IP Library Granted Patent US 10,454,941
Granted Patent B2
US 10,454,941 · App. 15/588,353 · Granted Oct 22, 2019

Person-to-person network architecture for secure authorization and approval

Inventors: Katherine Dintenfass (Lincoln, RI); Elizabeth S. Votaw (Potomac, MD); Cameron Darnell Wadley (Waxhaw, NC)
Assignee: Bank of America Corporation
H04L63/102H04L63/08G06F2221/2103G06F2221/2115G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,454,941
App. No.
15/588,353
Filed
May 5, 2017
Granted
Oct 22, 2019
Kind
B2
Art Unit
2439
USPC
726/24
Abstract

A system for configuring and executing a secure communication network for authorizing access to safeguarded resources is provided. In particular, the system uses person-to-person (P2P) authentication technology to securely transmit resources between users. In this way, an efficient way to for users to manage resources is provided.

Claims (98)

1. A system for configuring and executing a secure communication network for authorizing access to safeguarded resources, the system comprising:

a memory device; and

one or more processing devices operatively coupled to the memory device, wherein the one or more processing devices are configured to execute computer-readable program code to:

receive a request from a first user to grant a second user access to an account associated with the first user;

in response to receiving the request to grant the second user the access to the account associated with the first user, configure a secure dedicated communication channel between a computing device of the first user and a computing device of the second user;

transmit, via the secure dedicated communication channel, to the computing device of the second user, the request to grant the second user the access to the account associated with the first user;

receive, from the computing device of the second user, an acceptance of the request to grant the second user the access to the account associated with the first user;

in response to receiving the acceptance, transmit control signals configured to cause the computing device of the second user to display notification of an authentication challenge and a request for an input of an authentication challenge response, wherein the authentication challenge is configured to query memory of the computing device of the second user to retrieve data that identifies the second user and the input is authorization by the second user to query the memory of the computing device of the second user;

in response to the second user providing the input that authorizes querying of the memory of the computing device of the second user, receive, from the computing device of the second user, the authentication challenge response including the data that identifies the second user;

compare the received data that identifies the second user with authentication data of the second user stored in a database to determine that the received authentication challenge response is acceptable; and

in response to determining that the received authentication challenge response is acceptable, grant the second user with access rights to the account associated with the first user.

2. The system of claim 1 , wherein the one or more processing devices are further configured to execute computer-readable program code to:

receive the request from the first user to grant the second user the access to the account associated with the first user, wherein the request to grant the second user the access to the account associated with the first user comprises an electronic authorization document associated with the access to the account associated with the first user;

in response to determining that the received authentication challenge response is acceptable, transmit the electronic authorization document, via the secure dedicated communication channel, from the computing device of the first use to the computing device of the second user;

receive, from the computing device of the second user, the electronic authorization document;

determine that the electronic authorization document received from the computing device of the second user has successfully been completed; and

in response to determining that the electronic authorization document has successfully been completed, grant the second user the access rights to the account associated with the first user.

3. The system of claim 1 , wherein the one or more processing devices are further configured to execute computer-readable program code to:

receive the request from the first user to grant the second user the access to the account associated with the first user, wherein the request to grant the second user the access to the account associated with the first user is conditioned on an occurrence of a triggering event;

receive an indication of the occurrence of the triggering event; and

in response to receiving the indication of the occurrence of the triggering event, transmit, via the secure dedicated communication channel, to the computing device of the second user, the request to grant the second user the access to the account associated with the first user.

4. The system of claim 1 , wherein the one or more processing devices are further configured to execute computer-readable program code to:

receive a request from the first user to grant a third user limited access to the account associated with the first user;

in response to receiving the request to grant the third user the limited access to the account associated with the first user, configure a new secure dedicated communication channel between the computing device of the first user and a computing device of the third user;

transmit, via the new secure dedicated communication channel, to the computing device of the third user, the request to grant the second user the limited access to the account associated with the first user;

receive, from the computing device of the third user, an acceptance of the request to grant the third user the limited access to the account associated with the first user;

in response to receiving the acceptance, transmit control signals configured to cause the computing device of the third user to display notification of a limited authentication challenge and a request for an input of a limited authentication challenge response, wherein the limited authentication challenge is configured to query memory of the computing device of the third user to retrieve data that identifies the third user and the input is authorization by the third user to query the memory of the computing device of the third user;

in response to the third user providing the input that authorizes querying of the memory of the computing device of the third user, receive, from the computing device of the third user, the limited authentication challenge response including the data that identifies the third user;

compare the received data that identifies the third user with authentication data of the third user stored in the database to determine that the received limited authentication challenge response is acceptable; and

in response to determining that the received limited authentication challenge response is acceptable, grant the third user with limited access rights to the account associated with the first user.

