IP Library Granted Patent US 12,632,557
Granted Patent B2
US 12,632,557 · App. 18/583,025 · Granted May 19, 2026

System and method for improving security of software development life cycles

Inventors: George Albero (Charlotte, NC); Naga Vamsi Krishna Akkapeddi (Charlotte, NC); Sanjay Lohar (Charlotte, NC); James J. Siekman (Charlotte, NC); Elijah Clark (Charlotte, NC)
Assignee: Bank of America Corporation
G06F21/57G06F8/77G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,557
App. No.
18/583,025
Granted
May 19, 2026
Kind
B2
Abstract

A method includes accessing a first set of instructions corresponding to a first instance of a software application and a second set of instructions corresponding to a second instance of the software application; and determining a first interaction context associated with the first instance of the software application and a second interaction context associated with the second instance of the software application. The method further includes accessing a set of security roles assigned during a development phase of the first instance of the software application and the second instance of the software application, executing a machine-learning model trained to identify whether a security roles is assigned to both the first interaction context and the second interaction context, and in response to identifying that the a security role is assigned to both the first interaction context and the second interaction context, generating a reassignment recommendation for reassigning the security role.

Claims (40)

1 . A system, comprising:

a memory configured to store a first set of instructions corresponding to a first instance of a software application, a second set of instructions corresponding to a second instance of the software application, a third set of instructions corresponding to a third instance of the software application, and a set of security roles assigned during one or more development phases of the first instance of the software application and the second instance of the software application; and

one or more processors operably coupled to the memory and configured to:

access the first set of instructions corresponding to the first instance of the software application and the second set of instructions corresponding to the second instance of the software application;

determine, based on the first set of instructions and the second set of instructions, a first interaction context associated with the first instance of the software application and a second interaction context associated with the second instance of the software application;

access the set of security roles assigned during one or more development phases of the first instance of the software application and the second instance of the software application;

train a machine-learning model based on the third set of instructions corresponding to the third instance of the software application, one or more usage metrics associated with the third instance of the software application, and a set of security roles assigned during one or more development phases of the third instance of the software application;

execute the trained machine-learning model to identify whether one or more security roles of the assigned set of security roles is assigned to both the first interaction context associated with the first instance of the software application and the second interaction context associated with the second instance of the software application; and

in response to identifying that the one or more security roles are assigned to both the first interaction context and the second interaction context, generate a reassignment recommendation for reassigning the one or more security roles.

2 . The system of claim 1 , wherein the one or more processors are further configured to generate the reassignment recommendation for reassigning the one or more security roles by assigning a new security role to one of the first interaction context or the second interaction context.

3 . The system of claim 2 , wherein the one or more processors are further configured to assign the new security role to one of the first interaction context or the second interaction context by calling an application programming interface (API) associated with a security domain service.

4 . The system of claim 1 , wherein the first instance of the software application comprises an executing instance of the software application, and wherein the second instance of the software application comprises an in-development instance of the software application.

5 . The system of claim 1 , wherein the one or more processors are further configured to execute the machine-learning model to identify whether the one or more security roles are assigned to both the first interaction context and the second interaction context based on the first set of instructions, the second set of instructions, and one or more usage metrics associated with the first instance of the software application and the second instance of the software application.

6 . The system of claim 1 , wherein the machine-learning model comprises one or more sequence-to-sequence (Seq2Seq) models, one or more encoder-decoder sequence models, or one or more transformer models.

7 . The system of claim 1 , wherein the first interaction context or the second interaction context comprises one or more of a national interaction context, a jurisdictional interaction context, a provincial interaction context, a regulatory interaction context, a security requirements interaction context, a currency exchange interaction context, or a market interaction context.

8 . A method, comprising:

accessing a first set of instructions corresponding to a first instance of a software application and a second set of instructions corresponding to a second instance of the software application;

determining, based on the first set of instructions and the second set of instructions, a first interaction context associated with the first instance of the software application and a second interaction context associated with the second instance of the software application;

accessing a set of security roles assigned during one or more development phases of the first instance of the software application and the second instance of the software application;

training a machine-learning model based on a third set of instructions corresponding to a third instance of the software application, one or more usage metrics associated with the third instance of the software application, and a set of security roles assigned during one or more development phases of the third instance of the software application;

executing the trained machine-learning model to identify whether one or more security roles of the assigned set of security roles is assigned to both the first interaction context associated with the first instance of the software application and the second interaction context associated with the second instance of the software application; and

in response to identifying that the one or more security roles are assigned to both the first interaction context and the second interaction context, generating a reassignment recommendation for reassigning the one or more security roles.

9 . The method of claim 8 , wherein generating the reassignment recommendation for reassigning the one or more security roles further comprises assigning a new security role to one of the first interaction context or the second interaction context.

10 . The method of claim 9 , wherein assigning the new security role to one of the first interaction context or the second interaction context further comprises calling an application programming interface (API) associated with a security domain service.

11 . The method of claim 8 , wherein the first instance of the software application comprises an executing instance of the software application, and wherein the second instance of the software application comprises an in-development instance of the software application.

