Tamper proof forecourt controller and dispenser
The Cryptographic Assurance System (CAS) addresses the vulnerabilities in current fuel service station systems by employing advanced cryptographic methods to secure fuel dispensed information and operational commands, thereby ensuring data integrity and preventing unauthorized tampering, which enhances operational reliability and regulatory compliance.
Patent Information
- Application Number
- PCT/US2024/058195
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-03
- Filing Date
- 2024-12-03
- Publication Date
- 2025-06-12
AI Technical Summary
Current fuel service station systems lack robust encryption and authentication mechanisms, making them vulnerable to unauthorized tampering and manipulation of fuel dispensed information (FDI), pricing, and inventory records, which compromises operational reliability, regulatory compliance, and auditing accuracy.
The implementation of a Cryptographic Assurance System (CAS) that uses advanced cryptographic methods, including encryption and digital signatures, to secure FDI and operational commands, ensuring their integrity, authenticity, and confidentiality. This system employs secure storage of encryption keys in microcontroller units (MCUs) and can be implemented at multiple levels within the fuel delivery ecosystem.
The CAS effectively prevents unauthorized tampering and manipulation, ensuring the accuracy and integrity of FDI and operational data, thereby enhancing operational reliability, regulatory compliance, and customer trust, while reducing opportunities for fraudulent practices.
Smart Images

Figure US2024058195_12062025_PF_FP_ABST
Abstract
Description
TAMPER PROOF FORECOURT CONTROLLER AND DISPENSER Background of the InventionReference to Prior ApplicationThis application claims priority of the provisional patent application 63 / 605,547, filed on December 3, 2023 entitled TAMPER PROOF FORECOURT CONTROLLER AND DISPENSER by Miguel S. Giacaman.Field of the Invention
[0001] The present invention relates to systems and methods employed in fuel service stations, and more particularly, to a system and method for ensuring the integrity and security of data and commands exchanged between forecourt controllers, fuel dispensers, tank gauges, and management systems. This is achieved through the implementation of a cryptographic assurance system that prevents unauthorized tampering, ensures regulatory compliance, and enhances operational reliability.Description of the Prior Art
[0002] Fuel dispensers at service stations have evolved into sophisticated electronic systems eguipped with computers that control fuel dispensing operations and display transaction details. These dispensers often connect with centralized control systems via data communication ports, such as RS232 / 485, proprietary serial ports, wireless communication channels or other data interfaces. These connections enable the transmission of commands to dispensers, such as authorizing fuel delivery, setting limits on fuel volume or price, and adjusting operational parameters .
[0003] At the core of fuel station management lies the Fuel Delivery Management System (FDMS) , which integrates various components, including Point of Sale (ROS) systems andForecourt Controllers . These systems facilitate the control of multiple fuel dispensers , the aggregation of Fuel Dispensed Information ( FDI ) , and inventory management . Fuel tank gauges are often employed to monitor fuel storage levels in underground or above-ground tanks to report inventory and refueling events . Additionally, electronic price signs are often utili zed to inform the drivers in the approaching in the vehicles of the price per volume for the various fuels available at the fuel service station .
[0004] Some dispensers include an accessory unit known as Pay at the Pump ( PPI ) , or Credit Card Access Terminal ( CAT ) . These units allow customers to pay directly at the dispenser , typically using credit or debit cards . Unli ke PPI data , which is transmitted through an entirely independent communication channel and is typically encrypted or secured with hash signature-based integrity checks to protect sensitive payment information, the Fuel Dispensed Information ( FDI ) is exchanged neither in encrypted formats nor with hash signature-based integrity checks via separate data links to the FDMS . This lack of security leaves FDI vulnerable to unauthori zed manipulation or tampering by third-party applications .
[0005] While these interconnected systems streamline fuel station operations , they are vulnerable to exploitation . To enable compatibility with third-party software applications , manufacturers of fuel dispensers and fuel tank gauges must disclose their , sometimes proprietary, communication protocols . These protocols typically use simple binary or ASCI I coding and checksum-based integrity mechanisms , which are provided to the developers of the Fuel Management Software . However , these basic methods lack robust encryption or authentication, leaving the system open tounauthorized alterations of FDI, pricing, and inventory records. Such vulnerabilities create significant risks for operational reliability, regulatory compliance, and auditing accuracy .
[0006] In the prior art, communication between fuel dispensers, fuel tank gauges, Forecourt Controllers, electronic price signs and FDMS relies on communication protocols that lack encryption or cryptographic integrity measures, depending instead on rudimentary techniques like binary coding and checksums. Because the protocols and checksum calculations are shared with third-party developers, unauthorized parties can exploit this openness to manipulate critical data and commands without detection. Examples of vulnerabilities include:
[0007] 1. Manipulation of Dispensed Volume and Amount:Third-party applications can modify the reported volume of fuel dispensed or the monetary amount of transactions. This allows for fraudulent practices, such as underreporting dispensed volumes or transaction amounts, which can bypass integrity checks by recalculating checksums.
[0008] 2. Alteration of Price Per Unit (PPU) :Malicious actors may manipulate the PPU, creating discrepancies in pricing records and enabling fraudulent practices. This includes reporting different prices to the controlling entity that differ from those used by the fuel dispenser and potentially also from the prices displayed on the electronic price signs.
[0009] 3. Tampering with Electronic Totalizers:Electronic totalizers, which maintain historical records of fuel dispensed since installation, are susceptible to tampering. Third-party applications can alter these values,compromising the integrity of long-term transaction and inventory records.
[0010] 4. Falsification of Fuel Tank Inventory:Fuel tank gauges, which report inventory levels and refueling events, can be manipulated to misrepresent fuel levels or falsify records. This compromises inventory tracking and compliance with regulatory requirements.
[0011] 5. Audit and Compliance Risks:Manipulated data compromises the accuracy of reports submitted to governmental, private, or law enforcement entities, eroding trust and accountability.
[0012] The lack of encryption or authentication mechanisms in the prior art leaves fuel delivery systems vulnerable to exploitation by third-party applications, undermining the reliability and security of the entire ecosystem.
[0013] Often, fuel service stations operate under the purview of a supervising entity. These entities could range from government agencies, business divisions, partners, or third-party companies with which a contractual agreement for the supervision and management of this data has been formed.
[0014] Fuel service stations typically employ a computerized Fuel Delivery Management System consisting of specialized software like point-of-sale (POS) , back-office applications, or other software applications pivotal to the station's operation. This software generally runs on a computer using either the Windows or Linux operating system or in a cloud-based setup. Often, this software is developed by a third-party organization or software developer business.
[0015] Access to this software is typically granted to the station owner, the management team, a third-party organization or software developer business and is notsubject to the supervising entity's oversight or control. At the most, the software must be certified by a Controlling Entity .
[0016] The primary point of potential data and control manipulations of the fuel dispensers resides in this system. At this juncture, it is relatively easy to alter data. The fuel service station's management could, by themselves or colluded with the POS or fuel management software provider, manipulate the fuel dispensers ' control and the Fuel Dispensed Information (FDI) before it's reported or transmitted to the supervising entity. It is imperative to ensure the robustness and adherence to strict protocols of these systems to uphold the accuracy and integrity of the transmitted FDI.
[0017] Given these issues, there is an urgent need to mitigate the following actions:•
[0018] Unauthorized modification of the FDI as specified by the supervising entity and reported to said supervising entity.•
[0019] Unauthorized modification of EGA or tampering with the fuel dispenser's control to permit unauthorized deliveries, unauthorized fuel pricing, or dispensation of unauthorized fuel volumes or amounts.•
[0020] Alteration of the operation of the Forecourt Controller as authorized or as specified by the supervising entity.•
[0021] Alteration of the operation of the fuel dispensers as authorized or as specified by the supervising entity.
[0022] In response to rising security concerns, controlling entities now mandate the use of cryptography to protect the Fuel Dispenser Information (FDI) relayed by the Fuel Dispenser Management System (FDMS) . In this enforced model, the Controlling Entity dispenses the encryption key either to the fuel service station's management or directly to the software developers managing the FDMS. This strategy ensures that the information being transmitted cannot be intercepted and decrypted by any unauthorized party, irrespective of their potential access to the network or any segment of the communication channel. Thus, it maintains the integrity and accuracy of the data that the Controlling Entity receives. However, it's essential to highlight that this approach doesn't prevent the FDMS from potentially altering the information before cryptographic protection is applied and before its transmission to the Controlling Entity.