5. The system of claim 1 , wherein the one or more processing devices are further configured to execute computer-readable program code to:

terminate the access rights of the second user to the account associated with the first user after a predetermined period of time or in response to receiving a request from the first user to terminate the access rights of the second user.

6. The system of claim 1 , wherein the request from the first user to grant the second user access to an account associated with the first user is associated with a request to grant the second user a power of attorney right with respect to at least the account associated with the first user.

7. The system of claim 1 , wherein the request from the first user to grant the second user access to an account associated with the first user is associated with a request to grant the second user a legal right to perform an action on behalf of the first user that the second user would otherwise not have the legal right to perform.

8. A computer program product for configuring and executing a secure communication network for authorizing access to safeguarded resources, the computer program product comprising at least one non-transitory computer readable medium comprising computer readable instructions, the instructions comprising instructions for:

receiving a request from a first user to grant a second user access to an account associated with the first user;

in response to receiving the request to grant the second user the access to the account associated with the first user, configuring a secure dedicated communication channel between a computing device of the first user and a computing device of the second user;

transmitting, via the secure dedicated communication channel, to the computing device of the second user, the request to grant the second user the access to the account associated with the first user;

receiving, from the computing device of the second user, an acceptance of the request to grant the second user the access to the account associated with the first user;

in response to receiving the acceptance, transmitting control signals configured to cause the computing device of the second user to display notification of an authentication challenge and a request for an input of an authentication challenge response, wherein the authentication challenge is configured to query memory of the computing device of the second user to retrieve data that identifies the second user and the input is authorization by the second user to query the memory of the computing device of the second user;

in response to the second user providing the input that authorizes querying of the memory of the computing device of the second user, receiving, from the computing device of the second user, the authentication challenge response including the data that identifies the second user;

comparing the received data that identifies the second user with authentication data of the second user stored in a database to determine that the received authentication challenge response is acceptable; and

in response to determining that the received authentication challenge response is acceptable, granting the second user with access rights to the account associated with the first user.

9. The computer program product of claim 8 , wherein the computer readable instructions further comprise instructions for:

receiving the request from the first user to grant the second user the access to the account associated with the first user, wherein the request to grant the second user the access to the account associated with the first user comprises an electronic authorization document associated with the access to the account associated with the first user;

in response to determining that the received authentication challenge response is acceptable, transmitting the electronic authorization document, via the secure dedicated communication channel, from the computing device of the first use to the computing device of the second user;

receiving, from the computing device of the second user, the electronic authorization document;

determining that the electronic authorization document received from the computing device of the second user has successfully been completed; and

in response to determining that the electronic authorization document has successfully been completed, granting the second user the access rights to the account associated with the first user.

10. The computer program product of claim 8 , wherein the computer readable instructions further comprise instructions for:

receiving the request from the first user to grant the second user the access to the account associated with the first user, wherein the request to grant the second user the access to the account associated with the first user is conditioned on an occurrence of a triggering event;

receiving an indication of the occurrence of the triggering event; and

in response to receiving the indication of the occurrence of the triggering event, transmitting, via the secure dedicated communication channel, to the computing device of the second user, the request to grant the second user the access to the account associated with the first user.

11. The computer program product of claim 8 , wherein the computer readable instructions further comprise instructions for:

receiving a request from the first user to grant a third user limited access to the account associated with the first user;

in response to receiving the request to grant the third user the limited access to the account associated with the first user, configuring a new secure dedicated communication channel between the computing device of the first user and a computing device of the third user;

transmitting, via the new secure dedicated communication channel, to the computing device of the third user, the request to grant the second user the limited access to the account associated with the first user;

receiving, from the computing device of the third user, an acceptance of the request to grant the third user the limited access to the account associated with the first user;

in response to receiving the acceptance, transmitting control signals configured to cause the computing device of the third user to display notification of a limited authentication challenge and a request for an input of a limited authentication challenge response, wherein the limited authentication challenge is configured to query memory of the computing device of the third user to retrieve data that identifies the third user and the input is authorization by the third user to query the memory of the computing device of the third user;

in response to the third user providing the input that authorizes querying of the memory of the computing device of the third user, receiving, from the computing device of the third user, the limited authentication challenge response including the data that identifies the third user;

comparing the received data that identifies the third user with authentication data of the third user stored in the database to determine that the received limited authentication challenge response is acceptable; and

in response to determining that the received limited authentication challenge response is acceptable, granting the third user with limited access rights to the account associated with the first user.

12. The computer program product of claim 8 , wherein the computer readable instructions further comprise instructions for:

terminating the access rights of the second user to the account associated with the first user after a predetermined period of time or in response to receiving a request from the first user to terminate the access rights of the second user.

13. The computer program product of claim 8 , wherein the request from the first user to grant the second user access to an account associated with the first user is associated with a request to grant the second user a power of attorney right with respect to at least the account associated with the first user.

