An ETC transaction monitoring and risk prevention and control method

By using ETC transaction monitoring and risk control methods, and through multi-dimensional data collection and fusion analysis, a dynamic risk profile and a hierarchical early warning mechanism are constructed. Combined with blockchain evidence storage, the problems of accurate risk identification and difficulty in tracing disputes in ETC transactions are solved, achieving efficient risk control and data security.

CN121281265BActive Publication Date: 2026-04-24BEIJING ZHONGKEHUIJU SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING ZHONGKEHUIJU SCI & TECH CO LTD
Filing Date
2025-10-11
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

The existing ETC transaction monitoring system lacks the ability to integrate and analyze multi-source data, resulting in low accuracy in risk identification, delayed response, difficulty in tracing disputes, and problems such as transaction information tampering, duplicate charges, proliferation of fake cloned devices, and easy tampering of transaction data.

Method used

By acquiring multi-dimensional data in real time through a three-level data collection architecture of vehicle-mounted terminals, roadside terminals, and cloud terminals, multi-source data fusion analysis is performed to build dynamic user risk profiles, establish a hierarchical early warning mechanism, and utilize blockchain for evidence storage and traceability to form a closed loop of prevention, evidence storage, and traceability.

Benefits of technology

It enables accurate identification of transaction risks, reduces losses for operators, improves user experience, simplifies dispute tracing processes, ensures data immutability, and provides an authoritative chain of evidence.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The application discloses to the technical field of intelligent transportation, specifically an ETC transaction monitoring and risk prevention and control method, comprising the following specific steps: S1, through a three-level acquisition architecture of a vehicle-mounted terminal, a roadside terminal and a cloud terminal, multi-dimensional original data of an ETC transaction whole process is acquired in real time, S2, the multi-dimensional original data is standardized and deeply checked, S3, a dynamic and multi-dimensional user risk assessment system is established, features are extracted from three dimensions of historical behavior, real-time performance and associated risks, S4, based on user risk levels and abnormal types, a one-level, two-level and three-level grading early warning mechanism is established, and S5, transaction whole process data is packaged into encrypted blocks and uploaded to a consortium chain jointly maintained by a traffic department, an operator and an auditing agency. Through the three-level architecture of the vehicle-mounted terminal, the roadside terminal and the cloud terminal, the application covers the equipment, vehicles, users and historical data of the ETC transaction whole process, and avoids the monitoring blind spot caused by the lack of single-dimensional data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent transportation technology, specifically to a method for monitoring and controlling risks associated with ETC transactions. Background Technology

[0002] With the rapid development of intelligent transportation systems, Electronic Toll Collection (ETC) systems have been widely applied in various toll collection scenarios due to their efficiency and convenience. Currently, my country has over 200 million ETC users, with over 90% usage on highways and an increasing coverage rate in urban parking lots. However, while the scale of ETC transactions continues to expand, transaction risks are also becoming more prominent: existing ETC monitoring systems rely heavily on single-dimensional data (such as OBU device number and transaction amount) for judgment, lacking dynamic perception of the entire transaction process and the ability to integrate and analyze multi-source data. This leads to frequent problems such as low accuracy in risk identification, delayed response, and difficulty in tracing disputes, seriously affecting the operator's revenue and user experience; specifically as follows:

[0003] I. Risk of transaction information tampering, failure of single data verification

[0004] The existing system only calculates tolls based on vehicle type and license plate number data sent by the OBU device, without comparing it with the actual characteristics of the vehicle. For example, a truck driver illegally modifies the vehicle type information stored in the on-board OBU device, changing "heavy truck" to "small car". When passing through the ETC toll station on the highway, the RSU (Roadside Unit) only reads the modified information sent by the OBU and deducts the toll according to the small car standard. This causes the operator a loss of nearly 200 yuan in tolls per passage. Moreover, such tampering can only be detected by manual verification afterward, which is extremely time-consuming.

[0005] 2. Transaction delays lead to duplicate charges due to a lack of real-time confirmation mechanisms.

[0006] Due to issues such as network signal fluctuations in toll station areas and communication interruptions between the OBU and RSU, transaction confirmation information is prone to transmission delays. For example, when a private car passes through an ETC toll station on an urban expressway, the OBU has completed the toll deduction operation, but due to network lag, the RSU does not receive the transaction confirmation signal. The system mistakenly determines that "the transaction was unsuccessful" and triggers a second deduction process, resulting in the user being charged twice for the same passage record (amounting to 50 yuan). Subsequently, the user needs to submit proof and the operator needs to manually verify before a refund can be issued. The process takes more than 3 working days, leading to numerous user complaints.

[0007] III. Proliferation of fake cloning devices and insufficient identity verification capabilities.

[0008] Criminals use technical means to copy the OBU device information (including device serial number, encryption key, and license plate association data) of legitimate users, creating "cloned OBUs" and installing them in vehicles without legitimate ETC (Electronic Toll Collection) qualifications. For example, a criminal cloned the OBU device of a ride-hailing vehicle and installed it in his own unlicensed used car. Within one month, the car passed through 12 highway ETC toll stations. The device information read by the system was consistent with that of a legitimate ride-hailing vehicle, and all tolls were deducted according to the normal process. This resulted in legitimate ride-hailing users being wrongly charged more than 800 yuan in tolls. Moreover, the operators could not identify the cloned devices through the existing monitoring system and could only manually retrieve toll station videos one by one after user complaints, resulting in extremely low traceability efficiency.

