Transaction Fraud Screening with Data Obfuscation and Risk Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of financial transactions, especially in banking, there is a challenge in balancing security and privacy needs, as existing systems often require excessive information sharing, which can compromise user privacy and expose sensitive data, while also struggling to effectively detect fraudulent activities.

Innovation Solution

A transactional system comprising a risk module and an obfuscation module that negotiates between security and privacy needs by uncovering only necessary risk-relevant data for assessment, requesting user consent, and aborting transactions if excessive information is required, thereby protecting customer data and ensuring fraud detection without data exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If extensive information is transferred to service providers for fraud detection, then fraud detection capability is improved, but user privacy is compromised

Engineering Contradiction:
Improvefraud detection capabilityVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the essential risk-relevant data from transactions for fraud detection, separating necessary security information from unnecessary personal data. The risk module identifies and transmits only specific risk indicators (such as transaction amount, frequency, and pattern anomalies) while leaving out sensitive personal information, thus achieving fraud detection without comprehensive data exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different levels of data sharing to different aspects of transaction information. Sensitive personal data is protected with higher privacy levels while risk-relevant transaction characteristics are shared with service providers. This localized differentiation allows the system to maintain privacy for personal identifiers while still providing sufficient information for effective fraud detection.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If comprehensive transaction data is shared with multiple banks and service providers, then fraud detection accuracy is improved, but data exposure risk increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoiddata exposure risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a risk module as an intermediary between the banking system and service providers. This module processes transaction data locally, identifies risk indicators, and transmits only these processed risk signals to service providers and other banks. The intermediary prevents raw personal data from being exposed while still enabling collaborative fraud detection through shared risk information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates simplified copies of transaction data that contain risk indicators but exclude sensitive personal information. Instead of sharing actual customer data, the system generates abstracted representations that preserve fraud detection capabilities while eliminating privacy risks. These copies can be safely shared across multiple institutions without exposing real customer identities.

Inventive Principle:
Principle #26Copying

3Measurement precision

If more information is uncovered for risk assessment, then risk assessment quality is improved, but privacy protection is weakened

Engineering Contradiction:
Improverisk assessment qualityVSAvoidcustomer data privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies partial action by uncovering only the necessary portion of transaction information required for risk assessment. The risk module selectively identifies and transmits specific risk-relevant data points (such as transaction patterns, amounts, and frequencies) without exposing complete customer profiles. This partial information sharing achieves sufficient risk assessment quality while maintaining privacy protection for unnecessary data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12093959B2System and method for enforcing granular privacy controls during transaction fraud screening by a third party
Publication Date: 2024.09.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12093959B2 patent drawing
  • US12093959B2 patent drawing
  • US12093959B2 patent drawing

AI summary

Methods, computer program products, and systems are presented. The methods include customer specific information exchange and an adjustment of the privacy level of this information. For this purpose an abstraction layer and an obfuscation module are introduced. Using a “fraud vector” a risk assessment is performed on the obfuscated transaction data.