Service Controller for Fraud Detection in Device-Assisted Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing data transmission capabilities of mobile devices have strained wireless network bandwidth, leading to higher costs for users due to potential data overages, and there is a need to secure both end-user devices and network elements from fraudulent activities related to data service policies.

Innovation Solution

Implementing a device-assisted services (DAS) system with a secure service controller architecture that includes a service processor on end-user devices and a network-based service controller, using device agents to enforce application-specific network access policies, detect fraudulent activities, and manage data usage through credential verification and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If device-assisted services are implemented to enable applications to send and receive large quantities of information, then data transmission capability is improved, but network bandwidth stress and data usage costs increase

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidnetwork bandwidth stress
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent segments data transmission by creating separate data sessions for different applications. The service processor divides overall data usage into application-specific sessions, allowing independent monitoring and control of each application's data consumption. This segmentation enables precise tracking of data usage per application, helping users understand and manage their data consumption patterns without reducing overall transmission capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If service processors are implemented on end-user devices to enforce network access policies, then policy enforcement capability is improved, but device security vulnerabilities increase

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoiddevice security vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The service processor is pre-configured with network access policies before the device connects to the network. Application credentials and policy rules are established in advance, allowing the service processor to automatically enforce policies without real-time intervention. This preliminary configuration reduces the attack surface by minimizing runtime policy modification opportunities and ensures consistent policy application from the outset of each data session.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The service processor acts as an intermediary layer between applications and the network, mediating all data transmission activities. It verifies application credentials, enforces network access policies, and monitors data usage without exposing the core device security mechanisms. This intermediary architecture isolates security-critical functions from direct user and application access, reducing vulnerability to spoofing and hacking attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If applications are allowed to access network services with minimal restrictions, then application functionality is improved, but fraudulent activity risks increase

Engineering Contradiction:
Improveapplication functionalityVSAvoidfraudulent activity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The service processor continuously monitors application data usage and provides feedback through usage reports and notifications. It tracks actual data consumption against allocated credentials and alerts users when thresholds are approached or exceeded. This feedback mechanism enables users to control application behavior and prevents fraudulent activities by making data usage transparent and accountable in real-time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements application-specific network access policies with tailored credentials for each application. Instead of uniform restrictions, each application receives customized data sessions with appropriate permissions and limits based on its functionality and user authorization. This local quality approach maintains necessary application functionality while applying precise security controls specific to each application's risk profile.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10064055B2Security, fraud detection, and fraud mitigation in device-assisted services systems
Publication Date: 2018.08.28 HEADWATER RESEARCH LLC
  • US10064055B2 patent drawing
  • US10064055B2 patent drawing
  • US10064055B2 patent drawing

AI summary

Secure architectures and methods for improving the security of mobile devices are disclosed. Also disclosed are apparatuses and methods to detect and mitigate fraud in device-assisted services implementations.