Methods for anonymously providing digital evidence

DE102020121305C5Active Publication Date: 2026-08-06GREENBILL GMBH
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
GREENBILL GMBH
Filing Date
2020-08-13
Publication Date
2026-08-06

AI Technical Summary

Technical Problem

Conventional printed receipts consume resources, generate waste, and require additional infrastructure and customer data sharing, posing challenges for digital receipt provision that are not adequately addressed by existing methods.

Method used

A method for anonymously providing digital receipts using a static information carrier with a unique identification and time stamp, allowing retrieval via a pre-installed web browser without additional hardware or customer registration, ensuring secure and immediate access.

Benefits of technology

Reduces resource consumption and waste while providing secure, anonymous, and cost-effective digital receipts without the need for additional infrastructure or customer data sharing, enhancing user acceptance and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for anonymously providing data packets (10a-10f), in particular digital receipts, to selected terminal equipment (12), comprising the steps of: a) generating a data packet (10a-10f), in particular a digital receipt; b) linking the data packet (10a-10f) with an individual identification (14a-14f) of an issuing office (16a-16f) and a timestamp; c) storing the data packet (10a-10f) on a storage unit (18) accessible by terminal equipment (12); d) reading an information carrier (20a-20f) associated with the individual identification (14a-14f) of the issuing office (16a-16f) with a terminal equipment (12), wherein the information carrier (20a-20f) comprises static connection information for retrieving the accessible storage unit (18) associated with the individual identification (14a-14f) of the issuing office (16a-16f). (16a-16f) is assigned, e) Retrieving the retrievable storage unit (18) with the terminal device (12) using the read static connection information,and f) Providing the data packet (10a-10f) with the individual identification (14a-14f) corresponding to the retrieval and the most recent timestamp from the retrievable storage unit (18) to the retrieving terminal device (12), wherein the retrievable storage unit (18) is configured such that, when retrieved by a terminal device (12), it can provide only the data packet (10a-10f) with the most recent timestamp for each individual identification (14a-14f).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for anonymously providing data packets, in particular digital documents, to selected terminal devices, a data processing system comprising means for executing selected steps of this method, and a computer program product. A computer-readable data carrier and a data carrier signal are also disclosed.

[0002] The subject matter of the invention is defined in the attached claims.

[0003] Issuing receipts is a necessary component of any cash register accounting system. It serves not only to document the purchase made to the customer but also to show taxes and other charges. Both the customer and the issuing company can use these receipts, sometimes simply referred to as vouchers or receipts, to document their sales and expenses.

[0004] The most familiar state-of-the-art technology in this area is probably issuing printed receipts to the customer. These receipts can be automatically generated by a point-of-sale system and handed directly to the customer by the cashier. This established method has proven its worth in numerous respects, particularly regarding data security and auditability.

[0005] Against the backdrop of growing ecological awareness among the population, the established system of printed receipts is increasingly viewed critically, as the production of conventional cash register receipts requires large quantities of paper and printer ink annually, which not only consumes significant resources but also incurs costs for companies.

[0006] Furthermore, traditional printed receipts are often immediately discarded by customers, especially for small amounts without tax implications, generating significant amounts of additional waste annually. These disadvantages are exacerbated by the fact that in recent years some countries have increasingly implemented regulations mandating receipt issuance and delivery to the customer even for small amounts, in order to combat tax fraud.

[0007] Given increasingly scarce resources and the general desire to minimize everyday waste, there has been a need for several years to digitize the creation and delivery of receipts to customers. However, the major challenge in designing processes for providing such digital receipts lies in the fact that these processes must be comparable to the traditional, analog method of printed receipts, particularly with regard to data security.

[0008] In particular, procedures for providing digital receipts must be designed to ensure that the digital receipt generated by the point-of-sale system is reliably and securely provided to the customer, specifically preventing unauthorized access to the digital receipt. Furthermore, the procedure must be suitable for providing the digital receipts to the customer immediately, i.e., without delay, so that the customer, for example while shopping at the supermarket, is able to directly verify the accuracy of the statement.

[0009] Some existing digital solutions to this problem rely on the customer identifying themselves to the point-of-sale (POS) system. This might involve scanning a QR code from the user's mobile device, after which the POS system forwards the receipt data to the customer from the server. However, this method typically requires both the customer and the retailer to use the same software system or compatible, specifically coordinated applications. This is often perceived as a disadvantage, particularly for businesses with a high volume of customers, such as those at airports or train stations, especially if application coverage or customer registration is low.Furthermore, these methods are regularly perceived as disadvantageous because the customer shares their data with the retailer and has only limited control over what other data the retailer reads from the customer's mobile device via the application. In addition, such methods are usually not completely anonymous, as the receipts can at least be assigned to individual users or their user accounts on the server side. From the company's perspective, it is also frequently considered a disadvantage that additional hardware must be purchased and maintained for communication between the customer's device and the point-of-sale system in order to read the information provided by the customer.

[0010] A much-discussed advancement over the method described above was achieved through a method for providing digital receipts, which the inventors of the present invention had already successfully launched on the market. To meet the general requirements for methods for providing digital receipts, this solution involves digitizing the receipts generated by a cash register using a data processing device connected via the printer port and displaying them directly to the customer at the cash register on a permanently installed digital display, such as a tablet, thus ensuring immediate verifiability of the receipt.This method fulfills the requirement that the customer must be able to take the digital receipt with them by displaying a QR code, individually generated for each transaction, on the permanently installed digital display along with the digital receipt. This individually generated QR code contains variable link information, i.e., a link to the displayed receipt on a server system, which is created anew for each receipt to be issued. The customer who wishes to take the digital receipt simply needs to scan the QR code with their device, such as a mobile phone, and will be directed via the individually generated link to the digital receipt stored on a server, which can then be saved, for example, on the customer's device.

