Verifiable Human Credentials for Bot-Resistant Online Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods, such as CAPTCHA, are inadequate in distinguishing between human and automated programs accessing networked computer resources, particularly in scenarios like event ticketing, leading to inefficiencies and resource overload.

Innovation Solution

Utilizing decentralized identifiers and verifiable credentials, including a decentralized digital identity that is not tied to certificate authorities, to authenticate users as humans without requiring login or CAPTCHA, and employing a blockchain for secure verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If CAPTCHA is used to prevent bot access, then automated program access is blocked, but human users experience time consumption and operational difficulty

Engineering Contradiction:
Improvebot access preventionVSAvoidhuman user convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent replaces the mechanical CAPTCHA challenge-response system with a behavioral analysis system that automatically observes and analyzes user interactions. The system uses machine learning models to detect bot behavior patterns through passive observation of navigation, clicking, and browsing behaviors, eliminating the need for active human participation in security challenges while maintaining bot detection effectiveness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically collecting behavioral data during normal user interactions and using this data to identify bots. The behavioral analysis model continuously learns from user patterns and autonomously makes access decisions without requiring human users to complete security tasks, making the security system serve itself through passive behavioral observation

Inventive Principle:
Principle #25Self-service

2Reliability

If CAPTCHA challenge-response authentication is implemented, then some bot access is prevented, but sophisticated bots with AI functionality can successfully respond to challenges

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidbot sophistication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by collecting and analyzing behavioral data during the user interaction process before making access decisions. Instead of waiting for CAPTCHA response, the system continuously monitors navigation patterns, click sequences, and browsing behaviors to pre-identify bot characteristics, enabling security verification to occur naturally during normal user flow rather than as a separate challenge

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The behavioral analysis system implements continuous feedback by monitoring user interactions in real-time and adjusting its bot detection decisions based on observed patterns. The system analyzes sequences of user actions, compares them against learned behavioral models, and dynamically adjusts access permissions based on the confidence level of bot detection, creating a responsive security system that adapts to observed behavior

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional centralized authentication systems are used, then user verification is achieved, but system complexity and dependency on certificate authorities increase

Engineering Contradiction:
Improveuser verificationVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication verification function from the centralized certificate authority infrastructure and embeds it directly into the browser extension and server system. The behavioral analysis model and access decision-making logic are distributed to the client-side extension, eliminating dependency on centralized authentication servers and reducing system complexity by removing the need for traditional certificate authority infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250232313A1Systems and methods for deterring bot access of computer resource
Publication Date: 2025.07.17 AXS GROUP LLC
  • US20250232313A1 patent drawing
  • US20250232313A1 patent drawing
  • US20250232313A1 patent drawing

AI summary

Aspects of the present disclosure relate to receiving a request from a remote device for access to an online computer-based service, transmitting to the remote device a request for a verifiable token encoding a verifiable credential containing an issuer's digital signature signed with a private key and an identifier indicating that a holder of the verifiable credential is human. If the verifiable token was not received, access to the online computer-based service is inhibited. If the verifiable token is received, its validity is confirmed utilizing an associated public key. If the validity is confirmed, the request from the remote device for access to the online computer-based service is determined to be from a human and the remote device is enabled to access the online computer-based service.