IP Library › Granted Patent US 12,265,957
Granted Patent B2
US 12,265,957 · App. 17/893,370 · Granted Apr 1, 2025

Methods and systems for pre-validating token-based access control

Inventors: Brent Marshall (Kitchener, CA); Nicole Sandford (Kitchener, CA)
Assignee: Shopify Inc.
G06Q20/367G06Q20/3278G06Q20/38215G06Q20/3825H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,957
App. No.
17/893,370
Granted
Apr 1, 2025
Kind
B2
Abstract

Methods and systems for blockchain token-based access control in which an access control rule sets an access condition that is satisfied if a wallet address holds one or more specified non-fungible tokens or tokens having specified attributes. To conduct in-person or on-location token-based gating, the system may employ pre-authentication of a wallet address. An identifier may be stored securely on both the system and a user device following pre-authentication. When seeking access, a user device provides identification data generated based on the identifier and the system verifies that the identification data was generated based on the identifier and, on that basis, retrieves a pre-authenticated wallet address. It then verifies using blockchain data that the wallet address holds the requisite token or tokens to satisfy the access condition.

Claims (57)

1. A computer-implemented method, comprising:

during a pre-authentication stage during a session with a user device,

receiving, from the user device, at a computing system, a digital signature and a wallet address;

validating the digital signature to authenticate the wallet address and, based on validation, storing, at the computing system, the wallet address in association with an identifier, wherein the identifier is also stored on the user device;

after the session terminates and during an on-location access stage,

receiving, at an on-location computing device coupled to the computing system, from the user device, over short-range, an access request including identification data, the identification data purporting to be based on the identifier, wherein the identification data is generated by the user device using the identifier and a nonce;

confirming that the identification data is based on the identifier by independently generating the nonce,

hashing the nonce together with the identifier stored in association with the wallet address to obtain a hash result, and

confirming that the hash result matches the identification data received;

responsive to confirming that the identification data is based on the identifier, retrieving the wallet address associated with the identifier;

determining, based on blockchain data from a blockchain network, that the wallet address is associated with one or more tokens and that the one or more tokens satisfy an access condition associated with the access request; and

responsive to determining that the wallet address is associated with the one or more tokens and that the one or more tokens satisfy the access condition associated with the access request, performing an action.

2. The method of claim 1 , wherein the access request is received from the user device via a short-range communication module in the on-location computing device coupled to the computing system.

3. The method of claim 2 , wherein performing an action includes outputting a success signal at the on-location computing device coupled to the computing system.

4. The method of claim 3 , wherein outputting includes outputting an audio-visual signal on the on-location computing device.

5. The method of claim 1 , wherein the on-location computing device includes a scanning device and wherein the identification data includes a hash of the identifier.

6. The method of claim 5 , wherein the scanning device includes an optical scanning device configured to obtain a QR code displayed on the user device, wherein the QR code encodes the identification data.

7. The method of claim 1 , wherein the nonce is time-based.

8. The method of claim 1 , wherein storing includes storing the wallet address and the identifier in association with a user identifier, wherein receiving the access request further includes receiving the user identifier, and wherein confirming further includes retrieving the identifier from memory based on the user identifier.

9. The method of claim 8 , wherein the user identifier includes a device identifier or a user account identifier for a user account on the computing system.

10. The method of claim 9 , wherein the computing system is an e-commerce system, the user identifier is the user account identifier for the user account on the e-commerce system, and wherein the user account identifier is associated with an e-commerce application on the user device.

11. The method of claim 1 , wherein the on-location computing device includes an image sensor and receiving includes detecting a machine-readable code displayed on a display screen of the user device.

12. The method of claim 11 , wherein the on-location computing device is one of an automated turnstile, a handheld scanning device, a smartphone, a tablet, or a point-of-sale device.

13. The method of claim 1 , wherein the access request includes a request to obtain a limited access item or a request to enter a limited access event.

14. A computing system, comprising:

one or more processing units;

one or more data storage units; and

memory storing processor-executable instructions that, when executed by the one or more processing units, are to cause the processing units to:

during a pre-authentication stage during a session with a user device,

receive, from the user device, at the computing system, a digital signature and a wallet address;

validate the digital signature to authenticate the wallet address and, based on validation, store the wallet address in association with an identifier,

wherein the identifier is also stored on the user device;

after the session terminates and during an on-location access stage,

receive, at an on-location computing device coupled to the computing system, from the user device, over short-range, an access request including identification data, the identification data purporting to be based on the identifier, wherein the identification data is generated by the user device using the identifier and a nonce;

confirm that the identification data is based on the identifier by independently generating the nonce,

hashing the nonce together with the identifier stored in association with the wallet address to obtain a hash result, and

confirming that the hash result matches the identification data received;

responsive to confirming that the identification data is based on the identifier, retrieve the wallet address associated with the identifier;

determine, based on blockchain data from a blockchain network, that the wallet address is associated with one or more tokens and that the one or more tokens satisfy an access condition associated with the access request; and

responsive to determining that the wallet address is associated with the one or more tokens and that the one or more tokens satisfy the access condition associated with the access request, perform an action.

