Method for managing event tickets

The hybrid connected/offline digital ticketing system addresses security vulnerabilities by encrypting tickets with spatial and temporal policies, enabling secure, offline validation, and reducing fraud during events.

WO2025210254A1PCT designated stage Publication Date: 2025-10-09USEAT
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/059334
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-04
Filing Date
2025-04-04
Publication Date
2025-10-09

Smart Images

  • Figure EP2025059334_09102025_PF_FP_ABST
    Figure EP2025059334_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a method for creating secure digital resources, consisting in: (a) receiving encrypted event-ticket information from a ticketing system, (b) creating a digital precursor for the event ticket, characterized in that it comprises the following steps: c) upon receipt of the event ticket, saving an encrypted digital precursor in the terminal of the user, d) transmitting a ticket key and commanding saving in a separate and secure area of the terminal of the beneficiary of the event ticket, d1) if the terminal is connected to the network, commanding execution on the terminal of an application for decrypting the precursor in order to issue a checkable event ticket, d2) in the absence of connectivity, commanding execution of an application for decrypting the encrypted precursor based on the saved decryption key in order to issue a checkable event ticket.
Need to check novelty before this filing date? Find Prior Art

Description

Event ticket management process Field of invention

[0001] The present invention relates to the field of online ticketing, in particular for access to events in physical locations such as sports stadiums or concert halls and live events. Online ticketing is intended to manage the online purchase of tickets for events attracting several tens or even hundreds of thousands of spectators, and to allow each ticket holder to easily and quickly access their seat in the venue where the event is taking place; finally, they allow the organizer to reliably and quickly check the conformity of the tickets.

[0002] For a long time, paper tickets were the norm. Tickets were often printed on expensive paper with elaborate graphics that made counterfeiting expensive and easier to spot. Advances such as holograms have made counterfeiting even more difficult, but not entirely impossible.

[0003] Control of these tickets by stewards is difficult during very large crowds, when spectators are impatient to get to their seats and the slightest hesitation due to the steward's doubts about the validity of the ticket makes them irritable to the point of triggering riots.

[0004] In the 2000s, with the emergence of digital technologies and personal computing and the widespread use of smartphones, the ticketing industry began to adopt printable tickets. Some of these were documents that could be printed at home, allowing for instant delivery via email and eliminating the need for postal mail or any actual physical distribution of tickets. The growth and adoption of mobile devices made digital tickets even more widespread, allowing not only the copying of these same digital documents, but also the use of technologies such as a digital wallet to store these tickets and, more specifically, the barcode required to gain access to venues.

[0005] While digital delivery and exchange offered a far greater level of convenience than paper tickets, they also created a huge security problem. Digital assets have a long history of piracy, ranging from copies of computer software to digital music files pirated via peer-to-peer services. The spread of the internet has allowed a growing number of malicious actors to participate in the piracy of these digital tickets. Because the main element of the ticket is the barcode or QR code, which can be defined, for example, by a string of characters no longer than a dozen symbols, replicating tickets can be easier than replicating software or a digital audio file. Since no effort is made to obfuscate these codes, replicating them is very simple.

[0006] In 2021, a UEFA-organized football match at the Stade de France gave rise to serious incidents due to a combination of organizational malfunctions, one of which involved ticketing failures. For 79,000 seats, the computer system recorded 8,000 ticket reading "incidents" at the gates that evening, including approximately 2,500 tickets that had already been read—and therefore possibly duplicated—as well as 2,500 unknown tickets. Other official sources put the figures ten times higher. Investigations into this final established that ticketing management was inadequate. Of course, issuing paper tickets was not in itself an exceptional situation, and this possibility was in accordance with the regulations.But it was known that the use of this type of note results in a significant risk of fraud and circulation of counterfeit notes, which was ten times higher than the averages usually observed.

[0007] Furthermore, by requiring the introduction of ticket validity checks at security pre-screening points, the organiser inadvertently contributed to the blocking of the checkpoints, particularly given the higher than usual number of people with valid tickets.

