Systems and methods for data access control using short-range transceivers

The system uses a short-range transceiver to securely link accounts without disclosing identifiers, addressing data access control issues and enhancing security and user experience.

JP7751973B2Active Publication Date: 2025-10-09CAPITAL ONE SERVICES LLC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021020004
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-04-30
Filing Date
2021-02-10
Publication Date
2025-10-09
Estimated Expiration
2041-02-10

AI Technical Summary

Technical Problem

Existing systems fail to provide users with effective control over their data access, especially in scenarios where multiple entities manage user information with varying policies, leading to potential breaches and unauthorized access due to compromised login credentials.

Method used

A data access control system using a short-range transceiver, such as a contactless card, interacts with client devices to link accounts without disclosing specific identifiers, enabling secure account linking through token exchange and approval processes.

Benefits of technology

Enhances data security and fraud prevention while improving the user experience by allowing controlled access to account information based on user-defined parameters.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007751973000001
    Figure 0007751973000001
  • Figure 0007751973000002
    Figure 0007751973000002
  • Figure 0007751973000003
    Figure 0007751973000003
Patent Text Reader

Abstract

To provide a system and a method for controlling data access through the interaction between a contactless card and a client device, which reduces the risk of user information to be stolen.SOLUTION: A method includes establishing a database that stores information for multiple accounts, receiving an account link request from a client device of a second account owner to link a first account to the second account, in which the account link request is generated in response to a tap action between a contactless card and the client device, transmitting a link approval request to approve the account link request to a client device of a first account owner, receiving a link approval message generated in response to an instruction from the first account owner to approve the account link request from the first account owner client device, and transmitting an account link to the second account owner client device.SELECTED DRAWING: Figure 1B
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates generally to user data control, and more particularly to exemplary systems and methods for active control of user access to data via interaction between short-range transceivers and client devices. [Background technology]

[0002] A typical user has several different accounts with one or more organizations (entities). When a user creates an account, the user typically provides a certain amount of personal identification information about the user and account access information, such as a username and password. Each entity may have, for example, different user data retention policies, different usage policies, and different user data sharing policies. Policies regarding the use of user information may further change without notice to the user. Furthermore, the owner of user information may change without notice to the user, often through a merger or acquisition of one entity by another.

[0003] Access to an account often relies on login credentials (e.g., username and password) to verify the cardholder's identity. However, if the login credentials are compromised, others may be able to access the user's account. Furthermore, the more entities or individuals with whom a user shares personal information, the greater the risk that a breach at any one entity will result in the theft of the user's information. Furthermore, a user may only want to share certain personal information with entities or individuals for limited purposes or for a limited time.

[0004] Therefore, it would be beneficial to provide exemplary systems and methods that allow users to control the use of their information to overcome at least some of the deficiencies described herein. Summary of the Invention

[0005] Aspects of the disclosed technology include systems and methods for controlling data access through interaction of a short-range transceiver, such as a contactless card, with a client device. Data access control can be provided in the context of account information, including processing a request to link a first account to a second account, through interaction of a short-range transceiver, such as a contactless card, with a client device, where the client device does not require disclosure of specific account identifier information or account login information to an individual or entity requesting access to the other individual's or entity's account data.

[0006] An embodiment of the present disclosure provides a data access control system comprising: a database storing information for a plurality of accounts, the database comprising a first account identifier and first account data for a first account associated with a first account holder and a second account identifier for a second account associated with a second account holder; a server configured to communicate over a network with a plurality of client devices, the server including a first client device associated with the first account holder and a second client device associated with the second account holder; a contactless card comprising a communications interface, a processor, and a memory, the memory storing applets and tokens, the contactless card being associated with the first account holder; and a client application comprising instructions for execution on at least one of the first client device or the second client device, the client application, when executed on the second client device, for accessing the contactless card and the second account holder. a processor in data communication with the server and the database configured to: receive a token from the contactless card in response to a tapping action between the client device and the contactless card; transmit the token and an account linking request to the server; link the first account to the second account; and receive an account linking confirmation message from the server including instructions to access the first account data; and, when executed on the first client device, transmit a linking approval message to the server approving the account linking request in response to a linking approval request from the server to approve the account linking request; the processor is configured to: receive the token and the account linking request from the second client device; identify the first account based on the token; transmit a linking approval request to the first client device to approve the account linking request; receive the linking approval message from the first client device approving the account linking request; and transmit the account linking confirmation message to the second client device including instructions to access the first account data;Provides a data access control system.

