Neuro-Symbolic API Access Control for Partial Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face challenges in efficiently, securely, and uniformly managing information exchange between internal and external computer systems, particularly in open banking scenarios where APIs are vulnerable to unauthorized access and lack robust digital identity validation.
Innovation Solution
A neuro-symbolic AI-based assessment system that uses neural networks and symbolic reasoning to identify access patterns, build sub-objects in real-time, and perform partial data transfers to ensure secure and controlled information sharing through APIs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional APIs are exposed to external interfaces for open banking, then information sharing efficiency is improved, but security vulnerability increases due to lack of digital identity validation and unauthorized access
Solution Approach 1:
The patent introduces an intermediary authentication and authorization system between internal enterprise systems and external API consumers. This intermediary layer performs digital identity validation, access pattern analysis, and dynamic object construction before data is transferred, thereby maintaining security while enabling efficient information sharing.
Solution Approach 2:
The system performs preliminary authentication and authorization actions before allowing API calls to proceed. By validating digital identities and analyzing access patterns in advance, the system prevents unauthorized access while maintaining efficient data exchange for authenticated users.
2Ease of operation
If full data transfer is performed for API calls, then data accessibility is improved, but data security risk increases due to potential unauthorized access and information leakage
Solution Approach 1:
The patent segments data transfer by constructing dynamic objects that include only the specific sub-objects relevant to the authenticated user's access rights. Instead of transferring complete datasets, the system divides data into manageable segments based on access patterns and authorization levels, thereby maintaining accessibility while minimizing security risks.
Solution Approach 2:
The system performs partial data transfer by providing only the necessary subset of data required for the specific API call and user access level. This partial action approach ensures that users receive sufficient information for their legitimate needs while preventing excessive data exposure that could compromise security.
3Reliability
If robust digital identity validation and access pattern analysis are implemented, then data security is improved, but system complexity increases
Solution Approach 1:
The authentication and authorization system is designed as a universal multi-functional platform that handles digital identity validation, access pattern analysis, dynamic object construction, and data transfer control through a single integrated framework. This universality reduces overall system complexity by consolidating multiple security functions into one cohesive system.
Solution Approach 2:
The system implements self-service authentication and authorization mechanisms that automatically validate digital identities, analyze access patterns, and determine appropriate data access levels without requiring manual intervention. This automation reduces operational complexity while maintaining robust security through continuous self-validation and adaptive access control.
Data Source
AI summary
Various aspects of the disclosure relate to dynamically determining user access levels to manage access to enterprise information via application programming interfaces (APIs). A neuro-symbolic AI-based assessment enabled system manages assessments and response to API calls to ensure data security of information shared with external sources via the API. This system identifies and analyze access patterns via neural networks and symbolic reasoning to dynamically manage a rule set to determine access levels and corresponding data sub-objects that are built in real time to be shared with an API response message.


