AI-based transaction protection and zero-trust authentication system for e-commerce platforms

DE202026104098U1Undetermined Publication Date: 2026-10-08PATEL YESHA
0 Cites 0 Cited by

Patent Information

Application Number
DE202026104098
Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2026-07-14
Publication Date
2026-10-08
Estimated Expiration
2036-07-31
Patent Text Reader

Abstract

An artificial intelligence-based system for transaction protection and zero-trust authentication for e-commerce platforms, wherein the system comprises: a. an AI fraud detection engine (100) comprising an ensemble of trained machine learning models configured to receive a transaction feature vector for each incoming e-commerce transaction and, by evaluating this transaction feature vector against learned patterns of fraudulent and legitimate transactions, output a fraud probability score;b. a “zero-trust” authentication module (200) that is functionally connected to a user device (800) and a secure token vault (600) and is configured to perform continuous cryptographic verification of the user identity, device state, and session token integrity on each transaction request, without granting implicit trust based on a previous authentication state; c. a behavioral analytics unit (300) that is functionally connected to the user device (800) and is configured to capture real-time session interaction signals, including keystroke dynamics, mouse movement patterns, device fingerprint attributes, and page navigation sequences, and to calculate behavioral anomaly scores by comparing these signals to established user baseline profiles;d. a dynamic risk assessment engine (400) that is operationally connected to the AI ​​fraud detection engine (100), the behavioral analysis unit (300) and a real-time threat information feed (700) and is configured to aggregate the fraud probability score, behavioral deviation scores and real-time threat indicators to generate a composite risk score and assign a transaction decision recommendation selected from a variety of risk levels;e. a multi-factor authentication gateway (500) that is functionally connected to the dynamic risk assessment engine (400) and the zero-trust authentication module (200) and is configured to adaptively submit authentication requests selected from biometric verification, one-time password provision, and cryptographic device attestation, proportional to the composite risk score assigned by the dynamic risk assessment engine (400); f. a secure token vault (600) that is configured to generate, store, and revoke short-lived, device-bound session tokens that are cryptographically signed using asymmetric key pairs managed within a hardware security module, and that maintains a directory of trusted devices and a token blocklist;andg. a real-time threat intelligence feed (700) configured to capture, normalize, deduplicate and make available in real time external and internal threat indicators - including compromised payment card identifiers, malicious IP address ranges, known bot-agent signatures and speed abuse patterns;characterized by the fact that the system enforces zero-trust authentication principles by requiring continuous cryptographic session verification regardless of the previous authentication status, and integrates an AI-driven fraud probability assessment with real-time behavioral anomaly detection and dynamic threat intelligence to generate a composite risk assessment that establishes an adaptive authentication level and transaction decision recommendation for each e-commerce transaction, without any implicit trust at any stage of the transaction lifecycle.
Need to check novelty before this filing date? Find Prior Art