[0009] IV. Risk events are difficult to trace, and transaction data is easily tampered with.

[0010] Currently, most ETC transaction data is stored in centralized databases, which poses a risk of tampering or loss. For example, a toll station employee, in an attempt to cover up their operational error (mistakenly switching the "ETC lane" to a "manual lane," resulting in multiple abnormal transactions), privately modified the transaction records in the database and deleted abnormal data entries. As a result, when users complained, the operator was unable to retrieve the original transaction vouchers, leading to a stalemate in dispute resolution.

[0011] Based on the above, an ETC transaction monitoring and risk control method is invented. Summary of the Invention

[0012] To address the aforementioned technical problems, according to one aspect of the present invention, the present invention provides the following technical solution:

[0013] A method for monitoring and controlling risks in ETC transactions, comprising the following specific steps:

[0014] S1, Real-time Collection of Multi-Dimensional Data: Through a three-level collection architecture of vehicle-mounted, roadside, and cloud terminals, multi-dimensional raw data of the entire ETC transaction process is acquired in real time. This includes basic vehicle information, transaction operation records, and real-time location data of the vehicle-mounted OBU device, as well as vehicle appearance images, passage time sequence, and weight detection data of the roadside RSU device. At the same time, it links with the cloud to retrieve user historical transactions and OBU registration information, and based on OBU physical status data, it finally forms a full-dimensional raw dataset of devices, vehicles, users, and history, providing complete data support for subsequent analysis, profiling, and early warning.

[0015] S2, Multi-source Data Fusion Analysis: Standardizes and deeply verifies multi-dimensional raw data; first, data standardization is achieved through data cleaning, feature extraction, and timestamp alignment; then, cross-validation is carried out from multiple dimensions; finally, a fusion analysis report containing anomaly types, data evidence, and comprehensive scores is output to accurately identify risks in transactions and provide quantitative basis for user risk profiling and graded early warning.

[0016] S3, Dynamic Construction and Differentiated Prevention and Control of User Risk Profiles: Construct a dynamic, multi-dimensional user risk assessment system, extract features from three dimensions: historical behavior, real-time performance, and associated risks, and classify users into three risk levels (low, medium, and high) through a weighted algorithm, and formulate targeted differentiated prevention and control strategies. Simplify verification for low-risk users to improve passage efficiency, strengthen verification and remind users of medium-risk users, and monitor and verify high-risk users in all dimensions. This achieves adaptive management where the higher the risk, the more precise the prevention and control, and the lower the risk, the more convenient the process, providing accurate decision-making direction for graded early warning and disposal.

[0017] S4, Tiered Intelligent Early Warning and Response: Based on the user's risk level and anomaly type, a tiered early warning mechanism of Level 1, Level 2, and Level 3 is established to quickly block high-risk behaviors and reduce losses through real-time response and tiered response, avoid excessive intervention that affects user experience, and achieve a balance between risk control and traffic efficiency.

[0018] S5, Blockchain Evidence Preservation and Traceability: Packages the entire transaction process data into encrypted blocks and uploads them to a consortium blockchain jointly maintained by transportation departments, operators, and auditing institutions. Through hash encryption and multi-node backup, the data is ensured to be tamper-proof. It also supports quick retrieval based on OBU number, license plate, and transaction time. In the event of transaction disputes or risk events, it can retrieve the original data with one click and verify its legality, quickly generate traceability reports, and provide an immutable chain of evidence for user refunds, case investigations, and liability determination, forming a complete closed loop of prevention, evidence preservation, and traceability.

[0019] As a preferred embodiment of the ETC transaction monitoring and risk control method described in this invention, the specific steps of S1 are as follows:

[0020] S11, Vehicle-mounted data collection: First, basic vehicle information is collected to generate raw information data packets; then, transaction operation data is collected to form transaction logs; then, vehicle location data is collected in real time; at the same time, OBU physical status data is collected; finally, the collected data is packaged into vehicle-mounted data packets and uploaded to the cloud data center in real time via 4G / 5G network.

[0021] S12, Roadside Data Collection: When a vehicle enters the ETC lane, the RSU device is triggered to collect vehicle appearance data, passage time sequence data, and weight data; at the same time, the appearance data, time sequence data, and weight data are packaged into a roadside data package and uploaded to the cloud data center simultaneously.

[0022] S13, Cloud Data Acquisition: After receiving vehicle-mounted data packets and roadside data packets in the cloud data center, the system retrieves user historical transaction data and OBU device registration data. At the same time, the retrieved data is integrated into cloud data packets and associated with vehicle-mounted data packets and roadside data packets to form a multi-dimensional raw dataset.

[0023] As a preferred embodiment of the ETC transaction monitoring and risk control method described in this invention, the specific steps of step S2 are as follows:

[0024] S21, Data Preprocessing: First, the cloud data center cleans the multi-dimensional raw dataset, removing invalid data and filling in missing data; then, feature extraction is performed on the image data, using CNN algorithms to identify license plate characters, vehicle body color RGB values, and vehicle outline features, and converting them into quantifiable data; then, time-series data is timestamped to ensure that the vehicle GPS time, roadside passage time, and cloud retrieval time are all consistent with UTC time.

