IP Library › Granted Patent US 12,524,522
Granted Patent B2
US 12,524,522 · App. 18/631,006 · Granted Jan 13, 2026

System and method for generating sandbox environments in a computing network

Inventors: Kalyan Chakravarthy Pallapolu (Hyderabad, IN); Mohan Sreenivas Gali (Tirupati, IN)
Assignee: Bank of America Corporation
G06F21/53G06F8/433G06F21/602G06F21/604G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,522
App. No.
18/631,006
Filed
Apr 9, 2024
Granted
Jan 13, 2026
Kind
B2
Art Unit
2432
USPC
726/26
Abstract

In response to receiving a request from a user to generate a sandbox, one or more smart contracts is selected based on complexity metrics associated with one or more data modules requested for copying from a production environment to the requested sandbox. Based on the selected one or more smart contracts, one or more approvers are determined that are authorized to approve access of the user to the data relating to the one or more data modules. An approval workflow is generated and transmitted to the determined one or more approvers. Upon receiving an indication of approval from the one or more approvers, the sandbox is generated by copying the one or more data modules from the production environment to the requested sandbox.

Claims (85)

1 . A system comprising:

a production environment deployed using one or more cloud instances of a cloud infrastructure, wherein the cloud infrastructure comprises a plurality of computing nodes and wherein each cloud instance comprises at least a portion of computing resources provided by one or more of the computing nodes; and

a processor communicatively coupled to the cloud infrastructure and configured to:

receive a request to generate a sandbox environment in the cloud infrastructure, wherein:

the requested sandbox environment comprises a copy of at least a portion of the production environment; and

the request comprises a request for one or more data modules to be copied from the production environment to the sandbox environment;

access a plurality of smart contracts stored in a blockchain network, wherein each of the smart contracts comprises one or more rules relating to selection of one or more approvers that are authorized to approve access of a user to data relating to one or more data modules included in the production environment;

select one or more smart contracts from the plurality of smart contracts based on complexity metrics associated with the one or more data modules;

determine, based on the selected one or more smart contracts, one or more approvers that are authorized to approve access of the user to the data relating to the one or more data modules to be copied from the production environment to the sandbox environment;

generate an approval workflow for access of the user to the data relating to the one or more data modules in the sandbox environment;

transmit the approval workflow to the determined one or more approvers;

receive an indication of approval from the one or more approvers;

in response to receiving the indication of approval, generate the sandbox environment by copying the one or more data modules from the production environment to the sandbox environment.

2 . The system of claim 1 , wherein the processor is further configured to:

for each data module:

determine whether the data module comprises data designated as sensitive data that is accessible to authorized users only; and

assign a weight to the data module based on an amount of the sensitive data in the data module, wherein the weight assigned to the data module represents at least a portion of the complexity metric associated with the sandbox environment.

3 . The system of claim 2 , wherein:

a selected smart contract from the one or more smart contracts identifies a plurality of approvers for a data module of the requested one or more data modules, wherein each approver is associated with a particular value of the weight assigned to the data module; and

the processor is further configured to select an approver associated with the data module of the requested one or more data modules, wherein the selected approver is associated with the assigned weight of the data module.

4 . The system of claim 2 , wherein the sensitive data comprises one or more of Non-Public Information (NPI), Personal Identification Information (PII) or Production Information.

5 . The system of claim 1 , wherein the processor is further configured to:

for each data module:

determine whether the data module comprises dependencies to other data modules of the production environment; and

assign a weight to the data module based on an amount of dependencies to the other data modules, wherein the weight assigned to the data module represents at least a portion of the complexity metric associated with the sandbox environment.

6 . The system of claim 5 , wherein the processor is further configured to:

when the weight equals or exceeds a threshold, select a smart contract that includes one or more rules for selecting approvers associated with multiple dependent data modules.

7 . The system of claim 1 , wherein the processor is further configured to:

generate a new block of a blockchain associated with the blockchain network, wherein the new block records the generation of the sandbox environment; and

store the new block as part of the blockchain of the blockchain network.

