MUMBAI, India, Sept. 28 -- Intellectual Property India has published a patent application (202611099213 A) filed by Mr. Perumalsamy Devaraj on August 17, 2026, for Ai-Based Adaptive Zero-Trust Access Control System For Dynamic Enterprise Resource Protection.
Inventor includes Mr. Perumalsamy Devaraj.
The application for the patent was published on September 25, 2026, under issue no. 39/2026.
Abstract: The present invention concerns a system and method for granting access to resources. In particular, the present invention relates to ensuring the security of enterprise resources against threats from unauthorized external and internal sources. The present invention is based upon an adaptive zero-trust access control paradigm which is driven by artificial intelligence. This paradigm provides for enhanced levels of assurance, permissions, and protections for accessing enterprise resources while taking into account the dynamic nature of the environment from which such access is being requested. Artificial intelligence is utilized to analyze a combination of the requesting entity's properties and attributes, contextual parameters relating to the requested access, a resource to which access is being requested, and patterns of behavior in an attempt to identify and score potential threats and then modifying levels of assurance, permissions, and protections granted in accordance with these scores. The overall system includes a plurality of decision nodes which are utilized to make decisions in accordance with one or more policies. Policies may be manually entered or defined or may be derived from artificial intelligence models which utilize training data to identify patterns which are indicative of threats. Policies may also include decision logic which is utilized to make tradeoffs between different levels of protection based on risk analysis performed by artificial intelligence while taking into account various other factors. The policies may also be utilized to dynamically adjust a level of security in response to different combinations of simultaneously occurring activities. Additionally or alternatively, policies may be utilized to dynamically restrict or allow activities based on a set of dynamically adjusted weighted objectives, including without limitation factors associated with each of the activities simultaneously occurring. Enterprise resource protection is utilized in accordance with the system and method of the present invention, including without limitation, data resources, computer hardware and computer software accessible by a network. This protection extends to ensuring the security of such resources, including without limitation, protecting those resources from unauthorized access or exploitation while providing assurance and protections commensurate with a dynamically adjusted level of security. Access to resources is granted, denied, permitted or restricted in accordance with policies. After access to a resource is granted, a monitoring process is utilized to observe the activity being performed, to include command sequences, data being accessed transferred or utilized, and any other relevant topological information concerning the entity accessing, the resource being accessed or the manner in which the accessing entity and the accessed resource are related. One or more artificial intelligence models may be utilized to analyze observed behavior in comparison to established norms and may respond by initiating additional testing, by restricting or denying access to particular resources and/or by taking other responsive action. Additionally, when a resource is dynamic, such as a computer server or virtual machine which is allocated and de-allocated on an ongoing basis or a repository of data which is continually created, organized, accessed, stored and archived, the system and method of the present invention provide for a continuous updated inventory of resources with sensitivity levels assigned thereto. This sensitivity level assignment may be performed in accordance with artificial intelligence models which assess the contents and organization of data and the value of such data. The system and method of the present invention are implemented utilizing a combination of one or more collection agent nodes, one or more analytics core nodes, and one or more policy enforcement nodes. Communication may occur securely and may be encrypted or otherwise secured between nodes. Artificial intelligence models may run on analytics core nodes or on other nodes such as collection agents, policy enforcement nodes, and/or other computing devices. Training data may be collected utilizing a combination of techniques, including without limitation, data which originates from one or more collection agents, analytics core nodes, policy enforcement nodes, or other nodes. Communication between nodes may be encrypted or otherwise secured. Artificial intelligence models may run on analytics core nodes, collection agent nodes, policy enforcement nodes, or other computing devices, and may be updated periodically, including without limitation, utilizing training data which is collected from various sources, including without limitation, the aforementioned nodes or agents. A significant benefit of the system and method of the present invention is the ability to provide for context-aware access control decisioning. Access requests, denials, restrictions, permissions, or other actions which are taken in accordance with the system and method of the present invention, consider and evaluate a variety of contextual parameters. In particular, a number of factors which may occur simultaneously or which may be relevant to the accessing entity, the accessed resource and other factors relevant to the context of the request, such as temporal, relational, and environmental factors, are considered and evaluated by artificial intelligence which is utilized to make decisions in accordance with the system and method of the present invention. A significant benefit of the system and method of the present invention is the ability to protect enterprise resources, including without limitation, data, computer hardware, and computer software accessible via computer networks. The system and method of the present invention ensure the security of such enterprise resources, including without limitation, protecting those