Efficient multi-network framework for risk evaluation and false decision correction
The multi-network framework addresses the issue of cross-network dependencies by determining user identifiers and security values across various networks to adjust security states, improving the accuracy of security evaluations and correcting false decisions.
Patent Information
- Application Number
- PCT/US2025/041304
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-09
- Filing Date
- 2025-08-08
- Publication Date
- 2026-02-12
AI Technical Summary
Traditional security modeling approaches fail to account for cross-network dependencies in user interactions, leading to inadequate real-time influence and inefficiencies in evaluating and correcting false decisions across multiple networks.
A multi-network framework that utilizes an analysis computer to determine user identifiers and security values across different interaction networks, calculating an other network total security factor to adjust security states based on these values, thereby optimizing security evaluations and correcting false decisions.
Enhances the accuracy of security assessments by considering interactions across multiple networks, reducing false positives and negatives, and optimizing security state classifications.
Smart Images

Figure US2025041304_12022026_PF_FP_ABST
Abstract
Description
PATENTAtorney Docket No.: 079900-1507073-9114W001 Client Reference No. : 9114WOO 1EFFICIENT MULTI-NETWORK FRAMEWORK FOR RISKEVALUATION AND FALSE DECISION CORRECTIONCROSS-REFERENCES TO RELATED APPLICATIONS
[0001] This PCT application claims the benefit of U.S. Provisional Application No. 63 / 681,685, filed August 9, 2024, which is herein incorporated by reference in its entirety for all purposes.BACKGROUND
[0002] Users associated with user accounts typically engage in activities spanning multiple networks. However, traditional security modeling approaches focus on one specific type of network due to 1) different data patterns across networks, 2) data availability, and 3) system capability for handling large amounts of data from multiple networks. However, these typical approaches neglect dependency across networks.
[0003] Currently, an interaction performed by a user on one network is not directly influenced in real-time by interactions performed by the user on another network.
[0004] Embodiments of the disclosure address this problem and other problems individually and collectively.SUMMARY
[0005] One embodiment is related to a method comprising: receiving, by a computer, current interaction data related to a current interaction conducted in a current interaction network, the current interaction data comprising a current user identifier for the current interaction network; determining, by the computer, a first user identifier for a first interaction network based on the current user identifier; determining, by the computer, a second user identifier for a second interaction network based on the current user identifier; determining, by the computer, a first security value corresponding to a first set of interaction data; determining, by the computer, a second security value corresponding to a second set of interaction data; determining, by the computer, an other network total security factor using the first security value and the secondsecurity value; determining, by the computer, a security state of one of two states for the current interaction; determining, by the computer, whether or not to adjust the security state to the other of the two states using the other network total security factor; and performing, by the computer, additional processing in relation to the current interaction based on the security state.
[0006] Another embodiment is related to computer comprising: a processor; and a non- transitory computer readable medium comprising code, executable by the processor, for performing a method comprising: receiving current interaction data related to a current interaction conducted in a current interaction network, the current interaction data comprising a current user identifier for the current interaction network; determining a first user identifier for a first interaction network based on the current user identifier; determining a second user identifier for a second interaction network based on the current user identifier; determining a first security value corresponding to a first set of interaction data; determining a second security value corresponding to a second set of interaction data; determining an other network total security factor using the first security value and the second security value; determining a security state of one of two states for the current interaction; determining whether or not to adjust the security state to the other of the two states using the other network total security factor; and performing, by the computer, additional processing in relation to the current interaction based on the security state.
[0007] Another embodiment is related to a system comprising: a user device; a processing network computer in a current interaction network; and an analysis computer comprising: a processor; and a non-transitory computer readable medium comprising code, executable by the processor for performing operations comprising: receiving current interaction data related to a current interaction conducted in a current interaction network, the current interaction data comprising a current user identifier for the current interaction network; determining a first user identifier for a first interaction network based on the current user identifier; determining a second user identifier for a second interaction network based on the current user identifier; determining a first security value corresponding to a first set of interaction data; determining a second security value corresponding to a second set of interaction data; determining an other network total security factor using the first security value and the second security value; determining a security state of one of two states for the current interaction; determining whether or not to adjust the security state to the other of the two states using the other network total security factor; and performing, by the computer, additional processing in relation to the current interaction based on the security state.
[0008] Further details regarding embodiments of the disclosure can be found in the Detailed Description and the Figures.BRIEF DESCRIPTION OF THE DRAWINGS
[0009] FIG. 1 shows a block diagram of a network evaluation system according to embodiments.
[0010] FIG. 2 shows a block diagram of components of an analysis computer according to embodiments.
[0011] FIG. 3 shows a diagram illustrating a plurality of networks according to embodiments.
[0012] FIG. 4 shows a diagram illustrating an other network total security factor determination method according to embodiments.
[0013] FIG. 5 shows a diagram illustrating security state adjustment according to embodiments.
[0014] FIG. 6 shows a graph illustrating tuning state adjustment limit values according to embodiments.
[0015] FIG. 7 shows a flowchart of an evaluation method according to embodiments.DETAILED DESCRIPTION
[0016] Prior to discussing embodiments of the disclosure, some terms can be described in further detail.
[0017] A “user” may include an individual or a computational device. In some embodiments, a user may be associated with one or more personal accounts and / or mobile devices. In some embodiments, the user may be a cardholder, account holder, or consumer.
[0018] A “user device” may be a device that is operated by a user. Examples of user devices may include a mobile phone, a smart phone, a card, a personal digital assistant (PDA), a laptop computer, a desktop computer, a server computer, a vehicle such as an automobile, a thin-client device, a tablet PC, etc. Additionally, user devices may be any type of wearable technology device, such as a watch, earpiece, glasses, etc. The user device may include one or more processors capable of processing user input. The user device may also include one or moreinput sensors for receiving user input. As is known in the art, there are a variety of input sensors capable of detecting user input, such as accelerometers, cameras, microphones, etc. The user input obtained by the input sensors may be from a variety of data input types, including, but not limited to, audio data, visual data, or biometric data. The user device may comprise any electronic device that may be operated by a user, which may also provide remote communication capabilities to a network. Examples of remote communication capabilities include using a mobile phone (wireless) network, wireless data network (e.g., 3G, 4G or similar networks), Wi-Fi, Wi-Max, or any other communication medium that may provide access to a network such as the Internet or a private network.
[0019] A “user identifier” can include any piece of data that can identify a user. A user identifier can comprise any suitable alphanumeric string of characters. In some embodiments, the user identifier may be derived from user identifying information. In some embodiments, a user identifier can include an account identifier associated with the user.
[0020] An “interaction” may include a reciprocal action or influence. An interaction can include a communication, contact, or exchange between parties, devices, and / or entities. Example interactions include a transaction between two parties and a data exchange between two devices. In some embodiments, an interaction can include a user requesting access to secure data, a secure webpage, a secure location, and the like. In other embodiments, an interaction can include a payment transaction in which two devices can interact to facilitate a payment.
[0021] “Interaction data” can include data related to and / or recorded during an interaction. In some embodiments, interaction data can be transaction data of the network data. Transaction data can comprise a plurality of data elements with data values.
[0022] An “ interaction network” can include a plurality of computers that operate together to process interactions. An interaction network can be a payment processing network, a blockchain network, a real-time payment network, a card payment network, a data transfer network, a peer-to-peer network, etc. A user can be associated with a user identifier, with which, they are identified in the interaction network.
[0023] A “security value” can include a numerical amount that indicates an amount of being free from threats. A security value can indicate an amount of being free from risk or fraud. A security value can be a calculated value that represents a likelihood of a threat (e.g., a fraudulent interaction) offering. A security value can correspond to a particular interaction network. Eachuser in each different interaction network can be associated with a different security value. For example, a first user in a first interaction network may perform low risk interactions and may thus be associated with a high level security value. A second user in the first interaction network may perform high risk interactions and may thus be associated with a low level security value.
[0024] A “other network total security factor” can include a numerical amount that indicates an amount of being free from threats based on a plurality of interaction networks. A total security value can indicate a user’s total level of security based on their interactions across a plurality of interaction networks.
