Device Fingerprinting Using Contact Data for Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device fingerprinting techniques are vulnerable to unauthorized device impersonation and compromised data security due to limitations in device identification data availability, particularly in mobile environments, which affects trust assessments and security.
Innovation Solution
A system that enhances device fingerprinting by incorporating user contact information, such as emergency contacts and authorized users, to create a more stable and secure device risk assessment by comparing device attributes over time, thereby preventing unauthorized transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional device fingerprinting uses only device identification data (serial number, device name, MAC address), then the device identification process is simple, but the security is compromised because these identifiers can be easily obtained by unauthorized actors to imitate devices
Solution Approach 1:
The patent combines device identification data with user contact information (emergency contacts, authorized users) to create a composite device fingerprint. This merging of data sources makes it significantly harder for unauthorized actors to impersonate devices, as they would need to compromise both device identifiers and access protected contact information. The system evaluates multiple data sources together to establish device trustworthiness.
2Measurement precision
If the system collects and compares multiple device attributes over time (first plurality and second plurality of device attributes), then the device risk assessment accuracy is improved, but the data processing complexity and time requirement increase
Solution Approach 1:
The system performs preliminary actions by collecting and storing device attributes (first plurality of device attributes including device identification data and user contact information) before the actual transaction occurs. This pre-collection and pre-storing of data allows the system to quickly compare attributes during the transaction verification process, reducing the time penalty associated with comprehensive verification.
Solution Approach 2:
The collected device attributes serve multiple functions: they are used for initial device identification, for ongoing risk assessment, for detecting unauthorized impersonation attempts, and for establishing device trustworthiness. This multi-functionality justifies the time investment in collecting comprehensive attributes, as the same data serves multiple security purposes.
3Reliability
If mobile operating systems expose limited hardware or software IDs to application developers, then device privacy is protected, but device risk assessment capability is reduced due to insufficient identification parameters
Solution Approach 1:
The system uses user contact information (emergency contacts, authorized users) as an intermediary data source that is both accessible to applications through standard operating system interfaces and sufficiently unique for risk assessment purposes. This intermediary data bridges the gap between privacy protection (limiting direct access to hardware IDs) and assessment capability (needing unique identifiers).
Data Source
AI summary
Embodiments disclosed are directed to a computing system that performs steps to perform enhanced device fingerprinting using user contacts data. The computing system receives, from an application, a first plurality of device attributes identifying a client device on which the application is being used. The first plurality of device attributes includes first device identification data and first user contacts data. Subsequently, when a user is attempting to perform a transaction using the application on the client device, the computing system receives, from the application, a second plurality of device attributes identifying the client device on which the application is being used. The second plurality of device attributes includes second device identification data and second user contacts data. The computing system compares the second plurality of device attributes to the first plurality of device attributes to determine whether the user is authorized to perform the transaction.


