Surya Prakash YadavSenior Software Developer
Back to All ProjectsFinTech & Enterprise MDM

EMI Device Locker Solution

Enterprise Android Device Policy Controller (DPC) & FinTech Lock System

An enterprise-grade Android Device Policy Controller (DPC) and kiosk lockdown ecosystem designed for consumer finance institutions to prevent loan defaults through remote device management, QR enrollment, and automated kiosk locking.

My RoleLead Systems & Mobile Engineer
Timeline & Scope6 Months • Scaled to 100k+ Devices

Key Verified Outcomes & Results

42%
Reduction in FinTech Loan Default Rates
100k+
Secured Enterprise Android Handsets
< 1.5s
Average Command Execution Latency
99.98%
DPC Heartbeat Uptime Reliability
The Business & Technical Challenge

FinTech lenders financing smartphones suffered significant non-performing asset (NPA) losses when borrowers defaulted on EMI payments. Traditional apps could be easily uninstalled, bypassed, or factory reset by delinquent borrowers.

The Engineered Solution

Engineered an Android Enterprise Device Policy Controller (DPC) app operating with full Device Owner privileges. Features Knox-level tamper protection, QR-code zero-touch factory enrollment, background heartbeat telemetry, and automated kiosk locking triggered by payment status APIs.

System Architecture

Android DPC Architecture + Native Platform Channel + Event-Driven Microservices

Production Verified

The native Kotlin layer acts as the Android DeviceAdminReceiver and DevicePolicyManager controller, communicating over high-speed binary platform channels with a custom Flutter lockdown UI. The backend orchestrates commands via Redis Pub/Sub and WebSocket sockets with fallback to high-priority FCM data pushes.

Android DPC
1. Device Provisioning

Device scanned via enterprise QR code at retailer during unboxing; becomes Device Owner.

Telemetry Engine
2. Persistent Telemetry Stream

Heartbeat worker pings backend with battery, SIM IMSI, and security posture.

FinTech Gateway
3. FinTech Payment Webhook

Banking API fires overdue EMI trigger to Node.js backend when payment grace expires.

Kiosk Enforcement
4. Instant Lockdown Execution

Device locks down into single-task mode with payment QR and support dialer.

Core Engineering Features & Capabilities

Enterprise Zero-Touch & 6-Tap QR Code Provisioning during initial Android setup
Full Device Owner Privileges preventing uninstallation, USB debugging, or factory reset
Kiosk Lock Screen overlay disabling notifications, app launcher, and camera upon EMI default
Emergency Dialer & Payment Gateway Whitelisting enabling borrower repayments while locked
Real-time WebSocket & Silent FCM Push triggers for instant remote lock/unlock commands
SIM Card Change Detection & Anti-Tamper geo-tracking alarms
Backend Fleet Telemetry Dashboard managing active devices, battery, and signal health
Offline Fail-safe Timers that autonomously lock devices if borrower disconnects internet

Complex Engineering Challenges & Technical Solutions

Challenge #1Bypassing Android OS Power-Saving & Doze Mode

Root Problem

Aggressive OEM battery savers (Xiaomi, Vivo, Samsung) killed background services, delaying lock commands.

Senior Implementation

Utilized DevicePolicyManager system-level battery optimization exemptions and structured a hybrid waking mechanism using WakeLocks, JobScheduler, and dual-channel persistent notification foreground services.

Challenge #2Offline Borrower Evasion (Airplane Mode)

Root Problem

Borrowers intentionally turned off Wi-Fi/data permanently to prevent lock signals from reaching the phone.

Senior Implementation

Implemented an onboard Hardware Cryptographic Countdown Timer. If the device fails to authenticate with the licensing server within a 72-hour rolling window, local DPC rules trigger lockdown automatically until network reconnect.

Challenge #3Factory Reset & Recovery Mode Tampering

Root Problem

Users attempted hard key recovery resets to bypass software control.

Senior Implementation

Enforced `DISALLOW_FACTORY_RESET`, `DISALLOW_SAFE_BOOT_PROMPT`, and configured FRP (Factory Reset Protection) credentials tied exclusively to enterprise Google accounts.

Complete Technology & Tooling Stack

Kotlin (Native DPC)mobile
Flutter (Kiosk UI)mobile
Android Management APIintegration
Node.js & Expressbackend
Redis Pub/Subbackend
MySQL & MongoDBdatabase
WebSockets & FCMintegration
Docker & AWS ECSdevops

Key Architectural Takeaways

  • Android Enterprise system APIs offer unmatched device control when implemented with strict native Kotlin adherence.
  • FinTech hardware security requires robust offline fallback mechanisms rather than relying solely on server pushes.