Frequent Pattern Tree for Entitlement Rule Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face challenges in identifying and managing complex entitlement rules for access to computing resources in real-time, due to the vast number of network devices and users with multiple combinations of entitlements, which can lead to security risks and inefficiencies in managing access controls.

Innovation Solution

A system utilizing a frequent pattern tree (FP-tree) is deployed to analyze entitlement data, generate patterns, and trigger actions based on the frequency of occurrence and correlation of entitlements, allowing for real-time identification and modification of access rules, thereby optimizing network resources and ensuring accurate access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional methods are used to manage access controls in enterprise networks, then manual management of entitlements can be performed, but the process is time-consuming and cannot be performed efficiently in real-time

Engineering Contradiction:
Improvespeed of entitlement rule identificationVSAvoidtime for manual entitlement management
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical processes of entitlement management with an automated computing system that uses FP-tree data structures and pattern matching algorithms to automatically identify entitlement rules, extract patterns from entitlement data, and trigger actions based on detected patterns, thereby eliminating time-consuming manual operations

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service by automatically monitoring entitlement data changes, updating FP-trees, detecting patterns, and triggering actions without requiring manual intervention, allowing the enterprise network to autonomously manage and update its entitlement rules in real-time

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive access control monitoring is implemented across vast enterprise networks, then security coverage is improved, but the complexity of managing and analyzing entitlement data increases significantly

Engineering Contradiction:
Improveaccess control securityVSAvoidcomplexity of entitlement data management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex entitlement data management problem into distinct components: FP-tree construction from entitlement data, pattern detection within the tree structure, and action triggering based on detected patterns. This segmentation simplifies the overall complexity by breaking down the monolithic management task into manageable, modular operations

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The FP-tree data structure serves as an intermediary between the raw entitlement data and the pattern detection process. It transforms complex entitlement relationships into a structured format that facilitates efficient pattern matching and rule extraction, thereby reducing the complexity of analyzing vast entitlement datasets

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If real-time entitlement rule identification is implemented, then access control accuracy is improved, but the computational resources required for analyzing entitlement data increase

Engineering Contradiction:
Improveaccuracy of entitlement rule identificationVSAvoidcomputational resources for data analysis
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary action by constructing the FP-tree data structure from entitlement data in advance, organizing the data into a pattern-friendly format before actual pattern detection is needed. This preprocessing step enables faster and more accurate real-time pattern identification without requiring intensive computational resources during the actual rule identification process

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11755927B2Identifying entitlement rules based on a frequent pattern tree
Publication Date: 2023.09.12 BANK OF AMERICA CORP
  • US11755927B2 patent drawing
  • US11755927B2 patent drawing
  • US11755927B2 patent drawing

AI summary

Aspects of the disclosure relate to identifying entitlement rules based on a frequent pattern tree. A computing platform may retrieve entitlement data associated with a relational database, where the entitlement data is indicative of user entitlements to computing resources in an enterprise network. Then, the computing platform may generate, for the entitlement data, a frequent pattern tree. Then, the computing platform may compare a pair of branches and may detect a pattern associated with a pair of entitlements. Then, the computing platform may determine, based on the frequent pattern tree, a frequency of occurrence of the pattern. Then, the computing platform may identify, based on the frequency of occurrence, a rule associated with the pattern. Subsequently, the computing platform may trigger, via the computing device and based on the rule, an action related to one or more of the entitlements of the pair of entitlements.