 may maintain a virtual wallet with a balance (which may be 0 dollars) of designated funds for which the server system 108 holds the accounts. The balance may, for example, represent cash, or the balance may be promotional value representing funds that may be spent under certain circumstances. If these funds begin to run out, the consumer may be notified (for example, via an application on the mobile device 106 or via electronic communication) that additional funds need to be designated and / or moved. Alternatively, funds from other sources (e.g., a funding source server) may be automatically moved to restore the predetermined balance.
[0022]
[0055] The (one or more) communication network 110 includes wired and / or wireless communication networks that enable ongoing connections (e.g., dedicated connections, dedicated online connections, and / or hardwired connections) or connections accessible on demand (e.g., the ability of machine 102 to make a temporary connection to server system 108, or the ability of a consumer to access server system 108 from mobile device 106). Generally, network connections are made via long-range communication technologies or long-range communication protocols (e.g., hardwired, telephone network technologies, cellular technologies (e.g., GSM, CDMA, etc.), Wi-Fi technologies, wide area networks (WANs), local area networks (LANs), or any known or yet undiscovered wired or wireless communication technologies over the Internet).
[0023]
[0056] The retailer machine 112 is any computing device located near the sales point of the management device 104 (for example, a terminal computing device at a checkout counter in the store). The retailer machine 112 communicates with the server system 108 through one or more communication networks 110 using long-range communication technology as described above.
[0024]
[0057] Figure 2 is a block diagram showing an exemplary management and supply machine 102 of a management and supply environment 100 in several implementation configurations. The management and supply machine 102 includes one or more processing units (CPUs) 202, one or more network interfaces 204, memory 206, and one or more communication buses 208 for interconnecting these components. The (one or more) CPUs 202, (one or more) network interfaces 204, memory 206, and (one or more) buses 208 may be implemented on an electronic processing unit (e.g., a printed circuit board) and / or in any other type of hardware housing installed or otherwise disposed in the management and supply machine 102.
[0025]
[0058] The managed supply machine 102 includes one or more supply mechanisms 210 for releasing products (items 124) stored therein. Examples include a rotating element for releasing the next item 124 in slot 122, or any other type of mechanical component (e.g., a release lever or arm) for physically manipulating the item 124 by causing the item 124 to be repositioned in an area of the machine 102 where a consumer can access the released product. In some implementations, the (one or more) supply mechanisms 210 move the product to an intermediate area (for scanning or otherwise retrieving information about the product, such as a product identifier) before moving the product to a release area (e.g., adjacent to a slot 119 providing access to the supplied product).
[0026]
[0059] The managed supply machine 102 optionally includes an onboard scanning device 118 (e.g., a camera 2102, Figures 21A-21C) for obtaining information about the product (e.g., a product identifier). The scanning device 118 may be an image-based device (e.g., a camera), a laser-based device, or any other type of device capable of identifying the product or its characteristics (e.g., a serial number, barcode, QR code®, etc.). In some implementations, the scanning device is an imaging device, a laser scanning device, or any other type of scanner configured to scan a barcode or any other type of visual indicator on the surface of the product being supplied in order to obtain a product identifier. In some implementations, the scanning device is a near-field communication (NFC) scanning device configured to scan an NFC tag on or associated with the product when the product is being supplied in order to obtain a product identifier. In some implementations, the machine 102 may stock the products in a manner in which many (or substantially all) product identifiers are visible at once. In some implementations, machine 102 periodically captures images (for example, using camera 2102, Figures 21A-21C) to count items in each slot, track sales, track unique identifiers, and track batch codes (for example, in the case of a recall). If a product is recalled or expires, machine 102 may disable (one or more) specific slots based on instructions received from a server, either based on local calculations or analyses in machine 102, or based on remote analysis either systematically or by a human.
[0027]
[0060] Memory 206 includes high-speed random-access memory, such as DRAM, SRAM, DDR RAM, or other random-access solid-state memory devices, and optionally includes non-volatile memory, such as one or more magnetic disk storage devices, one or more optical disk storage devices, one or more flash memory devices, or one or more other non-volatile solid-state memory devices. Memory 206 optionally includes one or more storage devices located remotely from one or more processing units 202. Memory 206, or alternatively the non-volatile memory within Memory 206, includes a non-temporary computer-readable storage medium. In some implementations, Memory 206, or the non-temporary computer-readable storage medium of Memory 206, stores the following programs, modules, and data structures, or subsets or supersets thereof: Operating System 216, including procedures for handling various basic system services and for performing hardware-dependent tasks. • A communication module 218 for connecting the management and supply machine 102 to other devices (e.g., a server system 108) via one or more network interfaces 204 (wired or wireless) and one or more communication networks 110, such as the Internet, other wide area networks, local area networks, metropolitan area networks, etc. • A supply module 220 for managing the supply mechanism 210 in accordance with supply orders received from the server system 108. • Scan module 222 for managing scan device 118 according to scan and supply operations. • Association module 224 for linking product identifiers associated with scanned and supplied products with user identifiers associated with the purchase of scanned and supplied products, and Machine data 226, including the following: ○ Inventory 228, including a listing of available products stored in machine 102, and ○ Transaction data 230, including user identifiers and product identifiers involved in the current and / or past purchases of products stored in machine 102.
[0028]
[0061] Each of the elements identified above may be stored in one or more of the aforementioned memory devices and corresponds to a set of instructions for performing the functions described above. The modules or programs (i.e., sets of instructions) identified above do not need to be implemented as separate software programs, procedures, modules, or data structures; therefore, various subsets of these modules may be combined or, in some cases, rearranged in various implementations. In some implementations, memory 206 optionally stores a subset of the modules and data structures identified above. Furthermore, memory 206 optionally stores additional modules and data structures not described above.
[0029]
[0062] Figure 3 is a block diagram showing an exemplary management device 104 of a management supply environment 100 in several implementation configurations. The management device includes one or more processing units (CPUs) 302, one or more network interfaces 304, memory 306, and one or more communication buses 308 for interconnecting these components. The (one or more) CPUs 302, (one or more) network interfaces 304, memory 306, and (one or more) buses 308 may be implemented on an electronic processing unit (e.g., a printed circuit board) and / or in any other type of hardware housing installed or otherwise disposed in the management device 104.
[0030]
[0063] The control device 104 includes a first electronic circuit 310 for managing one or more functions that are central to the control device 104. For example, if the control device is a vaping pen, the first circuit may manage the vaporization function of the vaping pen (e.g., a heating element and / or a temperature sensing circuit).
[0031]
[0064] The management device 104 includes a second electronic circuit 312 for managing one or more functions that are auxiliary to the management device 104. For example, if the management device is a vaping pen, the second circuit may manage a status display or a battery life indicator for the vaping pen.
[0032]
[0065] Memory 306 includes high-speed random-access memory, such as DRAM, SRAM, DDR RAM, or other random-access solid-state memory devices, and optionally includes non-volatile memory, such as one or more magnetic disk storage devices, one or more optical disk storage devices, one or more flash memory devices, or one or more other non-volatile solid-state memory devices. Memory 306 optionally includes one or more storage devices located remotely from one or more processing units 302. Memory 306, or alternatively the non-volatile memory within Memory 306, includes a non-temporary computer-readable storage medium. In some implementations, Memory 306, or the non-temporary computer-readable storage medium of Memory 306, stores the following programs, modules, and data structures, or subsets or supersets thereof: • A communication module 318 for connecting the management device 104 to other devices (e.g., mobile device 106) via one or more network interfaces 304 (wired or wireless) and one or more short-range communication networks, such as a BLE network. • Activation module 320 for activating and deactivating the first circuit 310 of the management device 104, For example, an association module 322 for linking the management device 104 to a specific mobile device 106 based on successful pairing with the mobile device 106, and Device data 324 includes the following: ○ Item ID 326, which is a unique product identifier associated with the management device 104, and ○ A mobile ID 328, which is a unique mobile device identifier associated with a specific mobile device 106.
[0033]
[0066] Each of the elements identified above may be stored in one or more of the aforementioned memory devices and corresponds to a set of instructions for performing the functions described above. The modules or programs (i.e., sets of instructions) identified above do not need to be implemented as separate software programs, procedures, modules, or data structures; therefore, various subsets of these modules may be combined or, in some cases, rearranged in various implementations. In some implementations, memory 306 optionally stores a subset of the modules and data structures identified above. Furthermore, memory 306 optionally stores additional modules and data structures not described above.
[0034]
[0067] Figure 4 is a block diagram showing an exemplary mobile device 106 of the management and supply environment 100 in several implementation configurations. The mobile device 106 includes one or more processing units (CPUs) 402, one or more network interfaces 404, memory 406, and one or more communication buses 408 for interconnecting these components.
[0035]
[0068] The mobile device 106 includes one or more input devices 410 (e.g., a touchscreen, keyboard, mouse, microphone, etc.) for receiving user input and one or more output devices 412 (e.g., a display screen, speaker, etc.) for displaying output to the user.
[0036]
[0069] Memory 406 includes high-speed random-access memory, such as DRAM, SRAM, DDR RAM, or other random-access solid-state memory devices, and optionally includes non-volatile memory, such as one or more magnetic disk storage devices, one or more optical disk storage devices, one or more flash memory devices, or one or more other non-volatile solid-state memory devices. Memory 406 optionally includes one or more storage devices located remotely from one or more processing units 402. Memory 406, or alternatively the non-volatile memory within Memory 406, includes a non-temporary computer-readable storage medium. In some implementations, Memory 406, or the non-temporary computer-readable storage medium of Memory 406, stores the following programs, modules, and data structures, or subsets or supersets thereof: • Operating System 416, which includes procedures for handling various basic system services and for performing hardware-dependent tasks. A communication module 418 for connecting a mobile device 106 to another device (for example, a server system 108) via one or more network interfaces 404 (wired or wireless) and one or more communication networks 110, such as the Internet, other wide area networks, local area networks, metropolitan area networks, etc. A user interface module 420 for receiving input from the user via (one or more) input devices 410 and displaying output to the user via (one or more) output devices 412. A browser application 422 for enabling internet browsing via one or more communication networks 110. • Refer to Figures 7-8 and see the following description of supply application 424 to enable product purchase. • Device data 426 including a unique mobile device identifier (mobile ID 428) associated with mobile device 106, and User data 430, including a unique user account identifier (user ID 432) associated with the user of mobile device 106.
[0037]
[0070] Each of the elements identified above may be stored in one or more of the aforementioned memory devices and corresponds to a set of instructions for performing the functions described above. The modules or programs (i.e., sets of instructions) identified above do not need to be implemented as separate software programs, procedures, modules, or data structures; therefore, various subsets of these modules may be combined or, in some cases, rearranged in various implementations. In some implementations, memory 406 optionally stores a subset of the modules and data structures identified above. Furthermore, memory 406 optionally stores additional modules and data structures not described above.
[0038]
[0071] Figure 5 is a block diagram showing an exemplary server system 108 of a management and supply environment 100 in several implementation configurations. The server system 108 includes one or more processing units (CPUs) 502, one or more network interfaces 504, memory 506, and one or more communication buses 508 for interconnecting these components.
[0039]
[0072] The server system 108 includes one or more input devices 510 (e.g., buttons, keypads, touchscreens, keyboards, mice, microphones, etc.) for receiving user input, and one or more output devices 512 (e.g., display screens, lights, LED or LCD displays, speakers, etc.) for displaying output to the user.
[0040]
[0073] Memory 506 includes high-speed random-access memory, such as DRAM, SRAM, DDR RAM, or other random-access solid-state memory devices, and optionally includes non-volatile memory, such as one or more magnetic disk storage devices, one or more optical disk storage devices, one or more flash memory devices, or one or more other non-volatile solid-state memory devices. Memory 506 optionally includes one or more storage devices located remotely from one or more processing units 502. Memory 506, or alternatively the non-volatile memory within Memory 506, includes a non-temporary computer-readable storage medium. In some implementations, Memory 506, or the non-temporary computer-readable storage medium of Memory 506, stores the following programs, modules, and data structures, or subsets or supersets thereof: Operating System 516 includes procedures for handling various basic system services and for performing hardware-dependent tasks. • A communication module 518 for connecting the mobile device 106 to other devices (for example, machine 102 and mobile device 106) via one or more network interfaces 504 (wired or wireless) and one or more communication networks 110, such as the Internet, other wide area networks, local area networks, metropolitan area networks, etc. • Age verification module 520 for implementing one or more age and / or ID verification processes for consumers as part of the account setup process. • Quantitative validation module 522 for verifying that a user account satisfies quantitative thresholds regarding the purchase and / or use of managed devices (for example, that the number of devices purchased within a given time period is less than or equal to a threshold number, or that the number of devices used within a given time period is less than or equal to a threshold number). • Payment handling module 524 for performing payment functions during a transaction (e.g., handling account balances, billing fund accounts, etc.) A verification module 526 to verify that the purchased management device 104 is not linked to any other mobile device 106 before allowing the purchased management device 104 to be linked to a specific mobile device 106 as part of the purchase of the management device 104. Regarding Figures 7 and 8, as explained below, a transaction module 528 enables purchases between the user account and the managed device 104. • For each user account, user account data 530 including data 532 for multiple user accounts, including the following: * User ID 534, a unique identifier associated with the user account, * Mobile ID 536, a unique identifier associated with the mobile device 106 linked to the user account. * Usage data 538 describing the usage statistics of one or more managed devices 104 linked to the user account (for example, how much and / or how often a particular device was used over a given amount of time), and For each machine, machine data 540 includes data 542 for multiple machines 102, including the following: * Machine ID 544, a unique identifier associated with the machine, and * Slot data 546 including scanned item ID 548 associated with management device 104 stocked in the machine.
[0041]
[0074] Each of the elements identified above may be stored in one or more of the aforementioned memory devices and corresponds to a set of instructions for performing the functions described above. The modules or programs (i.e., sets of instructions) identified above do not need to be implemented as separate software programs, procedures, modules, or data structures; therefore, various subsets of these modules may be combined or, in some cases, rearranged in various implementations. In some implementations, memory 506 optionally stores a subset of the modules and data structures identified above. Furthermore, memory 506 optionally stores additional modules and data structures not described above.
[0042]
[0075] The previous section described the details of the managed supply machine 102, the managed device 104, the mobile device 106, and the server system 108 in several implementation forms. This section describes the various interactions between these devices in the managed supply environment 100 during a transaction. Specifically, when a consumer associated with a user account stored in the server system 108 purchases the managed device 102 from the managed supply machine 102 using the mobile device 106, these devices interact with each other to link various components of the transaction in a way that restricts the purchase and use of the managed device so that only the consumer associated with that user account can purchase the managed device from the managed supply machine, and only that consumer's mobile device can enable the managed device to be used by the consumer.
[0043]
[0076] Figure 6A illustrates these links in more detail, in several implementation forms. Referring to the first line 602, the consumer sets up an account on the server system 108 using a mobile device 106 (or any other electronic device with access to the server system 108). During the account setup process, the server system identifies a user account with a unique user identifier, referred to herein as the “User ID”. This process is subject to the consumer passing an age verification process. Also as part of the account setup process, the consumer registers the mobile device 106. During this registration process, the server system 108 assigns a unique identifier, referred to herein as the “Mobile ID”, to the mobile device 106. Thus, the server system verifies the consumer’s age through the consumer’s user account and associates the User ID with the Mobile ID. Throughout this application, the term “associate” is synonymous with linking, relating, connecting, joining, combining, etc. In other words, the User ID and the Mobile ID may be described as being linked to each other, or both being linked to the same user account, or both being linked to the same consumer through the user account. In some implementations, a user ID may not be linked to a mobile ID (for example, a managed device may be linked to a user's account independently of the mobile device). In some implementations, a user ID may be linked to multiple mobile IDs (e.g., a work phone, a personal phone, a tablet, etc.). In some implementations, a mobile ID currently linked to a user ID may be replaced with a new mobile ID (for example, when a consumer replaces their phone).
[0044]
[0077] Referring to the second line 604, the consumer then selects a management device 104 (also referred to herein as “item”) in a particular machine 102. In implementations where machine 102 does not have input or cash acceptance functions, the consumer makes the selection using a dedicated application on a mobile device or through a web browser on a mobile device directed to a website associated with the consumer’s user account stored in the server system 108. The server system assigns an identifier (referred to herein as a selection ID) to the consumer’s selection. The selection ID may correspond to a specific storage location in the machine (e.g., slot 122) containing the desired product. Alternatively, the selection ID may correspond to a specific product, and machine 102 may interpret which product is stocked in which particular slot. As a result of the selection, the server system 108 associates the consumer’s selection ID with a user ID. In other words, the consumer’s selection is linked to the consumer’s user account.
[0045]
[0078] Referring to the third line 606, the server system 108 sends a supply command to the machine 102. The supply command initiates a supply process that includes actions for the machine to identify the correct item (for example, item 124) being supplied (of several items). Once the machine 102 obtains a unique identifier corresponding to the item (referred to herein as the item ID), it associates the user ID with the item ID and communicates this association to the server system 108.
[0046]
[0079] Referring to line 608 of the fourth paragraph, the server system 108 receives a communication involving the association of a user ID with an item ID. Based on the user ID, the server system accesses the consumer's user account and retrieves the consumer's mobile ID (obtained during account setup). The server system then associates the consumer's mobile ID with the item ID of the auto-sold item and communicates this association to the consumer's mobile device 106. This final association allows the consumer's mobile device 106 to activate the item associated with the item ID (and not any other mobile device not registered to the consumer's user account). Thus, managed devices can only be activated by the mobile devices of age-verified consumers, thereby restricting not only the purchase but also the use of managed devices.
[0047]
[0080] Figure 6B illustrates the association described above using an alternative implementation. Referring to the first line 612, the consumer sets up an account, just as in the account setup process described above, referring to line 602. Thus, the server system 108 associates the consumer's user ID with the consumer's mobile ID.
[0048]
[0081] However, referring to the second line 614, the server system 108 may have access to various items in machine 102 even before the consumer makes a selection. For example, while a person is stocking machine 102, that person may scan the item ID of each item, causing the item IDs to be uploaded to the server system 108 in the order in which the item IDs were scanned, corresponding to the order in which they were stocked. The person stocking machine 102 may, in addition or alternatively, scan just a single item in a batch if the server has separate access to all the serial numbers of that batch of products (for example, if the products in a batch are in a sequential order or were recorded together at the time of manufacture, each individual product does not necessarily need to be scanned when it is stocked). Thus, the server system 108 only needs to look at a list of item IDs corresponding to a particular machine in order to know the unique identity of the selected item, without requiring machine 102 to first scan the items during the supply operation. Therefore, before the consumer makes a product selection, the server system 108 may associate each selection ID in a particular machine (e.g., each slot 122) with an item ID corresponding to a particular product (e.g., each particular item 124 in each particular slot 122).
[0049]
[0082] Referring to the third line 616, by the time the consumer makes a selection, the server system 108 can associate the item ID with the user ID without having to first wait for the machine 102 to communicate the item ID, since the item IDs are already stored in the server system and already associated with each selection ID. Thus, the server system 108 sends a supply command to the machine 102 and already knows the exact item ID of the item being supplied.
[0050]
[0083] Referring to line 618 of the fourth row, the server system 108 associates the item ID of the auto-sold product with the mobile ID of the consumer's mobile device 106, based on the information stored in the consumer's user account. The server system sends this association to the mobile device 106 corresponding to the mobile ID, thereby enabling the consumer's mobile device 106 to activate the auto-sold managed device. Thus, the managed device can only be activated by the mobile device of an age-verified consumer, thereby restricting not only the purchase but also the use of the managed device.
[0051]
[0084] Figure 7 is a flowchart illustrating methods 700 corresponding to the managed supply environment 100 in several implementation forms. Method 700 includes a more specific set of operations for performing the various associations described in the previous section.
