Traceable multi-hop offline digital payments

EP4519815A4Pending Publication Date: 2025-10-15CRUNCHFISH DIGITAL CASH AB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023799771
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-05
Filing Date
2023-05-05
Publication Date
2025-10-15

AI Technical Summary

Technical Problem

Existing offline digital payment systems face challenges in detecting misuse and updating payment network resources, leading to delays and bottlenecks when the second offline digital payment is settled without awareness of the first offline digital payment's status, causing insufficient balance issues.

Method used

A method and system for traceable multi-hop offline digital payments, where a first offline payment is made from a first communication device to a second, and a second offline payment is composed of reserved funds and the first payment, with information about payers and payees communicated to a payment switch for settlement, enabling transparent and versatile digital cash transfer.

Benefits of technology

This solution allows for transparent and efficient settlement of offline digital payments, preventing misuse detection and ensuring timely settlement by maintaining accurate balance information, thus reducing delays and bottlenecks in the payment network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

A computerized method (300) of performing transparent and versatile transfer of digital cash is presented. A first offline digital payment (TX1) that represents a first amount of digital cash is made (310) from a first communication device (CD1) to a second communication device (CD2). A second offline digital payment (TX2) that represents a second amount of digital cash is then made (320) from the second communication device (CD2) to a third communication device (CD3). The second offline digital payment (TX2) is composed (130) of a combination of a) a deduction from digital cash which has been downloaded (110; 110a, 110b) to the second communication device (CD2) and corresponds to a reservation of funds in an account (UA2) maintained at a financial institution (FI2), and b) all or some of the first amount of digital cash as received in the first offline digital payment (TX1). Communication (330) is made with a computerized payment network resource to make a request (140) for settlement of the second offline digital payment (TX2), wherein the request for settlement includes information (142) about payers and payees (U1, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] TRACEABLE MULTI-HOP OFFLINE DIGITAL PAYMENTS

[0002] TECHNICAL FIELD

[0003] The present invention generally relates to the field of digital payments. More particularly, the present invention relates to technical improvements to offline digital payments. Even more particularly, the present invention relates to a computerized method of performing transparent and versatile transfer of digital cash. The present invention further relates to a digital payment system and to an associated communication device, computer program product and non-volatile computer readable media.

[0004] BACKGROUND

[0005] As everybody knows, there has been an overwhelming market penetration for communication devices such as smart phones, tablets and personal computers. Typically, such communication devices are enabled for wide-area network, WAN, communication (broadband RF -based or wired communication) with remote entities, for instance via cellular radio systems like 5G, UMTS or GSM, or via wireless local area network, WLAN, access to route IP traffic to and from such remote entities. In addition, communication devices are often enabled for short-range wireless data communication, such as Bluetooth, with other devices nearby. Such a nearby device may for instance be an accessory or peripheral device, like a wireless headset or wireless speakers.

[0006] Thanks to this ability, users of communication devices may enjoy a plethora of digital services that involve communication with cloud-based resources. A very popular type of such digital services is digital payments. Throughout this document, the term “digital payment” is to be construed broadly to embrace any kind of transfer of economic value in digital form on behalf of or between people of any types, roles etc.

[0007] Often, to perform a digital payment between two communication devices, contact with and approval by a financial institution, payment switch or another remote payment network resource (cloud-based resource) which be required through wide-area network communication. However, as a special kind of digital payments, an offline digital payment can be performed between two communication devices without involving contact with and approval by a remote payment network resource at the time of making the offline digital payment. The offline digital payment is stored in one or both of the communication devices, pending online settlement at some later stage. A typical use case for offline digital payments is when users of the two communication devices are physically proximate to one another at a physical place such as, for instance, a shop, restaurant, theatre, sport arena, workshop, or basically any place where people may want to perform a digital payment. The present applicant is a technical pioneer within offline digital payments, also known as digital cash. Reference is for instance made to applicant’s patent applications PCT / SE2020 / 051251, PCT / SE2022 / 050152 and SE 2250076-3, the contents of which are incorporated herein by reference.

[0008] It is generally desired to allow a receiver of a first offline digital payment to be able to use the value of the received first offline digital payment to make a second offline digital payment, the payee of the first offline digital payment thus becoming the payer of the second digital payment. However, this is technically challenging.

[0009] One technical problem is how to detect or prevent misuse or criminal activity, such as money laundry, by some party in the offline payment transaction chain acting as a proxy for an actual, hidden payer further behind in the transaction chain.

[0010] Another technical problem is how to keep the payment network resources updated. Assume, for instance, that the second offline digital payment is uploaded (by the payer or payee) to a payment switch or other payment network resource to cause settlement thereof, while for some reason there is a delay in the uploading of the first offline digital payment. When settling the second offline digital payment, the payment network resources will therefore not be aware of the first offline digital payment having been performed. Now, if the payer of the second offline digital payment had a local digital wallet balance that, as such, would have been insufficient to cover the second offline digital payment if the balance had not been increased by the receiving of the first offline digital payment, there is no way for the payment network resources to know that the second offline digital payment is actually ok to settle because the payer thereof actually had the benefit of being the payee of the first offline digital payment. As a result, when the payment network resources receive a request to settle the second offline digital payment, they would not be able to proceed because of the apparent shortage in balance. This will cause a delay in the whole settlement procedure and may also give rise to bottleneck problems by offline digital payments queuing up for settlement.

[0011] SUMMARY

[0012] In line with the observations above, the present inventors have made valuable technical insights to solve or at least mitigate one or more of the challenges referred to in the previous section. These insights will be presented as inventive aspects in the following description and the drawings. The list of inventive aspects is not to be seen as exhaustive but rather a summary of particularly beneficial inventive aspects.

[0013] In a nutshell, the present inventors have invented technical solutions which make traceable multi-hop offline digital payments possible.