14. The computer program product of claim 8 , wherein the request from the first user to grant the second user access to an account associated with the first user is associated with a request to grant the second user a legal right to perform an action on behalf of the first user that the second user would otherwise not have the legal right to perform.

15. A computer implemented method for configuring and executing a secure communication network for authorizing access to safeguarded resources, said computer implemented method comprising:

providing a computing system comprising a computer processing device and a non-transitory computer readable medium, where the computer readable medium comprises configured computer program instruction code, such that when said instruction code is operated by said computer processing device, said computer processing device performs the following operations:

receiving a request from a first user to grant a second user access to an account associated with the first user;

in response to receiving the request to grant the second user the access to the account associated with the first user, configuring a secure dedicated communication channel between a computing device of the first user and a computing device of the second user;

transmitting, via the secure dedicated communication channel, to the computing device of the second user, the request to grant the second user the access to the account associated with the first user;

receiving, from the computing device of the second user, an acceptance of the request to grant the second user the access to the account associated with the first user;

in response to receiving the acceptance, transmitting control signals configured to cause the computing device of the second user to display notification of an authentication challenge and a request for an input of an authentication challenge response, wherein the authentication challenge is configured to query memory of the computing device of the second user to retrieve data that identifies the second user and the input is authorization by the second user to query the memory of the computing device of the second user;

in response to the second user providing the input that authorizes querying of the memory of the computing device of the second user, receiving, from the computing device of the second user, the authentication challenge response including the data that identifies the second user;

comparing the received data that identifies the second user with authentication data of the second user stored in a database to determine that the received authentication challenge response is acceptable; and

in response to determining that the received authentication challenge response is acceptable, granting the second user with access rights to the account associated with the first user.

16. The computer implemented method of claim 15 , further comprising:

receiving the request from the first user to grant the second user the access to the account associated with the first user, wherein the request to grant the second user the access to the account associated with the first user comprises an electronic authorization document associated with the access to the account associated with the first user;

in response to determining that the received authentication challenge response is acceptable, transmitting the electronic authorization document, via the secure dedicated communication channel, from the computing device of the first use to the computing device of the second user;

receiving, from the computing device of the second user, the electronic authorization document;

determining that the electronic authorization document received from the computing device of the second user has successfully been completed; and

in response to determining that the electronic authorization document has successfully been completed, granting the second user the access rights to the account associated with the first user.

17. The computer implemented method of claim 15 , further comprising:

receiving the request from the first user to grant the second user the access to the account associated with the first user, wherein the request to grant the second user the access to the account associated with the first user is conditioned on an occurrence of a triggering event;

receiving an indication of the occurrence of the triggering event; and

in response to receiving the indication of the occurrence of the triggering event, transmitting, via the secure dedicated communication channel, to the computing device of the second user, the request to grant the second user the access to the account associated with the first user.

18. The computer implemented method of claim 15 , further comprising:

receiving a request from the first user to grant a third user limited access to the account associated with the first user;

in response to receiving the request to grant the third user the limited access to the account associated with the first user, configuring a new secure dedicated communication channel between the computing device of the first user and a computing device of the third user;

transmitting, via the new secure dedicated communication channel, to the computing device of the third user, the request to grant the second user the limited access to the account associated with the first user;

receiving, from the computing device of the third user, an acceptance of the request to grant the third user the limited access to the account associated with the first user;

in response to receiving the acceptance, transmitting control signals configured to cause the computing device of the third user to display notification of a limited authentication challenge and a request for an input of a limited authentication challenge response, wherein the limited authentication challenge is configured to query memory of the computing device of the third user to retrieve data that identifies the third user and the input is authorization by the third user to query the memory of the computing device of the third user;

in response to the third user providing the input that authorizes querying of the memory of the computing device of the third user, receiving, from the computing device of the third user, the limited authentication challenge response including the data that identifies the third user;

comparing the received data that identifies the third user with authentication data of the third user stored in the database to determine that the received limited authentication challenge response is acceptable; and

in response to determining that the received limited authentication challenge response is acceptable, granting the third user with limited access rights to the account associated with the first user.

19. The computer implemented method of claim 15 , further comprising:

terminating the access rights of the second user to the account associated with the first user after a predetermined period of time or in response to receiving a request from the first user to terminate the access rights of the second user.

20. The computer implemented method of claim 15 , wherein the request from the first user to grant the second user access to an account associated with the first user is associated with a request to grant the second user a power of attorney right with respect to at least the account associated with the first user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2017
From: DINTENFASS, KATHERINE; VOTAW, ELIZABETH S.; WADLEY, CAMERON DARNELL
To: BANK OF AMERICA CORPORATION
Reel/Frame 042260/0667 →
Continuity (1)
Related Publication 20180324186A1 · Nov 8, 2018