User Device Time-Based Fraud Detection via External Clock
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional risk management techniques for authenticating transactions lack a reliable external time source, making it difficult to meet regulatory requirements for time-based authentication and preventing fraudulent transactions.
Innovation Solution
A user device architecture is modified to communicatively couple a clock chip and an EMV chip, using an internal battery or capacitor to power the clock component and store time stamp information, allowing for time-based risk analysis and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional event-based counters and accumulators are used for risk management, then transaction authentication can be performed, but the system cannot reliably meet regulatory time-based requirements
Solution Approach 1:
The patent introduces a trusted third-party time server as an intermediary to provide accurate time information to the user device. This mediator ensures that both the user device and access device use synchronized time references, enabling reliable time-based authentication without requiring the user device to maintain its own precise clock, thus resolving the contradiction between authentication reliability and time measurement accuracy.
Solution Approach 2:
The system implements feedback mechanisms where time information is continuously exchanged between the user device, access device, and time server. The access device receives time information from the user device, compares it with time information from the time server, and provides feedback on authentication decisions. This feedback loop ensures that time-based requirements are met reliably while maintaining accurate time measurement through continuous synchronization.
2Reliability
If no external time source is used in the user device, then device complexity is reduced, but the device cannot reliably authenticate transactions based on time regulations
Solution Approach 1:
The patent extracts the timekeeping function from the user device by introducing a separate, dedicated time server that provides time information externally. The user device only needs to store and process time information received from this external source, rather than maintaining its own complex time synchronization mechanisms. This extraction maintains authentication reliability while significantly reducing the complexity of the user device architecture.
Solution Approach 2:
The time server serves multiple functions: it provides time information to both user devices and access devices, synchronizes time across the system, and enables regulatory compliance. This universal time source can be used by any device in the system without requiring each device to have its own timekeeping capabilities, thus maintaining authentication reliability while minimizing overall system complexity.
3Object-affected harmful factors
If time-based authentication is implemented, then fraudulent transactions can be detected, but the system requires synchronized time information from multiple sources
Solution Approach 1:
The trusted time server acts as an intermediary that simplifies time synchronization between user devices and access devices. Instead of each device needing to independently synchronize its clock with multiple time sources, the time server provides a single, authoritative time reference that both types of devices can query. This mediator approach enables effective fraud detection through time-based authentication while significantly reducing the complexity of maintaining synchronized time information across the system.
4Speed
If the user device stores time information locally, then authentication speed is improved, but time drift may occur without external synchronization
Solution Approach 1:
The system performs preliminary actions by pre-storing time information and time limit policies in the user device before transactions occur. The user device maintains local copies of time data and authentication policies, enabling rapid authentication decisions without requiring real-time external synchronization during each transaction. This preliminary preparation improves authentication speed while the continuous background synchronization with the time server ensures time accuracy remains reliable.
Solution Approach 2:
The patent implements continuous time synchronization between the user device and the time server, ensuring that time information remains accurate over extended periods. This continuous action allows the user device to maintain both fast local authentication processing and accurate time measurement, as the device constantly updates its time reference without interrupting the authentication workflow. The continuous synchronization prevents time drift accumulation while preserving the speed benefits of local time storage.
Data Source
AI summary
Techniques for identifying a fraudulent interaction of a user device using time based risk features are described herein. In embodiments, time stamp information provided by an external clock and time units may be maintained by a user device. The user device may include an authentication component that is communicatively coupled to a clock component that generates the time units. In response to conducting an interaction with an access device and user device first time information may be received from the access device. Second time information may be determined based at least in part on the time units from the clock component and the time stamp information. The second time information may be compared to the first time information. An authentication plan for the interaction may be determined based at least in part on the comparison of the second time information to the first time information.