[0011] This system addresses the important security requirement by generating a separate link for each digital receipt. This link is only displayed to the customer along with the receipt itself, which can then be accessed via the corresponding link. A major advantage of this solution, already established by its inventors, is that virtually any standard display device, such as a tablet computer, can be used. Furthermore, the system can be combined with older POS systems by utilizing the printer interface output.

[0012] Despite the success of the system described above, certain aspects are perceived as disadvantages. In particular, this method, which is known from the prior art, requires the company to provide a separate electronic device for displaying receipts at each individual point of sale, i.e., at each cash register or even at each waiter's mobile payment device. This can entail considerable costs, especially for large companies, and also requires the devices to be securely mounted at the points of sale to prevent theft. In addition to the increased energy consumption due to the extra electrical equipment, another disadvantage is that the tablets, which are usually operated via wireless networks, can themselves be potentially vulnerable to unauthorized access if they are not properly maintained and secured.

[0013] The method previously presented by the inventors has already proven to be very efficient in practice, especially compared to alternative systems that require the installation of a separate application on the customer's device and / or customer registration in a separate database. Nevertheless, there was a need to further develop the solutions already known from the prior art.

[0014] The overarching objective of the present invention was accordingly to provide a method for providing digital documents which, with regard to performance parameters, is comparable to the established method using printed documents, but eliminates or at least reduces the disadvantages of the prior art described above.

[0015] In particular, the object of the present invention was therefore to provide a method by which the consumption of paper and printing ink in the business operations of companies can be reduced and by which the amount of paper waste generated can be reduced.

[0016] The method to be specified should preferably allow the customer to view the receipt generated for them immediately upon receipt creation, in order to verify its accuracy. Furthermore, it was an important requirement of the present invention that the digital receipt must be made available to the customer for collection immediately at the point of issue, e.g., at the checkout.

[0017] An important objective of the present invention was to provide a method which, compared to the prior art, places fewer demands on the infrastructure to be provided by the company at the point of issue and, in particular, eliminates the need for separate electronic display devices.

[0018] Particular attention was paid to ensuring that the specified procedure provided the digital documents anonymously, i.e., without the company or other customers being able to obtain information about the customer.

[0019] In this context, a further objective of the invention was to design the method in such a way that it is not only protected against the accidental, unintentional transmission of digital documents to unauthorized end devices, but also against malicious access by unauthorized third parties.

[0020] One requirement was that the specified procedure should, if possible, function without the installation and / or use of specific applications on the customer's end devices, in order to enable the broadest possible applicability and to reduce any obstacles to the use of the corresponding procedure, in particular avoiding the need for separate user registration in a database.

[0021] Finally, it was an object of the present invention to provide a data processing system which includes means for carrying out the process steps required by the cash register system, as well as to provide an associated computer program product.

[0022] The inventors have realized that the aforementioned technical problems and tasks can surprisingly be solved by a method for anonymously providing digital receipts, which, unlike the prior art, uses a static information carrier located in the area of ​​the issuing point and which contains static connection information that is therefore the same for a large number of customers and does not need to be generated individually for each customer.

[0023] A customer who wants to retrieve a digital receipt after a purchase simply needs to scan the static information carrier, which could be, for example, a sticker with a QR code, and will receive the digital receipt using any web browser pre-installed on their device, whereas the next customer, using the same static information carrier and the same static connection information, will only see their own digital receipt, not that of the previous customer.

[0024] This system eliminates not only the need to install a separate application on the customer's device, but also the need for the company to provide a separate infrastructure beyond simply affixing a sticker with negligible material value, while also ensuring the anonymity of the process in a very special way, since the company's POS system does not need to read any data from the customer.

[0025] This advantageous method is realized by processing the digital receipt and its retrieval by the terminal device in a specific way using the data processing system in the inventive method. For each issuing point, i.e., for example, a cash register or a waiter's mobile payment device, an individual identifier is created. The information carrier located at the corresponding issuing point and the static connection information stored therein are linked to the individual identifier of that issuing point.If a digital receipt is to be issued at the relevant issuing point, the receipt generated by the data processing system is linked to the individual identification and a timestamp and stored on a server for retrieval, whereby a receipt batch is expediently generated for each individual identification, containing all receipts that were created for an individual identification, of which, however, only the last receipt, i.e. the receipt with the most current timestamp, is active and thus retrievable.

[0026] When the customer reads the static connection information from the data carrier, they are connected, for example, via a forwarding server, to a retrievable storage unit of the data processing system. The data processing system takes into account the individual identification associated with the end device's request, which depends on the read data carrier, as well as the time of retrieval, and generates dynamic connection information from this. This information directs the end device to the stored digital document. This so-called individual link, which is generated for each stored digital document only upon retrieval, can be limited in time and / or the number of times it can be accessed.

[0027] The method described above using an exemplary procedure provides an improved method for the anonymous provision of digital documents, which, according to the inventors, is also fundamentally suitable for the anonymous provision of other data packages that are to be transmitted to end devices in comparable situations, so that the inventive method is not in principle limited to the provision of digital documents, even if this application is explicitly preferred.

