Human-Machine Identification via Behavioral Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing CAPTCHA technologies, such as text, image, and audio CAPTCHAs, are vulnerable to attacks from machine learning algorithms and provide a poor user experience due to their susceptibility to cracking and difficulty in distinguishing between humans and machines effectively.

Innovation Solution

A method and system that utilize statistical analysis to differentiate between human and machine requests by monitoring request frequency, user or terminal activity, and time intervals, isolating abnormal access objects to prevent malicious computer program access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If text CAPTCHA with character distortion is used, then machine recognition is prevented to some extent, but user recognition becomes difficult and experience deteriorates

Engineering Contradiction:
Improveanti-machine recognition capabilityVSAvoiduser recognition ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the parameters of the CAPTCHA challenge from simple text distortion to a multi-dimensional verification system that includes device fingerprinting, behavioral analysis, and risk scoring. This allows the system to maintain high reliability in distinguishing humans from machines while providing a seamless user experience by automatically evaluating multiple parameters simultaneously without requiring users to complete difficult recognition tasks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If image CAPTCHA with large database support is used, then cracking resistance is improved, but generation capability and scalability deteriorate

Engineering Contradiction:
Improvecracking resistanceVSAvoidCAPTCHA generation rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a self-service mechanism where the system automatically generates and validates challenges based on device fingerprints and behavioral data without requiring manual image generation or large databases. The risk evaluation system autonomously assesses each request by analyzing multiple parameters including device information, network characteristics, and user behavior patterns, enabling high-speed automated decision-making that maintains security while achieving massive scalability.

Inventive Principle:
Principle #25Self-service

3Device complexity

If traditional CAPTCHA methods are used, then implementation simplicity is maintained, but distinction accuracy between humans and machines deteriorates

Engineering Contradiction:
Improvesystem implementation complexityVSAvoidhuman-machine distinction accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent creates a universal risk evaluation system that integrates multiple verification functions into a single platform. The system simultaneously performs device fingerprinting, behavioral analysis, risk scoring, and challenge generation across different service scenarios. This multi-functional approach maintains relative implementation simplicity by providing a unified solution that achieves high distinction accuracy through comprehensive parameter evaluation rather than requiring multiple separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3008873B1Method and system of distinguishing between human and machine
Publication Date: 2020.09.02 ALIBABA GROUP HOLDING LTD
  • EP3008873B1 patent drawingFigure 1
  • EP3008873B1 patent drawingFigure 2
  • EP3008873B1 patent drawingFigure 3

AI summary

A method and a system of distinguishing between a human and a machine are disclosed. The method includes: when a request for accessing a designated network service is received, recording information of the request which include a time of receiving the request and information of an access object that sends the request; computing a statistical value of requests sent by the access object in real time based on a record; and determining the access object to be abnormal when the statistical value of the requests sent by the access object falls outside a predetermined normal range. The disclosed system of distinguishing between a human and a machine includes a recording module, a computation module and a determination module. Identification between humans and machines using the disclosed scheme is difficult to be cracked down and can improve an accuracy rate of human-machine identification.