Transaction system and method for performing secure wireless transaction and performing a mechanical actuation
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-02-05
- Publication Date
- 2026-08-13
Smart Images

Figure NL2026050036_13082026_PF_FP_ABST
Abstract
Description
[0001] Title
[0002] Transaction system and method for performing secure wireless transaction and performing a mechanical actuation
[0003] Technical Field
[0004] The present disclosure relates to a transaction system, a method, loT device, mobile device and server for performing secure wireless transactions and performing a mechanical actuation upon a successful transaction.
[0005] Background
[0006] Payment terminals facilitate secure monetary transactions between customers and merchants or service providers. Traditional payment systems rely on a combination of hardware and software components that work together to process payments. When a customer initiates a payment using a card or mobile device, the terminal reads the payment details through methods like Near Field Communication (NFC), magnetic stripe readers, or chip-and-PIN technology. This data is then encrypted and sent to the terminal’s processing unit, where it is prepared for further communication with external systems.
[0007] To complete a transaction, payment terminals typically require an internet connection to communicate with a remote payment gateway. The gateway acts as an intermediary, transmitting transaction details to the customer’s and merchant’s banks for validation. This connection ensures that funds are available, authenticates the transaction, and processes approvals in compliance with strict security standards. Once validated, a confirmation is sent back to the terminal, completing the transaction. These processes depend heavily on stable internet connectivity and adherence to security protocols such as PCI DSS and EMVCo standards.
[0008] While these systems offer reliable functionality, they come with significant challenges. Payment terminals are often complex and expensive due to the integration of high-end hardware like screens, encryption modules, and specializedNFC components. Additionally, obtaining certifications to comply with regulatory requirements adds to development costs and time. Maintaining constant internet connectivity also introduces operational limitations, particularly in environments with poor network infrastructure. For small-scale implementations or embedded systems, such as in lockers or simple vending units, the cost and complexity of conventional payment terminals become prohibitive.
[0009] It is therefore a goal of the present invention to provide a transaction system and method that facilitates secure wireless transactions while reducing hardware complexity and eliminating the dependency on constant internet connectivity, thereby overcoming the above-mentioned disadvantages of the prior art at least in part.
[0010] Summary
[0011] It would therefore be advantageous if a payment system would be provided that facilitates secure wireless transaction while reducing the hardware complexity and eliminating the dependency on constant internet connectivity and adherence to security protocols such as PCI DSS and EMVCo standards.
[0012] In an aspect of the present disclosure, there is provided transaction system for performing secure wireless transactions and performing a mechanical actuation upon a successful transaction, the system comprising:
[0013] an Internet of Things (loT) device, arranged for offline operation and configured for integration with an external apparatus to perform a mechanical actuation, the loT device comprising:
[0014] a communication interface configured for Wireless Personal Area Network, WPAN, communication;
[0015] a processing unit configured to transmit transaction-related data over the WPAN communication interface and receive transaction confirmation data;
[0016] a mobile device configured to establish a WPAN communication link with the loT device, establish a wireless communication link with a remote server, receive the transaction-related data over the WPAN communication link, transmit the transaction-related data to the remote server, receive transaction confirmation datafrom the remote server, and transmit the transaction confirmation data to the loT device over the WPAN communication link;
[0017] a remote server (130) configured to receive the transaction-related data from the mobile device (120), execute the transaction, and generate transaction confirmation data for transmission to the mobile device (120);
[0018] wherein the remote server (130) uses a signature component arranged to sign the transaction confirmation data for the loT device (110) with a key corresponding to the loT device (110), and for the loT device (110) to validate the signed transaction confirmation data based on a signature verification mechanism that determines correspondence between the signed transaction confirmation data and the key corresponding to the loT device (110); and
[0019] wherein the loT device (110) is further configured to activate the mechanical actuation in response to successful validation of the transaction confirmation data.
[0020] In another aspect of the present disclosure, there is provided a method (200) for performing secure wireless transactions and performing a mechanical actuation upon a successful transaction, the method comprising the steps of:
[0021] establishing (201) a WPAN communication link between an Internet of Things (loT) device and a mobile device;
[0022] transmitting (202), by the loT device, transaction-related data to the mobile device over the WPAN communication link, wherein the transaction-related data is preferably signed prior to transmission with a signature component associated with the loT device;
[0023] establishing (203), by the mobile device, a wireless communication link with a remote server;
[0024] transmitting (204), by the mobile device, the transaction-related data to the remote server over the wireless communication link;
[0025] preferably, validating (205), by the remote server, the signed transaction-related data using a signature component, wherein the validating is based on a signature verification mechanism to determine authenticity of the transaction-related data;generating (206), by the remote server, transaction confirmation data upon performing the transaction, and wherein the transaction confirmation data is signed by remote server with a key corresponding to the loT device;
[0026] transmitting (207), by the remote server, the signed transaction confirmation data to the mobile device over the wireless communication link;
[0027] transmitting (208), by the mobile device, the signed transaction confirmation data to the loT device over the WPAN communication link;
[0028] activating (209), by the loT device, a mechanical actuation in response to successful validation of the signed transaction confirmation data based on a signature verification mechanism that determines correspondence between the signed transaction confirmation data and the key corresponding to the loT device.
[0029] In another aspect of the present disclosure, there is provided an loT device for a transaction system of an aspect of the present disclosure, wherein the loT device comprises:
[0030] a communication interface configured for WPAN communication with a mobile device;
[0031] a processing unit configured to transmit transaction-related data over the WPAN communication interface to the mobile device and receive transaction confirmation data from the mobile device over the same interface;
[0032] wherein the loT device is arranged for offline operation and configured to activate a mechanical actuation in response to successful validation of the transaction confirmation data;
[0033] wherein the loT device is configured to validate the signed transaction confirmation data based on a signature verification mechanism that determines correspondence between the signed transaction confirmation data and a key corresponding to the loT device (110). In another aspect of the present disclosure, there is provided a mobile device for a transaction system of an aspect of the present disclosure, wherein the mobile device is configured to:
[0034] establish a WPAN communication link with the loT device; receive transaction-related data from the loT device over the WPAN communication link;
[0035] establish a wireless communication link with a remote server;transmit the transaction-related data to the remote server over the wireless communication link;
[0036] receive transaction confirmation data from the remote server over the wireless communication link;
[0037] transmit the transaction confirmation data to the loT device over the WPAN communication link
[0038] wherein the mobile device is configured to transmit the transaction-related data from the loT device to the remote server over the wireless communication link and to forward the signed transaction confirmation data to the loT device over the WPAN communication link.
[0039] In another aspect of the present disclosure, there is provided an a server for a transaction system according to an aspect of the present disclosure, wherein the remote server is configured to:
[0040] receive transaction-related data from the mobile device;
[0041] execute a transaction based on the transaction-related data; generate transaction confirmation data upon successful validation of the transaction-related data;
[0042] sign the transaction confirmation data with a key corresponding to the loT device;
[0043] transmit the signed transaction confirmation data to the mobile device. In another aspect of the present disclosure, there is provided a computer program comprising instructions which, when the program is executed by a computer, cause the computer to carry out the steps of the method of an aspect of the present disclosure.
[0044] In another aspect of the present disclosure, there is provided a computer-readable storage medium comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method of an aspect of the present disclosure.
[0045] In another aspect of the present disclosure, there is provided a data carrier signal carrying the computer program of an aspect of the present disclosure.
