Database Access Control with Machine Learning Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are not equipped to securely manage sensitive personal data during Extract, Transform, Load (ETL) processes, facing challenges with disparate data pipeline tools, varying privacy regulations, and third-party intrusion threats, while manual security policies are inefficient and prone to compliance issues.

Innovation Solution

A centralized management system provides automated data security and privacy enforcement through a single interface, using machine learning to dynamically generate risk scores for adaptive access control, obfuscation, and compliance with regulations, implemented as SaaS or embedded in cloud services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security policies are implemented by system administrators, then security control over personal data is established, but the process is inefficient and prone to compliance issues

Engineering Contradiction:
Improvecompliance reliabilityVSAvoidsecurity policy implementation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service through automated risk assessment and access control. The machine learning model automatically evaluates access requests, assesses risk levels, and makes authorization decisions without requiring manual administrator intervention for each request, thereby improving both efficiency and compliance consistency

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual administrative processes are replaced with an automated machine learning-based system. The mechanical process of manual policy review and approval is substituted with an intelligent automated system that continuously assesses risk and dynamically adjusts access controls, eliminating human error and inconsistency

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If centralized automated security management is implemented, then scalability and efficiency are enhanced, but system complexity increases

Engineering Contradiction:
Improvedata protection automation efficiencyVSAvoidcentralized management system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized management system as an intermediary layer between users and cloud data platforms. This intermediary handles all security decisions, risk assessments, and access control operations, simplifying the interface for end users while consolidating complexity within the managed system itself

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The centralized management system performs multiple functions including risk assessment, access control, audit logging, and compliance monitoring within a single unified platform. This multi-functionality reduces the need for separate systems and interfaces, managing complexity through consolidation rather than proliferation of components

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250252216A1Systems and Methods for Dynamically Granting Access to Database Based on Machine Learning Generated Risk Score
Publication Date: 2025.08.07 TRUSTLOGIX INC
  • US20250252216A1 patent drawing
  • US20250252216A1 patent drawing
  • US20250252216A1 patent drawing

AI summary

Systems and methods for restricting access and visibility to sensitive personal data during ingestion and storing within a data repository are disclosed. In one embodiment, a process for determining whether to grant access to protected data includes defining risk thresholds for predetermined data access patterns of a data repository, monitoring new data access patterns to build a security data profile based on quantifiable characteristics as risk factors, receiving a second request for data from a client device at the data repository, determining if any access control policies applies to the second request generating a risk score for the second request for data based on the security data profile, determining whether to grant access to the second request for data based upon at least one applicable access control policy and the risk score, and providing the requested data in response to the second request for data when access is granted.