[0052]
[0085] Method 700 is implemented by a management supply machine 102, a management device 104, a mobile device 106, and a server system 108. Method 700 is optionally governed by instructions stored in computer memory or non-temporary computer-readable storage media (e.g., memories 206, 306, 406, and / or 506) and executed by one or more processors (e.g., one or more CPUs 202, 302, 402, and / or 502). Computer-readable storage media may include magnetic or optical disk storage devices, solid-state storage devices such as flash memory, or one or more other non-volatile memory devices. Instructions stored in computer-readable storage media may include source code, assembly language code, object code, or one or more other instruction forms interpreted by one or more processors. Some operations in Method 700 may be combined, and / or the order of some operations may be changed.
[0053]
[0086] Method 700 begins when a consumer creates an account (702). The consumer may, but is not required, use a mobile device 106 to create an account. The consumer may use any electronic device with access to the server system 108 to create an account, insofar as the consumer registers the mobile device 106 as the mobile device that will ultimately be required to activate any Automated Device 102 at some point during account creation. During account creation, the server system 108 performs an age verification process and, in some implementations, an identity verification process (704). These processes may be combined if the consumer's identity can also be verified by documents required to verify the consumer's age. An example of an age verification process includes a requirement that the consumer upload to the server system 108 an image of an identification document containing a photograph of the consumer (e.g., a driver's license, passport, military identification card) or an image or video of the consumer's face (e.g., using facial recognition software). Next, the server system 108 verifies the authenticity of the identification document or image or video (for example, by comparing the document or image with documents or images in a database and / or by using machine intelligence to determine authenticity). The server system 108 verifies the consumer's age based on the identification document. If the consumer meets the relevant age requirements, the server system 108 allows the consumer to create an account. As part of the account creation process, a user ID that identifies the consumer and a mobile ID that identifies the consumer's mobile device 106 are associated (i.e., linked), and this association is stored in the server system 108 along with the user's account. The user's identification document and / or information may also be verified by an external database or service to ensure that the presented document / information is valid, authentic, and / or not expired.
[0054]
[0087] At some point in time after account creation, the consumer selects a managed device (called an item) from a specific machine (708). As part of the selection process, the consumer uses a mobile device 106 to identify or select a machine, for example, by scanning a machine identifier, machine ID (e.g., label 120), that identifies a specific machine to the server system 108. Selection / identification may be done via the user interface of the mobile device 106, or via GPS, Bluetooth, or any other communication protocol / network, as an arbitrary other selection / identification method. The consumer uses the mobile device 106 to make a selection corresponding to the storage location (e.g., slot 122) of the desired item. The mobile device 106 sends the machine ID and selection ID to the server system 108. The server system verifies the transaction (710) and associates the selection ID with the user ID as described above. The server system sends the selection ID and user ID to the machine 102 identified by the machine ID. Machine 102 scans the selected item (712), determines the item identifier (item ID), and links the item ID to the user ID (714). Machine 102 transmits the linked item ID and user ID to the server system 108 and automatically sells the selected product (selected management device 104) (716).
[0055]
[0088] The server system 108 verifies the item ID (718) (for example, verifying that the item ID has not been previously linked to another user account or mobile device) and links the item ID to the consumer's mobile ID based on information stored in the user's account (registered mobile device identifier) (720).
[0056]
[0089] When the consumer is ready to use the management device 104 (722), the server system 108 sends the item ID to the mobile device 106 identified by the linked mobile ID (724). In some implementations, the server system sends the item ID before the consumer is ready to use the management device 104, so that the mobile device 106 already has access to the item ID when the consumer starts a usage session. The mobile device 106 uses the item ID to pair with the management device 104 (726). Upon successful pairing, the management device 104 activates its primary function (728) (for example, by activating or enabling the first circuit 310). The management device 104 may remain activated until it is unpaired from the mobile device 106, either as a result of the mobile device 106 ending its session (730) (the user turning off the mobile device 106 or otherwise actively ending the usage session), or as a result of the mobile device 106 being out of range of the management device 104. As a result of unpairing, the primary functions of the management device 104 are deactivated (732) (for example, by deactivating or disabling the first circuit 310).
[0057]
[0090] Figure 8 is a flowchart illustrating methods 800 corresponding to the managed supply environment 100 in several implementation forms. Method 800 includes an alternative set of operations for performing the various associations described in the previous section.
[0058]
[0091] Method 800 is implemented by a management supply machine 102, a management device 104, a mobile device 106, and a server system 108. Method 700 is optionally controlled by instructions stored in computer memory or non-temporary computer-readable storage media (e.g., memories 206, 306, 406, and / or 506) and executed by one or more processors (e.g., one or more CPUs 202, 302, 402, and / or 502). Computer-readable storage media may include magnetic or optical disk storage devices, solid-state storage devices such as flash memory, or one or more other non-volatile memory devices. Instructions stored in computer-readable storage media may include source code, assembly language code, object code, or one or more other instruction forms interpreted by one or more processors. Some operations in Method 700 may be combined, and / or the order of some operations may be changed.
[0059]
[0092] This method begins with the consumer creating an account (702), the server system performing verification (704), and linking the user ID with the mobile ID (706), as described in Method 700. However, in Method 800, the server system 108 obtains the item ID of an item in advance as the item is loaded into the machine. As the individual stocks the machine, the items are scanned (802) as they are loaded into their respective slots, and the server system 108 stores the item IDs in the order in which the items were loaded and scanned, as described above with reference to Figure 6B (804). In this way, when the consumer selects an item (708) and the server system verifies the transaction (710), the server system can obtain the item ID corresponding to the consumer's selection (806) without waiting for the supply machine 102 to automatically sell the item, scan the item ID, and upload the item ID. The remainder of this method corresponds to numbered operations similar to those described in Method 700.
[0060] Alternative implementation forms
[0093] Alternative methods to the management and supply methods described above include scenarios in which one or more of the operations are performed by a person. For example, in some implementations, a consumer may communicate to a retailer (e.g., an employee using a retailer machine 112) their intention to purchase a particular management device (e.g., 104). The consumer may (i) pay the retailer at a counter or via an application (e.g., running on the consumer's mobile device 106 or on the retailer machine 112), and / or (ii) verify the consumer's identity and / or age by showing the consumer's identification to the retailer at a counter or via an application (e.g., running on the consumer's mobile device 106 or on the retailer machine 112). The retailer approves the purchase and provides the consumer with a transaction code (e.g., a QR code). The transaction code may (i) be printed from (or caused to be printed by) the retailer machine 112, or (ii) be pre-printed (e.g., on a card). The consumer proceeds to machine 102 and scans a machine identifier (e.g., label 120) (e.g., using a mobile device 106). Any combination of machine 102 and mobile device 106 transmits the transaction code and machine identifier to server system 108, which verifies the transaction using one of the operations described above with reference to Figures 6A to 8. Upon transaction verification, server system 108 instructs machine 102 (via one or more networks 110) to supply the managed product (e.g., the product specified by the transaction code). Alternatively, server system 108 sends a communication to retailer machine 112 notifying the retailer that the transaction has been verified, and in response, the retailer may hand over the managed device to the consumer. In some implementations, the consumer uses a transaction code provided by the retailer to activate the managed device.
[0061]
[0094] In another alternative approach, the consumer uses a managed supply machine 102 as a pickup terminal for products purchased online. In some implementations, the consumer purchases a specific managed device on a website or application via a mobile device 106 and (one or more) networks 110. Payment and identity verification are handled through the website or application as described above. Upon successful payment and identity verification, the website or application directs the consumer to a specific machine 102 (for example, based on distance and / or product availability) or any machine 102 (for example, one the consumer may decide to use) to receive the managed device. At machine 102, the consumer scans a machine identifier (for example, label 120) using the mobile device 106, and the server system 108 instructs machine 102 to supply the managed device based on one of the operations described above with reference to Figures 6A to 8. In some implementations, the supplied device is then associated with the consumer (via the user's account) and / or the consumer's mobile device, as described above with reference to Figures 6A to 8.
[0062] Packaging of managed devices
[0095] In the methods described above, the management device 104 may be activated once it is supplied and associated with a user account and / or mobile device. In some implementations, the management device 104 may be activated or possibly unlocked before supply (while the management device 104 is still in machine 102). In such implementations, an authorized consumer may use the management device as soon as it is supplied.
[0063]
[0096] Figure 9 shows front and side views of the product package 900 in several implementation configurations. A management device (e.g., 104) is located inside the shell 902 of the package 900. The management device 104 is electrically coupled to two power contacts 904 and 906 (e.g., via their respective wires). The power contacts can be displaced vertically to ensure the correct polarity when the package 900 is placed in the machine 102. For example, contact 904 may be a positive power contact and contact 906 may be a negative power contact. The power contacts are made of any conductive material. When power is applied through contacts 904 and 906, the management device 104 can be powered up (e.g., for the purpose of receiving an activation signal). The package shell 902 optionally includes one or more communication contacts (not shown) (e.g., two contacts for serial peripheral interface communication) electrically coupled to the communication circuit of the management device 104.
[0064]
[0097] Figure 10 shows front and side views of row 1000 of machine 102 in several configurations. A row includes one or more shelves 1002, each shelf 1002 containing one or more management devices in a package shell 902. Each shelf 1002 is aligned with power rails 1014 (one on each side of the management device), which are electrically coupled to power contacts 1004 and 1006 (corresponding to contacts 906 and 904 of the package shell 902) and guides 1008 and 1010. The power contacts 1006 may include springs to maintain tension against the package shell 902, and the guides may be sized to keep the product shell 902 aligned on the shelf 1002. The power rails 1014 electrically couple the power contacts 1004 and 1006 to power provided by the power bus of machine 102. In some configurations, the shelf 1002 includes a supply spiral 1012, or other types of push mechanisms for supplying products. Each shelf 1002 optionally includes one or more communication rails (not shown) having contacts configured to physically connect to communication contacts on the package shell 902. In some implementations, only the packages in the frontmost slots are in contact with the rails (one or more) so that communications sent through the communication rails (one or more) are received only by the packages being supplied.
[0065]
[0098] Figure 11 shows front and side views of product package 1100 in several implementation configurations. Product package 1100 corresponds to product package 900, and product package 1100 includes power contacts (not shown) as described with respect to contacts 904 and 906 in Figure 9. However, instead of the contacts receiving power from the power rail 1014, the contacts receive power from a solar module 1102 (e.g., a solar cell or any other type of photovoltaic material) incorporated into (or physically in contact with) the packaging of the management device. As described above, the package shell optionally includes one or more communication contacts (not shown) (e.g., two contacts for serial peripheral interface communication) electrically coupled to the communication circuit of the management device 104. In some implementation configurations, the solar module 1102 of package 1100 can keep the management device 104 charged even after it has been supplied (e.g., by the user exposing package 1100 to sunlight or other types of light).
[0066]
[0099] Figure 12 shows a front view of row 1200 of machine 102 in several implementation configurations. The row includes one or more shelves 1202, each shelf 1202 including one or more management devices in a package shell with a solar module 1102. Machine 102 includes an internal light source 1204, which can provide illumination for consumers to view products inside the machine (in the case of machines with a transparent front panel) as well as illumination for the solar module 1102. To optimize the amount of light reaching the solar module 1102, each shelf 1202 optionally includes a lighting strip 1206 made of reflective material, and portions of the internal surface of the machine optionally are covered with reflective paint 1208 or any other type of reflective material. Each shelf 1002 optionally includes one or more communication rails (not shown) having contacts configured to be physically coupled to communication contacts of a package shell 902. In some implementations, only the package in the frontmost slot is in contact with the rails (one or more) so that communications sent through the rails (one or more) are received only by the package being supplied.
[0067]
[0100] The management device package described above provides power to each management device and optionally provides communication. In some implementations, the management device 104 is locked (or possibly deactivated) when the management device 104 is loaded into the machine 102. Packing for each management device 104 keeps each management device charged. As described above with reference to Figures 6A to 8, the consumer purchases a specific management device 104. However, instead of a deactivated device being supplied (e.g., in operation 716) and activated outside the machine 102 (e.g., in operation 728), the device may be activated before it is supplied. The machine 102 may communicate with the device being supplied and send an unlock code to the device's firmware. This unlocks the management device without requiring the management device to be paired with the mobile device 106. In some implementations, the management device 106 may be permanently unlocked. In some implementations, communication for unlocking the management device may be wireless (e.g., via the wireless communication module of machine 102, for example, using Bluetooth) or wired (e.g., via a serial communication bus through communication contacts in packaging as described above).
[0068] management supply
[0101] Figure 13 shows a controlled supply environment 1300 in several implementation forms. In environment 1300, a controlled supply machine 1302 (also called a controlled supply fixture, smart supply fixture, or smart trade fixture) supplies controlled products 1304 according to a controlled supply process 1400 (described below with reference to Figure 14), which includes (i) product identification / verification, (ii) consumer authentication / verification, and / or (iii) clerk authentication. The supply environment 1300 and supply process 1400 provide safety protection for consumers and liability protection for retailers and manufacturers. The supply environment 1300 implements a digital age and / or identity verification process for controlled products (e.g., tobacco, tobacco products, cannabis products, cannabidiol (CBD) products, vaping products, e-liquid products, e-cigarettes, nicotine pouches, nicotine gum, nutritional supplements, alcohol, lottery tickets, guns, security-restricted products, and / or identity-restricted products, as described above). In other words, the supply environment 1300 performs age and / or identity verification of the controlled product when it is sold and / or distributed by a person (such as a service provider, shop assistant, retailer, or employee) or retail store. As will be described in more detail below, the supply environment 1300 performs age and / or identity verification of the purchaser using scanning technology and / or automated software systems that show the purchaser's date of birth, age, and / or identity.
[0069]
[0102] Aspects of the controlled supply environment 1300 may complement one or more aspects of the controlled supply environment 100 described above (and vice versa). For example, when a controlled product (described with respect to environment 1300) is supplied, the product may be required to be activated (as described with respect to environment 100). Alternatively, the controlled supply environment 1300 may be implemented without any of the aspects described with respect to the controlled supply environment 100 (and vice versa). For example, when a controlled product (described with respect to environment 1300) is supplied, the product may be ready for use without being required to be activated as described above.
[0070]
[0103] The managed supply environment 1300 may include a retail machine 1312, such as a sales point device or any other type of computing device operated by a service provider (store clerk). The retail machine 1312 may support supply aspects of transactions relating to the managed product 1304 (e.g., managing the supply machine 1302) and / or non-supply aspects of transactions relating to the managed product 1304 (e.g., payment processing). In some implementations, the retail machine 1312 handles only the payment aspects of transactions and is completely independent of the managed supply aspects of transactions. In other words, the supply of managed products using the supply machine 1302 can be implemented completely independently of the payment handling components.
[0071]
[0104] The supply machine 1302 may be managed via a user interface on a display screen 1314 (described below with reference to Figures 16-19), an optional scanning device 1306 (the scanning device adds efficiency to the managed supply process, but manual data input via the user interface or input via any other peripheral device such as a keyboard / mouse may serve as a substitute), and a processing circuit 1316 that includes or communicates with memory storing a program that, when executed by elements of the processing circuit, performs one or more of the functions described below with reference to Figures 14-23. The display screen 1314, the scanning device 1306, and the processing circuit 1316 may be distributed between any combination of the supply machine 1302 and the retail machine 1312, as described below.
[0072]
[0105] The supply machine 1302 may include an onboard scanner 1318 in addition to or as an alternative to one or more of the remote scanning devices 1306. The scanning devices 1306 and / or the onboard scanner 1318 are configured to scan barcodes, QR codes, and / or any other type of scannable code, image, or string of characters (for example, on a consumer ID 1354 such as a driver's license or passport, and / or an employee ID 1356). In one exemplary implementation, a store clerk may use the scanning device 1306 to scan the barcode of a product selected by the consumer and the consumer ID 1354 (for example, using a placard 1352), and the onboard scanner 1318 to scan the store clerk's ID 1356 to enable the supply of the selected product. Other combinations of using the scanning device 1306 and / or the onboard scanner 1318 can be implemented (for example, scanner 1306 scanning all ID and product barcodes, scanner 1318 scanning all ID and product barcodes, or scanners 1306 / 1318 scanning different subsets of ID and product barcodes).
[0073]
[0106] The supply machine 1302 includes a slot 1320 that accommodates an area within the supply machine 1302 from which the controlled product 1304 can be removed after it has been supplied. The internal supply mechanics of the supply machine 1302 may include one or more mechanical features (e.g., slots, rows, rails, contacts, packaging, shelves, guides, solar modules, lighting strips, reflective paint, and / or light sources) as described herein with reference to Figures 1, 9 to 12, and / or Figures 21A to 21D. The supply machine 1302 may include one or more features described above with respect to the controlled supply machine 102 (Figures 1 to 2), and the controlled product 1304 may include one or more features described above with respect to the controlled device 104 (Figure 3). The controlled supply environment 1300 may include one or more features described above with respect to the controlled supply environment 100 (Figures 1 to 8).
[0074]
[0107] The supply machine 1302 includes one or more supply mechanisms for releasing the controlled products stored therein. Examples include a rotating element (e.g., supply spiral 1012, Figure 10) or a push element (e.g., supply mechanism 2106, Figure 21B) for releasing the next controlled product in a slot, or any other type of mechanical component (e.g., release lever or arm) for physically manipulating the controlled product by causing it to be repositioned in an area of the supply machine 1302 (e.g., slot 1320) where a consumer or retail employee can access the released product. In some implementations, the supply mechanism (one or more) moves the product to an intermediate area (for scanning or otherwise retrieving information about the product, such as a product identifier, as described above with reference to Figures 9–12) before moving the product to the release area.
[0075]
[0108] In some implementations, the display screen 1314, the scanning device 1306, and the processing circuit 1316 are integrated into or communicatively coupled to the supply machine 1302. In these implementations, the retailer machine 1312 may not be required to perform the supply mode of transactions relating to the managed product 1304. The scanning hardware for performing the scanning features described herein may be implemented in the structure of the supply machine 1302 (e.g., the onboard scanner 1318), as a separate component (e.g., the scanning device 1306, such as a handheld remote barcode scanner), or as a combination of the two (e.g., the onboard scanner 1318 and the scanning device 1306). The scanning device 1306 may be a handheld scanner communicatively coupled (paired) to the supply machine 1302 using a wired or wireless communication link (e.g., USB, wireless dongle, Ethernet, Wi-Fi, Bluetooth, etc.). The scanning device 1306 and / or the onboard scanner 1318 may be configured to scan / read barcodes, QR codes, and / or any other type of scannable code (e.g., on consumer ID 1354, such as a driver's license or passport, and / or employee ID 1356). The use of a handheld remote barcode scanner (scanning device 1306) allows a store clerk to scan a consumer's ID without having to walk away or turn around, while the consumer's ID remains in the clerk's hand. As a result, the clerk can quickly scan the consumer's ID and return it to the consumer before continuing with a supplying action (e.g., selecting / taking a supplied product), so that the consumer may be able to track their identity long while the consumer's ID is out of their hands.
[0076]
[0109] In some implementations, the display screen 1314 is contained within the retailer machine 1312, and the scanning device 1306 and processing circuit 1316 are incorporated into (or possibly communicate with) the supply machine 1302. In these implementations, the retailer machine 1312 provides means (e.g., the display screen and associated UI) for interacting with the processing circuit 1316 in the supply machine 1302.
[0077]
[0110] In some implementations, the display screen 1314, the scanning device 1306, and the processing circuit 1316 are integrated into (or possibly communicate with) the retailer machine 1312. In these implementations, the retailer machine 1312 provides means for interacting with the processing circuit 1316 (e.g., the display screen and associated UI) and acts as a controller for the supply machine 1302 (e.g., by providing supply commands to the supply machine 1302). In these implementations, the supply machine 1302 may be located under a counter or face-to-face with the consumer, and the only interaction with the supply machine 1302 during a supply operation would be the consumer taking the supplied product through the slot 1320. Alternatively, in such a consumer-facing implementation, the consumer may also scan a consumer ID 1354 using the onboard scanner 1318 in addition to taking the supplied product through the slot 1320. Alternatively, in these and other implementations, the store clerk retrieves the supplied product from slot 1320, which may allow for a scenario in which the consumer has no interaction with the dispensing machine 1302.
