Data Routing System Using NLP Classification for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data communication and information security technologies fail to reliably route data to authorized users, often resulting in over-sharing or under-sharing of data within organizations due to inadequate classification and access control.

Innovation Solution

A system and method that classify data items based on responsibility and sensitivity features using Natural Language Processing (NLP) algorithms, determining the appropriate access levels of users and routing data accordingly, while obfuscating sensitive information not authorized for access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current data communication and information security technologies are used, then data can be communicated among employees, databases, servers, and other entities within an organization, but data may be over-shared or under-shared due to inadequate classification and access control

Engineering Contradiction:
Improvedata routing reliabilityVSAvoiddata over-sharing or under-sharing
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments data into different sensitivity classes (e.g., public, internal, confidential, restricted) and routes each class through different communication paths based on the recipient's access level. This segmentation allows precise control over data distribution, preventing both over-sharing and under-sharing by matching data sensitivity with appropriate access channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary classification of data sensitivity levels before communication occurs. By pre-categorizing data and establishing access rules in advance, the system ensures that only authorized recipients receive appropriate data, eliminating the need for reactive security measures and preventing information loss from improper sharing.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If data is routed to all employees within an organization, then information accessibility is improved, but security risks increase due to potential unauthorized access

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different security attributes to different portions of data based on sensitivity. Each data element is tagged with its classification level, and access control is applied locally at the data level rather than uniformly across all data. This allows employees to easily access appropriate data while unauthorized access is blocked at the specific data level.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an intermediary classification mechanism that sits between the data source and recipients. This intermediary automatically classifies data sensitivity and mediates access requests by routing data through appropriate channels, maintaining ease of access for authorized users while blocking unauthorized access without requiring manual security checks for each interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If strict access control measures are implemented, then data security is improved, but data communication efficiency decreases due to additional verification steps

Engineering Contradiction:
Improvedata securityVSAvoiddata communication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary classification of data into sensitivity categories before communication occurs. By pre-establishing access rules and classification schemas, the system automates the verification process, allowing rapid determination of authorized recipients without manual security checks during actual communication, thus maintaining both security and efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service security where the data itself carries classification metadata that automatically guides routing and access control decisions. The system uses the embedded sensitivity information to self-regulate access without requiring external verification for each data transmission, eliminating redundant security steps while maintaining protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11520910B2System and method for routing data to authorized users based on security classification of data
Publication Date: 2022.12.06 BANK OF AMERICA CORP
  • US11520910B2 patent drawing
  • US11520910B2 patent drawing

AI summary

A system for classifying a data item to communicate to authorized users extracts features from the data item, where the features comprise a responsibility feature and a sensitivity feature. The responsibility feature indicates a job responsibility associated with the data item. The sensitivity feature indicates a sensitivity level of the data item. The system determines, based on the responsibility feature, that the data item belongs to a particular responsibility class. The system determines, based on the sensitivity feature, that the data item belongs to a particular sensitivity class. The system determines whether a user to whom the data item is directed belongs to the particular responsibility class and sensitivity class to which the data item belongs. The system sends the data item to the user, if is it determined that the user belongs to the particular responsibility class and sensitivity class to which the data item belongs.