[0023] To address these challenges, the present invention introduces a Cryptographic Assurance System (CAS) to overcome the vulnerabilities inherent in current systems. The CAS ensures the integrity, authenticity, and confidentiality of data and commands exchanged within the fuel delivery ecosystem by implementing advanced cryptographic methods. These include encryption to safeguard sensitive data, such as FDI, and digital signatures to guarantee the authenticity of operational commands, such as pricing updates or fuel delivery authorizations. By securing these critical elements, the CAS prevents unauthorized tampering and manipulation.
[0024] The Cryptographic Assurance System utilizes secure storage of encryption keys in non-volatile memory within microcontroller units (MCUs) integrated into forecourt controllers, fuel dispensers, and related components. TheseMCUs are equipped with advanced features to block unauthori zed access to cryptographic keys , ensuring that all encryption and authentication processes remain tamper-proof . Depending on the station ' s configuration , the CAS can be implemented at multiple levels . For example , it can provide encryption at the source within dispensers and tank gauges , or it can operate centrally through a forecourt controller , which acts as a secure gateway . This flexibility allows stations to maintain compatibility with legacy systems while adopting multilayered security strategies tailored to their needs .
[0025] The advantages of the present invention extend beyond data security . By generating Tamper-Proof Fuel Dispensed Information ( TPFDI ) , the system ensures that all operational data and reports submitted to controlling entities are accurate , verifiable , and compliant with regulatory standards . This compliance fosters trust between fuel service stations and regulatory bodies , enhancing the integrity of the entire operational ecosystem . Additionally, the CAS significantly reduces opportunities for fraudulent practices , such as price manipulation or unauthorized alterations to transaction data , thereby safeguarding the financial and operational reliability of the station .
[0026] The invention further enhances operational ef ficiency by integrating seamlessly with existing systems and enabling incremental implementation . Stations can begin by equipping forecourt controllers with CAS capabilities and gradually expand to other components , such as dispensers or tank gauges , without requiring immediate full-scale replacements . This cost-ef fective scalability makes the CAS an accessible solution for stations of varying si zes and technological maturity .
[0027] The Cryptographic Assurance System also prepares stations for future challenges. By supporting secure deployment of software updates and the integration of new cryptographic keys, the system adapts to evolving security requirements and regulatory standards. Its compatibility with third-party applications under strict cryptographic controls ensures that stations can integrate new functionalities without compromising security. Moreover, by delivering reliable, tamper-proof operations, the CAS enhances customer trust, as consumers can be confident in the accuracy of transactions and displayed pricing.
[0028] The present invention provides a robust, scalable, and future-proof solution to the vulnerabilities faced by current fuel service station systems. By leveraging advanced cryptographic technologies and flexible implementation strategies, the Cryptographic Assurance System ensures secure, reliable, and compliant operations, setting a new standard for the management of fuel delivery, inventory, and pricing.Summary of the Invention
[0029] It is therefore a main object of the present invention to provide a Cryptographic Assurance System (CAS) that secures the integrity, authenticity, and confidentiality of data and commands exchanged within the fuel delivery ecosystem.
[0030] It is another object of the present invention to provide a Cryptographic Assurance System (CAS) of the abovereferred nature, which leverages advanced cryptographic methods, including encryption and digital signatures, to ensure that sensitive data, such as Fuel DispensedInformation (FDI) , is protected against unauthorized tampering and manipulation.
[0031] It is a further object of the present invention to provide a Cryptographic Assurance System (CAS) that utilizes encryption algorithms, such as Advanced Encryption Standard (AES) and Public Key Encryption (PKE) , and cryptographic assurance through digital signatures or equivalent techniques, to safeguard critical data and prevent interception or alteration during transmission.
[0032] It is an additional object of the present invention to provide a Cryptographic Assurance System (CAS) that implements encryption or digital signatures to ensure the authenticity of operational commands, such as fuel delivery authorizations and pricing updates, preventing unauthorized modifications.
[0033] It is yet another object of the present invention to provide a Cryptographic Assurance System (CAS) that employs secure storage of encryption keys in non-volatile memory within microcontroller units (MCUs) integrated into forecourt controllers, fuel dispensers, and related components, ensuring that cryptographic processes remain tamper-proof and resistant to unauthorized access.
[0034] It is also an object of the present invention to provide a Cryptographic Assurance System (CAS) that supports flexible implementation strategies, allowing encryption to be applied at the source, such as dispensers and tank gauges, or centrally through forecourt controllers acting as secure gateways .
[0035] It is a further object of the present invention to provide a Cryptographic Assurance System (CAS) that generates Tamper-Proof Fuel Dispensed Information (TPFDI) to ensure accurate, verifiable, and compliant reporting of operational data to governmental or private controlling entities .
[0036] It is another object of the present invention to provide a Cryptographic Assurance System (CAS) that significantly reduces opportunities for fraudulent practices, including manipulation of fuel prices, transaction data, and inventory records, thereby enhancing operational reliability and financial integrity.
[0037] It is also an object of the present invention to provide a Cryptographic Assurance System (CAS) that enables incremental implementation, allowing fuel service stations to integrate cryptographic capabilities in stages, starting with forecourt controllers and expanding to other components, without requiring immediate full-system replacement.
[0038] It is yet another object of the present invention to provide a Cryptographic Assurance System (CAS) that supports secure deployment of software updates and new cryptographic keys, ensuring adaptability to evolving security threats and regulatory standards.
[0039] It is an additional object of the present invention to provide a Cryptographic Assurance System (CAS) that is compatible with third-party applications, maintaining interoperability under strict cryptographic controls to ensure security while enabling integration of new functionalities .
[0040] It is a further object of the present invention to provide a Cryptographic Assurance System (CAS) that enhances customer trust by ensuring the accuracy oftransactions , displayed pricing , and operational data , thereby improving the reputation and reliability of fuel service stations .
[0041] These and other obj ects and advantages of the present invention will become apparent from the detailed description that follows , demonstrating the comprehensive and robust nature of the Cryptographic Assurance System ( CAS ) in addressing the vulnerabilities of existing systems while enhancing operational security, reliability, and compliance in the fuel service station industry .BRIEF DESCRIPTION OF THE DRAWINGS
[0042] For a better understanding of the present invention , reference is to be made to the accompanying drawings . It is to be understood that the present invention is not limited to the precise arrangement shown in the drawings .
[0043] Figure 1 shows a Prior Art configuration in which a Fuel Management Systems and interconnected devices and equipment communicate via a protocol that is not protected by a Cryptographic Assurance System (CAS ) .
[0044] Figure 2 Is an embodiment of this invention that shows a Fuel Delivery Management System ( FDMS ) 10 and 11 that uses Cryptographic Assurance System (CAS ) to send and receive FDI via CAS enabled communication lines 12 , 15 and 17 to Fuel Dispensers that can be CAS enabled 14 , Fuel Tank Gauges that can be CAS enabled 16 and Electronic Fuel Price Signs that can be CAS enabled 18 .
[0045] Fig . 3 Is an embodiment of this invention that shows a Fuel Delivery Management System ( FDMS ) 10 and 11 that uses Cryptographic Assurance System (CAS ) and radio frequency transceivers 19 to communicate wirelessly to send and receive FDI to and from Fuel Dispensers that can be CAS enabled 14 ,Fuel Tank Gauges that can be CAS enabled 16 and Electronic Fuel Price Signs that can be CAS enabled 18.Terminology
[0046] Cryptographic Assurance System (CAS) : A system designed to prevent unauthorized modifications or alterations of data or information related to fuel delivery operations at a fuel service station, also known as a retail fuel dispensing facility. CAS ensures data integrity and authenticity by employing techniques such as encryption of Fuel Dispensed Information (FDI) or digitally signing the FDI using hashbased methods or similar cryptographic mechanisms. For the purposes of this patent, the term "encryption" encompasses the broader concept of CAS, including both data encryption and cryptographic assurance through digital signatures or equivalent techniques.
[0047] Electronic Fuel Dispenser (EFD) : This refers to any equipment used to deliver metered fuel to vehicles at fuel service stations, commonly known as "the fuel pump". It is comprised of at least a fuel meter, a computer, and a means of data communication.
[0048] Fuel Dispensed Information (FDI) : Is a set of data associated with the fuel dispensing operation and comprehensive data collection framework integral to fuel dispensing operations containing at least one value taken from a set of values including, but not limited to:
[0049] 1. Quantitative Measures: The total amount and volume of fuel dispensed.
[0050] 2. Economic Data: The cost per unit volume of the dispensed fuel.
[0051] 3. Fuel Specifications: Types or grades of fuel dispensed .
