System and method for generating and delivering a personalised rich media message having a redeemable component
The system delivers personalized rich media messages with pre-authenticated links that verify device characteristics, addressing the inconvenience and security issues of digital gift cards, providing immediate accessibility and enhanced security.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- MOBILE DIGITAL IP PTY LTD
- Filing Date
- 2025-10-29
- Publication Date
- 2026-05-21
AI Technical Summary
Existing digital gift card delivery methods are cumbersome, insecure, and inconvenient, often leading to lost or overlooked messages, impersonal experiences, and risks from cyber threats, which diminish the spontaneity and appeal of gifting.
A system and method for generating and delivering personalized rich media messages with a redeemable component, using pre-authenticated shortened links that verify device characteristics upon activation, ensuring security and immediate accessibility.
Enhances user experience with immediate usability and robust security, reducing fraud risks and streamlining the redemption process across multiple platforms.
Smart Images

Figure AU2025051232_21052026_PF_FP_ABST
Abstract
Description
TITLESystem and Method for Generating and Delivering a Personalised Rich Media Message Having a Redeemable ComponentFIELD OF THE INVENTION
[0001] The present invention relates generally to the field of digital communication and digital asset delivery systems. More particularly but not exclusively, the present invention relates to a system and method for generating and delivering unique, personalised rich media messages that include a redeemable component. These messages can be delivered across multiple messaging platforms and are immediately accessible by an individual recipient on a mobile computing device.BACKGROUND TO THE INVENTION
[0002] Typically, gift cards, also known as gift vouchers, tokens, or certificates, have a monetary value that can be exchanged for goods and / or services at specific businesses. Many retailers offer gift cards in the form of a plastic debit card with a magnetic strip or electronic chip that can be swiped through a reader at the point of sale. A disadvantage of such plastic cards is that users must remember to carry the cards with them when shopping, and large collections of such cards can be cumbersome to store in a wallet or purse.
[0003] Some retailers offer eGift cards for sale online. These gift cards generally include a code that users must click on to have the card delivered to their email address. When the code is clicked, users are redirected to a page displaying a gift card number that can be provided to the retailer, or a page including a barcode that can be printed and scanned by the retailer. Some retailers also send a message via email or short message service (SMS) to a recipient for whom the gift card has been purchased, providing a uniform resource locator (URL) link to a registration page where the recipient can sign up to access the gift card.
[0004] While online gift cards can be easier to purchase, the above approaches can make them less convenient to use than physical cards. In many instances, eGift cards are overlooked by the recipient, as they may get lost among the bulk of promotional emails. Additionally, the registration processes required for online cards are often impersonal and time-consuming, which detracts from the spontaneity and excitement typically associated with gifting. Clicking on unknown or truncated links also poses a risk to users, as it may lead to hesitation, thereby diminishing the immediacy and appeal of receiving a digital gift card.
[0005] Moreover, online gift cards are vulnerable to various forms of scam and cyber threats. Fraudulent messages that appear as legitimate gift card notifications are often sent via email or SMS, tricking recipients into clicking URL links that may install viruses, malware, or other harmful software on their devices. This risk of scams can discourage recipients from trusting and opening messages related to online gift cards, and such messages may also be blocked by spam filters, resulting in delays or the failure of gift card deliveries.
[0006] Existing methods for generating and delivering gift cards or vouchers using URLs, such as those described in U.S. Patent No. 11,830,025, have addressed some of these issues by providing a method for generating personalised rich media messages with immediately redeemable components. However, as digital messaging technologies evolve, so do the sophistication and variety of cyber threats targeting these systems. Techniques such as spoofing, VPNs, proxies, and automated bots present risks, including potential interception or unauthorised activation of digital gift card links. Implementing traditional security measures like multi-factor authentication, encryption, and rigorous identity verification can effectively mitigate these risks but often adds friction for end users, potentially impacting their experience.
[0007] Therefore, it would be advantageous to provide an improved system and method for generating and delivering personalised rich media messages with a redeemable component, while ensuring a high level of security and user convenience.OBJECT OF THE INVENTION
[0008] It is an object of the present invention to overcome and / or alleviate one or more of the disadvantages of the prior art or provide the consumer with a useful alternative.SUMMARY OF THE INVENTION
[0009] In one form, although not necessarily the broadest form, the invention resides in a method for delivering a personalised rich media message. The method comprises:generating, via a server, a pre-authenticated shortened link including a long Uniform Resource Locator (URL) and a recipient contact identifier identifying a recipient mobile number;incorporating, via the server, the pre-authenticated shortened link into a personalised rich media message having a redeemable component;transmitting, via a mobile messaging platform, the personalised rich media message to a mobile computing device using the recipient mobile number;requesting, by selecting, clicking or otherwise activating the preauthenticated shortened link, connection between the mobile computing device and the long URL; andperforming, via the server, a security verification of the connection request by obtaining one or more details of the mobile computing device and comparing these details with stored metadata and / or expected device characteristics obtained from the pre-authenticated link;wherein, upon detecting any discrepancies between the one or more details of the mobile computing device and stored metadata and / or expected device characteristics, triggering additional security challenges or blocking the connection request; orwherein, upon confirming a match between the one or more details of the mobile computing device and stored metadata and / or expected device characteristics, redirecting the mobile computing device to the long URL, wherein the redeemable component is accessible.
