Access decision management system for digital resources

By using machine learning models in the content access management platform to analyze the relationship information between content owners and content requesters, and automatically evaluate the access determination score, it solves the problem of waiting time extension caused by manual approval of access requests in the zero-trust architecture, realizes automated access decisions, and improves the efficiency of workflows.

CN120051966APending Publication Date: 2025-05-27MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380070396.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-21
Filing Date
2023-09-03
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In a zero-trust architecture, the process of manually approving access requests by content owners can lead to extended wait times for users, especially in large enterprises across time zones, affecting the efficiency of workflows.

Method used

Automatic decision-making of access requests is achieved by analyzing the relationship information between content owners and content requesters using machine learning models.

Benefits of technology

The solution automates access decisions, reduces user waiting time, improves workflow efficiency, and ensures content security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120051966A_ABST
    Figure CN120051966A_ABST
Patent Text Reader

Abstract

A data processing system implements: receiving an access request from a client device to access a content item, access rights to the content item being managed by a content access management platform; and obtaining access control information. The access control information includes information associated with a content owner associated with a content item, information associated with a content requester, and information associated with the content item. The system also implements: analyzing the access control information using a machine learning model trained to analyze the access control information and output an access determination score representing a deterministic level at which the content requester should be granted access to the content item; determining an automatic access decision to grant or deny the access request based on the access determination score; and notifying the content requester of whether the access request is granted or denied based on the automatic access decision.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Zero Trust is a cybersecurity architecture in which all users need to be authenticated and authorized before being granted access to enterprise content. Enterprise content can include various types of digital resources, such as but not limited to documents, applications, data sources, program code, and / or other such enterprise content. Users both inside and outside the enterprise network are subject to strict authentication and authorization requirements. In addition, all requests to access content are reviewed before access to the content is allowed. Although the Zero Trust architecture provides robust security protection for enterprise content, the implementation of such an architecture may pose technical and logistical challenges to enterprises. It may be necessary for content owners to manually approve access to certain enterprise content, which may create a bottleneck for users who need access to the content. The work schedules of content owners and users requesting access to content may not be aligned, especially in large enterprises spanning multiple time zones. In addition, even when the work schedules of content owners and content requesters are aligned, content owners may be occupied with other tasks or otherwise unable to process requests for granting access to content. Therefore, users requesting content may experience significant delays in obtaining access to the content they need to complete work tasks that depend on that content. Accordingly, there is a need for improved systems and methods for providing technical solutions for making access decisions for enterprise content. Summary of the Invention

[0002] An exemplary data processing system according to the present disclosure may include a processor and a machine-readable medium storing executable instructions. The instructions, when executed, cause the processor to perform operations including: receiving, from a client device of a content requester, an access request for accessing a content item, the access right to the content item being managed by a content access management platform; obtaining access control information, the access control information including information associated with a content owner associated with the content item, information associated with the content requester, and information associated with the content item; using a first machine learning model to analyze the access control information, the first machine learning model being trained to analyze the access control information and output an access determination score, the access determination score representing a level of certainty that the content requester should be granted access to the content item; determining an automatic access decision to grant or deny the access request based on the access determination score; and notifying the content requester whether the access request is granted or denied based on the automatic access decision.

[0003] An exemplary data processing system according to the present disclosure may include a processor and a machine-readable medium storing executable instructions. When executed, the instructions cause the processor to perform operations including: receiving an access request from a client device of a content requester, the access request for accessing a content item, the access right to the content item being managed by a content access management platform; obtaining information indicating a relationship between the content owner and the content requester; using a first machine learning model to analyze the relationship information, the first machine learning model being trained to analyze the relationship information and output an access determination score, the access determination score representing a level of certainty that the content requester should be granted access to the content item; determining an automatic access decision to grant or deny the access request based on the access determination score; and notifying the content requester whether the access request is granted or denied based on the automatic access decision.

[0004] An exemplary method for automatic access control decision-making implemented in a data processing system, the method including: receiving an access request from a client device of a content requester, the access request for accessing a content item, the access right to the content item being managed by a content access management platform; obtaining access control information, the access control information including information associated with a content owner associated with the content item, information associated with the content requester, and information associated with the content item; using a first machine learning model to analyze the access control information, the first machine learning model being trained to analyze the access control information and output an access determination score, the access determination score representing a level of certainty that the content requester should be granted access to the content item; determining an automatic access decision to grant or deny the access request based on the access determination score; and notifying the content requester whether the access request is granted or denied based on the automatic access decision.

[0005] The present invention content is provided to introduce a set of concepts in a simplified form, which will be further described in the detailed implementation below. The present invention content is not intended to identify the key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. In addition, the claimed subject matter is not limited to implementations that solve any or all of the disadvantages mentioned in any part of the present disclosure. Brief Description of the Drawings

[0006] The drawings depict one or more embodiments according to the present teachings by way of example only and not limitation. In the drawings, the same reference numerals refer to the same or similar elements. In addition, it should be understood that the drawings are not necessarily drawn to scale.

[0007] Figure 1A diagram showing an exemplary computing environment in which the techniques for access decision management disclosed herein can be implemented.

[0008] Figure 2 Is a diagram showing Figure 1 Additional features of the content access management platform, client device, and application service shown.

[0009] Figures 3A to 3C Shows an example of the interaction between the client device and the content access management platform shown in the foregoing diagram.

[0010] Figures 4A to 4I A diagram of an exemplary user interface for accessing content managed by a content access management platform from the client device shown in the foregoing diagram.

[0011] Figures 5A to 5G A diagram of an exemplary user interface for managing access to content managed by the content service platform shown in the foregoing diagram.

[0012] Figure 6 A diagram of an exemplary flowchart of another exemplary process for access decision management.

[0013] Figure 7 A block diagram showing an exemplary software architecture, various parts of which can be used in combination with the various hardware architectures described herein and which can implement any of the described features.

[0014] Figure 8 A block diagram showing the components of an exemplary machine configured to read instructions from a machine-readable medium and perform any of the features described herein. Detailed Description

[0015] Techniques for access decision management of digital resources are provided. These techniques address the technical problems associated with managing access requests to content items in a content access management platform with a strict security architecture. When a user who requests access rights to protected content does not have access to the content required to complete their work tasks, strict access control policies can lead to significant disruptions in the workflow within an enterprise. Currently, users who cannot access such content must attempt to contact the content owner to grant permission to the required content. However, this is not a practical solution in large enterprises. Users are typically located in multiple time zones and may not have overlapping work schedules. In addition, the content owner may be busy with other tasks and may not be able to respond immediately to such requests to grant access rights to the content item.

[0016] The techniques herein provide a technical solution to the problem of managing such access decisions by balancing the needs of enterprise users to access content and the content owners' control over who can access the content without compromising the security of the content. These techniques collect and analyze metadata and network information indicative of the relationship between the content owner and the user requesting access to the content and the relationship between the user requesting access to the content and the content being requested. This information can be collected from multiple data sources and analyzed by one or more machine learning models, which are trained to make access decisions based on the collected information. The technical benefit of this approach is that access decisions regarding whether to allow a user to access the requested content can typically be automated without compromising the security of the content. One or more machine learning models evaluate whether a user requesting access to a content item should be granted access to the requested content. The system includes a unit for providing feedback to the object owner and / or other users regarding the automated access decisions to improve the access decisions made by the models. This approach provides an improved user experience by automating many access decisions to avoid interrupting the user workflow while implementing security and privacy considerations associated with the requested content item. The techniques herein can be applied to various types of security architectures, including but not limited to zero-trust architectures, where users both inside and outside the enterprise network are subject to strict authentication and authorization requirements to access digital content protected by the security architecture. These and other technical benefits of the techniques disclosed herein will be apparent from the discussion of the following exemplary embodiments.

