System and method for determining trusted devices

By combining machine learning models and static rules, personalized trust scores are generated, and the problem of high authentication challenge rate in the existing technology is solved, achieving lower authentication challenge rate and higher fraud prevention efficiency.

CN120344981APending Publication Date: 2025-07-18CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380078712.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-09-15
Filing Date
2023-09-15
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

When conducting online transactions, the prior art usually uses consistent static rules to authenticate user equipment, resulting in high authentication challenge rate, poor user experience, and difficulty in effectively reducing fraud risks.

Method used

The machine learning model (MLM) is used to combine static rules to generate personalized trust scores, dynamically adjust the authentication process, reduce the authentication challenge rate and improve the efficiency of fraud detection.

Benefits of technology

Trust scores generated through MLM can effectively reduce the authentication challenge rate, improve user experience, while maintaining a low fraud recall rate, and improving the system's fraud prevention capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120344981A_ABST
    Figure CN120344981A_ABST
Patent Text Reader

Abstract

The disclosed embodiments may include a system for determining a trusted device. The system may receive data corresponding to a plurality of users. The system may receive, via a plurality of user devices associated with a plurality of users, respective requests to conduct a plurality of transactions. The system may generate trust scores associated with the plurality of users and the plurality of user devices via the MLM and based on the data, wherein each trust score indicates a probability that a user device of the plurality of user devices is associated with a user of the plurality of users. The system may determine whether each trust score of the plurality of trust scores exceeds a predetermined threshold. In response to determining that a trust score of the plurality of trust scores exceeds a predetermined threshold, the system may perform an anti-fraud action with respect to the corresponding user device and user.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application is a Patent Cooperation Treaty (PCT) application of U.S. Non - Provisional Patent Application No. 17 / 945,961, filed on September 15, 2022, and claims priority thereto under PCT Article 8. The entire content of the U.S. non - provisional patent application is incorporated herein by reference as if fully set forth below. Technical Field

[0003] The disclosed technology relates to systems and methods for determining trusted devices. Specifically, the disclosed technology relates to determining a trust score associated with a user - device pair. Background Art

[0004] With the increasing prevalence of online transactions, traditional systems attempt to authenticate individuals before allowing them to conduct higher - risk transactions (such as those involving higher amounts of currency or those that may pose greater risks to the liable party (such as an entity or organization)). When conducting these types of online transactions, individuals are typically requested to provide one or more forms of authentication (such as passwords, biometric information, answers to security questions, etc.) so that the liable party can be confident in the identity of the individual.

[0005] Accordingly, there is a need for improved systems and methods for determining trusted devices. Embodiments of the present disclosure can address this and other considerations. Summary of the Invention

[0006] The disclosed embodiments can include a system for determining a trusted device. The system may include one or more processors and a memory communicatively coupled to the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to share data. The system can receive data corresponding to multiple users. The system can receive corresponding requests to conduct multiple transactions via multiple user devices associated with the multiple users. The system can generate trust scores associated with the multiple users and the multiple user devices via a machine learning model (MLM) and based on the data, where each trust score indicates the probability that a user device among the multiple user devices is associated with a user among the multiple users. The system can determine whether each of the multiple trust scores exceeds a predetermined threshold. In response to determining that a trust score among the multiple trust scores exceeds the predetermined threshold, the system can perform one or more anti - fraud actions regarding the corresponding user device and user, where the ratio of performing one or more anti - fraud actions for the multiple users is 30% or less.

[0007] The disclosed embodiments may include a system for determining a trusted device. The system may include one or more processors, and a memory communicatively coupled to the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to share data. The system may receive data corresponding to a user. The system may receive an authentication request via a user device. The system may determine that the request does not meet one or more static rules. In response to determining that the request does not meet one or more static rules, the system may generate a trust score associated with the user and the user device via an MLM and based on the data, wherein the trust score indicates the probability that the user device is associated with the user. The system may determine whether the trust score exceeds a predetermined threshold. In response to determining that the trust score exceeds the predetermined threshold, the system may perform one or more anti-fraud actions.

[0008] The disclosed embodiments may include a method for determining a trusted device. The method may include receiving data corresponding to a user. The method may include receiving a request to conduct a transaction via a user device. The method may include generating a trust score associated with the user and the user device via an MLM and based on the data, wherein the trust score indicates the probability that the user device is associated with the user. The method may include determining whether the trust score exceeds a predetermined threshold. In response to determining that the trust score exceeds the predetermined threshold, the method may include performing one or more anti-fraud actions.

[0009] Further implementations, features, and aspects of the disclosed technology, and the advantages provided thereby, are described in more detail below and may be understood with reference to the following detailed description, the drawings, and the claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Reference will now be made to the drawings, which are not necessarily drawn to scale, and which illustrate various implementations, aspects, and principles of the disclosed technology. In the drawings:

[0011] Figure 1 is a flowchart showing an exemplary method for determining a trusted device according to certain embodiments of the disclosed technology.

[0012] Figure 2 is a flowchart showing an exemplary method for determining a trusted device according to certain embodiments of the disclosed technology.

[0013] Figure 3 is a block diagram of an example trust score generation system for determining a trusted device according to an example implementation of the disclosed technology.

[0014] Figure 4 is a block diagram of an example system that can be used to determine a trusted device according to an example implementation of the disclosed technology. Detailed implementation manners

[0015] Systems and methods for determining trusted devices can rely on static rules for user-device pair authentication. For example, when a device fails to pass the static rules, the system may require additional steps to authenticate the user on the device. These static rules are typically applied across all user-device pairs (e.g., whether the user has passed the authentication challenge on the device in the past 30 days), resulting in a high ratio of additional authentication steps required on the user device to authenticate a given session, which can impose a heavy burden on the user. Thus, responsible application providers may find that their interaction or application usage rate decreases based on users abandoning certain application interactions when they feel the authentication challenge burden is too heavy.

[0016] Accordingly, examples of the present disclosure can provide receiving an authentication and / or authorization request from a user via a user device, generating a trust score associated with the user and the user device (user-device pair) based on predicted fraud, determining whether the trust score exceeds a predetermined threshold, and making an anti-fraud decision based on this determination.

[0017] The disclosed embodiments can employ a machine learning model (MLM) as well as other computerized techniques to determine a trust score associated with each user-device pair authentication attempt (e.g., when attempting a transaction). A machine learning model is a unique computer technology that involves training the model to perform tasks and make decisions. These techniques may help improve database and network operations. For example, in some cases, the systems and methods described herein can utilize an MLM that is necessarily rooted in computers and technology to determine a fraud-prediction-based trust score associated with a user-device pair, and then determine whether it is necessary to take an anti-fraud action regarding a particular user-device pair. In some examples, this may involve using user-specific, device-specific, and / or user-device-specific input data and an applied MLM to determine the user-device pair trust score. Using an MLM and a computer system configured in this manner can allow the system to maintain an acceptable fraud rate while reducing the overall user challenge rate.

[0018] This can provide advantages and improvements over the prior art, which requires the same user-device authentication across all user-device pairs based on a set of static rules. The present disclosure addresses this problem by adopting a customized user-device authentication method such that any required authentication can be intelligently based on a specific user-device pair. Additionally, examples of the present disclosure can also increase the speed at which a computer can determine trusted user-device pairs. Overall, the disclosed systems and methods have significant practical applications in the fields of authentication and fraud prevention because of the obvious improvement in the customization of authentication challenges, which is important for solving the existing problems with this technology.

