DYNAMIC PROCESS VERIFICATION SYSTEM

TR202613302A2Pending Publication Date: 2026-08-21TURKCELL TEKNOLOJI ARASTIRMA & GELISTIRME AS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TR202613302
Authority / Receiving Office
TR · TR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-08-06
Publication Date
2026-08-21

Smart Images

  • Figure 00000015_0000
    Figure 00000015_0000
Patent Text Reader

Abstract

This invention relates to a system (1) that enables the generation of dynamic verification codes and scenarios for each transaction by analyzing transaction data, and the execution of the generated verification codes in a secure isolated execution environment, in order to reduce the risk of fraud in electronic payment transactions.
Need to check novelty before this filing date? Find Prior Art

Description

1 TARIFF DYNAMIC PROCESS VERIFICATION SYSTEM Technical Area This invention replaces the traditional static rules used for payment systems with each It generates micro-code snippets specific to the current risk conditions for a financial transaction, and by executing the codes in a secure area, the payment process is dynamic. It is related to a system that enables verification. Previous Technique Rule engines used in current systems are largely predefined. It is based on static rules. These rules are determined by system administrators. It is manually created and updated by [the system / individual]. A new attack 15 When the model emerges, the relevant rules need to be redeveloped, tested, and It needs to be transferred to the production environment. This process causes a loss of time. security is also being compromised by attackers using new methods. It allows it to overcome its mechanisms. In addition, the machine Learning-based systems only produce a risk score, and the 20 in question... How the score will be evaluated is a fixed decision within the system. These mechanisms determine the attack scenarios. Although it changes, the decision-making logic remains the same. Patent number US20250021980A1, which is included in the prior art, 25 the document states that transaction data is used to detect fraud in electronic transactions. A method for generating rule sets is described. together, dynamic validation codes at runtime for each operation. creation, execution of the generated code in a secure, isolated execution environment and the validation logic, which varies according to the transaction conditions, is automatically 30 There is no technical solution for its production. 2 Brief Description of the Invention The purpose of this invention is to improve financial transactions carried out in electronic payment systems. To enhance transaction security, verification specific to each transaction is performed. algorithms that are automatically generated at runtime and the 5 generated algorithms Secure execution of verification algorithms independent of the main application. The goal is to develop a system that operates within that environment. Another aim of the invention is to replace predefined static rule sets with process rules. By generating dynamic verification codes that can vary depending on their characteristics, 10 The goal is to make it more difficult for attackers to predict system behavior. Detailed Description of the Invention The “Dynamic Process Verification 15” process was carried out to achieve the purpose of this invention. The "System" is shown in the attached figure; Figure 1. Schematic view of a system that is the subject of the invention. The parts shown in the figure are individually numbered, and these numbers correspond to 20. The corresponding answers are given below. 1. System 2. Electronic device 3. Database 25 4. Server D. External server Analyzing fraud risks in electronic payment transactions, on a transaction-by-transaction basis. Generates dynamic authentication codes, securely executes the generated codes. 3 operating in their environments and making transaction decisions based on the results obtained. The subject of the invention is the system (1); - the user initiates payment transactions, verification to ensure that the results and generated warnings are presented to the user. at least one electronic device configured to (2), 5 - transaction logs, user behavior information, device information, transaction their histories, risk scores, dynamically generated codes, code templates, verification results, feedback records, system logs, at least one database structured to store learning data (3) and 10 - payment infrastructures, digital payment platforms, network security systems and through at least one external server (D) in the form of corporate information resources information obtained regarding the payment transaction, device identification information, geographic location information, user behavior logs, transaction frequency, To determine the risk level related to payment transactions, successful and 15 Retrieving failed transaction logs, performing data processing on the retrieved data. performing processing operations, analyzing transaction data, processing determining the behavior and risk level, the dynamics specific to each transaction. validation scenarios and runtime executable validation codes to generate, isolate the generated verification codes from the main application 20 to run in a secure execution environment, as a result of execution Approval of the transaction by evaluating the verification results obtained, rejection or redirection to additional security verifications to make decisions regarding the results of the analysis and verification performed 25 by saving to the database (3) and learning from past transaction results updating verification scenarios and electronically publishing the results obtained at least one configured to deliver to the user via device (2) Includes server (4). 4 The system in question consists of (1) electronic devices (2), smartphones, tablet computers or a device in the form of a portable computer. The electronic device in question (2) any remote communication protocol included in the known state of the art by using the server (4) to establish a connection with the server and through this communication established with the server It is structured to exchange data with (4). The invention is preferred 5 In the application made, the electronic device (2) server (4) and the Internet as a data bus It is configured to exchange data using electronic means. device (2), transaction by the user regarding electronic payment transactions initiating, verifying payment and fulfilling transaction security requests It is configured to provide a user interface that allows entry. 10 Electronic device (2), authentication requests, transaction approval or rejection a user who enables the display of decisions and security alerts It is configured to provide the interface. Electronic device (2), server (4) transaction verification results, risk scores, and transactions generated by security statuses, verification statements and analyses performed 15 to provide an interface that allows the viewing of related outputs It is being structured. In the system that is the subject of the invention, the database (3) in (1) is in communication with the server (4) and is configured to be managed by the server (4). The invention is preferred In the implemented application, the database (3), transaction 20 regarding payment transactions their identities, transaction amounts, transaction time information, transaction channel information, user transaction histories, user behavior patterns, device fingerprint information, IP records, location information, success and failure results. transaction records, risk scores, generated dynamic code templates, work Metadata relating to instantly generated verification codes is securely isolated. 