Dynamic User Access Control via AI Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access management systems are time-consuming and require significant human intervention, lacking the ability to dynamically and automatically grant, revoke, and manage access to data resources for users or groups, leading to potential unauthorized data breaches and inefficient access processes.

Innovation Solution

A dynamic user access control management system that uses an artificial intelligence-based classification engine to classify data and users based on exposure ratings and access history, generating access groups and automatically determining access levels through machine learning analysis of log files and server performance metrics, minimizing the need for manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated user management applications are implemented, then productivity is improved, but the extent of automation is limited due to lack of dynamic management capabilities

Engineering Contradiction:
Improveaccess management efficiencyVSAvoiddynamic access management capability
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system dynamically adjusts user access rights based on real-time analysis of log files, server performance metrics, and user behavior patterns. The user management engine continuously monitors and modifies access levels without manual intervention, making the access control system adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-management by automatically granting, revoking, and adjusting user access rights based on predefined policies and real-time data analysis. The artificial intelligence classification engine and user management engine work autonomously to manage access without requiring manual administrator intervention for each access decision.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual access approval processes are used, then access control reliability is maintained, but loss of time increases due to multiple approval steps

Engineering Contradiction:
Improveaccess control securityVSAvoidaccess approval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system replaces the mechanical manual approval process with an artificial intelligence-based automated decision-making system. The user management engine analyzes log files, server performance, and user classifications to automatically make access decisions, substituting human manual review with machine-based automated control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system continuously monitors server performance metrics, log files, and user access patterns, using this feedback to dynamically adjust access rights. The artificial intelligence classification engine processes ongoing data to refine access decisions, creating a closed-loop system that adapts based on observed behavior and system state.

Inventive Principle:
Principle #23Feedback

3Reliability

If periodic reapproval processes are implemented, then access control reliability is improved, but productivity deteriorates due to repeated approval steps

Engineering Contradiction:
Improveaccess review accuracyVSAvoidaccess management throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of periodic discrete reapproval steps, the system implements continuous monitoring and dynamic adjustment of access rights. The user management engine continuously analyzes log files and server performance, maintaining constant oversight of user access without interrupting workflow for periodic reviews.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary classification of users and data resources using the artificial intelligence classification engine before access requests occur. User classifications and data classifications are established in advance based on historical behavior and requirements, enabling rapid automated access decisions without requiring review at the time of access request.

Inventive Principle:
Principle #10Preliminary action

4Extent of automation

If automated determination of access levels is implemented, then extent of automation is improved, but device complexity increases due to multiple analysis components

Engineering Contradiction:
Improveaccess level determination automationVSAvoidsystem architecture complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The user management engine serves multiple functions: it classifies users, classifies data resources, analyzes log files, monitors server performance, and determines access rights. The artificial intelligence classification engine performs multiple classification tasks universally across different users and data types, reducing the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the classification engine, log analysis capabilities, performance monitoring, and access decision-making into an integrated user management engine. By combining these functions into a single cohesive system rather than separate components, the architecture manages complexity while maintaining comprehensive automated access control.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11777949B2Dynamic user access control management
Publication Date: 2023.10.03 BANK OF AMERICA CORP
  • US11777949B2 patent drawing
  • US11777949B2 patent drawing
  • US11777949B2 patent drawing

AI summary

An illustrative computing system for a dynamic user access control management system classifies users and data resources according to their risk and importance by a user management engine with artificial intelligence, machine learning characteristics. The dynamic user access control management system analyzes the log files of data resources to measure system performance characteristics and user access behavior. This system monitors the device and network by which a data access request to a data resource is made. The dynamic user access control management system validates the leave status of a user initiating a data access request. The dynamic user access control management system automatically determines a user access level for a data resource through intelligent analysis of collected information and defers to a user's manager for an access level determination when the determination to grant an access level is outside of the knowledge base of the user management engine.