IP Library Granted Patent US 11,720,899
Granted Patent B2
US 11,720,899 · App. 17/529,813 · Granted Aug 8, 2023

Methods and systems for detecting suspicious activities during an electronic payment transaction by authenticating registered users

Inventors: Jonathan Stewart Vokes (London, GB); Daren L. Pickering (Rugby, GB)
Assignee: Worldpay, LLC
G06Q20/40145G06F21/316G06Q20/3224G06Q20/4016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,720,899
App. No.
17/529,813
Granted
Aug 8, 2023
Kind
B2
Abstract

Systems and methods are disclosed for detecting a suspicious and/or a non-suspicious activity during an electronic transaction performed by a user device. One method comprises identifying, by a monitoring and detection component, a starting check point in the electronic transaction. The monitoring and detection component may then receive contextual data from one or more sensors of the user device. Based on the contextual data and a machine learning model, the monitoring and detection component may determine whether an expected behavior occurred. Entry of user credentials may be enabled in response to determining that the expected behavior occurred, whereas the electronic transaction may be terminated in response to determining that the expected behavior did not occur.

Claims (53)

1. A computer-implemented method of detecting a suspicious activity during an electronic transaction, comprising:

determining, by a monitoring and detection component, that a transfer of a user device from a first user to a second user occurred during the electronic transaction;

receiving, by the monitoring and detection component, facial images of the first user and the second user during the transfer of the user device;

generating, by the monitoring and detection component, one or more user interfaces for display by the user device prompting entry of user credentials by the first user and the second user upon determining the facial images of the first user matches biometric data of a registered seller and the facial images of the second user matches biometric data of a registered buyer; and

inhibiting or postponing, by the monitoring and detection component, the entry of the user credentials by the second user upon determining a presence of a third user within a proximity threshold of the user device and the second user, wherein the third user is not a registered user.

2. The computer-implemented method of claim 1 , further comprising:

configuring, by the monitoring and detection component, to collect contextual data of one or more users via one or more sensors of a plurality of user devices wherein the contextual data includes the biometric data and device movement data;

preparing, by a model building component, the collected contextual data by randomizing an ordering of the contextual data, visualizing the contextual data to identify relevant relationships between different variables, and identifying data imbalances; and

training, by the model building component, a machine learning model using the prepared contextual data to detect one or more patterns associated with the suspicious activity during the electronic transaction.

3. The computer-implemented method of claim 2 , wherein a hash of the biometric data of the one or more users is stored for each of the electronic transaction to detect the third user attempting to enter the user credentials.

4. The computer-implemented method of claim 2 , further comprising:

determining, by the monitoring and detection component, a starting check point to capture the contextual data of the one or more users, wherein the starting check point is initiated upon a presentation of the one or more user interfaces in the user device for the entry of a transaction amount; and

determining, by the monitoring and detection component, an ending check point to halt the capturing of the contextual data of the one or more users, wherein the ending check point is activated upon successful entry of the user credentials.

5. The computer-implemented method of claim 4 , further comprising:

transmitting, by the monitoring and detection component, an aggregated contextual data upon determining the ending check point, wherein the aggregated contextual data is transmitted to the model building component to analyze behavior patterns across an entire user base and a local model building component of a user application in the user device to analyze the behavior patterns localized to the user device.

6. The computer-implemented method of claim 1 , further comprising:

deactivating, by the monitoring and detection component, the entry of the user credentials upon determining the facial images of the first user matches the facial images of the second user, wherein the deactivation of the entry of the user credentials include a hiding of a numeric keypad to disable an input of numerical digits; and

generating, by the monitoring and detection component, a visual and/or an aural notification in the user device to transfer the user device to the registered buyer or on an occurrence of the suspicious activity.

7. The computer-implemented method of claim 6 , further comprising:

activating, by the monitoring and detection component, the entry of the user credentials upon determining the facial images of the first user is different from the facial images of the second user, wherein the facial images of the second user matches the biometric data of the registered buyer, and wherein the activation of the entry of the user credentials include a revealing of the numeric keypad to enable the input of the numerical digits.

8. The computer-implemented method of claim 2 , wherein the contextual data comprises image data and sound data received from the one or more sensors of the plurality of user devices, wherein the sound data is processed to determine a sound pattern to deduce a movement and the transfer of the user device.

9. The computer-implemented method of claim 2 , wherein the contextual data comprises vector displacement measurements received from an accelerometer of the plurality of user devices and rotation measurements received from a gyroscope and a magnetometer of the plurality of user devices.

10. The computer-implemented method of claim 1 , wherein the electronic transaction is terminated upon determining the transfer of the user device from the first user to the second user did not occur within a pre-determined time threshold.

