METHODS AND APPARATUS FOR AUTHORIZING AND PROVIDING OF GOODS
A method includes broadcasting with a transceiver of a reader device of a transaction system a first identifier to a smart device, receiving with the transceiver an ephemeral ID not permanently associated with a user of the smart device from the smart device, providing with the transceiver of a second identifier and a unique data packet to the smart device, receiving with the transceiver a token determined by an authentication server in response to the second identifier and the unique data packet from the smart device, wherein the token comprises a payload portion, determining with a processor of the reader device whether the token is valid, and directing with the processor the transaction system to perform a user-perceptible action for the user, that authorizes the user to enter or exit a location associated with the transaction system in response to determining the token to be valid.
1 . A method for a system comprising:
broadcasting with a first short-range transceiver of a reader device associated with transaction system to a smart device, a first identifier;
receiving with the first short-range transceiver of the reader device from the smart device, an ephemeral ID, wherein the ephemeral ID is not permanently associated with a user of the smart device;
providing with the first short-range transceiver of the reader device to the smart device, a second identifier and a unique data packet;
receiving with the first short-range transceiver of the reader device from the smart device a token, wherein the token is determined by an authentication server in response to the second identifier and the unique data packet, and wherein the token comprises a payload portion;
determining with a processor of the reader device whether the token is valid; and
directing with the processor of the reader device the transaction system to perform a user-perceptible action for the user, that authorizes the user to enter or exit a location associated with the transaction system in response to determining the token to be valid.
2 . The method of claim 1 wherein the user-perceptible action is selected from a group consisting of: opening a gate, unlatching a turnstile, displaying an image, playing audio data, unlatching a door, delivering a good, deactivating an alarm, and printing a receipt.
3 . The method of claim 1
wherein the payload portion comprises financial data associated with the user;
wherein the method further comprising:
determining with the processor of the reader device a transaction amount;
requesting with the processor of the reader device that the transaction amount and the financial account associated with the user are recorded; and
receiving with the processor of the reader device an indication that transaction amount and the financial account associated with the user are recorded; and
wherein the directing with the processor of the reader device the transaction system to perform the user-perceptible action for the user authorizing the user to enter or exit the location with the reader device is also in response to receiving the indication that the transaction amount and the financial account are recorded.
4 . The method of claim 1
wherein the payload portion comprises financial data associated with the user;
wherein the method further comprising:
providing with a first wide-area transceiver the financial data associated with the user and data associated with the reader device to a financial server associated with the financial data; and
receiving with the first wide-area transceiver of the reader device from the financial server an indication that the financial data associated with the user and the data associated with the reader device are recorded; and
wherein the directing with the processor of the reader device the transaction system to perform the user-perceptible action for the user is also in response to receiving the indication that financial data and the data associated with the reader are recorded.
5 . The method of claim 1 wherein the unique data packet is selected from a group consisting: a pseudorandom number, a nonce, a random number, and a time stamp.
6 . The method of claim 1
wherein the directing with the processor of the reader device the peripheral device to perform the user-perceptible action comprises directing with the processor of the reader device the peripheral device to perform the user-perceptible action for the user, authorizing the user to enter the location associated with the reader device in response to determining the token to be valid; and
wherein the method further comprises:
broadcasting with the first short-range transceiver of the reader device associated with the point of sale (transaction) system to the smart device, the first identifier;
receiving with the first short-range transceiver of the reader device from the smart device, the ephemeral ID, wherein the ephemeral ID is not permanently associated with the user of the smart device;
providing with the first short-range transceiver of the reader device to the smart device, the second identifier and another unique data packet;
receiving with the first short-range transceiver of the reader device from the smart device another token, wherein the other token is determined by the authentication server in response to the second identifier and the other unique data packet, and wherein the other token comprises another payload portion;
determining with the processor of the reader device whether the other token is valid; and
directing with the processor of the reader device the transaction system to perform another user-perceptible action for the user, that authorizes the user to exit the location associated with the transaction system in response to determining the other token to be valid.
7 . The method of claim 1 further comprising:
capturing with a first biometric sensor of the reader device biometric data associated with the user;
forming with the processor of the reader device secure biometric data in response to the biometric data;
providing with the first short-range transceiver of the reader device to the smart device, the secure biometric data; and
wherein the token is determined by the authentication server in response to the second identifier, the unique data packet, and the secure biometric data.