[0014] A first aspect of the invention is a computerized method of performing transparent and versatile transfer of digital cash. The method involves: making a first offline digital payment, representing a first amount of digital cash, from a first communication device to a second communication device, making a second offline digital payment, representing a second amount of digital cash, from the second communication device to a third communication device, wherein the second offline digital payment is composed of a combination of a) a deduction from digital cash which has been downloaded to the second communication device and corresponds to a reservation of funds in an account maintained at a financial institution, and b) all or some of the first amount of digital cash as received in the first offline digital payment, and communicating with a computerized payment network resource, such as a computerized payment switch, to make a request for settlement of the second offline digital payment, wherein the request for settlement includes information about payers and payees of the first as well as second offline digital payments.

[0015] A second aspect of the invention is a digital payment system which comprises a plurality of communication devices and a computerized payment switch. Each communication device comprises a local digital wallet being configured for accommodating a first digital cash repository and a second digital cash repository. The first digital cash repository represents digital cash that corresponds to a reservation of funds in an account which is maintained at a financial institution and is associated with a user of the communication device. The second digital cash repository represents digital cash that has been transferred in one or more offline digital payments from one or more of the other communication devices of the system.

[0016] In the digital payment system, a first communication device is configured for making a first offline digital payment to a second communication device. The second communication device is configured for storing the first offline digital payment in its second digital cash repository. The second communication device is further configured for making a second offline digital payment to a third communication device, wherein the second offline digital payment is composed of a combination of digital cash from the first and second digital cash repositories of the second communication device, including all or some of said first offline digital payment.

[0017] At least one of the second and third communication devices is configured for storing the second offline digital payment in its respective second digital cash repository, wherein the storing includes storing information about payers and payees of the first as well as second offline digital payments. Said at least one of the second and third communication devices is configured for requesting settlement of the second offline digital payment by communicating to the computerized payment switch the stored second offline digital payment, including the information about the payers and payees of the first as well as second offline digital payments.

[0018] A third aspect of the invention is a communication device that comprises a trusted execution environment configured for accommodating a local digital wallet having a first digital cash repository and a second digital cash repository. The first digital cash repository represents digital cash that corresponds to a reservation of funds in an account which is maintained at a financial institution and is associated with a user of the communication device. The second digital cash repository represents digital cash that has been transferred in one or more offline digital payments from one or more other communication devices. The communication device is configured for: receiving a first offline digital payment from another communication device, storing the first offline digital payment in the second digital cash repository, composing a second offline digital payment as a combination of digital cash from the first and second digital cash repositories, including all or some of said first offline digital payment, sending the second offline digital payment to another communication device, storing the second offline digital payment in the second digital cash repository, wherein the storing includes storing information about payers and payees of the first as well as second offline digital payments, and requesting settlement of the second offline digital payment by communicating the stored second offline digital payment, including the information about the payers and payees of the first as well as second offline digital payments.

[0019] A fourth aspect of the invention is a non-volatile computer readable medium having stored thereon a computer program, i.e. a computer program product, which comprises computer program code for performing the following functionality when the computer program code is executed by a processing device: accommodating, in a trusted execution environment, a local digital wallet having a first digital cash repository and a second digital cash repository, the first digital cash repository representing digital cash that corresponds to a reservation of funds in an account which is maintained at a financial institution, and the second digital cash repository representing digital cash that has been transferred in one or more offline digital payments; receiving a first offline digital payment from a communication device, storing the first offline digital payment in the second digital cash repository, composing a second offline digital payment as a combination of digital cash from the first and second digital cash repositories, including all or some of said first offline digital payment, sending the second offline digital payment to another communication device, storing the second offline digital payment in the second digital cash repository, wherein the storing includes storing information about payers and payees of the first as well as second offline digital payments, and requesting settlement of the second offline digital payment by communicating the stored second offline digital payment, including the information about the payers and payees of the first as well as second offline digital payments.

[0020] As used in this document, the term “wide area network communication” (abbreviated as “WAN communication”) includes any form of data network communication with a party which may be remote (e.g. cloud-based), including cellular radio communication like W-CDMA, GSM, UTRAN, HSPA, LTE, LTE Advanced or 5G, possibly communicated as TCP / IP traffic, or via a WLAN (WiFi) access point, without limitation. Moreover, the terms “long-range data communication” and “broadband data communication” are considered as synonyms of “wide-area network communication”.

[0021] Expressions like “[entity] is configured for. . . [performing activity]” or “[entity] is configured to . . . [perform activity]” will include typical cases where a computerized entity (having one or more controllers, processing units, programmable circuitry, etc.) executes software or firmware installed in the computerized entity, wherein the execution occurs in order to perform the activity in question. Generally, all terms used herein are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the [element, device, component, means, step, etc.]" are to be interpreted openly as referring to at least one instance of the element, device, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.

[0022] BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The following detailed description of the invention will be based upon the attached drawings. In the drawings:

[0024] Figure l is a schematic illustration of a digital payment system that supports offline digital payments.

[0025] Figure 2 illustrates an alternative to Figure 1.

[0026] Figure 3 is a schematic flowchart diagram of a computerized method of performing transparent and versatile transfer of digital cash.

[0027] Figure 4 is a schematic block diagram of a communication device that may be used in the digital payment system and computerized method in Figures 1-3.

[0028] Figure 5 is a schematic illustration of a non-volatile computer-readable medium in one exemplary embodiment, capable of storing a computer program product.

[0029] Figure 6 illustrates a multi-layered digital payment system architecture according to embodiments of the invention, being an add-on to an existing core banking system.

[0030] Figure 7 is a graph to exemplify some of the functionality of the digital payment system and computerized method in Figures 1-3.

[0031] Figures 8-17 are sequence and signal diagrams illustrating embodiments of the present invention.

[0032] DETAILED DESCRIPTION

[0033] Figure 1 illustrates a digital payment system (100) which comprises a plurality of communication devices (CD1-CD3), and a computerized payment network resource in the form of a computerized payment switch (PS). As seen in Figure 1, the environment in which the digital payment system (100) operates comprises additional computerized payment network resources as well, including a plurality of financial institutions (FI1-FI3) and a central bank (CB). In this context, a financial institution may, for instance, be a bank or a payment service provider, without limitation.