[0025] S22, Multi-dimensional Verification and Analysis: First, identity consistency verification is performed, comparing the vehicle type / VIN sent by the OBU with the vehicle characteristics / appearance extracted by the RSU. If the OBU displays a small car, but the RSU identifies it as a truck, the identity is deemed abnormal. Next, weight verification is performed. If the OBU is bound to a light truck but the weighing data is greater than the weight of a light truck (>4.5 tons), the identity is deemed abnormal. Then, OBU physical status verification is performed. If the physical status marker is forcibly removed / the shell is damaged, and the currently bound vehicle is inconsistent with the registered vehicle, the device is deemed to have been tampered with abnormally. Finally, spatiotemporal rationality analysis is performed. Based on GPS positioning data and roadside passage time, the vehicle passage speed is calculated and compared with the OBU's historical passage path. At the same time, transaction continuity verification is performed, comparing the OBU transaction log with the cloud record, and checking the number of times the same passage record is charged.

[0026] S23, Analysis Results Output: First, the verification results are comprehensively scored based on the deep learning model; then, a fusion analysis report is generated and pushed to the user risk profile dynamic construction and differentiated prevention and control.

[0027] As a preferred embodiment of the ETC transaction monitoring and risk control method described in this invention, the specific steps of S3 are as follows:

[0028] S31, User Risk Profile Construction: First, extract basic dimension data of the profile, then use a weighted algorithm to calculate the user risk level to divide users into three risk levels: low, medium and high; then generate a dynamic risk profile and push it to the hierarchical intelligent early warning and handling system.

[0029] S32, Differentiated prevention and control strategy formulation: For low-risk users, simplify the verification process first, and then optimize the passage efficiency; for medium-risk users, strengthen real-time verification first, and then remind users; for high-risk users, conduct full-dimensional monitoring first, and then conduct related verification.

[0030] As a preferred embodiment of the ETC transaction monitoring and risk control method described in this invention, the step of extracting the basic dimension data of the profile in S31 is as follows:

[0031] S311, Historical Behavior Dimension: Statistics on the number of abnormal transactions in the past 12 months, stability of commonly used routes, and historical status of OBU devices;

[0032] S312, Real-time Behavior Dimension: Import the fusion analysis report and extract the comprehensive score and current anomaly type;

[0033] S313, Associated Risk Dimension: Retrieve data from the vehicle management office to check if the bound vehicle has any records of license plate fraud / overloading violations; and query the OBU activation IP address. If it is consistent with the activation IP of other high-risk users, mark it as associated risk.

[0034] As a preferred embodiment of the ETC transaction monitoring and risk control method described in this invention, the specific steps of S4 are as follows:

[0035] S41, Warning Level Matching: First, receive the dynamic risk profile and integrated analysis report, then match the warning level according to the following rules:

[0036] Level 1 Warning: High-risk users + abnormal device tampering / cloning device characteristics;

[0037] Level 2 Warning: Medium-risk users + abnormal time and space / abnormal transaction synchronization;

[0038] Level 3 alert: Low-risk users + minor data deviations;

[0039] S42, Tiered Execution: Level 1 alert handling includes real-time interception, device control, personnel notification, and user notification; Level 2 alert handling includes transaction control, operator notification, and user reminder; Level 3 alert handling includes data tagging, background review, and result feedback.

[0040] As a preferred embodiment of the ETC transaction monitoring and risk control method described in this invention, the specific steps of S5 are as follows:

[0041] S51, Blockchain Data Packaging: After each transaction is completed, the cloud data center first collects the data scope, including multi-dimensional raw data, integrated analysis reports, risk profiles, and early warning and handling records; then it performs a hash operation on the collected data to generate a unique hash value and adds a timestamp; then it packages the encrypted data, hash value, and timestamp into a transaction block, with the OBU hardware serial number / license plate number marked in the block header;

[0042] S52, Consortium Blockchain Upload and Storage: First, the transaction block is uploaded to the ETC industry consortium blockchain; then, the consortium blockchain nodes synchronously verify the legality of the block, and write it into the blockchain ledger after verification; then, a multi-node backup mechanism is adopted to synchronize each block to at least 5 consortium blockchain nodes to avoid single-point data loss.

[0043] S53, Risk Event Tracing: When a transaction dispute or risk event occurs, the tracing initiator first submits a tracing application; then the consortium blockchain system retrieves the corresponding block based on the application information and extracts the original data; then the tracing party verifies the legality of the data by comparing the block hash value with the original data hash value to confirm that the data has not been tampered with; finally, a tracing report is generated, automatically organizing the data comparison results and abnormal node analysis, and supporting export to PDF format.

[0044] Compared with existing technologies:

[0045] I. Real-time collection of multi-dimensional data

[0046] Comprehensive data coverage: Through a three-tier architecture of vehicle-side terminal - roadside terminal - cloud, it covers the entire ETC transaction process, including equipment, vehicles, users, and historical data, avoiding monitoring blind spots caused by missing data from a single dimension;

[0047] Data support is fundamental: a complete and real-time data foundation is formed for equipment, vehicles, users and history across all dimensions, providing a complete data foundation for subsequent integrated analysis, risk profiling and early warning and response, and ensuring the effective operation of downstream processes.

[0048] II. Multi-source data fusion analysis

[0049] Data processing standardization: Through data cleaning, feature extraction, and timestamp alignment, multi-format raw data is transformed into standardized data, solving the compatibility problem of data from different sources;

[0050] Accuracy of anomaly detection: Conduct cross-verification of identity, time and space, transaction, physical and weight to avoid misjudgment or omission caused by a single verification dimension, and accurately capture risks such as tampering, cloning and delay.