[0010] Preferably, the one or more details of the mobile computing device are aggregated to generate a unique fingerprint of the mobile computing device and / or between the mobile computing device and the server. The one or more details preferably include one or more of the following: user-agent string, browser type and version, browser plugins, screen resolution, language settings, time zone, operating system type and version, installed fonts, device model, central processing unit CPU type and architecture, graphics processing unit details, available memory, battery level and charging status, Internet Protocol (IP) address, connection type, proxy or virtual private network (VPN) usage, Transmission Control Protocol / lnternet Protocol (TCP / IP) stack fingerprinting, local and public IP addresses, unique device identifier (UUID), cookies or other tracking identifiers, mouse movement patterns, touch screen data, cipher suites, Transport Layer Security (TLS) version, and elliptic curves and extensions used.
[0011] Preferably, the stored metadata includes one or more of the following: recipient mobile number, recipient name, sender mobile number, sender name, a timestamp of the long URL and recipient mobile number, sender agent string, sender device type, sender IP address, sender connection type, sender geolocation, message preferences and scheduled delivery date.
[0012] Preferably, the expected device characteristics are based on historical user-agent strings and other metadata collected from previous interactions.
[0013] In some embodiments, where discrepancies are related to dynamic device or session characteristics that are expected to change over time or under certain conditions but are not typically indicative of fraud or malicious behaviour, such as changes in IP address within a common geographic location and / or browser settings, the security verification presents, via the server, a CAPTCHA challenge on the mobile computing device, requesting multi-factor authentication or sending a verification code to the mobile computing device using the recipient mobile number. Where discrepancies are related to static or persistent device identifiers that are unlikely to change frequently and whose alteration suggests a higher risk of unauthorised access, such as UUlDs and use of VPNs or proxies, the security verification step blocks the IP address and / or the UUID of the mobile computing device.
[0014] In some embodiments, the method further comprises implementing, via the server, rate limiting for successive connection requests based on the one or more details of the mobile computing device and / or session token, wherein each unsuccessful connection request results in an exponentially increasing block time before the mobile computing device is permitted to attempt another connection.
[0015] In some embodiments, the method further comprises integrating, via the server, with third-party reputation services to identify connection requests associated with known malicious IP addresses, Virtual Private Networks (VPNs), or suspicious user agents. Upon identifying such connection requests, the security verification step blocks the IP address and / or UUID of the mobile computing device.
[0016] In some embodiments, the method further comprises tracking, via the server, successive connection requests from multiple IP addresses associated with the mobile computing device or user session. Upon detecting multiple IP addresses in a predetermined timeframe, the security verification step blocks the UUID of the mobile computing device.
[0017] In some embodiments, the method further comprises tracking, via the server, rapid changes in geo-location between successive connection requests based on an elapsed time and geographic distance between the connection requests. Upon detecting any such rapid changes, the security verification step blocks the UUID of the mobile computing device.
[0018] In some embodiments, the method further comprises generating, via the server, a short-lived session token upon a first valid connection request and validating the short-lived session token for each successive connection request. After a predetermined time or after detecting any discrepancies between the one or more details of the mobile computing device and stored metadata and / or expected device characteristics, the short-lived session token is invalidated.
[0019] In some embodiments, the method further comprises monitoring, via the server, a timestamp and frequency of requests from a single session or IP address. Upon detecting excessive connection requests inconsistent withexpected user activity patterns based on historical data or predefined thresholds, the security verification steps triggers additional security challenges.
[0020] In some embodiments, the method further comprises storing, via the server, a record of each successful and unsuccessful connection request in a metadata database.
[0021] Preferably, the messaging platform is selected from a group consisting of Multimedia Messaging Service (MMS), Rich Communication Services (RCS), and any equivalent or technologically advanced messaging service that provides substantially similar functionality in delivering rich media content to mobile devices.
[0022] Preferably, the URL and recipient contact identifier of the preauthenticated shortened link are generated using a timestamp and a hashing algorithm.
[0023] In some embodiments, for a first-time user, the method includes, via the server, guiding the user through a simplified registration process upon redirection to the long URL. Additionally, for a returning user, the method includes bypassing, via the server, the registration process, login, and product selection steps, thereby directing the user to a pre-populated cart where the redeemable component is immediately accessible upon redirection to the long URL.
[0024] Preferably, the personalised rich media message includes a personalised animation with an intuitive identifier that includes embedded instructions and / or IP lookup functionality.
[0025] The method of any one of the preceding claims, wherein the redeemable component comprises a digital gift card, voucher, coupon or advertisement.
[0026] In another form, although not necessarily the broadest form, the invention resides in a system for delivering a personalised rich media message. The system comprises:one or more processors; anda memory storing instructions that, when executed by the one or more processors, performs the method according to the first form of the invention.