[0007] An embodiment of the present disclosure is a method for controlling data access, comprising: establishing a database storing information of a plurality of accounts, the database comprising, for a first account associated with a first account holder, a first account identifier, first account data, and data control parameters, and for a second account associated with a second account holder, a second account identifier; and receiving, via a network, from a client device of the second account holder, an account linking request to link the first account to the second account, the account linking request being generated in response to a tapping action between a contactless card and the second account holder client device, the account linking request involving a token stored on the contactless card, the contactless card being associated with the first account holder. a first account associated with the first account holder based on the token; identifying the first account based on the token; sending, via the network, a link approval request to a client device of the first account owner to approve the account linking request; receiving, via the network, a link approval message from the first account owner client device, the link approval message being generated in response to an instruction by the first account owner approving the account linking request; and sending, via the network, an account link confirmation message to a second account owner client device, the account link confirmation message confirming approval of the account linking request and providing instructions for accessing the first account data.

[0008] An embodiment of the present disclosure provides a method for controlling data access, the method comprising: establishing a database storing information of a plurality of accounts, the database comprising a first account identifier, first account data, and data control parameters for a first account associated with a first account holder, and a second account identifier for a second account associated with a second account holder; providing a contactless card comprising a communications interface, a processor, and a memory, the memory storing applets and tokens, the communications interface configured to support at least one of near field communication, Bluetooth, or Wi-Fi, the contactless card being associated with the first account holder; and executing the database on at least one of a first client device of the first account holder or a second client device of the second account holder. providing a client application comprising instructions, the client application being configured, when executed on the second client device, to: receive a token from the contactless card in response to a tap operation between the contactless card and the second client device; send the token and an account linking request to a server to link the first account to the second account; receive from the server an account linking confirmation message including instructions to access the first account data, wherein data access is provided according to the data control parameters; and, when executed on the first client device, determine a tap operation between the contactless card and the first client device, a tap operation responsive to a linking approval request to approve the account linking request, a tap operation indicating approval of the account linking request, and send a linking approval message to the server approving the account linking request.

[0009] Further features of the disclosed design and advantages offered thereby are described below and are explained in more detail below with reference to specific exemplary embodiments illustrated in the accompanying drawings. [Brief explanation of the drawings]

[0010] [Figure 1A] FIG. 1 is an illustration of a data access control system in accordance with one or more exemplary embodiments. [Figure 1B] FIG. 1 illustrates a sequence for providing data access control in accordance with one or more exemplary embodiments. [Figure 2] 1 illustrates components of a client device for use in a data access control system according to one or more exemplary embodiments. [Figure 3] 1 illustrates components of a short-range transceiver for use in a data access control system according to one or more exemplary embodiments. [Figure 4] FIG. 1 illustrates an interaction between a client device and a short-range transceiver used in a data access control system according to one or more exemplary embodiments. [Figure 5] FIG. 1 illustrates an interaction between a client device and a short-range transceiver used in a data access control system according to one or more exemplary embodiments. [Figure 6] 1 is a flowchart illustrating a method of data access control according to one or more exemplary embodiments. [Figure 7] 1 is a flowchart illustrating a method of data access control according to one or more exemplary embodiments. [Figure 8] 1 is a flowchart illustrating a method of data access control according to one or more exemplary embodiments. DETAILED DESCRIPTION OF THE INVENTION

[0011] The following description of the embodiments provides non-limiting representative examples that refer to numerals to particularly explain the features and teachings of different aspects of the present invention. It should be recognized that the described embodiments can be implemented separately or in combination with other embodiments from the description of the embodiments. Those skilled in the art who review the description of the embodiments should be able to learn and understand the different described aspects of the present invention. The description of the embodiments should facilitate understanding of the present invention so that other embodiments not specifically covered but within the knowledge of those skilled in the art who read the description of the embodiments will be understood to be consistent with the application of the present invention.