[0052] 4. Operational Parameters: Unique conditions applied during the dispensation process, such as predetermined fuel blending ratios and precision calibration standards for fuel measurement.
[0053] 5. Identification Information: Details identifying the involved parties, which may include the client, driver of the vehicle being filed up, operator of the fuel dispenser, fuel delivery facility of station, owner, location and tax identifier.
[0054] Some of these values are variable while the fuel is being dispensed but become part of the FDI once the fuel dispensing operation concludes, usually by returning the fuel nozzle to the dispenser, signaling the end of the dispensing operation. The FDI could also include the values of the electronic totalizers, which are electronic counters within the Dispenser that reflect the accumulated amount and volumes since the last reset of the electronic totalizer values, which are updated by the dispenser at the end of each fuel dispensing operation.
[0055] POS (Point of Sales, also known as Point of Purchase) : This is any software or equipment used in the management or processing of sales at a fuel service station. It collects information, such as FDI, from one or more fuel dispensers at a fuel service station and may generate receipts, connect to credit card clearing services, generate reports, etc. Such information may be collected directly from the Dispenser, or by means of a Forecourt Controller or from one or more Interfaces to Dispensers, or from one or more Add-on Devices.
[0056] Fuel Delivery Management System (FDMS) : This term refers to an integrated array of hardware components, software applications, and communication protocols used at afuel service station to comprehensively manage, control, and supervise the entire fuel delivery process. This system' s functionalities encompass fuel dispensation control, fuel inventory management, transaction processing, price setting, and the implementation of security measures. It may comprise various digital tools such as point-of-sale systems, back- office and accounting software, payment processing mechanisms, and invoice generation systems. These tools may interface directly with fuel dispensers or via auxiliary devices like a forecourt controller, all collaboratively functioning to ensure efficient, secure, and accurate fuel delivery to vehicles. Additionally, the system may have the capability to communicate with external controlling entities to receive encrypted or unencrypted commands or authorization tokens, thereby bolstering operational security and control.
[0057] Forecourt Controller (FC) : This is electronic equipment that interfaces or communicates with the Dispensers via a data link and has the capacity to at least collect FDI from one or more Dispensers and make it available to at least one POS or any other part of the Fuel Delivery Management System. The Controller usually has additional capacities like general control of the fueling, changing the price of fuel, etc. This interface is also known as interface to dispensers or control console.
[0058] Add-on Device: This is a device connected to the Dispensers' FDI data link to add functionalities not provided by the dispenser manufacturer, like providing a TPFDI message to the POS .
[0059] SFDI (Source of FDI) : This is any equipment or device that provides the POS or controlling third party with data related to the sales of fuel at a fuel service station.Examples of SFDI could be the dispenser, the Interface to Dispensers, or an Add-on Device.
[0060] Tamper-Proof Fuel Dispensed Information (TPFDI) : TPFDI refers to Fuel Dispensed Information (FDI) that has been safeguarded against unauthorized alterations. This is achieved either by adding a digital signature (hash) to verify its integrity or by encrypting the FDI itself.
[0061] Encrypted Authorization Commands (EAC) : EACs are directives dispatched by the Fuel Management System, either in an encrypted or digitally signed (hashed) format. These commands can be relayed directly to a fuel dispenser or channeled through a Forecourt Controller. Their purpose is multifaceted; they can set specifications on the maximum volume or amount of fuel to be dispensed, delineate the permissible types of fuel, or establish other related conditions. When routed through a Forecourt Controller, these commands can either retain their encrypted or hashed format or be decrypted to align with the proprietary protocol determined by the fuel dispenser's manufacturer.
[0062] PPI (Pay at the Pump Information) : This is information associated with payment means, like the credit card, client card, PIN numbers, additional services or products like car wash, and may include FDI. The PPI is usually collected and provided by an add-on device commonly known as "Pay at the Pump".Detailed Description of a the inventionPrior Art
[0063] The Fuel Delivery Management System or Point of Sales 1 is usually a one or more software applications that are relevant to the fuel dispensing operation at a fuel delivery retail facility. They are usually running in one ormore computers that can be in the management office, front desk of the convenience store or any other appropriate location. This Fuel Management System may connect directly to the fuel dispensers via an appropriate communications interface 2 or indirectly by connecting to a Forecourt Controller 2. In either case, the connection and control of the Fuel Dispensers 5 are done via the appropriate communications interface 2 and a set of one or more communication lines 3. The Forecourt Controller 2 differs from a communications interface by having a computer that sends and receives the data and commands to and from the Fuel Dispensers 5.
[0064] The present invention will now be described in accordance with a preferred embodiment, which comprises a method for securely managing Fuel Dispensed Information (FDI) through the generation, transformation, and communication of this data within the fuel delivery ecosystem. The method is completely carried out automatically by one or more data processing means. The method ensures the integrity, authenticity, and confidentiality of the FDI by utilizing an encryption key securely generated and managed by the Controlling Entity. The general method includes the following steps :
[0065] a) Producing one or more encryption keys
[0066] The method begins with the Controlling Entity, which is tasked with overseeing and ensuring the secure operation of fuel delivery systems. An encryption key is generated within a specialized device designed to securely house and manage the key. This encryption key forms the cornerstone of all cryptographic operations within the system, enabling the secure transformation of Fuel DispensedInformation (FDI) and the authentication of operational commands .
[0067] The specialized device incorporates advanced security mechanisms, including tamper-proof memory and microcontroller units (MCUs) with integrated cryptographic capabilities. These features ensure that the encryption key remains protected against unauthorized access or tampering throughout its lifecycle. Once generated, the key is securely stored within the device, accessible only to authorized processes. This approach guarantees the integrity of the encryption key and safeguards the overall security of the system.
[0067] b) Transforming the FDI into the Tamper-Proof Fuel Dispensed Information (TPFDI) format using the encryption key
[0068] In this stage, the encryption key is used to transform raw FDI into a secure format known as Tamper-Proof Fuel Dispensed Information (TPFDI) . FDI includes transactional data such as the volume of fuel dispensed, the transaction amount, the price per unit (PPU) , and totalizer values. Using encryption or digital signatures, the FDI is converted into TPFDI to ensure its integrity and authenticity .
[0069] The transformation process takes place within secure modules integrated into the system, such as the Forecourt Controller, the fuel dispenser, or the Fuel Delivery Management System (FDMS) . Cryptographic methods such as Advanced Encryption Standard (AES) or Public Key Encryption (PKE) are employed to provide robust protection. In cases where digital signatures are used, unauthorized modifications can be detected immediately, adding another layer of security.
[0070] This stage is designed for efficiency and seamless integration into the operational workflow of the fuel station, ensuring minimal disruption to normal activities .
[0071] c) Conveying the TPFDI to the specific section of the Fuel Delivery Management System (FDMS) responsible for communicating with the Controlling Entity
[0072] The next stage involves transmitting the TPFDI to the designated section of the FDMS. This section is responsible for managing and reporting operational data to the Controlling Entity. The transmission occurs through secure communication pathways designed to protect the TPFDI from interception or unauthorized access during transit.
[0073] The FDMS processes the received TPFDI for reporting purposes, ensuring that the data is accurate and unaltered before being submitted to the Controlling Entity. Depending on the system configuration, the TPFDI may be sent directly from the Forecourt Controller or fuel dispenser to the FDMS, or routed through intermediate components while maintaining its secure format. Verification mechanisms are employed to authenticate the TPFDI before it is accepted by the FDMS, ensuring the integrity of the transmitted data.
[0074] This stage enables the Controlling Entity to utilize the secure and authenticated TPFDI for auditing, regulatory compliance, and operational oversight, fostering trust within the fuel service station ecosystem.
[0075] d) Receiving encrypted authorization commands (EAC) from the Controlling Entity
[0076] In this stage, encrypted authorization commands (EAC) are received by the system components, including fuel dispensers, fuel tank gauges, or the Forecourt Controller.These commands are issued by the Controlling Entity and specify operational parameters such as fuel dispensing limits, inventory adjustments, or pricing configurations. The use of encryption ensures that these commands remain authentic and secure during transmission.
[0077] e) Decrypting the EAC
[0078] Once received, the encrypted authorization commands are decrypted at the respective component, whether it is a fuel dispenser, fuel tank gauge, or Forecourt Controller. The decryption process verifies the integrity and authenticity of the commands, ensuring that only valid instructions are executed. This step is crucial for maintaining the security and reliability of the system' s operations .
