PROCEDURES FOR PROVIDING EVIDENCE

DE602021058509T2Active Publication Date: 2026-08-12TAQT SOLUTIONS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602021058509
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-05-27
Filing Date
2021-05-27
Publication Date
2026-08-12
Estimated Expiration
2041-05-27

AI Technical Summary

Technical Problem

Existing proof-of-presence systems are complex to implement, require contact or specific equipment, are vulnerable to fraud, and lack user identification, posing hygiene and security risks.

Method used

A system and method using a digital device with a screen displaying dynamic matrix codes, initialized with random parameters, encrypting data, and synchronized with a server, allowing contactless, tamper-proof presence validation without external connections.

Benefits of technology

Provides a simple, secure, and hygienic method for verifying presence, resistant to fraud, with energy-efficient, self-sufficient equipment and precise synchronization.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Technical field of the invention

[0001] The invention relates to a method for providing proof of presence at a predefined location, based on the scanning of a matrix code. The invention also relates to digital equipment comprising a screen capable of displaying a dynamic matrix code. The invention further relates to a system for providing proof of presence at a predefined location. Prior art

[0002] In many fields, there is a need to signal or prove a person's presence at a particular location. For example, in the home care sector, employees may be required to make rounds that take them to different locations. Various systems have been proposed to remotely monitor the smooth running of these rounds.

[0003] First, there are known systems for providing proof of presence, such as time clocks with an electronic device equipped with a button. The device is connected via a wired or wireless connection to a remote server. When a user presses the button, the server receives information confirming a person's presence at the device. These systems are complex to implement because they require a powered device connected to the server. Furthermore, these systems do not allow for the identification of the person who pressed the button. The button can be pressed by anyone, leading to false attendance records. Finally, such systems require contact between the user's finger and the button.For hygiene reasons and / or to avoid the transmission of diseases, it is best to avoid contact with buttons that other people may have handled previously.

[0004] We also know of contactless proof-of-presence systems based on NFC (Near Field Communication) technology. While such systems can prove a user's presence and identify them without contact, these solutions are complex to implement and require each user to be equipped with a specific NFC badge.

[0005] Finally, there are also systems for providing proof of presence that rely on the use of matrix codes, such as QR codes. A given matrix code is printed and affixed to a predefined location. When a person wishes to confirm their presence at that location, they scan the matrix code with their smartphone. This action triggers the transmission of a message to a server connected to the smartphone, which records the presence. Such systems have the advantage of being contactless and simple to implement. However, they can be easily misused. Indeed, a malicious user can take a picture of the matrix code, print this picture, and then repeat the scanning process from anywhere.

[0006] To overcome this difficulty, systems for providing proof of presence are now available, including equipment capable of displaying variable matrix codes. These matrix codes are transmitted by the equipment to a server. When a person wishes to confirm their presence at a given location, they scan the matrix code with their smartphone. This action triggers the transmission of a message to a server connected to the smartphone. The server can then compare the matrix code received from the smartphone with the matrix code transmitted directly by the equipment. If these two codes are identical, it can be deduced that a user was indeed present at the predetermined location for scanning the matrix code. Such a system is more reliable but complex to implement, notably because it requires communication between the equipment and the server and that the equipment be connected to the electrical grid.

[0007] The prior art is known for example from US2018285546A1 which describes a method for providing proof of presence at a predefined location, based on a code. Presentation of the invention

[0008] The object of the invention is to provide a system and method for providing proof of presence which remedies the above disadvantages and improves upon the systems and methods for providing proof of presence known in the prior art.

[0009] The invention is defined by the attached claims.

[0010] More specifically, a first object of the invention is a system and method for providing proof of presence that is simple to install, in particular not requiring means of communication between equipment and a server.

[0011] A second object of the invention is a system and method for providing tamper-proof proof of presence.

[0012] A third object of the invention is a system and method for providing contactless proof of presence. Summary of the invention

[0013] The invention relates to a method for providing proof of presence at a predefined location, the method comprising: an initialization step during which initialization data for a digital device is transmitted to a server, the device being installed at the predefined location, the device being equipped with a screen capable of displaying a matrix code, the initialization data comprising: a starting index, at least one calculation parameter, and a refresh rate data, then an iterative calculation step by the device, according to the refresh rate, of a temporal index, the temporal index being equal to the result of an operation based on the at least one calculation parameter and on the temporal index calculated during a previous iteration of the calculation step, an initial value of the temporal index being equal to the result of an operation based on the at least one calculation parameter and on the starting index, then a step of displaying a validation matrix code on the device's screen,The validation matrix code includes the calculated time index, followed by a presence validation step at the predefined location, comprising a sub-step of scanning the validation matrix code displayed on the equipment screen using a communication terminal, and then a sub-step of transmitting the time index from the scanned validation matrix code to the server via the communication terminal.

