Automatic user group manager

US12244602B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12244602-B2
Application numberUS-202217804832-A
CountryUS
Kind codeB2
Filing dateMay 31, 2022
Priority dateMay 31, 2022
Publication dateMar 4, 2025
Grant dateMar 4, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system of automatically managing assignments of users to user groups comprisesa processor to implement instructions for an automatic user group manage (AUGM) to access to two or more users and the assignments of the users to the user groups, observe activity of the users, calculate user behavior signatures for one of at least two users of the users, at least one user of the users and one group of the user groups, or at least two groups of the user groups, calculate a numeric degree of variance between at least two of the user behavior signatures, compare the calculated degree of variance to at least one threshold, and determine if a behavior of one of the at least two users, the at least one user and the one group, or the at least two groups are similar or different.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for automatically assigning users of a computer system to user groups by reference to a data collection of information about previously classified activities of a plurality of grouped users of the computer system, the method comprising: monitoring activity of a first user of the computer system; creating and storing a first user activity log for the monitored first user from the monitored first user activity; calculating a user behavior signature of monitored first user activity as a new behavior vector of values representing events related to the monitored activity; calculating a degree of variance (DoV) of the monitored first user activity from a behavior signature of the previously classified activities, wherein the behavior signature of the previously classified activities is a previous behavior vector of values representing events related to the previously classified activity, and the DoV is the distance between the new behavior vector and the previous behavior vector; comparing the (DoV) to a predetermined threshold; when the calculated DoV is less than or equal the predetermined threshold, determining that the first user will be assigned to a group with the previously grouped users associated with the behavior signature of the previously classified activities; when the calculated DoV is greater than the predetermined threshold, determining that the first user will not be assigned in the same group with the previously grouped users associated with the behavior signature of the previously classified activities; identifying the first user with the data collection of information about previously classified activities of a plurality of grouped users of the computer system; and sending an indication to a destination in the computer system about the determination of group assignment for the first user. 2. The method of claim 1 , wherein the monitored activity of the first user comprises actions of applications related to the first user applications running on behalf of the first user, when the first user is logged in and logged off, or a resource of the computer system shared by the first user. 3. The method of claim 1 , wherein the monitored activity of the first user comprises a beginning, an end, a frequency, or a duration of an event related to the first user. 4. The method of claim 1 , wherein the monitored activity of the first user comprises a first user authentication event including timing Internet Protocol based geolocation or device-based geolocation. 5. The method of claim 1 , wherein the monitored activity of the first user comprises the first user's access to the first user's computer, the first user's mobile device, or a hardware device associated with the first user. 6. The method of claim 1 , wherein the monitored activity of the first user comprises activity in a web browser or other software accessing cloud services including file storage, online collaboration, electronic mail, scheduling, file sharing,or social networks. 7. The method of claim 1 , wherein the monitored activity of the first user comprises first user network traffic including Internet Protocol addresses, port numbers, protocol types, volumes of data sent and received, and types of information sent and received. 8. The method of claim 1 , further comprising analyzing a behavior vector of the first user for similarity and dissimilarity using pre-programmed heuristic rules, statistical analysis, a neural network, or support vector machines. 9. The method of claim 1 , further comprising-analyzing a behavior vector of the first user to determine whether to add or remove the first user to or from at least one user group of the computer system. 10. The method of claim 1 , comprising adding the first user to or removing the first user from a group of the user groups and communicating the addition or removal of the first user to at least one destination in the computer system. 11. In a computer network, a system for monitoring and automatically managing assignments of users to user groups, the system comprising: a data collection of information about previously classified activities of a plurality of grouped users of the computer network; a microprocessor coupled to a memory, the processor being configured to: monitor an activitiy of a first user of the computer network; create and store a user activity log for the monitored first user from the monitored first user activity; calculate a first user behavior signature of monitored user activity as a new behavior vector of values representing events related to the monitored activity calculate a degree of variance (DoV) of the monitored activity from a behavior signature of the previously classified activities, wherein the behavior signature of the previously classified activities is a previous behavior vector of values representing events related to the previously classified activity, and the DoV is the distance between the new behavior vector and the previous behavior vector; compare the DoV to a predetermined threshold; when the calculated DoV is less than or equal the predetermined threshold, determine that the first user belongs in a group with the previously grouped user associated with the behavior signature of the previously classified activities; when the calculated DoV is greater than the predetermined threshold, determine that the first user does not belong in the same group with the previously grouped user associated with the behavior signature of the previously classified activities; identify the first user with the data collection of information about previously classified activities of a plurality of grouped users of the computer network; and send an indication to a destination in the computer network about the determination has been identified for the first user. 12. The system of claim 11 , wherein the microprocessor is further configured to create and store values for: actions of, applications running on behalf of the first user, when the first user is logged in and logged off, or a resource of the computer network shared by the first user. 13. The system of claim 11 , wherein the microprocessor is further configured to create and store values for an activity of the first user comprising a beginning, end, frequency, or duration of an event related to a resource of the computer network and the first user. 14. The system of claim 11 , wherein the microprocessor is further configured to create and store values for activity of the first user including first user authentication events including timing, Internet Protocol based geolocation, or device-based geolocation. 15. The system of claim 11 , wherein the microprocessor is further configured to create and store values for activity of the first user including the first user's access to the first user's computer, the first user's mobile device, or a hardware device associated with the first user. 16. The system of claim 11 , wherein the microprocessor is further configured to create and store values for activity of the first user including activity in a web browser or other software accessing cloud services including file storage, online collaboration, electronic mail, scheduling, file sharing, or social networks. 17. The system of claim 11 , wherein the microprocessor is further configured to create and store values for the activity of the first user including first user network traffic comprising one or more of Internet Protocol addresses, port numbers, protocol types, volumes of data sent and received, and types of information sent and

Assignees

Inventors

Classifications

  • Entity profiles · CPC title

  • wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • H04L63/104Primary

    Grouping of entities · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12244602B2 cover?
A system of automatically managing assignments of users to user groups comprisesa processor to implement instructions for an automatic user group manage (AUGM) to access to two or more users and the assignments of the users to the user groups, observe activity of the users, calculate user behavior signatures for one of at least two users of the users, at least one user of the users and one grou…
Who is the assignee on this patent?
Acronis Int Gmbh
What technology area does this patent fall under?
Primary CPC classification H04L63/104. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 04 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).