Account Credential Sharing Detection via IP Hub Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Over-the-top (OTT) video services face challenges in detecting account sharing, which can lead to revenue loss and security breaches, as current measures like device limitations and password resets are inadequate and may annoy customers, lacking confidence in distinguishing authorized from unauthorized access.

Innovation Solution

A method involving monitoring IP addresses over time to identify groups of devices using common credentials, predicting account sharing by analyzing the number of hubs, and performing mitigation actions such as adjusting device groups and taking sharing mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current measures like device limitations and password resets are used to prevent account sharing, then account security is improved, but customer experience deteriorates and false positives increase

Engineering Contradiction:
Improveaccount securityVSAvoidcustomer experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system changes the parameters used to detect account sharing from simple device counts to complex behavioral patterns including IP address analysis, device fingerprinting, viewing habits, and temporal patterns. This allows more accurate distinction between legitimate multi-device usage and actual account sharing, reducing false positives while maintaining security

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements continuous monitoring and feedback loops that track account usage patterns over time. By analyzing behavioral data and comparing it against established patterns, the system can dynamically adjust security measures based on actual risk levels, avoiding unnecessary disruptions to legitimate users while targeting actual account sharing

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If the number of devices per account is limited to prevent sharing, then unauthorized access is reduced, but legitimate multi-device usage is blocked

Engineering Contradiction:
Improveunauthorized accessVSAvoidmulti-device usage
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system applies different security rules and monitoring levels to different devices and usage patterns. Instead of a blanket device limit, it analyzes each device's characteristics, location, usage behavior, and relationship to the account holder to determine appropriate access permissions, allowing legitimate devices while blocking unauthorized ones

Inventive Principle:
Principle #3Local quality

3Reliability

If device logout and password reset are implemented to combat sharing, then account protection is enhanced, but customer annoyance increases and revenue is lost

Engineering Contradiction:
Improveaccount protectionVSAvoidrevenue loss
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary analysis of account usage patterns to identify actual account sharing before taking protective actions. By pre-screening accounts using multiple data points including IP addresses, device fingerprints, and behavioral patterns, it can target interventions only at genuine cases of account sharing, avoiding unnecessary password resets and logouts that would frustrate legitimate customers and cause revenue loss

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If simple device counting is used to detect account sharing, then detection simplicity is maintained, but detection accuracy deteriorates

Engineering Contradiction:
Improvedetection simplicityVSAvoidsharing detection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The system transitions from one-dimensional device counting to multi-dimensional analysis by incorporating IP address data, device fingerprint information, viewing behavior patterns, temporal patterns, and geographic location. This dimensional expansion enables accurate distinction between legitimate household members using multiple devices and actual account sharing, dramatically improving detection precision

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11785306B2Method and apparatus to monitor account credential sharing in communication services
Publication Date: 2023.10.10 WARNER MEDIA LLC
  • US11785306B2 patent drawing
  • US11785306B2 patent drawing
  • US11785306B2 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, a system or method that collects or otherwise accesses information indicating connection patterns such as IP addresses being utilized by communication devices for communication services over a time period, where the communication devices use a same credential of a single account for accessing the communication services. Hubs can be identified according to groups of the communication devices that exhibit a particular sharing pattern such as having used the one or more common IP addresses. A prediction or estimation that the single account is engaging in sharing activity can be made based on an analysis of the hubs, such as based on a number of the hubs. Other embodiments are disclosed.