[0027] In another form, although not necessarily the broadest form, the invention resides in a non-transitory computer-readable medium storing instructions that, when executed by one or more processors, perform the method according to the first form of the invention.BRIEF DESCRIPTION OF THE DRAWINGS
[0028] In order that the invention may be readily understood and put into practical effect, reference will now be made to preferred embodiments of the present invention with reference to the accompanying drawings, wherein like features have been denoted with like reference numbers to indicate similar elements across the various figures.
[0029] FIG. 1 is a flow chart illustrating a method for delivering a personalised rich media message, according to one form of the invention;
[0030] FIG. 2 is a message sequence diagram illustrating a method for ordering and transmitting a personalised rich media message, according to an embodiment of the invention;
[0031] FIG. 3 is a message sequence diagram illustrating a method for generating and integrating a pre-authenticated shortened link with a redeemable component, according to an embodiment of the invention;
[0032] FIG. 4 is a message sequence diagram illustrating a method for verifying a connection request initiated upon a recipient selecting, clicking, or otherwise activating a pre-authenticated shortened link, in accordance with an embodiment of the invention;
[0033] FIG. 5A is an illustration of an exemplary digital gift card, according to an embodiment of the invention;
[0034] FIG. 5B is an illustration of another exemplary digital gift card, according to an alternative embodiment of the invention;
[0035] FIG. 6 is an illustration of an exemplary advertisement, according to an embodiment of the invention;
[0036] FIG. 7 is an illustration of a process flow of another exemplary advertisement, according to an alternative embodiment of the invention; and
[0037] FIG. 8 is a system diagram illustrating a system according to an embodiment of the invention.
[0038] Skilled addressees will appreciate that the drawings may be schematic and that elements in the drawings are illustrated for simplicity and clarity and have not necessarily been drawn to scale. For example, the relative dimensions of some of the elements in the drawings may be distorted to help improve understanding of embodiments of the present invention.DETAILED DESCRIPTION OF THE INVENTION
[0039] Embodiments of the present invention reside primarily in a system and method for delivering a personalised rich media message as described, detailing only those specific aspects necessary for a person skilled in the art to implement the invention. However, it will be appreciated that the invention is not limited to this particular field of use and may also be utilised in various other applications where similar functionalities are required.
[0040] In this specification, the phrase “and / or,” as used herein in the specification and in the claims, should be understood to mean “either or both” of the elements so conjoined, i.e. , elements that are conjunctively present in some cases and disjunctively present in other cases.
[0041] Multiple elements listed with “and / or” should be construed in the same fashion, i.e., “one or more” of the elements so conjoined. Other elements may optionally be present other than the elements specifically identified by the “and / or” clause, whether related or unrelated to those elements specifically identified. Thus, as a non-limiting example, a reference to “A and / or B”, when used in conjunction with open-ended language such as “comprising” can refer, in one embodiment, to A only (optionally including elements other than B); in another embodiment, to B only (optionally including elements other than A); in yet another embodiment, to both A and B (optionally including other elements); etc.
[0042] Terms such as “or” should be understood to have the same meaning as “and / or” as defined above. For example, when separating items in a list, “or” or “and / or” shall be interpreted as being inclusive, i.e. , the inclusion of at least one, but also including more than one, of a number or list of elements, and, optionally, additional unlisted items. Only terms clearly indicated to the contrary, such as “only one of’ or “exactly one of,” or, when used in the claims, “consisting of,” will refer to the inclusion of exactly one element of a number or list of elements. In general, the term “or” as used herein shall only be interpreted as indicating exclusive alternatives (i.e. “one or the other but not both”) when preceded by terms of exclusivity, such as “either”, “one of,” “only one of,” or “exactly one of.” “Consisting essentially of,” when used in the claims, shall have its ordinary meaning as used in the field of patent law.
[0043] The term “approximately”, as used herein, means that the amount is nominally the number following the term “approximately” but the actual amount may vary from this precise number to an unimportant degree.
[0044] Words such as “comprises,” “includes,” “consisting,” “containing,” or any of their derivatives, are intended to define a non-exclusive inclusion. Thus, a method, system or computer-readable medium that comprises a list of elements does not limit the inclusion to only those elements but may also include additional elements not expressly listed, including elements inherent to such a method or apparatus.
[0045] FIG. 1 illustrates a method 100 for delivering a personalised rich media message according to one form of the present invention. The method 100 comprises the following steps:
[0046] At step 110, the method 100 comprises generating, via a server, a preauthenticated shortened link including a long URL and a recipient contact identifier identifying a recipient mobile number.
[0047] At step 120, the method 100 comprises incorporating, via the server, the pre-authenticated shortened link into a personalised rich media message having a redeemable component. As described herein, the personalised rich media message can include a personalised animation with a user-intuitive interface for a recipient.
[0048] At step 130, method 100 comprises transmitting the personalised rich media message to a recipient's mobile computing device via a mobile messaging platform, using the recipient's mobile number. Such messaging platforms can include Multimedia Messaging Service (MMS), Rich Communication Services (RCS), or any equivalent or advanced messaging service that provides substantially similar functionality in delivering rich media content to mobile devices.
[0049] At step 140, the method 100 comprises requesting, by selecting, clicking or otherwise activating the pre-authenticated shortened link, connection between the mobile computing device and the long URL.
