Chain transactions for fraud prevention
By generating and maintaining audit trails for digital currency tokens, the problem of fraud detection after transaction amounts are split in peer-to-peer payments is solved, enabling secure payments without intermediaries, reducing computational burden, and supporting fraud detection and investigation.
Patent Information
- Application Number
- CN202480020676.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-04-15
- Filing Date
- 2024-04-08
- Publication Date
- 2025-11-04
AI Technical Summary
In peer-to-peer payments, it is difficult to track fraudulent activities involving splitting transaction amounts, especially when the transaction amount is split into multiple transactions. Existing technologies are insufficient to effectively detect and prevent fraudulent transactions.
Generate audit trails associated with the cryptocurrency transaction chain by splitting the cryptocurrency amount into multiple cryptocurrency tokens, attaching digital credential elements to the receiving wallet in each transaction and performing cryptographic signing, and maintaining the audit trail of each token for subsequent detection of fraudulent transactions.
It enables fraud detection of peer-to-peer payments without intermediaries, reduces computing resource requirements, supports post-event investigation and fraud detection, and enhances the device's defense capabilities.
Smart Images

Figure CN120898219A_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims the benefit and priority of U.S. Provisional Patent Application Serial No. 63 / 496,398, filed April 15, 2023, the entire disclosure of which is incorporated herein by reference for all purposes. Background Technology
[0003] Users can transfer data from one computing device to another using several options. Multiple users upload data from one computing device to a server, allowing other users to download data from that server to another computing device. Alternatively, users can use peer-to-peer data transfer technology to achieve direct data transfer from sender to receiver. Summary of the Invention
[0004] Some examples provide a system for detecting fraudulent transactions in peer-to-peer payments without intermediaries. The system includes a processor and a computer storage medium storing instructions that cause the processor to perform the following operations: receive a request to identify whether a transaction chain involving the transfer of one or more digital currency tokens is a fraudulent transaction; retrieve and associate a first audit trail with a first digital currency token associated with a first transaction, wherein the first transaction is part of a transaction chain and is associated with one or more digital currency tokens; detect wallet cloning or value tampering in the first digital currency token associated with the first transaction, at least by analyzing the first audit trail; and designate the first transaction as a fraudulent transaction based on the detection of wallet cloning or value tampering. Each sending wallet is configured to generate one or more audit trails associated with the transaction to transfer digital currency from the sending wallet to a receiving wallet; digitally attach one or more elements of a digital certificate from the receiving wallet to each of the one or more digital currency tokens; and cryptographically sign each of the one or more digital currency tokens before the transfer to the receiving wallet, wherein each digital currency token maintains an audit trail of the digital wallets through which the digital currency token was transacted before being received by the receiving wallet.
[0005] Other examples provide a method for generating one or more audit trails associated with a transaction to transfer a digital currency from a sending wallet to a receiving wallet, an amount of the digital currency being split into one or more digital currency tokens; the sending wallet digitally attaching one or more elements of a digital credential of the receiving wallet to each of the one or more digital currency tokens and cryptographically signing each of the one or more digital currency tokens prior to transfer to the receiving wallet, each digital currency token maintaining an audit trail of digital wallets the digital currency token transits through prior to being received by the receiving wallet; receiving a request to identify whether a first transaction is a fraudulent transaction, the first transaction being part of the transaction and associated with one of the one or more digital currency tokens; and in response to receiving the request: retrieving and a first audit trail associated with a first digital currency token associated with the first transaction; detecting a wallet clone or a value tamper in the first digital currency token associated with the first transaction by at least analyzing the first audit trail; and designating the first transaction as a fraudulent transaction based on detecting the wallet clone or the value tamper.
[0006] Other examples also provide a computer storage medium storing computer executable instructions that, when executed by a processor, cause the processor to at least: generate one or more audit trails associated with a transaction chain to transfer a digital currency from a sending wallet to a receiving wallet, an amount of the digital currency comprising one or more digital currency tokens, the sending wallet digitally attaching one or more elements of a digital credential of the receiving wallet to each of the one or more digital currency tokens and cryptographically signing each of the one or more digital currency tokens prior to transfer to the receiving wallet, each digital currency token maintaining an audit trail of digital wallets the digital currency token transits through prior to being received by the receiving wallet; receive a request to identify whether a first transaction is a fraudulent transaction, the first transaction being part of the transaction and associated with one of the one or more digital currency tokens; and in response to receiving the request: retrieve and a first audit trail associated with a first digital currency token associated with the first transaction; detect a wallet clone or a value tamper in the first digital currency token associated with the first transaction by analyzing the first audit trail; and designate the first transaction as a fraudulent transaction based on detecting the wallet clone or the value tamper.
[0007] This Summary is intended to introduce selected concepts of the concepts set forth in a simplified form that are further described below in the DETAILED DESCRIPTION. This Summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used to determine the scope of the claimed subject matter. BRIEF DESCRIPTION OF DRAWINGS
[0008] The present application will be better understood from the following detailed description read in light of the accompanying drawings, wherein:
[0009] Figure 1 is a block diagram illustrating an example system configured to detect fraudulent transactions in peer-to-peer payments;
[0010] Figure 2 is a block diagram illustrating an example system configured to generate an audit trail;
[0011] Figure 3 is a flowchart illustrating an example method for transferring a digital currency token to a receiving wallet;
[0012] Figure 4 is a flowchart illustrating an example method for detecting fraudulent transactions in peer-to-peer payments;
[0013] Figure 5A is a block diagram illustrating an example token;
[0014] Figure 5B is a block diagram illustrating an example audit trail;
[0015] Figure 5C is a block diagram illustrating an example token including a plurality of audit trails; and
[0016] Figure 6 An example computing device is illustrated in a functional block diagram.