[0025] A “security state” can include a condition that indicates a security classification. A security state can be determined for and assigned to an interaction. A security state can be in one of two states. For example, a security state can be “fraudulent” or “not fraudulent.” As additional examples, the security state can be “low risk” or “high risk,” “low value” or “high value,” “exposed” or “not exposed,” etc. In some embodiments, a security state can be in one of a plurality of states. For example, a security state can be in one of two states in a set of four states including “no risk,” “low risk,” “medium risk,” and “high risk.” For example, the two states can be “medium risk” and “high risk,” low risk” and “medium risk,” etc.
[0026] An “authorization request message” may be an electronic message that requests authorization for an interaction. In some embodiments, it is sent to a transaction processing computer and / or an issuer of a payment card to request authorization for a transaction. An authorization request message according to some embodiments may comply with International Organization for Standardization (ISO) 8583, which is a standard for systems that exchange electronic transaction information associated with a payment made by a user using a payment device or payment account. The authorization request message may include an issuer account identifier that may be associated with a payment device or payment account. An authorization request message may also comprise additional data elements corresponding to “identification information” including, by way of example only: a service code, a CVV (card verification value), a dCVV (dynamic card verification value), a PAN (primary account number or “account number”), a payment token, a user name, an expiration date, etc. An authorization request message may also comprise “transaction information,” such as any information associated with a current transaction, such as the transaction value, merchant identifier, merchant location, acquirer bank identification number (BIN), card acceptor ID, information identifying itemsbeing purchased, etc., as well as any other information that may be utilized in determining whether to identify and / or authorize a transaction.
[0027] An “authorization response message” may be a message that responds to an authorization request. In some cases, it may be an electronic message reply to an authorization request message generated by an issuing financial institution or a transaction processing computer. The authorization response message may include, by way of example only, one or more of the following status indicators: Approval — transaction was approved; Decline — transaction was not approved; or Call Center — response pending more information, merchant must call the toll-free authorization phone number. The authorization response message may also include an authorization code, which may be a code that a credit card issuing bank returns in response to an authorization request message in an electronic message (either directly or through the transaction processing computer) to the merchant's access device (e.g., POS equipment) that indicates approval of the transaction. The code may serve as proof of authorization.
[0028] An “authorizing entity” may be an entity that authorizes a request. Examples of an authorizing entity may be an issuer, a governmental agency, a document repository, an access administrator, etc. An authorizing entity may operate an authorizing entity computer. An “issuer” may refer to a business entity (e.g., a bank) that issues and optionally maintains an account for a user. An issuer may also issue payment credentials stored on a user device, such as a cellular telephone, smart card, tablet, or laptop to the consumer, or in some embodiments, a portable device.
[0029] A “processor” may include a device that processes something. In some embodiments, a processor can include any suitable data computation device or devices. A processor may comprise one or more microprocessors working together to accomplish a desired function. The processor may include a CPU comprising at least one high-speed data processor adequate to execute program components for executing user and / or system-generated requests. The CPU may be a microprocessor such as AMD's Athlon, Duron and / or Opteron; IBM and / or Motorola's PowerPC; IBM's and Sony's Cell processor; Intel's Celeron, Itanium, Pentium, Xeon, and / or XScale; and / or the like processor(s).
[0030] A “memory” may be any suitable device or devices that can store electronic data. A suitable memory may comprise a non-transitory computer readable medium that stores instructions that can be executed by a processor to implement a desired method. Examples ofmemories may comprise one or more memory chips, disk drives, etc. Such memories may operate using any suitable electrical, optical, and / or magnetic mode of operation.
[0031] A “server computer” may include a powerful computer or cluster of computers. For example, the server computer can be a large mainframe, a minicomputer cluster, or a group of servers functioning as a unit. In one example, the server computer may be a database server coupled to a Web server. The server computer may comprise one or more computational apparatuses and may use any of a variety of computing structures, arrangements, and compilations for servicing the requests from one or more client computers.
[0032] Embodiments of the disclosure provide for an efficient multi-network framework for risk evaluation and false decision correction. Embodiments provide for a framework that evaluates the security of interactions (e.g., financial activities, payment activities, data transfers, etc.) spanning multiple networks. An analysis computer can evaluate the crossdependency of security in an efficient way.
[0033] For any interaction that is to be evaluated in a target network(e.g., a current interaction in a current network), an analysis computer can optimize a classification of a security state based on observations and modeling results from other networks that are external to the target network.
[0034] For example, an analysis computer can receive interaction data for a current interaction between a user device and an interaction network (e.g., resource provider computer in a first network). The analysis computer can identify a user identifier associated with the user device and / or a user that is operating the user device. The analysis computer can identify user identifiers in other interaction networks. The analysis computer can obtain a set of interaction data from each interaction network that the user device and / or the user is associated with. After obtaining the sets of interaction data, the analysis computer can determine a security value based on the set of interactions for each interaction network. The security value can indicate a level of security of the interactions. The analysis computer can generate an other network total security factor based on each security value of each interaction network.
[0035] The analysis computer can determine a security state for the current interaction. The security state can be one of two states (e.g., fraudulent or not fraudulent, risky or not risky, high value or not high value, etc.). The analysis computer can determine the security state using a machine learning model, a statistical model, or other suitable security determination method to classify the current interaction.
[0036] After determining the security state and the other network total security factor, the analysis computer can determine whether or not the security state will be adjusted to the other of the two states using the other network total security factor and a limit value. For example, based on the other network total security factor and the limit value, the analysis computer can determine that the security state is a false positive, a false negative, a true positive, or a true negative. The analysis computer can adjust the security state based on the aforementioned determination.
[0037] As such, the analysis computer can modify the determined security state of a user’s interaction based on other networks within which the user interacts.
[0038] FIG. 1 shows a system 100 according to embodiments of the disclosure. The system 100 comprises a user device 102, an analysis computer 104, a first network 106, a second network 116, and an Nth network 118. The first network 108 can include a resource provider computer 108, transport computer 110, a network processing computer 112, an authorizing entity computer 114, and a user database 120.
[0039] The user device 102 can be in operative communication with the first network 106, the second network 116, and the Nth network 118. The analysis computer 104 can be in operative communication with the first network 106, the second network 116, the Nth network 118, and the user database 120. The user device 102 and the analysis computer 104 can be in operative communication with computers within each network. As an example, the user device 102 can be in operative communication with the resource provider computer 108 in the first network 106. The analysis computer 104 can be in operative communication with the network processing computer 112 in the first network.
[0040] For simplicity of illustration, a certain number of components are shown in FIG. 1. It is understood, however, that embodiments of the invention may include more than one of each component. In addition, some embodiments of the invention may include fewer than or greater than all of the components shown in FIG. 1. For example, the system 100 can include any number of networks.
[0041] Messages between the devices in the system 100 illustrated in FIG. 1 can be transmitted using a secure communications protocols such as, but not limited to, File Transfer Protocol (FTP); HyperText Transfer Protocol (HTTP); Secure Hypertext Transfer Protocol (HTTPS), SSL, ISO (e.g., ISO 8583) and / or the like. The communications network may include any one and / or the combination of the following: a direct interconnection; the Internet; a LocalArea Network (LAN); a Metropolitan Area Network (MAN); an Operating Missions as Nodes on the Internet (OMNI); a secured custom connection; a Wide Area Network (WAN); a wireless network (e.g., employing protocols such as, but not limited to a Wireless Application Protocol (WAP), I-mode, and / or the like); and / or the like. The communications network can use any suitable communications protocol to generate one or more secure communication channels. A communications channel may, in some instances, comprise a secure communication channel, which may be established in any known manner, such as through the use of mutual authentication and a session key, and establishment of a Secure Socket Layer (SSL) session.
[0042] The user device 102 can include a device operated by a user. A user can utilize the user device 102 to perform interactions. The user device 102 can access any network (e.g., the first network 106, the second network 116, the Nth network 118, etc.) to perform an interaction.
[0043] The analysis computer 104 can include a computer or server that is configured to analyze data. However, it is understood that the analysis computer 104 is not limited to only analyzing data. The analysis computer 104 can obtain interaction data from a plurality of networks. The analysis computer 104 can determine a security state for a current interaction performed by the user device 102. The security state can be one of two states (e.g., classified as a fraudulent transaction or a not-fraudulent transaction, a risky interaction or a non-risky interaction, a high value interaction or a low value interaction, etc.). The analysis computer 104 can determine an other network total security factor using the interactions from the networks. The analysis computer 104 can determine whether or not to adjust the security state of the current interaction using the other network total security factor.
