Access Policy Anomaly Detection Using User-Resource Embeddings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control systems face challenges in maintaining consistent, minimal, and complete access control policies due to user and resource changes, leading to inconsistent, excessive, and incomplete access control, which increases the risk of unauthorized access and data breaches.

Innovation Solution

Utilizing non-negative matrix factorization and embedding techniques to identify user-resource anomalies, assign correct access rights, and manage access control policies efficiently, ensuring consistency and completeness by clustering user and resource embeddings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional access control policy management methods are used in large organizations with constantly changing users and resources, then manual policy maintenance becomes increasingly complex and error-prone, but automated solutions using matrix factorization and embedding techniques require significant computational resources and data processing infrastructure

Engineering Contradiction:
Improveaccess control policy maintenanceVSAvoidcomputational infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent replaces manual mechanical policy maintenance with automated computational analysis using matrix factorization and embedding techniques. The system automatically processes user-resource access data, identifies anomalies, and generates policy recommendations, eliminating the need for manual tracking and updating of access control policies in large organizations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms access control policy management by changing the parameters from manual discrete policy definitions to continuous mathematical representations through matrix factorization. User and resource attributes are converted into embedding vectors, allowing for automated similarity analysis and anomaly detection based on mathematical distance metrics rather than manual policy rules.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive access control policies are maintained for all users and resources, then security coverage is maximized, but the complexity of managing and detecting anomalies in access patterns increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidanomaly detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates simplified copies of the complex access control system by generating embedding representations of users and resources. These embeddings capture the essential access patterns and relationships in a condensed mathematical form, enabling efficient anomaly detection through distance calculations without requiring direct analysis of the full complexity of all access policies.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces matrix factorization and embedding techniques as intermediary layers between the raw access control data and the anomaly detection process. These mathematical transformations serve as mediators that convert complex user-resource access patterns into comparable vector representations, making anomaly detection computationally feasible while maintaining comprehensive security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If access control policies are frequently updated to adapt to changing organizational needs, then adaptability is improved, but consistency and minimality of policies deteriorate due to accumulation of changes

Engineering Contradiction:
Improvepolicy adaptabilityVSAvoidpolicy consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously analyzes current access patterns, compares them against learned embeddings, and automatically generates policy recommendations. This closed-loop approach ensures that policy updates are based on actual usage data and similarity analysis, maintaining consistency by only making changes that align with the underlying access patterns rather than accumulating arbitrary modifications.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary analysis of access patterns and generates policy recommendations before actual policy updates are implemented. By pre-processing the data through matrix factorization and embedding, the system identifies optimal policy configurations in advance, allowing for coordinated updates that maintain consistency rather than reactive changes that may conflict with existing policies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12615299B2Access control policy management
Publication Date: 2026.04.28 INTUIT INC
  • US12615299B2 patent drawing
  • US12615299B2 patent drawing
  • US12615299B2 patent drawing

AI summary

Certain aspects of the disclosure provide techniques for access control policy management. A method generally includes factorizing a user access co-occurrence data element to generate two data sub-elements, wherein: the user access co-occurrence data element represents co-occurrences between users of a system and resources of the system, a product of the two data sub-elements approximates the user access co-occurrence data element, and each of the two data sub-elements has reduced dimensionality compared to the user access co-occurrence data element; generating an approximated user access co-occurrence data element based on the product of the two data sub-elements; comparing the user access co-occurrence data element and the approximated user access co-occurrence data element to determine one or more anomalies, wherein each of the one or more anomalies relates to access for a user to a resource of the system; and taking one or more actions to rectify the one or more anomalies.