Device-Assisted Services Fraud Detection and Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing data transmission capabilities of mobile devices have strained wireless network bandwidth, leading to higher costs for users due to potential data overages, and there is a need to secure both end-user devices and network elements from fraudulent activities related to data service policies.
Innovation Solution
Implementing a device-assisted services (DAS) system with a secure service controller architecture that includes a service processor on end-user devices and a network-based service controller, using device agents to enforce application-specific network access policies, detect fraudulent activities, and manage data usage through credential verification and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If mobile devices access large amounts of information, then data transmission capability is improved, but data usage cost increases due to potential overages
Solution Approach 1:
The system implements continuous monitoring of data usage by device agents that track application-specific network access and provide feedback to both users and network operators. This feedback mechanism enables users to understand their consumption patterns and avoid unexpected overages, while allowing operators to optimize billing and resource allocation.
Solution Approach 2:
End-user devices perform self-monitoring of their own data usage through device agents that automatically track network access by applications. The devices generate their own usage reports and policy compliance information, eliminating the need for extensive network-side monitoring infrastructure and reducing overall system complexity.
2Extent of automation
If device-assisted services are implemented, then service policy enforcement is improved, but security vulnerability increases due to potential spoofing and hacking
Solution Approach 1:
Device agents serve as intermediaries between applications and the network, enforcing service policies locally on the device. This intermediary approach allows automated policy enforcement while maintaining security, as the agents operate within the device's secure environment and only communicate authenticated information with the network.
Solution Approach 2:
The system segments service policy enforcement into device-level and network-level components. Device agents handle local policy enforcement and monitoring, while the network handles billing and high-level policy decisions. This segmentation reduces security vulnerabilities by distributing trust and limiting the attack surface at each level.
3Reliability
If service controller verifies software and hardware, then security is improved, but system complexity increases
Solution Approach 1:
The service controller performs preliminary verification of device agents, software, and hardware credentials before allowing full service access. This preliminary action establishes security credentials in advance, enabling automated trust verification without adding complexity to ongoing operations. Devices that pass verification gain streamlined access while maintaining security.
Data Source
AI summary
Secure architectures and methods for improving the security of mobile devices are disclosed. Also disclosed are apparatuses and methods to detect and mitigate fraud in device-assisted services implementations.