[0028] The aforementioned tasks are solved accordingly by methods for anonymously providing data packets, in particular digital documents, to selected terminal devices, as well as data processing systems and computer program products, as defined in the claims. Preferred embodiments of the invention are described in the dependent claims and the following descriptions.

[0029] Such features of methods according to the invention for anonymously providing data packets, in particular digital documents, to selected terminal devices, which are hereinafter referred to as preferred, are combined in particularly preferred embodiments with other features referred to as preferred. Combinations of two or more of the methods hereinafter referred to as particularly preferred are therefore especially preferred. Additional features of preferred system and computer program products according to the invention result from the features of preferred methods.

[0030] The invention relates to a method for anonymously providing data packets, in particular digital documents, to selected terminal devices, comprising the steps: a) Generating a data package, in particular a digital document, b) Linking the data package with an individual identifier of an issuing point and a timestamp, c) Storing the data packet on a storage unit accessible by terminal equipment, d) Reading an information carrier assigned to the individual identification of the issuing point with an end device, wherein the information carrier includes static connection information for retrieving the retrievable storage unit assigned to the individual identification of the issuing point, e) Retrieving the accessible storage unit with the terminal device using the read static connection information, and f) Providing the data package with the individual identification matching the retrieval and the most recent timestamp from the retrievable storage unit to the retrieving terminal device.

[0031] The inventive method provides data packets to selected terminal devices, whereby the data processing system used in the method does not need to receive any individual information from the selected terminal device, so that the provision is anonymous.

[0032] Although the method according to the invention is generally suitable for providing different data packages, it is particularly preferred that the data packages are digital documents.

[0033] A digital receipt is a compilation of data that includes, in particular, payment information and details about the company that created the digital receipt. Digital receipts are intended for distribution to customers and may contain further information, such as details of promotional offers and / or voucher programs.

[0034] In the method according to the invention, a data package is first generated, which can in particular be a digital receipt. This generation is carried out, for example, by a point-of-sale system, which can be a single cash register or a network of several cash registers connected to each other in a larger data processing system. A digital receipt can be generated, for example, by a waiter using a mobile payment device to settle the bill for food consumed at the table, or by a cashier recording purchased goods with a cash register and processing the transaction, whereupon a data processing device creates the digital receipt.

[0035] Within the scope of the present invention, the devices used to record the invoice data, for example, the mobile billing device used by a waiter to record the bill or the cashier's cash register, are referred to as the issuing point, because in analogous processes with printed receipts, the receipt would typically also be issued to the customer at these points. The device used for billing, i.e., the issuing point, is either alone or in conjunction with other devices part of a data processing system suitable for carrying out the method according to the invention and through which the anonymous provision of the data packet to the terminal device takes place.

[0036] Each issuing point is assigned a unique identifier. This unique identifier is regularly unique within the data processing system and serves to identify the issuing point within the system. The unique identifier can also contain additional information about the issuing point or be assigned based on it, in particular system parameters of the device used at the issuing point to create the data package, as well as other markers such as the responsible employee, the number of the table served, the location at the time of settlement, or other parameters, regardless of whether these are later included in the digital receipt.

[0037] A preferred method according to the invention is therefore one in which each dispensing point is assigned its respective individual identification depending on one or more parameters, in particular depending on the location and / or the area of ​​responsibility and / or the responsible operator.

[0038] The data packet generated in step a) is linked to the individual identification of the corresponding output point. This allows the generated data packet to be assigned to the corresponding output point. Furthermore, the generated data packet is linked to a timestamp. Within the scope of the present invention, a timestamp is essentially any information that enables a chronological arrangement of the timestamped data packets.

[0039] In the method according to the invention, the generated data packet is stored on a storage unit accessible by end devices, which in turn is part of the data processing system. In the method according to the invention, the order in which steps b) and c) are executed is irrelevant, and simultaneous execution is also possible. For example, the linking of the data packet with the individual identification of the issuing point and the timestamp can take place before, simultaneously with, or after the data packet is stored on the storage unit accessible by end devices.

[0040] According to the invention, the storage unit is accessible from end devices. Within the scope of the present invention, the term "end device" refers to devices with which the customer retrieves the generated data packet. Thus, the end device used in the inventive method is not part of the data processing system that the company must set up in order to carry out the inventive method. The accessible storage unit must therefore be accessible during the intended operation of the customer's end devices. This retrieval can, for example, be carried out via a wireless connection, in particular a wireless internet connection.

[0041] A particularly relevant example in practice of a storage unit accessible by end devices is a server connected to the internet and accessible via connection information.

[0042] In step d) of the method according to the invention, for example by a customer, an information carrier is read using an end device. This information carrier is assigned to the individual identification of the issuing point. The corresponding information carrier comprises static connection information for the direct or indirect, i.e., for the indirect or direct, retrieval of the retrievable storage unit, i.e., for example, the server, wherein the static connection information is assigned to the same individual identification of the issuing point as the information carrier itself.

[0043] A preferred method according to the invention is wherein the static connection information comprises a link to an object on the retrievable storage unit.

[0044] Although this is usually disadvantageous for practical application, one of the simplest ways to implement the information carrier is theoretically by using a piece of paper on which the static connection information is written out as a link. This link can be read by the end device, if necessary with the involvement of the device user, to obtain the static connection information for retrieving the accessible storage unit. The assignment of the static connection information for retrieving the accessible storage unit to the individual identification of the issuing point is achieved, for example, by assigning the target on the accessible storage unit to which the static connection information refers.In the more practically relevant cases, the information carrier assigned to the individual identification of the issuing point is a QR code or an NFC chip, which can be easily read with commercially available devices, such as mobile phones, and enables automatic reading of the static connection information.

