IP Library › Granted Patent US 12,455,979
Granted Patent B2
US 12,455,979 · App. 18/413,483 · Granted Oct 28, 2025

Permission based information transfer based on internet of things (IoT) insights

Inventors: George Albero (Charlotte, NC); Maharaj Mukherjee (Poughkeepsie, NY); Ariel Fontaine Hill (Arlington, VA); Elijah John Clark (Charlotte, NC)
Assignee: Bank of America Corporation
G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,455,979
App. No.
18/413,483
Granted
Oct 28, 2025
Kind
B2
Abstract

A computing platform may receive, from a plurality of IoT information sources, historical information associated with a user. The computing platform may generate, based on the historical information, a user specific policy, defining information distribution rules for the user. The computing platform may receive, from an information collection system, a request for information. The computing platform may identify whether or not the request for information requests personal information of the user. Based on identifying that the request for information requests the personal information of the user, the computing platform may identify whether or not the requested personal information violates the user specific policy. Based on identifying that the requested personal information does not violate the user specific policy, the computing platform may obscure the requested personal information, and send, to the information collection system, the obscured personal information.

Claims (63)

1. A computing device comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

receive, from a plurality of internet of things (IoT) information sources, historical information associated with a user;

generate, based on the historical information, a user specific policy, wherein the user specific policy defines information distribution rules for the user indicating types of information for which permission is needed prior to automated distribution of the corresponding information;

receive, from an information collection system, a request for information;

identify whether or not the request for information requests personal information of the user; and

based on identifying that the request for information does request the personal information of the user:

identify whether or not the requested personal information violates the user specific policy, and

based on identifying that the requested personal information does not violate the user specific policy:

obscure the requested personal information, and

send, to the information collection system, the obscured personal information.

2. The computing device of claim 1 , wherein the plurality of IoT information sources includes one or more of: an electric vehicle charger, an automated teller machine, a vehicle sensor, a wearable device, or a mobile device.

3. The computing device of claim 1 , wherein the historical information comprises one or more of: text information, voice information, image information, geolocation information, social information, date of birth information, address information, passport numbers, or account numbers.

4. The computing device of claim 1 , wherein generating the user specific policy comprises generating a knowledge graph including a plurality of nodes and edges connecting pairs of nodes within the plurality of nodes, wherein each node defines a portion of the historical information, and wherein each edge defines an information distribution rule, of the information distribution rules, indicating one or more of:

the corresponding node information may be automatically sent without prompting the user for permission,

the corresponding node information may be sent if the user provides permission via a prompt, or

the corresponding node information may not be sent.

5. The computing device of claim 1 , wherein the user specific policy is automatically generated based on the historical information.

6. The computing device of claim 1 , wherein the user specific policy is generated based on user input.

7. The computing device of claim 1 , wherein identifying whether or not the request for information requests personal information of the user comprises comparing the requested information to known types of personal information.

8. The computing device of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

based on identifying that the request for information does not request the personal information of the user, automatically send the requested information without prompting the user for approval.

9. The computing device of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

based on identifying that the requested personal information does violate the user specific policy, prevent the requested information from being sent without approval from the user.

10. The computing device of claim 1 , wherein obscuring the requested personal information comprises scrambling the requested personal information.

11. The computing device of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

identify, based on the historical information, whether or not the information collection system exhibits anomalous behavior, wherein sending the obscured personal information to the information collection system is responsive to identifying that the information collection system does not exhibit anomalous behavior.

12. The computing device of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

identify, based on the historical information, whether or not the information collection system exhibits anomalous behavior; and

based on identifying that the information collection system exhibits anomalous behavior, identify an alternative information collection system that does not exhibit the anomalous behavior.

13. The computing device of claim 12 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

display, on a mapping interface, the information collection system, the alternative information collection system, and a recommendation to engage with the alternative information collection system rather than the information collection system.

14. A method comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

receiving, from a plurality of internet of things (IoT) information sources, historical information associated with a user;

generating, based on the historical information, a user specific policy, wherein the user specific policy defines information distribution rules for the user indicating types of information for which permission is needed prior to automated distribution of the corresponding information;

receiving, from an information collection system, a request for information;

identifying whether or not the request for information requests personal information of the user; and

based on identifying that the request for information does request the personal information of the user:

identifying whether or not the requested personal information violates the user specific policy, and

based on identifying that the requested personal information does not violate the user specific policy:

obscuring the requested personal information, and

sending, to the information collection system, the obscured personal information.

15. The method of claim 14 , wherein the plurality of IoT information sources includes one or more of: an electric vehicle charger, an automated teller machine, a vehicle sensor, a wearable device, or a mobile device.

16. The method of claim 14 , wherein the historical information comprises one or more of: text information, voice information, image information, geolocation information, social information, date of birth information, address information, passport numbers, or account numbers.

17. The method of claim 14 , wherein generating the user specific policy comprises generating a knowledge graph including a plurality of nodes and edges connecting pairs of nodes within the plurality of nodes, wherein each node defines a portion of the historical information, and wherein each edge defines an information distribution rule, of the information distribution rules, indicating one or more of:

the corresponding node information may be automatically sent without prompting the user for permission,

the corresponding node information may be sent if the user provides permission via a prompt, or

the corresponding node information may not be sent.

18. The method of claim 14 , wherein the user specific policy is automatically generated based on the historical information.

19. The method of claim 14 , wherein the user specific policy is generated based on user input.

20. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

receive, from a plurality of internet of things (IoT) information sources, historical information associated with a user;

generate, based on the historical information, a user specific policy, wherein the user specific policy defines information distribution rules for the user indicating types of information for which permission is needed prior to automated distribution of the corresponding information;

receive, from an information collection system, a request for information;

identify whether or not the request for information requests personal information of the user; and

based on identifying that the request for information does request the personal information of the user:

identify whether or not the requested personal information violates the user specific policy, and

based on identifying that the requested personal information does not violate the user specific policy:

obscure the requested personal information, and

send, to the information collection system, the obscured personal information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2024
From: ALBERO, GEORGE; MUKHERJEE, MAHARAJ; HILL, ARIEL FONTAINE; CLARK, ELIJAH JOHN
To: BANK OF AMERICA CORPORATION
Reel/Frame 066136/0464 →
Continuity (1)
Related Publication 20250232056A1 · Jul 17, 2025
References Cited (17)
US 9635034B2 · Jamison et al. · 2017 [cited by applicant]
US 11063760B2 · Subba · 2021 [cited by applicant]
US 11582040B2 · Soundararajan et al. · 2023 [cited by applicant]
US 20190051420A1 · Zhao · 2019 [cited by examiner]
US 20210243192A1 · Kim · 2021 [cited by applicant]
US 20210282181A1 · Yi et al. · 2021 [cited by applicant]
US 20210368341A1 · Liao · 2021 [cited by applicant]
US 20220012101A1 · Lee · 2022 [cited by applicant]
US 20220070267A1 · McCall et al. · 2022 [cited by applicant]
US 20220094560A1 · Gaur et al. · 2022 [cited by applicant]
US 20220210854A1 · Lam et al. · 2022 [cited by applicant]
US 20220263820A1 · Barton et al. · 2022 [cited by applicant]
US 20220277061A1 · Pagidi · 2022 [cited by applicant]
US 20220338111A1 · Edge · 2022 [cited by applicant]
US 20220353244A1 · Kahn et al. · 2022 [cited by applicant]
US 20220400118A1 · Jiang et al. · 2022 [cited by applicant]
US 20240427928A1 · Alphin, III · 2024 [cited by examiner]