[0079] f) Executing the decrypted EAC
[0080] In the final stage, the decrypted authorization commands are executed by the respective components. For fuel dispensers, this may include dispensing fuel according to specified volume or pricing parameters. For fuel tank gauges, it may involve adjusting inventory records to reflect recent operations. The execution of authenticated commands ensures that all actions align with the secure and authorized instructions provided by the Controlling Entity, reinforcing the operational integrity of the system.Additional Aspects of the Method
[0081] Role of the Controlling Entity:
[0082] The Controlling Entity, defined as the overseer of fuel dispensing operations, plays a critical function. It can dispatch encrypted or digitally signed fuel authorization commands to fuel dispensers and receive encrypted or digitally signed information back from them. These commandscan authorize fuel dispensation, dictate conditions, or establish boundaries for the fuel dispensing procedures. Examples of Controlling Entities range from business headquarters to government regulatory bodies or other organizations authorized to supervise fueling operations and set its guidelines.
[0083] Encryption Key Utility:
[0084] The encryption key is central, serving a dual purpose. Whether generating a cryptographic hash or encrypting the commands sent to the Fuel Dispensers and the data they produce, the key is vital. This design ensures that all communication regarding fuel delivery authorizations (EAC) between the Forecourt Controller and the FDMS components in touch with the Controlling Entity remains secure against unauthorized tampering. This key can be housed in multiple facets of the FDMS - be it software applications , cloud systems, local station computers, Forecourt Controllers, or Fuel Dispensers. It can be seamlessly woven into an application's coding or securely held in a computer' s non-volatile storage.
[0085] Security Reinforcements :
[0086] A significant embodiment of this system sees the encryption key stored in the non-volatile memory of a Micro Computer Unit (MCU) , essentially a computer realized on a singular integrated circuit. In this setup, the MCU is part of either a Forecourt Controller or a Fuel Dispenser. Its security credentials are boosted by features that block unauthorized code or memory reading. Once programmed, a specific security bit within the MCU is activated, effectively preventing further memory access - a potent step towards bolstering system security.
[0087] Functionality of Fuel Dispenser and Forecourt Controller :
[0088] Both these devices are equipped to process encrypted or digitally signed commands (EAC) from the Controlling Entity. These commands cater to varied needs, including but not limited to: fuel dispensation authorization, setting volume or price limits, determining fuel types, imposing unique conditions on fuel dispensation, setting fuel blending ratios and calibration of fuel measurement .
[0089] To illustrate, when the Controlling Entity receives a fuel dispensation request, whether for a specific vehicle, individual, or organization, it can issue one or several EACs . Conditions for dispensation might be rooted in credit limits, availability of prepaid fuel, subsidies, reward programs, or other special terms negotiated with clients .
[0090] Transmission Pathways:
[0091] The Controlling Entity dispatches EACs to the EDMS within the fuel station. From there, these commands can either be directly transmitted to a Fuel Dispenser or channeled through a Forecourt Controller. Depending on where the cryptographic operations are executed — be it the Forecourt Controller or the Fuel Dispenser — these communications may adopt encrypted or unencrypted formats. A direct communication link bridges the Controlling Entity' s computing systems to either the Fuel Dispenser or the Forecourt Controller.Hardware
[0092] The method is processed by means of one or more computerized devices within the Fuel Delivery Management System (FDMS) or the electronic fuel dispensers, capable of encrypting or decrypting FDI and EAC, specifically:
[0093] 1. Encryption at Source: A primary embodiment allows fuel dispensers to transmit and receive encrypted data or commands to and from the FDMS, ensuring encryption right from the data source. However, this method necessitates upgrading each fuel dispenser at a station with an component capable to perform the proposed encryption system, which may be costly option.
[0094] 2. Forecourt Controller Solution: As a cost- effective alternative, a Forecourt Controller can be deployed to interact with fuel dispensers using unencrypted data and commands. Conversely, interactions with the FDMS remain encrypted. This setup restricts unencrypted communication solely between the Forecourt Controller and fuel dispensers, safeguarding the system without excessive expense.Software
[0095] Encryption Methods:
[0096] Several formats can be employed to encrypt FDI or EAC :
[0097] a) AES, End-to-End Encryption (E2EE) : This method utilizes a private encryption key provided by a Controlling Entity. Stored within select FC electronic components, this key remains inaccessible to unauthorized entities. For instance, AES is an example of E2EE.
[0098] b) Digital Signature or Hash (DS) : A cryptographic approach prioritizing data integrity. It enables data readability while preventing unauthorized modifications. One instance of this method is MD5.
[0099] c) PRE and Inverse PRE Encryption Schemes:•
[0100] Traditional PKE: Here, the controlling entity retains a private key, providing a public key to controlled entities— particularly FDMS units. This setup aids the FDMS in encrypting FDI, with decryption rights reserved for the controlling entity .•
[0101] Inverse PKE: This methodology employs the tenets of asymmetric cryptography. Here, the Controlling Entity establishes the private key, which is then housed either within a fuel dispenser or a designated segment of the FDMS, such as the Forecourt Controller which employs its unique private key to encrypt the data. This encrypted payload can subsequently be shared with other FDMS components, which remain oblivious to the specifics of this private key. Yet, a public key, available to both the comprehensive FDMS network and the Controlling Entity, enables decryption.
[0102] Encryption Schemes
[0103] a) FDI and TPFDI (Encrypted FDI) : Here, the encryption key is exclusive to the controlling entity, safeguarded from stakeholders such as fuel station managers or software developers. This can be symmetric (like E2EE) or asymmetric (like PKE or its inverse) . Notably, while the public key in PKE is typically accessible, in this context, it's considered private.
[0104] b) DSFDI (Digitally Signed FDI) : The controlling entity holds the private key for digital signing. Although the FDMS can read the FDI, the digital signature bars any unauthorized amendments.
[0105] c) Encrypted Authorization Commands (EAC) : The EDMS receives EACs from the Controlling Entity, setting stipulations for fuel delivery (e.g. , volume, price, or type) . These can apply to singular or multiple deliveries or be time-bound or permanent, subject to future alterations. EAC issuance might follow EDMS requests or third-party appeals .
[0106] These EACs can be de-encrypted by the Fuel Management System, by the Forecourt Controller or by the Fuel Dispensers. Since, in most cases, the code and data stored in the computers used by the Fuel Management Systems are accessible by its software developers, the private key sent by the Controlling Entity could be stored in the fuel dispensers or in the Forecourt Controller, which can send the unencrypted commands to a fuel dispenser.Preferred embodiments of the method•
[0107] One or more initial encryption keys are embedded by the Manufacturers into a Forecourt Controller, Fuel Dispensers, or the Controlling Entity. These one or more keys serves the purpose of encrypting the EFDI, DSFDI, or EAC. Moreover, these one or more initial encryption keys have the versatility of being used to decrypt and subsequently store one or more new encryption keys. These succeeding keys can complement the original, serve as its replacement, or introduce supplementary encryption strategies specifically designed for varied FDI and EAC encryption schemes.•
[0108] One or more initial encryption keys are embedded by the Manufacturers into an MCU that forms an integral part of their Forecourt Controllers or Fuel Dispensers,or this embedding might be directly executed by the Controlling Entity . These particular keys, in conjunction with any subsequently added or replaced keys, are designated to decrypt novel executable code intended for, and then loaded into, the aforementioned MCU. This MCU assumes the responsibility of applying cryptography to the EDI or EAC within the confines of either a Forecourt Controller or a Fuel Dispenser. By leveraging this methodology, potential unauthorized alterations to the operations of a Forecourt Controller or Fuel Dispenser are firmly thwarted, ensuring that only the executable code which has received approval from the Controlling Entity is incorporated into any encrypting MCU that is part of a Forecourt Controller or Fuel Dispenser.•
[0109] The Controlling Entity generates EACs based on client-specific parameters such as credit constraints, pre-paid fuel provisions, loyalty rewards, or subsidies. These EACs can either be relayed to the Fuel Dispenser through the Fuel Management System, which interfaces with the Forecourt Controller (that in turn connects to the fuel dispenser) , or via a direct linkage between the Controlling Entity' s computing infrastructure and the Fuel Dispenser or the Forecourt Controller overseeing the fuel dispensers. These directives grant fuel dispensation permissions or stipulate specific conditions or caps. Such criteria might be mandated by various stakeholders, including corporate headquarters, audit departments, governmental agencies, or other supervisory bodies. Typically, the Controlling Entity issues these encrypted directives in response tosolicitations from the Fuel Management System. The EACs can undergo decryption processes at multiple points: the Fuel Management System, the Forecourt Controller, or directly at the Fuel Dispensers. Given that, in many scenarios, the programming and datasets residing on the computers integral to the Fuel Management Systems are accessible to software engineers or the management personnel at the station, the private decryption key provided by the Controlling Entity might be better safeguarded within the fuel dispensers or the Forecourt Controller. This ensures only authorized transmission of unencrypted commands to a fuel dispenser.•
[0110] Either the Forecourt Controller manufacturers, the Fuel Dispenser manufacturers , or the Controlling Entity can embed a foundational encryption key. This key serves to cipher the EFDI, DSFDI, or EAC, and upon its decryption, introduces and retains one or several novel encryption keys. These can either supersede the original key(s) or expand the pool of keys tailored for diverse FDI and EAC encryption methodologies.•
[0111] Entities such as the Forecourt Controller manufacturers , Fuel Dispenser manufacturers , or the Controlling Entity can embed a primary decryption key. This key's purpose is to decrypt the executable software designated for the Microcontroller Unit (MCU) that orchestrates the functionalities of a Forecourt Controller or a Fuel Dispenser. Post this decryption, the system can introduce and retain one or several fresh decryption keys, either to replace the original key(s) or to decrypt newer executable software versions. Through this design, unauthorized modifications to aForecourt Controller' s or Fuel Dispenser' s operations— via illicit software injections into the MCU— are thwarted, as only software endorsed by the Controlling Entity can be executed.Relationship Between Specific Embodiments and the General Method Steps
[0112] The specific embodiments described below are closely related to the steps of the general method. Each embodiment illustrates a particular implementation or application of the general method, emphasizing how encryption keys, cryptographic operations, and secure data management enhance the security and reliability of fuel service station operations. Below is an explanation of how each embodiment aligns with specific steps of the method:
[0113] 1. Embedding Initial Encryption Keys
[0114] This embodiment involves the embedding of one or more initial encryption keys into Forecourt Controllers, Fuel Dispensers, or directly into the Controlling Entity. These keys are utilized to encrypt Fuel Dispensed Information (FDI) , Digitally Signed Fuel Dispensed Information (DSFDI) , or Encrypted Authorization Commands (EAC) . Additionally, these keys have the flexibility to decrypt and store new encryption keys, enabling dynamic updates to encryption strategies .