[0050] At step 150, the method 100 comprises performing, via the server, a security verification of the connection request by obtaining one or more details of the mobile computing device and comparing these details with stored metadata and / or expected device characteristics obtained from the preauthenticated link. If any discrepancies are detected between the one or more details of the mobile computing device and stored metadata and / or expected device characteristics, the server initiates additional security challenges or blocks the connection request. Alternatively, if the server confirms a match between the one or more details of the mobile computing device and stored metadata and / or expected device characteristics, allowing the connection request to proceed successfully, the server then redirects the mobile computing device to the long URL, where the redeemable component is accessible. In some embodiments as described herein, the redeemable component is accessible immediately.
[0051] Various embodiments of the present invention can offer advantages that provide an effective solution for various applications, particularly those related to gifting for special occasions, customer reward programs, promotional campaigns and giveaways. Notable advantages include:• Multiplatform Compatibility: The method allows rich media messages to be delivered across various messaging platforms, allowing users and recipients using different device types to send and receive messages without limitations;• Enhanced User Experience: The personalised rich media message can incorporate user-centric design elements and intuitive interfaces, providing recipients with an engaging and memorable experience that fosters both enjoyment and trust. By leveraging customisable features, the rich media message can visually distinguish itself from potential scams, allowing recipients to quickly recognise legitimate messages, thereby reducing confusion and increasing user confidence. The use of shortened links over long URLs further enhances this benefit by making the message more concise and appealing, thereby improving user trust and click-through rates.• Active on Arrival: Unlike many conventional e-gift cards that require recipients to complete authentication steps after delivery, the personalised rich media message generated according to the present invention is active on arrival from the user’s perspective. The devicebinding and pre-authentication of the link are performed prior to delivery, and any security verification that occurs after delivery is performed automatically and transparently upon link activation without requiring further input from the recipient. Accordingly, when the message is delivered, the redeemable component is immediately usable without post-delivery recipient-side activation steps, thereby maintaining spontaneity while still preserving security.• Robust Security and Fraud Protection: The integrated security verification step offers robust protection against various forms of fraud, including spoofing, automated bot attacks, and other techniques used to target the redeemable component. By cross-referencing device-specific details with pre-authenticated metadata and / or expected device characteristics, the method significantly reduces the risk of unauthorised access or misuse, helping ensure the redeemable component remains secure for both senders and users. Moreover, the personalisation of each link creates a unique identifier for every recipient, allowing for tracking and monitoring of user interactions with the link, further enhancing security and fraud protection measures.
[0052] Those skilled in the art will appreciate that not all of the above advantages are necessarily present in all embodiments of the present invention.
[0053] FIG. 2 illustrates a process flow of a method 200 for ordering and transmitting a personalised rich media message, according to an embodiment of the present invention. In this embodiment, the rich media is in the form of a digital gift card 210, which will be described herein for explanatory purposes as a digital gift card 210 delivered to a recipient as part of a gifting process. The method 200 utilises various interconnected components specifically referenced in relation to the digital gift card 210, including a Gift Card Portal 220, MobileDigital Portal 230, MobileDigital API 240, Smarter Shortened Links 250, and Multi-Dimension Verification 260. However, while the example herein employs a digital gift card as the rich media, it should be understood that other forms of personalised rich media, such as vouchers, coupons, advertisements, or redeemable messages, may be similarly ordered and transmitted through the method 200 to a mobile computing device of the recipient.
[0054] The method 200 of ordering and delivering personalised rich media is initiated when a user or consumer selects the digital gift card 210 through a client’s sales platform, represented herein as the Gift Card Portal 220. Upon selection and purchase, payment for the digital gift card 210 is processed by an integrated payment gateway. Once payment is confirmed, the Gift Card Portal 220 transmits essential transactional data to the MobileDigital Portal 230 via the MobileDigital API 240.
[0055] The transmitted data includes one or more various elements for creating the personalised rich media message, such as recipient’s mobile number, recipient’s name, sender’s mobile number, sender’s name, a timestamp of the transaction, a long URL, sender agent string, sender device Universally Unique Identifier (UUID), sender device type, sender IP address, sender connection type, sender geolocation, message preferences including digital gift card template details, fields for populating media and text components, and a scheduled delivery date. This data is stored in a metadatabase as metadata.
[0056] The MobileDigital Portal 230 then performs a multi-dimensional verification process 260 on the metadata. This verification process generates a risk score based on factors such as sender identity, device details, and connection metadata, contributing to fraud prevention and ensuring transaction security. Following the risk assessment, the MobileDigital Portal 230 receives a risk score along with an acceptance or rejection decision. If the transaction is approved, an acceptance notification is sent back to the Gift Card Portal 220.
[0057] Upon risk acceptance, the MobileDigital Portal 230 generates a preauthenticated shortened link, or a "Smarter Shortened Link" 250, dedicated to redemption of the digital gift card 210. This shortened link 250, unique to the transaction, is incorporated into an animated image including a final gift card code. The consumer can choose this animated image from various templates, allowing for personalisation in the gifting experience. Once the digital gift card 210 is generated with the embedded shortened link 250, it is prepared for delivery to the recipient.
