IP Library Granted Patent US 12,052,251
Granted Patent B1
US 12,052,251 · App. 17/319,837 · Granted Jul 30, 2024

Compliance management system

Inventors: Rajesh Padincharekkara Mannachery (Bangalore, IN); Parul Ghosh (Bangalore, IN); Rameshchandra Bhaskar Ketharaju (Hyderabad, IN); Chandrasekaran Sivaraman (Bangalore, IN); Shanmukeswara Rao Donkada (Hyderabad, IN)
Assignee: Wells Fargo Bank, N.A.
H04L63/10G06F21/604G06F21/62G06F21/6245H04L47/70H04L67/63H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,251
App. No.
17/319,837
Granted
Jul 30, 2024
Kind
B1
Abstract

Compliance management is disclosed. A user can submit a data request, which can trigger the generation of a permission token for a service operator and a service request for the data request. An identified service operator can be provided with exclusive permissions to solve the data request. Access to data is managed to allow non-compliance to be detected and addressed. An attempt is made to locate the performance token and the service request associated with a customer data request. Further, the permission token and service token can be evaluated. A compliance state is set to non-compliant when a search fails to locate the permission token and the service token or when the permission token is expired or the service request is invalid. If the compliance state is non-compliant, an alert or security action can be initiated.

Claims (57)

1. A system, comprising:

a processor coupled to a memory that includes instructions that, when executed by the processor, cause the processor to:

attempt to locate a permission token and a service request, wherein the permission token and the service request are associated with a service operator's access to customer data;

change a compliance state from compliant to non-compliant when the attempt to locate the permission token or the service request fails;

evaluate the permission token and the service request when the attempt to locate the permission token and the service request succeeds;

determine, based on the evaluation of the permission token and the service request, that the service operator has exceeded exclusive permission to the customer data;

change a status of the permission token to expired and invalidate the service request based on determining that the service operator has exceeded exclusive permission to the customer data;

change the compliance state from compliant to non-compliant when the permission token is expired and when the service request is invalidated;

determine, based on an escalation matrix triggered by the change in the compliance state from compliant to non-compliant, one or more recommended security actions—and to revoke a non-compliant service operator's access to the customer data;

output the compliance state; and

execute the one or more recommended security actions.

2. The system of claim 1 , wherein the instructions further cause the processor to generate an alert when the compliance state is non-compliant.

3. The system of claim 2 , wherein the instructions further cause the processor to generate the alert according to the escalation matrix that identifies one or more people or authorities to notify of the non-compliant compliance state.

4. The system of claim 1 , wherein the service operator's access to the customer data is limited to one of a plurality of views.

5. The system of claim 1 , wherein the instructions further cause the processor to:

detect access of the customer data by a different service operator than the service operator with the exclusive permission; and

set the compliance state to non-compliant.

6. The system of claim 5 , wherein the instructions further cause the processor to cause expiration of the permission token in response to detection of access of the customer data by a different service operator.

7. A method, comprising:

initializing a compliance state to compliant;

attempting to locate a permission token and a service request, wherein the permission token and the service request are associated with a service operator's access to customer data;

setting the compliance state to non-compliant when the attempt to locate the permission token or the service request fails;

evaluating the permission token and the service request when the attempt to locate the permission token and the service request succeeds;

determining, based on the evaluation of the permission token and the service request, that the service operator has exceeded exclusive permission to the customer data;

changing a status of the permission token to expired and invalidating the service request based on determining that the service operator has exceeded exclusive permission to the customer data;

setting the compliance state to non-compliant when the permission token is expired and when the service request is invalidated;

determining, based on an escalation matrix triggered by the change in the compliance state from compliant to non-compliant, one or more recommended security actions and to revoke a non-compliant service operator's access to the customer data;

outputting the compliance state; and

executing the one or more recommended security actions.

8. The method of claim 7 , further comprising generating an alert when the compliance state is non-compliant.

9. The method of claim 8 , further comprising generating the alert according to the escalation matrix that identifies one or more people or authorities to notify of the non-compliant compliance state.

10. The method of claim 7 , further comprising:

detecting access of the customer data by a different service operator than the operator with exclusive permission; and

setting the compliance state to non-compliant.

11. The method of claim 10 , further comprising causing expiration of the permission token in response to detection of access of the customer data by a different service operator.

12. The method of claim 7 , wherein the service operator's access to the customer data is limited to one of a plurality of views.

13. A method, comprising:

executing instructions on a processor that cause the processor to perform operations, comprising:

initializing a compliance state to compliant;

searching for a permission token and service request, wherein the permission token and the service request are associated with a service operator's access to customer data;

setting the compliance state to non-compliant when the searching fails to locate the permission token and the service request;

evaluating the permission token and the service request when the search locates the permission token and the service request;

determining, based on the evaluation of the permission token and the service request, that the service operator has exceeded exclusive permission to the customer data;

changing a status of the permission token to expired and invalidating the service request based on determining that the service operator has exceeded exclusive permission to the customer data;

setting the compliance state to non-compliant when the permission token is expired and when the service request is invalidated; and

determining, based on an escalation matrix triggered by the change in the compliance state from compliant to non-compliant, one or more recommended security actions and to revoke a non-compliant service operator's access to the customer data;

outputting the compliance state; and

executing the one or more recommended security actions.

14. The method of claim 13 , wherein the operations further comprise:

determining a context associated with the service operator's access to the customer data, wherein the context is associated with a customer account out of at least two customer accounts, and wherein the context limits the service operator's access to the associated customer account.

15. The method of claim 13 , wherein the operations further comprise generating an alert when the compliance state is non-compliant.

16. The method of claim 15 , wherein the operations further comprise generating the alert according to the escalation matrix that identifies one or more people or authorities to notify of the non-compliant compliance state.

17. The method of claim 13 , wherein the service operator's access to the customer data is limited to one of a plurality of views.

18. The method of claim 13 , wherein the operations further comprise:

detecting access of the customer data by a different service operator than the service operator with the exclusive permission; and

setting the compliance state to non-compliant.

19. The method of claim 18 , wherein the instructions further cause the processor to cause expiration of the permission token in response to detection of access of the customer data by a different service operator.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0143 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2021
From: MANNACHERY, RAJESH PADINCHAREKKARA; GHOSH, PARUL; KETHARAJU, RAMESHCHANDRA BHASKAR; SIVARAMAN, CHANDRASEKARAN; DONKADA, SHANMUKESWARA RAO
To: WELLS FARGO BANK, N.A.
Reel/Frame 056235/0022 →
Continuity (1)
Continuation 15891991 · Feb 8, 2018