IP Library Granted Patent US 11,580,548
Granted Patent B2
US 11,580,548 · App. 16/736,260 · Granted Feb 14, 2023

Device reputation

Inventors: Prashanth Ranganathan (San Francisco, CA); Alexander J. Olson (Menlo Park, CA); Frieder Bluemle (San Francisco, CA); Tobias Speckbacher (Menlo Park, CA)
Assignee: PAYPAL, INC.
G06Q20/4016G06F21/33G06F21/51H04L63/0876G06F2221/031G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,580,548
App. No.
16/736,260
Granted
Feb 14, 2023
Kind
B2
Abstract

A user device is associated with a dynamic trust score that may be updated as needed, where the trust score and the updates are based on various activities and information associated with the mobile device. The trust score is based on both parameters of the device, such as device type, registered device location, device phone number, device ID, the last time the device has been accessed, etc. and activities the device engages in, such as amount of transactions, dollar amount of transactions, amount of denied requests, amount of approved requests, location of requests, etc. Based on a transaction request from the user device, the trust score and a network reputation score is used to determine an overall trust/fraud score associated with the transaction request.

Claims (52)

1. A method, comprising:

receiving an indication that a user device has initiated an action, via a network, to access particular functionality of an online system, and wherein the action has one or more action characteristics;

determining a set of device parameters associated with the user device;

determining a unique identifier corresponding to the user device based on the set of device parameters and a hash function associated with the online system, wherein the unique identifier was previously generated by the hash function utilizing the set of device parameters that guarantees a threshold low probability rate of a false match for the unique identifier with another device that has accessed the online system;

using the unique identifier, accessing a device trust score for the user device;

based on a network address used by the user device to initiate the action, accessing a network trust score for the user device, wherein the network trust score is based on one or more devices, including the user device, that are associated with the network address;

determining a risk level for the action based on the device trust score, the network trust score, and the one or more action characteristics;

in response to the determined risk level exceeding a threshold, requiring the user device to perform an authentication process in order to allow access to the particular functionality of the online system; and

updating one or more of the device trust score or the network trust score based on a result of the authentication process.

2. The method of claim 1 , further comprising:

receiving an indication that the user device has successfully performed the authentication process and in response, allowing the action to access the particular functionality of the online system.

3. The method of claim 1 , wherein the unique identifier is based on one or more hardware characteristics of the user device.

4. The method of claim 1 , wherein the unique identifier is based on one or more software characteristics of the user device.

5. The method of claim 4 , wherein the one or more software characteristics include information reported to the online system regarding one or more characteristics of a web browser installed on the user device.

6. The method of claim 1 , wherein the particular functionality comprises a login to an electronic transaction system.

7. The method of claim 6 , wherein the electronic transaction system is configured to allow transfers of currency between a plurality of user accounts.

8. The method of claim 1 , wherein the threshold low probability rate is not greater than one in six hundred million.

9. The method of claim 1 , further comprising:

wherein the network trust score is lowered after a threshold period of time has elapsed since a last action was taken relative to the online system using the network address.

10. The method of claim 1 , further comprising:

based on an indication that the user device has failed to complete the action, lowering the device trust score for the user device.

11. The method of claim 1 , wherein the updating the network trust score includes raising the network trust score by a given amount or lowering the network trust score by at least 1.5 times the given amount.

12. The method of claim 1 , wherein the network trust score is based on one or more previous actions attempted relative to the online system by the one or more devices.

13. A system comprising:

a non-transitory memory;

a network interface device; and

one or more hardware processors coupled to the non-transitory memory and configured to read instructions from the non-transitory memory to cause the system to perform operations comprising:

receiving an indication that a user device has initiated an action, via a network, to access particular functionality of an online system, and wherein the action has one or more action characteristics;

determining a set of device parameters associated with the user device, wherein the set of device parameter comprise at least one hardware characteristic of the user device and at least one software characteristic of the user device;

determining a unique identifier corresponding to the user device based on the set of device parameters and a hash function associated with the online system, wherein the unique identifier is generated based on the hash function that guarantees a threshold low probability rate of a false match for the unique identifier with another device that has accessed the online system;

using the unique identifier, accessing a device trust score for the user device;

based on a network address used by the user device to initiate the action, accessing a network trust score for the user device, wherein the network trust score is based on one or more devices, including the user device, that are associated with the network address;

determining a risk level for the action based on the device trust score, the network trust score, and the one or more action characteristics;

in response to the determined risk level exceeding a threshold, requiring the user device to perform an authentication process in order to allow access to the particular functionality of the online system; and

updating one or more of the device trust score or the network trust score based on a result of the authentication process.

14. The system of claim 13 , wherein the operations further comprise:

receiving an indication that the user device has successfully performed the authentication process and in response, allowing access to additional functionality of the online system.

15. The system of claim 13 , wherein the updating the device trust score includes raising the device trust score by a given amount or lowering the network trust score by at least 1.5 times the given amount.

16. The system of claim 13 , wherein the particular action includes a transaction between a first user account associated with the user device and a second user account, the first and second user accounts corresponding to the online system.

17. The system of claim 13 , wherein the updating the network trust score includes raising the network trust score by a given amount or lowering the network trust score by at least twice the given amount.

18. A non-transitory computer-readable medium having stored thereon instructions that are executable by a system to cause the system to perform operations comprising:

receiving an indication that a user device has initiated an action, via a network, to access particular functionality of an online system, and wherein the action has one or more action characteristics;

determining a set of device parameters associated with the user device;

determining a unique identifier corresponding to the user device based on the set of device parameters and a hash function associated with the online system, wherein the unique identifier was previously generated by the hash function utilizing the set of device parameters that guarantees a a threshold low probability rate of a false match for the unique identifier with another device that has accessed the online system;

using the unique identifier, accessing a device trust score for the user device;

based on a network address used by the user device to initiate the action, accessing a network trust score for the user device, wherein the network trust score is based on one or more devices, including the user device, that are associated with the network address;

determining a risk level for the action based on the device trust score, the network trust score, and the one or more action characteristics;

in response to the determined risk level exceeding a threshold, requiring the user device to perform an authentication process in order to allow access to the particular functionality of the online system; and

updating one or more of the device trust score or the network trust score based on a result of the authentication process.

19. The non-transitory computer-readable medium of claim 18 , wherein the unique identifier is based on one or more software characteristics of the user device.

20. The non-transitory computer-readable medium of claim 18 , wherein the operations further comprise:

based on an indication that the user device has completed the action, raising the device trust score for the user device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2022
From: RANGANATHAN, PRASHANTH; OLSON, ALEXANDER J.; BLUEMLE, FRIEDER; SPECKBACHER, TOBIAS
To: EBAY INC.
Reel/Frame 061173/0722 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2022
From: EBAY INC.
To: PAYPAL, INC.
Reel/Frame 061173/0731 →
Continuity (5)
Continuation 15076563 · Mar 21, 2016
Continuation 14511785 · Oct 10, 2014
Continuation 13415184 · Mar 8, 2012
Provisional Application 61450789 · Mar 9, 2011
Related Publication 20200143380A1 · May 7, 2020
Cited By (1)
US 12,408,221