Verifiable Human Credentials for Bot-Resistant Online Service Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods, such as CAPTCHA, are inadequate in distinguishing between human and automated programs accessing networked computer resources, particularly in scenarios like event ticketing, leading to inefficiencies and resource overload.
Innovation Solution
Utilizing decentralized identifiers and verifiable credentials, including a decentralized digital identity that is not tied to certificate authorities, to authenticate users as humans without requiring login or CAPTCHA, and employing a blockchain for secure verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If CAPTCHA is used to prevent bot access, then automated program access is blocked, but human users experience time consumption and operational difficulty
Solution Approach 1:
The patent replaces the mechanical CAPTCHA challenge-response system with a behavioral analysis system that automatically observes and analyzes user interactions. The system uses machine learning models to detect bot behavior patterns through passive observation of navigation, clicking, and browsing behaviors, eliminating the need for active human participation in security challenges while maintaining bot detection effectiveness
Solution Approach 2:
The system performs self-service by automatically collecting behavioral data during normal user interactions and using this data to identify bots. The behavioral analysis model continuously learns from user patterns and autonomously makes access decisions without requiring human users to complete security tasks, making the security system serve itself through passive behavioral observation
2Reliability
If CAPTCHA challenge-response authentication is implemented, then some bot access is prevented, but sophisticated bots with AI functionality can successfully respond to challenges
Solution Approach 1:
The system performs preliminary action by collecting and analyzing behavioral data during the user interaction process before making access decisions. Instead of waiting for CAPTCHA response, the system continuously monitors navigation patterns, click sequences, and browsing behaviors to pre-identify bot characteristics, enabling security verification to occur naturally during normal user flow rather than as a separate challenge
Solution Approach 2:
The behavioral analysis system implements continuous feedback by monitoring user interactions in real-time and adjusting its bot detection decisions based on observed patterns. The system analyzes sequences of user actions, compares them against learned behavioral models, and dynamically adjusts access permissions based on the confidence level of bot detection, creating a responsive security system that adapts to observed behavior
3Reliability
If traditional centralized authentication systems are used, then user verification is achieved, but system complexity and dependency on certificate authorities increase
Solution Approach 1:
The patent extracts the authentication verification function from the centralized certificate authority infrastructure and embeds it directly into the browser extension and server system. The behavioral analysis model and access decision-making logic are distributed to the client-side extension, eliminating dependency on centralized authentication servers and reducing system complexity by removing the need for traditional certificate authority infrastructure
Data Source
AI summary
Aspects of the present disclosure relate to receiving a request from a remote device for access to an online computer-based service, transmitting to the remote device a request for a verifiable token encoding a verifiable credential containing an issuer's digital signature signed with a private key and an identifier indicating that a holder of the verifiable credential is human. If the verifiable token was not received, access to the online computer-based service is inhibited. If the verifiable token is received, its validity is confirmed utilizing an associated public key. If the validity is confirmed, the request from the remote device for access to the online computer-based service is determined to be from a human and the remote device is enabled to access the online computer-based service.