[0008] It is also worth noting the inadequacy of the system for handling ticket disputes, which led to people being turned away having to park in front of the screening points, as well as the poor training of stewards who quickly seemed overwhelmed by the situation. Finally, the ticket verification procedures were also the subject of debate, with the use of pens to mark tickets and the electronic ticket verification system not being considered sufficiently practical.

[0009] A first recommendation was to make the use of tamper-proof, i.e., electronic, tickets mandatory, combined with reliable control devices for events with the highest stakes. Another recommendation was to require organizers to inform ticket holders in real time, by email, SMS, or messaging, of the conditions for access to the event site, unforeseen events, and changes decided by the authorities when difficulties arise. State of the art

[0010] Known in the state of the art is patent application US2021201597 describing an electronic ticketing system intended to combat fraud and the illegitimate resale of tickets.

[0011] This prior art solution is based on the use of a dynamic entry code stored on a mobile device, which changes from an inoperative state to a functional state only in temporal or geographical proximity to the event.

[0012] This code, which is not readable by humans (e.g., a hidden QR code), is only visible and usable after activation. Upon purchase, the ticket is linked to personal identifiers (name, phone number, device ID), which are verified before authorizing the activation of the code. The system also integrates a user credibility index, based on the history of purchases, resales, and uses, to limit abuse. Resale may be authorized but remains regulated by the central server. Disadvantages of the prior art

[0013] The solution proposed by US2021201597 is not entirely satisfactory. It does not provide a clear separation between ticketing data and its final representation, which introduces weaknesses regarding security and resilience to fraud. In the prior art solution, the data stored on the terminal, such as the keys, are sensitive to software attacks, malware, or malicious users.

[0014] The previous solution requires mandatory network access to complete the transaction. It becomes ineffective in offline mode, particularly in cases of network saturation or in areas without coverage, which can trigger serious dissatisfaction or even riots.

[0015] US20210201597A1 describes a system in which the digital ticket (often in the form of a hidden visual code, e.g. invisible QR code) is only activated when approaching the event, based on spatio-temporal criteria (location and time) verified by the central system.

[0016] “The activation of the access code is conditioned upon confirmation of the user's proximity to the event location and the timing of the event”

[0017] This implies that: the system must access the location data of the user terminal in real time; the system must know the exact time the ticket was viewed or used; activation is triggered by the server, not locally.

[0018] This earlier solution uses elements such as: terminal ID, phone number, credibility index based on ticket history, transfer or resale rules.

[0019] This information is hosted on a central server.

[0020] Without a connection, it is impossible to verify the criteria, which excludes any autonomous activation of the ticket locally. Solution provided by the invention

[0021] In order to overcome these drawbacks, the present invention relates to a method for creating secure digital resources, offering a hybrid connected / offline solution, robust and secure.

[0022] The method comprising the steps of:

[0023] (a) receive, over a ticket distribution or management network, encrypted event ticket information regarding an event from a ticketing system

[0024] (b) creating a digital precursor for the event ticket based on the ticket information, and a set of policies governing one or more ticket transactions of the event ticket, wherein the set of policies enforces spatial and temporal requirements with respect to the event ticket, and wherein enforcing the spatial requirements includes obtaining and confirming global positioning system coordinates of the location of the one or more ticket transactions;

[0025] Characterized in that it further includes the following steps:

[0026] (c) upon receipt of said event ticket, record an encrypted digital precursor in the memory of a user terminal,

[0027] (d) at least once, proceed with the transmission of the ticket key and order the recording automatically in a separate and secure storage area of ​​the connected terminal of the beneficiary of the event ticket

[0028] d1) in the case where said terminal is connected to the network, ordering the execution on said terminal of an application for decrypting said encrypted precursor to edit a controllable event ticket and ordering the display of said controllable event ticket

[0029] d2) in the absence of connectivity, locally controlling the execution on said terminal of a decryption application, from the decryption key recorded in said separate and secure storage area, of said encrypted precursor to edit a controllable event ticket and controlling the display of said controllable event ticket

[0030] e) ordering, when a control equipment reads a controllable event ticket, the transmission to a server by said control equipment of a digital message deactivating the corresponding event ticket.

[0031] Advantageously, said command to execute said decryption application in the absence of connectivity is conditioned by the conformity of at least one parameter of said terminal.

