IP Library › Granted Patent US 12,744,831
Granted Patent B2
US 12,744,831 · App. 19/027,186 · Granted Sep 22, 2026

Customer identity and access management

Inventors: John Bruno (Scottsdale, AZ); Thirupathirao Modukuri (Chandler, AZ); Mahesh Tawari (Fremont, CA)
Assignee: Wells Fargo Bank, N.A.
H04L67/306G06F8/36G06F8/38H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,831
App. No.
19/027,186
Granted
Sep 22, 2026
Kind
B2
Abstract

An example system for managing identity and access within a federated digital ecosystem includes functionality to store and manage identity data associated with users across federated identity domains, which represent distinct organizational boundaries. The system provides authentication and access control services based on open standards and enforces a unified policy framework for access control, entitlements, and consent management. A marketplace stores and manages reusable, modular micro frontend experiences, enabling their retrieval and reuse across application experiences. The system dynamically generates personalized user experiences by assembling micro frontend experiences based on contextual rules and user preferences, integrating identity data to tailor interactions across channels, including web, mobile, and embedded third-party systems. Communication and synchronization ensure consistent propagation of identity updates, including user attributes, entitlements, and consent settings, across federated domains and user interfaces, enabling secure, adaptive, and scalable operations.

Claims (36)

1 . A system, comprising:

at least one processor; and

non-transitory computer-readable storage storing instructions that, when executed by the at least one processor, cause the system to:

store and manage identity data associated with a plurality of users associated with one or more federated identity domains representing a distinct organizational boundary for managing identity and access;

provide authentication and access control services based on one or more publicly available protocols;

implement a unified policy framework for enforcing access control, user entitlements, and consent management across the one or more federated identity domains;

store and manage a repository of micro frontend experiences in a marketplace, wherein each of the micro frontend experiences is a reusable, modular user interface component conformant with a predefined platform framework, and wherein the marketplace is configured to enable retrieval and reuse of the micro frontend experiences across a plurality of application experiences associated with the one or more federated identity domains;

dynamically generate user experiences by assembling the micro frontend experiences retrieved from the marketplace based on contextual rules and user preferences;

integrate identity and access management data associated with at least one federated identity domain of the one or more federated identity domains to personalize the user experiences across one or more channels, the one or more channels including web, mobile, and embedded third-party systems; and

manage communication and synchronization to ensure that updates to the identity data, including user attributes, the user entitlements, and consent settings, are consistently propagated across the one or more federated identity domains, and that such updates are reflected in the retrieval, assembly, and presentation of the user experiences.

2 . The system of claim 1 , wherein the system is further configured to support multi-factor authentication for verifying user identity across the one or more federated identity domains.

3 . The system of claim 1 , wherein the unified policy framework includes at least one of: (a) role-based access control, which associates predefined roles with specific sets of permissions to grant or restrict access to resources within the one or more federated identity domains; or (b) attribute-based access control, which evaluates user-specific attributes, including user location, device type, or security clearance, to dynamically determine access permissions within the one or more federated identity domains.

4 . The system of claim 1 , wherein the system is configured to manage the identity data by synchronizing user credentials, roles, and entitlements across the one or more federated identity domains, ensuring consistent identity attributes across the one or more channels.

5 . The system of claim 1 , wherein the system is configured to implement an adaptive authentication mechanism, wherein one or more authentication requirements dynamically adjust based on contextual factors, including user behavior, geographic location, or a sensitivity of an accessed resource.

6 . The system of claim 1 , wherein the identity data includes a user role, entitlement, and channel-specific preferences, and wherein the system ensures that the identity data conforms to access policies defined within the unified policy framework.

7 . The system of claim 1 , wherein the system is configured to enable users to specify and update permissions for sharing specific identity attributes across the one or more federated identity domains.

8 . The system of claim 1 , further comprising a notification engine configured to alert users of changes to the consent settings, the user entitlements, or authentication activity within the one or more federated identity domains.

9 . The system of claim 1 , wherein the system is further configured to integrate with regulatory compliance systems and is configured to maintain an audit log of authentication attempts, access requests, and consent updates to ensure compliance with data privacy regulations applicable to the one or more federated identity domains.