[0014] The validation matrix code may also include a computer address of the server.

[0015] The initialization step may include a sub-step of transmitting initialization data to the server using a communication terminal, such as a smartphone.

[0016] The initialization step may include: a sub-step of displaying on the equipment screen an initialization matrix code including a computer address of the server and said initialization data, then a sub-step of scanning by a communication terminal of the initialization matrix code, then a sub-step of transmitting to the server, by the communication terminal, the initialization data from the scanned initialization matrix code.

[0017] The initialization step can be automatically executed as soon as the equipment is powered on, the said display substep having a predefined duration, in particular a duration of between ten seconds and ten minutes inclusive.

[0018] The starting index and / or at least one calculation parameter can be set randomly by the equipment.

[0019] The proof-of-presence method may include an equipment encryption step of the initialization data, including XOR or AES encryption, followed by a server decryption step of the received initialization data, and / or it may include an equipment encryption step of the calculated time index, including XOR or AES encryption, followed by a server decryption step of the received time index.

[0020] The initialization data and / or validation matrix code may include a voltage value from an energy storage means of the equipment.

[0021] The initialization step and / or the validation step of a presence at the predefined location may further include the transmission to the server, by the communication terminal, of a communication terminal identifier and / or a communication terminal user identifier and / or an equipment identifier and / or a timestamp data indicating the time at which the validation matrix code was scanned.

[0022] The step of validating a presence at the predefined location may include a sub-step of comparison by the server of the time index received from the communication terminal with a time index calculated by the server using a method identical to that used by the equipment to calculate the time index during said calculation step.

[0023] The invention also relates to a digital device comprising a screen capable of displaying a dynamic matrix code, an energy storage means and hardware and software means configured to randomly generate at least one calculation parameter and a starting index, and to iteratively calculate, at a refresh rate, a time index, the time index being equal to the result of an operation based on at least one calculation parameter and on a time index calculated during a previous iteration, an initial value of the time index being equal to the starting index.

[0024] The equipment may include an electronic ink display device.

[0025] The equipment may include a means of producing electrical energy, in particular a photovoltaic means.

[0026] The equipment may include fastening means intended to cooperate with a support, the fastening means being configured such that manipulation of the fastening means to detach the equipment from the support results in disconnection of the energy storage means.

[0027] The invention also relates to a proof-of-presence system comprising a server, and equipment equipped with a screen capable of displaying a dynamic matrix code and / or equipment as defined above, the equipment and the server comprising hardware and software means configured to implement a proof-of-presence method as defined above.

[0028] The invention also relates to a computer program product comprising program code instructions recorded on a computer-readable medium to implement the steps of the proof-of-attendance method as defined above when said program is running on a computer.

[0029] The invention also relates to a computer-readable data recording medium on which is recorded a computer program comprising program code instructions for implementing the proof-of-attendance provision method as defined above. Presentation of the figures

[0030] These objects, features and advantages of the present invention will be described in detail in the following description of a particular embodiment, given by way of non-limiting example, with reference to the accompanying figures, among which: [ Fig. 1 ] There figure 1is a schematic view of a system for providing proof of presence according to an embodiment of the invention. Fig. 2 ] There figure 2 is a synoptic diagram of a method for providing proof of presence according to an embodiment of the invention. Detailed description

[0031] There figure 1This schematically illustrates a system for providing proof of presence 1 according to an embodiment of the invention. A system for providing proof of presence is a control system designed to signal and / or attest to the presence of a person or product at a specific location. Such a system can, in particular, be used to verify the proper execution of a route across different geographical locations. As a specific example, and without limitation, the system for providing proof of presence can, for instance, be used to attest to the passage or presence of an employee in different rooms of a building, for example, to perform maintenance or cleaning services. Other examples of applications of the invention will be developed later.

[0032] The system for providing proof of presence, more simply referred to as "system 1", includes on the one hand at least one digital device 10 and on the other hand a server 20.

[0033] The digital device 10 is installed in a predefined location. This location could be, for example, a private space, such as an office, a room, or a common area in a building. The predefined location could be in a restricted access zone. It could also be positioned outdoors, for example, in front of a building, apartment block, or private residence. The predefined location could also be in a public place, such as a train station, hospital, or administrative building. It could also be installed on public transportation, such as a train or bus.

