Mobile Device Identification via Location Data Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying mobile devices during secure transactions, such as device fingerprinting, are vulnerable to security breaches as hackers can reverse-engineer executable code, compromising the validation process.
Innovation Solution
A method involving the use of historical location data stored on a mobile device, which is matched with stored location data at a transaction server to verify the device's identity, utilizing algorithms to select and transmit location data windows for identification purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If device fingerprinting with executable code is used to identify mobile devices, then device identification capability is improved, but security is worsened because hackers can reverse-engineer the code and imitate devices
Solution Approach 1:
The patent extracts the identification mechanism from executable code to hardware-level immutable characteristics. Instead of using software-based fingerprints that can be reverse-engineered, the system extracts unique hardware identifiers (IMEI, MAC address, device model) that are embedded in the device's physical structure and cannot be replicated or modified by hackers.
Solution Approach 2:
The system performs preliminary registration of device hardware characteristics before transactions occur. During the registration phase, the mobile device's immutable hardware identifiers are collected, processed into a secure fingerprint, and stored in the database. This preliminary action ensures that when transactions occur, the identification is already established and cannot be spoofed in real-time.
2Ease of operation
If active fingerprinting with executable code is implemented, then device identification is achieved, but the system becomes vulnerable to reverse engineering and hacking
Solution Approach 1:
The patent creates a secure copy of device hardware characteristics that cannot be forged. Instead of using the actual executable code as the identifier, the system creates a cryptographic hash or fingerprint of the hardware identifiers that serves as an immutable copy. This copied identifier can be transmitted and verified without exposing the original hardware characteristics to reverse engineering.
3Reliability
If cloud-based secure server stores payment card details, then security is improved by removing sensitive data from mobile devices, but device verification becomes more complex
Solution Approach 1:
The patent merges multiple hardware identifiers (IMEI, MAC address, device model) into a single unified device fingerprint. This combination approach simplifies the verification process by consolidating multiple verification points into one comprehensive identifier that the server can validate against stored records, reducing the complexity of multi-step verification procedures.
Data Source
AI summary
The disclosure provides systems and methods for identifying a mobile device when requesting a secure transaction. In a method conducted at a transaction server access to stored location data having been periodically received relating to a mobile device and stored with an identifier of the mobile device is provided. Historical location data having been stored locally at a mobile device is received from the mobile device when requesting a secure transaction. The historical location data received from the mobile device is matched to a subset of the stored location data to obtain or verify an identifier of the mobile device requesting the secure transaction. The mobile device requesting the secure transaction is associated with the identifier so as to identify or verify the identity of the mobile device requesting the secure transaction.