[0046] Aspects of the present disclosure described above relate to a transaction system for performing secure wireless transactions and performing a mechanical actuation upon a successful transaction. A transaction system may be understood asa combination of interconnected components configured to execute a sequence of operations involving data exchange, validation, and physical actions. Wireless transactions refer to monetary exchanges carried out without the use of physical connections, typically through the transfer of data over short-range communication technologies such as Wireless Personal Area Network, WPAN communication. A mechanical actuation may be understood as a physical movement performed by a mechanical component, such as unlocking or locking an apparatus, triggered by an external signal or condition. Mechanical actuation in the context of the present disclosure may include, but is not limited to, actions such as engaging or disengaging a latch, triggering a solenoid, rotating or displacing a mechanical element, activating a motor-driven component, or initiating a physical response in an apparatus based on an electronic control signal. The actuation may be carried out by various mechanical systems including levers, springs, actuators, servo motors, pneumatic or hydraulic components, or other mechanical means capable of translating an electronic transaction confirmation into a physical action. The specific nature of the actuation may depend on the type of external apparatus with which the loT device is integrated, where such an apparatus may include access control systems, dispensing mechanisms, automated vending units, electronic locks, vehicle charging stations, or other devices requiring a secure transaction-based activation. The term mechanical actuation as used herein does not imply any limitation to simple predefined movements but extends to any form of mechanical engagement or displacement that is triggered upon successful transaction validation, whether the movement is fixed, variable, single-action, or multi-step in nature.
[0047] The system comprises an Internet of Things (loT) device arranged for offline operation and configured for integration with an external apparatus to perform a mechanical actuation. An loT device may be understood as a physical device equipped with for example sensors, processing capabilities, and communication interfaces, enabling it to interact with other devices or systems. A typical example of such an loT device is a module which has processing and communication capabilities and is arranged to interface with an apparatus to trigger a mechanical actuation such as a physical movement performed by a mechanical component, such as an actuator, motor, or means for unlocking or locking an apparatus or element thereof, triggeredby an external signal or condition like the successful completion of a transaction by the transaction system.
[0048] The loT device may be a separate module configured for integration with an external apparatus, but it may also be fully integrated into a single physical unit, such as a (programmable) microcontroller unit (MCU) with equipped with suitable communication capabilities (NFC / BLE), either as an addon board or part of the MCU. The MCU may be integrated within a door handle to control its locking and unlocking mechanism or within a central control interface of a locker arrangement or such. Hence, the loT device according to the present disclosure may be implemented both as an integrated implementation and as a standalone loT device, which can be sold separately for incorporation into and interfacing with various external apparatuses.
[0049] The interface between the loT device and the external apparatus may be achieved through various technical implementations, depending on the requirements of the mechanical actuation. For example, the loT device may control an electric relay to switch a connected actuator or motor, or it may use a General-Purpose Input / Output (GPIO) pin to send a digital high or low signal to trigger the mechanical operation. Additionally, the interface may be implemented using serial communication protocols such as l2C or SPI to transmit control commands to an embedded controller within the external apparatus. Alternatively, the loT device may output a predefined voltage level or a Pulse Width Modulation (PWM) signal or other modulated signal to control actuation intensity or duration. The selection of a specific interface may depend on the power constraints, latency requirements, and integration complexity of the target apparatus.
[0050] Offline operation of the loT device ensures that the device can function independently without requiring constant connectivity to a network or server or internet connection, which can enhance reliability in environments with limited internet access. This arrangement provides an effect of reducing dependency on continuous network infrastructure, thereby improving the device’s operational flexibility and resilience. The integration capability allows the loT device to be connected to external apparatuses, such as locks or mechanical actuators, enabling seamless communication and operation within larger systems.
[0051] The loT device comprises a communication interface configured for WPAN communication. A communication interface may be understood as a hardwareor software component enabling data exchange between devices. WPAN communication facilitates one- or bi-directional data transfer within a limited range, allowing the loT device to securely exchange information with a mobile device. This arrangement provides an effect of enabling real-time, secure data transmission while minimizing latency and reducing bandwidth requirements, as data is transmitted over a localized communication channel.
[0052] In all aspects and examples of the present disclosure, the communication interface of the loT device may be understood as a hardware or software component enabling data exchange between the loT device and the mobile device over a short-range wireless communication link. The communication interface may be configured for Wireless Personal Area Network (WPAN) communication, which facilitates the secure and efficient exchange of transaction-related data between the loT device and the mobile device without requiring direct internet connectivity. WPAN communication allows devices in close proximity to establish a dedicated communication link, ensuring a localized and controlled data transfer process. The communication interface may support one or more WPAN technologies suitable for short-range wireless communication, including but not limited to Bluetooth, Bluetooth Low Energy (BLE), Zigbee, Z-Wave, Ultra-Wideband (UWB), Nea-Field Communication (NFC) or other similar communication protocols that facilitate secure, low-power, and efficient data transmission between devices within a limited range. The selection of a specific WPAN technology may depend on factors such as power consumption, required data throughput, latency, and the operational environment of the loT device.
[0053] In an example, the WPAN communication link between the loT device and the mobile device may be established either solely through WPAN technologies or in combination with other types of local short-range communication means. For example, the communication link may be established by a combination of WPAN and a visual code-based authentication mechanism such as a QR code. In this implementation, the loT device generates and displays a QR code, which is scanned by the mobile device using its camera. Upon scanning, the mobile device extracts the necessary connection credentials and initiates a pairing process with the loT device over the WPAN, thereby establishing the WPAN link. This combination allows for a flexible and seamless device pairing and authentication process.The QR code used for establishing the WPAN link may be a static but more preferably a dynamic QR code. A dynamic QR code may be generated and updated at fixed or random intervals, ensuring that the QR code content frequently changes. This prevents unauthorized replication, tampering, or cloning, thereby enhancing the security of the transaction system. By dynamically altering the QR code content, potential replay attacks or unauthorized reuse of previously captured QR codes are mitigated, ensuring that only a valid, real-time generated QR code can be used to establish the WPAN link and complete the transaction process.
[0054] In another example, the WPAN communication link may also be initiated or set up by alternative means, such as Near Field Communication (NFC), scanning a visual code such as a QR code, or similar proximity-based triggers for initiating the communication. The loT device may comprise an NFC tag that, when tapped by the mobile device, triggers the setup of the WPAN link. In this implementation, the NFC interaction serves as an initial pairing mechanism, allowing the mobile device to retrieve the necessary connection credentials and establish the WPAN communication with the loT device. The NFC-based initiation method ensures quick and intuitive pairing, reducing the need for manual user input and enhancing the ease of use of the transaction system. The NFC trigger may be implemented in a passive NFC tag that does not require power from the loT device, or as an active NFC module integrated into the loT device. Hence, as used herein and through the present disclosure, a 'tapping action' is not limited to NFC-like tapping only, but to be understood as a user-initiated action that establishes a communication link by bringing the mobile device into close proximity with the loT device. The skilled person will appreciate that throughout the description, the “tapping action” may thus also be interpreted and understood to include, but is not limited to, an NFC tap, the scanning of a visual code such as a QR code, or a similar proximity-based trigger for initiating communication.
[0055] In an example the setup and management of the WPAN link may be facilitated by a software application running on the mobile device. This application may be a pre-installed full application that provides a complete set of functionalities for managing the communication link, processing transactions, and executing additional operations related to the transaction system. Alternatively, the setup of the WPAN link may be performed using an ephemeral application, such as an App Clip or an Instant App, which allows the mobile device to temporarily execute the necessary softwarewithout requiring prior installation. The ephemeral application may enable quick and seamless device interaction without requiring the user to download and install a dedicated app beforehand. In some implementations, the ephemeral application may initiate the installation of a full application on the mobile device, allowing for a transition from a temporary interaction to a persistent and more feature-rich software experience. This combination of an ephemeral application and a full application ensures a balance between ease of use, security, and extended functionality, allowing users to engage with the system without requiring prior setup while providing the option for a full-featured application for repeated or advanced usage scenarios.
[0056] The loT device further comprises a processing unit configured to transmit transaction-related data over the WPAN communication interface and receive transaction confirmation data. A processing unit may be understood as an integrated circuit or module responsible for executing instructions and processing data. Transaction-related data refers to information required for initiating and verifying a transaction, while transaction confirmation data indicates the validation status of the transaction. The processing unit allows the loT device to securely manage transaction data exchanges, ensuring accurate and efficient transaction processing without reliance on external processing resources.