[0032] According to a variant, said command for the execution of said decryption application in the absence of connectivity is conditioned by the conformity of a plurality of parameters of said terminal.

[0033] Advantageously, said parameters include geolocation information, the timestamp of the terminal, the status of a biometric control means, the status of a KYC (Know Your Customer) verification means, the connectivity status, or the terminal identifier.

[0034] Detailed description of a non-limiting example of embodiment

[0035] The present invention will be better understood on reading the following description, concerning non-limiting examples of embodiment illustrated by the appended drawings where:

[0036] represents the diagram of the hardware architecture of the invention

[0037] represents the diagram of the functional architecture of the invention

[0038] represents the functional diagram of an optional local processing of the invention General principles of the invention

[0039] The invention provides a solution for providing digital tickets to participants in an event in a space whose access is secured by access control requiring the presentation of a valid ticket, generally in the form of a graphic display, for example of the QR Code / Aztec / PDF417 type, on the screen of an individual terminal, generally a smartphone.

[0040] The invention relates to an event ticket distribution system for enabling access control to a site, and which acts as a complement to a ticket management system.

[0041] An “event ticket” means a right to participate in an event associated with the ticket, which right may be represented by a digital sequence and / or a graphic representation, for example a QR Code, a barcode, or a document containing text and / or images.

[0042] An event ticket will initially be materialized by a “digital precursor” which is a digital sequence whose processing by a “local application” will produce a “controllable event ticket”.

[0043] The invention generally relates to a method for creating secure digital resources for event tickets, with specific technical steps relating to: creating an encrypted digital precursor from ticketing information, applying spatial and temporal policies, local or remote conditional management of decryption, secure recording in a separate area, and deactivating the ticket after verification.

[0044] The invention relates to a method for securely managing a digital event ticket, intended to enable conditional access control to an event, said method being implemented using a connected user terminal, and comprising the following steps:

[0045] (a) generate, from information relating to an event ticket, an encrypted digital precursor,

[0046] (b) recording said encrypted digital precursor in the memory of the user terminal,

[0047] (c) transmit to this terminal a ticket key associated with said precursor, said key being automatically stored in a separate and secure storage area of ​​the terminal,

[0048] (d) run on the terminal a local application intended to:

[0049] • verify one or more predefined contextual conditions, including at least one spatial, temporal or terminal identification condition,

[0050] • and, if the conditions are met, locally decrypt the digital precursor using said key to produce a verifiable event ticket,

[0051] (e) display or transmit the controllable ticket from the terminal for validation purposes,

[0052] (f) and, upon validation, transmit to a server a signal to deactivate the event ticket in order to prevent any subsequent reuse.

[0053] More specifically, the invention relates to a method for creating and managing a secure digital resource in the form of an event ticket, comprising the steps of: (a) receiving, on a ticket distribution or management network, encrypted information relating to an event ticket, from a ticketing system, (b) generating a digital precursor associated with the event ticket on the basis of said information, (c) associating with said digital precursor a set of policies defining one or more conditions of use of the event ticket, comprising at least one contextual requirement depending on the environment of the beneficiary's terminal, said requirement being able to include one or more spatial, temporal, biometric or terminal identification conditions,

[0054] the method being characterized in that it further comprises the following steps: (d) recording the encrypted digital precursor in the memory of a connected terminal of the beneficiary, (e) transmitting at least one ticket key and ordering its recording in a separate and secure storage area of ​​said terminal, accessible only by an authorized local application,

[0055] (f) commanding the execution, by said local application, of a decryption process of the digital precursor to generate a controllable event ticket, said process being:

[0056] performed via the network when the terminal is connected,

[0057] or, in the absence of connectivity, executed locally by said application from the ticket key stored in said secure area, provided that the requirements defined by said policies are locally satisfied,

[0058] (g) activate the display or transmission of the event ticket controllable by the terminal, (h) and, when said ticket is read by control equipment, command the transmission to a server of a digital message deactivating the corresponding ticket.

[0059] A local application is provided to each recipient of an event ticket by the ticket distribution system server, for example via a download link accessible on the website of the service provider or a partner or an online store. The downloaded file is installed on a connected terminal of the user. It consists of a digital code executable by the computer of the connected terminal of the user.

