System for controlling functions of mobile application based on device fingerprint and sim card information and method thereof

TWI938073BActive Publication Date: 2026-09-01TAIWAN BUSINESS BANK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
TW114139141
Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-10-09
Publication Date
2026-09-01
Estimated Expiration
2045-10-08

Smart Images

  • Figure TWG2TB001909061_001
    Figure TWG2TB001909061_001
  • Figure TWG2TB001909061_002
    Figure TWG2TB001909061_002
  • Figure TWG2TB001909061_003
    Figure TWG2TB001909061_003
Patent Text Reader

Abstract

A system and method for controlling mobile application functions based on device fingerprint and SIM card information, which collects the current device fingerprint after the user logs in, and when the current device fingerprint does not match the pre-stored reference device fingerprint, queries the user's identity module change record based on the mobile phone number used by the device, and sets specific functions to be restricted or prohibited when the user identification module is determined to have been changed within a certain period of time based on the change record. This technical means can effectively prevent SIM card swapping, device spoofing or environmental manipulation attacks while reducing the false positive rate, while taking into account both financial transaction security and user experience.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A system for controlling mobile application functions based on device fingerprint and SIM card information, applied to an application installed on a device, the device having a Subscriber Identity Module (SIM), the system comprising at least: a customer login module for providing user login; an information collection module for collecting a current device fingerprint of the device after the user logs in, the current device fingerprint including device information of the device and identity information of the user identity module or hardware information of a hardware component on the device; an information processing module for obtaining a mobile phone number used by the device when the current device fingerprint does not match a pre-stored reference device fingerprint, and querying a change record of the user identity module based on the mobile phone number; and a function control module for restricting or prohibiting operation of at least one specific function of the application when the user identification module has been changed within a certain period of time based on the change record. An identity verification module is used to perform an identity verification operation when the user confirms the execution of at least one specific function item; and a function execution module is used to execute the normal function item when the user selects to execute one of the normal functions of the application, and to execute the at least one specific function item that has been confirmed to be executed after the identity verification operation is successfully completed.

2. The system for managing mobile application functions based on device fingerprint and SIM card information as described in claim 1, wherein the information processing module is further used to transmit the current device fingerprint to the mobile banking server when a user of the device logs into a mobile banking server for the first time using a mobile banking account through the application, so that the mobile banking server stores the current device fingerprint as the reference device fingerprint.

3. The system for managing mobile application functions based on device fingerprint and SIM card information as described in claim 1, wherein the system further includes a mobile banking server for adjusting a trust score based on the identity verification method and the verification operation process of the identity verification operation after the identity verification operation is successfully completed, and storing the current device fingerprint as another reference device fingerprint with a validity period when the trust score is greater than a predetermined risk value.

4. The system for managing mobile application functions based on device fingerprint and SIM card information as described in claim 1, wherein the function execution module is further used to collect the user's operation instructions for operating one of the at least one specific function items, and to execute the at least one specific function item in a delayed manner according to the operation instructions.

5. The system for managing mobile application functions based on device fingerprint and SIM card information as described in claim 1, wherein the identity recognition module is further used to determine the verification strength of the identity verification operation based on the risk level of the at least one specific function and the user's operating context.

6. A method for controlling mobile application functions based on device fingerprint and SIM card information, applied to a device having a user identification module, the method comprising at least the following steps: collecting a current device fingerprint of the device after a user logs in, the current device fingerprint including device information and identity information of the user identification module or hardware information of a hardware component on the device; when it is determined that the current device fingerprint does not match a pre-stored reference device fingerprint, obtaining a mobile phone number used by the device, and querying a change record of the user identification module based on the mobile phone number; when it is determined based on the change record that the user identification module has been changed within a certain period of time, setting at least one specific function of the application to be restricted or prohibited from operation; executing a normal function of the application when the user selects to execute it; and performing an identity verification operation when the user confirms the execution of the at least one specific function, and executing the confirmed execution of the at least one specific function after the identity verification operation is successfully completed.

7. The method for controlling mobile application functions based on device fingerprint and SIM card information as described in claim 6, wherein before the step of determining whether the current device fingerprint matches the pre-stored reference device fingerprint, the method further includes the step of determining that when a user of the device logs into a mobile banking server for the first time using a mobile banking account through the application, the current device fingerprint is transmitted to the mobile banking server, so that the mobile banking server stores the current device fingerprint as the reference device fingerprint.

8. The method for managing mobile application functions based on device fingerprint and SIM card information as described in claim 6, wherein after the identity verification operation is successfully completed, the method further includes a step in which a mobile banking server adjusts a trust score based on the identity verification method and the verification operation process of the identity verification operation, and when the trust score is greater than a predetermined risk value, stores the current device fingerprint as another reference device fingerprint with a validity period.

9. The method for managing mobile application functions based on device fingerprint and SIM card information as described in claim 6, wherein the step of executing the at least one specific function item that has been confirmed to be executed further includes collecting the user's operation instruction for operating the at least one specific function item, and delaying the execution of the at least one specific function item according to the operation instruction.

10. The method for managing mobile application functions based on device fingerprint and SIM card information as described in claim 6, wherein the step of performing the identity verification operation further includes a step of determining the verification strength of the identity verification operation based on the risk level of the at least one specific function item and the user's operating context.

Citation Information

Patent Citations

  • A method for constructing a reusable engineering management business component library

    CN115145561B

  • User interface and computer program product

    TW201537317A

  • User interface and computer program product

    TWI498698B