[0034] The digital equipment 10 includes fastening means 11 arranged to fix the digital equipment in the predefined location. These fastening means may include, for example, mounting holes and / or screws and / or rivets and / or adhesive. Advantageously, the fastening equipment is permanently fixed to a non-removable support in the predefined location and cannot be easily detached or moved.

[0035] The equipment 10 also includes a screen 12 capable of displaying a dynamic matrix code, that is, a matrix code that varies over time. A matrix code can be a two-dimensional code forming a grid in which cells are displayed in two distinct colors (for example, black or white). The matrix code can be, for example, a Datamatrix code and / or a QR code. Advantageously, the matrix code displayed on the screen 12 of the equipment 10 is a standardized code. It can, for example, conform to the ISO / IEC 16022 standard. The matrix code can thus be automatically deciphered by a communication terminal such as a smartphone, without the prior installation of an application or a dedicated decryption key. More generally, a matrix code can refer to any code containing digital information.The resolution of a 12-inch screen can be sufficient to display a matrix code with approximately 200 cells on the x-axis and 200 cells on the y-axis. Thus, the 12-inch screen can be particularly simple, as it can be limited to a monochrome screen of approximately 200 pixels by 200 pixels. Advantageously, a matrix code allows a large amount of information to be displayed in a small area. The screen size can be large enough to allow a smartphone camera to detect and read the displayed matrix code.

[0036] In a preferred embodiment, the equipment 10 may include an electronic ink display device, also known as "e-ink" or "e-paper". Such a device is based on a technology also used in the design of e-readers. It has the advantage of being very energy efficient.

[0037] The equipment 10 further includes a memory 13, a processing unit 14 or microprocessor, and an energy storage means 15, such as a battery or rechargeable cell. The memory 13 and the processing unit 14 can be integrated into an electronic board connected to the display 12 via a ribbon cable. The energy storage means 15 provides power to the display 12 and the processing unit 13. The equipment 10 does not require connection to an electrical network. Furthermore, the equipment may not include any wired or wireless connection means. It may also not include any buttons or any other means of interaction other than the display 12. Thus, the design of the equipment is particularly simple and robust.

[0038] According to one embodiment, the equipment could, however, include a button or control means configured to turn the screen 12 on or off to save energy. According to another embodiment, the equipment 10 could also include a reset button to reset the equipment and thus restart a process initialization step, which will be detailed later. In such a case, the reset button would advantageously be well hidden and / or difficult to access to prevent any malicious use of the equipment.

[0039] The equipment 10 can be dedicated to the implementation of a process for providing evidence. It can also be integrated into any support and / or device performing different functions, provided that it includes sufficient space to integrate the screen 12 and the electronic card connected to the screen.

[0040] Optionally, the equipment 10 may include a means of generating electrical energy, in particular a photovoltaic system. The photovoltaic system could, for example, be positioned behind or beside the screen 12. In this way, the equipment 10 could benefit from increased energy autonomy, or even become completely self-sufficient.

[0041] The server 20 is a computer device. It includes communication means 21, notably for receiving digital information from a communication terminal such as a smartphone. It also includes memory 22 and a processing unit 23 or microprocessor.

[0042] Memory units 13 and 22 are data storage media, readable by a computer, on which computer programs are stored, comprising program code instructions for implementing a method of providing proof of presence according to an embodiment of the invention. The processing units 14 and 23 are capable of executing the programs stored respectively in memory units 13 and 22.

[0043] The implementation of the proof-of-presence method also relies on the use of a communication terminal 30, such as a smartphone. The communication terminal 30 comprises a camera 31, communication means 32 for transmitting data to the server 20, and a processing unit 33, notably capable of deciphering a matrix code. Advantageously, these means 31, 32, and 33 are now standard equipment on all commercially available smartphones. Alternatively, the communication terminal 30 could be a simple electronic device whose functionalities are limited to implementing the invention. In the described embodiment, the communication terminal 30 can be held by a user whose presence at the predefined location is to be verified.Advantageously, the communication terminal may also include a memory in which a communication terminal identifier and / or a user identifier is recorded.

[0044] We now describe a method for implementing the proof-of-attendance process in relation to the figure 2 The process can be broken down into four main steps: E1, E2, E3 and E4.

[0045] The first step, E1, is an initialization step. During this step, initialization data is transmitted from the device 10 to the server 20. This initialization data includes: an INDD startup index, at least one INCA calculation parameter, an FMIN refresh rate data.

[0046] The number of calculation parameters can be arbitrary. However, the process can already be implemented with a single calculation parameter. The explanations that follow can easily be applied to a more complex process using multiple calculation parameters.