10 . The system of claim 1 , wherein the marketplace is further configured to provide metadata tagging for the micro frontend experiences, enabling enhanced discoverability and reuse of the micro frontend experiences across the one or more federated identity domains.

11 . A method for managing identity and access in a federated digital ecosystem, comprising:

storing and managing identity data associated with a plurality of users, wherein each of the plurality of users is associated with one or more federated identity domains, each of the one or more federated identity domains representing a distinct organizational boundary for managing identity and access;

providing authentication and access control services based on one or more publicly available protocols;

implementing a unified policy framework for enforcing access control, user entitlements, and consent management across the one or more federated identity domains;

storing and managing a repository of micro frontend experiences in a marketplace, wherein each of the micro frontend experiences is a reusable, modular user interface component conformant with a predefined platform framework, and enabling retrieval and reuse of the micro frontend experiences across a plurality of application experiences associated with the one or more federated identity domains;

dynamically generating user experiences by assembling the micro frontend experiences retrieved from the marketplace based on contextual rules and user preferences;

integrating identity and access management data associated with at least one federated identity domain to personalize the user experiences across one or more channels, the one or more channels including web, mobile, and embedded third-party systems; and

managing communication and synchronization to ensure that updates to the identity data, including user attributes, the user entitlements, and consent settings, are consistently propagated across the one or more federated identity domains, and that such updates are reflected in retrieval, assembly, and presentation of the user experiences.

12 . The method of claim 11 , further comprising supporting multi-factor authentication for verifying user identity across the one or more federated identity domains.

13 . The method of claim 11 , wherein the unified policy framework includes at least one of: (a) role-based access control, which associates predefined roles with specific sets of permissions to grant or restrict access to resources within the one or more federated identity domains; or (b) attribute-based access control, which evaluates user-specific attributes, including user location, device type, or security clearance, to dynamically determine access permissions within the one or more federated identity domains.

14 . The method of claim 11 , further comprising synchronizing user credentials, roles, and entitlements across the one or more federated identity domains to ensure consistent identity attributes across the one or more channels.

15 . The method of claim 11 , further comprising implementing an adaptive authentication mechanism, wherein one or more authentication requirements dynamically adjust based on contextual factors, including user behavior, geographic location, or a sensitivity of an accessed resource.

16 . The method of claim 11 , wherein the identity data includes a user role, entitlement, and channel-specific preferences, and further comprising ensuring that the identity data conforms to access policies defined within the unified policy framework.

17 . The method of claim 11 , further comprising enabling users to specify and update permissions for sharing specific identity attributes across the one or more federated identity domains.

18 . The method of claim 11 , further comprising alerting users of changes to the consent settings, the user entitlements, or authentication activity within the one or more federated identity domains via a notification engine.

19 . The method of claim 11 , further comprising integrating with regulatory compliance systems and maintaining an audit log of authentication attempts, access requests, and consent updates to ensure compliance with data privacy regulations applicable to the one or more federated identity domains.

