IP Library › Granted Patent US 12,284,190
Granted Patent B2
US 12,284,190 · App. 18/474,748 · Granted Apr 22, 2025

Systems and methods for authenticating data access requests

Inventors: Denny Devasia Kuruvilla (Toronto, CA); Esli Gjini (Etobicoke, CA); Sarah Reeve (Toronto, CA); Matija Bosnjakovic (Oakville, CA); Guy Dagmara (Toronto, CA); Jaspal Singh Samra (Brampton, CA); Abhiney Natarajan (Stoney Creek, CA); Haobin Li (Kitchener, CA); Richard Yu (Mississauga, CA); Md Abdur Razzak Chowdhury (Mississauga, CA); Dani Kartikay (Brampton, CA); Ryan Wu (Vaughan, CA); Andrey Petrov (Toronto, CA); Peter Horvath (Toronto, CA); Prashanth Dappula (King City, CA); Sivashanthan Sivapalan (Markham, CA); Nolan Glynn-Udrow (Mississauga, CA)
Assignee: The Toronto-Dominion Bank
H04L63/108H04L63/0428H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,190
App. No.
18/474,748
Granted
Apr 22, 2025
Kind
B2
Abstract

A computer-implemented method is disclosed. The method includes: authenticating a user for login to a service for a first authenticated user session; in response to authenticating the user, sending, to a client device associated with the user, a first data string associated with a first validity period; receiving, from the client device after expiry of the first authenticated user session, a data access request to access protected data, the data access request including the first data string; validating the first data string based on checking the first validity period; and in response to determining that the first data string is valid, transmitting, to the client device, a data access response including at least a subset of the requested protected data.

Claims (44)

1. A computing system, comprising:

a processor; and

a memory coupled to the processor, the memory storing instructions that, when executed by the processor, configure the processor to:

authenticate a user for login to a service for a first authenticated user session;

in response to authenticating the user, send, to a client device associated with the user, a first data string associated with a first validity period;

receive, from the client device after expiry of the first authenticated user session, a data access request to access protected data, the data access request including the first data string;

validate the first data string based on checking the first validity period; and

in response to determining that the first authenticated user session has expired and that the first data string is valid, transmit, to the client device, a data access response including at least a subset of the requested protected data.

2. The computing system of claim 1 , wherein the instructions, when executed, further configure the processor:

in response to determining that the first data string is not valid, transmit, to the client device, an instruction to request login credentials from the user of the client device.

3. The computing system of claim 1 , wherein the first validity period defines an expiry date set as a predetermined number of days from a time of receipt of a login request to log the user in to the service.

4. The computing system of claim 1 , wherein the instructions, when executed, further configure the processor to encrypt the first data string prior to sending the first data string to the client device, and wherein validating the first data string comprises decrypting the encrypted first data string.

5. The computing system of claim 1 , wherein the first data string comprises a version identifier that is stored in the memory, and wherein validating the first data string is based on checking a version associated with the first data string.

6. The computing system of claim 1 , wherein the instructions, when executed, further configure the processor to:

authenticate the user for login to the service for a second authenticated user session subsequent to the first authenticated user session;

in response to authenticating the user for the second authenticated user session, generate a second data string different from the first data string; and

send, to the client device, the second data string and an instruction to replace any currently valid data string stored at the client device with the second data string.

7. The computing system of claim 1 , wherein the data access response includes at least the subset of the requested protected data in response to determining that access of the protected data is a permitted operation in a non-authenticated user session.

8. The computing system of claim 1 , wherein validating the first data string comprises determining that a current date falls within the first validity period.

9. The computing system of claim 1 , wherein the data access request comprises a request to retrieve real-time quotes for one or more tradeable objects, and wherein the instructions, when executed, further configure the processor to transmit, to a remote data source, a query for real-time quotes data.

10. The computing system of claim 1 , wherein the first data string is associated with a predetermined set of operations, and wherein the instructions, when executed, further configure the processor to:

receive, via the communications module from the client device, a request to perform a first operation; and

in response to determining that the first operation is not among the predetermined set of operations associated with the first data string, transmit, to the client device, an instruction to request login credentials from a user of the client device.

11. A computer-implemented method, comprising:

authenticating a user for login to a service for a first authenticated user session;

in response to authenticating the user, sending, to a client device associated with the user, a first data string associated with a first validity period;

receiving, from the client device after expiry of the first authenticated user session, a data access request to access protected data, the data access request including the first data string;

validating the first data string based on checking the first validity period; and

in response to determining that the first authenticated user session has expired and that the first data string is valid, transmitting, to the client device, a data access response including at least a subset of the requested protected data.

12. The method of claim 11 , further comprising:

in response to determining that the first data string is not valid, transmitting, to the client device, an instruction to request login credentials from the user of the client device.

13. The method of claim 11 , wherein the first validity period defines an expiry date set as a predetermined number of days from a time of receipt of a login request to log the user in to the service.

