Flexible risk assessment techniques for controlling access to computing systems

The risk assessment system addresses vulnerabilities in binary identity verification by generating a comprehensive risk indicator from multiple data sources, enhancing security and accuracy in access control decisions.

WO2025155280A1PCT designated stage expired Publication Date: 2025-07-24EQUIFAX INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/US2024/011627
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-16
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Conventional binary identity verification systems lack insight into the factors contributing to access decisions, making them vulnerable to impersonation and providing inadequate security against sophisticated threats.

Method used

A risk assessment system generates a risk indicator by combining element scores from multiple data sources, using weights based on association, match type, and data source trustworthiness to evaluate the likelihood that a target entity is who they claim to be, providing a more comprehensive and flexible approach to access control.

Benefits of technology

The system enhances security by accurately predicting the legitimacy of access requests, reducing fraudulent activities, and improving decision-making through a robust and flexible risk assessment framework.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024011627_24072025_PF_FP_ABST
    Figure US2024011627_24072025_PF_FP_ABST
Patent Text Reader

Abstract

A system can generate a risk assessment associated with a target entity. For example, the system can receive a request for a risk indicator associated with a target entity. For each data source in a set of data sources, the system can: retrieve identity data associated with the target entity based on the identity of the target entity; and generate a set of element scores associated with each element of the set of elements. The system can determine an aggregate element score by combining the data source-level element scores for the set of data sources. The system can determine the risk indicator by combining the aggregated element scores of the set of elements based on a set of element weights. The system can also transmit, to a remote computing device, a responsive message including at least the risk indicator.
Need to check novelty before this filing date? Find Prior Art

Description

Attorney Docket No.096923-1398661 FLEXIBLE RISK ASSESSMENT TECHNIQUES FOR CONTROLLING ACCESS TO COMPUTING SYSTEMS TECHNICAL FIELD

[0001] The present disclosure relates generally to controlling interactions between computing systems. More specifically, but not by way of limitation, this disclosure relates to risk assessment based on personally identifiable information (PII) combinations for controlling interactions between computing systems. BACKGROUND

[0002] Various systems use binary identity verification to control access to restricted data or restricted computing environments. The output of a binary identity verification system can simply indicate whether an identity is or is not affiliated with an entity. However, limited insights can be drawn from a binary verification output. Further, a binary verification output does not provide insights into how the output was generated and what factors the output was generated with. This leads systems relying on such verification potentially vulnerable to bad actors using sophisticated methods to impersonate identities to gain access to restricted systems. SUMMARY

[0003] Various aspects of the present disclosure provide systems and methods for risk assessment using a risk indicator. The system can receive a request for a risk indicator associated with a target entity, where the request comprises a set of elements associated with an identity of the target entity. In some aspects, for each data source in a set of data sources, the system can: retrieve identity data associated with the target entity based on the identity of the target entity; and generate, based on the identity data, a set of element scores associated with each element of the set of elements thereby creating a data source-level element score for each data source and each element. For each element in the set of elements, the system determine an aggregate element score by combining the data source-level element scores for the set of data sources, where the aggregate element score is based, in part, on a set of data source weights associated with each respective data source. In some aspects, the system can further determine the risk indicator by combining the US2008230481161Attorney Docket No.096923-1398661 aggregated element scores of the set of elements based on a set of element weights, where each element weight is associated with each respective element of the set of elements. The system can transmit, to a remote computing device, a responsive message comprising at least the risk indicator for use in controlling access of the target entity to one or more interactive computing environments.

[0004] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to appropriate portions of the entire specification, any or all drawings, and each claim.

[0005] The foregoing, together with other features and examples, will become more apparent upon referring to the following specification, claims, and accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] FIG. 1 is a block diagram depicting an example of an operating environment in which a risk assessment computing system can be used to provide a risk assessment associated with a target entity according to some aspects of the present disclosure.

[0007] FIG.2 is a block diagram depicting a system for generating a risk assessment associated with a target entity according to some aspects of the present disclosure.

[0008] FIG. 3 is a block diagram depicting an example of a risk assessment application for generating a risk assessment associated with a target entity according to some aspects of the present disclosure.

[0009] FIG.4 is a flow chart illustrating a method for generating a risk assessment associated with a target entity according to some aspects of the present disclosure.

[0010] FIG. 5 is a block diagram depicting an example of a computing device, which can be used to implement the embodiments described herein according to some aspects of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0011] Controlling interactions between computing systems, such as providing access to a secure resource or computing environment, is important to the security of such resources and US2008230481161Attorney Docket No.096923-1398661 computing environments. Interactions and access can be controlled based on risk assessments using personally identifiable information (PII) combinations. For example, an entity can provide a name and address to verify to the computing system that the entity is who they represent themselves to be. Affiliating a target entity with an identity (i.e., the provided name and address) based on PII with a high degree of certainty facilitates the implementation of security solutions to mitigate risk when a target entity is attempting to access a secure computing environment. For example, a determination that the target entity is what it claims to be can ensure the computing environment remains protected from bad actors or from entities attempting to access protected or confidential information.

[0012] Certain aspects described herein for performing risk assessments on target entities using personally identifiable information (PII) can address one or more of the foregoing issues. Generating a risk indicator (e.g., a score indicating a degree of risk associated with allowing a target entity to access a computing environment) associated with the target entity by generating confidence scores for a set of PII elements associated with the target entity can provide a more comprehensive and flexible approach to risk assessment compared to conventional techniques. For example, the systems and methods described herein can provide an explorable set of confidence scores that facilitates more informed and accurate decisions (e.g., whether to allow a target entity to access a computing environment). This can improve an entity’s ability to prevent fraudulent activities and enhance security in online environments and of online interactions. Unlike conventional techniques involving binary assessments, techniques described herein are robust and flexible, providing more metrics from which to base a risk assessment of a target entity.

[0013] In some examples, a risk assessment computing system can receive a request for a risk indicator associated with a target entity. The request can include identity data associated with the target identity such that the identity data maps to PII elements. PII elements can include a name, a Social Security number (SSN), an address, a phone number, an email address, or a date of birth (DOB). The request can be received from, for example, an interactive computing environment as part of a process for authenticating the target entity to access the interactive computing environment. In another example, the request can be received from a client computing system requesting a risk indicator for a monitored identity. In some aspects, the number and type of PII elements used to generate the risk indicator can be modified based on a desired level of security. US2008230481161Attorney Docket No.096923-1398661

[0014] Using the identity data from the request, the system can retrieve sets of records matching the identity data. For example, the system can query one or more external data sources (e.g., external databases) to retrieve, from each data source, any records containing data matching the target entity’s identity data. In one example, the target entity may be associated with a name. The system can query a number of data sources to retrieve records including a name matching that of the target entity. Using the retrieved records and the information therein, the system can generate the risk indicator for the target entity.