[0051] Quantifiable decision-making basis: The output includes analysis reports containing anomaly types, data evidence, and comprehensive scores, providing quantifiable and traceable judgment basis for risk profiling and triggering early warning and response, rather than subjective decision-making.

[0052] III. Dynamic Construction and Differentiated Prevention of User Risk Profiles

[0053] Risk assessment is dynamic: Combining historical behavior, real-time performance, and related risks, the user's risk level is updated with each transaction to avoid the problem that static profiles cannot adapt to changes in user behavior.

[0054] Precision of prevention and control strategies: Differentiated strategies are developed for low, medium and high-risk users to avoid the waste of resources or insufficient prevention and control caused by "one-size-fits-all" prevention and control, and to achieve precise management of "risk matching".

[0055] Balancing efficiency and risk control: Simplify the verification process for low-risk users to improve passage efficiency, strengthen monitoring for high-risk users to ensure security, and take into account both user experience and risk control objectives.

[0056] IV. Tiered Intelligent Early Warning and Response

[0057] Timely risk response: Real-time interception and freezing of high-risk behaviors (such as cloned devices) avoids the lag of manual intervention and minimizes losses for operators;

[0058] Targeted handling measures: Match handling methods to risk levels (high-risk interception, medium-risk review, low-risk background verification) to avoid excessive handling affecting normal user access, or insufficient handling leading to risk spread;

[0059] Closed-loop execution process: From early warning triggering to handling and execution (such as notifying personnel and reminding users) and subsequent review, a complete execution chain is formed to avoid the problem of "idle running" without follow-up after early warning.

[0060] V. Blockchain Evidence Storage and Traceability Module

[0061] Data security and reliability: Through hash encryption and multi-node backup, we ensure that the data in the entire transaction process is immutable and not lost, solving the trust problem of centralized storage being easily tampered with;

[0062] Efficiency and convenience of traceability: It supports quick retrieval based on OBU number, license plate and transaction time, without the need for manual data retrieval at each step, which greatly simplifies the traceability process for disputes or risk events;

[0063] Authority in determining liability: It provides an unalterable chain of original data evidence, providing authoritative basis for user refunds, case investigations, and liability division, avoiding deadlocks in dispute resolution due to data disputes, and forming a closed loop of "prevention-evidence preservation-traceability". Detailed Implementation

[0064] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below.

[0065] This invention provides a method for monitoring and controlling risks in ETC transactions, comprising the following specific steps:

[0066] S1, Real-time Collection of Multi-Dimensional Data: Through a three-level collection architecture of vehicle-mounted, roadside, and cloud terminals, multi-dimensional raw data of the entire ETC transaction process is acquired in real time. This includes basic vehicle information, transaction operation records, and real-time location data of the vehicle-mounted OBU device, as well as vehicle appearance images, passage time sequence, and weight detection data of the roadside RSU device. At the same time, it links with the cloud to retrieve user historical transactions and OBU registration information, and based on OBU physical status data, it finally forms a full-dimensional raw dataset of devices, vehicles, users, and history, providing complete data support for subsequent analysis, profiling, and early warning.

[0067] S2, Multi-source Data Fusion Analysis: Standardizes and deeply verifies multi-dimensional raw data; first, data standardization is achieved through data cleaning, feature extraction, and timestamp alignment; then, cross-validation is carried out from multiple dimensions; finally, a fusion analysis report containing anomaly types, data evidence, and comprehensive scores is output to accurately identify risks in transactions and provide quantitative basis for user risk profiling and graded early warning.

[0068] S3, Dynamic Construction and Differentiated Prevention and Control of User Risk Profiles: Construct a dynamic, multi-dimensional user risk assessment system, extract features from three dimensions: historical behavior, real-time performance, and associated risks, and classify users into three risk levels (low, medium, and high) through a weighted algorithm, and formulate targeted differentiated prevention and control strategies. Simplify verification for low-risk users to improve passage efficiency, strengthen verification and remind users of medium-risk users, and monitor and verify high-risk users in all dimensions. This achieves adaptive management where the higher the risk, the more precise the prevention and control, and the lower the risk, the more convenient the process, providing accurate decision-making direction for graded early warning and disposal.

[0069] S4, Tiered Intelligent Early Warning and Response: Based on the user's risk level and anomaly type, a tiered early warning mechanism of Level 1, Level 2, and Level 3 is established to quickly block high-risk behaviors and reduce losses through real-time response and tiered response, avoid excessive intervention that affects user experience, and achieve a balance between risk control and traffic efficiency.

[0070] S5, Blockchain Evidence Preservation and Traceability: Packages the entire transaction process data into encrypted blocks and uploads them to a consortium blockchain jointly maintained by transportation departments, operators, and auditing institutions. Through hash encryption and multi-node backup, the data is ensured to be tamper-proof. It also supports quick retrieval based on OBU number, license plate, and transaction time. In the event of transaction disputes or risk events, it can retrieve the original data with one click and verify its legality, quickly generate traceability reports, and provide an immutable chain of evidence for user refunds, case investigations, and liability determination, forming a complete closed loop of prevention, evidence preservation, and traceability.

