IP Library Granted Patent US 10,803,458
Granted Patent B1
US 10,803,458 · App. 16/226,877 · Granted Oct 13, 2020

Methods and systems for detecting suspicious or non-suspicious activities involving a mobile device use

Inventors: Jonathan Stewart Vokes (London, GB); Daren L. Pickering (Rugby, GB)
Assignee: Worldpay, LLC
G06Q20/40145G06F21/316G06Q20/3224G06Q20/4016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,803,458
App. No.
16/226,877
Granted
Oct 13, 2020
Kind
B1
Abstract

Systems and methods are disclosed for detecting a suspicious and/or a non-suspicious activity during an electronic transaction performed by a user device. One method comprises identifying, by a monitoring and detection component, a starting check point in the electronic transaction. The monitoring and detection component may then receive contextual data from one or more sensors of the user device. Based on the contextual data and a machine learning model, the monitoring and detection component may determine whether an expected behavior occurred. Entry of user credentials may be enabled in response to determining that the expected behavior occurred, whereas the electronic transaction may be terminated in response to determining that the expected behavior did not occur.

Claims (59)

1. A computer-implemented method of detecting a suspicious activity and/or a non-suspicious activity during an electronic transaction performed by a user device, comprising:

receiving, by a model building component, sample contextual data from one or more sensors of a plurality of user devices, the sample contextual data being captured during transfer of each of the plurality of user devices from one user to another;

training, by the model building component and using the sample contextual data, a machine learning model to identify a transfer of a user device from one user to another;

identifying, by a monitoring and detection component, a starting check point in an electronic transaction using a user device;

receiving, by the monitoring and detection component, contextual data from one or more sensors of the user device;

determining, by the monitoring and detection component and using the trained machine learning model, whether an expected behavior occurred, the expected behavior being a transfer of the user device from a first user to a second user, and the contextual data comprising a post-transfer facial image; and

in response to determining that the expected behavior occurred:

determining, by the monitoring and detection component, whether there is only one face detected in the post-transfer facial image; and

in response to determining that there is only one face detected in the post-transfer facial image, enabling, by the monitoring and detection component, entry of user credentials; or

in response to determining that there are more than one face detected in the post-transfer facial image, disabling, by the monitoring and detection component, entry of user credentials.

2. The method of claim 1 , wherein the sample contextual data comprises at least one or more of: i) vector displacement measurements received from an accelerometer of each of the plurality of user devices, ii) rotation measurements received from a gyroscope and a magnetometer of each of the plurality of user devices, iii) sound measurements received from one or more microphones of each of the plurality of user devices, or iv) image data received from one or more cameras of each of the plurality of user devices.

3. The method of claim 1 , wherein the contextual data further comprises at least one or more of: i) vector displacement measurements received from an accelerometer of the user device, ii) rotation measurements received from a gyroscope and a magnetometer of the user device, iii) sound measurements received from one or more microphones of the user device, or iv) image data received from one or more cameras of the user device.

4. The method of claim 1 , wherein the electronic transaction is terminated in response to determining that the expected behavior did not occur within a predetermined time.

5. The method of claim 1 , wherein the contextual data further comprises a pre-transfer facial image, further comprising:

in response to determining that the expected behavior occurred:

determining, by the monitoring and detection component, whether a first face detected in the pre-transfer facial image is different from a second face detected in the post-transfer facial image; and

in response to determining that the first face is different from the second face, enabling, by the monitoring and detection component, entry of user credentials; or

in response to determining that the first face matches the second face, disabling, by the monitoring and detection component, entry of user credentials.

6. The method of claim 1 , wherein the starting check point is a point in time at which the monitoring and detection component directs the one or more sensors of the user device to begin transmitting the contextual data.

7. The method of claim 6 , further comprising:

identifying an ending check point at which the monitoring and detection component directs the one or more sensors of the user device to halt transmitting the contextual data.

8. A system for detecting a suspicious activity and/or a non-suspicious activity during an electronic transaction performed by a user device, comprising:

one or more processors;

a non-transitory computer readable medium storing instructions which, when executed by the one or more processors, cause the one or more processors to perform a method comprising:

receiving, by a model building component, sample contextual data from one or more sensors of a plurality of user devices, the sample contextual data being captured during transfer of each of the plurality of user devices from one user to another;

training, by the model building component and using the sample contextual data, a machine learning model to identify a transfer of a user device from one user to another;

identifying, by a monitoring and detection component, a starting check point in an electronic transaction using a user device;

receiving, by the monitoring and detection component, contextual data from one or more sensors of the user device;

determining, by the monitoring and detection component and using the trained machine learning model, whether an expected behavior occurred, the expected behavior being a transfer of the user device from a first user to a second user, and the contextual data comprising a post-transfer facial image; and

in response to determining that the expected behavior occurred:

determining, by the monitoring and detection component, whether there is only one face detected in the post-transfer facial image; and

in response to determining that there is only one face detected in the post-transfer facial image, enabling, by the monitoring and detection component, entry of user credentials; or

in response to determining that there are more than one face detected in the post-transfer facial image, disabling, by the monitoring and detection component, entry of user credentials.