[0015] To generate the risk indicator, the system may generate a set of attributes associated with the target entity. The set of attributes can, for example, include the PII elements and a set of element pairs. The element pairs may be, for example, “name-address,” “name-phone number,” “name-email address,” “name-DOB,” “name-SSN,” “SSN-address,” “SSN-phone number,” etc. Each element pair may be associated with an association weight and each individual element may be associated with an element weight. The association weight can, for example, reflect the degree to which a particular combination of elements is likely to identify an individual (i.e., the target entity). Similarly, the element weight can reflect a degree to which an element is likely to identify an individual. As an example, an SSN may be given a higher weight than an address. In addition to the element weight and association weight, the system may also generate a data source weight and a match weight. The value of the data source weight can be based on, for example, a trustworthiness or accuracy of each data source. The value of the match weight can be based on, for example, the type of match identified between the target entity information and each element pair.

[0016] Using these weights, the system can construct the risk indicator, which can be a composite score that reflects a weighted combination of the element scores for each element (e.g., each PII element). In some instances, these four weights (the element weight, the association weight, the match weight, and the data source weight) can be referred to as target variables. Each can be determined based on application of a separate machine-learning model to the records retrieved by the system using the target entity’s identity data.

[0017] Once the weights are determined, the system can generate an element credential (e.g., an element score) for each element at the data source level. Then, for the set of data sources, the system can generate an aggregate element credential, or score, based on the data source-level US2008230481161Attorney Docket No.096923-1398661 element credential for each data source and the data source weight associated with each data source. From the aggregate element credential, the system can apply an algorithm to generate an element score. Once the score for each element is calculated, the element scores can be combined using the element weights to generate the risk indicator.

[0018] The system can then transmit the risk indicator to a remote computing system. In some examples, this may be the system from which the risk indicator was requested. The risk indicator can be used to control access of the target entity to an interactive computing environment. For example, the risk indicator can be included in a responsive message to the request for evaluating the target entity such that the responsive message can be used to allow, challenge, or deny access to the target entity. For example, if the risk indicator is below a predefined threshold, a request by the target entity to access the interactive computing environment may be automatically denied or flagged for manual review.

[0019] Certain aspects described herein, which can include generating one or more risk indicators associated with target entities and providing a responsive message using the risk indicator, can improve at least the technical fields of controlling interactions between computing environments, access control for a computing environment, or a combination thereof. For instance, by generating and transmitting the responsive message, the risk assessment computing system can cause access to a computing system to be controlled more accurately. The risk indicator may be used to better predict whether the target entity requesting access is legitimate, and using the risk indicator may yield fewer malicious interactions than if the responsive message is not used. Further, the risk assessment computing system leverages distinctive components of the risk indicator to create a robust and easily implemented framework.

[0020] These illustrative examples are given to introduce the reader to the general subject matter discussed here and are not intended to limit the scope of the disclosed concepts. The following sections describe various additional features and examples with reference to the drawings in which like numerals indicate like elements, and directional descriptions are used to describe the illustrative examples but, like the illustrative examples, should not be used to limit the present disclosure. Operating Environment Example for Generating a Risk Indicator associated with a Target Entity US2008230481161Attorney Docket No.096923-1398661

[0021] Referring now to the drawings, FIG. 1 is a block diagram depicting an example of an operating environment in which a risk assessment computing system can be used to provide a risk assessment associated with a target entity according to some aspects of the present disclosure. FIG. 1 depicts examples of hardware components of a risk assessment computing system 102, according to some aspects. The risk assessment computing system 102 can be a specialized computing system that may be used for processing large amounts of data using a large number of computer processing cycles. In other examples, the risk assessment computing system 102 may be or include a general- purpose computing system. The risk assessment computing system 102 can include a risk assessment server 104 for performing a risk assessment (e.g., predicting future risk associated with the target entity, predicting the legitimacy of the target entity, etc.) with respect to a target entity, such as a target individual or a user computing device.

[0022] The risk assessment server 104 can include one or more processing devices that can execute program code, such as a risk assessment application 106. The program code can be stored on a non-transitory computer-readable medium or other suitable medium. The risk assessment application 106 can include one or more modules or components executing software code to complete one or more steps for determining a risk indicator. For example, the risk assessment application 106 can include: an attribute creation module 108; a target variable module 110; a weight calculation engine 112; and a score model 114. The attribute creation module 108 can create a set of attributes based on data associated with the target entity. These attributes can be passed to the target variable module 110, which may determine target variables for each component (e.g., elements, element pairs, match types, and data sources) that affect the risk indicator, as will be discussed further below. The weight calculation engine 112 can determine, based on the attributes, a set of weights associated with each target variable, which are used by the score model 114 in calculating the risk identifier.

[0023] The risk assessment server 104 can perform risk assessment operations or access control operations for validating or otherwise authenticating the target entity, for example using other suitable modules, models, components, etc. of the risk assessment server 104. The risk assessment server 104 can receive data associated with the target entity from external data sources 116, data repository 118, or any suitable combination thereof. In some aspects, the risk assessment application 106 can authenticate or deny a request for an interaction involving the target entity by US2008230481161Attorney Docket No.096923-1398661 generating a risk indicator using the target entity data retrieved from the external data sources 116 and the data repository 118.

[0024] In some aspects, the target entity data can be determined or stored in one or more network-attached storage units on which various repositories, databases, or other structures are stored. An example of these data structures can include the data repository 118. Additionally or alternatively, training datasets 120 can be stored in the data repository 118. In some examples, the training datasets 120 can be used to train the machine-learning models associated with each weight (the element weight, the association weight, the match type weight, and the data source weight). Each machine-learning model can be trained to generate each respective weight that are then used in calculating the risk indicator. For example, to generate each weight, a binary output may be generated based on a set of rules and applied to a machine-learning model.

[0025] Network-attached storage units may store a variety of different types of data organized in a variety of different ways and from a variety of different sources. For example, the network- attached storage unit may include storage other than primary storage located within the risk assessment server 104 that is directly accessible by processors located therein. In some aspects, the network-attached storage unit may include secondary, tertiary, or auxiliary storage, such as large hard drives, servers, and virtual memory, among other types of suitable storage. Storage devices may include portable or non-portable storage devices, optical storage devices, and various other mediums capable of storing and containing data. A machine-readable storage medium or computer-readable storage medium may include a non-transitory medium in which data can be stored and that does not include carrier waves or transitory electronic signals. Examples of a non- transitory medium may include, for example, a magnetic disk or tape, optical storage media such as a compact disk or digital versatile disk, flash memory, memory devices, or other suitable media.