[0044] The user device 102 and the analysis computer 104 can be in communication with any number of networks. The networks can be interaction networks. For example, an interaction network can be a card payment network (e.g., credit card and / or debit card networks), a real-time payment network, and a blockchain network (e.g., a cryptocurrency network, a smart contract network, etc.), a secure access network, electronic fund transfer networks, peer-to-peer transfer networks, etc.
[0045] The first network 106 can be a first interaction (e.g., transaction) processing network such as a card payment network. The first network 106 can process interactions performed between a user of the user device 102 and a resource provider of the resource provider computer108. The first network 106 can include the resource provider computer 108, the transport computer 110, the network processing computer 112, and the authorizing entity computer 114.
[0046] The resource provider computer 108 can include any suitable computational apparatus operated by a resource provider (e.g., a merchant). In some embodiments, the resource provider computer 108 may include one or more server computers that may host one or more websites associated with the resource provider (e.g., a merchant). In some embodiments, the resource provider computer 108 may be configured to send data to the network processing computer 112 via the transport computer 110 as part of a payment verification and / or authentication process for a transaction between the user (e.g., consumer) and the resource provider. The resource provider computer 108 may also be configured to generate authorization request messages for transactions between a resource provider and a user, and route the authorization request messages to the authorizing entity computer 114 for transaction processing.
[0047] The transport computer 110 can include a server computer. The transport computer 110 may be associated with an acquirer, which may be an entity (e.g., a commercial bank) that has a relationship with a particular resource provider or other entity. Some entities can perform both issuer and acquirer functions. Some embodiments may encompass such single entity issuer-acquirers.
[0048] The network processing computer 112 can include a server computer. The network processing computer 112 may be disposed between the transport computer 110 and the authorizing entity computer 114. The network processing computer 112 may include data processing subsystems, networks, and operations used to support and deliver authorization services, exception file services, and clearing and settlement services. For example, the network processing computer 112 may comprise a server coupled to a network interface (e.g., by an external communication interface), and databases of information. The network processing computer 112 may be representative of a transaction processing network. An exemplary transaction processing network may include VisaNet™. Transaction processing networks such as VisaNet™ are able to process credit card transactions, debit card transactions, and other types of commercial transactions. VisaNet™, in particular, includes a VIP system (Visa Integrated Payments system) which processes authorization requests and a Base II system which performs clearing and settlement services. The network processing computer 112 may use any suitable wired or wireless network, including the Internet.
[0049] The authorizing entity computer 114 can include a server computer operated by an authorizing entity. The authorizing entity computer 114 may be associated with an authorizing entity, which may be an entity that authorizes a request. An example of an authorizing entity may be an issuer, which may be an entity (e.g., a bank) that maintains an account for a user. An issuer may also issue and manage an account associated with the user device 102.
[0050] The second network 116 and the Nth network 118 can include interaction processing networks. The second network 116 and the Nth network 118 can process interactions in any suitable manner that may be the same as or different from the first network 106. For example, the second network 116 can be a real-time payment network and the Nth network 118 can be a blockchain network.
[0051] The user database 120 can store user accounts for users and / or user devices. The user database 120 can a plurality of user accounts. Each user account can comprise a plurality of user identifiers. For example, a first user account can comprise three user identifiers, where each of the three user identifiers is associated with a different interaction network. The user database 120 can include any suitable database. The database may be a conventional, fault tolerant, relational, scalable, secure database such as those commercially available from Oracle™ or Sybase™.
[0052] FIG. 2 shows a block diagram of an analysis computer 104 according to embodiments. The exemplary analysis computer 104 may comprise a processor 204. The processor 204 may be coupled to a memory 202, a network interface 206, and a computer readable medium 208. The computer readable medium 208 can comprise one or more modules. For example, the computer readable medium 208 can comprise a user identifier module 208A, a security value determination module 208B, a total security factor module 208C, a security state determination module 208D, and a security state adjustment module 208E.
[0053] The memory 202 can be used to store data and code. For example, the memory 202 can store interaction data, identifiers, security values, other network total security factors, machine learning models, machine learning weights, etc. The memory 202 may be coupled to the processor 204 internally or externally (e.g., cloud based data storage), and may comprise any combination of volatile and / or non-volatile memory, such as RAM, DRAM, ROM, flash, or any other suitable memory device.
[0054] The computer readable medium 208 may comprise code, executable by the processor 204, for performing a method comprising: receiving, by a computer, current interaction datarelated to a current interaction conducted in a current interaction network, the current interaction data comprising a current user identifier for the current interaction network; determining, by the computer, a first user identifier for a first interaction network based on the current user identifier; determining, by the computer, a second user identifier for a second interaction network based on the current user identifier; determining, by the computer, a first security value corresponding to a first set of interaction data; determining, by the computer, a second security value corresponding to a second set of interaction data; determining, by the computer, an other network total security factor using the first security value and the second security value; determining, by the computer, a security state of one of two states for the current interaction; and determining, by the computer, whether or not to adjust the security state to the other of the two states using the other network total security factor, wherein the security state is then used to process the current interaction.
[0055] The user identifier module 208A may comprise code or software, executable by the processor 204, for determining, processing, and locating user identifiers. The user identifier module 208A, in conjunction with the processor 204, can identify user identifiers and find user identifiers in other networks.
[0056] The user identifier module 208A, in conjunction with the processor 204, can determine a user identifier for a first interaction network for a current interaction. For example, the user identifier module 208A, in conjunction with the processor 204, can obtain current interaction data that comprises a first user identifier. The user identifier module 208A, in conjunction with the processor 204, can extract the first user identifier from the current interaction data. For example, the first user identifier can be an alphanumeric value, such as “123456789.”
[0057] The user identifier module 208A, in conjunction with the processor 204, can determine a second user identifier for a second interaction network based on the first user identifier. In some embodiments, the user identifier module 208A, in conjunction with the processor 204, can determine the second user identifier based on the first user identifier.
[0058] In some embodiments, the user identifier module 208A, in conjunction with the processor 204, can identify a user that is associated with the first user identifier. The analysis computer 104 can maintain a user database of user accounts. Each user account can be linked to a plurality of user identifiers. The user identifier module 208A, in conjunction with the processor 204, can search the user database for the first user identifier. The user identifiermodule 208A, in conjunction with the processor 204, can identify a user account in the user database that is associated with the first user identifier. The user identifier module 208A, in conjunction with the processor 204, can obtain the second user identifier and any other user identifiers that are stored in association with the user account.
[0059] In other embodiments, the user identifier module 208A, in conjunction with the processor 204, can search the second interaction network for the second user identifier that matches the first user identifier. For example, the user may be associated with the same user identifier in each interaction network. The user identifier module 208A, in conjunction with the processor 204, can identify the second user identifier by searching for (e.g., querying) and locating a user identifier in the second network that matches the first user identifier.
[0060] The security value determination module 208B may comprise code or software, executable by the processor 204, for determining security values. The security value determination module 208B, in conjunction with the processor 204, can determine a security value for a user’s activities in a network. For example, the security value determination module 208B, in conjunction with the processor 204, can obtain a first set of interaction data related to the first user identifier for the first network. The security value determination module 208B, in conjunction with the processor 204, can evaluate the first set of interaction data to determine a first security value for the user in the first network. The security value determination module 208B, in conjunction with the processor 204, can determine a different security value for the user in each different interaction network.
[0061] The security value determination module 208B, in conjunction with the processor 204, can determine the security value based on the data in the set of interaction data. The security value determination module 208B, in conjunction with the processor 204, can determine the security value based on a volume of risky activities associated with the user identifier in the set of interaction data, an amount of risky activities associated with the user identifier in the set of interaction data, a ratio of risky activities to not risky activities associated with the user identifier in the set of interaction data, and / or other data included in the interaction data of the set of interaction data.
[0062] The total security factor module 208C may comprise code or software, executable by the processor 204, for determining and / or otherwise processing a total security factor (e.g., an other network total security factor). The total security factor can be a value that indicates a level of security of a set of networks related to a particular user’s interactions in the networks.In some embodiments, the total security factor is not based on the network within which the current interaction is being performed. In other embodiments, the total security factor is based on the network within which the current interaction is being performed.
