Mobile Commerce Fraud Mitigation via Device Inventory Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication devices are vulnerable to electronic commerce fraud, such as identity theft, during payment transactions, as existing technologies lack effective real-time fraud mitigation strategies.
Innovation Solution
A system that includes a mobile communication device with an electronic commerce mobile application that determines the device's hardware and software inventory, transmits this information to a security server, and initiates escalated security checks based on a risk score, prompting additional authentication if necessary, to mitigate fraud risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional payment processing is used without real-time security verification, then transaction speed is maintained, but fraud vulnerability increases
Solution Approach 1:
The system performs preliminary actions by collecting device inventory information (hardware identifiers, installed applications, system configurations) during normal app operations and storing it in advance. When fraud is suspected, this pre-collected data is immediately compared against known fraud patterns, enabling rapid detection without delaying the transaction flow.
Solution Approach 2:
The system implements continuous feedback loops where device inventory data is constantly monitored and compared against fraud databases. The security application receives real-time feedback from the operating system about device state changes and immediately responds by updating risk assessments, creating a dynamic defense mechanism that adapts to emerging threats without interrupting normal operations.
2Reliability
If device inventory information is collected and transmitted for security verification, then fraud detection capability is improved, but system complexity increases
Solution Approach 1:
The patent introduces a security application as an intermediary layer between the operating system and payment applications. This intermediary collects device inventory information through standardized OS interfaces, processes it through security algorithms, and provides verification results to payment apps. This mediator approach simplifies the overall system architecture by centralizing security functions rather than embedding complex verification logic in every payment application.
Solution Approach 2:
The system creates and maintains copies of device inventory information in multiple locations: local storage on the mobile device, cached data in the security application, and synchronized records in remote databases. These copies enable rapid security verification by allowing comparison against known fraud patterns without requiring real-time access to the original device state, thereby reducing computational complexity during transaction processing.
3Reliability
If real-time security risk assessment is implemented during transactions, then fraud prevention is enhanced, but transaction processing time increases
Solution Approach 1:
The system implements partial security verification by performing lightweight risk assessments on all transactions using pre-collected device inventory data, and only escalating to full verification protocols when risk indicators are detected. This selective approach processes the majority of legitimate transactions quickly with minimal overhead while maintaining enhanced security for suspicious cases, thereby preserving overall transaction throughput.
Solution Approach 2:
Device inventory information and security baseline parameters are collected and prepared in advance during normal app operations, before transactions occur. This preliminary preparation creates a ready-to-use security profile that enables instantaneous risk assessment during transactions without requiring time-consuming data gathering at the moment of payment, thus maintaining transaction speed while enhancing security.
Data Source
AI summary
A mobile communication device. The device comprises a cellular radio transceiver, a short range radio transceiver, a processor, a memory, and an electronic commerce mobile application stored in the memory. When executed by the processor, the electronic commerce mobile application determines an inventory of mobile applications of the device, transmits the inventory via one of the radio transceivers to a security server application executing on a computer system external to the mobile communication device, and detects when the device enters a retail store associated with the electronic commerce mobile application. The electronic commerce mobile application further, responsive to detecting entrance to the retail store, transmits a request for a security risk score to the security server application executing on the computer system external to the device, and implements an escalated level of security check during a payment transaction conducted based on a received security risk score exceeding a predefined threshold.