[0115] This embodiment aligns with step (a) :
[0116] It describes the initialization and secure embedding of encryption keys into system components, ensuring the keys are generated and securely stored to support cryptographic operations.
[0117] This embodiment aligns with step (b) :
[0118] The embedded keys are directly used to encrypt FDI, producing Tamper-Proof Fuel Dispensed Information (TPFDI) , thereby securing the data against tampering.
[0119] 2. Embedding Encryption Keys in MCUs for Secure Operations
[0120] In this embodiment, manufacturers embed encryption keys into microcontroller units (MCUs) within Forecourt Controllers or Fuel Dispensers. These keys are utilized to decrypt executable code or perform cryptographic operations. The MCU ensures that only authorized executable code is run, safeguarding the cryptographic integrity of the FDI and EAC processes.
[0121] This embodiment aligns with step (a) :
[0122] It complements the production of encryption keys by embedding them within tamper-proof MCUs during manufacturing or deployment, ensuring the keys remain secure throughout the system's lifecycle.
[0123] This embodiment aligns with step (b) :
[0124] The embedded keys are used for encrypting or digitally signing FDI, transforming it into TPFDI in a secure and controlled environment.
[0125] This embodiment aligns with step (e) :
[0126] The MCU uses the embedded keys to decrypt EACs received from the Controlling Entity, verifying their authenticity and integrity before execution.
[0127] 3. Generating EACs Based on Client-Specific Parameters
[0128] This embodiment focuses on the generation of Encrypted Authorization Commands (EACs) tailored to specific client parameters, such as credit constraints, prepaid fuelprovisions, or loyalty rewards. The EACs can be relayed to Fuel Dispensers through the Fuel Delivery Management System (FDMS) or directly via a secure link.
[0129] This embodiment aligns with step (c) :
[0130] It describes the receipt of EACs by Fuel Dispensers, Forecourt Controllers, or Fuel Tank Gauges, which is a critical part of secure operational workflows.
[0131] This embodiment aligns with step (e) :
[0132] The received EACs are decrypted at the respective system components, ensuring they are valid and unaltered.
[0133] This embodiment aligns with step (f) :
[0134] The decrypted EACs are executed to control operational parameters, such as fuel dispensation limits or inventory adjustments, as specified by the Controlling Entity .
[0135] 4. Embedding a Foundational Encryption Key for Dynamic Key Management
[0136] This embodiment describes the embedding of a foundational encryption key by manufacturers or the Controlling Entity. This key can encrypt FDI, DSFDI, or EACs and can introduce new encryption keys to replace or expand existing ones .
[0137] This embodiment aligns with step (a) :
[0138] It provides a secure foundation for managing encryption keys by embedding a foundational key that supports the production and management of additional keys.
[0139] This embodiment aligns with step (b) :
[0140] The foundational key is directly applied to encrypt or digitally sign FDI, ensuring the authenticity and integrity of the resulting TPFDI .
[0141] 5. Decrypting and Updating Executable Code inMCUs
[0142] In this embodiment, encryption keys embedded in MCUs are used to decrypt and securely store executable code received from the Controlling Entity. This ensures that only authorized software can be executed, preventing unauthorized modifications .
[0143] This embodiment aligns with step (e) :
[0144] The process of decrypting executable code aligns with the decryption of EACs, ensuring secure handling of encryption keys and validating the integrity of the system.
[0145] This embodiment aligns with step (f) :
[0146] By verifying the integrity of executable code, this embodiment ensures that operational commands and updates are securely executed, reinforcing the reliability of the system.Application-Specific Embodiments
[0147] The following section describes applicationspecific embodiments of the invention, illustrating practical implementations of the system that depend on the general method for operation. These embodiments do not introduce additional steps to the general method but demonstrate the versatility and adaptability of the invention in addressing specific operational scenarios within the fuel delivery ecosystem. Each embodiment leverages the results of the general method— such as the generation, transformation, and secure transmission of Tamper-Proof Fuel Dispensed Information (TPFDI)— to meet particular use cases, including electronic invoicing, regulatory compliance, and secure software updates. These examples highlight the flexibility ofthe invention and its capacity to enhance various aspects of fuel service station operations while maintaining data integrity and security.
[0148] Electronic Invoicing via Forecourt Controller or Fuel Dispenser
[0149] This embodiment features a Forecourt Controller or Fuel Dispenser equipped with integrated software that establishes a connection to the Controlling Entity for the transmission of FDI or TPFDI. In response, the Controlling Entity can transmit an electronic invoice in a digital format, such as HTML, either directly to the FDMS or through a Forecourt Controller. This electronic invoice, containing client and sales information along with a barcode encapsulating pertinent details, can then be archived in an FDMS database or printed as a hard copy.
[0150] Presently, some FDMS platforms transmit the FDI to the Controlling Entity using encrypted or digitally signed formats. However, in these current implementations, the Encryption Key is known to the fuel filling station or the developers of the FDMS software. While such cryptographic measures prevent unauthorized third-party access or interference, they still permit potential modifications to the genuine FDI data before encrypting it.Fiscal Forecourt Controller or Fuel Dispenser
[0151] This embodiment comprises a Forecourt Controller or Fuel Dispenser integrated with software that facilitates communication with a governmental Controlling Entity, enabling the transmission of FDI or TPFDI. This setup is in line with mandatory requirements for reporting fuel sales, detailing both purchaser information and identifying the seller and the source of the fuel dispensed.
[0152] In the current landscape, some FDMS platforms convey the FDI to the Controlling Entity. However, the transmission might take place through various software components within the FDMS, leading to potential data tampering. Although several FDMS implementations utilize encryption or digital signatures, the Encryption Key is often known to the fuel filling station or the FDMS software developers. While this cryptographic approach guards against unauthorized third-party interventions, it doesn't wholly preclude the potential alteration of the original FDI prior to its encryption.
[0153] In this proposed embodiment, the report utilizes TPFDI, which is generated by a device capable of both storing and executing cryptography. Notably, the Encryption Key is configured by the Controlling Entity, ensuring that the FDI remains untampered with by the FDMS. Secure Bridge Forecourt Controller or FDMS
[0154] A Forecourt Controller or FDMS designed as a "Secure Bridge" establishes a connection with the Controlling Entity. This connection facilitates the updating of new executable code within a Secure Fuel Dispenser (SFD) . This embodiment ensures a secure pathway for software updates, minimizing risks and vulnerabilities that might arise during code integration.
