Dynamic Device Profile for Mobile Payment State Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud-based systems, the security of user devices is compromised when access data is not stored on hardware, making authentication critical to prevent fraud, and frequent user authentication during transactions is cumbersome, deterring consumers from using their devices for transactions.
Innovation Solution
A dynamic device profile system that manages a user device's state, allowing it to transition between trusted, suspended, and untrusted states based on predetermined actions, enabling or restricting transactions accordingly, and performing security tests to maintain the device's state, thereby minimizing consumer friction and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If frequent user authentication is required during transactions, then security is improved, but consumer friction increases and ease of operation deteriorates
Solution Approach 1:
The patent implements dynamic device profiling where the authentication requirements are not fixed but adapt based on the device's current trust level. The system transitions between trusted, suspended, and untrusted states, dynamically adjusting authentication thresholds. This allows the system to maintain high security for untrusted devices while enabling frictionless transactions for trusted devices, resolving the contradiction between security and ease of operation.
Solution Approach 2:
The system changes the parameter of authentication requirement based on the device state. For trusted devices, the authentication threshold is raised (more transactions allowed without re-authentication), while for untrusted devices, the threshold is lowered (strict authentication required). This parameter change allows the system to optimize both security and user experience across different device states.
2Adaptability or versatility
If cloud-based systems are used instead of hardware storage, then device versatility is improved, but security reliability deteriorates
Solution Approach 1:
The patent introduces a cloud-based device profile system as an intermediary between the user's access data and the transaction processing system. This intermediary maintains security by continuously verifying device trust levels while enabling versatility through cloud-based management. The device profile acts as a mediator that can suspend or enable transactions based on security assessments, allowing cloud-based systems to achieve both security and versatility.
Solution Approach 2:
The system implements continuous feedback loops where device security is constantly monitored and assessed. Based on this feedback, the system dynamically adjusts the device's trust level and corresponding transaction permissions. This feedback mechanism allows cloud-based systems to maintain security reliability while preserving device versatility through adaptive trust management.
3Ease of operation
If dynamic device profiling is implemented, then ease of operation is improved by reducing authentication friction, but device complexity increases
Solution Approach 1:
The device profile system operates autonomously by automatically assessing device security, determining trust levels, and managing transaction permissions without requiring manual user intervention. The system self-manages the complexity of security assessments and state transitions, presenting a simple interface to users while handling the complex underlying logic automatically.
Data Source
AI summary
Described herein are systems and methods for creating and managing a device profile on a mobile device for continued authentication of the mobile device. The device profile includes a state assigned to a mobile device. The state of the device can be managed through the device profile. The mobile device is allowed to conduct payments based on the current state assigned to the mobile device. In response to a request to conduct a payment transaction using the mobile device, the state information in the mobile device profile is checked. The payment transaction using the mobile device is allowed when the state information indicates a trusted state. The payment transaction using the mobile device is limited when the state information indicates a suspended state. The payment transaction using the mobile device is prevented when the state information indicates an untrusted state.


