Fuel Dispenser Security via Encrypted Challenge-Response Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing fuel dispenser security systems are vulnerable to unauthorized access and tampering, as they rely on simple passwords and mechanical seals that can be easily circumvented by malicious parties.

Innovation Solution

A secure authentication process is implemented, where users are presented with an encrypted challenge that requires a session password obtained from a server, which authenticates the user and controls access based on privileges, using a unique secret key for each fuel dispenser and a secure element for key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simple passwords and mechanical seals are used for fuel dispenser security, then ease of operation is improved, but reliability of security is worsened

Engineering Contradiction:
Improveease of accessVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces mechanical security systems (physical locks, mechanical seals) with an electronic authentication system that uses encrypted challenges, secret keys, and session passwords. This substitution maintains ease of operation through electronic interfaces while dramatically improving security reliability through cryptographic protection against unauthorized access

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the security parameter from static mechanical states (locked/unlocked, sealed/unsealed) to dynamic cryptographic parameters (encrypted challenges, session passwords, authentication tokens). This allows the system to maintain user-friendly operation while providing robust security through changing cryptographic states that cannot be easily circumvented

Inventive Principle:
Principle #35Parameter changes

2Reliability

If feature-specific access control is implemented, then security reliability is improved, but device complexity is worsened

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments access control into feature-specific permissions, where different users have different levels of access to specific functions (calibration, diagnostics, configuration). This segmentation is implemented through a structured authentication system that evaluates user credentials against required access levels for each protected function, providing fine-grained security control

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between users and protected functions. The system uses encrypted challenges and session passwords as intermediaries to verify user credentials and grant appropriate access rights, abstracting the complexity of feature-specific control from the user interface while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3609159B1Systems and methods for fuel dispenser security
Publication Date: 2022.08.10 DOVER FUELING SOLUTIONS UK LTD
  • EP3609159B1 patent drawingFigure 1~2
  • EP3609159B1 patent drawingFigure 3
  • EP3609159B1 patent drawingFigure 4

AI summary

Systems and methods for fuel dispenser security are disclosed herein. In some embodiments, a user seeking access to a protected function of the fuel dispenser is presented with a challenge that is encrypted using a secret key that is unique to the fuel dispenser. To access the secured function, the user must obtain a session password from a server which authenticates the user, decrypts the challenge using a counterpart of the secret key, determines whether the user is authorized to access the secured function, and returns the session password extracted from the challenge only when the user is authorized. The server can thus control access to certain fuel dispenser functions according to a set of user access privileges. The challenge can also include additional information which can be used by the fuel dispenser and/or by the server to store a log of access activity.