[0057] The system further comprises a mobile device configured to establish a WPAN communication link with the loT device, establish a wireless communication link with a remote server, receive the transaction-related data over the WPAN communication link, transmit the transaction-related data to the remote server, receive transaction confirmation data from the remote server, and transmit the transaction confirmation data to the loT device over the WPAN communication link. A mobile device may be understood as a portable electronic device, such as a smartphone or tablet, capable of wireless communication. The ability to establish communication links allows the mobile device to act as an intermediary between the loT device and the remote server. This arrangement provides an effect of enabling the system to offload certain tasks, processing and validation tasks to the server while maintaining secure and seamless data flow between all components, optimizing processing efficiency and reducing the loT device's computational burden.
[0058] In an example, the remote server may be configured to interact with a payment provider or financial institution to facilitate the processing of monetarytransactions. When the mobile device transmits the transaction-related data to the remote server, the server may forward relevant payment details to a payment provider, which processes the transaction according to standard financial protocols, such as credit card payments, digital wallet transactions, or direct bank transfers. Upon successful completion of the payment, the payment provider generates a payment confirmation, which is received by the remote server and included in the transaction confirmation data sent back to the mobile device. The skilled person will appreciate that the specific implementation details of payment processing, including communication with financial institutions, compliance with regulatory standards, and integration with third-party payment providers, may be carried out using conventional methods and are outside the core scope of the present invention, which focuses on the secure transmission of transaction-related data and the associated mechanical actuation.
[0059] In an example, the transaction system may leverage existing certified hardware and software capabilities of mobile devices to facilitate secure debit card transactions. Certain mobile devices, such as smartphones equipped with NFC payment capabilities, already comply with industry security certifications for handling financial transactions, including hardware security certification for processing encrypted payment data. In such implementations, the mobile device may serve as an intermediary payment terminal, allowing users to complete a transaction by tapping a physical debit card or digital payment method (such as Apple Pay or Google Pay) against the mobile device’s NFC reader. This process enables secure payments by utilizing the mobile device’s existing secure element and cryptographic processing capabilities, ensuring compliance with financial regulations. If the transaction system is certified to process debit card data within the application, the system may allow for seamless integration with major payment networks, including Visa, Maestro, and Mastercard, without requiring additional hardware on the loT device itself.
[0060] The skilled person will appreciate that implementing such a payment processing capability involves compliance with financial security standards, such as PCI DSS (Payment Card Industry Data Security Standard) and EMVCo protocols, and requires certification for both the secure handling of hardware and the secure processing of transaction data. While the present disclosure focuses on the secure transmission of transaction-related data and the execution of mechanical actuationsbased on transaction confirmation, the integration of mobile-based payment processing can be implemented using known certification procedures and industrystandard protocols.
[0061] The system also comprises a remote server configured to receive the transaction-related data from the mobile device and generate transaction confirmation data for transmission to the mobile device. A remote server may be understood as a centralized computing system capable of processing and storing data. Before the loT device activates the mechanical actuation, the loT device may use a signature component to sign the transaction-related data prior to transmission over the WPAN communication link, and may validate the transaction confirmation data based on a signature verification mechanism that ensures correspondence between and authenticity of the transaction confirmation data and the originally signed transaction-related data. The signature component and signature verification mechanism ensures the authenticity and integrity of the transaction-related data through secure algorithms, providing an effect of safeguarding the transaction from unauthorized manipulation or tampering. This arrangement enhances the overall security and reliability of the system by validating transactions independently of the loT device and mobile device.
[0062] Finally, the loT device is further configured to activate the mechanical actuation in response to successful validation of the transaction confirmation data. This arrangement enables the system to seamlessly translate a validated transaction into a physical action, such as unlocking a lock or dispensing an item, providing an effect of improving the utility and versatility of the system in applications where secure transactions are linked to mechanical operations.
[0063] The transaction-related data transmitted by the loT device may in an example be digitally signed to ensure authenticity and integrity of the date. The transaction confirmation data is in any example signed by a signature component of the server with a key corresponding or associated with the loT device. The signing may be performed and the transaction-related data and / or transaction confirmation data is (encoded and) signed using a (cryptographic) signature generation mechanism. A preferred implementation may utilize JSON Web Signature (JWS) as specified in RFC 7519, where the transaction-related data and / or transaction confirmation data may be signed using an asymmetric cryptographic algorithm such as RS256 (RSA Signature with SHA-256) or ES256 (ECDSA with P-256 and SHA-256).Upon reception of the transaction-related data, the remote server may validate authenticity and integrity by verifying the signature using a signature verification mechanism based on a corresponding public key. Correspondingly, upon reception of the transaction confirmation data, the loT device may validate authenticity and integrity by verifying the signature using a signature verification mechanism based on a corresponding key. Hence, the remote server digitally signs the transaction confirmation data before transmission to the mobile device, using a server-side signature component. In either implementation of the remote server performing the step of verifying the transaction-related data or not, the loT device validates the received transaction confirmation data. The validation of that data is done using a signature verification mechanism that determines correspondence between and authenticity of the transaction confirmation data and the originally signed transaction-related data.
[0064] Hence, at a minimum, the loT device validates the transaction confirmation data, ensuring that the signature remains authentic and corresponds the signature or key of the loT device. When the correspondence is established, it is determined that the transaction authentic and successful and the mechanical actuation may be performed. The remote server may also verify the authenticity of the transaction-related data before executing the transaction. This mutual validation mechanism ensures transaction integrity, prevents unauthorized modifications, and protects against fraud.
[0065] In an example, the transaction-related data and / or transaction confirmation data may be both signed and encrypted to additionally provide for confidentiality of the data in addition to integrity. JSON Web Encryption (JWE) as specified in RFC 7516 may be used to encrypt the signed transaction-related data before transmission. The encryption may be performed using a content encryption key (CEK), which is encrypted using RSA-OAEP or another asymmetric encryption scheme with the recipient's public key. The payload containing the signed transaction data may then be encrypted using a symmetric encryption algorithm such as AES-GCM or AES-CBC.
[0066] Upon reception, the recipient decrypts the CEK using its private key, followed by decryption of the ciphertext to retrieve the original signed transaction data. This ensures that transaction-related data and transaction confirmation data remainboth authentic and confidential, preventing unauthorized access or tampering during transmission.
[0067] The above mentioned examples of digital signatures and encryption mechanism are merely provided as examples for the skilled person to understand how the method and system may be implemented, but the skilled person will appreciate that the invention is not limited as such by any these examples and may be implemented in accordance with other, known and established digital signature and encryption mechanisms.
[0068] In an example, the transaction system may be configured to support two or more, i.e. multiple sequential transactions for a single loT device, allowing a user to interact with the loT device multiple times in distinct transaction phases. For example, in the case of a locker system, a first transaction may be executed to initiate a mechanical actuation that locks the locker, while a second transaction is executed at a later time to unlock the locker. The system may be configured to associate the first transaction with an identifier linked to the user or mobile device, enabling the server and loT device to authenticate a returning user before allowing the second transaction to proceed. The authentication mechanism may be based on transaction history, a cryptographic token stored on the mobile device, or a user-specific cryptographic signature generated at the time of the initial transaction. This ensures that only authorized users can reverse or modify a prior mechanical actuation, preventing unauthorized access or tampering.
[0069] In another example, the transaction system may be configured to apply variable transactfion conditions based on predefined rules, transaction history, or realtime factors such as elapsed time. For example, in a locker rental scenario, the first transaction may require an initial payment, while the second transaction may be contingent on additional conditions, such as a refund upon returning to unlock the locker within a specified period or an additional charge if the locker is unlocked after a longer duration. Similarly, in an access control system such as a parking barrier, the first transaction may be executed to grant access at no cost, while the second transaction, required to exit, may include a dynamically calculated fee based on the duration of stay. The transaction confirmation data generated by the remote server may include a variable transaction amount determined based on the time elapsed since the initial transaction or on predefined pricing structures.To support these implementations, the transaction system may maintain a transaction record that associates a given loT device with a prior transaction identifier, allowing the system to determine whether a subsequent transaction is linked to a previous one. The loT device may store a locally signed record of the prior transaction or retrieve transaction details from the remote server. The transaction record may include a timestamp, user or device authentication data, and pricing information to ensure that subsequent transactions are handled in accordance with predefined business rules. By implementing this transaction management framework, the system provides enhanced flexibility for use cases where multiple transactions for the same loT device are required, while maintaining security, authentication, and variable pricing capabilities.
