Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

36 results about "Role-based access control" patented technology

In computer systems security, role-based access control (RBAC) or role-based security is an approach to restricting system access to authorized users. It is used by the majority of enterprises with more than 500 employees, and can implement mandatory access control (MAC) or discretionary access control (DAC).

System for real-time detection of supply chain disruptions and forecasting of financial impacts using AI-driven ERP environments

ActiveDE202026100486U1FinanceCommerceRole-based access controlForward looking
A computer-implemented system (100) for real-time detection of supply chain disruptions and forecasting of the financial impact in a computer-driven ERP environment, wherein the system (100) comprises: a data acquisition interface (1) configured to continuously capture structured and unstructured operational data from one or more ERP modules, supply chain execution systems, and enterprise event streams; a data management and harmonization engine (2) configured to validate, normalize, deduplicate and semantically map the captured data into a unified, time-aligned canonical enterprise schema; a disturbance signal fusion and anomaly detection engine (3) configured to fuse signals from multiple sources and detect disturbance events using one or more machine learning models to output a disturbance value, event class and a list of affected nodes; a supply chain dependency graph and a digital twin builder (4) configured to create and update a dynamic dependency graph representing suppliers, facilities, transportation routes, SKUs, orders, contracts and lead times, and propagate disruption effects across the graph; a financial impact forecasting engine (5) configured to estimate the real-time and forward-looking effects of the disruption on one or more financial measures, including sales, margin, working capital, cash flow, service level penalties and inventory holding costs, and furthermore the effects on the cost of goods sold (COGS) and / or the landed costs using a Kl-based forecast with a range of uncertainty; a module for coordinating corrective actions and automating workflows (6) configured to generate ranked corrective actions and initiate ERP workflow steps, including reordering, reassignment, alternative sources of supply, production rescheduling and logistics diversions, wherein the ranked corrective actions include recommendations to resolve the disruption by using available stock, reassigning low-priority shipments or diverting shipments that can be delivered later within a lead time window; an explainability, audit trail and compliance logging module (7) configured to record model inputs, feature assignments, decision justifications, scenario assumptions and action results as an immutable audit trail; and a visualization, alerting and collaboration interface (8) configured to output real-time alerts, dashboards and scenario comparisons to authorized users and downstream systems via APIs and role-based access controls, wherein the interface (8) generates a quick report view that displays early disruption signals and impact on manufacturing costs, delivers notifications to mobile devices, triggers a special urgent notification if the disruption affects a high-priority trading partner, and accepts user responses on mobile devices that automatically and without delay trigger corrective actions or updates in the ERP system.
Owner:GUPTA PRASHANT PROSPER +2

Telemetry data processing in cluster file system with dynamic registration and RBAC rule allocation of new metrics

PendingUS20260039719A1Securing communicationClustered file systemRole-based access control
A telemetry processing system in a cluster network generates telemetry data from a plurality of telemetry producers and formats it into a structured format for storage. Producers define new metrics for use in a running network. Role-based access control (RBAC) levels for metrics are mapped to users based on roles within an organization using the produced telemetry data. A final RBAC level of a new metric is established through a recommendation and validation process between the producer and an RBAC recommendation module. Once validated, the final RBAC level and new metric are stored in a telemetry catalog. Telemetry datasets for the new metric are sent for storage and transmitted to appropriate users based on RBAC rules including the final RBAC level.
Owner:DELL PROD LP

Cloud architecture for enforcing multi-dimensional data security using security assignments beyond role-based access controls

ActiveUS12587530B2Securing communicationRole-based access controlEngineering
An object access service is implemented on a computer system for configuring and enforcing multi-dimensional data security using security assignments beyond role-based access controls. The computer system accesses a request submitted on behalf of a user for access to database structure(s). The computer system requests predicate(s) mapped to role(s) assigned to the user and stored in association with the database structure(s). Predicate(s) submitted to the database may be dynamically filled in by the database pursuant to retrieving data from the database structure(s) to reference security assignment field(s) and security assignment value(s) of the security assignment. The predicate(s) are used to retrieve a security assignment that restricts access to the database structure(s) beyond the role(s) assigned to the user. The security assignment is used to restrict data accessible from the database structure(s) to generate a result set, which is transmitted to a client consumer system for consumption via a consumer interface.
Owner:ORACLE INT CORP

