IP Library › Granted Patent US 11,805,134
Granted Patent B2
US 11,805,134 · App. 17/583,315 · Granted Oct 31, 2023

Systems and methods for authenticating data access requests

Inventors: Denny Devasia Kuruvilla (Toronto, CA); Esli Gjini (Etobicoke, CA); Sarah Reeve (Toronto, CA); Matija Bosnjakovic (Oakville, CA); Guy Dagmara (Toronto, CA); Jaspal Singh Samra (Brampton, CA); Abhiney Natarajan (Stoney Creek, CA); Haobin Li (Kitchener, CA); Richard Yu (Mississauga, CA); Md Abdur Razzak Chowdhury (Mississauga, CA); Dani Kartikay (Brampton, CA); Ryan Wu (Vaughan, CA); Andrey Petrov (Toronto, CA); Peter Horvath (Toronto, CA); Prashanth Dappula (King City, CA); Sivashanthan Sivapalan (Markham, CA); Nolan Glynn-Udrow (Mississauga, CA)
Assignee: The Toronto-Dominion Bank
H04L63/108H04L63/0428H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,805,134
App. No.
17/583,315
Granted
Oct 31, 2023
Kind
B2
Abstract

A computer-implemented method is disclosed. The method includes: authenticating a user for login to a service for a first authenticated user session; in response to authenticating the user, generating a first data string associated with a first validity period; sending, to a client device associated with the user, the first data string; receiving, from the client device, a data access request to access a first data set at a remote data source, the data access request including the first data string; determining that the first authenticated user session has been terminated at a time of receiving the data access request; validating the first data string based on checking the first validity period; and in response to determining that the first authenticated user session has been terminated and that the first data string is valid, transmitting, to the client device, a data access response including at least a subset of the first data set.

Claims (49)

1. A computing system, comprising:

a processor;

a communications module coupled to the processor; and

a memory coupled to the processor, the memory storing instructions that, when executed, configure the processor to:

authenticate a user for login to a service for a first authenticated user session;

in response to authenticating the user, generate a first data string associated with a first validity period;

send, to a client device associated with the user, the first data string;

receive, via the communications module from the client device, a data access request to access a first data set at a remote data source, the data access request including the first data string;

determine that the first authenticated user session has been terminated at a time of receiving the data access request;

validate the first data string based on checking the first validity period; and

in response to determining that the first authenticated user session has been terminated and that the first data string is valid, transmit, to the client device, a data access response including at least a subset of the first data set.

2. The computing system of claim 1 , wherein the instructions, when executed, further configure the processor:

in response to determining that the first data string is not valid, transmit, to the client device, an instruction to request login credentials from the user of the client device.

3. The computing system of claim 1 , wherein the first validity period defines an expiry date set as a predetermined number of days from a time of receipt of a login request from the client device to log the user in to the service.

4. The computing system of claim 1 , wherein the instructions, when executed, further configure the processor to encrypt the first data string prior to sending the first data string to the client device, and wherein validating the first data string comprises decrypting the encrypted first data string.

5. The computing system of claim 1 , wherein the first data string represents a version identifier that is stored in the memory, and wherein validating the first data string is based on checking a version associated with the first data string.

6. The computing system of claim 1 , wherein the instructions, when executed, further configure the processor to:

authenticate the user for login to the service for a second authenticated user session subsequent to the first authenticated user session;

in response to authenticating the user for the second authenticated user session, generate a second data string different from the first data string; and

send, to the client device, the second data string and an instruction to replace any currently valid data string stored at the client device with the second data string.

7. The computing system of claim 1 , wherein the data access response includes at least the subset of the first data set in response to determining that access of the first data set is a permitted operation in a non-authenticated user session.

8. The computing system of claim 1 , wherein validating the first data string comprises determining that a current date falls within the first validity period.

9. The computing system of claim 1 , wherein the data access request comprises a request to retrieve real-time quotes for one or more tradeable objects, and wherein the instructions, when executed, further configure the processor to transmit, to the remote data source, a query for real-time quotes data.

10. The computing system of claim 1 , wherein the first data string is associated with a predetermined set of operations, and wherein the instructions, when executed, further configure the processor to:

receive, via the communications module from the client device, a request to perform a first operation; and

in response to determining that the first operation is not among the predetermined set of operations associated with the first data string, transmit, to the client device, an instruction to request login credentials from a user of the client device.

11. A computer-implemented method, comprising:

authenticating a user for login to a service for a first authenticated user session;

in response to authenticating the user, generating a first data string associated with a first validity period;

sending, to a client device associated with the user, the first data string;

receiving, from the client device, a data access request to access a first data set at a remote data source, the data access request including the first data string;

determining that the first authenticated user session has been terminated at a time of receiving the data access request;

validating the first data string based on checking the first validity period; and

in response to determining that the first authenticated user session has been terminated and that the first data string is valid, transmitting, to the client device, a data access response including at least a subset of the first data set.

12. The method of claim 11 , further comprising:

in response to determining that the first data string is not valid, transmitting, to the client device, an instruction to request login credentials from the user of the client device.

13. The method of claim 11 , wherein the first validity period defines an expiry date set as a predetermined number of days from a time of receipt of a login request from the client device to log the user in to the service.

14. The method of claim 11 , further comprising encrypting the first data string prior to sending the first data string to the client device, and wherein validating the first data string comprises decrypting the encrypted first data string.

15. The method of claim 11 , wherein the first data string represents a version identifier that is stored in memory, and wherein validating the first data string is based on checking a version associated with the first data string.

16. The method of claim 11 , further comprising:

authenticating the user for login to the service for a second authenticated user session subsequent to the first authenticated user session;

in response to authenticating the user for the second authenticated user session, generating a second data string different from the first data string; and

sending, to the client device, the second data string and an instruction to replace any currently valid data string stored at the client device with the second data string.

17. The method of claim 11 , wherein the data access response includes at least the subset of the first data set in response to determining that access of the first data set is a permitted operation in a non-authenticated user session.

18. The method of claim 11 , wherein validating the first data string comprises determining that a current date falls within the first validity period.

19. The method of claim 11 , wherein the data access request comprises a request to retrieve real-time quotes for one or more tradeable objects, and wherein the instructions, when executed, further configure the processor to transmit, to the remote data source, a query for real-time quotes data.

20. The method of claim 11 , wherein the first data string is associated with a predetermined set of operations, and wherein the method further comprises:

receiving, from the client device, a request to perform a first operation;

in response to determining that the first operation is not among the predetermined set of operations associated with the first data string, transmitting, to the client device, an instruction to request login credentials from a user of the client device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2022
From: KURUVILLA, DENNY DEVASIA; GJINI, ESLI; REEVE, SARAH; BOSNJAKOVIC, MATIJA; DAGMARA, GUY; SAMRA, JASPAL SINGH; NATARAJAN, ABHINEY; LI, HAOBIN; YU, RICHARD; CHOWDHURY, MD ABDUR RAZZAK; KARTIKAY, DANI; WU, RYAN; PETROV, ANDREY; HORVATH, PETER; DAPPULA, PRASHANTH; SIVAPALAN, SIVASHANTHAN; GLYNN-UDROW, NOLAN
To: THE TORONTO-DOMINION BANK
Reel/Frame 058754/0807 →
Continuity (2)
Continuation 16520505 · Jul 24, 2019
Related Publication 20220150231A1 · May 12, 2022