IP Library Granted Patent US 10,692,138
Granted Patent B1
US 10,692,138 · App. 15/337,879 · Granted Jun 23, 2020

Secure data exchange

Inventors: Traci Nguyen (San Francisco, CA); Lila Fakhraie (Belmont, CA); Anthony Burton (Charlotte, NC); Alyce F. Thornton (Discovery Bay, CA); Ravi Thota (San Francisco, CA); Meghan E. Butler (Lakeville, MN)
Assignee: Wells Fargo Bank, N.A.
G06Q40/02H04L63/083H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,692,138
App. No.
15/337,879
Granted
Jun 23, 2020
Kind
B1
Abstract

In an example, a computer-implemented method includes determining a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with a user and held by a financial institution, and generating authorization data that authenticates the third-party and authorizes the third-party to access the types of account data specified by the set of permissions. The method also includes transmitting the authorization data to the third-party, receiving a request for authorization that includes the authorization data and a request for account data of the one or more financial accounts that conforms to the types of account data specified by the set of permissions, authorizing the third-party based on the authorization data, and transmitting the account data that conforms to the types of account data specified by the set of permissions.

Claims (64)

1. A method comprising:

initiating, by a computing device, a secure session that allows a user to provide user authentication data;

authenticating, by the computing device, the user based on the user authentication data;

receiving, by the computing device and from the user, permissions data that indicates a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with the user and held by a financial institution;

determining, by the computing device, the set of permissions from the permissions data;

generating, by the computing device, authorization data that authenticates the third-party and authorizes the third-party to access the types of account data specified by the set of permissions, wherein the authorization data includes one or more access tokens that indicate authorization of the third-party to access the types of account data specified by the set of permissions;

receiving, by the computing device, a request from the third-party for the authorization transmitting, by the computing device and in response to receiving the request for the authorization data, the authorization data to the third-party;

receiving, by the computing device, from the third-party, and after transmitting the authorization data, a request for authorization, wherein the request for authorization includes the one or more access tokens and a request for account data of the one or more financial accounts that conforms to the types of account data specified by the set of permissions;

authorizing, by the computing device, the third-party based on the authorization data in response to receiving the request for authorization from the third-party; and

transmitting, by the computing device and to the third-party, the account data that conforms to the types of account data specified by the set of permissions in response to authorizing the third-party.

2. The method of claim 1 , wherein receiving the permissions data that indicates the set of permissions comprises receiving the permissions data in response to selection of user-selectable user interface elements that indicate the types of account data.

3. The method of claim 1 , wherein the types of account data comprise types of accounts, such that determining the set of permissions comprises determining the types of accounts of the one or more financial accounts for which financial account data is to be shared.

4. The method of claim 3 , wherein the types of accounts comprise at least one of a checking account, a savings account, a brokerage account, a mortgage account, or a credit card account.

5. The method of claim 1 , wherein the types of account data comprises balance level data or transaction level data, such that determining the set of permissions comprises determining whether balance level data or transaction level data of the one or more financial accounts is to be shared.

6. The method of claim 1 , wherein the set of permissions specifies a first type of account data for a first account of the one or more financial accounts and a second type of account data for a second account of the one or more financial accounts.

7. The method of claim 1 , wherein generating the authorization data comprises generating an access token for the third-party, and wherein authorizing the third-party based on the authorization data comprises authorizing the third-party based on the access token.

8. The method of claim 1 , further comprising:

storing the determined set of permissions; and

wherein authorizing the third-party based on the authorization data comprises comparing the authorization data to the stored set of permissions.

9. The method of claim 1 , further comprising:

determining an approved provider list that includes the third-party;

receiving a request for second authorization data from a second third-party that is not included on the approved provider list; and

denying the request for the second authorization data.

10. The method of claim 1 , further comprising:

receiving, from the third-party, a request to access a second type of account data that does not conform to the types of account data specified by the set of permissions;

determining that the second type of account data does not conform to the types of account data specified by the set of permissions; and

blocking the request to access the second type of account data.

11. The method of claim 1 , further comprising:

receiving a request from a second third-party to access account data of the one or more financial accounts of the user;

determining that the second third-party is not authorized to access the account data; and

in response to determining that the second third-party is not authorized to access the account data, blocking the request to access the account data based on the request.

