Mechanism

Roadway tolling is parameterized onto the matched-pair settlement primitive as a domain instance. The tolling marker is a governance-credentialed party, and the passing vehicle is a governance-credentialed party. Each party is identified through continuity-preserving identity and bears an authority credential under the governance authority taxonomy.

The first observation is the tolling marker's broadcast carrying location, authority, and rate. The second observation is the vehicle's counter-observation carrying vehicle identifier, classification, and timestamp. The matched-pair recognition rule for roadway tolling requires spatial-coincidence at the tolling marker plus temporal-coincidence within the vehicle's pass-through window; a received first observation and second observation that satisfy this rule constitute a matched pair.

The spatial-proximity evaluator verifies that the observations are within a governance-policy-defined spatial window using mesh-derived coordinates, and the temporal-proximity evaluator verifies that they are within a governance-policy-defined temporal window using mesh-derived time. A per-party authority evaluator verifies each party's authority credential, and a composite admissibility evaluator admits the matched pair as a settlement candidate. A cryptographic binding mechanism then produces a cryptographically-bound settlement artifact supporting non-repudiation, in which each party signs its own observation and the pair binds both signatures together with the spatial-proximity and temporal-proximity attestations.

The bound settlement is a persistent record admissible by downstream consumers without third-party intermediary, without centralized consensus, and without pre-negotiated session state. A settlement-lineage recorder records each first observation, second observation, pairing determination, and binding in the governance-chain lineage field. A downstream-consumer routing mechanism delivers the settlement record to authorized consumers.

Operating Parameters

Spatial and temporal proximity windows are the gating parameters. Spatial-window verification uses mesh-derived coordinates with governance-chain-preserving position lineage, and temporal-window verification uses mesh-derived time with governance-chain-preserving temporal lineage. A proximity-window violation produces governance-chain-preserving rejection, with lineage recording the violation type, the first and second observations, the measured and required windows, and the governance-policy-defined rejection consequences. This grounds settlement in physical reality: the parties must be co-located within the spatial window, so a marker cannot settle against a vehicle it did not detect and a vehicle cannot be settled against a marker it did not pass.

The first observation carries the rate, and the vehicle's classification is carried in the second observation. The recognition rule, observation content schema, proximity windows, settlement-record format, and downstream-consumer routing are governance-policy-configurable per transaction type and per deployment.

A dispute-resolution mechanism supports governance-credentialed challenge and resolution of settled pairs, routed to a governance-policy-defined dispute-resolution authority and procedure. Because the settlement record is bilateral and cryptographically bound, both parties hold the same record; non-repudiation supports downstream verification that the settlement was authentically produced by the claimed parties at the claimed location and time.

Alternative Embodiments

The same primitive is used across deployments with domain-specific observation content schemas, matched-pair recognition rules, proximity windows, settlement-record formats, downstream-consumer routings, and dispute-resolution procedures. The recognition rule for a given tolling deployment is governance-policy-configurable; the roadway tolling instance disclosed here uses spatial-coincidence at the tolling marker plus temporal-coincidence within the vehicle's pass-through window, and other deployments may apply additional governance-policy-defined pairing rules, including authority-pair rules wherein a tolling-authority credential is paired with a vehicle-operator credential.

The matched-pair settlement primitive integrates a counter-offer and negotiation mechanism supporting iterated pair exchange before terminal settlement, an escrow and chained-settlement mechanism supporting conditional-release and cross-settlement dependencies, and a settlement-failure and rollback mechanism handling timeout, non-acceptance, and failed-fulfillment conditions. A tolling deployment may draw on these mechanisms where its governance policy provides for them.

Vehicles transiting multiple tolling authorities are addressed through the cross-authority taxonomy translation of the architecture: each authority operates under its own authority taxonomy, and a credential issued under one taxonomy is translated for recognition under another. The primitive supports multi-authority admissibility with cross-jurisdictional co-existence on a single physical location. Settlements remain bilateral within each authority's scope, without any cross-authority clearing layer.

Composition

The tolling embodiment composes the matched-pair settlement primitive with the mesh-derived coordinate primitive and the mesh-derived time primitive. The spatial-proximity-window evaluation draws on mesh-derived coordinates, and the temporal-proximity-window evaluation draws on mesh-derived time and governance-credentialed timestamp attestation. These supply the spatial and temporal windows within which the marker broadcast and the vehicle counter-observation must coincide to constitute a matched pair.

Party identity composes with the continuity-preserving identity primitive: the tolling marker and the vehicle are each identified through continuity-preserving identity and bear authority credentials under the governance authority taxonomy. The composite admissibility evaluator corroborates the matched pair as a settlement candidate, and the cross-domain coherence evaluator admits it through multi-source pair corroboration.

Composition with the architecture's dispute-resolution mechanism supplies recourse. Disputes are resolved by inspection of the bilateral settlement record, under a governance-credentialed challenge and resolution procedure routed to a governance-policy-defined dispute-resolution authority.

Prior-Art Distinction

The matched-pair settlement primitive is structurally distinguished from prior settlement architectures in several respects, which carry directly into the tolling instance. Prior centralized payment processors settle through a third-party intermediary with intermediary-held counterparty risk, whereas the present primitive settles directly between the transacting parties without intermediary. Prior clearing-house and settlement-network architectures operate through regulated intermediaries with counterparty-risk management overhead, whereas the present primitive operates without intermediary.

Prior blockchain settlement architectures settle through distributed consensus, producing block-commit-granularity finality with minutes-scale latency, whereas the present primitive produces observation-granularity settlement with mesh-propagation latency. Prior paired-authentication protocols produce transient authentication outcomes without a persistent settlement artifact, whereas the present primitive produces a governance-chain-preserving settlement record.

Prior transactional architectures bind consent at account-level setup, producing implicit per-transaction consent, whereas the present primitive produces explicit per-transaction bilateral consent through per-transaction paired observations. Prior architectures address abstract digital addresses without physical-space grounding, whereas the present primitive requires the parties to be co-located within the governance-policy-defined spatial window, producing physical-reality-grounded transactions. For tolling, this means the marker and the vehicle settle as the two transacting parties at the moment and place of passage, with the settlement record held by both and admissible by downstream consumers without any intervening clearing layer.

Disclosure Scope

U.S. Provisional Application No. 64/049,409 discloses roadway tolling as one domain instance of the matched-pair settlement primitive, parameterized so that the first observation is the tolling marker's broadcast carrying location, authority, and rate, and the second observation is the vehicle's counter-observation carrying vehicle identifier, classification, and timestamp. The recognition rule for this instance requires spatial-coincidence at the tolling marker plus temporal-coincidence within the vehicle's pass-through window. The same primitive generalizes to any bilateral physical-world exchange admitting paired-observation settlement through governance-policy-configurable observation schemas, recognition rules, proximity windows, settlement-record formats, downstream-consumer routings, and dispute-resolution procedures.

The settlement is cryptographically bound for non-repudiation, with each party signing its own observation and the pair binding both signatures together with the spatial-proximity and temporal-proximity attestations. Each settlement is held by both parties and is admissible by downstream consumers without third-party intermediary, without centralized consensus, and without pre-negotiated session state.

Audit posture follows from this structure. Because the settlement record is bilateral and cryptographically bound, both parties hold the same record, and a downstream consumer can verify that the settlement was authentically produced by the claimed parties at the claimed location and time. The settlement-lineage recorder preserves each observation, pairing determination, and binding in the governance-chain lineage field, supporting regulatory audit, legal discovery, and forensic reconstruction.