POS application security signature system and method based on cloud service

PendingCN121907584AUser identity/authority verificationData synchronizationRole-based access control
The invention provides a POS application security signature system and method based on cloud service. The system architecture is clearly divided into a front-end service area and a high-security trusted area. The front-end service area is deployed in a special network management area which is logically isolated from the Internet and comprises a Web management background and a Web management background database; the high-security trusted area is a trusted environment, and an application signature server, an application signature server database and a hardware security module are deployed in the high-security trusted area. An application developer accesses the system through a controlled client environment. According to the method, responsibility separation of a submitter, a security officer and a key administrator is realized through role-based access control, hierarchical strong identity authentication is adopted, and a rigorous process is followed; a submitter verifies the hash of a file and then creates a task, the task data is synchronized to a high-security credible area after two security officers approve the task independently in sequence, and two key administrators execute dual control to start an HSM key to complete signature. The whole process operation is recorded in an auditing log which cannot be tampered. According to the invention, automation, high security and compliance of the cloud signature process are realized.
Owner:FUJIAN MOREFUN ELECTRONICS TECH CO LTD

Minimization of unused resource-access permissions across roles

PendingUS20260149723A1Securing communicationRole-based access controlGreedy algorithm
The technology disclosed herein enables the reduction of unused, or excess, access permissions in roles assigned to users. In a particular example, a method includes identifying access permissions used by a user and applying a greedy algorithm to select a set of roles from a plurality of roles available for role-based access control (RBAC) to enable the access permissions. Each iteration of the greedy algorithm selects a different role for inclusion the set of roles based on a blast radius of the different role. The method further includes assigning the set of roles to the user; and enforcing the access permissions granted by the set of roles.
Owner:VEZA TECH INC

SAAS vehicle management system of multi-tenant architecture

PendingCN121616235AResource allocationRelational databasesLogistics managementRole-based access control
The invention discloses a multi-tenant architecture SAAS vehicle management system, and belongs to the technical field of SAAS systems and vehicle management. Aiming at the problems that a traditional localized vehicle management system is high in deployment cost and poor in data isolation and an existing SAAS system is insufficient in adaptability, the system adopts a layered architecture design: an infrastructure layer realizes elastic deployment based on a Docker container; the data storage layer adopts a MySQL5.7 database, and realizes data logic isolation through tenant IDs; the core service layer integrates customized modules of vehicle scheduling, data acquisition and the like, and can automatically generate a maintenance plan and dynamically schedule vehicles. The authority management layer adopts an RBAC (Role Based Access Control) mechanism to realize refined authority distribution; the front-end interaction layer supports browser and applet zero-deployment access; and the operation platform overall plans operation and maintenance and security assurance. According to the method, hardware deployment and IT maintenance of enterprises are not needed, the use cost can be reduced, data isolation is safe and reliable, the vehicle scheduling response speed is increased, and the method can meet the requirements of multiple industries such as logistics and engineering.
Owner:SHANGHAI MEIHU TECHNOLOGY CO LTD

On demand biospecimen collection

A computer-implemented system and method for administrating human biospecimen collection facilitates secure, de-identified coordination among donors, scientists, and administrators through a modular digital interface. The system enables administrators to manage project dashboards, assign donor identities to sample jobs, initiate and track collections, configure lab and location settings, and process payments using integrated financial services. Scientists can create, schedule, and monitor biospecimen requests, set donor inclusion criteria, and manage sample delivery. Donors can register, undergo identity verification, opt in to sample types, and track donation history. The platform supports automated notifications, real-time courier tracking, configurable appointment durations, and differential compensation models. Technical benefits include enhanced data integrity via role-based access control, improved efficiency through integrated scheduling and payment APIs, and reduced administrative burden via automated matching and logistics coordination. The system provides compliance with privacy standards while enabling scalable, institution-specific or marketplace-based biospecimen acquisition.
Owner:TAWADROS PATRICIA