8 . A method for controlling access to data in a sandbox environment, comprising:

receiving a request from a user to generate the sandbox environment in a cloud infrastructure, wherein:

the requested sandbox environment comprises a copy of at least a portion of a production environment;

the production environment is deployed using one or more cloud instances of the cloud infrastructure, wherein the cloud infrastructure comprises a plurality of computing nodes and wherein each cloud instance comprises at least a portion of computing resources provided by one or more of the computing nodes; and

the request comprises a request for one or more data modules to be copied from the production environment to the sandbox environment;

accessing a plurality of smart contracts stored in a blockchain network, wherein each of the smart contracts comprises one or more rules relating to selection of one or more approvers that are authorized to approve access of the user to data relating to one or more data modules included in the production environment;

selecting one or more smart contracts from the plurality of smart contracts based on complexity metrics associated with the one or more data modules;

determining, based on the selected one or more smart contracts, one or more approvers that are authorized to approve access of the user to the data relating to the one or more data modules to be copied from the production environment to the sandbox environment;

generating an approval workflow for access of the user to the data relating to the one or more data modules in the sandbox environment;

transmitting the approval workflow to the determined one or more approvers;

receiving an indication of approval from the one or more approvers;

in response to receiving the indication of approval, generating the sandbox environment by copying the one or more data modules from the production environment to the sandbox environment.

9 . The method of claim 8 , further comprising:

for each data module:

determining whether the data module comprises data designated as sensitive data that is accessible to authorized users only; and

assigning a weight to the data module based on an amount of the sensitive data in the data module, wherein the weight assigned to the data module represents at least a portion of the complexity metric associated with the sandbox environment.

10 . The method of claim 9 , wherein:

a selected smart contract from the one or more smart contracts identifies a plurality of approvers for a data module of the requested one or more data modules, wherein each approver is associated with a particular value of the weight assigned to the data module; and

further comprising selecting an approver associated with the data module of the requested one or more data modules, wherein the selected approver is associated with the assigned weight of the data module.

11 . The method of claim 9 , wherein the sensitive data comprises one or more of Non-Public Information (NPI), Personal Identification Information (PII) or Production Information.

12 . The method of claim 8 , further comprising:

for each data module:

determining whether the data module comprises dependencies to other data modules of the production environment; and

assigning a weight to the data module based on an amount of dependencies to the other data modules, wherein the weight assigned to the data module represents at least a portion of the complexity metric associated with the sandbox environment.

13 . The method of claim 12 , further comprising:

when the weight equals or exceeds a threshold, selecting a smart contract that includes one or more rules for selecting approvers associated with multiple dependent data modules.

14 . The method of claim 8 , further comprising:

generating a new block of a blockchain associated with the blockchain network, wherein the new block records the generation of the sandbox environment; and

storing the new block as part of the blockchain of the blockchain network.

15 . A non-transitory computer-readable medium storing instructions that when executed by a processor cause the processor to:

receive a request from a user to generate a sandbox environment in a cloud infrastructure, wherein:

the requested sandbox environment comprises a copy of at least a portion of a production environment;

the production environment is deployed using one or more cloud instances of the cloud infrastructure, wherein the cloud infrastructure comprises a plurality of computing nodes and wherein each cloud instance comprises at least a portion of computing resources provided by one or more of the computing nodes; and

the request comprises a request for one or more data modules to be copied from the production environment to the sandbox environment;

access a plurality of smart contracts stored in a blockchain network, wherein each of the smart contracts comprises one or more rules relating to selection of one or more approvers that are authorized to approve access of the user to data relating to one or more data modules included in the production environment;

select one or more smart contracts from the plurality of smart contracts based on complexity metrics associated with the one or more data modules;

determine, based on the selected one or more smart contracts, one or more approvers that are authorized to approve access of the user to the data relating to the one or more data modules to be copied from the production environment to the sandbox environment;

generate an approval workflow for access of the user to the data relating to the one or more data modules in the sandbox environment;

transmit the approval workflow to the determined one or more approvers;

receive an indication of approval from the one or more approvers;

in response to receiving the indication of approval, generate the sandbox environment by copying the one or more data modules from the production environment to the sandbox environment.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the processor to:

for each data module:

determine whether the data module comprises data designated as sensitive data that is accessible to authorized users only; and

assign a weight to the data module based on an amount of the sensitive data in the data module, wherein the weight assigned to the data module represents at least a portion of the complexity metric associated with the sandbox environment.

