Account asset protection via an encoded physical mechanism
Abstract
Systems and methods of the present invention provide for one or more server computers communicatively coupled to a network and configured to: receive a request for a physical certificate authenticating a user to transfer a domain name, as well as a domain name and domain name transfer instructions; print the physical certificate, including a QR code encoding a user id, the domain name, an EPP key and the transfer instructions; lock the domain name account against modification; receive a request to execute a domain name transfer; scan the user id, the domain name, the EPP key and the transfer instructions encoded within the QR code; unlock an administrative function of the account; authenticate, via the EPP key, the domain name transfer; and execute the domain name transfer.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1 . A system, comprising at least one processor executing instructions on a server computer coupled to a network, the server computer being configured to:
receive a first transmission from a website control panel encoding a request for a physical certificate authenticating a user to transfer a domain name, the first transmission further encoding a user identification and a domain name identification; print the physical certificate, the physical certificate including the user identification, the domain name identification, and a security key; programmatically lock an account for the domain name against modification; receive a scanned data from a scanning device, the scanned data comprising the user identification, the domain name identification, and the security key; and programmatically unlock at least one administrative function of the account.
2 . The system of claim 1 , wherein the server computer is configured to:
set an EPP key to a random value; and encrypt, using a key pair, the user identification, the domain name identification, and the EPP key to generate the security key.
3 . The system of claim 1 , wherein the server computer is configured to:
store, within a database coupled to the network in association with the user identification, at least one data record comprising a user contact; receive a second transmission from the website control panel encoding a request to execute a transfer of the domain name; and responsive to receiving the second transmission, transmit, to the user contact, a request for the physical certificate.
4 . The system of claim 1 , wherein the user identification, the domain name identification, and the security key are stored on:
a USB drive; or a cell phone.
5 . The system of claim 1 , wherein the security key is not stored on the server computer.
6 . A system, comprising at least one processor executing instructions on a server computer coupled to a network, wherein the server computer is configured to:
receive a first transmission encoding a request for a physical mechanism authenticating a user to update an electronic asset, the first transmission further encoding a user identification, and an electronic asset identification; generate the physical mechanism, and affixed to, or stored on, the physical mechanism, a block of data encoding the user identification, the electronic asset identification, and a change key; and programmatically lock an account for the electronic asset against modification of the electronic asset.
7 . The system of claim 6 , wherein the server computer is configured to:
receive a second transmission encoding a request to execute electronic transaction instructions; receive a data entry including at least a portion of the block of data from the physical mechanism, the data entry including the user identification, the electronic asset identification, and the change key; programmatically unlock at least one administrative function of the account; authenticate a transaction for the electronic asset using the change key; and execute the electronic transaction instructions.
8 . The system of claim 7 , wherein the server computer is configured to:
store, within a database coupled to the network in association with the user identification and the electronic asset identification, at least one data record comprising the electronic transaction instructions; and responsive to receiving the second transmission, verify that the at least one data record matches the electronic transaction instructions.
9 . The system of claim 7 , wherein the server computer is configured to:
store, within a database coupled to the network in association with the user identification, at least one data record comprising a user contact; and responsive to receiving the second transmission, transmit, to the user contact, a request for the physical mechanism.
10 . The system of claim 6 , wherein the server computer is configured to:
set the change key to a random value; and encrypt the block of data using a key pair.
11 . The system of claim 6 , wherein the physical mechanism comprises:
a printed certificate; or a USB drive; or a cell phone.
12 . The system of claim 6 , wherein the change key comprises an EPP key not stored on the server computer.
13 . The system of claim 6 , wherein the block of data is encoded into a machine readable optical label and is affixed to or stored within the physical mechanism.
14 . A method, comprising:
receiving a first transmission encoding a request for a physical mechanism authenticating a user to update an electronic asset, the first transmission further encoding a user identification, and an electronic asset identification; generating the physical mechanism, and affixed to, or stored on, the physical mechanism, a block of data encoding the user identification, the electronic asset identification, and a change key; and programmatically locking an account for the electronic asset against modification of the electronic asset.
15 . The method of claim 14 , further comprising:
receiving a second transmission encoding a request to execute electronic transaction instructions; receiving a data entry including at least a portion of the block of data from the physical mechanism, the data entry including the user identification, the electronic asset identification, and the change key; programmatically unlocking at least one administrative function of the account; authenticating a transaction for the electronic asset using the change key; and executing the electronic transaction instructions.
16 . The method of claim 15 , further comprising:
storing, within a database coupled to a network in association with the user identification and the electronic asset identification, at least one data record comprising the electronic transaction instructions; and responsive to receiving the second transmission, verifying that the at least one data record matches the electronic transaction instructions.
17 . The method of claim 15 , further comprising:
storing, within a database coupled to a network in association with the user identification, at least one data record comprising a user contact; and responsive to receiving the second transmission, transmitting, to the user contact, a request for the physical mechanism.
18 . The method of claim 14 , further comprising:
setting the change key to a random value; and encrypting the block of data using a key pair.
19 . The method of claim 14 , further comprising encoding the block of data into a machine readable optical label configured to be affixed to the physical mechanism.Join the waitlist — get patent alerts
Track US2018167202A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.