Enforcing Role-Based Access Controls in Large Language Models

PendingUS20260141089A1Digital data protectionDigital data authenticationProgramming languageRole-based access control
Systems and methods for enforcing granular access controls in large language models. The system can receive a user query, and an access token associated with an access profile. The method includes ingesting, by a machine-learned metamodel, the user query and the access token. The machine-learned metamodel can be configured to compare the access profile with one or more topics, wherein the one or more topics are associated with data source permissions and based on the comparison, retrieve data associated with the one or more topics. The method includes receiving, by a machine-learned model, the user query, the access token, and the data associated with the one or more topics. The method includes generating, by the machine-learned model, a query response, wherein the query response includes a response comprising the one or more topics that are filtered according to the access profile and the data source permissions.
Owner:UBER TECHNOLOGIES INC

Role-based access control systems filtering access to permissions for a domain

PendingUS20260093840A1Digital data protectionDigital data authenticationUser deviceRole-based access control
Systems and methods receive an access request for a knowledge domain framework for generative AI model development, the access request including user credentials, and filter, based on the user credentials being authenticated, permissions defining a user-specific access level for utilizing the knowledge domain framework. Display of a user interface that includes prompts facilitating inputs to the knowledge domain framework is initiated, the prompts being regulated based on the permissions. Information to establish a desired knowledge domain is received from a user device associated with the user interface, the desired knowledge domain including a corpus of selected documents, and an indication of a type of a generative artificial intelligence model to be developed is received from the user device. Display of a prompt template for receiving user inputs and providing generative outputs is initiated, and text submission(s) are received. Response(s) to the text submission(s) are generated.
Owner:TRUIST BANK

Method and apparatus for role-based content adaptation

PendingCN122095364Aefficient managementRobust access controlDigital data protectionLinguistic modelRole-based access control
For role-based content adaptation, a set of predefined user roles and role-based transformation instructions are obtained from the role-based access control system. The role-based transformation instructions define content adaptation rules for each of the roles. Then, a large language model is used to transform the input content for each of the obtained roles, creating a role-based adapted content instance of the input content. The large language model is used to retrieve role-related content from the input content using the role-based transformation instructions. The role-based adapted content instances are stored in a role-partitioned content storage, where each instance is tagged to identify the associated role. Through role-aware content partitioning, various content types can be managed efficiently.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Role-based access control systems filtering access to permissions for a domain

PendingUS20260093839A1Digital data protectionDigital data authenticationUser deviceRole-based access control
Systems and methods receive an access request for a knowledge domain framework for generative AI model development, the access request including user credentials, and filter, based on the user credentials being authenticated, permissions defining a user-specific access level for utilizing the knowledge domain framework. Display of a user interface that includes prompts facilitating inputs to the knowledge domain framework is initiated, the prompts being regulated based on the permissions. Information to establish a desired knowledge domain is received from a user device associated with the user interface, the desired knowledge domain including a corpus of selected documents, and an indication of a type of a generative artificial intelligence model to be developed is received from the user device. Display of a prompt template for receiving user inputs and providing generative outputs is initiated, and text submission(s) are received. Response(s) to the text submission(s) are generated.
Owner:TRUIST BANK

Role-based access control systems for controlling access to a customized knowledge domain for secure agentic ai model development

PendingUS20260095461A1Computer security arrangementsSecuring communicationLinguistic modelRole-based access control
Systems and methods receive an input selecting functions for inclusion during creation of agentic large language model(s) (LLM), the functions being defined in accordance with role-based access controls (RBACs) provide an operative connection to existing LLM(s) to be included in a customized knowledge domain framework. Further, instructions on use and deployment to be included as selectable metadata for establishing guardrails for the agentic LLM(s) are obtained, where the guardrails establish rules for integration and use of the agentic LLM(s). Parser(s) for selection to be applied to the agentic LLM(s) are established. Selection of prompt template(s) for structuring user inputs and model outputs for the agentic LLM(s) is facilitated, and an operative connection to existing agentic LLM(s) for selection is provided. Further, access to existing validation large language model(s) is provided for selection.
Owner:TRUIST BANK

Metadata-based enterprise data architecture system for automated data collection, processing, and reporting.

