IP Library Granted Patent US 11,030,332
Granted Patent B1
US 11,030,332 · App. 14/684,708 · Granted Jun 8, 2021

Database controlled web service type architecture

Inventor: Nicholas R. Gillis (West Des Moines, IA)
Assignee: Wells Fargo Bank, N.A.
G06F21/6218G06F16/25
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,030,332
App. No.
14/684,708
Granted
Jun 8, 2021
Kind
B1
Abstract

A first electronic computing device includes a processing unit and system memory. A first electronic database is installed on the first electronic computing device. The system memory includes instructions which, when executed by the processing unit, cause the first electronic database to receive a request from a second electronic computing device to access information stored on the first electronic database. A web services catalog that is part of the first electronic database is used to determine an access authorization level for the request. When a determination is made that the access authorization level is valid for the request, a security check is performed on a syntax of the access request. When a determination is made that the syntax is valid, the requested information is obtained from one or more tables in the first electronic database and the requested information is sent to the second electronic computing device.

Claims (43)

1. A first electronic computing device comprising:

a processing unit; and

system memory, a first electronic database installed on the first electronic computing device and stored in the system memory, the system memory including instructions which, when executed by the processing unit, cause the first electronic database to:

receive an access request from a second electronic computing device to access information stored on the first electronic database, the access request including a uniform resource locator having web procedure string parameters;

use a web services catalog that is part of the first electronic database to determine an access authorization level for the request; and

when a determination is made that the access authorization level is valid for the request:

perform a security check for malware in the uniform resource locator of the access request, including to check a syntax of a command in the web procedure string parameters of the uniform resource locator for conformance with a predetermined format;

when a determination is made that the syntax is valid:

obtain the requested information from one or more tables in the first electronic database; and

send the requested information to the second electronic computing device.

2. The first electronic computing device of claim 1 , further comprising:

send a request from the first electronic database to a second electronic database to access information stored on the second electronic database; and

receive the information from the second electronic database.

3. The first electronic computing device of claim 1 , wherein receive a request from the second electronic computing device to access information stored on the first electronic database comprises receiving a request from a web server computer to access information on the first electronic database.

4. The first electronic computing device of claim 1 , wherein receive a request from the second electronic computing device to access information stored on the first database comprises receiving a request from a client computer via a shared data file to access information on the first electronic database.

5. The first electronic computing device of claim 1 , wherein the accessing of information stored on the first electronic database is limited to one or more procedures stored on the first electronic database.

6. The first electronic computing device of claim 1 , wherein determine an access authorization level for the request comprises determining a role status for a user and a subset of database information that can be accessed by the user.

7. The first electronic computing device of claim 1 , wherein determine an access authorization level for the request comprises:

determine a time period during which the first electronic database can be accessed for a user having the access authorization level;

identify a current time period; and

determine whether the user can access the database during the current time period.

8. The first electronic computing device of claim 1 , wherein perform a security check on the access request comprises decoding a parameter string in the request to determine whether the request is in a proper format.

9. The first electronic computing device of claim 8 , wherein after a determination that the parameter string is in an incorrect format, returning a null output for the access request.

10. The first electronic computing device of claim 1 , further comprising logging each access request to either a guest user event log or to a user event log.

11. The first electronic computing device of claim 1 , further comprising tracking each access request and each result of each access request to an event tracking log.

12. The first electronic computing device of claim 1 , further comprising permitting the selection of an output format for the requested information, the selection being made from one of a plurality of formats, the plurality of formats including HTML and XML.

13. A first electronic computing device comprising:

a processing unit; and

system memory, a first electronic database installed on the first electronic computing device and stored in the system memory, the system memory including instructions which, when executed by the processing unit, cause the first electronic database to:

receive an access request from a second electronic computing device to access information stored on the first electronic database, the access request including a uniform resource locator having web procedure string parameters with at least one Structured Query Language command;

use a web services catalog that is part of the first electronic database to determine an access authorization level for the request, the determination of the access authorization level comprising:

determining an identity of a user making the request;

determining an authorization level for the user; and

determining a date and time for which the user is authorized to make the request;

when a determination is made that the access authorization level is valid for the request:

perform a security check that no unexpected characters are included in a command used in the uniform resource locator of the access request, including to check a syntax of the command in the web procedure string parameters of the uniform resource locator for conformance with a predetermined format;

when a determination is made that the syntax is valid:

obtain the requested information from one or more tables in the first electronic database; and

send the requested information to the second electronic computing device;

identify information to be requested from a second electronic database;

send a request for the identified information directly to the second electronic database; and

receive the identified information from the second electronic database; and

when a determination is made that the access authorization level is not valid for the request, send a null output to the second electronic computing device.

Assignments (2)
STATEMENT OF CHANGE OF ADDRESS OF ASSIGNEE Recorded Jun 17, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071649/0465 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2015
From: GILLIS, NICHOLAS R.
To: WELLS FARGO BANK, N.A.
Reel/Frame 037354/0105 →
Cited By (2)
US 12,340,131 US 12,632,831