[0017] Figure 1 FIG. is a diagram showing an exemplary computing environment 100 in which the techniques for access decision management disclosed herein can be implemented. The computing environment 100 may include a content access management platform 110. The exemplary computing environment 100 may also include client devices 105a, 105b, 105c, and 105d (collectively client devices 105) and an application service 125. The client devices 105a, 105b, 105c, and 105d may communicate with the content access management platform 110 and / or the application service 125 via a network 120. Additionally, the application service 125 may communicate with the content access management platform 110 via the network 120. The network 120 may be a combination of one or more public and / or private networks and may be at least partially implemented by the Internet.

[0018] In Figure 1In the example shown, the content access management platform 110 is implemented as a cloud-based service or set of services. The content access management platform 110 is configured to store and manage access rights to enterprise content for client devices 105a - 105d. Enterprise content can include various types of digital resources such as, but not limited to, documents, files, applications, data sources, program code, and / or other such digital content. The content access management platform 110 is configured to make automated access decisions in response to user requests to access content items.

[0019] In some embodiments, the content access management platform 110 is configured to receive an access request from a content requester to access specific content and forward the request to the content owner for processing. The content requester is a user who does not have access rights to the requested content item, and the content owner is the user who created the content item and / or manages who can access the content item. In some embodiments, the content owner can specify in the access control parameters associated with the content item that the content owner must manually approve or deny all access requests for the content item. In such an embodiment, the content access management platform 110 sends the access request to the content owner, which identifies the content requester and the content item for which access rights are being sought. The content owner can then respond to the access request by granting the content requester access rights to the content item or denying the content requester access rights to the content item. As will be discussed in more detail in the following examples, the content owner can configure the access level and the length of time for which access rights are granted. Additionally, the content owner can provide a reason for which the access request was denied.

[0020] In some cases, the content access management platform 110 is configured to automate access decisions. In some embodiments, the content access management platform 110 is configured to automatically make access decisions for content when the content owner is unavailable. The term "unavailable" user, as used herein, refers to a content owner who is offline and / or busy with other tasks and is thus unlikely to be able to respond to an access request in a timely manner. The content access management platform 110 collects data from various information sources, such as but not limited to calendar information, work schedule information, meeting invitations, and / or other types of information that can be used to predict whether a content owner is likely to respond to an access request within a predetermined amount of time. When determining whether to make an automated access decision, the content access management platform 110 can also consider how long it typically takes the content owner to respond to an access request. In some embodiments, the content access management platform 110 can grant the content requester temporary and / or limited access to the requested content and send an access request to the content owner for confirmation of whether access should have been granted. The content owner can confirm that the access grant was correctly determined by the content access management platform 110 or revoke the access rights granted to the content requester. The user can also configure the access levels granted to the user. The control management platform 110 uses one or more machine learning models to make these grant decisions, and the one or more machine learning models are trained to predict whether access rights should be granted to the requesting user. Feedback provided by the content owner is used to improve the access grant predictions made by the one or more models. The one or more models are trained to analyze various types of information to make automated access control decisions, including but not limited to information indicating the relationship between the content owner and the content requester, information indicating the relationship between the content requester and the content for which access rights are being requested, access control settings associated with the requested content, and / or historical information indicating the type of user. Additional details of the functionality provided by the content access management platform 110 are provided in the following examples.

[0021] In some embodiments, at least a portion of the content access management platform 110 or its functionality can be implemented by the application service 125 to provide content storage and / or management of access rights to content for users of the application service. In other embodiments, at least a portion of the content access management platform 110 or its functionality can be implemented by native applications on the client devices 105a, 105b, 105c, and 105d.

[0022] Application service 125 provides cloud-based software and services accessible to users via client devices 105a, 105b, 105c, and 105d. Application service 125 provides one or more software applications, including but not limited to communication platforms and / or collaboration platforms, word processing applications, presentation design applications, and / or other types of applications in which users can create and / or access electronic content. The electronic content can be stored on content access management platform 110 and / or client devices 105a - 105d. The term "electronic content" as used herein can represent any document or component in electronic form that can be created by a computing device, stored on a machine-readable medium, and / or transmitted among computing devices via a network connection or via a machine-readable medium. Examples of such electronic documents include but are not limited to word processing documents, program code, presentations, websites (e.g., Microsoft sites), digital drawings, media files, their components, etc.

[0023] Client devices 105a, 105b, 105c, and 105d are each computing devices that can be implemented as portable electronic devices, such as mobile phones, tablet computers, laptop computers, portable digital assistant devices, portable game consoles, and / or other such devices. Client devices 105a, 105b, and 105c can also be implemented as computing devices with other form factors, such as desktop computers, in-vehicle computing systems, kiosks, point-of-sale systems, video game consoles, and / or other types of computing devices. Although Figure 1 the exemplary embodiment shown includes four client devices, other embodiments can include a different number of client devices 105 that utilize application service 125 and / or content access management platform 110. Additionally, in some embodiments, the application functionality provided by application service 125 is implemented by native applications installed on client devices 105a, 105b, 105c, and 105d, and client devices 105a, 105b, 105c, and 105d communicate directly with content access management platform 110 via a network connection.

[0024] In Figure 1In the exemplary embodiments shown, each of client devices 105a, 105b, 105c, and 105d is associated with the same user to more clearly illustrate the techniques herein. In this exemplary embodiment, client device 105a is a laptop computer, client device 105b is a desktop computer, client device 105c is a mobile phone, and client device 105d is a tablet computer 105d. However, in other embodiments, a user may be associated with a different number and / or different type or multiple types of client devices. In typical embodiments, content access management platform 110 provides file storage and management services to a number of users associated with one or more client devices 105. Additionally, in some embodiments, content access management platform 110 facilitates file synchronization among the devices of more than one user. For example, users within an organization or enterprise, a family, or other user group may allow certain files and / or folders to be shared with other designated users and synchronized with one or more client devices 105 of other users.

[0025] Figure 2 FIG. is a diagram showing additional features of content access management platform 110, client device 105, and application service 125. Content access management platform 110 includes a request processing unit 205, an access determination unit 210, an access determination model 215, a content management data store 220, an authentication unit 225, a user interface unit 230, a model adjustment unit 235, and an access-related data source 240.

[0026] Request processing unit 205 receives an incoming request for accessing content managed by content access management platform 110 from client device 105 and / or application service 125. The incoming request may be for a content item that the content requestor already has access rights to, or may be for a content item that the content requestor does not have access rights to. The request includes information identifying one or more content items being requested and identifying the content requestor. Request processing unit 205 provides the incoming request to access determination unit 210, which determines whether the user is authorized to access the requested content.

[0027] The access determination unit 210 accesses content information from the content management data store 220, which stores access control information associated with files managed by the content access management platform 110. The access control information identifies the content owners of each content item and any access control policies associated with those content items. The access control policies indicate which users can access those content items. In some embodiments, the access control policies enumerate the specific users granted access rights to a particular content item, and the access levels of these users are provided. In a non-limiting example, a first user is granted full access rights to a content item, which allows the first user to access and / or modify the content item, while a second user is granted limited access rights to the content item, which provides read-only access rights to the second user. In some embodiments, the access control policies may indicate that certain user groups are allowed to access the content items. Such groups may include, but are not limited to, certain teams, groups, or departments within an enterprise. The access control policies may also impose restrictions on how the content items can be utilized. Such restrictions may include, but are not limited to, preventing the content item from being printed, sent via email to email addresses outside the enterprise, preventing the content from being copied and pasted from the content item to another content item, and / or other such restrictions on the use of the content item.

[0028] The access determination unit 210 is configured to process access control requests from content requesters. The access determination unit 210 determines whether an access request from a content requester requires manual approval by the content owner. The access determination unit 210 accesses the access control information from the content management data store 220 for the content item for which access rights have been requested. If the access control information indicates that manual approval by the content owner is required, the access determination unit generates an access request message and sends it to the content owner. The access request message identifies the content item being requested, the content requester, and / or other relevant information that the content owner can use to evaluate whether to grant or deny access rights to the content item. Other relevant information may include, but is not limited to, the date and time the access request was received by the content access management platform 110, information provided by the content requester indicating why access to the content item is being requested, and / or such information. The access request message may be sent to the content owner via email or via other types of messaging. In some embodiments, the access request message is provided via a user interface provided by the user interface unit 230 of the content access management platform 110. An example of such a user interface is provided in the following example.