[0071] The specific steps of S1 are as follows:

[0072] S11, Vehicle-mounted data collection: First, basic vehicle information (such as vehicle type, chassis number, engine number, and OBU device hardware serial number) is collected to generate raw information data packets; then, transaction operation data (such as recording deduction time (accurate to milliseconds), deduction amount, and transaction encryption signature (to prevent data tampering)) is collected to form a transaction log; subsequently, vehicle location data is collected in real time, with location information updated every 5 seconds; simultaneously, OBU physical status data (including hardware tampering data, such as capturing device disassembly actions through an accelerometer, if acceleration...) is collected... A speed greater than 5 m / s² is considered forced disassembly; the continuity of contact points is detected by the shell integrity sensor, and if it is disconnected, it is considered shell damage; operational status data (such as power supply voltage collected by a voltage sensor, if it drops by more than 20% and lasts for more than 10 seconds, it is marked as power supply abnormality); environmental adaptation data (such as OBU operating temperature collected, if it is greater than 70℃ / less than -20℃, and the deviation from the vehicle ambient temperature is greater than 15℃, it is marked as environmental abnormality) are collected; finally, the collected data is packaged into a vehicle-mounted data packet and uploaded to the cloud data center in real time via 4G / 5G network.

[0073] S12, Roadside Data Collection: When a vehicle enters the ETC lane (5-10 meters from the RSU device), the RSU device is triggered to collect vehicle appearance data (using a high-definition camera (resolution ≥1080P) to capture front / side images of the vehicle, extracting license plate number, body color, and vehicle characteristics (such as truck / car, wheelbase)), traffic timing data (recording the time the vehicle enters the lane and the time it reaches the RSU communication range (accurate to milliseconds), associated with the lane number (such as "Highway G1-01 lane")), and weight data (for truck scenarios, triggering the lane weighing sensor to obtain the actual weight of the vehicle (accuracy ≤50kg), and generating a weight detection report); at the same time, the appearance data, timing data, and weight data are packaged into a roadside data package and uploaded to the cloud data center simultaneously;

[0074] S13, Cloud Data Collection: After receiving vehicle-mounted end data packets and roadside end data packets in the cloud data center, retrieve the user's historical transaction data (travel routes in the past 6 months (including toll stations passed through and travel times), historical toll deduction standards (e.g., trucks are tolled by weight, cars are tolled per trip)), and OBU device registration data (device activation time, vehicle information bound (consistent with the registration in the vehicle management office), historical repair / replacement records (e.g., whether it has been repaired due to faults)). At the same time, integrate the retrieved data into cloud data packets, and associate them with vehicle-mounted end data packets and roadside end data packets (matched through OBU hardware serial numbers / license plate numbers) to form a multi-dimensional original data set.

[0075] The specific steps of S2 are as follows:

[0076] S21, Data Preprocessing: First, make the cloud data center clean the multi-dimensional original data set,剔除 invalid data (such as blurred license plate images, GPS positioning drift data), and补全 missing data (mark "to be verified" when weight data is missing); then extract features from the image data (vehicle appearance), identify license plate characters, body color RGB values, and vehicle type contour features through the CNN algorithm, and convert them into quantifiable data (such as "License plate: Beijing AXXXX, Color: #FFFFFF, Vehicle type: small car"); afterwards, align the timestamps of the time series data (travel time, positioning time) to ensure that the GPS time of the vehicle-mounted end, the travel time of the roadside end, and the retrieval time of the cloud are all unified as UTC time;

[0077] Note: There are some Chinese words in the English translation that should be filled with the correct English expressions according to the context although they are not translated accurately here. For example, "剔除" should be "exclude" and "补全" should be "complete". Also, it's better to use more accurate terms for "historical toll deduction standards" like "historical toll charging standards". But following the rule of only returning the translated content without adding extra explanations, the above translation is presented as is.S22, Multi-dimensional Verification and Analysis: First, identity consistency verification is performed, comparing the vehicle type / VIN sent by the OBU with the vehicle characteristics / appearance extracted by the RSU. If the OBU displays a small car, but the RSU identifies it as a truck, the identity is deemed abnormal. Next, weight verification is performed. If the OBU is bound to a light truck (≤4.5 tons) but the weighing data is greater than the weight of a light truck (>4.5 tons), the identity is deemed abnormal. Then, OBU physical status verification is performed. If the physical status marker is forcibly removed / the outer shell is damaged, and the currently bound vehicle is inconsistent with the registered vehicle, the device is deemed to have been tampered with abnormally. Finally, spatiotemporal rationality analysis is performed, calculating the vehicle speed based on GPS positioning data and roadside passage time. If the distance from toll station A (T1 time) to toll station B (T2 time) is 120 kilometers, and T2-T1 < 1.5 hours (minimum speed limit 80km / h), it is judged as "spatiotemporal anomaly"; and the historical travel path of the OBU is compared (if the current travel path deviates from the commonly used path in the past 3 months by more than 100 kilometers, and there is no prior reporting record, it is marked as "path anomaly"); at the same time, a transaction continuity check is performed, comparing the OBU transaction log with the cloud record (if the OBU shows "charged" but there is no corresponding record in the cloud, it is judged as "transaction not synchronized anomaly"); and the number of times the same toll record is checked (if there are ≥2 toll records in the same lane and under the same timestamp, it is judged as "duplicate toll anomaly").

