Centralized Authentication System for Account Takeover Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional credential protection mechanisms are inadequate in defending against account take over (ATO) fraud attacks, often locking out legitimate users while failing to effectively block illegitimate access, as they are designed to target single-account brute-force attacks rather than network-wide attempts.

Innovation Solution

A centralized authentication evaluation system (CAES) monitors user credential login attempts across a network of websites, tracking valid and failed login counts within rolling time windows to allow or block access based on predefined thresholds, thereby enhancing protection against ATO fraud attacks while minimizing the impact on legitimate users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional credential protection mechanisms are used to block brute-force attacks, then security against single-account attacks is improved, but legitimate users are incorrectly locked out and network-wide ATO attacks are not effectively prevented

Engineering Contradiction:
Improvesecurity against brute-force attacksVSAvoidlegitimate user access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple single-account protection mechanisms into a centralized network-wide protection system. The centralized authentication evaluation system aggregates login attempt data from multiple accounts and websites, evaluating them collectively to distinguish between legitimate users and ATO attackers, thereby resolving the contradiction between protecting against attacks and maintaining legitimate access.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system provides universal protection across multiple accounts and websites simultaneously. Instead of implementing separate protection mechanisms for each account, the centralized system evaluates login attempts network-wide, providing both security against ATO attacks and assurance of legitimate user access through a single multi-functional system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional single-account protection mechanisms are implemented, then individual account security is improved, but network-wide ATO attacks remain undetected and protection is ineffective

Engineering Contradiction:
Improveindividual account securityVSAvoidnetwork-wide attack detection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from evaluating login attempts at the individual account level to evaluating them at the network-wide level. By adding the dimension of network-wide aggregation and collective evaluation, the system can detect ATO attacks that target multiple accounts while maintaining effective protection for individual accounts.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If aggressive blocking rules are applied to prevent ATO attacks, then security against illegitimate access is improved, but legitimate users experience account lockouts

Engineering Contradiction:
Improveprotection against illegitimate accessVSAvoiduser access availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system continuously monitors and evaluates login attempts in real-time, using feedback from the collective pattern of attempts across multiple accounts to dynamically adjust protection measures. This feedback mechanism allows the system to distinguish between legitimate users and ATO attackers, providing strong protection against illegitimate access while avoiding false lockouts of legitimate users.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11936674B2Identify and prevent account take over fraud attacks
Publication Date: 2024.03.19 SAP SE
  • US11936674B2 patent drawing
  • US11936674B2 patent drawing
  • US11936674B2 patent drawing

AI summary

This application provides an example method, system, and computer-readable medium for identifying potential account take over fraud attacks through monitoring of user credential login attempts across a network of websites. One example method includes identifying a login attempt to a particular website. The method further includes determining whether the login user credentials correspond to site-specific user credentials for the particular website. The method also includes in response to determining that the login user credentials correspond to the site-specific user credentials, determining whether the login attempt to the particular website is allowed by a first allowance rule associated with the first RTW, and in response to determining that the login attempt to the particular website is allowed by the first allowance rule, setting a first allowance indicator to indicate that the login attempt to the particular website is to be allowed by the first allowance rule.