[0078]
[0111] In implementations where the retailer machine 1312 is involved in the supply of transactions relating to the managed product 1304 (for example, at least a portion of the processing circuit 1316 is incorporated into the retailer machine 1312), the retailer machine 1312 may communicate with the supply machine 1302 using a secure connection (either wired or wireless). In some implementations, the secure connection is encrypted to provide additional security to prevent unauthorized supply of the managed product 1304. In some implementations, the retailer machine 1312 is a handheld computing device configured to communicate wirelessly with the supply machine 1302.
[0079]
[0112] In some implementations, the processing circuit 1316 (integrated into the supply machine 1302 and / or the retail machine 1312) communicates with the server system 1308 via one or more local and / or wide-area communication networks 1310 (e.g., Wi-Fi, the Internet, etc.). The server system 1308 may be located in the same location as the supply machine 1302 (e.g., in the same store) or in a remote location (e.g., in a server farm, which is operated by or possibly associated with the manufacturer of the managed product 1304).
[0080]
[0113] Controlled Products 1304 may be age-restricted (e.g., tobacco, vaping products, alcohol, cannabis, etc.) as described throughout this disclosure. Controlled Products 1304 may not be age-restricted and instead may be identity-restricted, such as products that can be purchased by consumers of any age but may require consumers to provide identification at the time of purchase (e.g., spray paint, telephone cards, pharmaceutical products, etc.). Controlled Products 1304 may be both age-restricted and identity-restricted. Such products may be quantity-restricted (e.g., no individual may purchase more than a certain number of items within a given time period). Controlled Products 1304 may include any controlled devices (e.g., controlled devices described throughout this disclosure) and / or accessories, cartridges, refills, pods, or any other products designed for use with such devices.
[0081]
[0114] The managed supply environment 1300 may optionally include a placard 1352 indicating a managed product 1304 available for sale. Each managed product 1304 on the placard 1352 may be associated with a scannable barcode, QR code, or any other type of marking that identifies the product when scanned. The placard 1352 may be implemented as a mat placed on a counter in close proximity to the employee and the consumer, a sign placed on a surface visible to the employee and the consumer, or any other type of medium (e.g., an electronic display) capable of indicating products for consumer selection and employee scanning. Exemplary implementations of the placard 1352 are described below with reference to Figures 16A and 16B.
[0082]
[0115] The management supply environment 1300 may optionally communicate with a mobile device 1307. The mobile device 1307 is a personal electronic device associated with a consumer (e.g., the consumer's smartphone). The mobile device 1307 includes, but is not limited to, a smartphone, a tablet or laptop computer, or a personal digital assistant (PDA), a smart card, or a voice assistance device (such as Alexa), or other known or yet-discovered technologies (e.g., combinations of hardware and software) having a similar structure and / or capabilities to the mobile device described herein. The mobile device 1307 includes long-range communication capabilities (e.g., modems, transceivers, etc.) for communicating through (one or more) networks 1310, and short-range communication capabilities (e.g., BLE) for optionally communicating with the management product 1304 and / or other devices within the range of the mobile device 1307's short-range radio (e.g., a Bluetooth radio). The communication technologies described herein may be replaced by alternative communication technologies, and therefore, the specific communication technologies shown herein are not intended to be limiting. For example, Wi-Fi technology can be replaced by other long-range communication technologies.
[0083]
[0116] The server system 1308 communicates with the managed supply machine 1302, the mobile device 13107, and / or the retailer machine 1312 through (one or more) communication networks 1310. The server system 1308 stores user accounts associated with consumers of the managed product 1304. The server system 1308 includes one or more host processing servers that may be operated by a company associated with the seller of the managed product 1304. For each consumer, the server system 1308 may maintain a virtual wallet with a balance (which may be 0 dollars) of designated funds for which the server system 1308 holds the accounts. The balance may, for example, represent cash, or the balance may be promotional value representing funds that may be spent under certain circumstances. If these funds begin to run out, the consumer may be notified (for example, via an application on the mobile device 1307 or via electronic communication) that additional funds need to be designated and / or moved. Alternatively, funds from other sources (for example, a fund source server) may be automatically moved to restore the designated balance.
[0084]
[0117] The (one or more) communication network 1310 includes wired and / or wireless communication networks that enable ongoing connections (e.g., dedicated connections, dedicated online connections, and / or hardwired connections) or connections accessible on demand (e.g., the ability of machine 1302 to make a temporary connection to server system 1308, or the ability of a consumer to access server system 1308 from mobile device 1307). Generally, network connections are made via long-range communication technologies or long-range communication protocols (e.g., hardwired, telephone network technologies, cellular technologies (e.g., GSM, CDMA, etc.), Wi-Fi technologies, wide area networks (WANs), local area networks (LANs), or any known or yet undiscovered wired or wireless communication technologies over the Internet).
[0085]
[0118] The retailer machine 1312 is any computing device located near the sales point of the managed product 1304 (for example, a terminal computing device at a checkout counter in the store). The retailer machine 1312 communicates with the server system 1308 through one or more communication networks 1310 using long-range communication technology as described above.
[0086]
[0119] Figure 14 is a flowchart of the management and supply method 1400 in several implementation forms. Method 1400 can be controlled by instructions stored in computer memory or a non-temporary computer-readable storage medium and executed by one or more processors (e.g., processing circuit 1316). The computer-readable storage medium may include magnetic or optical disk storage devices, solid-state storage devices such as flash memory, or one or more other non-volatile memory devices. The instructions stored in the computer-readable storage medium may include one or more of source code, assembly language code, object code, or other instruction forms interpreted by one or more processors. Some operations in Method 1400 may be combined, and / or the order of some operations may be changed. Optional operations are transmitted by dashed lines.
[0087]
[0120] Some operations of Method 1400 (for example, 1402B, 1406B, and / or 1408) may be controlled by instructions stored in the memory or non-temporary computer-readable storage medium of the server system 1308 and executed by one or more processors of the server system 1308. The computer-readable storage medium of the server system 1308 may include magnetic or optical disk storage devices, solid-state storage devices such as flash memory, or one or more other non-volatile memory devices. Instructions stored in the computer-readable storage medium of the server system 1308 may include one or more of source code, assembly language code, object code, or other instruction formats interpreted by one or more processors.
[0088]
[0121] Method 1400 may begin as a result of a consumer (also called a user or supply requester) communicating their intention to purchase a controlled product 1304. The consumer may identify the controlled product 1304 using a placeholder in the store (e.g., an empty package, paper, or cardboard) that identifies the product the consumer has selected. The consumer may be building a shopping cart on a mobile application or website, and such application or website may provide an identifier (e.g., a barcode) associated with the shopping cart or product selection. The consumer may point to a specific controlled product 1304 on a display of a supply machine 1302 or retail machine 1312. The consumer may point to a specific controlled product 1304 on signage or a countertop display (e.g., a placard 1352) that has the product name or image. The consumer may verbally tell a store employee which specific controlled product 1304 they wish to purchase. Regardless of the product identification method, the supply method 1400 may be performed as a result of a specific controlled product 1304 being identified by a consumer (labeled in the figure as “start”). The inputs required by the supply method 1400 (described below with respect to operations 1402, 1404, and 1406) may be provided by a store clerk, a consumer, or any combination thereof.
[0089]
[0122] To supply the desired controlled product 1304, the processing circuit 1316 of the supply machine 1302 or the retail machine 1312 requires that at least one of operations 1402, 1404, and 1406 be performed. Depending on the implementation, at least two of operations 1402, 1404, and 1406 must be performed, or all three of operations 1402, 1404, and 1406 must be performed, in order to supply the desired controlled product 1304. The operations may be performed in any order. For example, operation 1402 may be performed, followed by operations 1404 and / or 1406 (or 1406 and / or 1404) by choice. Alternatively, operation 1404 may be performed, followed by operations 1402 and / or 1406 (or 1406 and / or 1402) by choice. Alternatively, operation 1406 may be performed, followed by, optionally, operations 1402 and / or 1404 (or 1404 and / or 1402). A subset of operations 1402, 1404, and 1406 required to perform supply operation 1410 may be customizable based on the desired level of safety and / or liability protection (e.g., by the store operator, by the manufacturer, etc.).
[0090]
[0123] In operation 1402, the processing circuit 1316 identifies the managed product 1304. The product may be identified based on any of the consumer or store clerk actions described above with respect to providing product identification. For example, a product identifier, such as a barcode or image representing the product, may be selected (on the user interface of the display screen 1314) or scanned using the scanning device 1306 and / or the onboard scanner 1318 (for example, by scanning a barcode on a placard 1352 or by scanning a code on the consumer's mobile device).
[0091]
[0124] In some implementations, upon receiving a product identifier, processing circuit 1316 checks the inventory status of the identified product (1402A) and / or evaluates the bulk sales limit for the identified product (1402B). The bulk sales limit (also called the purchase limit, supply limit, limit threshold, or supply limit threshold) may (i) limit the number of products that can be purchased and / or supplied by a consumer in a single transaction, and / or (ii) limit the number of products that can be purchased and / or supplied by a single consumer within a given time period (for example, by restricted use restrictions associated with a controlled product). In other words, the limit threshold may correspond to the maximum number of products that can be supplied to a given consumer over a given time period. Such limits may apply per product (e.g., only four of a particular product can be purchased per transaction or per day), per product category (e.g., only one product of type 1 and four products of type 2 can be purchased per transaction or per day), and per total item (e.g., only a total of eight items can be purchased per transaction or per day). Such limits may be applied based on the amount of time between purchases for a particular consumer (for example, a consumer may purchase only four items per day, per week, per month, etc.). Any of the stated limits may be specific to a particular supply machine, or they may apply across a group of machines or an entire network of machines. Limits may also be specific to a geographical area.
[0092]
[0125] In accordance with the bulk / purchase limit processing, the processing circuit 1316 may track a consumer's transactions (and by extension, how many and which products were purchased) by tracking the consumer's identification (obtained in operation 1406 below). Consumer transactions may be tracked locally (for example, in the processing circuit 1316 of a particular supply machine 1302 or retail machine 1312) or across a network (for example, by a tracking process implemented in a server system 1308 communicating with the processing circuits 1316 of multiple supply machines 1302 and / or retail machines 1312). In accordance with the bulk / purchase limit processing, the processing circuit 1316 may adjust the purchase limit for a particular consumer based on a risk score for that consumer. The processing circuit 1316 may evaluate a consumer's risk score in operation 1406 below. The higher the risk score, the lower the bulk limit for a particular transaction may be adjusted. Similarly, the lower the risk score, the higher the bulk limit for a particular transaction may be adjusted. If a machine is offline (not connected to a communication network) and a network-wide product limit is established, a separate offline limit may apply. For example, if a consumer is allowed to purchase eight products per month across a group of machines, and the consumer wishes to make a purchase on a machine that is currently offline (meaning it is not possible to check the network limit), an alternative local limit of two products may be granted. When the offline machine regains connectivity, the purchased products may be subject to the consumer's network-wide limit. Offline limits may vary depending on the consumer's risk score, provided they are locally available on the offline machine.
[0093]
[0126] In operation 1404, processing circuit 1316 identifies and authenticates the employee. This operation is optional and is not required for all transactions. Processing circuit 1316 may authenticate the employee by scanning the employee's badge or access card 1356 using the scanning device 1306 and / or the onboard scanner 1318. During such a scan, the employee may be logged into the supply machine 1302 and / or the retail machine 1312, and as a result, supply operations associated with the authorized employee may be unlocked (authorized) for the supply machine 1302 and / or the retail machine 1312. Operation 1404 may be performed before operation 1402. In some implementations, when operation 1404 is performed, the employee may be authenticated for a predetermined amount of time (e.g., a 4-hour shift), during which time the employee remains authenticated for subsequent transactions and supply operations. Alternatively, operation 1404 may be required to be performed for each subsequent supply operation to provide a more detailed record of the approval process for each supply operation of the managed product 1304. In some implementations, processing circuit 1316 may associate a clerk (during scanning or login as described above) with a supply operation handled by the clerk. Such associations may be used to track sales by a particular clerk for incentive payments, for security limits, and to prevent a clerk from using their own ID instead of a consumer ID. For example, if a clerk's ID is associated with a particular user account, the system can prevent the consumer ID for that user account from being used for a transaction (when the consumer ID is the same as the clerk's ID, or possibly the same as the ID of another clerk employed at the same location).
[0094]
[0127] In operation 1406, processing circuit 1316 identifies the consumer and / or verifies the consumer's eligibility to obtain the identified product 1304. This may include verifying the consumer's age or other information on the consumer's ID card 1354 (e.g., name, date of birth, expiration date, and / or license / identification number on the consumer's driver's license, passport, military identification card, or any other type of identification document) (1406A). Consumer identification information may be acquired by scanning devices 1306 / 1318 or manually entered using a user interface on the display screen 1314. Facial recognition software in scanning devices 1306 / 1318 or in the retail machine 1312 may be used to identify / authenticate the consumer. Optionally, consumer identification information may be acquired by an optional external camera (not shown) mounted on or communicating with machine 1302 or the retail machine 1312, configured to acquire an image of the consumer and identify the consumer based on that image. Consumer identification information may be obtained by scanning an identification code (e.g., a QR code) on the consumer's mobile device (using scanning devices 1306 / 1318), and the mobile device runs an application that displays the identification code on the mobile device's display for scanning by a store employee during optional biometric verification of the consumer's identity. In some implementations, processing circuit 1316 may verify or validate the authenticity of an identification document or image by comparing the document or image with documents or images in a database (searching the database) and / or by using machine intelligence to determine authenticity. The database and / or machine intelligence application may be implemented in or otherwise accessible by the server system 1308. For example, an authentication database for identification cards (e.g., a driver's license or passport) may be accessed by the supply machine 1302 or the server system 1308 using an application programming interface (API). The server system 1308 verifies the consumer's age based on the identification document.
[0095]
[0128] In some implementations, the processing circuit 1316 may hash consumer identification information or extract a consumer identifier from the identification information. By hashing the consumer identification information locally (for example, by applying a hashing algorithm to the identification number on consumer ID 1354) before sending the hashed data to the server system 1308 for further identification and / or purchase limit processing, the server system 1308 does not obtain personally identifiable information (PII) associated with the consumer. Specifically, instead of obtaining the consumer's name or date of birth (or other PII), the server obtains only the hashed identification number, which it can use to track consumer purchases (for example, as described below with respect to operations 1402B, 1406B, and / or 1408). In other words, the consumer ID transmitted in operation 1502 may be the hashed identification number. Thus, consumer privacy is respected while still providing the server system 1308 with a way to track the consumer's purchase history for the purpose of evaluating purchase limits and consumer standards (for example, as described below with respect to operation 1504).
[0096]
[0129] As part of operation 1406, the clerk has the opportunity to physically verify that the image on the consumer's identification card matches the consumer's appearance. Thus, the clerk authentication operation (1404) may act as a digital signature or electronic record of the clerk verifying the consumer's identity and / or age for a particular transaction and supply operation.
[0097]
[0130] In some implementations, after identifying a consumer and / or verifying the consumer's age, the processing circuit 1316 may evaluate, determine, or, in some cases, obtain several consumer criteria (1406B). Consumer criteria may be based on risk, health, and / or compliance with controlled product restrictions. Consumer criteria may be determined locally based on the consumer's purchase history (also called supply history) (e.g., how many and which products were purchased per transaction, per day, per week, per month, etc.). Consumer criteria may be determined remotely (e.g., by a risk determination process implemented in a server system 1308 communicating with processing circuits 1316 of multiple supply machines 1302 and / or retailer machines 1312). Consumer criteria may be based on the number of products purchased from one or more supply machines 1302 at one or more locations (stores) during a particular time period, or the number of transactions (supply operations) performed by one or more supply machines 1302 at one or more locations during a particular time period. A higher number of products purchased (or completed transactions), or a higher number of transactions, results in a higher consumer risk score. Similarly, a lower number of products purchased, or a lower number of transactions, results in a lower consumer risk score. Consumer criteria may be influenced by other risk-based, health-based, and / or compliance-based factors, such as purchase activity (e.g., whether products were purchased in different jurisdictions (e.g., city, county, or state) over a short time interval) and / or purchase location characteristics (e.g., locations with historically high crime and / or medical activity, or locations close to schools). In some implementations, instead of a score, consumer criteria may be assessed by comparing the above criteria to predetermined thresholds that may be set based on the level of risk or liability that the retailer or manufacturer associated with the controlled product 1304 is willing to accept or is legally permitted to implement.
[0098]
[0131] Once consumer criteria are obtained, processing circuit 1316 may evaluate consumer criteria by comparing the number and / or types of products identified (or subsequently identified) in operation 1402 with predetermined thresholds according to the risk score / criteria as described above. Higher risk scores may be associated with lower criterion thresholds (further restricting purchases), and lower risk scores may be associated with higher criterion thresholds (allowing increased purchases). The higher the threshold, the more products the consumer may be able to purchase, and / or the more transactions the consumer may be able to complete in a given time period (e.g., per day, per week, per month). Thresholds may be determined on a location-by-location basis. For example, thresholds for a store may be adjusted depending on the store and how much risk the store manager is willing to accept (or is legally permitted to accept).
[0099]
[0132] By evaluating the consumer criteria by comparing the threshold associated with the risk score / criteria with the type and / or number of products identified in operation 1402, the processing circuit 1316 may or may not allow the requested products to be supplied. If it does not allow the requested products to be supplied, the clerk / consumer may reduce the number of products identified in operation 1402 for supply or cancel the supply operation altogether. Once the supply operation is complete, the processing circuit 1316 may update (or cause the consumer's risk score / criteria to be updated) the consumer's risk score / criteria based on the number and / or type of products supplied.
[0100]
[0133] In some implementations, operations 1402B and 1406B may be performed independently of operations 1402 and 1406 as separate verification operations 1408 (or more verification operations 1408) performed when identifying one or more controlled products (in operation 1402) and when identifying a consumer (in operation 1406). When identifying one or more controlled products and a consumer, the processing circuit 1316 may verify purchase limits and consumer criteria (as described above) in one or more operations 1408 before proceeding to supply (1410) the identified controlled products.
[0101]
[0134] Figure 15 shows an exemplary verification operation 1408 of the managed supply method 1400 in several implementation forms. Verification operation 1408 may be implemented in the supply machine 1302 and server system 1308 (as described above with reference to Figure 13). Verification operation 1408 may be triggered upon completion of product selection / identification (operation 1402) and consumer identification (operation 1406) (and optionally, clerk authentication (operation 1404)). Upon completion of the above operations, verification operation 1408 may be triggered by selection of a user interface element on the display screen 1314 (e.g., element 1902 as described below with reference to Figure 19), by barcode scanning (e.g., using scanning devices 1306 / 1308 to scan a code corresponding to a supply command), or by a determination that a predetermined amount of time has elapsed since the activity related to operations 1402, 1404, and / or 1406.
[0102]
[0135] In the supply machine 1302, once one or more managed products are selected / identified (product ID) and the consumer is verified (consumer ID) (e.g., age verification and / or identity verification), the supply machine 1302 transmits the product ID (also called the first identifier) and the consumer ID (also called the second identifier) to the server system 1308 (1502). The server system 1308 determines whether it can approve the supply of (one or more) products to the consumer by evaluating the consumer's purchase history and other criteria to determine whether purchase limits or other consumer criteria (e.g., as described above with respect to operations 1402B and 1406B) allow the products (one or more) to be supplied to the consumer (1504). For example, the server system 1308 may compare the requested products (one or more) with products previously purchased by the same consumer over a period of time and determine whether the supply can be approved based on predetermined limits set for the supply machine 1302 or for the entire network of supply machines 1302. For example, a consumer ID may be blocked (supply may be denied) based on several criteria, such as whether the consumer is suspected of resale, fraud, redistribution, and / or other factors affecting consumer standards. Even if a consumer is within their purchase limits, they may still be blocked from accessing the requested products (one or more) based on consumer standards.
