IP Library › Granted Patent US 12,585,808
Granted Patent B2
US 12,585,808 · App. 18/475,505 · Granted Mar 24, 2026

Systems and methods for content based access control

Inventors: Gopi Kishan (Bangalore, IN); Rohit Jalagadugula (Visakhapatnam, IN)
Assignee: SAP SE
G06F21/6218G06N5/022
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,808
App. No.
18/475,505
Granted
Mar 24, 2026
Kind
B2
Abstract

Embodiments of the present disclosure include techniques for controlling access to electronic content. In one embodiment, a user generates content in an electronic document. The system retrieves the content and a profile for the user. A predictive engine determines an access control list comprising a plurality of entries based on the content and the profile. The access control list may be presented to the user, and the system receives a verification from the user of the plurality of entries in the access control list.

Claims (56)

1 . A method of controlling access to electronic content comprising:

generating, by a user, content in an electronic document;

retrieving a profile for the user;

determining, by a predictive engine, an access control list comprising a plurality of entries based on the content and the profile, wherein the predictive engine comprises a trained transformer model with inputs of a first numeric vector mapping the profile and the content and a second numeric vector token mapping a first pre-existing access control list; and

receiving a verification from the user of the plurality of entries in the access control list.

2 . The method of claim 1 , wherein the trained transformer model is updated after the verification from the user.

3 . The method of claim 1 , further comprising modifying the predictive engine based on the verification from the user, and wherein:

when the user indicates that an entry in the access control list is a wrong entry produces negative points;

when the user indicates that an entry in the access control list is a correct entry produces positive points;

when the user indicates a missing entry in the access control list produces negative points; and

when an entry is unchanged by the user in the access control list produces a cumulative score over a time period time.

4 . The method of claim 1 , the method further comprising:

accessing data comprising user profiles, document content, file metadata, and access control lists;

generating numerical vectors from the user profiles, the document content, the file metadata, and the access control lists;

providing the numerical vectors for the user profiles, the document content, and the file metadata as an input embedding to the trained transformer model, and providing the numerical vectors for the access control lists as an output embedding to the trained transformer model, to produce output probabilities corresponding to generated access control lists; and

verifying the generated access control lists to train the trained transformer model.

5 . The method of claim 1 , wherein the content comprises text data.

6 . The method of claim 1 , wherein the access control list is a discretionary access control list (DACL).

7 . A computer system comprising:

at least one processor;

at least one non-transitory computer readable medium storing computer executable instructions that, when executed by the at least one processor, cause the computer system to perform a method of controlling access to electronic content comprising:

generating, by a user, content in an electronic document;

retrieving a profile for the user;

determining, by a predictive engine, an access control list comprising a plurality of entries based on the content and the profile, wherein the predictive engine comprises a trained transformer model with inputs of a first numeric vector mapping the profile and the content and a second numeric vector token mapping a first pre-existing access control list; and

receiving a verification from the user of the plurality of entries in the access control list.

8 . The computer system of claim 7 , wherein the trained transformer model is updated after the verification from the user.

9 . The computer system of claim 7 , further comprising modifying the predictive engine based on the verification from the user, and wherein:

when the user indicates that an entry in the access control list is a wrong entry produces negative points;

when the user indicates that an entry in the access control list is a correct entry produces positive points;

when the user indicates a missing entry in the access control list produces negative points; and

when an entry is unchanged by the user in the access control list produces a cumulative score over a time period time.

10 . The computer system of claim 7 , the method further comprising:

accessing data comprising user profiles, document content, file metadata, and access control lists;

generating numerical vectors from the user profiles, the document content, the file metadata, and the access control lists;

providing the numerical vectors for the user profiles, the document content, and the file metadata as an input embedding to the trained transformer model, and providing the numerical vectors for the access control lists as an output embedding to the trained transformer model, to produce output probabilities corresponding to generated access control lists; and

verifying the generated access control lists to train the trained transformer model.

11 . The computer system of claim 7 , wherein the content comprises text data.

12 . The computer system of claim 7 , wherein the access control list is a discretionary access control list (DACL).

13 . A non-transitory computer-readable medium storing computer-executable instructions that, when executed by at least one processor, perform a method of controlling access to electronic content, the method comprising:

generating, by a user, content in an electronic document;

retrieving a profile for the user;

determining, by a predictive engine, an access control list comprising a plurality of entries based on the content and the profile, wherein the predictive engine comprises a trained transformer model with inputs of a first numeric vector mapping the profile and the content and a second numeric vector token mapping a first pre-existing access control list; and

receiving a verification from the user of the plurality of entries in the access control list.

14 . The non-transitory computer-readable medium of claim 13 , wherein the trained transformer model is updated after the verification from the user.

15 . The non-transitory computer-readable medium of claim 13 , further wherein the method further comprises modifying the predictive engine based on the verification from the user, and wherein:

when the user indicates that an entry in the access control list is a wrong entry produces negative points;

when the user indicates that an entry in the access control list is a correct entry produces positive points;

when the user indicates a missing entry in the access control list produces negative points; and

when an entry is unchanged by the user in the access control list produces a cumulative score over a time period time.

16 . The non-transitory computer-readable medium of claim 13 , the method further comprising:

accessing data comprising user profiles, document content, file metadata, and access control lists;

generating numerical vectors from the user profiles, the document content, the file metadata, and the access control lists;

providing the numerical vectors for the user profiles, the document content, and the file metadata as an input embedding to the trained transformer model, and providing the numerical vectors for the access control lists as an output embedding to the trained transformer model, to produce output probabilities corresponding to generated access control lists; and

verifying the generated access control lists to train the trained transformer model.

17 . The non-transitory computer-readable medium of claim 13 , wherein the content comprises text data.

18 . The non-transitory computer-readable medium of claim 13 , wherein the access control list is a discretionary access control list (DACL).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2023
From: KISHAN, GOPI; JALAGADUGULA, ROHIT
To: SAP SE
Reel/Frame 065046/0155 →
Continuity (1)
Related Publication 20250103741A1 · Mar 27, 2025
References Cited (5)
US 20130239172A1 · Murakami · 2013 [cited by examiner]
US 20180285839A1 · Yang · 2018 [cited by examiner]
US 20200007554A1 · Vincent · 2020 [cited by examiner]
US 20220291855A1 · Hasegawa · 2022 [cited by examiner]
US 20240256582A1 · Jain · 2024 [cited by examiner]