IP Library Granted Patent US 10,839,065
Granted Patent B2
US 10,839,065 · App. 15/908,548 · Granted Nov 17, 2020

Systems and methods for assessing security risk

Inventor: Christopher Everett Bailey (Langley, CA)
Assignee: Mastercard Technologies Canada ULC
G06F21/36G06F21/31H04L63/1433G06F2221/2103G06F2221/2133
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,839,065
App. No.
15/908,548
Granted
Nov 17, 2020
Kind
B2
Abstract

Systems and methods for providing identification tests. In some embodiments, a system and a method are provided for generating and serving to a user an animated challenge graphic comprising a challenge character set whose appearance may change over time. In some embodiments, marketing content may be incorporated into a challenge message for use in an identification test. The marketing content may be accompanied by randomly selected content to increase a level of security of the identification test, in some embodiments, a challenge message for use in an identification test may be provided based on information regarding a transaction for which the identification test is administered. For example, the transaction information may include a user identifier such as an IP address. In some embodiments, identification test results may be tracked and analyzed to identify a pattern of behavior associated with a user identifier. A score indicative of a level of trustworthiness may be computed for the user identifier.

Claims (33)

1. A system for managing an electronic transaction, the system comprising at least one processor programmed to:

receive, during the electronic transaction, a request from a user system to access at least one resource;

cause an identification test to be administered to the user system;

analyze information relating to the identification test to determine whether the electronic transaction is associated with an elevated level of risk, wherein the information relating to the identification test indicates a manner in which a response is submitted by the user system; and

in response to determining that the electronic transaction is not associated with an elevated level of risk, grant access to the at least one resource even if the response is incorrect,

wherein the at least one processor is programmed to determine the electronic transaction is associated with the elevated level of risk based at least in part on how rapidly the user system submits the response and when an amount of time taken by the user system to submit the response indicates the response is from a software robot.

2. The system of claim 1 , wherein the at least one processor is programmed to determine whether the electronic transaction is associated with an elevated level of risk based at least in part on a total number of responses submitted by the user system within a selected time period.

3. The system of claim 1 , wherein the at least one processor is programmed to determine whether the electronic transaction is associated with an elevated level of risk based at least in part on how a plurality of responses submitted by the user system were distributed over time.

4. The system of claim 1 , wherein the at least one processor is programmed to determine whether the electronic transaction is associated with an elevated level of risk based at least in part on a time of day at which the response was submitted by the user system.

5. The system of claim 1 , wherein the at least one processor is programmed to determine whether the electronic transaction is associated with an elevated level of risk based at least in part on a number of times the user system requested a new challenge graphic via a refresh button.

6. The system of claim 1 , wherein the at least one processor is further programmed to impose one or more security measures during the electronic transaction.

7. A method for managing an electronic transaction, the method comprising acts of:

receiving, during the electronic transaction, a request from a user system to access at least one resource;

causing an identification test to be administered to the user system;

analyzing information relating to the identification test to determine whether the electronic transaction is associated with an elevated level of risk, wherein the information relating to the identification test indicates a manner in which a response is submitted by the user system; and

in response to determining that the electronic transaction is not associated with an elevated level of risk, granting access to the at least one resource even if the response is incorrect,

wherein determining the electronic transaction is associated with the elevated level of risk is based at least in part on how rapidly the user system submits the response and when an amount of time taken by the user system to submit the response indicates the response is from a software robot.

8. The method of claim 7 , wherein the act of analyzing comprises determining whether the electronic transaction is associated with an elevated level of risk based at least in part on a total number of responses submitted by the user system within a selected time period.

9. The method of claim 7 , wherein the act of analyzing comprises determining whether the electronic transaction is associated with an elevated level of risk based at least in part on how a plurality of responses submitted by the user system were distributed over time.

10. The method of claim 7 , wherein the act of analyzing comprises determining whether the electronic transaction is associated with an elevated level of risk based at least in part on a time of day at which the response was submitted by the user system.

11. The method of claim 7 , wherein the act of analyzing comprises determining whether the electronic transaction is associated with an elevated level of risk based at least in part on a number of times the user system requested a new challenge graphic via a refresh button.

12. The method of claim 7 , further comprising an act of imposing one or more security measures during the electronic transaction.

13. At least one non-transitory computer-readable storage medium having encoded thereon instructions which, when executed by at least one processor, cause the at least one processor to perform a method for managing an electronic transaction, the method comprising acts of:

receiving, during the electronic transaction, a request from a user system to access at least one resource;

causing an identification test to be administered to the user system;

analyzing information relating to the identification test to determine whether the electronic transaction is associated with an elevated level of risk, wherein the information relating to the identification test indicates a manner in which a response is submitted by the user system; and

in response to determining that the electronic transaction is not associated with an elevated level of risk, granting access to the at least one resource even if the response is incorrect,

wherein determining the electronic transaction is associated with the elevated level of risk is based at least in part on how rapidly the user system submits the response and when an amount of time taken by the user system to submit the response indicates the response is from a software robot.

14. The at least one computer-readable storage medium of claim 13 , wherein the act of analyzing comprises determining whether the electronic transaction is associated with an elevated level of risk based at least in part on a total number of responses submitted by the user system within a selected time period.

15. The at least one computer-readable storage medium of claim 13 , wherein the act of analyzing comprises determining whether the electronic transaction is associated with an elevated level of risk based at least in part on how a plurality of responses submitted by the user system were distributed over time.

16. The at least one computer-readable storage medium of claim 13 , wherein the act of analyzing comprises determining whether the electronic transaction is associated with an elevated level of risk based at least in part on a time of day at which the response was submitted by the user system.

17. The at least one computer-readable storage medium of claim 13 , wherein the act of analyzing comprises determining whether the electronic transaction is associated with an elevated level of risk based at least in part on a number of times the user system requested a new challenge graphic via a refresh button.

18. The at least one computer-readable storage medium of claim 13 , further comprising an act of imposing one or more security measures during the electronic transaction.

Assignments (4)
CONFIRMATORY Recorded May 22, 2018
From: BAILEY, CHRISTOPHER EVERETT
To: LEAP MARKETING TECHNOLOGIES INC.
Reel/Frame 046202/0243 →
CHANGE OF NAME Recorded May 22, 2018
From: NUCAPTCHA INC.
To: NUDATA SECURITY INC.
Reel/Frame 046202/0260 →
CHANGE OF NAME Recorded May 22, 2018
From: LEAP MARKETING TECHNOLOGIES INC.
To: NUCAPTCHA INC.
Reel/Frame 046202/0341 →
CERTIFICATE OF AMALGAMATION Recorded Apr 23, 2018
From: NUDATA SECURITY INC.
To: MASTERCARD TECHNOLOGIES CANADA ULC
Reel/Frame 045997/0492 →
Continuity (5)
Continuation 14481698 · Sep 9, 2014
Division 12935927
Provisional Application 61050839 · May 6, 2008
Provisional Application 61041556 · Apr 1, 2008
Related Publication 20180189475A1 · Jul 5, 2018