11. A system for detecting a suspicious activity during an electronic transaction, comprising:

determining, by a monitoring and detection component using at least one processor, that a transfer of a user device from a first user to a second user occurred during the electronic transaction;

receiving, by the monitoring and detection component, facial images of the first user and the second user during the transfer of the user device;

generating, by the monitoring and detection component, one or more user interfaces for display by the user device prompting entry of user credentials by the first user and the second user upon determining the facial images of the first user matches biometric data of a registered seller and the facial images of the second user matches biometric data of a registered buyer; and

inhibiting or postponing, by the monitoring and detection component, the entry of the user credentials by the second user upon determining a presence of a third user within a proximity threshold of the user device and the second user, wherein the third user is not a registered user.

12. The system of claim 11 , further comprising:

configuring, by the monitoring and detection component, to collect contextual data of one or more users via one or more sensors of a plurality of user devices wherein the contextual data includes the biometric data and device movement data;

preparing, by a model building component, the collected contextual data by randomizing an ordering of the contextual data, visualizing the contextual data to identify relevant relationships between different variables, and identifying data imbalances; and

training, by the model building component, a machine learning model using the prepared contextual data to detect one or more patterns associated with the suspicious activity during the electronic transaction.

13. The system of claim 12 , wherein a hash of the biometric data of the one or more users is stored for each of the electronic transaction to detect the third user attempting to enter the user credentials.

14. The system of claim 12 , further comprising:

determining, by the monitoring and detection component, a starting check point to capture the contextual data of the one or more users, wherein the starting check point is initiated upon a presentation of the one or more user interfaces in the user device for the entry of a transaction amount; and

determining, by the monitoring and detection component, an ending check point to halt the capturing of the contextual data of the one or more users, wherein the ending check point is activated upon successful entry of the user credentials.

15. The system of claim 14 , further comprising:

transmitting, by the monitoring and detection component, an aggregated contextual data upon determining the ending check point, wherein the aggregated contextual data is transmitted to the model building component to analyze behavior patterns across an entire user base and a local model building component of a user application in the user device to analyze the behavior patterns localized to the user device.

16. The system of claim 11 , further comprising:

deactivating, by the monitoring and detection component, the entry of the user credentials upon determining the facial images of the first user matches the facial images of the second user, wherein the deactivation of the entry of the user credentials include a hiding of a numeric keypad to disable an input of numerical digits; and

generating, by the monitoring and detection component, a visual and/or an aural notification in the user device to transfer the user device to the registered buyer or on an occurrence of the suspicious activity.

17. The system of claim 16 , further comprising:

activating, by the monitoring and detection component, the entry of the user credentials upon determining the facial images of the first user is different from the facial images of the second user, wherein the facial images of the second user matches the biometric data of the registered buyer, and wherein the activation of the entry of the user credentials include a revealing of the numeric keypad to enable the input of the numerical digits.

18. A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform a method of detecting a suspicious activity during an electronic transaction, the method comprising:

determining, by a monitoring and detection component, that a transfer of a user device from a first user to a second user occurred during the electronic transaction;

receiving, by the monitoring and detection component, facial images of the first user and the second user during the transfer of the user device;

generating, by the monitoring and detection component, one or more user interfaces for display by the user device prompting entry of user credentials by the first user and the second user upon determining the facial images of the first user matches biometric data of a registered seller and the facial images of the second user matches biometric data of a registered buyer; and

inhibiting or postponing, by the monitoring and detection component, the entry of the user credentials by the second user upon determining a presence of a third user within a proximity threshold of the user device and the second user, wherein the third user is not a registered user.

19. The non-transitory computer readable medium of claim 18 , further comprising:

configuring, by the monitoring and detection component, to collect contextual data of one or more users via one or more sensors of a plurality of user devices wherein the contextual data includes the biometric data and device movement data;

preparing, by a model building component, the collected contextual data by randomizing an ordering of the contextual data, visualizing the contextual data to identify relevant relationships between different variables, and identifying data imbalances; and

training, by the model building component, a machine learning model using the prepared contextual data to detect one or more patterns associated with the suspicious activity during the electronic transaction.

20. The non-transitory computer readable medium of claim 19 , wherein a hash of the biometric data of the one or more users is stored for each of the electronic transaction to detect the third user attempting to enter the user credentials.

Assignments (5)
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2021
From: VOKES, JONATHAN STEWART; PICKERING, DAREN L.
To: WORLDPAY, LLC
Reel/Frame 058155/0384 →
Continuity (3)
Continuation 17012361 · Sep 4, 2020
Continuation 16226877 · Dec 20, 2018
Related Publication 20220076270A1 · Mar 10, 2022