Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

100 results about "Role-based access control" patented technology

In computer systems security, role-based access control (RBAC) or role-based security is an approach to restricting system access to authorized users. It is used by the majority of enterprises with more than 500 employees, and can implement mandatory access control (MAC) or discretionary access control (DAC).

Context-aware, artificial intelligence-based system for increasing employee engagement and automating the integration of business processes.

A system for improving employee engagement and automating the integration of business processes. The system includes: a user interaction module configured to receive multimodal inputs, including natural language text and voice requests from employees via enterprise portals, mobile applications, voice-activated devices, and collaboration platforms, and to generate real-time responses via conversational output channels; a context processor that is operationally coupled with the user interaction module, wherein the context processor stores the interaction history, employee preferences, organizational role metadata, and task results in both short-term and long-term memory and dynamically derives context for controlling responses and initiating workflows; A natural language and intent processor that is communicatively linked to the context processor. The intent engine consists of large language models trained on company-specific lexicons to perform intent detection, entity extraction, ambiguity resolution, and sentiment or urgency classification from employee queries; a workflow orchestration layer in communication with the intent engine and the context processor, wherein the workflow orchestration layer includes a rule-based and AI-powered process execution engine configured to automatically initiate, route, and complete cross-functional business tasks, including approvals, escalations, and compliance checks, with workflows defined using modular templates that include conditional logic and time-based triggers; Webhooks and authentication protocols provide secure interoperability between the workflow orchestration layer and external enterprise platforms; a feedback and learning module that is operationally coupled with the workflow orchestration layer and the natural language understanding engine, wherein the feedback and learning module is configured to analyze task completion rates, response accuracy, latency metrics, and user feedback signals, and to retrain underlying language and workflow models for adaptive improvement in real time; and an administration console with role-based access controls, compliance dashboards, audit trails and interfaces for workflow configuration, whereby the administration console enables authorized personnel to monitor system operations, adjust interaction rules and enforce data protection restrictions across departments.
Owner:KURAPATI SURESH KHAMMAM +3

Database management method and management system

The invention discloses a database management method and management system, and relates to the technical field of general database management, and the system comprises a user information management module, a work management module, a salary settlement module, an evaluation feedback module, an analysis prediction module, a multi-terminal integration module and a safety guarantee module. In the invention, a role-based access control permission model is constructed in a permission control layer and a module definition, and a field-level data control mechanism is implemented for three roles of a platform administrator, a customer enterprise and an employee, for example, the employee can only check a specific public field in a salary list, and sensitive fields such as a salary calculation formula are dynamically shielded; through a permission inheritance mechanism, the system automatically adds a filtering condition that employee ID = current user ID for a query request of an employee role, data isolation is ensured, a multi-dimensional data relation graph of employee-post-customer-contract is constructed, and a dynamic association path between entities is mapped in real time through a visual view.
Owner:HIPPO INTERNET INFORMATION TECH (SHENZHEN) CO LTD

A system for securing cloud-based large language models through cyber threat defense and compliance monitoring

A system (100) for securing cloud-based large language models through cyber threat defense and compliance monitoring, comprising: (a) an access control and authentication module configured to authenticate users and applications using role-based access control (RBAC) and multi-factor authentication (MFA); (b) a data protection and encryption module configured to encrypt data in transit and at rest and to anonymize sensitive input / output data using cryptographic techniques; (c) a threat detection and behavior monitoring module employing machine learning algorithms to identify anomalies and detect potential cyber threats in real time;(d) a regulatory compliance monitoring module configured to continuously assess system operations against applicable regulatory frameworks and generate alerts in the event of deviations from the regulations; (e) an incident response and mitigation module configured to automatically execute predefined response actions upon detection of threats or regulatory violations; (f) a logging, auditing, and forensic analysis module configured to securely log system activities, interactions, and threat events with cryptographic integrity protection; and (g) a governance and policy management module configured to define, update, and enforce organizational AI usage and compliance policies via the cloud-based LLM infrastructure.
Owner:ULAGANATHAN ILAKIYA

