IP Library › Granted Patent US 12,323,535
Granted Patent B2
US 12,323,535 · App. 18/196,230 · Granted Jun 3, 2025

Dynamic management and implementation of consent and permissioning protocols using container-based applications

Inventors: Milos Dunjic (Oakville, CA); Arthur Carroll Chow (Markham, CA); David Samuel Tax (Toronto, CA); Armon Rouhani (Toronto, CA); Keith Sanjay Ajmani (Toronto, CA); Gregory Albert Kliewer (Barrie, CA); Anthony Haituyen Nguyen (Toronto, CA); Martin Albert Lozon (London, CA); Kareem El-Onsi (Toronto, CA); Ashkan Alavi-Harati (Markham, CA); Arun Victor Jagga (Mississauga, CA)
Assignee: The Toronto-Dominion Bank
H04L9/3247H04L9/30H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,535
App. No.
18/196,230
Granted
Jun 3, 2025
Kind
B2
Abstract

The disclosed exemplary embodiments include computer-implemented systems, devices, apparatuses, and processes that dynamically implement and manage consent and permissioning protocols using container-based applications. By way of example, a device may receive, through a programmatic interface, a first request for an element of data generated by an executed application program. When the first request is consistent with consent data associated the executed application program, the device may obtain the requested data element and a digital signature applied to the requested data element by a computing system. Based on a verification of the applied digital signature, the device may generate and present a representation of the requested data element within a digital interface, along with an interface element that confirms the verification of the digital signature.

Claims (72)

1. A device, comprising:

a communications interface;

a memory storing instructions; and

at least one processor coupled to the communications interface and to the memory, the at least one processor being configured to execute the instructions to:

receive a request for an element of data from an application program executed by the at least one processor, the request being generated by the executed application program, and the request comprising a first digital token associated with the executed application program;

load a second digital token from a portion of the memory that is inaccessible to the executed application program; and

when the first digital token is consistent with the second digital token, and when the request is consistent with a level or type of access granted to the executed application program, obtain the data element and a digital signature applied to the data element, and based on a verification of the digital signature, perform operations that present a representation of the data element within a digital interface, the digital interface comprising an interface element that confirms the verification of the digital signature, and the interface element comprising at least one of an icon, a glyph, or a digital image.

2. The device of claim 1 , wherein:

the device further comprises a display unit coupled to the at least one processor; and

the at least one processor is further configured to present, via the display unit, the representation of the data element within the digital interface, when the first digital token is consistent with the second digital token, and when the request is consistent with the level or type of access granted to the executed application program.

3. The device of claim 1 , wherein

the at least one processor is further configured to execute the instructions to verify the applied digital signature using a public cryptographic key associated with the device.

4. The device of claim 1 , wherein:

the first digital token is maintained within a portion of the memory that is accessible to the executed application program; and

the at least one processor is further configured to execute the instructions to receive the request from the executed application program through a programmatic interface.

5. The device of claim 1 , wherein the at least one processor is further configured to execute the instructions to:

determine that the first digital token is consistent with the second digital token;

load consent data from an additional portion of the memory that is inaccessible to the executed application program, the consent data specifying the level or type of access granted to the executed application program; and

based on the consent data, determine that the request is consistent with the level or type of access granted to the executed application program.

6. The device of claim 1 , wherein:

the request comprises an identifier of an operation involving the data element; and

the at least one processor is further configured to execute the instructions to:

when the first digital token is consistent with the second digital token, obtain consent data specifying the level or type of access granted to the executed application program;

based on the identifier and the consent data, determine that a performance of the operation is consistent with the level or type of access granted to the executed application program; and

perform the operation involving the data element in accordance with the request.

7. The device of claim 6 , wherein the operation comprises the presentation of the representation of the data element within the digital interface.

8. The device of claim 6 , wherein:

the operation comprises provisioning the data element to the executed application program; and

the at least one processor is further configured to execute the instructions to:

based on the identifier and the consent data, determine that the executed application program (i) is permitted to access the data element and (ii) is not permitted to distribute the data element to at least one of an additional computing system or an additional executed application program;

perform operations that modify the data element in accordance with rubric data established by a centralized authority; and

provision the modified data element to the executed application program through a programmatic interface.

9. The device of claim 1 , wherein the at least one processor is further configured to execute the instructions to, when the first digital token is consistent with the second digital token and when the request is consistent with the level or type of access granted to the executed application program, obtain the data element from at least one of a computing system or an additional portion of the memory inaccessible to the executed application program.

10. A computer-implemented method, comprising:

receiving, using at least one processor, a request for an element of data, the request being generated by an application program executed by the at least one processor, and the request comprising a first digital token associated with the executed application program;

loading, using the at least one processor, a second digital token from a portion of a data repository that is inaccessible to the executed application program; and

when the first digital token is consistent with the second digital token, and when the request is consistent with a level or type of access granted to the executed application program, obtaining the data element and a digital signature applied to the data element using the at least one processor, and based on a verification of the digital signature, performing operations, using the at least one processor, that present a representation of the data element within a digital interface, the digital interface comprising an interface element that confirms the verification of the digital signature, and the interface element comprising at least one of an icon, a glyph, or a digital image.

11. A device, comprising:

a communications interface;

a memory storing instructions; and

at least one processor coupled to the communications interface and to the memory, the at least one processor being configured to execute the instructions to:

receive, from an application program executed by the at least one processor, a request to perform an operation involving an element of data, the request being generated by the executed application program, and the request comprising a first digital token associated with the executed application program and an identifier of the operation;

load a second digital token from a portion of the memory that is inaccessible to the executed application program; and

when the first digital token is consistent with the second digital token, and when the operation is consistent with a level or type of access granted to the executed application program, obtain the data element and a digital signature applied to the data element, and based on a verification of the digital signature, perform the operation involving the data element and present an interface element that confirms the verification of the digital signature within a digital interface, and the interface element comprising at least one of an icon, a glyph, or a digital image.