ActiveDE202026100557U1Office automationResourcesData OriginRole-based access control
A metadata-driven enterprise data architecture system for automated data collection, processing, and reporting, consisting of: a centralized metadata control repository configured to store canonical enterprise data models and business semantic definitions, source-destination mapping rules and transformation logic, data quality thresholds and matching parameters, governance policies and compliance controls, data provenance relationships and audit tracking rules, security and access control configurations, planning instructions and reporting specifications; an execution and orchestration engine that is operationally connected to the metadata control repository and configured to dynamically interpret metadata definitions, automatically implements data ingestion pipelines to extract data from legacy systems, cloud platforms, application interfaces, files, and streaming sources, performs transformation operations such as normalization, enrichment, deduplication, aggregation, and format harmonization to align the ingested data with the canonical enterprise data model, applies metadata-driven data quality validation, exception handling, and reconciliation processes to ensure accuracy and consistency, and enforces metadata-defined security policies, including role-based access control, encryption, and data masking.Automatic capture of complete data provenance and audit records across all processing stages and creation of standardized operational, analytical, and regulatory reports based on metadata-defined reporting structures and business metrics; where changes to metadata definitions automatically modify the collection, processing, governance, security, and reporting behavior without requiring manual redesign of data pipelines or application code.
Owner:DIBOULIYA ASHISH WILTON

Adaptive energy management system and method based on the use of tokenized energy profiles (TOE)

PCT designated stageWO2026078063A1Data processing applicationsAutomatic controlRole-based access control
Adaptive energy management system and method based on tokenized energy profiles (TEP) in a distribution network, comprising a data ingestion module configured to acquire, aggregate and encrypt structured and unstructured data in real time; a real-time intelligent analysis module based on neural networks and configured to detect patterns of energy consumption and generation, to classify these patterns by generating energy footprints associated with one or multiple users, to predict consumption or generation values and to obtain optimization actions in real time; an automated control and activation module configured to control elements of electricity generation and consumption using model-based predictive control (MPC) techniques and fuzzy algorithms; and a security module configured to encrypt communications using encryption techniques, role-based access control (RBAC), blockchain storage, and real-time monitoring of anomalies.
Owner:GREEN SKILLS S L U

Telemetry data processing in cluster file system using role-based access control (RBAC) based dynamic catalog

ActiveUS20260032125A1Securing communicationClustered file systemRole-based access control
A telemetry processing system in a cluster network generates telemetry data from a plurality of telemetry producers and formats it into a structured format for storage in a datastore. Users of the telemetry data are mapped to specific role-based access control (RBAC) rules per an identity and management (LAM) module. This mapping is stored in a dynamic RBAC-based telemetry catalog for further rules checking as telemetry data is generated. This adds a second layer above user subscription terms to safeguard the security of telemetry data based on RBAC rules, and allows the system to define conditions under which certain users can receive certain types of telemetry data in an efficient and dynamic manner.
Owner:DELL PROD LP

Alternative function and evaluation system based on dynamic arrangement and heterogeneous data standardization

PendingCN121879745ARelational databasesDigital data authenticationData streamRole-based access control
The invention discloses an alternative function and evaluation system based on dynamic arrangement and heterogeneous data standardization, and belongs to the technical field of computer data processing. The system adopts a B / S (Browser / Server) distributed architecture, and is mainly composed of an evaluation authority verification unit, a visual substitution function arrangement unit, a heterogeneous data standardization conversion unit, a tamper-proof feedback auditing unit and a multi-field strategy plug-in interface unit. Wherein the evaluation authority verification unit controls the trigger authority of an alternative function based on an access control model of a role and an object relation mapping technology; the visual alternative function arrangement unit constructs logic nodes by utilizing a Web data flow programming technology, and realizes automatic routing switching of main logic and alternative logic through front-end DOM configuration; the heterogeneous data standardization conversion unit cleans unstructured data in different fields into unified standard indexes by using a database storage process and a regular analysis algorithm; and the tamper-proofing feedback auditing unit generates operation fingerprints by adopting a Hash chain technology, so that the whole process is traceable. The technical problems that a traditional evaluation system is poor in logic rigidity and data compatibility, and manual intervention is difficult to audit are effectively solved, and flexible application and fair evaluation in the fields of education, law, industrial quality inspection and the like are optimized to a certain extent.
Owner:BEIJING HUAMAI CENTURY SOFTWARE TECH CO LTD

