42 - Services scientifiques, technologiques et industriels, recherche et conception
45 - Services juridiques; services de sécurité; services personnels pour individus
Produits et services
Providing temporary use of online non-downloadable software for use in credit card and identity fraud detection and prevention, and post-fraud detection, investigation, resolution, and support, namely, for use in automating credit card transaction screening, credit card transaction filtering and prioritization, credit card transaction review, credit card transaction resolution, credit card chargeback processing, and credit card fraud analyst monitoring; application service provider, namely, providing, hosting, managing, developing, and maintaining applications, software, websites, and databases in the fields of credit card and identity fraud detection and prevention; Electronic monitoring of credit card activity to detect fraud via the internet; Electronic monitoring of credit card use for online purchasing to detect fraud via the internet; Electronic monitoring of personally identifying information to detect identity theft via the internet; Electronic monitoring of banking activity to detect fraud via the internet; providing advice and consultation related to the electronic monitoring of credit card activity to detect fraud via the internet; Providing user authentication services using biometric hardware, trusted path and device recognition software technology, tranformer neural networks and artificial intelligence for e-commerce transactions Personal background verification services
42 - Services scientifiques, technologiques et industriels, recherche et conception
45 - Services juridiques; services de sécurité; services personnels pour individus
Produits et services
Providing temporary use of online non-downloadable software for use in credit card and identity fraud detection and prevention, and post-fraud detection, investigation, resolution, and support, namely, for use in automating credit card transaction screening, credit card transaction filtering and prioritization, credit card transaction review, credit card transaction resolution, credit card chargeback processing, and credit card fraud analyst monitoring; application service provider, namely, providing, hosting, managing, developing, and maintaining applications, software, websites, and databases in the fields of credit card and identity fraud detection and prevention; Electronic monitoring of credit card activity to detect fraud via the internet; Electronic monitoring of credit card use for online purchasing to detect fraud via the internet; Electronic monitoring of personally identifying information to detect identity theft via the internet; Electronic monitoring of banking activity to detect fraud via the internet; providing advice and consultation related to the electronic monitoring of credit card activity to detect fraud via the internet; Providing user authentication services using biometric hardware, trusted path and device recognition software technology, tranformer neural networks and artificial intelligence for e-commerce transactions Personal background verification services
A system for detecting whether a device seeking communication with a server is a returning device that previously communicated with the server includes a database that stores groups of device attributes based on observable device characteristics and unique identifiers. The database is generally not accessible to the devices. Each attribute group and the associated device identifier (DID) can uniquely identify a particular device, and the associated DID is generally not derivable from the attributes. The database may satisfy a uniqueness property so that each attribute value in the database may also uniquely identify a device.
A system for establishing a trusted path for secure communication between client devices and server devices, such as between an account holder and a financial institution, can provide the core security attributes of confidentiality (of the parties), integrity (of the information), anti-replay (protection against replay fraud) and/or anti-tampering (protection against unauthorized changes to information being exchanged and/or modules that generate and communicate such information). A messaging layer implementation in favor of a transport layer implementation can provide a trusted path. This infrastructure features secure cryptographic key storage, and implementation of a trusted path built using the cryptographic infrastructure. The trusted path protects against unauthorized information disclosure, modification, or replays. These services can effectively protect against Man-in-the-Middle, Man-in-the-Application, and other attacks.
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
A system for detecting whether a device seeking communication with a server is a returning device that previously communicated with the server includes a database that stores groups of device attributes based on observable device characteristics and unique identifiers. The database is generally not accessible to the devices. Each attribute group and the associated device identifier (DID) can uniquely identify a particular device, and the associated DID is generally not derivable from the attributes. The database may satisfy a uniqueness property so that each attribute value in the database may also uniquely identify a device.