Automatic effective permissions discovery for cloud resources

Examples analyze effective permissions in a role-based access control system. A prompt is created for a large language model (LLM). The prompt includes a role definition for a role of a role-based access control system, and action definitions. The role definition for the role includes an action and effective permissions text describing a summary of permission limitations provided by the role. The action definitions are provided in a hierarchical format. Query text is added to the prompt. The query text includes a question about effective permissions associated with the role. The prompt is submitted to the LLM, thereby generating response text from the LLM. The response text is displayed to a user.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Multi-department medical sample collaborative management system and method

The invention discloses a multi-department medical sample collaborative management system and method, and relates to the technical field of medical information, and the system comprises an integrated information interaction platform which is used for achieving the real-time sharing of basic information, clinical diagnosis information and inspection reports of patients; the unique identification module is used for carrying out full-life-cycle tracking on a patient sample through a bar code or a radio frequency tag and dynamically associating the patient sample with patient information; the Internet of Things monitoring module is used for collecting and uploading temperature and humidity parameters of the sample storage environment in real time and triggering abnormal early warning; the automatic storage equipment executes sample classified storage and calling based on a platform instruction, and synchronously updates a sample state with the information system; and the data security module is used for realizing data encryption, dynamic authority management and operation traceability by adopting role-based access control and a block chain technology. According to the technical scheme, the core problems of data islands, low operation efficiency, weak safety and the like in traditional medical management can be systematically solved.
Owner:ZHEJIANG CANCER HOSPITAL

Multi-party data cooperative exchange method, system, device, medium and product

The invention provides a multi-party data collaborative exchange method, system and device, a medium and a product, and belongs to the technical field of data information processing, and the method comprises the steps: in a data exchange process, after identity authentication of participants of data exchange is passed in a trusted space, carrying out the dynamic verification of the access authority of the participants based on the real-time attributes of the participants; under the condition that the dynamic verification is passed, executing data exchange in the trusted space to obtain a data exchange result; sending the data exchange result to a data decryption party corresponding to the data user, so that the data decryption party decrypts the data exchange result; wherein the real-time attributes of the participants comprise real-time environment attributes, behavior attributes of the participants and static attributes of the participants. When the access permission is verified, transition from role-based access control to behavior-based access control is realized on the basis of dynamic combination of multi-dimensional attributes, and dynamic control on the access permission is realized on the aspect of finer granularity.
Owner:INSPUR TIANYUAN COMM INFORMATION SYST CO LTD

Data security isolation and sharing framework implementation method for multiple tenants

The invention discloses a data security isolation and sharing framework implementation method for multiple tenants. The method comprises the following steps of performing multi-tenant data isolation design; the method comprises the steps of S1, role-based access control and dynamic authority management design, S3, data sandbox and sharing mechanism design and S4, performance optimization and resource management. S5, a unified security management and monitoring platform, and relates to the technical field of computers.According to the method, multi-tenant data isolation design is adopted, and effective isolation of tenant data is achieved through combination of logic isolation and physical isolation; controlling access of the tenants to the shared data through access control and dynamic authority management of roles; through a data sandbox and a sharing mechanism, the safe operation of the shared data by the tenant is realized; the resource utilization rate is improved through a cache mechanism, load balancing, a resource recycling mechanism and asynchronous processing, and performance optimization and resource management are achieved.
Owner:JIANGSU LONGCHENG STATE-OWNED HOLDING GROUP CO LTD

AI-powered system for detecting and preventing data breaches

AI-powered data breach detection and prevention system that includes: a threat monitoring module for continuous analysis of network traffic, system logs and user activities; an AI-powered anomaly detection module that uses machine learning to detect threats, including zero-day attacks and insider threats; a behavioral analysis module that tracks user authentication, access patterns, and privilege escalations; an automated incident response module that isolates threats, blocks unauthorized access, and alerts security teams; a threat intelligence module that integrates global cybersecurity databases for proactive risk mitigation; a multi-layered security system with endpoint protection, encryption and role-based access control; a privacy-preserving mechanism that uses homomorphic encryption and federated learning to protect sensitive data; a compliance and audit module that ensures compliance with cybersecurity regulations.
Owner:MURALINATHAN SRINATH UNION CITY