9. The system of claim 8 , wherein the sample contextual data comprises at least one or more of: i) vector displacement measurements received from an accelerometer of each of the plurality of user devices, ii) rotation measurements received from a gyroscope and a magnetometer of each of the plurality of user devices, iii) sound measurements received from one or more microphones of each of the plurality of user devices, or iv) image data received from one or more cameras of each of the plurality of user devices.

10. The system of claim 8 , wherein the contextual data further comprises at least one or more of: i) vector displacement measurements received from an accelerometer of the user device, ii) rotation measurements received from a gyroscope and a magnetometer of the user device, iii) sound measurements received from one or more microphones of the user device, or iv) image data received from one or more cameras of the user device.

11. The system of claim 8 , wherein the electronic transaction is terminated in response to determining that the expected behavior did not occur within a predetermined time.

12. The system of claim 8 , wherein the contextual data further comprises a pre-transfer facial image and the method further comprises:

in response to determining that the expected behavior occurred:

determining, by the monitoring and detection component, whether a first face detected in the pre-transfer facial image is different from a second face detected in the post-transfer facial image; and

in response to determining that the first face is different from the second face, enabling, by the monitoring and detection component, entry of user credentials; or

in response to determining that the first face matches the second face, disabling, by the monitoring and detection component, entry of user credentials.

13. A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform a method of detecting a suspicious activity and/or a non-suspicious activity during an electronic transaction performed by a user device, the method comprising:

receiving, by a model building component, sample contextual data from one or more sensors of a plurality of user devices, the sample contextual data being captured during transfer of each of the plurality of user devices from one user to another;

training, by the model building component and using the sample contextual data, a machine learning model to identify a transfer of a user device from one user to another;

identifying, by a monitoring and detection component, a starting check point in an electronic transaction using a user device;

receiving, by the monitoring and detection component, contextual data from one or more sensors of the user device;

determining, by the monitoring and detection component and using the trained machine learning model, whether an expected behavior occurred, the expected behavior being a transfer of the user device from a first user to a second user, and the contextual data comprising a post-transfer facial image; and

in response to determining that the expected behavior occurred:

determining, by the monitoring and detection component, whether there is only one face detected in the post-transfer facial image; and

in response to determining that there is only one face detected in the post-transfer facial image, enabling, by the monitoring and detection component, entry of user credentials; or

in response to determining that there are more than one face detected in the post-transfer facial image, disabling, by the monitoring and detection component, entry of user credentials.

14. The non-transitory computer readable medium of claim 13 , wherein the sample contextual data comprises at least one or more of: i) vector displacement measurements received from an accelerometer of each of the plurality of user devices, ii) rotation measurements received from a gyroscope and a magnetometer of each of the plurality of user devices, iii) sound measurements received from one or more microphones of each of the plurality of user devices, or iv) image data received from one or more cameras of each of the plurality of user devices.

15. The non-transitory computer readable medium of claim 13 , wherein the contextual data further comprises at least one or more of: i) vector displacement measurements received from an accelerometer of the user device, ii) rotation measurements received from a gyroscope and a magnetometer of the user device, iii) sound measurements received from one or more microphones of the user device, iv) image data received from one or more cameras of the user device.

16. The non-transitory computer readable medium of claim 13 , wherein the electronic transaction is terminated in response to determining that the expected behavior did not occur within a predetermined time.

17. The non-transitory computer readable medium of claim 13 , wherein the contextual data further comprises a pre-transfer facial image and the method further comprises:

in response to determining that the expected behavior occurred:

determining, by the monitoring and detection component, whether a first face detected in the pre-transfer facial image is different from a second face detected in the post-transfer facial image; and

in response to determining that the first face is different from the second face, enabling, by the monitoring and detection component, entry of user credentials; or

in response to determining that the first face matches the second face, disabling, by the monitoring and detection component, entry of user credentials.

Assignments (5)
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2018
From: VOKES, JONATHAN STEWART; PICKERING, DAREN L.
To: WORLDPAY, LLC
Reel/Frame 047828/0316 →
Cited By (2)
US 12,244,619 US 12,321,428