US2022284082A1PendingUtilityA1
Authentication challenges based on fraud initiation requests
Assignee: AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INCPriority: Feb 14, 2018Filed: May 25, 2022Published: Sep 8, 2022
Est. expiryFeb 14, 2038(~11.5 yrs left)· nominal 20-yr term from priority
G06F 21/44G06Q 20/4016G06Q 20/382G06F 21/31G06Q 20/4097G06F 21/45G06F 21/64G06Q 20/385
60
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Systems for issuing authentication challenges based on fraud initiation requests are provided. The system may calculate a fraud risk level based on a fraud initiating request comprising identity-based data. In response to the fraud risk level indicating a risk of fraud, the system may determine an authentication challenge type. The system may cause a display on the client device of an authentication challenge and verify an authentication challenge response received from a client device.
Claims
exact text as granted — not AI-modifiedTherefore, the following is claimed:
1 . A method, comprising:
receiving, by a computing device, a provisioning request for a payment instrument to a digital wallet of a client device; initiating, by the computing device, an authorization process by generating a fraud initiating request in response to receiving the provisioning request; calculating, by the computing device, a fraud risk level for the fraud initiating request based at least in part on an internet protocol address of the client device; determining, by the computing device, an authentication challenge type in response to the fraud risk level meeting a threshold; causing, by the computing device, a display on the client device of an authentication challenge based at least in part on the authentication challenge type; verifying, by the computing device, an authentication challenge response received from the client device based at least in part on comparing the authentication challenge response to identity-based data associated with the fraud initiating request; and authorizing, by the computing device, the provisioning request of the payment instrument to the digital wallet of the client device based at least in part on verifying the authentication challenge response.
2 . The method of claim 1 , wherein the fraud risk level is further calculated based at least in part on a velocity of receiving a plurality of additional fraud initiating requests that have a common data attribute with the fraud initiating request.
3 . The method of claim 1 , further comprising:
receiving, by the computing device, an error indicator associated with processing the fraud initiating request; and modifying, by the computing device using a machine learning model, in real-time a set of eligible challenge types based at least in part on the error indicator associated with the fraud initiating request.
4 . The method of claim 1 , further comprising:
determining, by the computing device, an authentication challenge delivery channel based at least in part on verifying the identity-based data associated with the fraud initiating request.
5 . The method of claim 4 , wherein the authentication challenge delivery channel comprises at least one of an email service, a short message service (SMS), an instant messaging service, or a phone service.
6 . The method of claim 4 , further comprising:
receiving, by the computing device, an error indicator associated with processing the fraud initiating request; and modifying, by the computing device using a machine learning model, in real-time a set of eligible challenge delivery channels based at least in part on the error indicator associated with the fraud initiating request.
7 . The method of claim 1 , wherein the authentication challenge type comprises at least one of a one-time password, a predefined password, a driver's license number, an international mobile equipment identity (IMEi), a transaction card number, or a transaction card verification value.
8 . A system comprising:
a computing device that comprises a processor and memory, machine instructions stored in the memory that, when executed by the processor, cause the computing device to at least:
receive a provisioning request for a payment instrument to a digital wallet of a client device;
initiate an authorization process by generating a fraud initiating request in response to receiving the provisioning request;
calculate a fraud risk level for the fraud initiating request based at least in part on an internet protocol address of the client device;
determine an authentication challenge type in response to the fraud risk level meeting a threshold;
cause a display on the client device of an authentication challenge based at least in part on the authentication challenge type;
verify an authentication challenge response received from the client device based at least in part on comparing the authentication challenge response to identity-based data associated with the fraud initiating request; and
authorize the provisioning request of the payment instrument to the digital wallet of the client device based at least in part on verifying the authentication challenge response.
9 . The system of claim 8 , wherein the fraud risk level is further calculated based at least in part on a velocity of receiving a plurality of additional fraud initiating requests that have a common data attribute with the fraud initiating request.
10 . The system of claim 8 , wherein the machine instructions stored in the memory that, when executed by the processor, cause the computing device to at least:
receive an error indicator associated with processing the fraud initiating request; and modify, using a machine learning model, in real-time a set of eligible challenge types based at least in part on the error indicator associated with the fraud initiating request.
11 . The system of claim 8 , wherein the machine instructions stored in the memory that, when executed by the processor, cause the computing device to at least:
determine an authentication challenge delivery channel based at least in part on verifying the identity-based data associated with the fraud initiating request.
12 . The system of claim 11 , wherein the machine instructions stored in the memory that, when executed by the processor, cause the computing device to at least:
receive an error indicator associated with processing the fraud initiating request; and modify, using a machine learning model, in real-time a set of eligible challenge delivery channels based at least in part on the error indicator associated with the fraud initiating request.
13 . The system of claim 11 , wherein the authentication challenge delivery channel comprises at least one of an email service, a short message service (SMS), an instant messaging service, or a phone service.
14 . The system of claim 8 , wherein the authentication challenge type comprises at least one of a one-time password, a predefined password, a driver's license number, an international mobile equipment identity (IMEi), a transaction card number, or a transaction card verification value.
15 . An article of manufacture including a non-transitory, tangible computer readable storage medium having instructions stored thereon that, in response to execution by a computer based system, cause the computer based system to at least:
receive a provisioning request for a payment instrument to a digital wallet of a client device; initiate an authorization process by generating a fraud initiating request in response to receiving the provisioning request; calculate a fraud risk level for the fraud initiating request based at least in part on an internet protocol address of the client device; determine an authentication challenge type in response to the fraud risk level meeting a threshold; cause a display on the client device of an authentication challenge based at least in part on the authentication challenge type; verify an authentication challenge response received from the client device based at least in part on comparing the authentication challenge response to identity-based data associated with the fraud initiating request; and authorize the provisioning request of the payment instrument to the digital wallet of the client device based at least in part on verifying the authentication challenge response.
16 . The article of manufacture of claim 15 , wherein the fraud risk level is further calculated based at least in part on a velocity of receiving a plurality of additional fraud initiating requests that have a common data attribute with the fraud initiating request.
17 . The article of manufacture of claim 15 , wherein the instructions stored thereon that, in response to the execution by the computer based system, cause the computer based system to at least:
receive an error indicator associated with processing the fraud initiating request; and modify, using a machine learning model, in real-time a set of eligible challenge types based at least in part on the error indicator associated with the fraud initiating request.
18 . The article of manufacture of claim 15 , wherein the instructions stored thereon that, in response to the execution by the computer based system, cause the computer based system to at least:
determine an authentication challenge delivery channel based at least in part on verifying the identity-based data associated with the fraud initiating request.
19 . The article of manufacture of claim 18 , wherein the authentication challenge delivery channel comprises at least one of an email service, a short message service (SMS), an instant messaging service, or a phone service.
20 . The article of manufacture of claim 18 , wherein the instructions stored thereon that, in response to the execution by the computer based system, cause the computer based system to at least:
receive an error indicator associated with processing the fraud initiating request; and modify, using a machine learning model, in real-time a set of eligible challenge delivery channels based at least in part on the error indicator associated with the fraud initiating request.Join the waitlist — get patent alerts
Track US2022284082A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.