Remote Server Trust Level Assessment for Device Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to determine the trustworthiness of a user device before engaging in communication or transactions to prevent potential fraud or theft, as existing solutions do not effectively assess the trust level of communicating devices in a distributed environment.

Innovation Solution

A remote server collects information on user device activities and determines a trust level based on this data, which is then transmitted to a requesting device, allowing users to assess the trustworthiness of potential interlocutors by evaluating the trust level against a predefined threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a remote server collects information from user devices to determine trust levels, then the reliability of trust assessment is improved, but the device complexity and data processing requirements increase

Engineering Contradiction:
Improvetrust level assessment reliabilityVSAvoidserver system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote server as an intermediary between user devices. The server collects device information, determines trust levels, and provides assessments to requesting devices. This intermediary approach resolves the contradiction by centralizing complex data processing and trust assessment algorithms on the server side, while keeping individual user devices simple. The server acts as a mediator that handles the complexity of information collection and analysis, allowing reliable trust assessment without increasing the complexity of individual devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive device information is collected to assess trustworthiness, then the measurement precision of trust level is improved, but the loss of time for data collection and processing increases

Engineering Contradiction:
Improvetrust level measurement precisionVSAvoiddata collection and processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having user devices automatically send their information reports to the remote server in advance, before any trust assessment is needed. The server stores these reports and pre-computes trust levels based on the collected information. When a trust assessment is requested, the server can quickly retrieve pre-analyzed data rather than collecting and processing information in real-time. This resolves the contradiction by performing data collection and initial processing beforehand, enabling fast trust level retrieval without sacrificing measurement precision.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If trust level information is made available to all requesting devices, then the ease of operation for users is improved, but the loss of information security increases

Engineering Contradiction:
Improvetrust level accessibilityVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts sensitive device information from individual devices and centralizes it on a secure remote server. Only processed trust level assessments, not raw device data, are transmitted to requesting devices. The server acts as a secure repository that handles sensitive information, applying access controls and processing logic to protect data security. This resolves the contradiction by taking out sensitive information from distributed devices and concentrating security management on the server side, enabling easy trust level access while maintaining information security through centralized control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3090376B1Method for accessing a service and a corresponding server
Publication Date: 2020.03.04 THALES DIS FRANCE SA
  • EP3090376B1 patent drawingFigure 1~2

AI summary

The invention relates to a method 20 for accessing a service. According to the invention,the method comprises the following steps. At least one first user device 12 executes a first application that communicates with a second user device application. The first user device sends to a remote server 110 data 24 relating to the first application execution, as a first user device report. The data relating to the first application execution includes information relating to either an incoming event or an outgoing event and at least one attribute relating to the first application execution. The remote server determines, based upon at least the first user device report, a trust level relating to the first user device. A third user device 114 sends to the remote server a request 26 for getting a trust level relating to the first user device. The remote server sends to the third user device, as a request response, the trust level 28 relating to the first user device. The invention also relates to a corresponding server.