[0029] In cases where the access control policy does not require the content owner to manually grant or deny access to the content item and the content owner is currently unavailable, the access determination unit 210 makes an automatic access determination. The access determination unit 210 analyzes data from multiple access-related data sources 240 to determine an access determination score for a specific access request for access to the content item from a specific content requester. The access determination unit 210 considers various factors indicating the relationship between the content owner and the content requester and the relationship between the content requester and the content item being requested. Additional details of the metadata that can be collected and analyzed are described with respect to the access-related data sources 240.

[0030] In some embodiments, the access determination unit 210 uses an access determination model 215 to analyze the metadata to calculate an access determination score for a specific access request. The access determination model 215 is a machine learning model that has been trained to analyze various information about the content requester, the content owner, and the content item being requested to determine an access determination score representing the level of certainty that the content requester should be granted access to the content item. The access determination model 215 can initially be trained offline using a set of labeled training data that trains the model to evaluate the various factors described above when determining whether to automatically grant or deny an access request from the content requester. In various embodiments, various types of machine learning and / or deep learning models can be used to implement the access determination model 215. In some embodiments, the access determination unit 210 is configured to grant the access request if the access determination score exceeds a predetermined threshold. Otherwise, the access request is automatically denied or sent to the content owner for manual approval or denial. In other embodiments, the access determination unit 210 is configured to automatically grant different access levels to the content requester based on the content score. Each access level is associated with a score range, and the access level is granted to the content requester based on the score range into which the access determination score falls. Additional details of how the access determination unit 210 processes access requests are provided in the following examples.

[0031] The user interface unit 230 provides a web application that can be accessed by a browser application or a browser-enabled native application of the client devices 105a - 105d. The web application provides a user interface for accessing content items managed and / or stored on the content access management platform 110. Figures 4A to 4I and Figures 5A to 5G An example of a user interface that can be provided by the user interface unit 230 is shown.

[0032] The content management data store 220 is a persistent data store that the content access management platform 110 uses to store files and / or folders synchronized from the client devices 105a - 105d, metadata associated with the files and / or folders, data collected from various data sources for determining the relationship between the content owner and the content requester, access policy information, and / or other information used by various components of the content access management platform 110.

[0033] The authentication unit 225 provides the function for verifying whether a user is allowed to access the services provided by the content access management platform 110. In some embodiments, the authentication unit 225 provides the function for receiving the user's authentication credentials from the user's corresponding client device 105 and / or from the application service 125. The authentication unit 225 can be configured to verify that the authentication credentials are valid and, in response to the authentication credentials being valid, allow the user to access the services provided by the content access management platform 110.

[0034] The model adjustment unit 235 is configured to fine tune the performance of the access determination model 215. The model adjustment unit 235 is configured to receive feedback from the content owner and / or other authorized users that indicates whether the automated decision to grant the content requester access to a particular content item is correct. In some embodiments, the feedback includes information indicating whether the access level granted to the content requester for a particular content item is correct. The model training unit 235 implements a feedback loop for improving the predictions made by the access determination model 215. The specific implementation of this feedback loop can vary depending on the implementation of the access determination model 215.

[0035] The access - related data sources 240 are various data sources that provide information that can be used to evaluate the relationship between the content requester and the content owner. These data sources can vary depending on the embodiment. Sources of such information include telemetry and usage data collected by the content access management platform 110, the application service 125, and / or the client device 105. Other sources of information include email, messaging data, calendars, and / or meeting information. In addition to or instead of one or more of these data sources, other sources of information can also be utilized.

[0036] The access-related data source 240 also provides information indicating the relationship between the content requester and the content item for which the content requester is requesting access rights. The access-related data source 240 includes enterprise-related data sources, which may include information about the content owner and / or the content requester, such as but not limited to the tenure of a person or a team within the enterprise, the title and / or position of a person within the enterprise, and / or other information indicating the role or responsibility of the person within the enterprise. A significant mismatch between the roles and / or seniority levels of the content owner and the content requester may indicate that the content requester should not be automatically granted access rights to the content item. In some embodiments, the access-related data source 240 includes content-related classification information, such as but not limited to the business impact of the subject matter of the content item, the degree of knowledge of the subject matter of the content item within the organization, and / or other such information indicating how the risk of granting access rights to the content item may be.

[0037] In some embodiments, the access-related data source 240 includes relationship information between the content owner and the content requester, such as but not limited to the frequency of collaboration between the content owner and the content requester, the frequency of communication via email, email, and / or messages, and the frequency of meetings between the content owner and the content requester. The relationship information may indicate that the content owner and the content requester are frequent collaborators. A match between the subject matter of the communication between the content owner and the content requester and the subject matter of the content item being requested indicates that the content requester already knows the content of the content item and may need access rights to the content item. Other relationship information, such as whether the content owner and the content requester are on the same team or different teams within the enterprise, whether they have similar roles within the enterprise, and / or In some embodiments, the access-related data source 240 includes the work pattern of the content requester. The work pattern can be derived from online presence information and / or application usage information collected by the content access management platform 110, the application service 125, and / or the client device 105. The work pattern of the content requester may include information such as but not limited to the typical working hours of the content requester, the device from which the content requester typically accesses the content access management platform 110, the typical volume of access requests submitted by the content requester, and / or other information identifying the typical work pattern of the content requester. Whether two-factor authentication or other trusted authentication techniques have been used to authenticate the content requester is also a factor in the work behavior of the content requester. A significant change in work behavior may indicate that the client device 105 and / or the authentication credentials of the content requester may have been compromised, and any access requests originating from the content requester should not be automatically granted by the content access management platform 110.

[0038] In some embodiments, accessing the relevant data source 240 may include additional information about the content requester, which can be used to evaluate whether the content requester can be trusted and whether the content access management platform 110 can automatically grant access rights to content items. This information may include how long the content requester has worked at the enterprise and / or the title and seniority level of the content requester within the enterprise. The content access management platform 110 assigns a higher access determination score to content requesters who have worked at the enterprise for a longer time and / or hold senior positions within the enterprise because such users are less likely to act maliciously.

[0039] The application service 125 includes an application service unit 260 and / or an authentication unit 265. The application service unit 260 provides functions for users to consume, create, share, collaborate, and / or modify various types of electronic content. The application service unit 260 may utilize the content access management platform 110 to store electronic content in files and / or access existing electronic content in files stored on the content access management platform 110 and / or client devices 105a - 105d. Files may also be organized into folders, and folders may also include a mixture of files and other folders. In some embodiments, the application service unit 260 provides a web-based interface to enable users to access at least a portion of the services provided by the application service 125. In other embodiments, users may access the services provided by the application service 125 via one or more native applications 250. The application service unit 260 may further obtain the services provided by the content access management platform 110.

[0040] The authentication unit 265 provides a function for verifying whether a user is allowed to access the services and / or documents provided by the application service 125 and / or the content access management platform 110. In some embodiments, the authentication unit 265 provides a function for receiving the user's authentication credentials from the user's corresponding client device 105. In such embodiments, the authentication unit 265 verifies that the authentication credentials are valid and allows the user to access the services and / or documents provided by the application service 125 and / or the content access management platform 110 in response to the authentication credentials being valid.

[0041] The client device 105 may include one or more native applications 250 and / or browser applications 255. In some embodiments, one or more native applications 250 include native applications configured to communicate with the application service 125 to enable a user to consume, create, share, collaborate, and / or modify electronic content using the services provided by the application service 125. In some embodiments, one or more native applications 250 include native applications configured to communicate with the content access management platform 110. In such embodiments, the native applications provide an interface for the user to interact with the content access management platform 110. The user interface also enables a content requester to select content and submit a request for access rights to the content item. Examples of such user interfaces are shown in Figures 4A to 4I as shown. The user interface also enables a content owner to manage access requests. Examples of such user interfaces are shown in Figures 5A to 5G as shown.