17 . The non-transitory computer-readable medium of claim 16 , wherein:

a selected smart contract from the one or more smart contracts identifies a plurality of approvers for a data module of the requested one or more data modules, wherein each approver is associated with a particular value of the weight assigned to the data module; and

wherein the instructions further cause the processor to select an approver associated with the data module of the requested one or more data modules, wherein the selected approver is associated with the assigned weight of the data module.

18 . The non-transitory computer-readable medium of claim 16 , wherein the sensitive data comprises one or more of Non-Public Information (NPI), Personal Identification Information (PII) or Production Information.

19 . The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the processor to:

for each data module:

determine whether the data module comprises dependencies to other data modules of the production environment; and

assign a weight to the data module based on an amount of dependencies to the other data modules, wherein the weight assigned to the data module represents at least a portion of the complexity metric associated with the sandbox environment.

20 . The non-transitory computer-readable medium of claim 19 , wherein the processor is further configured to:

when the weight equals or exceeds a threshold, select a smart contract that includes one or more rules for selecting approvers associated with multiple dependent data modules.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2024
From: PALLAPOLU, KALYAN CHAKRAVARTHY; GALI, MOHAN SREENIVAS
To: BANK OF AMERICA CORPORATION
Reel/Frame 067058/0134 →
Continuity (1)
Related Publication 20250315515A1 · Oct 9, 2025
References Cited (31)
US 8924543B2 · Raleigh et al. · 2014 [cited by applicant]
US 9557889B2 · Raleigh et al. · 2017 [cited by applicant]
US 9810729B2 · Frediani · 2017 [cited by applicant]
US 9952276B2 · Frediani et al. · 2018 [cited by applicant]
US 10161993B2 · Frediani et al. · 2018 [cited by applicant]
US 10162007B2 · Chan et al. · 2018 [cited by applicant]
US 10288681B2 · Champoux et al. · 2019 [cited by applicant]
US 10462627B2 · Raleigh et al. · 2019 [cited by applicant]
US 10869199B2 · Raleigh et al. · 2020 [cited by applicant]
US 10976361B2 · Malisic et al. · 2021 [cited by applicant]
US 11122424B1 · Branscomb · 2021 [cited by examiner]
US 11218854B2 · Raleigh et al. · 2022 [cited by applicant]
US 11430536B2 · Malisic et al. · 2022 [cited by applicant]
US 11494837B2 · Raleigh et al. · 2022 [cited by applicant]
US 11570309B2 · Raleigh et al. · 2023 [cited by applicant]
US 11860229B2 · Su · 2024 [cited by applicant]
US 20140040975A1 · Raleigh et al. · 2014 [cited by applicant]
US 20140248852A1 · Raleigh et al. · 2014 [cited by applicant]
US 20170353309A1 · Gray · 2017 [cited by examiner]
US 20180191714A1 · Jentzsch · 2018 [cited by examiner]
US 20190303623A1 · Reddy · 2019 [cited by examiner]
US 20200028691A1 · Rao · 2020 [cited by examiner]
US 20210117298A1 · Su et al. · 2021 [cited by applicant]
US 20240137208A1 · Zhu · 2024 [cited by examiner]
US 20240214229A1 · Han · 2024 [cited by examiner]
US 20250062924A1 · Zhu · 2025 [cited by examiner]
US 20250238254A1 · Schmid · 2025 [cited by examiner]
US 20250278906A1 · Witchey · 2025 [cited by examiner]
CN 115994354A · 2023 [cited by applicant]
RU 2750554C2 · 2021 [cited by applicant]
NPL Search Terms (Year: 2025). [cited by examiner]
Cited By (1)
US 12,705,034