IP Library Granted Patent US 12,632,523
Granted Patent B2
US 12,632,523 · App. 18/829,213 · Granted May 19, 2026

Systems and methods for authentication of physical access tokens at access terminals

Inventor: Stanley Kevin Miles (Foresthill, CA)
G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,523
App. No.
18/829,213
Granted
May 19, 2026
Kind
B2
Abstract

In certain embodiments, a physical network access token at a network access terminal may be authenticated for modification of records at a remote server system. In some embodiments, a set of records and counterpart records having the same record identifiers and resource amounts may be stored independently on a physical token or user device and the remote server system. When a connection is established between an access terminal and the physical token (e.g., for authenticating a modification of record(s)), the access terminal may transmit input data to the token, which may use the input data with the records stored on the token to generate authentication data, which may be used by the remote server to authenticate a network action requested via the token.

Claims (45)

1 . An access terminal for facilitating authentication of a physical access token for modification of records at a remote server system, the access terminal comprising:

one or more processors and non-transitory, computer-readable media comprising instructions that, when executed by the one or more processors, cause operations comprising:

establishing a connection with the physical access token associated with a user, wherein the physical access token stores a set of records including a first record comprising (a) a record identifier identifying the first record of the user and (b) a resource amount associated with the first record of the user, and wherein the record identifier and resource amount are a same record identifier and resource amount of a first counterpart record of a set of counterpart records stored at a remote server system;

responsive to establishing connection with the physical access token, transmitting input data comprising a random seed value and a requested resource amount to the physical access token;

receiving, from the physical access token, authentication data generated based on (i) the random seed value, (ii) the requested resource amount, and (iii) the set of records stored at the physical access token;

transmitting, to the remote server system, a verification request for verifying the physical access token, wherein the verification request comprises the authentication data, the requested resource amount, and the random seed value, and wherein, in connection with the verification request, the remote server system performs verification using a hash-based value derived from hashing a combination of inputs including data from a first counterpart record of the set of counterpart records stored at the remote server system; and

in response to the verification indicating a match between the authentication data and the hash-based value derived from hashing of the combination of inputs, receiving an indication of authorization and causing presentation of an authorization related to the requested resource amount.

2 . The access terminal of claim 1 , wherein, in connection to the verification, the remote server system is configured to update the set of counterpart records to reflect a transfer corresponding to the requested resource amount by generating a new counterpart record that (i) is a modified instance of the first counterpart record and (ii) comprises a resource amount and a record identifier different from the record identifier of the first counterpart record.

3 . The access terminal of claim 1 , wherein, in connection to the verification, the remote server system is configured to modify the set of counterpart records to reflect (i) a first transfer of at least some of the resource amount of the first counterpart record to a second counterpart record or (ii) a second transfer of at least some of the resource amount of the second counterpart record to one or more records associated with one or more users by modifying record identifiers and resource amounts of each.

4 . The access terminal of claim 1 , wherein performing verification by the remote server system comprises:

hashing the first counterpart record of the set of counterpart records to a hash value;

generating a reference value based on the authentication data and a public key associated with the user; and

comparing the hash value and the reference value.

5 . A method for facilitating authentication of a physical access token for modification of records at a remote server system, the method comprising:

establishing a connection with the physical access token, wherein the physical access token stores a set of records including a first record of a user comprising (a) a record identifier identifying the first record and (b) a resource amount for transfer between the first record and a second record, and wherein the record identifier and resource amount are a same record identifier and resource amount of a first counterpart record of a set of counterpart records stored at a remote server system;

responsive to transmitting input data comprising a random seed value and a requested resource amount, receiving, from the physical access token, authentication data generated based on (i) the random seed value, (ii) the requested resource amount, and (iii) the set of records stored at the physical access token;

transmitting, to the remote server system, a verification request for verifying the physical access token, wherein the verification request comprises the authentication data, the requested resource amount, and the random seed value, and wherein, in connection with the verification request, the remote server system performs verification using a hash-based value derived from hashing a combination of inputs including data from the first counterpart record of the set of counterpart records stored at the remote server system; and

in response to the verification indicating a match between the authentication data and the hash-based value derived from hashing of the combination of inputs, receiving an indication of authorization and causing presentation of an authorization related to the requested resource amount.

6 . The method of claim 5 , wherein, in connection to the verification, the remote server system is configured to update the set of counterpart records to reflect a transfer corresponding to the requested resource amount by generating a new counterpart record that (i) is a modified instance of the first counterpart record and (ii) comprises a resource amount and a record identifier different from the record identifier of the first counterpart record.

