System and method for authorising payment in in-person self-service environments

The system addresses inefficiencies in unattended payment environments by using a tokenization module and token server to enable secure contactless payments, enhancing user experience and provider control.

WO2026104746A1PCT designated stage Publication Date: 2026-05-21SEGLAN
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SEGLAN
Filing Date
2025-11-11
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing payment systems in unattended environments, such as vending machines, do not effectively address the unique requirements of these settings, leading to inefficiencies and lack of control for service providers, and do not leverage contactless smart card technology optimally.

Method used

A system comprising an unattended device with a tokenization module and communication module, connected to a token server and payment network, enabling secure contactless payments through a tokenization process that maintains control over service delivery and allows for personalized user experiences.

Benefits of technology

Enables secure, contactless payments without third-party restrictions, optimizing user experience and service provider control, while facilitating transaction analysis and personalized marketing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure ES2025070692_21052026_PF_FP_ABST
    Figure ES2025070692_21052026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is a system and method for authorising payment in in-person self-service environments such as vending machines or devices without in-person assistance, Internet of Everything (IoT) devices, in which payment is made contactlessly using mobile devices or cards known as "contactless" cards. The invention also relates to a system, a server and different elements of the self-service machine for carrying out the method. The system comprises a token server (5), a payment means network (6), and an in-person self-service device (1), which comprises a tokenisation module (2) and a communication module (3).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM AND METHOD FOR ENABLING PAYMENT IN UNASSISTED FACE-TO-FACE ENVIRONMENTS OBJECT OF THE INVENTION

[0002] The present invention relates to a method for enabling payment in unattended face-to-face environments such as vending machines or unattended devices, Internet of Things (IoT) devices, etc., where payment is made without contact using mobile devices or cards known as "contactless" cards.

[0003] This invention also relates to a system, a server, and various elements in the unattended device for carrying out the method.

[0004] BACKGROUND OF THE INVENTION

[0005] The transformation from traditional cash to card payments in vending machines can improve the convenience and security of the operation for all participants in the ecosystem, reduce costs and simplify management, opening up new possibilities for transaction analysis and personalized marketing.

[0006] The development of electronic payment in vending machines and unattended machines in general has had a significant impact over the past few years in a significant number of markets.

[0007] In all cases to date, this development has been handled in the same way as the development of in-person payments in stores, that is, by deploying conventional payment devices such as card readers, pinpads, etc. on the machines themselves.

[0008] The problem with the previous solution is that it has not taken into consideration the specificity of an unattended payments environment, and therefore, the unattended environment has not been effectively resolved, having placed the rules and operations that operate in traditional commerce in an environment different from that of traditional commerce.

[0009] Furthermore, the use of contactless smart cards for payment, which began years ago, can now be considered fully accepted and used by cardholders either directly with the corresponding card or indirectly through one of the manufacturer's wallets on the mobile phone (Google, Samsung or Apple, etc.).

[0010] Well, with all this, the present invention proposes to open a new path in which, by involving a system, a server and hardware-software elements in the service delivery machine, a significant step can be taken towards optimizing the personalized user experience and the relationship with the customer by the operator of unattended on-site devices.

[0011] DESCRIPTION OF THE INVENTION

[0012] An object of the invention is therefore to provide a payment system to providers of vending services in unattended machines or devices, with a secure method that can be carried out entirely within the domain of the service providers themselves, thereby helping them to maintain full control of their service.

[0013] The present invention allows brand, business and contactless payments to coexist without third-party restrictions.

[0014] In a first aspect of the invention, a system for enabling payment in unattended, in-person environments is disclosed. The system comprises:

[0015] • an unattended presence device that, identified by a machine-ID, is configured to generate an operation-ID when a user selects a product / service on the unattended presence device;

[0016] • a tokenization module on the unattended, on-site device;

[0017] • a communication module on the unattended, on-site device;

[0018] • a token server connected to a payment network and to the tokenization module via the communication module; and,

[0019] • an unattended on-site device operator connected to the token server; optionally, the device operator can also be directly connected to the unattended on-site device without the token server.

