Portable Device Cryptogram Validation for Event Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional paper tickets for events are inconvenient, prone to loss or theft, and pose security risks due to the need for sensitive information storage at venues, while using portable consumer devices for ticketing raises security concerns about data protection and complexity.

Innovation Solution

A method using portable consumer devices to generate and validate cryptograms for event access, ensuring secure storage and transmission of sensitive data by comparing first and second validation cryptograms, eliminating the need for physical tickets and reducing data storage requirements at venues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If paper tickets are used for event access, then consumers can physically hold and present tickets, but tickets can be lost, misplaced, stolen, or require queuing at will call windows

Engineering Contradiction:
Improveticket securityVSAvoidticket storage and retrieval
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical paper ticket system with an electronic cryptogram validation system. Instead of physical tickets that can be lost or stolen, the system uses portable consumer devices with encrypted cryptograms that are validated electronically at event access points, eliminating the physical medium while maintaining security and convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a digital copy of the ticket information in the form of a cryptogram stored on the consumer's portable device. This cryptogram is a condensed representation of the ticket data that can be easily copied and transferred electronically without the risks associated with physical tickets, allowing consumers to access events using their existing portable devices.

Inventive Principle:
Principle #26Copying

2Ease of operation

If portable consumer devices are used for ticketing, then consumers can use existing devices without physical tickets, but sensitive payment card information would need to be stored at venues or entrance points

Engineering Contradiction:
Improveticket access convenienceVSAvoiddata security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary validation information (cryptogram) from the full payment card data and stores it on the consumer's portable device. The venue systems only need to validate the cryptogram, not store or process sensitive payment information, thereby removing the security risk while maintaining the convenience of electronic ticketing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms sensitive payment card information into a cryptogram with different security parameters. The cryptogram is an encrypted representation that can be validated without revealing the underlying sensitive data, changing the data format from something that must be protected through secure storage to something that can be safely transmitted and validated.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If separate lists or databases of payment card numbers are maintained for each event, then access control can be differentiated by event, date, time, and level, but the system becomes complex and the availability of sensitive information increases security breach risk

Engineering Contradiction:
Improveevent-specific access controlVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the access control information into event-specific cryptograms that are generated and stored on the consumer's portable device. Each cryptogram contains the necessary event, date, time, and access level information in a condensed format, eliminating the need for complex centralized databases while maintaining detailed access control capabilities.

Inventive Principle:
Principle #1Segmentation

4Object-affected harmful factors

If cryptograms are generated and validated using portable consumer devices, then security is enhanced and data exposure is reduced, but the system requires encryption infrastructure and validation processes

Engineering Contradiction:
Improvedata exposure riskVSAvoidencryption infrastructure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent performs the encryption and cryptogram generation in advance during the ticket purchase process. The cryptogram is created and stored on the consumer's device before the event, so that during validation only the cryptogram needs to be read and compared, not the sensitive underlying data. This preliminary action reduces the complexity of the validation infrastructure while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10579995B2Event access with data field encryption for validation and access control
Publication Date: 2020.03.03 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10579995B2 patent drawing
  • US10579995B2 patent drawing
  • US10579995B2 patent drawing

AI summary

The utility of a portable consumer device is extended by allowing account holders the ability to gain entry into access-controlled venues (e.g., baseball or soccer game, cinema, public transit) using a portable consumer device that is associated with an account that was used to purchase the admission or tickets to the event at the access-controlled venue. Techniques disclosed allow cardholder authentication in a non-payment setting that enables cardholders access to a location or a specific event. A first validation cryptogram is generated in the purchase cycle and is stored. A second validation cryptogram is generated in the validation cycle at the venue. If the second validation cryptogram matches the first validation cryptogram, the consumer is granted access. Validation cryptograms may be based on input data that is specific to the payment card holder (e.g., primary account number), specific to the ticket selling merchant (e.g., merchant identifier), specific to the event (e.g., event identifier, date/time, location, etc.), and/or specific to the transaction (e.g., authorization code from a payment network). Based on the input data, validation cryptograms may be generated using encryption, hashing, a combination of encryption and hashing, and/or other operations on the input data.