[0078] S23, Analysis Results Output: First, the verification results are comprehensively scored based on the deep learning model (out of 100 points), with 25-50 points deducted for each anomaly (e.g., 50 points for identity anomaly, 25 points for path anomaly); then, a fusion analysis report is generated, including anomaly type (e.g., identity anomaly / spatiotemporal anomaly), anomaly data screenshots (e.g., license plate comparison difference chart), comprehensive score, and pushed to the dynamic construction and differentiated prevention and control of user risk profiles.

[0079] The specific steps of S3 are as follows:

[0080] S31, User Risk Profile Construction: First, extract basic dimension data of the profile. Then, use a weighted algorithm to calculate the user risk level to divide users into three risk levels: low, medium, and high. Low risk refers to no abnormal historical behavior + real-time score ≥ 80 points + no associated risks; medium risk refers to ≤ 1 historical abnormality + real-time score 50-79 points + no associated risks; high risk refers to ≥ 2 historical abnormalities + real-time score < 50 points + associated risks / device tampering abnormalities. Then, generate a dynamic risk profile, including risk level, key risk points (such as "path abnormality"), profile update time (automatically updated after each transaction), and push it to the hierarchical intelligent early warning and handling system.

[0081] S32, Differentiated Prevention and Control Strategy Formulation: For low-risk users, first simplify the verification process (subsequent transactions only require consistency of "OBU identity information + RSU license plate recognition" to proceed, without repeated verification of GPS positioning / weight data), then optimize traffic efficiency (ETC lane priority is increased, and barrier lifting delay is shortened to 0.5 seconds (compared to 1 second)); For medium-risk users, first strengthen real-time verification (subsequent transactions require consistency of "OBU information + RSU image + GPS positioning," and if any one of these is abnormal, a second verification is immediately triggered), then provide user reminders (send SMS notifications stating "Currently in the enhanced risk verification phase, please pay attention to data consistency"); For high-risk users, first conduct full-dimensional monitoring (subsequent transactions require verification of five items: "OBU information + RSU image + weight data + GPS positioning + physical status," and any abnormality in any one item triggers the highest level warning), then conduct correlation verification (synchronize user information to regulatory agencies to check for "batch cloned device" associations (such as other OBU devices activated by the same IP address)).

[0082] The specific steps for extracting the basic dimension data of the portrait in S31 are as follows:

[0083] S311, Historical Behavior Dimension: Statistics on the number of abnormal transactions in the past 12 months (such as complaints of duplicate charges, identity verification failures), stability of commonly used travel routes (number of times the deviation is >100 kilometers), and historical status of OBU devices (such as whether there are repair / disassembly records).

[0084] S312, Real-time Behavior Dimension: Import the fusion analysis report and extract the comprehensive score (e.g., 85 points / 60 points / 30 points) and the current anomaly type (e.g., no anomaly / path anomaly / device tampering anomaly).

[0085] S313, Associated Risk Dimension: Retrieve data from the vehicle management office to check if the bound vehicle has any records of license plate fraud / overloading violations; and query the OBU activation IP address. If it is consistent with the activation IP of other high-risk users (overall score < 50 points), mark it as associated risk.

[0086] The specific steps of S4 are as follows:

[0087] S41, Warning Level Matching: First, receive the dynamic risk profile and integrated analysis report, then match the warning level according to the following rules:

[0088] Level 1 warning: High-risk users + abnormal device tampering / cloned device characteristics (such as the same OBU operating simultaneously in two locations);

[0089] Level 2 Warning: Medium-risk users + abnormal time and space / abnormal transaction synchronization;

[0090] Level 3 warning: Low-risk users + minor data deviations (such as GPS positioning drift ≤10 meters, weight deviation ≤50 kg).

[0091] S42, Tiered Implementation: For Level 1 warning response, this includes real-time interception (sending instructions to the toll station control system to prevent the ETC lane barrier from lifting, while simultaneously triggering a lane audible and visual alarm (flashing red light + voice prompt "Equipment malfunction, please cooperate with verification")), equipment control (freezing the transaction permissions of the OBU device and prohibiting subsequent deduction operations), personnel notification (pushing warning information (including vehicle images, screenshots of abnormal data, and risk profiles) to toll station management personnel to guide on-site verification), and user notification (sending an SMS to the registered mobile phone number ("Your ETC device is at risk of cloning / tampering and has been temporarily frozen. Unfreezing requires contacting customer service for verification")); for Level 2 warning response, this includes transaction control (suspending the settlement process of the transaction to avoid...). The process includes: no fund transfer required), operator notification (pushing abnormal data to the operator's monitoring center and arranging back-end personnel to review it (such as contacting the user to confirm whether the passage actually occurred)), and user reminder (sending an SMS to inform the user that "your ETC transaction has a delay / path abnormality, please do not repeat the passage, the verification results will be notified later"). For the three-level warning handling, there are data marking (automatically marking the transaction as "pending review" in the cloud database, which does not affect real-time passage), back-end review (automatically summarizing the three-level warning data every morning and pushing it to the manual review team to complete the review within 24 hours (such as confirming whether GPS drift is a signal problem)), and result feedback (if there is no problem in the review, the "pending review" mark is canceled; if an abnormality is confirmed, it is upgraded to a two-level warning and the handling process is completed).

[0092] The specific steps of S5 are as follows:

[0093] S51, Blockchain Data Packaging: After each transaction is completed (including the end of early warning handling), the cloud data center first collects the data scope, including multi-dimensional raw data, integrated analysis reports, risk profiles, and early warning handling records; then, it performs a hash operation on the collected data to generate a unique hash value and adds a timestamp; then, it packages the encrypted data, hash value, and timestamp into a transaction block, with the OBU hardware serial number / license plate number marked in the block header (for easy subsequent retrieval).