[0026] Furthermore, the risk assessment computing system 102 can communicate with various other computing systems. The other computing systems can include user computing systems 122, such as smartphones, personal computers, etc., client computing systems 124, and other suitable computing systems. For example, user computing systems 122 may transmit, such as in response to receiving input from the target entity, requests for accessing the interactive computing environment 126 to the client computing systems 124. In response, the client computing systems 124 can send authentication queries to the risk assessment server 104, and the risk assessment US2008230481161Attorney Docket No.096923-1398661 server 104 can receive data associated with the target entity used in the request and generate a risk indicator associated with the target entity. While FIG. 1 illustrates that the risk assessment computing system 102 and the client computing systems 124 are separate systems, the risk assessment computing system 102 and the client computing systems 124 can be one system. For example, the risk assessment computing system 102 can be a part of the client computing systems 124, or vice versa.

[0027] As illustrated in FIG. 1, the risk assessment computing system 102 may interact with the client computing systems 124, the user computing systems 122, or a combination thereof via one or more public data networks 128 to facilitate interactions between users of the user computing systems 122 and the interactive computing environment 126. For example, the risk assessment computing system 102 can facilitate the client computing systems 124 providing a user interface to the user computing system 122 for receiving various data from the user. The risk assessment computing system 102 can transmit validated risk assessment data, for example similarity- preserving hashes, comparisons or scores determined therefrom, etc., to the client computing systems 124 for providing, challenging, or rejecting, etc. access of the target entity to the interactive computing environment 126. In some examples, the risk assessment computing system 102 can additionally communicate with third-party systems to receive risk assessment data, entity data, and the like, through the public data network 128. In some examples, the third-party systems can provide real-time (e.g., streamed) data about the target entity, historical data about the target entity, etc. to the risk assessment computing system 102.

[0028] Each client computing system 124 may include one or more devices such as individual servers or groups of servers operating in a distributed manner. A client computing system 124 can include any computing device or group of computing devices operated by a seller, lender, or other suitable entity that can provide products or services. The client computing system 124 can include one or more server devices. The one or more server devices can include or can otherwise access one or more non-transitory computer-readable media.

[0029] The client computing system 124 can further include one or more processing devices that can be capable of providing an interactive computing environment 126, such as a user interface, etc., that can perform various operations. The interactive computing environment 126 can include executable instructions stored in one or more non-transitory computer-readable media. US2008230481161Attorney Docket No.096923-1398661 The instructions providing the interactive computing environment 126 can configure one or more processing devices to perform the various operations. In some aspects, the executable instructions for the interactive computing environment 126 can include instructions that provide one or more graphical interfaces. The graphical interfaces can be used by a user computing system 122 to access various functions of the interactive computing environment 126. For instance, the interactive computing environment 126 may transmit data to and receive data, such as via the graphical interface, from a user computing system 122 to shift between different states of the interactive computing environment 126, where the different states allow one or more electronic interactions between the user computing system 122 and the client computing system 124 to be performed.

[0030] In some examples, the client computing system 124 may include other computing resources associated therewith (e.g., not shown in FIG. 1), such as server computers hosting and managing virtual machine instances for providing cloud computing services, server computers hosting and managing online storage resources for users, server computers for providing database services, and others. The interaction between the user computing system 122, the client computing system 124, and the risk assessment computing system 102, or any suitable sub-combination thereof may be performed through graphical user interfaces, such as the user interface, presented by the risk assessment computing system 102, the client computing system 124, other suitable computing systems of the computing environment 100, or any suitable combination thereof. The graphical user interfaces can be presented to the user computing system 122. Application programming interface (API) calls, web service calls, or other suitable techniques can be used to facilitate interaction between any suitable combination or sub-combination of the client computing system 124, the user computing system 122, and the risk assessment computing system 102.

[0031] A user computing system 122 can include any computing device or other communication device that can be operated by a user or entity, such as the user entity, which may include a consumer or a customer. The user computing system 122 can include one or more computing devices such as laptops, smartphones, and other personal computing devices. A user computing system 122 can include executable instructions stored in one or more non-transitory computer-readable media. The user computing system 122 can additionally include one or more processing devices configured to execute program code to perform various operations. In various examples, the user computing system 122 can allow a user to access certain online services or other suitable products, services, or computing resources from a target entity, such as the client US2008230481161Attorney Docket No.096923-1398661 computing system 124, to engage in mobile commerce with the client computing system 124, to obtain controlled access to electronic content, such as the interactive computing environment 126, hosted by the client computing system 124, etc.

[0032] In some examples, the user or a target entity can use the user computing system 122 to engage in an electronic interaction with the client computing system 124 via the interactive computing environment 126. The risk assessment computing system 102 can receive a request, for example from the user computing system 122, to access the interactive computing environment 126 and can use target entity data or any other suitable data or signals determined therefrom, to determine whether to provide access, to challenge the request, to deny the request, etc. An electronic interaction between the user computing system 122 and the client computing system 124 can include, for example, the user computing system 122 being used to request a financial loan or other suitable services or products from the client computing system 124, and so on. An electronic interaction between the user computing system 122 and the client computing system 124 can also include, for example, one or more queries for a set of sensitive or otherwise controlled data, accessing online financial services provided via the interactive computing environment 126, submitting an online credit card application or other digital application to the client computing system 124 via the interactive computing environment 126, operating an electronic tool within the interactive computing environment 126 (e.g., a content-modification feature, an application- processing feature, etc.), etc.

[0033] In some aspects, an interactive computing environment 126 implemented through the client computing system 124 can be used to provide access to various online functions. As a simplified example, a user interface or other interactive computing environment 126 provided by the client computing system 124 can include electronic functions for requesting computing resources, online storage resources, network resources, database resources, or other types of resources. In another example, a website or other interactive computing environment 126 provided by the client computing system 124 can include electronic functions for obtaining one or more financial services, such as an asset report, management tools, credit card application and transaction management workflows, electronic fund transfers, etc.

[0034] A user computing system 122 can be used to request access to the interactive computing environment 126 provided by the client computing system 124. The client computing system 124 US2008230481161Attorney Docket No.096923-1398661 can submit a request, such as in response to a request made by the user computing system 122 to access the interactive computing environment 126, for risk assessment to the risk assessment computing system 102 and can selectively grant or deny access to various electronic functions based on risk assessment performed by the risk assessment computing system 102. Based on the request, or continuously or substantially contemporaneously, the risk assessment computing system 102 can determine one or more risk signals or risk indicators for data associated with the target entity, which may submit or may have submitted the request via the user computing system 122. Based on a risk indicator determined from the score model 114, the risk assessment computing system 102, the client computing system 124, or a combination thereof can determine whether to grant the access request of the user computing system 122 to certain features of the interactive computing environment 126. The risk assessment computing system 102, the client computing system 124, or a combination thereof can use the risk indicator for other suitable purposes such as identifying a manipulated identity, controlling a real-world interaction, and the like.

