IP Library › Granted Patent US 12,549,561
Granted Patent B2
US 12,549,561 · App. 18/099,565 · Granted Feb 10, 2026

Systems and methods for dynamic access permissions to secure data resources in a distributed network

Inventors: Malu Goff (Plano, TX); Michael Dee Conoly (Mesquite, TX)
Assignee: BANK OF AMERICA CORPORATION
H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,561
App. No.
18/099,565
Granted
Feb 10, 2026
Kind
B2
Abstract

Systems, methods, and computer program products are provided herein for dynamic access permissions to secure data resources in a distributed network. An example method includes identifying an application from amongst a plurality of applications with which the system interacts and determining one or more access permissions associated with secure interactions between the system and the identified application. The method further includes determining an absence of a least a first access permission from amongst the one or more access permissions with respect to the system and modifying a database of the system to register the at least first access permission. The one or more access permissions associated with the secure interactions between the system and the identified application define an interaction time period during which at least a first portion of the one or more access permissions were used.

Claims (45)

1 . A system for dynamic access permissions to secure data resources in a distributed network, the system comprising:

at least one non-transitory storage device; and

at least one processor coupled to the at least one non-transitory storage device, wherein the at least one processor is configured to:

access a plurality of permissions transmissions from a plurality of applications with which the system interacts;

identify an application from amongst the plurality of applications;

determine a plurality of access permissions which collectively enable secure interactions between the system and the identified application, such that each of the plurality of access permissions are required for establishing a secure interaction between the system and the identified application, wherein the plurality of access permissions are received by the system via the plurality permissions transmissions;

deploy a trained machine learning (ML) model on the one or more access permissions;

determine an absence of at least a first access permission from amongst the plurality of access permissions with respect to the system indicative of an absence of the first access permission in the plurality of permissions transmissions received by the system, wherein the absence of the first access permission is determined based on an inference by the trained ML model, and wherein the absence of the first access permission from amongst the plurality of access permission precludes establishing the secure interaction between the system and the identified application; and

modify a database of the system to register the at least first access permission.

2 . The system of claim 1 , wherein the plurality of access permissions associated with the secure interactions between the system and the identified application define an interaction time period during which at least a first portion of the one or more access permissions were used.

3 . The system of claim 2 , wherein, in determining the absence of a least the first access permission, the at least one processor is further configured to:

compare each of the access permissions in the first portion with access permissions stored by the database; and

determine the absence of at least the first access permission in an instance in which the first access permissions fails to be stored by the database.

4 . The system of claim 3 , wherein the at least one processor is further configured to iteratively compare each of the access permissions in the first portion with the access permissions stored by the database.

5 . The system of claim 2 , wherein the at least one processor is further configured to determine a second portion of the plurality of access permissions, wherein the second portion comprises one or more access permissions that are unused during the interaction time period.

6 . The system of claim 5 , wherein the at least one processor is further configured to perform one or more revocation operations associated with the second portion of the one or more access permissions.

7 . The system of claim 1 , wherein the at least one processor is further configured to generate a user interface comprising a visual representation of the database modification.

8 . A computer program product for dynamic access permissions to secure data resources in a distributed network, the computer program product comprising a non-transitory computer-readable medium comprising code causing an apparatus to:

access a plurality of permissions transmissions from a plurality of applications with which the system interacts;

identify an application from amongst the plurality of applications;

determine a plurality of access permissions which collectively enable secure interactions between the system and the identified application, such that each of the plurality of access permissions are required for establishing a secure interaction between the system and the identified application, wherein the plurality of access permissions are received by the system via the plurality permissions transmissions;

deploy a trained machine learning (ML) model on the one or more access permissions;

determine an absence of at least a first access permission from amongst the plurality of access permissions with respect to the system indicative of an absence of the first access permission in the plurality of permissions transmissions received by the system, wherein the absence of the first access permission is determined based on an inference by the trained ML model, and wherein the absence of the first access permission from amongst the plurality of access permission precludes establishing the secure interaction between the system and the identified application; and

modify a database of the system to register the at least first access permission.

9 . The computer program product of claim 8 , wherein the plurality of access permissions associated with the secure interactions between the system and the identified application define an interaction time period during which at least a first portion of the one or more access permissions were used.