[0017] Corresponding reference numbers indicate corresponding parts throughout the drawings. In Figures 1 to 6 , systems are shown in schematic form. The drawings can not be to scale. Any drawing can be combined into a single example or embodiment. DETAILED DESCRIPTION
[0018] Card-to-card payments in the real world, without the need for merchant terminals, telephones, or internet connectivity, can bring the cash economy of developing countries into digital payments and eventually into the financial system, with access to credit, micro-investments, and other services. Large populations in countries still use cash, which is inconvenient for both local residents and visitors. This cash cannot be spent online, which limits investment, import and export, and tourism consumption in these countries.
[0019] Peer-to-peer transactions are difficult to trace, especially when the transaction amount associated with the transaction is split into multiple transaction amounts and multiple transactions associated with the multiple transaction amounts occur. For example, a fraudster can commit fraud by tampering with the transaction value of one or more of the multiple transactions or cloning a fake wallet as a receiving wallet. Simple ledgers are not sufficient to protect against such attacks, and thus peer-to-peer payments are not secure.
[0020] In contrast, aspects of the present disclosure provide systems and methods for detecting fraudulent transactions in peer-to-peer payments without the need for intermediaries. The present disclosure is configured to generate an audit trail associated with a chain of transactions for transferring digital currency from an initial sending wallet to a final receiving wallet. The digital currency amount is split into one or more digital currency tokens. For example, when a transaction occurs to transfer digital currency from one wallet to another, the amount is composed of digital currency tokens of a fixed denomination. In one example, a digital wallet is capable of loading $1, $5, $10, $20 digital currency tokens, or any combination thereof, up to a potentially defined limit for that wallet. For clarity, if $35 of digital currency needs to be transferred from a sending wallet to a receiving wallet, the $35 can be split into five $1 tokens, one $20 token, and two $5 tokens.
[0021] When a transaction occurs between two digital wallets, the sending wallet digitally attaches elements of the receiving wallet's digital credentials to each digital currency token, and each digital currency token is cryptographically signed before being transferred to the receiving wallet. When the receiving digital wallet uses the received tokens, it performs the same process. That is, the receiving wallet becomes a sending wallet to send the tokens to another wallet (which becomes a receiving wallet at that time). The process repeats until the tokens reach the final receiving wallet. Through this mechanism, the tokens maintain an audit trail, which in some examples is a list of digital wallets that the token passed through for the transaction. Thus, each digital currency token maintains an audit trail of the digital wallets that the digital currency token passed through before being received by the final receiving wallet.
[0022] The audit trail can be retrieved by an acquirer or its network operator for fraud detection purposes. Such an audit trail can be used to detect and investigate wallet cloning or value tampering (e.g., by tampering with token values, cloning tokens, manufacturing fake tokens). For example, a request is received (e.g., from an acquirer or a law enforcement agency with legal authorization to do so, if it has the digital wallet) to identify whether a first transaction (e.g., a $1, $20, or $5 transaction) associated with one of the digital currency tokens and that is part of a chain of transactions is a fraudulent transaction. In response to the request, a first audit trail associated with the first digital currency token associated with the first transaction is retrieved. Upon analyzing the first audit trail, and if wallet cloning or value tampering is detected in the first digital currency token associated with the first transaction, the first transaction is determined to be a fraudulent transaction. For example, the first transaction is flagged, labeled, or otherwise designated as fraudulent.
[0023] Analyzing the first audit trail includes one or more of the following: analyzing the first digital currency token for token value tampering (e.g., a fraudster can tamper a $1 token value to a $5 token value, which is greater than the $1 token value), analyzing whether the first digital currency token is a clone of a second digital currency token (e.g., a fraudster can create a clone of a $20 token), and / or analyzing whether the first digital currency token is a fake token (e.g., a fraudster can create a fake token of a $10 token value).
[0024] The present disclosure operates in an unconventional manner by maintaining audit trails of digital currency tokens as they pass through digital wallets before being received by a final receiving wallet. If fraud prevention or law enforcement investigation is needed, the audit trails trace the chain of transactions without intermediaries (e.g., without third party intermediaries signing and / or validating the digital currency tokens). The audit trails are protected by encryption to safeguard privacy while being available for fraud detection or law enforcement investigation purposes. Thus, a technical solution is provided to the technical problem.
[0025] Further, maintaining the audit trails makes the present disclosure flexible, which reduces the computational burden of devices in identifying and / or preventing fraudulent transactions, thereby enhancing device functionality. Implementing secure peer-to-peer payments without intermediaries eliminates the need for intermediary servers. Thus, the computational resource usage for tracing the chain of transactions for fraud prevention or law enforcement investigation is reduced. It supports post-mortem investigations and fraud detection, enabling truly peer-to-peer transactions based on battery-powered credit / debit cards or low-power mobile phones in the Internet or real world.