7 . The method of claim 5 , wherein, in connection to transmitting input data comprising the requested resource amount, the physical access token is configured to update the set of records to reflect a transfer corresponding to the requested resource amount by generating a new record that (i) is a modified instance of the first record and (ii) comprises a resource amount and a record identifier different from the record identifier of the first record.

8 . The method of claim 7 , wherein the record identifier of the new record is based on an output generated by inputting a combination of (i) a secret key stored at the remote server system and the physical access token, (ii) a time associated with an establishment of connection to the physical access token, or (iii) the record identifier of the first record into a hash-based message authentication code (HMAC) algorithm.

9 . The method of claim 5 , wherein, in connection to the verification, the remote server system is configured to modify the set of counterpart records to reflect (i) a first transfer of at least some of the resource amount of the first counterpart record to a second counterpart record or (ii) a second transfer of at least some of the resource amount of the second counterpart record to one or more records associated with one or more users by modifying record identifiers and resource amounts of each.

10 . The method of claim 5 , wherein, in connection to transmitting input data comprising the requested resource amount, the physical access token is configured to modify the set of records to reflect (i) a first transfer of at least some of the resource amount of the first record to the second record, or (ii) a second transfer of at least some of the resource amount of the second record to one or more records associated with one or more users by modifying record identifiers and resource amounts of each.

11 . The method of claim 5 , wherein performing verification by the remote server system comprises:

hashing the first counterpart record of the set of counterpart records to a hash value;

generating a reference value based on the authentication data and a public key associated with the user; and

comparing the hash value and the reference value.

12 . The method of claim 5 , wherein the authentication data is configured to be generated by:

hashing a combination of record identifiers of one or more records of the set of records stored at the physical access token, the random seed value, or the requested resource amount to obtain a hash value; and

encrypting the hash value using a private key associated with the user.

13 . One or more non-transitory, computer-readable media comprising instructions recorded thereon that, when executed by one or more processors, cause operations for facilitating authentication of a physical access token for modification of records at a remote server system, comprising:

establishing a connection with the physical access token, wherein the physical access token stores a set of records including a first record of a user comprising (a) a record identifier identifying the first record and (b) a resource amount for transfer between the first record and a second record, and wherein the record identifier and resource amount are a same record identifier and resource amount of a first counterpart record of a set of counterpart records stored at a remote server system;

responsive to transmitting input data comprising a random seed value and a requested resource amount, receiving, from the physical access token, authentication data generated based on (i) the random seed value, (ii) the requested resource amount, and (iii) the set of records stored at the physical access token;

transmitting, to the remote server system, a verification request for verifying the physical access token, wherein the verification request comprises the authentication data, the requested resource amount, and the random seed value, and wherein, in connection with the verification request, the remote server system performs verification using a hash-based value derived from hashing a combination of inputs including data from the first counterpart record of the set of counterpart records stored at the remote server system; and

in response to the verification indicating a match between the authentication data and the hash-based value derived from hashing of the combination of inputs, receiving an indication of authorization and causing presentation of an authorization related to the requested resource amount.

14 . The one or more non-transitory, computer-readable media of claim 13 , wherein, in connection to the verification, the remote server system is configured to update the set of counterpart records to reflect a transfer corresponding to the requested resource amount by generating a new counterpart record that (i) is a modified instance of the first counterpart record and (ii) comprises a resource amount and a record identifier different from the record identifier of the first counterpart record.

15 . The one or more non-transitory, computer-readable media of claim 13 , wherein, in connection to transmitting input data comprising the requested resource amount, the physical access token is configured to update the set of records to reflect a transfer corresponding to the requested resource amount by generating a new record that (i) is a modified instance of the first record and (ii) comprises a resource amount and a record identifier different from the record identifier of the first record.

16 . The one or more non-transitory, computer-readable media of claim 15 , wherein the record identifier of the new record is based on an output generated by inputting a combination of (i) a secret key stored at the remote server system and the physical access token, (ii) a time associated with an establishment of connection to the physical access token, or (iii) the record identifier of the first record into a hash-based message authentication code (HMAC) algorithm.

17 . The one or more non-transitory, computer-readable media of claim 13 , wherein, in connection to the verification, the remote server system is configured to modify the set of counterpart records to reflect (i) a first transfer of at least some of the resource amount of the first counterpart record to a second counterpart record or (ii) a second transfer of at least some of the resource amount of the second counterpart record to one or more records associated with one or more users by modifying record identifiers and resource amounts of each.