Role-based access control recommendation systems

A method for role-based access control recommendation includes obtaining one or more security logs from a security analytics platform. The method includes determining access rights to the one or more security logs for one or more users of the security analytics platform. The determining includes generating one or more clusters of security logs based on the one or more security logs. The determining includes providing, to a user of the security analytics platform, a recommendation for a first data access group for the security analytics platform based on a first cluster of the one or more clusters. The determining includes, responsive to input from the user of the security analytics platform, generating the first data access group for the security analytics platform based on the first cluster of the one or more clusters.
Owner:GOOGLE LLC

System for real-time detection of supply chain disruptions and forecasting of financial impacts using AI-driven ERP environments

A computer-implemented system (100) for real-time detection of supply chain disruptions and forecasting of the financial impact in a computer-driven ERP environment, wherein the system (100) comprises: a data acquisition interface (1) configured to continuously capture structured and unstructured operational data from one or more ERP modules, supply chain execution systems, and enterprise event streams; a data management and harmonization engine (2) configured to validate, normalize, deduplicate and semantically map the captured data into a unified, time-aligned canonical enterprise schema; a disturbance signal fusion and anomaly detection engine (3) configured to fuse signals from multiple sources and detect disturbance events using one or more machine learning models to output a disturbance value, event class and a list of affected nodes; a supply chain dependency graph and a digital twin builder (4) configured to create and update a dynamic dependency graph representing suppliers, facilities, transportation routes, SKUs, orders, contracts and lead times, and propagate disruption effects across the graph; a financial impact forecasting engine (5) configured to estimate the real-time and forward-looking effects of the disruption on one or more financial measures, including sales, margin, working capital, cash flow, service level penalties and inventory holding costs, and furthermore the effects on the cost of goods sold (COGS) and / or the landed costs using a Kl-based forecast with a range of uncertainty; a module for coordinating corrective actions and automating workflows (6) configured to generate ranked corrective actions and initiate ERP workflow steps, including reordering, reassignment, alternative sources of supply, production rescheduling and logistics diversions, wherein the ranked corrective actions include recommendations to resolve the disruption by using available stock, reassigning low-priority shipments or diverting shipments that can be delivered later within a lead time window; an explainability, audit trail and compliance logging module (7) configured to record model inputs, feature assignments, decision justifications, scenario assumptions and action results as an immutable audit trail; and a visualization, alerting and collaboration interface (8) configured to output real-time alerts, dashboards and scenario comparisons to authorized users and downstream systems via APIs and role-based access controls, wherein the interface (8) generates a quick report view that displays early disruption signals and impact on manufacturing costs, delivers notifications to mobile devices, triggers a special urgent notification if the disruption affects a high-priority trading partner, and accepts user responses on mobile devices that automatically and without delay trigger corrective actions or updates in the ERP system.
Owner:GUPTA PRASHANT PROSPER +2

Multi-domain, role-based access control using large language models

Disclosed are various embodiments for multi-domain, role-based access control (RBAC) using large language models. Various embodiments can receive an access request from a client device associated with a user. Various embodiments can then send a prompt to identify a user role for the user to an agent of a machine learning model. Various embodiments can receive the user role for the user from the agent. The various embodiments can determine the capability for the user to access a resource by comparing the user role for the user to allowed user roles for the resource. Various embodiments can then send an access response to the client device that indicates whether the user can access the resource.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

