Bot Detection via Access Control Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting bots in user networks are either cumbersome, requiring specialized equipment like biometrics or tedious user verification processes, making them unsuitable for all situations.

Innovation Solution

A method involving a user terminal that receives an identifier associated with a network user account, transmits it to an access control system, and uses representative data elements, such as access frequency and geographical location, to determine if the account holder is a bot, without revealing the access control system's identity to the server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric verification is used to distinguish human users from bots, then detection reliability is improved, but device complexity and implementation cost increase due to requiring specialized biometric sensors

Engineering Contradiction:
Improvebot detection reliabilityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary access control system that acts as a mediator between the user terminal and the server. This system collects behavioral data (identifier reception events) and transmits representative data elements to the server, eliminating the need for direct biometric verification while maintaining detection reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/biometric verification system with an electronic behavioral analysis system. Instead of using physical biometric sensors, the system uses digital identifier transmission events and representative data elements to infer human presence, substituting complex hardware with software-based detection

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If supporting documents are required for user verification, then bot detection accuracy is improved, but ease of operation deteriorates due to tedious verification processes

Engineering Contradiction:
Improvebot detection accuracyVSAvoiduser verification convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service verification where the user terminal automatically transmits identifiers and the access control system automatically collects and transmits representative data elements without requiring user action. The verification process happens in the background, improving ease of operation while maintaining detection accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary data collection by having the access control system continuously monitor and record identifier reception events before the actual bot detection query is made. This preliminary action prepares the representative data elements in advance, making the verification process seamless for users

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If access control system identity is revealed to the server, then measurement precision is improved for tracking, but loss of information increases due to privacy concerns and data security requirements

Engineering Contradiction:
Improveaccess tracking precisionVSAvoidprivacy information loss
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the essential representative data elements (identifier reception events, timestamps, frequencies) from the access control system data while leaving out identifying information about the access control system itself. This selective extraction maintains measurement precision for bot detection while preserving privacy and security information

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11354388B2Method for detecting bots in a user network
Publication Date: 2022.06.07 IDEMIA PUBLIC SECURITY FRANCE
  • US11354388B2 patent drawing
  • US11354388B2 patent drawing

AI summary

A method for detecting bots in a user network (R), the method comprising the following steps: receiving (102) by a user terminal (2) an identifier (ID) associated with a network user account; transmitting (104), by the user terminal (2), the identifier (ID) to an access control system (3) configured to determine whether or not a mobile terminal owner has the right to access an area or service, the area or service being independent of the user network (R); transmitting (106), by the access control system (3) to the server (1), a representative data element supporting that the identifier (ID) has been received by the access control system (3); and using (108) by the server (1) the representative data element to determine whether the user of the account associated with the identifier (ID) is a bot or not.