[0020] The token server is configured to: • store a user token-ID and a payment token associated with the token-ID, where the payment token associated with the token-ID is provided by the payment network;

[0021] • receive the token-ID, machine-ID and operation-ID from the unattended on-site device;

[0022] • send a management request to the unattended on-site device operator, where the management request comprises at least: the token-ID, the machine-ID, and the operation-ID;

[0023] • receive a response to the management request, where the response comprises at least the token-ID, the machine-ID, and the operation-ID;

[0024] • send an authorization request to the payment network, where the request comprises at least: the token-ID, the payment token, and the transaction-ID;

[0025] • receive a response to the request for authorization to the payment network;

[0026] where the response comprises at least the token-ID, the payment token, and the transaction-ID;

[0027] • Send the response to the unattended on-site device where the response comprises at least the token-ID, the machine-ID, and the operation-ID.

[0028] The machine-ID is a code that identifies an unattended, in-person device. The transaction-ID is a data string that includes at least the following information: the item / product requested by the user, the cost of the item / service, whether the purchase was authorized or denied, any errors that occurred during the purchase, and any other relevant data related to the purchase. Optionally, the transaction-ID may also include discounts and promotions offered in marketing campaigns.

[0029] The token-ID structure will consist of a string of between 12 and 19 digits and may include a final control character similar to a Luhm code. It may also include a prefix of up to 8 digits to indicate the token's originating operator and scope of use. The first three digits of the prefix will indicate the origin (the operator that first captured the token), the next three will indicate the token-ID's usability with other unattended presence device operators, and the final two will represent client control and reliability codes. In one embodiment of the invention, the token server is connected to M unattended presence devices and additionally connected to N unattended presence device operators. The values ​​of "M" and "N" may be the same or different. Typically, there are more unattended presence devices than unattended presence device operators.Therefore, it is common for “M” to be greater than “N”.

[0030] In another embodiment of the invention, the unattended on-site device is a vending machine.

[0031] In another embodiment of the invention, the tokenization module is configured to request and capture payment credentials from the user. To this end, the tokenization module comprises a contactless reading module with Host Card Emulation (HCE) application processing capabilities, which read payment information stored on the user's mobile device (such as a digital wallet) or bank card.

[0032] In another embodiment of the invention, the token server may additionally comprise:

[0033] • a database of unattended on-site device operators authorized to operate on the system;

[0034] • a database of unattended on-site devices for each of the unattended on-site device operators in the system;

[0035] • a customer database along with their respective token-IDs, where the activation points (unattended on-site devices where the token-ID is activated) and token-ID usage and token-ID lifetimes for each user are stored;

[0036] • a customer profile database in which, along with the token-ID, the temporary aggregate of purchases made on the network of unattended physical devices is stored for a time window (day, week, month) in the system.

[0037] In a second aspect of the invention, a method for enabling payment in unattended, in-person environments is disclosed. The method is implemented on the system described in the first aspect of the invention. The method comprises:

[0038] a) request from the user, through the tokenization module, the token-ID that identifies the user;

[0039] b) generate an operation-ID when the user selects a product / service on the unattended in-person device;

[0040] c) send, from the tokenization module to the token server, the token-ID, the machine-ID and the operation-ID;

[0041] d) send a management request, from the token server to the unattended on-site device operator, where the management request comprises at least: the token-ID, the machine-ID, and the operation-ID;

[0042] e) receive on the token server, a response to the management request, where the response comprises at least the token-ID, the machine-ID and the operation-ID; f) send, from the token server to the payment media network, an authorization request, where the request comprises at least: the token-ID, the payment token and the operation-ID;

[0043] g) receiving, on the token server, a response to the request for authorization to the payment network; wherein the response comprises at least the token-ID, the payment token and the transaction-ID;

[0044] h) send to the unattended on-site device the response to the authorization request, where the response comprises at least the token-ID, the machine-ID and the operation-ID.

[0045] The management request, the response request and their respective responses (steps d) ah)) may include adding or modifying the operation-ID.

[0046] In one embodiment of the invention, step a) of the method may further comprise:

[0047] • ask the user for payment methods associated with the user;

[0048] • Send the payment methods to the token server via the communication module;

[0049] • receive, from the token server, the token-l D generated by the payment network for the user's payment methods (this token-ID will be associated with the payment token and will be unique in the unattended physical device network so that the server can identify whether a customer is a new customer in the network or is a pre-existing customer with previous purchases);

[0050] • Send the user the token-ID, using a Host Card Emulation “HCE” application to a smartphone with application execution capabilities or to a bank card; this step can be performed from the token server or from the operator of unattended on-site devices.

[0051] The transaction ID is a data string that includes at least the following information: the item / product requested by the user, the cost of the item / service, the authorization / denial of the purchase, any errors that occurred during the purchase, and any other relevant information related to the purchase. Optionally, the transaction ID may also include discounts and promotions offered in marketing campaigns.

