Digital Account Security Tiers for Fraud Risk-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face inefficiencies, security issues, and inflexibility in managing account takeovers, leading to time-consuming account access recovery processes, exposure of sensitive information, and unnecessary computational resource usage.
Innovation Solution
An account security management system that determines a fraud risk score for user interactions, assigns a security tier based on this score, applies corresponding security limitations, and releases these limitations upon successful personal identity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional systems logout all devices upon detecting account takeover, then account security is improved, but user convenience deteriorates and computational resources are wasted
Solution Approach 1:
The system applies different security treatments to different devices associated with the same account. Instead of logging out all devices uniformly, it identifies and logs out only the fraudulent device while maintaining access for legitimate devices, achieving localized security response that preserves user convenience for authenticated users.
Solution Approach 2:
The system performs preliminary verification of device authenticity before applying security measures. By pre-establishing device trust profiles and authentication states, the system can quickly determine which devices are legitimate versus fraudulent, enabling rapid response that maintains convenience for genuine users while blocking attackers.
2Measurement precision
If conventional systems require multiple documents for account recovery, then verification accuracy is improved, but processing time increases and computational resources are consumed
Solution Approach 1:
The system requests only the necessary minimum verification information rather than requiring multiple documents. By using pre-collected device authentication data and trust profiles, the system achieves sufficient verification accuracy with minimal documentation, reducing recovery time and computational overhead.
Solution Approach 2:
The system uses copies of previously collected authentication data (device fingerprints, trust profiles, cached verification information) instead of requiring users to submit original documents again. This approach maintains verification accuracy while dramatically reducing processing time and resource consumption.
3Adaptability or versatility
If conventional systems store sensitive documents in multiple channels, then accessibility is improved, but security deteriorates due to increased exposure risk
Solution Approach 1:
The system extracts sensitive document storage from vulnerable communication channels (SMS, email) and relocates it to secure server-side storage. By removing sensitive data from insecure channels while maintaining accessibility through authenticated device profiles, the system eliminates exposure risks without sacrificing adaptability.
4Reliability
If conventional systems rigidly require specific verifying information, then security control is improved, but system flexibility deteriorates
Solution Approach 1:
The system dynamically adjusts verification requirements based on device trust profiles and authentication history. Instead of rigidly requiring the same verification information for all cases, it adapts the verification process to the specific context, maintaining security control while increasing flexibility for trusted devices.
Data Source
AI summary
This disclosure describes embodiments of systems, methods, and non-transitory computer-readable storage media that can solve one or more of the foregoing (or other problems) in the art in addition to providing other benefits by applying customized security limitations to a secure digital account, and removing the security limitations based on efficiently verifying personal identity information associated with the secure digital account. For example, the disclosed system can receive a user interaction associated with a secure digital account and determine a fraud risk score corresponding to the interaction. The system can then assign the secure digital account a security tier and apply appropriate security limitations based on the security tier that corresponds with a determined risk of fraud. The system may request a personal identity verification and based on the verification matching stored information corresponding to the secure digital account, remove the security limitations from the secure digital account.


