US2023274279A1PendingUtilityA1

System and method for identity chaining

Assignee: VISA INT SERVICE ASSPriority: Oct 28, 2011Filed: May 1, 2023Published: Aug 31, 2023
Est. expiryOct 28, 2031(~5.2 yrs left)· nominal 20-yr term from priority
Inventors:B. Scott Boding
G06Q 20/4014G06Q 20/4016
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An identity chaining fraud detection method that allows each current transaction to be linked to other transactions through commonly shared identities. Over a period of time the links create a chain of associated transactions which can be analyzed to determine if identity variances occur, which indicates that fraud is detected. Additionally, if a specific identity is detected as being fraudulent, that identity can be tagged as fraudulent and can be referenced by a plurality of other merchant transaction chains to determine fraud.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 processing, by a chaining engine executing on a central server computer, transaction data from a plurality of merchant computers to identify a plurality of transactions;   generating, by the chaining engine, a dynamic chain of linked transactions based on shared identities in transaction data of the plurality of transactions, wherein the dynamic chain of linked transactions is configured to be updated by adding one or more additional transactions in real-time;   receiving, at the central server computer from a first merchant computer, first transaction data of a first transaction, wherein the first transaction data includes a first plurality of identities;   updating in real-time, by the chaining engine, the dynamic chain of linked transactions by:
 linking, in real-time, the first transaction to at least one of the plurality of transactions previously linked to each other, 
 wherein in the dynamic chain of linked transactions the first transaction is linked to a second transaction through a first identity that is included in the first plurality of identities associated with the first transaction and a second plurality of identities associated with the second transaction; 
   comparing, in real-time and by the chaining engine, each identity stored in the dynamic chain of linked transactions to a negative list database of identities associated with one or more fraudulent activities to determine whether the first transaction is fraudulent;   matching, by the chaining engine based on the dynamic chain of linked transactions, a second identity from the second plurality of identities associated with the second transaction to an identity from the negative list database of identities, wherein the second identity is not included in the first plurality of identities associated with the first transaction, the second transaction is linked to the first transaction in the dynamic chain of linked transactions;   based on the matching:
 identifying, by the central server computer, the first transaction as a fraudulent transaction; 
 generating, by the central server computer, a first message indicating a first fraud alert for the first transaction; 
 sending, by the central server computer, the first message to the first merchant computer indicating the first fraud alert for the first transaction; and 
   updating, by the central server computer, the negative list database of identities based on the dynamic chain of linked transactions to include a third identity from the first plurality of identities, the third identity not previously included in the negative list database of identities.   
     
     
         2 . The method of  claim 1 , further comprising:
 applying, by the central server computer, a fraud screening procedure to the first transaction, the fraud screening procedure determined based on a number of links between the first transaction as a suspect transaction and the second transaction as a known fraudulent transaction in the dynamic chain of linked transactions.   
     
     
         3 . The method of  claim 1 , wherein the first plurality of identities includes information specific to the first transaction including at least one of a username, a billing address, a shipping address, a payment card account number, a phone number, a device identifier, and an email address. 
     
     
         4 . The method of  claim 1 , further comprising:
 receiving a third transaction, subsequent to the first transaction, from the first merchant computer; and   dynamically linking the third transaction to the dynamic chain of linked transactions.   
     
     
         5 . The method of  claim 1 , further comprising:
 sending a response to the first merchant computer, the response indicating whether the first transaction is fraudulent, wherein the response includes a fraud score.   
     
     
         6 . The method of  claim 5 , wherein the first transaction is linked to a fraudulent transaction conducted by a different merchant that shares at least one identity with the first transaction, and the response further indicates that the first transaction is linked to the one or more fraudulent activities. 
     
     
         7 . The method of  claim 1 , further comprising:
 generating a visualization of the plurality of transactions, wherein the visualization shows links between the plurality of transactions based on the dynamic chain of linked transactions; and   displaying the visualization such that fraudulent transactions in the plurality of transactions can be identified on the visualization.   
     
     
         8 . The method of  claim 7 , further comprising:
 dynamically updating the visualization of the plurality of transactions based on updating the negative list database.   
     
     
         9 . The method of  claim 7 , wherein the visualization includes one or more controls for identifying areas of the visualization linked to known fraudulent transactions. 
     