[0026] In summary, a computerized method of detecting fraudulent transactions in peer-to-peer payments without intermediaries is described. Audit trails associated with a chain of transactions transferring digital currency from an initial sending wallet to a final receiving wallet are generated. The amount of digital currency includes one or more digital currency tokens. The sending wallet or other logic digitally attaches a digital credential element of the receiving wallet and the sending wallet to each digital currency token and cryptographically signs each token before transferring to the receiving wallet. Each digital currency token maintains an audit trail of digital wallets it passes through before being received by the receiving wallet. A request to identify whether a first transaction that is part of the chain of transactions and associated with one of the digital currency tokens is a fraudulent or sanctioned transaction is received. In response to the request, a first audit trail associated with a first digital currency token associated with the first transaction is retrieved. The first transaction is designated as a fraudulent transaction when a wallet clone or value tampering is detected in the first digital currency token associated with the first transaction, e.g., by analyzing the first audit trail.
[0027] Figure 1is a block diagram illustrating an example system 100 configured to detect fraudulent transactions in point-to-point payments. In some examples, the system 100 includes an initial sending wallet 102 to transfer a certain amount of digital currency to a final receiving wallet 104. For example, a first token Tl (e.g., a $1 token) is sent from the first initial sending wallet 102 to the final receiving wallet 104 through an intermediary wallet 106, thereby generating an audit trail for the token Tl. In this case, the intermediary wallet 106 first becomes a receiving wallet for the first initial sending wallet 102 and subsequently becomes a sending wallet to send the token Tl to the final receiving wallet 104. In this way, the audit trail grows as the token Tl passes through multiple intermediary wallets, as each intermediary wallet attaches its own audit trail (i.e., digital credential elements of the sending and / or receiving wallet, and encrypts the generated audit trail including the token Tl ) to the token Tl. Depending on the implementation, the number of intermediary wallets (such as the intermediary wallet 106) can be more or less for transferring the token Tl from the initial sending wallet 102 to the final receiving wallet 104.
[0028] Similarly, tokens T2, T3, and T4 (e.g., a $20 token, a $5 token, and another $5 token, respectively) are sent from the initial sending wallet 102 to the final receiving wallet 104 through an intermediary wallet 108, thereby generating an audit trail for the tokens T2, T3, and T4. In this case, the intermediary wallet 108 first becomes a receiving wallet for the initial sending wallet 102 and subsequently becomes a sending wallet to send the tokens T2, T3, and T4 to the final receiving wallet 104. Depending on the implementation, the number of intermediary wallets (such as the intermediary wallet 108) can be more or less for transferring the tokens T2, T3, and T4 from the initial sending wallet 102 to the final receiving wallet 104. Furthermore, in at least one example, the tokens (such as the tokens Tl to T4) are transferred from the initial sending wallet 102 to the final receiving wallet 104 via different wallets (or different numbers of intermediary wallets) than shown. Figure 1
[0029] Each digital currency token maintains an audit trail of the digital wallets it has passed through before being received by the final receiving wallet 104. For example, as shown in Figure 1 the initial sending wallet 102 attaches a digital credential element of the intermediary wallet 106 to the token Tl and cryptographically signs the token Tl before transferring to the wallet 106. The wallet 106 then acts as a sending wallet and attaches a digital credential element of the final receiving wallet 104 to the token Tl and cryptographically signs the token Tl before transferring to the final receiving wallet 104. Those skilled in the art will appreciate that Figure 1 The tokens T1 shown in the middle are different in that they have attached to them a digital credential element of the respective receiving wallet (e.g., initially wallet 106, and subsequently wallet 104), and are also cryptographically signed by the respective sending wallet (e.g., initially wallet 102, and subsequently wallet 106).
[0030] In some embodiments, the audit trail is encrypted and attached to its respective digital currency token. Thus, the audit trail is stored in encrypted form by the digital wallet. The audit trail is encrypted using an encryption key issued by one or more issuer servers. In some examples, the audit trail is encrypted multiple times using multiple encryption keys. Using multiple encryption keys will require the consent of all holders of the audit trail decryption key to decrypt the audit trail. The non-consent of any one holder of the audit trail decryption key will prevent the audit trail from being decrypted and read.
[0031] In some examples, one or more audit trails (i.e., token audit trail data) are stored multiple times with one or more digital currency tokens, where each copy of the one or more audit trails is encrypted using one or more audit trail encryption keys. This allows the audit trail to be decrypted and viewed by multiple holders of the corresponding decryption keys for the audit trail data copy. In some examples, a multi-party key management scheme can be applied to this model of one or more digital currency tokens, which includes encrypting the decryption key using the encryption keys of multiple audit trail decryption key holders. For example, the audit trail for each recorded transaction is encrypted such that the audit trail can only be accessed by authorized parties, such as a payment processor, law enforcement, or a combination of the two.
[0032] In some implementations, the initial sending wallet 102 is issued by an issuer server and exists in the form of software on a computer, an application on a mobile phone, a credit or debit card, or a service on the Internet or other network. Depending on the implementation, the final receiving wallet 104 is associated with an acquirer (e.g., a merchant) that accepts digital cash from one or more digital wallets (e.g., the initial sending wallet 102). The issuer server issues or receives digital credentials (e.g., account numbers, and / or public or private encryption keys) to or from the digital wallet. If the credentials are generated by the digital wallet, the issuer server receives the credentials, or the issuer server issues a credential to a digital wallet that does not generate its own keys.