resources from unauthorized access or exploitation while providing assurance and protections commensurate with a dynamically adjusted level of security. Additionally, the system and method of the present invention are utilized to make a determination concerning whether an access request should be allowed or denied, or whether a particular activity, operation, or other action should be permitted or restricted, taking into account a number of factors and utilizing artificial intelligence to identify patterns which may indicate threats or other issues. In accordance with the system and method of the present invention, once an access request is received, observation is performed to collect relevant telemetry data, including without limitation, data originating from the accessing entity, accessed resource, and other relevant data concerning the context of the request. Observations of entities may include without limitation, monitoring network traffic which utilizes the entity as either a source or destination, analyzing computer network packets which originate from or are directed to the entity, monitoring and analyzing behavior of the entity, analyzing any computer software applications, processes, or programs utilized by the entity, and any other relevant activity or behavior of the entity. Observation of a computer resource may include without limitation, monitoring the resource's utilization, analyzing computer network packets which originate from or are directed to the resource, monitoring and analyzing behavior of the resource, analyzing any computer hardware or software components associated with the resource, and any other relevant activity or behavior of the resource. Once observation data has been collected, assessment is performed to analyze the data utilizing artificial intelligence, including without limitation, determining a potential threat score or determining other potential issues. Once an assessment has been made, a decision is taken concerning what actions, if any, should be performed in accordance with policies. Such decisions may include without limitation, denying an access request, permitting an access request, restricting an access request, denying an activity or operation request, permitting an activity or operation request, restricting an activity or operation request, or taking other responsive action. After a decision has been taken, enforcement is performed to implement responsive actions, including without limitation, denying an access request, permitting an access request, restricting an access request, denying an activity or operation request, permitting an activity or operation request, restricting an activity or operation request, or taking other responsive action. In accordance with the system and method of the present invention, data concerning the enforcement of decisions is utilized to support further learning which may contribute to future decisions. In particular, data concerning successful requests, denied requests, denied activities, permitted activities, restricted activities, and other relevant information concerning enforcement may be utilized in accordance with the present invention. The system and method of the present invention are particularly beneficial when utilized to protect enterprise data and resources in accordance with an adaptive zero-trust access control paradigm, which provides for enhanced levels of assurance, permissions, and protections for accessing enterprise resources while taking into account the dynamic nature of the environment from which such access is being requested. The system and method of the present invention provide for an increased level of protection when compared to conventional approaches which may utilize static rules to make access control decisions. The system and method of the present invention, utilizing artificial intelligence, enables a greater degree of flexibility and responsiveness while still providing enhanced levels of security and protection when compared to systems and methods which utilize only manual processes to define and modify rules to make access control decisions. Additionally, the system and method of the present invention provide for audit trail information and explanations concerning decisions taken in accordance with the system and method of the present invention, thus enabling a greater degree of compliance and facilitating decision-making by humans reviewing such decisions and/or supporting information. The system and method of the present invention provide for greater ease of use, including without limitation, reduced false positives and reduced disruptions to legitimate activity. While the present invention has been described above in detail with reference to a preferred embodiment thereof, it will be understood by those skilled in the art, that numerous variations and modifications of the invention may be made without departing from the inventive concept. For example, the system and method of the present invention may be employed to secure other types of resources or data in addition to those specifically described above. The system and method of the present invention may be utilized with other systems, including without limitation, identity providers, analytics systems, and other orchestration systems, to provide for enhanced levels of security. The system and method of the present invention may also be applied to systems and environments which may not be fully integrated or which may otherwise have limitations or shortcomings. In addition, the system and method of the present invention may be configured to utilize a wide range of artificial intelligence techniques, including without limitation, supervised learning, unsupervised learning, reinforcement learning or other techniques or combinations thereof, and may employ such techniques in a number of ways and in combination with various other aspects of the present invention. Many such variations and modifications may be made to the embodiments of the invention described above without departing from the inventive concept. It will therefore be understood that the scope of the present invention is not to be limited to the specific details disclosed herein, but is intended to embrace all such variations and modifications which fall within the scope of the claims and equivalents thereof.
Disclaimer: Curated by HT Syndication.