25 execution environment (sandbox) results, feedback logs, and learning It is structured to ensure that data is kept on record. The server (4) in the system (1) which is the subject of the invention, any remote communication to communicate with the electronic device (2) using the protocol and the established protocol 30 to exchange data with electronic devices (2) via communication is being configured. The server (4) in question enters new data into the database (3). recording, deleting the registered data in the database (3) or data Modifying the registered data in the database (3), within the database (3) Data processing involves operations such as updating and retrieving recorded data. It is configured to manage the base (3). The server (4) is configured by the user 5 Payment initiation, payment verification, transaction transmitted via electronic device (2) regarding confirmation, transaction cancellation, identity verification, and additional security verification. It is configured to receive requests. The server (4) is a payment service. providers, at least in the form of digital wallet platforms and virtual POS infrastructures. Transaction amount, transaction time, transaction 10 for payment processing via an external server (D) channel, process ID, device fingerprint, IP address, network connection information, geographic location information, user behavior logs, successful and The server (4) is configured to retrieve data on failed transaction histories. The received data is configured to be saved into the database (3). Server (4) performs data processing and analysis operations on the data stored in the database (3) 15 It is configured to be carried out via the server (4), the received data data cleaning, data validation, missing Data completion (Missing Value Imputation), data normalization (Normalization), data standardization (Standard Scaling), data enrichment (Data Enrichment), Feature Extraction, Process Vector 20 creation (Transaction Vector Generation) and analysis of a common data structure to perform at least one of the creation processes It is configured. The server (4) processes the generated operation vectors past operations. comparing the operation vectors obtained from the records, similar operations 25 in order to determine their behavior and identify abnormal processing patterns It is configured to perform vector similarity analysis. Server (4), to determine the transaction risk level as a result of the analyses performed It is configured. Server (4), transaction amount, transaction when determining risk level frequency, device change, IP address change, geographical location change, device fingerprint tracking information, user behavior model, past transaction records and transaction 30 to evaluate execution time data together 6 is configured. Server (4), each depending on the determined risk level It is structured to create dynamic scenarios for financial transactions. Server (4) analyzes incoming transaction data and verifies the relevant transaction-specific data. to determine the logic and create a suitable validation scenario It is being configured. Server (4) is within the scope of dynamic scenario creation 5 a template pool containing predefined safe code templates from risk The server (4) is configured to select the template that is suitable for the type. Transaction parameters, risk thresholds, and validation variables within the template By placing it, it can be interpreted at runtime using a domain-specific description language. It is configured to generate a verification code. Server (4), briefly 10 in case an unusual geographical location change is detected within to generate an authentication code that includes biometric authentication It is being configured. Server (4), high-value transaction with device change. If this is done, the device will perform fingerprint verification and additional 15 to generate another verification code that includes security checks is configured. The server (4) is configured according to the transaction properties for each transaction. It is configured to create different validation logic. Server (4), You can obtain the verification code generated during the transaction from the main payment application. To transfer to a secure, isolated execution environment in the form of a sandbox. It is configured. The server (4) only sends the generated verification code to the relevant 20 allowing access to transaction data, primary payment method, operating system to prevent direct access to resources and application components. It is configured. The server (4) gives the generated verification code a specific lifespan. It is configured to assign a time period. The server (4), after the process is completed by deleting the verification code from memory and restarting it for subsequent operations. It is configured to create a secure execution environment. The server (4) By evaluating the verification results obtained, the transaction is approved. decision to reject or apply additional security verifications It is configured to provide. The server (4) provides all the analysis performed. the results, the validation scenarios created, the 30 generated during the study Metadata related to verification codes, Sandbox execution results, process 7 recording decisions and user feedback into the database (3) It is configured to record successful and unsuccessful transaction logs. The server (4) to activate the feedback and learning mechanism by using It is structured. The server (4) contains code templates, risk assessment by updating its parameters and dynamic scenario generation processes, the next 5 to enable the creation of more advanced verification scenarios in transactions It is being structured. 15 8 Industrial Application of the Invention The system in question (1) is a financial system implemented in electronic payment systems. to increase the security of transactions and detect fraud attempts It can be implemented in information processing infrastructures. System (1), payment 5 It analyzes data related to operations, performing dynamic on-site operations at the moment of processing. generating verification codes, securely storing the generated verification codes running in the execution environment and processing operations according to the results obtained. approval, rejection, or referral to additional verification steps This invention provides banking systems and payment services. providers, electronic money institutions, digital wallet platforms, virtual POS It can be implemented in infrastructure and other electronic payment systems. Within the framework of these fundamental concepts, the subject of the invention is "Dynamic Process Verification". It is possible to develop various arrangements regarding the system (1), and the invention 15 The scope of invention protection is not limited to the examples described here. As defined in the requirements.

