1. Device enrollment
The organization registers the employee and the phone key protected by iOS or Android.
MesaiGo does not consider “the phone saw the gateway” sufficient. Every attempt checks the phone, gateway, entry point, time, required security level, and organization rules together.
Information from the phone, gateway, and server is not combined merely because it appeared at the same time. Every piece is linked to one transaction, so data from another attempt cannot be reused.
The organization registers the employee and the phone key protected by iOS or Android.
The app verifies the relevant server, entry point, and gateway.
The gateway creates a request that works only once and expires shortly after it is created.
When an organization rule requires it, the user approves the specific transaction on the phone.
Standard BLE communication or a secure UWB distance measurement is completed between the phone and gateway.
The gateway signs only the live interaction it observed and submits it to the server.
The server checks identity, whether the request expired or was already used, device assignment, and organization rules together in one operation.
The signed final result is written to the transaction history together with the security level used.
Compare Standard and High Assurance by hardware, user approval, and the security each provides.