[0155] The current invention offers a comprehensive system to ensure tamper-proof fuel dispensation information. Through encryption keys, secure transmission pathways, and multiple preferred embodiments, the invention aims to revolutionize the fuel dispensing industry, upholding data integrity and security.Fuel Delivery Management System
[0156] The present invention further comprises a fuel delivery management system (FDMS) designed to securely manage fuel dispensed information (FDI) and authorization commands (EAC) within a fuel service station. The system employs advanced cryptographic assurance system (CAS) capabilities to ensure the integrity, authenticity, and confidentiality of critical data exchanged between its components. The FDMS includes the following elements:
[0157] 1. Forecourt Controller with Cryptographic Assurance System (CAS) Capabilities (101)
[0158] The forecourt controller (101) serves as the central node within the fuel delivery management system. It is equipped with cryptographic assurance system (CAS) capabilities, allowing it to securely process and manage FDI and EACs. This component ensures that data integrity and security are maintained throughout the system's operations.
[0159] The forecourt controller (101) includes cryptographic modules (102) that encrypt or digitally sign FDI received from fuel dispensers (201) or fuel tank gauges (301) , transforming it into Tamper-Proof Fuel Dispensed Information (TPFDI) . This transformation ensures the authenticity and protection of the data during storage or transmission. Additionally, the forecourt controller decrypts encrypted authorization commands (EACs) received from the controlling entity (401) , verifying their integrity and authenticity before transmitting them to the relevant devices .
[0160] The forecourt controller (101) incorporates a microcontroller unit (MCU) (103) with non-volatile memory (104) for securely storing encryption keys. These keys are critical for cryptographic operations, such as producing TPFDI and processing EACs. The non-volatile memory (104)protects the keys from unauthorized access, ensuring that they remain secure throughout the lifecycle of the system. Furthermore, the encryption keys used by the forecourt controller are controlled exclusively by the controlling entity (401) and are inaccessible to other components within the system.
[0161] The forecourt controller (101) also functions as a "Secure Bridge, " enabling the secure communication and updating of cryptographic keys and executable code between the controlling entity (401) and other components. This design prevents unauthorized modifications while ensuring the system remains adaptable to evolving operational requirements .
[0162] 2. Means for Receiving Fuel Dispensed Information (FDI) (202)
[0163] The system includes mechanisms (202) for securely receiving fuel dispensed information (FDI) from one or more fuel dispensers (201) or fuel tank gauges (301) . The FDI consists of critical transactional data, including the volume of fuel dispensed, transaction amounts, price per unit (PPU) , and totalizer values.
[0164] These mechanisms (202) ensure the secure transmission of FDI from its source to the forecourt controller (101) . The data is collected through secure communication pathways (105) , which protect it against interception or tampering. This initial step preserves the accuracy and reliability of the FDI before it is processed into TPFDI.
[0165] 3. Means for Encrypting or Digitally Signing the FDI to Produce TPFDI (102)
[0166] The system includes cryptographic modules (102) designed to encrypt or digitally sign the EDI, transforming it into Tamper-Proof Fuel Dispensed Information (TPFDI) . This transformation ensures the integrity and authenticity of the data, making it tamper-proof for subsequent transmission or storage .
[0167] The cryptographic operations are carried out within secure modules (102) integrated into the forecourt controller (101) . Robust cryptographic algorithms, such as Advanced Encryption Standard (AES) or Public Key Encryption (PKE) , are employed to protect the data. In cases where digital signatures are used, unauthorized modifications can be detected immediately, adding an additional layer of security .
[0168] This process is designed to be seamless and efficient, integrating smoothly into the operational workflow of the fuel service station without causing disruptions.
[0169] 4. Means for Communicating the TPFDI to a Controlling Entity (401)
[0170] The system incorporates mechanisms (106) for securely transmitting TPFDI to the controlling entity (401) . This communication occurs via secure channels (107) designed to protect the data from unauthorized access or interception during transit.
[0171] The forecourt controller (101) acts as the intermediary, transmitting the TPFDI generated within the system to the controlling entity (401) . Once received, the TPFDI is used by the controlling entity for various purposes, including auditing, compliance with regulatory requirements, and operational oversight. The secure transmission ensuresthat the data remains authentic and unaltered throughout the communication process.
[0172] 5. Means for Decrypting EACs and Transmitting Them to Fuel Dispensers or Fuel Tank Gauges (201, 301)
[0173] The system includes capabilities (103, 104) for decrypting encrypted authorization commands (EACs) received from the controlling entity (401) and securely transmitting them to the appropriate devices, such as fuel dispensers (201) or fuel tank gauges (301) .
[0174] The forecourt controller (101) decrypts the EACs, verifying their integrity and authenticity before relaying them to the relevant components (201, 301) . These commands dictate operational parameters, such as fuel dispensing limits or inventory adjustments. The secure decryption and transmission of EACs ensure that only authorized instructions are executed, maintaining the reliability and security of the system' s operations.[Detailed Functional Description of the Fuel Delivery Management System
[0176] The following section provides a detailed functional description of each component within the Fuel Delivery Management System (FDMS) . Each component is analyzed in terms of its role within the system, the information it receives, the information it produces, and the transmission of data to and from other elements.
[0177] 1. Forecourt Controller with Cryptographic Assurance System (CAS) Capabilities (101)
[0178] Function : Serves as the central node of the system, managing and processing fuel dispensed information (FDI) and authorization commands (EAC) using cryptographic capabilities .
[0180] Ensures the integrity and authenticity of information through encryption and digital signing.
[0181] Decrypts authorization commands (EACs) before transmitting them to the relevant devices.
[0182] Information Received:
[0183] Receives: EDI from fuel dispensers (201) and fuel tank gauges (301) .
[0183] Receives: Encrypted EACs from the Controlling Entity (401) .
[0184] Information Produced:
[0185] Produces: Tamper-Proof Fuel Dispensed Information (TPFDI) through the transformation of FDI .
[0186] Produces: Decrypted EACs.
[0187] Data Transmission:
[0188] Sends: TPFDI to the Controlling Entity (401) via secure communication channels (107) .
[0189] Sends: Decrypted EACs to fuel dispensers (201) or fuel tank gauges (301) .
[0190] 2. Means for Receiving Fuel Dispensed Information (FDI) (202, 302)
[0191] Function:
[0192] Collects fuel dispensed information (FDI) from fuel dispensers (201) or fuel tank gauges (301) for further processing .
[0193] Information Received:
[0194] Receives: FDI, which includes data such as the volume of fuel dispensed, transaction amounts, price per unit (PPU) , and totalizer values.
[0195] Source: Fuel dispensers (201) and fuel tank gauges ( 301 ) .
[0196] Information Produced:
[0197] Produces: Unaltered FDI, which is transmitted to the Forecourt Controller (101) .
[0198] Data Transmission:
[0199] Sends: FDI to the Forecourt Controller (101) via secure communication pathways (105) .
[0200] 3. Means for Encrypting or Digitally Signing the FDI to Produce TPFDI (102)
[0201] Function:
[0202] Converts received FDI into TPFDI using encryption or digital signing to ensure its integrity and authenticity.
[0203] Information Received:
[0204] Receives: FDI from the mechanism for receiving information (Means for Receiving FDI: 202, 302) .
[0205] Source: Forecourt Controller (101) or directly from fuel dispensers (201) / fuel tank gauges (301) .
[0206] Information Produced:
[0207] Produces: TPFDI, a secure and tamper-proof data format .
[0208] Data Transmission:
[0209] Sends: TPFDI to the Controlling Entity (401) via secure communication channels (107) managed by the Forecourt Controller (101) .
[0210] 4. Means for Communicating the TPFDI to aControlling Entity (106)
[0211] Function:
[0212] Transmits generated TPFDI to the Controlling Entity (401) for purposes such as auditing, regulatory compliance, and operational oversight.
[0213] Information Received:
[0214] Receives: TPFDI from the encryption or digital signing mechanism (Means for Encrypting or Digitally Signing FDI : 102) .
[0215] Source: Forecourt Controller (101) .
[0216] Information Produced:
[0217] Produces: Verified TPFDI in a secure and reliable format for use by the Controlling Entity (401) .
[0218] Data Transmission:
[0219] Sends: TPFDI to the Controlling Entity (401) via secure communication channels (107) .