[0034] Each communication device (CD1-CD3) in the digital payment system (100) comprises a local digital wallet (LDW) being configured for accommodating a first digital cash repository (DC Rep 1) and a second digital cash repository (DC Rep 2). The first digital cash repository (DC Rep 1) represents digital cash that corresponds to a reservation of funds in an account (UA1-UA3) which is maintained at one of the financial institutions (FI1-FI3) and is associated with a user (U1-U3) of the communication device (CD1-CD3). The second digital cash repository (DC Rep 2) represents digital cash that has been transferred in one or more offline digital payments from one or more of the other communication devices of the system (100).

[0035] In the digital payment system (100), a first communication device (CD1) is configured for making a first offline digital payment (TX1) to a second communication device (CD2). This can be seen at (120). The second communication device (CD2) is configured for storing (125) the first offline digital payment (TX1) in its second digital cash repository (DC Rep 2). Exemplary implementation details of this functionality can be seen in Figures 8 and 9 (with the first offline digital payment (TX1) being referred to as “ transaction 7”).

[0036] The second communication device (CD2) is further configured for making a second offline digital payment (TX2) to a third communication device (CD3), see (135). The second offline digital payment (TX2) is composed (130) of a combination of digital cash from the first and second digital cash repositories (DC Rep 1, DC Rep 2) of the second communication device (CD2), including all or some of said first offline digital payment (TX1). Moreover, at least one of the second and third communication devices (CD1, CD2) is configured for storing (137, 137’) the second offline digital payment (TX2) in its respective second digital cash repository (DC Rep 2). This includes storing information about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2). Exemplary implementation details of this functionality can be seen in Figures 10-11 (where the full value of the first offline digital payment (TX1) is used for composing the second offline digital payment (TX2)), and in Figures 12-13 (where only a partial value of the first offline digital payment (TX1) is used for composing the second offline digital payment (TX2)). In these drawings, the second offline digital payment (TX2) is referred to as "transaction^'. Note, in particular, that a function get spendable amount is executed by the paying user’s communication device when composing the second offline digital payment (TX2, transaction2 : an embodiment of this function is shown in Figure 7.

[0037] Said at least one of the second and third communication devices (CD1, CD2) is configured for requesting settlement (140, 140’) of the second offline digital payment (TX2) by communicating to the computerized payment switch (PS) the stored second offline digital payment (TX2), including the information (142, 142’) about the payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2).

[0038] Exemplary implementation details of this functionality can be seen in Figures 16 and 17. More specifically, Figures 16 and 17 illustrate settlement of the second offline digital payment (TX2) when performed as in Figures 12-13. Settlement of the second offline digital payment (TX2) when performed as in Figures 10-11 will be settled in the corresponding manner. Moreover, Figures 14 and 15 illustrate settlement of the first offline digital payment (TX1).

[0039] The actual settlement takes places at 150 in Figure 1. In conjunction with this, misuse or criminal behavior of the kind referred to in the Background section may be detected and acted upon, since all parties of the transaction chain formed by the second offline digital payment (TX2) (i.e., in the present example, users Ul, U2 and U3) can be determined from the information 142 / 142’ communicated in the settlement request 140 / 142’. See, for instance, the action “ Transaction traceability checks’" performed by the payment switch PS in Figures 14 and 16.

[0040] Moreover, a problem with an intermediate offline digital payment (e.g. TX1) not yet having been settled and thus potentially delaying the settlement also for a subsequent offline digital payment (e.g. TX2), as explained in the Background section, can be avoided thanks to the invention.

[0041] Figure 3 illustrates a computerized method (300) of performing transparent and versatile transfer of digital cash. The method involves making (310) a first offline digital payment (TX1), representing a first amount of digital cash, from a first communication device (CD1) to a second communication device (CD2). This may correspond to the functionality at 120-125 in Figure 1.

[0042] The method (300) further involves making (320) a second offline digital payment (TX2), representing a second amount of digital cash, from the second communication device (CD2) to a third communication device (CD3), wherein the second offline digital payment (TX2) is composed (130) of a combination of a) a deduction from digital cash which has been downloaded (110; 110a, 110b) to the second communication device (CD2) and corresponds to a reservation of funds in an account (UA2) maintained at a financial institution (FI2), and b) all or some of the first amount of digital cash as received in the first offline digital payment (TX1). This may correspond to the functionality at 130-137 / 137’ in Figure 1.

[0043] Finally, the method (300) involves communicating (330) with a computerized payment network resource, such as the payment switch (PS) in Figure 1, to make a request (140) for settlement of the second offline digital payment (TX2), wherein the request for settlement includes information (142) about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2). This may correspond to the functionality at 140 / 140’ -142 / 142’ in Figure 1.

[0044] Reference will now be made to the implementation examples in Figures 8-17 for a description of some beneficial features of embodiments of the present invention. Since the implementation examples are illustrated in Figures 8-17 by way of detailed and very informative sequence and signal diagrams, the contents of which will no doubt be easily understood by the skilled reader. Nevertheless, the following explanations are provided as to the terms appearing in these drawings:

[0045] • App[n], n being 1 ...3 : Software executed by one of the communication devices (CD[n]) as described in this document.

[0046] • walletfn], n being 1 ...3 : A local digital wallet (LDW) of one of the communication devices (CD[n]), the software App[n] operating on this walletfn],

[0047] • [entity] _pri v_key: A private cryptographic key associated with [entity], with [entity] being for instance one of the communication devices (CD[n]) (or a user (U1, U2, U3) of it).

[0048] • [entity]_cert: A digital certificate which includes a public cryptographic key corresponding to the private cryptographic key of [entity],

[0049] • aliasfn]: A substitute name or identifier that is used in place of a user's actual name or account number when making transactions or sending and receiving payments. The user alias is typically a unique name or identifier that is chosen by the user and registered with a financial institution (e.g. a payment service provider or bank). Using a user alias may serve to provide an extra layer of privacy and security, as it allows users to conduct transactions without revealing their actual identity or financial information.

[0050] • balancefn]: The balance of the aforementioned first digital cash repository (DC Rep 1) accommodated in the local digital wallet (LDW / wallet[n]) of the communication device (CD[n]).

