AI Intent Analysis for Real-Time Insider Access Restriction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web-based environments are vulnerable to insider threats and cyberattacks, which compromise the security and integrity of user data stored across databases.

Innovation Solution

A system and method utilizing generative artificial intelligence models to analyze real-time natural language exchanges between internal and external users to identify user intent, determining whether subsequent interactions are authorized or unauthorized, and adjusting access rights accordingly to secure sensitive user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If access rights are granted to internal users for servicing applications, then productivity and ease of operation are improved, but vulnerability to insider threats and cyberattacks increases

Engineering Contradiction:
Improveapplication servicing efficiencyVSAvoidinsider threat vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

An AI-based intent analysis system is introduced as an intermediary between internal users and sensitive user data. The system monitors natural language exchanges, analyzes user intent in real-time, and dynamically adjusts access rights based on whether the intent aligns with authorized interactions. This mediator enables continued productivity while filtering out malicious insider threats through intelligent analysis of communication patterns and contextual information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time monitoring of user interactions is implemented to detect insider threats, then security is improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvesecurity against insider threatsVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Traditional rule-based access control systems are replaced with an AI-based intent analysis system that uses machine learning models to understand natural language communications. The system processes real-time exchanges between internal users and external users, automatically determining whether interactions are authorized based on contextual understanding rather than rigid predetermined rules. This substitution reduces the need for complex manual configuration and enables more nuanced security decisions.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The intent analysis system operates autonomously by automatically analyzing natural language exchanges, determining user intent, and adjusting access rights without requiring constant human intervention. The AI model continuously learns from interaction patterns and makes real-time security decisions independently, reducing the operational complexity of managing security monitoring while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

3Device complexity

If traditional access control methods are used, then system simplicity is maintained, but the ability to detect and respond to insider threats in real-time is insufficient

Engineering Contradiction:
Improveaccess control system simplicityVSAvoidreal-time threat detection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system transitions from static access control parameters (fixed permissions and roles) to dynamic parameters that change in real-time based on analyzed user intent. The AI model continuously evaluates natural language communications and adjusts access rights accordingly, allowing the system to adapt to emerging threats while maintaining operational simplicity. This parameter dynamicization enables real-time threat response without requiring complex manual access control management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12505249B2System and method for securing user data against internal cyber threats
Publication Date: 2025.12.23 BANK OF AMERICA CORP
  • US12505249B2 patent drawing
  • US12505249B2 patent drawing
  • US12505249B2 patent drawing

AI summary

A system includes a memory configured to store user profile data associated with a user, user interaction data associated with a preauthorized user, and a software application configured to access the user profile data. The system further includes processors configured to access the user interaction data, in which the user interaction data is captured in relation to a natural language exchange session. The processors execute a generative machine-learning model trained to identify an intent of the preauthorized user based on the user interaction data associated with the preauthorized user, determine, based on the identified intent, whether the user interaction data corresponds to a sequence of authorized user interactions or a sequence of unauthorized user interactions, and, in response to determining that the user interaction data corresponds to the sequence of unauthorized user interactions, cause the software application to restrict access of the preauthorized user to the user profile data.