[0220] 5. Means for Decrypting EACs and Transmitting Them to Fuel Dispensers or Fuel Tank Gauges (103, 104)
[0221] Function:
[0222] Decrypts encrypted authorization commands (EACs) received from the Controlling Entity (401) and transmits them to the appropriate devices for execution.
[0223] Information Received:
[0224] Receives: Encrypted EACs from the Controlling Entity (401) .
[0225] Source: Controlling Entity (401) via the Forecourt Controller (101) .
[0226] Information Produced:
[0227] Produces: Decrypted EACs ready for execution.
[0228] Data Transmission:
[0229] Sends: Decrypted EACs to fuel dispensers (201) or fuel tank gauges (301) for execution.Description! of the Fuel Dispenser
[0230] The present invention further comprises a fuel dispenser eguipped with cryptographic assurance system (CAS) capabilities. This dispenser securely manages fuel dispensed information (FDI) and encrypted authorization commands (EAC) to ensure the integrity, authenticity, and confidentiality ofcritical data. The dispenser integrates the following elements :•
[0231] Dispensing Mechanisms for FDI Generation (501)
[0232] The dispensing mechanisms serve as the starting point for the fuel dispensing process, generating Fuel Dispensed Information (FDI) as part of their operation. These mechanisms calculate essential transactional data, including the volume of fuel dispensed, transaction amounts, and totalizer values.
[0233] Function:
[0234] Dispenses fuel and generates FDI based on the operations performed.
[0235] Information Received:
[0236] Receives operational commands, such as start or stop signals, from the forecourt controller (101) or the controlling entity (401) .
[0237] Information Produced:
[0238] Produces FDI, which includes transactional and volumetric data.
[0239] Data Transmission:
[0240] Sends FDI to the cryptographic module (502) for secure transformation into Tamper-Proof Fuel Dispensed Information (TPFDI) .•
[0241] Cryptographic Module for Encrypting or Digitally Signing FDI (502)
[0242] The cryptographic module securely transforms the raw FDI into a tamper-proof format. This module ensures that the FDI remains unaltered and authentic during transmission and storage .
[0243] Function:
[0244] Encrypts or digitally signs the EDI to produce Tamper-Proof Fuel Dispensed Information (TPFDI) .
[0245] Provides security for operational parameters defined in the EACs, such as maximum allowable fuel volume, price per unit, and fuel type specifications.
[0246] Information Received:
[0247] Receives FDI from the dispensing mechanisms (501) .
[0248] Information Produced:Produces TPFDI, a secure and tamper-proof format of the FDI .
[0249] Data Transmission:
[0250] Sends TPFDI to the transmission mechanisms (503) for communication with the forecourt controller (101) or the controlling entity (401) .•
[0251] Transmission Mechanisms for TPFDI (503)
[0252] The transmission mechanisms ensure that the TPFDI is securely communicated to external components, maintaining the confidentiality and authenticity of the data.
[0253] Function:
[0254] Transmits TPFDI to the forecourt controller (101) or directly to the controlling entity (401) via secure communication channels.
[0255] Information Received:
[0256] Receives TPFDI from the cryptographic module (502) .
[0257] Information Produced:
[0258] Produces TPFDI prepared for external communication .
[0259] Data Transmission:
[0260] Sends TPFDI to the forecourt controller (101) or the controlling entity (401) through secure channels (107) . •
[0261] Mechanisms for Decrypting EACs (504)
[0262] The decryption mechanisms process encrypted authorization commands (EACs) received from the forecourt controller (101) or the controlling entity (401) . These commands dictate operational parameters for the fuel dispensing process.
[0263] Function:
[0264] Decrypts EACs and verifies their authenticity and integrity before execution.
[0265] Information Received:
[0266] Receives encrypted EACs from the forecourt controller (101) or the controlling entity (401) .
[0267] Information Produced:
[0268] Produces decrypted EACs ready for execution.
[0269] Data Transmission:
[0270] Sends operational parameters defined in the decrypted EACs to the dispensing mechanisms (501) for execution .
[0271] Conclusion
[0272] The described fuel dispenser equipped with cryptographic assurance system (CAS) capabilities ensures secure and reliable management of fuel dispensed information (EDI) and authorization commands (EAC) . By integrating robust cryptographic operations, this dispenser enhances the security, authenticity, and compliance of fuel service station operations. Each element interacts seamlessly to maintain the integrity and confidentiality of data, reinforcing the overall reliability of the fuel dispensing process .System for securely updating executable code in a fuel dispenser or a forecourt controller
[0273] The present invention also comprises a system for securely updating executable code in a fuel dispenser or a forecourt controller. This system ensures the integrity, authenticity, and confidentiality of the executable code, preventing unauthorized access or tampering. The system leverages advanced cryptographic assurance system (CAS) capabilities and includes the following elements:
[0274] 1. Secure Bridge Between the Fuel Dispenser or Forecourt Controller and the Controlling Entity (601)
[0275] Function:
[0276] The secure bridge serves as the communication channel between the fuel dispenser or forecourt controller and the controlling entity. It facilitates the secure transmission of encrypted executable code and ensures data integrity during transit.
[0277] Information Received:
[0278] Receives: Encrypted executable code from the controlling entity (401) .
[0279] Information Produced:
[0280] Produces: Transmitted encrypted executable code verified for integrity.
[0281] Data Transmission:
[0282] Sends: Encrypted executable code to the receiving mechanisms (602) for further processing.
[0283] 2. Means for Receiving Encrypted New Executable Code (602)
[0284] Function:
[0285] This component temporarily captures and stores the encrypted executable code received from the secure bridge. It ensures that the code is securely handled before decryption and verification.
[0286] Information Received:
[0287] Receives: Encrypted executable code from the secure bridge (601) .
[0288] Information Produced:
[0289] Produces: Prepared encrypted executable code ready for decryption.
[0290] Data Transmission:
[0291] Sends: Encrypted executable code to the decryption and storage mechanisms (603) .
[0292] 3. Means for Decrypting and Securely StoringExecutable Code (603)
[0293] Function:
[0294] This mechanism decrypts the received executable code to make it usable by the system. It securely stores the decrypted code in tamper-proof memory to ensure its integrity and protection.
[0295] Information Received:
[0296] Receives: Encrypted executable code from the receiving mechanisms (602) .
[0297] Information Produced:
[0298] Produces: Decrypted executable code ready for verification and use.
[0299] Data Transmission:
[0300] Sends: Decrypted executable code to the verification mechanisms (604) .
[0301] 4. Means for Verifying the Integrity andAuthenticity of the Executable Code (604)
[0302] Function:
[0303] This component validates the integrity and authenticity of the decrypted executable code using cryptographic assurance system (CAS) capabilities. It ensures that only authorized and unaltered software is used within the system.
[0304] Information Received:
[0305] Receives: Decrypted executable code from the decryption mechanisms (603) .
[0306] Information Produced:
[0307] Produces: Verified executable code ready for secure storage and execution.
[0308] Data Transmission:
[0309] Sends: Verified executable code to the internal memory of the fuel dispenser or forecourt controller for execution .
[0310] Additional Material Incorporated from General Description
[0311] Role of the Secure Bridge (601) :
[0312] Utilizes encryption methods, such as AES or digital signatures, to ensure secure communication between the controlling entity and the fuel dispenser or forecourt controller .
[0313] Integration with the Controlling Entity (401) :
[0314] The controlling entity serves as the source of the encrypted executable code, securely dispatching it through the secure bridge to the receiving mechanisms.
[0315] Tamper-Proof Storage:
[0316] The decrypted executable code is stored in tamper-proof memory, ensuring its protection against unauthorized access or manipulation.
[0317] The described system for securely updating executable code in a fuel dispenser or forecourt controller ensures the secure transmission, decryption, validation, and storage of critical software components. By incorporating advanced cryptographic assurance capabilities, the system prevents unauthorized tampering or execution of malicious code, maintaining the security and reliability of fuel delivery operations. This description aligns with the provided claims and integrates seamlessly with the broader invention framework.Fuel Tank Gauge Equipped with Cryptographic Assurance System (CAS) Capabilities
[0318] The present invention also includes a Fuel Tank Gauge equipped with Cryptographic Assurance System (CAS) capabilities. This system ensures the integrity, authenticity, and confidentiality of critical data related to fuel inventory levels and refueling events. Each component of the system is described below:•
[0319] Means for Measuring and Reporting Fuel Inventory
[0320] Levels and Refueling Events (701)
[0321] The fuel tank gauge includes a mechanism designed to measure fuel inventory levels with high precision and detect refueling events. This component is crucial for monitoring the status of the fuel inventory and recording operational data.
