IP Library › Granted Patent US 12,463,952
Granted Patent B2
US 12,463,952 · App. 17/516,394 · Granted Nov 4, 2025

Multichannel authentication and tokenization system

Inventors: Abhishek Paul (Union City, CA); Dipanjan Bandyopadhyay (Fremont, CA); Prem Kumar Mani (San Jose, CA)
Assignee: Walmart Apollo, LLC
H04L63/08G06F16/90335G06Q20/206H04L63/20H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,952
App. No.
17/516,394
Granted
Nov 4, 2025
Kind
B2
Abstract

In some embodiments, apparatuses and methods are provided herein useful to multichannel authentication and tokenization. A system comprises a first authentication system serving a plurality of in-store point of sale terminals and implementing a physical channel authentication policy and a second authentication system serving a plurality of user devices accessing an e-commerce service and implementing an e-commerce channel authentication policy, and a tokenization system. The tokenization system being configured to generate a first token in response to receiving a first user credential from an in-store point of sale terminal via the first authentication system, generate a second token in response to receiving a second user credential from a user device via the second authentication system, and forward the first token and the second token to the retailer backend system, wherein the first token and the second token are generated based on a same tokenization protocol.

Claims (67)

1 . A system for multichannel authentication, the system comprises:

a first authentication system serving a plurality of in-store point of sale terminals and implementing a physical channel authentication policy;

a second authentication system serving a plurality of user devices accessing an e-commerce service and implementing an e-commerce channel authentication policy; and

a tokenization system coupled to a retailer backend system, the first authentication system, and the second authentication system, the tokenization system configured to:

receive, from an in-store point of sale terminal of the plurality of in-store point of sale terminals via the first authentication system, a first user credential received at the in-store point of sale terminal;

receive a second user credential from a user device of the plurality of user devices via the second authentication system;

generate a first token in response to receiving the first user credential based on a first tokenization protocol;

generate a second token in response to receiving the second user credential based on the first tokenization protocol;

forward the first token to the in-store point of sale terminal for use by the in-store point of sale terminal in communicating with the retailer backend system;

forward the first token and the second token to the retailer backend system; and

in response to receiving, from a requesting device, a third token based on a second tokenization protocol:

query a membership services database using the third token to determine membership details associated with the third token;

convert the third token to a converted token based on the first tokenization protocol using the membership details; and

forward the converted token to the requesting device for use in communication with the retailer backend system.

2 . The system of claim 1 , wherein the physical channel authentication policy and the e-commerce channel authentication policy impose different requirements for authenticating user credentials.

3 . The system of claim 1 , further comprising the retailer backend system, and the retailer backend system is configured to:

associate the first token with user information associated with the first user credential in a user database; and

associate the second token with user information associated with the second user credential in the user database;

wherein components of the retailer backend system are configured to query the user database using the first token and the second token to retrieve the associated user information.

4 . The system of claim 3 , wherein the first token is included in subsequent communications between the in-store point of sale terminal and the retailer backend system to access the user information associated with the first user credential.

5 . The system of claim 3 , wherein the second token is forwarded to the user device and included in subsequent communications between the in-store point of sale terminal and the retailer backend system to access the user information associated with the second user credential.

6 . The system of claim 3 , wherein in an event that the first user credential and the second user credential are associated with a same user, the first token and the second token are handled identically by the retailer backend system.

7 . The system of claim 1 , wherein the tokenization system is further configured to generate a step-up token in response to receiving a step-up user credential from the first authentication system or the second authentication system.

8 . The system of claim 1 , wherein the first authentication system serves devices on a public network comprising the user device; and

wherein the second authentication system is part of a private network comprising the plurality of in-store point of sale terminals.

9 . The system of claim 1 , further comprising:

a third user authentication system coupled to a plurality of customer service contact center devices and implementing a contact center authentication policy; and

the tokenization system is further configured to generate a fourth token in response to receiving a third user credential from the third user authentication system based on the first tokenization protocol.

10 . The system of claim 1 , wherein:

the first authentication system is further configured to serve a plurality of in-store customer service terminals; and

the first token and the second token are generated based on the first tokenization protocol such that the retailer backend system can treat the first token and the second token as channel-agnostic.

11 . A method for multichannel authentication, the method comprises:

receiving, by a tokenization system from an in-store point of sale terminal via a first authentication system serving a plurality of in-store point of sale terminals and implementing a physical channel authentication policy, a first user credential received at the in-store point of sale terminal;

receiving, by the tokenization system, a second user credential from a user device via a second authentication system serving a plurality of user devices accessing an e-commerce service and implementing an e-commerce channel authentication policy;

generating, with the tokenization system, a first token in response to receiving the first user credential based on a first tokenization protocol;

generating, with the tokenization system, a second token in response to receiving the second user credential based on the first tokenization protocol;

forwarding the first token to the in-store point of sale terminal for use by the in-store point of sale terminal in communicating with a retailer backend system;

forwarding the first token and the second token to the retailer backend system; and

in response to receiving, from a requesting device, a third token based on a second tokenization protocol:

query a membership services database using the third token to determine membership details associated with the third token;

convert the third token to a converted token based on the first tokenization protocol using the membership details; and

forward the converted token to the requesting device for use in communication with the retailer backend system.