[0019] The disclosed embodiments can advantageously work in conjunction with static rules. For example, when certain static rule results (and / or combinations and permutations of static rule results) occur, the disclosed MLM processing can be employed. The disclosed embodiments can combine static rules with MLM processing to effectively utilize MLM resources by leveraging the MLM technology in situations where the MLM technology provides greater value. For example, one advantageous aspect of certain embodiments can include specific situations where MLM processing is employed.

[0020] Some implementations of the disclosed technology will be described more fully with reference to the accompanying drawings. However, the disclosed technology can be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. The components of the various elements that make up the disclosed technology described below are intended to be illustrative and not restrictive. Many suitable components that perform the same or similar functions as the components described herein are intended to be included within the scope of the disclosed electronic devices and methods.

[0021] Reference will now be made in detail to example embodiments of the disclosed technology shown in the drawings and disclosed herein. Wherever convenient, the same reference numbers will be used throughout the drawings to refer to the same or like parts.

[0022] Figure 1 is a flowchart showing an exemplary method 100 for determining a trusted device according to certain embodiments of the disclosed technology. The steps of method 100 can be performed by one or more components of system 400 (e.g., the trust score generation system 320 or the web server 410 of the fraud prevention system 408, or the user device 402), as described in more detail with reference to Figure 3 and Figure 4 Although certain blocks may be identified as optional, certain embodiments may omit blocks even if they are not necessarily identified as optional.

[0023] In block 102, the trust score generation system 320 can receive data corresponding to multiple users. For example, the multiple users can all be customers of the same organization (e.g., a financial institution), and thus the organization receives data associated with the users (e.g., account login credentials, associated user devices, personal information, financial information, etc.). In some embodiments, the system can be configured to continuously receive, update, and / or store data corresponding to multiple users to assist in accurate model prediction, as further discussed below.

[0024] In block 104, the trust score generation system 320 can receive corresponding requests for multiple transactions via multiple user devices associated with the multiple users. In some embodiments, each (or one or more) of the multiple users can request to conduct a transaction via the corresponding user device. For example, when each of the multiple users logs into the corresponding online account, each user can attempt to conduct a certain transaction, such as transferring funds, accessing certain transaction data or information, etc. In some embodiments, each (or one or more) of the multiple users can request to utilize an application or participate in some form of interaction within the application or system. For example, each of the multiple users can request to access an account (e.g., email), join a computer network, participate in a joint user session, etc. These transactions and / or interactions may be of a high-risk type, and thus the responsible party (e.g., the entity or organization that owns and / or operates the fraud prevention system 408) may experience a higher fraud rate, thereby requiring enhanced authentication from users requesting to conduct such transactions or participate in such interactions.

[0025] In optional block 106, the trust score generation system 320 can determine whether one or more static rules are true for each received request (e.g., to conduct a transaction and / or participate in an interaction) (block 104). The one or more static rules can include, for example, whether a particular user has failed an authentication request or process on a particular device in the past 30 days, whether the particular device is listed on a pre-determined list of unauthorized devices, whether the identified Internet Protocol (IP) address is unauthorized (e.g., based on source location, particular hosting provider, etc.), and so on. The advantage of initially determining whether one or more static rules are true for the requested transaction or interaction is that the system can be configured to determine at what particular stage of the overall authentication process MLM can be effectively employed to customize the authentication process for a particular user-device pair, as further discussed herein. The system can also be configured to prevent certain high-risk transactions or interactions from proceeding in the authentication process (e.g., those initiated by or conducted on a device identified by the system as having been used in the past for fraudulent transactions).

[0026] In optional block 108, in response to determining that one or more static rules are true for a particular user-device pair, the trust score generation system 320 may reject the corresponding request associated with the user-device pair.

[0027] In optional block 110, in response to determining that one or more static rules are not true for a particular user-device pair, the trust score generation system 320 may determine whether one or more additional static rules are true, e.g., whether a particular device is less than a particular age (e.g., seven days old). In some embodiments, in response to determining that one or more additional static rules are true, the trust score generation system 320 may perform one or more anti-fraud actions with respect to the corresponding user-device pair, as further discussed below with respect to block 118. One or more additional static rules may be configured to provide an additional potential anti-fraud layer before the system uses MLM to customize or enhance the authentication process, as further discussed herein.

[0028] In block 112, in response to determining that one or more additional static rules are not true for a particular user-device pair, the trust score generation system 320 may generate a fraud prediction-based trust score associated with multiple users and multiple user devices via MLM and based on data, where each trust score indicates the probability that a user device among the multiple user devices is associated with a user among the multiple users. For example, for each attempted transaction or interaction, the MLM may be trained to evaluate data associated with the particular user and user device (the particular user-device pair) attempting the transaction or interaction, and / or data associated with all other users and user devices among the multiple users and multiple user devices, to help predict whether the particular user-device pair is a trusted pair. For example, the system may be configured to compare data across multiple users and multiple user devices to make a prediction as to whether a particular user corresponds to (e.g., owns, typically operates, etc.) a particular user device. In some embodiments, the MLM may include a binary classifier to predict potential fraud (e.g., as an event) associated with a user-device pair and produce the probability that the user-device pair is fraudulent (e.g., the device does not belong to the user).

[0029] In some embodiments, the MLM may further generate trust scores based on one or more respective user-device interaction characteristics associated with multiple users and multiple user devices. Interaction characteristics may include, for example, login frequency, challenge ratio, abandonment ratio, success ratio, time since last activity, number of recent devices associated with the user, number of users associated with the user device, user device age, user device type, whether certain applications are installed on the device, type and / or method of authentication, etc. In some embodiments, the challenge ratio may include a respective rate for each of the multiple users for performing one or more anti-fraud actions, as discussed further below. In some embodiments, the abandonment ratio may include a respective rate associated with a respective request by each of the multiple users to abandon one or more transactions and / or participate in one or more interactions. For example, the abandonment ratio may indicate the ratio or frequency at which a user has initiated a transaction but abandoned the transaction before completion. In some embodiments, the success ratio may include a respective rate associated with a respective request action associated with each of the multiple users for successfully completing one or more anti-fraud actions, as discussed further below.

[0030] In block 114, the trust score generation system 320 may determine whether each of the multiple trust scores exceeds a predetermined threshold. In some embodiments, the predetermined threshold may be predefined by the system, for example, corresponding to the fraud tolerance or fraud ratio that the system is willing or able to accept. For example, the system may be configured to accept a fraud recall ratio of no more than 39% across all transactions and / or interactions conducted, and thus the predetermined threshold for each trust score may be set to achieve an overall fraud recall ratio of 39%. In such an example, if it is found that a trust score among the multiple trust scores exceeds the predetermined threshold, resulting in the overall fraud recall ratio increasing to more than 39%, the system may be configured to perform one or more anti-fraud actions, as discussed further below.

[0031] In block 116, in response to determining that a trust score among the multiple trust scores does not exceed the predetermined threshold, thereby providing an indication that a particular user-device pair may be trustworthy, the trust score generation system 320 may authorize the corresponding request (e.g., access account, conduct transaction, etc.) associated with the user-device pair without requesting additional authentication information from the user-device pair.

[0032] In block 118, in response to determining that a trust score among a plurality of trust scores exceeds a predetermined threshold, the trust score generation system 320 may perform one or more anti-fraud actions with respect to the corresponding user-device pair. In some embodiments, the one or more anti-fraud actions may include, for example, transmitting a notification to the corresponding user device and / or requesting the corresponding user to perform multi-factor authentication. It should be understood that the one or more anti-fraud actions may include various other actions requested by the user to increase the system's confidence that the user-device pair is trusted.