[0322] Function: Measures fuel levels and monitors refueling events in the tank, providing critical inventory data .
[0323] Information Received: Receives raw measurement data directly from the fuel tank's physical conditions.
[0324] Information Generated: Produces fuel inventory data, including current levels and refueling events.
[0325] Data Transmission: Sends the generated inventory data to the cryptographic module (702) for secure processing.•
[0326] Cryptographic Module for Encrypting or DigitallySigning Inventory Data to Produce Tamper-Proof Inventory Reports (702)
[0327] The cryptographic module is responsible for transforming the inventory data into secure, tamper-proof inventory reports (TPIR) by applying encryption or digital signatures. This ensures the integrity and authenticity of the data, preventing unauthorized alterations.
[0328] Function: Converts raw inventory data into TPIR by encrypting or digitally signing the data. Information Received: Receives inventory data from the measuring and reporting mechanism (701) .Information Generated: Produces tamper-proof inventory reports (TPIR) that are secure against tampering or interception .
[0329] Data Transmission: Sends the TPIR to the transmission mechanism (703) for delivery to the controlling entity or forecourt controller.
[0330] Means for Transmitting Tamper-Proof Inventory Reports (TPIR) to a Forecourt Controller or Controlling Entity (703)
[0331] This component is designed to transmit the tamper-proof inventory reports (TPIR) to the forecourt controller or directly to the controlling entity via secure communication pathways. The transmission mechanism ensures the data remains protected from unauthorized access during transit .
[0332] Function: Transmits TPIR to the forecourt controller or controlling entity for operational and compliance purposes.
[0333] Information Received: Receives TPIR from the cryptographic module (702) .
[0334] Information Generated: Produces securely transmitted TPIR ready for use by the receiving entity.
[0335] Data Transmission: Sends TPIR to the forecourt controller or directly to the controlling entity through secure channels.•
[0336] Means for Decrypting Encrypted AuthorizationCommands (EAC) Received from a Forecourt Controller or Controlling Entity (704)
[0337] The system includes a decryption mechanism that processes encrypted authorization commands (EAC) received from the forecourt controller or the controlling entity. This ensures that the instructions can be securely executed without risk of tampering.
[0338] Function: Decrypts encrypted EAC to allow secure execution of commands related to inventory adjustments or operational configurations.
[0339] Information Received: Receives encrypted EAC from the forecourt controller or controlling entity.
[0340] Information Generated: Produces decrypted EAC ready for implementation within the system.
[0341] Data Transmission: Sends decrypted EAC to internal systems responsible for executing the instructions. Conclusion
[0342] The Fuel Tank Gauge equipped with CAS capabilities is a vital component of the fuel delivery ecosystem. Its components work in tandem to measure and securely manage inventory data, protect the integrity ofoperational commands, and ensure compliance with security and operational requirements. This description provides a detailed explanation of each element's role, the information it processes, and its integration into the broader system, fully supported by the provided claims and descriptions.
[0343] Finally, the discussion included in this detailed description is intended to serve as a basic description. The reader should be aware that the specific discussion may not explicitly describe all embodiments possible and alternatives are implicit. Also, this discussion may not fully explain the generic nature of the invention and may not explicitly show how each feature or element can actually be representative or equivalent elements. Again, these are implicitly included in this disclosure. Where the invention is described in device-oriented terminology, each element of the device implicitly performs a function. It should also be understood that a variety of changes may be made without departing from the essence of the invention. Such changes are also implicitly included in the description. These changes still fall within the scope of this invention.
[0344] Further, each of the various elements of the invention and claims may also be achieved in a variety of manners. This disclosure should be understood to encompass each such variation, be it a variation of any apparatus embodiment, a method embodiment, or even merely a variation of any element of these. Particularly, it should be understood that as the disclosure relates to elements of the invention, the words for each element may be expressed by equivalent apparatus terms even if only the function or result is the same. Such equivalent, broader, or even more generic terms should be considered to be encompassed in the description of each element or action. Such terms can besubstituted where desired to make explicit the implicitly broad coverage to which this invention is entitled. It should be understood that all actions may be expressed as a means for taking that action or as an element which causes that action. Similarly, each physical element disclosed should be understood to encompass a disclosure of the action which that physical element facilitates. Such changes and alternative terms are to be understood to be explicitly included in the description .
Claims
What is claimed is :
1. A fuel delivery management system comprising: a station controller equipped with a Cryptographic Assurance System (CAS) configured to manage operational data and commands ; means for receiving fuel dispensed information (FDI) from one or more fuel dispensers or tank gauges; means for encrypting or digitally signing the FDI using cryptographic algorithms selected from the group consisting of Advanced Encryption Standard (AES) and Public Key Encryption (PKE) to generate Tamper-Proof Fuel Dispensed Information (TPFDI) ; means for transmitting the TPFDI to a controlling entity via secure communication channels; means for receiving and decrypting encrypted authorization commands (EAC) from the controlling entity and transmitting them to fuel dispensers or tank gauges; wherein the system prevents unauthorized tampering with the FDI and EAC data by securing cryptographic keys in nonvolatile memory within the station controller.
2. The system of Claim 1, wherein the controller includes a microcontroller unit (MCU) equipped with non-volatile memory configured to securely store encryption keys and digitally sign the FDI prior to transmission.
3. The system of Claims 1 or 2, wherein the cryptographic keys are exclusively provided and managed by the controlling entity and are protected from unauthorized access through tamper-proof hardware configurations.
4. A fuel dispenser equipped with a Cryptographic Assurance System (CAS) , comprising: a mechanism for dispensing fuel and calculating fuel dispensed information (FDI) , including data such as volume, transaction amount, and totalizer values; a cryptographic module configured to encrypt or digitally sign the FDI to generate Tamper-Proof Fuel Dispensed Information (TPFDI) ; means for transmitting the TPFDI to a station controller or directly to a controlling entity; means for receiving and decrypting encrypted authorization commands (EAC) from a station controller or controlling entity, and executing operational parameters defined in the EAC; wherein the cryptographic module secures operational parameters such as maximum allowable fuel volume, price per unit, and fuel type specifications, protecting them from tampering .
5. The fuel dispenser of Claim 4, wherein the cryptographic module includes a secure hardware element configured to prevent unauthorized access to cryptographic keys or processes.
6. A method for securely managing fuel dispensation and inventory data at a service station, comprising: receiving fuel dispensed information (FDI) from a fuel dispenser or tank gauge; encrypting or digitally signing the FDI using cryptographic algorithms selected from the group consisting of AES and PKE to generate Tamper-Proof Fuel Dispensed Information (TPFDI) ;transmitting the TPFDI to a controlling entity via a secure communication channel; receiving encrypted authorization commands (EAC) from the controlling entity; decrypting the EAC at the fuel dispenser, tank gauge, or station controller; executing the decrypted EAC to control fuel dispensing or inventory reporting operations; wherein each operation is secured against tampering by using cryptographic keys stored in tamper-proof non-volatile memory .
7. The method of Claim 6, further comprising securely storing the encryption keys used for encrypting the EDI or processing the EAC in tamper-proof non-volatile memory within the fuel dispenser, tank gauge, or station controller.
8. A system for securely updating executable code in a fuel dispenser or station controller, comprising: a secure link between the fuel dispenser or station controller and a controlling entity; means for receiving encrypted new executable code from the controlling entity; means for decrypting and securely storing the executable code within the fuel dispenser or station controller; means for verifying the integrity and authenticity of the executable code using a Cryptographic Assurance System ( CAS ) ; wherein the secure link utilizes CAS-based encryption to prevent unauthorized access or tampering with the code during transmission or storage.
9. The system of Claim 8, wherein the secure link employs CAS-based encryption algorithms selected from AES and PKE, ensuring end-to-end integrity and confidentiality of transmitted executable code.
10. A tank gauge equipped with a Cryptographic Assurance System (CAS) , comprising: means for measuring and reporting fuel inventory levels and refueling events; a cryptographic module configured to encrypt or digitally sign inventory data to generate Tamper-Proof Inventory Reports (TPIR) ; means for transmitting the TPIR to a station controller or directly to a controlling entity; means for receiving and decrypting encrypted authorization commands (EAC) from a station controller or controlling entity; wherein the tank gauge ensures the integrity and authenticity of inventory data and commands using cryptographic methods .
Citation Information
Patent Citations
Fuel dispenser utilizing tokenized user guidance and prompting for secure payment
US20220351308A1
Multimode retail system
US20230146404A1
Utilization of biometrics in creation of secure key or digital signature
US20230177489A1