12. The method of claim 11 , wherein blocking the request comprises blocking the request based on at least one of deterministic policies and heuristic policies.

13. The method of claim 12 , wherein the deterministic policies comprise at least one of an IP address policy, a user agent string policy, or an automated script policy.

14. The method of claim 12 , wherein the heuristic policies comprise at least one of a behavioral policy or a telemetric policy.

15. The method of claim 1 , further comprising:

receiving a request to access account data of the user from a party other than the third-party;

identifying a breach of one or more blocking policies based on the request;

providing access to the party other than the third-party to the account data; and

monitoring the party other than the third-party based on the breach of the one or more blocking policies.

16. The method of claim 1 , further comprising performing, by the computing device and prior to transmitting the authorization data to the third-party, a challenge to verify the request from the third-party, wherein the challenge is based on blocking policies.

17. The method of claim 1 , wherein the request for authorization does not include the user authentication data.

18. The method of claim 1 , wherein the user is directed to the secure session by the third-party.

19. An apparatus comprising:

a memory configured to store a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with a user and held by a financial institution; and

one or more processors configured to:

initiate a secure session that allows a user to provide user authentication data;

authenticate the user based on the user authentication data;

receive, from the user, permissions data that indicates the set of permissions;

determine the set of permissions from the permissions data;

generate authorization data that authenticates the third-party and authorizes the third-party to access the types of account data specified by the set of permissions, wherein the authorization data includes one or more access tokens that indicate authorization of the third-party to access the types of account data specified by the set of permissions;

transmit, in response to receiving a request from the third-party for the authorization data, the authorization data to the third-party;

receive, from the third-party and after transmitting the authorization data, a request for authorization, wherein the request for authorization includes the one or more access tokens and a request for account data of the one or more financial accounts that conforms to the types of account data specified by the set of permissions;

authorize the third-party based on the authorization data in response to receiving the request for authorization from the third-party; and

transmit, to the third-party, the account data that conforms to the types of account data specified by the set of permissions in response to authorizing the third-party.

20. A non-transitory computer-readable medium having instructions stored thereon that, when executed, cause one or more processors to:

initiate a secure session that allows a user to provide user authentication data;

authenticate the user based on the user authentication data;

receive, from the user, permissions data that indicates a set of permissions that specifies types of account data of one or more financial accounts of the user to share with a third-party;

determine set of permissions from the permissions data;

generate authorization data that authenticates the third-party and authorizes the third-party to access the types of account data specified by the set of permissions, wherein the authorization data includes one or more access tokens that indicate authorization of the third-party to access the types of account data specified by the set of permissions;

transmit, in response to receiving a request from the third-party for the authorization data, the authorization data to the third-party;

receive, from the third-party and after transmitting the authorization data, a request for authorization, wherein the request for authorization includes the one or more access tokens and a request for account data of the one or more financial accounts that conforms to the types of account data specified by the set of permissions;

authorize the third-party based on the authorization data in response to receiving the request for authorization from the third-party; and

transmit, to the third-party, the account data that conforms to the types of account data specified by the set of permissions in response to authorizing the third-party.

Assignments (4)
REQUEST FOR ADDRESS CHANGE Recorded Apr 16, 2026
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 075424/0021 →
REQUEST FOR ADDRESS CHANGE Recorded Dec 4, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 074387/0936 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2019
From: BUTLER, MEGHAN
To: WELLS FARGO BANK, N.A.
Reel/Frame 049315/0192 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2018
From: NGUYEN, TRACI; FAKHRAIE, LILA; BURTON, ANTHONY; THORNTON, ALYCE F.; THOTA, RAVI
To: WELLS FARGO BANK, N.A.
Reel/Frame 045324/0173 →
Continuity (1)
Provisional Application 62247653 · Oct 28, 2015
Cited By (12)
US 12,205,082 US 12,301,575 US 12,307,424 US 12,341,833 US 12,379,837 US 12,423,454 US 12,423,455 US 12,443,987 US 12,563,035 US 12,694,143 US 12,699,975 US 12,717,952