US2021295335A1PendingUtilityA1
Secure access-based resource delegation
Est. expiryMar 31, 2037(~10.7 yrs left)· nominal 20-yr term from priority
G06Q 20/38215G06Q 20/385G06Q 20/405G06Q 20/3274H04W 12/77G06Q 20/3276G06Q 20/389H04W 12/084H04L 63/10H04W 12/082G06Q 20/32
48
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A secure token defines use-based access restrictions to a first user resource. The secure token is delegated to a second user. The second user redeems the secure token for access to the first user's resource. The access during redemption is constrained by the use-based access restrictions defined by the first user.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A method, comprising:
receiving restrictions defined on a resource from a first user; identifying a second user from the restrictions; creating a token that comprises the restrictions; encoding the token in a barcode format; and delivering the token to the first user for delegation by the first user to the second user, wherein when the second user presents the token in the barcoded format, the second user is granted access to the resource associated with the first user, wherein access is controlled by the restrictions defined in the token.
3 . The method of claim 2 further comprising, obtaining audit information when the second user gains access to the resource by presenting the token and maintaining the audit information as verifiable tracking information for at least the first user.
4 . The method of claim 2 further comprising:
receiving second restrictions defined on the resource from the second user;
identifying a third user from the second restrictions;
creating a second token that comprises the restrictions and the second restrictions;
encoding the second token in the barcode format; and
delivering the second token to the second user for delegation by the second user to the third user, wherein when the third user presents the second token in the barcoded format, the third user is granted access to the resource associated with the first user, wherein access is controlled by the restrictions and the second restrictions defined in the second token.
5 . The method of claim 2 further comprising:
at a time prior to the second user presenting the token for access to the resource:
receiving modifications to the restrictions from the first user;
identifying the second user from modified restrictions associated with the modifications;
creating a modified token that comprises the modified restrictions;
encoding the modified token in the barcode format; and
delivering the modified token to the first user for delegation by the first user to the second user, wherein the token with the restrictions is replaced by the modified token.
6 . The method of claim 2 further comprising:
at a time prior to the second user presenting the token for access to the resource:
receiving a revocation to the token from the first user; and
invalidating the token for access to the resource based on the revocation.
7 . The method of claim 2 , wherein receiving further includes identifying a portion of the restrictions as authentication instructions to a redeeming party, wherein the redeeming party performs authentication of the second user using the authentication instructions when the second user presents the token to the redeeming party for access to the resource.
8 . The method of claim 2 , wherein receiving further includes identifying a portion of the restrictions as location-based restrictions on where the second user is permitted to redeem the token for access to the resource.
9 . The method of claim 2 , wherein receiving further includes identifying a portion of the restrictions as category-based restrictions on a category of enterprises that the second user is permitted to redeem the token for access to the resource.
10 . The method of claim 2 , wherein receiving further includes identifying a portion of the restrictions as date and time-of-day restrictions on a calendar date and time-of-day that the second user is permitted to redeem the token for access to the resource.
11 . The method of claim 2 , wherein receiving further includes identifying the resource as a bank account of the first user.
12 . The method of claim 11 , wherein receiving further includes identifying a portion of the restrictions as a predefined amount of money that the second user is permitted to withdraw from the back account of the first user.
13 . The method of claim 2 , wherein receiving further includes identifying the resource as a credit card account of the first user.
14 . A method, comprising:
obtaining a token from a device operated by a user; decoding the token and identifying a second user, an account of the second user, and restrictions placed on the user redeeming the token for access to the account of the second user; and redeeming the token during a transaction with the utilizing the account of the second user based on the restrictions.
15 . The method of claim 14 , wherein obtaining further includes obtaining the token as an image captured from a display of the device.
16 . The method of claim 14 , wherein obtaining further includes obtaining the token as information provided from the device when the device is tapped against a Near Field Communication (NFC) enabled device during the transaction.
17 . The method of claim 14 , wherein decoding further includes identifying authentication instructions for authenticating the user from the restrictions and obtaining authentication information from the user in accordance with the authentication instructions.
18 . The method of claim 14 further comprising, processing the method and the transaction on a Self-Service Terminal (SST).
19 . The method of claim 18 , wherein processing further includes processing the transaction as a self-checkout of the user at the SST for items being purchased by the user using the account of the second user as payment or processing the transaction as a cash withdraw from the account of the second user at the SST.
20 . A terminal, comprising:
a processor; a non-transitory computer-readable storage medium that comprises executable instructions; and the executable instructions when executed by the processor from the non-transitory computer-readable storage medium cause the processor to perform operations comprising:
obtaining a token from a device operated by a user;
decoding the token and identifying a second user, an account of the second user, and restrictions placed by the second user on the user when redeeming the token during a transaction being performed at the terminal for using the account of the second user for the transaction; and
performing the transaction using the account of the second user in accordance with the restrictions.
21 . The terminal of claim 21 , wherein the terminal is a Self-Service Terminal (SST), an Automated Teller Machine (ATM), or a Point-Of-Sale (POS) terminal operated by a clerk during the transaction.Join the waitlist — get patent alerts
Track US2021295335A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.