12 . The method of claim 11 , wherein the physical channel authentication policy and the e-commerce channel authentication policy impose different requirements for authenticating user credentials.

13 . The method of claim 11 , further comprising:

associating, at the retailer backend system, the first token with user information associated with the first user credential in a user database; and

associating, at the retailer backend system, the second token with user information associated with the second user credential in the user database;

wherein components of the retailer backend system are configured to query the user database using the first token and the second token to retrieve the associated user information.

14 . The method of claim 13 , wherein the first token is included in subsequent communications between the in-store point of sale terminal and the retailer backend system to access the user information associated with the first user credential.

15 . The method of claim 13 , wherein the second token is forwarded to the user device and included in subsequent communications between the in-store point of sale terminal and the retailer backend system to access the user information associated with the second user credential.

16 . The method of claim 13 , wherein in an event that the first user credential and the second user credential are associated with a same user, the first token and the second token are handled identically by the retailer backend system.

17 . The method of claim 11 , wherein the tokenization system is further configured to generate a step-up token in response to receiving a step-up user credential from the first authentication system or the second authentication system.

18 . The method of claim 11 , wherein the first authentication system serves devices on a public network comprising the user device; and

wherein the second authentication system is part of a private network comprising the plurality of in-store point of sale terminals.

19 . The method of claim 11 , further comprising:

generating a fourth token in response to receiving a third user credential from a third user authentication system based on the first tokenization protocol, the third user authentication system being coupled a plurality of customer service contact center devices and implementing a contact center authentication policy.

20 . An apparatus for multichannel authentication, the apparatus comprises:

a non-transitory storage medium storing a set of computer-readable instructions; and

a control circuit configured to execute the set of computer-readable instructions which cause the control circuit to:

receive, by a tokenization system from an in-store point of sale terminal via a first authentication system serving a plurality of in-store point of sale terminals and implementing a physical channel authentication policy, a first user credential received at the in-store point of sale terminal;

receive, by the tokenization system, a second user credential from a user device via a second authentication system serving a plurality of user devices accessing an e-commerce service and implementing an e-commerce channel authentication policy;

generate, with the tokenization system, a first token in response to receiving the first user credential based on a first tokenization protocol;

generate, with the tokenization system, a second token in response to receiving the second user credential based on the first tokenization protocol;

forward the first token to the in-store point of sale terminal for use by the in-store point of sale terminal in communicating with a retailer backend system; forward the first token and the second token to the retailer backend system; and

in response to receiving, from a requesting device, a third token based on a second tokenization protocol:

query a membership services database using the third token to determine membership details associated with the third token;

convert the third token to a converted token based on the first tokenization protocol using the membership details; and

forward the converted token to the requesting device for use in communication with the retailer backend system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2021
From: PAUL, ABHISHEK; BANDYOPADHYAY, DIPANJAN; MANI, PREM KUMAR
To: WALMART APOLLO, LLC
Reel/Frame 058365/0273 →
Continuity (1)
Related Publication 20230139491A1 · May 4, 2023
References Cited (18)
US 9282088B2 · Chin · 2016 [cited by applicant]
US 20060204051A1 · Holland · 2006 [cited by applicant]
US 20080046715A1 · Balazs · 2008 [cited by applicant]
US 20150127547A1 · Powell · 2015 [cited by examiner]
US 20150302398A1 · Desai · 2015 [cited by examiner]
US 20150334099A1 · Zhang · 2015 [cited by applicant]
US 20160027013A1 · Modi · 2016 [cited by examiner]
US 20160142409A1 · Frei · 2016 [cited by applicant]
US 20160283925A1 · Lavu · 2016 [cited by applicant]
US 20170053301A1 · Khan · 2017 [cited by examiner]
US 20170170963A1 · Xu · 2017 [cited by applicant]
US 20180268411A1 · Voldman · 2018 [cited by examiner]
US 20200296082A1 · Killoran, Jr. · 2020 [cited by applicant]
US 20210035086A1 · Khan · 2021 [cited by examiner]
US 20210065156A1 · Kadiwala · 2021 [cited by examiner]
Okta; “Unlocking Omni-channel With Unified Customer Identity”; https://www.okta.com/sites/default/files/pdf/Unlocking%20Omni-channel%20With%20Unified%20Customer%20Identity%20_0.pdf; Available at least as early as Aug. 2… [cited by applicant]
Tantillo, Davide et al.; “M2M authentication and authorization with OAuth 2.0 and OpenID Connect”; https://blog.mia-platform.eu/en/m2m-authentication-and-authorization-with-oauth-2.0-and-openid-connect; Published May 4,… [cited by applicant]
Chowhan, Rahul et al.; “Password-Less Authentication: Methods for User Verification and Identification to Login Securely Over Remote Sites”; Machine Learning and Cognitive Science Applications in Cyber Security; IGI Glo… [cited by applicant]