     
         10 . The method of  claim 7 , wherein the visualization includes a heat map that visually identifies different clusters of transactions in a particular identity chain depending on fraud scores of transactions. 
     
     
         11 . A system comprising:
 a central server computer that includes a computer readable medium and processor, in communication with a plurality of merchant computers,   a chaining engine, executing on the central server computer,   wherein the central server computer, in connection with the chaining engine, is configured to perform:
 processing transaction data from a plurality of merchant computers to identify a plurality of transactions; 
 generating a dynamic chain of linked transactions based on shared identities in transaction data of the plurality of transactions, wherein the dynamic chain of linked transactions is configured to be updated by adding one or more additional transactions in real-time; 
 receiving, from a first merchant computer, first transaction data of a first transaction, wherein the first transaction data includes a first plurality of identities; 
 updating in real-time the dynamic chain of linked transactions by:
 linking, in real-time, the first transaction to at least one of the plurality of transactions previously linked to each other, 
 wherein in the dynamic chain of linked transactions the first transaction is linked to a second transaction through a first identity that is included in the first plurality of identities associated with the first transaction and a second plurality of identities associated with the second transaction; 
 
 comparing, in real-time, each identity stored in the dynamic chain of linked transactions to a negative list database of identities associated with one or more fraudulent activities to determine whether the first transaction is fraudulent; 
 matching, based on the dynamic chain of linked transactions, a second identity from the second plurality of identities associated with the second transaction to an identity from the negative list database of identities, wherein the second identity is not included in the first plurality of identities associated with the first transaction, the second transaction is linked to the first transaction in the dynamic chain of linked transactions; 
 based on the matching:
 identifying the first transaction as a fraudulent transaction; 
 generating a first message indicating a first fraud alert for the first transaction; 
 sending the first message to the first merchant computer indicating the first fraud alert for the first transaction; and 
 
 updating the negative list database of identities based on the dynamic chain of linked transactions to include a third identity from the first plurality of identities, the third identity not previously included in the negative list database of identities. 
   
     
     
         12 . The system of  claim 11 , wherein the central server computer, in connection with the changing engine, is further configured to perform:
 applying a fraud screening procedure to the first transaction, the fraud screening procedure determined based on a number of links between the first transaction as a suspect transaction and the second transaction as a known fraudulent transaction in the dynamic chain of linked transactions.   
     
     
         13 . The system of  claim 11 , wherein the first plurality of identities includes information specific to the first transaction including at least one of a username, a billing address, a shipping address, a payment card account number, a phone number, a device identifier, and an email address. 
     
     
         14 . The system of  claim 11 , wherein the central server computer, in connection with the changing engine, is further configured to perform:
 receiving a third transaction, subsequent to the first transaction, from the first merchant computer; and   dynamically linking the third transaction to the dynamic chain of linked transactions.   
     
     
         15 . The system of  claim 11 , wherein the central server computer, in connection with the changing engine, is further configured to perform:
 sending a response to the first merchant computer, the response indicating whether the first transaction is fraudulent, wherein the response includes a fraud score.   
     
     
         16 . The system of  claim 15 , wherein the first transaction is linked to a fraudulent transaction conducted by a different merchant that shares at least one identity with the first transaction, and the response further indicates that the first transaction is linked to the one or more fraudulent activities. 
     
     
         17 . The system of  claim 11 , wherein the central server computer, in connection with the changing engine, is further configured to perform:
 generating a visualization of the plurality of transactions, wherein the visualization shows links between the plurality of transactions based on the dynamic chain of linked transactions; and   displaying the visualization such that fraudulent transactions in the plurality of transactions can be identified on the visualization.   
     
     
         18 . The system of  claim 17 , wherein the central server computer, in connection with the changing engine, is further configured to perform:
 dynamically updating the visualization of the plurality of transactions based on updating the negative list database.   
     
     
         19 . The system of  claim 17 , wherein the visualization includes one or more controls for identifying areas of the visualization linked to known fraudulent transactions. 
     
     
         20 . The system of  claim 17 , wherein the visualization includes a heat map that visually identifies different clusters of transactions in a particular identity chain depending on fraud scores of transactions.

Join the waitlist — get patent alerts

Track US2023274279A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.