[0033] In some embodiments, the rate (e.g., challenge rate) at which one or more anti-fraud actions are performed for a plurality of users may be, for example, 30% or lower. In some embodiments, although the challenge rate may be 30% or lower, the overall fraud recall rate may be, for example, approximately 39%. In contrast, some conventional systems and methods configured to provide an overall fraud recall rate of approximately 39% provide a challenge rate of, for example, approximately 63%. Thus, the systems and methods disclosed herein may provide a reduction in the challenge rate of approximately 52% ((0.63 - 0.30) / 0.63). The benefit of this reduction in the challenge rate is that more users may be willing to complete transactions and / or interactions rather than abandon them before completion due to the burden of authentication requests.

[0034] Figure 2 is a flowchart showing an exemplary method 200 for determining a trusted device according to certain embodiments of the disclosed technology. The steps of method 200 may be performed by one or more components of system 400 (e.g., the trust score generation system 320 or the web server 410 of the anti-fraud system 408, or the user device 402), as described in reference Figure 3 and Figure 4 more specifically described.

[0035] Figure 2 The method 200 of Figure 1 may be the same as or similar to the method 100 of

[0036] Figure 3 except that method 200 may be performed with respect to a single user-device pair rather than a plurality of user-device pairs. The corresponding descriptions of blocks 202, 204, 206, 208, 210, 212, 214, 216, and 218 of method 200 may be the same as or similar to the corresponding descriptions of blocks 102, 104, 106, 108, 110, 112, 114, 116, and 118 of method 100, except that blocks 202, 204, 206, 208, 210, 212, 214, 216, and 218 may refer to a single user-device pair and, thus, for the sake of brevity, are not repeated herein.

[0036] Figure 3 is a block diagram of an exemplary trust score generation system 320 for sharing data according to an example implementation of the disclosed technology. According to some embodiments, asFigure 4 The user device 402 and the network server 410 depicted and described below may have similar structures and components, which are similar to those described with respect to Figure 3 the trust score generation system 320 shown in. As shown, the trust score generation system 320 may include a processor 310, an input / output (I / O) device 370, and a memory 330 containing an operating system (OS) 340 and programs 350. In some embodiments, the program 350 may include an MLM 352, which may be trained, for example, to determine a trust score associated with a user and a user device pair. In certain implementations, the MLM 352 may issue commands in response to processing events according to a model that may be updated continuously or intermittently. Additionally, the processor 310 may execute one or more programs (e.g., via a rule-based platform or the trained MLM 352), which, when executed, perform functions related to the disclosed embodiments.

[0037] In certain example implementations, the trust score generation system 320 may be a single server or may be configured as a distributed computer system including multiple servers or computers that interoperate to perform one or more processes and functions associated with the disclosed embodiments. In some embodiments, the trust score generation system 320 may be one or more servers from a serverless or scaling server system. In some embodiments, the trust score generation system 320 may further include a peripheral interface, a transceiver, a mobile network interface communicating with the processor 310, a bus configured to facilitate communication between the various components of the trust score generation system 320, and a power source configured to power one or more components of the trust score generation system 320.

[0038] For example, the peripheral interface may include hardware, firmware, and / or software that enables communication with various peripheral devices, such as media drives (e.g., disk, solid-state, or optical disc drives), other processing devices, or any other input source used in conjunction with the disclosed technology. In some embodiments, the peripheral interface may include a serial port, a parallel port, a general-purpose input and output (GPIO) port, a game port, a universal serial bus (USB), a micro-USB port, a high-definition multimedia interface (HDMI) port, a video port, an audio port, a BluetoothTM port, a near-field communication (NFC) port, another similar communication interface, or any combination thereof.

[0039] In some embodiments, the transceiver may be configured to communicate with compatible devices and ID tags when they are within a predetermined range. The transceiver may be compatible with one or more of the following: Radio Frequency Identification (RFID), NFC, BluetoothTM, Bluetooth Low EnergyTM (BLE), WiFi TM , ZigBeeTM, Ambient Backscatter Communication (ABC) protocol, or similar technologies.

[0040] The mobile network interface may provide access to a cellular network, the Internet, or another wide area network or local area network. In some embodiments, the mobile network interface may include hardware, firmware, and / or software that allows the (one or more) processors 310 to communicate with other devices via a wired or wireless network (whether a local area network or a wide area network, private or public network, as is known in the art). The power supply may be configured to provide appropriate alternating current (AC) or direct current (DC) to power the components.

[0041] The processor 310 may include one or more or a combination of a microprocessor, a microcontroller, a digital signal processor, a coprocessor, etc. capable of executing stored instructions and operating on stored data. In some implementations, the memory 330 may include one or more suitable types of memory (such as, for example, volatile or non-volatile memory, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, floppy disks, hard disks, removable cartridges, flash memory, Redundant Array of Independent Disks (RAID), etc.) for storing files including an operating system, application programs (including, for example, a web browser application, a widget or gadget engine, and / or other necessary application programs), executable instructions, and data. In one embodiment, the processing techniques described herein may be implemented as a combination of executable instructions and data stored within the memory 330.

[0042] The processor 310 can be one or more known processing devices, such as but not limited to microprocessors from the CoreTM series manufactured by Intel Corporation, the RyzenTM series manufactured by AMD Corporation, or system-on-chip processors using the ARMTM or other similar architectures. The processor 310 can constitute a single-core processor or a multi-core processor that performs parallel processing simultaneously, a central processing unit (CPU), an accelerated processing unit (APU), a graphics processing unit (GPU), a microcontroller, a digital signal processor (DSP), a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), or another type of processing component. For example, the processor 310 can be a single-core processor configured with virtual processing technology. In some embodiments, the processor 310 can use logical processors to execute and control multiple processes simultaneously. The processor 310 can implement virtual machine (VM) technology or other similar known technologies to provide the ability to execute, control, run, manipulate, store, etc., multiple software processes, applications, programs, etc. Those of ordinary skill in the art will understand that other types of processor arrangements that provide the capabilities disclosed herein can be implemented.

[0043] According to certain example embodiments of the disclosed technology, the trust score generation system 320 can include one or more storage devices configured to store information for the processor 310 (or other components) to perform certain functions related to the disclosed embodiments. In one example, the trust score generation system 320 can include a memory 330 that includes instructions enabling the processor 310 to execute one or more applications (such as server applications, network communication processes, and any other type of application or software known to be available on a computer system). Alternatively, the instructions, applications, etc. can be stored in an external memory or obtained from a memory via a network. The one or more storage devices can be volatile or non-volatile, magnetic, semiconductor, tape, optical, removable, non-removable, or other types of storage devices or tangible computer-readable media.

[0044] The trust score generation system 320 can include a memory 330 that includes instructions that, when executed by the processor 310, perform one or more processes consistent with the functions disclosed herein. The methods, systems, and articles of manufacture consistent with the disclosed embodiments are not limited to separate programs or computers configured to perform dedicated tasks. For example, the trust score generation system 320 can include a memory 330 that can include one or more programs 350 to perform one or more functions of the disclosed embodiments. For example, in some embodiments, the trust score generation system 320 can additionally manage conversations and / or other interactions with customers via the program 350.

[0045] Processor 310 may execute one or more programs 350 that are located remotely from trust score generation system 320. For example, trust score generation system 320 may access one or more remote programs that, when executed, perform functions related to the disclosed embodiments.

