Online Authorization Gate Access Device for Transit Fare Collection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Transit fare collection systems face challenges with slow transaction processing times, security risks, and fraud prevention due to the use of off-line contactless payment card transactions, which are not authenticated and lack real-time authorization, leading to issues with counterfeiting, negative balances, and data security compliance.
Innovation Solution
Implementing an on-line authorization process that directly connects gate access devices to payment processing networks, allowing for immediate card authentication and authorization, reducing the need for negative lists and enhancing data security by using cryptograms and issuer verification, thereby enabling faster transaction times and improved fraud detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If off-line contactless payment card transactions are used, then transaction speed is improved (300ms or less), but security and fraud prevention deteriorate (no card authentication, potential for counterfeiting)
Solution Approach 1:
The system performs preliminary card authentication and authorization checks before allowing transaction processing. The gate access device verifies card validity, checks negative lists, and authenticates cardholders in advance, ensuring security measures are in place before the actual transaction occurs, thus maintaining both speed and security
Solution Approach 2:
The patent introduces an intermediary authorization system that acts as a mediator between the contactless payment card and the fare collection system. This intermediary layer performs authentication and verification functions, including checking against negative lists and validating card authenticity, without significantly impacting transaction speed
2Loss of time
If off-line transactions are used, then transaction time is reduced, but fraud detection capability deteriorates (transactions not approved in real time, lost/stolen/counterfeit cards cannot be blocked)
Solution Approach 1:
The system implements feedback mechanisms where transaction data is continuously monitored and analyzed. The authorization system receives real-time information about card status, negative list updates, and fraud patterns, allowing the system to respond dynamically to emerging threats while maintaining fast transaction processing through pre-established authentication protocols
3Reliability
If negative lists are used to prevent fraud, then fraud prevention is improved, but device complexity and memory requirements worsen (negative list must grow unbounded, memory space limited, search time prohibitive)
Solution Approach 1:
The patent segments the negative list management into multiple components: a compact local negative list stored in the gate access device for immediate checks, and a comprehensive central negative list maintained by the authorization system. This segmentation allows the local device to maintain low complexity while still providing effective fraud prevention through coordinated checking against both lists
Solution Approach 2:
The system extracts the bulk of negative list data and management functions from the gate access device and places them in the centralized authorization system. This extraction reduces the memory and processing requirements at the gate level, allowing the negative list to grow unbounded in the central system without impacting device complexity or search time at the access points
4Adaptability or versatility
If contactless payment card data is collected and stored, then transaction capability is improved, but data security compliance worsens (PCI/DSS compliance difficult, costly encryption systems required)
Solution Approach 1:
The patent extracts sensitive cardholder data collection and storage functions from the transit fare collection system and places them entirely within the contactless payment card and centralized authorization system. The gate access device only processes authentication tokens and transaction authorizations, never storing actual card data, thereby eliminating PCI/DSS compliance requirements while maintaining full transaction capability
Solution Approach 2:
The system introduces an intermediary authorization layer that handles all sensitive data processing between the contactless card and the fare collection system. This intermediary performs tokenization and data protection functions, allowing the transit system to benefit from contactless payment capabilities without directly handling or storing sensitive cardholder data, thus avoiding costly encryption infrastructure
Data Source
AI summary
A method is disclosed. The method includes interacting with a gate access device that is capable of preventing access to a location, where the gate access device subsequently sends an authorization request message to an issuer for approval, the authorization request message including a request to charge a predetermined amount of money to pay for access to a location, and entering the location if the gate access device receives an authorization response message indicating that the charge is authorized.


