Mobile App Card Reader Compromise Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Card readers are vulnerable to tampering, particularly through skimming devices that go undetected due to their ability to function normally while collecting data, and their widespread distribution across multiple networks complicates security breach detection.

Innovation Solution

A mobile application-based system that uses geolocation API to identify potentially compromised card readers by collecting user reports, determining the location, and publishing alerts to a data feed, thereby improving detection and remedial actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If card readers are deployed widely across multiple networks for security applications and transactions, then the coverage and utility of card reader systems is improved, but the difficulty of detecting compromised card readers increases

Engineering Contradiction:
Improvecoverage areaVSAvoiddetection difficulty
Core Design Contradiction:
Area of stationary objectVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements feedback mechanisms where card readers report their operational status, error codes, and transaction data to a central monitoring system. This continuous feedback loop enables automated detection of anomalies and compromised devices across the distributed network, resolving the detection difficulty while maintaining wide coverage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

A central monitoring system acts as an intermediary between distributed card readers and security analysts. This intermediary aggregates data from multiple readers, applies detection algorithms, and filters out false positives, making the detection process scalable across wide networks without requiring direct human inspection of each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-generated harmful factors

If skimming devices are attached to card readers to collect data, then the ability to steal information is improved, but the operational normalcy of the card reader makes detection harder

Engineering Contradiction:
Improvedata theft capabilityVSAvoidoperational normalcy
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The system applies preliminary anti-action by implementing proactive monitoring for signs of tampering before skimming devices can successfully compromise card readers. Error reporting mechanisms detect anomalies in card reader behavior that may indicate attempted skimming, allowing preventive measures to be taken before data theft occurs.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system changes the 'color' or state of card reader operation by implementing distinct error codes and status indicators that signal potential compromise. When a card reader exhibits behavior consistent with skimming attachment, it generates specific error patterns that differentiate it from normal operation, making detection possible despite operational normalcy.

Inventive Principle:
Principle #32Color changes

3Measurement precision

If error reporting systems are implemented for card readers, then the detection capability is improved, but the complexity of the system increases

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The error reporting system implements self-service by automatically generating, transmitting, and processing error reports without requiring manual intervention. Card readers autonomously monitor their own operational status and report anomalies, reducing the complexity burden on human operators while maintaining high detection precision through automated analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system segments error reporting into distinct components: local error detection at the card reader level, intermediate data transmission through communication interfaces, and centralized analysis at the monitoring system level. This segmentation allows each component to remain relatively simple while achieving high overall detection precision through coordinated operation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11244127B1Mobile application-based error response
Publication Date: 2022.02.08 BANK OF AMERICA CORP
  • US11244127B1 patent drawing
  • US11244127B1 patent drawing
  • US11244127B1 patent drawing

AI summary

An apparatus is configured to receive a data feed. The data feed includes location data of a first card reader that may be compromised and an identifier of the party that initiated the alert. The apparatus is further configured to determine that the location data of the first card reader matches a location identifier associated with a first card reader owner profile. The apparatus is also configured to determine that the owner of the card reader is not the entity receiving the alert. The apparatus then determines that there is not a match between the identifier of the party that initiated the alert and a user identifier from a plurality of user account profiles. The apparatus is further configured to transmit a message to the card reader owner indicating that the card reader may be compromised.