IP Library Granted Patent US 11,386,223
Granted Patent B1
US 11,386,223 · App. 16/204,831 · Granted Jul 12, 2022

Access control tower

Inventors: Lila Fakhraie (Belmont, CA); Brian M. Pearce (Pleasanton, CA); Steven Pulido (San Francisco, CA); Benjamin Soccorsy (Larkspur, CA); James Stahley (San Francisco, CA); Mojdeh Tomsich (San Francisco, CA)
Assignee: WELLS FARGO BANK, N.A.
G06F21/6245H04L63/10G06F16/215G06F21/6263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,386,223
App. No.
16/204,831
Granted
Jul 12, 2022
Kind
B1
Abstract

Systems, methods, and apparatuses for providing a customer a central location to manage permissions provided to third-parties and devices to access and use customer information maintained by a financial institution are described. The central location serves as a central portal where a customer of the financial institution can manage all access to account information and personal information stored at the financial institution. Accordingly, the customer does not need to log into each individual third-party system or customer device to manage previously provided access to the customer information or to provision new access to the customer information. A user additionally is able to have user data and/or third-party accounts of the user deleted from devices, applications, and third-party systems via a central portal.

Claims (57)

1. A method comprising:

receiving, by a service provider computing system, a first application programming interface (API) call via a first API between the service provider computing system and a third-party computing system, the first API call specifying customer information of a customer;

in response to receiving the first API call from the third-party computing system, transmitting, by the service provider computing system, to the third-party computing system via the first API, the customer information specified in the first API call;

presenting, by the service provider computing system, via a graphical user interface of a service provider client application running on a computing device of the customer:

a third-party account that is linked to the service provider computing system, the third-party account with the customer information, the third-party account being stored in a database of the third-party computing system, wherein the customer information is accessible to the third-party computing system; and

a toggle corresponding to the third-party account, wherein the toggle visually indicates that the customer can specify to delete the customer information stored in the database of the third-party computing system;

detecting, by the service provider computing system, via the service provider client application running on the computing device of the customer, selection of the toggle;

in response to detecting the selection of the toggle, generating, by the service provider computing system, a scrub command identifying the third-party account of the customer to be deleted from the database of the third-party computing system;

transmitting, by the service provider computing system, the scrub command in a second API call to the third-party computing system via the first API or a second API to cause the third-party computing system to delete, from the database of the third-party computing system, the third-party account with the customer information that is specified in the first API call and that was stored in the database of the third-party computing system; and

presenting, by the service provider computing system, via the graphical user interface of the service provider client application running on the computing device of the customer, a status indicator indicating that the third-party account was deleted.

2. The method of claim 1 , wherein the toggle is a first toggle, wherein the selection is a first selection, wherein the scrub command is a first scrub command, wherein the status indicator is a first status indicator, and further comprising:

presenting, by the service provider computing system, via the graphical user interface, a second toggle corresponding to the third-party account, wherein the second toggle visually indicates that the customer can select to delete a specified type of third-party accounts with the customer information of the customer stored in the database of the third-party computing system;

detecting, by the service provider computing system, via the service provider client application running on the computing device of the customer, a second selection of the second toggle to delete the specified type of the third-party accounts with the customer information of the customer stored in the database of the third-party computing system;

in response to detecting the second selection via the graphical user interface presented by the service provider client application to delete the specified type of the third-party accounts with the customer information of the customer stored in the database of the third-party computing system, generating, by the service provider computing system, a second scrub command identifying the specified type of the third-party accounts with the customer information of the customer to be deleted from the database of the third-party computing system;

transmitting, by the service provider computing system, the second scrub command in a third API call to the third-party computing system via the first API or the second API to cause the third-party computing system to delete, from the database of the third-party computing system, the specified type of the third-party accounts with the customer information that is specified in the first API call and that was stored in the database of the third-party computing system; and

presenting, by the service provider computing system, via the graphical user interface of the service provider client application running on the computing device of the customer, a second status indicator indicating that the specified type of the third-party accounts were deleted.

3. The method of claim 1 , further comprising allowing the customer, via the service provider client application, to place restrictions on what customer information is accessible to the third-party computing system.

4. The method of claim 1 , further comprising allowing the customer, via the service provider client application, to place restrictions on how the accessible customer information may be used by the third-party computing system.