[0042] The browser application 255 is an application for accessing and viewing web-based content, which may be provided by the application service 125 and / or the content access management platform 110. The application service 125 may provide a web application 290 that enables a user to consume, create, share, collaborate, and / or modify content. A user of the client device 105 may access the web application 290 via the browser application 255, and the browser application presents a user interface for interacting with the application service 125 within the browser application 255. In some embodiments, the user interface unit 230 of the content access management platform 110 provides a web application that enables a user to utilize the services of the content access management platform 110 in a manner similar to the native applications described above.

[0043] The application service 125 and / or the content access management platform 110 may support both one or more web-enabled native applications 250 and one or more web applications 290, and the user may choose which approach best suits their needs. The content access management platform 110 may also provide support for one or more native applications 250, browser applications 255, or both, to provide functionality for a user of the client device 105 to obtain the services provided by the content access management platform 110.

[0044] Figures 3A to 3C An example of the interaction between the client device 105 and the content access management platform 110 is shown. In Figure 3AIn the example shown, the client device 105b of the content requester sends an access request 302 to the content access management platform 110. In some embodiments, the access request 302 is generated by the native application 250 on the client device 105b. In other embodiments, the access request 302 is generated by a web-based interface of a web application implemented by the content access management platform 110, and the web-based interface is accessed via the browser application 255. An example of a user interface that can be presented to the user on the client device 105 is shown in Figures 4A to 4I and is described in detail in the following example. The access request includes an identifier of the user.

[0045] The access determination unit 210 of the content access management platform 110 accesses content information from the content management data store 220 to determine the content owner of the content item for which access rights have been requested. The access determination unit 210 then sends an access request 304 to the client device 105a of the content owner. In this embodiment, the content owner has requested to manually process access requests from other users. This approach provides the content owner with an opportunity to consider the request and decide whether to grant or deny access rights to the content item. In other embodiments, the content access management platform 110 determines that the content provider is contactable or likely to become contactable within a predetermined amount of time. The content access management platform 110 generates an access request 304 and sends it to the client device 105a of the content owner. The access request 304 includes information identifying the content item for which access rights have been requested and information identifying the content requester. This information can be obtained at least in part from the access request 302 sent to the content access management platform 110 and can include additional information about the content requester from the content management data store 220. In some embodiments, the content access management platform 110 obtains information such as, but not limited to, work relationship information, information about current and / or past collaborations between the content requester and the content owner, meeting information, and / or other information indicating the relationship between the content requester and the content owner.

[0046] The client device 105a sends a content access response 306 to the content access management platform 110, and the content access response 306 indicates whether the content owner has granted or denied the access request 304. The client device 105a presents a user interface via the native application 250 or the browser application 255. In Figures 5A to 5D an example of such an interface that can be presented to the content owner to grant or deny access rights to the content item is shown and is described in detail in the following example. In response to receiving the content access response 306 from the client device 105a of the content owner, the access determination unit 210 of the client management platform 110 generates a content access response 308 for the client device 105b of the content requester.

[0047] Figure 3B is a diagram of another exemplary embodiment, where the access determination unit 210 of the content access management platform 110 requests information from the content requester to justify granting the content requester access rights to the content item. The access request 310 is similar to Figure 3A the access request 302 shown in Figure 3B In the exemplary embodiment shown, the access determination unit 210 of the content access management platform 110 sends a request 312 for access justification reasons to the client device 105b of the content requester. The client device 105b of the content requester prompts the content requester to provide a short description of one or more reasons for the content requester to request access rights to the content item. Figure 4H An exemplary user interface for requesting information from the content requester is shown in The client device 105b of the content requester sends the justification information 314 to the content access management platform 110. The access determination unit 210 performs semantic analysis on the justification information 314 to extract the meaning of the information provided by the content requester. The semantic analysis can be achieved by analyzing the justification information 314 using a natural language processing (NLP) model configured to perform semantic analysis of text content. The semantic model can be one of several access determination models 215 utilized by the content access management platform 110. The content item and / or the metadata associated with the content item stored in the content management data store 220 may include semantic information. In other embodiments, the content item can be analyzed by the semantic model to obtain semantic information about the content item. In some embodiments, the content management data store 220 analyzes the content item in response to the content item being added to the content access management platform 110 by the content owner. The access determination unit 210 compares the semantic information of the content item with the semantic information of the justification information 314 to determine a relevance score. If the relevance score exceeds a predetermined threshold, the access determination unit 210 determines that the content requester has a legitimate business reason for requesting the content item.

[0048] In Figure 3B the embodiment shown, the access determination unit 210 uses the relevance score as one of the factors for determining whether to automatically grant access rights to the content item. The content access management platform 110 generates a content access response 316 indicating whether access rights to the content item have been granted or denied, and sends the response to the client device 105b of the content requester.

[0049] In such an embodiment, the access determination unit 210 of the content access management platform 110 generates a confirmation request 318 to the content owner, which is used to request the content owner to verify that the automatic access decision made by the content access management platform 110 to grant or deny the access right to the content item is correct. The client device 105a of the content owner presents a user interface that enables the content owner to provide feedback to the content access management platform 110. The feedback can be used to fine-tune the performance of the model used to make the automatic access decision. The client device 105b of the content owner provides a content owner response 320 to the content access management platform 110, including the feedback provided by the content owner.

[0050] Figure 3C FIG. is of another exemplary embodiment, in which the access determination unit 210 of the content access management platform 110 requests confirmation from a user associated with the content owner. Figure 3C The process shown in can be used in cases where the content owner fails to respond to the request and / or is otherwise unable to confirm whether the content access management platform 110 has correctly granted or denied the access right to the content item. In such an embodiment, the access request 322 is respectively similar to Figure 3A and Figure 3B the access requests 302 and 310 shown in. The request 324 for access justification is similar to Figure 3B the request 312 for access justification shown in. The justification information 326 is similar to Figure 3B the justification information 314 shown in, and the content access response 332 is respectively similar to Figure 3A and Figure 3B the content access responses 308 and 316 shown in.

[0051] In some cases, the content owner may be unable to be contacted or may not respond to requests from the content access management platform 110 for granting or denying access rights to a content item or for confirming an automated decision. The access determination unit 210 accesses information about the content owner to identify an alternative user who can confirm whether the content access management platform 110 has made a correct automated decision to grant or deny access rights to the content item. In some embodiments, the access determination unit 210 may obtain information about the content owner's supervisor and send a confirmation request 328 to the client device 105c of the content owner's supervisor. In other embodiments, the access determination unit 210 determines whether any other user has contributed to the development of the content item. In some embodiments, the content access management platform 110 tracks which users created portions of the content item or otherwise contributed to the content item. In some embodiments, this information is stored in the version history of the content item. In a non-limiting example, the content owner creates a document, but a second user contributes to the creation of the document. The access determination unit 210 uses this information to identify a second user who is a colleague of the content owner and who contributed to the content item, and sends a confirmation request 328 to the second user. The client device 105c of the second user then sends a confirmation response 330 that indicates whether the automated access decision to grant or deny access rights to the content item is correct. The second user may also choose not to respond to the message, or may suggest an alternative user who may be more suitable for confirming whether the automated access decision is correct. The access determination unit 210 may rely on various sources of information to determine the relationship between the user and an alternative user who may be able to confirm whether the automated access decision made by the content access management platform 110 is appropriate.

[0052] Figures 4A to 4I FIG. is a diagram of an exemplary user interface 405 associated with the content access management platform 110. In some embodiments, the user interface 405 is provided by a native application 250 of the client device 105 of the content requester. In other embodiments, the user interface 405 is provided by a web application implemented by the user interface unit 230 of the content access management platform 110, and the web application is accessed via a browser application 255 of the client device 105 of the content requester. The user interface 405 shows a content item 402 stored on the user's client device 105. The user interface also shows content items associated with a first item 404 and content items associated with a second item 410. In this example, the requesting user needs to access a document 406 named "Document C" in this example. However, the user does not have permission to access the document 406.