System for providing event-driven distributed data mesh analytics

A system for event-driven distributed data network analysis, the system includes: a multitude of domain data nodes, each comprising a stream storage, a multitude of transformation pods, and a product API, with each domain data node ingesting heterogeneous event streams, validating schema compliance, performing enrichments, and making data products available under versioned schema contracts; each domain data node further comprises a hardware-based edge intelligence appliance comprising an enclosure, a compute module with heterogeneous processing units selected from CPUs, GPUs, and TPUs, a secure enclave module for confidential execution of transformation code on encrypted data, a protocol-structured stream storage medium supporting multi-level retention, and industrial I / O interfaces configured for direct interaction with sensors, programmable logic controllers, and cloud-native services; an event mesh backbone processor configured to connect the multitude of domain data nodes via a publish-subscribe architecture, with the backbone guaranteeing exactly one-time delivery, partition-level sorting, and geo-replicated durability; a Contextual Intelligence Engine coupled with the Event Mesh Backbone processor, the engine comprising a semantic graph memory and a Streaming Graph Reasoner configured to map raw events into an ontology, perform graph joins in real time, and recognize composite causal patterns across multiple domain data nodes; a governance and policy control unit integrated into both the data and control layers. This layer enforces zero-trust security, role-based access control, real-time provenance tracking, and regulatory compliance; and An actuation interface coupled with the contextual intelligence engine and the governance layer. The actuation interface is configured to generate control commands for operational technology devices and digital workflows, thus closing the loop from data acquisition to autonomous decision-making.
Owner:GUTTIKONDA BHANU SEKHAR KRISHNA +4

Cloud architecture distributed data processing method and device, equipment and storage medium

The invention relates to the technical field of cloud architecture distributed data processing. The cloud architecture distributed data processing method comprises the following steps: verifying identity data based on multiple identity authentication, if the identity verification is passed, allocating data access authority through a role-based access control mechanism, establishing a distributed data center based on a cloud architecture, and sending the distributed data center to the cloud architecture. Receiving real-time monitoring data from a plurality of terminals, storing the real-time monitoring data to the distributed data center based on the cloud architecture, and after the real-time monitoring data is stored to the distributed data center based on the cloud architecture, sending the real-time monitoring data to the server; network traffic in a distributed data center based on a cloud architecture is monitored through an intelligent intrusion detection mechanism driven by artificial intelligence to obtain user access request data, and dynamic security assessment is performed on an access request of a data access user by using a zero-trust architecture. The method has the effects of realizing dynamic access control and efficient data protection.
Owner:SHANDONG DENENG IOT TECH CO LTD

Data desensitization display method and device

The invention discloses a data desensitization display method and device. The method comprises the following steps: in response to a display request of to-be-displayed data sent by a target object, obtaining a biological feature vector of the target object at the current moment; target data is obtained, and the target data is obtained after the to-be-displayed data is encrypted; after the biological feature vector of the target object at the current moment is successfully authenticated, determining an encryption seed of the target object according to the biological feature vector of the target object at the current moment and pre-stored auxiliary data; generating a private key based on the encryption seed; and decrypting the target data by using the private key, and displaying the to-be-displayed data obtained after decryption. The method provided by the invention at least solves the technical problem that the display mode is single due to the fact that the data is displayed in a role-based access control mode in related technologies.
Owner:CHINA TELECOM CORP LTD

Telemetry data processing in cluster file system with dynamic registration and RBAC rule allocation of new metrics

A telemetry processing system in a cluster network generates telemetry data from a plurality of telemetry producers and formats it into a structured format for storage. Producers define new metrics for use in a running network. Role-based access control (RBAC) levels for metrics are mapped to users based on roles within an organization using the produced telemetry data. A final RBAC level of a new metric is established through a recommendation and validation process between the producer and an RBAC recommendation module. Once validated, the final RBAC level and new metric are stored in a telemetry catalog. Telemetry datasets for the new metric are sent for storage and transmitted to appropriate users based on RBAC rules including the final RBAC level.
Owner:DELL PROD LP

Role-based access control using cloud-native objects in multi-tenant environments

Disclosed herein are system, method, and computer program product embodiments for role-based access control in multi-tenancy environments using cloud-native objects. An embodiment operates by executing an application in a cluster. The embodiment creates roles corresponding to a user or group of users. The embodiment defines a set of permissions for the roles. The embodiment binds the roles to native objects in a cloud orchestrator based on the set of permissions for the roles. The embodiment receives a first request from a user to log in. The embodiment transmits a request to authenticate the user. The embodiment receives a list of a set of permissions for the user. The embodiment causes a display of system assets on a user interface of a client device based on the list of the set of permissions for the user.
Owner:KASTEN INC