Sharing of artificial intelligence models in a clean room with controlled data access

PCT designated stageWO2026107012A1Error detection/correctionPlatform integrity maintainanceAgent architectureRole-based access control
A secure clean room environment for sharing artificial intelligence (Al) models between multiple parties uses access control mechanisms and role-based access control for governing access to the Al models within the clean room environment. Isolated sandbox environments within the clean room environment allow authorized parties to test and use the Al models, monitor and log all activities performed within the clean room environment, and enforce usage controls on the Al models. The clean room leverages a retrieval-augmented generation (RAG) framework, multi-agent architecture, and confidential computing to enable safe, purpose-specific machine learning (ML) model sharing. A centralized knowledge graph and confidential virtual machines (VMs) create isolated environments where partners can securely access and query ML models.
Owner:LIVERAMP

Systems and methods for providing role-based access control to web services using mirrored, secluded web instances

Systems and methods are provided for providing access to data on a personalized basis. A service operating on a server is identified, where data at the service is associated with a first user and other users. Data associated with the first user is extracted. A network location is spawned for the first user. The extracted data is transferred to the spawned network location to make the extracted data available to the first user in a read-only fashion by accessing the spawned network location. Additional network locations are spawned for second and third users, respectively, wherein data associated with the second and third users is transferred such that they are available to the second and third users by accessing their respective additional network locations.
Owner:CYBER IP HLDG LLC

Identify provider agnostic departmental multi-tenancy management of storage resources

PendingUS20260133714A1Input/output to record carriersResource assignmentRole-based access control
Examples described herein provide a computer-implemented method for identity provider agnostic departmental multi-tenancy management of storage resources that includes providing a software-defined storage-as-a-service (SDSaaS) workspace that defines a tenancy circle, wherein the SDSaaS workspace interconnects an open-source container orchestration system namespace and the storage resources. The method further includes assigning the storage resources to departments within the SDSaaS workspace. The method further includes enabling departments to manage their own storage resources independently from one another. The method further includes implementing role-based access control at a SDSaaS workspace level to control user access to the storage resources of the SDSaaS workspace.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Access control list (ACL) and role-based access control (RBAC) management using content-based datasets

ActiveUS12670277B2Data setRole-based access control
Providing content based data access protection for data stored in a system by creating a dataset by grouping metadata for data objects that are grouped together by one or more filters. The dataset can span multiple storage devices of different types to define a single data access protection unit for the corresponding content data. A user query generates the one or more filters, and an access rule is defined that allows or denies access to the dataset by users or processes as the single unit based on data content rather than location. The access rule can comprise at least one of an Access Control List (ACL) rule or a Role-Based Access Control (RBAC) rule, where the ACL lists permissions associated with certain data elements that grant access to specific users or processes, and the RBAC rules allow or deny access on the basis of role-permissions within the system.
Owner:DELL PROD LP

Enhanced Role-Based Access Control For Cross-Namespace References In Compute Clusters

PendingUS20260134133A1Digital data protectionRedundant operation error correctionRole-based access controlWebhook
The disclosure describes a system for enforcing role-based access control in a multi-tenant compute cluster with cross-namespace references. A control plane of the compute cluster receives a custom-resource request from a tenant to create or modify a first custom resource in a tenant namespace. The first custom resource references if a second custom resource in an administrative namespace. In response to the request, the control plane transmits a validating admission request to a data-protection controller registered as a webhook endpoint for admission validation. The data-protection controller retrieves access metadata from the referenced second custom resource and generates an admission determination indicating whether the tenant's request satisfies cross-namespace access conditions defined in the metadata. The controller returns the admission determination to the control plane, which admits or denies the custom-resource request accordingly.
Owner:NETAPP INC

Ad hoc network dynamic authorization method and system based on improved FP-Growth optimized RBAC