[0012] Exemplary embodiments of the disclosed system and method provide for controlling data access through the interaction of a short-range transceiver, such as a contactless card, with a client device. Data access control may be provided in the context of controlling access to account information. A request to link a first account to a second account may be processed through the interaction of a short-range transceiver, such as a contactless card, with a client device so as not to require the disclosure of specific account identifier information or account login information to an individual or entity requesting access to the other individual's or entity's account data. Advantages of the disclosed technology may include improved data security of account information, improved fraud prevention, and an improved user experience.

[0013] 1A shows a diagram illustrating a data access control system 100 according to one or more exemplary embodiments. As described further below, system 100 may include client device 101, client device 103, short-range transceiver 105, server 110, processor 120, and database 130. Client device 101 and client device 103 may communicate with server 110 via network 115. Although FIG. 1 shows certain components connected in a particular manner, system 100 may include additional or multiple components connected in various ways.

[0014] System 100 may include one or more client devices, such as client device 101 and / or client device 103, each of which may be a network-enabled computer. As referred to herein, a network-enabled computer may include a computing device or a communication device, including, for example, but not limited to, a server, a network appliance, a personal computer, a workstation, a telephone, a handheld PC, a personal digital assistant, a thin client, a fat client, an Internet browser, or other device. Each of client devices 101 and 103 may also be a mobile device. For example, mobile devices may include an Apple® iPhone®, iPod®, iPad®, or other mobile device running Apple's iOS® operating system, a device running Microsoft's Windows® Mobile operating system, a device running Google's Android® operating system, and / or other smartphones, tablets, or similar wearable mobile devices. Additional functionality that may be included in a client device, such as client device 101 and / or client device 103, is further described below with reference to FIG. 2.

[0015] System 100 may include one or more short-range transceivers, such as short-range transceiver 105. Short-range transceiver 105 may wirelessly communicate with client devices, such as client device 101 and / or client device 103, within a short-range communication range, such as, for example, near field communication (NFC). Short-range transceiver 105 may include, for example, a contactless card, a smart card, or may include devices having various form factors, such as a fob, pendant, or other device configured to communicate within a short-range communication range. In other embodiments, short-range transceiver 105 may be the same as or similar to client devices 101, 103. Additional functionality that may be included in a short-range transceiver, such as short-range transceiver 105, is further described below with reference to FIG. 3.

[0016] System 100 may include one or more servers 110. In some exemplary embodiments, server 110 may include one or more processors (e.g., microprocessors, etc.) coupled to memory. Server 110 may be configured as a central system, server, or platform for controlling and calling various data at different times to perform multiple workflow actions. Server 110 may be a dedicated server computer, such as a blade server, or may be a personal computer, laptop computer, notebook computer, palmtop computer, network computer, mobile device, or any processor-controlled device capable of supporting system 100.

[0017] Server 110 may be configured for data communication (e.g., via a connection, etc.) with one or more processors, such as processor 120. In some exemplary embodiments, server 110 may incorporate processor 120. In some exemplary embodiments, server 110 may be physically separate and / or remote from processor 120. Processor 120 may be configured to function as a back-end processor. Processor 120 may be configured for data communication (e.g., via a connection, etc.) with database 130 and / or server 110. Processor 120 may include one or more processing devices such as a microprocessor, a RISC processor, an ASIC, etc., along with associated processing circuitry. Processor 120 may include or be connected to memory that stores executable instructions and / or data. Processor 120 may communicate, send, or receive messages, requests, notifications, data, etc., from other devices, such as client devices 101 and / or 103, via server 110.