[0053] Figure 4BShows an example of menu 420 displayed in response to a user clicking, hovering over, or otherwise interacting with document 406. Menu 420 provides various options for interacting with document 406, including an option to request access to the file. In other embodiments, user interface 405 may attempt to access and open an instance of document 406 in response to the user clicking on document 406 or otherwise interacting with document 406. In such an embodiment, a notification may be presented to the user, such as Figure 4C notification 422 shown in Figure 4C , which notifies the user that they do not have access to the file. Notification 422 provides information about the content owner and asks the content requester if they want to submit an access request to the content owner to obtain access to the file. Notification 422 may also be displayed in response to the user selecting the "Request access to file" option from menu 420. Clicking or otherwise activating the "Request access" option from notification 422 causes the content requester's client device 105b to send an access request, similar to Figures 3A to 3C access requests 302, 310, and 322 shown in Figures 3A to 3C .

[0054] Figure 4D is another example of user interface 405, which provides notification 424 indicating that an access request for document 406 is currently pending. In this exemplary embodiment, notification 424 includes an estimate of how long it typically takes for the content owner to respond to an access request. Notification 424 may include a button or other control that allows the content requester to cancel the pending request. Access determination unit 210 accesses historical information indicating how long each content owner typically takes to respond to an access request. In some embodiments, the time taken for each content owner to respond to an access request may be averaged to determine the estimate. In other embodiments, the response times to access requests may be weighted, where more recent response times are given greater weight compared to less recent response times.

[0055] Figure 4E is another example of user interface 405, which provides notification 426 indicating that an access request for document 406 is pending, but the content requester has been granted temporary read-only access to the requested content item. In some embodiments, access determination unit 210 provides temporary access to the requested content item while the request is pending. In some embodiments, access determination unit 210 provides limited access rights to the content requester while the access request is pending. Access determination unit 210 may limit the type of actions that the content requester is allowed to perform and / or the length of time that the content requester has access to the content item based on an access score determined by access determination model 215.

[0056] Figure 4Fis another example of the user interface 405 that provides a notification 428 indicating that an access request from a content requester has been granted. The access request can be granted manually by the content owner or automatically by the access determination unit 210.

[0057] Figure 4G is another example of the user interface 405 that provides a notification 430 indicating that an access request from a content requester has been denied. In some embodiments, the notification 430 includes information indicating why the request was denied. The notification 430 can be provided in response to the content owner manually denying the access request or in response to the access determination unit 210 automatically determining that the access request should be denied.

[0058] Figure 4H is another example of the user interface 405 that provides a notification 432 requesting additional information from the content requester. The notification 432 can be used to capture the justification information 314 or 326 shown in Figure 3B and Figure 3C respectively. The notification 432 can be presented to the user in response to a request for access justification, such as the requests 312 and 324 shown in Figure 3B and Figure 3C respectively.

[0059] Figure 4I is another example of the user interface 405 that provides a notification 434 indicating that the access right to a content item has been revoked. In some embodiments, the access determination unit 210 of the content access management platform 110 is configured to monitor the behavior of a content requester once an access right for accessing a content item has been granted to the content requester. The access right can be granted manually by the content owner or automatically by the content access management platform 110. A significant change in the behavior of the content requester can indicate that the client device 105 of the content requester and / or the authentication credentials of the content requester may have been compromised, and a malicious actor may be using the client device 105 of the content requester and / or the authentication credentials to access the content items whose access rights are managed by the content access management platform 110. In some embodiments, after the content access management platform 110 automatically grants an access right to a content item, the access determination unit 210 determines that the access right to the content item should not be granted based on the behavior of the content requester. In some embodiments, the access determination unit 210 determines that the content owner should not manually grant an access right to a content item based on the information available to the content access management platform 110.

[0060] The access determination unit 210 automatically withdraws the access rights that have been granted in response to determining that the access rights should not be granted to the content requester. The access determination unit 210 notifies the content requester that the access rights have been withdrawn. In some embodiments, the access determination unit 210 causes the notification 434 to be presented to the content requester. In some embodiments, the access determination unit 210 generates an email or other notification to the content requester. The access determination unit 210 notifies the content owner and / or other users that the access rights granted to the content requester have been withdrawn.

[0061] Figures 5A to 5G is an example of a user interface that can be used by a content owner to grant or deny access requests and / or configure the access level granted to a content requester. In some embodiments, Figures 5A to 5G the user interface example shown in is provided by the native application 250 of the content owner's client device 105. In other embodiments, Figures 5A to 5G the user interface example shown in is provided by a web application implemented by the user interface unit 230 of the content access management platform 110, and the web application is accessed via the browser application 255 of the content owner's client device 105.

[0062] Figure 5A shows an exemplary user interface 505 that displays an access request message that has been sent to the content owner. The access request message can be Figure 3A the access request 304 shown in. The access request identifies the content requester and the content item being requested. The user interface 505 provides controls that enable the content owner to grant access rights to the content requester or deny access rights to the content owner.

[0063] Figure 5B is similar to Figure 5A a diagram of an exemplary user interface 510 similar to the user interface 505 shown in. The user interface 510 includes justification information provided by the content requester. This information can help the content owner make a decision on granting or denying access rights to the content item.

[0064] Figure 5C is a diagram of an exemplary user interface 515. The user interface 515 provides controls that enable the content user to configure the access level granted to the content requester for the requested content item. The user interface 515 provides controls for submitting access configuration information entered by the user and for canceling the configuration of the granted access rights. The user interface 515 can be displayed in response to the user selecting "Grant Access Rights" on the user interface 505 or 510 or selecting "Configure Access Rights" on the user interface 520.

[0065] Figure 5DIt is a diagram of an exemplary user interface 520. The user interface 520 shows a confirmation request that has been sent to the content owner in response to an automatic access decision made by the content access management platform 110. The user interface 520 includes controls for confirming that access rights should have been granted, revoking access rights that have been granted, and configuring the access level that has been granted.

[0066] Figure 5E It is a diagram of an exemplary user interface 525. The user interface 525 provides a means for a content owner or other authorized user to provide a reason why the access rights of a content requester should be revoked. The user interface 525 can be displayed in response to the user selecting the "Revoke Access Rights" action from the user interface 520. The information collected from the user interface 525 can be used as feedback for the model training and adjustment unit 235 to fine-tune the access control predictions made by the access determination model 215.

[0067] Figure 5F It shows an exemplary user interface 530 that displays an access revocation message that has been sent to the content owner. In Figure 5F the example shown, the content access management platform 110 automatically grants access rights to a content requester and then determines that the access rights should be revoked. The content access management platform 110 notifies the content owner that the access rights to the content item have been revoked for the content requester. The content owner can confirm that they agree to the revocation by clicking the "Confirm Revocation" button. If the content owner does not agree to the revocation, the content owner can manually configure the access rights by clicking the "Configure Access Rights" button, which overrides the decision of the content access management platform 110. Then the Figure 5C user interface shown in can be presented to the content owner to configure the access rights for the content requester. In some embodiments, the access revocation message provides a reason why the access rights have been revoked. In other embodiments, the content owner can click the "More Information" button to obtain additional information about why the access rights have been revoked.

[0068] Figure 5G It shows an exemplary user interface 535 that displays an access revocation message that has been sent to the content owner. In Figure 5G the example shown, the content owner grants access rights to the content requester, and the content access management platform 110 determines that the access rights should be revoked. The content access management platform 110 notifies the content owner that the access rights to the content item have been revoked for the content requester. The content owner can confirm that they agree to the revocation by clicking the "Confirm Revocation" button. If the content owner does not agree to the revocation, the content owner can manually configure the access rights by clicking the "Configure Access Rights" button, which overrides the decision of the content access management platform 110. Then the Figure 5CThe user interface shown in is presented to the content owner to configure access rights for the content requester. In some embodiments, the access revocation message provides the reason why the access rights have been revoked. In other embodiments, the content owner can click a "more information" button to obtain additional information that the access rights have been revoked.

