IP Library Granted Patent US 11,394,719
Granted Patent B2
US 11,394,719 · App. 16/790,270 · Granted Jul 19, 2022

Dynamic user access control management

Inventors: Vijaya Kumar Vegulla (Hyderabad, IN); Netla Hanumantha Reddy (Hyderabad, IN); Sandeep D'Souza (Mumbai, IN); Kumar Mahadeva Setty (Newbury Park, CA); Anil Kumar Venkata Kalyanam (Hyderabad, IN); Venugopala Rao Randhi (Hyderabad, IN)
Assignee: Bank of America Corporation
H04L63/105G06N5/04G06N20/00H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,394,719
App. No.
16/790,270
Granted
Jul 19, 2022
Kind
B2
Abstract

An illustrative computing system for a dynamic user access control management system classifies users and data resources according to their risk and importance by a user management engine with artificial intelligence, machine learning characteristics. The dynamic user access control management system analyzes the log files of data resources to measure system performance characteristics and user access behavior. This system monitors the device and network by which a data access request to a data resource is made. The dynamic user access control management system validates the leave status of a user initiating a data access request. The dynamic user access control management system automatically determines a user access level for a data resource through intelligent analysis of collected information and defers to a user's manager for an access level determination when the determination to grant an access level is outside of the knowledge base of the user management engine.

Claims (50)

1. A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

monitor, by a user management engine, messages sent via a network from a computing device requesting access to a data resource;

monitor, by the user management engine, a plurality of messages received via the network from a plurality of user devices;

determine, by the user management engine and based on the monitored plurality of messages, a plurality of communications metrics comprising a data access metric, an access frequency metric, and a connection history metric;

analyze, by the user management engine and based on log files associated with the data resource, server performance data;

determine, by a machine learning module, a user access level to the data resource;

determine, by the user management engine based on the plurality of communications metrics, a plurality of user access groups;

generate, by the machine learning module, dynamic user access rights for each of the plurality of user devices; and

send, by the user management engine, a data access request message via a network based on the user access level.

2. The computing platform of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing platform to:

determine, by the user management engine, a data resource classification based on historical user access information and a predefined weight metric.

3. The computing platform of claim 1 , wherein the instructions, when executed by the one or more processors, cause the computing platform to:

determine, by the user management engine, a user access classification based on a number of data violations associated with a user and logged by an enterprise computing system.

4. The computing platform of claim 1 , wherein the user access level is determined from at least two of the historical user access information, data resource classification information, device communication information, server performance data, resource usage information, a manager approval input, a user's employment history information, and user leave status information.

5. The computing platform of claim 4 , wherein the user leave status information comprises one or more of a user's planned leave, unplanned leave, paid leave, unpaid leave, vacation, suspension, and termination information.

6. The computing platform of claim 1 , wherein the user access level comprises one of full access to the data resource, read access to the data resource, and no access to the data resource.

7. A method, comprising:

monitoring, by a user management engine, messages sent via a network from a computing device requesting access to a data resource;

monitoring, by the user management engine, a plurality of messages received via the network from a plurality of user devices;

determining, by the user management engine and based on the monitored plurality of messages, a plurality of communications metrics comprising a data access metric, an access frequency metric, and a connection history metric;

analyzing, by the user management engine and based on log files associated with the data resource, server performance data;

determining, by a machine learning module, a user access level to the data resource;

determining, by the user management engine based on the plurality of communications metrics, a plurality of user access groups; and

generating, by the machine learning module, dynamic user access rights for each of the plurality of user devices; and

sending, by the user management engine, a data access request message via a network based on the user access level.

8. The method of claim 7 , comprising:

determining, by the user management engine, a data resource classification based on historical user access information and a predefined weight metric.

9. The method of claim 7 , comprising:

determining, by the user management engine, a user access classification based on a number of data violations associated with the user and logged by an enterprise computing system.

10. The method of claim 7 , wherein the user access level is determined from at least two of the historical user access information, data resource classification information, device communication information, server performance data, resource usage information, a manager approval input, a user's employment history information, and user leave status information.

11. The method of claim 10 , wherein the user leave status information comprises one or more of a user's planned leave, unplanned leave, paid leave, unpaid leave, vacation, suspension, and termination information.

12. The method of claim 7 , wherein the user access level comprises one of full access to the data resource, read access to the data resource, and no access to the data resource.

13. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, memory, and a communication interface, cause the computing platform to:

monitor, by a user management engine, messages sent via a network from a computing device requesting access to a data resource;

monitor, by the user management engine, a plurality of messages received via the network from a plurality of user devices;

determine, by the user management engine and based on the monitored plurality of messages, a plurality of communications metrics comprising a data access metric, an access frequency metric, and a connection history metric;

analyze, by the user management engine and based on log files associated with the data resource, server performance data;

determine, by a machine learning module, a user access level to the data resource;

determine, by the user management engine based on the plurality of communications metrics, a plurality of user access groups; and

generate, by the machine learning module, dynamic user access rights for each of the plurality of user devices; and

send, by the user management engine, a data access request message via a network based on the user access level.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, cause the computing platform to:

determine, by the user management engine, a data resource classification based on historical user access information and a predefined weight metric.

15. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, cause the computing platform to:

determine, by the user management engine, a user access classification based on a number of data violations associated with the user and logged by an enterprise computing system.

16. The one or more non-transitory computer-readable media of claim 13 , wherein the user access level is determined from at least two of the historical user access information, data resource classification information, device communication information, server performance data, resource usage information, a manager approval input, a user's employment history information, and user leave status information.

17. The one or more non-transitory computer-readable media of claim 13 , wherein the user access level comprises one of full access to the data resource, read access to the data resource, and no access to the data resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2020
From: VEGULLA, VIJAYA KUMAR; REDDY, NETLA HANUMANTHA; D'SOUZA, SANDEEP; SETTY, KUMAR MAHADEVA; KALYANAM, ANIL KUMAR VENKATA; RANDHI, VENUGOPALA RAO
To: BANK OF AMERICA CORPORATION
Reel/Frame 051815/0406 →
Continuity (1)
Related Publication 20210258321A1 · Aug 19, 2021
Cited By (1)
US 12,339,987