[0103]
[0136] In some implementations, a consumer's purchase history is tracked locally at the location of the supply machine 1302 (for example, in a store). For example, the processing circuit 1316 and the local memory of the supply machine 1302 may obtain a blocklist of consumer IDs (or hash values of consumer IDs) (for example, by downloading it from the server system 1308). If consumer ID 1354 (or hash value of consumer ID 1354) matches a consumer ID (or hash value of consumer ID) on the blocklist, the consumer may be blocked from accessing the requested products (one or more). Such a blocklist may include consumer IDs (or hashes of consumer IDs) associated with fraudulent IDs previously caught or flagged by a store employee. The blocklist may be stored and updated in the server system 1308 and periodically transmitted to the supply machine 1302. Alternatively, the blocklist may be stored and updated locally (for example, in the retailer machine 1312), and the server system 1308 may no longer be required to maintain and use the blocklist.
[0104]
[0137] The server system 1308 may verify or confirm the authenticity of an identification document corresponding to a consumer ID by comparing the document with a document in the database and / or by using machine intelligence to determine its authenticity. The database and / or machine intelligence application may be implemented in or accessible through the server system 1308. For example, an authentication database for identification cards (e.g., a driver's license or passport) may be implemented on a server not included in the server system 1308, and the server system 1308 may access or utilize the authentication database using an application programming interface (API).
[0105]
[0138] To track all managed products supplied to a particular consumer, the server system 1308 may pool supply data (e.g., the number and / or identity of supplied products) from all supply machines 1302 (e.g., supply machines 1302 located in different stores, cities, states, etc.) that are communicably connected to the server system 1308 via one or more networks 1310. In addition to, or as an alternative to, central tracking of supply data in the server system 1308, supply data for multiple supply operations associated with multiple consumers may be tracked via a distributed network of supply machines 1302, for example, using a blockchain protocol.
[0106]
[0139] For example, each of several supply machines 1302 on network 1310 may maintain a ledger of all transactions over the past 30 days (or any other time period). The ledger of each machine may be updated with blocks distributed later using the blockchain protocol. If a supply machine 1302 loses its connection to network 1310 (goes offline), the supply machine 1302 may independently and locally apply purchase or supply limits using a local copy of the transaction ledger (for example, by comparing previous purchase or supply actions associated with a particular consumer with several requested products to determine if a limit threshold is met, and if the limit threshold is met, by supplying the products).
[0107]
[0140] As another example, each of the multiple supply machines 1302 on network 1310 may periodically download a blocklist of consumer IDs from server system 1308. The blocklist may include consumer IDs that are not permitted to be supplied (for example, for fraudulent IDs that have been previously caught or flagged by a store employee). The blocklist may be maintained at the local level if the supply machine 1302 is not connected to network 1310.
[0108]
[0141] If the server system 1308 determines that supplying the requested products (one or more) to the consumer will not violate any purchase limits and / or other consumer standards (for example, supplying the requested products to the consumer will not violate any purchase limits associated with the products with respect to the consumer), the server system 1308 approves the supply of the requested products. Otherwise, the server system 1308 refuses the supply of the requested products.
[0109]
[0142] Upon evaluating the requested supply operation, the server system 1308 transmits the result of the evaluation operation 1504 (an approval notification if the supply is approved or a rejection notification if the supply is rejected) to the supply machine 1302 (1506). The server system 1308 also updates the consumer's purchase history to log the supplied products (one or more) (1508). The updated purchase history for the consumer may play a role in rejecting subsequent supply requests (for example, if such requests would result in a violation of purchase limits). In some implementations, rather than approving or rejecting the supply request as a whole, the approval or rejection notification may partially approve the supply of a subset of the requested products in order to satisfy the relevant limit thresholds. For example, if a consumer is limited to three specific types of controlled products on a given day, and the consumer requests five of such products, the server system 1308 may send a notification to the supply machine 1302 approving the supply of only three of the five requested products. In such a scenario, the supply machine 1302 may display a message indicating the reason for the partial approval. Such messages may be included in transmissions from server system 1308.
[0110]
[0143] Upon receiving the evaluation result, the supply machine 1302 causes the requested product to be supplied (as described in operation 1410 described above) if the supply is approved (1510), or prevents the requested product from being supplied if the supply is rejected. In some implementations, the supply machine 1302 may notify the employee / consumer of a rejected supply by causing a message to be displayed on the display screen 1314 or on the retailer machine 1312.
[0111]
[0144] If a supply is approved by the server system 1308, but the supply operation 1410 fails in the supply machine 1302 (for example, due to a mechanical problem or insufficient stock), the supply machine 1302 may report the failed supply operation by sending a notification to the server system 1308 (1512). Upon receiving notification of a failed supply operation, the server system 1308 may update the consumer's purchase history by crediting (1514) the (one or more) products that it failed to supply, thereby reflecting that the consumer never used the (one or more) requested products. As a result, the failed supply operation will not adversely affect subsequent supply operations associated with the consumer (for example, the consumer's purchase history and limits will be reset to their respective states prior to the current supply operation).
[0112]
[0145] In some implementations, instead of the verification operations being performed on the server (operations 1504, 1506, 1508, 1514), one or more of these operations may be performed locally at the supply machine 1302. For example, supply limits may be at the transaction level or the machine level. More specifically, there may be a maximum number of managed products that can be supplied per transaction, per consumer, and / or per supply machine 1302. In such implementations, the number of requested products can be compared locally at the supply machine 1302 with device limits per transaction, per consumer, and / or per machine, so that server communication is not required to approve the requested supply operation. The supply machine 1302 verifies the consumer ID locally and can supply the requested number of products as long as it is less than the number of products that can be supplied per transaction, per consumer, and / or per machine.
[0113]
[0146] Returning to Figure 14, in operation 1410, processing circuit 1316 (for example, in operation 1510, upon receiving the approved evaluation result in Figure 15) approves to supply the controlled product 1304 identified in operation 1402. Upon approval for supply, processing circuit 1316 may, upon receiving a command via the user interface (for example, the selection of the "supply" element), supply or be supplied with the approved product. Processing circuit 1316 may withhold, suppress, and / or disable the supply of one or more products requested by the consumer until an approval notification is received from the server system 1308 (in operation 1510). Processing circuit 1316 approves to supply the identified product in accordance with the successful completion of operations 1402, 1404, and / or 1406 (depending on which operations were required), and optionally in accordance with the approval notifications received in accordance with verification operations 1402B, 1406B, and / or 1408. For example, if all three operations 1402, 1404, and 1406 are required and verification in operation 1408 is successful, the processing circuit 1316 will authorize the supply of the product identified in operation 1402 (for example, when determining positive stock and purchase limits), provided that the clerk is authenticated in operation 1404, the consumer is verified in operation 1406 (for example, when age and / or identity is verified and / or when the requested product results in a positive risk / criteria assessment due to meeting the threshold), and the supply is verified in operation 1408. If at least one of these required operations fails to complete successfully, the processing circuit 1316 will not authorize the supply of the product identified in operation 1402. In such a scenario, the processing circuit 1316 may provide a message via the user interface on the display screen 1314 regarding which operations failed to complete successfully and / or the steps that need to be performed to successfully complete a particular operation.
[0114]
[0147] The controlled supply method 1400 controls the supply of controlled product 1304 in accordance with a transaction initiated by the consumer. Other aspects of such a transaction, such as payment processing, may or may not involve the supply machine 1302. In other words, the supply operation described with respect to method 1400 can be completed independently of any payment function.
[0115]
[0148] In some implementations, supply and payment operations may be integrated into the same process. For example, upon product identification in operation 1402, or approval for the supply of such products in operation 1410, processing circuit 1316 may provide the products (for example, by transmitting product identifiers associated with the identified and / or approved products) or the prices associated with those products to retail machine 1312, which then enables payment functions (for example, determining the outstanding amount based on product price, taxes, discounts, etc., collecting payment by processing credit card transactions, providing receipts, etc.).
[0116]
[0149] In some implementations, the supply operation and the payment operation may be processed separately, either in parallel or sequentially. For example, while the processing circuit 1316 of the supply machine 1302 is performing the supply operation (method 1400), the retail machine 1312 may perform the payment operation (including, for example, the clerk manually entering the amount to be charged or selecting the identified products, and performing other payment operations as described above). Alternatively, the clerk may use the retail machine 1312 to process the payment first, and when the clerk receives confirmation that the payment was successful, the supply machine 1302 may perform the supply operation. Alternatively, the clerk may cause the supply machine 1302 to perform the supply operation first, and when the supply of the requested products is successful, the retail machine 1312 may perform the payment operation.
[0117]
[0150] In some implementations, the supply machine 1302 may store each supply operation in local memory for auditing purposes. The supply machine 1302 may optionally transmit the stored supply operations to the server system 1308 so that the supply records pooled across the network of supply machines 1302 can be audited. Such auditing functionality is useful for determining compliance with regulations associated with the supply of controlled product 1304. Furthermore, such auditing functionality, along with other functions described above with reference to Figures 14 and 15, facilitates accountability in the regulation of the supply of controlled product 1304 (including, for example, regulations on which consumers may receive such products and how many of such products may be supplied in a given transaction).
[0118]
[0151] Figures 16 to 19 show exemplary user interface screens (for example, for display on a display screen 1314) in several implementation configurations. The exemplary user interfaces may support touch or voice interaction. In the touch interaction implementation configuration, the exemplary screen may execute one or more commands upon selection and display one or more selectable affordances, as described below.
[0119]
[0152] Figure 16A shows a user interface 1610 with product images and corresponding labels (A-F) including product labels (product category X, product category Y, product category Z). The product images and / or labels may be selectable affordances, the selection of which identifies the product as described in operation 1402. The labels help the salesperson identify the product the consumer desires, and the product images may be animated. The user interface 1610 may also include a price display, which may be changed locally on the supply machine 1302 or retailer machine 1312, or remotely on the server system 1308. There may be several different product variants for a given product (e.g., flavor of a vaping product or color of spray paint). The user interface 1610 may include warnings (not shown) that convey the controlled nature of the product, and / or rules that restrict access to such products. The user interface 1610 may be displayed on the display screen 1314 (for example, as an idle screen displayed between supply operations) and / or implemented as a placard 1352. Implementing the same or similar user interface on the display screen 1314 and the placard 1352 increases the ease with which consumers and store employees can identify the desired product.
[0120]
[0153] Figure 16B shows a user interface 1620 having product images (product X, product Y, product Z) and corresponding scannable barcodes. The barcodes can be scanned by a scanning device 1306, which identifies the product as described in operation 1402. The product images may be animated. The user interface 1620 may also include a price display (not shown), which can be changed locally on the dispensing machine 1302 or the retailer machine 1312, or remotely on the server system 1308. There may be several different product variants for a given product (e.g., flavor of a vaping product or color of spray paint). The user interface 1620 may include warnings that convey the controlled nature of the product and / or rules that restrict access to such product. The user interface 1620 may be displayed on a display screen 1314 (e.g., as an idle screen displayed between dispensing operations) and / or implemented as a placard 1352. The placard 1352 may also have additional barcodes or QR codes for machine operations, such as dispensing and / or cancellation commands. For example, a store employee may use a scanner device 1306 to scan the consumer's ID, scan the product barcode on the placard, and then scan the dispensing barcode. The employee can then simply walk to the dispensing machine and take the product without having to directly touch or interact with the machine. Implementing the same or similar user interface on the display screen 1314 and the placard 1352 increases the ease with which consumers and store employees can identify the desired product. In some implementations, the user interface 1610 may be displayed on a touch-sensitive display screen 1314 (e.g., an idle screen on the dispensing machine 1302), and the user interface 1620 may be displayed as a scannable placard 1352 (e.g., a card with a scannable barcode).
[0121]
[0154] In some implementations, the scanning device 1306 may provide feedback to the store clerk regarding the scan. For example, if the consumer ID is valid and the purchase is approved, the scanner may output an audible (e.g., "beep") or visual indication that the consumer is approved. If the consumer ID is rejected, a different audible or visual indication may be presented to the store clerk.
[0122]
[0155] When a product is selected (for example, using user interface 1610 or 1620), the user interface proceeds to the transaction screen, as shown in Figure 17A. For example, when product Y variant I is selected in user interface 1610 (Figure 16A), the quantity affordance "1" is highlighted, indicating that one product Y variant I has been selected (Figure 17A). The transaction screen includes arrays of quantity affordances (e.g., numbers 1, 2, 3, and 4 for each product), product images, text, and prices. Each of the above elements may be selectable. Each product is associated with multiple quantity affordances representing different quantities of the corresponding product.
[0123]
[0156] In some implementations, each quantity affordance may indicate a selection status based on whether or not it has been selected. For example, selected quantity affordances may be displayed with highlighting or texture (e.g., an affordance of 1 for product B). In some implementations, selecting a quantity affordance that has already been selected results in that quantity affordance becoming unselected and the quantity of the selected product being adjusted accordingly.
[0124]
[0157] In some implementations, each quantity affordance may indicate an availability status based on (i) a quantity limit for the corresponding product or a quantity limit for the transaction, and (ii) the number of products already selected. If selecting a particular quantity affordance would result in the number of selected products exceeding the relevant product limit or transaction limit, that particular affordance may be indicated as unavailable (for example, by being grayed out) and become unselectable (for example, the 4 affordance for products C-F). Such indications are referred to herein as availability indications.
[0125]
[0158] In some implementations, the availability status of quantity affordances is updated in real time to indicate which quantity affordances can still be selected, as described above. Figures 17A–17F show an example of real-time quantity affordance updates. In this example, there is a quantity limit of one for product X (also referred to herein as a bulk limit) and a combined product limit of four for products Y and Z. Therefore, for a single supply transaction, only one product X may be selected, and up to four products Y and / or Z may be selected.
[0126]
[0159] In Figure 17A, one product Y is selected. Therefore, all quantity affordances that would cause the number of selected products Y and Z to exceed four (quantity limit) are grayed out. In this case, the quantity affordance of 4 is grayed out for the other products Y and Z. The selection of 4 for the selected products causes the selected 1 to become unselected, resulting in a total of 4 new selected quantities, which satisfies the quantity limit, so this 4 is not grayed out.
[0127]
[0160] In Figure 17B, two more product Ys are selected, bringing the total number of selected product Y / Z to three. Therefore, further quantity affordances are shown in gray.
[0128]
[0161] In Figure 17C, another product Y is selected, bringing the total number of selected products Y / Z to four, which is the quantity limit. Therefore, all other quantity affordances for the other product Y / Z are grayed out, except for one affordance for product Y variant II, because selecting this affordance deselects two affordances, which reduces the total number of selected products Y / Z to three.
[0129]
[0162] In Figure 17D, one instance of product X is selected, thereby satisfying the quantity limit for product X.
[0130]
[0163] In Figure 17E, one product Y variant III is deselected, which reduces the total number of selected products Y / Z to three, causing further quantity affordances to indicate selectability.
[0131]
[0164] In Figure 17F, three affordances are selected for product Y variant II, which causes two affordances for that product to be deselected, resulting in the total of selected product Y / Z being back to four, which is the quantity limit. As a result of the total of selected product Y / Z reaching the quantity limit of four, the quantity affordances associated with the other products are grayed out to indicate that they are no longer selectable.
[0132]
[0165] Returning to Figure 17A, the transaction screen may include a status section 1702, which includes status elements (e.g., ID checkbox, clerk checkbox, and product checkbox) that indicate the completion status of the operations required for supply (e.g., operations 1402, 1404, and 1406). When each operation is completed, the corresponding status element is updated to indicate the completion of that operation (e.g., the box becomes checked).
[0133]
[0166] The transaction screen may include an instruction box 1704 containing instructions that inform the clerk which (one or more) operations remain incomplete. However, regardless of which (one or more) instructions are displayed, the operations may be completed in any order, as described above. The guidance provided by the instruction box 1704 enables an untrained clerk to complete the managed supply method 1400.
[0134]
[0167] The transaction screen may include an Identification (ID) section 1706 containing information about the scanned or manually entered (typed) consumer ID. A manual entry affordance ("Type ID") allows the clerk to manually enter information from the consumer ID (e.g., date of birth, expiration date, driver's license number, etc.). Alternatively, the clerk may scan the consumer ID using the storage controller 124 as described above. Regardless of the method of entry, the ID section may be updated to show information associated with the consumer ID (see Figure 19). Adjacent to the ID section may be a "Verified by" message (see Figure 19) which informs the clerk that they are accountable for physically verifying a photograph of the consumer ID on which the information is being scanned. The "Verified by" line may include the clerk's name or other identifying information obtained in operation 1404.
[0135]
[0168] The transaction screen may include a product overview section 1708, which includes quantity limits and the number of selected products associated with each quantity limit, as described above. The transaction screen may include a cancellation affordance 1710, the selection of which terminates the supply session. A pause affordance may appear adjacent to the cancellation affordance, the selection of which extends the supply session (for example, if the clerk receives a phone call or other distraction). The transaction screen may include a supply affordance 1902 (see Figure 19). A supply affordance appears only after each required action (e.g., 1402, 1404, and 1406) has been completed (e.g., one or more products have been selected, the consumer is of valid age, has a valid ID, the clerk is logged in, and the selected products are within limits). The selection of a supply affordance causes the supply machine 1302 to supply the selected products (e.g., causes the processing circuit 1316 to send an instruction to the supply mechanism associated with each selected product to supply a specified quantity of each respective product).
[0136]
[0169] Returning to Figure 17F, five products have been selected: one product X (meeting the quantity limit for such a product) and four products Y / Z (meeting the quantity limit for such a product). At this point in the supply process, quantity affordances may be deselected or alternative quantity affordances may be selected to change the quantity and type of products to be supplied. As long as at least one product is selected, the product status elements in status section 1702 are checked. At this point (or, as described above, before product selection or after consumer verification), the clerk may scan a badge or access card using the storage controller 124 as described above with respect to operation 1404. As part of this operation, the user interface may display a PIN entry screen (Figure 18A). Once the clerk's PIN is entered (or, if a PIN is not required, once the clerk's badge is scanned), the status section 1702 of the user interface indicates the completion of clerk authentication operation 1404 (e.g., the clerk elements are checked, see Figure 18B). At this point in the supply operation (or, as described above, before the clerk authentication operation and / or product selection operation), the consumer's ID may be scanned using the storage controller 124 or entered manually. The ID section 1706 may display confirmation that the ID is valid (Figure 19), or an "Invalid ID" message if the ID is found to be expired or otherwise invalid, or a "Minor" message if the consumer's age does not meet the age threshold for the selected product. When a valid consumer ID has been scanned or entered successfully, the status section 1702 indicates that the consumer verification operation is complete (e.g., the ID box is checked). Once all three operations 1402, 1404, and 1404 (or a subset of those operations, depending on which operations are required) are complete, the supply affordance 1902 is displayed, and its selection causes the selected product to be supplied.
[0137]
[0170] Figure 20 is a diagram of the managed supply environment 2000. Items corresponding to those in the managed supply environment 1300 (Figure 13) are similarly numbered, and some are not further described for brevity. In the managed supply environment 2000, multiple secondary supply machines 2002A-N may be communicatively coupled to the master supply machine 1302. The interconnected supply machines may communicate with a single controller, or more specifically, a single instance of the processing circuit 1316. The interconnected supply machines may be further coupled to a single scanning device 1306 and / or a single retailer machine 1312. For example, a scanned product identifier (e.g., a barcode) may be transmitted to the processing circuit 1316 of the supply machine 1302 or the retailer machine 1312, and the processing circuit 1316 will determine which supply machine will contain the desired managed product 1304. A dispensing machine containing the desired product receives a “dispensing” command from processing circuit 1316 when the required dispensing operations (e.g., 1402, 1404, and / or 1406) are successfully completed. In some implementations, processing circuit 1316 may transmit a message on the display screen 1314 of dispensing machine 1302 or retailer machine 1312, directing the employee to a specific dispensing machine to retrieve the dispensed product. In some implementations, a routing table is included in the memory of processing circuit 1316 that routes each managed product 1304 to the respective dispensing machine (1302 or 2002A-N) that houses them. Dispensing machines 1302 and 2002A-N may be connected in a communicative manner via a wired or wireless local area network as described above, or via a wide area network (e.g., via one or more communication networks 1310 and server system 1308 as described above). Therefore, multiple supply machines can be employed in the managed supply environment 2000 without the requirement for a separate scanning device for each supply machine, and confusion regarding which supply machine to retrieve the supplied product from can be avoided. In some implementations, one or more of the machines 2002A-N may not have a display screen.
