Mobile Device Risk Assessment via Dynamic Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current device fingerprinting methods for mobile devices only assess risk once or on an ad-hoc basis, making them vulnerable to fraudsters who can evade detection by using device modification tools selectively, and they require a long history of device and user data for comparison, which increases bandwidth and storage requirements.
Innovation Solution
A method and system for continuously assessing risk on a mobile device by monitoring parameters for predetermined triggering events, executing a fingerprinting routine to obtain a current state of device attributes, and comparing it with a previous state to generate device intelligence, which reduces the need for long-term data storage and transmission, allowing for real-time risk assessment and reduced bandwidth usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device fingerprinting is performed continuously to detect fraud in real-time, then security detection capability is improved, but device complexity and processing overhead increase
Solution Approach 1:
The system performs fingerprinting assessments periodically based on risk scores rather than continuously. The risk score determines the assessment frequency, with lower scores triggering periodic reassessment and higher scores triggering immediate reassessment. This periodic approach maintains security while reducing processing overhead compared to continuous monitoring.
Solution Approach 2:
The system changes the parameter of assessment frequency based on the risk score value. When risk score is below threshold, assessments occur periodically; when risk score exceeds threshold, immediate reassessment occurs. This dynamic parameter adjustment optimizes the balance between detection capability and processing load.
2Measurement precision
If a long history of device and user data is stored for comparison, then measurement precision of risk assessment is improved, but bandwidth and storage requirements increase
Solution Approach 1:
The system extracts only the essential comparison elements needed for risk assessment rather than storing and transmitting complete historical datasets. By focusing on specific fingerprint attributes and risk indicators, the system achieves accurate comparison with reduced data volume, lowering storage and bandwidth requirements.
Solution Approach 2:
The system performs preliminary risk scoring and fingerprinting to identify only those cases requiring detailed historical comparison. By pre-filtering assessments based on initial risk evaluation, the system reduces the volume of data that needs to be stored and transmitted while maintaining assessment accuracy for high-risk cases.
3Device complexity
If risk assessment is performed only once at registration or ad-hoc, then device complexity is reduced, but reliability of fraud prevention deteriorates
Solution Approach 1:
The system dynamically adjusts assessment frequency based on risk scores rather than using a static single-time or fixed ad-hoc approach. The risk score acts as a dynamic trigger that determines when reassessment occurs, enabling the system to maintain high reliability for risky devices while reducing complexity for low-risk devices.
Solution Approach 2:
The system uses risk scores as feedback to determine subsequent assessment timing. The outcome of each assessment feeds into the next assessment schedule, creating a closed-loop system that adapts to device behavior. This feedback mechanism improves fraud prevention reliability without requiring continuous complex monitoring.
Data Source
AI summary
A method and a system for enhancing security and fraud prevention from mobile devices running mobile applications includes continuously monitoring the mobile devices for certain triggering events while initiating, loading or running the mobile applications. Upon a triggering event a device fingerprinting routine is run the results of which are transmitted to a risk engine running on a server where it is then analyzed. Based on the analysis, device intelligence information is generated and transmitted back to the mobile device where actions are taken, depending on the potential risk and other factors. This enhancement does not require storing in a server a history of user habits in other circumstances.