[0070] Furthermore, the transaction system may incorporate authentication mechanisms to ensure that a returning user or mobile device is authorized to execute a second transaction related to a prior one. This may be achieved through cryptographic signatures, transaction-linked authentication tokens, or device-specific secure identifiers. For example, at the time of the first transaction, the remote server may generate a cryptographic token that is securely transmitted to the mobile device, which must present the token to validate its authorization for the subsequent transaction. Alternatively, a digital signature may be generated based on the first transaction data and verified during the second transaction to ensure that the same user or device is involved. This prevents unauthorized access and ensures that a transaction can only be reversed or modified by an authenticated entity.
[0071] A similar aspect of the present disclosure relates to a method for performing secure wireless transactions and performing a mechanical actuation upon a successful transaction. The method correspondingly comprises establishing a WPAN communication link between an Internet of Things (loT) device and a mobile device, transmitting transaction-related data from the loT device to the mobile device, and forwarding this data to a remote server via a wireless communication link. The loT device validates transaction confirmation data using a verification component, which transaction confirmation data is generated after the transaction being executed, which transaction confirmation data is transmitted back to the loT device through the mobile device. Upon successful validation, the loT device activates a mechanical actuation. This sequence of steps provides an effect of ensuring secure, efficient transactionprocessing while maintaining offline functionality for the loT device, thereby reducing reliance on continuous internet connectivity.
[0072] Similar aspects of the present disclosure relate to an loT device, mobile device, server, computer program, computer readable storage medium and a data carrier.
[0073] In an example, the transaction system may comprise transaction-related data and transaction confirmation data as structured data objects, wherein each structured data object comprises a transaction payload and a cryptographic verification component configured to encode the transaction payload using a cryptographic key. A structured data object may be understood as an organized format for encapsulating data in a defined structure that ensures consistency and simplifies processing. A cryptographic verification component may be understood as an algorithm or mechanism that applies cryptographic methods to encode the payload for secure transmission. This feature provides an effect of protecting the integrity of the data during transmission, ensuring it cannot be tampered with or altered without detection. Encoding with a cryptographic key provides an effect of restricting data access to authorized parties, ensuring confidentiality and security.
[0074] Structured data objects, may be understood as compact, digitally-signed representations of claims designed for secure transmission. Such structured data objects may as be implemented according to the concept of a token such as a JSON Web Token (JWT). Each structured data object may comprise three components: a header, a payload, and a cryptographic signature. The header contains metadata about the token, including the type of token and the algorithm used for signing, such as HMAC-SHA256 or RSA-SHA256. The payload encapsulates the transaction-related data, such as identifiers, timestamps, or amounts, in a standardized and lightweight format. The cryptographic verification component corresponds to the signature of the JWT, which is created by encoding the header and payload, concatenating them with a period, and signing the result using a secret key for HMAC or a private key for RSA. This signature allows the recipient to verify both the authenticity and integrity of the data object, ensuring it has not been altered and originates from a trusted source. By leveraging the cryptographic signature, the structured data object provides secure andefficient data transfer, with the effect of enabling tamper-resistant and confidential transactions even in untrusted environments.
[0075] It may be provided that the structured data objects comprise cryptographically signed data objects, each comprising a header containing metadata about the cryptographic signature, a payload containing the transaction-related data, and a signature generated using a cryptographic key, wherein the signature allows verification of the integrity and authenticity of the data object. A header may be understood as a portion of the structured data object that contains metadata regarding the cryptographic signature, enabling the receiving device to process the signature efficiently. A signature may be understood as a cryptographic component generated by applying the cryptographic key to the payload, serving as proof of authenticity. This feature provides an effect of facilitating quick and reliable validation of the data object, ensuring its integrity and source authenticity while minimizing processing overhead.
[0076] The cryptographic key used to generate the signature in the structured data object may be either a symmetric key or an asymmetric key. In the case of a symmetric key, a single secret key is shared exclusively between the loT device and the server, and is used for both generating the signature and verifying it. The mobile device does not use or have access to the symmetric key, ensuring that sensitive cryptographic operations remain confined to the loT device and the server. For an asymmetric key system, such as RSA, the loT device uses a private key to generate the signature by encrypting the hash of the header and payload, while the server, possessing the corresponding public key, verifies the signature. The mobile device, again, does not use or know the private or public keys, acting only as an intermediary for data transmission. This arrangement ensures that critical cryptographic keys remain secured within the trusted components (loT device and server), providing an effect of enhancing the system’s security while maintaining the integrity and authenticity of the structured data objects.
[0077] In an example, a secure key update mechanism may be provided for replacing cryptographic keys on the loT device while preventing interception or unauthorized access by the mobile device. The key update process may be initiated by the server upon detecting a security risk, reaching a predefined key expiration threshold, or in response to a manual key rotation request. In the case of asymmetric encryption, the server may generate a new key pair and encrypt the private key usinga pre-existing shared secret or a device-specific encryption key that is known only to the loT device. The encrypted private key is then transmitted to the loT device via the mobile device, which acts solely as a transport layer without being able to decrypt or access the key. The loT device receives the encrypted key and decrypts it using its pre-stored decryption key or a secure hardware module, thereby updating its cryptographic keys without exposing them to the mobile device. Similarly, for symmetric encryption, the server may generate a new shared secret key and encrypt it before transmission, ensuring that the new key is only accessible to the loT device upon decryption.
[0078] To further enhance security, the key update process may involve mutual authentication between the loT device and the server, preventing unauthorized entities from injecting malicious keys. The loT device may verify the authenticity of the received key update message by checking a digital signature generated by the server before accepting the new key. Additionally, the new key may be stored in a secure enclave or a tamper-resistant memory within the loT device to prevent extraction or rollback attacks. Optionally, the loT device may notify the server upon successful key installation, allowing the server to invalidate the previous key and maintain a secure audit trail of key rotations. By implementing this key update method, the system ensures that cryptographic security can be maintained without requiring physical replacement of the loT device, even in cases where the server's key database has been compromised. This approach provides resilience against security breaches while allowing for flexible and controlled cryptographic key management in deployed loT devices.
[0079] The cryptographic key may be a key suitable for implementing the cryptographic verification component within the framework of the system, and particularly in the context of JWTs, and may include both symmetric and asymmetric key types. For symmetric encryption, the HMAC-SHA family of algorithms, such as HMAC-SHA256 or HMAC-SHA512, can be employed. These algorithms use a shared secret key for signing and verification, providing a balance of security and computational efficiency. Symmetric keys are typically shorter, ranging from 128 to 512 bits, making them suitable for environments with constrained resources while still maintaining strong security properties.For asymmetric encryption, RSA and Elliptic Curve Digital Signature Algorithm (ECDSA) are examples that are well-suited. RSA keys are widely supported and typically range in size from 2048 to 4096 bits, with larger keys offering enhanced security at the cost of higher computational overhead. ECDSA, on the other hand, provides equivalent levels of security with significantly smaller key sizes, such as 256 or 384 bits, making it particularly advantageous for systems with limited bandwidth or processing capabilities. Both RSA and ECDSA align well with JWT implementations, as they support robust digital signatures and are compatible with widely adopted cryptographic standards. These options provide flexibility in selecting a key type that balances security, performance, and resource constraints, ensuring optimal implementation of the invention.