[0046] Memory 330 may include one or more memory devices that store data and instructions for performing one or more features of the disclosed embodiments. Memory 330 may also include any combination of one or more databases (e.g., a document management system, a Microsoft SQL database, a SharePointTM database, an OracleTM database, a SybaseTM database, or other relational or non-relational databases) controlled by a memory controller device (e.g., a server, etc.) or software. Memory 330 may include software components that, when executed by processor 310, perform one or more processes consistent with the disclosed embodiments. In some embodiments, memory 330 may include fraud detection system database 360 for storing relevant data to enable trust score generation system 320 to perform one or more processes and functions associated with the disclosed embodiments.

[0047] User tracking system database 360 may include stored data related to status data (e.g., average session duration data, location data, idle time between sessions, and / or average idle time between sessions) and historical status data. According to some embodiments, the functionality provided by user tracking system database 360 may also be provided by a database external to trust score generation system 320 (e.g., database 416 as Figure 4 shown).

[0048] Trust score generation system 320 may also be communicatively connected locally or via a network to one or more memory devices (e.g., databases). The remote memory devices may be configured to store information and may be accessed and / or managed by trust score generation system 320. For example, the remote memory devices may be a document management system, a Microsoft SQL database, a SharePointTM database, an Oracle database, a SybaseTM database, or other relational or non-relational databases. However, the systems and methods consistent with the disclosed embodiments are not limited to separate databases, or even to the use of databases.

[0049] The trust score generation system 320 may also include one or more I / O devices 370. The I / O devices 370 may include one or more interfaces for receiving signals or inputs from devices and providing signals or outputs to one or more devices, and these interfaces allow the trust score generation system 320 to receive and / or send data. For example, the trust score generation system 320 may include interface components that can provide interfaces to one or more input devices (such as one or more keyboards, mouse devices, touchscreens, trackpads, trackballs, rollers, digital cameras, microphones, sensors, etc.), enabling the trust score generation system 320 to receive data from a user (such as, for example, via the user device 402).

[0050] In an example of the disclosed technology, the trust score generation system 320 may include any number of hardware and / or software applications that are executed to facilitate any operation. One or more I / O interfaces can be used to receive or collect data and / or user instructions from a variety of input devices. The received data can be processed by one or more computer processors and / or stored in one or more memory devices as needed in various embodiments of the disclosed technology.

[0051] The trust score generation system 320 may contain programs for training, implementing, storing, receiving, retrieving, and / or transmitting one or more MLMs. Machine learning models may include neural network models, generative adversarial models (GANs), recurrent neural network (RNN) models, deep learning models (e.g., long short-term memory (LSTM) models), random forest models, convolutional neural network (CNN) models, support vector machine (SVM) models, logistic regression, XGBoost, and / or another machine learning model. The models may include ensemble models (e.g., models composed of multiple models). In some embodiments, the training of the model may terminate when a training criterion is met. The training criterion may include a plurality of epochs, training time, performance metrics (e.g., an estimate of accuracy when reproducing test data), etc. The trust score generation system 320 may be configured to adjust model parameters during training. Model parameters may include weights, coefficients, offsets, etc. The training may be supervised or unsupervised.

[0052] Consistent with the disclosed embodiments, the trust score generation system 320 can be configured to train a machine learning model by optimizing model parameters and / or hyperparameters (hyperparameter tuning) using optimization techniques. Hyperparameters may include training hyperparameters that may affect the way model training occurs, or may include architecture hyperparameters that may affect the structure of the model. Optimization techniques can include grid search, random search, Gaussian processes, Bayesian processes, covariance matrix adaptation evolution strategy (CMA-ES), derivative-based search, stochastic hill climbing, neighborhood search, adaptive random search, etc. The trust score generation system 320 can be configured to use known optimization techniques to optimize a statistical model.

[0053] Additionally, the trust score generation system 320 can include programs configured to retrieve, store, and / or analyze the properties of data models and data sets. For example, the trust score generation system 320 can include or be configured to implement one or more data profiling models. Consistent with the disclosed embodiments, a data profiling model can include machine learning models and statistical models to determine the data patterns and / or statistical profiles of a data set (e.g., to profile a data set). The data profiling model can include an RNN model, a CNN model, or other machine learning models.

[0054] The trust score generation system 320 can include algorithms for determining the data type, key-value pairs, row-column data structure, the statistical distribution of information such as keys or values, or other properties that can configure the data pattern to return the statistical profile of a data set (e.g., using a data-profiling model). The trust score generation system 320 can be configured to implement univariate and multivariate statistical methods. The trust score generation system 320 can include regression models, Bayesian models, statistical models, linear discriminant analysis models, or other classification models that are configured to determine one or more descriptive metrics of a data set. For example, the trust score generation system 320 can include algorithms for determining the mean, median, standard deviation, quantiles, quartiles, probability distribution function, range, moments, variance, covariance, covariance matrix, dimensions, and / or dimensional relationships (e.g., as generated by dimensional analysis, such as length, time, mass, etc.) or any other descriptive metric of a data set.

[0055] The trust score generation system 320 can be configured to return a statistical profile of a dataset (e.g., using a data profiling model or other model). The statistical profile can include multiple descriptive metrics. For example, the statistical profile can include the mean, median, standard deviation, range, moment, variance, covariance, covariance matrix, similarity measure, or any other statistical metric of the selected dataset. In some embodiments, the trust score generation system 320 can be configured to generate a similarity measure representing a measure of similarity between data in the dataset. The similarity measure can be based on correlation, covariance matrix, variance, frequency of overlapping values, or other measures of statistical similarity.

[0056] The trust score generation system 320 can be configured to generate a similarity measure based on data model outputs (including data model outputs representing data model properties). For example, the trust score generation system 320 can be configured to generate a similarity measure based on activation function values, embedding layer structure and / or output, convolution results, entropy, loss function, model training data, or other data model outputs). For example, a synthetic data model can generate a first data model output based on a first dataset and a data model output based on a second dataset, and the similarity measure can be based on a measure of similarity between the first data model output and the second data model output. In some embodiments, the similarity measure can be based on the correlation, covariance, mean, regression results, or other similarity between the first data model output and the second data model output. The data model output can include any data model output as described herein or any other data model output (e.g., activation function values, entropy, loss function, model training data, or other data model outputs). In some embodiments, the similarity measure can be based on data model outputs from a subset of model layers. For example, the similarity measure can be based on data model outputs from model layers after the model input layer or after the model embedding layer. As another example, the similarity measure can be based on data model outputs from the last layer or multiple layers of the model.

[0057] The trust score generation system 320 can be configured to classify a data set. Classifying a data set can include determining whether the data set is related to another data set. Classifying a data set can include clustering the data set and generating information indicating whether the data set belongs to a data set cluster. In some embodiments, classifying a data set can include generating data that describes the data set (e.g., a data set index), which includes metadata, an indicator of whether the data elements include actual data and / or synthetic data, a data pattern, a statistical profile, the relationship between the test data set and one or more reference data sets (e.g., node and edge data), and / or other descriptive information. Edge data can be based on a similarity metric. Edge data can indicate the similarity and / or hierarchical relationship (e.g., data lineage, parent-child relationship) between data sets. In some embodiments, classifying a data set can include generating graphical data, such as an anodediagram, dendrogram, or vector diagram of the data set. Classifying a data set may include estimating the likelihood that the data set is related to another data set, the likelihood being based on a similarity metric.