[0045] Within the scope of the present invention, specifying the connection information as static connection information means that the information carrier is provided and intended for reading by several terminal devices in the course of providing several different digital documents, wherein the static connection information, i.e., for example, the link to the retrievable storage unit, does not change between 2 or more, preferably 10 or more, particularly preferably 100 or more, and most preferably 1000 or more, retrievals.

[0046] A method according to the invention is particularly preferred in which steps a) to f) are performed n times to retrieve data packets by different terminal devices, reading the same information carrier and using the same static connection information, where n = 2 or more, preferably 10 or more, particularly preferably 100 or more, most preferably 1000 or more.

[0047] Methods according to the invention are particularly preferred in which the static connection information contained by the information carrier cannot be modified by the output point.

[0048] The foregoing statements mean that an information carrier with static connection information can also exist if the form of representation is not static in the sense of being permanent and unchanging. For example, a sticker with a printed QR code that does not change until the sticker is manually removed is in any case an information carrier with static connection information within the meaning of the present invention. At the same time, however, it might be possible to implement the corresponding QR code not by means of a sticker, but by displaying it on a digital display surface, even though this solution is explicitly not preferred in view of the additional effort required for electronic infrastructure.In this case, the term static connection information applies if the displayed QR code is intended for multiple uses by end devices and is not regenerated depending on each new digital document to be provided, i.e., it is not adapted to a new individual link for each digital document to be provided, i.e., dynamic connection information.

[0049] In the method according to the invention, in step e) the terminal device retrieves the accessible storage unit, using the static connection information read from the information carrier. The corresponding retrieval thus contains information recognizable to the accessible storage unit about individual information of the issuing point to which the information carrier is assigned. The retrieval of the accessible storage unit by the terminal device in step e) can be carried out either directly or indirectly, for example by interposing a further data processing device, such as a forwarding server, which facilitates the retrieval of the accessible storage unit by the terminal device by generating dynamic connection information.

[0050] As a result of the retrieval in step e), the method according to the invention provides the retrieving terminal device with each data packet from the retrievable storage unit that not only matches the individual identification of the issuing point associated with the retrieval, but also has the most recent timestamp for the corresponding individual identification. In principle, various implementations are conceivable for this step, which can be realized by the retrievable storage unit.For example, methods according to the invention are preferred in which the retrievable storage unit is configured such that, when retrieved by an end device, it can only provide the data packet with the most recent timestamp for each individual identification, and / or in which step c) is carried out in such a way that, at least temporarily, preferably at all times, all data packets except the data packet with the most recent timestamp are deactivated and / or archived for a given individual identification, so that they are no longer retrievable, and / or in which stored data packets on the retrievable storage unit are deactivated and / or archived after a predetermined number of retrievals by an end device, so that they are no longer retrievable.

[0051] Since these methods regularly exhibit particularly high user acceptance and require particularly low investment, methods according to the invention are preferred, wherein the terminal device does not include a data processing program specifically tailored to the method and / or wherein the terminal device is not registered for use in the method, and / or wherein no electronic devices for displaying variable connection information to the terminal device are provided at the output point.

[0052] Steps a), b), c), and f) of the method according to the invention are the steps that are not performed by the customer's terminal device, but for which the infrastructure is regularly provided by the business. Accordingly, these steps are performed by a data processing system. This data processing system expediently comprises a data processing device with at least one output point, the output point being understood as defined above. Furthermore, the data processing system includes the retrievable storage unit. In the simplest case, which would probably be rather rare in practice, the data processing system could, for example, be formed by a single cash register or a single mobile payment terminal.In this case, the relevant device is both the issuing point and the data processing device used to create the digital receipt. It must also include a storage unit accessible to the end device, so that this device, for example, because it is connected to the internet, can also constitute the accessible storage unit. In practice, the data processing system will regularly consist of a central data processing device, such as a point-of-sale system, which is connected to numerous separate issuing points, such as various cash registers, potentially in different branches. In this case, the accessible storage unit could, in principle, be the data processing device itself. However, a data processing system in which the accessible storage unit is decentralized and connected to multiple data processing devices is particularly preferred.

[0053] Thus, methods according to the invention are preferred, wherein steps a), b), c) and f) are carried out by a data processing system, wherein the data processing system preferably comprises a data processing device with at least one output point, in particular a cash register system with at least one output point, and the retrievable storage unit, wherein the at least one output point is preferably a cash register or a mobile billing point.

[0054] A method according to the invention is particularly preferred, wherein the retrievable storage unit is a retrievable server, which is preferably connected to several data processing devices.

[0055] In practice, such methods according to the invention have proven particularly advantageous in which the information carrier is a QR code, an RFID chip, or an NFC chip on which the static connection information is stored. Given the widespread use of mobile phones, these information carriers, which are particularly easy and convenient to read, have proven their worth, especially since they are particularly easy to attach and inexpensive to provide. The corresponding information carriers can be read with all commercially available mobile devices and eliminate the need to manually enter complex connection information. With regard to the method according to the invention, it has proven particularly advantageous to place the information carrier at the point of issue or...The digital receipt should be placed near the point of issue so that customers can receive their receipts at the same location where they are accustomed to receiving them using traditional methods. Possible examples of where to place the receipt include in the checkout area of ​​a supermarket or on a waiter's payment terminal.

