Event access with data field encryption for validation and access control
Abstract
The utility of a portable consumer device is extended by allowing account holders the ability to gain entry into access-controlled venues (e.g., baseball or soccer game, cinema, public transit) using a portable consumer device that is associated with an account that was used to purchase the admission or tickets to the event at the access-controlled venue. Techniques disclosed allow cardholder authentication in a non-payment setting that enables cardholders access to a location or a specific event. A first validation cryptogram is generated in the purchase cycle and is stored. A second validation cryptogram is generated in the validation cycle at the venue. If the second validation cryptogram matches the first validation cryptogram, the consumer is granted access. Validation cryptograms may be based on input data that is specific to the payment card holder (e.g., primary account number), specific to the ticket selling merchant (e.g., merchant identifier), specific to the event (e.g., event identifier, date/time, location, etc.), and/or specific to the transaction (e.g., authorization code from a payment network). Based on the input data, validation cryptograms may be generated using encryption, hashing, a combination of encryption and hashing, and/or other operations on the input data.
Claims
exact text as granted — not AI-modified1 .- 30 . (canceled)
31 . A method comprising:
receiving, at a point of validation terminal, account information associated with a portable consumer device of a user seeking to access an access controlled event; generating, by a processor provided in communication with the point of validation terminal, a validation cryptogram; accessing, by the processor provided in communication with the point of validation terminal, a validation cryptogram database that includes a plurality of stored validation cryptograms that were previously generated when users purchased permission to access the access controlled event; verifying, by the processor provided in communication with the point of validation terminal, that the generated validation cryptogram matches one of a plurality of stored validation cryptograms that was previously generated when the user purchased permission to access the access controlled event; and opening a physical barrier to permit, by the point of validation terminal, the user to access the access controlled event only after the generated validation cryptogram is verified to match one of the stored validation cryptograms.
32 . The method of claim 31 , wherein the validation cryptogram and the stored validation cryptograms are generated using a cryptogram generator that includes an encryption module for encrypting data in accordance with the Data Encryption Standard (DES).
33 . The method of claim 31 , wherein the portable consumer device is a credit or debit card with a magnetic stripe.
34 . The method of claim 31 , wherein the point of validation terminal comprises a payment card reader.
35 . The method of claim 31 , wherein a display on the point of validation terminal is configured to display an access permissions message.
36 . The method of claim 35 , wherein the display is further configured to display seating information.
37 . The method of claim 31 , wherein the processor provided in communication with the point of validation terminal is contained in a server separate from the point of validation terminal.
38 . The method of claim 37 , wherein the server is located at a venue where the access controlled event occurs.
39 . The method of claim 31 , wherein the processor provided in communication with the point of validation terminal is contained in the point of validation terminal.
40 . The method of claim 31 , wherein the processor provided in communication with the point of validation terminal transmits to the point of validation terminal an access permissions message if the validation cryptogram is determined to be acceptable.
41 . A point of validation terminal comprising:
a processor; a physical barrier; and a non-transitory computer-readable medium coupled to the processor, including code that is executable by the processor, for implementing a method comprising: receiving account information associated with a portable consumer device of a user seeking to access an access controlled event; generating, by the processor, a validation cryptogram; accessing a validation cryptogram database that includes a plurality of stored validation cryptograms that were previously generated when users purchased permission to access the access controlled event; verifying that the generated validation cryptogram matches one of a plurality of stored validation cryptograms that was previously generated when the user purchased permission to access the access controlled event; and opening the physical barrier to permit the user to access the access controlled event only after the generated validation cryptogram is verified to match one of the stored validation cryptograms.
42 . The point of validation terminal of claim 41 , wherein the generating of the validation cryptogram includes sending the account information associated with the portable consumer device to a remote validation server or a venue validation server.
43 . The point of validation terminal of claim 41 , wherein the generating of the validation cryptogram includes encrypting the account information and event-specific data.
44 . The point of validation terminal of claim 41 , wherein accessing the validation cryptogram database and verifying the generated validation cryptogram includes communicating with a venue validation server or a remote validation server.
45 . The point of validation terminal of claim 41 wherein the validation cryptogram database is coupled to the processor.
46 . The point of validation terminal of claim 41 , wherein the physical barrier is a turnstile.
47 . The point of validation terminal of claim 41 further comprising:
a printer unit coupled to the processor, wherein the printer unit is configured to print seating information.
48 . A system comprising:
one or more processors, and one or more non-transitory computer readable media, the non-transitory computer readable media comprising code, executable by the processor, to implement a method comprising: receiving account information associated with a portable consumer device of a user seeking to access an access controlled event; generating, by the one or more processors, a validation cryptogram; accessing, by the one or more processors, a validation cryptogram database that includes a plurality of stored validation cryptograms that were previously generated when users purchased permission to access the access controlled event; verifying, by the one or more processors, that the generated validation cryptogram matches one of a plurality of stored validation cryptograms that was previously generated when the user purchased permission to access the access controlled event; and opening a physical barrier to permit the user to access the access controlled event only after the generated validation cryptogram is verified to match one of the stored validation cryptograms.
49 . The system of claim 48 , further comprising:
a point of validation terminal which contains the one or more processors.
50 . The system of claim 49 , further comprising:
a validation server, wherein the one or more processors are contained within the point of validation terminal and the validation server.Join the waitlist — get patent alerts
Track US2020151717A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.