IP Library Granted Patent US 12,393,718
Granted Patent B2
US 12,393,718 · App. 18/689,112 · Granted Aug 19, 2025

System and method for managing data access requests

Inventors: Adam Ben Gur (Mevaseret-Zion, IL); Adi Hod (Ramat Gan, IL)
Assignee: Velotix Ltd.
G06F21/6218G06N5/022
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,718
App. No.
18/689,112
Granted
Aug 19, 2025
Kind
B2
Abstract

In data access management, a data access request builder module is used to receive data characterizing a data access request and generate one or more knowledge graphs therefrom. One or more knowledge graphs of previously approved data access requests having similarities with the one or more knowledge graphs generated for the data access request can be identified by a model trainer module, to thereby generate a global knowledge graph combining the one or more knowledge graphs generated for the data access request with the identified one or more knowledge graphs, and for determining from the global knowledge graph one or more recommendations for improving probability of approval of the data access request. At least one of the one or more knowledge graphs generated for the data access request based on the generated recommendations can be modified and/or augmented by a compliance engine, to thereby generate a modified and/or augmented data access request.

Claims (37)

1. A computer-implemented data access management system comprising:

at least one hardware processor;

at least one communication interface connected to a data communication network;

at least one non-transitory computer-readable storage medium storing executable code, and a policy catalogue database, that when executed by said at least one hardware processor, causes the at least one hardware processor to:

receive, via the communication interface, data characterizing a data access request requesting access to at least one database connected to the data communication network;

generate, using a domain specific language (DSL), one or more knowledge graphs from the received data access request, wherein the knowledge graphs represent entities and data items of the data access request and relationships therebetween;

identify one or more knowledge graphs of previously approved data access requests stored in the policy catalogue database having similarities with the one or more generated knowledge graphs;

generate a global knowledge graph by combining the identified knowledge graphs with the generated knowledge graphs;

determine, using cybernetic modeling, one or more recommendations for improving probability of approval of the data access request by analyzing patterns of actions and conditions in the global knowledge graph;

modify and/or augment at least one of the one or more knowledge graphs based on the determined recommendations;

issue a modified data access request;

manage and monitor authorization of the modified data access request by executing data handling actions specified in the approved request; and

control and monitor data access to the at least one database by executing data transformation operations according to authorized request limitations.

2. The computer-implemented data access management system according to claim 1 , wherein said executable code further cause the at least one hardware processor, when executed by said at least one hardware processor, to receive and to process resolution data indicative of approval or denial of the modified and/or augmented data access request, and to generate based thereon recommendation data for further processing of said modified and/or augmented data access request.

3. The computer-implemented data access management system according to claim 2 wherein the recommendation data is configured to cause the at least one hardware processor, when executing said executable code, to generate a policy from the one or more knowledge graphs of the modified and/or augmented data access request whenever the resolution data is indicative of approval of said modified and/or augmented data access request.

4. The computer-implemented data access management system according to claim 1 , wherein the recommendation data is configured to cause the at least hardware processor, when executing said executable code, to further augment and/or modify the knowledge graphs of the modified and/or augmented data access request according to weights and/or priorities of elements of knowledge graphs included in the global knowledge graph.

5. The computer-implemented data access management system according to claim 4 wherein the recommendation data is configured to further cause the at least hardware processor, when executing said executable code, to generate a policy from the one or more knowledge graphs of the further modified and/or augmented data access request.

6. The computer-implemented data access management system according to claim 1 , comprising a data catalogue repository configured for storing metadata and/or tagging data items incorporated in the data access requests.

7. The computer-implemented data access management system according to claim 1 , wherein said executable code further cause the at least one hardware processor, when executed by said at least one hardware processor, to extract and/or transform data from one or more data sources and represent the same within limitations defined by the authorized data access request.

8. The computer-implemented data access management system according to claim 1 , comprising a policy repository for storing knowledge graphs of the modified and/or augmented data access requests that been authorized, and their generated recommendations.