15. The computing system of claim 14 , wherein the access request is received from the user device via a short-range communication module in the on-location computing device coupled to the computing system.

16. The computing system of claim 14 , wherein the on-location computing device includes an image sensor, and wherein the instructions, when executed, are to cause the one or more processing units to receive the access request by detecting a machine-readable code displayed on a display screen of the user device.

17. The computing system of claim 14 , wherein the instructions, when executed, are to cause the one or more processing units to store the wallet address and the identifier in association with a user identifier, and wherein the instructions, when executed, are to cause the one or more processing units to receive the access request by further receiving the user identifier and to retrieve the identifier from memory based on the user identifier.

18. A non-transitory computer-readable media storing processor-executable instructions, wherein the instructions, when executed, are to cause one or more processing units to:

during a pre-authentication stage during a session with a user device,

receive, from the user device, at a computing system, a digital signature and a wallet address;

validate the digital signature to authenticate the wallet address and, based on validation, store the wallet address in association with an identifier, wherein the identifier is also stored on the user device;

after the session terminates and during an on-location access stage,

receive, at an on-location computing device coupled to the computing system, from the user device, over short-range, an access request including identification data, the identification data purporting to be based on the identifier, wherein the identification data is generated by the user device using the identifier and a nonce;

confirm that the identification data is based on the identifier by independently generating the nonce,

hashing the nonce together with the identifier stored in association with the wallet address to obtain a hash result, and

confirming that the hash result matches the identification data received;

responsive to confirming that the identification data is based on the identifier, retrieve the wallet address associated with the identifier;

determine, based on blockchain data from a blockchain network, that the wallet address is associated with one or more tokens and that the one or more tokens satisfy an access condition associated with the access request; and

responsive to determining that the wallet address is associated with the one or more tokens and that the one or more tokens satisfy the access condition associated with the access request, perform an action.