[0056] Therefore, methods according to the invention are preferred, wherein the information carrier is a QR code or an RFID chip, preferably a QR code or an NFC chip, wherein the terminal device comprises means for reading the information carrier, wherein the information carrier is preferably arranged at or near the point of issue, and / or wherein the terminal device is a mobile terminal device, preferably a mobile phone or a tablet computer.

[0057] In particularly preferred methods according to the invention, the information carrier is a sticker or a plaque, in particular a sticker or a plaque with a QR code.

[0058] In principle, the method according to the invention can be implemented with any type of timestamp, provided that this timestamp allows for a chronological classification of the digital documents generated for each individual identification. However, it has proven advantageous to provide the timestamp in such a way that it correlates with the time of generation of the data packet. In a particularly simple embodiment, the timestamp corresponds exactly to the time of generation of the data packet.

[0059] A preferred method is therefore one according to the invention in which the timestamp includes information that correlates with the time of generation of the data packet.

[0060] Regarding the organization of the retrievable storage unit, it has proven effective to generate so-called stacks of data packets for each individual identification within the retrievable storage unit. This means that the data packets belonging to an individual identification are not stored arbitrarily on the retrievable storage unit after generation, but are grouped together in a stack-like manner, such that only the topmost data packet of a stack is retrievable at any given time, with the most recently generated data packet being stored as the topmost and thus retrievable data packet on each stack. A preferred method according to the invention is one in which the retrievable storage unit comprises a separate stack of data packets for each individual identification.

[0061] Although various solutions are conceivable in principle to provide only the data packet with the most recent timestamp for a specific individual identification upon request by an end device, in practice it has proven particularly efficient to execute the request in such a way that a dynamic connection information is generated from the read static connection information and the time of the request by a corresponding algorithm, which includes a link to the corresponding data packet with the individual identification matching the request and the most recent timestamp on the retrievable storage unit.

[0062] A method according to the invention is therefore particularly preferred, wherein the provision in step f) is carried out by correlating the static connection information with the time of retrieval in order to generate dynamic connection information which includes a link to the data packet with the individual identification matching the retrieval and the most recent timestamp on the retrievable storage unit, wherein the dynamic connection information is preferably generated only as a result of a retrieval by an end device.

[0063] With knowledge of the invention, a corresponding algorithm or application that performs this correlation and creates the dynamic connection information is programmable for the person skilled in the art based on their specialist knowledge, whereby they can adapt it to the infrastructure and the needs of their respective data processing system.

[0064] The preferred method according to the invention described above has proven to be particularly advantageous, especially with regard to the wide range of safeguarding options that can be provided, and is, in the opinion of the inventors, superior to alternative solution concepts in this respect.

[0065] Correlation can be performed, for example, by the accessible storage unit or by a computer program product located on it. However, configurations in which correlation is performed by a separate forwarding server positioned upstream of the accessible storage unit are particularly preferred. This setup has proven especially effective because the forwarding server, which in this case forms part of the data processing system, can be centrally provided by a single vendor for multiple data processing devices, such as point-of-sale systems. This also allows for centralized security measures to be implemented at the forwarding server level.A preferred method according to the invention is therefore one in which the correlation is preferably carried out by a forwarding server, particularly preferably by a forwarding server which is connected to several devices for data processing, and in which separate dynamic connection information is preferably generated for each data packet.

[0066] The forwarding server ultimately only needs information on how the data packets are stored on the retrievable storage unit depending on the individual identification and the timestamp, or which connection information is assigned to a corresponding data packet on the retrievable storage unit, in order to generate the associated dynamic connection information as a result of a retrieval by an end device that includes information about the individual identification and taking the timestamp into account, by which the retrieving end device is directed to the corresponding data packet on the retrievable storage unit.

[0067] As explained above, a major advantage of the method according to the invention and the preferred embodiment lies in the fact that various protective measures can be provided particularly efficiently to make the method especially secure. This may be necessary in some cases to ensure particularly comprehensive protection of potentially sensitive information.

[0068] It has proven to be a particularly efficient security measure if the dynamic connection information generated in the preferred method according to the invention—i.e., the connection information for the most recent data packet generated from the static connection information—is only retrievable after a separate authorization, for example, by the cashier pressing a physical or digital button at the dispensing point, and only for a predetermined number of retrievals or for a specific period of time. For particularly sensitive information, it has proven effective to limit the number of retrievals to a single retrieval, whereas for less critical situations, such as a supermarket checkout, it may be advantageous to allow at least a second retrieval should problems arise during the first attempt.

[0069] A particular advantage of the preferred embodiment of the inventive method for generating dynamic connection information lies in the fact that this dynamic connection information can be hidden from the user of the terminal device. While the static connection information stored in the information carrier is thus, in principle, accessible to everyone, the connection information that actually leads to the digital document is additionally protected, so that even unintentional subsequent access by the user of the accessing terminal device can be prevented.

[0070] A preferred method according to the invention is therefore one in which the dynamic connection information is only usable for a predetermined time after the generation of the data packet and / or only for a predetermined time after release at the output point and / or only for a predetermined number of retrievals, wherein the dynamic connection information is preferably hidden in such a way that it cannot be retrieved separately by the user of the terminal device.

