Machine-Learned Resource Access Rules for Precise Security Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access permission systems in computing systems lack precision, leading to either overly restrictive or overly permissive access, which consumes significant computing resources and fails to effectively prevent malicious activities such as exfiltration of sensitive information.

Innovation Solution

A system that uses machine learning to dynamically determine and update access rules based on user and resource characteristics, monitoring user activity to generate or update access rules in real-time, and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional access permission systems are used, then access control is implemented, but the precision of access control is low leading to overly restrictive or permissive rules

Engineering Contradiction:
Improveaccess control precisionVSAvoidaccess rule flexibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access rules that automatically adjust based on real-time user behavior patterns, resource sensitivity levels, and contextual factors. The system continuously learns from user interactions and modifies access permissions without manual intervention, transforming static access control into an adaptive, living system that evolves with organizational needs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters simultaneously including user behavior metrics, resource sensitivity classifications, temporal patterns, and contextual conditions to determine access decisions. By monitoring and adjusting these parameters dynamically, the system achieves precise access control while maintaining flexibility in response to changing conditions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional access permission systems are used, then access control is implemented, but computing resources are consumed significantly

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary analysis of user behavior patterns, resource sensitivity, and access contexts before making access decisions. By pre-establishing baseline behaviors and sensitivity classifications, the system avoids computationally expensive real-time analysis for every access request, reducing overall resource consumption while maintaining high security effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control system serves itself by automatically learning from user behaviors and adjusting permissions without requiring manual security administration. This self-service capability reduces the computational overhead of centralized security management and enables the system to optimize its own resource usage patterns over time.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If traditional access permission systems are used, then access control is implemented, but malicious activities are not effectively prevented

Engineering Contradiction:
Improvemalicious activity preventionVSAvoidtime for monitoring and remediation
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system implements continuous feedback loops where access decisions, user behaviors, and security events are constantly monitored and fed back into the machine learning models. This real-time feedback enables the system to detect anomalous patterns indicating malicious activities and automatically adjust access rules to prevent further harm, reducing the time required for manual monitoring and remediation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system takes preliminary anti-actions by proactively identifying potential security threats through behavior analysis and preventing malicious activities before they can cause significant damage. By detecting unusual patterns early and automatically responding with appropriate access restrictions, the system neutralizes threats before they escalate, minimizing both harm and response time.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12355772B2Resource access control
Publication Date: 2025.07.08 CAPITAL ONE SERVICES LLC
  • US12355772B2 patent drawing
  • US12355772B2 patent drawing
  • US12355772B2 patent drawing

AI summary

In some implementations, a device may monitor user activity in a computing system. The device may detect, based on monitoring the user activity, modification of a resource of the computing system by a user. The device may determine, using a machine learning model and based on detecting the modification of the resource, a set of access rules for the resource based on one or more characteristics associated with the user and one or more characteristics associated with the resource. The device may control access to the resource based on the set of access rules.