19. The method claimed in claim 1 , wherein the nonce includes a time step.

20. The method claimed in claim 19 , wherein the time step is valid for a window of time.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2024
From: MARSHALL, BRENT
To: SHOPIFY INC.
Reel/Frame 069445/0038 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2022
From: MARSHALL, BRENT
To: SHOPIFY INC.
Reel/Frame 062102/0941 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2022
From: SANDFORD, NICOLE
To: SHOPIFY INC.
Reel/Frame 061283/0439 →
Continuity (2)
Provisional Application 63358571 · Jul 6, 2022
Related Publication 20240013199A1 · Jan 11, 2024
References Cited (133)
US 6401118B1 · Thomas · 2002 [cited by applicant]
US 10505726B1 · Andon et al. · 2019 [cited by applicant]
US 10929842B1 · Arvanaghi et al. · 2021 [cited by applicant]
US 11062284B1 · Cunningham et al. · 2021 [cited by applicant]
US 11075891B1 · Long · 2021 [cited by applicant]
US 11276014B2 · Augustine et al. · 2022 [cited by applicant]
US 11295363B1 · Kao et al. · 2022 [cited by applicant]
US 11443838B1 · Cordonnier · 2022 [cited by applicant]
US 11455694B2 · Dinunzio et al. · 2022 [cited by applicant]
US 11657428B1 · Ritchie · 2023 [cited by applicant]
US 20050208940A1 · Takase · 2005 [cited by examiner]
US 20070174079A1 · Kraus · 2007 [cited by applicant]
US 20100131386A1 · Shiely et al. · 2010 [cited by applicant]
US 20100235218A1 · Erhart et al. · 2010 [cited by applicant]
US 20130246146A1 · Fischer et al. · 2013 [cited by applicant]
US 20140129422A1 · Zhou · 2014 [cited by examiner]
US 20140351953A1 · Bhatia · 2014 [cited by applicant]
US 20140358629A1 · Shivaswamy et al. · 2014 [cited by applicant]
US 20150186980A1 · Wood · 2015 [cited by applicant]
US 20150249872A1 · Lee et al. · 2015 [cited by applicant]
US 20150324840A1 · Ramnath Krishnan · 2015 [cited by applicant]
US 20150363783A1 · Ronca · 2015 [cited by applicant]
US 20150363858A1 · Kleinhandler et al. · 2015 [cited by applicant]
US 20160171486A1 · Wagner · 2016 [cited by examiner]
US 20160171534A1 · Linden · 2016 [cited by applicant]
US 20160210674A1 · Allen et al. · 2016 [cited by applicant]
US 20160292672A1 · Fay et al. · 2016 [cited by applicant]
US 20170011460A1 · Molinari et al. · 2017 [cited by applicant]
US 20170116693A1 · Rae · 2017 [cited by applicant]
US 20170140408A1 · Wuehler · 2017 [cited by applicant]
US 20170155515A1 · Androulaki et al. · 2017 [cited by applicant]
US 20170221029A1 · Lund et al. · 2017 [cited by applicant]
US 20170330174A1 · Demarinis · 2017 [cited by applicant]
US 20170357966A1 · Chandrasekhar et al. · 2017 [cited by applicant]
US 20180108036A1 · Laufenberg et al. · 2018 [cited by applicant]
US 20180150869A1 · Finnegan · 2018 [cited by applicant]
US 20190066065A1 · Wright et al. · 2019 [cited by applicant]
US 20190073666A1 · Ortiz et al. · 2019 [cited by applicant]
US 20190130439A1 · Handrigan et al. · 2019 [cited by applicant]
US 20190139136A1 · Molinari et al. · 2019 [cited by applicant]
US 20190164157A1 · Balaraman · 2019 [cited by applicant]
US 20190220836A1 · Caldwell · 2019 [cited by applicant]
US 20190220917A1 · Busjaeger · 2019 [cited by applicant]
US 20190266616A1 · Strutton · 2019 [cited by applicant]
US 20190294817A1 · Hennebert · 2019 [cited by examiner]
US 20190303892A1 · Yantis et al. · 2019 [cited by applicant]
US 20190311341A1 · Rice · 2019 [cited by applicant]
US 20200005284A1 · Mjayan · 2020 [cited by applicant]
US 20200112446A1 · Yoshihama · 2020 [cited by applicant]
US 20200134660A1 · Kadaster · 2020 [cited by applicant]
US 20200153607A1 · Shi et al. · 2020 [cited by applicant]
US 20200242105A1 · Rich et al. · 2020 [cited by applicant]
US 20200244752A1 · Trainor · 2020 [cited by applicant]
US 20200272767A1 · Dunjic · 2020 [cited by examiner]
US 20200311724A1 · Dunjic · 2020 [cited by examiner]
US 20200364703A1 · Joveski · 2020 [cited by applicant]
US 20200379981A1 · Yoon · 2020 [cited by applicant]
US 20210014042A1 · Sivathanu · 2021 [cited by applicant]
US 20210027273A1 · Bhuptani · 2021 [cited by examiner]
US 20210124616A1 · Verma · 2021 [cited by applicant]
US 20210241351A1 · Francis et al. · 2021 [cited by applicant]
US 20210243201A1 · Tandel · 2021 [cited by applicant]
US 20210256070A1 · Tran · 2021 [cited by applicant]
US 20210366586A1 · Ryan et al. · 2021 [cited by applicant]
US 20210383334A1 · Krasnyansky · 2021 [cited by applicant]
US 20210390531A1 · Voorhees · 2021 [cited by applicant]
US 20220035936A1 · Lin · 2022 [cited by applicant]
US 20220045869A1 · Skeete · 2022 [cited by examiner]
US 20220058633A1 · Yantis · 2022 [cited by applicant]
US 20220076279A1 · Renaud · 2022 [cited by applicant]
US 20220198418A1 · Kang · 2022 [cited by applicant]
US 20220210061A1 · Simu · 2022 [cited by applicant]
US 20220222364A1 · Roberts · 2022 [cited by applicant]
US 20220292490A1 · Collen · 2022 [cited by applicant]