[0033] In some examples, the digital credential is a digital certificate signed by the private key of the issuer and countersigned by the digital wallet. The signed certificate or credential includes elements of the digital credential (e.g., account number, issuer ID, expiration date, transaction limits, and custom features such as wallet total limit, brand identification, foreign exchange). The digital wallet is loaded with digital currency. Depending on the implementation, the digital wallet is loaded by one or more of a bank, a wallet issuer, a payment gateway, a virtual asset service provider (VASP), an ATM cash machine, an acquirer, a merchant, and the like. The digital wallet can also be loaded with digital currency by one or more other digital wallets, i.e., a so-called “transaction” — e.g., a transaction that sends digital currency from an initial sending wallet 102 to a final receiving wallet 104 that loads the digital currency into the wallet 104.
[0034] Further, in some examples, the digital wallets of the system 100 (e.g., the digital wallets 102-108) are implemented on one or more computing devices (e.g., computing devices of Figure 6 are configured to communicate with each other over one or more communication networks (e.g., an intranet, the Internet, a cellular network, other wireless networks, other wired networks, and the like).
[0035] Figure 2 is a block diagram illustrating an example system 200 configured to generate one or more audit trails 212. In some examples, the system 200 is used to implement the wallets (e.g., the wallets 102-108) of the system 100 shown as Figure 1 Further, it is understood that the computing device 202 generates the audit trails 212 for detecting fraudulent transactions in peer-to-peer payments without the need for intermediaries. The computing device 202 includes a processor 204 and a memory 206. In some implementations, the memory 206 stores a digital wallet 208 (e.g., the wallets 102-108 in Figure 1 and a token 210 for transferring an amount of digital currency from the digital wallet 208 (which can act as the initial sending wallet 102) to another wallet, e.g., the final receiving wallet 104. The digital wallet 208 attaches elements of an electronic digital credential (EDC) of the receiving wallet to each of the tokens 210, thereby generating the audit trails 212. For clarity, the audit trails 212 are shown separate from the tokens 210, but the audit trails 212 are not stored separate from the tokens 210, which reduces the security risk of someone clearing the audit trails 212 but still redeeming the funds. Depending on the implementation, the EDC includes an account number, an issuer ID, an expiration date, transaction limits, or custom features.
[0036] In some examples, the audit trails 212 are stored in the memory 206 as a blockchain. For example, for T1-T4 (as shown in Figure 1The audit trails 212 (shown) are stored in different blockchains. These blockchains can be analyzed by machine learning to find evidence of fraudulent behavior. The analysis includes scoring and other actionable metrics that enable entities to fulfill their compliance requirements, such as anti-money laundering compliance. Entities that can implement the present disclosure include, but are not limited to, issuer servers, acquirer servers, cryptocurrency exchanges / platforms, hedge funds, money services businesses, regulatory agencies (e.g., government agencies), intelligence agencies, lawyers, auditors, banks, brokerage firms, and security researchers.
[0037] Storing the audit trails 212 in blockchains is technically advantageous because it enables the audit trails 212 to be analyzed to determine whether a transaction or portion thereof was modified due to fraudulent behavior by a fraudster, as described herein.
[0038] In some implementations, the computing device 202 has a user interface (UI) 214 that prompts a user of the computing device 202 to input an amount of digital currency to transfer from the initial sending wallet 102 to the final receiving wallet 104. In some examples, if a portion of the transaction is determined to be a fraudulent transaction, the UI 214 displays to the user that the transaction has been modified by a fraudster before being transferred to the final receiving wallet 104, and thus the transaction has been declined. In this way, fraudulent transactions can be prevented in real-time using aspects of the present disclosure.
[0039] Figure 3 is a flowchart illustrating an example method 300 for transferring digital currency tokens from a sending wallet to a receiving wallet. The method 300 details steps for generating an audit trail for each digital currency token for each sending wallet. The method 300 loops through each intermediate wallet that a digital currency token transaction passes through until reaching the final receiving wallet. In some examples, the method is performed or otherwise implemented by a system such as the system 100 of Figure 1 or the system 200 of Figure 2 .
[0040] At operation 302, an audit trail is generated associated with a transaction that moves digital currency from a sending wallet to a receiving wallet. The digital currency amount includes one or more digital currency tokens. At operation 303, one or more elements of a digital credential of the sending wallet are attached to each of the one or more digital currency tokens. At operation 304, one or more elements of a digital credential of the receiving wallet are attached to each of the one or more digital currency tokens. At operation 306, each of the one or more digital currency tokens is cryptographically signed prior to movement to the receiving wallet. At operation 308, the sending wallet moves the one or more digital currency tokens to the receiving wallet. The process loops back to operation 302 for each intermediate wallet used to move the digital currency token from an initial sending wallet to a final receiving wallet. Each intermediate receiving wallet then becomes a sending wallet.
[0041] The audit trail is part of the digital currency token and moves with the digital currency token. The audit trail is not stored separately from the digital currency token, which reduces the security risk of someone clearing the audit trail but still redeeming the funds or harassing the issuer's customer support. In at least one example, the audit trail can be stored separately, but the token has a hash and signature of the audit trail to verify its authenticity. In at least one implementation, a one-time token (OTP) is stored in one or more audit trails to verify authenticity and prevent replay attacks.
[0042] At optional operation 309, a digital receipt is received from the recipient.
