Device-Assisted Service Policy Enforcement for Fraud Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices can exceed data usage limits without user awareness, leading to expensive overages, and there is a risk of fraudulent access to data services through device spoofing or hacking, necessitating secure software and hardware protection and fraud detection in device-assisted services systems.
Innovation Solution
Implementing a device-assisted services system with end-user devices equipped with modems, memory, and device agents to enforce application-specific network access policies, including flow-tagging, application programming interfaces, and multi-tiered policy verification to secure and monitor data usage, prevent unauthorized modifications, and detect fraudulent activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If device-assisted services are implemented to enable applications to send and receive large quantities of information, then data communication capability is improved, but the risk of fraudulent access and data usage overages increases
Solution Approach 1:
The patent segments the service policy implementation into multiple components: network-wide policies, application-specific policies, and device-level enforcement. This segmentation allows for granular control and monitoring of data usage by different applications, enabling fraud detection while maintaining high data communication capability.
Solution Approach 2:
The patent introduces service processors and service controllers as intermediary components between the network and end-user devices. These intermediaries enforce service policies, monitor data usage, and detect fraudulent activities, thereby securing the system without impeding legitimate data communication.
2Device complexity
If service policies are enforced at the network level only, then implementation complexity is reduced, but the ability to detect and prevent device-level fraud is insufficient
Solution Approach 1:
The patent implements service policy enforcement at multiple levels with different qualities: network-wide policies provide broad coverage, while application-specific and device-level policies provide localized, granular control. This multi-level approach enhances fraud detection capability without requiring complete redesign of the entire system.
Solution Approach 2:
The patent adds a new dimension to policy enforcement by introducing service processors within end-user devices that work alongside network-level controllers. This creates a multi-dimensional enforcement architecture that combines network-wide and device-level monitoring, improving fraud detection while distributing complexity across multiple layers.
3Ease of operation
If unlimited data service plans are offered, then user convenience is improved, but network operators face financial loss from overages and fraudulent usage
Solution Approach 1:
The patent implements feedback mechanisms where service processors continuously monitor data usage by applications and report to network operators. This real-time feedback enables operators to identify overages and fraudulent usage patterns, allowing them to maintain convenient service plans while preventing financial losses through active monitoring and enforcement.
Solution Approach 2:
The patent applies preliminary service policies that set usage limits and monitoring rules before data consumption occurs. Service processors pre-configure application-specific policies and enforce them proactively, preventing overages and fraudulent usage before they can cause financial loss, while still allowing convenient unlimited access within acceptable parameters.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Secure architectures and methods for improving the security of mobile devices are disclosed. Also disclosed are apparatuses and methods to detect and mitigate fraud in device-assisted services implementations.