IP Library Granted Patent US 12,346,906
Granted Patent B2
US 12,346,906 · App. 17/548,808 · Granted Jul 1, 2025

Method, apparatus and computer program product for reporting an exchange of messages between nodes in a network

Inventors: Syed Asim Ali Shah (Harrow, GB); David William Divitt (Eye, GB)
Assignee: Vocalink International Limited
G06Q20/4016H04L51/216
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,346,906
App. No.
17/548,808
Granted
Jul 1, 2025
Kind
B2
Abstract

A method, apparatus and computer program product for reporting an exchange of messages between nodes in a network is provided by the present disclosure, the method comprising: receiving from a first device, using circuitry, a request for data for a target node, the data indicative of an exchange of messages between nodes in a network linked to the target node determining, by the circuitry, whether a request for data for the target node has previously been received; and, when a request for data for the target node has previously been received, the method comprises: building, by the circuitry, data indicative of the exchange of messages between nodes in the network linked to the target node; identifying, by the circuitry, a new portion of the data based on a comparison of the data with previous data which has been built for the target node; and reporting to the first device, by the circuitry, the new portion of the data.

Claims (45)

1. A method of reporting an exchange of messages between nodes in a network, the method comprising:

receiving from a first device, using circuitry, a first fraud investigation request for data for a target node, the data indicative of an exchange of messages between nodes in a network linked to the target node, the first fraud investigation request indicating that the target node is linked to potentially fraudulent activity, the target node and the nodes being separate from the first device;

building, by the circuitry, first data indicative of a first exchange of one or more messages between nodes in the network linked to the target node, the first data being built in response to receiving the first fraud investigation request;

storing, by the circuitry, a record of the fraud investigation request in a database configured to store records corresponding to fraud investigation requests associated with potentially fraudulent activity in the network;

receiving, from the first device, using the circuitry, a second fraud investigation request for data for the target node, the data indicative of an exchange of messages between nodes in the network linked to the target node, the nodes being separate from the first device;

determining, by the circuitry, that a fraud investigation request for data for the target node has previously been received, the determination including querying the database to identify the record of the first fraud investigation request, the determination indicating that the target node was subject to the first fraud investigation request;

based on the determination that the first fraud investigation request was previously received,

building, by the circuitry, second data indicative of a second exchange of one or more messages between nodes in the network linked to the target node;

based on the determination that the first fraud investigation request has previously been received, identifying, by the circuitry, a new portion of the second data based on a comparison of the second data with the first data built for the target node, the new portion of the second data excluding the first data; and

reporting, to the first device, by the circuitry, the new portion of the second data.

2. The method according to claim 1 , wherein the first data and the second data include information regarding a source node, the target node and a message value for each of the one or more messages of the first and the second exchanges.

3. The method according to claim 1 , wherein the first and second fraud investigation requests comprise information identifying the target node.

4. The method according to claim 1 , wherein the first and second fraud investigation requests comprise an identifier identifying the one or more messages of the first and second exchanges, respectively.

5. The method according to claim 1 , wherein the target node is an account in a banking network and wherein the one or more messages of the first and second exchanges include transactions between the accounts.

6. The method according to claim 1 , wherein the method comprises replacing, in the database, the first data which has been built for the target node with the second data indicative of the exchange of messages between nodes in the network linked to the target node.

7. The method according to claim 1 , wherein the method comprises replacing the first data which has been built for the target node by augmenting the first data with the new portion of the second data and storing the augmented first data in the database.

8. The method according to claim 1 , wherein the data indicative of an exchange of messages between nodes in a network linked to the target nodes is a dispersion tree showing the dispersion of messages through the network linked to the target node.

9. The method according to claim 1 , wherein the new portion of the second data indicative of the second exchange of one or more messages between nodes in the network linked to the target node includes information identifying new nodes and new messages which were not previously identified as being linked with the target node.

10. The method according to claim 1 , wherein the method comprises identifying one or more second devices which have previously made a fraud investigation request for data for the target node; and reporting, to the one or more second devices, by the circuitry, the new portion of the second data.

11. The method according to claim 1 , wherein the method further comprises formulating the new portion of the second data into a standardised data structure; and reporting the new portion of the second data in the standardised data structure.

12. The method according to claim 1 , wherein the first and second fraud investigation requests include an identifier of the first device; and wherein determining whether a fraud investigation request for the request for data for the target node has previously been received includes determining whether a fraud investigation request for data for the target node has previously been received from the first device.

