Secure Transaction System for Road Tolling Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current road tolling systems using GPS and GSM are vulnerable to tampering, allowing users to falsify their location and distance traveled, compromising the integrity of data transactions between remote devices and servers, which affects security, privacy, and cost accuracy.
Innovation Solution
A system comprising a server and a remote device that implements a secure transaction process using encryption algorithms to verify the integrity of data processing, involving input data processing, storage of verification information, and communication of processed data to ensure that output is correctly derived from input, with a verification request and response mechanism to detect tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If GPS and GSM systems are used for road tolling, then location and distance tracking is enabled, but the system becomes vulnerable to signal tampering and data falsification
Solution Approach 1:
The patent applies preliminary action by pre-processing input data through a security process before transmission, generating verification information in advance that can be used to detect tampering. The security process is executed beforehand to transform input data into a secure format with embedded verification capabilities.
Solution Approach 2:
The patent implements feedback by transmitting verification information from the remote device to the server, which then verifies the integrity of processed data. This feedback mechanism allows the server to detect any tampering that occurred during transmission or processing by comparing verification information against expected values.
2Reliability
If verification mechanisms are added to prevent tampering, then data integrity is improved, but device complexity increases
Solution Approach 1:
The patent applies the extraction principle by separating verification information from the main data processing flow. The security process extracts essential verification elements from input data, stores them separately, and transmits them independently to the server for verification, simplifying the overall system architecture.
Solution Approach 2:
The patent uses an intermediary approach by introducing verification information as a mediator between the input data and the final processed output. This verification information acts as a bridge that carries integrity checks without requiring complex real-time verification during the main processing operation.
3Reliability
If encryption algorithms are used to process data, then security is improved, but processing time increases
Solution Approach 1:
The patent applies preliminary action by performing encryption and verification information generation in advance during the security process, rather than during real-time data transmission or at the server端. This pre-processing approach reduces the time penalty of encryption by completing it before critical operations.
Solution Approach 2:
The patent applies partial action by focusing encryption and verification only on critical portions of the data that require security protection, rather than encrypting entire data sets. This selective approach reduces processing overhead while maintaining security for essential information.
Data Source
AI summary
A system implements a secure transaction of data between a server and a remote device. The remote device comprises: processing means adapted to process input data according to a security process; data storage means adapted to store verification information derived from the input data according to an encryption algorithm; and communication means for communicating the input data which has been processed by the security process to the server. The server is adapted to transmit a verification request to the remote device, and to verify the integrity of the security process based on verification information received from the communication means of the remote device in response to the verification request.