[0063] The total security factor module 208C, in conjunction with the processor 204, can obtain a plurality of security values that are associated with a plurality of interaction networks. The total security factor module 208C, in conjunction with the processor 204, can determine the total security factor in any suitable manner.
[0064] In some embodiments, for example, the total security factor module 208C, in conjunction with the processor 204, can determine a sum of each security factor and can utilize the summed value as the total security factor.
[0065] In other embodiments, for example, the total security factor module 208C, in conjunction with the processor 204, can determine a weighted average of each security factor based on the volume or amount of interactions in each set of interactions to be the total security factor.
[0066] The security state determination module 208D may comprise code or software, executable by the processor 204, for determining security states. A security state can a determined classification for an interaction. For example, the security state can be one of two possible states (e.g., fraudulent or not fraudulent, risky or not risky, fake or real, dangerous or safe, etc.). It is understood that in some embodiments, the security state can be a classification of any number of states. For example, a security state can have three states (e.g., low risk, medium risk, and high risk).
[0067] The security state determination module 208D, in conjunction with the processor 204, can determine a security state (also referred to as qnherein) for a current interaction in a current interaction network. The security state determination module 208D, in conjunction with the processor 204, can determine the security state using a machine learning model that is trained to determine security states based on interaction data. The security state determination module 208D, in conjunction with the processor 204, can input the current interaction data into a machine learning model (e.g., a security machine learning model) to determine the security state. For example, the machine learning model can be a deep neural network.
[0068] The security state adjustment module 208E may comprise code or software, executable by the processor 204, for adjusting the security state. The security state adjustmentmodule 208E, in conjunction with the processor 204, can modify the security state based on the total security factor. In some embodiments, the security state adjustment module 208E, in conjunction with the processor 204, can also modify the security state based on a determined limit value, as described in further detail herein.
[0069] For example, the security state adjustment module 208E, in conjunction with the processor 204, can adjust the security state of “not fraudulent” to “fraudulent” based on the total security factor that indicates risky and / or fraudulent behavior by the user in other interaction networks.
[0070] The network interface 206 may include an interface that can allow the analysis computer 104 to communicate with external computers. The network interface 206 may enable the analysis computer 104 to communicate data to and from another device (e.g., the first network 106, the second network 116, the Nth network 118, etc.). Some examples of the network interface 206 may include a modem, a physical network interface (such as an Ethernet card or other Network Interface Card (NIC)), a virtual network interface, a communications port, a Personal Computer Memory Card International Association (PCMCIA) slot and card, or the like. The wireless protocols enabled by the network interface 206 may include Wi-FiTM. Data transferred via the network interface 206 may be in the form of signals which may be electrical, electromagnetic, optical, or any other signal capable of being received by the external communications interface (collectively referred to as “electronic signals” or “electronic messages”). These electronic messages that may comprise data or instructions may be provided between the network interface 206 and other devices via a communications path or channel. As noted above, any suitable communication path or channel may be used such as, for instance, a wire or cable, fiber optics, a telephone line, a cellular link, a radio frequency (RF) link, a WAN or LAN network, the Internet, or any other suitable medium.
[0071] FIG. 3 shows a diagram illustrating a plurality of networks according to embodiments. FIG. 3 illustrates a user account 302 that is associated with a plurality of networks including the first network 106, the second network 116, and the Nth network 118.
[0072] A user can open, maintain, and / or utilize the user account 302. The user account 302 can be store or otherwise be associated with a user account identifier. The user account can include a plurality of user identifiers of the user for each interaction network. The user identifiers of the plurality of user identifiers can identify the user’s network account in eachinteraction network. The user account 302 can be utilized to identify the user’s network accounts in each interaction network.
[0073] An account holder (e.g., user) associated with the user account 302 can be active in one or more networks as illustrated in FIG. 3. Interactions can be performed in parallel or following a sequence, depending on the nature of the networks. The user can perform interactions with each of the interaction networks of the plurality of interaction networks. Interaction data from each interaction can be stored in the interaction network within which the interaction was performed.
[0074] The interactions depicted in FIG. 3 are illustrated in order of time of performance from left to right. For example, the user can first perform an interaction A 304 in the first network 106. At some point later in time, the user can perform an interaction B 306 in the second network 116. The user can then perform an interaction C 308 in the first network 106. The user can then perform an interaction D 310 in the Nth network 118. The user can then perform an interaction E 312 in the second network 116. The user can then perform an interaction F 314 in the first network 106. The user can then perform an interaction G 316 in the first network 106. The user can then perform an interaction H 318 in the second network 116. The user can then perform an interaction I 320 in the Nth network 118.
[0075] Each interaction in each different interaction can be associated with different interaction data. For example, interactions in the first network 106 can include interaction data such as user identifier, resource provider identifier, amount, and user credential (e.g., primary account number, account token, etc.), as in a card transaction network. Interactions in the second network 116 can include interaction data such as sending user identifier, receiving user identifier, amount, date, and time, as in a peer-to-peer network. Interactions in the Nth network 118 can include a version number, an input transaction identifier, an output amount, a witness, and a time, as in a blockchain network.
[0076] FIG. 4 shows a diagram illustrating an other network total security factor determination method according to embodiments. The method can be performed by a computer, such as the analysis computer 104. FIG. 4 illustrates the user account 302 being associated with an interaction 402. The interaction 402 can be an interaction in a target network (e.g., a current interaction in a current network) that is to be evaluated and determined as being in a particular state of two states (e.g., being classified as fraud or classified as not fraud). Theinteraction 402 can be a current interaction. The interaction 402 can be an interaction that was not processed by the first network 106, the second network 116, or the Nth network 118.
[0077] For example, the interaction 402 can be currently processed by a third network (not shown). A computer in the third network (e.g., a network processing computer, such as the network processing computer 112 as illustrated in FIG. 1) can provide current interaction data for the current interaction to the analysis computer 104 for security analysis. The current interaction data can include a third user identifier for the user in the third interaction network.
[0078] Upon receiving the current interaction data, the analysis computer 104 can identify the user account 302 that includes the third user identifier. For example, the analysis computer 104 can search a user database using the third user identifier to locate the user account 302.
[0079] After identifying the user account 302 based on the third user identifier in the interaction 402, the analysis computer 104 can obtain a plurality of user identifiers in the user account 302. For example, the user account 302 can include a first user identifier, a second user identifier, the third user identifier, and an Nth user identifier. Each user identifier can be associated with a different interaction network and may be stored in association with an interaction network identifier that identifies the corresponding interaction network.
[0080] The analysis computer 104 can query each interaction network of a plurality of interaction networks for a set of interaction data related using the plurality of user identifiers. The analysis computer 104 can query each interaction network that is not the current interaction network (e.g., the third interaction network). For example, the analysis computer 104 can query the first network 106, the second network 116, and the Nth network 118 for interaction data that relates to the user identifier for that interaction network.
[0081] For example, the analysis computer 104 can generate a first interaction data request message comprising the first user identifier for the first network 106. The analysis computer 104 can generate a second interaction data request message comprising the second user identifier for the second network 116. The analysis computer 104 can generate an Nth interaction data request message comprising the Nth user identifier for the Nth network 118.
[0082] The analysis computer 104 can respectively send the first interaction data request message, the second interaction data request message, and the Nth interaction data request message to the first network 106, the second network 116, and the Nth network 118.
[0083] The analysis computer 104 can obtain a first set of interaction data (e.g., transaction data) associated with first interactions conducted using the first network 106 from the first network 106. The analysis computer 104 can obtain a second set of interaction data associated with second interactions conducted using the second network 116 from second network 116. The analysis computer 104 can obtain an Nth set of interaction data associated with Nth interactions conducted using the Nth network 118 from the Nth network 118. The obtained interaction data can be interactions that involve the user of the user account 302.
[0084] In some embodiments, the analysis computer 104 can query and obtain interactions from the interactions networks that occurred within a certain time window (e.g., starting from a datetime of the current interaction and ending a certain time in the past). For example, the analysis computer 104 can query each interaction network for interactions that occurred within the last week and that are associated with the relevant user identifier. Depending on the nature of the networks (e.g., frequency of normal and risky activities, frequency of data updating, etc.), the analysis computer 104 can utilize different time windows with short-term and / or longterm values (e.g., 1 hour, 6 hours, 1 day, 7 days, 30 days, etc.). In some embodiments, the time window can be optimized to provide the best performance based on false positive (FP) and false negative (FN) corrections together with tuned limit values, as described in further detail herein.