18 . The one or more non-transitory, computer-readable media of claim 13 , wherein, in connection to transmitting input data comprising the requested resource amount, the physical access token is configured to modify the set of records to reflect (i) a first transfer of at least some of the resource amount of the first record to the second record or (ii) a second transfer of at least some of the resource amount of the second record to one or more records associated with one or more users by modifying record identifiers and resource amounts of each.

19 . The one or more non-transitory, computer-readable media of claim 13 , wherein performing verification by the remote server system comprises:

hashing the first counterpart record of the set of counterpart records to a hash value;

generating a reference value based on the authentication data and a public key associated with the user; and

comparing the hash value and the reference value.

20 . The one or more non-transitory, computer-readable media of claim 13 , wherein the authentication data is configured to be generated by hashing a combination of record identifiers of one or more records of the set of records stored at the physical access token, the random seed value, or the resource amount to obtain a hash value and encrypting the hash value using a private key associated with the user.

Continuity (2)
Continuation 18585017 · Feb 22, 2024
Related Publication 20250272366A1 · Aug 28, 2025
References Cited (109)
US 5805702A · Curry et al. · 1998 [cited by applicant]
US 6789068B1 · Blaze et al. · 2004 [cited by applicant]
US 7346579B2 · Matsumoto · 2008 [cited by applicant]
US 7467999B2 · Walker · 2008 [cited by examiner]
US 7835994B1 · Hopkins, III · 2010 [cited by applicant]
US 8549602B2 · Vaeth · 2013 [cited by examiner]
US 9715690B2 · Licciardello et al. · 2017 [cited by applicant]
US 10079683B1 · Chebaro · 2018 [cited by applicant]
US 10089612B2 · Wolfs et al. · 2018 [cited by applicant]
US 10277400B1 · Griffin et al. · 2019 [cited by applicant]
US 10552637B1 · Phillips et al. · 2020 [cited by applicant]
US 10630667B2 · Zhang · 2020 [cited by examiner]
US 11004072B2 · Georgiadis et al. · 2021 [cited by applicant]
US 11301847B1 · Chang et al. · 2022 [cited by applicant]
US 11321149B1 · McClure · 2022 [cited by examiner]
US 11405189B1 · Bennison · 2022 [cited by applicant]
US 11803840B1 · Smith et al. · 2023 [cited by applicant]
US 11941608B1 · Cook · 2024 [cited by examiner]
US 11968265B2 · Devine et al. · 2024 [cited by applicant]
US 12086220B1 · Miles · 2024 [cited by examiner]
US 12141209B2 · Harris · 2024 [cited by examiner]
US 12182247B1 · Miles · 2024 [cited by examiner]
US 20030061170A1 · Uzo · 2003 [cited by applicant]
US 20040083182A1 · Moribatake et al. · 2004 [cited by applicant]
US 20080027865A1 · Usui et al. · 2008 [cited by applicant]
US 20080272541A1 · Walker · 2008 [cited by examiner]
US 20090030844A1 · Hoffman · 2009 [cited by examiner]
US 20110276402A1 · Boone et al. · 2011 [cited by applicant]
US 20120028609A1 · Hruska · 2012 [cited by applicant]
US 20120072353A1 · Boone et al. · 2012 [cited by applicant]
US 20120191615A1 · Schibuk · 2012 [cited by examiner]
US 20130159188A1 · Andon · 2013 [cited by applicant]
US 20140201086A1 · Gadotti et al. · 2014 [cited by applicant]
US 20140282929A1 · Tse · 2014 [cited by examiner]
US 20140379584A1 · Ward · 2014 [cited by applicant]
US 20150106275A1 · Wolfs et al. · 2015 [cited by applicant]
US 20150363774A1 · Priebatsch et al. · 2015 [cited by applicant]
US 20160027015A1 · Redpath · 2016 [cited by applicant]
US 20160212126A1 · Sadacharam et al. · 2016 [cited by applicant]
US 20160284146A1 · Moore · 2016 [cited by examiner]
US 20160292686A1 · Laxminarayanan · 2016 [cited by examiner]
US 20160301530A1 · He · 2016 [cited by examiner]
US 20160371668A1 · Priebatsch · 2016 [cited by examiner]