14. The method of claim 11 , further comprising encrypting the first data string prior to sending the first data string to the client device, and wherein validating the first data string comprises decrypting the encrypted first data string.

15. The method of claim 11 , wherein the first data string comprises a version identifier that is stored in the memory, and wherein validating the first data string is based on checking a version associated with the first data string.

16. The method of claim 11 , further comprising:

authenticating the user for login to the service for a second authenticated user session subsequent to the first authenticated user session;

in response to authenticating the user for the second authenticated user session, generating a second data string different from the first data string; and

sending, to the client device, the second data string and an instruction to replace any currently valid data string stored at the client device with the second data string.

17. The method of claim 11 , wherein the data access response includes at least the subset of the requested protected data in response to determining that access of the protected data is a permitted operation in a non-authenticated user session.

18. The method of claim 11 , wherein validating the first data string comprises determining that a current date falls within the first validity period.

19. The method of claim 11 , wherein the data access request comprises a request to retrieve real-time quotes for one or more tradeable objects, and wherein the instructions, when executed, further configure the processor to transmit, to a remote data source, a query for real-time quotes data.

20. The method of claim 11 , wherein the first data string is associated with a predetermined set of operations, and wherein the method further comprises:

receiving, from the client device, a request to perform a first operation;

in response to determining that the first operation is not among the predetermined set of operations associated with the first data string, transmitting, to the client device, an instruction to request login credentials from a user of the client device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2023
From: KURUVILLA, DENNY DEVASIA; GJINI, ESLI; REEVE, SARAH; BOSNJAKOVIC, MATIJA; DAGMARA, GUY; SAMRA, JASPAL SINGH; NATARAJAN, ABHINEY; LI, HAOBIN; YU, RICHARD; CHOWDHURY, MD ABDUR RAZZAK; KARTIKAY, DANI; WU, RYAN; PETROV, ANDREY; HORVATH, PETER; DAPPULA, PRASHANTH; SIVAPALAN, SIVASHANTHAN; GLYNN-UDROW, NOLAN
To: THE TORONTO-DOMINION BANK
Reel/Frame 065225/0519 →
Continuity (3)
Continuation 17583315 · Jan 25, 2022
Continuation 16520505 · Jul 24, 2019
Related Publication 20240015166A1 · Jan 11, 2024
References Cited (29)
US 7415715B2 · Fradkov et al. · 2008 [cited by applicant]
US 7761313B1 · Brown et al. · 2010 [cited by applicant]
US 8250102B2 · Madhavarapu et al. · 2012 [cited by applicant]
US 8688559B2 · Calman et al. · 2014 [cited by applicant]
US 8799136B2 · Brady et al. · 2014 [cited by applicant]
US 8881229B2 · Barton et al. · 2014 [cited by applicant]
US 9002907B2 · San Martin et al. · 2015 [cited by applicant]
US 9148460B1 · Sun et al. · 2015 [cited by applicant]
US 9367868B2 · McNall et al. · 2016 [cited by applicant]
US 9369457B2 · Grajek et al. · 2016 [cited by applicant]
US 9490984B2 · Leicher et al. · 2016 [cited by applicant]
US 9549032B2 · Boyette et al. · 2017 [cited by applicant]
US 9979715B2 · Cicchitto et al. · 2018 [cited by applicant]
US 10262001B2 · Faith et al. · 2019 [cited by applicant]
US 20080065510A1 · Yu · 2008 [cited by applicant]
US 20130262858A1 · Neuman · 2013 [cited by examiner]
US 20150161583A1 · Phelps et al. · 2015 [cited by applicant]
US 20150161695A1 · Koby et al. · 2015 [cited by applicant]
US 20150379519A1 · Schultz et al. · 2015 [cited by applicant]
US 20170099280A1 · Goel · 2017 [cited by examiner]
US 20190114160A1 · Yehuda et al. · 2019 [cited by applicant]
CN 108573448 · 2018 [cited by applicant]
KR 20010105424 · 2001 [cited by applicant]
CA Office Action dated Feb. 27, 2024; Canadian Patent Application No. 3,050,492. [cited by applicant]
CIPO: CA Office Action relating to CA application No. 3,050,492, dated Mar. 31, 2023. [cited by applicant]
“Citi Launches Citi Mobile Snapshot Across the U.S”; https://www.citigroup.com/citi/news/2014/140521a.htm; Located via Google May 21, 2014. [cited by applicant]
N/A;“How to Get Real-Time Quotes”; https://www.fidelity.com/customer-service/how-to-get-real-time-quotes; Found via Google Scholar; available at least as early as May 2, 2019. [cited by applicant]
Christian Zibreg; “Yahoo redesigns Finance app for real-time”; Found via Google Scholar Jul. 30, 2014. [cited by applicant]
Editorial Staff; “Money Management Executive, Financial Planning”; https://www.financial-planning.com/news/morningstar-adds-mutual-fund-data-to-quotespeed; Oct. 11, 2010. [cited by applicant]