20 . The method of claim 11 , further comprising providing metadata tagging for the micro frontend experiences within the marketplace, enabling enhanced discoverability and reuse of the micro frontend experiences across the one or more federated identity domains.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2025
From: BRUNO, JOHN; MODUKURI, THIRUPATHIRAO; TAWARI, MAHESH
To: WELLS FARGO BANK, N.A.
Reel/Frame 072653/0378 →
Continuity (1)
Related Publication 20260214146A1 · Jul 23, 2026
References Cited (61)
US 7610233B1 · Leong · 2009 [cited by examiner]
US 7761794B1 · Chari et al. · 2010 [cited by applicant]
US 9104392B1 · Dunagan et al. · 2015 [cited by applicant]
US 10230815B2 · Pinko · 2019 [cited by applicant]
US 10439898B2 · Ranjekar · 2019 [cited by applicant]
US 10983782B1 · Mitra et al. · 2021 [cited by applicant]
US 11086698B1 · Nitsopoulos · 2021 [cited by applicant]
US 11137887B1 · Garibaldi et al. · 2021 [cited by applicant]
US 11150791B1 · Garibaldi et al. · 2021 [cited by applicant]
US 11216602B2 · Bourhani et al. · 2022 [cited by applicant]
US 11411800B1 · Murugesan et al. · 2022 [cited by applicant]
US 11475513B2 · Bowie · 2022 [cited by examiner]
US 12517725B2 · Belardo · 2026 [cited by examiner]
US 20020196277A1 · Bushey et al. · 2002 [cited by applicant]
US 20030126079A1 · Roberson et al. · 2003 [cited by applicant]
US 20070255653A1 · Tumminaro et al. · 2007 [cited by applicant]
US 20090150536A1 · Wolman et al. · 2009 [cited by applicant]
US 20130207988A1 · Artigue et al. · 2013 [cited by applicant]
US 20150379581A1 · Bruno et al. · 2015 [cited by applicant]
US 20160034258A1 · Wijngaard et al. · 2016 [cited by applicant]
US 20160283833A1 · Peek · 2016 [cited by applicant]
US 20160335454A1 · Choe et al. · 2016 [cited by applicant]
US 20160350197A1 · Amichai et al. · 2016 [cited by applicant]
US 20170024308A1 · Knoulich · 2017 [cited by applicant]
US 20180284975A1 · Carrier et al. · 2018 [cited by applicant]
US 20180307390A1 · Fang et al. · 2018 [cited by applicant]
US 20190347143A1 · Carteri et al. · 2019 [cited by applicant]
US 20200204618A1 · Agarwal et al. · 2020 [cited by applicant]
US 20200285516A1 · Darling et al. · 2020 [cited by applicant]
US 20200387965A1 · Cella · 2020 [cited by applicant]
US 20210117571A1 · Prakash et al. · 2021 [cited by applicant]
US 20210132962A1 · Makhija et al. · 2021 [cited by applicant]
US 20210192106A1 · Bourhani et al. · 2021 [cited by applicant]
US 20210248205A1 · Tank et al. · 2021 [cited by applicant]
US 20210294717A1 · Wang et al. · 2021 [cited by applicant]
US 20210326396A1 · Chugh et al. · 2021 [cited by applicant]
US 20210365445A1 · Robell et al. · 2021 [cited by applicant]
US 20220114214A1 · Reddymakireddy et al. · 2022 [cited by applicant]
US 20220283805A1 · Dasa et al. · 2022 [cited by applicant]
US 20220300524A1 · Banerjee et al. · 2022 [cited by applicant]
US 20220358240A1 · Neal et al. · 2022 [cited by applicant]
US 20220382522A1 · Heynemann Nascentes Da Silva et al. · 2022 [cited by applicant]
US 20220383284A1 · Rastogi et al. · 2022 [cited by applicant]
US 20220405152A1 · Edamadaka et al. · 2022 [cited by applicant]
US 20230009811A1 · Bakos et al. · 2023 [cited by applicant]
US 20230036980A1 · Chen et al. · 2023 [cited by applicant]
US 20230110520A1 · Ding et al. · 2023 [cited by applicant]
US 20230251835A1 · Manohar et al. · 2023 [cited by applicant]
US 20230368288A1 · Bruno et al. · 2023 [cited by applicant]
US 20240103939A1 · Singh et al. · 2024 [cited by applicant]
US 20240220217A1 · Hori · 2024 [cited by examiner]
US 20240394021A1 · Bhargava · 2024 [cited by examiner]
US 20260037947A1 · Angel · 2026 [cited by examiner]
US 20260058027A1 · Moyer · 2026 [cited by examiner]
WO 2018097928A1 · 2018 [cited by applicant]
WO 2020118457A1 · 2020 [cited by applicant]
WO 2022221610A1 · 2022 [cited by applicant]
U.S. Appl. No. 17/658,015, filed Apr. 5, 2022. [cited by applicant]
U.S. Appl. No. 63/268,935, filed Mar. 7, 2022. [cited by applicant]
U.S. Appl. No. 17/663,572, filed May 16, 2022. [cited by applicant]
U.S. Appl. No. 18/174,054, filed Feb. 24, 2023. [cited by applicant]