[0058] The MobileDigital Portal 230 then transmits the digital gift card 210 to the mobile computing device via a secure direct carrier connection, selecting the optimal messaging platform based on the device’s capabilities. For instance, if the mobile computing device supports RCS, the MobileDigital Portal 230 will default to RCS for message delivery. Alternatively, if RCS is not supported, the MobileDigital Portal 230 will use Multimedia MMS. Advantages of this approach include improved delivery rates and enhanced user experience.
[0059] Once delivered, the MobileDigital Portal 230 monitors a delivery status and receives notifications indicating the success, failure, or retrieval status of the personalised rich media message. These notifications, along with any responses from the recipient, are stored in the metadatabase, providing a comprehensive log for tracking message performance and recipient interactions.
[0060] FIG. 3 illustrates a process flow of a method 300 for generating and integrating a pre-authenticated shortened link with a redeemable component, according to an embodiment of the present invention. The method 300 beginsby establishing a URL structure that includes user-intuitive identifiers designed to enhance user experience and accessibility. For instance, the identifier “tap2redeem” serves as a user-friendly prompt that indicates to recipients the action they can take. Such identifiers are specifically chosen to be clear and actionable, promoting user engagement. However, while the identifier “tap2redeem” is used for explanatory purposes herein, it should be understood that other user-intuitive links can be applied, such as “Tap2Buy,” “Tap2Win,” and “Tap2Review” etc. These identifiers are characterised by their simplicity and directness, making them easily memorable and encouraging user interaction.
[0061] When a consumer orders a rich media item in accordance with the embodiments described herein, the pre-authenticated link has a URL structure as follows:• Format: https: / / Tap2Redeem.link / {param1} / {param2}• paraml: generate_short_id(long_url)• param2: generate_short_id(mobile_number)
[0062] The generate_short_id function operates by using input parameters, such as a current timestamp and a hashing algorithm (e.g., SHA256), to extract the first 8 characters of the resulting hash. Each parameter is configured to be 8 characters long and is comprised of hexadecimal characters, generating an exceptionally large number of unique combinations - approximately 1.84467 x 10A19. This high number of combinations, coupled with the time-based generation process, ensures that the link is virtually unguessable. To predict the generated ID, knowledge of the exact creation time would be required, adding an additional layer of security. Furthermore, the method 300 incorporates embedded instructions and / or IP lookups to enhance functionality and tracking.
[0063] Incorporating a recipient’s mobile number as a unique parameter within the link structure also adds an extra layer of protection. For example, even if the link is shared, the specific association of the link with the mobile computing device of a recipient ensures access is restricted solely to the intended user. This user-specific access control, combined with the direct delivery of the linkto the mobile computing device, eliminates the need for additional two-factor authentication, thereby enhancing usability and streamlining the redemption process.
[0064] To further reinforce security, all sensitive data, including original URLs, is encrypted before transmission. Additionally, the method 300 employs HTTPS for all communications, ensuring data protection throughout the transmission process.
[0065] FIG. 4 illustrates a process flow of a method 400 for verifying a connection request initiated upon a recipient selecting, clicking, or otherwise activating a pre-authenticated shortened link, in accordance with an embodiment of the present invention. Method 400 employs a security check system which incorporates a Mobile Device Verification (MDV) server configured to authenticate the connection request based on device characteristics and environmental conditions associated with a mobile computing device of the recipient.
[0066] Upon activation of the pre-authenticated shortened link by a recipient, the MDV server records one or more details from the recipient mobile computing device initiating the connection request. These details are aggregated to generate a unique fingerprint of the mobile computing device and / or establish a secure link between the mobile computing device and the MDV server. The fingerprinting process may include capturing one or more of the following details from the mobile computing device: user-agent string, browser type and version, installed browser plugins, screen resolution, language settings, time zone, operating system type and version, installed fonts, device model, central processing unit (CPU) type and architecture, graphics processing unit details, available memory, battery level and charging status, Internet Protocol (IP) address, connection type, proxy or virtual private network (VPN) usage, Transmission Control Protocol / lnternet Protocol (TCP / IP) stack fingerprinting, local and public IP addresses, unique device identifier (UUID), cookies or other tracking identifiers, mouse movement patterns, touch screen data, cipher suites, Transport Layer Security (TLS) version, and elliptic curves and extensions used.
[0067] In some embodiments, the one or more details further include carrierlevel subscription identifiers made available by an embedded SIM (eSIM) or embedded universal integrated circuit card (elllCC) associated with the mobile computing device. Such identifiers may include, for example, an elllCC Identifier (EID), an Integrated Circuit Card Identifier (ICCID) of an installed profile, an International Mobile Subscriber Identity (IMSI), or other subscription identifiers that persist at the hardware level. Incorporating such eSIM-based identifiers into the fingerprint provides a tamper resistant and persistent verification signal that is resistant to device-level spoofing and contributes to establishing a trusted redemption event.
