IP Library › Granted Patent US 12,271,885
Granted Patent B2
US 12,271,885 · App. 17/245,403 · Granted Apr 8, 2025

System and method for device initialization by secondary user

Inventors: Sangwoo Kim (Thornhill, CA); Albert Le (Toronto, CA); Brad Sokol (Toronto, CA); Polly Auyeung (Richmond Hill, CA); Nabeel Chaudhry (Milton, CA); Rahim Damji (Markham, CA)
Assignee: SHOPIFY INC.
G06Q20/206G06F21/31G06Q20/202
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,271,885
App. No.
17/245,403
Granted
Apr 8, 2025
Kind
B2
Abstract

Methods and systems for enabling initialization of a device by a secondary user are described. A request is received, from a first device, to initialize the first device with an online account. A notification is transmitted to one or more administrative user devices associated with at least one administrative user associated with the online account, seeking approval of the request to initialize the first device. A response is received from at least one of the one or more administrative user devices, indicating approval to initialize the first device. A credential is transmitted to enable initialization of the first device with the online account.

Claims (74)

1. A computer-implemented method comprising:

receiving, by a server from a first device, a request associated with a secondary user to initialize the first device with an online account;

generating, at the server, a machine-readable credential to enable initialization of the first device with the online account by:

transmitting, by the server to one or more administrative user devices associated with at least one administrative user associated with the online account, the at least one administrative user being different from the secondary user, a request for input of a first credential specific to the at least one administrative user to approve the request to initialize the first device;

receiving, by the server from at least one of the one or more administrative user devices, a response indicating input of the first credential specific to the at least one administrative user; and

responsive to the response received from the at least one of the one or more administrative user devices, generating, at the server, the machine-readable credential that is different from the first credential, the machine-readable credential being useable by the secondary user and being not specific to the at least one administrative user; and

transmitting, by the server, the machine-readable credential to a secondary user device associated with the secondary user, the machine-readable credential being scannable by the first device to enable initialization of the first device with the online account.

2. The method of claim 1 ,

wherein the online account is a merchant account;

wherein the request to initialize the first device is a request to initialize the first device as a point-of-sale (POS) device associated with the merchant account; and

wherein the machine-readable credential enables initialization of the first device as the POS device associated with the merchant account.

3. The method of claim 1 , wherein the request for input of the first credential includes information to enable the at least one administrative user to make a decision to approve the request to initialize the first device, the information including an identification of at least one of:

the secondary user associated with the request to initialize the first device;

an identification of a location associated with the request to initialize the first device; or

context information that was captured by the first device and received by the server with the request to initialize the first device.

4. The method of claim 1 , wherein the machine-readable credential is a Quick Response (QR) code; or

a barcode.

5. The method of claim 1 , further comprising:

prior to transmitting the request for input of the first credential to the one or more administrative user devices, verifying validity of the request to initialize the first device.

6. The method of claim 5 , wherein verifying validity of the request to initialize the first device comprises at least one of:

verifying that the first device is in a valid geographic area associated with the online account;

verifying that the request to initialize the first device is from a valid network address associated with the online account; or

verifying that the request to initialize the first device is associated with a valid user associated with the online account.

7. The method of claim 1 , wherein the machine-readable credential is a restricted credential, and wherein validity of the restricted credential is restricted by at least one of:

a defined time limit;

a defined number of uses;

a defined geographic area; or

use by a defined user.

8. The method of claim 1 , wherein the initialization of the first device comprises registering the first device against the online account.

9. A system comprising:

a processor in communication with storage, the processor configured to execute instructions from the storage to cause the system to:

receive, from a first device, a request associated with a secondary user to initialize the first device with an online account;

generate a machine-readable credential to enable initialization of the first device with the online account by:

transmitting, to one or more administrative user devices associated with at least one administrative user associated with the online account, the at least one administrative user being different from the secondary user, a request for input of a first credential specific to the at least one administrative user to approve the request to initialize the first device;

receiving, from at least one of the one or more administrative user devices, a response indicating input of the first credential specific to the at least one administrative user; and

responsive to the response received from the at least one of the one or more administrative user device, generating, at the server, the machine-readable credential that is different from the first credential, the machine-readable credential being useable by the secondary user and being not specific to the at least one administrative user; and

transmit the machine-readable credential to a secondary user device associated with the secondary user, the machine-readable credential being scannable by the first device to enable initialization of the first device with the online account.

10. The system of claim 9 ,

wherein the online account is a merchant account;

wherein the request to initialize the first device is a request to initialize the first device as a point-of-sale (POS) device associated with the merchant account; and

wherein the machine-readable credential enables initialization of the first device as the POS device associated with the merchant account.

11. The system of claim 9 , wherein the request for input of the first credential includes information to enable the at least one administrative user to make a decision to approve the request to initialize the first device, the information including an identification of at least one of:

the secondary user associated with the request to initialize the first device;

an identification of a location associated with the request to initialize the first device; or

context information that was captured by the first device and received by the server with the request to initialize the first device.