[0060] This processing may take into account a “ticket key” which may be generic or specific to each event ticket. This “ticket key” is a numerical sequence stored in a separate and secure storage area of ​​the user’s terminal, accessible only by the application

[0061] This controllable event ticket may be edited in digital or graphic form to interact with control equipment to order authorization, in the event of compliance and validity, to the event for which the event ticket was generated by a ticketing system.

[0062] The event ticket distribution system:

[0063] (a) Receives event tickets from the ticketing system in the form of digital precursors consisting of digital files containing information relating to each ticket and its beneficiary, in encrypted form,

[0064] b) Transmits to a connected terminal, for example a smartphone, one or more digital precursors and a link to download a local application on the connected terminal, if the latter does not already have this local application. This local application controls the recording in memory of the digital precursor(s).

[0065] c) Subsequently transmits to the connected terminals of the event ticket recipients, at a time close to the opening of the event, “ticket keys” consisting of digital information required for the activation of the graphical edition of the event ticket on the connected terminal. The local application orders ticket keys in a separate and secure storage area of ​​the connected terminal

[0066] During access control, when the user controls the graphic display or digital transmission of the event ticket, the local application controls processing for editing and displaying the controllable ticket based on data delivered by one or more sensors of said connected terminal. This information is, for example, geolocation information, timestamp information or information captured locally by the camera of the smart terminal or by an NFC sensor. This information is transmitted to the server of the ticket distribution service which transmits in return a digital means controlling the execution by the local application of a routine for graphic display or digital transmission of the event ticket(s).

[0067] In the absence of connectivity, the local application conditionally commands the decryption of the ticket stored in the memory of the connected terminal, from the decryption information stored in the separate and secure storage area. The compliance of the activation condition is calculated by the execution of the local application, based on geolocation data, timestamp or information captured locally by the camera of the smart terminal or by an NFC sensor. If the information or a combination of information complies with a validity criterion associated with the event ticket, the local application executes a routine for graphical display or digital transmission of the event ticket(s) by processing taking into account the digital precursor(s) stored in the memory of the terminal as well as the ticket key(s) stored in the separate and secure storage area of ​​the terminal.

[0068] Detailed description of a non-limiting example of embodiment

[0069] The figure represents a schematic view of the hardware architecture of the invention.

[0070] The event ticket distribution and management system according to the invention is coupled to a ticketing system (100) comprising a server (1) associated with a secure data center (2), and connected to ticket kiosks (3), ticket machines (4), distribution agencies (5) and online purchasing services via smartphones (6). The invention complements existing ticketing systems, so as not to modify the uses of the solutions in place.

[0071] It is interfaced with the server (1) of the ticketing system (100) via a server (7) communicating with the server (1) of the ticketing system (100) via a communication protocol with end-to-end encryption.

[0072] The server (1) transmits to the server (7) digital messages comprising an identifier of an event ticket, as well as an identifier of the beneficiary of the ticket. This information can be supplemented in the same message or by pointers to pre-recorded information by information relating to the event ticket payment policy (time, date and location of the payment zone, etc.) and seating (imposed seating or by zone, etc.).

[0073] The server (7) records this event ticket data and transmits to the beneficiary a digital message comprising a link to an application server as well as a code constituting a digital precursor. This digital precursor is associated with an event ticket in a bijective manner. This digital precursor will make it possible to generate a ticket controllable by a specific processing executed by an application executed by the computer of a smartphone (8) of the beneficiary, after receiving other information distinct and complementary to the digital precursor.

[0074] The message received by the beneficiary's smartphone (8) activates a notification commanding the display of a page proposing the registration of the digital precursor in a digital wallet managed by the management application. If this application is not already installed on the beneficiary's smartphone (8), the user activates a link appearing on the page viewed, which commands the download from the application server of the executable code and the loading of the digital precursor after activation of the application.

[0075] In a time-shifted manner, the server (7) commands the sending of a generic or personalized message for each beneficiary of an event ticket, containing a ticket key that is automatically saved in a separate and secure storage area that can only be addressed by the management application. The data contained in the secure area cannot be transferred to other devices via unapproved sharing methods such as USB or Wi-Fi Direct.