8 . A system comprising:
a transaction system configured to perform a user-perceptible action; and
a reader device having a first-short range transceiver coupled to the transaction system, wherein the first short-range transceiver is configured to output a first identifier to a smart device, wherein the first short-range transceiver is configured to receive an ephemeral ID from the smart device, wherein the ephemeral ID is not permanently associated with a user of the smart device, wherein the first short-range transceiver is configured to output a second identifier and a unique data packet to the smart device, wherein the first short-range transceiver is configured to receive a token from the smart device, wherein the token is determined by an authentication server in response to the second identifier and the unique data packet, and wherein the token comprises a payload portion comprising transaction data, wherein a processor of the reader device is configured determine whether the token is valid, wherein the processor of the reader device is configured determine whether the transaction data indicates a success condition, wherein the processor of the reader device is configured to direct the transaction system to perform the user-perceptible action for the user in response to determining that the token is valid and the transaction data indicates the success condition.
9 . The system of claim 8 wherein the user-perceptible action is selected from a group consisting of: opening a gate, unlatching a turnstile, displaying an image, playing audio data, unlatching a door, delivering a good, deactivating an alarm, unlocking a lockbox, and printing a receipt.
10 . The system of claim 8
wherein the payload portion also comprises financial data associated with the user;
wherein the processor of the reader device is configured to receive a transaction amount from the transaction system;
wherein requesting with the processor of the reader device that the transaction amount and the financial account associated with the user are recorded; and
receiving with the processor of the reader device an indication that transaction amount and the financial account associated with the user are recorded; and
wherein the directing with the processor of the reader device the transaction system to perform the user-perceptible action for the user authorizing the user to enter or exit the location with the reader device is also in response to receiving the indication that the transaction amount and the financial account are recorded.
11 . The system of claim 8 further comprising
a biometric sensor coupled to the reader device, wherein the biometric sensor is configured to capture biometric data associated with the user;
wherein the processor of the reader device is configured to determine secured biometric data in response to the biometric data;
wherein the first short-range transceiver is configured to send the secured biometric data to the smart device; and
wherein the token is determined by the authentication server in response to the second identifier, the unique data packet, and to the secured biometric data.
12 . The system of claim 8 further comprising the authentication system coupled to the reader device via the smart device, wherein the authentication system is configured to receive the second identifier, the unique data packet, a transaction amount, an identifier associated with the user, and user financial data, wherein the authentication system is configured to transmit the transaction amount, and the user financial data to a transaction server, and wherein the authentication system is configured to receive a financial authorization from the transaction server, and wherein the authentication server is configured to determine the token also in response to the financial authorization.
13 . The system of claim 12 wherein the transaction system is configured to provide the transaction amount to the authentication system.
14 . The system of claim 12
wherein the user financial data comprises encrypted user account data;
wherein the authentication system is configured to receive user account data from the smart device; and
wherein the authentication system is configured to determine the encrypted user account information in response to the user account data.
15 . A method for a system comprising:
broadcasting with a first short-range transceiver of a reader device associated with transaction system a first identifier to a smart device;
receiving with the first short-range transceiver of the reader device an ephemeral ID from the smart device, wherein the ephemeral ID is not permanently associated with a user of the smart device;
providing with the first short-range transceiver of the reader device transaction data comprising a second identifier and a unique data packet to the smart device;
receiving from a second transceiver of the authentication server the transaction data, a transaction amount and a user identifier from the smart device;
determining with a first processor in the authentication server a financial server associated with the user in response to the user identifier;
determining with the first processor in the authentication server user financial data in response to the user identifier;
providing with a third transceiver of the authentication server, the user financial data and the transaction amount to the financial server;
receiving with the third transceiver a response from the financial server in response to the user financial data and the transaction amount, wherein the response comprises an approved condition or an unapproved condition;
determining with the first processor a token in response to the response and the transaction data;
providing with the second transceiver the token to the smart device;
receiving with the first transceiver the token from the smart device;
determining with a second processor of the reader device whether the token is authentic;
determining with a second processor of the reader device whether the response is the approved condition; and
directing with the second processor a peripheral device to perform a user-perceptible action in response to determining the token is authentic and in response to the determining the response is the approved condition.
16 . The method of claim 15 wherein the user-perceptible action is selected from a group consisting of: opening a gate, unlatching a turnstile, displaying an image, playing audio data, unlatching a door, delivering a good, deactivating an alarm, activating a vending machine, vending a product and printing a receipt.
17 . The method of claim 15 further comprising:
capturing with a first biometric sensor of the reader device biometric data associated with the user;
forming with the second processor secure biometric data in response to the biometric data;
providing with the first short-range transceiver of the reader device to the smart device, the secure biometric data.
18 . The method of claim 17 further comprising:
receiving in the second transceiver the secure biometric data from the smart device;
determining in the first processor stored biometric data in response to the user identifier;
determining a match condition when the stored biometric data matches the secure biometric data; and
wherein the token is also determined in response to the response, the transaction data and to the match condition.
19 . The method of claim 17 wherein the biometric data is selected from a group consisting of: facial data, print data, finger print data, palm print data, iris data, motion data, audio data, and user performance data.
20 . The method of claim 15 further comprising the transaction server determining a transaction amount.