[0069] Figure 6 is an exemplary flow chart of an exemplary process 600 for automatic access control decisions. The process 600 may be implemented by the content access management platform 110.

[0070] Process 600 includes an operation 610 of receiving an access request from a client device of a content requester, the access request being for access to a content item for which access rights are managed by a content access management platform. Figures 3A to 3C As shown in other aforementioned examples, the client device 105 of the content requester sends an access request to the content access management platform 110. The request processing unit 205 of the content access management platform 110 receives the access request and provides the request to the access determination unit 210 for processing.

[0071] Process 600 includes an operation 620 of obtaining access control information. The access control information may include information related to a content owner associated with the content item, information associated with a content requester, and information associated with the content item. Access determination unit 210 accesses information from multiple data sources, as discussed in the previous examples, to make an access determination of whether to automatically grant or deny access to a content requester to a content item. Information from these various sources may be stored in content management data storage area 220.

[0072] Process 600 includes an operation 630 of analyzing access control information using a first machine learning model that is trained to analyze access control information and output an access determination score. The first machine learning model is access determination model 215. The access determination score represents a level of certainty that a content requester should be granted access to the content item.

[0073] The process 600 includes an operation 640 of determining an automatic access decision to grant or deny the access request based on the access determination score. As discussed in the previous example, the access determination unit 210 grants at least a certain level of access to the content requester in response to the access determination score exceeding a predetermined threshold. Otherwise, the access determination unit 210 denies the access request. In other embodiments, the access determination unit 210 is configured to grant different levels of access based on the access determination score.

[0074] Process 600 includes operation 650 of notifying a content requester whether the access request is granted or denied based on an automated access decision. The content access management platform 110 provides a content access response to the client device 105 of the content requester. At least as Figures 4C to 4G shown, the content access response is presented to the user on the user interface of the client device 105 of the content requester.

[0075] To illustrate the present disclosure and its benefits, detailed examples of systems, devices, and techniques described in connection with Figures 1 to 6 are presented herein. Such usage examples should not be construed as limiting the embodiments of the logical processes of the present disclosure, nor should variations from the user interface methods described herein be considered outside the scope of the present disclosure. It should be understood that references to displaying or presenting an item (such as, but not limited to, presenting an image on a display device, presenting audio via one or more speakers, and / or a vibrating device) include issuing instructions, commands, and / or signals that cause or reasonably expect to cause a device or system to display or present the item. In some embodiments, Figures 1 to 6 the various features described in are implemented in corresponding modules, which may also be referred to as and / or include logic, components, units, and / or mechanisms. Modules may constitute software modules (e.g., code embodied on a machine-readable medium) or hardware modules.

[0076] In some examples, hardware modules may be implemented mechanically, electronically, or using any suitable combination thereof. For example, a hardware module may include dedicated circuitry or logic configured to perform certain operations. For example, a hardware module may include a dedicated processor, such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). A hardware module may also include programmable logic or circuitry that is temporarily configured by software to perform certain operations, and may include a portion of machine-readable media data and / or instructions for such configuration. For example, a hardware module may include software contained within a programmable processor configured to execute a software instruction set. It should be understood that the decision to implement a hardware module mechanically, in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost, time, support, and engineering considerations.

[0077] Accordingly, the phrase "hardware module" should be understood to encompass a tangible entity capable of performing certain operations and that can be configured or arranged in some physical manner, which can be physically constructed, permanently configured (e.g., hardwired), and / or temporarily configured (e.g., programmed) to operate or perform certain operations described herein in a certain way. As used herein, a "hardware-implemented module" refers to a hardware module. Considering examples where a hardware module is temporarily configured (e.g., programmed), each hardware module need not be configured or instantiated at any given moment. For example, in the case where a hardware module includes a programmable processor that is configured by software to become a dedicated processor, the programmable processor can be configured at different times to be different dedicated processors (e.g., including different hardware modules). Software can accordingly configure one or more processors, e.g., to constitute a particular hardware module at one moment and different hardware modules at different moments. A hardware module implemented using one or more processors can be referred to as "processor-implemented" or "computer-implemented".

[0078] Hardware modules can provide information to and receive information from other hardware modules. Accordingly, the described hardware modules can be regarded as communicatively coupled. In cases where multiple hardware modules are present simultaneously, communication can be achieved via signal transmission between or among two or more hardware modules (e.g., via appropriate circuitry and buses). In embodiments where multiple hardware modules are configured or instantiated at different times, communication between such hardware modules can be achieved, for example, by storing and retrieving information in a memory device accessible by the multiple hardware modules. For example, one hardware module can perform an operation and store the output in a memory device, and another hardware module can then access the memory device to retrieve and process the stored output.

[0079] In some examples, at least some operations of a method can be performed by one or more processors or processor-implemented modules. Additionally, one or more processors can also operate to support the performance of related operations in a "cloud computing" environment or as "software as a service" (SaaS). For example, at least some of the operations can be performed by multiple computers (as examples of machines including processors) and / or among multiple computers, where the operations can be accessed via a network (e.g., the Internet) and / or via one or more software interfaces (e.g., application programming interfaces (APIs)). The performance of certain operations can be distributed among processors, not only residing within a single machine but also deployed across several machines. Processors or processor-implemented modules can be in a single geographical location (e.g., in a home or office environment or within a server farm), or can be distributed across multiple geographical locations.

[0080] Figure 7FIG. 700 is a block diagram showing an exemplary software architecture 702, various parts of which can be used in conjunction with the various hardware architectures described herein and which can implement any of the above features. Figure 7 This is a non-limiting example of a software architecture, and it should be understood that many other architectures can be implemented to facilitate the functions described herein. The software architecture 702 can execute on hardware such as Figure 8 a machine 800 including a processor 810, a memory 830, input / output (I / O) components 850, etc. A representative hardware layer 704 is illustrated and can represent, for example, Figure 8 a machine 800. The representative hardware layer 704 includes a processing unit 706 and associated executable instructions 708. The executable instructions 708 represent the executable instructions of the software architecture 702, including the implementation of the methods, modules, etc. described herein. The hardware layer 704 also includes a memory / storage 710, which also includes the executable instructions 708 and accompanying data. The hardware layer 704 may also include other hardware modules 712. The instructions 708 held by the processing unit 706 may be part of the instructions 708 held by the memory / storage 710.

[0081] The exemplary software architecture 702 can be conceptualized as layers, each layer providing various functions. For example, the software architecture 702 can include layers and components such as an operating system (OS) 714, libraries 716, frameworks 718, applications 720, and a presentation layer 744. In operation, the applications 720 and / or other components within the layer can make API calls 724 to other layers and receive corresponding results 726. The illustrated layers are representative in nature, and other software architectures may include additional or different layers. For example, some mobile or dedicated operating systems may not provide a framework / middleware 718.

[0082] The OS 714 can manage hardware resources and provide common services. The OS 714 can include, for example, a kernel 728, services 730, and drivers 732. The kernel 728 can act as an abstraction layer between the hardware layer 704 and other software layers. For example, the kernel 728 can be responsible for memory management, processor management (e.g., scheduling), component management, networking, security settings, etc. The services 730 can provide other common services to other software layers. The drivers 732 can be responsible for controlling or interfacing with the underlying hardware layer 704. For example, depending on the hardware and / or software configuration, the drivers 732 can include a display driver, a camera driver, a memory / storage driver, a peripheral driver (e.g., via a Universal Serial Bus (USB)), a network and / or wireless communication driver, an audio driver, etc.

[0083] The library 716 can provide a common infrastructure that can be used by the application 720 and / or other components and / or layers. The library 716 generally provides functions used by other software modules to perform tasks, rather than directly interacting with the OS 714. The library 716 can include system libraries 734 (such as the C standard library) that can provide functions such as memory allocation, string manipulation, and file operations. Additionally, the library 716 can include API libraries 736, such as media libraries (e.g., supporting the rendering and manipulation of image, sound, and / or video data formats), graphics libraries (e.g., the OpenGL library for rendering 2D and 3D graphics on a display), database libraries (e.g., SQLite or other relational database functions), and web libraries (e.g., WebKit that can provide web browsing functionality). The library 716 can also include a variety of other libraries 738 to provide numerous functions for the application 720 and other software modules.

