Anomalous Authorization Alerting via Proximity Graph

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face inefficiencies and inaccuracies in managing user authorization requests for access to applications and modules, relying heavily on manual reviews by managers, which is time-consuming and prone to errors.

Innovation Solution

Implementing a system that uses organizational relationships and machine learning to calculate a critical score for user authorization requests, comparing them to peer group datasets to autonomously approve or deny access based on normalized IDF and Jensen-Shannon Divergence analysis, and validating user profiles by determining normalized divergence values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review by managers is used to authorize user requests, then authorization accuracy can be maintained through human judgment, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improveauthorization accuracyVSAvoidauthorization processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by generating peer group datasets and calculating baseline probability distributions of authorization patterns before evaluating individual requests. This pre-computed contextual information enables rapid automated decision-making while maintaining accuracy, resolving the contradiction between speed and reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary automated authorization system that acts as a mediator between user requests and final approval. This intermediary uses machine learning models to analyze requests against peer group patterns, handling routine cases automatically while flagging only anomalous cases for human review, thus reducing processing time without sacrificing accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated systems are used to process authorization requests, then processing speed and efficiency are improved, but accuracy and detection of anomalous requests may deteriorate

Engineering Contradiction:
Improveauthorization processing throughputVSAvoiddetection accuracy of anomalous requests
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where automated authorization decisions are continuously evaluated against actual outcomes and peer group patterns. The machine learning models are retrained with new data, and the probability distributions are updated, creating a closed-loop system that improves detection accuracy over time while maintaining high processing throughput.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent dynamically adjusts decision thresholds and probability cutoffs based on contextual factors and historical performance. By changing the sensitivity parameters of the detection system, the automated model can optimize the balance between processing speed and detection accuracy for different operational contexts.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If individual user authorization requests are reviewed manually to ensure security, then security accuracy is maintained, but the complexity and resource requirements of the system increase

Engineering Contradiction:
Improvesecurity verification accuracyVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization system is segmented into distinct functional modules: peer group dataset generation, probability distribution calculation, request evaluation, and anomaly detection. Each module performs a specific function and can be independently optimized or updated, reducing overall system complexity while maintaining security verification accuracy.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If manual authorization review processes are used, then detailed analysis of each request can be performed, but the quantity of requests that can be processed decreases

Engineering Contradiction:
Improverequest analysis depthVSAvoidnumber of requests processed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies full analytical depth only to requests that deviate from normal peer group patterns, while routine requests receive streamlined processing. By performing detailed analysis partially (only when necessary), the system maintains measurement precision for anomalous cases while significantly increasing overall productivity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12177224B2Alerting on anomalous authorization requests derived with proximity graph
Publication Date: 2024.12.24 BANK OF AMERICA CORP
  • US12177224B2 patent drawing
  • US12177224B2 patent drawing
  • US12177224B2 patent drawing

AI summary

An information-security automated process for authorizing a user request for access to a module and for identifying anomalous user authorization requests, may be implemented on a computer machine and may include the steps of receiving a user request for access to a module, generating a peer group proximity dataset, generating a user dataset, calculating a critical score, determining if the critical score is less than an enterprise threshold, and generating an approval or denial of the user request based upon the critical score. In some examples the process may include the step of executing machine learning instructions to generate a second approval or a second denial of a second user request for access to a second module. In another examples an information-security automated process for validating a user authorization access profile is disclosed herein.