IP Library › Granted Patent US 12,627,668
Granted Patent B2
US 12,627,668 · App. 18/659,254 · Granted May 12, 2026

Role-based access control recommendation systems

Inventor: James Paul Black (Sunnyvale, CA)
Assignee: Google LLC
H04L63/101H04L63/104H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,668
App. No.
18/659,254
Filed
May 9, 2024
Granted
May 12, 2026
Kind
B2
Art Unit
2431
USPC
726/4
Abstract

A method for role-based access control recommendation includes obtaining one or more security logs from a security analytics platform. The method includes determining access rights to the one or more security logs for one or more users of the security analytics platform. The determining includes generating one or more clusters of security logs based on the one or more security logs. The determining includes providing, to a user of the security analytics platform, a recommendation for a first data access group for the security analytics platform based on a first cluster of the one or more clusters. The determining includes, responsive to input from the user of the security analytics platform, generating the first data access group for the security analytics platform based on the first cluster of the one or more clusters.

Claims (68)

1 . A method to provide access group recommendations, comprising:

obtaining a plurality of security logs from a security analytics platform, wherein:

each security log of the plurality of security logs indicates an action occurring on a computing system, and

each security log of the plurality of security log comprises a plurality of key-value pairs; and

determining access rights to the plurality of security logs for a plurality of users of the security analytics platform, wherein the plurality of users include a first subset of the plurality of users having access to a first subset of the plurality of security logs, and wherein the determining comprises:

generating a plurality of clusters of security logs based on at least a portion of the key-value pairs of the plurality of security logs,

providing, to a user of the security analytics platform, a recommendation for a first data access group for the security analytics platform based on a first cluster of the plurality of clusters, wherein the first data access group comprises data indicating the first subset of the plurality of security logs of the security analytics platform and the first subset of the plurality of users to have access to the subset of the plurality of security logs of the security analytics platform, and

responsive to user input indicating approval of the user of the security analytics platform, generating the first data access group for the security analytics platform based on the first cluster of the plurality of clusters.

2 . The method of claim 1 , wherein the at least a portion of the key-value pairs of the plurality of security logs comprises at least one of:

a vendor key-value pair;

a product key-value pair; or

a product type key-value pair.

3 . The method of claim 1 , wherein the at least a portion of the key-value pairs of the plurality of security logs comprises at least one of:

a business unit key-value pair; or

a geographic location key-value pair.

4 . The method of claim 1 , wherein obtaining the plurality of security logs from the security analytics platform comprises obtaining one or more event logs of the computing system.

5 . The method of claim 1 , further comprising obtaining a second data access group from the security analytics platform, wherein:

the second data access group includes a data access group generated using input of the user of the security analytics platform; and

the second data access group includes data indicating a second subset of users of the plurality of users of the security analytics platform.

6 . The method of claim 5 , wherein providing, to the user of the security analytics platform, the recommendation for the first data access group comprises:

determining that a similarity metric indicates a dissimilarity regarding the first data access group and the second data access group above a threshold amount; and

alerting the user of the security analytics platform of a data access leak.

7 . The method of claim 1 , further comprising performing a data access group size analysis on the first data access group.

8 . The method of claim 7 , wherein performing the data access group size analysis on the first data access group comprises:

obtaining a directory service forest of the computing system;

comparing a size of the first subset of the plurality of users of the security analytics platform to a size of a subset of the directory service forest; and

responsive to a difference in the size of the first subset of the plurality of users and the size of the subset of the directory service forest being above a threshold difference, modifying the first subset of the plurality of users.

9 . The method of claim 7 , wherein performing the data access group size analysis on the first data access group comprises:

obtaining identity and access management (IAM) policy data of the computing system;

comparing a size of the first subset of the plurality of users of the security analytics platform to a size of a group of users of the IAM policy data; and

responsive to a difference in the size of the first subset of the plurality of users and the size of the subset of the data access group of the IAM policy data being above a threshold difference, modifying the first subset of the plurality of users.