[0084] The framework 718 (sometimes also referred to as middleware) provides a higher-level common infrastructure that can be used by the application 720 and / or other software modules. For example, the framework 718 can provide various graphical user interface (GUI) functions, advanced resource management, or advanced location services. The framework 718 can provide a wide range of other APIs for the application 720 and / or other software modules.

[0085] The application 720 includes built-in applications 740 and / or third-party applications 742. Examples of built-in applications 740 can include, but are not limited to, a contacts application, a browser application, a location application, a media application, a messaging application, and / or a gaming application. Third-party applications 742 can include any application developed by an entity other than the vendor of a particular platform. The application 720 can use the functions available via the OS 714, the library 716, the framework 718, and the presentation layer 744 to create a user interface to interact with the user.

[0086] Some software architectures use virtual machines, as shown by the virtual machine 748. The virtual machine 748 provides an execution environment in which applications / modules can execute as if they were executing on a hardware machine (e.g., Figure 8 machine 800). The virtual machine 748 can be hosted by a host OS (such as the OS 714) or a hypervisor, and can have a virtual machine monitor 746 that manages the operation of the virtual machine 748 and its interoperability with the host operating system. A software architecture different from the software architecture 702 outside the virtual machine can execute within the virtual machine 748, such as an OS 750, a library 752, a framework 754, an application 756, and / or a presentation layer 758.

[0087] Figure 8FIG. 0 is a block diagram showing components of an exemplary machine 800 configured to read instructions from a machine-readable medium (e.g., a machine-readable storage medium) and perform any of the features described herein. The exemplary machine 800 is in the form of a computer system in which instructions 816 (e.g., in the form of software components) can be executed to cause the machine 800 to perform any of the features described herein. Thus, the instructions 816 can be used to implement the modules or components described herein. The instructions 816 cause the unprogrammed and / or unconfigured machine 800 to act as a particular machine configured to perform the described features. The machine 800 can be configured to act as a stand-alone device or can be coupled (e.g., networked) to other machines. In a networked deployment, the machine 800 can operate in the capacity of a server machine or a client machine in a server-client network environment, or as a node in a peer-to-peer or distributed network environment. The machine 800 can be embodied as, for example, a server computer, a client computer, a personal computer (PC), a tablet computer, a laptop computer, a netbook, a set-top box (STB), a gaming and / or entertainment system, a smart phone, a mobile device, a wearable device (e.g., a smart watch), and an Internet of Things (IoT) device. Further, although only a single machine 800 is shown, the term "machine" includes a collection of machines that individually or jointly execute the instructions 816.

[0088] The machine 800 can include a processor 810, a memory 830, and I / O components 850, which can be communicatively coupled via, for example, a bus 802. The bus 802 can include multiple buses that couple the various elements of the machine 800 via various bus technologies and protocols. In an example, the processor 810 (including, for example, a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), an ASIC, or a suitable combination thereof) can include one or more processors 812a through 812n that can execute the instructions 816 and process data. In some examples, one or more of the processors 810 can execute instructions provided or identified by one or more other processors 810. The term "processor" includes multi-core processors that include cores that can execute instructions simultaneously. Although Figure 8 multiple processors are shown, the machine 800 can include a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors each with a single core, multiple processors each with multiple cores, or any combination thereof. In some examples, the machine 800 can include multiple processors distributed across multiple machines.

[0089] The memory / storage device 830 may include a main memory 832, a static memory 834, or other memories, as well as storage units 836, both of which may be accessed by the processor 810, for example, via the bus 802. The storage units 836 and the memories 832, 834 store instructions 816 embodying any one or more of the functions described herein. The memory / storage device 830 may also store temporary, intermediate, and / or long-term data for the processor 810. The instructions 816 may also reside, in whole or in part, within at least one of the memories 832, 834, within the storage units 836, within at least one of the processors 810 (e.g., within a command buffer or cache memory), within at least one of the I / O components 850, or in any suitable combination thereof during their execution. Accordingly, the memories 832, 834, the storage units 836, the memories in the processors 810, and the memories in the I / O components 850 are examples of machine-readable media.

[0090] As used herein, "machine-readable medium" refers to a device that can temporarily or permanently store instructions and data that cause a machine 800 to operate in a specific manner, and may include, but is not limited to, random access memory (RAM), read-only memory (ROM), buffer memory, flash memory, optical storage media, magnetic storage media and devices, cache memory, network-accessible or cloud storage devices, other types of storage devices, and / or any suitable combination thereof. The term "machine-readable medium" applies to a single medium or a combination of multiple media used to store instructions (e.g., instructions 816) executable by a machine 800 such that the instructions, when executed by one or more processors 810 of the machine 800, cause the machine 800 to perform one or more of the features described herein. Thus, "machine-readable medium" may refer to a single storage device, as well as a "cloud-based" storage system or storage network that includes multiple storage devices or devices. The term "machine-readable medium" does not include signals themselves.

[0091] The I / O components 850 may include various hardware components adapted to receive input, provide output, generate output, transmit information, exchange information, capture measurements, and the like. The specific I / O components 850 included in a particular machine will depend on the type and / or function of the machine. For example, a mobile device such as a mobile phone may include a touch input device, while a headless server or an IoT device may not include such a touch input device. Figure 8The specific examples of the I / O components shown are in no way restrictive, and other types of components may be included in machine 800. The grouping of I / O components 850 is for simplicity of discussion only and is in no way restrictive. In various examples, I / O components 850 may include user output components 852 and user input components 854. User output components 852 may include, for example, display components for presenting information (e.g., liquid crystal display (LCD) or projector), acoustic components (e.g., speakers), haptic components (e.g., vibration motors or force feedback devices), and / or other signal generators. User input components 854 may include, for example, alphanumeric input components (e.g., keyboards or touchscreens), pointing components (e.g., mouse devices, touchpads, or other pointing instruments), and / or tactile input components (e.g., physical buttons or touchscreens that provide the location and / or force of a touch or touch gesture), which are configured to receive various user inputs, such as user commands and / or selections.

[0092] In some examples, I / O components 850 may include biometric components 856, motion components 858, environmental components 860, and / or positioning components 862, as well as various other physical sensor components. Biometric components 856 may include, for example, components for detecting body expressions (e.g., facial expressions, vocal expressions, hand or body gestures, or eye tracking), measuring biological signals (e.g., heart rate or brain waves), and identifying a person (e.g., via voice-, retina-, fingerprint-, and / or face-based recognition). Motion components 858 may include, for example, acceleration sensors (e.g., accelerometers) and rotational sensors (e.g., gyroscopes). Environmental components 860 may include, for example, lighting sensors, temperature sensors, humidity sensors, pressure sensors (e.g., barometers), acoustic sensors (e.g., microphones for detecting ambient noise), proximity sensors (e.g., infrared sensing of nearby objects), and / or other components that may provide an indication, measurement, or signal corresponding to the surrounding physical environment. Positioning components 862 may include, for example, position sensors (e.g., global positioning system (GPS) receivers), altitude sensors (e.g., barometric pressure sensors from which altitude may be derived), and / or orientation sensors (e.g., magnetometers).

[0093] The I / O component 850 may include a communication component 864 that implements various techniques operable to couple the machine 800 to the network 870 and / or the device 880 via respective communication couplings 872 and 882. The communication component 864 may include one or more network interface components or other suitable devices to interface with the network 870. The communication component 864 may include, for example, components suitable for providing wired communication, wireless communication, cellular communication, near field communication (NFC), Bluetooth communication, Wi-Fi, and / or communication via other modalities. The device 880 may include other machines or various peripheral devices (e.g., coupled via USB).