[0035] In a simplified example, the system illustrated in FIG. 1 can configure the risk assessment server 104 to be used for controlling access to the interactive computing environment 126. The risk assessment server 104 can retrieve data associated with the target entity in response to a request to access the interactive computing environment 126. The data may, for example, be retrieved based on identity information (e.g., information collected by the client computing system 124 via a user interface provided to the user computing system 122) provided by the client computing system 124 or received via other suitable computing systems. The risk assessment server 104 can retrieve the data associated with the target entity from one or more data sources 116. The data sources 116 can store, for example, historical data, transaction data, financial data, and the like. The risk assessment server 104 can determine a risk indicator associated with the target entity by generating a set of element scores and combining the element scores according to predefined weights. The risk assessment server 104 can transmit the risk indicator, or any inference derived therefrom, to the client computing system 124 for use in controlling access to the interactive computing environment 126.

[0036] The risk indicator associated with the target entity, or any suitable score or comparison determined therefrom, can be used, for example by the risk assessment computing system 102, the client computing system 124, etc., to determine whether the risk associated with the target entity accessing a good or a service provided by the client computing system 124 using exceeds a US2008230481161Attorney Docket No.096923-1398661 threshold, thereby granting, challenging, or denying access by the target entity to the interactive computing environment 126. For example, if the risk assessment computing system 102 determines that the risk indicator indicates that risk associated with the identity element is lower than a threshold value, then the client computing system 124 associated with the service provider can generate or otherwise provide access permission to the user computing system 122 that requested the access. The access permission can include, for example, cryptographic keys used to generate valid access credentials or decryption keys used to decrypt access credentials. The client computing system 124 can also allocate resources to the target entity and provide a dedicated web address for the allocated resources to the user computing system 122, for example, by adding the user computing system 122 in the access permission. With the obtained access credentials or the dedicated web address, the user computing system 122 can establish a secure network connection to the interactive computing environment 126 hosted by the client computing system 124 and access the resources via invoking API calls, web service calls, HTTP requests, other suitable mechanisms or techniques, etc.

[0037] In some examples, the risk assessment computing system 102 may determine whether to grant, challenge, or deny the access request made by the user computing system 122 for accessing the interactive computing environment 126. For example, based on the risk indicator associated with the target entity, the risk assessment computing system 102 can determine that the target entity is a legitimate entity that made the access request and may authenticate the request. In other examples, the risk assessment computing system 102 can challenge or deny the access attempt if the risk assessment computing system 102 determines that the target entity may not be a legitimate entity.

[0038] In some examples, the risk indicator used to determine access to the interactive computing environment 126 may be determined at least in part based on output from one or more machine-learning models. For example, each type of weight (the element weight, the association weight, the match weight, and the data source weight) can be generated based on the application of a machine-learning model associated with the weight to a binary output based on the retrieved data associated with the target entity. The binary output can be generated, for example, by applying a set of one or more rules or logic to the retrieved data, as will be described in further detail below. Based on the weights, the element scores and data source-level element scores can be combined to generate the risk indicator. US2008230481161Attorney Docket No.096923-1398661

[0039] Each communication within the computing environment 100 may occur over one or more data networks, such as a public data network 128, a network 130 such as a private data network, or some combination thereof. A data network may include one or more of a variety of different types of networks, including a wireless network, a wired network, or a combination of a wired and wireless network. Examples of suitable networks include the Internet, a personal area network, a local area network (“LAN”), a wide area network (“WAN”), or a wireless local area network (“WLAN”). A wireless network may include a wireless interface or a combination of wireless interfaces. A wired network may include a wired interface. The wired or wireless networks may be implemented using routers, access points, bridges, gateways, or the like, to connect devices in the data network.

[0040] The number of devices illustrated in FIG. 1 is provided for illustrative purposes. Different numbers of devices may be used. For example, while certain devices or systems are shown as single devices in FIG.1, multiple devices may instead be used to implement these devices or systems. Similarly, devices or systems that are shown as separate may be instead implemented in a signal device or system. Architecture for Implementing a System for Generating a Risk Indicator associated with a Target Entity

[0041] FIG. 2 is a block diagram depicting an example environment 200 for generating a risk assessment associated with a target entity according to some aspects of the present disclosure. The environment 200 can include components as described above with reference to FIG. 1. For example, the orchestrators 204 described with reference to FIG.2 can be provided by or by part of the risk assessment system 102. Other implementations or architectures, however, are possible.

[0042] The environment 200 can include one or more data systems 202. Each data system 202 can be, for example, a product or system associated with the risk assessment system 102 or a client computing system 124. Each data system 202 may manage or otherwise control an external data source 116, or may have access to data stored by a data platform 206. For example, the data platform 206 can be associated with the risk assessment system. The data platform 206 can be separate from or can include the data repository 118. The data platform 206 may manage data associated with a set of entities. For example, the data platform 206 can manage data sources US2008230481161Attorney Docket No.096923-1398661 storing entity data, such as identity information or PII elements (e.g., name, DOB, SSN, phone number, email address, address, ID). The data sources may store additional information, such as financial information, associated with each entity.

[0043] Each data system 202 can function independently from each other and from the risk assessment system 102. In some aspects, each data system 202 may be provided with an orchestrator 204. The orchestrator 204 can enable the data system 202 to retrieve data from the data platform 206 via a lookup API 208 of the data platform. The retrieved data can be associated with a target entity as part of a request for a risk assessment associated with the target entity. In some aspects, the orchestrator 204 can pull data associated with a target entity from data sources managed by the data platform 206. Certain data systems 202 can be associated with one or more external data sources 116 and may receive data directly from the external data source 116.

[0044] The orchestrator 204 can then transmit the received data associated with the target entity, via a modeling environment API 212, to a modeling environment 210. The modeling environment 210 can generate the weights (the element weight, the association weight, the match weight, and the data source weight) used to generate the risk assessment for the target entity. In some aspects, each weight may be determined using a machine-learning model (Model 1, Model 2, … Model N) where the number of models corresponds to the number of weights used to generate the risk indicator.