[0138]
[0171] Figures 21A to 21D show the management supply machine 2100, including an internal camera 2102, in several implementation configurations. The supply machine 2100 may correspond to the supply machine 102 (Figure 1) and / or the supply machine 1302 (Figure 13), and the features described above for these supply machines may be shared with the supply machine 2100.
[0139]
[0172] The supply machine 2100 includes a camera 2102 (or any other sensing device, such as a scanner) that is mounted either on the inside or on the outside, allowing a view of the products inside. In some implementations, the camera may be mounted inside the door 2110 or somewhere else inside the cabinet 2112 of the supply machine 2100. The camera 2102 has a field of view 2120 that covers the products disposed inside the machine 2100.
[0140]
[0173] As described above with respect to machines 102 (Figure 1) and 1302 (Figure 13), the feeding machine 2100 may include a plurality of slots 2104 and corresponding feeding mechanisms 2106 (e.g., spirals, pushers, etc.). For example, referring to Figure 21D, product 2122 may be placed inside slot 2104a and be fed by feeding mechanism 2106a, and product 2124 may be fed inside slot 2104b and be fed by feeding mechanism 2106b.
[0141]
[0174] In some implementations, products have text and / or barcode / QR labels on their packaging, which may be oriented so that the camera 2102 can image them all at once (by having the text / labels within the field of view 2120). This may be useful for tracking inventory levels (e.g., counting how many products are in each slot), tracking sales (e.g., by determining how many and which product labels are present), tracking batch codes (e.g., for recalling products), tracking serial numbers (e.g., for activation as described above), and / or identifying products filed or filled in the wrong place. In some implementations, if a product is recalled or expires, machine 2100 may deactivate the slot or supply mechanism corresponding to the recalled / expired product based on either local calculation or analysis in machine 2100's processor, or based on instructions received from a server (e.g., server system 1308, Figure 13) based on remote analysis in a server.
[0142]
[0175] In some implementations, the machine 2100 may periodically capture images using the camera 2102 to implement one or more of the tracking / identification operations described above. Image capture and associated processing may be triggered by a supply request (for example, operation 1402B or 1408, in Figure 14).
[0143]
[0176] Figure 22 is a flowchart of a remote verification method 2200 in a mobile device, including remote consumer account provisioning and remote product selection, in several implementation forms. Method 2200 may be controlled by instructions stored in the memory or non-temporary computer-readable storage medium of the mobile device (e.g., mobile device 1307) and executed by one or more processors of the mobile device. The computer-readable storage medium may include magnetic or optical disk storage devices, solid-state storage devices such as flash memory, or one or more other non-volatile memory devices. Instructions stored in the computer-readable storage medium may include one or more of source code, assembly language code, object code, or other instruction forms interpreted by one or more processors. Some operations in Method 2200 may be combined, and / or the order of some operations may be changed. Optional operations are communicated by dashed lines.
[0144]
[0177] In Method 2200, the consumer may use their phone (e.g., mobile device 1307) to perform some of the actions described above in Method 1400 (Figure 14) before going to the location where the supply machine 1302 is located (before going to the store), thereby saving time and adding convenience for the consumer without compromising age-based or identity-based compliance measures related to the sale of controlled products from the perspective of the retailer or manufacturer.
[0145]
[0178] Generally, the mobile device 1307 runs an application that verifies and confirms consumer information, allows the purchase of a managed product 1304, and enables communication with a server system 1308 via one or more communication networks 1310. If the consumer is a user of the application, the consumer can use the application to purchase and / or reserve a managed product 1304 at a desired store and receive a barcode in the application that identifies the reserved product and verifies the consumer (verifies the consumer's age and / or identity). When the consumer arrives at the selected store, a retail employee scans the barcode in the application (for example, using a scanner 1306). The consumer may provide further identity and / or age verification by performing biometric verification on the consumer's mobile device 1307 (for example, using Touch ID, Facial ID, or similar) to verify that the consumer is the owner of the mobile device 1307. After biometric verification is performed, the consumer is verified as the owner of the mobile device 1307, and the mobile device 1307 is associated with the consumer's account (after the application is installed), and the consumer's identity and / or age has been verified using that consumer's account (by performing a verification procedure during initial account setup), so the retail employee can presume that the consumer meets the age and / or identity requirements associated with the reserved controlled product. This presumptive can be based solely on the fact that the consumer has passed biometric verification on the mobile device and presented the barcode, and does not require any additional steps such as presenting a physical identification card. The supply machine 1302 then supplies the reserved controlled product 1307 based on consumer verification and product reservation and / or purchase.As a result of this method, once a consumer's account is verified (for example, the mobile device is verified to belong to the consumer and the consumer meets the age threshold), the consumer may not be required to use an ID card (e.g., 1354) for subsequent purchases of controlled products, as long as the consumer continues to use the same mobile device as described herein. This method is advantageous from a data privacy perspective because it would not require retailers to view or process consumer data (for example, they would not need to send consumer data to any server or query any database using queries). Instead, a retail employee could simply scan a barcode on the consumer's mobile device, which would automatically authorize the supply of controlled products while complying with age-based and / or identity-based regulations associated with the controlled products.
[0146]
[0179] Referring to Figure 22 in more detail, Method 2200 begins with the consumer account provisioning operation 2202. In some implementations, these operations replace some or all of the consumer verification operation 1406 in Method 1400 described above, which may allow the consumer to be verified even before going to the store. In operation 2202A, the consumer creates an account and undergoes one-time age verification, which may be performed through an external service, such an external service requiring the consumer to upload a copy of their driver's license for remote verification of identity and / or age, as well as / or upload a live image of the consumer's face (sometimes called a live selfie). Alternatively, one or more identity and / or age verification steps may be performed directly in the store. For example, in some implementations, the consumer may be required to show a physical ID 1354 to a retail employee, who verifies and confirms the ID as described above with respect to operations 1406 and 1406A. The retail employee then scans a barcode generated by an application running on the consumer's mobile device 1307 (for example, using a scanning device 1306). The supply machine 1302 then sends a notification to the server system 1308 that the consumer's account (corresponding to the scanned barcode) has been age-verified and / or identity-verified. In the case of subsequent product supply operations (for example, involving a later visit by the consumer to the store), the consumer's identity and / or age can be verified using only the mobile device 1307 (for example, by logging into the consumer's account and performing biometric verification), rather than requiring the retail employee to again request a physical ID 1354.
[0147]
[0180] In other words, when a consumer enters a store for the first time and attempts to purchase a controlled product, the consumer may be prompted to show their physical ID 1354 to a retail employee for verification operation 1406 (either in an application running on a mobile device 1307 or on the display screen of the dispensing machine 1302). The dispensing machine 1302 and the server system 1308 then link the physical ID 1354 to the mobile device 1307. Thus, when the consumer enters the store again, they will not need to show their physical ID 1354 (operation 2206, described below, will be sufficient to verify the consumer). Optionally, the dispensing machine 1302 or the dispensing application running on the mobile device 1307 may, in either case, randomly request the physical ID 1354 (as part of a random spot check to ensure compliance with identity and / or age-based restrictions). These subsequent physical ID checks may be random or based on a risk factor (e.g., quantity purchased). For example, if a consumer purchases more managed products than the threshold per hour (e.g., more than two vaping pods per week), the consumer may be prompted to present a physical ID 1354 to ensure that the consumer, mobile device 1307, and consumer account remain linked (behavior 1406). A positive outcome of such a check (e.g., physical ID 1354 is confirmed to belong to the consumer linked to the account and mobile device 1307) may increase confidence in that consumer for subsequent purchases of managed products, thereby lowering the risk score associated with the consumer, and thus making physical ID checks less frequent.
[0148]
[0181] As part of consumer account provisioning, consumers may be required to secure their accounts using biometric features on their mobile device 1307 (e.g., facial ID, touch ID, etc.) (2202B). For example, an application may prompt a user to use built-in biometric features to access the application for subsequent purchases of managed products. Thus, a consumer account (associated with verified identity and / or age) is linked to the consumer, the consumer is linked to the mobile device 1307, and the consumer account is accessed on the mobile device 1307. In other words, as a result of operation 2202B, the consumer is linked to the mobile device 1307, the consumer accesses their account on the mobile device 1307, and as a result of operation 2202A, the consumer's identity and / or age is verified through the consumer's link to the account. Thus, the consumer, the mobile device 1307, and the verified account are all linked as a result of operation 2202.
[0149]
[0182] Once a consumer account is provisioned in operation 2202 (thus linking the consumer with the consumer account and mobile device 1307), method 2200 proceeds to the selection (2204) of one or more controlled products 1304. Similar to provisioning operation 2202, the selection operation 2204 may be performed before the consumer arrives at the store (e.g., at home or some other remote location), thereby saving time and adding convenience for the consumer without compromising age-based or identity-based compliance measures related to the sale of controlled products from the retailer's or manufacturer's perspective. In some implementations, operation 2204 may replace some or all of the product identification operation 1402 in method 1400 described above, which may allow the consumer to identify, reserve, and / or pay for one or more controlled products 1304 even before going to the store.
[0150]
[0183] In operation 2204A, the consumer may use a mobile application (on mobile device 1307) to find a desired store (for example, one near the customer or one where the customer will be at a later date or time), and the mobile application retrieves from the server system 1308 a list of products that are normally stocked (or currently stocked) in the managed supply machine 1302 at that store. Optionally, the server system 1308 may also include price information and / or current availability of the managed products 1304 (this, for example, describing which managed products are in stock). In operation 2204B, the consumer selects one or more managed products from the list retrieved from the server system 1308 on the mobile application, and the mobile application reserves the selected products. Optionally, the mobile application may enable payment for the purchase of the selected products (2204C), thereby enabling the consumer to both reserve the desired managed products and pay for them before going to the store.
[0151]
[0184] Once a consumer account is provisioned in operation 2202 (thus linking the consumer to the consumer account and mobile device 1307) and (one or more) managed products 1304 are reserved via the mobile application, method 2200 proceeds to in-store verification operation 2206. When the consumer arrives at the store, the consumer launches the mobile application on the consumer's mobile device 1307. Optionally, the mobile device 1307 uses location services (e.g., GPS or Bluetooth) to determine when the consumer is located in the store (or within a geofence around the store), causing the mobile application to automatically launch and proceed to the appropriate screen. In some implementations, this screen provides the consumer with an option to indicate that the consumer is ready to pick up the reserved product 1304. At this point, the mobile application performs a biometric verification operation (e.g., either facial ID or touch ID) to unlock the barcode (2206A). The in-store biometric operation 2206 ensures that the person accessing the mobile application is the same person who provisioned the consumer account in operation 2202 (and therefore satisfies the identity and / or age requirements associated with the managed product 1304).
[0152]
[0185] As a result of consumer verification (biometric behavior 2206A), the mobile device provides a verification code on its display (2206B). The verification code may be a barcode, such as a two-dimensional matrix barcode, such as a quick response (QR) code. Any other barcode, or a visual representation of a code (e.g., a sequence of numbers, letters, and / or symbols), may be displayed on the mobile device 1307. When the consumer presents the verification code to a retail employee (by showing the display of the mobile device 1307), the retail employee knows that the biometric verification (2206A) has passed and that the person who presented the verification code is linked to the mobile device 1307, which is linked to a consumer account associated with verified identity and / or age that satisfies the restrictions associated with (one or more) controlled products 1304. In other words, the retail employee can be confident that the holder of the mobile device 1307 is a person whose identity and / or age has been verified by biometric verification, so the retail employee does not need to ask the consumer for a physical ID 1354.
[0153]
[0186] The clerk then scans the verification code displayed on the mobile device 1307 (for example, using the scanning device 1306), and the supply machine 1302 verifies the code against the server system 1308 (for example, confirming that the verification code is still valid and has not expired, and / or that the reserved product 1304 has not yet been supplied). If this verification operation is successful, the supply machine 1302 supplies the reserved (pre-ordered) product 1304. This scanning operation may cover both payment and ID authentication, and therefore, when the supply machine 1302 supplies the reserved product 1304, the retail clerk may hand the product to the consumer, and the consumer may leave the store. Alternatively, if the consumer has not paid for the reserved product remotely (2204C), the consumer may pay in person at the store before leaving with the supplied product 1304.
[0154]
[0187] Figure 23 is a flowchart of a remote verification method 2300 on a mobile device, including remote consumer account provisioning and in-store product selection, in several implementation forms. Method 2300 may be controlled by instructions stored in the memory or non-temporary computer-readable storage medium of the mobile device (e.g., mobile device 1307) and executed by one or more processors of the mobile device. The computer-readable storage medium may include magnetic or optical disk storage devices, solid-state storage devices such as flash memory, or one or more other non-volatile memory devices. Instructions stored in the computer-readable storage medium may include one or more of source code, assembly language code, object code, or other instruction forms interpreted by one or more processors. Some operations in Method 2300 may be combined, and / or the order of some operations may be changed. Optional operations are communicated by dashed lines.
[0155]
[0188] In Method 2300, the consumer may use their phone (e.g., mobile device 1307) to perform some of the actions described above in Method 1400 (Figure 14) before going to the location where the supply machine 1302 is located (before going to the store), thereby saving time and adding convenience for the consumer without compromising age-based or identity-based compliance measures related to the sale of managed products from the perspective of the retailer or manufacturer. In Method 2200, the consumer does both provision an account and select (reserve) managed products before entering the store, whereas in Method 2300, the consumer provisions an account before entering the store and then makes product selections in the store. In other words, if the consumer has not placed an order in advance, the consumer can still go to the store and use the mobile application for identification, however, after the retail employee scans the verification code displayed by the application on the mobile device 1307, the consumer tells the retail employee which products the consumer wants, or otherwise selects products in the store as described above with respect to action 1402. Consumers can then pay for the selected products at the store (or optionally using a mobile application).
[0156]
[0189] Method 2300 begins with a consumer account provisioning operation 2202, which includes an initial verification of the consumer's identity and / or age (2202A) and an initial configuration of biometric verification to secure the verified account for the consumer (2202B), as described above in Method 2200. In some implementations, these operations replace some or all of the consumer verification operation 1406 in Method 1400 described above, which may allow consumers to be verified even before they go to the store. As described above, operation 2202 may be performed remotely (before the consumer goes to the store), thereby saving time and adding convenience for consumers without compromising age-based or identity-based compliance measures related to the sale of controlled products from the retailer's or manufacturer's perspective.
[0157]
[0190] Method 2300 follows an in-store verification operation 2206, which includes performing biometric verification (2206A) and providing a verification code for display on a mobile device 1307 (2206B), as described above in Method 2200. Thus, when a consumer orders a controlled product from a supply machine 1302, a retail employee may infer that the consumer meets the identity-based and / or age-based requirements associated with the controlled product by scanning the verification code on the consumer's mobile device.
[0158]
[0191] Method 2300 follows the product selection operation 2310. In some implementations, the consumer obtains a list of managed products 1304 available for supply in the store (2310A) by looking at a display screen 1314 or a placard 1352, as described above with respect to operation 1402, or otherwise can view the managed products 1304. Alternatively, the list of managed products 1304 available for supply may be communicated to a mobile app by the supply machine 1302 via a short-range communication protocol (e.g., Bluetooth) while the consumer is in the store.
[0159]
[0192] Consumers may reserve desired controlled products by showing them to a retail clerk (e.g., by pointing to them on a display screen 1314 or placard 1352, or by selecting them otherwise) (2310B). Alternatively, a mobile application may automatically select one or more controlled products. For example, a consumer may have preferences already stored in the mobile application (e.g., configured by the consumer and / or based on purchase history). When the verification code is scanned, the product identifiers (one or more) selected by the consumer may be encoded (by the mobile application) in the verification code in addition to the user information, so that the consumer does not need to tell the retail clerk which (one or more) controlled products they wish to purchase. These options may be configurable so that, instead of automatic selection based on preferences, the mobile application and / or dispensing machine 1302 can suggest preferred products for the consumer to confirm. For example, the consumer may agree to the suggested products being supplied, or the consumer may select different products for supply. In such a scenario, the selection may be used to update the consumer's preferences (which are stored in the mobile application and / or in the server system 1308 along with the consumer's account).
[0160]
[0193] Alternatively, the server system 1308 may automatically select one or more managed products. For example, instead of the mobile application encoding product identifiers in the verification code, consumer preferences (e.g., configured by the consumer and / or based on purchase history) may be associated with the consumer's account and stored in the server system 1308. When the supply machine 1302 is verifying the consumer (operation 1406), the supply machine 1302 can also download the consumer's preference selection from the server system 1308 and automatically select (one or more) preferred managed products for supply, thus eliminating the need to tell the retailer which (one or more) managed products the consumer wishes to purchase. These options may be configured so that, instead of automatic selection based on preferences, preferred products may be suggested by the mobile application and / or the supply machine 1302 for the consumer to confirm. For example, the consumer may agree to the suggested products being supplied, or the consumer may select different products for supply. In such a scenario, the selection may be used to update the consumer's preferences (which are stored in the mobile application and / or in the server system 1308 along with the consumer's account).
[0161]
[0194] The supply machine 1302 then supplies (one or more) selected controlled products 1304. The user may pay in the store at the same time as (immediately before, during, or immediately after) the supply operation as described above (2310C). The user may pay directly at the point of sale (for example, using cash or credit card) (for example, using the retailer machine 1312). Alternatively, a mobile application may enable payment as described above (for example, with respect to operation 2204C). In some implementations, the consumer may select an option on the mobile application to pay for (one or more) selected products before the retail employee scans the verification code. Therefore, when a retail employee (or supply machine 1302) scans the verification code, the retail machine 1312 (or supply machine 1302) may upload the product selection to the server system 1308, which ensures that the consumer has sufficient funds and, if so, authorizes the supply (for example, by sending a supply authorization command to supply machine 1302) and charges the payment account associated with the consumer's account. In such a scenario, direct payment at the store is not required, thereby further increasing convenience without compromising age-based or identity-based compliance measures regarding the sale of controlled products from the perspective of the retailer or manufacturer.
[0162]
[0195] Figure 24 is a flowchart of a remote verification method 2400 in a managed supply system 1300, including remote consumer account provisioning and remote product selection (as described above with respect to method 2200), in several implementation forms. Method 2400 may be controlled by instructions stored in the memory or non-temporary computer-readable storage medium of the server system (e.g., server system 1308), mobile device (e.g., mobile device 1307), and supply machine (e.g., supply machine 1302), and executed by one or more processors of the aforementioned systems, devices, and machines. The computer-readable storage medium may include magnetic or optical disk storage devices, solid-state storage devices such as flash memory, or other non-volatile memory devices. Instructions stored in the computer-readable storage medium may include one or more of source code, assembly language code, object code, or other instruction forms interpreted by one or more processors. Some operations in Method 2400 may be combined, and / or the order of some operations may be changed. Optional operations are communicated by dashed lines.
[0163]
[0196] In method 2400, the managed supply system includes a supply facility 1302 which includes input peripherals (e.g., scanner 1318 or 1306), a plurality of managed products (e.g., identity-restricted or age-restricted managed products 1304), and a supply mechanism (e.g., 2106), and a server system 1308 which is communicably coupled to the supply facility 1302 and the user's mobile device 1307 via a communication network 1310. The mobile device sends verification data (e.g., as described above with respect to operation 2202) to the server system (2402), and the server system receives image data from the mobile device that corresponds to the user's identification document (e.g., 1354) or face (e.g., live selfie). The server system verifies the user's identity or age based on the image data received from the mobile device (2404). In some implementations, the server system stores user verification data based on verifying the user's identity or age (2406) and sends subsequent approval data to the mobile device for subsequent supply approval actions based in part on the verification data (for example, approving subsequent supply actions for a future store visit, as described above with respect to action 2206).