[0051] • transact! on_trees[n]: A data tree structure that implements the aforementioned second digital cash repository (DC Rep 2) accommodated in the local digital wallet (LDW / wallet[n]) of the communication device (CD[n]).

[0052] • PSP[n] / Bank[n]: A payment service provider or bank, i.e. a financial institution (FI1-F13), that the user (Ul, U2, U3) of communication device (CD[n]) is associated with. • CA: A trusted entity (Certificate Authority) that issues digital certificates.

[0053] • RL[n]: Risk limits defined for offline payments performable by the user (Ul, U2, U3) of the communication device (CD[n]), typically set by the financial institution (FI1-F13) that the user is associated with. Generally, the risk limits may define one or more of the following restrictions, singly or in any combination: a total spending limit for digital payments that have not yet been settled; a maximum payment amount for each digital payment; a maximum accumulated payment amount for digital payments, and / or a maximum number of digital payments, performable until requesting settlement; a maximum accumulated payment amount for digital payments performable during a certain time (such as a day, week, month, etc.); a maximum number of digital payments performable during a certain time (such as a day, week, month, etc.); a definition (e.g. aliases) of payment receivers that a payer is allowed to make digital payments to; and a definition (e.g. aliases) of payment receivers that the payer is not allowed to make digital payments to.

[0054] • TBS[m], m={ empty}, 2, 3, 4: A data set that is generated for the first or second digital payment (TX1, TX2; transaction!, transaction2) by a paying communication device (CD1; CD2) or for a payment request by a payment receiving communication device (CD2; DC3).

[0055] • S[m], m={empty}, 2, 3, 4: A digital signature applied to the data set TBSfm] by the paying communication device (CD1; CD2) or the payment receiving communication device (CD2; DC3).

[0056] As can be seen in Figures 8-17, the making (310) of the first offline digital payment (TX1) may advantageously involve the first communication device (CD1) signing the first offline digital payment (TX1) and the second communication device (CD2) performing local verification of the signed first offline digital payment (TX1) without assistance or authorization from a financial institution (FI1-FI3), the payment switch (PS) or any other remote payment network resource.

[0057] For instance, see the box labelled “Create Payment:” in Figure 8, as performed by software (Appl) executed by the first communication device (CD1) and operating on the local digital wallet (LDW / walletl) thereof, the first digital cash repository (DC Rep 1) thereof having a balance (balancel). This box involves a step in which a data set (TBS2) is generated for the first digital payment (TX1 / transaction!) and signed (S2) by a private cryptographic key (walletl _priv_key) kept secret within the first communication device (CD!). Furthermore, see the box containing the step labelled “ Verify Payment Signature” in Figure 8, as performed by software (App2) executed by the second communication device (CD2) and operating on the local digital wallet (LDW / wallet2) thereof. In this step, the signature S2 of the received data set (TBS2) for the first digital payment (TXl / transactionl) is verified locally by the second communication device (CD2) using a digital certificate (walletl cert) which includes a public cryptographic key corresponding to the private cryptographic key (walletl _priv_key) of the first communication device (CD1). In order to trust the digital certificate (walletl cert), the second communication device (CD2) may first verify it using a chain of trusted certificates (ca root, de ceit), with the CA being the issuer of the root certificate (ca root).

[0058] Similarly, the making (320) of the second offline digital payment (TX2) may advantageously involve the second communication device (CD2) signing the second offline digital payment (TX2) and the third communication device (CD3) performing local verification of the signed second offline digital payment (TX2) without assistance or authorization from a financial institution (FI1-FI3), the payment switch (PS) or any other remote payment network resource.

[0059] Here, see the box labelled “ Create Payment:” in Figure 10, as performed by the software (App2) executed by the second communication device (CD2) and operating on the local digital wallet (LDW / wallet2) thereof, the first digital cash repository (DC Rep 1) thereof having a balance (balance2). This box involves a step in which a data set (TBS4) is generated for the second digital payment (TX2 / transaction2) and signed (S4) by a private cryptographic key (wallet2 _priv_key) kept secret within the second communication device (CD2).

[0060] Furthermore, see the box containing the step labelled “ Verify Payment Signature” in Figure 10, as performed by software (App3) executed by the third communication device (CD3) and operating on the local digital wallet (LDW / wallet3) thereof. In this step, the signature S4 of the received data set (TBS4) for the second digital payment (TX2 / transaction2) is verified locally by the third communication device (CD3) using a digital certificate (wallet2_cert) which includes a public cryptographic key corresponding to the private cryptographic key (wallet2 _priv_key) of the second communication device (CD2). In order to trust the digital certificate (wallet2_cert), the third communication device (CD3) may first verify it using a chain of trusted certificates (ca root, de ceit), again with the CA being the issuer of the root certificate (ca root). In some implementations, the making (310) of the first offline digital payment (TX1) involves short-range data communication over a proximity link between the first communication device (CD1) and the second communication device (CD2). Correspondingly, the making (320) of the second offline digital payment (TX2) may involve short-range data communication over a proximity link between the second communication device (CD2) and the third communication device (CD3). The communicating (330) with the computerized payment switch (PS) will, on the other hand, involve wide area network communication.

[0061] In advantageous embodiments, said at least one of the second and third communication devices (CD1, CD2) is configured for storing (137, 137’) the first offline digital payment (TX1) as a first node and the second offline digital payment (TX2) as a second node in a payment transaction data tree structure in its respective second digital cash repository (DC Rep 2). Implementation examples of such a payment transaction data tree structure can be seen as transaction trees 1, transaction tree s2 and transaction trees3 in Figures 8-17.

[0062] In advantageous embodiments, the second communication device (CD2) is further configured, when composing (130) the second offline digital payment (TX2), to traverse the payment transaction data tree structure in the second digital cash repository (DC Rep 2) to identify available digital cash from previously received offline digital payments, represented as nodes in the payment transaction data tree structure, each node comprising a generation counter (cf. hops in Figures 8-17) of the respective offline digital payment, and wherein the digital cash of a given node is considered unavailable if the generation counter (hops') does not satisfy a threshold value.