[0058] The trust score generation system 320 can include one or more data classification models to classify a data set based on a data pattern, a statistical profile, and / or an edge. The data classification model can include a convolutional neural network, a random forest model, a recurrent neural network model, a support vector machine model, or another machine learning model. The data classification model can be configured to classify data elements into actual data, synthetic data, related data, or any other data category. In some embodiments, consistent with the disclosed embodiments, the trust score generation system 320 is configured to generate and / or train a classification model to classify a data set.

[0059] The trust score generation system 320 can also include one or more prediction models. The prediction models can include statistical algorithms that are used to determine the probability of an outcome considering a set amount of input data. For example, the prediction model can include a regression model that estimates the relationship between input and output variables. The prediction model can also use one or more classifiers to rank the elements of a data set to determine the probability of a particular outcome. The prediction model can be a parametric, non-parametric, and / or semi-parametric model.

[0060] In some examples, the prediction model can cluster data points into groups of functions (such as "random forests"). A random forest may include a combination of decision tree predictors. (A decision tree may include a data structure that maps observations about something in the "branches" of the tree to conclusions about the target value of that thing in the "leaves" of the tree.) Each tree may depend on the values of independently sampled random vectors and have the same distribution for all trees in the forest. The prediction model can also include an artificial neural network. An artificial neural network can model the input / output relationships of variables and parameters by generating multiple interconnected nodes that include activation functions. The activation function of a node can define the resulting output of the node given an argument or a set of arguments. The artificial neural network can generate patterns for the network via an "input layer" that communicates with one or more "hidden layers", where the system determines a regression via weighted connections. The prediction model can additionally or alternatively include classification trees and regression trees, or other types of models known to those skilled in the art. To generate the prediction model, the asset detection system can apply machine learning methods to analyze information.

[0061] Although the trust score generation system 320 has been described as one form for implementing the techniques described herein, other functionally equivalent techniques may be employed. For example, some or all of the functions implemented via executable instructions may also be implemented using firmware and / or hardware devices (e.g., application-specific integrated circuits (ASICs), programmable logic arrays, state machines, etc.). Additionally, other implementations of the trust score generation system 320 may include more or fewer components than those shown.

[0062] Figure 4 is a block diagram of an example system that can be used to view and interact with the fraud prevention system 408 according to an example implementation of the disclosed technology. Figure 4 The components and arrangements shown are not intended to limit the disclosed embodiments, as the components used to implement the disclosed processes and features may vary. As shown, the fraud prevention system 408 can interact with the user device 402 via the network 406. In certain example implementations, the fraud prevention system 408 can include a local network 412, a trust score generation system 320, a network server 410, and a database 416.

[0063] In some embodiments, a corresponding user may operate a user device 402. The user device 402 may include one or more of the following: a mobile device, a smart phone, a general-purpose computer, a tablet computer, a laptop computer, a telephone, a public switched telephone network (PSTN) landline, a smart wearable device, a voice command device, other mobile computing devices, or any other device capable of communicating with a network 406 and ultimately with one or more components of the fraud prevention system 408. In some embodiments, the user device 402 may include or incorporate an electronic communication device for users with hearing or vision impairments.

[0064] A user may include an individual, such as, for example, a subscriber, a customer, a potential customer, or a patron of an entity associated with an organization, e.g., an individual who has, will, or may obtain a product, service, or consultation from, or conduct a transaction with, an entity associated with the fraud prevention system 408. According to some embodiments, the user device 402 may include environmental sensors (e.g., a microphone and / or a digital camera) for obtaining audio or visual data, a geographic location sensor for determining the location of the device, an input / output device (e.g., a transceiver) for sending and receiving data, a display for displaying digital images, one or more processors, and a memory communicatively coupled to the one or more processors.

[0065] The trust score generation system 320 may include programs (scripts, functions, algorithms) to configure data for visualization and provide visualization of data sets and data models on the user device 402. This may include programs for generating and displaying graphs. The trust score generation system 320 may include programs for generating histograms, scatter plots, time series, etc. on the user device 402. The trust score generation system 320 may also be configured to display attributes of the data model and data model training results on the user device 402, including, for example, architecture, loss function, cross entropy, activation function values, embedding layer structure and / or output, convolution results, node outputs, etc.

[0066] The network 406 may be of any suitable type (including separate connections via the Internet, such as cellular or WiFi networks). In some embodiments, the network 406 may use direct connections such as RFID, NFC, Bluetooth™, BLE, WiFi™, ZigBee™, ABC protocol, USB, WAN, or LAN to connect terminals, services, and mobile devices. Due to the information being transmitted may be personal or confidential, security concerns may dictate encrypting or otherwise protecting one or more of these types of connections. However, in some embodiments, the information being transmitted may be less personal and thus a network connection may be chosen for convenience rather than security.

[0067] Network 406 can include any type of computer networking arrangement for exchanging data. For example, network 406 can be the Internet, a private data network, a virtual private network (VPN) using a public network, and / or any other suitable connection that enables components in the system 400 environment to send and receive information between components of the system 400. Network 406 can also include a PSTN and / or a wireless network.

[0068] The anti-fraud system 408 can be associated with and optionally controlled by one or more entities, such as enterprises, companies, individuals, partnerships, or any other entity that provides one or more goods, services, and consultations to individuals (such as customers). In some embodiments, the anti-fraud system 408 can be controlled by a third party on behalf of another enterprise, company, individual, or partnership. The anti-fraud system 408 can include one or more servers and computer systems for performing one or more functions associated with the products and / or services provided by the organization.

[0069] The web server 410 can include a computer system configured to generate and provide one or more websites accessible to customers and any other individuals involved in the normal operation of accessing the anti-fraud system 408. The web server 410 can include a computer system configured to receive communications from the user device 402 via, for example, a mobile application, a chat program, an instant messaging program, a voice-to-text program, an SMS message, an email, or any other type or format of written or electronic communication. The web server 410 can have one or more processors 422 and one or more web server databases 424, which can be any suitable repository of website data. The information stored in the web server 410 can be accessed (e.g., retrieved, updated, and added) by one or more devices or systems of the system 400 via the local network 412 and / or the network 406. In some embodiments, the web server 410 can host a website or application accessible to the user device 402. For example, the web server 410 can host a financial service provider website that the user device can access by providing an attempt to log in authenticated by the trust score generation system 320. According to some embodiments, the web server 410 can include software tools similar to those described above for the user device 402, which can allow the web server 410 to obtain network identity data from the user device 402. The web server can also be hosted by an online provider of website hosting, networking, cloud, or backup services (such as Microsoft AzureTM or Amazon Web ServicesTM).

[0070] The local network 412 can include any type of computer networking arrangement for exchanging data in a local area (e.g., WiFi, Bluetooth™, Ethernet, and other suitable network connections), which enable the components of the fraud prevention system 408 to interact with each other and connect to the network 406 to interact with components in the system 400 environment. In some embodiments, the local network 412 can include an interface for communicating with or linking to the network 406. In other embodiments, certain components of the fraud prevention system 408 can communicate via the network 406 without a separate local network 406.

[0071] The fraud prevention system 408 can be hosted in a cloud computing environment (not shown). The cloud computing environment can provide software, data access, data storage, and computing. In addition, the cloud computing environment can include resources such as applications (apps), virtual machines (VMs), virtual storage (VS), or hypervisors (HYP). The user device 402 can be able to access the fraud prevention system 408 using the cloud computing environment. The user device 402 may be able to access the fraud prevention system 408 using dedicated software. The cloud computing environment can eliminate the need to install dedicated software on the user device 402.