[0094] In some examples, the communication component 864 may detect an identifier or include components suitable for detecting an identifier. For example, the communication component 864 may include a radio frequency identification (RFID) tag reader, an NFC detector, an optical sensor (e.g., a one-dimensional or multi-dimensional barcode or other optical code), and / or an acoustic detector (e.g., a microphone for identifying an audio signal of a tag). In some examples, location information may be determined based on information from the communication component 862, such as but not limited to a geographical location via an Internet Protocol (IP) address, a location via Wi-Fi, cellular, NFC, Bluetooth, or other wireless station identification and / or signal triangulation.

[0095] In the foregoing detailed description, numerous specific details have been set forth by way of example in order to provide a thorough understanding of the relevant teachings. However, it will be apparent that the teachings may be practiced without such details. In other instances, well-known methods, procedures, components, and / or circuits have been described at a relatively high level without detail in order to avoid unnecessarily obscuring aspects of the teachings.

[0096] Although various embodiments have been described, the description is intended to be exemplary and not restrictive, and it should be understood that more embodiments and implementations within the scope of the embodiments are possible. Although many possible combinations of features are shown in the figures and discussed in this detailed description, many other combinations of the disclosed features are possible. Unless specifically restricted, any feature of any embodiment may be used in combination with or substituted for any other feature or element in any other embodiment. Accordingly, it should be understood that any features shown and / or discussed in this disclosure may be implemented together in any suitable combination. Thus, the embodiments are not limited except as defined by the appended claims and their equivalents. Moreover, various modifications and changes may be made within the scope of the appended claims.

[0097] Although the best mode and / or other examples have been described above, it should be understood that various modifications can be made therein, and the subject matter disclosed herein can be implemented in various forms and examples, and the teachings can be applied to many applications, only some of which are described herein. The appended claims are intended to claim any and all applications, modifications, and variations that fall within the true scope of this teaching.

[0098] Unless otherwise specified, all measurements, values, ratings, positions, magnitudes, sizes, and other specifications set forth in this specification (including in the appended claims) are approximate and not exact. They are intended to have a reasonable range that is consistent with the functions they relate to and the conventions of the fields to which they belong.

[0099] The scope of protection is limited only by the appended claims. When interpreted in light of this specification and the subsequent prosecution history, this scope is intended to and should be construed to be consistent with the ordinary meaning of the language used in the claims and to cover all structural and functional equivalents. Nevertheless, none of the claims are intended to cover subject matter that fails to meet the requirements of Sections 101, 102, or 103 of the Patent Act, nor should they be construed in such a way. Accordingly, no protection is sought for any accidental circumvention of such subject matter.

[0100] Except as just stated above, nothing that has been stated or shown is intended or should be construed to dedicate to the public any component, step, feature, object, benefit, advantage, or equivalent thereof, whether or not recited in the claims.

[0101] It should be understood that the terms and expressions used herein have an ordinary meaning consistent with the corresponding query and study fields to which these terms and expressions pertain, unless a specific meaning is otherwise set forth herein. Relative terms such as first and second can be used only to distinguish one entity or action from another entity or action, and do not necessarily require or imply any actual such relationship or order between these entities or actions. The term "comprising," "including," or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements does not include only those elements but may include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without further limitation, an element preceded by "a" or "an" does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes that element.

[0102] A summary of the present disclosure is provided to enable a reader to quickly ascertain the nature of the technical disclosure. It should be understood that it will not be used to interpret or limit the scope or meaning of the claims. Additionally, in the foregoing detailed description, it can be seen that for the purpose of simplifying the present disclosure, various features are grouped together in various examples. The method of the present disclosure should not be construed as reflecting an intention that the claims require more features than those expressly recited in each claim. On the contrary, as reflected by the appended claims, the inventive subject matter lies in less than all of the features of a single disclosed example. Accordingly, the appended claims are hereby incorporated into the detailed description, where each claim stands on its own as a separately claimed subject matter.

Claims

1. A data processing system, comprising: a processor; and a machine-readable medium storing executable instructions that, when executed, cause the processor to perform operations, the operations including: receiving an access request from a client device of a content requester, the access request for requesting access rights to a content item, the access rights to the content item being managed by a content access management platform; obtaining access control information, the access control information including information associated with a content owner associated with the content item, information associated with the content requester, and information associated with the content item; using a first machine learning model to analyze the access control information, the first machine learning model being trained to analyze the access control information and output an access determination score, the access determination score representing a level of certainty that the content requester should be granted access rights to the content item; determining an automatic access decision to grant or deny the access request based on the access determination score; and notifying the content requester whether the access request is granted or denied based on the automatic access decision.

2. The data processing system according to claim 1, wherein, determining to automatically grant or deny the access request based on the access determination score further includes: determining an access level to be granted to the content requester based on the access determination score.

3. The data processing system according to claim 2, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: determining that the content requester should be granted temporary access rights to the content item based on the access determination score.

4. The data processing system according to claim 3, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: sending an access control request to a client device of the content owner, the access control request for granting or denying access rights to the content item; receiving a content access response from the client device of the content owner, the content access response indicating whether the content requester should be granted or denied access rights to the content item; and granting or denying the content requester access rights to the content item in response to receiving the content access response.

5. The data processing system according to claim 3, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: receiving access configuration information from the client device of the content owner, the access configuration information indicating the access level to be granted to the content requester; and granting the content requester access rights at the access level indicated in the access configuration information.

6. The data processing system according to claim 2, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: sending a confirmation request to the content owner, the confirmation request for requesting the content owner to confirm whether the automatic access decision is correct; and receiving a confirmation response from the content owner.

7. The data processing system according to claim 6, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: in response to the confirmation response from the content owner indicating that the automatic access decision is incorrect, veto the automatic access decision.

8. The data processing system according to claim 6, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: receive access configuration information from the client device of the content owner, the access configuration information indicating the access level that the content requester should have been granted; and veto the access level associated with the automatic access decision based on the access configuration information received from the content requester.

9. The data processing system according to claim 6, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: fine-tune the parameters of the first machine learning model based on the confirmation response received from the content owner.

10. The data processing system according to claim 6, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: determine that the content owner cannot be contacted; in response to determining that the content owner cannot be contacted, identify an alternative user associated with the content owner; send the confirmation request to the alternative user, the confirmation request for requesting whether the alternative user confirms that the automatic access decision is correct; and receive a confirmation response from the alternative user.

11. The data processing system according to claim 2, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: send a request for information justifying the access right to the content item to the client device of the content requester; receive justification information from the client device of the content requester; and use a second machine learning model to analyze the justification information, the second machine learning model being trained to receive text content as input, perform semantic analysis of the justification information, and output semantic information based on the justification information, wherein analyzing the access control information using the first machine learning model includes: analyzing the semantic information output by the first machine learning model.

12. The data processing system according to claim 2, wherein, the machine-readable medium includes instructions configured to cause the processor to perform the following operations: monitor the behavior of the content requester after granting the content requester access to the content item; determine based on the behavior of the content requester that the access right to the content item should be revoked; in response to determining that the access right to the content item should be revoked, automatically revoke the content requester's access right to the content item.

13. A method for automatic access control decision implemented in a data processing system, the method comprises: Receive an access request from a client device of a content requester, the access request being for requesting access rights to a content item, the access rights to the content item being managed by a content access management platform; Obtain access control information, the access control information including information associated with a content owner associated with the content item, information associated with the content requester, and information associated with the content item; Use a first machine learning model to analyze the access control information, the first machine learning model being trained to analyze the access control information and output an access determination score, the access determination score representing a level of certainty that the content requester should be granted access rights to the content item; Determine an automatic access decision to grant or deny the access request based on the access determination score; And Notify the content requester whether the access request is granted or denied based on the automatic access decision.

14. The method according to claim 13, wherein, Determining to automatically grant or deny the access request based on the access determination score further includes: Determining an access level to be granted to the content requester based on the access determination score.

15. The method according to claim 14, further comprising: Determining that the content requester should be granted temporary access rights to the content item based on the access determination score.