[0071] As explained above, the basic embodiment of the method according to the invention provides that, for each individual identification, the data package with the most recent timestamp is available for retrieval. However, particularly with sensitive data, it can be advantageous if, after a predetermined time and / or a predetermined number of retrievals, and possibly other factors, the data packages with the most recent timestamp are automatically deactivated or archived.The benefit of such a device is particularly evident to those skilled in the art when considering, for example, the last billing transaction of the business day, which would otherwise result in the corresponding digital document being accessible on the server overnight until the next business day, especially if a method is chosen that does not rely on the dynamic connection information method described above as preferred. A preferred method in this respect is one in which stored data packets on the retrievable storage unit are deactivated and / or archived after a predetermined time, regardless of retrieval by an end device or other factors, so that they are no longer retrievable.

[0072] Additionally or alternatively, retrieving the accessible storage unit with the terminal device using the static connection information or the dynamic connection information generated from it can be secured with further protective measures, which can advantageously be implemented particularly easily in the method according to the invention. One possibility is the entry of a password or a PIN, whereby in our own tests it has proven particularly practical to use the invoice amount, e.g., the last four digits of the invoice amount, as the PIN, since this information is quickly available and at the same time largely variable, in order to directly identify the authorized customer and their terminal device on site.

[0073] Additionally or alternatively, a further information carrier containing additional authentication information can be provided at the point of dispensing, thus enabling authentication according to the public-private key principle. In this process, the information carrier is first scanned using the method according to the invention, whereupon the user is prompted to read a further information carrier containing the locally available key for unlocking the static connection information, which can only be consciously released at the point of dispensing, for example, by the waiter or cashier.

[0074] It has also proven particularly efficient to read the location information of the end device for authentication purposes and compare it with a predetermined location, namely, in particular, the location of the issuing point. In other words, in many practically relevant scenarios, it can be assumed that the customer retrieving the digital receipt is, within a certain margin of error, near the corresponding issuing point or within the area of ​​responsibility of a waiter.

[0075] Preferred are methods according to the invention, wherein the retrieval of the retrievable storage unit with the terminal device is carried out using the static connection information. i) requires the entry of a password or PIN, and / or ii) requires the reading of another information carrier, and / or ii) can only take place if the location information of the terminal device matches a predetermined location information, in particular the location information of the issuing point.

[0076] In addition to preventing unwanted access, it can be important to ensure traceability as to whether, despite security measures, unauthorized access may have occurred. For such cases, the methods according to the invention are preferred, wherein each retrieval of the data packet from the accessible storage unit is recorded as information within the data packet, which is also transmitted to the terminal device with each subsequent retrieval.

[0077] In addition to preventing and documenting unauthorized access, it is often advantageous, with a view to minimizing further consequential damage, to implement measures that prevent a detected intruder, e.g., a third party unauthorized to access the documents, from causing further damage. The inventors recognized that the inventive method achieves a particularly high level of security when terminal devices are blocked that exhibit a specific usage pattern which contradicts the retrieval behavior intended within the framework of the inventive method and / or, depending on its identification parameters, do not belong to the group of expected retrieving terminal devices.In particular, the latter, if implemented as a general rule, advantageously also provides a fundamental protective effect, for example, if a regionally active company is generally blocked from accessing data whose identification parameters indicate that the access originates from abroad. Similarly, in many cases, it can be assumed that the provided digital documents will be retrieved using mobile devices, so it may be beneficial to generally block access from non-mobile devices, such as desktop computers, because misuse is more likely in these cases.

[0078] The inventors recognized that the concept of partially blocking endpoints can also be used in cases where authentication, as described above as the preferred method, does not succeed immediately or after a certain number of attempts. Suspicious access behavior would, for example, be the repeated retrieval of static and / or dynamic connection information from the same IP address.

[0079] A preferred method according to the invention is wherein an end device which directs one or more requests to the retrievable storage unit is at least temporarily blocked while all stored data packets with the associated individual identification are deactivated and / or archived, and / or while the dynamic connection information generated from the static connection information is not usable for retrieval, and / or wherein the end device is blocked from retrieving the data packet based on identification parameters, in particular its location and / or its retrieval behavior, wherein preferably all non-mobile end devices are blocked from retrieval.

[0080] The inventors have recognized that a special level of safety can be achieved in the inventive method if the static connection information is changed at predetermined intervals or after predetermined events.

[0081] If an NFC chip is used as the information carrier, the static connection information stored in the NFC chip can be deliberately changed, for example, after misuse has been observed. It should be noted that despite the fundamental possibility of modification, this information remains static and is intended for use in many different requests from separate devices. However, in individual cases, it may be advisable to change the static connection information again after a digital receipt has been issued, for example, because further misuse has been detected.

[0082] A preferred method according to the invention is wherein the information carrier is an NFC chip and wherein the static connection information in the NFC chip is changed at predetermined intervals and / or after predetermined events, wherein the change preferably takes place using encrypted communication with the NFC chip and wherein the changed static connection information is preferably only readable by the terminal device when the change process has been completed.

[0083] Since, unlike NFC chips, subsequent adjustment of static connection information is not easily possible with other information carriers, such as stickers with QR codes, the inventors have developed a concept to enable updates of the static connection information even in this case. Here, each issuing point is assigned two or more information carriers, which can be provided to the company together, for example, in the form of several stickers. Of these, only one of the stored static connection information is active at any given time, so that one of the information carriers can fulfill the role of the information carrier in the inventive method.If no static connection information is set as active on the server side, the first static connection information read and used for retrieval is subsequently set as active and can then be used in the method according to the invention. After a certain criterion is met, for example, a certain number of connection attempts, the previously active static connection information can be deactivated so that, according to the principle described above, one of the remaining static connection information can be activated, for example, after the sticker has been covered over.Several scenarios are conceivable for the fate of the previously active information carrier, whereby, particularly in view of the reusability of a limited quantity of information carriers, it is advantageous to block a previously used information carrier only for a certain period of time or even only for the determination of the next activated connection information.