[0072] According to certain example embodiments of the disclosed technology, the fraud prevention system 408 can include one or more computer systems configured to compile data from multiple sources (the trust score generation system 320, the network server 410, and / or the database 416). The trust score generation system 320 can correlate the compiled data, analyze the compiled data, arrange the compiled data, generate exported data based on the compiled data, and store the compiled and exported data in a database (such as the database 416). According to some embodiments, the database 416 can be a database associated with an organization and / or related entity that stores various information related to customers, transactions, ATMs, and business operations. The database 416 can also be used as a backup storage device and can contain data and information that is also stored, for example, on the database 360, as discussed in the reference Figure 3 discussed.

[0073] Embodiments consistent with the present disclosure may include a data set. The data set may include actual data reflecting real-world conditions, events, and / or measurements. However, in some embodiments, the disclosed systems and methods may relate entirely or in part to synthetic data (e.g., anonymized actual data or fabricated data). The data set may relate to digital data, text data, and / or image data. For example, the data set may include transaction data, financial data, demographic data, public data, government data, environmental data, traffic data, network data, video data transcripts, genomic data, proteomic data, and / or other data. The data set of an embodiment may be in various data formats, including but not limited to PARQUET, AVRO, SQLITE, POSTGRESQL, MYSQL, ORACLE, HADOOP, CSV, JSON, PDF, JPG, BMP, and / or other data formats.

[0074] The data set of the disclosed embodiments may have a corresponding data schema (e.g., structure), which includes data types, key-value pairs, labels, metadata, fields, relationships, views, indexes, packages, programs, functions, triggers, sequences, synonyms, links, directories, queues, etc. The data set of an embodiment may contain foreign keys (e.g., data elements that appear in multiple data sets and can be used to cross-reference data and determine relationships between data sets). The foreign key may be unique (e.g., a personal identifier) or shared (e.g., a zip code). The data set of an embodiment may be "clustered", e.g., a group of data sets may share common characteristics, such as overlapping data, shared statistical properties, etc. The clustered data sets may share a hierarchical relationship (e.g., data lineage).

[0075] Example Use Cases

[0076] The following example use cases describe examples of typical user flow patterns. This section is intended for illustrative purposes only and is not limiting.

[0077] In one example, Sally may be a customer of a financial institution and may regularly provide the institution with various account, personal, and financial information. The financial institution may store this information in, for example, one or more of Sally's accounts. Sally may monitor her accounts and conduct transactions in an online account or profile that she has established with the financial institution. Once Sally logs into her account, for example, by entering her username and password, Sally may be able to navigate through various tabs and pages in order to conduct different transactions. Sally may decide that she wants to virtually view her credit card (including the card number, expiration date, and card verification value (CVV) code). This feature may be beneficial to her when Sally shops online as it may prevent her from always having to keep track of her physical card.

[0078] In her account, Sally can initiate or request the system to allow her to virtually view her credit card. Since this type of transaction may introduce potential fraud risks to the financial institution (e.g., by potentially allowing someone other than Sally to view Sally's credit card information), the financial institution can utilize an MLM to determine whether the current user (possibly Sally) and Sally's device (e.g., a mobile device) are a trusted user-device pair. The MLM can be configured to make such a determination by evaluating Sally's account, personal, and financial / monetary information archived with the financial institution, and / or equivalent information corresponding to other customers of the financial institution. The MLM can further evaluate various interaction characteristics associated with Sally and Sally's mobile device, such as the frequency with which Sally uses this mobile device to log in to her account, the frequency with which Sally has been challenged historically (e.g., asked to enter authentication information), the frequency with which Sally initiates a transaction but abandons the process pre-completion, how long it has been since Sally has conducted a transaction or activity within her account, etc. Based on evaluating this information and data, the MLM can be configured to determine a trust score associated with Sally and her mobile device. The system can then determine whether the trust score exceeds a pre-determined threshold, which indicates that the financial institution's overall fraud recall ratio may increase above an acceptable pre-defined ratio. If it is found that the trust score exceeds the pre-determined threshold, the system can transmit a notification to Sally's mobile device or another device known to be associated with Sally, requesting Sally to perform multi-factor authentication (e.g., enter biometric information). Once the system receives Sally's multi-factor authentication input and determines that it matches the authentication information of Sally archived with the financial institution, Sally can then be able to complete the transaction she requested, i.e., virtually view her credit card. Alternatively, if the system finds that the trust score does not exceed the pre-determined threshold, Sally may be allowed to simply complete the transaction she requested without having to enter any additional information into the system.

[0079] In some examples, the disclosed system or method may relate to one or more of the following clauses:

[0080] Clause 1: A system includes: one or more processors; and a memory communicatively coupled to the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to: receive data corresponding to multiple users; receive corresponding requests for multiple transactions via multiple user devices associated with the multiple users; generate trust scores associated with the multiple users and the multiple user devices via a machine learning model (MLM) and based on the data, where each trust score indicates the probability that a user device among the multiple user devices is associated with a user among the multiple users; determine whether each of the multiple trust scores exceeds a predetermined threshold; and in response to determining that a trust score among the multiple trust scores exceeds the predetermined threshold, perform one or more anti-fraud actions with respect to the corresponding user device and user, where the ratio of performing the one or more anti-fraud actions for the multiple users is 30% or less.

[0081] Clause 2: The system according to Clause 1, wherein the one or more anti-fraud actions include transmitting a notification to the corresponding user device, requesting the corresponding user to perform multi-factor authentication, or both.

[0082] Clause 3: The system according to Clause 1, wherein generating the trust scores is further based on one or more corresponding features associated with the multiple users and the multiple user devices.

[0083] Clause 4: The system according to Clause 3, wherein the one or more corresponding features include one or more of the following: login frequency, challenge ratio, abandonment ratio, success ratio, time since previous activity, number of recent devices associated with the user, number of users associated with the user device, user device age, user device type, or a combination thereof.

[0084] Clause 5: The system according to Clause 4, wherein the challenge ratio includes the corresponding ratio of performing the one or more anti-fraud actions for each of the multiple users.

[0085] Clause 6: The system according to Clause 4, wherein: the abandonment ratio includes a first corresponding ratio associated with the corresponding request of each of the multiple users to abandon one or more transactions; and the success ratio includes a second corresponding ratio associated with the successful completion of one or more of the requested actions associated with the one or more anti-fraud actions for each of the multiple users.

[0086] Clause 7: A system includes: one or more processors; and a memory communicatively coupled to the one or more processors and storing instructions that, when executed by the one or more processors, are configured to cause the system to: receive data corresponding to a user; receive an authentication request via a user device; determine that the request does not satisfy one or more static rules; in response to determining that the request does not satisfy the one or more static rules, generate a trust score associated with the user and the user device via a machine learning model (MLM) and based on the data, wherein the trust score indicates the probability that the user device is associated with the user; determine whether the trust score exceeds a predetermined threshold; and in response to determining that the trust score exceeds the predetermined threshold, perform one or more anti-fraud actions.

[0087] Clause 8: The system of clause 7, wherein a rate of performing the one or more anti-fraud actions for a plurality of users is 30% or less, and wherein the plurality of users includes the user.

[0088] Clause 9: The system of clause 7, wherein the one or more anti-fraud actions include transmitting a notification to the user device, requesting the user to perform multi-factor authentication, or both.

