Device Registry Fraud Verification via Risk Scores
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online transaction systems face limitations in fraud prevention due to restricted data fields in authorization requests, making it difficult for merchants and consumers to verify transaction legitimacy, leading to potential fraudulent activities.
Innovation Solution
A system that transmits device identifying codes to merchant servers, which collect device characteristics and risk scores, merging this data with authorization requests to enhance fraud verification through a device registry and transaction account issuer, creating an enhanced authorization process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authorization requests with limited fields are used, then the system maintains simplicity and fast processing, but fraud detection capability deteriorates due to insufficient data
Solution Approach 1:
The system performs preliminary actions by collecting device characteristics and creating device profiles before the actual transaction authorization. Device risk scores are calculated in advance based on historical data and device behavior patterns, so that when an authorization request comes in, the system already has pre-computed risk assessments ready to enhance the decision-making process.
Solution Approach 2:
The patent introduces an intermediary device registry system that acts as a mediator between the merchant/issuer and the device characteristics. The registry stores device profiles and risk scores, and provides this information to the authorization system without requiring direct integration between all components. This intermediary layer adds fraud detection capability while maintaining relative simplicity in the core authorization flow.
2Reliability
If additional device data is collected and transmitted, then fraud verification improves, but data transmission complexity and processing time increase
Solution Approach 1:
Device characteristics, profiles, and risk scores are collected and pre-processed before the authorization request is submitted. The system performs preliminary device identification and risk assessment in advance, so that when the authorization request arrives with enhanced data, the processing time is minimized because the heavy lifting of data collection and initial analysis has already been completed.
Solution Approach 2:
The system applies different levels of data collection and processing to different devices based on their risk profiles. High-risk devices undergo more stringent verification with additional data collection, while low-risk devices experience faster processing with minimal additional checks. This localized approach to security verification improves overall transaction security while minimizing the time loss for legitimate transactions.
3Reliability
If device characteristics are integrated into authorization requests, then fraud prevention improves, but the complexity of data merging and processing increases
Solution Approach 1:
The device registry serves as an intermediary that standardizes and pre-processes device characteristic data before it reaches the authorization system. Instead of requiring the merchant or issuer to directly collect and process raw device characteristics, the registry acts as a central hub that aggregates, validates, and formats this data, significantly reducing the processing complexity at other system points.
Solution Approach 2:
The system transforms raw device characteristics into standardized parameters and risk scores that are easier to process and integrate. By changing the parameters from raw device data to pre-computed risk metrics, the system simplifies the data merging process while maintaining enhanced fraud prevention capability. The complex device fingerprinting is converted into simple risk score comparisons during authorization.
Data Source
AI summary
A merchant server may integrate device identifying code into a webpage. In response to a device accessing the webpage, the device identifying code may cause the merchant server to obtain characteristics of the device. A device registry may compare the characteristics of the device with known device profiles to determine a risk level of the device. A transaction account issuer may utilize the risk level in performing an authorization evaluation.


