Session Management with Security Scoring and Friction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively manage and detect malicious activities, such as identity theft and denial of service attacks, which can go undetected until significant fraud occurs, due to the lack of intelligent session management and security scoring mechanisms.

Innovation Solution

A system that monitors and analyzes session behavior profiles to identify anomalous activities, calculates security scores based on user interactions, and applies additional security measures, such as friction management, to prevent and mitigate potential threats by denying or terminating suspicious sessions and offering security suggestions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If multiple concurrent sessions are allowed using the same authentication credentials, then user convenience and accessibility are improved, but the risk of malicious activity and fraud increases

Engineering Contradiction:
Improveconcurrent session accessVSAvoidmalicious activity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors session behavior and provides feedback by comparing actual session patterns against established behavior profiles. When anomalies are detected (such as unexpected geographic locations, devices, or activity patterns), the system responds by terminating suspicious sessions or requiring re-authentication, thus maintaining security while allowing legitimate concurrent access

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system establishes baseline behavior profiles for each user account before malicious activity occurs. These profiles capture normal session patterns including typical devices, locations, time zones, and activity types. When a new session is initiated, the system preliminarily evaluates it against the established profile, preventing fraudulent sessions before they can cause harm

Inventive Principle:
Principle #10Preliminary action

2Reliability

If strict session limits are imposed to prevent fraud, then security is improved, but user flexibility and convenience deteriorate

Engineering Contradiction:
Improvefraud preventionVSAvoidsession management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts session management policies based on real-time behavior analysis rather than imposing static limits. Legitimate users experiencing unusual circumstances (such as traveling to a new location or using a new device) can maintain multiple sessions if their behavior profile indicates legitimacy, while fraudulent sessions are automatically terminated regardless of number, providing both security and flexibility

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If comprehensive session monitoring and analysis are implemented, then detection precision of malicious activity is improved, but system complexity increases

Engineering Contradiction:
Improvemalicious activity detectionVSAvoidsession management system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically establishes behavior profiles by monitoring and learning from user session patterns without requiring manual configuration or intervention. The profiling mechanism self-adjusts as users exhibit new legitimate behaviors, and the system automatically updates thresholds and parameters, reducing operational complexity while maintaining high detection precision

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The monitoring system is divided into independent modular components: behavior profile establishment, real-time session analysis, anomaly detection, and response execution. Each component operates independently and can be configured separately, managing system complexity while enabling comprehensive monitoring and precise detection of malicious activities

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11848957B1Session management
Publication Date: 2023.12.19 WELLS FARGO BANK NA
  • US11848957B1 patent drawing
  • US11848957B1 patent drawing
  • US11848957B1 patent drawing

AI summary

One or more embodiments of techniques or systems for session management, security scoring, and friction management are provided herein. Sessions may be monitored for commonalities or other attributes or aspects and closed, terminated, or a freeze placed on additional sessions from being initiated. A security score may be provided which is indicative of how secure a user is with respect to one or more ways the user interacts with a resource. One or more suggested actions or score improvement strategies may be suggested to facilitate improvement of a security score for a user. Friction management may be provided by having one or more additional layers of security applied to an account of a user or an entity based on suspicious behavior or other factors.