12. The system of claim 9 , wherein the processor is configured to execute instructions to further cause the system to:

prior to transmitting the request for input of the first credential to the one or more administrative user devices, verify validity of the request to initialize the first device.

13. A non-transitory computer-readable medium storing instructions that, when executed by a processor of a system, cause the system to:

receive, from a first device, a request associated with a secondary user to initialize the first device with an online account;

generate a machine-readable credential to enable initialization of the first device with the online account by:

transmitting, to one or more administrative user devices associated with at least one administrative user associated with the online account, the at least one administrative user being different from the secondary user, a request for input of a first credential specific to the at least one administrative user to approve the request to initialize the first device;

receiving, from at least one of the one or more administrative user devices, a response indicating input of the first credential specific to the at least one administrative user; and

responsive to the response received from the at least one of the one or more administrative user devices, generating, at the server, the machine-readable credential that is different from the first credential, the machine-readable credential being useable by the secondary user and being not specific to the at least one administrative user; and

transmit the machine-readable credential to a secondary user device associated with the secondary user, the machine-readable credential being scannable by the first device to enable initialization of the first device with the online account.

14. The method of claim 5 , further comprising:

prior to transmitting the request for input of the first credential to the one or more administrative user devices, receiving a secondary credential associated with the secondary user;

wherein verifying validity of the request comprises verifying the secondary credential.

15. The system of claim 9 , wherein the processor is configured to execute instructions to further cause the system to:

prior to transmitting the request for input of the first credential to the one or more administrative user devices, receive a secondary credential associated with the secondary user; and

prior to transmitting the request for input of the first credential to the one or more administrative user devices, verify validity of the request to initialize the first device by verifying the secondary credential.

16. The non-transitory computer-readable medium of claim 13 , wherein the instructions further cause the system to:

prior to transmitting the request for input of the first credential to the one or more administrative user devices, verify validity of the request to initialize the first device.

17. The non-transitory computer-readable medium of claim 13 , wherein the instructions further cause the system to:

prior to transmitting the request for input of the first credential to the one or more administrative user devices, receive a secondary credential associated with the secondary user; and

prior to transmitting the request for input of the first credential to the one or more administrative user devices, verify validity of the request to initialize the first device by verifying the secondary credential.

18. The method of claim 3 , wherein the request for input of the first credential includes context information captured by the first device to enable the at least one administrative user to make the decision to approve the request to initialize the first device, wherein the context information captured by the first device is at least one of:

a captured screenshot associated with the request to initialize the first device; or

a captured photograph associated with the request to initialize the first device.

19. The system of claim 9 , wherein the machine-readable credential is a Quick Response (QR) code; or

a barcode.

20. The system of claim 12 , wherein verifying validity of the request to initialize the first device comprises at least one of:

verifying that the first device is in a valid geographic area associated with the online account;

verifying that the request to initialize the first device is from a valid network address associated with the online account; or

verifying that the request to initialize the first device is associated with a valid user associated with the online account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2021
From: KIM, SANGWOO; LE, ALBERT; SOKOL, BRAD; AUYEUNG, POLLY; CHAUDHRY, NABEEL; DAMJI, RAHIM
To: SHOPIFY INC.
Reel/Frame 056227/0269 →
Continuity (1)
Related Publication 20220351169A1 · Nov 3, 2022
References Cited (18)
US 9374349B1 · Corlett · 2016 [cited by examiner]
US 9479922B2 · Borggaard · 2016 [cited by examiner]
US 9686287B2 · Manton · 2017 [cited by examiner]
US 10050787B1 · Johansson · 2018 [cited by examiner]
US 10867291B1 · Yien · 2020 [cited by examiner]
US 11432149B1 · Dhanoa · 2022 [cited by examiner]
US 20050071630A1 · Thornton · 2005 [cited by examiner]
US 20100058053A1 · Wood · 2010 [cited by examiner]
US 20140373099A1 · Durbha · 2014 [cited by examiner]
US 20150059003A1 · Bouse · 2015 [cited by examiner]
US 20150281239A1 · Brophy · 2015 [cited by examiner]
US 20190342753A1 · Zhu · 2019 [cited by examiner]
US 20200104505A1 · Wipf · 2020 [cited by examiner]
US 20210166228A1 · Wagner · 2021 [cited by examiner]
US 20220222640A1 · Mimassi · 2022 [cited by examiner]
NPL “What is OAuth? How the open authorization framework works” by J. Fruhlinger and R. Grimes, published in CSO dated Sep. 20, 2019 and available at https://www.csoonline.com/article/562635/what-is-oauth-how-the-open-a… [cited by examiner]
NPL What is OpenID Connect (OIDC), author unknown, date unknown, available at https://www.oauth.com/oauth2-servers/openid-connect/authorization-vs-authentication/ (Year: 2024). [cited by examiner]
NPL Mozilla InfoSec, author unknown, date unknown, available at https://infosec.mozilla.org/guidelines/iam/openid_connect.html (Year: 2024). [cited by examiner]