ML-Based Access Revocation for Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in accurately predicting and managing user access requirements for applications within organizations, leading to either insufficient or excessive access, which can hinder productivity and pose security risks.

Innovation Solution

A machine learning model is employed to analyze user group information and access history to predict and adjust access permissions, ensuring each user has the minimum necessary access by training on a dataset that includes user associations and access information, and making predictions on required access to application functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If manual assessment of access requirements is used, then implementation simplicity is maintained, but access prediction accuracy deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidaccess prediction accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent replaces the manual mechanical assessment process with an automated machine learning system. The ML model analyzes user profiles, application requirements, and historical access data to automatically predict and determine appropriate access levels, eliminating the need for manual assessment while significantly improving accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service access management by allowing the machine learning model to autonomously evaluate and determine access requirements without human intervention. The model continuously learns from data and automatically adjusts access predictions, making the system self-improving and reducing manual workload.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If group membership is used for assigning access, then ease of operation is improved, but access precision deteriorates

Engineering Contradiction:
Improveaccess assignment simplicityVSAvoidaccess requirement accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent moves from uniform group-based access assignment to individualized access determination. The machine learning model evaluates each user's specific characteristics, role, and context to determine precise access requirements, ensuring that each user receives locally optimized access rights rather than blanket group permissions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system transitions from static group membership parameters to dynamic, multi-factor parameters including user profile attributes, application-specific requirements, historical access patterns, and contextual information. The ML model processes these varied parameters to determine optimal access levels for each user-application pair.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If excessive user access is provided, then user productivity is improved, but security risk increases

Engineering Contradiction:
Improveuser productivityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access management where the machine learning model continuously evaluates and adjusts access rights based on current user needs, contextual factors, and security requirements. Access permissions are not static but adapt dynamically to changing conditions, ensuring users have sufficient access for productivity while maintaining security through ongoing evaluation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where the ML model analyzes user behavior patterns, access utilization data, and security events to continuously improve access predictions. The model learns from feedback about actual user needs and security outcomes, refining its predictions to balance productivity and security optimally.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240232393A1Predicting access revocation for applications using machine learning models
Publication Date: 2024.07.11 CAPITAL ONE SERVICES LLC
  • US20240232393A1 patent drawing
  • US20240232393A1 patent drawing
  • US20240232393A1 patent drawing

AI summary

Methods and systems are described herein for predicting user access revocation for applications. The system may retrieve, based on user identifiers, user access information and user association information. The system may generate a dataset comprising entries for the user identifiers, where the entries include the user access information and the user association information. The system may input the dataset into a machine learning model to obtain predictions as to whether each user identifier requires access to one or more functions of one or more applications. In some embodiments, the machine learning model is trained to predict required user access. In response to determining that a particular prediction does not include one or more particular functions included in the user access information for a respective user identifier, the system may revoke access to the one or more particular functions from the user identifier.