Cloud architecture for enforcing multi-dimensional data security using security assignments beyond role-based access controls

An object access service is implemented on a computer system for configuring and enforcing multi-dimensional data security using security assignments beyond role-based access controls. The computer system accesses a request submitted on behalf of a user for access to database structure(s). The computer system requests predicate(s) mapped to role(s) assigned to the user and stored in association with the database structure(s). Predicate(s) submitted to the database may be dynamically filled in by the database pursuant to retrieving data from the database structure(s) to reference security assignment field(s) and security assignment value(s) of the security assignment. The predicate(s) are used to retrieve a security assignment that restricts access to the database structure(s) beyond the role(s) assigned to the user. The security assignment is used to restrict data accessible from the database structure(s) to generate a result set, which is transmitted to a client consumer system for consumption via a consumer interface.
Owner:ORACLE INT CORP

Implementing multi-party authorizations within an identity and access management regime

Role-based access controls (RBAC) are extended to include multi-party authorizations for certain computing cluster operations or data items. Upon receiving a request to perform an operation over a computing cluster or its data, a check is carried out to determine if the operation (e.g., READ, WRITE, EXECUTE, DELETE, etc.) is subject to both a role-based access control as well as a multi-party authorization (MPA) consensus protocol. The determination to allow or deny the request includes (1) accessing a role-based access control record corresponding to the operation or data item, and (2) invoking the multi-party authorization consensus protocol. Prior to performance of the operation, a computer program collects “approve” or “deny” responses from individual ones of the multiple parties. When approval consensus is reached, the operation is performed. If approval is denied, or if an approval consensus is not reached within a time limit, then the operation is not performed.
Owner:NUTANIX INC

POS application security signature system and method based on cloud service

The invention provides a POS application security signature system and method based on cloud service. The system architecture is clearly divided into a front-end service area and a high-security trusted area. The front-end service area is deployed in a special network management area which is logically isolated from the Internet and comprises a Web management background and a Web management background database; the high-security trusted area is a trusted environment, and an application signature server, an application signature server database and a hardware security module are deployed in the high-security trusted area. An application developer accesses the system through a controlled client environment. According to the method, responsibility separation of a submitter, a security officer and a key administrator is realized through role-based access control, hierarchical strong identity authentication is adopted, and a rigorous process is followed; a submitter verifies the hash of a file and then creates a task, the task data is synchronized to a high-security credible area after two security officers approve the task independently in sequence, and two key administrators execute dual control to start an HSM key to complete signature. The whole process operation is recorded in an auditing log which cannot be tampered. According to the invention, automation, high security and compliance of the cloud signature process are realized.
Owner:FUJIAN MOREFUN ELECTRONICS TECH CO LTD

Industrial internet of things multi-key fuzzy search method based on walsh matrix

The application discloses a kind of industrial internet of things multi-key fuzzy search method based on Walsh matrix, comprising the following steps: S1, system initialization is carried out;S2, based on system initialization result, key distribution is carried out;S3, based on key distribution result, generate ciphertext index;S4, based on key distribution result, generate security query trapdoor;S5, according to ciphertext index and security query trapdoor, carry out ciphertext matching and authorized interception.The application realizes the bottom unification of retrieval and access control, effectively resists structured information disclosure attack, and seamlessly nests the polynomial coefficient of role-based access control into the data structure of encryption matrix.
Owner:NORTH CHINA UNIVERSITY OF TECHNOLOGY

Minimization of unused resource-access permissions across roles

The technology disclosed herein enables the reduction of unused, or excess, access permissions in roles assigned to users. In a particular example, a method includes identifying access permissions used by a user and applying a greedy algorithm to select a set of roles from a plurality of roles available for role-based access control (RBAC) to enable the access permissions. Each iteration of the greedy algorithm selects a different role for inclusion the set of roles based on a blast radius of the different role. The method further includes assigning the set of roles to the user; and enforcing the access permissions granted by the set of roles.
Owner:VEZA TECH INC

