US2022138755A1PendingUtilityA1

Detecting unauthorized devices

Assignee: SQUARE INCPriority: Mar 29, 2018Filed: Nov 5, 2021Published: May 5, 2022
Est. expiryMar 29, 2038(~11.7 yrs left)· nominal 20-yr term from priority
Inventors:Todd Aument
G06Q 20/4016H04L 63/1433G07F 7/0886H04W 8/005H04L 2463/102G07F 7/0893H04W 4/80G07F 19/2055G06Q 20/3278G07F 7/0873G06Q 20/3223G06Q 20/204G06Q 20/3226H04L 63/1475
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A payment reader and a POS terminal may communicate over a wireless connection. The methods and systems include monitoring one or more parameters corresponding to a payment reader and another device in proximity to the payment reader. The first device, through a set of customized instructions, determines whether behavior of the second device substantially corresponds to the first device, in order to detect suspected hardware or software intrusion associated with the secure first device. On successful detection of a suspected intrusion, the first device generates an alert for a user of the first device if illegal intrusion is suspected by the processor.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A payment system comprising:
 one or more processors; and   one or more non-transitory computer-readable media storing instructions executable by the one or more processors, wherein the instructions program the one or more processors to perform actions comprising:
 monitoring, by a fraud detection component, one or more parameters corresponding to a first device; 
 monitoring, by the fraud detection component, the one or more parameters corresponding to a second device in proximity to the payment system; 
 determining, by the fraud detection component, whether behavior of the second device substantially corresponds with behavior of the first device; and 
 outputting, based at least in part on the behavior of the second device, on a user interface communicatively coupled with the one or more processors, an indication to a user of the first device that the second device represents a security vulnerability. 
   
     
     
         22 . The payment system of  claim 21 , wherein:
 the first device comprises a payment object reader, the POS terminal, or a payment application; and   the second device comprises an illicit skimmer having a wireless transceiver capable of communicating sensitive data from the payment object reader to an illicit computing device.   
     
     
         23 . The payment system of  claim 21 , further comprising instructions to apply a predictive model to indicate a probability of the second device being the security vulnerability, and wherein the predictive model is based on one or more characteristics of the second device, selected from a group of characteristics including timing parameters, emitted power levels, radiated performance, wireless performance, quality of communication links, radio frequency response, transmission measurements, receiver measurements, and engineering tolerances, being comparable to similar characteristics of the first device. 
     
     
         24 . The payment system of  claim 23 , wherein the predictive model is based on one or more trigger actions comprising at least one of: (a) introducing the second device in proximity to the first device; (b) fraudulently accessing a payment account associated with the first device; (c) physically swapping a component of the first device with a component of the second device; (d) changing location of the first device; (e) performing a payment transaction using the second device in proximity to the first device; (f) performing a payment transaction using the second device in proximity to the first device at a time when another payment transaction is in progress at the first device; (g) performing a payment transaction for an amount that is more than a predefined amount; (h) introducing the second device in a geographical perimeter; (i) physically altering the first device; (j) obtaining a card reader signal; (k) obtaining a merchant or server initiated trigger; or (l) waiting for lapse of a period of time. 
     
     
         25 . The payment system of  claim 21 , further comprising instructions configured for:
 determining whether the second device emits a signal with a strength that corresponds to a strength of a signal emitted from the first device;   determining whether reaction of the second device to a sub-routine corresponds to a reaction of the first device to the sub-routine;   determining whether movement of the second device corresponds to a movement of the first device; and   determining whether orientation of the second device corresponds to an orientation of the first device.   
     
     
         26 . The payment system of  claim 21 , further comprising instructions for:
 identifying, by a server, one or more devices matching a profile of the first device;   customizing, by the server, the instructions based on the identified one or more devices; and   transferring, by the server, the instructions to the identified one or more devices matching the profile of the first device to detect another security vulnerability similar to the security vulnerability in the identified one or more devices.   
     
     
         27 . The payment system of  claim 21 , further comprising instructions for determining that the second device is an unauthorized device with respect to the first device, based at least in part on one or more of:
 determining whether the second device emits a signal of a substantially same strength as a signal emitted from the first device;   determining whether the second device behaves in a manner substantially similar to the first device;   determining whether the second device reacts, to a sub-routine, in a manner substantially similar to the first device;   determining whether movement of the second device is substantially similar to that of the first device; or   determining whether an orientation of the second device is substantially similar to that of the first device.   
     
     
         28 . The payment system of  claim 21 , further comprising instructions for:
 in response to determining that the second device represents the security vulnerability, canceling or aborting pending payment transactions performed using the first device;   disabling a connection between the first device and a monitoring device; and   sending, to a merchant using a communication identifier associated with at least one of a name, an address, an email address, a phone number, or a payment application, an indication of a possibility of the security vulnerability.   
     
     
         29 . The payment system of  claim 21 , further comprising instructions for further comprising performing one or more actions to revert the first device to an original state by requesting that the user of the first device re-authorize the first device. 
     
