IP Library › Granted Patent US 12,067,137
Granted Patent B2
US 12,067,137 · App. 17/490,743 · Granted Aug 20, 2024

System and method of processing a data access request

Inventors: Shishir Dattatraya Bhat (Toronto, CA); Marcus Edward Furlong (Sandy Springs, GA); Katherine Kanczuga (Toronto, CA); Sumathi Seetharaman (Etobicoke, CA)
Assignee: The Toronto-Dominion Bank
G06F21/6218G06Q40/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,067,137
App. No.
17/490,743
Granted
Aug 20, 2024
Kind
B2
Abstract

Computing platforms, methods, and storage media for processing a data access request are disclosed. Exemplary implementations may: receive, at an apparatus, a data access request from a communication device and via a network; and generate, at the apparatus and based on the received data access request, a revocable 1:1:1 token that authorizes data sharing for a specific combination of third party application-aggregator-institution. Exemplary implementations may transmit the revocable 1:1:1 token for storage in a token database, and may store the 1:1:1 tokens in a token database associated with an institution related to the data access request; this allows access to be managed by the user and controlled by the institution, without relying on the aggregator. Exemplary implementations may provide a dashboard enabling a user to individually remove apps from data sharing, based on management of the 1:1:1 tokens.

Claims (43)

1. A computing platform configured for processing a data access request, the computing platform comprising:

a non-transient computer-readable storage medium having instructions embodied thereon; and

one or more processors configured to execute the instructions to:

receive, at the computing platform, a data access request from a communication device and via a network, the data access request relating to a third party application and to a user associated with the communication device;

generate, at the computing platform and based on the received data access request, a revocable 1:1:1 token that authorizes data sharing for a specific combination of third party application-aggregator-institution for the user associated with the communication device; and

manage, in conjunction with a server associated with the computing platform, third party application connectivity of a plurality of third party applications based on tracking associated revocable 1:1:1 tokens in a plurality of access tokens, each revocable 1:1:1 token having a different access period for the specific combination of third party application-aggregator-institution.

2. The computing platform of claim 1 , wherein the one or more processors are further configured to execute the instructions to:

transmit, from the computing platform, the revocable 1:1:1 token for storage in a token database.

3. The computing platform of claim 1 , wherein the one or more processors are further configured to execute the instructions to:

transmit, from the computing platform of the institution, the revocable 1:1:1 token and a user identifier associated with the user, for storage in a token database to associate the revocable 1:1:1 token with a user-specific data access request.

4. The computing platform of claim 1 , wherein the one or more processors are further configured to execute the instructions to:

initiate storage of the 1:1:1 token in a token database associated with the institution specified in the 1:1:1 token.

5. The computing platform of claim 1 , wherein the one or more processors are further configured to execute the instructions to:

provide, in conjunction with a server of the institution in communication with the computing platform of the institution, a dashboard configured to enable a user to individually remove the third party application from data sharing based on the generated 1:1:1 token.

6. The computing platform of claim 1 , wherein the one or more processors are further configured to execute the instructions to:

generate, in conjunction with a server of the institution in communication with the computing platform of the institution, the revocable 1:1:1 token independent of the third party aggregator.

7. The computing platform of claim 1 , wherein:

the access request comprises an open banking access request associated with the user; the third party application comprises a third party financial application; and

the institution comprises a financial institution storing data associated with the user.

8. A method of processing a data access request, the method comprising:

receiving, at an apparatus of an institution, a data access request from a communication device and via a network, the data access request relating to a third party application registered with the institution via a third party aggregator and to a user associated with the communication device;

generating, at the apparatus of the institution and based on the received data access request, a revocable 1:1:1 token that authorizes data sharing for a specific combination of the third party application, the third party aggregator, and the institution for the user associated with the communication device; and

managing, in conjunction with a server of the institution associated with the apparatus of the institution, third party application connectivity of a plurality of third party applications based on tracking associated revocable 1:1:1 tokens in a plurality of access tokens, each revocable 1:1:1 token having a different access period for the specific combination of the third party application, the third party aggregator, and the institution.

9. The method of claim 8 , further comprising:

transmitting, from the apparatus of the institution, the revocable 1:1:1 token for storage in a token database.

10. The method of claim 8 , further comprising:

transmitting, from the apparatus of the institution, the revocable 1:1:1 token and a user identifier associated with the user, for storage in a token database to associate the revocable 1:1:1 token with a user-specific data access request.

11. The method of claim 8 , further comprising:

Initiating, by the apparatus of the institution, storage of the 1:1:1 token in a token database associated with the institution specified in the 1:1:1 token.

12. The method of claim 8 , further comprising: providing, in conjunction with the server of the institution in communication with the apparatus of the institution, a dashboard configured to enable a user to individually remove the third party application from data sharing based on the generated 1:1:1 token.

13. The method of claim 8 , further comprising: generating, in conjunction with the server of the institution in communication with the apparatus of the institution, the revocable 1:1:1 token independent of the third party aggregator.

14. The method of claim 8 , wherein:

the access request comprises an open banking access request associated with the user; the third party application comprises a third party financial application; and

the institution comprises a financial institution storing data associated with the user.

15. A system configured for processing a data access request, the system being a system of an institution and comprising:

a processor configured to receive a data access request from a communication device and via a network, the data access request relating to a third party application registered with the institution via a third party aggregator and to a user associated with the communication device; and

a server associated with the institution and in communication with the processor and configured to generate, based on the received data access request, a revocable 1:1:1 token that authorizes data sharing for a specific combination of the third party application, the third party aggregator, and the institution for the user associated with the communication device; and

electronic storage configured to store a plurality of access tokens including the revocable 1:1:1 token generated by the server of the institution

wherein the processor and the server of the institution cooperate to: manage third party application connectivity of a plurality of third party applications based on tracking associated revocable 1:1:1 tokens in a plurality of access tokens stored in the electronic storage, each revocable 1:1:1 token having a different access period for the specific combination of the third party application, the third party aggregator, and the institution.

16. The system of claim 15 , wherein the processor and the server of the institution cooperate to:

provide a dashboard configured to enable a user to individually remove the third party application from data sharing based on the generated 1:1:1 token.

17. The system of claim 15 , wherein the processor and the server of the institution cooperate to:

transmit the revocable 1:1:1 token and a user identifier associated with the user, for storage in the electronic storage to associate the revocable 1:1:1 token with a user-specific data access request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2024
From: BHAT, SHISHIR DATTATRAYA; FURLONG, MARCUS EDWARD; KANCZUGA, KATHERINE; SEETHARAMAN, SUMATHI
To: THE TORONTO-DOMINION BANK
Reel/Frame 067768/0749 →
Continuity (1)
Related Publication 20230096672A1 · Mar 30, 2023