5. The method of claim 1 , further comprising transmitting, by the service provider computing system, to the computing device of the customer, for presentation via the service provider client application running on the computing device, status information indicating whether the link is active or inactive.

6. The method of claim 1 , wherein the scrub command instructs the third-party computing system to delete all the customer information stored at the third-party computing system.

7. A service provider computing system having a processor and memory with instructions which, when executed by the processor, cause the service provider computing system to:

receive a first application programming interface (API) call via a first API between the service provider computing system and a third-party computing system, the first API call specifying customer information of a customer;

in response to receiving the first API call from the third-party computing system, transmit, to the third-party computing system via the first API, the customer information specified in the first API call;

present, via a graphical user interface of a service provider client application running on a computing device of the customer:

a third-party account that is linked to the service provider computing system, the third-party account with the customer information, the third-party account being stored in a database of the third-party computing system, wherein the customer information is accessible to the third-party computing system; and

a toggle corresponding to the third-party account, wherein the toggle visually indicates that the customer can specify to delete the customer information stored in the database of the third-party computing system;

detect, via the service provider client application running on the computing device of the customer, selection of the toggle;

in response to detecting the selection of the toggle, generate a scrub command identifying the third-party account of the customer to be deleted;

transmit the scrub command in a second API call to the third-party computing system via the first API or a second API to cause the third-party computing system to delete, from the database of the third-party computing system, the third-party account with the customer information that is specified in the first API call and that was stored in the database of the third-party computing system; and

present, via the graphical user interface of the service provider client application running on the computing device of the customer, a status indicator indicating that the third-party account was deleted.

8. The service provider computing system of claim 7 , wherein the toggle is a first toggle, wherein the selection is a first selection, wherein the scrub command is a first scrub command, wherein the status indicator is a first status indicator, and wherein the instructions further cause the service provider computing system to:

present, via the graphical user interface, a second toggle corresponding to the third-party account, wherein the second toggle visually indicates that the customer can select to delete a specified type of third-party accounts with the customer information of the customer stored in the database of the third-party computing system;

detect, via the service provider client application running on the computing device of the customer, a second selection of the second toggle to delete the specified type of the third-party accounts with the customer information of the customer stored in the database of the third-party computing system;

in response to detecting the second selection via the graphical user interface presented by the service provider client application to delete the specified type of the third-party accounts with the customer information of the customer stored in the database of the third-party computing system, generate, a second scrub command identifying the specified type of the third-party accounts with the customer information of the customer to be deleted from the database of the third-party computing system;

transmit, the second scrub command in a third API call to the third-party computing system via the first API or the second API to cause the third-party computing system to delete, from the database of the third-party computing system, the specified type of the third-party accounts with the customer information that is specified in the first API call and that was stored in the database of the third-party computing system; and

present, via the graphical user interface of the service provider client application running on the computing device of the customer, a second status indicator indicating that the specified type of the third-party accounts were deleted.

9. The service provider computing system of claim 7 , wherein the instructions further cause the service provider computing system to allow the customer, via the service provider client application, to place restrictions on what customer information is accessible to the third-party computing system.

10. The service provider computing system of claim 7 , wherein the instructions further cause the service provider computing system to allow the customer, via the service provider client application, to place restrictions on how accessible customer information may be used by the third-party computing system.

11. The service provider computing system of claim 7 , wherein the scrub command instructs the third-party computing system to delete all the customer information stored at the third-party computing system.

12. A non-transitory computer readable medium having machine instructions stored thereon, the instructions being executable by a processor of a service provider computing system to cause the processor to perform operations comprising:

receiving, a first application programming interface (API) call via a first API between the service provider computing system and a third-party computing system, the first API call specifying customer information of a customer;

in response to receiving the first API call from the third-party computing system, transmitting, to the third-party computing system via the first API, the customer information specified in the first API call;

presenting, via a graphical user interface of a service provider client application running on a computing device of the customer:

a third-party account that is linked to the service provider computing system, the third-party account with the customer information, the third-party account being stored in a database of the third-party computing system, wherein the customer information is accessible to the third-party computing system; and

