Machine-Learning Trusted Device Scoring for Risk-Based Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems require the same authentication steps for all user-device pairs, leading to high rates of additional authentication challenges and user burden, which can reduce interaction rates due to the perceived burden.
Innovation Solution
Employing machine learning models (MLMs) to generate trust scores for user-device pairs based on specific user and device data, allowing for customized authentication challenges and reducing the overall user challenge rate while maintaining an acceptable fraud rate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems apply the same authentication steps for all user-device pairs, then fraud prevention coverage is maintained, but user burden increases and interaction rates decrease
Solution Approach 1:
The patent applies local quality by differentiating authentication requirements based on specific user-device pair characteristics. Instead of uniform authentication for all users, the system generates customized authentication challenges tailored to each user-device pair's risk profile, device attributes, and historical behavior patterns. This allows low-risk users to experience minimal friction while maintaining stringent security for high-risk scenarios.
Solution Approach 2:
The system dynamically adjusts authentication challenge selection based on real-time risk assessment. The machine learning model continuously evaluates user behavior, device attributes, and transaction context to determine appropriate authentication measures. This dynamic approach enables the system to adapt authentication intensity to actual risk levels rather than applying static uniform rules.
2Reliability
If traditional authentication systems challenge all users with additional verification steps, then fraud detection rate is maintained, but user interaction rates decrease due to perceived burden
Solution Approach 1:
The system applies partial action by selectively challenging only those user-device pairs that exceed specific risk thresholds. Rather than universally applying additional authentication steps to all users, the machine learning model identifies and challenges only the portion of users whose behavior patterns indicate elevated fraud risk, leaving low-risk users to complete transactions without additional friction.
Solution Approach 2:
The system changes the parameter of authentication challenge selection from a static universal approach to a dynamic risk-based approach. By adjusting the challenge selection parameter based on machine learning risk scores, the system optimizes the balance between fraud detection and user experience, challenging only when necessary while maintaining high interaction rates.
3Productivity
If machine learning models are used to generate customized authentication challenges, then user challenge rate decreases by 52%, but system complexity increases
Solution Approach 1:
The system employs self-service by utilizing machine learning models that automatically analyze user behavior patterns, device attributes, and transaction context to generate customized authentication challenges without manual intervention. The model continuously learns from new data and autonomously adjusts challenge selection, reducing the need for manual system configuration and maintenance while achieving significant reductions in user challenge rates.
Data Source
AI summary
Disclosed embodiments may include a system for determining trusted devices. The system may receive data corresponding to a plurality of users. The system may receive, via a plurality of user devices associated with the plurality of users, a respective request to conduct a plurality of transactions. The system may generate, via an MLM and based on the data, trust scores associated with the plurality of users and the plurality of user devices, wherein each trust score indicates a probability that a user device, of the plurality of user devices, is associated with a user of the plurality of users. The system may determine whether each trust score of a plurality of trust scores exceeds a predetermined threshold. Responsive to determining a trust score of the plurality of trust scores exceeds the predetermined threshold, the system may conduct fraud prevention action(s) with respect to a corresponding user device and user.