[0164]
[0197] The mobile device sends a request for a list of available controlled products for purchase at a desired store (for example, stocked in a supply machine at the desired store) (2408). The server system receives a request from the mobile device to retrieve a list of multiple controlled products contained in the supply equipment. In response to the request to retrieve a list of multiple controlled products, the server system sends a list of multiple controlled products to the mobile device (2410), and the mobile device receives the item list (2412).
[0165]
[0198] The mobile device receives a user request to reserve one or more of the available managed products (for example, as described above with respect to operation 2204) (2414) and sends the request to the server system. The server system receives a request from the mobile device to reserve a first managed product from among several managed products included in the supply equipment (2416). Based on the user's identity and / or age verification (operation 2404) and the request to reserve the product (operation 2416), the server system sends supply authorization data to the mobile device (for example, corresponding to a verification code as described above with respect to operation 2206B) (2418). The supply authorization data indicates that the user has been verified (meeting the identity and / or age-based requirements associated with the reserved managed product) and indicates which (one or more) managed products were requested.
[0166]
[0199] In other words, in accordance with (i) verifying the user's identity or age (operation 2404) and (ii) a request to reserve a first managed product (operation 2416) (before the mobile device is present at the supply facility location (e.g., store)), the server system transmits supply authorization data to the mobile device (2418) including (i) an instruction that the user's identity or age has been verified and (ii) a product indicator corresponding to the first managed product. Optionally, the server system processes the payment initiated by the user on the mobile device for the first managed product.
[0167]
[0200] The mobile device receives supply authorization data (2420), and when the user is at the location and ready to request the supply of the reserved product, the mobile device displays a supply code (e.g., the verification code described above with respect to operation 2206) for scanning by an input peripheral of the supply equipment (e.g., scanner 1306 or 1318). The supply equipment obtains the supply code provided by the mobile device (e.g., the supply code is a visual code displayed on the mobile device, such as a barcode) via the input peripheral (e.g., scanner 1306 or 1318) (2422). The supply code corresponds to the supply authorization data sent from the server system to the mobile device. In accordance with obtaining the supply code, one or more processors of the supply machine cause the supply mechanism to supply the first controlled product (reserved controlled product) (2424).
[0168]
[0201] In some implementations, the operations described above with respect to method 2200 may be performed in addition to those described above with respect to method 2400.
[0169]
[0202] Figure 25 is a flowchart of a remote verification method in a managed supply system 1300, including remote consumer account provisioning and local product selection (as described above with respect to Method 2300), in several implementation forms. Method 2500 may be controlled by instructions stored in the respective memories or non-temporary computer-readable storage media of a server system (e.g., server system 1308), a mobile device (e.g., mobile device 1307), and a supply machine (e.g., supply machine 1302), and executed by one or more processors of the aforementioned systems, devices, and machines. The computer-readable storage media may include magnetic or optical disk storage devices, solid-state storage devices such as flash memory, or other non-volatile memory devices. Instructions stored in the computer-readable storage media may include one or more of source code, assembly language code, object code, or other instruction forms interpreted by one or more processors. Some operations in Method 2500 may be combined, and / or the order of some operations may be changed. Optional operations are communicated by dashed lines.
[0170]
[0203] In method 2500, the managed supply system includes a supply facility 1302 which includes input peripherals (e.g., scanners 1318 or 1306), a plurality of managed products (e.g., identity-restricted or age-restricted managed products 1304), and a supply mechanism (e.g., 2106), and a server system 1308 which is communicably coupled to the supply facility 1302 and the user's mobile device 1307 via a communication network 1310. The mobile device sends verification data (e.g., as described above with respect to operation 2202) to the server system (2502), and the server system receives image data from the mobile device that corresponds to the user's identification document (e.g., 1354) or face (e.g., live selfie). The server system verifies the user's identity or age based on the image data received from the mobile device (2504). In some implementations, the server system stores user verification data based on verifying the user's identity or age (2506) and sends subsequent approval data to the mobile device for subsequent supply approval actions based in part on the verification data (for example, approving subsequent supply actions for a future store visit, as described above with respect to action 2206).
[0171]
[0204] In accordance with verifying the user's identity or age (and before the mobile device is present at the supply facility's location (e.g., store)), the server system transmits consumer verification data to the mobile device (2508) that includes an instruction that the user's identity or age has been verified (meeting the identity-based and / or age-based restrictions associated with the managed product 1304) (based on operation 2504). The mobile device 1307 receives the consumer verification data (2510) and displays a consumer verification code (as described above with respect to operation 2206B).
[0172]
[0205] The supply equipment obtains a consumer verification code provided by the mobile device via an input peripheral (for example, by scanning a visual code displayed on the mobile device, such as a barcode) (2512), the consumer verification code corresponding to consumer verification data sent from the server system to the mobile device. The supply equipment obtains the user selection of a first managed product from among several managed products (for example, as described above with respect to operation 2310) (2514). In accordance with the consumer verification code (which verifies that the user meets the identity-based or age-based requirements associated with the selected managed product) and the user selection (of the first managed product), one or more processors of the supply equipment cause the supply mechanism to supply the first managed product (the selected managed product) (2516).
[0173]
[0206] In some implementations, the operations described above with respect to method 2300 may be performed in addition to those described above with respect to method 2500.
[0174] Remote store clerk support supply
[0207] Some products, such as tobacco and alcohol (or any of the controlled products described above), are subject to restrictions that require the purchaser to be of a certain age, for example, 21 years or older. For decades, unmanned retail of restricted products (such as tobacco vending machines) has been prohibited by local and state jurisdictions due to the ease of access for underage purchasers. Those machines operated simply as a payment and good-faith system (honor system). There was no systematic control in place to limit the sale of products to consumers who did not meet the minimum age requirement.
[0175]
[0208] Technology has advanced significantly over the past 20 years, and today's automated vending machines can be even more accurate and secure than retail stores, as the human judgment factor can be eliminated. Furthermore, automated systems can incorporate multiple authentication factors, including facial recognition, artificial intelligence, third-party database lookups, phone number verification, and social security number verification. Various inputs or signals can be analyzed in milliseconds to determine whether a transaction should be approved or rejected.
[0176]
[0209] However, depending on the nature of the law, in many cases, unmanned vending machines will be illegal, even if they have controls in place to verify age before supply. This disclosure provides a solution for age-restricted automated retail.
[0177]
[0210] Referring to Figure 26, the managed supply environment 2600 includes a managed supply machine (also called a supply facility) (for example, having one or more features corresponding to machine 1302 shown in Figure 13) that can be operated by an end user; a mobile device (such as a smartphone) having an application or web browser (for example, having one or more features corresponding to mobile device 1307 shown in Figure 13); a module in the supply machine (for example, having one or more features corresponding to circuit 1316 shown in Figure 13) that communicates between the controller of the supply machine and the mobile device (such communication may be local communication such as Bluetooth or via a long-distance network such as the Internet); a platform management center (for example, having one or more features corresponding to server system 1308 shown in Figure 13); and a remote computing device (computer, tablet, or smartphone) having an application or web browser (for example, having one or more features corresponding to mobile device 1307 or retail machine 1312 (excluding those located remotely from the supply machine) shown in Figure 13), each of which is connected to one or more communication networks (for example, having one or more features corresponding to one or more networks 1310 shown in Figure 13).
[0178]
[0211] When a consumer is interested in making an age-restricted purchase, they approach a managed supply machine and initiate interaction with their mobile device. There are three essential steps to completing the transaction: product selection (Figure 27A), payment (Figure 27B), and initial consumer verification (Figure 27C), which can be completed in any order.
[0179]
[0212] Products can be selected physically on the machine through a machine interface, or products can be selected through a smartphone interface.
[0180]
[0213] Payments (such as cash or card payments) may be made physically on a machine, or cashless payments may be made through the consumer's mobile phone.
[0181]
[0214] Initial consumer verification may be performed on the consumer's mobile device and may include taking a photo of the front of the consumer's driver's license, a photo of the back of the consumer's driver's license, taking a selfie, or providing one or more personal information, including but not limited to name, address, city, state, zip code, telephone number, social security number (or part of social security number), driver's license number, and credit bureau information (such as mortgage amount, lender's name, car payment, or parts of account or card number). Initial verification may include a more stringent initial setup, after which subsequent transactions may be able to access the consumer's profile through biometric verification (such as facial ID or touch ID).
[0182]
[0215] Once all three prerequisites are met (or, in some implementations, once initial consumer verification is met), the remote clerk or agent can further verify the user (provide subsequent consumer verification). This verification may include a live video feed from the consumer's mobile device or from the supply machine, and optionally audio. The remote clerk can then view the consumer, along with other information to help the clerk determine whether this request is from a valid and legally aged consumer for purchase. The clerk can approve or reject the transaction. If the remote clerk approves the transaction, the message is relayed to the machine and the product is supplied. If the clerk does not approve, the user cannot complete the purchase and the product is not supplied. The user is not charged for the product when it is not supplied. Alternative implementations of these subsequent consumer verification operations are shown in Figures 27D and 27E.
[0183]
[0216] In some implementations, this system is neither self-service nor fully automated. Rather, two parties are always required to complete a transaction. A human employee located remotely (for example, not in the same store or geographical location as the dispensing machine) must approve the transaction in real time. In some implementations, this approval cannot be queued or remembered for future dispensing. This approval is only valid for the short duration that the consumer is near the machine.
[0184]
[0217] To ensure that the consumer is in the vicinity of the machine being verified, the system may rely on short-range communication (such as Bluetooth). If the consumer is physically present, the supply machine can receive secure, encrypted authentication from the consumer's mobile device. If the consumer is not physically present, the supply machine cannot receive secure, encrypted authorization from the consumer's mobile device. In an alternative embodiment, short-range communication is not used, and GPS coordinates from the consumer's mobile device, which can be matched to a known location of the supply machine, are shared to ensure that the consumer is physically present near the supply machine.
[0185]
[0218] In the optional selection embodiment, when all products in the supply machine are age-restricted, the consumer does not need to make a selection first. The consumer can first prove their identity, then the remote clerk can approve the consumer (verify or confirm the consumer's age), and the consumer can independently complete the selection and payment for that session only.
[0186]
[0219] Figures 28A–28Q show exemplary user interfaces between a consumer's mobile device (Figures 28A–28J, 28L, 28N, and 28P), also referred to herein as the first computing device, and a store clerk's computing device (Figures 28K, 28M, 28O, and 28Q), also referred to herein as the second computing device. The consumer begins an initial verification process (Figures 28A–28B), which includes selecting an available machine and uploading images of the consumer's driver's license and a live selfie (Figures 28C–28F). If the initial verification process is successful, the consumer begins a subsequent verification process (Figures 28G–28I), which includes verification by a live agent. While the consumer is waiting for an agent (Figure 28J), the agent selects the consumer (Figure 28K). While the consumer continues to wait (Figure 28L), the consumer's mobile device sends live video and / or audio signals to the agent's computing device, and the agent verifies that the consumer in the live video is the same consumer as the consumer in the uploaded image (Figure 28M). The agent approves the consumer (Figure 28O), and the consumer is notified that they have been approved (Figure 28N). The session between the consumer's mobile device and the agent's computing device ends (Figures 28P-28Q).
[0187]
[0220] In some implementations, the managed supply system comprises a supply facility containing multiple managed products and a server system (also referred to herein as a platform management center), the server system being communicably coupled via a communication network to the supply facility (for example, via a module or processing circuit 1316), a first computing device associated with a consumer (the consumer's mobile device), and a second computing device associated with a retail agent (the agent's computing device).
[0188]
[0221] The server system receives image data corresponding to an identification document (e.g., Figure 28D) and / or the consumer's face (e.g., Figure 28F) from a first computing device, verifies the consumer's identity or age based on the image data received from the first computing device (Figure 27C), and after verifying the consumer's identity or age, retrieves a live video feed of the consumer from the first computing device or a supply facility (Figure 28L), transmits (i) the consumer's live video feed and (ii) the image data corresponding to the consumer's identification document and / or face to a second computing device (Figure 28M), receives a verification message from the second computing device indicating that the consumer in the live video feed corresponds to the consumer's identification document and / or face (Figure 28O), and transmits consumer verification data (approval request, Figure 27D or Figure 27E) containing an indication that the consumer's identity or age has been verified to the first computing device (Figure 28P).
[0189]
[0222] The supply equipment further includes one or more processors and a memory for storing one or more programs to be executed by the one or more processors, the one or more programs including instructions for obtaining a consumer verification code (authorization to supply, Figure 27D or Figure 27E) from a first computing device, the consumer verification code corresponding to consumer verification data sent from a server system to the first computing device (sent only when an authorization request is received from the server system), obtaining a consumer selection of a first controlled product among a plurality of controlled products (Figure 27A), and causing the supply mechanism of the supply equipment to supply the first controlled product (supply, Figure 27E or Figure 27E) in accordance with the consumer verification code and the consumer selection.
[0190] NFC Verification Bypass
[0223] The techniques described above for restricting the purchase and / or use of managed products share a common theme: each requires a reliable method for verifying the user's identity and / or age in order to meet the identity-based and / or age-based restrictions associated with the managed product.
[0191]
[0224] One technique that uses technology to supplement the identity and / or age verification process involves the use of a mobile ID (e.g., a digital driver's license) stored in a digital wallet application on the user's mobile device. For example, if a user has an iPhone®, the user may store a digital version of their driver's license in the iPhone's wallet application. Other mobile devices and mobile operating systems may include similar implementations of digital wallet applications that can be configured to store mobile ID cards (e.g., Google® Wallet, Samsung® Pay, etc.).
[0192]
[0225] A digital wallet application that stores a user's mobile ID typically communicates with the mobile ID reader (sometimes referred to herein as a verification device) by using a short-range wireless communication link (e.g., NFC, Bluetooth, Wi-Fi Aware) between the user's mobile device and the mobile ID reader. The mobile ID reader uses specialized hardware (e.g., an NFC reader) to support the short-range communication link. Furthermore, the mobile ID reader may be configured to communicate with an issuing authority (e.g., a state motors department authorized to issue a driver's license) to verify the mobile ID.
[0193]
[0226] The use of mobile IDs and the operation of mobile ID readers generally conform to standards such as ISO 18013-5, which specifies interface specifications for the implementation of digital driver's licenses, relating to (i) the interface between the mobile ID and the mobile ID reader, and (ii) the interface between the mobile ID reader and the issuing authority infrastructure. However, such standards generally require that the mobile ID reader include special hardware, such as an NFC reader, to support the short-range communication link and verification algorithm specified by the standard.
[0194]
[0227] In detail, standards defining interface specifications for the implementation of a mobile identity platform may require a short-range communication link between a mobile device and a mobile identity reader to support the standardized exchange of data. Examples of such data include certificates from a trust list (e.g., a signer certificate using private and public key data), device involvement parameters (e.g., required for the mobile device and mobile identity reader to connect), portrait data (e.g., a photograph of the mobile identity holder), passive authentication data (e.g., a signer certificate), and active authentication data (e.g., a cryptographic certificate stating that the data was not cloned from a different device).
[0195]
[0228] For example, when a mobile device and a mobile identity reader are disconnected, the mobile identity verification standard may require that the devices securely connect using standardized key exchange and encryption of data transport. The mobile identity reader can then use a signer certificate to verify that the data received from the mobile device is authentic and unaltered. The process proves to the mobile identity reader that the data has not been cloned from another, different mobile device. When the mobile device and mobile identity reader are connected, the mobile identity verification standard may require that the mobile device and mobile identity reader use security certificates, TLS encryption, and / or Open ID Connect (OIDC) infrastructure to secure the mobile identity reader connection to the issuing authority.
[0196]
[0229] To support the standardized data exchange between mobile devices and mobile ID readers, mobile ID readers may need to include specialized hardware (e.g., NFC readers). However, with the introduction of new standards (such as those for mobile ID readers), it often takes several years for retail hardware to catch up in supporting the features required by such standards. For example, a large grocery store chain may not have the budget or willingness to immediately update every cash register across all its stores to include the NFC readers or other hardware necessary to accept mobile IDs for the purchase of managed products. The same hardware-related problems occur in non-retail cases. For example, a police station or security company may not have the budget or willingness to immediately update the equipment of every officer or security guard on the scene to include the NFC readers or other hardware necessary to verify mobile IDs as part of interactions with the public (e.g., during road closures or other interactions involving ID checks).
[0197]
[0230] In some scenarios, standards defining interface specifications for the implementation of a mobile ID platform may allow less specialized or more accessible hardware (e.g., a QR code scanner or Bluetooth beacon) to initiate the mobile ID verification process without requiring the user to tap their phone on an NFC reader. However, once the mobile ID verification process is initiated, such a platform will still require the aforementioned exchange of data between the mobile device and the mobile ID reader to comply with specific standards. As described above, this aforementioned exchange of data between the mobile device and the mobile ID reader would require the use of specialized hardware and security certificates on both sides to enable both the mobile device and the mobile ID reader to connect securely via a communication link, and most retail and non-retail operations will likely not be equipped with this hardware for the next few years.
[0198]
[0231] Accordingly, this disclosure describes a system and method for supporting mobile identity verification using a digital identity stored in a mobile device's digital wallet application without requiring a secure connection or the aforementioned standardized exchange of data between the mobile device and the mobile identity reader. Thus, such a system and method does not require special hardware (e.g., an NFC reader or short-range communication hardware) to enable mobile identity verification, and enables both retail and non-retail operations to support mobile identity verification with a lower barrier to entry.
[0199]
[0232] Figure 29 is a system diagram of the Age / Identity Verification Platform 2900 in several implementation forms. Platform 2900 (alternatively referred to as Environment 2900) enables parties to use a mobile ID reader (verification device 2904 equipped with scan device 2906) to retrieve mobile ID data (e.g., age and / or identity data) from a digital wallet application on the user's mobile device 2902, associate that mobile ID data with the user, and authenticate the source of the mobile ID data using a remote server system 2908 and (one or more) long-range communication networks 2910. Instead, the only data exchanged between the two devices is the scanning of a barcode displayed on the screen of the mobile device 2902. Therefore, the mobile ID reader does not require a short-range communication system (e.g., NFC or Bluetooth) to verify the age / identity information stored in the user's mobile device's digital wallet application.
[0200]
[0233] Rather than supporting standardized data exchange between the user's mobile device 2902 and the retailer's verification device 2904 over a short-range communication link (as specified, for example, in ISO 18013-5), platform 2900 enables two long-range communication links, including (i) a first link between the mobile device 2902 and the server system 2908 over one or more communication networks 2910, and (ii) a second link between the verification device 2904 and the server system 2908 over one or more communication networks 2910. The user performs biometric authentication on the mobile device to obtain digital ID data (e.g., age and / or identity data) and transmit that digital ID data to the server system 2908. The server system 2908 performs additional verification operations (described in more detail below with respect to operation 3310 in Figure 33), generates a barcode, and transmits that barcode to the mobile device 2902. The verification device 2904 uses a barcode reader (e.g., scanning device 2906) to acquire a barcode from the screen of the mobile device 2902 and transmits the scanned barcode to the server system 2908. The server system 2908 verifies the scanned barcode (as described in more detail below with reference to Figure 33, operation 3318) and sends a message to the verification device 2904 indicating that the barcode scanned from the mobile device 2902 corresponds to digital ID data stored in the mobile device 2902 and that the digital ID data corresponds to a person who meets the requirements for purchasing and / or using the managed product (or, in some implementations, a person who meets an age threshold or is associated with a specific identity unrelated to the managed product). The server system 2908 may be associated with private companies when none of the operations performed by the server system 2908 require access to the issuing authority. In other words, server system 2908 can perform the operations described below with reference to Figures 32-34 without being an issuing authority (as defined in ISO 18013-5).Such operations involve receiving digital ID data, comparing the digital ID data with identity and / or age-based restrictions or regulations, generating a barcode based on such comparison, and cross-checking the barcode received from verification device 2904 with the barcode sent to mobile device 2902. Such operations do not require the services of an issuing authority (as defined in ISO 18013-5). As a result, platform 2900 enables age and / or identity verification using digital ID data while bypassing the need for (i) NFC communication between the mobile device and the verification device and (ii) communication with an issuing authority, in environments that may traditionally require these communications.