[0045] In some aspects, the modeling environment 210 can be a component of the risk assessment system 102. For example, the risk assessment application 106 can include or interact with the modeling environment 210 to receive the calculated weights and generate the risk indicator. Exemplary Application for Generating a Risk Indicator associated with a Target Entity

[0046] FIG. 3 is a block diagram depicting an example risk assessment application 106 for generating a risk assessment associated with a target entity according to some aspects of the present disclosure. As discussed with reference to FIG.1, the risk assessment application can be stored on a risk assessment server 104 and can be used by the risk assessment system 102 to generate risk indicators for target entities in response to requests from the client computing systems 124 or the user computing systems 122. Other implementations or architectures, however, are possible. US2008230481161Attorney Docket No.096923-1398661

[0047] As discussed with reference to FIG.1, the risk assessment application 106 can include an attribute creation module 108, a target variable module 110, a weight calculation engine 112, and a score model 114. In response to receiving a request for a risk assessment of a target entity, the risk assessment application 106 can receive data associated with the target entity from external data sources 116. For example, the risk assessment application 106 can generate a query or request for data associated with the target entity and communicate that request to a data system (e.g., data system 202) in communication with an external database or data platform 206. In some aspects, the external data sources 116 may be populated by a database 302 storing a master dataset. As discussed above, each data system 202 can manage or access a portion of the master dataset.

[0048] The attribute creation module 108 can receive the data associated with the target entity and generate a set of attributes. In some aspects, the set of attributes can correspond to a set of PII elements (e.g., name, DOB, SSN, email address, phone number, address). In addition to the attributes corresponding to each individual element, the attribute creation module 108 can generate element pairs (e.g., “name-address,” “name-phone number,” “name-email address,” “name- DOB,” “name-SSN,” “name-ID,” “SSN-address,” “SSN-phone number,” etc.). An element pair, for example, “name-address,” can represent an instance in which a name of the target entity is associated with an address of the target entity in a particular data source. As an example, for six PII elements, there are fifteen unique element pairs.

[0049] In some aspects, the attribute creation module 108 can compare the identity information of the target entity with attributes (e.g., elements and element pairs) created by the attribute creation module 108. The comparison can determine various types of matches between the identity information and the element and element pairs. Examples of types of matches include: exact match; fuzzy match; and implied exact match. Additional match metrics can include: frequency; consistency, duration, and recency; and usage. By accounting for the types of matches and match metrics, disclosed systems and methods can account for numerous aspects of the target entity’s digital footprint.

[0050] An exact match can refer to an instance in which identity information of the target entity exactly matches data from the data source. For example, a name or a name-address combination found exactly in data from the data source is an exact match. A fuzzy match can refer to an instance in which the identity data associated with the target entity matches data from the US2008230481161Attorney Docket No.096923-1398661 data source within a predetermined threshold. For example, to determine a fuzzy match, the attribute creation module 108 can use a string comparison function, such as the Jaro-Winkler distance or the Levenshtein distance. If the distance is below a predetermined threshold, the data from the data source can be considered a match for the identity data. An implied exact match can refer to an instance in which data contains a direct match on a combination of a first element and a second element, and a second direct match on a combination of a second element and a third element, and thus there is an implied exact match between the first element and the third element. Each type of match can be given a different weight for calculating the risk indicator. For example, an exact match can have a higher weight than a fuzzy match or an implied exact match.

[0051] In certain aspects, the attribute creation module 108 can determine other match metrics. For example, the attribute creation module 108 can determine a frequency with which an element pair is found in data from a data source. The attribute creation module 108 can also determine a consistency, recency, and duration with which an element pair is found in data from the data source. The attribute creation module 108 can further determine a usage (e.g., a number of times the identity information is found as an element pair). The usage can refer to, for example, a number of times the target entity name is associated with a first address, compared with a number of times the target entity name is associated with a second address in the data source. The association occurring a greater number of times may, for example, be given a higher weight when determining the risk indicator.

[0052] Thus, as described above, the attribute creation module 108 can determine, for each element and element pair, the number and type of matches found in data from each data source. This information can then be passed to the target variable module 110. The target variable module 110 can create target variables, which quantify the importance of each component that will be factored into the risk indicator. For example, components can include: PII element (e.g., a target variable based on the type of PII element); match type (e.g., a target variable based on whether a match is exact, fuzzy, or implied exact); association (e.g., a target variable based on each element pair); and data source (e.g., a target variable based on metrics associated with each particular data source). Each target variable can be generated using a set of rules to generate a binary output for the particular target variable. US2008230481161Attorney Docket No.096923-1398661

[0053] The data source target variable can be generated based on whether elements matching the identity information are contained in the records retrieved from the data source. For example, the target variable module 110 can apply a set of rules to the data received from a data source for a particular element. An example rule for the “name” element is: if there exists an exact match for “name” then 1 or if there exists a fuzzy match for “name” then 1 or if there exists an implied exact match for “name” then 1, else 0. Thus, a binary output can be generated for each element where the binary output includes a 1 when the data source contains the element and 0 when it does not.

[0054] The match type target variable can be generated based on a type of match between identity information and the element pairs for each element. For example, to generate a binary output, the target variable module 110 can apply a set of rules. The set of rules can be, for example: if (exact “name-address” in Data Source 1) or if (exact “name-phone number” in Data Source 1) or … then 1 or if (exact “name-address” in Data Source 2) or if (exact “name-phone number” in Data Source 2) or… then 1 … else 0

[0055] A similar set of rules can be applied for fuzzy match and for implied exact match. Thus, the generated binary output indicates which type of match is most prevalent for each element. In other words, a confidence in a particular element pair may be based on that element pair occurring more often across the queried data sources.

[0056] The association target variable can be generated based on element pairs that occur in the retrieved data. For example, the target variable module 110 can generate a binary output by applying a set of rules to the retrieved data. An example set of rules can be, for the element pair “name-address”: if exact “name-address” in Data Source 1 then 1 or if fuzzy “name-address” in Data Source 1 then 1 or if implied exact “name-address” in Data Source 1 then 1 or if exact “name-address” in Data Source 2 then 1 or US2008230481161Attorney Docket No.096923-1398661 if fuzzy “name-address” in Data Source 2 then 1 or if implied exact “name-address” in Data Source 2 then 1 or …. else 0

[0057] The resulting binary output can indicate which associations (e.g., element pairs) occur most commonly in the set of received data associated with the target entity.