[0063] Generation counters may be used in the digital payment system (100) in an incremental or decrementing manner, depending on implementation. An incremental generation counter is increased each time the digital cash of an offline digital payment is used in a next offline digital payment, i.e. the generation counter in this case reflects the number of offline transactions that the digital cash has been used for. A decrementing generation counter is instead decreased each time the digital cash of an offline digital payment is used in a next offline digital payment, i.e. the generation counter in this case reflects the number of remaining offline transactions that the digital cash may be used for.

[0064] The threshold value for the generation counter may be set by the respective financial institutions (FI1-F13) that the users (Ul, U2, U3) of the communication devices (CD[n]) are associated with, advantageously as part of the aforementioned risk limits (RL[n]). Alternatively, the threshold value for the generation counter may be a global value for all users of the digital payment system (100). The global value may be a default value that may or may not evolve over time. An example of the former case is that all new users in the digital payment system (100) may have the same global default threshold value of the generation counter. As an individual user uses the digital payment system (100) more and more times and has proven to be a reliable user, he or she may be entrusted with a more “relaxed” threshold value, allowing the user to make use of more “mature” digital cash (having traversed a larger number of offline transactions).

[0065] This will therefore allow a beneficial use case wherein the threshold value of the generation counter (hops) is assigned to the user (U2) of the second communication device (CD2) by the financial institution (FI1-FI3) that the user (U2) of the second communication device (CD2) is associated with, specifically such that said digital cash of said given node in the payment transaction data tree structure is considered available to the user (U2) of the second communication device (CD2) but would have been considered unavailable for the same value of the generation counter (hops) for another user being assigned another threshold value in the digital payment system (100).

[0066] In the above or other advantageous embodiments, the second communication device (CD2) is further configured, when composing (130) the second offline digital payment (TX2), to traverse the payment transaction data tree structure in the second digital cash repository (DC Rep 2) to identify available digital cash from previously received offline digital payments, represented as nodes in the payment transaction data tree structure, each node comprising an age indication of the respective offline digital payment, and wherein the digital cash of a given node is considered unavailable if the age indication exceeds a threshold value.

[0067] Figures 2 illustrates an alternative to Figure 1 as regards how digital cash may be downloaded (110a, 110b) to the communication devices (CD1-CD2) for the purpose of topping up the first digital cash repositories (DC Rep 1) of the their respective local digital wallets (LDW). The digital system (100) in Figure 2 involves a computerized digital wallet server function (DCWS) which manage digital wallets (DCW-DCWn) for different users, including users (U1-U3). The digital wallets (DCW. . DCWn) can be used for online digital payments and may be topped up (110a) from users accounts (UA1-UA3) managed by the financial institutions (FI1-FI3). In turn, the local digital wallets LDW (used for offline digital payments as described above for Figure 1) may be topped up (110b) from the digital wallets (DCW. . .DCWn). The digital wallet server function (DCWS) can be implemented in various different ways in the digital payment system (100). For instance, it may be implemented in, by or as a server-based computing resource at any of the financial institutions (FI1- FI3) or as a separate server-based computing resource connected to, interacting with or controlled by such a financial institution (a cloud computing resource being a typical example of such a separate server-based computing resource). In some embodiments, the digital wallet server function (DCWS) may be seen as a complement or additional computerized layer of an existing digital payment system that involves the computerized core banking resources (such as server resources, storage resources and network resources) of the financial institution. The computerized digital wallet server function (DCWS) may even be hosted by the financial institution. Alternatively, the digital wallet server function (DCWS) may be implemented in, by or as a server-based computing resource at a payment service provider or as a separate server-based computing resource (e.g. cloud computing resource) connected to, interacting with or controlled by such a payment service provider. Other implementation alternatives are also conceivable.

[0068] In this context, Figure 6 illustrates a multi-layered digital payment system architecture, or layout, offered by embodiments of the present invention as an add-on to an existing core banking system layer 651. The multi-layered digital payment system architecture comprises three additional layers which are seen at 661, 671 and 681 in Figure 6. The core banking system layer 651 pertains to a financial institution and includes various computerized core banking resources, collectively indicated at 652 in Figure 6. The computerized core banking resources 652 maintains an account balance 653 for each account owned or controlled by a bank client. For a user, this means the balance of a user account UA1-UA3. A certain part of the account balance 653 can be reserved 654 for use as a digital cash online balance 663.

[0069] The first additional layer 661 is a digital cash online layer which allows users of computerized devices 662 (CD1-CD3) to make online digital payments by using the digital cash online balance 663 which has been reserved from the account balance 653 in the core banking system layer 651. Taking the user U2 using the communication device CD2 as an example, this will mean using the balance of U2’s digital wallet DCW for the digital payment. As can be seen at 664, the available digital cash online balance 663 may be shared between different payment service applications (Appl, App2) run by the user’s communication device. As seen at 665, some (or all) of the available digital cash online balance 663 may be reserved for use as one or more digital cash offline balances 673, potentially one for each payment service application. See (Appl, App2) in Figure 6. Such digital cash offline balances 673 pertain to the second additional layer 671 which, thus, is a digital cash offline layer for mobile applications (application programs for mobile communication devices). The digital cash offline layer 671 allows users of mobile communication devices 672 (such as smart phones or tablet computers) to make offline digital payments in the manner described above, i.e. by using a digital cash offline balance which has been reserved from the digital cash online balance 663 in the digital cash online layer 661. For user U1 using the communication device CD2, this will mean using the balance of the first digital cash repository (DC Rep 1) in his or her local digital wallet LWD for the digital payment, as previously described in this document.

[0070] As can be seen at 674, an available digital cash offline balance 673 may be transferred partly (or fully) between the user’s mobile communication device 672 and a smart card, smart chip or similar small device 682 by way of short-range data communication. The smart card, smart chip or similar small device 682 may be a separate physical (stand-alone) device, or coupled to, included in or integrated with a mobile communication device or other computerized device, as can be seen from the example devices shown at 682 in Figure 6. The smart card, smart chip or similar small device 6will thus have a digital cash offline balance 683 which can be used for offline digital payments. The digital cash offline balance 683 pertains to the third additional layer 681 which, thus, is an extra digital cash offline layer, particularly suited for use with devices which are not enabled for mobile applications. In this way, even those kind of devices are enabled to make offline digital payments.

