IP Library Granted Patent US 9,912,653
Granted Patent B2
US 9,912,653 · App. 15/390,265 · Granted Mar 6, 2018

Controlled token distribution to protect against malicious data and resource access

Inventors: Phillip Volini (Beverly Hills, CA); John Raymond Werneke (Naperville, IL); Carl Schumaler (Beverly Hills, CA); Michael Smith (Palentine, IL); Frank Giannantonio (Verona, WI); Vito Iaia (Santa Monica, CA); Sean Moriarty (Pasadena, CA)
Assignee: Live Nation Entertainment, Inc.
H04L63/0807H04L63/08H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,653
App. No.
15/390,265
Granted
Mar 6, 2018
Kind
B2
Abstract

Techniques are described for controlling data and resource access. For example, methods and systems can facilitate controlled token distribution across systems and token processing in a manner so as to limit access to and to protect data that includes access codes.

Claims (75)

1. A computer-implemented method for token-based generation of access rights to resources, the method comprising:

receiving, at a first system, a first communication from a second system, the first communication corresponding to a credential of the second system, and the second system corresponding to an entity;

in response to the receiving, generating, at the first system, a token based on or to correspond with each of the entity and a resource;

transmitting, from the first system, a second communication to the second system at a first time, the second communication including the token;

receiving, at the first system, a third communication from the second system, the third communication corresponding to a notification that the token has been transferred to a data requesting system, and the third communication being received at a second time that is after the first time;

identifying, at the first system, the resource that corresponds to the token based on the received third communication corresponding to the notification;

in response to identifying the resource that corresponds to the token, generating an access-enabling code for the token, the access-enabling code granting the data requesting system access to the resource during a defined time period;

receiving, at the first system, a fourth communication from the data requesting system, the fourth communication corresponding to a request for access to the resource and including the token, the fourth communication being received at a third time that is after the second time; and

determining whether the token corresponds to the access-enabling code, and when the determination indicates that the token corresponds to the access-enabling code, facilitating access to the resource for the data requesting system, the access to the resource for the data requesting system being facilitated using the access-enabling code.

2. The computer-implemented method for token-based generation of access rights to resources, as recited in claim 1 , further comprising:

storing an indication that a status of one or more access-enabling codes provided by a third system are defined as unreliable; and

inhibiting the third system from providing the one or more access-enabling codes based on the stored indication.

3. The computer-implemented method for token-based generation of access rights to resources, as recited in claim 1 , wherein receiving the fourth communication from the data requesting system occurs at a defined spatial area associated with the resource at the second time, wherein the second time is within a threshold time before the defined time period.

4. The computer-implemented method for token-based generation of access rights to resources, as received in claim 1 , further comprising:

in response to receiving the fourth communication, determining whether the token corresponds to the access-enabling code, wherein when the token corresponds to the access-enabling code, determining whether the access-enabling code has been previously retrieved in association with the resource.

5. The computer-implemented method for token-based generation of access rights to resources, as received in claim 1 , wherein facilitating the access to the resource for the data requesting system comprises:

receiving, at the first system, the token;

determining whether the token corresponds to the access-enabling code; and

in response to determining that the token corresponds to the access-enabling code, transmitting the access-enabling code to the data requesting system, wherein the access-enabling code corresponds to a particular defined portion of the defined spatial area.

6. The computer-implemented method for token-based generation of access rights to resources, as received in claim 1 , wherein facilitating the access to the resource for the data requesting system comprises:

receiving, at the first system, the token;

determining whether the token corresponds to the access-enabling code; and

in response to determining that the token corresponds to the access-enabling code, selecting a particular defined portion within the defined spatial area, assigning the particular defined portion to the access-enabling code, and transmitting the access-enabling code to the data requesting system, wherein the access-enabling code corresponds to the particular defined portion of the defined spatial area.

7. The computer-implemented method for token-based generation of access rights to resources, as received in claim 1 , further comprising:

storing, at a data store, an indication indicating how one or more access-enabling codes are to be allocated to at least two different channels, each of the two different channels being associated with a particular system that facilitates assignment of the one or more access-enabling codes.

8. A system for token-based generation of access rights to resources, the system comprising:

one or more data processors; and

a non-transitory computer-readable storage medium containing instructions which, when executed on the one or more data processors, cause the one or more data processors to perform operations including:

receiving, at a first system, a first communication from a second system, the first communication corresponding to a credential of the second system, and the second system corresponding to an entity;

in response to the receiving, generating, at the first system, a token based on or to correspond with each of the entity and a resource;

transmitting, from the first system, a second communication to the second system at a first time, the second communication including the token;

receiving, at the first system, a third communication from the second system, the third communication corresponding to a notification that the token has been transferred to a data requesting system, and the third communication being received at a second time that is after the first time;

identifying, at the first system, the resource that corresponds to the token based on the received third communication corresponding to the notification;

in response to identifying the resource that corresponds to the token, generating an access-enabling code for the token, the access-enabling code granting the data requesting system access to the resource during a defined time period;

receiving, at the first system, a fourth communication from the data requesting system, the fourth communication corresponding to a request for access to the resource and including the token, the fourth communication being received at a third time that is after the second time; and

determining whether the token corresponds to the access-enabling code, and when the determination indicates that the token corresponds to the access-enabling code, facilitating access to the resource for the data requesting system, the access to the resource for the data requesting system being facilitated using the access-enabling code.

9. The system for token-based generation of access rights to resources, as recited in claim 8 , wherein the operations further comprise:

storing an indication that a status of one or more access-enabling codes provided by a third system are defined as unreliable; and

inhibiting the third system from providing the one or more access-enabling codes based on the stored indication.