[0094] S52, Consortium Blockchain Upload and Storage: First, the transaction block is uploaded to the ETC industry consortium blockchain (a distributed node network jointly maintained by the transportation authority, ETC operators, and third-party auditing institutions); then, the consortium blockchain nodes (such as provincial transportation department nodes and operator headquarters nodes) synchronously verify the legality of the block (checking the hash value and timestamp), and write it into the blockchain ledger after successful verification; then, a multi-node backup mechanism is adopted to synchronize each block to at least 5 consortium blockchain nodes to avoid single-point data loss;

[0095] S53, Risk Event Tracing: When a transaction dispute (such as a user complaint about duplicate charges) or a risk event (such as a cloned device case) occurs, the tracing initiator (such as the operator / regulatory agency) first submits a tracing application (including OBU number / license plate / transaction time); then, the consortium blockchain system retrieves the corresponding block based on the application information and extracts the original data (such as OBU transaction logs, RSU images, and warning records); next, the tracing party verifies the legality of the data by comparing the block hash value with the original data hash value to confirm that the data has not been tampered with; finally, a tracing report is generated, automatically compiling the data comparison results and abnormal node analysis (such as the passage timeline of cloned devices), and supports exporting to PDF format (for dispute handling / case investigation).

[0096] Although the present invention has been described above with reference to embodiments, various modifications can be made and components can be replaced with equivalents without departing from the scope of the invention. In particular, as long as there is no structural conflict, the features in the disclosed embodiments can be combined with each other in any manner. The lack of an exhaustive description of these combinations in this specification is merely for the sake of brevity and resource conservation. Therefore, the present invention is not limited to the specific embodiments disclosed herein, but includes all technical solutions falling within the scope of the claims.

Claims

1. A method for monitoring and controlling risks in ETC transactions, characterized in that, The specific steps are as follows: S1, Real-time Collection of Multi-Dimensional Data: Through a three-level collection architecture of vehicle-mounted, roadside, and cloud terminals, multi-dimensional raw data of the entire ETC transaction process is acquired in real time. This includes basic vehicle information, transaction operation records, and real-time location data of the vehicle-mounted OBU device, as well as vehicle appearance images, passage time sequence, and weight detection data of the roadside RSU device. At the same time, it links with the cloud to retrieve user historical transactions and OBU registration information, and based on OBU physical status data, it finally forms a full-dimensional raw dataset of devices, vehicles, users, and history, providing complete data support for subsequent analysis, profiling, and early warning. S2, Multi-source Data Fusion Analysis: Standardizes and deeply verifies multi-dimensional raw data; first, data standardization is achieved through data cleaning, feature extraction, and timestamp alignment; then, cross-validation is carried out from multiple dimensions; finally, a fusion analysis report containing anomaly types, data evidence, and comprehensive scores is output to accurately identify risks in transactions and provide quantitative basis for user risk profiling and graded early warning. S3, Dynamic Construction and Differentiated Prevention and Control of User Risk Profiles: Construct a dynamic, multi-dimensional user risk assessment system, extract features from three dimensions: historical behavior, real-time performance, and associated risks, and classify users into three risk levels (low, medium, and high) through a weighted algorithm, and formulate targeted differentiated prevention and control strategies. Simplify verification for low-risk users to improve passage efficiency, strengthen verification and remind users of medium-risk users, and monitor and verify high-risk users in all dimensions. This achieves adaptive management where the higher the risk, the more precise the prevention and control, and the lower the risk, the more convenient the process, providing accurate decision-making direction for graded early warning and disposal. S4, Tiered Intelligent Early Warning and Response: Based on the user's risk level and anomaly type, a tiered early warning mechanism of Level 1, Level 2, and Level 3 is established to quickly block high-risk behaviors and reduce losses through real-time response and tiered response, avoid excessive intervention that affects user experience, and achieve a balance between risk control and traffic efficiency. S5, Blockchain Evidence Preservation and Traceability: Packages the entire transaction process data into encrypted blocks and uploads them to a consortium blockchain jointly maintained by transportation departments, operators, and auditing institutions. Through hash encryption and multi-node backup, the data is ensured to be tamper-proof. It also supports quick retrieval based on OBU number, license plate, and transaction time. In the event of transaction disputes or risk events, it can retrieve the original data with one click and verify its legality, quickly generate traceability reports, and provide an immutable chain of evidence for user refunds, case investigations, and liability determination, forming a complete closed loop of prevention, evidence preservation, and traceability. The specific steps of S2 are as follows: S21, Data Preprocessing: First, the cloud data center cleans the multi-dimensional raw dataset, removing invalid data and filling in missing data; then, feature extraction is performed on the image data, using CNN algorithms to identify license plate characters, vehicle body color RGB values, and vehicle outline features, and converting them into quantifiable data; then, time-series data is timestamped to ensure that the vehicle GPS time, roadside passage time, and cloud retrieval time are all consistent with UTC time. S22, Multi-dimensional Verification and Analysis: First, identity consistency verification is performed, comparing the vehicle type / VIN sent by the OBU with the vehicle characteristics / appearance extracted by the RSU. If the OBU displays a small car, but the RSU identifies it as a truck, the identity is deemed abnormal. Next, weight verification is performed. If the OBU is bound to a light truck but the weighing data is greater than the weight of a light truck, the identity is deemed abnormal. Then, OBU physical status verification is performed. If the physical status marker is forcibly removed / the shell is damaged, and the currently bound vehicle is inconsistent with the registered vehicle, the device is deemed to have been tampered with abnormally. Finally, spatiotemporal rationality analysis is performed. Based on GPS positioning data and roadside passage time, the vehicle passage speed is calculated and compared with the OBU's historical passage path. At the same time, transaction continuity verification is performed, comparing the OBU transaction log with the cloud record, and checking the number of times the same passage record is charged. S23, Analysis Results Output: First, the verification results are comprehensively scored based on the deep learning model; then, a fusion analysis report is generated and pushed to the user risk profile dynamic construction and differentiated prevention and control.