[0047] According to a preferred embodiment of the invention, the INDD startup index and the INCA calculation parameter are randomly generated by the equipment 10. The INDD startup index and the INCA calculation parameter can, for example, be generated automatically and randomly as soon as the equipment is powered on, i.e., as soon as the energy storage means 15 is connected. Thus, no control button is required on the equipment for its commissioning. As will be seen later, validation matrix codes will then be generated periodically based on the INDD startup index and the INCA calculation parameter. The advantage of defining these two parameters randomly is that it makes it more difficult to predict the matrix codes that will be generated by the equipment.

[0048] In one embodiment, the INDD starting index and the INCA calculation parameter could be defined not randomly, but according to a more or less complex algorithm, and therefore more or less difficult to detect. In another, simpler embodiment, the INDD starting index and the INCA calculation parameter could be defined during the equipment manufacturing process. With this embodiment, the equipment could be simpler to manufacture and the initialization step could be faster. However, in this case, the validation matrix codes generated by the equipment could be more easily detected.

[0049] The refresh rate (FMIN) can be a predefined value set during the equipment's manufacturing process. As we will see later, the FMIN corresponds to the frequency at which the matrix codes generated and displayed by the equipment are renewed. This FMIN can be any value. For example, it can be on the order of one second, one minute, one hour, one day, or even one week. Equipment 20 therefore includes an internal clock that renews these matrix codes according to the FMIN frequency.

[0050] According to one embodiment of the invention, the equipment could include a means for adjusting the FMIN frequency. The FMIN frequency would be set during the initialization step and would not be changed thereafter unless the equipment is reset.

[0051] Advantageously, when the initialization data is generated by the equipment, it can be transmitted from the equipment to the server via the Smartphone 30. In this case, the initialization step E1 can include a first substep E11 in which an initialization matrix code is displayed on the screen 12 of the equipment 10. The initialization matrix code can then include a computer address of the server, in other words, a server URL, and the said initialization data. The computer address of the server can be presented in such a form that the communication terminal automatically connects to the server 20 when the initialization matrix code is scanned, i.e., when the camera of the communication terminal is activated opposite the initialization matrix code. The initialization matrix code can contain a message of the form: http(s): / / zz.xxx.yy?s=<<cryptojeton_init> > , where http(s): / / zz.xxx.yy designates the server's address and cryptojeton_init contains the initialization data. The cryptojeton_init data can, for example, be obtained by concatenating the different initialization data.

[0052] The initialization matrix code can remain displayed on the equipment's screen 12 for a predefined period, for example, between ten seconds and ten minutes inclusive, in particular a period of approximately one minute. This period can be calculated from the generation of the initialization data and / or from the time the equipment is powered on. A duration can be chosen that allows the user sufficient time to comfortably scan the matrix code displayed on the screen. Advantageously, the matrix code is not directly intelligible to the user. It is also impossible to memorize once it exceeds a certain size. This enhances the security of the method according to the invention.

[0053] In a second substep E12, the initialization matrix code is scanned with the camera 31 of the communication terminal 30. Advantageously, when the initialization matrix code contains a message in the form http(s): / / zz.xxx.yy?s=<<cryptojeton_init> >, the communication terminal 30 automatically communicates the cryptojeton_init data containing the initialization data to the server 20. This sub-step can therefore be executed very simply since the user only needs to activate the camera of his communication terminal, aim at the initialization matrix code displayed on the screen 12 and validate the connection proposal to the server which is automatically displayed.

[0054] Alternatively, the message contained in the initialization matrix code could take any other form allowing automatic transmission of the initialization data to the server. According to another alternative, the initialization matrix code might not contain the server's address. The initialization data could then be transmitted manually to the server or via a dedicated application for the communication terminal. However, such an alternative would take longer to implement and would require, if necessary, the installation of an application on the communication terminal.

[0055] According to another feature of the invention, all or part of the initialization data can be encrypted before being displayed on the screen 12. The encryption aims to prevent the interception of the INDD startup index and / or the INCA calculation parameter during the display of the initialization matrix code. In particular, XOR encryption can be used. Such encryption is based on the use of a secret encryption key and a logical operator corresponding to an "exclusive OR". The data to be encrypted and the encryption key are converted into binary code, and each bit of the data to be encrypted is encrypted using the "exclusive OR" function with the encryption key, which is repeated if it is shorter than the data to be encrypted. The secret key can be stored in a memory of the equipment 10. The advantage of XOR encryption is that it is simple to implement and completely impossible to decipher when the secret key is unknown.Alternatively, Advanced Encryption Standard (AES) encryption, or any other type of encryption algorithm, can be used. AES encryption is particularly secure. The initialization data can thus be encrypted in a substep E10 executed before substep E11, which displays the initialization matrix code.