[0052] Communications between the token server and the payment network are carried out via a secure mTLS connection with a TR-TSP service from a certified brand tokenization service provider.

[0053] In another embodiment of the invention, the method further comprises storing the token-ID and the payment token associated with the token-ID on the token server. Optionally, the server module, associated with each token-ID, accumulates the daily, weekly, and monthly amounts of purchases made by each customer.

[0054] In another embodiment of the invention, the method may additionally comprise carrying out the following steps on the token server:

[0055] • activate, deactivate or delete logic of unattended on-site devices (points of sale), that is, of tokenization modules and communication modules deployed in the field;

[0056] • manage the customer lifecycle, including: token-IDs, active life periods, renewals, and an additional set of data that the HCE application manages for each customer;

[0057] • manage authorized payment channels (being able to manage main and alternative channels and managing in each of them the authorized payment mechanisms that can be updated as the evolution of payment protocols does so; currently the authorized channels include: 3DS, TAVV and Moto);

[0058] • Settle and reconcile payment transactions managed by the operator of unattended in-person devices, unattended in-person devices, and a merchant that owns the unattended in-person devices.

[0059] In another embodiment of the invention, the method may additionally comprise carrying out the following steps on the token server:

[0060] • receive from an unattended on-site device operator, marketing actions to be carried out on specific unattended on-site devices of the unattended on-site device operator's network, or in specific time periods of the unattended on-site device operator's network (these marketing campaigns may involve reductions in the price of the product and / or service, or even make it free);

[0061] • Generate a payment authorization request with a recalculated amount based on an applied marketing campaign, or generate an authorization if it is a free scenario;

[0062] • Directly manage the payment (without intervention from the operator of unattended physical devices) and once authorized by the payment network, increase the accumulated amount corresponding to the token-ID in each of the corresponding periodic periods, if there is no specific marketing campaign to carry out.

[0063] In another embodiment of the invention, the method may further comprise, on the token server: managing the generation of fixed fees for the customer to access the goods and services provided by the operator of unattended kiosks, a merchant owning at least one unattended kiosk, and / or a point of sale, incorporating recurring payments into a managed payment channel. Optionally, the method may further comprise:

[0064] • Divide a granted right into several partitions and generate a separate credential for each of the partitions (the right can be differentiated for each client based on their risk profile or purchase history, last digits of the prefix associated with each token-ID);

[0065] • send an initial set of credentials to the HCE application (the server will have a minimum threshold in the HCE application so that it can request the token server to send new credentials again or up to the limit of the right granted to use services;

[0066] • incrementally generate credentials for each token-ID and incorporate a summary of the token server's electronic signature;

[0067] • Validate, through the HCE application, each of the received credentials by validating the embedded signature;

[0068] • Check an index of the first downloaded credential and verify that the first downloaded credential corresponds to the one that should have been downloaded from the server.

[0069] A credential or set of credentials can be disabled in the mobile phone application by sending a deactivation (or deletion) message for the corresponding credentials.

[0070] Activating credentials in the customer profile avoids managing payment operations in each transaction, allowing for better response times and optimization of commercial conditions.

[0071] BRIEF DESCRIPTION OF THE FIGURES

[0072] To aid in a better understanding of the characteristics of the invention and to complement this description, the following figures are included as an integral part thereof, the nature of which is illustrative and not limiting:

[0073] FIG. 1 is a block diagram illustrating an example embodiment of the system of the present invention.

[0074] FIG. 2 is a flowchart illustrating the main steps of an example embodiment of the method of the present invention.

[0075] DETAILED DESCRIPTION

[0076] Figure 1 shows a block diagram illustrating an example of the implementation of the system of the present invention. The system comprises the unattended vending machine 1 (a vending machine) identified by an identification code called “machine-ID” T, the tokenization module 2 and the communication module 3, both located in the unattended vending machine 1, the token server 5, and the payment network 6. The token server 5 is connectable to the payment network 6 and to the tokenization module 2, the latter via the communication module 3, and to the unattended vending machine operator 4 via an internet connection 7. The system, through its various components (detailed above), is configured to carry out the steps of the method described below.

[0077] Tokenization module 2 is embedded in the unattended in-person device 1, which, in FIG. 1, is a vending machine. Tokenization module 2 is the key element in customer interaction as it allows for the identification of the customer and their payment methods.