[0085] After receiving the sets of interaction data from each interaction network, the analysis computer 104 can determine a security value rtfor each interaction network using the sets of interaction data. The analysis computer 104 can determine a first security value rx404 for the first network 106 using the first set of interaction data. The analysis computer 104 can determine a second security value r2406 for the second network 116 using the second set of interaction data. The analysis computer 104 can determine an Nth security value rN408 for the Nth network 118 using the Nth set of interaction data.
[0086] The analysis computer 104 can determine each security value for each interaction network based on the interactions that were obtained from the interaction network. For example, the analysis computer 104 can determine the security value as a volume of risky activities or an amount of risky activities. For example, the security value can be a number of interactions in the network involving the user account 302 that are labelled (by the network) as being risky. In some embodiments, the analysis computer 104 can evaluate each obtained interaction and determine whether or not the interaction is risky using a classification process,such as a machine learning model that is trained to classify interactions as risky or not risky, fraud or not fraud, low risk or high risk, or other suitable classification scheme.
[0087] After determining the first security value r 404, the second security value r2406, and the Nth security value rN408, the analysis computer can determine an other network total security factor qn410. The analysis computer 104 can determine the other network total security factor qn410 using each determined security value. For example, the analysis computer 104 can determine the other network total security factor qn410 using the first security value rx404, the second security value r2406, and the third security value r3408.
[0088] The analysis computer 104 can determine the other network total security factor qn410 by determining a ratio of the sum of all security values for the queried networks to the total number of interactions queried from the networks. The analysis computer 104 can determine the other network total security factor qn410 by determining:
[0089] In some embodiments, the other network total security factor qn410 can be a percentage (and can alternatively referred to as qn° / o). The other network total security factor qn410 can be a percentage of the number of risky interactions to the total number of interactions.
[0090] In some embodiments, the analysis computer 104 can determine the other network total security factor qn410 as a sum of the first security value rx404, the second security value r2406, and the Nth security value rN408.
[0091] In other embodiments, the analysis computer 104 can determine the other network total security factor qn410 as an average of the first security value r 404, the second security value r2406, and the Nth security value rN408.
[0092] FIG. 5 shows a diagram illustrating security state adjustment according to embodiments. FIG. 5 illustrates a positive security state adjustment process 500 and a negative security state adjustment process 510. A positive security state can include a security state that indicates low security or high risk. A negative security state can include a security state that indicates high security or low risk.
[0093] During the positive security state adjustment process 500, for an input positive security state 502 from a network n for an interaction, the analysis computer 104 can aim to reduce false positives (FP), while retaining true positives (TP), based on a risk level of queried interactions in the other networks. The analysis computer 104 can determine whether or not to adjust the input positive security state 502 based on the other network total security factor qn. The analysis computer 104 can compare the other network total security factor qnto a limit value. When the security state is the input positive security state 502, the analysis computer 104 can compare the other network total security factor qnto a limit value that is a false positive limit value limP, which can sometimes be referred to as limP% in some cases.
[0094] The analysis computer 104 can determine whether to revert (e.g., adjust) the input positive security state 502 to an output negative security state 506 for the interaction or to maintain the input positive security state 502 as an output positive security state 504. The analysis computer 104 can determine to adjust the input positive security state 502 if the other network total security factor qnis below a certain limit value (e.g., below the false positive limit value limp). A small other network total security factor qncan imply an overall low risk in the connected networks. This adjustment of the input positive security state 502 can provide a set of new decisions for the predicted positive security states that are adjusted. A low limPmay have little impact on FP corrections, while a high limPmay yield a false negative (FN). Determining an optimal limit value limPis described in reference to FIG. 6.
[0095] As an example, the positive state adjustment 502 can be a process that may occur when a first interaction is predicted as having a positive security state (e.g., as being fraudulent, risky, high value, etc.) by a classification process that classifies interactions as positive or negative. The analysis computer 104 can compare the other network total security factor qn(e.g., as determined as described in reference to FIG. 4) to a first limit value limP. If the other network total security factor qnis greater than or equal to the first limit value limP, then the analysis computer 104 can determine that the security state of the first interaction is to stay as a current state (e.g., stay as predicted as fraudulent). If the other network total security factor qnis less than the first limit value limP, then the analysis computer 104 can determine that the security state of the first interaction is to change to the other state of the two states (e.g., change from being predicted as fraudulent to not fraudulent).
[0096] During the negative security state adjustment process 510, for an input negative security state 512 from the network n, the analysis computer 104 aims to reduce false negatives(FN), while retaining true negatives (TN), based on a risk level of queried interactions in the other networks. The analysis computer 104 can determine whether or not to adjust the input negative security state 512 based on the other network total security factor qn. The analysis computer 104 can compare the other network total security factor qnto a limit value. When the security state is the input negative security state 512, the analysis computer 104 can compare the other network total security factor qnto a limit value that is a false negative limit value limP.
[0097] The analysis computer 104 can determine whether to adjust the input negative security state 512 to an output negative security state 516 for the interaction or to maintain the input negative security state 512 as an output negative security state 514. The analysis computer 104 can determine to adjust the input negative security state 512 if the other network total security factor qnis below a certain limit value (e.g., below the false negative limit value limN). limNcan alternatively be referred to as limN% in some cases. A large other network total security factor qncan imply an overall high risk in the connected networks. This adjustment of the input negative security state 512 can provide a set of new decisions for the predicted negative security states that are adjusted. A high limNmay have little impact on false negative corrections, while a low limNmay yield false positives. Determining an optimal limit value limPis described in reference to FIG. 6.
[0098] As an example, the negative state adjustment 510 can be a process that may occur when a second interaction is predicted as being having a negative security state (e.g., as being not fraudulent, not risky, low value, etc.) by a classification process that classifies interactions as positive or negative. The analysis computer 104 can compare the other network total security factor qnto a second limit value limN. If the other network total security factor qnis less than the second limit value limN, then the analysis computer 104 can determine that the security state of the second interaction is to stay as a current state (e.g., stay as predicted as not fraudulent). If the other network total security factor qnis greater than or equal to the second limit value limN, then the analysis computer 104 can determine that the security state of the second interaction is to change to the other state of the two states (e.g., change from being predicted as not fraudulent to fraudulent).
[0099] FIG. 6 shows a graph illustrating tuning state adjustment limit values according to embodiments. The graph illustrated in FIG. 6 illustrates tuning a first limit value (e.g., a false positive limit value limp) and a second limit value (e.g., a false negative limit value limN). Ingeneral, false positives and false negatives are negatively correlated. The analysis computer 104 can balance the two metrics when performing decision optimization. By checking how the two metrics vary with different false positive limit values limPand false negative limit values limN, the analysis computer 104 can determine an optimal rule for decision correction. For example, the analysis computer 104 can determine and utilize a combination of the limit values [limP, limN] that gives optimal rates of false positives and false negatives.
[0100] Tuning the limit values [limP, limN] is a bi-variate optimization problem, which can be solved by searching or non-parametric optimization algorithms, using validation data (which can have ground truth risk labels) in a risk modeling system. The analysis computer 104 can perform any suitable optimization method to optimize the false positive rates and false negative rates by changing the first limit value limPand the second limit value limN.
[0101] FIG. 6 includes a graph 600 that illustrates a false positive rate and a false negative rate as the first limit value limPand the second limit value limNare changed (e.g., on the x- axis) from 0 to 1. The graph illustrates example points along the x-axis, including a first point 602, a second point 604, and a third point 606. The y-axis of the graph 600 indicates false negative rates and false positive rates.
[0102] The first point 602 illustrates an example point at which the false negative rate is smallest. If the first limit value limpand the second limit value limNare tuned (e.g., along the x-axis) to yield the first point 602, then the false negative rate can be minimized, however, the false positive rate is not.
[0103] The second point 604 illustrates an example point at which the false positive rate is smallest. If the first limit value limpand the second limit value limNare tuned (e.g., along the x-axis) to yield the second point 604, then the false positive rate can be minimized, however, the false negative rate is not.
