Automated Permission Assignment via User Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in accurately and efficiently assigning resource permissions to new users within a network, as too many permissions can compromise security, while too few can hinder job efficiency, making it difficult to balance access levels across millions of unique resources.

Innovation Solution

A system that automatically assigns resource permissions by grouping users based on job characteristics, such as job title or supervisor, using machine learning to update and refine permission levels, ensuring consistent access for users within a group and allowing administrators to confirm or adjust these assignments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual permission assignment is used for each user, then individual access control is achieved, but the time and complexity required to assign permissions across millions of resources increases significantly

Engineering Contradiction:
Improveaccess control accuracyVSAvoidpermission assignment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple users with similar job characteristics into user groups, assigning permissions at the group level rather than individually to each user. This consolidation reduces the time required to assign permissions across millions of resources while maintaining appropriate access control through group-based policies.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary actions by pre-defining user groups based on job characteristics and pre-establishing permission templates for these groups. When a new user is added, their permissions are automatically assigned based on their group membership, eliminating the need for manual permission configuration at the time of user creation.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If more permission levels are assigned to users, then user job efficiency is improved, but network security is compromised

Engineering Contradiction:
Improveuser job efficiencyVSAvoidnetwork security risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different permission levels to different user groups based on their specific job characteristics and requirements. Each user group receives precisely the permissions needed for their role, neither more nor less, achieving appropriate access control tailored to local needs while maintaining overall network security.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If individual permission requests are processed for each user, then accurate access levels are assigned, but the complexity of managing permissions across the network increases

Engineering Contradiction:
Improveaccess level accuracyVSAvoidpermission management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements universality by creating user groups that can be applied to multiple users with similar job characteristics. A single group definition and permission template serves multiple users, reducing the complexity of permission management while maintaining accurate access levels through the universal application of group-based policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12107864B2System and method for automatically assigning network and application permissions to a network device based on user attributes
Publication Date: 2024.10.01 BANK OF AMERICA CORP
  • US12107864B2 patent drawing
  • US12107864B2 patent drawing
  • US12107864B2 patent drawing

AI summary

Systems, methods, and computer program products are provided for automatically assigning resource permission levels. The method includes assigning a user to a user group based on one or more job characteristics. The user group includes one or more users associated with a common job type. The method also includes determining a resource permission level for one or more resources based on the user group of the user. Each of the users in a user group receive the same resource permission level for at least one of the one or more resources. The method further includes allowing the user access to one or more resources on a user device associated with the user.