10. The system for token-based generation of access rights to resources, as recited in claim 8 , wherein receiving the fourth communication from the data requesting system occurs at a defined spatial area associated with the resource at the second time, wherein the second time is within a threshold time before the defined time period.

11. The system for token-based generation of access rights to resources, as recited in claim 8 , wherein the operations further comprise:

in response to receiving the fourth communication, determining whether the token corresponds to the access-enabling code, wherein when the token corresponds to the access-enabling code, determining whether the access-enabling code has been previously retrieved in association with the resource.

12. The system for token-based generation of access rights to resources, as recited in claim 8 , wherein facilitating the access to the resource for the data requesting system comprises:

receiving, at the first system, the token;

determining whether the token corresponds to the access-enabling code; and

in response to determining that the token corresponds to the access-enabling code, transmitting the access-enabling code to the data requesting system, wherein the access-enabling code corresponds to a particular defined portion of the defined spatial area.

13. The system for token-based generation of access rights to resources, as recited in claim 8 , wherein facilitating the access to the resource for the data requesting system comprises:

receiving, at the first system, the token;

determining whether the token corresponds to the access-enabling code; and

in response to determining that the token corresponds to the access-enabling code, selecting a particular defined portion within the defined spatial area, assigning the particular defined portion to the access-enabling code, and transmitting the access-enabling code to the data requesting system, wherein the access-enabling code corresponds to the particular defined portion of the defined spatial area.

14. The system for token-based generation of access rights to resources, as recited in claim 8 , wherein the operations further comprise:

storing, at a data store, an indication indicating how one or more access-enabling codes are to be allocated to at least two different channels, each of the two different channels being associated with a particular system that facilitates assignment of the one or more access-enabling codes.

15. A computer-program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions configured to cause a data processing apparatus to perform operations including:

receiving, at a first system, a first communication from a second system, the first communication corresponding to a credential of the second system, and the second system corresponding to an entity;

in response to the receiving, generating, at the first system, a token based on or to correspond with each of the entity and a resource;

transmitting, from the first system, a second communication to the second system at a first time, the second communication including the token;

receiving, at the first system, a third communication from the second system, the third communication corresponding to a notification that the token has been transferred to a data requesting system, and the third communication being received at a second time that is after the first time;

identifying, at the first system, the resource that corresponds to the token based on the received third communication corresponding to the notification;

in response to identifying the resource that corresponds to the token, generating an access-enabling code for the token, the access-enabling code granting the data requesting system access to the resource during a defined time period;

receiving, at the first system, a fourth communication from the data requesting system, the fourth communication corresponding to a request for access to the resource and including the token, the fourth communication being received at a third time that is after the second time; and

determining whether the token corresponds to the access-enabling code, and when the determination indicates that the token corresponds to the access-enabling code, facilitating access to the resource for the data requesting system, the access to the resource for the data requesting system being facilitated using the access-enabling code.

16. The computer-program product of claim 15 , wherein the operations further comprise:

storing an indication that a status of one or more access-enabling codes provided by a third system are defined as unreliable; and

inhibiting the third system from providing the one or more access-enabling codes based on the stored indication.

17. The computer-program product of claim 15 , wherein receiving the fourth communication from the data requesting system occurs at a defined spatial area associated with the resource at the second time, wherein the second time is within a threshold time before the defined time period.

18. The computer-program product of claim 15 , wherein the operations further comprise:

in response to receiving the fourth communication, determining whether the token corresponds to the access-enabling code, wherein when the token corresponds to the access-enabling code, determining whether the access-enabling code has been previously retrieved in association with the resource.

19. The computer-program product of claim 15 , wherein facilitating the access to the resource for the data requesting system comprises:

receiving, at the first system, the token;

determining whether the token corresponds to the access-enabling code; and

in response to determining that the token corresponds to the access-enabling code, transmitting the access-enabling code to the data requesting system, wherein the access-enabling code corresponds to a particular defined portion of the defined spatial area.

20. The computer-program product of claim 15 , wherein facilitating the access to the resource for the data requesting system comprises:

receiving, at the first system, the token;

determining whether the token corresponds to the access-enabling code; and

in response to determining that the token corresponds to the access-enabling code, selecting a particular defined portion within the defined spatial area, assigning the particular defined portion to the access-enabling code, and transmitting the access-enabling code to the data requesting system, wherein the access-enabling code corresponds to the particular defined portion of the defined spatial area.

Assignments (3)
SECURITY AGREEMENT Recorded Jan 4, 2021
From: LIVE NATION ENTERTAINMENT, INC.; LIVE NATION WORLDWIDE, INC.
To: U.S. BANK NATIONAL ASSOCIATION
Reel/Frame 054891/0552 →
SECURITY AGREEMENT Recorded May 20, 2020
From: LIVE NATION ENTERTAINMENT, INC.; LIVE NATION WORLDWIDE, INC.
To: U.S. BANK NATIONAL ASSOCIATION
Reel/Frame 052718/0016 →
SECURITY AGREEMENT Recorded Oct 17, 2019
From: LIVE NATION ENTERTAINMENT, INC.; LIVE NATION WORLDWIDE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 050754/0505 →
Continuity (11)
Continuation In Part 14973205 · Dec 17, 2015
Continuation In Part 12435972 · May 5, 2009
Continuation In Part 14617765 · Feb 9, 2015
Continuation 14289010 · May 28, 2014
Continuation 13606934 · Sep 7, 2012
Division 13358469 · Jan 25, 2012
Division 12204648 · Sep 4, 2008
Provisional Application 62093828 · Dec 18, 2014
Provisional Application 61050543 · May 5, 2008
Provisional Application 60969884 · Sep 4, 2007
Related Publication 20170111350A1 · Apr 20, 2017