     
         30 . A method implemented in part by a payment system, comprising:
 monitoring, by a fraud detection component of the payment system, one or more parameters corresponding to a first device;   monitoring, by the fraud detection component, the one or more parameters corresponding to a second device in proximity to the payment system;   determining, by the fraud detection component, whether behavior of the second device substantially corresponds with behavior of the first device; and   outputting, based at least in part on the behavior of the second device, and on a user interface communicatively coupled with a processor of the payment system, an indication to a user of the first device that the second device represents a security vulnerability.   
     
     
         31 . The method of  claim 30 , further comprising applying a predictive model to indicate a probability of the second device being the security vulnerability, and wherein the predictive model is based on one or more characteristics of the second device, selected from a group of characteristics including timing parameters, emitted power levels, radiated performance, wireless performance, quality of communication links, radio frequency response, transmission measurements, receiver measurements, and engineering tolerances, being comparable to similar characteristics of the first device. 
     
     
         32 . The method of  claim 31 , wherein the predictive model is based on one or more trigger actions comprising at least one of: (a) introducing the second device in proximity to the first device; (b) fraudulently accessing a payment account associated with the first device; (c) physically swapping a component of the first device with a component of the second device; (d) changing location of the first device; (e) performing a payment transaction using the second device in proximity to the first device; (f) performing a payment transaction using the second device in proximity to the first device at a time when another payment transaction is in progress at the first device; (g) performing a payment transaction for an amount that is more than a predefined amount; (h) introducing the second device in a geographical perimeter; (i) physically altering the first device; (j) obtaining a card reader signal; (k) obtaining a merchant or server initiated trigger; and (l) waiting for lapse of a period of time. 
     
     
         33 . The method of  claim 30 , further comprising:
 determining whether the second device emits a signal with a strength that corresponds to a strength of a signal emitted from the first device;   determining whether reaction of the second device to a sub-routine corresponds to a reaction of the first device to the sub-routine;   determining whether movement of the second device corresponds to a movement of the first device; and   determining whether orientation of the second device corresponds to an orientation of the first device.   
     
     
         34 . The method of  claim 30 , further comprising:
 identifying, by a server, one or more devices matching a profile of the first device;   customizing, by the server, instructions based on the identified one or more devices; and   transferring, by the server, the instructions to the identified one or more devices matching the profile of the first device to detect another security vulnerability similar to the security vulnerability in the identified one or more devices.   
     
     
         35 . The method of  claim 30 , further comprising:
 determining that the second device is an unauthorized device with respect to the first device, based at least in part on one or more of:   determining whether the second device emits a signal of a substantially same strength as a signal emitted from the first device;   determining whether the second device behaves in a manner substantially similar to the first device;   determining whether the second device reacts, to a sub-routine, in a manner substantially similar to the first device;   determining whether movement of the second device is substantially similar to that of the first device; or   determining whether an orientation of the second device is substantially similar to that of the first device.   
     
     
         36 . The method of  claim 30 , further comprising:
 in response to determining that the second device represents the security vulnerability, canceling or aborting pending payment transactions performed using the first device;   disabling a connection between the first device and a monitoring device; and   sending, to a merchant using a communication identifier associated with at least one of a name, an address, an email address, a phone number, or a payment application, an indication of a possibility of the security vulnerability.   
     
     
         37 . One or more non-transitory computer-readable media maintaining instructions stored in a memory that, when executed by one or more processors of a payment system, program the one or more processors of the payment system to perform acts comprising:
 monitoring one or more parameters corresponding to a first device;   monitoring the one or more parameters corresponding to a second device in proximity to the payment system;   determining whether behavior of the second device substantially corresponds with behavior of the first device; and   outputting, based at least in part on the behavior of the second device, on a user interface of the first device, an indication to a user of the first device that the second device represents a security vulnerability   
     
     
         38 . The one or more non-transitory computer-readable media of  claim 37 , wherein:
 the first device comprises a payment object reader, a point of sale (POS) terminal, or a payment application; and   the second device comprises an illicit skimmer having a wireless transceiver capable of communicating sensitive data from the payment object reader to an illicit computing device.   
     
     
         39 . The one or more non-transitory computer-readable media of  claim 37 , the acts further comprising:
 determining that the second device is an unauthorized device with respect to the first device is further based on one or more of:   determining whether the second device emits a signal of a substantially same strength as a signal emitted from the first device;   determining whether the second device behaves in a manner substantially similar to the first device;   determining whether the second device reacts, to a sub-routine, in a manner substantially similar to the first device;   determining whether movement of the second device is substantially similar to that of the first device; or   determining whether an orientation of the second device is substantially similar to that of the first device.   
     
     
         40 . The one or more non-transitory computer-readable media of  claim 37 , the acts further comprising:
 determining whether the second device emits a signal with a strength that corresponds to a strength of a signal emitted from the first device;   determining whether reaction of the second device to a sub-routine corresponds to a reaction of the first device to the sub-routine;   determining whether movement of the second device corresponds to a movement of the first device; and   determining whether orientation of the second device corresponds to an orientation of the first device.

Join the waitlist — get patent alerts

Track US2022138755A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.