[0201]
[0234] A retail employee (or any other individual interested in verifying the user's age or identity) can trust and assume that the user of the mobile device meets the age or identity requirements, based on (i) a message verifying that the scanned barcode corresponds to digital ID data that meets the age or identity requirements, and (ii) knowledge that the user of the mobile device 2902 authenticated themselves biometrically to obtain the digital ID data corresponding to the barcode. To increase the reliability of the assumption that the user meets the age and / or identity requirements, other measures may be taken at the option of visually checking the user's photograph displayed on the digital ID in the mobile device 2902's digital wallet application, which would further verify that the digital ID corresponds to the user of the mobile device 2902.
[0202]
[0235] Referring to Figure 29, the mobile device 2902 may be any personal electronic device associated with an individual. The mobile device 2902 may include, but is not limited to, a smartphone, a tablet or laptop computer, a personal digital assistant (PDA), a smart card, a voice assistance device (such as Alexa), or other known or undiscovered technologies (e.g., combinations of hardware and software) having a similar structure and / or capabilities to the mobile devices described herein. The mobile device 2902 is equipped with long-range communication capabilities (e.g., modems, transceivers, etc.) for communicating through (one or more) networks 2910. The communication technologies described herein may be replaced by alternative communication technologies and are therefore not limited to any particular communication technology. For example, Wi-Fi technology may be replaced by another long-range communication technology. In some implementations, the mobile device 2902 may include one or more of the components and / or implement one or more of the features described above with respect to the mobile device 106 (Figures 1 and 4) or the mobile device 1307 (Figure 13).
[0203]
[0236] The verification device 2904 is any computing device located in the vicinity of the mobile device 2902. Examples include a terminal computing device at a checkout counter in a store, a handheld device (such as the mobile device as defined above), or any other computing device capable of long-range communication as defined above. The verification device 2904 includes or is associated with the scanning device 2906 (e.g., physically coupled or communicatively coupled), and the scanning device 2906 may be any type of input device capable of scanning a graphic barcode (e.g., a QR code) or any other type of scannable code, image, or string on the screen of the mobile device 2902. The scanning device 2906 may be a handheld scanner communicatively coupled (paired) to the verification device 2904 using a wired or wireless communication link (e.g., USB, wireless dongle, Ethernet, Wi-Fi, Bluetooth, etc.). Alternatively, the scanning device 2906 may be incorporated into the structure of the verification device 2904 (e.g., an onboard scanner) rather than being implemented as a separate component. In some implementations, instead of the scanning device 2906, the verification device 2904 may use an alternative input device configured to receive data (e.g., a mouse, keyboard, or audio receiver configured for voice input). The verification device 2904 communicates with the server system 2908 through one or more communication networks 2910 using long-range communication techniques as described above. In some implementations, the verification device 2904 may include one or more of the components and / or implement one or more of the features described above with respect to the retail machine 112 (Figure 1) or the retail machine 1312 (Figure 13).
[0204]
[0237] Importantly, platform 2900 does not require any data communication between mobile device 2902 and verification device 2904 (other than a simple scan or similar input of a graphic barcode or other type of code displayed on the screen of mobile device 2902). In detail, verification device 2904 can perform age / identity verification functions (for example, with respect to Figure 33 below) without using any short-range communication technology or protocol to communicate with mobile device 2902. Examples of short-range communication technologies or protocols include Bluetooth (e.g., Bluetooth 4.0, Bluetooth Smart, Bluetooth Low Energy (BLE)), near-field communication (NFC), ultra-wideband (UWB), radio frequency identification (RFID), infrared wireless, inductive wireless, WiFi, or any other wired or wireless technology that may be used to communicate over small distances (e.g., about 100 feet or closer) that are known or not yet discovered. Such technologies and protocols are not required or otherwise used by verification device 2904 to perform the age / identity verification features described herein. Similarly, no long-range communication technology or protocol (as defined above) is required or otherwise used by the verification device 2904 to implement the age / identity verification features described herein.
[0205]
[0238] The server system 2908 includes one or more electronic servers, each electronic server including long-range communication technology configured to communicate with multiple mobile devices 2902 and multiple verification devices 2904 through one or more communication networks 2910. In some implementations, the server system 2908 may include one or more of the components and / or implement one or more of the features described above with respect to the server system 108 (Figures 1 and 5) or the server system 1308 (Figure 13).
[0206]
[0239] The (one or more) communication networks 2910 include wired and / or wireless communication networks that enable ongoing connections or connections accessible on request. Generally, network connections are made via one or more long-distance communication technologies or protocols. Examples include hardwired, telephone network technologies, cellular technologies (e.g., GSM, CDMA, etc.), Wi-Fi technologies, wide area networks (WANs), local area networks (LANs), or any known or yet-to-be-discovered wired or wireless communication technologies over the Internet.
[0207]
[0240] Figure 30 is a block diagram of a mobile device 2902 of the age / identity verification platform 2900 in several implementation configurations. The mobile device 2902 includes one or more processing units (CPUs) 3002, one or more network interfaces 3004, memory 3006, and one or more communication buses 3008 for interconnecting these components.
[0208]
[0241] The mobile device 2902 includes one or more input devices 3010 (e.g., a touchscreen, keyboard, mouse, microphone, etc.) for receiving user input and one or more output devices 3012 (e.g., a display screen, speaker, etc.) for displaying output to the user.
[0209]
[0242] Memory 3006 includes high-speed random-access memory, such as DRAM, SRAM, DDR RAM, or other random-access solid-state memory devices, and optionally includes non-volatile memory, such as one or more magnetic disk storage devices, one or more optical disk storage devices, one or more flash memory devices, or one or more other non-volatile solid-state memory devices. Memory 3006 optionally includes one or more storage devices located remotely from one or more processing units 3002. Memory 3006, or alternatively the non-volatile memory within Memory 3006, includes a non-temporary computer-readable storage medium. In some implementations, Memory 3006, or the non-temporary computer-readable storage medium of Memory 3006, stores the following programs, modules, and data structures, or subsets or supersets thereof: Operating System 3016 includes procedures for handling various basic system services and for performing hardware-dependent tasks. A communication module 3018 for connecting a mobile device 2902 to another device (for example, a server system 2908) via one or more network interfaces 3004 (wired or wireless) and one or more communication networks 2910, such as the Internet, other wide area networks, local area networks, metropolitan area networks, etc. A user interface module 3020 for receiving input from the user via (one or more) input devices 3010 and displaying output to the user via (one or more) output devices 3012. An authentication application 3022 is configured to receive user biometric data and authenticate the user based on the received biometric data; in other words, it is configured to acquire user biometric data (e.g., fingerprint scan, face scan, etc.) and to use one or more input devices 3010 to authenticate the user of a mobile device 2902 by biometric authentication (e.g., fingerprint authentication such as Touch ID, face recognition such as Face ID, etc.) by acquiring user biometric data (e.g., fingerprint authentication such as Touch ID, face recognition such as Face ID, etc.) and comparing the acquired biometric data with biometric data 3022a that was previously stored corresponding to the user (e.g., fingerprint data previously scanned and stored for Touch ID, face data previously scanned and stored for use with Face ID, etc.), • It is configured to store the user's identity and / or age information and to provide the user's identity and / or age information only when the user has been successfully authenticated using the authentication application, in other words, it securely stores digital payment data (e.g., credit card) 3024a and digital identity and / or age data 3024b (e.g., name, date of birth (DOB), gender, ID number, state, issue date, expiration date, real ID status, ID photo, etc., driver's license data) (e.g., digital driver's license conforming to the ISO 18013-5 mobile driver's license standard or a similar digital identification standard), (e.g., A digital wallet application 3024 is configured to provide digital payment data 3024a and digital identity and / or age data 3024b only when an authentication operation using an authentication application 3022 (which acquires biometric data and matches the acquired biometric data with biometric data previously stored on the user of the mobile device 2902) is successful (for example, by displaying the data on the screen of the mobile device 2902 or by providing the data to another application on the mobile device 2902 via an application programming interface (API)). A browser application 3026 configured to enable internet communication (e.g., browsing) over one or more communication networks 2910, including a digital wallet API 3026a configured to access or retrieve user payment data 3024a and identity and / or age data 3024b from a digital wallet application 3024 when user authentication using authentication application 3022 is successful (optionally, the digital wallet API 3026a may be configured to access or retrieve only the identity and / or age data 3024b of the primary user of the mobile device 2902 by accepting only a first set of biometric data (e.g., fingerprint or facial data) corresponding to only one user), and An identity (ID) verification application 3028 configured to provide an alternative standalone application to the browser application 3026, which includes a digital wallet API 3028a configured to retrieve payment data 3024a and identity and / or age data 3024b from the digital wallet application 3024 when an authentication operation using the authentication application 3022 is successful, and to send the data 3024a / 3024b to a remote device (e.g., a server system 2908) via one or more network interfaces 3004.
[0210]
[0243] In some implementations, memory 3006 may contain one or more of the modules and / or applications described above with respect to mobile device 106 (Figures 1 and 4) and / or mobile device 1307 (Figure 13).
[0211]
[0244] Each of the elements identified above may be stored in one or more of the aforementioned memory devices and corresponds to a set of instructions for performing the functions described above. The modules or programs (i.e., sets of instructions) identified above do not need to be implemented as separate software programs, procedures, modules, or data structures; therefore, various subsets of these modules may be combined or, in some cases, rearranged in various implementations. In some implementations, memory 3006 optionally stores a subset of the modules and data structures identified above. Furthermore, memory 3006 optionally stores additional modules and data structures not described above.
[0212]
[0245] Figure 31 is a block diagram of the verification device 2904 of the age / identity verification platform 2900 in several implementation configurations. The verification device 2904 includes one or more processing units (CPUs) 3102, one or more network interfaces 3104, memory 3106, and one or more communication buses 3108 for interconnecting these components.
[0213]
[0246] The verification device 2904 includes, or is otherwise associated with (e.g., communicatively coupled with) one or more input devices 3110 (e.g., a scanning device 2906, buttons, keypads, touchscreens, keyboards, mice, microphones, etc.) for receiving user input and one or more output devices 3112 (e.g., display screens, lights, LED or LCD displays, speakers, etc.) for displaying output to the user.
[0214]
[0247] Memory 3106 includes high-speed random-access memory, such as DRAM, SRAM, DDR RAM, or other random-access solid-state memory devices, and optionally includes non-volatile memory, such as one or more magnetic disk storage devices, one or more optical disk storage devices, one or more flash memory devices, or one or more other non-volatile solid-state memory devices. Memory 3106 optionally includes one or more storage devices located remotely from one or more processing units 3102. Memory 3106, or alternatively the non-volatile memory within Memory 3106, includes a non-temporary computer-readable storage medium. In some implementations, Memory 3106, or the non-temporary computer-readable storage medium of Memory 3106, stores the following programs, modules, and data structures, or subsets or supersets thereof: Operating System 3116 includes procedures for handling various basic system services and for performing hardware-dependent tasks. • A communication module 3118 for connecting the verification device 2904 to other devices (for example, a server system 2908) via one or more network interfaces 3104 (wired or wireless) and one or more communication networks 2910, such as the Internet, other wide area networks, local area networks, metropolitan area networks, etc. A user interface module 3120 configured to display a graphical user interface on (one or more) output devices 3112 and to acquire data (e.g., barcode scans) using (one or more) input devices 3110, and A QR verification module 3122 is configured to use an input device 3110 (for example, a scanning device 2906) to acquire a scanned image of a barcode (or any other scannable element), to send data corresponding to the scanned image of the barcode to a server system 2908 using one or more network interfaces 3104, to receive an identity / age verification message from the server system 2908 using one or more network interfaces 3104, and to display the identity / age verification message on an output device 3112.
[0215]
[0248] In some implementations, memory 3106 may contain one or more of the modules and / or applications described above with respect to retail machine 112 (Figure 1) and / or retail machine 1312 (Figure 13).
[0216]
[0249] Each of the elements identified above may be stored in one or more of the aforementioned memory devices and corresponds to a set of instructions for performing the functions described above. The modules or programs (i.e., sets of instructions) identified above do not need to be implemented as separate software programs, procedures, modules, or data structures; therefore, various subsets of these modules may be combined or, in some cases, rearranged in various implementations. In some implementations, memory 3106 optionally stores a subset of the modules and data structures identified above. Furthermore, memory 3106 optionally stores additional modules and data structures not described above.
[0217]
[0250] Figure 32 is a block diagram of the server system 2908 of the age / identity verification platform 2900 in several implementation configurations. The server system 2908 includes one or more processing units (CPUs) 3202, one or more network interfaces 3204, memory 3206, and one or more communication buses 3208 for interconnecting these components.
[0218]
[0251] The server system 2908 includes one or more input devices 3210 (e.g., buttons, keypads, touchscreens, keyboards, mice, microphones, etc.) for receiving user input, and one or more output devices 3212 (e.g., display screens, lights, LED or LCD displays, speakers, etc.) for displaying output to the user.
[0219]
[0252] Memory 3206 includes high-speed random-access memory, such as DRAM, SRAM, DDR RAM, or other random-access solid-state memory devices, and optionally includes non-volatile memory, such as one or more magnetic disk storage devices, one or more optical disk storage devices, one or more flash memory devices, or one or more other non-volatile solid-state memory devices. Memory 3206 optionally includes one or more storage devices located remotely from one or more processing units 3202. Memory 3206, or alternatively the non-volatile memory within Memory 3206, includes a non-temporary computer-readable storage medium. In some implementations, Memory 3206, or the non-temporary computer-readable storage medium of Memory 3206, stores the following programs, modules, and data structures, or subsets or supersets thereof: Operating System 3216 includes procedures for handling various basic system services and for performing hardware-dependent tasks. • A communication module 3218 for connecting the server system 2908 to other devices (for example, multiple mobile devices 2902 and multiple verification devices 2904) via one or more network interfaces 3204 (wired or wireless) and one or more communication networks 2910, such as the Internet, other wide area networks, local area networks, metropolitan area networks, etc. An age / identity verification module 3220 is configured to receive age / identity data 3024b from a mobile device 2902, compare that age / identity data to one or more age or identity-based restrictions (for example, to determine if the age meets the minimum threshold for using a particular controlled product), and determine whether the age / identity data 3024b meets the age or identity-based restrictions (for example, to determine if the age data meets the minimum threshold required for purchasing tobacco products in a particular jurisdiction). The QR generation module 3222 is configured to generate a QR code (or any other type of code) representing the age / identity verification determination made by module 3220 (for example, verifying the user's age), transmit the QR code to the mobile device 2902 using one or more network interfaces 3204, and store the QR code in QR storage 3222a for cross-checking by the QR verification module 3224, as well as A QR verification module 3224 is configured to receive data corresponding to a QR code (for example, based on a scanned image of the QR code) from a verification device 2904, cross-check the received data with a QR code stored in QR storage 3222a (for example, to verify that the QR code corresponds to a user of a specific mobile device 2902), and send a QR verification decision to the verification device (for example, determining that the scanned QR code matches a QR code received from mobile device 2902).
[0220]
[0253] In some implementations, memory 3206 may contain one or more of the modules and / or applications described above with respect to server system 108 (Figures 1 and 5) and / or server system 1308 (Figure 13).
[0221]
[0254] Each of the elements identified above may be stored in one or more of the aforementioned memory devices and corresponds to a set of instructions for performing the functions described above. The modules or programs (i.e., sets of instructions) identified above do not need to be implemented as separate software programs, procedures, modules, or data structures; therefore, various subsets of these modules may be combined or, in some cases, rearranged in various implementations. In some implementations, memory 3206 optionally stores a subset of the modules and data structures identified above. Furthermore, memory 3206 optionally stores additional modules and data structures not described above.
[0222]
[0255] Figure 33 is a flowchart of an age / identity verification method 3300 using an age / identity verification platform 2900, in several implementation forms. The method 3300 may be controlled by instructions stored in the computer memory or non-temporary computer-readable storage medium (memory 3006) of the mobile device 2902, the computer memory or non-temporary computer-readable storage medium (memory 3106) of the verification device 2904, and / or the computer memory or non-temporary computer-readable storage medium (memory 3206) of the server system 2908. The instructions may be contained in one or more programs stored in one or more non-temporary computer-readable storage mediums. When executed by one or more processors (3002, 3102, and / or 3202), the instructions cause the mobile device 2902, the verification device 2904, and / or the server system 2908 to perform their respective operations of the method 3300. (One or more) non-temporary computer-readable storage media may include one or more solid-state storage devices (e.g., flash memory), magnetic or optical disk storage devices, or other non-volatile memory devices. Instructions may include source code, assembly language code, object code, or any other instruction form that can be interpreted by one or more processors. Some actions in a process may be combined, and the order of some actions may be changed.
[0223]
[0256] Method 3300 begins when a user wishes to purchase a regulated product (e.g., an age-restricted item). The user proceeds to a web page (3302) using the browser application 3026 on the mobile device 2902. The user can proceed to the web page by obtaining user input indicating the user's physical location, such as by scanning a barcode (e.g., a QR code or any other type of scannable code configured to cause the browser application to navigate to a specific URL) while at the physical location of the regulated product (e.g., while in the checkout line, when in the store). Alternatively, the user can manually proceed to the web page in the browser application 3026, for example, by selecting a store (optionally using GPS verification via the GPS sensor in the mobile device 2902 to verify that the user is located at the selected store). The user can select the store via GPS, address, or other types of identification information corresponding to the store of the user's current location. In non-retail use cases, the user can proceed to the web page using any suitable method of accessing the web page using the browser application 3026, regardless of the physical location.
[0224]
[0257] The web page can be associated with the store or, alternatively, with the regulated product or service requested by the user (e.g., a web page for a police station, a web page for an age / identity verification company, a web page for the manufacturer of the regulated product, a web page for a location with access restrictions such as a bar or club, etc.). In some implementations, instead of proceeding to the web page, the user can open the stand-alone ID verification application 3028 already installed on the mobile device 2902.
[0225]
[0258] In some implementations, the web page can open a web application (application software that runs on a web server rather than locally on the mobile device 2902). In a retail scenario where the user proceeds to a web page (or a web application or a stand-alone application) before arriving at the store, the user may be required to proceed to the web page again upon arrival at the store in order to ensure (using biometric verification) that the person verifying the ID is the person who purchased the regulated product.
[0226]
[0259] Optionally, in some retail scenarios, the web page (or web application or stand-alone application) can obtain item selections as described above with respect to operations 1402 (FIG. 14), 2204 (FIG. 22), 2310 (FIG. 23), or 2416 (FIG. 24). In these scenarios, the web page (or web application or stand-alone application) can optionally obtain payment details, such as the user's credit card information or any other type of data associated with an online payment for the selected item.
[0227]
[0260] In some implementations, the web page can be associated with the server system 2908. Alternatively, the web page can be associated with a server system other than the server system 2908. In the latter scenario, the server system associated with the web page instructs the user to perform an age / ID verification operation (after 3304), provides a link to the server system 2908, and through such link, the authenticated age / ID data (as a result of operation 3308) can be transmitted.
[0228]
[0261] Method 3300 follows age / identity verification operations 3304 and 3306. In detail, the browser application 3026 receives a command from the server system associated with the web page (or web application or standalone application) to verify the user's identity and / or age information (3304) by retrieving the user's identity and / or age information from the digital wallet application 3024. In other words, the browser application 3026 prompts the user to perform identity verification by verifying the user's identity and / or age using the user's digital ID card stored in the digital wallet application. In some implementations, the browser application receives a command to verify the identity and / or age information in response to the user selecting an option on the web page to verify the user's identity and / or age (for example, by selecting a user interface element in the form of a button that says “Verify ID” or “Verify ID using wallet”).
