MaaS Publisher Node Authentication via Intermediary Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional Mobility-as-a-Service (MaaS) platforms face security concerns and operational bottlenecks due to insecure access of new ticketing terminals, leading to prolonged repair times and operational disruptions.
Innovation Solution
A system and method for secure access management of publisher nodes in the MaaS network using a server-based authentication and authorization system, which includes a publisher node device transmitting authentication credentials and receiving authorization to ensure only validated devices access the network, preventing counterfeit or insecure devices and facilitating secure data ownership among transportation providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If new ticketing terminals are deployed to meet demand or replace faulty devices, then service availability is improved, but security risks increase due to insecure access methods
Solution Approach 1:
The system performs preliminary authentication and authorization actions before allowing ticketing terminals to access the MaaS network. Devices must undergo identity verification, certificate validation, and authorization checks prior to network access, preventing insecure devices from joining the network while maintaining rapid deployment capabilities.
Solution Approach 2:
An authentication server acts as an intermediary between ticketing terminals and the MaaS network. This mediator verifies device identities, validates security certificates, and manages authorization protocols, enabling secure access without requiring direct trust between terminals and network components.
2Reliability
If faulty ticketing terminals are repaired or replaced, then network reliability is improved, but operational time increases due to lengthy repair and operationalization processes
Solution Approach 1:
The system enables self-service operationalization where new or repaired ticketing terminals automatically undergo authentication and authorization processes without manual intervention. The automated provisioning system handles device registration, certificate validation, and network configuration automatically, significantly reducing operational time while ensuring reliability.
Solution Approach 2:
Authentication and authorization actions are performed preliminarily before device operationalization. By validating device identities and security certificates in advance, the system enables rapid deployment of repaired or new terminals without time-consuming verification processes during operationalization.
3Object-affected harmful factors
If authentication and authorization systems are implemented for publisher nodes, then security is improved, but device complexity increases
Solution Approach 1:
An authentication server serves as an intermediary that handles complex authentication and authorization logic externally. Ticketing terminals only need to present their identity and certificate, while the server manages the complex verification protocols, reducing the complexity burden on individual devices while maintaining strong security.
Solution Approach 2:
The authentication server provides universal authentication and authorization services to all ticketing terminals regardless of their specific implementations. This multi-functional system handles various authentication methods, certificate validations, and authorization checks through a single unified platform, simplifying device requirements while ensuring comprehensive security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system including a server and a first publisher node device is provided. The first publisher node device transmits a request including an authentication credential associated with the first publisher node device to the server and receives a response including authentication of the first publisher node device as a ticket processing client for a first transportation service. The first publisher node device captures, as the ticket processing client, an event associated with the first transportation service based on the received response and transmits, based on the captured event, a transaction request to a broker node device. The transaction request includes a transaction message and an authorization request to route the transaction message to a first subscriber node device of the MaaS network. The server receives the authorization request from the broker node device and authorizes the broker node device to route the transaction message based on the received authorization request.