[0078] In tokenization module 2, located in vending machine 1, the contactless payment credential presented by customer 10 is captured. The payment credential can be a plastic card or a payment wallet. Tokenization module 2 sends the payment credential to the token server 5 to be tokenized as a payment token according to the rules imposed by the payment card brands. To do this, tokenization module 2 first has the necessary hardware for contactless communication with payment cards and with HCE (Host Card Emulation) applications presented from smartphones, typically running operating systems like Android and iOS. This low-level hardware can communicate either with the AIDs (Application Identifiers) database of the established payment card brands or with the mobile application that the customer's loyalty program allows them to download.It then establishes a secure mTLS connection with a TR-TSP service, either from a certified brand tokenization service provider or from the established provider service network. Previously, during the configuration and commissioning of the system of this invention, the token server 5 must have managed the activation of the unattended point-of-sale (APOS) operator 4 and each of its points of sale (unattended APOS device 1) as partner merchants for managing the tokenization of the presented payment card data. Additionally, in cases where the HCE application of the partner operator or merchant is present, the tokenization module 2 may, in the event of interruptions to the data communication service 12, make authorization decisions for the release of the product or service based on data associated with the HCE application.

[0079] The token server 5 is the central element that communicates via the internet 7 with the other elements (1, 4, 6) of the system. The token server 5 comprises:

[0080] • a database of unattended on-site device operators 4 authorized to operate in the system;

[0081] • a database of unattended on-site devices 1 for each of the unattended on-site device operators 4 in the system;

[0082] • a customer database along with their respective token-IDs, where the activation points (unattended on-site devices where the token-ID is activated) and token-ID usage and token-ID lifetimes for each user are stored;

[0083] • a customer profile database in which, along with the token-ID, the temporary aggregate of purchases made on the network of unattended physical devices is stored 1 per time window (day, week, month) in the system.

[0084] The token server 5, through embedded logic, is configured to:

[0085] • be responsible for the activation and deactivation or even logical removal of points of sale, that is, of tokenization modules 2 deployed in the field;

[0086] • Be responsible for managing the customer lifecycle, which involves managing token IDs, their active lifecycles, renewals, and the additional data set that the HCE application manages for each customer. The token ID structure will consist of a string of between 12 and 19 digits and may include a final control character similar to a Luhm code. It may also include a prefix of up to 8 digits to indicate the token's originating operator and scope of use. The first three digits of the prefix will indicate the origin (the operator that first captured the customer), the next three will indicate the token ID's usability with other operators, and the final two will represent customer control and reliability codes.

[0087] • Responsible for managing authorized payment channels, including primary and alternative channels, and managing the authorized payment mechanisms within each channel, which can be updated as payment protocols evolve. Currently, authorized channels include: 3DS, TAVV, and Moto.

[0088] Furthermore, token server 5 will be responsible for the settlement and reconciliation of payment transactions handled by the unattended in-person device operator 4, the merchant that manages the unattended in-person device 1 and the point of sale (unattended in-person device 1).

[0089] Figure 2 shows the flowchart illustrating the main steps of an example embodiment of the method of the present invention. The method comprises: a) requesting, by tokenization module 2, from user 10, the token-ID 8 that identifies said user 10;

[0090] b) generate 21 an operation-ID 1” when a user 10 selects a product / service on the unattended on-site device 1;

[0091] c) send 22, from tokenization module 2 to token server 5, token-ID 8, machine-ID T and operation-ID 1”;

[0092] d) send 23 a management request, from the token server 5 to the unattended on-site device operator 4, where the management request comprises at least: token-ID 8, machine-ID 1', and operation-ID 1”; e) receive 24 on the token server 5, a response to the management request, where the response comprises at least token-ID 8, machine-ID T and operation-ID 1”;

[0093] f) send 25, from token server 5 to payment media network 6, an authorization request, wherein the request comprises at least: token-ID 8, payment token 9 and operation-ID 1”;

[0094] g) receive 26, on the token server 5, a response to the request for authorization to the payment media network 6; wherein the response comprises at least the token-ID 8, the payment token 9 and the operation-ID 1”;

[0095] h) send 27, from token server 5 or from unattended on-site device operator 4, to unattended on-site device 1, the response to the authorization request, wherein the response comprises at least token-ID 8, machine-ID T and operation-ID 1.”

[0096] The method may additionally include storing the token-ID and the payment token associated with that token-ID on the token server. Optionally, the server module, associated with each token-ID, accumulates the daily, weekly, and monthly amounts of purchases made by each customer.