[0076] During the check, the smartphone user (8) can order the display of a controllable ticket in the form of a QR Code, a barcode or even the edition of an NFC message, from the management application.

[0077] Preferably, the displayed QR Code contains in its center the clickable photo of the user's verified profile.

[0078] Tapping on this photo makes it appear larger, allowing for visual identification of the smartphone owner. Since the photo itself was verified during KYC, the "probative" value of this visual identification is considerably enhanced.

[0079] This application applies online processing of the ticket precursor to generate the controllable ticket, when the smartphone (8) is connected.

[0080] If it is not connected or the network is too evanescent, the application orders a local processing of ticket production controllable by processing the ticket precursor and the ticket key recorded in the separate and secure area.

[0081] Operation of a non-limiting example of an embodiment

[0082] It represents a schematic view of the functional architecture of the invention.

[0083] Step (10): First, the user purchases a ticket through the event organizer's usual ticketing system (100)

[0084] Step (11): the ticketing server (100) transmits, after validation of the purchase of the event ticket, the information to the server (7) which orders the sending of a digital message to the address of the beneficiary. This message triggers a notification on the beneficiary's telephone (8), inviting the beneficiary to download the event ticket and, if he does not have the service-specific application on the smartphone (8), to download it.

[0085] Step (12) the application checks if the user has a user account.

[0086] If so, the server (7) orders the association of the event ticket with the user account (step (13).

[0087] Otherwise, the server (7) orders an account opening procedure (step (14)) before moving on to the previous step (13) of associating the event ticket with the user account.

[0088] As the date of the event approaches, the server (7) orders the issue of ticket keys (step (15). Upon receipt of this message, the management application executes on the user's smartphone (8) a command to register this ticket key in a secure detached area of ​​the smartphone (8).

[0089] During access control, a notification is sent to the smartphone (8) step (17). If the smartphone (8) is connected to the network, (control (8)), the controllable ticket associated with the event ticket is transmitted by the server (7) to the phone (8), which allows the user to proceed to display or edit the controllable ticket and present it at the control station (step 19). The event ticket is then immediately deactivated in the ticketing system (100) and on the server (7) to prevent fraudulent reuse (step 22).

[0090] If the smartphone (8) cannot connect to the network, the application commands a local processing (step (21)) consisting of locally calculating the controllable ticket from the ticket precursor and the ticket key, to then proceed to step (20). Conditional treatment

[0091] Local processing (21) optionally provides conditional activation.

[0092] It is only executed if a compliance criterion, or a combination of compliance criteria, is verified locally, from the information available on the smartphone (8), even in offline mode.

[0093] These conditions may include:

[0094] Geolocation information (31) provided by the smartphone (8). This information can be used alone, to control the activation of the controllable ticket calculation processing when the location is less than a predefined distance from the event organization location. This geolocation information (31) can also be weighted by a factor P31 to be taken into account with other information.

[0095] The timestamp information (32) constitutes another criterion that can be used alone, to control the activation of the controllable ticket calculation processing when the time is close to the time and date of organization of the event. This timestamp information (32) can also be weighted by a factor P32 to be taken into account with other information.

[0096] The biometric information (33) provided by the biometric sensor of the cell phone (8) constitutes another criterion which can be used alone, to control the activation of the calculation processing of the controllable ticket when the user is recognized by the fingerprint or facial recognition sensor. This biometric information (33) can also be weighted by a factor P33 to be taken into account with other information.

[0097] Other information (3n) may be taken into account. KYC (Know Your Customer) information is a procedure implemented to verify the identity of a person. Information to verify a smartphone identifier (8), for example the IMSI number.

[0098] The activation of the production of the controllable ticket may be ordered based on the conformity of one or more of these criteria, or by a combination of the relative degree of conformity of several of these criteria. Variant with display of an enriched QR Code

[0099] As mentioned above, the processing advantageously results in the display of an enriched QR code, integrating personalized visual elements (such as a photograph) and possibly interactive features, such as a clickable link. Here is how it is technically possible, starting from the principles of the QR code and adapting them to the context:

[0100] A QR code is a graphical representation of a string of data. It can contain: plain text (e.g., "Username"), a clickable URL (e.g., https: / ticket.event / 123456), structured data (JSON, vCard, etc.), or encrypted encoding interpreted by a dedicated application.