[0056] Optionally, the initialization data may also include other useful information. For example, the initialization data may also include a number of restarts (NBD) performed by the equipment since it was put into service. This NBD number can then be used to enhance the security of the matrix codes generated by the equipment.

[0057] The initialization data may also include a voltage value TP of the energy storage medium 15 of the equipment 10. This voltage value can be interpreted to calculate the remaining operating time of the equipment. Thus, maintenance operations can be scheduled to replace or recharge the energy storage medium 15 before the equipment ceases to function.

[0058] In a third substep E13 of the initialization step, the communication terminal 30 transmits the initialization data from the scanned initialization matrix code to the server. When the initialization data is encrypted, the server decrypts it. The decryption of the initialization data can be performed during a substep E14 following substep E13. For this purpose, the server may also include a decryption key in memory, specifically the key used to perform the XOR or AES encryption.

[0059] Next, the initialization step E1 may include an authentication substep E15 to ensure that the initialization step E1 is executed by an authorized user. For example, in response to server 20 receiving the initialization data, the server may redirect the communication terminal 30 to an interface where the user is prompted to enter a username and / or password. The entered username and / or password are transmitted from the communication terminal 30 to server 20. Server 20 can then verify, by consulting a database of authorized users, that the user is indeed authorized to perform a process initialization. If the username and / or password are recognized as valid, the server can store the received initialization data.If the username and / or password are not recognized as valid, the server can simply ignore the received initialization data. This ensures that the process can only be initialized by authorized personnel, further enhancing process security.

[0060] Since the transmission of initialization data is immediate or near-immediate when the initialization matrix code is scanned, server 20 can be considered to receive it instantaneously or shortly thereafter following the scan. This allows synchronization of equipment 10 and server 20. The synchronization between equipment 10 and server 20 then has a precision roughly equal to the duration for which the initialization matrix code is displayed. It is therefore understandable that a relatively short display time for the initialization matrix code may be desirable in order to achieve precise temporal synchronization of equipment 10 and server 20.

[0061] Advantageously, during the initialization step, the communication terminal 30 can also transmit to the server 20 a communication terminal identifier and / or a communication terminal user identifier and / or an equipment identifier 10 and / or a timestamp indicating the time at which the initialization matrix code was scanned. The communication terminal identifier can be, for example, a communication terminal serial number or any other reference that allows the communication terminal to be identified. The communication terminal user identifier can be, for example, a username, an email address, or any other code that allows the communication terminal user to be identified.These identifiers can be stored in the communication terminal's memory and automatically included with the initialization data transmitted by the communication terminal 30 to the server 20. These identifiers could also be entered manually at the prompt of the communication terminal. The identifier of the equipment 10 could, for example, be the equipment's serial number. Advantageously, it can be part of the initialization data and thus communicated to the communication terminal 30 by displaying the initialization matrix code. Alternatively, it could be entered at the prompt of the communication terminal. Using this information, the server will be able to associate a given piece of equipment with one or more communication terminals and / or one or more users.

[0062] Finally, at the end of the initialization step, both device 10 and server 20 have the initialization data in memory, namely at least the startup index INDD, the calculation parameter INCA, and the frequency FMIN. Furthermore, device 10 and server 20 are synchronized so that they can calculate a time index based on this initialization data almost simultaneously.

[0063] In a second step E2, the equipment iteratively calculates a time index INDT at the FMIN frequency. This second step E2 can be executed automatically after the initialization step E1. The initial value of the time index INDT is equal to the result of an operation based on the INCA calculation parameter and the INDD start index. Subsequently, the time index INDT is equal to the result of an operation based on the INCA calculation parameter and the INDT time index calculated during a previous iteration of the second step E2.

[0064] The calculation parameter can be, for example, a number that will be added to the time index INDT calculated in a previous iteration. Alternatively, the calculation parameter can be combined with the time index INDT calculated in a previous iteration in any type of operation, including multiplication, subtraction, or division. In yet another variation, the type of operation itself is specified by the calculation parameter INCA or by a part of the INCA calculation parameter. For example, the first two bits of the INCA calculation parameter can be used to define whether the subsequent bits of the INCA calculation parameter should be added, multiplied, subtracted, or divided with the time index INDT calculated in a previous iteration. If the process relies on the use of several calculation parameters, even more complex calculations of the time index INDT can be proposed.For example, one could add a first calculation parameter during one iteration of the second step E2, and then add a second calculation parameter during the following iteration of the second step E2. Such a process would be more complex to implement but could lead to enhanced security of the proof-of-presence process against attempts to decipher or circumvent it. If applicable, the INDT time index can also be calculated based on the number NBD of restarts performed by the equipment since it was put into service.