[0084] A preferred method according to the invention is therefore one in which two or more information carriers with static connection information are assigned to the individual identification of the output point, of which at most one static connection information is active, wherein, if no static connection information is active, the first static connection information read out and used for retrieval is set as active, so that the remaining static connection information is inactive from this point on.

[0085] A preferred method according to the invention is wherein the active static connection information is deactivated after a certain number of uses and / or after the occurrence of another criterion, so that a different static connection information read out and used for retrieval after deactivation is set as active.

[0086] Alternatively, a preferred method according to the invention is also preferred, wherein the active static connection information is deactivated as soon as another information carrier assigned to the individual identification of the output point, whose static connection information is not active, is read out, wherein the static connection information of the last read out information carrier is set as active.

[0087] A particularly preferred method according to the invention is also preferred, wherein the static connection information deactivated after prior activation is available for further use. i) completely, or ii) for a specific period of time, or iii) only for determining the next activated static connection information, will be blocked.

[0088] From the foregoing, it is evident to a person skilled in the art that the invention also relates to a data processing system comprising means for carrying out steps a), b), c) and f) of the method according to the invention. The corresponding data processing system is not only suitable for carrying out steps a), b), c) and f) of the method according to the invention, but also includes means specifically designed for carrying out these steps.

[0089] A preferred system according to the invention for data processing comprises a device for data processing with at least one output point, in particular a cash register system with at least one output point, and a retrievable storage unit, wherein the at least one output point is preferably a cash register or a mobile billing unit, and wherein the retrievable storage unit is preferably a retrievable server, which is preferably connected to several devices for data processing, wherein the retrievable storage unit is most preferably spatially separated from the device for data processing.

[0090] A particularly preferred system for data processing according to the invention additionally comprises a forwarding server, comprising means for correlating the static connection information with the time of retrieval in order to generate dynamic connection information, which includes a link to the data packet with the individual identification matching the retrieval and the most recent timestamp on the retrievable storage unit.

[0091] Within the scope of the present invention, the information carrier read out in the inventive method can also be assigned to the inventive data processing system. A data processing system according to the invention comprising at least one information carrier is preferred, wherein the information carriers are preferably arranged at the associated output points.

[0092] It is evident to the person skilled in the art that the present invention further relates to a computer program product comprising instructions which, when the computer program is executed by a data processing device of a data processing system, preferably a data processing system according to the invention, cause the latter to execute steps a), b), c) and f) of the method according to the invention.

[0093] Finally, a computer-readable data carrier on which the computer program product according to the invention is stored and a data carrier signal that transmits the computer program product according to the invention are also disclosed.

[0094] A preferred embodiment of the invention is explained and described in more detail below with reference to the accompanying drawing. The drawing shows: Fig. 1 A schematic representation of a data processing system according to the invention in a preferred embodiment.

[0095] Fig. Figure 1 schematically shows a data processing system 28 according to the invention, the central component of which is a retrievable storage unit 18. The retrievable storage unit 18 is connected to a forwarding server 24 and, in this example, to two data processing devices 22a and 22b. The first data processing device 22a has three output locations 16a, 16b, and 16c, each with its corresponding individual identifiers 14a, 14b, and 14c. Similarly, the second data processing device 22b has three assigned output locations 16b, 16e, and 16f, each of which is assigned its corresponding individual identifier 14d, 14e, and 14f.

[0096] Each of the output points 16a - 16f shown has an information carrier 20a, 20b, 20c, 20d, 20e, 20f assigned to output point 16a - 16f. A data packet 10a, 10b, 10c, 10d, 10e, 10f, for example a digital receipt, which is generated at one of the output points 16a - 16f or in the data processing devices 22a, 22b, is stored on the retrievable storage unit 18 together with the previously generated data packets 10a, 10b, 10c, 10d, 10e, 10f of the corresponding individual identification 14a - 14f, so that stacks 26a, 26b, 26c, 26d, 26e, 26f of data packets are formed, each assigned to an individual identification 14a - 14f and in which only the topmost data packet 10a - 10f is active. The sorting criterion for the stacks 26a - 26f is the time or the timestamp, which in Fig. 1 is indicated by the ascending arrow and the sketched clock, as well as the respective individual identification 14a - 14f.

[0097] In the Fig. In the example shown, the two data processing devices 22a, 22b are to be understood as central data processing devices 22a, 22b of two cash register systems in two spatially separate companies, to which three cash registers as dispensing points 16a, 16b, 16c or three mobile billing devices of waiters as dispensing points 16d, 16e, 16f are assigned, whose respective information carriers 20a - 20f with the static connection information are each attached near the dispensing points.