2. The ETC transaction monitoring and risk control method according to claim 1, characterized in that, The specific steps of S1 are as follows: S11, Vehicle-mounted data collection: First, basic vehicle information is collected to generate raw information data packets; then, transaction operation data is collected to form transaction logs; then, vehicle location data is collected in real time; at the same time, OBU physical status data is collected; finally, the collected data is packaged into vehicle-mounted data packets and uploaded to the cloud data center in real time via 4G / 5G network. S12, Roadside Data Collection: When a vehicle enters the ETC lane, the RSU device is triggered to collect vehicle appearance data, passage time sequence data, and weight data; at the same time, the appearance data, time sequence data, and weight data are packaged into a roadside data package and uploaded to the cloud data center simultaneously. S13, Cloud Data Acquisition: After receiving vehicle-mounted data packets and roadside data packets in the cloud data center, the system retrieves user historical transaction data and OBU device registration data. At the same time, the retrieved data is integrated into cloud data packets and associated with vehicle-mounted data packets and roadside data packets to form a multi-dimensional raw dataset.

3. The ETC transaction monitoring and risk control method according to claim 1, characterized in that, The specific steps of S3 are as follows: S31, User Risk Profile Construction: First, extract basic dimension data of the profile, then use a weighted algorithm to calculate the user risk level to divide users into three risk levels: low, medium and high; then generate a dynamic risk profile and push it to the hierarchical intelligent early warning and handling system. S32, Differentiated prevention and control strategy formulation: For low-risk users, simplify the verification process first, and then optimize the passage efficiency; for medium-risk users, strengthen real-time verification first, and then remind users; for high-risk users, conduct full-dimensional monitoring first, and then conduct related verification.

4. The ETC transaction monitoring and risk control method according to claim 3, characterized in that, The specific steps for extracting the basic dimension data of the portrait in S31 are as follows: S311, Historical Behavior Dimension: Statistics on the number of abnormal transactions in the past 12 months, stability of commonly used routes, and historical status of OBU devices; S312, Real-time Behavior Dimension: Import the fusion analysis report and extract the comprehensive score and current anomaly type; S313, Associated Risk Dimension: Retrieve data from the vehicle management office to check if the bound vehicle has any records of illegal license plate use or overloading; It also queries the OBU activation IP address, and if it is the same as the activation IP of other high-risk users, it marks the associated risk.

5. The ETC transaction monitoring and risk control method according to claim 1, characterized in that, The specific steps of S4 are as follows: S41, Warning Level Matching: First, receive the dynamic risk profile and integrated analysis report, then match the warning level according to the following rules: Level 1 Warning: High-risk users + abnormal device tampering / cloning device characteristics; Level 2 Warning: Medium-risk users + abnormal time and space / abnormal transaction synchronization; Level 3 alert: Low-risk users + minor data deviations; S42, Tiered Response Execution: For Level 1 early warning response, this includes real-time interception, equipment control, personnel notification, and user notification; The handling of Level 2 warnings includes transaction control, operator notification, and user reminders; the handling of Level 3 warnings includes data tagging, back-end review, and result feedback.

6. The ETC transaction monitoring and risk control method according to claim 1, characterized in that, The specific steps of S5 are as follows: S51, Blockchain Data Packaging: After each transaction is completed, the cloud data center first collects the data scope, including multi-dimensional raw data, integrated analysis reports, risk profiles, and early warning and handling records; then it performs a hash operation on the collected data to generate a unique hash value and adds a timestamp; then it packages the encrypted data, hash value, and timestamp into a transaction block, with the OBU hardware serial number / license plate number marked in the block header; S52, Consortium Blockchain Upload and Storage: First, the transaction block is uploaded to the ETC industry consortium blockchain; then, the consortium blockchain nodes synchronously verify the legality of the block, and write it into the blockchain ledger after successful verification; then, a multi-node backup mechanism is adopted to synchronize each block to at least 5 consortium blockchain nodes to avoid single-point data loss. S53, Risk Event Tracing: When a transaction dispute or risk event occurs, the tracing initiator first submits a tracing application; then the consortium blockchain system retrieves the corresponding block based on the application information and extracts the original data; then the tracing party verifies the legality of the data by comparing the block hash value with the original data hash value to confirm that the data has not been tampered with; finally, a tracing report is generated, automatically organizing the data comparison results and abnormal node analysis, and supporting export to PDF format.

Citation Information

Patent Citations

  • Risk-prevention-and-control-oriented toll station ETC barrier gate delayed opening control method

    CN112037351A

  • ETC transaction security method and device based on block chain technology

    CN112116726A