Intelligent Creation of Secure Roles for Role-Based Access Control

PendingUS20250350603A1Securing communicationSecurity RoleLinguistic model
Disclosed herein are system, method, and computer program product embodiments for creating a tailored access profile for improving the security of an access control system. An embodiment operates by extracting application access requirements for a role from a role description using a first large language model. The embodiment then generates an embedding corresponding to the application access requirements using a second large language model. The embodiment then searches for a first access profile in a data store based on the embedding. The embodiment then generates a second access profile based on the application access requirements using the first large language model. The embodiment then selects the first access profile or the second access profile based on the application access requirements. The embodiment finally tailors the selected access profile based on feedback, thereby creating the tailored access profile.
Owner:SAP SE

Military hospital comprehensive medical record information management method and system

The invention discloses an army hospital comprehensive medical record information management method and system, and the method comprises the following steps: collecting medical record data of a patient through terminal equipment in a hospital, and carrying out the preliminary verification; encrypting the medical record data in a mode of combining a symmetric encryption algorithm and an asymmetric encryption algorithm; according to the invention, encryption processing is carried out on the medical record data, so that the security of the data in the storage and transmission process is ensured; the role-based access control model is adopted for permission setting and distribution, fine permission management is achieved, and users of different roles can only access and operate medical record information within the permission range of the users; and the data encryption strength and the authority distribution weight are calculated in combination with a calculation formula, so that the scientificity and rationality of the system are improved. Meanwhile, the system has the functions of data storage, query, updating, sharing, destruction, maintenance and the like, comprehensive management of medical record information of the army hospitals is achieved, and the efficiency and safety of medical record management of the army hospitals are improved.
Owner:THE 940TH HOSPITAL OF THE CHINESE PEOPLES LIBERATION ARMY JOINT LOGISTICS SUPPORT FORCE

Qubit-implemented role-based access control

A quantum computing system receives, from a requestor, a first access request that identifies a subject, an action, and a resource. A mapping structure that identifies a plurality of qubits that are in superposition and encoded with a plurality of rules that govern access to the resource is accessed. Based on the mapping structure it is determined that a set of qubits of the plurality of qubits applies to the access request. Data encoded in the set of qubits or a reference to each qubit in the set of qubits is provided to the requestor.
Owner:RED HAT LLC

Comprehensive quality management early warning and supervision system

The invention discloses a comprehensive quality management early-warning and supervision system, relates to the technical field of quality management, and solves the problems that a defect type classification model is difficult to construct, whether a secondary early-warning signal needs to be triggered is difficult to judge through a comprehensive index obtained by standardization values of various production devices, and the production efficiency is high. And the comparison judgment of the comprehensive quality safety coefficient and the normal comprehensive quality safety index is lacked. Comprising a production data acquisition and transmission management module, a user identity verification module, a fan defect and ledger data analysis module and a quality safety index comparison and early warning module, and is used for acquiring operation parameters, appearance quality and ledger data of production equipment; constructing role-based access control and dual verification; constructing a defect type classification model, a production equipment operation state comprehensive index and a comprehensive risk proportionality coefficient; and comparing the comprehensive quality safety coefficient with a normal comprehensive quality safety index, and judging whether a primary early warning signal is triggered or not.
Owner:CGN (FUJIAN) WIND POWER CO LTD

Intelligent finance and tax auditing system and method based on block chain

The invention provides an intelligent finance and tax auditing system and method based on a block chain, and relates to the technical field of finance and tax auditing. The system comprises a block chain underlying architecture, a data encryption module, an access control module, an intelligent contract module, a private key management module and an audit application interface. And the block chain bottom layer architecture adopts a permission system block chain network, so that tampering resistance and traceability of finance and taxation data are ensured. And the data encryption module is combined with symmetric and asymmetric encryption algorithms to protect the security of enterprise sensitive finance and tax data. The access control module implements a role-based access control mechanism, integrates multi-factor authentication, and records an audit log on a block chain. According to the invention, through comprehensive application of the block chain, the encryption technology, the smart contract and other means, the problems of data security, privacy protection, smart contract vulnerability and private key management in traditional finance and taxation auditing are effectively solved, and the efficiency and accuracy of finance and taxation auditing are significantly improved.
Owner:SHANDONG VOCATIONAL COLLEGE OF ECONOMICS & TRADE