10 . The computer program product of claim 9 , wherein, in determining the absence of a least the first access permission, the apparatus is further configured to:

compare each of the access permissions in the first portion with access permissions stored by the database; and

determine the absence of at least the first access permission in an instance in which the first access permissions fails to be stored by the database.

11 . The computer program product of claim 10 , wherein the apparatus is further configured to iteratively compare each of the access permission in the first portion with the access permissions stored by the database.

12 . The computer program product of claim 9 , wherein the apparatus is further configured to determine a second portion of the plurality of access permissions, wherein the second portion comprises one or more access permissions that are unused during the interaction time period.

13 . The computer program product of claim 12 , wherein the apparatus is further configured to perform one or more revocation operations associated with the second portion of the one or more access permissions.

14 . A method for dynamic access permissions to secure data resources in a distributed network, the method comprising:

accessing a plurality of permissions transmissions from a plurality of applications with which the system interacts;

identifying an application from amongst the plurality of applications;

determining a plurality of access permissions which collectively enable secure interactions between the system and the identified application, such that each of the plurality of access permissions are required for establishing a secure interaction between the system and the identified application, wherein the plurality of access permission are received by the system via the plurality permissions transmissions;

determining an absence of at least a first access permission from amongst the plurality of access permissions with respect to the system indicative of an absence of the first access permissions in the plurality of permissions transmissions received by the system, wherein the absence of the first access permission is determined based on an inference by the trained ML model, and wherein the absence of the first access permission from amongst the plurality of access permission precludes establishing the secure interaction between the system and the identified application; and

modifying a database of the system to register the at least first access permission.

15 . The method of claim 14 , wherein the one or more access permissions associated with the secure interactions between the system and the identified application define an interaction time period during which at least a first portion of the one or more access permissions were used.

16 . The method of claim 15 , wherein determining the absence of a least the first access permission further comprises:

comparing each of the plurality of access permissions in the first portion with access permissions stored by the database; and

determining the absence of at least the first access permission in an instance in which the first access permissions fails to be stored by the database.

17 . The method of claim 16 , further comprising iteratively comparing each of the access permissions in the first portion with the access permissions stored by the database.

18 . The method of claim 16 , further comprising determining a second portion of the plurality of access permissions, wherein the second portion comprises one or more access permissions that are unused during the interaction time period.

19 . The method of claim 18 , further comprising performing one or more revocation operations associated with the second portion of the one or more access permissions.

20 . The method of claim 14 , further comprising generating a user interface comprising a visual representation of the database modification.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2023
From: GOFF, MALU; CONOLY, MICHAEL DEE
To: BANK OF AMERICA CORPORATION
Reel/Frame 062438/0577 →
Continuity (1)
Related Publication 20240250956A1 · Jul 25, 2024
References Cited (17)
US 7607015B2 · Fascenda · 2009 [cited by applicant]
US 8572714B2 · Radhakrishnan · 2013 [cited by applicant]
US 9774586B1 · Roche et al. · 2017 [cited by applicant]
US 10454938B2 · Anderson et al. · 2019 [cited by applicant]
US 10572874B1 · Shahidzadeh et al. · 2020 [cited by applicant]
US 10863359B2 · Talwar · 2020 [cited by applicant]
US 11455641B1 · Shahidzadeh et al. · 2022 [cited by applicant]
US 20030051140A1 · Buddhikot et al. · 2003 [cited by applicant]
US 20080189788A1 · Bahl · 2008 [cited by applicant]
US 20120036550A1 · Rodriguez et al. · 2012 [cited by applicant]
US 20120204235A1 · Jaudon · 2012 [cited by examiner]
US 20190139050A1 · Maheshwari · 2019 [cited by examiner]
US 20200053091A1 · Childress · 2020 [cited by examiner]
US 20210144144A1 · Parks · 2021 [cited by examiner]
US 20230306126A1 · Bishop · 2023 [cited by examiner]
WO WO2022251702A2 · 2022 [cited by examiner]
Sahil Arora, Pranav Khare, Sandeep Gupta; A Machine Learning for Role Based Access Control: Optimizing Role Management and Permission Management; 2024 First International Conference on Pioneering Developments in Compute… [cited by examiner]
Cited By (1)
US 12,730,922