Remote Mobile App Revocation via Device-Card Co-location Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile banking and financial applications lack effective protections for customers whose devices and bank cards are compromised, leaving them vulnerable to unauthorized transactions and data breaches.

Innovation Solution

A system that remotely accesses a user's mobile device based on compromised transaction vehicles, such as bank cards, by identifying the device, reconfiguring applications, and providing notifications to suspend or terminate services, ensuring real-time protection and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile banking applications are made accessible on mobile devices, then customer convenience and accessibility are improved, but security vulnerabilities increase when devices or cards are compromised

Engineering Contradiction:
Improvecustomer accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing co-location relationships between mobile devices and transaction cards before transactions occur. The financial institution system continuously monitors and verifies that authorized devices remain in close proximity to authorized cards, preventing unauthorized access before it can result in harmful transactions

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback by monitoring the co-location status of mobile devices and transaction cards in real-time. When separation is detected, the system immediately responds by blocking transactions and notifying the financial institution, creating a closed-loop security mechanism that adapts to changing conditions

Inventive Principle:
Principle #23Feedback

2Reliability

If remote access to mobile devices is implemented for security purposes, then protection against compromised devices is improved, but system complexity increases

Engineering Contradiction:
Improvedevice protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service security by allowing the mobile device and transaction card to continuously verify their own co-location status through their respective sensors and communication capabilities. Each device independently contributes to the security verification process, reducing the burden on centralized system complexity while maintaining robust protection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The financial institution system performs multiple functions through a unified co-location monitoring framework: it authenticates devices, authorizes transactions, detects compromise, and blocks unauthorized access. This multi-functional approach consolidates what could be separate complex systems into a single integrated solution

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If continuous monitoring of transaction vehicles is performed, then detection of compromised cards is improved, but loss of time and energy increases

Engineering Contradiction:
Improvecompromise detectionVSAvoidmonitoring overhead
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements periodic monitoring of co-location status between mobile devices and transaction cards rather than continuous exhaustive surveillance. The monitoring occurs at regular intervals sufficient to detect separation or compromise events, balancing detection precision with acceptable time and energy consumption

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9595032B2Remote revocation of application access based on non-co-location of a transaction vehicle and a mobile device
Publication Date: 2017.03.14 BANK OF AMERICA CORP
  • US9595032B2 patent drawing
  • US9595032B2 patent drawing
  • US9595032B2 patent drawing

AI summary

Embodiments of the invention relate to an invention for accessing a remotely located mobile device of a user based on certain events is provided. The system, method, and computer program product are configured to: (a) monitor one or more transaction involving a transaction vehicle of a user; (b) determine a physical location of a transaction vehicle based at least partially on the one or more transactions; (c) determine a geographic location of a mobile device of the user, wherein the mobile device is associated with the transaction vehicle; (d) determine whether or not the transaction vehicle of the user and the mobile device of the user are co-located; and (e) reconfigure one or more applications accessible to the mobile device or one or more functional features of the mobile device based at least partially on determining that the mobile device and the transaction vehicle of the user are not co-located.