[0080] It may be provided that the transaction payload comprises a unique transaction identifier to identify the transaction, a payment amount in a currency or a product code resolvable into a payment amount by the server using a database, and a transaction description. This unique transaction identifier, used to identify the transaction for financial and logging purposes, may be distinct from the unique identifier generated by the loT device for security purposes (such as a timestamp or a random number for preventing replay attacks). In some embodiments, the unique transaction identifier within the payload may be the same as, or derived from, the unique identifier generated by the loT device. In other embodiments, they may be separate identifiers, wherein the security identifier ensures the integrity of the communication session, and the payload identifier tracks the financial transaction. A unique transaction identifier may be understood as a data element that ensures each transaction is distinguishable, enabling accurate tracking and validation. A payment amount in a currency or a resolvable product code allows the payload to accommodate both direct monetary values and indirect references to products or services, increasing its versatility. A transaction description may be understood as additional context or information about the transaction, such as details about the purchased product or service, which enhances user understanding. This feature provides an effect of enabling the system to handle diverse types of transactions flexibly and with high accuracy.
[0081] It may be provided that the transaction payload includes a unique transaction identifier comprising one or more of a timestamp, a random numbergenerated uniquely for each transaction by the loT device, or a sequential identifier maintained by the remote server, wherein the loT device stores the last successfully processed sequential identifier and rejects any transaction with an identifier that is lower than or equal to the last successfully processed identifier. A timestamp may be understood as a temporal marker indicating when the transaction was initiated, ensuring temporal uniqueness. A random number may be understood as a value generated independently for each transaction to ensure uniqueness. A sequential identifier maintained by the server allows for centralized tracking and validation of transactions, and the loT device’s rejection of reused or outdated identifiers provides an effect of preventing replay attacks, ensuring only valid transactions are processed.
[0082] In an example, the random number used as part of the unique transaction identifier may be generated by the remote server instead of the loT device. This approach ensures that the random number is produced using a high-entropy cryptographic random number generator (RNG) with a high degree of unpredictability, reducing the risk of identifier collisions or predictability that may arise from lower-quality RNG implementations in resource-constrained embedded devices. By delegating random number generation to the server, the system benefits from centralized entropy management, allowing for enhanced security while ensuring that each generated identifier remains unique across transactions. The loT device may receive the generated random number as part of the transaction confirmation process and incorporate it into its local validation checks to maintain transaction integrity and prevent replay attacks.
[0083] In an example, the loT device may be configured to initiate a cryptographic key renewal process when a sequential transaction identifier reaches a predefined maximum value. In such an implementation, the loT device tracks the last successfully processed sequential identifier and rejects any transaction with an identifier that is lower than or equal to the last stored identifier. When the stored identifier reaches its maximum allowable value, the loT device generates a key renewal request that is transmitted to the server via the mobile device. Upon receiving the request, the server initiates a secure key update process, wherein a new cryptographic key pair is generated, encrypted using a pre-existing security mechanism, and securely transmitted to the loT device. The loT device decrypts and installs the new key, resetting its sequential identifier to an initial state and ensuringcontinued transaction validation without risk of identifier exhaustion. This mechanism further improves the security of the system.
[0084] It may thus be provided that the transaction payload includes a unique transaction identifier comprising one or more of a timestamp, a random number generated uniquely for each transaction by the loT device, or a sequential identifier maintained by the remote server, with each identifier securely encoded within the cryptographic signature of the structured data object. The skilled person will appreciate which other implementations may be applicable to function as a precise temporal marker generated at the moment the transaction is initiated, thereby ensuring that each token is temporally unique and tied to a specific instance. A random number may be understood as a value generated through an onboard random number generator, which provides unpredictability and ensures that no two transactions can inadvertently share the same identifier. In cases where the loT device lacks the capability to generate random numbers or timestamps, a sequential identifier may be maintained by the server, where the server tracks the incrementally increasing sequence and the loT device stores the most recently processed identifier. By encoding these identifiers securely within the cryptographic signature, using either a shared secret key (for symmetric encryption) or a private key (for asymmetric encryption), the system ensures the authenticity and integrity of each identifier, preventing unauthorized replication or reuse. This arrangement provides an effect of robust protection against replay attacks and ensures the transaction payload remains verifiable and tamper-resistant throughout the process.
[0085] It may be provided that the transaction payload transmitted from the loT device to the mobile device includes a product code, and the mobile device is configured to display an interactive user interface within the ephemeral application based on the product code, the interface enabling the user to select transaction options including at least one of a quantity or duration of the product or service to be purchased. A product code may be understood as a unique identifier associated with a product or service. An interactive user interface may be understood as a dynamic graphical or textual element that allows the user to input preferences or select options. This feature provides an effect of reducing the hardware complexity of the loT device by eliminating the need for physical user input mechanisms and shifting thisfunctionality to the mobile device, enhancing user convenience and interaction flexibility.
[0086] It may be provided that the WPAN communication link is based on Near Field Communication (NFC) technology, the communication interface of the loT device comprising an NFC antenna and an NFC controller configured for the WPAN communication link to be initiated by bringing the mobile device into proximity with the loT device, such that the NFC antenna of the loT device establishes communication with the mobile device upon tapping. NFC technology may be understood as a wireless communication standard enabling data exchange over short distances. An NFC antenna and controller enable the loT device to establish a reliable connection with the mobile device by detecting its presence within the NFC range. This feature provides an effect of simplifying the connection process, ensuring secure and efficient initiation of communication without requiring complex pairing mechanisms.
[0087] It may be provided that the WPAN communication between the loT device and the mobile device comprises a tapping action, wherein the transaction-related data is transmitted from the loT device to the mobile device, and a further tapping action, subsequent to the successful validation of the transaction-related data by the remote server, wherein transaction confirmation data is transmitted from the mobile device to the loT device. A tapping action may be understood as a user interaction involving bringing the devices into proximity to trigger communication. This feature provides an effect of streamlining user interaction and ensuring precise initiation of data exchanges, enhancing the system’s reliability and ease of use.
[0088] It may be provided that the tapping action comprises a first tapping action, wherein the mobile device establishes a WPAN communication link with the loT device and launches an ephemeral application on the mobile device, and a second tapping action, wherein the loT device transmits the transaction-related data to the mobile device, the data being processed within the ephemeral application. An ephemeral application may be understood as a lightweight, temporary application that operates without requiring prior installation. This feature provides an effect of reducing the need for pre-installed software on the mobile device, simplifying the transaction process while maintaining secure and efficient communication between the loT device and the mobile device.In a preferred embodiment, the loT device is configured for dual-mode operation, particularly for applications where high availability is essential, such as electronic locks for office lockers. In a primary, online mode, the loT device is provided with its own internet connection and communicates directly with the remote server to execute transactions and receive operational commands, such as activating the mechanical actuation. The system further comprises means, for example within the processing unit, to detect an interruption of this internet connection, for instance by the failure of periodic heartbeat signals to the server.
[0089] Upon detection of such an interruption, the loT device automatically switches to a secondary, offline fallback mode. In this mode, the protocol as described in the present disclosure is activated. The loT device activates its WPAN communication interface and awaits a connection from an authorized mobile device, such as the smartphone of a service technician or administrator. The transaction to activate the mechanical actuation is then performed using the mobile device as an intermediary. This system solves the technical problem of ensuring operational continuity of business-critical, normally online-connected systems, even during an internet outage. The technical effect is a significantly increased reliability and operational resilience of the overall system.
[0090] In a further embodiment, the hardware complexity of the loT device is minimized by shifting user interface functionality to the mobile device. When the transaction-related data is transmitted from the loT device to the mobile device, it may include a product code instead of a fixed amount. The remote server, based on this product code, can return a set of transaction options to the mobile device. The ephemeral application on the mobile device then displays an interactive interface, such as a form with selection menus or buttons, allowing the user to select options, for example the desired duration of a service or the quantity of products to be vended. In this manner, the loT device itself does not require buttons, a keypad, or a display for such selections.
