IP Library › Granted Patent US 11,972,016
Granted Patent B2
US 11,972,016 · App. 17/393,613 · Granted Apr 30, 2024

Sensitive data management system

Inventors: Gerardo Fang (El Paso, TX); Nicholas Hermann (Rockledge, FL)
Assignee: Capital One Services, LLC
G06F21/6245H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,972,016
App. No.
17/393,613
Granted
Apr 30, 2024
Kind
B2
Abstract

Disclosed herein are various embodiments for a sensitive data management system. An embodiment operates by receiving a web form from a transaction account of a web application associated with a first user, the form indicating a request for sensitive information of a second user. A request for an authorization to release the sensitive information to the web application. The authorization from the second user to release the sensitive information to the transaction account associated with the first user is received. The web form is populated with the sensitive information of the second user responsive to receiving the authorization from the second user to release the sensitive information, and the populated form including the sensitive information of the second user is provided to the web application.

Claims (59)

1. A computer-implemented method, comprising:

receiving a web form from a transaction account of a web application associated with a first user operating a first computing device, the web form indicating a request for sensitive information of a second user, wherein the first user is performing a transaction on behalf of the second user through the transaction account of the web application, wherein the web application is hosted across one or more servers and the transaction account of the first user is accessible from the first computing device;

verifying that the sensitive information of the second user exists in a data management system;

identifying, by one or more processors, contact information for the second user from the data management system;

providing, by the one or more processors, an electronic request for an authorization to the second user based on the contact information, wherein the electronic request for the authorization requests permission to release the sensitive information of the second user to the web application based on the request for the sensitive information from the transaction account associated with the first user, wherein the providing the electronic request for the authorization is performed subsequent to receiving the web form requesting the sensitive information;

receiving, responsive to the electronic request for the authorization, an authorization from the second user to release the sensitive information to the web application;

populating the web form with the sensitive information of the second user responsive to receiving the authorization from the second user to release the sensitive information; and

providing the populated web form including the sensitive information of the second user to the one or more servers hosting the web application, wherein the populated web form is inaccessible to the transaction account associated with the first user operating the first computing device.

2. The computer-implemented method of claim 1 , wherein the sensitive information comprises a social security number and birthdate of the second user.

3. The computer-implemented method of claim 1 , wherein the transaction comprises a loan prequalification.

4. The computer-implemented method of claim 3 , wherein the populating comprises:

identifying a format for the sensitive information from the web form;

reformatting at least a portion of the sensitive information associated with the second user in accordance with the format associated with the web form; and

populating the web form with the reformatted portion of the sensitive information.

5. The computer-implemented method of claim 1 , further comprising:

identifying non-sensitive information associated with the second user associated with the web form; and

populating the web form with the non-sensitive information associated with the second user prior to receiving the authorization to release the sensitive information.

6. The computer-implemented method of claim 1 , wherein the providing the electronic request for the authorization comprises:

transmitting the electronic request for the authorization to a user device identified by the contact information and associated with the second user.

7. The computer-implemented method of claim 6 , wherein the providing the electronic request for the authorization comprises:

determining that the user device has an app associated with sensitive information installed on the user device, wherein the sensitive information was received through the app; and

transmitting the electronic request for the authorization to the user device via the app.

8. The computer-implemented method of claim 1 , wherein the authorization to release the sensitive information comprises a code associated with the second user.

9. The computer-implemented method of claim 8 , wherein the code comprises a portion of a social security number of the second user.

10. A system comprising:

a memory; and

at least one processor coupled to the memory and configured to perform operations comprising:

receiving a web form from a transaction account of a web application associated with a first user operating a first computing device, the web form indicating a request for sensitive information of a second user, wherein the first user is performing a transaction on behalf of the second user through the transaction account of the web application, wherein the web application is hosted across one or more servers and the transaction account of the first user is accessible from the first computing device;

verifying that the sensitive information of the second user exists in a data management system;

identifying, by one or more processors, contact information for the second user from the data management system;

providing, by the one or more processors, an electronic request for an authorization to the second user based on the contact information, wherein the electronic request for the authorization requests permission to release the sensitive information of the second user to the web application based on the request for the sensitive information from the transaction account associated with the first user, wherein the providing the electronic request for the authorization is performed subsequent to receiving the web form requesting the sensitive information;

receiving, responsive to the electronic request for the authorization, an authorization from the second user to release the sensitive information to the web application;

populating the web form with the sensitive information of the second user responsive to receiving the authorization from the second user to release the sensitive information; and

providing the populated web form including the sensitive information of the second user to the one or more servers hosting the web application, wherein the populated web form is inaccessible to the transaction account associated with the first user operating the first computing device.

11. The system of claim 10 , wherein the sensitive information comprises a social security number and birthdate of the second user.

12. The system of claim 10 , wherein the transaction comprises a loan prequalification.

13. The system of claim 12 , wherein the populating comprises:

identifying a format for the sensitive information from the web form;

reformatting at least a portion of the sensitive information associated with the second user in accordance with the format associated with the web form; and

populating the web form with the reformatted portion of the sensitive information.

14. The system of claim 10 , the operations further comprising:

identifying non-sensitive information associated with the second user associated with the web form; and

populating the web form with the non-sensitive information associated with the second user prior to receiving the authorization to release the sensitive information.

15. The system of claim 10 , wherein the providing the electronic request for the authorization comprises:

transmitting the electronic request for the authorization to a user device identified by the contact information and associated with the second user.

16. The system of claim 15 , wherein the providing the electronic request for the authorization comprises:

determining that the user device has an app associated with sensitive information installed on the user device, wherein the sensitive information was received through the app; and

transmitting the electronic request for the authorization to the user device via the app.

17. The system of claim 10 , wherein the authorization to release the sensitive information comprises a code associated with the second user.

18. The system of claim 17 , wherein the code comprises a portion of a social security number of the second user.

19. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:

receiving a web form from a transaction account of a web application associated with a first user operating a first computing device, the web form indicating a request for sensitive information of a second user, wherein the first user is performing a transaction on behalf of the second user through the transaction account of the web application, wherein the web application is hosted across one or more servers and the transaction account of the first user is accessible from the first computing device;

verifying that the sensitive information of the second user exists in a data management system;

identifying, by one or more processors, contact information for the second user from the data management system;

providing, by the one or more processors, an electronic request for an authorization to the second user based on the contact information, wherein the electronic request for the authorization requests permission to release the sensitive information of the second user to the web application based on the request for the sensitive information from the transaction account associated with the first user, wherein the providing the electronic request for the authorization is performed subsequent to receiving the web form requesting the sensitive information;

receiving, responsive to the electronic request for the authorization, an authorization from the second user to release the sensitive information to the web application;

populating the web form with the sensitive information of the second user responsive to receiving the authorization from the second user to release the sensitive information; and

providing the populated web form including the sensitive information of the second user to the one or more servers hosting the web application, wherein the populated web form is inaccessible to the transaction account associated with the first user operating the first computing device.

20. The non-transitory computer-readable medium of claim 19 , wherein the sensitive information comprises a social security number and birthdate of the second user, and wherein the authorization from the second user comprises at least a portion of one of the social security number or birthdate of the second user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2021
From: FANG, GERARDO; HERMANN, NICHOLAS
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 057078/0021 →
Continuity (1)
Related Publication 20230038128A1 · Feb 9, 2023
Cited By (1)
US 12,299,170