IP Library Granted Patent US 10,372,938
Granted Patent B2
US 10,372,938 · App. 15/182,899 · Granted Aug 6, 2019

Resource protection using tokenized information

Inventor: Steve Kirsch (Palo Alto, CA)
Assignee: Token, Inc.
G06F21/6245H04L63/0823H04L63/102H04W12/08H04L63/068H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,372,938
App. No.
15/182,899
Granted
Aug 6, 2019
Kind
B2
Abstract

A method of using tokens to securely process actions for protected resources may include receiving a request to activate a token associated with a resource with rules governing an action associated with the resource and a signature by a first computer system. The method may also include verifying the signature by the first computer system, and assigning a token identifier to the resource. The method may additionally include receiving the token identifier from a second computer system and a request to perform the action associated with the resource, and determining whether the rules governing the action have been met. The method may further include performing, based on a determination that the one or more rules governing the action have been met, the action associated with the resource.

Claims (65)

1. A method of using tokens to securely process actions for protected resources, the method comprising:

receiving, by a hardware processor at a server, a request to activate a token associated with a resource, wherein the request comprises:

one or more rules governing an action associated with the resource, the one or more rules comprising:

an indication of a computer system that is authorized to request that an action associated with a resource be performed; and

characteristics that are specific to a transaction involving a first computer system and a second computer system; and

a signature by the first computer system;

verifying, at the server, the signature by the first computer system;

assigning, at the server, a token identifier to the resource;

receiving, at the server, and from the second computer system:

the token identifier; and

a request to perform the action associated with the resource;

determining, by the hardware processor at the server, whether the one or more rules governing the action have been met, including verifying that the second computer system comprises the computer system that is authorized to request that the action associated with a resource be performed and verifying that the request to perform the action conforms with the characteristics that are specific to the transaction; and

performing, by the hardware processor at the server, and based on a determination that the one or more rules governing the action have been met, the action associated with the resource.

2. The method of claim 1 , wherein the request to activate the token further comprises the token identifier.

3. The method of claim 1 , wherein the token comprises an output numerical string.

4. The method of claim 1 , wherein the request to activate the token further comprises one or more actions that may be performed using the resource.

5. The method of claim 1 , wherein the request to activate the token further comprises a public signature associated with the second computer system.

6. The method of claim 1 , further comprising generating, by the server, the token identifier in response to receiving the request to activate the token.

7. The method of claim 1 , further comprising storing, at the server, the token identifier, a reference to the resource, and the one or more rules governing the action associated with the resource as an entry in a data structure.

8. A non-transitory, computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, at a server, a request to activate a token associated with a resource, wherein the request comprises:

one or more rules governing an action associated with the resource, the one or more rules comprising;

an indication of a computer system that is authorized to request that an action associated with a resource be performed; and

characteristics that are specific to a transaction involving a first computer system and a second computer system; and

a signature by the first computer system;

verifying, at the server, the signature by the first computer system;

assigning, at the server, a token identifier to the resource;

receiving, at the server, and from the second computer system:

the token identifier; and

a request to perform the action associated with the resource;

determining whether the one or more rules governing the action have been met, including verifying that the second computer system comprises the computer system that is authorized to request that the action associated with a resource be performed and verifying that the request to perform the action conforms with the characteristics that are specific to the transaction; and

performing, by the server, and based on a determination that the one or more rules governing the action have been met, the action associated with the resource.

9. The non-transitory, computer-readable medium according to claim 8 , comprising additional instructions that cause the one or more processors to perform additional operations comprising:

sending, by the server, the token identifier to the first computer system and not the second computer system.

10. The non-transitory, computer-readable medium according to claim 8 , comprising additional instructions that cause the one or more processors to perform additional operations comprising:

sending, by the server, the token identifier to the second computer system and not the first computer system.

11. The non-transitory, computer-readable medium according to claim 8 , comprising additional instructions that cause the one or more processors to perform additional operations comprising:

receiving, at the server, and from a second computer system, a signature by the second computer system; and

verifying, at the server, the signature by the second computer system.

12. The non-transitory, computer-readable medium according to claim 8 , wherein the resource comprises personal information of a user of the first computer system.

13. The non-transitory, computer-readable medium according to claim 8 , wherein the resource comprises a physical asset owned by a user of the first computer system.

14. The non-transitory, computer-readable medium according to claim 8 , wherein the one or more rules comprises a limitation on the an amount of the resource that may be affected by the action.

15. A system comprising:

one or more processors; and

one or more memory devices comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, at a server, a request to activate a token associated with a resource, wherein the request comprises:

one or more rules governing an action associated with the resource, the one or more rules comprising:

an indication of a computer system that is authorized to request that an action associated with a resource be performed; and

characteristics that are specific to a transaction involving a first computer system and a second computer system; and

a signature by the first computer system;

verifying, at the server, the signature by the first computer system;

assigning, at the server, a token identifier to the resource;

receiving, at the server, and from the second computer system:

the token identifier; and

a request to perform the action associated with the resource;

determining whether the one or more rules governing the action have been met, including verifying that the second computer system comprises the computer system that is authorized to request that the action associated with a resource be performed and verifying that the request to perform the action conforms with the characteristics that are specific to the transaction; and

performing, by the server, and based on a determination that the one or more rules governing the action have been met, the action associated with the resource.

16. The system of claim 15 wherein the one or more rules comprises a time window during which the action may be performed.

17. The system of claim 15 wherein the action associated with the resource comprises verifying that information provided by the second computer system about the resource is correct.

18. The system of claim 15 wherein the action associated with the resource comprises transferring at least a portion of the resource to a third computer system.

19. The system of claim 15 wherein the action associated with the resource comprises transmitting at least a portion of the resource to the second computer system.

20. The system of claim 15 , wherein the one or more memory devices further comprise additional instructions that cause the one or more processors to perform additional operations comprising:

determining that at least one of the one or more rules comprises a callout function with a web address;

sending the callout function to the web address; and

receiving a determination of whether the action can be performed from the web address.

Assignments (2)
SECURITY INTEREST Recorded Aug 5, 2026
From: TOKEN, INC.
To: HSBC INNOVATION BANK LIMITED
Reel/Frame 075539/0591 →
SECURITY INTEREST Recorded Oct 29, 2019
From: TOKEN, INC.
To: COLUMBIA LAKE PARTNERS GROWTH LENDING I (LUXCO) S.À.R.L.
Reel/Frame 050854/0821 →
Continuity (4)
Provisional Application 62309310 · Mar 16, 2016
Provisional Application 62234552 · Sep 29, 2015
Provisional Application 62175862 · Jun 15, 2015
Related Publication 20160294879A1 · Oct 6, 2016