US 20160371685A1 · Smith · 2016 [cited by examiner]
US 20170046890A1 · Smith · 2017 [cited by examiner]
US 20170083917A1 · Sjoholm · 2017 [cited by applicant]
US 20170272253A1 · Lavender · 2017 [cited by examiner]
US 20170293902A1 · Florimond · 2017 [cited by applicant]
US 20170323354A1 · Martell · 2017 [cited by applicant]
US 20170364895A1 · Van Heerden · 2017 [cited by examiner]
US 20170373852A1 · Cassin · 2017 [cited by examiner]
US 20180152304A1 · Ebrahimi et al. · 2018 [cited by applicant]
US 20180276666A1 · Haldenby et al. · 2018 [cited by applicant]
US 20180336553A1 · Brudnicki et al. · 2018 [cited by applicant]
US 20190014149A1 · Cleveland et al. · 2019 [cited by applicant]
US 20190122191A1 · Filipiak · 2019 [cited by examiner]
US 20190392409A1 · Mei · 2019 [cited by applicant]
US 20200005290A1 · Madisetti et al. · 2020 [cited by applicant]
US 20200154270A1 · Byington et al. · 2020 [cited by applicant]
US 20200167798A1 · Lee et al. · 2020 [cited by applicant]
US 20200219103A1 · Mandloi · 2020 [cited by examiner]
US 20200279458A1 · France · 2020 [cited by applicant]
US 20200286170A1 · Kramer et al. · 2020 [cited by applicant]
US 20200399929A1 · Hardter · 2020 [cited by examiner]
US 20210133740A1 · Wang · 2021 [cited by examiner]
US 20210144140A1 · Murphy · 2021 [cited by examiner]
US 20210209582A1 · Paliwal et al. · 2021 [cited by applicant]
US 20210209684A1 · Foote et al. · 2021 [cited by applicant]
US 20210233337A1 · Myers · 2021 [cited by examiner]
US 20210406878A1 · Ferenczi et al. · 2021 [cited by applicant]
US 20220027519A1 · Kataria · 2022 [cited by examiner]
US 20220036339A1 · Guo · 2022 [cited by examiner]
US 20220108314A1 · Mehta et al. · 2022 [cited by applicant]
US 20220237599A1 · Petersen et al. · 2022 [cited by applicant]
US 20220284112A1 · Seader et al. · 2022 [cited by applicant]
US 20230094247A1 · Nuhoglu · 2023 [cited by examiner]
US 20230216679A1 · Tomar · 2023 [cited by applicant]
US 20230252382A1 · Simpson · 2023 [cited by applicant]
US 20230252435A1 · Arvapally et al. · 2023 [cited by applicant]
US 20230267226A1 · Balinsky et al. · 2023 [cited by applicant]
US 20230283463A1 · Shaffer et al. · 2023 [cited by applicant]
US 20230291562A1 · Lim · 2023 [cited by applicant]
US 20230325833A1 · Chen et al. · 2023 [cited by applicant]
US 20230360042A1 · Doney et al. · 2023 [cited by applicant]
US 20230379179A1 · Davis et al. · 2023 [cited by applicant]
US 20230396454A1 · Grover · 2023 [cited by applicant]
US 20230401574A1 · Smith et al. · 2023 [cited by applicant]
US 20230412639A1 · Xu et al. · 2023 [cited by applicant]
US 20230419308A1 · Madisetti et al. · 2023 [cited by applicant]
US 20230421543A1 · Doney et al. · 2023 [cited by applicant]
US 20240005312A1 · Kulkarni et al. · 2024 [cited by applicant]
US 20240005409A1 · Doney · 2024 [cited by applicant]
US 20240029051A1 · Sethia et al. · 2024 [cited by applicant]
US 20240070789A1 · Jenson · 2024 [cited by applicant]
US 20240086906A1 · Sota et al. · 2024 [cited by applicant]
US 20240086911A1 · Merkel et al. · 2024 [cited by applicant]
US 20240089105A1 · Duque et al. · 2024 [cited by applicant]
US 20240095220A1 · Isaacs et al. · 2024 [cited by applicant]
US 20240104642A1 · Kang et al. · 2024 [cited by applicant]
US 20240106671A1 · Fortuna et al. · 2024 [cited by applicant]
US 20240112160A1 · Xu et al. · 2024 [cited by applicant]
US 20240126919A1 · Ankrom et al. · 2024 [cited by applicant]
US 20240137230A1 · Osborn et al. · 2024 [cited by applicant]
US 20240154959A1 · Mishra · 2024 [cited by examiner]
US 20250088470A1 · Hassanali · 2025 [cited by examiner]
US 20250329204A1 · Bardack · 2025 [cited by examiner]
Non-Final Office Action issued in U.S. Appl. No. 18/585,011 on Jun. 3, 2024. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 18/585,017 on May 2, 2024. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 18/585,011 on Aug. 23, 2024. [cited by applicant]