[0043] Figure 4 FIG. 4 is a flowchart illustrating an example method 400 for detecting fraudulent transactions in peer-to-peer payments. In some examples, the method 400 is performed or otherwise implemented by a system, such as the system 200 of FIG. 2. Figure 2
[0044] At operation 402, a request is received to identify whether a first transaction is a fraudulent transaction. In some examples, the first transaction is part of a transaction chain initiated by an initial sending wallet 102 to a final receiving wallet 104. The first transaction is associated with one of the one or more digital currency tokens. In response to the request, at operation 404, a first audit trail associated with the first digital currency token associated with the first transaction is retrieved. At operation 406, the first audit trail is analyzed. At operation 408, based on the analysis, it is determined or detected whether a wallet cloning or value tampering occurred in the first digital currency token associated with the first transaction. If a wallet cloning or value tampering is detected at operation 408, the first transaction is determined to be a fraudulent transaction at operation 412. If no wallet cloning or value tampering is detected at operation 408, at operation 409, if it is determined that there are additional audit trails in the first digital currency token, the process loops to operation 404 to analyze the next audit trail. For example, if there are five audit trails, operations 404-408 are performed five times. Only through the complete audit trail, a fraudulent hot spot can be determined. Depending on the implementation, the content of the fraudulent audit trail is as simple as wallet / card ID and transaction amount and date time. The audit chain can be linked with other audit chains in the system to detect money launderers, wallet copiers, or other fraudulent actors or schemes.
[0045] Once there are no more audit trails to analyze at operation 409, and no wallet cloning or value tampering is detected, the first transaction is determined to be a real transaction at operation 410.
[0046] Figure 5Ais a block diagram illustrating an example token, such as a digital currency token 210. The digital currency token 210 includes an identifier 502 associated with the token that uniquely identifies the digital currency token 210, and an amount 504 represented by the digital currency token 210. Each token can have more than one audit trail. For example, the digital currency token 210 includes both a fraud audit trail 506 and an investigation audit trail 508, which are generated as the digital currency token 210 passes through different wallets, such as the wallets 102-108. The fraud audit trail 506 includes a transaction trail or log, such as a wallet ID, an amount, and optionally a date or one-time token. This audit trail can be encrypted with a symmetric key or private key, or a symmetric key encrypted with a public key of a fraud auditor or wallet issuer. This audit trail, in combination with other audit trail analysis that shows unusual behavior in the number of transactions or fiat value, can provide valuable and actionable fraud insights without revealing the identity of the wallet holder or other personal information. The one or more investigation audit trails 508, on the other hand, contain other data that can be useful for investigations, such as transaction date and time, or can contain travel rule information that can be required for certain higher value wallets or cards. There can also be another audit trail that can carry travel rule information for sanctions and other screening purposes for higher value wallets. This reduces the computational resource requirements for detecting fraudulent transactions, as a computing device, such as the apparatus 618, only needs to process the fraud audit trail 506 and / or the investigation audit trail 508, rather than the entire audit trail P 510 (as shown in Figure 5B and 5C ). In addition, it also allows for the detection of fraud that would otherwise be difficult to find in a peer-to-peer digital transaction system, and allows for regulatory compliance for sanctions and other KYC region requirements by using key management mechanisms to enable secure and controlled access to wallet holder data, such as real name and other KYC due diligence requirements in line with Financial Action Task Force (FATF) Recommendation 15. This can form the basis for third party reliance on other party KYC.
[0047] Figure 5B is a block diagram illustrating an example audit trail P 510. The audit trail P 510 includes an identifier 512 of a wallet (e.g., the initial sending wallet 102 and / or the final receiving wallet 104) and a signature 514. In certain versions, the signature 514 includes a hash of the audit trail P 510 and / or a public key or other identifier of the initial sending wallet 102. In one example, the audit trail P 510 includes an audit trail P-1 516, which is an audit trail generated at a previous level. In another example, the audit trail P 510 is generated by the intermediate wallet 106, while the audit trail P-1 516 is generated by the initial sending wallet 102 (as shown in Figure 1(As shown). Depending on the implementation, the number of audit trails may be more or less. Figure 5B As shown, without departing from any aspect of this disclosure.
[0048] Figure 5C This is a block diagram illustrating an example token that includes multiple audit trails. In some implementations, digital currency token 210 includes audit trail P 510, which in turn includes audit trail P-1 516. Similarly, audit trail P-1 516 includes audit trail P-2 518, which further includes audit trail P-3 520. In this way, the audit trails are nested, and the path traversed by token 210 can be known from audit trail P 510, which includes the path the token takes from the originating wallet (e.g., initial sending wallet 102) to the final sending wallet (e.g., intermediate wallet 106). Depending on the implementation, there may be more or fewer audit trails. Figure 5C The audit trails shown are nested without departing from any aspect of this disclosure. In at least one example, the contents of these audit trails are encrypted by one or more key controllers, authorized audit decryptors, and / or auditors.
[0049] Example operating environment
[0050] This disclosure may be based on Figure 6 The computing device 618 of the embodiment shown in the functional block diagram 600 operates collaboratively. In one example, components of the computing device 618 are implemented as part of an electronic device according to one or more embodiments described herein. The computing device 618 includes one or more processors 619, which may be a microprocessor, a controller, or any other suitable processor type for processing computer-executable instructions to control the operation of the electronic device. Alternatively or additionally, the processor 619 is any technology capable of executing logic or instructions, such as a hard-coded machine. In some examples, platform software including an operating system 620 or any other suitable platform software is provided on the device 618 to enable application software 621 to execute on the device. In some examples, the ability to detect fraudulent transactions in peer-to-peer payments without intermediaries, as described herein, is implemented through software, hardware, and / or firmware.