[0018] Server 110 may be configured for data communication (e.g., via a connection) with one or more databases, such as database 130. Database 130 may be a relational database or a non-relational database, or a combination of multiple databases. In some exemplary embodiments, server 110 may incorporate database 130. In some exemplary embodiments, database 130 may be physically separate and / or remote from server 110, located on another server, a cloud-based platform, or any storage device in data communication with server 110.

[0019] The connections between server 110, processor 120, and database 130 may be via any wired and / or wireless communication line, link, or network, or combination thereof, suitable for communication between these components. Such networks may include network 115 and / or one or more networks of the same or similar type as those described herein with reference to network 115. In some exemplary embodiments, the connections between server 110, processor 120, and database 130 may include a corporate LAN.

[0020] The server 110 and / or database 130 may contain user login credentials used to control access to user accounts, including, but not limited to, usernames, passwords, access codes, security questions, swipe patterns, image recognition, identification scans (e.g., driver's license scans or passport scans), device registrations, phone numbers, email addresses, social media account access information, and biometrics (e.g., voice recognition, fingerprint scans, retinal scans, facial scans).

[0021] Database 130 may contain data related to one or more accounts. The accounts may be maintained by (or on behalf of) and / or associated with any one or more of a variety of entities, such as, for example, a bank, a merchant, an online retailer, a service provider, a merchandiser, a manufacturer, a social media provider, a sporting or entertainment event provider or promoter, or a hotel chain. For example, database 130 may include, but is not limited to, account identification information (e.g., account number, account owner identification number, account owner name and contact information—any one or more of which may comprise an account identifier), account characteristics (e.g., account type, funding and transaction limits, access and other activity limits), financial information (e.g., balance information, payment history, transaction history, etc.), social information, personal information, and other data related to the account. Data stored in database 130 may be stored in any suitable format, and may be stored in an encrypted and secure format to prevent unauthorized access. Any suitable algorithms / procedures may be used for encrypting and authorized decrypting data.

[0022] Server 110 may be configured to communicate with one or more client devices, such as client device 101 and / or client device 103, over one or more networks, such as network 115. Network 115 may include one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect client device 101 and / or 103 to server 110. For example, network 115 may include an optical fiber network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless local area network (LAN), a global system for mobile communications, a personal communication service, a personal area network, a wireless application protocol, a multimedia messaging service, an enhanced messaging service, a short message service, a time division multiplex-based system, a code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi, etc.

[0023] Additionally, network 115 may include, but is not limited to, telephone lines, optical fiber, IEEE Ethernet 902.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Furthermore, network 115 may support an Internet network, a wireless communication network, a cellular network, or the like, or any combination thereof. Network 115 may further include one network or any number of the exemplary types of networks listed above, operating as a standalone network or in cooperation with one another. Network 115 may utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 115 may translate one or more protocols of network devices to and from other protocols. While network 115 is shown as a single network, it should be understood that, according to one or more exemplary embodiments, network 115 may comprise multiple interconnected networks, such as the Internet, a service provider network, a cable television network, an enterprise network such as a credit card association network, a LAN, and / or a home network.

[0024] In some demonstrative embodiments, server 110 may access records, including records, in database 130 to determine one or more methods for communicating with client device 101 and / or client device 103. Communication methods may include executable push notifications to and from applications stored on client device 101 and / or client device 103. Other communication methods may include text messages, email, or other messaging techniques suitable for a network-based client / server configuration. Messages or requests by client device 101 and / or 103 may be communicated to server 110 via applications on the client device, or may be sent by text message, email, or other messaging techniques suitable for a network-based client / server configuration. Communications originating from client device 101 or client device 103 may be sent to server 110 using the same communication method as communications originating from server 110, or via a different communication method.

