Device-Assisted Services Fraud Detection and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing data transmission capabilities of mobile devices have strained wireless network bandwidth, leading to higher costs for users due to potential data overages, and there is a need to secure both end-user devices and network elements from fraudulent activities related to data service policies.

Innovation Solution

Implementing a device-assisted services (DAS) system with a secure service controller architecture that includes a service processor on end-user devices and a network-based service controller, using device agents to enforce application-specific network access policies, detect fraudulent activities, and manage data usage through credential verification and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If mobile devices access large amounts of information, then data transmission capability is improved, but data usage cost increases due to potential overages

Engineering Contradiction:
Improvedata transmission capabilityVSAvoiddata usage cost
Core Design Contradiction:
SpeedVSLoss of energy

Solution Approach 1:

The system implements continuous monitoring of data usage by device agents that track application-specific network access and provide feedback to both users and network operators. This feedback mechanism enables users to understand their consumption patterns and avoid unexpected overages, while allowing operators to optimize billing and resource allocation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

End-user devices perform self-monitoring of their own data usage through device agents that automatically track network access by applications. The devices generate their own usage reports and policy compliance information, eliminating the need for extensive network-side monitoring infrastructure and reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

2Extent of automation

If device-assisted services are implemented, then service policy enforcement is improved, but security vulnerability increases due to potential spoofing and hacking

Engineering Contradiction:
Improveservice policy enforcementVSAvoidsecurity vulnerability
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

Device agents serve as intermediaries between applications and the network, enforcing service policies locally on the device. This intermediary approach allows automated policy enforcement while maintaining security, as the agents operate within the device's secure environment and only communicate authenticated information with the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments service policy enforcement into device-level and network-level components. Device agents handle local policy enforcement and monitoring, while the network handles billing and high-level policy decisions. This segmentation reduces security vulnerabilities by distributing trust and limiting the attack surface at each level.

Inventive Principle:
Principle #1Segmentation

3Reliability

If service controller verifies software and hardware, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The service controller performs preliminary verification of device agents, software, and hardware credentials before allowing full service access. This preliminary action establishes security credentials in advance, enabling automated trust verification without adding complexity to ongoing operations. Devices that pass verification gain streamlined access while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250008377A1Security, Fraud Detection, and Fraud Mitigation in Device-Assisted Services Systems
Publication Date: 2025.01.02 HEADWATER RESEARCH LLC
  • US20250008377A1 patent drawing
  • US20250008377A1 patent drawing
  • US20250008377A1 patent drawing

AI summary

Secure architectures and methods for improving the security of mobile devices are disclosed. Also disclosed are apparatuses and methods to detect and mitigate fraud in device-assisted services implementations.