A system for establishing a trusted path for secure communication between client devices and server devices, such as between an account holder and a financial institution, can provide the core security attributes of confidentiality (of the parties), integrity (of the information), anti-replay (protection against replay fraud) and/or anti-tampering (protection against unauthorized changes to information being exchanged and/or modules that generate and communicate such information). A messaging layer implementation in favor of a transport layer implementation can provide a trusted path. This infrastructure features secure cryptographic key storage, and implementation of a trusted path built using the cryptographic infrastructure. The trusted path protects against unauthorized information disclosure, modification, or replays. These services can effectively protect against Man-in-the-Middle, Man-in-the-Application, and other attacks.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
G06F 21/64 - Protection de l’intégrité des données, p. ex. par sommes de contrôle, certificats ou signatures
G06Q 20/38 - Protocoles de paiementArchitectures, schémas ou protocoles de paiement leurs détails
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
A system for establishing a trusted path for secure communication between client devices and server devices, such as between an account holder and a financial institution, can provide the core security attributes of confidentiality (of the parties), integrity (of the information), anti-replay (protection against replay fraud) and/or anti-tampering (protection against unauthorized changes to information being exchanged and/or modules that generate and communicate such information). A messaging layer implementation in favor of a transport layer implementation can provide a trusted path. This infrastructure features secure cryptographic key storage, and implementation of a trusted path built using the cryptographic infrastructure. The trusted path protects against unauthorized information disclosure, modification, or replays. These services can effectively protect against Man-in-the-Middle, Man-in-the-Application, and other attacks.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
G06Q 20/38 - Protocoles de paiementArchitectures, schémas ou protocoles de paiement leurs détails
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
H04W 12/03 - Protection de la confidentialité, p. ex. par chiffrement
H04W 12/128 - Dispositions anti-programmes malveillants, p. ex. protection contre la fraude par SMS ou les programmes malveillants mobiles
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
A system for detecting whether a device seeking communication with a server is a returning device that previously communicated with the server includes a database that stores groups of device attributes based on observable device characteristics and unique identifiers. The database is generally not accessible to the devices. Each attribute group and the associated device identifier (DID) can uniquely identify a particular device, and the associated DID is generally not derivable from the attributes. The database may satisfy a uniqueness property so that each attribute value in the database may also uniquely identify a device.
A system of classifying devices and/or app instances a new or returning divides attributes generated from observations received from an uncharacterized device/software app into base-fingerprint attributes and predictor attributes, where the two kinds of attributes have different longevities. Predictor attribute tuples from attribute tuples having the same base fingerprint as the base fingerprint corresponding to the uncharacterized device/app, and the predictor attribute tuple corresponding to the uncharacterized device/app are analyzed using a machine learned predictor function to obtain a final fingerprint. Machine learning techniques such as logistic regression, support vector machine, and artificial neural network can provide a predictor function that can decrease the conflict rate of the final fingerprint and, hence, the utility thereof, without significantly affecting the accuracy of classification.
A system for establishing a trusted path for secure communication between client devices and server devices, such as between an account holder and a financial institution, can provide the core security attributes of confidentiality (of the parties), integrity (of the information), anti-replay (protection against replay fraud) and/or anti-tampering (protection against unauthorized changes to information being exchanged and/or modules that generate and communicate such information). A messaging layer implementation in favor of a transport layer implementation can provide a trusted path. This infrastructure features secure cryptographic key storage, and implementation of a trusted path built using the cryptographic infrastructure. The trusted path protects against unauthorized information disclosure, modification, or replays. These services can effectively protect against Man-in-the-Middle, Man-in-the-Application, and other attacks.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
G06Q 20/38 - Protocoles de paiementArchitectures, schémas ou protocoles de paiement leurs détails
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
H04W 12/03 - Protection de la confidentialité, p. ex. par chiffrement
H04W 12/128 - Dispositions anti-programmes malveillants, p. ex. protection contre la fraude par SMS ou les programmes malveillants mobiles
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
A system for detecting whether a device seeking communication with a server is a returning device that previously communicated with the server includes a database that stores groups of device attributes based on observable device characteristics and unique identifiers. The database is generally not accessible to the devices. Each attribute group and the associated device identifier (DID) can uniquely identify a particular device, and the associated DID is generally not derivable from the attributes. The database may satisfy a uniqueness property so that each attribute value in the database may also uniquely identify a device.
A system for establishing a trusted path for secure communication between client devices and server devices, such as between an account holder and a financial institution, can provide the core security attributes of confidentiality (of the parties), integrity (of the information), anti-replay (protection against replay fraud) and/or anti-tampering (protection against unauthorized changes to information being exchanged and/or modules that generate and communicate such information). A messaging layer implementation in favor of a transport layer implementation can provide a trusted path. This infrastructure features secure cryptographic key storage, and implementation of a trusted path built using the cryptographic infrastructure. The trusted path protects against unauthorized information disclosure, modification, or replays. These services can effectively protect against Man-in-the-Middle, Man-in-the-Application, and other attacks.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
G06Q 20/38 - Protocoles de paiementArchitectures, schémas ou protocoles de paiement leurs détails
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
H04W 12/00 - Dispositions de sécuritéAuthentificationProtection de la confidentialité ou de l'anonymat
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
H04W 12/02 - Protection de la confidentialité ou de l'anonymat, p. ex. protection des informations personnellement identifiables [PII]
13.
Systems and methods for recognizing a device and/or an instance of an app invoked on a device
A system of classifying devices and/or app instances a new or returning divides attributes generated from observations received from an uncharacterized device/software app into base-fingerprint attributes and predictor attributes, where the two kinds of attributes have different longevities. Predictor attribute tuples from attribute tuples having the same base fingerprint as the base fingerprint corresponding to the uncharacterized device/app, and the predictor attribute tuple corresponding to the uncharacterized device/app are analyzed using a machine learned predictor function to obtain a final fingerprint. Machine learning techniques such as logistic regression, support vector machine, and artificial neural network can provide a predictor function that can decrease the conflict rate of the final fingerprint and, hence, the utility thereof, without significantly affecting the accuracy of classification.