[0051] In some examples, computer-executable instructions are provided using any computer-readable media 618 accessible to computing device 618. Computer-readable media 618 includes computer storage media, such as memory 622, and communication media. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, random access memory (RAM), read only memory (ROM), erasable programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), solid state drives, flash memory or other memory technology, compact disc read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non- transmission medium that can be used to store information for access by a computing device. In contrast, communication media embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transport mechanism. As defined herein, computer storage media does not include communication media. Therefore, a computer storage medium is not a modulated data signal. Likewise, a computer storage medium is not a propagated signal. Although the computer storage media 622 is shown within computing device 618, it should be appreciated that in some examples, the storage can be distributed or located remotely and accessed by the computing device through the network or other communication link (e.g., using communication interface 623).
[0052] In addition, in some examples, computing device 618 includes input / output controller 624 configured to output information to one or more output devices 625, such as a display or speaker, which can be integral to or separate from the electronic device. Additionally or alternatively, input / output controller 624 is configured to receive and process input from one or more input devices 626, such as a keyboard, microphone, or touchpad. In one example, output device 625 also functions as an input device. An example of such a device is a touch-sensitive display. Input / output controller 624 can also output data to devices other than the output devices, such as a locally connected printing device. In some examples, a user provides input to input device(s) 626 and / or receives output from output device(s) 625.
[0053] The functions described herein can be executed by one or more hardware logic components. In this regard, according to an embodiment, when the program code is executed by the processor 619, the computing device 618 is configured to perform an embodiment of the operations and functionality described. Alternatively, or in addition, the function described herein can also be performed, at least in part, by one or more hardware logic components. For example, and without limitation, illustrative types of hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Application-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), Graphics Processing Units (GPUs).
[0054] At least some of the functions of the various elements described in the figures can be performed by other elements or entities not shown in the figures (e.g., processors, network services, servers, applications, computing devices, etc.).
[0055] Although described in association with an example computing system environment, examples of the present disclosure can be implemented utilizing numerous other general purpose or special purpose computing system environments, configurations, or devices.
[0056] Examples of well-known computing systems, environments, and / or configurations that can be suitable for use with aspects of the present disclosure include, but are not limited to, mobile or portable computing devices such as smartphones, personal computers, server computers, handheld devices (e.g., tablets) or laptop devices, multiprocessor systems, gaming consoles or controllers, microprocessor-based systems, set top boxes, programmable consumer electronics, mobile telephones, wearable or accessory form factor mobile computing and / or communication devices (e.g., watches, glasses, headsets or earpieces), network PCs, minicomputers, mainframe computers, distributed computing environments that include any of the above systems or devices, and the like. In general, the present disclosure can be operational with any device that has a processing capability to execute instructions such as those described herein. Such a system or device accepts user input in any way including through input devices such as a keyboard or pointing device, via gesture input, proximity input such as hover, and / or via voice input.
[0057] Examples of the present disclosure can be described in the general context of computer-executable instructions, such as program modules, being executed by one or more computers or other devices, software, firmware, hardware, or combinations thereof. Computer-executable instructions can be organized into one or more computer-executable components or modules. Generally, program modules include, but are not limited to, routines, programs, objects, components, and data structures that perform particular tasks or implement particular abstract data types. Aspects of the present disclosure can be implemented with various computer-executable components or modules that interoperate in suitably-programmed computing devices. For example, aspects of the present disclosure are not limited to a particular computing or software environment.
[0058] In examples involving general-purpose computers, aspects of the present disclosure transform a general-purpose computer into a special-purpose computing device when configured to perform the instructions described herein.
[0059] An example system includes a processor; a computer storage medium storing instructions that, when executed by the processor, operate to receive a request to identify whether a chain of transactions that transfers a digital currency from an initial sending wallet to a final receiving wallet is a fraudulent transaction, wherein an amount of the digital currency comprises one or more digital currency tokens; retrieve a first audit trail associated with a first digital currency token associated with a first transaction, wherein the first transaction is part of the transaction that transfers the digital currency from the initial sending wallet to the final receiving wallet and is associated with one of the one or more digital currency tokens; detect a wallet clone or a value tampering in the first digital currency token associated with the first transaction by at least analyzing the first audit trail; and designate the first transaction as the fraudulent transaction based on detecting the wallet clone or the value tampering, wherein each sending wallet is configured to generate one or more audit trails associated with a transaction that transfers a digital currency from the sending wallet to a receiving wallet; digitally attach one or more elements of a digital credential of the receiving wallet to each of the one or more digital currency tokens; and cryptographically sign each of the one or more digital currency tokens before transferring to the receiving wallet, wherein each digital currency token maintains an audit trail of digital wallets that the digital currency token transits through before being received by the receiving wallet.
[0060] An example computerized method includes generating one or more audit trails associated with a transaction to transfer a digital currency from a sending wallet to a receiving wallet, an amount of the digital currency being split into one or more digital currency tokens, the sending wallet digitally attaching one or more elements of a digital credential of the receiving wallet to each of the one or more digital currency tokens, and cryptographically signing each of the one or more digital currency tokens prior to transfer to the receiving wallet, each digital currency token maintaining an audit trail of digital wallets the digital currency token passed through prior to being received by the receiving wallet; receiving a request to identify whether a first transaction is a fraudulent transaction, the first transaction being part of the transaction and associated with one of the one or more digital currency tokens; and in response to receiving the request: retrieving a first audit trail associated with a first digital currency token associated with the first transaction; detecting a wallet clone or a value tampering in the first digital currency token associated with the first transaction by analyzing the first audit trail; and based on detecting the wallet clone or the value tampering, determining that the first transaction is a fraudulent transaction.