Claims

9 REQUESTS 1. Analyzing the risks of fraud in electronic payment transactions, the process Generating dynamic verification codes on a per-system basis, securely generating the generated codes. run in execution environments and process according to the results obtained. 5 that enable the formation of decisions - the user initiates payment transactions, verification to ensure that the results and generated warnings are presented to the user. at least one electronic device configured to (2), - transaction logs, user behavior information, device information, transaction their histories, risk scores, dynamically generated codes, code 10 templates, verification results, feedback records, system logs, at least those configured to store learning data. a database (3) and - payment infrastructures, digital payment platforms, network security systems and At least one external server (D) in the form of corporate information resources 15 payment transaction information obtained through the device identity information, geographic location information, user behavior records, transaction frequency, risk level related to payment transactions successful and unsuccessful transaction log data to determine obtaining and performing data preprocessing operations on the received data, 20 Analyzing trading data to understand trading behavior and risk levels. to determine, dynamic validation scenarios specific to each process, and generating runtime execution verification codes, generated verification codes are stored in a secure environment isolated from the main application. running in the execution environment, 25 obtained as a result of execution Confirmation of the transaction by evaluating the verification results, rejection or redirection to additional security verifications making decisions regarding the matter, analysis and verification carried out. to record the results in the database (3), past transaction results by learning and updating the validation scenarios and the 30 obtained to present the results to the user via an electronic device (2) a server characterized by containing at least one configured server (4) system (1).

2. Smartphone, tablet computer, desktop computer or portable 5 Claim characterized by a computer-like electronic device (2) A system like the one in 1 (1).

3. Connect to the server (4) using any remote communication protocol. to establish and transmit data between the server (4) and the established connection 10 an electronic device configured to facilitate a transaction A system like the one in Claim 1 or 2 characterized by (2) (1).

4. Connecting to the server (4) via a data network such as the Internet. Claim 15 is characterized by an electronic device (2) configured to do so. A system like the one in 3 (1).

5. Transactions related to electronic payment transactions by the user. initiation, payment verification and transaction security 20 configured to provide an interface that allows requests to be entered from the above claims characterized by electronic device (2) a system like any other (1).

6. Identity verification requests, transaction approval or rejection decisions, and security alerts, transaction validation generated by server (4) 25 results, risk scores, transaction security statuses, verification explanations and the outputs of the analyses carried out configured to provide an interface that allows its display any of the above claims characterized by an electronic device (2) a system like one of them (1). 30 11 7. To be in communication with Server (4) and to be managed by Server (4) above characterized by the structured database (3) a system like any of the requests (1).