A system of classifying devices and/or app instances a new or returning divides attributes generated from observations received from an uncharacterized device/software app into base-fingerprint attributes and predictor attributes, where the two kinds of attributes have different longevities. Predictor attribute tuples from attribute tuples having the same base fingerprint as the base fingerprint corresponding to the uncharacterized device/app, and the predictor attribute tuple corresponding to the uncharacterized device/app are analyzed using a machine learned predictor function to obtain a final fingerprint. Machine learning techniques such as logistic regression, support vector machine, and artificial neural network can provide a predictor function that can decrease the conflict rate of the final fingerprint and, hence, the utility thereof, without significantly affecting the accuracy of classification.
A system for detecting whether a device seeking communication with a server is a returning device that previously communicated with the server includes a database that stores groups of device attributes based on observable device characteristics and unique identifiers. The database is generally not accessible to the devices. Each attribute group and the associated device identifier (DID) can uniquely identify a particular device, and the associated DID is generally not derivable from the attributes. The database may satisfy a uniqueness property so that each attribute value in the database may also uniquely identify a device.
A system facilitates secure communication between an authorized user device and two or more servers via two or more channels that are associated with the respective servers. For each communication channel, the system receives a device identifier for the authorized user device and links the device identifiers together via another identifier, thereby allowing the system to recognize that the different device identifiers identify the same authorized user device. The system can identify an unauthorized device masquerading as the authorized user device by determining that a communication from the unauthorized device does not include another identifier linking the two or more device identifiers and/or by determining that a device identifier computed during the registration process is different from a linked identifier.
A system for establishing a trusted path for secure communication between client devices and server devices, such as between an account holder and a financial institution, can provide the core security attributes of confidentiality (of the parties), integrity (of the information), anti-replay (protection against replay fraud) and/or anti-tampering (protection against unauthorized changes to information being exchanged and/or modules that generate and communicate such information). A messaging layer implementation in favor of a transport layer implementation can provide a trusted path. This infrastructure features secure cryptographic key storage, and implementation of a trusted path built using the cryptographic infrastructure. The trusted path protects against unauthorized information disclosure, modification, or replays. These services can effectively protect against Man-in-the-Middle, Man-in-the-Application, and other attacks.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06Q 20/38 - Protocoles de paiementArchitectures, schémas ou protocoles de paiement leurs détails
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
42 - Services scientifiques, technologiques et industriels, recherche et conception
45 - Services juridiques; services de sécurité; services personnels pour individus
Produits et services
Providing temporary use of online non-downloadable software for use in credit card and identity fraud detection and prevention, and post-fraud detection, investigation, resolution, and support, namely, for use in automating credit card transaction screening, credit card transaction filtering and prioritization, credit card transaction review, credit card transaction resolution, credit card chargeback processing, and credit card fraud analyst monitoring; application service provider, namely, providing, hosting, managing, developing, and maintaining applications, software, websites, and databases in the fields of credit card and identity fraud detection and prevention Credit card and identity fraud detection services, namely, fraud detection services in the field of credit cards for on-line purchasing, telephone orders, and card-not present (CNP) transactions; credit card and identify fraud prevention services, namely, providing authentication of personal identification information; post-fraud detection services in the field of credit cards for on-line purchasing, telephone orders, and card-not present (CNP) transactions; providing advice and consultation in the field of credit card and identity fraud detection; identification verification services, namely, providing authentication of personal identification information
42 - Services scientifiques, technologiques et industriels, recherche et conception
45 - Services juridiques; services de sécurité; services personnels pour individus
Produits et services
Providing temporary use of online non-downloadable software for use in credit card and identity fraud detection and prevention, and post-fraud detection, investigation, resolution, and support, namely, for use in automating credit card transaction screening, credit card transaction filtering and prioritization, credit card transaction review, credit card transaction resolution, credit card chargeback processing, and credit card fraud analyst monitoring; application service provider, namely, providing, hosting, managing, developing, and maintaining applications, software, websites, and databases in the fields of credit card and identity fraud detection and prevention Credit card and identity fraud detection services, namely, fraud detection services in the field of credit cards for on-line purchasing, telephone orders, and card-not present (CNP) transactions; credit card and identify fraud prevention services, namely, providing authentication of personal identification information; post-fraud detection services in the field of credit cards for on-line purchasing, telephone orders, and card-not present (CNP) transactions; providing advice and consultation in the field of credit card and identity fraud detection; identification verification services, namely, providing authentication of personal identification information