[0098] In Fig. Figure 1 schematically shows how a customer wants to collect the receipt from the issuing point 16a using the terminal device 12, whereby the method according to the invention is carried out in a preferred embodiment. In the interaction of the issuing point 16a and the data processing device 22a, a data package 10a is generated, which is provided with the corresponding individual identification 14a and a corresponding timestamp, so that it is stored on the retrievable storage unit 18 on the associated stack 26a and the generated data package 10a is retrievable as the most recent data package 10a, while all underlying data packages 10a of the stack 26a are deactivated or archived, so that they are no longer retrievable.The customer now uses terminal device 12 to read the information carrier 20a assigned to the output point 16a in order to read the static connection information contained in this information carrier 20a for retrieving the retrievable storage unit 18, which is assigned to the individual identification 14a.In the schematically outlined preferred method according to the invention, the retrieval of the retrievable storage unit 18 is carried out indirectly via an intermediate forwarding server 24, in which the static connection information from the information carrier 20a is correlated with the time of retrieval by the terminal device 12 in order to generate dynamic connection information that includes a link to the corresponding data packet 10a with the individual identification 14a matching the retrieval and the most recent timestamp, so that the corresponding document 10a is provided to the terminal device 12 without the system for data processing 28 requiring any further information from the terminal device 12, so that the provision can be anonymous.

[0099] In the Fig. In the example shown, the terminal device 12 is a mobile terminal device 12, namely a mobile phone. Fig.1. The information carriers 20a - 20f are also each designed as a sticker with a QR code, which can be read via a camera built into the terminal device 12 and evaluated with commercially available pre-installed software.

[0100] The data package 10a, retrieved by the customer using an end device 12, can then be viewed and further processed by the customer using a standard web browser, for example, saved or sent as an email. If suitable software is installed on the end device 12, the digitally provided document can also be used to digitally authorize a necessary payment. Reference symbol list 10a-10f data packet 12 End device 14a-14f Individual Identification 16a-16f Issuing point 18 retrievable storage units 20a-20f Information carrier 22a, 22b Device for data processing 24 forwarding servers 26a-26f Stack 28 Data processing system

Claims

[1] Methods for anonymously providing data packets (10a-10f), in particular digital documents, to selected terminal equipment (12), comprising the steps: a) Generating a data package (10a-10f), in particular a digital document, b) Linking the data package (10a-10f) with an individual identification (14a-14f) of an issuing office (16a-16f) and a timestamp, c) Storing the data packet (10a-10f) on a storage unit (18) accessible by terminal equipment (12), d) Reading one of the information carriers (20a-20f) assigned to the individual identification (14a-14f) of the issuing office (16a-16f) with an end device (12), wherein the information carrier (20a-20f) comprises static connection information for retrieving the retrievable storage unit (18) assigned to the individual identification (14a-14f) of the issuing office (16a-16f), e) Retrieving the retrievable storage unit (18) with the terminal device (12) using the read static connection information, and f) Providing the data packet (10a-10f) with the individual identification (14a-14f) matching the retrieval and the most recent timestamp from the retrievable storage unit (18) to the retrieving terminal device (12). [2] Method according to claim 1, wherein steps a), b), c) and f) are performed by a data processing system (28), wherein the data processing system (28) preferably comprises a data processing device (22a, 22b) with at least one output point (16a-16f), in particular a cash register system with at least one output point (16a-16f), and the retrievable storage unit (18), wherein the at least one output point (16a-16f) is preferably a cash register or a mobile billing point. [3] Method according to one of claims 1 or 2, wherein the information carrier (20a-20f) is a QR code or an RFID chip, preferably a QR code or an NFC chip, wherein the terminal device (12) comprises means for reading the information carrier (20a-20f), wherein the information carrier (20a-20f) is preferably arranged at the dispensing point (16a-16f) or in the vicinity of the dispensing point (16a-16f). [4] Method according to any one of claims 1 to 3, wherein the retrievable storage unit (18) comprises a separate stack (26a-26f) of data packets (10a-10f) for each individual identification (14a-14f). [5] Method according to any one of claims 1 to 4, wherein the provision in step f) is carried out by correlating the static connection information with the time of retrieval to generate dynamic connection information which includes a link to the data packet (10a-10f) with the individual identification (14a-14f) corresponding to the retrieval and the most recent timestamp on the retrievable storage unit (18), wherein the correlation is preferably carried out by a forwarding server (24). [6] Method according to any one of claims 1 to 5, wherein the retrievable storage unit (18) is configured such that, when retrieved by an end device (12), it can provide only the data packet (10a-10f) with the most recent timestamp for each individual identification (14a-14f). [7] Method according to any one of claims 1 to 6, wherein step c) is carried out such that at least temporarily, preferably at all times, for a given individual identification (14a-14f) all data packets (10a-10f) except the data packet (10a-10f) with the most recent timestamp are deactivated and / or archived, so that they are no longer retrievable by the terminal device (12). [8] Method according to any one of claims 1 to 7, wherein the terminal device (12) does not include a data processing program specifically tailored to the method and / or wherein the terminal device (12) is not registered for use in the method, and / or wherein no electronic devices for displaying variable connection information to the terminal device (12) are provided at the output point (16a-16f). [9] Data processing system (28) comprising means for carrying out steps a), b), c) and f) of the method according to any one of claims 1 to 8. [10] Computer program product comprising instructions which, when the computer program is executed by a data processing device (22a, 22b) of a data processing system (28), cause the latter to perform steps a), b), c) and f) of the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method for depicting information

    EP2275986A1

  • Electronic receipt issuing system

    EP3043304A1

  • System and Method for Generating and Storing Digital Receipts for Electronic Shopping

    US20140244462A1

  • Receipt production system, printer, and receipt production method

    US20150254633A1

  • Electronic receipt manager apparatuses, methods and systems

    WO2012155081A1