13. An apparatus for reporting an exchange of messages between nodes in a network, the apparatus comprising circuitry configured to:

receive from a first device a first fraud investigation request for data for a target node, the data indicative of an exchange of messages between nodes in a network linked to the target node, the first fraud investigation request indicating that the target node is linked to potentially fraudulent activity, the target node and the nodes being separate from than the first device;

build first data indicative of a first exchange of one or more messages between nodes in the network linked to the target node, the first data being built in response to receiving the fraud investigation request;

store a record of the fraud investigation request in a database configured to store records corresponding to fraud investigation requests associated with potentially fraudulent activity in the network;

receive, from the first device, a second fraud investigation request for data for the target node, the data indicative of an exchange of messages between nodes in the network linked to the target node, the nodes being separate from the first device;

determine that a fraud investigation request for data for the target node has previously been received, the determination including querying the database to identify the record of the first fraud investigation request, the determination indicating that the target node was subject to the first fraud investigation request;

based on the determination that the first fraud investigation request was previously received,

the circuitry is further configured to:

build second data indicative of a second exchange of one or more messages between nodes in the network linked to the target node;

based on the determination that the first fraud investigation request has previously been received, identify a new portion of the second data based on a comparison of the second data with the first data built for the target node, the new portion of the second data excluding the first data; and

report to the first device the new portion of the second data.

14. The apparatus according to claim 13 , wherein the new portion of the second data indicative of the second exchange of one or more messages between nodes in the network linked to the target node includes information identifying new nodes and new messages which were not previously identified as being linked with the target node.

15. The apparatus according to claim 13 , wherein the apparatus is configured to identify one or more second devices which have previously made a fraud investigation request for data for the target node; and report to the one or more second devices the new portion of the second data.

16. A non-transitory machine-readable medium having instructions stored thereon that, when executed by at least one processor, cause the at least one processor to perform operations comprising:

receiving from a first device a first fraud investigation request for data for a target node, the data indicative of an exchange of messages between nodes in a network linked to the target node, the first fraud investigation request indicating that the target node is linked to potentially fraudulent activity, the target node and the nodes being separate from the first device;

building first data indicative of a first exchange of one or more messages between nodes in the network linked to the target node, the first data being built in response to receiving the fraud investigation request;

storing a record of the fraud investigation request in a database configured to store records corresponding to fraud investigation requests associated with potentially fraudulent activity in the network;

receiving, from the first device, a second fraud investigation request for data for the target node, the data indicative of an exchange of messages between nodes in the network linked to the target node, the nodes being separate from the first device;

determining that a fraud investigation request for data for the target node has previously been received, the determination including querying the database to identify the record of the first fraud investigation request, the determination indicating that the target node was subject to the first fraud investigation request;

based on the determination that the first fraud investigation request was previously received,

building second data indicative of a second exchange of one or more messages between nodes in the network linked to the target node;

based on the determination that the first fraud investigation request has previously been received, identifying a new portion of the second data based on a comparison of the second data with the first data built for the target node, the new portion of the second data excluding the first data; and

reporting to the first device the new portion of the second data.

17. The non-transitory machine-readable medium according to claim 16 , wherein the new portion of the second data indicative of the second exchange of one or more messages between nodes in the network linked to the target node includes information identifying new nodes and new messages which were not previously identified as being linked with the target node.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME ON THE COVER SHEET PREVIOUSLY RECORDED AT REEL: 062678 FRAME: 0257. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 15, 2023
From: VOCALINK LIMITED
To: VOCALINK INTERNATIONAL LIMITED
Reel/Frame 062752/0884 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2023
From: VOCALINK LIMITED
To: VOCALINK INTERNATIONA LIMITED
Reel/Frame 062678/0257 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2023
From: VOCALINK LIMITED
To: VOCALINK INTERNATIONAL LIMITED
Reel/Frame 062605/0360 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2021
From: SHAH, SYED ASIM ALI; DIVITT, DAVID
To: VOCALINK LIMITED
Reel/Frame 058373/0685 →
Priority Claims (1)
GB 2020525 · Dec 23, 2020 · national
Continuity (1)
Related Publication 20220198456A1 · Jun 23, 2022
References Cited (16)
US 11526933B1 · Adapala · 2022 [cited by examiner]
US 20080082454A1 · Dilip · 2008 [cited by examiner]
US 20130218765A1 · Hammad · 2013 [cited by examiner]
US 20150073981A1 · Adjaoute · 2015 [cited by examiner]
US 20160132886A1 · Burke · 2016 [cited by examiner]
US 20160364794A1 · Chari et al. · 2016 [cited by applicant]
US 20170228706A1 · Parziale · 2017 [cited by examiner]
US 20200106688A1 · Dewar · 2020 [cited by examiner]
US 20200106689A1 · Dewar · 2020 [cited by applicant]
US 20210400066A1 · Sood · 2021 [cited by examiner]
EP 2689384 · 2014 [cited by applicant]
EP 3570185 · 2019 [cited by applicant]
EP 3629273 · 2020 [cited by applicant]
GB 2509433 · 2014 [cited by applicant]
International Search Report and Written Opinion for PCT Application No. PCT/EP2021/082017 (Mar. 3, 2022). [cited by applicant]
UK Search Report for Application No. GB2020525.8 entitled A Method, Apparatus and Computer Program Product for Reporting an Exchange of Messages Between Nodes in a Network (dated Jun. 22, 2021). [cited by applicant]