[0229]
[0262] In response to receiving a command to verify the user's identity and / or age information, the browser application 3026's digital wallet API 3026a accesses the digital wallet application 3024, which causes the user to authenticate using a biometric authentication application 3022 (e.g., facial ID, touch ID, etc.) (3306). In other words, the browser application's digital wallet API accesses the digital wallet application and requests age and / or identity data 3024b (e.g., from the user's digital driver's license or other ID card), and retrieves the requested data when biometric authentication triggered by the digital wallet application 3024 is successful by calling the authentication application 3022. In other words, the digital wallet verifies (authenticates) the user based on whether the user's face or fingerprint matches the face data or fingerprint data 3022a associated with the age / identity data 3024b stored in the digital wallet. As a result of verification (authentication), the digital wallet application 3024 provides the requested age / identity data 3024b to the browser application 3026 via the browser application 3026's digital wallet API 3026a.
[0230]
[0263] In some implementations, the digital wallet application 3024 securely provides the requested age / identity data 3024b to the browser application in an encrypted trusted area of the mobile device 2902's memory 3006. In some implementations, the digital wallet application 3024 uses operating system level (OS level) security to provide the requested age / identity data 3024b only to users whose biometric data matches the specific age / identity data 3024b. For example, even if an OS level facial ID or touch ID certificate works for two users, the digital wallet application 3024 may be configured to provide the age / identity data 3024b to only one user (sometimes called the primary user of the mobile device 2902) whose biometric data 3024b matches the specific age / identity data 3024b (for example, the user associated with the biometric data 3022a corresponding to the age / identity data 3024b).
[0231]
[0264] In some implementations, as an alternative to authentication operations 3304-3306, the browser application 3026 may use a third-party service to retrieve age / identity data to match a life selfie photo or video clip with a digital ID photo stored in the digital wallet application 3024 (for example, using one or more of the user verification operations described above with reference to Figures 27A-27E and 28A-28Q).
[0232]
[0265] When user authentication is successful, the browser application 3026 obtains (receives or acquires) the user's identity and / or age information from the digital wallet application 3024 and transmits this identity and / or age information to the server system 2908 (3308). Optionally, the browser application 3026 also transmits item selection and / or payment data to the server system 2908 along with the identity and / or age information. Identity information may be the name or any other data indicating the user's identity, and age information may be the date of birth (DOB) or any other data indicating the user's age.
[0233]
[0266] The server system 2908 receives age / identity data 3024b and verifies the age / identity limits corresponding to the managed product or any other commodity or service associated with age or identity requirements (3310). Specifically, using the age / identity verification module 3220, the server system 2908 compares the received age / identity data to one or more age or identity-based limits (for example, comparing the user's age to the minimum age threshold for using a particular managed product in a particular jurisdiction) and, based on the comparison, determines whether the age / identity data 3024b meets the age or identity-based limits (for example, determining whether the user's age meets or does not meet the minimum threshold required for purchasing a particular managed product for a particular jurisdiction).
[0234]
[0267] In some implementations, the verification operation 3310 may include comparing the user's identity (from the received data 3024b) to a list of identities authorized to purchase or use a particular managed product, and determining whether the user's identity matches any of the identities in the list.
[0235]
[0268] In some implementations, verification operation 3310 may include one or more of the product and / or consumer verification operations described above with reference to Figure 14 (e.g., operations 1402, 1402A, 1402B, 1406, 1406A, 1406B, and / or 1408) and the product and / or consumer verification operations described above with reference to Figure 15 (e.g., operations 1504 and / or 1508).
[0236]
[0269] In some implementations, in non-retail scenarios, validation operation 3310 may include comparing the user's age or identity (from received data 3024b) to any age or identity-based restrictions associated with any restricted access, such as controlled access to a location (e.g., bars, clubs, restaurants, airport restricted areas, or federal buildings), age-based activity (e.g., driving or car rental), or identity-based activity (e.g., hotel check-in, flight check-in, or any other type of identity-based check-in process).
[0237]
[0270] In some implementations, instead of receiving age / identity data 3024b from the browser application 3026, the browser application 3026 (or a web application or standalone application) performs an age / identity verification operation locally on the mobile device 2902 and sends the results of the verification operation to the server system 2908 for use in further operations (e.g., 3312 and beyond).
[0238]
[0271] Moving forward with respect to method 3300, the QR generation module 3222 of the server system 2908 generates a secure and / or unique QR code (or any other type of graphic barcode and / or scannable code) that represents the age / identity verification determination made by module 3220 in operation 3310 (for example, the determination or decision that the user's age and / or identity meets the relevant age / identity-based restrictions or regulations) (3312). In alternative implementations (for example, in a non-retail setting), the QR code may represent the age or identity data itself, rather than a determination corresponding to an age / identity-based restriction associated with the managed product.
[0239]
[0272] The server system 2908 transmits a QR code to the mobile device 2902. In some implementations, the server system 2908 transmits a QR code to the mobile device 2902 according to an age / identity verification decision (for example, according to a decision that the user's identity and / or age information meets the identity and / or age requirements associated with the managed product). In other implementations, the server system 2908 may transmit a QR code to the mobile device 2902 regardless of an age / identity verification decision, and the QR code indicates whether the user's identity and / or age meets or does not meet the identity / age-based requirements, or it indicates the user's identity and / or age itself.
[0240]
[0273] In operation 3318 (described below), the server system 2908 stores the QR code in QR storage 3222a for cross-checking by the QR verification module 3224. In some implementations, the QR code is stored along with additional information corresponding to the specific mobile device 2902 that transmitted the age / identity data 3024b, so that a subsequent cross-check can confirm that the stored QR code corresponds to the mobile device 2902 owned by the user authenticating the user's identity and / or age.
[0241]
[0274] In some implementations, the server system 2908 starts a timer when it stores and / or transmits the QR code in operation 3312. Alternatively, instead of starting a timer, the server system 2908 may create a timestamp corresponding to the generation or transmission of the QR code in operation 3312 and store the timestamp along with the QR code in QR storage 3222a. Thus, the QR code may expire upon the expiration of a predetermined time period. In implementations for retail, the time period may be set to an amount of time corresponding to the settlement interaction at the point of sale (e.g., 5 minutes), which minimizes the possibility that the mobile device 2902 is passed to different people after biometric operation 3316 and before the display of the QR code in operation 3314 (described below). In some implementations, the server system 2908 transmits to the mobile device 2902, in addition to the QR code itself, a timestamp (corresponding to the generation and / or transmission of the QR code to the mobile device 2902) and time window data (corresponding to the expiration of the QR code). The timestamp and time window data can be embedded within the QR code or transmitted separately from the QR code.
[0242]
[0275] In some implementations, a QR code may expire at any time for any reason (e.g., it may be deleted from QR storage 3222a or otherwise labeled as invalid). Illustrative reasons for expiring a QR code may include fraud detection (e.g., detection of a screenshot of another user's digital ID or detection of a QR code previously received on a mobile device 2902), detection of a user attempting to interact with two verification devices 2904 in the same transaction, or detection that a user is not physically close to a verification device 2904 when performing one or more of the actions 3302-3308 and 3314 (e.g., using GPS data or any other type of location data generated on the user's mobile device 2902).
[0243]
[0276] Moving forward with respect to method 3300, the mobile device 2902 (through the browser application 3026) receives a QR code from the server system 2908 and displays the QR code on the display of the mobile device 2902 (for example, on the screen of the user's smartphone) (3314). This allows the user to show the QR code to a retail employee (or, in a non-retail setting, to someone operating the verification device 2904). In some implementations, the browser application 3026 also receives timing data corresponding to the time windows described above with respect to operations 3310-3312 (for example, timestamps corresponding to the generation and / or transmission of the QR code from the server system 2908 to the mobile device 2902). Upon expiration of the time window, the browser application 3026 may be configured to stop displaying the QR code. In some implementations, timing data may be embedded within the QR code itself so that when the verification device 2904 scans the QR code in operation 3316 (described below), the verification device 2904 can determine whether the QR code is still valid or has expired.
[0244]
[0277] The verification device 2904 scans a QR code displayed on the screen of the mobile device 2902 (3316). Although method 3300 describes scanning a QR code, other types of graphical barcodes may be scanned. In some implementations, non-graphical codes may be used. For example, the mobile device 2902 may display a numerical (or alphanumeric) code for the user to read to the person operating the verification device 2904. Alternatively, the user may directly enter the code into the input device of the verification device 2904 (e.g., a keyboard or keypad). As described above with reference to Figure 29, the verification device 2904 may directly obtain the code using an onboard scanning device or using an external scanning device 2906 (e.g., a handheld scanner), with the external scanning device 2906 then communicating the code to the verification device 2904 via a wired or wireless connection.
[0245]
[0278] The verification device 2904 transmits the QR code (or data corresponding to the QR code) to the server system 2908 for QR code verification in operation 3318 (described below). In some implementations, the verification device 2904 determines whether the QR code is still valid by decrypting timing data from the QR code (e.g., timestamp and / or time window data embedded in the QR code, as described above) and determining whether the decrypted timing data indicates that the QR code has expired or is still valid. The verification device 2904 may be configured to transmit the QR code to the server system 2908 only if the QR code has not yet expired.
[0246]
[0279] Server system 2908 receives the QR code (or data corresponding to the QR code) transmitted by verification device 2904 and verifies the QR code (3318). Specifically, the QR verification module 3224 of server system 2908 determines whether the QR code received from verification device 2904 (in operation 3318) matches or otherwise corresponds to the QR code transmitted to mobile device 2902 (in operation 3312). This determination may include comparing (cross-checking) the QR code received from verification device 2904 (in operation 3318) with the QR code stored in QR storage 3222a to determine whether the received QR code matches the QR code transmitted to mobile device 2902 (in operation 3312).
[0247]
[0280] In some implementations, the QR verification module 3224 further determines whether the QR code transmitted to mobile device 2902 (in operation 3312) that matches the QR code received from verification device 2904 (in operation 3318) has not yet expired and / or is still valid (e.g., not invalidated due to detected fraud or any of the other reasons described above with respect to operations 3310 - 3312).
[0248]
[0281] The server system 2908 (specifically, the QR verification module 3224) transmits an identity and / or age verification determination (also called a code verification determination, information, or data) to the verification device 2904 in accordance with one or more of the decisions described above. Specifically, the determination identity and / or age verification determination indicates (i) the identity and / or age of the user corresponding to the QR code (based on the QR code being verified), (ii) whether the user is permitted (or not permitted) to proceed with restricted activities (e.g., purchasing a controlled product, entering a restricted area), and / or (iii) whether the QR code was not verified (e.g., due to a poor match, detected fraud, or the QR code being expired or otherwise invalid).
[0249]
[0282] In some implementations, if the user makes product selections in operation 3304, the server system 2908 may further transmit those selections to the verification device 2904 in operation 3318. In some implementations, if the user provides payment details in operation 3304, the server system 2908 may process the payment for the selected items and, in operation 3318, transmit confirmation that the payment was successful to the verification device 2904.
[0250]
[0283] The verification device 2904 receives an identity and / or age verification determination transmitted by the server system 2908 and displays the identity and / or age verification determination on the display of the verification device 2904 (3320). In some implementations, the identity and / or age determination indicates that the user meets the identity and / or age requirements associated with the managed product or restricted activity. Additionally or alternatively, the identity and / or age determination indicates the user's identity and / or age. In some implementations, if the verification device 2904 receives item selection data and / or payment confirmation data from the server system 2908, the verification device 2904 also displays the selected item and / or payment confirmation.
[0251]
[0284] Optionally, the verification device 2904 is communicatively coupled to a managed dispensing machine (e.g., 102 in Figure 1 or 1302 in Figure 13) configured to dispense a managed product in response to the verification device 2904 receiving an identity and / or age verification determination from a server system. Alternatively, the managed dispensing machine may not be communicatively coupled to the verification device 2904, in which case the retail employee may complete the transaction by retrieving the managed product from the managed dispensing machine and / or processing payment (cash or cashless) at the counter.
[0252]
[0285] Figure 34 shows the operation of the age / identity verification method 3300 (Figure 33) using the age / identity verification platform 2900 in several implementation forms. A user of a mobile device 2902 uses a browser application to navigate to a webpage corresponding to a restricted product or activity (a product or activity subject to age and / or identity restrictions as described above). While interacting with the webpage, the webpage prompts the user to provide authenticated age and / or identity data, to which the user responds by accessing a digital wallet application (step 1), authenticating with biometric authentication, and providing the browser with age and / or identity data (e.g., name / DOB) corresponding to a digital ID card stored in the digital wallet application. The browser application on the mobile device 2902 sends the age and / or identity data to the server system 2908 (step 2). Steps 1 and 2 in Figure 34 correspond to operations 3302 to 3308 in method 3300 (Figure 33).
[0253]
[0286] The server system 2908 validates the data (for example, in the context of a restricted purchase or activity) (step 3), generates a QR code, transmits the QR code to the mobile device 2902 (step 4), and the mobile device 2902 displays the QR code on its display. Steps 3-4 in Figure 34 correspond to operations 3310-3314 in method 3300 (Figure 33).
[0254]
[0287] The verification device 2904 (using the scanning device 2906) acquires a QR code by scanning the display of the mobile device 2902 (step 5) and transmits the QR code to the server system 2908 (step 6). Steps 5-6 in Figure 34 correspond to operation 3316 in method 3300 (Figure 33).
[0255]
[0288] The server system 2908 verifies the QR code (step 7), sends the verification result to the mobile device 2902 (step 8), and the mobile device 2902 displays the result on its display. Steps 7-8 in Figure 34 correspond to operations 3318-3320 in method 3300 (Figure 33).
[0256]
[0289] Therefore, biometrically authenticated age and / or identity data retrieved from the digital wallet application on the mobile device (step 1) can be securely communicated to the verification device 2904 without relying on a complex exchange of data between the mobile device 2902 and the verification device 2904. Instead, the verification device 2904 can effectively obtain verification of the biometrically authenticated age and / or identity data by scanning the screen of the mobile device 2902 and obtaining verification from the server system 2908.
[0257] others
[0290] The above description relates to a specific implementation. However, the above illustrative description is neither exhaustive nor does it limit the claims to the exact form disclosed. Many variations are possible in light of the above teachings. The implementations have been selected and described in a manner that best illustrates the principle of operation and practical applications, thereby enabling others skilled in the art to do so.
[0258]
[0291] Various drawings show several elements in a specific order. However, elements that are not order-dependent can be rearranged, and other elements can be combined or separated. Some rearrangements or other groupings are described in detail, while others will be obvious to those skilled in the art, and therefore the orderings and groupings presented herein are not an exhaustive list of alternatives.
[0259]
[0292] As used herein, the singular forms “a,” “an,” and “the” also include the plural unless the context otherwise explicitly indicates; the term “and / or” encompasses any possible combination of one or all of the related listed items; terms such as “first,” “second,” etc., are used solely to distinguish one element from another and do not limit the elements themselves; the term “if” may be interpreted, depending on the context, as “when,” “upon,” “in response to,” or “in accordance with”; and the terms “include,” “including,” “comprise,” and “comprising” specify a particular feature or action but do not exclude additional features or actions.
Claims
1. A mobile device comprising one or more processors and memory for storing one or more programs to be executed by the one or more processors, wherein the one or more programs are An authentication application configured to receive a user's biometric data and authenticate the user based on the received biometric data, A digital wallet application configured to store the user's identity and / or age information and to provide the user's identity and / or age information only upon successful authentication of the user using the authentication application, A browser application including an application programming interface configured to access the user's identity and / or age information stored in the digital wallet application upon successful authentication of the user using the authentication application, and Mobile devices An identity and / or age verification system comprising: The aforementioned browser application Obtaining user input and Navigating to a webpage based on the aforementioned user input, Receiving a command from the server system associated with the webpage to retrieve the user's identity and / or age information from the digital wallet application, In response to the aforementioned command, the user's identity and / or age information is obtained from the digital wallet application upon successful authentication of the user using the authentication application. Transmitting the user's identity and / or age information to the server system, Receiving a graphic barcode from the server system corresponding to the server system's determination that the user's identity and / or age information meets the identity and / or age requirements associated with the managed product, This causes the graphic barcode to be displayed on the mobile device's screen. It is configured to do the following: The identity and / or age verification system further includes a verification device which includes one or more processors and a memory which stores one or more programs to be executed by the one or more processors, and the one or more programs are This causes the scanner of the verification device to scan the graphic barcode on the display of the mobile device, To transmit data corresponding to the graphic barcode to the server system, (i) receiving an identity and / or age verification determination from the server system that corresponds to the determination by the server system that the data corresponding to the graphic barcode corresponds to the graphic barcode transmitted to the mobile device, and (ii) that the graphic barcode has not expired; The fact that the identity and / or age verification determination is displayed on the display of the verification device, and that the identity and / or age verification determination includes a notification that the user's identity and / or age information meets the identity and / or age requirements associated with the management product. An identity and / or age verification system, including an identity and / or age verification application configured to perform the following.
2. The server system further comprises one or more processors and a memory for storing one or more programs to be executed by the one or more processors, and the one or more programs are Receiving the user's identity and / or age information from the mobile device, The determination that the user's identity and / or age information meets the identity and / or age requirements associated with the management product, Transmit the graphic barcode to the mobile device in accordance with the determination that the user's identity and / or age information meets the identity and / or age requirements associated with the managed product. Purchase verification application configured to perform The identity and / or age verification system according to claim 1, including the above.
3. The one or more programs of the server system are Receiving the data corresponding to the graphic barcode from the verification device, The data corresponding to the graphic barcode received from the verification device is determined to correspond to the graphic barcode transmitted to the mobile device. Determining that the graphic barcode transmitted to the mobile device has not expired, Transmitting the identity and / or age verification determination to the verification device in accordance with the determination that the data corresponding to the graphic barcode received from the verification device corresponds to the graphic barcode transmitted to the mobile device, and the determination that the graphic barcode transmitted to the mobile device has not expired. Barcode verification application configured to perform The identity and / or age verification system according to claim 1, further comprising:
4. The identity and / or age verification system according to claim 1, wherein the managed product is an age-restricted or identity-restricted product, service, or activity.
5. The identity and / or age verification system according to claim 1, wherein the user's identity and / or age information is stored in the digital wallet application in the form of an ISO / IEC 18013-5 compliant mobile driver's license.
6. The authentication application is configured to authenticate the two or more users of the mobile device based on biometric data received from each of the two or more users of the mobile device. The identity and / or age verification system according to claim 1, wherein the application programming interface of the browser application is configured to access the identity and / or age information only upon successful authentication of the primary user among the two or more users of the mobile device.
7. The identity and / or age verification system according to claim 1, wherein the browser application is configured to obtain user input by accessing the camera or scanner of the mobile device and causing the camera or scanner to obtain an image or scan of a barcode representing the uniform resource locator (URL) of the web page.
8. The identity and / or age verification system according to claim 1, wherein the web page is associated with an identity and / or age verification service configured to verify one or more identity and / or age requirements associated with the management product.
9. The identity and / or age verification system according to claim 1, wherein the verification device is a sales point computing device configured for operation by a retailer.
10. The identity and / or age verification system according to claim 1, wherein the verification device is communicably coupled to a managed supply machine configured to supply the managed product in response to the verification device receiving the identity and / or age verification determination from the server system.
11. A method comprising the operation described in any one of claims 1 to 10.
12. A non-temporary computer-readable storage medium for storing one or more programs configured for execution by a computer system, wherein the one or more programs include instructions for performing the operations described in any one of claims 1 to 10.
Citation Information
Patent Citations
Validating identification of a user for purchase of age-restricted items
US20190050921A1
Systems and methods for the sale of age-restricted merchandise
US20200098023A1