10 . A system to provide access group recommendations, comprising:

a memory; and

a processing device, coupled to the memory, configured to perform operations, comprising:

obtaining a plurality of security logs from a security analytics platform, wherein:

each security log of the plurality of security logs indicates an action occurring on a computing system, and

each security log of the plurality of security log comprises a plurality of key-value pairs; and

determining access rights to the plurality of security logs for a plurality of users of the security analytics platform, wherein the plurality of users include a first subset of the plurality of users having access to a first subset of the plurality of security logs, and wherein the determining comprises:

generating a plurality of clusters of security logs based on at least a portion of the key-value pairs of the plurality of security logs,

providing, to a user of the security analytics platform, a recommendation for a first data access group for the security analytics platform based on a first cluster of the plurality of clusters, wherein the first data access group comprises data indicating the first subset of the plurality of security logs of the security analytics platform and the first subset of the plurality of users to have access to the subset of the plurality of security logs of the security analytics platform, and

responsive to user input indicating approval of the user of the security analytics platform, generating the first data access group for the security analytics platform based on the first cluster of the plurality of clusters.

11 . The system of claim 10 , wherein the at least a portion of the key-value pairs of the plurality of security logs comprises at least one of:

a vendor key-value pair;

a product key-value pair; or

a product type key-value pair.

12 . The system of claim 10 , wherein the at least a portion of the key-value pairs of the plurality of security logs comprises at least one of:

a business unit key-value pair; or

a geographic location key-value pair.

13 . The system of claim 10 , wherein obtaining the plurality of security logs from the security analytics platform comprises obtaining one or more event logs of the computing system.

14 . The system of claim 10 , wherein the operations further comprise obtaining a second data access group from the security analytics platform, wherein:

the second data access group includes a data access group generated using input of the user of the security analytics platform; and

the second data access group includes data indicating a second subset of users of the plurality of users of the security analytics platform.

15 . The system of claim 14 , wherein the operation of providing, to the user of the security analytics platform, the recommendation for the first data access group comprises:

determining that a similarity metric indicates a dissimilarity regarding the first data access group and the second data access group above a threshold amount; and

alerting the user of the security analytics platform of a data access leak.

16 . The system of claim 10 , wherein the operations further comprise performing a data access group size analysis on the first data access group.

17 . A method to provide access group recommendations, comprising:

obtaining a plurality of security logs from a security analytics platform, wherein:

each security log of the plurality of security logs indicates an action occurring on a computing system, and

each security log of the plurality of security logs comprises a plurality of key-value pairs; and

determining access rights to the plurality of security logs for a plurality of users of the security analytics platform, wherein the plurality of users of the security analytics platform have access to a subset of the plurality of security logs, and wherein the determining comprises:

obtaining a first data access group of the security analytics platform,

selecting, based on the first data access group, the subset of the plurality of security logs of the security analytics platform,

generating a plurality of clusters based on at least a portion of the key-value pairs of the subset of the plurality of security logs, and

responsive to the selected subset of the plurality of security logs including one or more security logs belonging to different clusters that differ from a first cluster of the plurality of clusters, providing, to a user of the security analytics platform, a recommendation for a modification to the first data access group of the security analytics platform.

18 . The method of claim 17 , wherein the data access group comprises a data access group generated using user input to the security analytics platform.

19 . The method of claim 17 , further comprising, responsive to input from the user of the security analytics platform, generating a data access group for the security analytics platform based on the first data access group as modified by the recommendation.

20 . The method of claim 17 , wherein obtaining the plurality of security logs from the security analytics platform comprises obtaining one or more event logs of the computing system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2024
From: BLACK, JAMES PAUL
To: GOOGLE LLC
Reel/Frame 067374/0341 →
Continuity (1)
Related Publication 20250350602A1 · Nov 13, 2025
References Cited (5)
US 11115421B2 · Nevatia et al. · 2021 [cited by applicant]
US 11416771B2 · Patil et al. · 2022 [cited by applicant]
US 11501257B2 · Schornack et al. · 2022 [cited by applicant]
US 12107874B2 · Malhotra · 2024 [cited by examiner]
US 12238119B1 · Chivu · 2025 [cited by examiner]