PendingCN121547246ANetwork topologiesSecurity arrangementRole-based access controlDistributed computing
The invention discloses an Ad hoc network dynamic authorization method and system based on improved FP-Growth optimized RBAC, and the method comprises the steps: determining key attributes of Ad hoc network equipment, constructing a role-based access control RBAC model according to different functions of the Ad hoc network equipment in a border environment, and defining roles and corresponding permissions; key attributes of the equipment and data of corresponding roles are collected, and a strong association rule between the key attributes and the roles of the equipment is mined by adopting an FP-Growth algorithm with multiple minimum support degrees; screening a strong association rule for role dynamic allocation, and solving role allocation conflicts based on a priority matching rule; according to the equipment trust evaluation value, constructing an authority level, refining the authority corresponding to the role, and realizing fine-grained authorization of the ad hoc network equipment; according to the invention, fine-grained dynamic authorization of the ad hoc network equipment is realized, an accurate and dynamic authorization strategy can be provided for equipment executing different tasks, and the safety of authorization management and the adaptability to complex tasks are remarkably improved.
Owner:JIANGSU UNIV OF SCI & TECH

Cloud architecture for enforcing multi-dimensional data security using security assignments beyond role-based access controls

PendingUS20260189566A1Role-based access controlEngineering
An object access service is implemented on a computer system for configuring and enforcing multi-dimensional data security using security assignments beyond role-based access controls. The computer system accesses a request submitted on behalf of a user for access to database structure(s). The computer system requests predicate(s) mapped to role(s) assigned to the user and stored in association with the database structure(s). Predicate(s) submitted to the database may be dynamically filled in by the database pursuant to retrieving data from the database structure(s) to reference security assignment field(s) and security assignment value(s) of the security assignment. The predicate(s) are used to retrieve a security assignment that restricts access to the database structure(s) beyond the role(s) assigned to the user. The security assignment is used to restrict data accessible from the database structure(s) to generate a result set, which is transmitted to a client consumer system for consumption via a consumer interface.
Owner:ORACLE INT CORP

Domestic gas turbine TCS network security protection method

PendingCN121418120ASecuring communicationReal time analysisRole-based access control
The invention discloses a domestic gas turbine TCS network security protection method, which relates to the technical field of network security protection, and comprises the following steps: establishing an intrusion detection system and an intrusion prevention system, performing data auditing and abnormal behavior monitoring, performing access control and identity verification, and performing log analysis and centralized management. The security of the TCS network environment is ensured by constructing a defense mechanism of internal detection and external defense; through monitoring and auditing TCS network gas turbine flow data, an instruction message of a gas turbine control system is analyzed in real time, the validity of an instruction is judged in combination with a gas turbine operation condition, a control logic and a technological process, harm from an attack is evaluated, and a grading alarm instruction is triggered; by implementing a role-based access control strategy, the user permission is ensured to be matched with the responsibility, and meanwhile, a multi-factor identity verification mechanism is introduced to enhance the security of an account; through the log analysis system and the security information event management system, security events are collected, analyzed and reported, real-time analysis of the security events is realized, the network security of the domestic gas turbine TCS is effectively protected, and stable operation and data security of the whole system are ensured.
Owner:熊兴武

Role-based access control recommendation systems

ActiveUS12627668B2Securing communicationRole-based access controlData access
A method for role-based access control recommendation includes obtaining one or more security logs from a security analytics platform. The method includes determining access rights to the one or more security logs for one or more users of the security analytics platform. The determining includes generating one or more clusters of security logs based on the one or more security logs. The determining includes providing, to a user of the security analytics platform, a recommendation for a first data access group for the security analytics platform based on a first cluster of the one or more clusters. The determining includes, responsive to input from the user of the security analytics platform, generating the first data access group for the security analytics platform based on the first cluster of the one or more clusters.
Owner:GOOGLE LLC

Role-based access control systems for controlling access to a customized knowledge domain for secure ai model development

