Secure Controller Architecture for Fuel Dispenser Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fuel dispensers face challenges in securely handling sensitive payment information, leading to complex and costly certification processes for changes to the controller, which can impact other functions and require recertification.

Innovation Solution

The implementation of a secure controller that operates separately from other components, such as a display, to manage access and communications, ensuring secure handling of sensitive information without requiring recertification of other components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the controller is configured to handle sensitive payment information, then security requirements are met, but any changes to the controller design require recertification which is protracted and expensive

Engineering Contradiction:
ImprovesecurityVSAvoidcertification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the user interface into separate functional components: a display controller that handles general display functions and a secure controller that handles sensitive payment information. This segmentation allows the display controller to be modified without triggering recertification, as long as the secure controller's handling of payment data remains unchanged.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure controller is extracted as a distinct component from the overall user interface system. By isolating the payment information handling functions in a separate secure controller, the patent enables independent modification of other components without affecting the certification status of the payment processing subsystem.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the controller handles sensitive payment information, then payment processing is secure, but changes to the controller impact other functions and require recertification

Engineering Contradiction:
Improvepayment information securityVSAvoidcomponent modification capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The user interface is segmented into independent functional modules with clearly defined boundaries. The display controller manages non-sensitive functions while the secure controller manages payment information, allowing each module to be developed, modified, and maintained independently without affecting the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure controller acts as an intermediary between the display controller and the payment processing subsystem. It receives display data from the display controller, processes it through security protocols, and only allows authorized display of payment-related information, thereby protecting sensitive data while enabling functional integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If all components are integrated in one controller, then system integration is simple, but security requirements for payment information increase complexity and certification costs

Engineering Contradiction:
Improvecontroller integrationVSAvoidpayment information security compliance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Rather than integrating all functions in one controller, the system strategically segments the controller into a display controller and a secure controller. This segmentation maintains manageable system complexity while ensuring that payment information handling meets security requirements through dedicated secure processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure controller is designed as a universal component that can work with various display controllers and user interface configurations. This multi-functionality allows the same secure controller to be used across different fuel dispenser models and interface types, reducing overall system complexity while maintaining security compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4266277B1Fuel dispenser user interface system architecture
Publication Date: 2025.01.22 GILBARCO SRL
  • EP4266277B1 patent drawingFigure 1
  • EP4266277B1 patent drawingFigure 2
  • EP4266277B1 patent drawingFigure 3A

AI summary

A vending machine user interface can include a first controller operatively connected to an input device capable of receiving payment or account information. The first controller can, with another device, via a second controller, or otherwise, allow secure communication of data from the input device. The first controller, in this regard, can control the communication between the input device and the other device to protect the input device from unwarranted communication from the other device. The first controller can establish a secure channel with the other device using encrypted communications. The first controller, second controller, etc. can be connected to independent printed circuit boards (PCB). Activation of sensors connected to the PCBs can cause the first and/or second controllers to erase data necessary to ascertain/decode communications from the input device, such as encryption/decryption information, or may otherwise decommission the input device or a portion thereof.