[0065] In a third step E3, a validation matrix code is displayed on screen 12. This validation matrix code includes the INDT time index calculated in the second step E2. In other words, the validation matrix code is a matrix-coded representation of the INDT time index. The validation matrix code displayed on screen 12 is thus updated at the FMIN frequency. The first validation matrix code can be displayed automatically as soon as the predefined time for displaying the initialization matrix code has elapsed. A given validation matrix code can remain displayed on the screen until a new validation matrix code replaces it. Therefore, the screen only needs to be refreshed at the FMIN frequency, which saves energy, especially when screen 12 includes an electronic ink display.

[0066] The validation matrix code is therefore dependent on the INDD startup index, the INCA calculation parameter, the FMIN frequency, and, where applicable, the NBD number of restarts performed by the equipment since it was put into service.

[0067] Advantageously, the INDT time index can be encrypted before being displayed on screen 12. The encryption aims to make it more difficult, or even impossible, to deduce the calculation method of the INDT time index by observing the successively displayed validation matrix codes. Specifically, XOR or AES encryption can be used. The encryption of the INDT time index can be based on a secret key identical to the secret key used for encrypting the initialization data. The INDT time index can thus be encrypted in a substep E21 executed after the INDT time index calculation step E2 and before the validation matrix code display step E3.

[0068] Similar to the display of the initialization matrix code, the validation matrix code can include other useful data in addition to the INDT time index. First, the matrix code can include the server's address, so that the communication terminal automatically connects to that server when the validation matrix code is scanned. The validation matrix code can contain a message of the form: http(s): / / zz.xxx.yy?s=<<cryptojeton_valid> > , where http(s): / / zz.xxx.yy denotes the computer address of the server and cryptojeton_valid contains the INDT time index, possibly in encrypted form.

[0069] Furthermore, the validation matrix code can include the number of restarts (NBD) performed by the equipment since it was commissioned. The validation matrix code can therefore not only be calculated based on the NBD but also contain this information. The validation matrix code can also include the voltage value (TP) of the energy storage device (15) of the equipment (10).

[0070] In a fourth step, E4, a user's presence at the predefined location is validated. To do this, the user is prompted to scan the matrix code displayed on the equipment's screen when they wish to indicate their presence at the predefined location. More specifically, the fourth step, E4, includes a substep, E41, of scanning the validation matrix code displayed on screen 12 using the camera of a communication terminal. This communication terminal can be the same as the one used for the initialization step or, alternatively, a different communication terminal.

[0071] Next, the fourth step E4 includes a substep E42 of transmission to server 20, via the communication terminal, of the INDT time index derived from the scanned validation matrix code. Server 20 is assumed to receive the INDT time index instantaneously or shortly after the validation matrix code is scanned. Substep E42 can be executed automatically when the validation matrix code includes the computer address of server 20. Therefore, the fourth step E4 can be executed very simply, as the user only needs to activate the camera on their communication terminal, aim at the validation matrix code displayed on screen 12, and confirm the connection to the server proposed by their communication terminal.

[0072] In addition to transmitting the INDT time index, one can transmit in a substep E43 an identifier of the communication terminal used to scan the validation matrix code and / or an identifier of the user of the communication terminal and / or an identifier of the equipment on which the validation matrix code was displayed and / or a timestamp indicating the time at which the validation matrix code was scanned.

[0073] When the time index has been encrypted in accordance with step E21, the fourth step E4 includes a substep E44 of decrypting the time index, notably by means of the secret key shared with the equipment.

[0074] Next, the fourth step E4 includes a substep E45 of comparison by the server of the time index INDT received from the communication terminal during substep E42 with a time index INDT_B calculated by the server according to a method identical to that used by the equipment to calculate the time index during the calculation step E2.

[0075] Since server 20 has the initialization data shared during the initialization step, it can apply the same calculation algorithm as device 10 to also calculate a time index INDT_B. It can also repeat this calculation according to the FMIN frequency. The server can therefore predict the time index INDT calculated by device 10 at any time without having to establish communication with it. If the time index INDT is identical to the time index INDT_B, the presence of a user at the predefined location can be reliably confirmed. If the time index INDT is different from the time index INDT_B, a fraud attempt can be assumed.

[0076] It is also possible to estimate when the user was present at the predefined location. The FMIN frequency can be adjusted according to the intended use of the proof-of-presence system. In particular, if it is necessary to know precisely when the user scanned the validation matrix code, a higher FMIN refresh rate can be used. The process only requires the user to handle their own communication terminal. Therefore, the process is hygienic and limits the transmission of diseases.