[0071] Reference is now made to Figure 4 and the communication device (CD) which is illustrated at 400. The communication device (CD) may implement any of the communication devices (CD1-CD3) in the digital payment system (100) and computerized method (300) in Figures 1-3. To this end, the communication device (CD) comprises a processing device (402), local storage including a memory (404), a short- range data communication interface (406), a wide area network communication interface (408) and a user interface (410).

[0072] The processing device (402) acts as a controller of the communication device (400) and may be implemented in any known controller technology, including but not limited to microcontroller, processor (e.g. PLC, CPU, DSP), FPGA, ASIC or any other suitable digital and / or analog circuitry capable of performing the intended functionality. The memory (404) may be implemented in any known memory technology, including but not limited to ROM, RAM, SRAM, DRAM, CMOS, FLASH, DDR, SDRAM or some other memory technology. In some embodiments, the memory or parts thereof may be integrated with or internal to the processing device (402). The memory may store program instruction for execution by the processing device (402) (also see the description of Figure 5 below), as well as temporary and permanent data for use by the processing device (402).

[0073] The short-range data communication interface (406) may be configured for Bluetooth communication, or any other radio-based short-range wireless data communication such as, for instance, Bluetooth Low Energy, RFID, WLAN, WiFi, mesh communication or LTE Direct, without limitation, or any non-radio-based short- range wireless data communication such as, for instance, magnetic communication (such as NFC), (ultra)sound communication, or optical communication (such as IrDA) without limitation. In some embodiments, the short-range data communication interface 406 comprises equipment and functionality for presenting or scanning a QR code. The short-range data communication interface (406) may thus be used to establish the proximity link and perform the short-range data communication for any of the first or second offline digital payments (TX1, TX2) as referred to above.

[0074] The wide area network communication interface (408) may be configured for wide area network communication compliant with, for instance, one or more of W- CDMA, GSM, UTRAN, HSPA, LTE, LTE Advanced or 5G, and TCP / IP, and / or WLAN (WiFi), without limitation.

[0075] The user interface (410) may comprise an input device and a presentation device, as is generally known per se. In some embodiments, the input device and the presentation device are constituted by one common physical device, such as for instance a touch screen (touch-sensitive display screen), implemented in for instance resistive touch technology, surface capacitive technology, projected capacitive technology, surface acoustic wave technology or infrared technology.

[0076] The communication device (CD) further comprises a trusted execution environment (TEE) or alternatively a secure element, i.e. a tamper-resistant virtual or hardware-based platform. In the former case, the secure element may have its own CPU and protected memory. In the latter case, the trusted execution environment (TEE) may be implemented in software and may reside in the local storage or even the memory (404). The trusted execution environment (TEE) or secure element is capable of securely hosting applications and storing confidential and cryptographic data and therefore provides a trusted environment for execution of such applications, a.k.a. secure runtime. Advantageously, some of the data and functionality in embodiments of the invention may be stored in and performed by the trusted execution environment (TEE) (or secure element), as will be clear from other sections of this document and, in particular, from the drawings.

[0077] As mentioned, the communication device in Figure 4 may, for instance, implement the communication device (CD2). Accordingly, a communication device (CD, CD2) is provided as follows. The communication device (CD, CD2) comprises a trusted execution environment (TEE) configured for accommodating a local digital wallet (LWD) having a first digital cash repository (DC Rep 1) and a second digital cash repository (DC Rep 2), the first digital cash repository (DC Rep 1) representing digital cash that corresponds to a reservation of funds in an account (UA2) which is maintained at a financial institution (FI2) and is associated with a user (U2) of the communication device (CD2), and the second digital cash repository (DC Rep 2) representing digital cash that has been transferred in one or more offline digital payments from one or more other communication devices, wherein the communication device (CD; CD2) is configured for: receiving (120) a first offline digital payment (TX1) from another communication device (CD1), storing (125) the first offline digital payment (TX1) in the second digital cash repository (DC Rep 2), composing (130) a second offline digital payment (TX2) as a combination of digital cash from the first and second digital cash repositories (DC Rep 1, DC Rep 2), including all or some of said first offline digital payment (TX1), sending (135) the second offline digital payment (TX2) to another communication device (CD3), storing (137’) the second offline digital payment (TX2) in the second digital cash repository (DC Rep 2), wherein the storing includes storing information about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2), and requesting settlement (140’) of the second offline digital payment (TX2) by communicating the stored second offline digital payment (TX2), including the information (142’) about the payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2). Each of the communication devices (CD1-CD3; CD) as described in this document may, for instance, be any of the following: a mobile communication device; a mobile phone; a smart phone; a tablet computer; a personal digital assistant; a portable computer; smart glasses; a smart wearable; a smart watch; a smart bracelet; a smart card; and a smart chip.

[0078] Figure 5 is a schematic illustration of a computer-readable medium (500) in one exemplary embodiment, capable of storing a computer program product (510). The computer-readable medium (500) in the disclosed embodiment is a portable memory device, such as a Universal Serial Bus (USB) stick. The computer-readable medium (500) may however be embodied in various other ways instead, as is well-known per se to the skilled person. The portable memory device (500) comprises a housing (530) having an interface, such as a connector (540), and a memory chip (520). In the disclosed embodiment, the memory chip (520) is a flash memory, i.e. a non-volatile data storage that can be electrically erased and re-programmed. The memory chip (520) stores the computer program product (510) which is programmed with computer program code (instructions) that when loaded into a processing device, such as a CPU, will perform any of the functionalities listed in the next paragraph. The processing device may, for instance, be the aforementioned processing device (402). The portable memory device (500) is arranged to be connected to and read by a reading device for loading the instructions into the processing device. It should be noted that a computer- readable medium can also be other media such as compact discs, digital video discs, hard drives or other memory technologies commonly used. The computer program code (instructions) can also be downloaded from the computer-readable medium via a wireless interface to be loaded into the processing device.