[0068] The MDV server then compares the gathered device details with expected device characteristics stored in association with the pre-authenticated link. These expected characteristics are generated based on historical metadata such as user-agent strings and other interaction data collected from previous interactions with the device. If any discrepancies are detected between the mobile computing device details and the stored metadata or expected device characteristics, the MDV server initiates additional security challenges or, if warranted, blocks the connection request.
[0069] Alternatively, if the server confirms a match between the mobile computing device details and the stored metadata or expected characteristics, allowing the connection request to proceed, the server redirects the mobile computing device to the long URL, where the redeemable component is accessible. In certain embodiments described herein, the redeemable component may be accessible immediately following verification.
[0070] In some embodiments, the expected device characteristics further include one or more eSIM-based identifiers previously associated with the preauthenticated link, such as an EID, ICCID, or IMSI obtained from prior interactions or registration data, such that a match or mismatch between the obtained eSIM-based identifiers and the expected identifiers contributes to the verification decision.
[0071] For discrepancies that relate to dynamic or session-specific device characteristics that may change over time or under certain conditions but arenot typically indicative of fraud or malicious behaviour, such as IP address shifts within a common geographic location or updates to browser settings, the server may present a CAPTCHA challenge to the mobile computing device, request multi-factor authentication, or send a verification code to the device using the recipient’s mobile number.
[0072] In contrast, for discrepancies related to static or persistent device identifiers, which are unlikely to change frequently and whose alteration may suggest a higher risk of unauthorised access, such as UlllDs or indications of VPN or proxy use, the MDV server may block the IP address associated with the mobile computing device or take other measures to restrict access.
[0073] In some embodiments, the method 400 further comprises implementing rate limiting for successive connection requests based on the details of the mobile computing device and / or session token. Each unsuccessful connection request results in an exponentially increasing block time, thereby progressively delaying further attempts by the same device. Such a progressive blocking mechanism can help mitigate the risk of automated spam attacks by making it impractical for bots or other automated systems to continuously attempt reconnections. For example, the block time could increase from 10 seconds after the first failed attempt, to 30 seconds after the second, to 60 seconds after the third, and so forth, making the blocking duration virtually impossible to circumvent for malicious automated attempts without significant delay.
[0074] In some embodiments, method 400 comprises integrating, via the server, with third-party reputation services to identify connection requests associated with known malicious IP addresses, VPNs, or suspicious user agents. Upon identifying such characteristics, the server may block the IP address and / or UUID of the mobile computing device. This integration advantageously leverages pre-existing knowledge bases of malicious entities, enabling proactive blocking that reduces exposure to previously identified threats.
[0075] In certain embodiments, method 400 tracks successive connection requests originating from multiple IP addresses associated with the same mobile computing device or user session. If multiple IP addresses are detectedwithin a predetermined timeframe, the MDV server may block the UUID of the mobile computing device. This feature is advantageous for mitigating security risks associated with IP-hopping techniques often employed by attackers attempting to bypass traditional IP-based security checks.
[0076] Method 400 may further comprise tracking rapid geo-location changes between successive connection requests. This tracking may consider elapsed time and geographic distance, and upon detecting any significant and rapid location shifts, the MDV server may block the UUID of the mobile computing device. This approach is particularly beneficial in detecting and mitigating attacks involving VPNs or other location-masking technologies, where suspiciously fast geo-location changes indicate a potential fraudulent attempt.
[0077] In some embodiments, method 400 includes generating a short-lived session token upon a valid initial connection request and validating this session token for successive requests. The short-lived token is invalidated after a predetermined period or upon detecting inconsistencies between the mobile device details and stored metadata or expected device characteristics. This token-based approach limits session validity, providing an added layer of protection against replay attacks or unauthorised reuse of session credentials.
[0078] Additionally, method 400 may comprise monitoring timestamps and request frequency from a single session or IP address. When excessive connection requests are detected that deviate from expected user activity patterns based on historical data or predefined thresholds, the MDV server may trigger additional security challenges. This proactive measure provides a safeguard against denial-of-service attacks or bot-driven connection attempts by analysing anomalous request patterns.
[0079] Method 400 may also comprise storing records of each successful and unsuccessful connection request in a metadata database. This metadata record-keeping serves as an audit trail, offering significant advantages for postevent analysis of security incidents, identification of suspicious behaviour patterns, and the enhancement of adaptive security protocols based on evolving threat landscapes.
[0080] FIGS. 5A and 5B show exemplary digital gift cards 500, 500’ according to an embodiment of the present invention. Each digital gift card comprises a unique code, such as a barcode or quick response (QR) code 510, 510’, that can be scanned directly from a mobile computing device of a recipient to pay for one or more products and / or services. In one embodiment, the barcode is a PDF barcode, which is compatible with standard laser scanners commonly used in retail environments, thereby facilitating in-store redemption.
[0081] Additionally, each digital gift card 500, 500’ includes several informational elements: (1) a monetary value 520, 520’ denoting the balance available on the card 500, 510’, (2) a validity date 530, 530’ indicating the expiration date of the card, (3) a business identifier 540, 540’ specifying the business or organisation with which the card 500, 500’ is associated, (4) a reference number 550, 550’ unique to the card 500, 500’, (5) a PIN number 560, 560’ to enhance security, and (6) a personalised message 570, 570’ intended for the recipient.