[0104] The third point 606 illustrates an example point at which the sum of the false negative rate and the false positive rate is smallest. If the first limit value limpand the second limit value limNare tuned (e.g., along the x-axis) to yield the third point 606, then the sum of the false negative rate and the false positive rate can be minimized.
[0105] FIG. 7 shows a flowchart of an evaluation method according to embodiments. The method illustrated in FIG. 7 will be described in the context of the analysis computer 104 receiving current interaction data for a current interaction. The analysis computer 104 candetermine security state for the current interaction and determine an other network total security factor based on interactions in other interaction networks. The analysis computer 104 can adjust the security state based on the other network total security factor.
[0106] The method illustrated in FIG. 7 can be performed by the analysis computer 104, the user database 120, a current network computer 702, a first network computer 704, and a second network computer 706. The current network computer 702 can be a computer in a current interaction network. For example, the current network computer 702 can be a network processing computer (e.g., such as the network processing computer 112 illustrated in FIG. 1). The first network computer 704 can be a computer in a first interaction network. For example, the first network computer 704 can be a network processing computer in the first interaction network. The second network computer 706 can be a computer in a second interaction network. For example, the second network computer 706 can be a node computer in a blockchain network that is the second interaction network.
[0107] At step 708, the current network computer 702 can generate a security state request message. The security state request message can comprise current interaction data for a current interaction that is being processed by the current interaction network. The current interaction can involve a user of a user device and a resource provider of a resource provider computer, for example.
[0108] The current interaction data can comprise a current user identifier. The current user identifier can identify a user and / or a user device that is involved in the current interaction. The current interaction data can include additional data. For example, the current interaction data can include a date, a time, a primary account number, an amount, a resource provider identifier, and / or other data that indicates information regarding the entities involved in the interaction and / or how the interaction is processed.
[0109] As an illustrative example, the current interaction data can include a current user identifier of “1122334455,” a date of “01-01-2025,” a time of “1 :00 PM,” a primary account number of “01234567890123456,” an amount of “$800,” a resource provider identifier of “00000123,” an interaction number of “123,” and an interaction type of “purchase.”
[0110] At step 710, the current network computer 702 can provide the security state request message to the analysis computer 104.[OHl] After receiving the security state request message comprising the current interaction data, the analysis computer 104 can obtain data to aid in the determination of a first user identifier based on the current user identifier. The first user identifier can identify the user and / or the user device in the first interaction network. For example, the analysis computer 104 and the user database 120 can perform steps 714-720 to allow the analysis computer 104 to obtain data that aids in the determination of the first user identifier.
[0112] At step 712, the analysis computer 104 can query the user database using the current user identifier to determine the user account. The analysis computer 104 can generate a user account request message comprising the current user identifier. The user and / or the user device can be associated with a user account that is associated with a plurality of user identifiers. The user account can be stored in the user database 120 in association with the plurality of user identifiers.
[0113] At step 714, the analysis computer 104 can provide the user account request message to the user database 120.
[0114] At step 716, after receiving the user account request message, the user database 120 can identify the user account stored in memory using the current user identifier. For example, the user account can include the current user identifier and can be located in memory thereby. The user database 120 can generate a user account response message comprising the user account.
[0115] At step 718, the user database 120 can provide the user account response message to the analysis computer 104 in response to the user account request message.
[0116] At step 720, after receiving the user account response message, the analysis computer 104 can determine a first user identifier using the user account. For example, the analysis computer 104 can obtain the plurality of user identifiers that are associated with the user account. Each user identifier of the plurality of user identifiers can be stored in association with or can otherwise indicate within which interaction network the user identifier is utilized. The analysis computer 104 can obtain the first user identifier from the plurality of user identifiers.
[0117] In other embodiments, the analysis computer 104 can determine the first user identifier by searching the first interaction network for a first user identifier that matches the current user identifier. In such a case, the first user identifier and the current user identifier can be the same value.
[0118] At step 722, the analysis computer 104 can determine a second user identifier based on the current user identifier. The second user identifier can identify the user and / or the user device in the second interaction network. The analysis computer 104 can determine the second user identifier using the user account.
[0119] At step 724, the analysis computer 104 can generate a first interaction data request message. The first interaction data request message can comprise the first user identifier. The first interaction data request message can request a first set of interaction data from the first interaction network. The analysis computer 104 can provide the first interaction data request message to the first network computer 704, or any computer in the first interaction network capable of obtaining the first set of interaction data.
[0120] In some embodiments, the analysis computer 104 can determine a time range (e.g., a look-back window) to use as a filter for the interactions. The time range can be 10 minutes, 1 hour, 3 hours, 12 hours, 1 day, 3 days, 1 week, 1 month, 6 months, 1 year, or other length of time. The analysis computer 104 can include the time range into the first interaction data request message.
[0121] In some embodiments, the time range can be determined based on the type of network that the first interaction data request message is to be provided. For example, some interaction networks process interactions more frequently than other networks. An interaction network that processes interactions more frequently can have a smaller time range than an interaction network that processes interactions infrequently.
[0122] At step 726, after receiving the first interaction data request message, the first network computer 704 can create the first set of interaction data using the first user identifier. The first network computer 704 can identify interactions and associated interaction data that were processed by the first interaction network and are associated with the first user identifier. For example, each instance of interaction data can contain the first user identifier for which the user and / or the user device was involved. The first network computer 704 can generate the first set of interaction data by identifying and collecting such interaction data.
[0123] In some embodiments, if the first interaction data request message includes the time range, then the first network computer 704 can filter the obtained interactions based on the time range when forming the first set of interaction data.
[0124] The first network computer 704 can generate a first interaction data response message comprise the first set of interaction data.
[0125] At step 728, the first network computer 704 can provide the first interaction data response message to the analysis computer 104. The analysis computer 104 can obtain the first set of interaction data associated with first interactions conducted using the first interaction network. The first set of interaction data can include interaction data from interactions that involve the first user identifier.
[0126] At step 730, the analysis computer 104 can generate a second interaction data request message. The second interaction data request message can comprise the second user identifier. The second interaction data request message can request a second set of interaction data from the second interaction network. The analysis computer 104 can provide the second interaction data request message to the second network computer 706, or any computer in the second interaction network capable of obtaining the second set of interaction data.
[0127] At step 732, after receiving the second interaction data request message, the second network computer 706 can create the second set of interaction data using the second user identifier. The second network computer 706 can identify interactions and associated interaction data that were processed by the second interaction network and are associated with the second user identifier. For example, each instance of interaction data can contain the second user identifier for which the user and / or the user device was involved. The second network computer 706 can generate the second set of interaction data by identifying and collecting such interaction data.
[0128] The second network computer 706 can generate a second interaction data response message comprise the second set of interaction data.
[0129] At step 734, the second network computer 706 can provide the second interaction data response message to the analysis computer 104. The analysis computer 104 can obtain the second set of interaction data associated with second interactions conducted using the second interaction network. The second set of interaction data can include interaction data from interactions that involve the second user identifier.
[0130] At step 736, after obtaining the first set of interaction data, the analysis computer 104 can determine a first security value corresponding to the first set of interaction data. The analysis computer 104 can determine the first security value based on the interaction dataincluded in the first set of interaction data. For example, the first security value can be a total number of interactions labeled as a particular security state (e.g., a positive security state such as risky or fraudulent) in the first set of interaction data.
[0131] In some embodiments, the first security value can be a total amount that is a sum of the amounts in each instance of interaction data in the set of interaction data for risky (positive security state) interactions. In other embodiments, the first security value can be a ratio of interactions that have a positive security state to interactions that have a negative security state.
[0132] As an illustrative example, the first set of interaction data can include interaction data for 10 interactions. The analysis computer 104 can analyze a security state of each of the 10 instances of interaction data. The analysis computer 104 can determine that 2 of the 10 instances are labeled with positive security states that indicate that the interactions were risky. The analysis computer 104 can determine that the first security value is equal to 20%.
[0133] At step 738, the analysis computer 104 can determine a second security value corresponding to the second set of interaction data. The analysis computer 104 can determine the second security value based on the interaction data included in the second set of interaction data. For example, the second security value can be a total number of interactions labeled as a particular security state (e.g., a positive security state such as risky or fraudulent) in the second set of interaction data.