[0079] In one embodiment, therefore, the computer program product (510) comprises computer code for performing the functionality of the communication device (CD; CD2) in the system (100) or method (300) as described herein when the computer program code is executed by the processing device. Hence, Figure 5 can be considered to illustrate a non-volatile computer readable medium (500) having stored thereon a computer program (i.e. a computer program product) comprising computer program code for performing the following functionality when the computer program code is executed by a processing device: accommodating, in a trusted execution environment (TEE), a local digital wallet (LDW) having a first digital cash repository (DC Rep 1) and a second digital cash repository (DC Rep 2), the first digital cash repository (DC Rep 1) representing digital cash that corresponds to a reservation of funds in an account which (UA2) is maintained at a financial institution (FI2), and the second digital cash repository (DC Rep 2) representing digital cash that has been transferred in one or more offline digital payments; receiving a first offline digital payment (TX1) from a communication device (CD1), storing the first offline digital payment (TX1) in the second digital cash repository (DC Rep 2), composing a second offline digital payment (TX2) as a combination of digital cash from the first and second digital cash repositories (DC Rep 1, DC Rep 2), including all or some of said first offline digital payment (TX1), sending the second offline digital payment (TX2) to another communication device (CD 3), storing the second offline digital payment (TX2) in the second digital cash repository (DC Rep 2), wherein the storing includes storing information about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2), and requesting settlement of the second offline digital payment (TX2) by communicating the stored second offline digital payment (TX2), including the information (142’) about the payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2).

[0080] Any cloud computing resources as referred to in this document may for instance be implemented as one or more physical server computers or computer systems, or one or more distributed networks of computing resources, for instance providing cloud computing services based on Amazon Web Services (AWS), Microsoft Azure or Google Cloud Platform (GCP).

[0081] Any digital certificates referred to in this document including its appended drawings may, for instance, be DER-encoded X.509-based certificates which comprise public cryptographic keys for the respective entities of the digital payment system 100, as described above.

[0082] When reference in this document or the appended drawings is being made to a private cryptographic key which is associated with a particular digital certificate, this includes a case where the particular digital certificate comprises a public cryptographic key, and where the private (secure) cryptographic key and the public cryptographic key together constitute a cryptographic key pair as is generally known for asymmetric data encryption and decryption.

[0083] When reference in this document is being made to “settlement”, it may also be considered to refer, implicitly if not explicitly, to “clearing” as a preparatory or preceding step of the actual settlement. Hence, “requesting settlement of an offline digital payment” shall be construed to include all of the following alternatives: initiating actual settlement, initiating clearing as an integrated part of settlement, and initiating clearing which in turn invokes, causes or is otherwise followed by settlement”.

Claims

CLAIMS1. A computerized method (300) of performing transparent and versatile transfer of digital cash, the method involving: making (310) a first offline digital payment (TX1), representing a first amount of digital cash, from a first communication device (CD1) to a second communication device (CD2), making (320) a second offline digital payment (TX2), representing a second amount of digital cash, from the second communication device (CD2) to a third communication device (CD3), wherein the second offline digital payment (TX2) is composed (130) of a combination of a) a deduction from digital cash which has been downloaded (110; 110a, 110b) to the second communication device (CD2) and corresponds to a reservation of funds in an account (UA2) maintained at a financial institution (FI2), and b) all or some of the first amount of digital cash as received in the first offline digital payment (TX1), and communicating (330) with a computerized payment network resource to make a request (140) for settlement of the second offline digital payment (TX2), wherein the request for settlement includes information (142) about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2).

2. The computerized method (300) as defined in claim 1, wherein the making (310) of the first offline digital payment (TX1) involves the first communication device (CD1) signing the first offline digital payment (TX1) and the second communication device (CD2) performing local verification of the signed first offline digital payment (TX1) without assistance or authorization from a financial institution (FI1-FI3), the payment switch (PS) or any other remote payment network resource, and wherein the making (320) of the second offline digital payment (TX2) involves the second communication device (CD2) signing the second offline digital payment (TX2) and the third communication device (CD3) performing local verification of the signed second offline digital payment (TX2) without assistance or authorization from a financial institution (FI1-FI3), the payment switch (PS) or any other remote payment network resource.

3. The computerized method (300) as defined in claim 1 or 2,wherein the making (310) of the first offline digital payment (TX1) involves short-range data communication over a proximity link between the first communication device (CD1) and the second communication device (CD2), wherein the making (320) of the second offline digital payment (TX2) involves short-range data communication over a proximity link between the second communication device (CD2) and the third communication device (CD3), and wherein the communicating (330) with the computerized payment switch (PS) involves wide area network communication.

4. A digital payment system (100), the system comprising: a plurality of communication devices (CD1-CD3); and a computerized payment switch (PS), each communication device (CD1-CD3) comprising a local digital wallet (LDW) being configured for accommodating a first digital cash repository (DC Rep 1) and a second digital cash repository (DC Rep 2), the first digital cash repository (DC Rep 1) representing digital cash that corresponds to a reservation of funds in an account (UA1-UA3) which is maintained at a financial institution (FI1-FI3) and is associated with a user (U1-U3) of the communication device (CD1-CD3), and the second digital cash repository (DC Rep 2) representing digital cash that has been transferred in one or more offline digital payments from one or more of the other communication devices of the system, wherein: a first communication device (CD1) is configured for making a first offline digital payment (TX1) to a second communication device (CD2), the second communication device (CD2) is configured for storing the first offline digital payment (TX1) in its second digital cash repository (DC Rep 2), the second communication device (CD2) is further configured for making a second offline digital payment (TX2) to a third communication device (CD3), wherein the second offline digital payment (TX2) is composed (130) of a combination of digital cash from the first and second digital cash repositories (DC Rep 1, DC Rep 2) of the second communication device (CD2), including all or some of said first offline digital payment (TX1), at least one of the second and third communication devices (CD1, CD2) is configured for storing (137, 137’) the second offline digital payment (TX2) in its respective second digital cash repository (DC Rep 2), wherein the storing includesstoring information about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2), and said at least one of the second and third communication devices (CD1, CD2) is configured for requesting settlement (140, 140’) of the second offline digital payment (TX2) by communicating to the computerized payment switch (PS) the stored second offline digital payment (TX2), including the information (142, 142’) about the payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2).