US 20220318233A1 · Martinez · 2022 [cited by applicant]
US 20220351187A1 · Kim · 2022 [cited by applicant]
US 20220398340A1 · Jakobsson · 2022 [cited by applicant]
US 20230043095A1 · Miliam · 2023 [cited by applicant]
US 20230062776A1 · Vosseller · 2023 [cited by applicant]
US 20230073545A1 · Kurian · 2023 [cited by applicant]
US 20230079195A1 · Matheson · 2023 [cited by applicant]
US 20230086191A1 · Jakobsson · 2023 [cited by applicant]
US 20230195855A1 · Mavromatis · 2023 [cited by applicant]
US 20230206218A1 · Defour · 2023 [cited by applicant]
US 20230306412A1 · Gaur · 2023 [cited by applicant]
US 20230360007A1 · Krishnaswamy · 2023 [cited by examiner]
US 20230360029A1 · Pranger · 2023 [cited by applicant]
US 20240020682A1 · Castagna · 2024 [cited by applicant]
US 20240037593A1 · Navon · 2024 [cited by applicant]
US 20240039722A1 · Deluca · 2024 [cited by applicant]
US 20240046074A1 · Lewis · 2024 [cited by applicant]
CN 110111102 · 2019 [cited by applicant]
CN 110490752 · 2019 [cited by applicant]
CN 108364173 · 2021 [cited by applicant]
CN 109272380 · 2023 [cited by applicant]
EP 3748914 · 2020 [cited by applicant]
EP 4148643A1 · 2023 [cited by applicant]
RU 2018132715A · 2020 [cited by applicant]
TW 1674543 · 2019 [cited by applicant]
WO 2013111142A2 · 2013 [cited by applicant]
WO 2016202952 · 2016 [cited by applicant]
WO 2017197110 · 2017 [cited by applicant]
WO 2020092900 · 2020 [cited by applicant]
WO 2022204404 · 2022 [cited by applicant]
Cruz-Piris; Methodology for massive configuration of OAuth 2.0 tokens; IEEE; pp. 5-12; 2020. [cited by examiner]
Ethelbert; A Json Token-Based Authentication and Access Management; IEEE; pp. 47-53; 2017. [cited by examiner]
Xingxiong Zhu et al.; “Application of Blockchain in Document Certification, Asset Trading and Payment Reconciliation”; Journal of Physics: Conference Series, vol. 1187, Issue 5. [cited by applicant]
European Search Report dated Oct. 10, 2022, EP Application No. 22169579.4. [cited by applicant]
Sep. 10, 2021, XP055966676, Retrieved from the Internet: URL: http://en.wikipedia.org/w/index.php?title=Non-fungible_token&oldid=3593775#Collectibles. [cited by applicant]
US Office Action dated Oct. 17, 2022, U.S. Appl. No. 17/344,251. [cited by applicant]
US Office Action dated Jul. 11, 2023, U.S. Appl. No. 17/475,240. [cited by applicant]
US Office Action dated Mar. 6, 2023, U.S. Appl. No. 17/479,650. [cited by applicant]
US Office Action dated Apr. 21, 2021, U.S. Appl. No. 16/782,561. [cited by applicant]
US Office Action dated Oct. 7, 2021, U.S. Appl. No. 16/782,561. [cited by applicant]
US Office Action dated Jan. 20, 2022, U.S. Appl. No. 16/782,561. [cited by applicant]
US Office Action dated Jul. 26, 2022, U.S. Appl. No. 16/782,561. [cited by applicant]
Office Action dated Nov. 25, 2022, U.S. Appl. No. 16/782,561. [cited by applicant]
Office Action dated Apr. 14, 2023, U.S. Appl. No. 16/782,561. [cited by applicant]
Dialog, Online Searcher, to Be or Not to Be Competitive Intelligence Tools, Aug. 2019. [cited by applicant]
US Office Action dated Jul. 27, 2021, U.S. Appl. No. 16/782,556. [cited by applicant]
US Office Action, U.S. Appl. No. 17/473,284, filed Sep. 21, 2023. [cited by applicant]
USPTO; Office Action relating to U.S. Appl. No. 17/955,631 dated Apr. 15, 2024. [cited by applicant]
Antonopoulos, Andreas; “Mastering Bitcoin Unlocking Digital Cryto-Currencies”, O'Reilly Media, Inc., all pages (Year 2014). [cited by applicant]
G. Gan, E. Chen, Z. Zhou and Y. Zhu, “Token-Based Access Control,” in IEEE Access, vol. 8, pp. 54189-54199, 2020, doi: 10.1109 /ACCESS.2020.2979746. (Year: 2020). [cited by applicant]
Rafati et al., “DeTi: A Decentralized Ticketing Management Platform,” J Netw Syst Manage, 2022, 30(4):62. doi: 10.1007/s10922-022-09675-3. Epub Jul. 26, 2022. PMCID: PMC9315850. (Year: 2022). [cited by applicant]
Regner et al., “NFTs in Practice—Non-Fungible Tokens as Core Component of a Blockchain-based Event Ticketing Application.” retrieved from https://www. researchgate. neUpublication/336057493_N FTs_in_Practice_-_Non- Fung… [cited by applicant]
Feulner et al., “Exploring the use of self-sovereign identity for event ticketing systems,” Electron Mark, 2022, 32 (3):1759-1777. doi: 10.1007/s12525-022-00573-9. Epub Jul. 30, 2022. PMID: 35965736; PMCID: PMC9361939. … [cited by applicant]
US Office Action dated Sep. 20, 2024, U.S. Appl. No. 17/955,631. [cited by applicant]
US Office Action dated Sep. 25, 2024, U.S. Appl. No. 17/866,746. [cited by applicant]
US Office Action dated Sep. 29, 2024, U.S. Appl. No. 17/867,975. [cited by applicant]
US Office Action, U.S. Appl. No. 17/475,240 dated May 9, 2024. [cited by applicant]
PCT Supplementary International Search Report relating to Application No. PCT/CA2023/050452 dated Jul. 12, 2024. [cited by applicant]
US Office Action, U.S. Appl. No. 17/903,109, filed Jun. 3, 2024. [cited by applicant]