[0134] As an illustrative example, the second set of interaction data can include interaction data for 55 interactions. The analysis computer 104 can analyze a security state of each of the 55 instances of interaction data. The analysis computer 104 can determine that 15 of the 55 instances are labeled with positive security states that indicate that the interactions were risky. The analysis computer 104 can determine that the second security value is equal to 27%.
[0135] At step 740, the analysis computer 104 can determine an other network total security factor qnusing the first security value and the second security value. The analysis computer 104 can combine the first security value and the second security value in different manners to form the other network total security factor qn.
[0136] For example, in some embodiments, the analysis computer 104 can determine the other network total security factor qnas being the ratio of interactions labelled as risky in the first set of interactions and the second set of interactions to the total number of interactions in the first set of interactions and the second set of interactions.
[0137] For example, in some embodiments, the analysis computer 104 can determine the other network total security factor qnas being the weight average of the first security value and the second security value. As an illustrative example, the first security value can be a value of 20% with 10 total interactions and the second security value can be a value of 27% with 55 total interactions. The analysis computer 104 can determine the other network total security factor qnas follows:
[0138] At step 742, the analysis computer 104 can determine a security state of one of two states for the current interaction. For example, the analysis computer 104 can perform a classification process to classify the interaction as a first state or a second state. The analysis computer 104 can utilize a machine learning model that is trained to classify an interaction as being fraudulent (e.g., the first state) or as being not fraudulent (e.g., the second state).
[0139] As an illustrative example, the analysis computer 104 can determine a negative security state (e.g., not fraudulent or low risk) for the current interaction, based on the current interaction itself and / or the user’s and / or user device’s history in the current interaction network. For example, the user can be typically associated with low risk interactions in the current interaction network.
[0140] At step 744, the analysis computer 104 can determine whether or not to adjust the security state to the other of the two states using the other network total security factor qnand a limit value. The analysis computer 104 can compare the other network total security factor qnto the limit value. The limit value can be a false positive limit value limPor a false negative limit value limN.
[0141] If the current interaction is determined to have a positive security state (e.g., high risk), then the analysis computer 104 can compare the other network total security factor qnto a limit value that is a false positive limit value limP. If the other network total security factor qnis greater than or equal to the false positive limit value limp, then the analysis computer 104 can determine that the security state of the current interaction is to stay as the current security state (e.g., stay as predicted as high risk). If the other network total security factor qnis less than the false positive limit value limP, then the analysis computer 104 can determine that the security state of the current interaction is to be adjusted to the other state of the two states (e.g., change from being predicted as high risk to low risk).
[0142] If the current interaction is determined to have a negative security state (e.g., low risk), then the analysis computer 104 can compare the other network total security factor qnto a limit value that is a false negative limit value limN. If the other network total security factor qnis less than the false negative limit value limN, then the analysis computer 104 can determine that the security state of the current interaction is to stay as the current security state (e.g., stay as predicted as low risk). If the other network total security factor qnis greater than or equal to the false negative limit value limN, then the analysis computer 104 can determine that the security state of the current interaction is to be adjusted to the other state of the two states (e.g., change from being predicted as low risk to high risk).
[0143] As an illustrative example, the other network total security factor qncan be equal to a value of 25.9%. Since the current interaction is associated with a negative security state (e.g., not fraudulent or low risk), the analysis computer 104 can compare the other network total security factor qnto the false negative limit value limNto determine whether or not the negative security state is a false negative in view of the information obtained from the other networks. The analysis computer 104 can compare the other network total security factor qnof 25.9% to a false negative limit value limNof, for example, 30%. The other network total security factor qnis less than the false negative limit value limN. The analysis computer 104 can determine to adjust the security state for the current interaction. The analysis computer 104 can adjust the security state of the current interaction from a negative security state (e.g., low risk) to a positive security state (e.g., high risk). The adjustment from the negative security state to the positive security state allows the analysis computer 104 to influence the security state of the current interaction in the current interaction network based on the user’ s interactions in other networks. In this example, the user is associated with many high risk interactions in other networks, and thus the security state of the current interaction is commensurately adjusted.
[0144] At step 744, after determining the security state, the analysis computer 104 can generate a security state response message. The security state response message can comprise the security state. The security state response message can also include the current user identifier and the current interaction data. The analysis computer 104 can provide the security state response message to the current network computer 702 in response to the security state request message received at step 710.
[0145] After receiving the security state request message, the current network computer 702 can evaluate the security state determined and potentially adjusted by the analysis computer 104. The current network computer 702 can determine whether or not to continue processing the current interaction depending on the value of the security state. For example, in some embodiments, if the security state indicates high risk or fraud, then the current network computer 702 can deny the interaction and / or otherwise stop processing the interaction. If the security state indicates low risk or fraud, then the current network computer 702 can approve the interaction and / or otherwise continue processing the interaction.
[0146] In some embodiments, if the current network computer 702 is a network processing computer, then the current network computer 702 can communicate with an authorizing entity computer to approve the current interaction. For example, the current network computer 702 can provide an authorization request message comprising the current interaction data and, in some embodiments, the security state, to the authorizing entity computer. The authorizing entity computer can determine whether or not to authorize the current interaction based on the current interaction data, the security state, and / or other data accessible by the authorizing entity computer. The authorizing entity computer can generate an indication of whether or not the current interaction is authorized. The authorizing entity computer can provide an authorization response message comprising the indication and the current interaction data to the current network computer 702 in response. The current network computer 702 can provide, via a transport computer, the authorization response message to a resource provider computer that is involved in the current interaction with the user device.
[0147] In some embodiments, the analysis computer 104 can perform additional processing on the current interaction based on the security state.
[0148] For example, the analysis computer 104 can deny the current interaction. If the security state is a state that indicates a predetermined denial state such as “fraudulent,” then the analysis computer 104 can deny the current interaction. The analysis computer 104 can generate an indicator that indicates that the current interaction is denied. The analysis computer 104 can include the indicator in the current interaction data and / or in the security state response message.
[0149] As another example, the analysis computer 104 can approve the current interaction. If the security state is a state that indicates a predetermined denial state such as “safe,” then the analysis computer 104 can approve the current interaction. The analysis computer 104 cangenerate an indicator that indicates that the current interaction is approved. The analysis computer 104 can include the indicator in the current interaction data and / or in the security state response message.
[0150] As another example, the analysis computer 104 can modify the current interaction data itself to include the security state. In some embodiments, the analysis computer 104 can digitally sign the security state using an analysis computer private key that corresponds to an analysis computer public key that can be accessible by other devices using a digital certificate.
[0151] In another example, the analysis computer 104 can perform an additional process to automatically block further interactions from the parties conducting the current interaction. This might be done, if for example, one of the parties to the interaction is performing fraudulent or nefarious activities. Some ways to automatically block further interactions may be to put one or both of the parties or their IP addresses on a negative list so that further actions from the one or both of the parties are not processed.
[0152] In another example, the analysis computer 104 can perform an additional process to take further security measures on the interaction or parties to the interaction. For example, additional authentication processes (e.g., one time passwords or the like) may be invoked in response to the security state.
[0153] The aforementioned example describes interaction networks that include payment processing networks. However, it is understood that embodiments are not limited thereto. For example, a system can include a plurality of interaction networks that are social media networks. An interaction can include a social media post or other action performed by a user and / or a user device on a particular social media network. During a current interaction (e.g., a current attempt by a user device at posting a message to the social media network), the analysis computer 104 can determine a security state for the current interaction. The security state can indicate whether or not the post is created and / or performed by a bot or by a human. The analysis computer 104 can analyze data from other networks, as described herein, to determine an other network total security factor based on actions performed by the user device in other networks. The analysis computer 104 can determine whether or not to adjust the security state of the current interaction based on the other network total security factor. For example, the user device may be associated with posts by bots on other social media networks, but the current interaction is associated with a security state of human. The person running the bot may try to first post more human created looking posts on a social media network and then later post botcreated posts to try to build credibility for the bot. However, the analysis computer 104, using the information obtained from other social media networks, can adjust the current security state to bot from human to identify the account as being associated with a bot. In some embodiments, the analysis computer 104 can label the account related to the current interaction as being a bot account. In this example, additional processing may include closing the account associated with the current interaction because it is likely to be a fake account.