[0082] By incorporating a personalised rich media message with a redeemable component and a uniquely rendered image, the digital gift card 500, 500’ enhances the recipient’s experience, capturing more of the excitement, spontaneity, and warmth typical of an “in-person” gift exchange. For example, in some embodiments, the digital gift card 500, 500’ may be redeemed instantly upon clicking a pre-authenticated shortened link 580, 580’ embedded within the rich media message, bypassing the need for time-consuming registration or authentication steps. Alternatively, the gift card 500, 500’ can be partially redeemed, allowing the recipient to use a portion of the balance immediately while storing the remainder on their mobile computing device for future use. Furthermore, because rich media messages are generally monitored closely by mobile device users, senders can time the delivery of the digital gift card to coincide with an ideal moment, maximising the emotional impact of the gift.
[0083] Additionally, the digital gift card 500, 500’ can be used immediately for online purchases or stored on the mobile computing device for future in-store redemption, providing the recipient with versatile options for how and when they redeem the card 500, 500’. This flexibility allows users to make purchases conveniently, either online or in physical stores, as suits their preference.
[0084] FIG. 6 shows an exemplary advertisement 600, according to another embodiment of the present invention. Rather than including a barcode that can be scanned directly from a recipient's mobile device, the advertisement incorporates a clickable pre-authenticated shortened link 610 associated with a redeemable component. Clicking this link 610 initiates a process for immediately redeeming the redeemable component online. For example, according to some embodiments, upon link activation, a recipient is taken directly to a checkout page featuring a pre-authorised payment link, which automatically adds a promoted product to a recipient product cart. In other embodiments, activation of the link 610 may guide the recipient through a simplified registration process upon redirecting to a longer URL.
[0085] FIG. 7 shows another exemplary advertisement 700, according to an embodiment of the present invention. This advertisement presents a scenario where a recipient has left an item in their cart, complemented by rich media that includes a reminder message 710 about a promoted product. Additionally, the rich media includes a clickable pre-authenticated shortened link 720. Upon clicking this link 720, a server recognises a pre-authenticated session and automatically logs the recipient in to a checkout page 730. The promoted product is instantly added to a pre-populated cart at a predetermined price. For returning users, this process bypasses the login and product selection steps, directing them straight to the pre-populated cart for review and checkout. This simplified checkout process allows the user to review the pre-populated cart, confirm or modify shipping details if necessary, and complete the purchase with minimal clicks. The advantages of this approach include reduced friction in the purchasing process, elimination of the need for manual login, product searches, and cart population, significantly streamlining the acquisition of the product while still maintaining robust security and fraud protection measures.
[0086] FIG. 8 illustrates a system 800 according to another form of the present invention. For example, the method 100, the method 200, the method 300 and the method 400.
[0087] The system 800 comprises one or more processors 810, each having access to a computer memory, such as a computer-readable medium. The computer memory stores computer-readable code components that, whenselectively executed by the one or more processors 810, implement aspects of the present invention, such as the method 100, method 200, method 300, and method 400.
[0088] As will be understood by those of ordinary skill in the art, the computer-readable medium may be any non-transitory storage medium that stores instructions which, when executed by one or more processors, performs aspects of the present invention, such as method 100, method 200, method 300, and method 400.
[0089] It should also be understood that, unless clearly indicated to the contrary, in any methods claimed herein that include more than one step or act, the order of the steps or acts of the method is not necessarily limited to the order in which the steps or acts of the method are recited.
[0090] The above description of various embodiments of the present invention is provided for the purposes of illustration to one of ordinary skill in the related art. It is not intended to be exhaustive or to limit the invention to the specific embodiments disclosed. Numerous alternatives and variations will be apparent to those skilled in the art based on the above teachings. Additionally, features from different embodiments may be combined to create further variations of the invention. Accordingly, while some alternative embodiments have been discussed specifically, other embodiments will be apparent or readily developed by those of ordinary skill in the art. This patent specification is intended to embrace all alternatives, modifications, and variations of the present invention that have been discussed herein, as well as other embodiments that fall within the spirit and scope of the described invention.
[0091] It will be clearly understood that, if a prior art publication is referred to herein, this reference does not constitute an admission that the publication forms part of the common general knowledge in the art in Australia or in any other country.
Claims
CLAIMS1. A method for delivering a personalised rich media message, the method comprising:generating, via a server, a pre-authenticated shortened link including a long Uniform Resource Locator (URL) and a recipient contact identifier identifying a recipient mobile number;incorporating, via the server, the pre-authenticated shortened link into a personalised rich media message having a redeemable component;transmitting, via a mobile messaging platform, the personalised rich media message to a mobile computing device using the recipient mobile number;requesting, by selecting, clicking or otherwise activating the preauthenticated shortened link, connection between the mobile computing device and the long URL; andperforming, via the server, a security verification of the connection request by obtaining one or more details of the mobile computing device and comparing these details with stored metadata and / or expected device characteristics obtained from the pre-authenticated link;wherein, upon detecting any discrepancies between the one or more details of the mobile computing device and stored metadata and / or expected device characteristics, triggering additional security challenges or blocking the connection request; orwherein, upon confirming a match between the one or more details of the mobile computing device and stored metadata and / or expected device characteristics, redirecting the mobile computing device to the long URL, wherein the redeemable component is accessible.
