Push Token Device Fingerprinting Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device fingerprinting systems are vulnerable to unauthorized devices imitating legitimate devices, compromising security and data integrity.
Innovation Solution
The system employs push tokens and push notifications to enhance device fingerprinting by using a third-party provided push token as a secure identifier, which is integrated into device fingerprints and used to authenticate high-risk transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If device fingerprints use device serial number, device name, and other device information, then device identification capability is improved, but security is worsened because these sources may be compromised allowing unauthorized devices to imitate legitimate devices
Solution Approach 1:
The patent introduces push tokens as an intermediary element provided by a third-party push notification service. These tokens serve as a mediator between the device and the fingerprinting system, delivering identification information that is independent of the device's own data sources. The push token acts as a trusted intermediary that cannot be easily compromised or imitated, thereby resolving the security vulnerability while maintaining identification capability.
Solution Approach 2:
The patent replaces the traditional mechanical approach of using device-internal identifiers (serial numbers, device names) with a signal-based system using push tokens from a third-party notification service. This substitution transitions from relying on device-generated identification mechanisms to using externally-provided identification signals that are more secure and harder to replicate.
2Ease of operation
If device fingerprints rely on device-internal information sources, then ease of collection is improved, but susceptibility to compromise is worsened
Solution Approach 1:
The push token from a third-party push notification service serves as an intermediary information source that bridges the gap between ease of collection and security. The token is automatically provided by the push notification service without requiring complex extraction from device internals, while simultaneously providing security through its external origin and independence from device compromise.
Solution Approach 2:
The patent uses the push token as a copy or representation of device identity that is provided by an external service rather than directly extracted from device internals. This copied identification information maintains the ease of collection while improving security because the push token service independently generates and manages these identifiers, making them resistant to device-level compromises.
Data Source
AI summary
Embodiments disclosed are directed to a system that performs steps to perform enhanced device fingerprinting. The system at least at receives from an application, a plurality of device attributes identifying a client device on which the application is being used. The plurality of device attributes includes a push token provided by a push token service to the client device. The push token is uniquely paired to the client device. The system further transmits, to a device database, the plurality of device attributes for storage in a device profile. The system also transmits, to the application, a push notification based on the push token. The system receives, from the application, a deliverable status indicating whether the push notification was successfully transmitted to the client device, and transmits, to a notification database, the deliverable status for storage in a notification delivery profile. The system can use the information to authenticate a device.