[0077] Thanks to this invention, there is a high level of security against attempts to predict the validation matrix codes that will be displayed in the future. In particular, the use of randomly defined initialization data and the application of encryption to the displayed data as matrix codes provide double security. It is therefore particularly difficult to falsify proof of presence.

[0078] A malicious individual attempting to scan a validation matrix code at a location other than the originally intended one would be forced to move the entire equipment 10. To prevent such a circumvention, the equipment may include fastening means 11 that are difficult to remove. Alternatively, fastening means 11 may be provided that require temporary disconnection of the energy storage means 15. For example, the equipment 10 could be secured with screws, and at least one of these screws could have a screw head inside a recess intended for the energy storage means 15. Thus, moving the equipment 10 would necessarily require powering it down and therefore losing synchronization with the server 20. The equipment 10 could no longer be used to validate a user's presence before performing a new initialization.The NBD number can optionally be monitored to prevent any attempt to reset the equipment. As another example, equipment 10 could be configured so that its batteries are automatically ejected if the equipment is removed from its mounting bracket.

[0079] If the communication terminal ID and / or the communication terminal user ID transmitted during substep E43 do not match an ID registered by the server, particularly an ID registered on the server during the initialization step, the server may ignore the message received from the communication terminal. This prevents any attempts to validate presence made with an unauthorized communication terminal and / or by an unauthorized user. If the communication terminal ID and / or the communication terminal user ID transmitted during substep E43 do match an ID registered by the server, then presence can be recorded and assigned to the registered ID.When different communication terminals and / or different users are registered by the server as authorized to scan a validation matrix code, it is possible to identify which of these communication terminals and / or which of these users scanned the validation matrix code. Substep E44 can be executed as soon as server 20 receives the timestamp sent by the communication terminal or, alternatively, executed later, for example at the end of the day.

[0080] Note that server 20's knowledge of the validation matrix code displayed on equipment 10 requires accurate synchronization of the internal clocks of the equipment and the server. The internal clock of the equipment and / or the server may drift from a reference time base. The accuracy of the internal clock of the equipment and / or the server is typically on the order of 0.06%. To mitigate any potential time drift between the internal clock of the equipment and the internal clock of the server, the proof-of-presence process may also include a time resynchronization step between server 20 and equipment 10. For example, this resynchronization could be performed when a user scans two different validation matrix codes in quick succession.

[0081] Tolerance periods, which may be adjustable, can also be defined for each transition of the INDT_B time index calculated by server 20. These tolerance periods can be, for example, a few seconds or a few tens of seconds long. The duration of the tolerance periods can be chosen or calculated based on the accuracy of the internal clocks of the equipment and / or the server, as well as the average scan frequency of the validation matrix code. Advantageously, the duration of the tolerance periods can be adjusted on the server and requires no intervention on the equipment 10 and / or the communication terminal 30. If server 20 receives an INDT time index corresponding to an earlier or later INDT_B time index during the tolerance period, a time desynchronization between the server and the equipment can be concluded, and resynchronization can be performed.

[0082] Advantageously, when a timestamp indicating the time the validation matrix code was scanned is transmitted from the communication terminal 30 to the server 20 during validation step E4, substep E45 can be performed after any delay following substep E41. Based on the timestamp, the server 20 can determine which validation matrix code was displayed on the equipment 10 at the time it was scanned. This compensates for any potential time lag between the execution of substeps E41 and E45.

[0083] The invention can be applied to various use cases. For example, the invention can be used in the following cases: to validate a maintenance intervention on a site, to validate the proper execution of a tour to different predefined locations, for the timekeeping of seconded personnel, to prove the deposit of a package at a location in the absence of the recipient, to prove or report the presence or passage of a person, including a carrier, at a predefined location such as a residence or a business, to replace a doorbell or intercom at the entrance of a residence.

Claims

1. Method for providing proof of presence at a predefined location, comprising : • an initializing step (E1) during which initialization data of a digital device (10) are transmitted to a server (20), the device being installed at said predefined location, the device being provided with a screen (12) able to display a matrix barcode, the initialization data comprising: ∘ a start index (INDD), ∘ at least one computational parameter (INCA), ∘a datum on refresh frequency (FMIN), then • a computing step (E2) in which the device iteratively computes, at the refresh frequency (FMIN), a time index (INDT), the time index (INDT) being equal to the result of an operation based on the at least one computational parameter (INCA) and on the time index (INDT) computed in a preceding iteration of the computing step (E2), an initial value of the time index (INDT) being equal to the result of an operation based on the at least one computational parameter (INCA) and on the start index (INDD), then • a step (E3) of displaying a validation matrix barcode on the screen of the device, the validation matrix barcode comprising the computed time index (INDT), then • a step (E4) of validating a presence at the predefined location comprising: ∘ a substep (E41) of scanning the validation matrix barcode displayed on the screen of the device by means of a communication terminal (30), then ∘ a transmitting substep (E42) in which the communication terminal transmits to the server the time index (INDT) obtained from the scanned validation matrix barcode.