12 . The method of claim 8 , wherein executing the machine-learning model further comprises identifying whether the one or more security roles are assigned to both the first interaction context and the second interaction context based on the first set of instructions, the second set of instructions, and one or more usage metrics associated with the first instance of the software application and the second instance of the software application.

13 . The method of claim 8 , wherein the machine-learning model comprises one or more sequence-to-sequence (Seq2Seq) models, one or more encoder-decoder sequence models, or one or more transformer models.

14 . The method of claim 8 , wherein the first interaction context or the second interaction context comprises one or more of a national interaction context, a jurisdictional interaction context, a provincial interaction context, a regulatory interaction context, a security requirements interaction context, a currency exchange interaction context, or a market interaction context.

15 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a system, cause the one or more processors to:

access a first set of instructions corresponding to a first instance of a software application and a second set of instructions corresponding to a second instance of the software application;

determine, based on the first set of instructions and the second set of instructions, a first interaction context associated with the first instance of the software application and a second interaction context associated with the second instance of the software application;

access a set of security roles assigned during one or more development phases of the first instance of the software application and the second instance of the software application;

train a machine-learning model based on a third set of instructions corresponding to a third instance of the software application, one or more usage metrics associated with the third instance of the software application, and a set of security roles assigned during one or more development phases of the third instance of the software application;

execute the trained machine-learning model trained to identify whether one or more security roles of the assigned set of security roles is assigned to both the first interaction context associated with the first instance of the software application and the second interaction context associated with the second instance of the software application; and

in response to identifying that the one or more security roles are assigned to both the first interaction context and the second interaction context, generate a reassignment recommendation for reassigning the one or more security roles.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the one or more processors to generate the reassignment recommendation for reassigning the one or more security roles by assigning a new security role to one of the first interaction context or the second interaction context.

17 . The non-transitory computer-readable medium of claim 16 , wherein the instructions further cause the one or more processors to assign the new security role to one of the first interaction context or the second interaction context by calling an application programming interface (API) associated with a security domain service.

18 . The non-transitory computer-readable medium of claim 15 , wherein the first instance of the software application comprises an executing instance of the software application, and wherein the second instance of the software application comprises an in-development instance of the software application.

19 . The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the one or more processors to execute the machine-learning model to identify whether the one or more security roles are assigned to both the first interaction context and the second interaction context based on the first set of instructions, the second set of instructions, and one or more usage metrics associated with the first instance of the software application and the second instance of the software application.

20 . The non-transitory computer-readable medium of claim 15 , wherein the first interaction context or the second interaction context comprises one or more of a national interaction context, a jurisdictional interaction context, a provincial interaction context, a regulatory interaction context, a security requirements interaction context, a currency exchange interaction context, or a market interaction context.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2024
From: ALBERO, GEORGE; AKKAPEDDI, NAGA VAMSI KRISHNA; LOHAR, SANJAY; SIEKMAN, JAMES J.; CLARK, ELIJAH
To: BANK OF AMERICA CORPORATION
Reel/Frame 066513/0442 →
Continuity (1)
Related Publication 20250265338A1 · Aug 21, 2025
References Cited (25)
US 7725891B2 · Demuth et al. · 2010 [cited by applicant]
US 8091065B2 · Mir et al. · 2012 [cited by applicant]
US 8645843B2 · Chee et al. · 2014 [cited by applicant]
US 9383984B2 · Mantripragada et al. · 2016 [cited by applicant]
US 10411975B2 · Martinez et al. · 2019 [cited by applicant]
US 10454938B2 · Anderson et al. · 2019 [cited by applicant]
US 10740469B2 · Zheng · 2020 [cited by applicant]
US 10848498B2 · Childress et al. · 2020 [cited by applicant]
US 10880189B2 · Martinez et al. · 2020 [cited by applicant]
US 11379219B2 · Bhalla et al. · 2022 [cited by applicant]
US 11853430B2 · Bhalla et al. · 2023 [cited by applicant]
US 12141291B1 · Rappaport · 2024 [cited by examiner]
US 20080216056A1 · Bate et al. · 2008 [cited by applicant]
US 20120117531A1 · Rosenbaum et al. · 2012 [cited by applicant]
US 20170177860A1 · Suarez · 2017 [cited by examiner]
US 20190303541A1 · Reddy et al. · 2019 [cited by applicant]
US 20190303579A1 · Reddy et al. · 2019 [cited by applicant]
US 20190303623A1 · Reddy et al. · 2019 [cited by applicant]
US 20190305957A1 · Reddy et al. · 2019 [cited by applicant]
US 20190305959A1 · Reddy et al. · 2019 [cited by applicant]
US 20190306173A1 · Reddy et al. · 2019 [cited by applicant]
US 20200117434A1 · Biskup · 2020 [cited by examiner]
US 20210014275A1 · Martinez et al. · 2021 [cited by applicant]
US 20220171857A1 · McHugh · 2022 [cited by examiner]
US 20250244965A1 · Bar · 2025 [cited by examiner]