[0097] The method additionally comprises carrying out the following steps on token server 5: • receiving from an unattended presence device operator 4, marketing actions to be carried out on specific unattended presence devices 1 of the unattended presence device operator 4's network, or at specific time periods of the unattended presence device operator 4's network;

[0098] • Generate a payment authorization request with a recalculated amount based on an applied marketing campaign, or generate an authorization if it is a free scenario;

[0099] • Directly manage the payment and, once authorized by the payment network 6, increase the accumulated amount corresponding to the token-ID in each of the corresponding periodic periods, if there is no specific marketing campaign to carry out.

[0100] When the customer wants to use the system for the first time, i.e., the unattended on-site device 1 for the first time, the method comprises the following steps:

[0101] • Client 10 installs an HCE mobile application on their mobile terminal that uses the payment SDK (payment file according to the operating system present on the mobile terminal) and registers as a client in the system;

[0102] • The login process returns to the application / SDK a unique client identifier, a dynamic key that will be used for encrypting messages during the session, and a list of the token-IDs associated with the client;

[0103] • With this HCE application, client 10 will be able to have a complete visualization of the marketing campaigns of each operator of unattended on-site devices 4 in the system and will be able to access the vending machines (unattended on-site device 1) by simply bringing their mobile terminal close to the vending machine, in which the HCE application will present the token-ID 8 to the tokenization module 2.

[0104] Through the previous steps, the token-ID 8 along with the purchase data (operation-ID D) is transferred to the token server 5 where the payment token 9 will be taken.

Claims

CLAIMS 1. A system to enable payment in unattended in-person environments, characterized in that it comprises: • an unattended presence device (1) which, identified by a machine-ID (T), is configured to generate an operation-ID (1”) when a user (10) selects a product / service on the unattended presence device (1); • a tokenization module (2) in the unattended presence device (1); • a communication module (3) in the unattended presence device (1); • a token server (5) connected to a payment media network (6) and to the tokenization module (2) via the communication module (3); • an unattended on-site device operator (4) connected to the token server (5); where the token server (5) is configured to: • store a user token-ID (8) (10) and a payment token (9) associated with the token-ID (8), wherein the payment token (9) associated with the token-ID (8) is provided by the payment media network (6); • receive the token-ID (8), the machine-ID (T) and the operation-ID (1”) from the unattended on-site device (1); • send a management request to the unattended on-site device operator (4), wherein the management request comprises at least: the token-ID (8), the machine-ID (T), and the operation-ID (1”); • receive a response to the management request, where the response comprises at least the token-ID (8), the machine-ID (T) and the operation-ID (1”); • send an authorization request to the payment media network (6), wherein the request comprises at least: the token-ID (8), the payment token (9) and the operation-ID (1”); • receive a response to the request for authorization to the payment media network (6); wherein the response comprises at least the token-ID (8), the payment token (9) and the transaction-ID (1”); • send the response to the unattended on-site device (1) where the response comprises at least the token-ID (8), the machine-ID (1)' and the operation-ID (1”). 2.- A system for enabling payment in unattended face-to-face environments, according to claim 1, characterized in that the token server (5) is connected to M unattended face-to-face devices (1), and additionally connected to N unattended face-to-face device operators (4). 3.- A system for enabling payment in unattended face-to-face environments, according to claim 1, characterized in that the unattended face-to-face device is a vending machine (1). 4.- A system for enabling payment in unattended face-to-face environments, according to claim 1, characterized in that the tokenization module (2) is configured to request and capture payment credentials from the user (10). 5.- A system for enabling payment in unattended face-to-face environments, according to claim 4, characterized in that the tokenization module (2) comprises a contactless reading module with Host Card Emulation “HCE” application processing means.

6. A system for enabling payment in unattended, in-person environments, according to claim 1, wherein the token server (5) comprises: • a database of unattended on-site device operators (4) authorized to operate on the system; • a database of unattended on-site devices (1) for each of the unattended on-site device operators (4) in the system; • a customer database along with their respective token-IDs, where unattended on-site devices (4) are stored where the token-ID is activated, a token-ID usage and token-ID lifetimes for each user; • a customer profile database (10) in which, along with the token-ID, the temporary aggregate of purchases made on the unattended physical device network (1) is stored per time window in the system.