[0058] The element target variable can be generated based on matches identified for element pairs involving each element across data sources. For example, the target variable module 110 can apply a set of rules to the retrieved data associated with the target entity for each element (e.g., for name, DOB, SSN, email address, phone number, address). An example set of rules for “name” can be: if exact “name-address” in Data Source 1 then 1 or if exact “name-phone number” in Data Source 1 then 1 or if exact “name-SSN” in Data Source 1 then 1 … if fuzzy “name-address” in Data Source 1 then 1 or if fuzzy “name-phone number” in Data Source 1 then 1 or if fuzzy “name-SSN” in Data Source 1 then 1 … if implied exact “name-address” in Data Source 1 then 1 or if implied exact “name-phone number” in Data Source 1 then 1 or if implied exact “name-SSN” in Data Source 1 then 1 … if exact “name-address” in Data Source 2 then 1 or if exact “name-phone number” in Data Source 2 then 1 or if exact “name-SSN” in Data Source 2 then 1 …. else 0

[0059] As previously discussed a set of weights can be generated for use in calculating the risk indicator. The weights can be generated by the weight calculation engine 112 using the sets of binary output generated by the target variable module 110. The weight calculation engine can US2008230481161Attorney Docket No.096923-1398661 apply the binary output of each target variable to a model associated with that weight or target variable. In some aspects, the model can be a linear regression model:(Equation 1) where y is the target variable, xpare the “features” where there are p features in the target variable, and wpare the weights. As an example, for the match type target variable for an element, the features can be each type of match (exact, fuzzy, implied exact), thus there are three features. Linear regression can be used to determine the weight associated with each of these three features for a particular element. In other aspects, other models or functions can be used to determine the weights of each target variable. For example, a SHAP package can be used in XGBoost or other machine-learning platform to use Shapley values to accurately estimate the contribution of each component (e.g., data source, association, match type, and element) to the risk indicator.

[0060] Exemplary weights calculated by the weight calculation engine 112 are shown below in Tables 1-4. Table 1Table 2US2008230481161Attorney Docket No.096923-1398661Table 4US2008230481161Attorney Docket No.096923-1398661

[0061] These calculated weights can be passed to the score model 114 to be used in calculating the risk indicator. In some aspects, in calculating each weight, the weight calculation engine 112 can perform cross-validation to ensure the weights are accurate, stable, and indicative the contribution to the risk indicator of each represented component (data source, match type, association, and element).

[0062] The score model 114 can receive attributes (e.g., elements and element pairs) from the attribute creation module 108 and weights from the weight calculation engine 112 and use the attributes and weights (e.g., the respective element weights and association weights) to calculate the risk indicator for the target entity.

[0063] The score model 114 can first create element scores at the data source level. As an example, the name score for a first data source (e.g., Data Source 1) can be given by: name_score_data_source_1 = (name-address_exact * association weight 1 + name- address_exact * association weight 2 +…) * match type weight_exact + (name-address_fuzzy * association weight 1 + name-address_fuzzy * association weight 2 +…) * match type weight_fuzzy + (name- address_implied * association weight 1 + name-address_implied * association weight 2 +…) * match type weight_implied

[0064] The score model 114 can repeat the above algorithm for each element in each data source. The element score for each data source can then be combined to create an aggregate score for each element. As an example, an aggregated name score can be given by: aggregated_name_score = normalize(name_score_data_source_1 * data_source_1_weight + name_score_data_source_2 * US2008230481161Attorney Docket No.096923-1398661 data_source_2_weight name_score_data_source_n * data_source_n_weight )

[0065] The above algorithm can be used to generate an aggregated score for each element (e.g., for name, address, DOB, phone number, email address, and SSN). In turn, the aggregated element score can be used to determine a final element score. As an example, the final name score can be determined using the formula: name_score = normalized(aggregated_name_score + (number of data sources affiliating / n) + (type of data source / t) * 100 where the number of data sources affiliating refers to the number of data sources in which a match for name is found, n is the number of data sources, type of data source refers to the type of data source (e.g., internal or external), and t is the number of types of data sources (e.g., two). The output of the above equation for name_score will be a score value ranging from 0 to 100 where 100 indicates a strong likelihood that the target entity is who they represent themselves to be based on the name element and 0 indicates a likelihood that the target entity is not who they represent themselves to be.

[0066] In some aspects, the score model 114 can also compute scores for element pairs (e.g., “name-address,” “name-phone number,” “name-email address,” “name-DOB,” “name-SSN,” “SSN-address,” “SSN-phone number,” etc.). For example, the name-to-address score can be calculated using the formula: name_to_address_score = normalized(sum of all data sources_name_to_address_exact + sum of all data sources_name_to_address_fuzzy + sum of all data sources_name_to_address_implied) In other words, the name_to_address_score is a normalized sum of the number of data sources of the set of n data sources in which the name-address pair matching the name and address of the target entity was found.

[0067] Finally, the score model 114 can determine the risk indicator based on the equation: US2008230481161Attorney Docket No.096923-1398661 risk indicator = normalized(name_score * name_weight + address_score * address_weight + phone_score * phone_weight + email_score * email_weight + DOB_score * DOB_weight + SSN_score * SSN_weight) Although shown here for six PII elements, the risk indicator can be calculated using any number of elements and corresponding element weights.

[0068] In some aspects, the calculated risk indicator can be transmitted to a remote device (e.g., the client computing device 124 or the user computing device 122) for use in controlling access of the target entity to the interactive computing environment 126. For example, a risk indicator having a high value can indicate a high level of confidence that the target entity is who they represent themselves to be. A risk indicator having a low value can indicate the target entity may not be who they represent themselves to be. The risk indicator can therefore be used to make decisions to allow or deny the target entity to access the interactive computing system 126. Techniques for Generating a Risk Indicator associated with a Target Entity

[0069] FIG. 4 is a flow chart illustrating an example of a process 400 for generating a risk assessment associated with a target entity according to some aspects of the present disclosure. In some examples, the operations of the process 400, or any subset thereof, may be performed by the risk assessment computing system 102 via the risk assessment server 104, but other suitable systems, devices, or subsets or combinations thereof may perform one or more operations described with respect to the process 400. For illustrative purposes, the process 400 is described with reference to certain examples depicted in the figures. Other implementations, however, are possible.

[0070] At block 402, the process 400 involves receiving a request for a risk indicator associated with a target entity. The request can include a set of elements associated with an identity of the target entity. The elements can be, for example, a name, address, SSN, DOB, phone number, or email address. The request may be generated as part of an authentication process initiated when the target entity attempts to access an interactive computing environment 126.

[0071] At block 404, the process 400 involves retrieving, for each data source, identity data associated with the target entity based on the identity of the target entity. In some aspects, each data source is associated with a data source weight. For example, the risk assessment application US2008230481161Attorney Docket No.096923-1398661 106 can generate a query based on the received identity information to query a set of data sources (e.g., data sources 116) to retrieve identity data associated with the target entity. As discussed above, the records can be retrieved using an orchestrator 202 loaded on a data system 202 (e.g., a product managed by the risk assessment system 102).