[0091] To prevent replay attacks, wherein an old transaction confirmation is presented again, it is essential that each transaction is unique. This is achieved by the transaction-related data, generated by the loT device, containing a unique transaction identifier.In a first embodiment, the processing unit of the loT device generates a random number or a timestamp that is unique for each transaction attempt. This unique element is transmitted to the server and is part of the data that is signed by the server. The loT device will only accept a transaction confirmation that corresponds to the most recent unique value it has issued.
[0092] In an alternative embodiment, for loT devices that lack a reliable clock or a random number generator, RNG, a sequential counter can be used. The remote server maintains a counter for each loT device, tracking successfully completed transactions. With each new transaction confirmation, the server includes the next number in the sequence, for example transaction #1 , #2, #3, and so on. The loT device stores the number of the last successfully executed transaction. It will reject any new transaction confirmation in which the number is lower than or equal to the last stored number.
[0093] The transaction system may further be provided with a mechanism for securely updating the cryptographic keys on the loT device. This process can be initiated by the server, for example when a key is compromised or a predefined lifetime has been reached. The new key is encrypted by the server with a device-specific encryption key known only to the loT device. The encrypted new key is then transmitted to the loT device via the mobile device. The mobile device acts as a 'blind transport channel' and cannot read the new key. The loT device decrypts and installs the new key, and may invalidate the old key. This mechanism can also be extended to securely transmit not only keys, but also configuration parameters or even small, executable instruction payloads ('virtual firmware updates') to the offline loT device, encapsulated within the transaction confirmation data.
[0094] In another aspect of the present disclosure, there is provided a transaction system for performing secure wireless transactions and performing a mechanical actuation upon a successful transaction, the system comprising:
[0095] an Internet of Things, loT, device, arranged for offline operation and configured for integration with an external apparatus to perform a mechanical actuation;
[0096] a mobile device acting as an intermediary between the loT device and a remote server;
[0097] a remote server configured to process transactions;wherein the system is arranged to transfer transaction confirmation data from the remote server to the loT device, characterized in that the transaction confirmation data is encapsulated in a JSON Web Token, JWT, which is cryptographically signed by the remote server using JSON Web Signature, JWS, and wherein the loT device is configured to validate the authenticity and integrity of the received JWT by verifying the JWS signature before activating the mechanical actuation.
[0098] In the appended figures, similar components and / or features may have the same reference label. Further, various components of the same type may be distinguished by following the reference label by a dash and a second label that distinguishes among the similar components. If only the first reference label is used in the specification, the description is applicable to any one of the similar components having the same first reference label irrespective of the second reference label.
[0099] The above and other aspects of the disclosure will be apparent from and elucidated with reference to the examples described hereinafter.
[0100] Brief description of the figures
[0101] The present disclosure will be explained in more detail below by means of examples of a device according to the present disclosure shown in the drawings, in which:
[0102] Fig. 1 shows a transaction system comprising an loT device, a mobile device, and a remote server, illustrating the communication links between these components;
[0103] Fig. 2 shows a flow diagram of a method for performing secure wireless transactions and executing a mechanical actuation upon successful validation of the transaction.
[0104] Detailed description
[0105] It is noted that in the description of the figures, same reference numerals refer to the same or similar components performing a same of essentially similar function.A more detailed description is made with reference to particular examples, some of which are illustrated in the appended drawings, such that the features of the present disclosure may be understood in more detail. It is noted that the drawings only illustrate typical examples and are therefore not to be considered to limit the scope of the subject matter of the claims. The drawings are incorporated for facilitating an understanding of the disclosure and are thus not necessarily drawn to scale. Advantages of the subject matter as claimed will become apparent to those skilled in the art upon reading the description in conjunction with the accompanying drawings.
[0106] The ensuing description above provides preferred exemplary embodiment(s) only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the preferred exemplary embodiment(s) will provide those skilled in the art with an enabling description for implementing a preferred exemplary embodiment of the disclosure, it being understood that various changes may be made in the function and arrangement of elements, including combinations of features from different embodiments, without departing from the scope of the disclosure.
[0107] Unless the context clearly requires otherwise, throughout the description and the claims, the words "comprise," "comprising," and the like are to be construed in an inclusive sense, as opposed to an exclusive or exhaustive sense; that is to say, in the sense of "including, but not limited to." As used herein, the terms "connected," "coupled," or any variant thereof means any connection or coupling, either direct or indirect, between two or more elements; the coupling or connection between the elements can be physical, logical, electromagnetic, or a combination thereof. Additionally, the words "herein," "above," "below," and words of similar import, when used in this application, refer to this application as a whole and not to any particular portions of this application. Where the context permits, words in the Detailed Description using the singular or plural number may also include the plural or singular number respectively. The word "or" in reference to a list of two or more items, covers all the following interpretations of the word: any of the items in the list, all of the items in the list, and any combination of the items in the list.
[0108] These and other changes can be made to the technology considering the following detailed description. While the description describes certain examples ofthe technology, and describes the best mode contemplated, no matter how detailed the description appears, the technology can be practiced in many ways. Details of the system may vary considerably in its specific implementation, while still being encompassed by the technology disclosed herein.
[0109] In Fig. 1, a transaction system 100 is shown. The system comprises an Internet of Things (loT) device 110, which is either attached to or integrated within a locker 140, where it is arranged for performing a mechanical actuation. The mechanical actuation may include unlocking or locking the locker 140, or engaging with another mechanical system to control access or enable a transaction-based physical response. The loT device 110 is configured for offline operation, meaning that it does not require a direct or continuous internet connection to function. The loT device 110 comprises a processing unit 111 and a mobile communication unit 112. The processing unit 111 is responsible for handling transaction-related data, processing validation results, and triggering the mechanical actuation upon receiving transaction confirmation data. The mobile communication unit 112 facilitates WPAN communication with a mobile device 120, allowing the exchange of transaction-related data. The WPAN communication link 115 may be based on one or more short-range wireless communication protocols, such as Bluetooth, Bluetooth Low Energy (BLE), Zigbee, Z-Wave, or other similar technologies. Additionally, the loT device 110 may support alternative means of communication, such as displaying a dynamically generated QR code or incorporating an NFC (Near Field Communication) module for initiating data exchange with the mobile device 120.
[0110] The mobile device 120 serves as an intermediary between the loT device 110 and a remote server 130. The mobile device 120 establishes a WPAN communication link 115 with the loT device 110 to receive transaction-related data. The mobile device 120 further establishes a remote wireless communication link 125 with the remote server 130. This remote wireless communication link 125 may utilize cellular network technologies such as 3G, 4G, 5G, or 6G, or may be implemented using a Wi-Fi network, an internet-based communication channel, or another public or private network infrastructure. The mobile device 120 transmits the transaction-related data received from the loT device 110 to the remote server 130 over the wireless communication link 125.The remote server 130 is configured to receive the transaction-related data, validate the transaction using a cryptographic verification component, and generate transaction confirmation data upon successful validation. The cryptographic verification component may be based on symmetric or asymmetric cryptographic methods, ensuring the integrity and authenticity of the transaction data. Once the transaction is validated, the remote server 130 transmits the transaction confirmation data back to the mobile device 120 over the wireless communication link 125. The mobile device 120 then transmits the received transaction confirmation data to the loT device 110 over the WPAN communication link 115. Upon receiving valid transaction confirmation data, the loT device 110 executes the mechanical actuation, such as unlocking the locker 140. Whether or not the transaction confirmation data is valid is determined by the loT device by validation of the transaction confirmation data signed by the server, based on a signature verification mechanism that determines correspondence between the signed transaction confirmation data and the key corresponding to the loT device.
[0111] The system 100 enables secure transactions while minimizing hardware complexity. The loT device 110 does not require an integrated internet module, reducing power consumption and cost, as all server communication is handled through the mobile device 120. Additionally, by using WPAN communication for data exchange between the loT device 110 and the mobile device 120, the system can function in environments where direct internet access is unavailable or unreliable.
[0112] Fig. 2 illustrates a method 200 for performing secure wireless transactions and executing a mechanical actuation upon successful validation of the transaction. The method comprises multiple steps that involve the communication and validation processes between the loT device 110, the mobile device 120, and the remote server 130.