PendingUS20260093837A1Digital data protectionTransmissionLinguistic modelRole-based access control
Systems and methods provide an operative connection to existing large language model(s) to be included in the customized knowledge domain framework. Further, instructions on use and deployment to be included as selectable metadata for establishing guardrails for a generative artificial intelligence application are obtained, where the guardrails establish rules for integration and use of the generative artificial intelligence application. Parser(s) for selection to be applied to the generative artificial intelligence application are established. Selection of prompt template(s) for structuring user inputs and model outputs for the generative artificial intelligence application is facilitated, and an operative connection to existing agentic large language models for selection is provided. Further, access to existing validation large language model(s) is provided for selection.
Owner:TRUIST BANK

A centralized system for synchronizing financial data for S / 4HANA environments

ActiveDE202026101299U1FinanceResourcesData synchronizationRole-based access control
A centralized financial data synchronization system for S / 4HANA environments, consisting of: A data ingestion module configured to capture financial transactions, master data records, journal entries, tax data, and intercompany postings from multiple enterprise modules and external third-party systems. a centralized synchronization engine that is operationally connected to the data ingestion module and configured to process and synchronize the collected financial data in real time or near real time; a validation and harmonization layer configured to standardize heterogeneous financial data structures into a unified data model, detect inconsistencies, duplicates and structural discrepancies, and apply predefined financial governance rules; a reconciliation processor configured to compare synchronized financial records with the records of the source system to identify discrepancies and automatically generate exception alerts or corrective workflows; a security framework that includes encryption mechanisms for data in transit and at rest, role-based access control, and activity logging to protect sensitive financial information; and a reporting interface configured to generate consolidated financial reports, audit trails, variance reports, and centralized dashboards for authorized users; the system ensures centralized, secure and scalable synchronization of financial data across cloud, on-premise or hybrid S / 4 HANA infrastructures.
Owner:JAYARAMAN KAJENDRAN WEST CHESTER

Telemetry data processing in cluster file system using role-based access control (RBAC) based dynamic catalog

ActiveUS12652287B2Securing communicationClustered file systemRole-based access control
A telemetry processing system in a cluster network generates telemetry data from a plurality of telemetry producers and formats it into a structured format for storage in a datastore. Users of the telemetry data are mapped to specific role-based access control (RBAC) rules per an identity and management (LAM) module. This mapping is stored in a dynamic RBAC-based telemetry catalog for further rules checking as telemetry data is generated. This adds a second layer above user subscription terms to safeguard the security of telemetry data based on RBAC rules, and allows the system to define conditions under which certain users can receive certain types of telemetry data in an efficient and dynamic manner.
Owner:DELL PROD LP

Unified data management and analytics in cloud-based data lake environments

A cloud-based data platform is disclosed, enabling storage-agnostic data management and analytics in a unified environment. The system may integrate a data lake implemented as a hyperscaler object store, a cloud-based database management system (DBMS), elastic compute resources, and analytics engines. Data may be stored in open table formats, such as Apache Parquet, Delta Lake, and Apache Iceberg, supporting ACID transactions, schema evolution, and efficient query processing. Virtual tables may map data stored in the data lake to the DBMS, enabling in-situ query processing via SQL interfaces. The platform may support advanced features, including change data capture (CDC), time travel, and lifecycle management using a SAGA pattern for atomic operations. Security may be ensured through X.509 certificates, web tokens, and role-based access controls. Elastic compute resources, such as Apache Spark, facilitate large-scale data transformations and analytics.
Owner:SAP SE

Method and System for Role-Based Access Control, Conditional Release, and Decryption of Encrypted Digital Data Vaults

A computer-implemented system and method are disclosed for secure encryption, decentralized storage, and conditional decryption of digital data using a role-based access control (RBAC) framework. A data owner registers trustees and assigns roles including validation, key holder, and file holder, each governed by RBAC policies. Encrypted data is encapsulated within an encrypted data vault (EDV), which includes trigger conditions, trustee instructions, and configurable parameters for key release delay and scheduled release with an optional safety-net period.The EDV is processed in a secure enclave, where decryption keys are generated, wrapped with post-quantum cryptography, and distributed through a key management system. The encrypted data is stored decentrally. Access to the EDV is enabled only upon collaborative validation of trigger events by trustees, satisfaction of RBAC policies, and time-based conditions. After decryption, the EDV automatically resets, requiring renewed validation for future access.
Owner:AST RODNEY EDWARD