[0061] One or more computer storage media storing computer-executable instructions that, when executed by a processor, cause the processor to at least: generate one or more audit trails associated with a transaction to transfer a digital currency from a sending wallet to a receiving wallet, an amount of the digital currency comprising one or more digital currency tokens, the sending wallet digitally attaching one or more elements of a digital credential of the receiving wallet to each of the one or more digital currency tokens, and cryptographically signing each of the one or more digital currency tokens prior to transfer to the receiving wallet, each digital currency token maintaining an audit trail of digital wallets the digital currency token passed through prior to being received by the receiving wallet; receive a request to identify whether a first transaction is a fraudulent transaction, the first transaction being part of the transaction and associated with one of the one or more digital currency tokens; and in response to receiving the request: retrieve a first audit trail associated with a first digital currency token associated with the first transaction; detect a wallet clone or a value tampering in the first digital currency token associated with the first transaction by analyzing the first audit trail; and based on detecting the wallet clone or the value tampering, determine that the first transaction is a fraudulent transaction.
[0062] Alternatively, or in addition to other examples described herein, examples include any combination of the following:
[0063] wherein analyzing the first audit trail includes one or more of: analyzing a token value tampering in the first digital currency token, analyzing whether the first digital currency token is a clone of a second digital currency token, and analyzing whether the first digital currency token is a counterfeit token.
[0064] wherein one or more of the audit trails are encrypted and attached to their respective digital currency tokens.
[0065] wherein the encryption key used to encrypt the one or more audit trails is issued by one or more issuer servers.
[0066] wherein the one or more audit trails are encrypted multiple times by multiple encryption keys.
[0067] wherein the decryption key used to decrypt the one or more encrypted audit trails is encrypted using an encryption key of one or more audit trail decryption key holders.
[0068] wherein the one or more audit trails are stored multiple times with one or more digital currency tokens, wherein each copy of the one or more audit trails is encrypted using one or more audit trail encryption keys.
[0069] wherein each of the one or more audit trails is stored in memory as a blockchain.
[0070] Any ranges or device numerical values given herein can be extended or modified without losing the intended effect, as will be apparent to those skilled in the art.
[0071] Examples have been described with reference to data monitored and / or collected from users (e.g., user identity data about user profiles). In certain examples, users are provided with notice about data collection (e.g., through a dialog box or preference settings), and given the opportunity to consent or decline monitoring and / or collection. The consent takes the form of opt-in consent or opt-out consent.
[0072] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
[0073] It is to be understood that the benefits and advantages described above apply to some embodiments, yet not necessarily all embodiments. Embodiments are not limited to embodiments that solve any or all of the stated problems. Rather, embodiments are intended to be broadly applicable, but not necessarily to the solutions of any or all of the stated problems. It will be readily understood to those skilled in the art that the above description is illustrative only and not restrictive, since other embodiments will become apparent to those skilled in the art in view of the foregoing description.
[0074] The embodiments shown and described herein, as well as embodiments not specifically described herein but within the scope of aspects of the claims presented, constitute exemplary ways of detecting fraudulent transactions without intermediaries in peer-to-peer payments.
[0075] The term "include" as used in this specification means "comprising," and thus specifies the presence of stated features or actions, but does not preclude the presence or addition of one or more other features or actions.
[0076] In some examples, the operations illustrated in the figures are implemented as software instructions encoded on a computer readable medium, or implemented in hardware programmed or designed to perform such operations, or both. For example, aspects of the present disclosure can be implemented as a system on a chip or other circuitry including a plurality of interconnected conductive elements.
[0077] The order of execution or performance of the operations in the examples of the present disclosure illustrated and described herein is not essential, unless otherwise specified. That is, the operations can be performed in any order, unless otherwise specified, and examples of the present disclosure can include additional or fewer operations than those disclosed herein. For example, it is contemplated that executing or performing a particular operation before, contemporaneously with, or after another operation is within the scope of aspects of the present disclosure.
[0078] When introducing elements of aspects of the present disclosure or the examples thereof, the articles "a," "an," "the" and "said" are intended to mean that there are one or more of the elements. The terms "comprising," "including," and "having" are intended to be inclusive and mean that there can be additional elements other than the listed elements. The term "exemplary" is intended to mean "an example of." The phrase "one or more of the following: A, B, and C" means "at least one of A and / or at least one of B and / or at least one of C."
[0079] Having thus described aspects of the present disclosure in detail, it will be apparent that modifications and variations are possible without departing from the scope of aspects of the present disclosure as defined in the appended claims. Since modifications and variations are possible using the structure, products, and methods described herein, the intent is to include all such modifications and variations in the scope of the present disclosure. Accordingly, it is submitted that all matter contained in the above description and shown in the accompanying drawings shall be interpreted as illustrative and not in a limiting sense.