[0089] Clause 10: The system of clause 7, wherein generating the trust score is further based on one or more characteristics associated with the user and the user device.

[0090] Clause 11: The system of clause 10, wherein the one or more characteristics include one or more of the following: login frequency, challenge rate, abandonment rate, success rate, time since previous activity, number of recent devices associated with the user, number of users associated with the user device, user device age, user device type, or a combination thereof.

[0091] Clause 12: The system of clause 11, wherein the challenge rate includes a rate of performing the one or more anti-fraud actions for the user.

[0092] Clause 13: The system of clause 11, wherein: the abandonment rate includes a first rate associated with the user's abandonment of the request to perform the transaction; and the success rate includes a second rate associated with the user's successful completion of one or more requested actions associated with the one or more anti-fraud actions.

[0093] Clause 14: A method includes: receiving data corresponding to a user; receiving, via a user device, a request to conduct a transaction; generating, via a machine learning model (MLM) and based on the data, a trust score associated with the user and the user device, where the trust score indicates the probability that the user device is associated with the user; determining whether the trust score exceeds a predetermined threshold; and in response to determining that the trust score exceeds the predetermined threshold, performing one or more anti-fraud actions.

[0094] Clause 15: The method according to Clause 14, wherein a ratio of performing the one or more anti-fraud actions for a plurality of users is 30% or lower, and wherein the plurality of users includes the user.

[0095] Clause 16: The method according to Clause 14, wherein the one or more anti-fraud actions include transmitting a notification to the user device, requesting the user to perform multi-factor authentication, or both.

[0096] Clause 17: The method according to Clause 14, wherein generating the trust score is further based on one or more characteristics associated with the user and the user device.

[0097] Clause 18: The method according to Clause 17, wherein the one or more characteristics include one or more of the following: login frequency, challenge ratio, abandonment ratio, success ratio, time since previous activity, number of recent devices associated with the user, number of users associated with the user device, user device age, user device type, or a combination thereof.

[0098] Clause 19: The method according to Clause 18, wherein the challenge ratio includes a ratio of performing the one or more anti-fraud actions for the user.

[0099] Clause 20: The method according to Clause 18, wherein: the abandonment ratio includes a first ratio associated with the user's abandonment of the request to conduct the transaction; and the success ratio includes a second ratio associated with the user's successful completion of one or more requested actions associated with the one or more anti-fraud actions.

[0100] The features and other aspects and principles of the disclosed embodiments can be implemented in various environments. Such environments and related applications can be specifically constructed to perform the various processes and operations of the disclosed embodiments, or they can include general-purpose computers or computing platforms that are selectively activated or reconfigured by program code to provide the necessary functionality. Additionally, the processes disclosed herein can be implemented through a suitable combination of hardware, software, and / or firmware. For example, the disclosed embodiments can implement a general-purpose machine configured to execute a software program that performs processes consistent with the disclosed embodiments. Alternatively, the disclosed embodiments can implement a dedicated device or system configured to execute a software program that performs processes consistent with the disclosed embodiments. Moreover, although some of the disclosed embodiments can be implemented by a general-purpose machine as computer processing instructions, all or part of the functionality of the disclosed embodiments can instead be implemented in dedicated electronic hardware.

[0101] The disclosed embodiments also relate to tangible and non-transitory computer-readable media that include program instructions or program code that, when executed by one or more processors, perform one or more computer-implemented operations. The program instructions or program code can include instructions or code that are specifically designed and constructed, and / or instructions and code that are well-known and available to those of ordinary skill in the computer software art. For example, the disclosed embodiments can execute high-level and / or low-level software instructions such as machine code (e.g., code generated by a compiler) and / or high-level code that can be executed by a processor using an interpreter.

[0102] The techniques disclosed herein generally relate to the advanced design effort of constructing computing systems capable of appropriately handling unpredictable data. Mathematical algorithms can be used as building blocks of the framework, but certain implementations of the system can autonomously learn their own operating parameters, thereby achieving better results, higher accuracy, fewer errors, fewer crashes, and faster speeds.

[0103] As used in this application, the terms "component", "module", "system", "server", "processor", "memory", etc. are intended to include one or more computer-related units, such as but not limited to hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component can be but not limited to a process, an object, an executable file, an execution thread, a program, and / or a computer running on a processor. As an illustration, both an application running on a computing device and the computing device can be components. One or more components can reside within an execution process and / or thread, and components can be localized on one computer and / or distributed between two or more computers. In addition, these components can execute from various computer-readable media on which various data structures are stored. These components can communicate via local and / or remote processes (e.g., according to a signal having one or more data packets, such as data from one component that interacts with another component in a local system, a distributed system, and / or across a network, such as the Internet, with other systems).

[0104] Certain embodiments and implementations of the disclosed technology have been described above with reference to block diagrams and flowcharts of systems and methods and / or computer program products according to example embodiments or implementations of the disclosed technology. It should be understood that one or more blocks in the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, can be implemented correspondingly by computer-executable program instructions. Similarly, according to some embodiments or implementations of the disclosed technology, some blocks in the block diagrams and flowcharts may not necessarily need to be executed in the order presented, can be repeated, or may not necessarily need to be executed at all.

[0105] These computer-executable program instructions can be loaded onto a general-purpose computer, a special-purpose computer, a processor, or other programmable data processing apparatus to produce a particular machine, such that the instructions executed on the computer, processor, or other programmable data processing apparatus create means for implementing one or more of the functions specified in one or more of the flowchart blocks. These computer program instructions can also be stored in a computer-readable memory, which can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means for implementing one or more of the functions specified in one or more of the flowchart blocks.

[0106] For example, embodiments or implementations of the disclosed technology may provide a computer program product that includes a computer-usable medium having computer-readable program code or program instructions embodied therein, the computer-readable program code being adapted to be executed to implement one or more functions specified in one or more flowchart blocks. Similarly, computer program instructions may be loaded onto a computer or other programmable data processing apparatus to cause a series of operational elements or steps to be executed on the computer or other programmable apparatus, thereby producing a computer-implemented process such that the instructions executed on the computer or other programmable apparatus provide elements or steps for implementing the functions specified in one or more flowchart blocks.

[0107] Accordingly, the blocks of the block diagrams and flowcharts support combinations of means for performing the specified functions, combinations of elements or steps for performing the specified functions, and means for program instructions for performing the specified functions. It will also be understood that each block of the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, can be implemented by special, hardware-based computer systems that perform the specified functions, elements or steps, or combinations of special hardware and computer instructions.

[0108] Certain implementations of the disclosed technology described above with reference to user equipment may include mobile computing devices. Those skilled in the art recognize that there are several types of mobile devices, commonly referred to as portable computing devices, which may run on batteries but are generally not classified as laptop computers. For example, mobile devices may include, but are not limited to, portable computers, tablet PCs, Internet tablet computers, PDAs, ultra-mobile PCs (UMPCs), wearable devices, and smart phones. In addition, implementations of the disclosed technology may be utilized with Internet of Things (IoT) devices, smart TVs and media devices, appliances, automobiles, toys, and voice command devices, as well as peripheral devices that interface with these devices.

[0109] In this description, numerous specific details have been set forth. However, it should be understood that embodiments of the disclosed technology may be practiced without these specific details. In other instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this description. References to "one embodiment", "an embodiment", "some embodiments", "example embodiments", "various embodiments", "one implementation", "an implementation", "example implementations", "various implementations", "some implementations", etc. indicate that the embodiments of the disclosed technology so described may include a particular feature, structure, or characteristic, but not every embodiment must include the particular feature, structure, or characteristic. Moreover, the repeated use of the phrase "in one implementation" does not necessarily refer to the same implementation, although it may.

