PII Footprint Modeling for Malicious Access Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in securely managing and controlling access to personal identifiable information (PII) within enterprise organizations, balancing the need for access with the risk of malicious activities.

Innovation Solution

A computing platform that masks PII based on enterprise data management policies, logs requests to unmask PII for malicious event detection, and applies machine learning models to identify and remediate potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PII is masked to enhance security, then PII safety and security is improved, but access to PII for legitimate business operations becomes restricted

Engineering Contradiction:
ImprovePII safety and securityVSAvoidaccess to PII for legitimate business operations
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts the masking state of PII based on user identity, context, and authorization levels. Different users see different levels of masking (e.g., full masking for general users, partial unmasking for authorized users), allowing the system to adapt security measures to individual needs while maintaining both security and operational efficiency.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The masking application is selective and localized rather than universal. The system applies masking to specific PII fields based on user roles, data sensitivity levels, and access policies. Authorized users can have specific fields unmasked while others remain masked, creating a granular approach that balances security with operational requirements.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If PII is unmasked to allow access for job functions, then ease of operation is improved, but risk of malicious activities increases

Engineering Contradiction:
Improveaccess to PII for job functionsVSAvoidrisk of malicious activities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system continuously monitors access patterns, user behavior, and contextual information to detect anomalies. When suspicious activity is detected (e.g., unusual access timing, abnormal data requests), the system provides feedback by alerting security systems or automatically adjusting access controls, creating a closed-loop security mechanism that responds to real-time conditions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary security assessments before allowing PII access. User authorization levels, access policies, and security contexts are evaluated in advance to determine whether unmasking should be permitted. This preemptive verification ensures that only authorized operations proceed, preventing malicious activities before they can occur.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access control mechanisms are implemented to prevent malicious activities, then PII safety is improved, but productivity of legitimate operations decreases

Engineering Contradiction:
ImprovePII safetyVSAvoidproductivity of legitimate operations
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security policies, access controls, and authorization frameworks are established and configured in advance before users need to access PII. This preliminary setup eliminates the need for real-time manual security approvals, allowing legitimate operations to proceed efficiently while maintaining strong security postures through pre-defined access matrices and policies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically manages access control decisions based on user identities, roles, and contextual information without requiring manual intervention. Authorization determinations are made autonomously by the system based on predefined policies, eliminating bottlenecks from manual security reviews and allowing legitimate operations to proceed at full speed while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12216796B2Insight generation using personal identifiable information (PII) footprint modeling
Publication Date: 2025.02.04 BANK OF AMERICA CORP
  • US12216796B2 patent drawing
  • US12216796B2 patent drawing
  • US12216796B2 patent drawing

AI summary

Aspects of the disclosure relate to information masking. A user device may receive a request to access information that includes personal identifiable information (PII) and retrieve source data comprising the PII. The user device may mask, within the source data and based on a data management policy, the PII, resulting in masked information. The user device may display the masked information. The user device may receive a request to unmask the masked information and unmask the PII, resulting in unmasked PII. The user device may display the unmasked PII and send unmasking event information to a PII footprint modeling platform, which may cause the PIT footprint modeling platform to: log the request to unmask the masked information in an unmasking event log, 2) apply a machine learning model to the unmasking event log to identify malicious events, and 3) trigger remediation actions based on identification of the malicious events.