SAAS vehicle management system of multi-tenant architecture

The invention discloses a multi-tenant architecture SAAS vehicle management system, and belongs to the technical field of SAAS systems and vehicle management. Aiming at the problems that a traditional localized vehicle management system is high in deployment cost and poor in data isolation and an existing SAAS system is insufficient in adaptability, the system adopts a layered architecture design: an infrastructure layer realizes elastic deployment based on a Docker container; the data storage layer adopts a MySQL5.7 database, and realizes data logic isolation through tenant IDs; the core service layer integrates customized modules of vehicle scheduling, data acquisition and the like, and can automatically generate a maintenance plan and dynamically schedule vehicles. The authority management layer adopts an RBAC (Role Based Access Control) mechanism to realize refined authority distribution; the front-end interaction layer supports browser and applet zero-deployment access; and the operation platform overall plans operation and maintenance and security assurance. According to the method, hardware deployment and IT maintenance of enterprises are not needed, the use cost can be reduced, data isolation is safe and reliable, the vehicle scheduling response speed is increased, and the method can meet the requirements of multiple industries such as logistics and engineering.
Owner:SHANGHAI MEIHU TECHNOLOGY CO LTD

On demand biospecimen collection

A computer-implemented system and method for administrating human biospecimen collection facilitates secure, de-identified coordination among donors, scientists, and administrators through a modular digital interface. The system enables administrators to manage project dashboards, assign donor identities to sample jobs, initiate and track collections, configure lab and location settings, and process payments using integrated financial services. Scientists can create, schedule, and monitor biospecimen requests, set donor inclusion criteria, and manage sample delivery. Donors can register, undergo identity verification, opt in to sample types, and track donation history. The platform supports automated notifications, real-time courier tracking, configurable appointment durations, and differential compensation models. Technical benefits include enhanced data integrity via role-based access control, improved efficiency through integrated scheduling and payment APIs, and reduced administrative burden via automated matching and logistics coordination. The system provides compliance with privacy standards while enabling scalable, institution-specific or marketplace-based biospecimen acquisition.
Owner:TAWADROS PATRICIA

Enforcing Role-Based Access Controls in Large Language Models

Systems and methods for enforcing granular access controls in large language models. The system can receive a user query, and an access token associated with an access profile. The method includes ingesting, by a machine-learned metamodel, the user query and the access token. The machine-learned metamodel can be configured to compare the access profile with one or more topics, wherein the one or more topics are associated with data source permissions and based on the comparison, retrieve data associated with the one or more topics. The method includes receiving, by a machine-learned model, the user query, the access token, and the data associated with the one or more topics. The method includes generating, by the machine-learned model, a query response, wherein the query response includes a response comprising the one or more topics that are filtered according to the access profile and the data source permissions.
Owner:UBER TECHNOLOGIES INC

Role-based access control systems filtering access to permissions for a domain

Systems and methods receive an access request for a knowledge domain framework for generative AI model development, the access request including user credentials, and filter, based on the user credentials being authenticated, permissions defining a user-specific access level for utilizing the knowledge domain framework. Display of a user interface that includes prompts facilitating inputs to the knowledge domain framework is initiated, the prompts being regulated based on the permissions. Information to establish a desired knowledge domain is received from a user device associated with the user interface, the desired knowledge domain including a corpus of selected documents, and an indication of a type of a generative artificial intelligence model to be developed is received from the user device. Display of a prompt template for receiving user inputs and providing generative outputs is initiated, and text submission(s) are received. Response(s) to the text submission(s) are generated.
Owner:TRUIST BANK