[0101] The user's photo can be integrated in two ways: Graphically in the center of the QR code: The QR code is generated with error tolerance (ECC correction – Error Correction Code). This allows up to 30% of the QR code to be hidden without affecting its readability. A photo or logo can therefore be inserted in the center of the QR code (often in a square), while maintaining its readability. The QR code is then readable by a conventional reader, and visually personalized with the user's photo, which facilitates quick visual verification by an agent (such as a steward). Photo linked by reference in the data: The QR code can also contain a link to a page or a post, for example:

[0102] Arduino

[0103] CopyEdit

[0104] https: / billet.secure / event / ABC12345?token=xyz789

[0105] This page contains the user's verified photo (taken during KYC), as well as the full ticket to be displayed, or details to be verified. The image is not in the QR code itself, but associated via a secure URL.

[0106] Although a QR code is often scanned by an optical reader, it can also be displayed on a smartphone screen, or contain a clickable URL if consulted from an app (digital wallet, ticket app, etc.) or even trigger an event in the application that displays it (e.g.: validation, deactivation, sending a token to the server).

[0107] Ex: The user presents his phone to the steward and opens his ticket in the app; the steward sees the QR code with his photo in the center; He can click on the photo or on a button "Validate my passage" (this is the equivalent of the clickable link); This click triggers the sending of a message to the server to signal the passage (see step (e): deactivation of the ticket).

[0108] This variant allows a combination of human (photo) + automated (QR / link / validation) verification resulting in enhanced security, even in the event of a rapid visual check or fluctuating network.

[0109] The invention significantly improves security compared to the prior art while improving operational robustness, particularly in the event of poor network coverage, thanks to the following characteristics: Local secure storage of the key, inaccessible without the authorized application; Conditional decryption executed locally, even without a network; Logical separation between precursor and final ticket (no direct QR code); Centralized deactivation triggered from a decentralized control; Extensible contextual conditions (geoloc, biometrics, timestamp, terminal ID).

Claims

– A method for creating secure digital assets, comprising the steps of:(a) receiving, over a ticket distribution or management network, encrypted event ticket information about an event from a ticketing system;(b) creating a digital precursor for the event ticket based on the ticket information, and a set of policies governing one or more ticket transactions of the event ticket, wherein the set of policies enforces spatial and temporal requirements with respect to the event ticket, and wherein enforcing the spatial requirements includes obtaining and confirming global positioning system coordinates of the location of the one or more ticket transactions;Characterized by further comprising the steps of:(c) upon receipt of said event ticket,recording an encrypted digital precursor in the memory of a user terminal,d) at least at one time, transmitting the ticket key and automatically ordering the recording in a separate and secure storage area of ​​the connected terminal of the beneficiary of the event ticketd1) in the case where said terminal is connected to the network, ordering the execution on said terminal of an application for decrypting said encrypted precursor to edit a controllable event ticket and ordering the display of said controllable event ticketd2) in the absence of connectivity, locally ordering the execution on said terminal of an application for decrypting, from the decryption key recorded in said separate and secure storage area, said encrypted precursor to edit a controllable event ticket and ordering the display of said controllable event tickete) ordering,when a control equipment reads a controllable event ticket, the transmission to a server by said control equipment of a digital message deactivating the corresponding event ticket., – Method for creating secure digital resources, according to claim 1 characterized in that said command of the execution of said decryption application in the absence of connectivity is conditioned by the conformity of at least one parameter of said terminal. – Method for creating secure digital resources, according to claim 2 characterized in that said command of the execution of said decryption application in the absence of connectivity is conditioned by the conformity of a plurality of parameters of said terminal. – Method for creating secure digital resources, according to claim 2 or 3, characterized in that said parameters include geolocation information, the timestamp of the terminal, the state of a biometric control means, the state of a KYC verification means of Customer Knowledge, the connectivity state, or the terminal identifier.

Citation Information

Patent Citations

  • Electronic Ticketing System

    US20210201597A1