[0110] Throughout the specification and claims, unless the context clearly dictates otherwise, the following terms have at least the meanings explicitly associated herein. The term "connected" means that one function, feature, structure, or property is directly joined to another function, feature, structure, or property or communicates with that other function, feature, structure, or property. The term "coupled" means that one function, feature, structure, or property is directly or indirectly joined to another function, feature, structure, or property or communicates with that other function, feature, structure, or property. The term "or" is intended to mean an inclusive "or". Additionally, the terms "a", "an", and "the" are intended to mean one or more, unless otherwise specified or clearly indicated as singular from the context. "Comprising", "containing", or "including" means that at least the named elements or method steps are present in the article or method, but does not exclude the presence of other elements or method steps, even if such other elements or method steps have the same function as the specified content.

[0111] It should be understood that the mention of one or more method steps does not exclude the presence of additional method steps or intermediate method steps between those explicitly identified. Similarly, it should also be understood that the mention of one or more components in a device or system does not exclude the presence of additional components or intermediate components between those explicitly identified.

[0112] Although embodiments have been described herein with respect to a system or method, it is contemplated that embodiments having the same or substantially similar features may alternatively be implemented as a system, method, and / or non - transitory computer - readable medium.

[0113] As used herein, unless otherwise specified, the use of the ordinal adjectives "first", "second", "third", etc. to describe a common object merely indicates that different instances of similar objects are being referred to and is not intended to imply that the objects so described must be in a given order (whether in time, space, ranking, or any other way).

[0114] Although certain embodiments of the present disclosure have been described in connection with what are presently considered to be the most practical and diverse embodiments, it should be understood that the present disclosure is not limited to the disclosed embodiments, but on the contrary, is intended to cover various modifications and equivalent arrangements included within the scope of the appended claims. Although specific terms have been employed herein, they are used in a general and descriptive sense only and not for purposes of limitation.

[0115] This written description uses examples to disclose certain embodiments of the technology and also enables those skilled in the art to practice certain embodiments of the technology (including making and using any device or system and performing any combined methods). The patentable scope of certain embodiments of the technology is defined in the claims and may include other examples that occur to those skilled in the art. If these other examples have structural elements that are indistinguishable from the literal language of the claims, or if they include equivalent structural elements that are not materially different from the literal language of the claims, then these other examples are intended to be within the scope of the claims.

Claims

1. A system, comprising: one or more processors; and a memory that communicates with the one or more processors and stores instructions that, when executed by the one or more processors, are configured to cause the system to: receive data corresponding to a plurality of users; receive corresponding requests to conduct a plurality of transactions via a plurality of user devices associated with the plurality of users; generate trust scores associated with the plurality of users and the plurality of user devices via a machine learning model, i.e., an MLM, and based on the data, wherein each trust score indicates the probability that a user device among the plurality of user devices is associated with a user among the plurality of users; determine whether each of the plurality of trust scores exceeds a predetermined threshold; and in response to determining that a trust score among the plurality of trust scores exceeds the predetermined threshold, perform one or more anti-fraud actions with respect to the corresponding user device and user, wherein the ratio of performing the one or more anti-fraud actions for the plurality of users is 30% or less.

2. The system according to claim 1, wherein The one or more anti-fraud actions include transmitting a notification to the corresponding user device, requesting the corresponding user to perform multi-factor authentication, or both.

3. The system according to claim 1, wherein, Generating the trust scores is further based on one or more corresponding characteristics associated with the plurality of users and the plurality of user devices.

4. The system according to claim 3, wherein The one or more corresponding characteristics include one or more of the following: login frequency, challenge ratio, abandonment ratio, success ratio, time since the previous activity, number of recent devices associated with the user, number of users associated with the user device, user device age, user device type, or a combination thereof.

5. The system according to claim 4, wherein, The challenge ratio includes the corresponding ratio of performing the one or more anti-fraud actions for each of the plurality of users.

6. The system according to claim 4, wherein: the abandonment ratio includes a first corresponding ratio associated with the corresponding request of each of the plurality of users to abandon one or more transaction requests; and the success ratio includes a second corresponding ratio associated with the corresponding request of each of the plurality of users to successfully complete one or more requested actions associated with the one or more anti-fraud actions.

7. A system, comprising: one or more processors; and a memory that communicates with the one or more processors and stores instructions that, when executed by the one or more processors, are configured to cause the system to: receive data corresponding to a user; receive an authentication request via a user device; determine that the request does not satisfy one or more static rules; in response to determining that the request does not satisfy the one or more static rules, generate a trust score associated with the user and the user device via a machine learning model, i.e., an MLM, and based on the data, wherein the trust score indicates the probability that the user device is associated with the user; determine whether the trust score exceeds a predetermined threshold; and in response to determining that the trust score exceeds the predetermined threshold, perform one or more anti-fraud actions.

8. The system according to claim 7, wherein The ratio of performing the one or more anti-fraud actions for multiple users is 30% or lower, and wherein the multiple users include the user.

9. The system according to claim 7, wherein, The one or more anti-fraud actions include transmitting a notification to the user device, requesting the user to perform multi-factor authentication, or both.

10. The system according to claim 7, wherein, Generating the trust score is further based on one or more characteristics associated with the user and the user device.

11. The system according to claim 10, wherein The one or more characteristics include one or more of the following: login frequency, challenge ratio, abandonment ratio, success ratio, time since previous activity, number of recent devices associated with the user, number of users associated with the user device, user device age, user device type, or a combination thereof.

12. The system according to claim 11, wherein, The challenge ratio includes the ratio of performing the one or more anti-fraud actions for the user.

13. The system according to claim 11, wherein: The abandonment ratio includes a first ratio associated with the user's abandonment of the request to perform the transaction; and The success ratio includes a second ratio associated with the user's successful completion of one or more of the requested actions associated with the one or more anti-fraud actions.

14. A method, comprising: Receiving data corresponding to a user; Receiving, via a user device, a request to perform a transaction; Generating, via a machine learning model, i.e., an MLM, and based on the data, a trust score associated with the user and the user device, wherein the trust score indicates the probability that the user device is associated with the user; Determining whether the trust score exceeds a predetermined threshold; and In response to determining that the trust score exceeds the predetermined threshold, performing one or more anti-fraud actions.

15. The method according to claim 14, wherein The ratio of performing the one or more anti-fraud actions for multiple users is 30% or lower, and wherein the multiple users include the user.

16. The method according to claim 14, wherein, The one or more anti-fraud actions include transmitting a notification to the user device, requesting the user to perform multi-factor authentication, or both.

17. The method according to claim 14, wherein, Generating the trust score is further based on one or more characteristics associated with the user and the user device.

18. The method according to claim 17, wherein The one or more characteristics include one or more of the following: login frequency, challenge ratio, abandonment ratio, success ratio, time since previous activity, number of recent devices associated with the user, number of users associated with the user device, user device age, user device type, or a combination thereof.

19. The method according to claim 18, wherein the challenge ratio includes the ratio of performing the one or more anti-fraud actions for the user.

20. The method according to claim 18, wherein: The abandonment ratio includes a first ratio associated with the user's abandonment of the request to perform the transaction; and The success ratio includes a second ratio associated with the user's successful completion of one or more of the requested actions associated with the one or more anti-fraud actions.