User Authorization Risk Scoring via Segmented Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authorization methods face challenges in balancing speed and reliability, particularly in preventing fraudulent account use, as they often require extensive data processing that can lead to delays and may not adequately protect against unauthorized access without risking false decisions.
Innovation Solution
A method that generates a risk score indicating the likelihood of unauthorized access, signaling the need for further information only when the risk is medium, allowing for instant decisions in clear cases and reducing data transmission by enabling device-generated risk scores without sending sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If risk detectors process extensive data for improved risk analysis, then fraud protection reliability is improved, but authentication speed deteriorates due to processing delays
Solution Approach 1:
The patent segments the risk assessment process into two distinct phases: a fast initial risk score generated immediately from basic request data, and a more comprehensive device-generated risk score that requires additional processing. This segmentation allows the system to provide rapid initial responses while optionally obtaining more accurate fraud assessment, thus resolving the contradiction between speed and reliability.
2Speed
If risk detectors are omitted to accelerate authentication, then authentication speed is improved, but fraud protection reliability deteriorates
Solution Approach 1:
The patent implements self-service by enabling the user's own device to generate its risk score locally using provided instructions and available device data. This eliminates the need for the server to perform extensive data processing and complex risk analysis, thereby maintaining high authentication speed while still achieving reliable fraud protection through the device's own risk assessment capabilities.
3Measurement precision
If extensive data is collected and transmitted for risk analysis, then measurement precision of user authorization is improved, but data transmission overhead and processing complexity increase
Solution Approach 1:
The patent introduces an intermediary approach where the server provides instructions and guidance to the user device, which then performs the complex data collection and risk score generation locally. This intermediary role allows the server to maintain measurement precision by controlling the risk assessment process while avoiding the complexity of handling extensive data transmission and processing, as the actual heavy lifting is performed by the user's own device.
Data Source
AI summary
The disclosure relates to a method (100) for assessing user authorization, the method comprising: receiving (110), via a data communication network (330), a request from a user device (300) for an access; generating (120), based on data associated with the request, a risk score indicating a risk that the request was sent by a non-authorized user, wherein the risk score indicates a high risk, a medium risk, or a low risk that the user (400) is a non-authorized user; and signaling (130), via the data communication network (330), the user device (300) a need for further information to enable a decision about the authorization of the user (400), if the risk score indicates medium risk. A further aspect relates to a method (200) for user authorization and to an electronic device (300).