2. Method for providing proof of presence according to the preceding claim, characterized in that the validation matrix barcode furthermore comprises a computer address of the server.

3. Method for providing proof of presence according to one of the preceding claims, characterized in that the initializing step (E1) comprises a transmitting substep (E13) in which the communication terminal, especially a smartphone, transmits to the server (20) the initialization data.

4. Method for providing proof of presence according to one of the preceding claims, characterized in that the initializing step (E1) comprises: • a substep (E11) of displaying, on the screen (12) of the device (10), an initialization matrix barcode comprising a computer address of the server and said initialization data, then • a scanning substep (E12) in which a communication terminal (30) scans the initialization matrix barcode, then • a transmitting substep (E13) in which the communication terminal transmits to the server (20) the initialization data obtained from the scanned initialization matrix barcode.

5. Method for providing proof of presence according to the preceding claim, characterized in that the initializing step (E1) is executed automatically as soon as the device (10) is supplied with power, said displaying substep (11) having a predefined duration, and especially a duration comprised between ten seconds and ten minutes inclusive.

6. Method for providing proof of presence according to one of the preceding claims, characterized in that the start index (INDD) and / or the at least one computational parameter (INCA) is defined randomly by the device (10).

7. Method for providing proof of presence according to one of the preceding claims, characterized in that it comprises an encrypting step (E10) in which the device (10) encrypts the initialization data, especially using XOR or AES encryption, then a decrypting step (E14) in which the server (20) decrypts the received initialization data, and / or in that it comprises an encrypting step (E21) in which the device (10) encrypts the computed time index, especially using XOR or AES encryption, then a decrypting step (E44) in which the server (20) decrypts the received time index.

8. Method for providing proof of presence according to one of the preceding claims, characterized in that the initialization data and / or the validation matrix barcode comprise(s) a voltage value (TP) of a power storage means (15) of the device (10).

9. Method for providing proof of presence according to one of the preceding claims, characterized in that the initializing step (E1) and / or the step (E4) of validating a presence at the predefined location furthermore comprises the transmission, to the server, by the communication terminal (30), of an identifier of the communication terminal (30) and / or of an identifier of a user of the communication terminal and / or of an identifier of the device (10) and / or a timestamp data indicating at which time the matrix barcode was scanned.

10. Method for providing proof of presence according to one of the preceding claims, characterized in that the step (E4) of validating a presence at the predefined location comprises a comparing substep (E45) in which the server compares the time index (INDT) received from the communication terminal (30) with a time index (INDT_B) computed by the server (20) using a method identical to that employed by the device (10) to compute the time index (INDT) in said computing step (E2).

11. Digital device (10) comprising a screen (12) able to display a dynamic matrix barcode, a power storage means (15) and hardware and software means configured to: - randomly generate at least one computational parameter (INCA) and a start index (INDD), and to - iteratively compute, at a refresh frequency (FMIN), a time index (INDT), the time index (INDT) being equal to the result of an operation based on the at least one computational parameter (INCA) and on a time index (INDT) computed in a preceding iteration, an initial value of the time index (INDT) being equal to the start index (INDD), the digital device being configured to carry out the steps of the method of claim 1 that are performed by the digital device (10) of claim 1.

12. Device (10) according to the preceding claim, characterized in that it comprises : - a display device utilizing electronic ink, and / or - a mean for generating electrical power, and especially a photovoltaic means, and / or - fastening means (11) intended to interact with a holder, the fastening means being configured so that manipulation of the fastening means with a view to detaching the device (10) from the holder results in a disconnection of the power storage means (15).

13. System (1) for providing proofs of presence, comprising a server (20), and a device (10) provided with a screen (12) able to display a dynamic matrix barcode and / or a device (10) according to one of Claims 11 or 12, the device and the server comprising hardware and software means configured to implement a method for providing proof of presence according to one of Claims 1 to 10 that are performed by the device and the servers of claims 1 to 10.

14. Computer program product comprising program-code instructions stored on a computer-readable medium, for implementing the steps of the method for providing proof of presence according to any one of Claims 1 to 10 when said program is run on a computer.

15. Computer-readable data storage medium on which is stored a computer program comprising program-code instructions for implementing the method for providing proof of presence according to one of Claims 1 to 10.