MaaS Publisher Node Authentication via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Mobility-as-a-Service (MaaS) platforms face security concerns and operational bottlenecks due to insecure access of new ticketing terminals, leading to prolonged repair times and operational disruptions.

Innovation Solution

A system and method for secure access management of publisher nodes in the MaaS network using a server-based authentication and authorization system, which includes a publisher node device transmitting authentication credentials and receiving authorization to ensure only validated devices access the network, preventing counterfeit or insecure devices and facilitating secure data ownership among transportation providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If new ticketing terminals are deployed to meet demand or replace faulty devices, then service availability is improved, but security risks increase due to insecure access methods

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and authorization actions before allowing ticketing terminals to access the MaaS network. Devices must undergo identity verification, certificate validation, and authorization checks prior to network access, preventing insecure devices from joining the network while maintaining rapid deployment capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An authentication server acts as an intermediary between ticketing terminals and the MaaS network. This mediator verifies device identities, validates security certificates, and manages authorization protocols, enabling secure access without requiring direct trust between terminals and network components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If faulty ticketing terminals are repaired or replaced, then network reliability is improved, but operational time increases due to lengthy repair and operationalization processes

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidrepair time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service operationalization where new or repaired ticketing terminals automatically undergo authentication and authorization processes without manual intervention. The automated provisioning system handles device registration, certificate validation, and network configuration automatically, significantly reducing operational time while ensuring reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authentication and authorization actions are performed preliminarily before device operationalization. By validating device identities and security certificates in advance, the system enables rapid deployment of repaired or new terminals without time-consuming verification processes during operationalization.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If authentication and authorization systems are implemented for publisher nodes, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

An authentication server serves as an intermediary that handles complex authentication and authorization logic externally. Ticketing terminals only need to present their identity and certificate, while the server manages the complex verification protocols, reducing the complexity burden on individual devices while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server provides universal authentication and authorization services to all ticketing terminals regardless of their specific implementations. This multi-functional system handles various authentication methods, certificate validations, and authorization checks through a single unified platform, simplifying device requirements while ensuring comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4154441B1Access management of publisher nodes for secure access to maas network
Publication Date: 2024.03.13 SONY GROUP CORP
  • EP4154441B1 patent drawingFigure 1
  • EP4154441B1 patent drawingFigure 2
  • EP4154441B1 patent drawingFigure 3

AI summary

A system including a server and a first publisher node device is provided. The first publisher node device transmits a request including an authentication credential associated with the first publisher node device to the server and receives a response including authentication of the first publisher node device as a ticket processing client for a first transportation service. The first publisher node device captures, as the ticket processing client, an event associated with the first transportation service based on the received response and transmits, based on the captured event, a transaction request to a broker node device. The transaction request includes a transaction message and an authorization request to route the transaction message to a first subscriber node device of the MaaS network. The server receives the authorization request from the broker node device and authorizes the broker node device to route the transaction message based on the received authorization request.