Mobile Device Identification via Location Data Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for identifying mobile devices during secure transactions, such as device fingerprinting, are vulnerable to security breaches as hackers can reverse-engineer executable code, compromising the validation process.

Innovation Solution

A method involving the use of historical location data stored on a mobile device, which is matched with stored location data at a transaction server to verify the device's identity, utilizing algorithms to select and transmit location data windows for identification purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If device fingerprinting with executable code is used to identify mobile devices, then device identification capability is improved, but security is worsened because hackers can reverse-engineer the code and imitate devices

Engineering Contradiction:
Improvedevice identification capabilityVSAvoidsecurity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent extracts the identification mechanism from executable code to hardware-level immutable characteristics. Instead of using software-based fingerprints that can be reverse-engineered, the system extracts unique hardware identifiers (IMEI, MAC address, device model) that are embedded in the device's physical structure and cannot be replicated or modified by hackers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary registration of device hardware characteristics before transactions occur. During the registration phase, the mobile device's immutable hardware identifiers are collected, processed into a secure fingerprint, and stored in the database. This preliminary action ensures that when transactions occur, the identification is already established and cannot be spoofed in real-time.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If active fingerprinting with executable code is implemented, then device identification is achieved, but the system becomes vulnerable to reverse engineering and hacking

Engineering Contradiction:
Improveautomatic device identificationVSAvoidsecurity breaches
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates a secure copy of device hardware characteristics that cannot be forged. Instead of using the actual executable code as the identifier, the system creates a cryptographic hash or fingerprint of the hardware identifiers that serves as an immutable copy. This copied identifier can be transmitted and verified without exposing the original hardware characteristics to reverse engineering.

Inventive Principle:
Principle #26Copying

3Reliability

If cloud-based secure server stores payment card details, then security is improved by removing sensitive data from mobile devices, but device verification becomes more complex

Engineering Contradiction:
ImprovesecurityVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple hardware identifiers (IMEI, MAC address, device model) into a single unified device fingerprint. This combination approach simplifies the verification process by consolidating multiple verification points into one comprehensive identifier that the server can validate against stored records, reducing the complexity of multi-step verification procedures.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11551224B2Systems and methods for identifying mobile devices
Publication Date: 2023.01.10 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11551224B2 patent drawing
  • US11551224B2 patent drawing
  • US11551224B2 patent drawing

AI summary

The disclosure provides systems and methods for identifying a mobile device when requesting a secure transaction. In a method conducted at a transaction server access to stored location data having been periodically received relating to a mobile device and stored with an identifier of the mobile device is provided. Historical location data having been stored locally at a mobile device is received from the mobile device when requesting a secure transaction. The historical location data received from the mobile device is matched to a subset of the stored location data to obtain or verify an identifier of the mobile device requesting the secure transaction. The mobile device requesting the secure transaction is associated with the identifier so as to identify or verify the identity of the mobile device requesting the secure transaction.