7. A method for enabling payment in unattended in-person environments, the method being executed in a system comprising: an unattended in-person device (1) identified by a machine-ID (T); a tokenization module (2) in the unattended in-person device (1); a communication module (3) in the unattended in-person device (1); a token server (5) connectable to a payment network (6) and to the tokenization module (2) via the communication module (3); an unattended in-person device operator (4) connected to the token server (5); where the method comprises: a) request (20) from the user (10), through the tokenization module (2), the token- ID (8) that identifies said user (10); b) generate (21) an operation-ID (1”) when the user (10) selects a product / service on the unattended on-site device (1); c) send (22), from the tokenization module (2) to the token server (5), the token-ID (8), the machine-ID (T) and the operation-ID (1”); d) sending (23) a management request, from the token server (5) to the unattended on-site device operator (4), wherein the management request comprises at least: the token-ID (8), the machine-ID (T), and the operation-ID (1”); e) receiving (24) on the token server (5), a response to the management request, wherein the response comprises at least the token-ID (8), the machine-ID (T), and the operation-ID (1”); f) send (25), from the token server (5) to the payment media network (6), an authorization request, wherein the request comprises at least: the token-ID (8), the payment token (9) and the transaction-ID (1”); g) receive (26), on the token server (5), a response to the request for authorization to the payment media network (6); wherein the response comprises at least the token-ID (8), the payment token (9) and the transaction-ID (1”); h) send (27) to the unattended on-site device (1), the response to the authorization request, wherein the response comprises at least the token-ID (8), the machine-ID (T) and the operation-ID (1”).

8. A method for enabling payment in unattended in-person environments, according to claim 7, wherein step a) of the method further comprises: • ask the user for payment methods associated with the user (10); • Send the payment methods to the token server (5) using the module communication (3); • receive, from the token server (5), the token-ID (8) generated by the payment network (6) for the user's payment method; • Send the user the token-l D using a Host Card Emulation “HCE” application to a smartphone with application execution capabilities or to a bank card.

9. A method for enabling payment in unattended face-to-face environments, according to claim 7, wherein the method further comprises storing the token-ID and the payment token associated with the token-ID on the token server.

10. A method for enabling payment in unattended face-to-face environments, according to claim 7, wherein step h) is carried out from the token server (5) or from the unattended face-to-face device operator (4).

11. A method for enabling payment in unattended face-to-face environments, according to claim 7, wherein the transaction-ID (1”) comprises at least data of the product / service selected by the user and the price of said product / service.

12. A method for enabling payment in unattended face-to-face environments, according to claim 7, wherein communications between the token server (5) and the payment media network (6) are carried out by means of a secure mTLS connection with a TR-TSP service from a certified brand tokenization service provider.

13. A method for enabling payment in unattended, in-person environments, according to claim 7, wherein the method further comprises performing the following steps on the token server (5): • activate, deactivate or delete logic of unattended presence devices (1); • manage the customer lifecycle, including: token-IDs (8), active life periods, renewals, and an additional set of data that the HCE application manages for each customer; • manage authorized payment channels; • settle and reconcile payment transactions managed by the operator of unattended in-person devices (4), unattended in-person devices attended (1) and a business that owns the unattended in-person devices (1).

14. A method for enabling payment in unattended, face-to-face environments, according to claim 7, wherein the method further comprises performing the following steps on the token server (5): • receive from an unattended on-site device operator (4), marketing actions to be carried out on specific unattended on-site devices (1) of the unattended on-site device operator's network (4), or in specific time periods of the unattended on-site device operator's network (4); • Generate a payment authorization request with a recalculated amount based on an applied marketing campaign, or generate an authorization if it is a free scenario; • manage the payment directly and once authorized by the payment network (6), increase the accumulated amount corresponding to the token-ID in each of the corresponding periodic periods, if there is no specific marketing campaign to carry out.

15. A method for enabling payment in unattended in-person environments, according to claim 7, wherein the method further comprises, in the token server (5): managing the generation of fixed fees for the customer to access the goods and services provided by the operator of unattended in-person devices (4), a merchant owning at least one unattended in-person device (1), and / or payment point incorporating recurring payments in a managed payment channel.

16. A method for enabling payment in unattended, in-person environments, according to claim 15, wherein the method further comprises: • divide a granted right into several partitions and generate a separate credential for each of the partitions; • send an initial set of credentials to the HCE application; • incrementally generate credentials for each token-ID and incorporate a summary of the electronic signature of the token server (5); • Validate, through the HCE application, each of the received credentials by validating the embedded signature; • Check an index of the first downloaded credential and verify that the first downloaded credential corresponds to the one that should have been downloaded from the server.