Claims
1. A system for detecting fraudulent transactions in peer-to-peer payments without intermediaries, the system comprising: processor; A computer storage medium storing instructions that, when executed by the processor, operate as follows: Receive a request to identify whether the transaction chain that transfers digital currency from an initial sending wallet to a final receiving wallet is a fraudulent transaction, wherein the amount of digital currency includes one or more digital currency tokens; Retrieve and associate a first audit trail with a first digital currency token associated with a first transaction, wherein the first transaction is part of the transaction chain and is associated with one of the one or more digital currency tokens; At least by analyzing the first audit trail, wallet cloning or value tampering in the first digital currency token associated with the first transaction can be detected; and Based on the detection of wallet cloning or value tampering, the first transaction is designated as a fraudulent transaction. Each sending wallet, starting from the initial sending wallet, is configured as follows: Generate one or more audit trails associated with the transaction that transfers digital currency from the sending wallet to the receiving wallet; Digitally attach one or more elements of the digital credentials of the receiving wallet to each of the one or more digital currency tokens; as well as Each of the one or more digital currency tokens is cryptographically signed before being transferred to the receiving wallet, wherein each digital currency token maintains an audit trail of the digital wallets through which the digital currency token has been transacted before being received by the receiving wallet.
2. The system according to claim 1, wherein analyzing the first audit trace includes one or more of the following: analyzing token value tampering in the first digital currency token, analyzing whether the first digital currency token is a clone of the second digital currency token, and analyzing whether the first digital currency token is a counterfeit token.
3. The system of claim 1, wherein the one or more audit trails are encrypted and attached to their respective digital currency tokens.
4. The system of claim 3, wherein the encryption key used to encrypt the one or more audit trails is issued by one or more issuing server servers.
5. The system of claim 3, wherein the one or more audit trails are encrypted multiple times using multiple encryption keys.
6. The system of claim 3, wherein the decryption key for decrypting the one or more encrypted audit trails is encrypted using encryption keys held by a plurality of audit trail decryption key holders.
7. The system of claim 1, wherein the one or more audit trails are stored multiple times together with the one or more digital currency tokens, and each copy of the one or more audit trails is encrypted using one or more audit trail encryption keys.
8. The system of claim 1, wherein each of the one or more audit trails is stored in a blockchain.
9. A computerized method, comprising: One or more audit trails are generated to associate with the transaction chain that transfers digital currency from a sending wallet to a receiving wallet, the amount of digital currency being divided into one or more digital currency tokens, the sending wallet digitally attaching one or more elements of the receiving wallet's digital credentials to each of the one or more digital currency tokens, and cryptographically signing each of the one or more digital currency tokens before being transferred to the receiving wallet, each digital currency token maintaining an audit trail of the digital wallets through which the transaction passed before being received by the receiving wallet; Receive a request to identify whether a first transaction is a fraudulent transaction, the first transaction being part of the transaction and associated with one of the one or more digital currency tokens; and In response to receiving the request: Retrieve and link the first audit trail to the first digital currency token associated with the first transaction; At least by analyzing the first audit trail, wallet cloning or value tampering in the first digital currency token associated with the first transaction can be detected; and Based on the detection of wallet cloning or value tampering, the first transaction is designated as a fraudulent transaction.
10. The computerized method according to claim 9, wherein analyzing the first audit trail includes one or more of the following: analyzing token value tampering in the first digital currency token, analyzing whether the first digital currency token is a clone of the second digital currency token, and analyzing whether the first digital currency token is a counterfeit token.
11. The computerized method of claim 9, wherein the one or more audit trails are encrypted and attached to their respective digital currency tokens.
12. The computerized method of claim 11, wherein the encryption key for encrypting the one or more audit trails is issued by one or more issuing server servers.
13. The computerized method of claim 11, wherein the one or more audit trails are encrypted multiple times using multiple encryption keys.
14. The computerized method of claim 11, wherein the decryption key for decrypting the one or more encrypted audit trails is encrypted using encryption keys held by a plurality of audit trail decryption key holders.
15. The computerized method of claim 9, wherein the one or more audit trails are stored multiple times together with the one or more digital currency tokens, and each copy of the one or more audit trails is encrypted using one or more audit trail encryption keys.
16. The computerized method of claim 9, wherein each of the one or more audit trails is stored in a blockchain.
17. A computer storage medium storing computer-executable instructions, said instructions, when executed by a processor, causing the processor to at least: Generate one or more audit trails associated with the transaction chain that transfers digital currency from a sending wallet to a receiving wallet, the amount of which includes one or more digital currency tokens, wherein the sending wallet digitally attaches one or more elements of the receiving wallet’s digital credentials to each of the one or more digital currency tokens, and cryptographically signs each of the one or more digital currency tokens before transferring to the receiving wallet, and each digital currency token maintains an audit trail of the digital wallets through which the transaction passed before being received by the receiving wallet; Receive a request to identify whether a first transaction is a fraudulent transaction, the first transaction being part of the transaction and associated with one of the one or more digital currency tokens; and In response to receiving the request: Retrieve and associate the first audit trail with the first digital currency token associated with the first transaction; By analyzing the first audit trail, wallet cloning or value tampering was detected in the first digital currency token associated with the first transaction; and Based on the detection of wallet cloning or value tampering, the first transaction is designated as a fraudulent transaction.
18. The computer storage medium of claim 17, wherein analyzing the first audit trail includes one or more of the following: analyzing token value tampering in the first digital currency token, analyzing whether the first digital currency token is a clone of the second digital currency token, and analyzing whether the first digital currency token is a counterfeit token.
19. The computer storage medium of claim 17, wherein the one or more audit trails are encrypted and attached to their respective digital currency tokens.
20. The computer storage medium of claim 17, wherein each of the one or more audit trails is stored in a blockchain.