a toggle corresponding to the third-party account, wherein the toggle visually indicates that the customer can specify to delete the customer information stored in the database of the third-party computing system;

detecting, via the service provider client application running on the computing device of the customer, selection of the toggle;

in response to detecting the selection of the toggle, generating a scrub command identifying the third-party account of the customer to be deleted from the database of the third-party computing system;

transmitting the scrub command in a second API call to the third-party computing system via the first API or a second API to cause the third-party computing system to delete, from the database of the third-party computing system, the third-party account with the customer information that is specified in the first API call and that was stored in the database of the third-party computing system;

present, via the graphical user interface of the service provider client application running on the computing device of the customer, a status indicator indicating that the third-party account was deleted.

13. The non-transitory computer readable medium of claim 12 , wherein the instructions further cause the processor to allow the customer, via the service provider client application, to place restrictions on at least one of: (i) what customer information is accessible to the third-party computing system, and (ii) how the accessible customer information may be used by the third-party computing system.

14. The non-transitory computer readable medium of claim 12 , wherein the scrub command instructs the third-party computing system to delete all the customer information, or a subset thereof, stored at the third-party computing system.

15. The non-transitory computer readable medium of claim 12 , wherein the toggle is a first toggle, wherein the selection is a first selection, wherein the scrub command is a first scrub command, wherein the status indicator is a first status indicator, and wherein the instructions further cause the processor to:

present, via the graphical user interface, a second toggle corresponding to the third-party account, wherein the second toggle visually indicates that the customer can select to delete a specified type of third-party accounts with the customer information of the customer stored in the database of the third-party computing system;

detect, via the service provider client application running on the computing device of the customer, a second selection of the second toggle to delete the specified type of the third-party accounts with the customer information of the customer stored in the database of the third-party computing system;

in response to detecting the second selection via the graphical user interface presented by the service provider client application to delete the specified type of the third-party accounts with the customer information of the customer stored in the database of the third-party computing system, generate, a second scrub command identifying the specified type of the third-party accounts with the customer information of the customer to be deleted from the database of the third-party computing system;

transmit, the second scrub command in a third API call to the third-party computing system via the first API or the second API to cause the third-party computing system to delete, from the database of the third-party computing system, the specified type of the third-party accounts with the customer information that is specified in the first API call and that was stored in the database of the third-party computing system; and

present, via the graphical user interface of the service provider client application running on the computing device of the customer, a second status indicator indicating that the specified type of the third-party accounts were deleted.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2019
From: TOMSICH, MOJDEH
To: WELLS FARGO BANK, N.A.
Reel/Frame 049615/0690 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2019
From: FAKHRAIE, LILA; PEARCE, BRIAN M.; PULIDO, STEVEN; SOCCORSY, BENJAMIN; STAHLEY, JAMES
To: WELLS FARGO BANK, N.A.
Reel/Frame 049458/0533 →
Continuity (6)
Continuation In Part 15723078 · Oct 2, 2017
Continuation In Part 15629423 · Jun 21, 2017
Provisional Application 62766400 · Oct 16, 2018
Provisional Application 62529360 · Jul 6, 2017
Provisional Application 62403396 · Oct 3, 2016
Provisional Application 62357737 · Jul 1, 2016
Cited By (52)
US 12,190,300 US 12,197,696 US 12,198,112 US 12,198,130 US 12,205,121 US 12,206,674 US 12,217,248 US 12,223,091 US 12,223,477 US 12,229,384 US 12,229,385 US 12,238,051 US 12,238,112 US 12,248,611 US 12,299,652 US 12,299,653 US 12,299,654 US 12,299,657 US 12,299,691 US 12,314,435 US 12,321,490 US 12,321,910 US 12,333,047 US 12,333,551 US 12,339,735 US 12,339,999 US 12,354,111 US 12,395,565 US 12,405,709 US 12,443,978 US 12,450,613 US 12,462,248 US 12,469,015 US 12,469,025 US 12,493,716 US 12,511,649 US 12,531,740 US 12,561,668 US 12,572,908 US 12,572,909 US 12,579,527 US 12,602,682 US 12,619,993 US 12,657,331 US 12,664,302 US 12,675,604 US 12,681,619 US 12,699,499 US 12,699,805 US 12,699,974 US 12,699,975 US 12,711,492