OTP Protection via Machine Learning Model for Vishing Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems lack effective protection against vishing attacks, where fraudsters exploit One-Time Passcodes (OTPs) by masquerading as legitimate entities, leading to security breaches and risks for users and service providers.

Innovation Solution

A computer-implemented method using a trained OTP protection machine learning model to identify phone numbers presenting a security risk, updating a contact list, and initiating security measures to safeguard OTPs, thereby automating the detection and prevention of fraudulent activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If OTP protection mechanisms are implemented to block fraudulent phone numbers, then security against vishing attacks is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-training the machine learning model with fraudulent phone number patterns before actual OTP protection is needed. The model is prepared in advance to quickly identify and block fraudulent numbers when OTPs are transmitted, reducing real-time processing complexity while maintaining high security reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A machine learning model serves as an intermediary between the OTP transmission system and fraudulent phone numbers. The model acts as a smart filter that automatically analyzes incoming calls and messages during OTP validity periods, blocking fraudulent attempts without requiring complex manual intervention or system-wide modifications

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If machine learning models are used to identify fraudulent phone numbers in real-time, then detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The machine learning model is pre-trained offline with extensive datasets of fraudulent phone number patterns, behaviors, and characteristics. This preliminary training enables the model to make rapid, accurate predictions during real-time OTP protection without requiring complex computations during the critical OTP validity period

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts its protection level based on the OTP validity period. During the short time window when an OTP is active, the model operates in a streamlined mode using pre-computed features and simplified decision rules, maintaining high detection accuracy while minimizing processing time to ensure OTP transactions are not delayed

Inventive Principle:
Principle #15Dynamics

3Reliability

If comprehensive security measures are implemented during OTP validity periods, then protection against fraudulent activities is improved, but user convenience and system operation ease deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically monitoring incoming calls and messages during OTP validity periods without requiring user intervention. The machine learning model autonomously identifies fraudulent attempts and blocks them, while the system automatically manages the contact list updates and security measure activation/deactivation based on OTP expiration, maintaining user convenience while ensuring comprehensive protection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security measures are activated periodically only during the specific time window when an OTP is valid. The system automatically enables enhanced protection protocols for the duration of the OTP's validity period and then deactivates them, providing comprehensive security when needed while minimizing interference with normal user operations during non-OTP periods

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11997082B2Computer-based systems configured for one-time passcode (OTP) protection and methods of use thereof
Publication Date: 2024.05.28 CAPITAL ONE SERVICES LLC
  • US11997082B2 patent drawing
  • US11997082B2 patent drawing
  • US11997082B2 patent drawing

AI summary

Systems and methods of anti-vishing OTP protection via machine learning techniques are disclosed. In one embodiment, an exemplary computer-implemented method may comprise: receiving a permission indicator identifying a permission by the user to detect OTPs and calls being received by a computing device; receiving an indication of an OTP data item being received; processing the OTP data item to determine a time duration during which a particular OTP included therein is valid; utilizing a trained OTP protection machine learning model to determine phone number(s) as presenting a security risk with respect to the OTP data item; and instructing the computing device to commence at least one security measure based at least in part on a contact list updated with an indication that the phone number(s) present a security risk with regard to the particular OTP during the time duration of the particular OTP.