[0072] In some aspects, using the weight calculation engine 112, the risk assessment application 106 can determine a set of weights including a data source weight, an association weight, a match type weight, and an element weight. For example, the data source weight can be based on a number of elements of the set of elements that are present in the set of records associated with each data source. The association weight for each element pair is based on a number of data sources of the set of data sources that contain the element pair. The match type weight associated with an element is based on whether a data source of the set of data sources contains an element pair associated with that element.

[0073] At block 406, the process 400 involves, generating, based on the identity data, a set of element scores associated with each element of the set of elements thereby creating a data source- level element score for each data source and each element. The data source-level element score can be based, in part, on the match type weights and the association weights for each element pair involving the element.

[0074] At block 408, the process 400 involves determining, for each element, an aggregate element score by combining the data source-level element scores for the set of data sources. In some aspects, the aggregate element score is based, in part, on a set of data source weights associated with each respective data source. For example, data sources containing more elements matching those of the target entity may be weighted more heavily than data sources containing fewer elements matching those of the target entity. In another example, the data source weights may be generated based on a relative trustworthiness of the data source or on an average accuracy of the data contained in the data source. In some aspects, these aggregated element scores can be normalized across the number and type of data sources in the set of data sources to generate a normalized aggregate element score ranging from 0 to 100.

[0075] At block 410, the process 400 involves determining the risk indicator by combining the aggregated element scores of the set of elements based on a set of element weights. The element weights can indicate, for example, a degree with which a particular element is likely to be US2008230481161Attorney Docket No.096923-1398661 associated with the target entity. For example, an SSN may have a relatively high weight, while an address that a number of entities have resided at may have a lower weight as it is less determinative of an identity. As discussed above, the score model 114 can generate the risk indicator by combining the elements by weight.

[0076] At block 414, the process 400 involves transmitting, to a remote computing device, a responsive message comprising at least the risk indicator for use in controlling access of the target entity to one or more interactive computing environments. For example, the risk indicator can be used in controlling an interaction involving a target entity or access of the target entity to a restricted system.

[0077] Systems and methods described herein provide advantages over traditional, binary identity verification systems. For example, rather than binary identity verification, disclosed systems and methods provide a measure of identity affiliation, i.e., a measure that the target entity is affiliated with an identity based on provided PII. In some examples, the risk assessment system 102 can provide an explorable risk indicator, allowing a user to review each element’s contribution to the risk indicator. Additionally, by incorporating data from a set of data sources, the risk assessment system 102 can generate a more accurate and dependable risk indicator. Further, by weighting the contribution of each data source, the risk assessment system 102 can generate a risk indicator that account for, for example, variations in the trustworthiness and accuracy of the data sources. Example of Computing System

[0078] Any suitable computing system or group of computing systems can be used to perform the operations for the techniques described herein. For example, FIG. 5 is a block diagram depicting an example of a computing device 500, which can be used to implement the risk assessment server 104. The computing device 500 can include various devices for communicating with other devices in the computing environment 100, as described with respect to FIG. 1. The computing device 500 can include various devices for performing one or more operations, such as risk assessment operations, described above with respect to FIGs.1-4.

[0079] The computing device 500 can include a processor 502 that can be communicatively coupled to a memory 504. The processor 502 can execute computer-executable program code stored in the memory 504, can access information stored in the memory 504, or both. Program US2008230481161Attorney Docket No.096923-1398661 code may include machine-executable instructions that may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc., may be passed, forwarded, or transmitted via any suitable means including memory sharing, message passing, token passing, network transmission, among others.

[0080] Examples of a processor 502 can include a microprocessor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or any other suitable processing device. The processor 502 can include any suitable number of processing devices, including one. The processor 502 can include or communicate with a memory 504. The memory 504 can store program code that, when executed by the processor 502, causes the processor 502 to perform the operations described herein.

[0081] The memory 504 can include any suitable non-transitory computer-readable medium. The computer-readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable program code or other program code. Non-limiting examples of a computer-readable medium can include a magnetic disk, memory chip, optical storage, flash memory, storage class memory, ROM, RAM, an ASIC, magnetic storage, or any other medium from which a computer processor can read and execute program code. The program code may include processor-specific program code generated by a compiler or an interpreter from code written in any suitable computer-programming language. Examples of suitable programming language can include Hadoop, C, C++, C#, Visual Basic, Java, Python, Perl, JavaScript, ActionScript, etc.

[0082] The computing device 500 may also include a number of external or internal devices such as input or output devices. For example, the computing device 500 is illustrated with an input / output interface 508 that can receive input from input devices or provide output to output devices. A bus 506 can also be included in the computing device 500. The bus 506 can communicatively couple one or more components of the computing device 500.

[0083] The computing device 500 can execute program code 514 that can include risk assessment application 106. The program code 514 for the risk assessment application 106 may be US2008230481161Attorney Docket No.096923-1398661 resident in any suitable computer-readable medium and may be executed on any suitable processing device. For example, and as illustrated in FIG. 5, the program code 514 for the risk assessment application 106 can reside in the memory 504 at the computing device 500 along with the program data 516 associated with the program code 514. Executing the risk assessment application 106 can configure the processor 502 to perform at least a portion of the operations described herein.

[0084] In some aspects, the computing device 500 can include one or more output devices. One example of an output device can be or include the network interface device 510 illustrated in FIG. 5. A network interface device 510 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks described herein. Non-limiting examples of the network interface device 510 can include an Ethernet network adapter, a modem, etc.

[0085] Another example of an output device can include the presentation device 512 depicted in FIG. 5. A presentation device 512 can include any device or group of devices suitable for providing visual, auditory, or other suitable sensory output. Non-limiting examples of the presentation device 512 can include a touchscreen, a monitor, a speaker, a separate mobile computing device, etc. In some aspects, the presentation device 512 can include a remote client- computing device that communicates with the computing device 500 using one or more data networks described herein. In other aspects, the presentation device 512 can be omitted.

[0086] The foregoing description of some examples has been presented only for the purpose of illustration and description and is not intended to be exhaustive or to limit the disclosure to the precise forms disclosed. Numerous modifications and adaptations thereof will be apparent to those skilled in the art without departing from the spirit and scope of the disclosure. US2008230481161

Claims

Attorney Docket No.096923-1411973 Claims What is claimed is:

1. A system comprising: a processor; and a non-transitory computer-readable medium comprising instructions that are executable by the processor for causing the processor to perform operations comprising: receiving a request for a risk indicator associated with a target entity, wherein the request comprises a set of elements associated with an identity of the target entity; for each data source in a set of data sources: retrieving identity data associated with the target entity based on the identity of the target entity; and generating, based on the identity data, a set of element scores associated with each element of the set of elements thereby creating a data source-level element score for each data source and each element; for each element in the set of elements, determining an aggregate element score by combining the data source-level element scores for the set of data sources, wherein the aggregate element score is based at least in part on a set of data source weights associated with each respective data source; determining the risk indicator by combining the aggregated element scores of the set of elements based on a set of element weights, wherein each element weight is associated with each respective element of the set of elements; and transmitting, to a remote computing device, a responsive message comprising at least the risk indicator used to control access of the target entity to one or more interactive computing environments.