[0113] In step 201, a WPAN communication link is established between the loT device 110 and the mobile device 120. The communication link may be initiated using standard Bluetooth pairing, automatic discovery mechanisms, QR code-based authentication, or NFC-based interaction. Upon successful establishment of the WPAN link, the loT device 110 is able to transmit transaction-related data to the mobile device 120.In step 202, the loT device 110 transmits transaction-related data to the mobile device 120 over the WPAN communication link 115. The transaction-related data may include a unique transaction identifier, a timestamp, a product code, or other relevant metadata necessary for transaction validation. The data may be encapsulated within a structured data object, ensuring its integrity and authenticity.
[0114] In step 203, the mobile device 120 establishes a wireless communication link 125 with the remote server 130. This connection may be made via a cellular network (e.g., 3G, 4G, 5G, 6G), a Wi-Fi network, or any other internet-based communication medium that allows for remote data transmission.
[0115] In step 204, the mobile device 120 transmits the transaction-related data to the remote server 130 over the wireless communication link 125. The transaction-related data is securely transmitted and may be encrypted or digitally signed to ensure data security during transmission.
[0116] In step 205, the remote server 130 validates the transaction-related data using a cryptographic verification component associated with the loT device 110. The cryptographic verification may involve symmetric or asymmetric encryption, where the loT device 110 may have previously registered a cryptographic key with the server 130. The validation ensures that the transaction request originates from a trusted source and that the transaction data has not been altered or replayed.
[0117] In step 206, the remote server 130 generates transaction confirmation data upon successful validation of the transaction-related data. This confirmation data serves as an approval signal for the loT device 110, indicating that the transaction has been verified and authorized.
[0118] In step 207, the remote server 130 transmits the transaction confirmation data back to the mobile device 120 over the wireless communication link 125. The mobile device 120 receives the confirmation data and prepares it for transmission to the loT device 110.
[0119] In step 208, the mobile device 120 transmits the transaction confirmation data to the loT device 110 over the WPAN communication link 115. The loT device 110 receives the confirmation data and processes it to determine whether the transaction is approved.
[0120] In step 209, upon successful validation of the transaction confirmation data, the loT device 110 activates a mechanical actuation. The mechanical actuationmay involve triggering an electromechanical lock to open or close a compartment, engaging a solenoid to release an access barrier, actuating a motor-driven mechanism, or performing another predefined physical operation linked to the transaction.
[0121] The method may be implemented in accordance with the sequential order indicated above, i.e. 201 , 202-209. It is however expressed that some or all steps may have different order or may even be performed in parallel to other steps.
[0122] The method 200 ensures that transactions are securely validated and processed while maintaining operational flexibility. By leveraging WPAN communication for localized data exchange and utilizing the mobile device 120 as an intermediary for internet-based communication, the system achieves a high level of security without imposing additional hardware or connectivity requirements on the loT device 110. Furthermore, cryptographic validation at the remote server 130 ensures the authenticity of transaction data, preventing unauthorized access or fraudulent transactions. Finally, the mobile 120 is used as an intermediary device to establish a communication link between the loT device 110 and the remote 130, such that the loT device 110 does not require an internet connection but despite that, still allows to perform transactions through remote services. Moreover, the mobile 120 may not only be used for its communication capabilities but also for as display and input device as a Graphical User Interface, GUI, for the user to for example select a product, service, quantity and / or duration thereof from the loT device and as a GUI for effectuating the transaction with the server, e.g. to perform a payment transaction with a remote payment provider and transmit relevant payment details thereto. These can be used to effectuate the transaction according to standard financial protocols, such as credit card payments, digital wallet transactions, or direct bank transfers.
[0123] As noted above, particular terminology used when describing certain features or aspects of the technology should not be taken to imply that the terminology is being redefined herein to be restricted to any specific characteristics, features, or aspects of the technology with which that terminology is associated. In general, the terms used in the following claims should not be construed to limit the technology to the specific examples disclosed in the specification, unless the Detailed Description section explicitly defines such terms.Accordingly, the actual scope of the technology encompasses not only the disclosed examples, but also all equivalent ways of practicing or implementing the technology under the claims.
Claims
CLAIMS1. A transaction system (100) for performing secure wireless transactions and performing a mechanical actuation upon a successful transaction, the system comprising:an Internet of Things (loT) device (110), arranged for offline operation and configured for integration with an external apparatus (140) to perform a mechanical actuation, the loT device (110) comprising:a communication interface (112) configured for Wireless Personal Area Network, WPAN, communication;a processing unit (111) configured to transmit transaction-related data over the WPAN communication interface and receive transaction confirmation data;a mobile device (120) configured to establish a WPAN communication link (115) with the loT device (110), establish a wireless communication link (125) with a remote server (130), receive the transaction-related data over the WPAN communication link (115), transmit the transaction-related data to the remote server (130), receive transaction confirmation data from the remote server (130), and transmit the transaction confirmation data to the loT device (110) over the WPAN communication link (115);a remote server (130) configured to receive the transaction-related data from the mobile device (120), execute the transaction, and generate transaction confirmation data for transmission to the mobile device (120);wherein the remote server (130) uses a signature component arranged to sign the transaction confirmation data for the loT device (110) with a key corresponding to the loT device (110), and for the loT device (110) to validate the signed transaction confirmation data based on a signature verification mechanism that determines correspondence between the signed transaction confirmation data and the key corresponding to the loT device (110); andwherein the loT device (110) is further configured to activate the mechanical actuation in response to successful validation of the transaction confirmation data.
2. The transaction system (100) according to claim 1, wherein the transaction confirmation data and / or the transaction-related data are structured data objects, comprising a transaction payload and a cryptographic verification component, wherein the structured data objects are preferably cryptographically signed JSON Web Tokens, JWT, signed using JSON Web Signature, JWS.
3. The transaction system (100) according to any of the preceding claims, wherein the transaction-related data comprises a unique transaction identifier, which is a random number or a timestamp uniquely generated for each transaction by the processing unit of the loT device, for ensuring uniqueness of the transaction from the source and preventing replay attacks.
4. The transaction system (100) according to any of the preceding claims, wherein the WPAN communication link is initiated by a first proximity based action such as a first tapping action between the mobile device and the loT device, wherein the mobile device launches an ephemeral application without prior installation being required, and wherein a second proximity based action such as a second tapping action is used for transferring data from or to the loT device.
5. The transaction system (100) according to any of the previous claims, wherein the transaction-related data and the transaction confirmation data are structured data objects, each comprising:a transaction payload; anda cryptographic verification component configured to encode the transaction payload using a cryptographic key.
6. The transaction system (100) according to any of the previous claims, wherein the structured data objects comprise cryptographically signed data objects, each comprising one or more of:a header containing metadata, preferably about the cryptographic signature;a payload containing the transaction-related data; anda signature generated using a cryptographic key, wherein the signature allows verification of the integrity and authenticity of the data object.
7. The transaction (100) system according to claim 5 or 6, wherein the transaction payload comprises:a unique transaction identifier to identify the transaction;a payment amount in a currency or a product code resolvable into a payment amount by the server using a database; anda transaction description.
8. The transaction system (100) according to any of the previous claims, wherein the transaction payload includes a unique transaction identifier to identify the transaction, the unique transaction identifier comprising one or more of:a timestamp;a random number generated uniquely for each transaction by the loT device;a sequential identifier maintained by the remote server, wherein the loT device stores the last successfully processed sequential identifier and rejects any transaction with an identifier that is lower than or equal to the last successfully processed identifier.
9. The transaction system (100) according to any of the previous claims 2-8, wherein the transaction payload transmitted from the loT device to the mobile device includes a product code, and the mobile device is configured to display an interactive user interface within the ephemeral application based on the product code, the interface enabling the user to select transaction options preferably comprising at least one of a selection, quantity or duration of the product or service to be purchased.