12. The device of claim 11 , wherein:

the first digital token is maintained within a portion of the memory that is accessible to the executed application program; and

the at least one processor is further configured to execute the instructions to receive the request from the executed application program through a programmatic interface.

13. The device of claim 11 , wherein the at least one processor is further configured to execute the instructions to:

determine that the first digital token is consistent with the second digital token;

load consent data from an additional portion of the memory that is inaccessible to the executed application program, the consent data specifying the level or type of access granted to the executed application program; and

based on the consent data and on the identifier, determine that the operation is consistent with the level or type of access granted to the executed application program.

14. The device of claim 11 , wherein the at least one processor is further configured to:

based on a verification of the applied digital signature, store the data element within an additional portion of the memory that is inaccessible to the executed application program.

15. The device of claim 11 , wherein:

the operation comprises presenting a representation of the data element within the digital interface; and

the at least one processor is further configured to execute the instructions to:

load consent data from an additional portion of the memory that is inaccessible to the executed application program, the consent data specifying the level or type of access granted to the executed application program;

based on the consent data and on the identifier, determine that the presentation of the representation of the data element within the digital interface is consistent with the level or type of access granted to the executed application program; and

perform operations that generate the representation of the data element and present the representation within the digital interface.

16. The device of claim 15 , wherein

the at least one processor is further configured to execute the instructions to verify the digital signature applied to the data element using a public cryptographic key associated with the device; and.

17. The device of claim 11 , wherein:

the operation comprises provisioning the data element to the executed application program; and

the at least one processor is further configured to execute the instructions to:

load consent data from an additional portion of the memory that is inaccessible to the executed application program, the consent data specifying the level or type of access granted to the executed application program;

based on the consent data and on the identifier, determine that the provisioning of the data element to the executed application program is consistent with the level or type of access granted to the executed application program; and

perform operations that provision the data element to the executed application program through a programmatic interface.

18. The device of claim 17 , wherein the at least one processor is further configured to execute the instructions to:

based on the identifier and the consent data, determine that the executed application program (i) is permitted to access the data element and (ii) is not permitted to distribute the data element to at least one of an additional computing system or an additional executed application program;

perform operations that modify at least a portion of the data element in accordance with rubric data established by a centralized authority; and

provision the modified data element to the executed application program through the programmatic interface.

19. The device of claim 11 , wherein the at least one processor is further configured to execute the instructions to, when the first digital token is consistent with the second digital token, and when the operation is consistent with the level or type of access granted to the executed application program, obtain the data element from at least one of a computing system or an additional portion of the memory that is inaccessible to the executed application program.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2023
From: DUNJIC, MILOS; CHOW, ARTHUR CARROLL; TAX, DAVID SAMUEL; ROUHANI, ARMON; AJMANI, KEITH SANJAY; KLIEWER, GREGORY ALBERT; NGUYEN, ANTHONY HAITUYEN; LOZON, MARTIN ALBERT; EL-ONSI, KAREEM; ALAVI-HARATI, ASHKAN; JAGGA, ARUN VICTOR
To: THE TORONTO-DOMINION BANK
Reel/Frame 063620/0172 →
Continuity (2)
Continuation 16431090 · Jun 4, 2019
Related Publication 20230291571A1 · Sep 14, 2023
References Cited (28)
US 5619671A · Bryant et al. · 1997 [cited by applicant]
US 9225511B1 · Wharton et al. · 2015 [cited by applicant]
US 10733685B1 · Gailloux et al. · 2020 [cited by applicant]
US 10749677B2 · Agrawal et al. · 2020 [cited by applicant]
US 11689370B2 · Dunjic · 2023 [cited by examiner]
US 20040054908A1 · Circenis et al. · 2004 [cited by applicant]
US 20060077904A1 · Brandenburg · 2006 [cited by examiner]
US 20090037994A1 · Buss · 2009 [cited by examiner]
US 20120240211A1 · Counterman et al. · 2012 [cited by applicant]
US 20130055347A1 · Chawla et al. · 2013 [cited by applicant]
US 20130086645A1 · Srinivasan et al. · 2013 [cited by applicant]
US 20130173642A1 · Oliver · 2013 [cited by applicant]
US 20160096508A1 · Oz · 2016 [cited by examiner]
US 20160132214A1 · Koushik · 2016 [cited by examiner]
US 20160134596A1 · Kovacs et al. · 2016 [cited by applicant]
US 20170085438A1 · Link et al. · 2017 [cited by applicant]
US 20170223005A1 · Birgisson · 2017 [cited by examiner]
US 20170330145A1 · Studnicka · 2017 [cited by examiner]
US 20180068130A1 · Chan et al. · 2018 [cited by applicant]
US 20180083971A1 · Brown et al. · 2018 [cited by applicant]
US 20180109532A1 · Cairns et al. · 2018 [cited by applicant]
US 20180115551A1 · Cole · 2018 [cited by applicant]
US 20180295126A1 · Gilpin · 2018 [cited by examiner]
US 20180359238A1 · Appiah · 2018 [cited by examiner]
US 20190188704A1 · Grendon et al. · 2019 [cited by applicant]
US 20190380020A1 · Pellegrini · 2019 [cited by examiner]
US 20200027067A1 · Hertzog et al. · 2020 [cited by applicant]
WO WO2007080588A1 · 2007 [cited by applicant]