[0154] Embodiments of the disclosure have a number of advantages. For example, embodiments provide for a framework for risk evaluation, which efficiently considers the dependency across networks into the decision-making process. Different networks can be connected through account holders, and the measured risk of different types of activities can support any target network.
[0155] Embodiments further reduce both false positive errors and false negative errors made from network-specific security state determinations. An analysis computer can adjust the security state to be more accurate based on evaluations performed using select data from other interaction networks. During experimentation, the false positive and false negative ratio was significantly reduced.
[0156] Although the steps in the flowcharts and process flows described above are illustrated or described in a specific order, it is understood that embodiments of the invention may include methods that have the steps in different orders. In addition, steps may be omitted or added and may still be within embodiments of the invention.
[0157] Any of the software components or functions described in this application may be implemented as software code to be executed by a processor using any suitable computer language such as, for example, Java, C, C++, C#, Objective-C, Swift, or scripting language such as Perl or Python using, for example, conventional or object-oriented techniques. The software code may be stored as a series of instructions or commands on a computer readable medium for storage and / or transmission, suitable media include random access memory (RAM), a read only memory (ROM), a magnetic medium such as a hard-drive or a floppy disk, or an optical medium such as a compact disk (CD) or DVD (digital versatile disk), flash memory, and the like. The computer readable medium may be any combination of such storage or transmission devices.
[0158] Such programs may also be encoded and transmitted using carrier signals adapted for transmission via wired, optical, and / or wireless networks conforming to a variety of protocols,including the Internet. As such, a computer readable medium according to an embodiment of the present invention may be created using a data signal encoded with such programs. Computer readable media encoded with the program code may be packaged with a compatible device or provided separately from other devices (e.g., via Internet download). Any such computer readable medium may reside on or within a single computer product (e.g., a hard drive, a CD, or an entire computer system), and may be present on or within different computer products within a system or network. A computer system may include a monitor, printer, or other suitable display for providing any of the results mentioned herein to a user.
[0159] The above description is illustrative and is not restrictive. Many variations of the invention will become apparent to those skilled in the art upon review of the disclosure. The scope of the invention should, therefore, be determined not with reference to the above description, but instead should be determined with reference to the pending claims along with their full scope or equivalents.
[0160] One or more features from any embodiment may be combined with one or more features of any other embodiment without departing from the scope of the invention.
[0161] As used herein, the use of "a," "an," or "the" is intended to mean "at least one," unless specifically indicated to the contrary.
Claims
WHAT IS CLAIMED IS:
1. A method compri sing : receiving, by a computer, current interaction data related to a current interaction conducted in a current interaction network, the current interaction data comprising a current user identifier for the current interaction network; determining, by the computer, a first user identifier for a first interaction network based on the current user identifier; determining, by the computer, a second user identifier for a second interaction network based on the current user identifier; determining, by the computer, a first security value corresponding to a first set of interaction data; determining, by the computer, a second security value corresponding to a second set of interaction data; determining, by the computer, an other network total security factor using the first security value and the second security value; determining, by the computer, a security state of one of two states for the current interaction; determining, by the computer, whether or not to adjust the security state to the other of the two states using the other network total security factor; and performing, by the computer, additional processing in relation to the current interaction based on the security state.
2. The method of claim 1, further comprising: obtaining, by the computer, the first set of interaction data associated with first interactions conducted using the first interaction network and the first user identifier; and obtaining, by the computer, the second set of interaction data associated with second interactions conducted using the second interaction network and the second user identifier.
3. The method of claim 1, wherein the current user identifier, the first user identifier, and the second user identifier are associated with a same user.
4. The method of claim 1, further comprising:determining, by the computer, a third user identifier for a third interaction network based on the current user identifier; obtaining, by the computer, a third set of interaction data associated with third interactions conducted using the third interaction network and the third user identifier; and determining, by the computer, a third security value corresponding to the third set of interaction data.
5. The method of claim 4, wherein determining the other network total security factor comprises: determining, by the computer, the other network total security factor using the first security value, the second security value, and the third security value .
6. The method of claim 1, wherein each interaction network is one of a card network, a real-time processing network, a social network, and a blockchain network.
7. The method of claim 1, wherein determining the first user identifier comprises: searching, by the computer, the first interaction network for the first user identifier that matches the current user identifier.
8. The method of claim 1, wherein determining the first user identifier comprises: identifying, by the computer, a user account in a user database that corresponds to the current user identifier; and determining, by the computer, the first user identifier using the user account.
9. The method of claim 1, wherein determining whether or not to adjust the security state to the other of the two states comprises: determining, by the computer, whether or not to adjust the security state to the other of the two states using the other network total security factor and a limit value, wherein the limit value is a false positive limit value or a false negative limit value.
10. The method of claim 1, wherein the current interaction data comprises a timestamp, an amount, and identifiers of parties to the interaction.
11. The method of claim 1, wherein additional processing includes initiating further authentication processing of parties to the interaction.
12. The method of claim 1, wherein the security state indicates that an account associated with the first user identifier is likely to be a fake account, and additional processing comprises automatically closing the account associated with the current user identifier.
13. The method of claim 1, wherein determining the security state comprises: inputting, by the computer, the current interaction data into a machine learning model that is trained to classify interaction data as being associated with a particular security state; and obtaining, by the computer from the machine learning model, the security state.
14. The method of claim 1, wherein determining the first security value comprises: performing, by the computer, an evaluation of the first set of interactions to determine one or more of: interaction data in the first set of interactions, an amount of low security activities associated with the first user identifier in the first set of interactions, a volume of low security activities associated with the first user identifier in the first set of interactions, and a ratio of low security activities to high security activities associated with the first user identifier in the first set of interactions; and determining, by the computer, the first security value based on the evaluation.
15. A computer compri sing : a processor; and a non-transitory computer readable medium comprising code, executable by the processor, for performing a method comprising:receiving current interaction data related to a current interaction conducted in a current interaction network, the current interaction data comprising a current user identifier for the current interaction network; determining a first user identifier for a first interaction network based on the current user identifier; determining a second user identifier for a second interaction network based on the current user identifier; determining a first security value corresponding to a first set of interaction data; determining a second security value corresponding to a second set of interaction data; determining an other network total security factor using the first security value and the second security value; determining a security state of one of two states for the current interaction; determining whether or not to adjust the security state to the other of the two states using the other network total security factor, wherein the security state is then used to process the current interaction; and performing, by the computer, additional processing in relation to the current interaction based on the security state.
16. The computer of claim 15, wherein the method further comprises: determining to adjust the security state to the other of the two states using the other network total security factor; and adjusting the security state to the other of the two states.
17. The computer of claim 15, wherein the other network total security factor indicates low security, the security state indicates not risky, and determining whether or not to adjust the security state comprises: adjusting, by the computer, the security state from a state of not risky to a state of risky.
18. The computer of claim 15, wherein receiving the current interaction data comprises:receiving a security state request message from a network processing computer in the current interaction network, wherein the security state request message comprises the current interaction data.
19. The computer of claim 18, wherein the method further comprises: generating a security state response message comprising the security state and the current interaction data; and providing the security state response message to the network processing computer.
20. A system comprising: a user device; a processing network computer in a current interaction network; and an analysis computer comprising: a processor; and a non-transitory computer readable medium comprising code, executable by the processor for performing operations comprising: receiving current interaction data related to a current interaction conducted in a current interaction network, the current interaction data comprising a current user identifier for the current interaction network, wherein the user device is involved in the current interaction; determining a first user identifier for a first interaction network based on the current user identifier; determining a second user identifier for a second interaction network based on the current user identifier; determining a first security value corresponding to a first set of interaction data; determining a second security value corresponding to a second set of interaction data; determining an other network total security factor using the first security value and the second security value; determining a security state of one of two states for the current interaction;determining whether or not to adjust the security state to the other of the two states using the other network total security factor, wherein the security state is then used to process the current interaction; and performing, by the computer, additional processing in relation to the current interaction based on the security state.
Citation Information
Patent Citations
Electronic device including hinge apparatus
KR1020230120379A
Real-time cross-channel fraud protection
US20150039512A1
Systems and methods for matching and scoring sameness
US20170070527A1
Providing a mobile communications device with access to a provider service conditioned upon a device security level determination
US20210342452A1
System architecture for fraud detection
US20220232122A1