Machine-Learning Access Analysis for Combined Authorization Risks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for an effective way to secure access to sensitive electronic data by managing combinations of access authorizations that could compromise data security, such as in the case of mergers or other events affecting multiple access rights.

Innovation Solution

A system that uses machine-learning to monitor data streams, analyze access authorizations, and predict potential security risks by computing probability and impact scores, then executes remediation processes like credential revocation or data encryption to protect sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access authorizations are granted to multiple third party systems for different subsets of secured data, then data accessibility and utility are improved, but the risk of unauthorized data combination increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized data combination risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of access authorization combinations using machine learning to predict potential security risks before they materialize. By continuously monitoring and analyzing access patterns, the system identifies problematic authorization combinations in advance and implements preventive measures, rather than reacting after unauthorized access occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The machine learning model acts as an intermediary between the access authorization system and security policies. It analyzes the complex relationships between multiple third-party access authorizations and determines whether their combination creates security risks, enabling automated decision-making about authorization validity without requiring manual security review of every access request.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If continuous monitoring and analysis of access authorizations is implemented, then security risk detection is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improvesecurity risk detectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses machine learning models that automatically learn and adapt to the organization's data access patterns and security requirements. The model continuously trains on historical access data and autonomously identifies risky authorization combinations without requiring manual configuration or intervention, reducing the operational complexity of maintaining the security system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system transforms the complex security analysis problem into computable parameters by representing access authorizations as structured data with specific attributes (data subsets, third-party systems, access levels). The machine learning model processes these parameterized representations efficiently, converting complex security relationships into mathematical computations that can be performed at scale.

Inventive Principle:
Principle #35Parameter changes

3Speed

If automated remediation processes are executed based on predicted security risks, then response time to threats is improved, but false positives and unnecessary disruptions may increase

Engineering Contradiction:
Improveresponse timeVSAvoidfalse positive rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system applies preliminary countermeasures by automatically revoking or modifying access authorizations that are predicted to create security risks. When the machine learning model identifies a high-probability risky combination, the system proactively prevents the unauthorized access before it can occur, rather than detecting and responding to actual breaches after they happen.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12375474B2System for secured electronic data access through machine-learning based analysis of combined access authorizations
Publication Date: 2025.07.29 BANK OF AMERICA CORP
  • US12375474B2 patent drawing
  • US12375474B2 patent drawing

AI summary

A system is provided for secured electronic data access through machine-learning based analysis of combined access authorizations. In particular, the system may maintain an access provisioning database which stores data regarding the data access authorizations that have been granted to one or more third party computing systems or entities. The system may further continuously monitor and aggregate electronic data from one or more electronic data streams and analyze the electronic data to intelligently generate probabilities for future events that create certain combinations of access authorizations that affect the security of the electronic data to which the third party computing systems have authorized access. In this way, the system may provide an effective way to manage access authorizations.