10. The transaction system (100) according to any of the previous claims, wherein the WPAN communication link is based on Near Field Communication (NFC) technology, the communication interface of the loT device comprising an NFC antenna and an NFC controller configured for the WPAN communication link to be initiated by bringing the mobile device into proximity with the loT device, such that the NFCantenna of the loT device establishes communication with the mobile device upon tapping.
11. The transaction system (100) according to claim 10, wherein the WPAN communication between the loT device and the mobile device comprises:a tapping action, wherein the transaction-related data is transmitted from the loT device to the mobile device; anda further tapping action, subsequent to the successful validation of the transaction-related data by the remote server, wherein transaction confirmation data is transmitted from the mobile device to the loT device.
12. The transaction system (100) according to claim 10 or 11, wherein the tapping action comprises:a first tapping action, wherein the mobile device establishes a near-field communication link with the loT device and launches an ephemeral application on the mobile device; anda second tapping action, wherein the loT device transmits the transaction-related data to the mobile device, the data being processed within the ephemeral application.
13. The transaction system (100) according to any of the previous claims, wherein the system is configured to support multiple sequential transactions for a single loT device (110), the loT device (110) being configured to:associate a first transaction with an identifier linked to the user or mobile device (120);store a locally signed record of the first transaction or retrieve transaction details from the remote server (130); andvalidate a second transaction based on the stored or retrieved transaction details, wherein the second transaction is required to trigger a corresponding mechanical actuation related to the first transaction.
14. The transaction system (100) according to claim 13, wherein the transaction confirmation data generated by the remote server (130) for the secondtransaction includes a configurable or variable transaction amount determined based on one or more predefined conditions, the predefined conditions comprising at least one of:the elapsed time since the first transaction;predefined pricing structures linked to the first transaction; or conditions requiring additional payment or validation before executing the corresponding mechanical actuation.
15. A method (200) for performing secure wireless transactions and performing a mechanical actuation upon a successful transaction, the method comprising the steps of:establishing (201) a WPAN communication link between an Internet of Things (loT) device and a mobile device;transmitting (202), by the loT device, transaction-related data to the mobile device over the WPAN communication link, wherein the transaction-related data is preferably signed prior to transmission with a signature component associated with the loT device;establishing (203), by the mobile device, a wireless communication link with a remote server;transmitting (204), by the mobile device, the transaction-related data to the remote server over the wireless communication link;preferably, validating (205), by the remote server, the signed transaction-related data using a signature component, wherein the validating is based on a signature verification mechanism to determine authenticity of the transaction-related data;generating (206), by the remote server, transaction confirmation data upon performing the transaction, and wherein the transaction confirmation data is signed by the server with a key corresponding to the loT device;transmitting (207), by the remote server, the signed transaction confirmation data to the mobile device over the wireless communication link;transmitting (208), by the mobile device, the signed transaction confirmation data to the loT device over the WPAN communication link;activating (209), by the loT device, a mechanical actuation in response to successful validation of the signed transaction confirmation data based on a signature verification mechanism that determines correspondence between the signed transaction confirmation data and the key corresponding to the loT device.
16. The method (200) according to claim 15, wherein the transaction-related data and the transaction confirmation data are structured data objects, each comprising:*a transaction payload; anda cryptographic verification component configured to encode the transaction payload using a cryptographic key.
17. The method (200) according to claim 16, wherein the structured data objects are cryptographically signed data objects, each comprising:a header containing metadata about the cryptographic signature; a payload containing the transaction-related data; anda signature generated using a cryptographic key, wherein the signature allows verification of the integrity and authenticity of the data object.
18. The method (200) according to claim 16 or 17, wherein the transaction payload comprises:a unique transaction identifier to identify the transaction;a payment amount in a currency or a product code resolvable into a payment amount by the server using a database; anda transaction description.
19. The method (200) according to any of claims 16 to 18, wherein the transaction payload includes a unique transaction identifier to identify the transaction, the unique transaction identifier comprising one or more of:a timestamp;a random number generated uniquely for each transaction by the loT device;a sequential identifier maintained by the remote server, wherein the loT device stores the last successfully processed sequential identifier and rejects any transaction with an identifier that is lower than or equal to the last successfully processed identifier.
20. The method (200) according to any of claims 16 to 18, wherein the transaction payload transmitted from the loT device to the mobile device includes a product code, and the method further comprises:displaying, by the mobile device, an interactive user interface within the ephemeral application based on the product code; andenabling, by the mobile device, the user to select transaction options including at least one of a quantity or duration of the product or service to be purchased.
21. The method (200) according to claim 15, wherein the WPAN communication link is based on Near Field Communication (NFC) technology, the communication interface of the loT device comprising an NFC antenna and an NFC controller, and wherein the method comprises initiating the WPAN communication link by bringing the mobile device into proximity with the loT device, such that the NFC antenna of the loT device establishes communication with the mobile device upon tapping.
22. The method (200) according to claim 21, wherein the two-way WPAN communication between the loT device and the mobile device comprises:a tapping action, wherein the transaction-related data is transmitted from the loT device to the mobile device; anda further tapping action, subsequent to the successful validation of the transaction-related data by the remote server, wherein transaction confirmation data is transmitted from the mobile device to the loT device.
23. The method (200) according to claim 21 or 22, wherein the tapping action comprises:a first tapping action, wherein the mobile device establishes a WPAN communication link with the loT device and launches an ephemeral application on the mobile device; anda second tapping action, wherein the loT device transmits the transaction-related data to the mobile device, the data being processed within the ephemeral application.
24. The method (200) according to claim 15, wherein the method is configured to support multiple sequential transactions for a single loT device (110), the method further comprising:associating a first transaction with an identifier linked to the user or mobile device (120);storing, by the loT device (110), a locally signed record of the first transaction or retrieving transaction details from the remote server (130); and validating a second transaction based on the stored or retrieved transaction details, wherein the second transaction is required to trigger a corresponding mechanical actuation related to the first transaction.
25. The method (200) according to claim 24, wherein the transaction confirmation data generated by the remote server (130) for the second transaction includes a configurable or variable transaction amount determined based on one or more predefined conditions, the predefined conditions comprising at least one of:the elapsed time since the first transaction;predefined pricing structures linked to the first transaction; or conditions requiring additional payment or validation before executing the corresponding mechanical actuation.
26. loT device (110) for a transaction system according to claim 1, wherein the loT device comprises:a communication interface configured for WPAN communication with a mobile device;a processing unit configured to transmit transaction-related data over the WPAN communication interface to the mobile device and receive signed transaction confirmation data from the mobile device over the same interface;wherein the loT device is arranged for offline operation and configured to activate a mechanical actuation in response to successful validation of the signed transaction confirmation data; andwherein the loT device is configured to validate the signed transaction confirmation data based on a signature verification mechanism that determines correspondence between the signed transaction confirmation data and a key corresponding to the loT device (110).
27. A mobile device (120) for a transaction system according to claim 1, wherein the mobile device is configured to:establish a WPAN communication link with the loT device; receive transaction-related data from the loT device over the WPAN communication link;establish a wireless communication link with a remote server; transmit the transaction-related data to the remote server over the wireless communication link;receive signed transaction confirmation data from the remote server over the wireless communication link;transmit the signed transaction confirmation data to the loT device over the WPAN communication link; andwherein the mobile device is configured to transmit the transaction-related data from the loT device to the remote server over the wireless communication link and to forward the signed transaction confirmation data to the loT device over the WPAN communication link.
28. A server (130) for a transaction system according to claim 1 , wherein the remote server is configured to:receive transaction-related data from the mobile device;execute a transaction based on the transaction-related data;generate transaction confirmation data upon successful validation of the transaction-related data;sign the transaction confirmation data with a key corresponding to the loT device;- transmit the signed transaction confirmation data to the mobile device.
29. A computer program comprising instructions which, when the program is executed by a computer, cause the computer to carry out the steps of the method of claim 15.
30. A computer-readable storage medium comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method of claim 15.
31. A data carrier signal carrying the computer program of claim 30.