Dynamic CAPTCHA Selection Based on Client Risk Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for distinguishing between human-controlled and automated access to network resources are becoming ineffective due to advancements in computing technologies, such as OCR and AI, which can recognize conventional CAPTCHAs, leading to potential overuse and increased costs for web services.

Innovation Solution

A client profile and service policy-based CAPTCHA technique that selects and generates CAPTCHAs based on client information and service policies, comparing the client's response to determine if the access is human-controlled or autonomous, utilizing timing information and risk scoring to assess the authenticity of the user input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional CAPTCHA techniques are used to distinguish human users from automated devices, then human user identification is achieved, but the system becomes vulnerable to advanced computing technologies like OCR and AI that can recognize captchas

Engineering Contradiction:
Improvehuman user identification accuracyVSAvoidresistance to OCR and AI recognition
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic CAPTCHA selection where the type and complexity of CAPTCHA presented to a user changes based on their interaction history, risk score, and behavioral patterns. This dynamic adaptation makes it difficult for automated systems to predict and solve CAPTCHAs while maintaining usability for human users who can adapt to varying challenges.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters including CAPTCHA complexity, time limits, number of attempts allowed, and challenge types based on the assessed risk level and user behavior. This parameter variation creates a moving target that adapts to both human capabilities and automated system limitations.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If more complex captchas are used to improve recognition accuracy, then automated device detection is enhanced, but human user recognition becomes more difficult

Engineering Contradiction:
Improveautomated access detection accuracyVSAvoidhuman user accessibility
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system applies CAPTCHA challenges selectively rather than universally. Low-risk users or those with established good behavior patterns may bypass CAPTCHA entirely, while only suspicious or high-risk accesses trigger the challenge. This partial application maintains security where needed while preserving ease of use elsewhere.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system continuously monitors user behavior, CAPTCHA solving time, and response patterns to adjust future CAPTCHA requirements. Users who consistently solve CAPTCHAs quickly and accurately may face reduced challenges, while unusual patterns trigger more stringent verification, creating a feedback loop that adapts to individual user characteristics.

Inventive Principle:
Principle #23Feedback

3Reliability

If CAPTCHA challenges are presented to all users to ensure security, then automated access is detected, but service costs and user experience deteriorate

Engineering Contradiction:
Improveaccess securityVSAvoidservice resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system segments users into different risk categories based on their behavior patterns, device characteristics, access timing, and historical data. This segmentation allows the system to apply different security measures to different groups, presenting CAPTCHA challenges only to high-risk segments while allowing low-risk segments to access services without interruption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary risk assessment using available client information and behavioral data before presenting CAPTCHA challenges. By evaluating risk factors in advance, the system can preemptively identify users who need verification while allowing low-risk users to proceed without challenges, optimizing resource usage before the actual authentication attempt.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10360365B2Client profile and service policy based CAPTCHA techniques
Publication Date: 2019.07.23 A10 NETWORKS INC
  • US10360365B2 patent drawing
  • US10360365B2 patent drawing
  • US10360365B2 patent drawing

AI summary

Client profile and service policy based captcha techniques. In one embodiment, a method comprises receiving a service request from a client device. A captcha is selected based upon the client information and a client policy in response to the service request. Captcha instructions and expected captcha response are generated for the selected captcha. The captcha instructions are sent to the client device for processing thereby. In response to the captcha instruction, a captcha response from the client device may be received. The captcha response is compared to the expected response to determine based on the service policy if the client device is operating under control of a user or operating autonomously.