Graduated Access Control for AR/VR Devices via ML Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face challenges in ensuring the security and integrity of sensitive data, particularly when providing remote devices, including augmented reality/virtual reality (AR/VR) devices, with access to secure enterprise information.

Innovation Solution

The use of machine-learning models to determine graduated levels of access to secured data for remote devices, involving the computation of authentication scores based on device information, AR/VR capabilities, user credentials, and behavioral data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If remote devices including AR/VR devices are provided with access to secure enterprise information, then device functionality and user access capability are improved, but security risk and vulnerability to unauthorized access increase

Engineering Contradiction:
Improvedevice access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access level adjustment based on real-time authentication scores. The system continuously monitors device behavior, connection stability, and user interactions, then dynamically modifies access permissions. When authentication scores decrease or suspicious behavior is detected, the system automatically reduces access levels or terminates connections, creating a responsive security mechanism that adapts to changing conditions rather than using static access controls.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters (access levels, authentication thresholds, monitoring intensity) based on computed authentication scores. Different parameter sets are applied depending on the device's trust level: high-trust devices receive broader access with lower monitoring intensity, while low-trust devices receive restricted access with enhanced monitoring. This allows the system to adjust security parameters dynamically without requiring complete access denial or acceptance.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If graduated levels of access are implemented with multiple authentication factors, then security control precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidauthentication system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments access control into multiple graduated levels (e.g., basic access, enhanced access, full access) corresponding to different authentication score thresholds. Each access level provides different permissions and capabilities. This segmentation allows the system to provide fine-grained access control precision without requiring a single complex authentication decision, as the multi-level structure naturally divides the control complexity into manageable segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication model serves multiple functions simultaneously: it evaluates device credentials, analyzes behavioral patterns, assesses connection stability, determines access levels, and triggers monitoring actions. By consolidating these functions into a single multi-functional authentication system rather than separate mechanisms for each function, the patent reduces overall system complexity while maintaining precise access control through the unified model's graduated output levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If real-time monitoring and dynamic access adjustment are implemented, then security response capability is improved, but computational resource consumption increases

Engineering Contradiction:
Improvesecurity response speedVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system implements partial monitoring and authentication verification based on device trust levels. High-trust devices with consistently high authentication scores receive reduced monitoring intensity and less frequent re-validation, consuming fewer computational resources. Low-trust or newly connected devices receive full monitoring and more frequent authentication checks. This partial action approach maintains fast security response capability for suspicious activities while reducing overall computational burden through selective monitoring intensity.

Inventive Principle:
Principle #16Partial or excessive action

4Measurement precision

If comprehensive device information and behavioral data are collected for authentication scoring, then authentication accuracy is improved, but data privacy risk increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddata privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies different data collection and processing intensities to different devices based on their authentication scores and trust levels. High-trust devices have their data processed with higher privacy protection (less detailed monitoring, aggregated analytics), while low-trust devices receive more intensive scrutiny. This local quality approach allows the system to maintain high authentication accuracy for risk assessment while protecting privacy for legitimate users, applying comprehensive data analysis only where security risks warrant it.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250045427A1Using machine-learning models to determine graduated levels of access to secured data for remote devices
Publication Date: 2025.02.06 BANK OF AMERICA CORP
  • US20250045427A1 patent drawing
  • US20250045427A1 patent drawing
  • US20250045427A1 patent drawing

AI summary

Aspects of the disclosure relate to using machine-learning models to determine graduated levels of access to secured data for remote devices. In some embodiments, a computing platform may establish a connection with a mobile device. Subsequently, based on establishing the connection, the platform may identify initial device information, device features, and user information. The platform may input the identified information into an authentication model to compute a baseline authentication score and then may identify an initial level of access to secured resources for the mobile device. Thereafter, the platform may receive from the mobile device, AR/VR device information captured by the mobile device. The platform may input the AR/VR device information into the authentication model to compute an augmented authentication score. Based on the augmented score, the platform may identify an augmented level of access to secured resources for the mobile device.