2. The method of claim 1 , wherein the one or more details of the mobile computing device are aggregated to generate a unique fingerprint of the mobile computing device and / or between the mobile computing device and the server, the one or more details including one or more of the following: user-agent string, browser type and version, browser plugins, screenresolution, language settings, time zone, operating system type and version, installed fonts, device model, central processing unit CPU type and architecture, graphics processing unit details, available memory, battery level and charging status, Internet Protocol (IP) address, connection type, proxy or virtual private network (VPN) usage, Transmission Control Protocol / lnternet Protocol (TCP / IP) stack fingerprinting, local and public IP addresses, unique device identifier (UUID), cookies or other tracking identifiers, mouse movement patterns, touch screen data, cipher suites, Transport Layer Security (TLS) version, and elliptic curves and extensions used.
3. The method of claim 1 or claim 2, wherein the stored metadata includes one or more of the following: recipient mobile number, recipient name, sender mobile number, sender name, a timestamp of the long URL and recipient mobile number, sender agent string, sender device type, sender IP address, sender connection type, sender geolocation, message preferences and scheduled delivery date.
4. The method of any one of the preceding claims, wherein the expected device characteristics are based on historical user-agent strings and other metadata collected from previous interactions.
5. The method of any one of the preceding claims, wherein for discrepancies related to dynamic device or session characteristics that are expected to change over time or under certain conditions but are not typically indicative of fraud of malicious behaviour, such as changes in IP address within a common geographic location and / or browser settings, presenting, via the server, a CAPTCHA challenge on the mobile computing device, requesting multi-factor authentication or sending a verification code to the mobile computing device using the recipient mobile number; and wherein for discrepancies related to static or persistent device identifiers that are unlikely to change frequently and whose alteration suggests a higher risk of unauthorised access, such as UUlDs and use of VPNs or proxies, blocking the IP address and / or the UUID of the mobile computing device.
6. The method of any one of the preceding claims, further comprising implementing, via the server, rate limiting for successive connection requests based on the one or more details of the mobile computing device and / or session token, wherein each unsuccessful connection request results in an exponentially increasing block time before the mobile computing device is permitted to attempt another connection.
7. The method of any one of the preceding claims, further comprising integrating, via the server, with third-party reputation services to identify connection requests associated with known malicious IP addresses, Virtual Private Networks (VPNs), or suspicious user agents, wherein upon identifying such connection requests, blocking the IP address and / or UUID of the mobile computing device.
8. The method of any one of the preceding claims, further comprising tracking, via the server, successive connection requests from multiple IP addresses associated with the mobile computing device or user session, wherein upon detecting multiple IP addresses in a predetermined timeframe, blocking the UUID of the mobile computing device.
9. The method of any one of the preceding claims, further comprising tracking, via the server, rapid changes in geo-location between successive connection requests based on an elapsed time and geographic distance between the connection requests, wherein upon detecting any such rapid changes, blocking the UUID of the mobile computing device.
10. The method of any one of the preceding claims, further comprising generating, via the server, a short-lived session token upon a first valid connection request and validating the short-lived session token for each successive connection request, wherein the short-lived session token is invalidated after a predetermined time or after detecting any discrepancies between the one or more details of the mobile computing device and stored metadata and / or expected device characteristics.
11. The method of any one of the preceding claims, further comprising monitoring, via the server, a timestamp and frequency of requests from a single session or IP address, wherein upon detecting excessive connectionrequests inconsistent with expected user activity patterns based on historical data or predefined thresholds, triggering additional security challenges.
12. The method of any one of the preceding claims, further comprising storing, via the server, a record of each successful and unsuccessful connection request in a metadata database.
13. The method of any one of the preceding claims, wherein the messaging platform is selected from a group consisting of Multimedia Messaging Service (MMS), Rich Communication Services (RCS), and any equivalent or technologically advanced messaging service that provides substantially similar functionality in delivering rich media content to mobile devices.
14. The method of any one of the preceding claims, wherein the URL and recipient contact identifier of the pre-authenticated shortened link are generated using a timestamp and a hashing algorithm.
15. The method of any one of the preceding claims, wherein for a firsttime user, further comprising, via the server, guiding the user through a simplified registration process upon redirection to the long URL; and wherein, for a returning user, further comprising bypassing, via the server, the registration process, login and product selection steps, directing the user to a pre-populated cart where the redeemable component is immediately accessible upon redirection to the long URL.
16. The method of any one of the preceding claims, wherein the personalised rich media message includes a personalised animation with an intuitive identifier that includes embedded instructions and / or IP lookup functionality.
17. The method of any one of the preceding claims, wherein the redeemable component comprises a digital gift card, voucher, coupon or advertisement.
18. A system for delivering a personalised rich media message, comprising:one or more processors; anda memory storing instructions that, when executed by the one or more processors, perform the method of any one of claims 1 to 17.
19. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, perform the method of any one of claims 1 to 17.