9. A computer-implemented data access management method, comprising:

receiving data characterizing a data access request requesting access to at least one database connected to a data communication network;

generating, using a domain specific language (DSL), one or more knowledge graphs from the received data access request, wherein the knowledge graphs represent entities and data items of the data access request and relationships therebetween;

identifying one or more knowledge graphs of previously approved data access requests stored in a policy catalogue database having similarities with the one or more generated knowledge graphs;

generating a global knowledge graph by combining the identified knowledge graphs with the generated knowledge graphs;

determining, using cybernetic modeling, one or more recommendations for improving probability of approval of the data access request by analyzing patterns of actions and conditions in the global knowledge graph;

modifying and/or augmenting at least one of the one or more knowledge graphs based on the determined recommendations;

issuing a modified data access request;

managing and monitoring authorization of the modified data access request by executing data handling actions specified in the approved request; and

causing at least one hardware processor to control and monitor data access to the at least one database by executing data transformation operations according to authorized request limitations.

10. The method according to claim 9 , comprising receiving and processing resolution data indicative of approval or denial of the modified and/or augmented data access request, and generating based thereon recommendation data for further processing of said modified and/or augmented data access request.

11. The method according to claim 10 comprising generating a policy from the one or more knowledge graphs of the modified and/or augmented data access request whenever the resolution data is indicative of approval of said modified and/or augmented data access request.

12. The method according to claim 9 , comprising further augmenting and/or modifying the knowledge graphs of the modified and/or augmented data access request according to weights and/or priorities of elements of knowledge graphs included in the global knowledge graph.

13. The method according to claim 12 comprising generating a policy from the one or more knowledge graphs of the further modified and/or augmented data access request.

14. The method according to claim 9 , comprising storing metadata and/or tagging data items incorporated in the data access requests in a dedicated repository.

15. The method according to claim 9 , further comprising extracting and/or transforming data from one or more data sources and representing the same within limitations defined by the authorized data access request.

16. The method according to claim 9 , comprising storing in a repository knowledge graphs of the modified and/or augmented data access request data access requests that been authorized, and their generated recommendations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2024
From: BEN GUR, ADAM; HOD, ADI
To: VELOTIX LTD.
Reel/Frame 067160/0566 →
Priority Claims (1)
IL 286186 · Sep 5, 2021 · national
Continuity (1)
Related Publication 20240273230A1 · Aug 15, 2024
References Cited (26)
US 11445035B2 · Duggal · 2022 [cited by examiner]
US 11562009B2 · Bhattacharya · 2023 [cited by examiner]
US 20110093460A1 · Lunt · 2011 [cited by applicant]
US 20150095303A1 · Sonmcz et al. · 2015 [cited by applicant]
US 20190155940A1 · Lecue · 2019 [cited by applicant]
US 20190179878A1 · Collins · 2019 [cited by examiner]
US 20190236215A1 · Agarwal et al. · 2019 [cited by applicant]
US 20200167426A1 · Scheideler et al. · 2020 [cited by applicant]
US 20200257730A1 · Srinivas et al. · 2020 [cited by applicant]
US 20200389495A1 · Crabtree · 2020 [cited by examiner]
US 20200412767A1 · Crabtree · 2020 [cited by examiner]
US 20220067204A1 · Hadar · 2022 [cited by examiner]
US 20220245267A1 · Vangala · 2022 [cited by examiner]
US 20220318426A1 · Solheim · 2022 [cited by examiner]
US 20220394052A1 · Grossman-Avraham · 2022 [cited by examiner]
US 20240048592A1 · Viswanathan · 2024 [cited by examiner]
US 20240195908A1 · Bansal · 2024 [cited by examiner]
WO WO2021028748 · 2021 [cited by applicant]
WO WO2021063104 · 2021 [cited by applicant]
WO WO2023031938 · 2023 [cited by applicant]
International Preliminary Report on Patentability Dated Mar. 14, 2024 From the International Bureau of WIPO Re. Application No. PCT/IL2022/050963 (6 Pages). [cited by applicant]
International Search Report and the Written Opinion Dated Nov. 24, 2022 From the International Searching Authority Re. Application No. PCT/IIL2022/050963. (7 Pages). [cited by applicant]
Office Action Dated Feb. 20, 2022 From the Israel Patent Office Re. Application No. 286186. 3 Pages). [cited by applicant]
Search Report Dated Feb. 15, 2022 From the Israel Patent Office Re. Application No. 286186. (4 Pages). [cited by applicant]
Search Report Dated Feb. 18, 2022 From the Israel Patent Office Re. Application No. 286186. (2 Pages). [cited by applicant]
Notice of Eligibility of Grant and Examination Report Dated Dec. 4, 2024 From the Intellectual Property Office of Singapore Re. Application No. 11202401501X. (4 Pages). [cited by applicant]