5. The digital payment system (100) as defined in claim 4, wherein said at least one of the second and third communication devices (CD1, CD2) is configured for storing (137, 137’) the first offline digital payment (TX1) as a first node and the second offline digital payment (TX2) as a second node in a payment transaction data tree structure in its respective second digital cash repository (DC Rep 2).

6. The digital payment system (100) as defined in claim 5, wherein the second communication device (CD2) is further configured, when composing (130) the second offline digital payment (TX2), to traverse the payment transaction data tree structure in the second digital cash repository (DC Rep 2) to identify available digital cash from previously received offline digital payments, represented as nodes in the payment transaction data tree structure, each node comprising a generation counter (hops) of the respective offline digital payment, and wherein the digital cash of a given node is considered unavailable if the generation counter (hops) does not satisfy a threshold value.

7. The digital payment system (100) as defined in 6, wherein the threshold value of the generation counter (hops) is assigned to the user (U2) of the second communication device (CD2) by the financial institution (FI1-FI3) that the user (U2) of the second communication device (CD2) is associated with, specifically such that said digital cash of said given node in the payment transaction data tree structure is considered available to the user (U2) of the second communication device (CD2) but would have been considered unavailable for the same value of the generation counter (hops) for another user being assigned another threshold value in the digital payment system (100).

8. The digital payment system (100) as defined in claim 5, 6 or 7, wherein the second communication device (CD2) is further configured, when composing (130) the second offline digital payment (TX2), to traverse the payment transaction data tree structure in the second digital cash repository (DC Rep 2) to identify available digital cash from previously received offline digital payments, represented as nodes in the payment transaction data tree structure, each node comprising an age indication of the respective offline digital payment, and wherein the digital cash of a given node is considered unavailable if the age indication exceeds a threshold value.

9. A communication device (CD; CD2), comprising: a trusted execution environment (TEE) configured for accommodating a local digital wallet (LWD) having a first digital cash repository (DC Rep 1) and a second digital cash repository (DC Rep 2), the first digital cash repository (DC Rep 1) representing digital cash that corresponds to a reservation of funds in an account (UA2) which is maintained at a financial institution (FI2) and is associated with a user (U2) of the communication device (CD2), and the second digital cash repository (DC Rep 2) representing digital cash that has been transferred in one or more offline digital payments from one or more other communication devices, wherein the communication device (CD; CD2) is configured for: receiving (120) a first offline digital payment (TX1) from another communication device (CD1), storing (125) the first offline digital payment (TX1) in the second digital cash repository (DC Rep 2), composing (130) a second offline digital payment (TX2) as a combination of digital cash from the first and second digital cash repositories (DC Rep 1, DC Rep 2), including all or some of said first offline digital payment (TX1), sending (135) the second offline digital payment (TX2) to another communication device (CD3), storing (137’) the second offline digital payment (TX2) in the second digital cash repository (DC Rep 2), wherein the storing includes storing information about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2), and requesting settlement (140’) of the second offline digital payment (TX2) by communicating the stored second offline digital payment (TX2), including theinformation (142’) about the payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2).

10. The communication device (CD) as defined in claim 9, wherein the communication device is one of the following: a mobile communication device; a mobile phone; a smart phone; a tablet computer; a personal digital assistant; a portable computer; smart glasses; a smart wearable; a smart watch; a smart bracelet; a smart card; and a smart chip.

11. A computer program product (510) comprising computer program code for performing the following functionality when the computer program code is executed by a processing device: accommodating, in a trusted execution environment (TEE), a local digital wallet (LDW) having a first digital cash repository (DC Rep 1) and a second digital cash repository (DC Rep 2), the first digital cash repository (DC Rep 1) representing digital cash that corresponds to a reservation of funds in an account which (UA2) is maintained at a financial institution (FI2), and the second digital cash repository (DC Rep 2) representing digital cash that has been transferred in one or more offline digital payments; receiving a first offline digital payment (TX1) from a communication device (CD1); storing the first offline digital payment (TX1) in the second digital cash repository (DC Rep 2); composing a second offline digital payment (TX2) as a combination of digital cash from the first and second digital cash repositories (DC Rep 1, DC Rep 2), including all or some of said first offline digital payment (TX1); sending the second offline digital payment (TX2) to another communication device (CD3); storing the second offline digital payment (TX2) in the second digital cash repository (DC Rep 2), wherein the storing includes storing information about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2); and requesting settlement of the second offline digital payment (TX2) by communicating the stored second offline digital payment (TX2), including the information(142’) about the payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2).

12. A non-volatile computer readable medium (500) having stored thereon a computer program comprising computer program code for performing the following functionality when the computer program code is executed by a processing device: accommodating, in a trusted execution environment (TEE), a local digital wallet (LDW) having a first digital cash repository (DC Rep 1) and a second digital cash repository (DC Rep 2), the first digital cash repository (DC Rep 1) representing digital cash that corresponds to a reservation of funds in an account which (UA2) is maintained at a financial institution (FI2), and the second digital cash repository (DC Rep 2) representing digital cash that has been transferred in one or more offline digital payments; receiving a first offline digital payment (TX1) from a communication device (CD1); storing the first offline digital payment (TX1) in the second digital cash repository (DC Rep 2); composing a second offline digital payment (TX2) as a combination of digital cash from the first and second digital cash repositories (DC Rep 1, DC Rep 2), including all or some of said first offline digital payment (TX1); sending the second offline digital payment (TX2) to another communication device (CD3); storing the second offline digital payment (TX2) in the second digital cash repository (DC Rep 2), wherein the storing includes storing information about payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2); and requesting settlement of the second offline digital payment (TX2) by communicating the stored second offline digital payment (TX2), including the information (142’) about the payers and payees (Ul, U2; U2, U3) of the first as well as second offline digital payments (TX1, TX2).