IP Library Granted Patent US 12,632,553
Granted Patent B2
US 12,632,553 · App. 18/647,502 · Granted May 19, 2026

Method and a system for identifying compromised devices in an application infrastructure

Inventor: Pavel Vladimirovich Krylov (Moscow, RU)
Assignee: GROUP-IB GLOBAL PRIVATE LIMITED
G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,553
App. No.
18/647,502
Granted
May 19, 2026
Kind
B2
Abstract

Methods, a server, and an electronic device for identifying compromised user devices in an application infrastructure. One of the methods comprises: in response to receiving, from a given user device, a data container including a unique identifier of the given user device: updating a then current value of the unique identifier in a database, thereby generating an updated value of the unique identifier; and transmitting the updated value of the unique identifier to the given user device; in response to receiving information of the given user device being compromised: generating a then updated value of the unique identifier, indicative of the given user device being compromised; and transmitting a then updated data container with the then updated value of the unique identifier to the given user device, thereby enabling other servers of the application infrastructure to identify the given user device as being compromised.

Claims (28)

1 . A computer-implemented method for identifying compromised user devices in an application infrastructure associated with an application family, the application infrastructure including a first application and a second application installed on the given user device, the first application being associated with a first server, and the second application being associated with a second server, the method comprising:

initiating the first application on the given user device;

initiating the second application on the given user device, determining that the first and second applications are from the application family, the determining comprising:

receiving a list of family applications installed on the given user device;

determining presence of a data container associated with the application family in service data of each one of the first and second applications;

retrieving, from the service data of the first application, the data container including a current value of a unique identifier of the given user device;

transmitting the data container to the first server associated with the first application for updating the current value of the unique identifier, thereby causing the first server to:

generate an updated value of the unique identifier, indicative of the given user device being compromised; and

transmit, to the given user device, the data container including the updated value of the unique identifier of the given user device;

receiving, from the first server, the data container including the updated value of the unique identifier;

storing the data container in the service data of both the first and second applications; and

transmitting, to the second server associated with the second application, the data container including the updated value of the unique identifier of the given user device, to enable the second server to identify the given user device as being compromised.

2 . The method of claim 1 , further comprising excluding system applications from the list of the family applications.

3 . The method of claim 2 , wherein the determining the presence of the data container associated with the application family comprises executing a content provider application associated with the application family.

4 . An electronic device for identifying compromised user devices in an application infrastructure associated with an application family, the electronic device being configured for executing: a first application and a second application installed on the electronic device, the first application being associated with a first server, and the second application being associated with a second server, the electronic device comprising:

at least one processor and at least one non-transitory computer-readable memory storing executable instructions, which, when executed by the at least one processor, cause the electronic device to:

initiate the first application on the electronic device;

initiate the second application on the electronic device;

determine that the first and second applications are from the application family, by:

receiving a list of family applications installed on the electronic device;

determining presence of a data container associated with the application family in service data of each one of the first and second applications;

retrieve, from the service data of the first application, the data container including a current value of a unique identifier of the electronic device;

transmit the data container to the first server associated with the first application for updating the current value of the unique identifier, thereby causing the first server to:

generate an updated value of the unique identifier, indicative of the electronic device being compromised; and

transmit, to the electronic device, the data container including the updated value of the unique identifier of the electronic device;

receive, from the first server, the data container including the updated value of the unique identifier;

store the data container in the service data of both the first and second applications; and

transmit, to the second server associated with the second application, the data container including the updated value of the unique identifier of the electronic device, to enable the second server to identify the electronic device as being compromised.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2025
From: F.A.C.C.T. ANTIFRAUD LLC
To: GROUP-IB GLOBAL PRIVATE LIMITED
Reel/Frame 071438/0815 →
CHANGE OF NAME Recorded Jul 19, 2024
From: GROUP IB, LTD
To: F.A.C.C.T. ANTIFRAUD LLC
Reel/Frame 068462/0907 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2024
From: KRYLOV, PAVEL VLADIMIROVICH
To: GROUP IB, LTD
Reel/Frame 067277/0391 →
Priority Claims (1)
RU 2023130150 · Nov 21, 2023 · national
Continuity (1)
Related Publication 20250165602A1 · May 22, 2025
References Cited (37)
US 8510820B2 · Oberheide et al. · 2013 [cited by applicant]
US 9154388B2 · Savage et al. · 2015 [cited by applicant]
US 9419951B1 · Felsher et al. · 2016 [cited by applicant]
US 10089683B2 · Dominguez · 2018 [cited by applicant]
US 10153901B2 · Thackston · 2018 [cited by applicant]
US 10339606B2 · Gupta et al. · 2019 [cited by applicant]
US 10706423B1 · Kuo et al. · 2020 [cited by applicant]
US 10785287B2 · Prakash et al. · 2020 [cited by applicant]
US 11170130B1 · Blumberg et al. · 2021 [cited by applicant]
US 11259183B2 · Richardson et al. · 2022 [cited by applicant]
US 11386983B2 · Miyamoto et al. · 2022 [cited by applicant]
US 12346436B2 · Lee · 2025 [cited by examiner]
US 20110196791A1 · Dominguez · 2011 [cited by applicant]
US 20120198535A1 · Oberheide et al. · 2012 [cited by applicant]
US 20150006384A1 · Shaikh · 2015 [cited by applicant]
US 20150372888A1 · Savage et al. · 2015 [cited by applicant]
US 20170195298A1 · Brand · 2017 [cited by examiner]
US 20180227263A1 · O'Reirdan · 2018 [cited by applicant]
US 20210097534A1 · Kurian et al. · 2021 [cited by applicant]
US 20210243596A1 · Lim et al. · 2021 [cited by applicant]
US 20210319437A1 · Johnson et al. · 2021 [cited by applicant]
US 20210352049A1 · Aabye et al. · 2021 [cited by applicant]
JP 2011257810A · 2011 [cited by applicant]
JP 5581820B2 · 2014 [cited by applicant]
RU 2607990C1 · 2017 [cited by applicant]
RU 2691830C1 · 2019 [cited by applicant]
RU 2795371C1 · 2023 [cited by applicant]
WO 2016135708A1 · 2016 [cited by applicant]
Invitation to Respond to Written Opinion with regard to the SG Patent Application No. 10202401331Q mailed Jan. 10, 2026. [cited by applicant]
Search Report with regard to the RU Patent Application No. 2020133675 completed on Mar. 3, 2021. [cited by applicant]
English Abstract for JP2011257810/JP5581820B2 retrieved on Espacenet on Apr. 14, 2021. [cited by applicant]
Search Report with regard to the counterpart RU Patent Application No. 2022124168 completed Mar. 27, 2023. [cited by applicant]
Search Report with regard to the counterpart NL Patent Application No. 2034890 completed Feb. 23, 2024. [cited by applicant]
“Privacy enhancing data de-identification terminology and classification of techniques”, Project Editor/Co-Editor, ISO/IEC 20889, 2018, 62 pages. [cited by applicant]
Wikipedia, “Card-not-present transaction”, retrieved on en.wikipedia.org/wiki/Card_not_present_transaction on Apr. 19, 2024, pdf 3 pages. [cited by applicant]
Search report issued on Aug. 5, 2025 by the Netherlands Intellectual Property Office in respect of the counterpart Netherlands patent application No. 2037654. [cited by applicant]
Notice of Allowance with regard to the counterpart U.S. Appl. No. 18/134,669 issued Feb. 27, 2025. [cited by applicant]