Proof-of-Work Validation for Blocking Automated Online Abuse
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Fraudulent or malicious online actors use automated scripts to launch attacks such as credential stuffing and account creation, compromising the security of online systems by gaining unauthorized access to sensitive data.
Innovation Solution
Implementing proof-of-work techniques that require client devices to solve dynamic and obfuscated problems, which are simple for humans but difficult for automated scripts, including non-interactive and interactive puzzles, to validate online activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated scripts are used to perform online activities, then productivity and speed of online operations are improved, but security and reliability deteriorate due to fraudulent activities
Solution Approach 1:
The patent introduces a validating computing system as an intermediary between the client device and the online server system. This mediator receives online activity requests, generates proof-of-work instructions, validates the solutions, and only then permits access to the online system. The intermediary filters out automated malicious scripts while allowing legitimate human users to proceed, thus resolving the contradiction between maintaining high productivity and ensuring security.
2Reliability
If proof-of-work problems are made more difficult to solve, then security against automated scripts is improved, but ease of operation deteriorates due to increased complexity
Solution Approach 1:
The patent applies local quality by making the proof-of-work problems locally optimized for human capabilities. The problems are designed to leverage human strengths such as pattern recognition, contextual understanding, and flexible thinking, while being specifically targeted against automated script weaknesses. The difficulty is calibrated to be easy for humans but hard for machines, resolving the contradiction between security and ease of operation.
Solution Approach 2:
The patent dynamically changes the parameters of proof-of-work problems based on various factors including the user's interaction history, the suspected level of automation, and security requirements. The system can adjust problem difficulty, type, and characteristics in real-time, making it easy for legitimate users while maintaining high security against automated attacks.
3Reliability
If proof-of-work validation is implemented for all online activities, then security is improved, but productivity deteriorates due to additional time required to solve problems
Solution Approach 1:
The patent implements partial proof-of-work validation rather than requiring it for all online activities indiscriminately. The system selectively applies proof-of-work challenges based on risk assessment, user behavior patterns, and the specific online activity being requested. Low-risk activities may bypass validation entirely, while high-risk activities receive stricter validation, thus maintaining security without unnecessarily slowing down legitimate operations.
Solution Approach 2:
The system performs preliminary risk assessment and user verification before deploying proof-of-work challenges. By pre-evaluating user credentials, device fingerprints, and behavior patterns, the system can determine whether proof-of-work validation is even necessary, thereby avoiding unnecessary delays for trusted users while maintaining security for suspicious activities.
Data Source
AI summary
Systems and methods for validating online activities through proof-of-work techniques are provided. In one example, a validating computing system receives a request for a proof-of-work instruction from a client device that has submitted an online activity request to an online server system. The validating computing system generates and transmits a proof-of-work instruction for solving a problem to the client device. The validating computing system further receives a response to the proof-of-work instruction from the client device. The validating computing system generates a validity decision based on whether the client device correctly solved the problem, and transmits, to the online server system, the validity decision for use in granting the online activity request to the online server system.