2. The system of claim 1, wherein generating a data source-level element score for an element comprises: identifying a set of element pairs including the element; US2008230481161Attorney Docket No.096923-1411973 determining, for each element pair, whether identity data from the data source matches the element pair, wherein identifying a match comprises at least one of: identifying an exact match between the identity data and the element pair, identifying a fuzzy match between the identity data and the element pair, or identifying an implied exact match between the identity data and the element pair, and wherein each type of match is associated with a match weight; based on the determination, generating the data source-level element score by combining the identified matches based on the match weight associated with each type of match.

3. The system of claim 2, wherein the data source weight is based on a number of element pairs matching the identity data that are identified in the identity data from the data source.

4. The system of claim 3, wherein the data source weight is generated by: generating a binary output based on the determination of whether identity data from the data source matches each element pair; and applying the binary output to a machine-learning model to determine the data source weight.

5. The system of claim 2, wherein the data source-level element score is based, in part, on an association weight for each element pair, wherein the association weight indicates a likelihood that the element pair identifies the target entity.

6. The system of claim 2, wherein the match weight associated with each type of match is based on a frequency at which the identity data matches the element pair for each type of match.

7. The system of claim 1, wherein the operations further comprise: normalizing each aggregated element score based on a number of data sources in the set of data sources and a number of types of data sources in the set of data sources. US2008230481161Attorney Docket No.096923-1411973 8. A method comprising: receiving, by a processor, a request for a risk indicator associated with a target entity, wherein the request comprises a set of elements associated with an identity of the target entity; for each data source in a set of data sources: retrieving, by the processor, identity data associated with the target entity based on the identity of the target entity; and generating, by the processor and based on the identity data, a set of element scores associated with each element of the set of elements thereby creating a data source-level element score for each data source and each element; for each element in the set of elements, determining, by the processor, an aggregate element score by combining the data source-level element scores for the set of data sources, wherein the aggregate element score is based, in part, on a set of data source weights associated with each respective data source; determining, by the processor, the risk indicator by combining the aggregated element scores of the set of elements based on a set of element weights, wherein each element weight is associated with each respective element of the set of elements; and transmitting, by the processor to a remote computing device, a responsive message comprising at least the risk indicator used to control access of the target entity to one or more interactive computing environments.

9. The method of claim 8, wherein generating a data source-level element score for an element comprises: identifying a set of element pairs including the element; determining, for each element pair, whether identity data from the data source matches the element pair, wherein identifying a match comprises at least one of: identifying an exact match between the identity data and the element pair, identifying a fuzzy match between the identity data and the element pair, or identifying an implied exact match between the identity data and the element pair, and wherein each type of match is associated with a match weight; US2008230481161Attorney Docket No.096923-1411973 based on the determination, generating the data source-level element score by combining the identified matches based on the match weight associated with each type of match.

10. The method of claim 9, wherein the data source weight is based on a number of element pairs matching the identity data that are identified in the identity data from the data source.

11. The method of claim 10, wherein the data source weight is generated by: generating a binary output based on the determination of whether identity data from the data source matches each element pair; and applying the binary output to a machine-learning model to determine the data source weight.

12. The method of claim 9, wherein the data source-level element score is based, in part, on an association weight for each element pair, wherein the association weight indicates a likelihood that the element pair identifies the target entity.

13. The method of claim 9, wherein the match weight associated with each type of match is based on the frequency at which the identity data matches the element pair for each type of match.

14. The method of claim 8, wherein the method further comprises: normalizing each aggregated element score based on a number of data sources in the set of data sources and a number of types of data sources in the set of data sources.

15. A non-transitory computer-readable medium comprising instructions that are executable by a processor for causing the processor to perform operations comprising: receiving a request for a risk indicator associated with a target entity, wherein the request comprises a set of elements associated with an identity of the target entity; for each data source in a set of data sources: US2008230481161Attorney Docket No.096923-1411973 retrieving identity data associated with the target entity based on the identity of the target entity; and generating, based on the identity data, a set of element scores associated with each element of the set of elements thereby creating a data source-level element score for each data source and each element; for each element in the set of elements, determining an aggregate element score by combining the data source-level element scores for the set of data sources, wherein the aggregate element score is based, in part, on a set of data source weights associated with each respective data source; determining the risk indicator by combining the aggregated element scores of the set of elements based on a set of element weights, wherein each element weight is associated with each respective element of the set of elements; and transmitting, to a remote computing device, a responsive message comprising at least the risk indicator used to control access of the target entity to one or more interactive computing environments.

16. The non-transitory computer-readable medium of claim 15, wherein generating a data source-level element score for an element comprises: identifying a set of element pairs including the element; determining, for each element pair, whether identity data from the data source matches the element pair, wherein identifying a match comprises at least one of: identifying an exact match between the identity data and the element pair, identifying a fuzzy match between the identity data and the element pair, or identifying an implied exact match between the identity data and the element pair, and wherein each type of match is associated with a match weight; based on the determination, generating the data source-level element score by combining the identified matches based on the match weight associated with each type of match. US2008230481161Attorney Docket No.096923-1411973 17. The non-transitory computer-readable medium of claim 16, wherein the data source weight is based on a number of element pairs matching the identity data that are identified in the identity data from the data source.

18. The non-transitory computer-readable medium of claim 17, wherein the data source weight is generated by: generating a binary output based on the determination of whether identity data from the data source matches each element pair; and applying the binary output to a machine-learning model to determine the data source weight.

19. The non-transitory computer-readable medium of claim 16, wherein the data source-level element score is based, in part, on an association weight for each element pair, wherein the association weight indicates a likelihood that the element pair identifies the target entity.

20. The non-transitory computer-readable medium of claim 15, wherein the operations further comprise: normalizing each aggregated element score based on a number of data sources in the set of data sources and a number of types of data sources in the set of data sources. US2008230481161

Citation Information

Patent Citations

  • Identity access management using access attempts and profile updates

    US11743245B2

  • Learning an entity's trust model and risk tolerance to calculate a risk score

    US20170293873A1

  • Identity fraud risk engine platform

    US20200042723A1