Machine-Learning Trusted Device Scoring for Risk-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require the same authentication steps for all user-device pairs, leading to high rates of additional authentication challenges and user burden, which can reduce interaction rates due to the perceived burden.

Innovation Solution

Employing machine learning models (MLMs) to generate trust scores for user-device pairs based on specific user and device data, allowing for customized authentication challenges and reducing the overall user challenge rate while maintaining an acceptable fraud rate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems apply the same authentication steps for all user-device pairs, then fraud prevention coverage is maintained, but user burden increases and interaction rates decrease

Engineering Contradiction:
Improvefraud prevention coverageVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating authentication requirements based on specific user-device pair characteristics. Instead of uniform authentication for all users, the system generates customized authentication challenges tailored to each user-device pair's risk profile, device attributes, and historical behavior patterns. This allows low-risk users to experience minimal friction while maintaining stringent security for high-risk scenarios.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts authentication challenge selection based on real-time risk assessment. The machine learning model continuously evaluates user behavior, device attributes, and transaction context to determine appropriate authentication measures. This dynamic approach enables the system to adapt authentication intensity to actual risk levels rather than applying static uniform rules.

Inventive Principle:
Principle #15Dynamics

2Reliability

If traditional authentication systems challenge all users with additional verification steps, then fraud detection rate is maintained, but user interaction rates decrease due to perceived burden

Engineering Contradiction:
Improvefraud detection rateVSAvoiduser interaction rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial action by selectively challenging only those user-device pairs that exceed specific risk thresholds. Rather than universally applying additional authentication steps to all users, the machine learning model identifies and challenges only the portion of users whose behavior patterns indicate elevated fraud risk, leaving low-risk users to complete transactions without additional friction.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the parameter of authentication challenge selection from a static universal approach to a dynamic risk-based approach. By adjusting the challenge selection parameter based on machine learning risk scores, the system optimizes the balance between fraud detection and user experience, challenging only when necessary while maintaining high interaction rates.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If machine learning models are used to generate customized authentication challenges, then user challenge rate decreases by 52%, but system complexity increases

Engineering Contradiction:
Improveuser challenge rateVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system employs self-service by utilizing machine learning models that automatically analyze user behavior patterns, device attributes, and transaction context to generate customized authentication challenges without manual intervention. The model continuously learns from new data and autonomously adjusts challenge selection, reducing the need for manual system configuration and maintenance while achieving significant reductions in user challenge rates.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250254166A1Systems and methods for determining trusted devices
Publication Date: 2025.08.07 CAPITAL ONE SERVICES LLC
  • US20250254166A1 patent drawing
  • US20250254166A1 patent drawing
  • US20250254166A1 patent drawing

AI summary

Disclosed embodiments may include a system for determining trusted devices. The system may receive data corresponding to a plurality of users. The system may receive, via a plurality of user devices associated with the plurality of users, a respective request to conduct a plurality of transactions. The system may generate, via an MLM and based on the data, trust scores associated with the plurality of users and the plurality of user devices, wherein each trust score indicates a probability that a user device, of the plurality of user devices, is associated with a user of the plurality of users. The system may determine whether each trust score of a plurality of trust scores exceeds a predetermined threshold. Responsive to determining a trust score of the plurality of trust scores exceeds the predetermined threshold, the system may conduct fraud prevention action(s) with respect to a corresponding user device and user.