Device Agents for Fraud Detection in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing data capabilities of mobile devices stress wireless network bandwidth, leading to high costs for exceeding data plan allowances, and there is a need to secure both end-user devices and network elements from fraudulent activities that exploit service policies for incorrect billing rates.

Innovation Solution

Implementing a secure device-assisted services system with end-user devices equipped with modems, memory for application-specific network access policies, and device agents that detect and enforce policies, including flow-tagging, credential verification, and fraud detection using multi-tiered verification processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices are equipped with enhanced data capabilities and device-assisted services, then service functionality and user experience are improved, but network bandwidth stress increases and fraudulent activities become more prevalent

Engineering Contradiction:
Improveservice functionalityVSAvoidfraudulent activities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security measures by embedding device agents and policy enforcement mechanisms within end-user devices before fraudulent activities can occur. These agents proactively monitor application behavior, enforce network access policies, and detect anomalies before they can result in fraud or excessive bandwidth consumption

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces device agents as intermediary components between applications and the network. These agents act as mediators that verify credential integrity, enforce access policies, and monitor data usage without requiring direct user intervention or compromising application functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-tiered verification processes and fraud detection mechanisms are implemented, then security and fraud prevention are improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security verification process into multiple independent tiers or layers. Each device agent implements specific verification functions (credential verification, policy enforcement, anomaly detection) as separate modular components, allowing complex security checks to be broken down into manageable, independently verifiable units

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables device agents to autonomously perform verification and security functions without requiring constant external validation. The agents self-manage credential verification, automatically enforce policies, and independently detect fraudulent behavior, reducing the overall system complexity despite enhanced security capabilities

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9491199B2Security, fraud detection, and fraud mitigation in device-assisted services systems
Publication Date: 2016.11.08 HEADWATER RESEARCH LLC
  • US9491199B2 patent drawing
  • US9491199B2 patent drawing
  • US9491199B2 patent drawing

AI summary

A device having: an application program that assists the device in accessing a data service over a wireless access network, an application credential associated with the application program, and a policy to be applied when the application program initiates or attempts to initiate communication over the wireless access network. The device also has one or more agents that detect an attempted installation of update software on the device, the update software purporting to be a modification, update, or replacement of the application program; obtain an update-software credential associated with the update software; obtain the application credential; allow the update software to be installed if the update-software credential matches the application credential; and interact with the application program to arrange a setting of the application program, the setting configured to assist in applying the policy when the application program initiates or attempts to initiate communication over the wireless access network.