Credential Sharing Detection via Non-Public Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in ensuring the security of their authentication credentials and preventing unauthorized access to non-public data in electronic networks, while also avoiding unnecessary burdens on trusted third parties.
Innovation Solution
A system that identifies unauthorized use of authentication credentials by employing a threat level machine learning model to determine the threat level of a user account based on access to non-public data, and generates interface components to configure a graphical user interface for managing such access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If high security protocols are implemented to prevent unauthorized use of authentication credentials, then security of non-public data is improved, but user experience deteriorates due to additional burdens on trusted third parties
Solution Approach 1:
The patent replaces manual security verification processes with an automated machine learning-based threat level assessment system. The system automatically evaluates access requests by analyzing user behavior patterns, device characteristics, and access context through algorithms, eliminating the need for manual security checks while maintaining high security standards. This substitution of mechanical/manual verification with automated computational analysis resolves the contradiction by providing both high security and ease of operation.
Solution Approach 2:
The patent dynamically adjusts security parameters based on the assessed threat level of each access request. Instead of applying uniform high-security protocols to all access attempts, the system modifies security measures according to the specific risk assessment results. For low-threat requests from trusted third parties, security barriers are reduced or removed, while high-threat requests trigger enhanced security protocols. This parameter-based adaptation resolves the contradiction by making security proportional to actual risk rather than universally restrictive.
2Measurement precision
If automated threat detection systems are deployed to identify unauthorized access, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments the threat detection system into distinct functional modules: a machine learning model for threat level assessment, an access analysis component for evaluating access requests, and a decision-making component for determining access outcomes. Each module performs a specific function and can be independently developed, tested, and maintained. This segmentation improves detection accuracy through specialized algorithms while managing system complexity by organizing functions into manageable, modular components with clear interfaces.
Solution Approach 2:
The patent introduces an intermediary machine learning model that acts as a mediator between raw access request data and security decisions. The ML model processes and interprets complex access patterns, device information, and user behavior data, transforming them into a simplified threat level assessment. This intermediary layer handles the complexity of analysis while presenting simplified results to the access control system, thereby improving detection accuracy without proportionally increasing overall system complexity.
Data Source
AI summary
Systems, computer program products, and methods are described herein for identifying unauthorized use of a user's authentication credentials to an electronic network based on non-public data access. The present invention is configured to receive a verified access attempt at a first time for a user account; receive an unverified access attempt at a second time for the user account; determine the unverified access attempt is a credential sharing event for the user account; receive unverified account access logs associated with the unverified access attempt, the unverified account access logs comprising access to non-public data; and generate an unverified data access interface component to configure a graphical user interface of a device associated with a manager of the system.