8. Transaction IDs, transaction amounts, and transaction times related to payment transactions. information, transaction channel information, user transaction history, user behavioral patterns, device fingerprint information, IP logs, location information, records of successful and unsuccessful transactions, risk their scores, the dynamic code templates generated, at runtime Metadata relating to the generated verification codes is securely isolated. 10 runtime (sandbox) results, feedback logs, and to ensure that learning data is recorded and stored The above is characterized by the database structured as (3) a system like any of the requests (1).

9. Using any remote communication protocol, electronic device (2) to communicate with and through this communication with electronic devices (2) server (4) configured to exchange data with as in any of the above characterized claims system (1). 20 10. Payment initiation, payment transmitted via electronic device (2). verification, transaction confirmation, transaction cancellation, identity verification, and additional server configured to receive security verification requests 25 as in any of the above claims characterized by (4). a system (1).

11. Payment service providers, digital wallet platforms, and virtual POS payment processing via at least one external server (D) in the form of infrastructure Transaction amount, transaction time, transaction channel, transaction ID, device ID 30 information (Device Fingerprint), IP address, network connection information, geographical 12 Location information, user behavior logs, successful and failed transactions. history characterized by the server (4) configured to receive data. a system like any of the above-mentioned requests (1).

12. Recording the received data into the database (3), data processing and analysis 5 to perform operations on data stored in the database (3) The above is characterized by the server (4) configured to do so. a system like any of the requests (1).

13. Data cleaning, data verification, missing data on the received data. 10 completion, data normalization, data standardization, data enrichment feature extraction, process vector generation and analysis at least one of the processes for creating a usable common data structure characterized by the server (4) configured to perform a system like any of the above requests (1). 15 14. The generated transaction vectors are derived from transaction records. to compare with vectors, identify similar processing behaviors, and Vector similarity analysis is used to detect abnormal transaction patterns. 20 characterized by the server (4) configured to perform a system like any of the above requests (1).

15. Determining the transaction risk level based on the results of the analyses performed, risk When determining the level, factors such as transaction amount, transaction frequency, device change, and IP address are considered. change, geographical location change, device fingerprint information, user 25 behavioral pattern, past transaction records and transaction execution time characterized by the server (4) configured to evaluate together a system like any of the above-mentioned requests (1). 13 16. Dynamic for each financial transaction depending on the determined risk level. characterized by the server (4) configured to create the scenario a system like any of the above requests (1).

17. By analyzing the incoming transaction data, develop the validation logic specific to that transaction. 5 to determine, create a suitable validation scenario and dynamic scenario predefined secure code templates within the scope of creation to select the template that matches the risk type from a pool of templates from the above requests characterized by the configured server (4) a system like any other (1). 10 18. Enter transaction parameters, risk thresholds, and validation into the selected template. Working by inserting variables and using a domain-specific definition language. configured to generate instantly interpretable verification code any of the above requests characterized by server (4) 15 a system like one of them (1).

19. Detection of an unusual change in geographical location within a short period of time. in this case a verification code that includes biometric authentication creating, high-value transaction 20 along with device replacement If this is done, the device will require fingerprint verification and additional features. to generate a different verification code that includes security checks from the above requests characterized by the configured server (4) a system like any other (1).

20. Different validation logic for each transaction depending on the transaction characteristics. to create, the verification code generated during the transaction to the main payment from the application, a secure execution isolated in a sandbox format. characterized by the server (4) configured to transfer to the environment a system like any of the above requests (1). 30 14 21. The generated verification code should only be used with the data related to the transaction. allowing access to the main payment system, operating system resources, and to prevent direct access to other application components from the above requests characterized by the configured server (4) a system like any of them (1). 5 22. Assigning a specific lifespan to the generated verification code, process After completion, the verification code is deleted from memory. Server configured to be re-created for subsequent operations (4) a 10 as in any of the above claims characterized by system (1).

23. Verification results obtained from a secure execution environment. by evaluating the transaction, approving, rejecting or adding 15 to decide on the implementation of security verifications from the above requests characterized by the configured server (4) a system like any other (1).

24. All analysis results performed are verified using the created validation system. scenarios, meta 20 relating to verification codes generated during runtime data, Sandbox execution results, transaction decisions, and user feedback. configured to record their notifications into the database (3) any of the above requests characterized by the server (4) a system like one of them (1).

25. Using records of successful and unsuccessful transactions for feedback and learning. to run the mechanism, code templates, risk assessment by updating its parameters and dynamic scenario generation processes creating more advanced validation scenarios in subsequent processes 30 characterized by the server (4) configured to provide a system like any of the above requests (1).