[0025] FIG. 1B shows a diagram illustrating a sequence for providing data access control according to one or more exemplary embodiments, which may include a request to link two accounts, each of which may be held by a separate account owner. FIG. 1B references similar components of exemplary embodiment system 100 as shown in FIG. 1A. Client device 101 may be associated with a first account owner. The first account owner may have an associated first account, which may include a first account identifier and first account data. Client device 101 may include an application 102, which may include instructions for execution by client device 101. Client device 101 may include functionality further described below with reference to FIG. 2. Application 102 may be configured to provide a user interface to the first account owner when using client device 101. Application 102 may be configured to communicate with other client devices, short-range transceiver 105, and server 110 via client device 101. Application 102 may be configured to receive requests and send messages as described herein with reference to client device 101. Account information, including account identifiers and account data, may be stored in database 130 .

[0026] The client device 103 may be associated with a second account holder. The second account holder may have an associated second account, which may include a second account identifier. The client device 103 may include an application 104, which may include instructions for execution by the client device 103. The client device 103 may include functionality further described below with reference to FIG. 2. The application 104 may be configured to provide a user interface to the second account holder when using the client device 103. The application 104 may be configured to communicate with other client devices, the short-range transceiver 105, and the server 110 via the client device 103. The application 104 may be configured to send requests and receive messages as described herein with reference to the client device 103.

[0027] The short-range transceiver 105 may be associated with the first account holder. The short-range transceiver 105 may include, for example, a contactless card and may include features further described below with reference to Figure 3. The short-range transceiver 105 may have memory that stores the applet 106 and / or the token 107, which may be associated with the first account holder.

[0028] Tokens may be used to enhance security through token authorization. The server 110 may send a verification request to the client device 101 and / or 103, receive response information from the client device 101 and / or 103, and, if verified, send a verification token back to the client device 101 and / or 103. The verification token may be based on a predetermined token or may be a dynamic token based on an algorithm that may be secret and known only to the server 110 and the client device 101 and / or 103. The algorithm may include live parameters that participants can independently verify, such as the temperature or time of day at a specific location. The token may be used to verify the identity of a first or second account holder. The verification request and / or verification token may be based on a token 107 stored in the short-range transceiver 105.

[0029] In some demonstrative embodiments, the application 104 may display instructions on the client device 103 to prompt the second account holder to initiate a tapping action between the short-range transceiver 105 and the client device 103. As used herein, a tapping action may include tapping the short-range transceiver 105 against the client device 103 (or vice versa). For example, if the short-range transceiver 105 is a contactless card and the client device 103 is a mobile device, the tapping action may include tapping the contactless card on a screen or other portion of the client device 103. However, the tapping action is not limited to a physical tap by the short-range transceiver 105 against the client device 103, but may include other gestures such as, for example, a wave or other movement of the short-range transceiver 105 near the client device 103 (or vice versa).

[0030] There may be a tapping action between the short-range transceiver 105 and the client device 103 at label 150. The tapping action may be in response to a prompt displayed on the client device 103.

[0031] At label 152, application 104 may communicate with short-range transceiver 105 (via client device 103) (e.g., after short-range transceiver 105 is brought close to client device 103). Communication between application 104 and short-range transceiver 105 may involve short-range transceiver 105 (e.g., a contactless card, etc.) being sufficiently close to a card reader (not shown) of client device 103 to enable NFC data transfer between application 104 and short-range transceiver 105, and may occur in conjunction with (or in response to) a tapping action between short-range transceiver 105 and client device 103 (e.g., a tapping action on label 150, etc.). The communication may include an exchange of data or commands to establish a communication session between application 104 and short-range transceiver 105. The exchange of data may include the transfer or exchange of one or more keys. These may be pre-existing keys or generated as session keys. In some demonstrative embodiments, communication may occur when the short-range transceiver 105 enters the short-range communication range of the client device 103 prior to a tap operation between the short-range transceiver 105 and the client device 103 .

[0032] At label 154, short-range transceiver 105 may transmit a token 107 associated with the first account owner to application 104. The token 107 may include a first account identifier that may be unique to a particular user account. In exemplary embodiments, token 107 may include an identifier unique to the first account owner, rather than a particular account. In this case, if the first account owner has multiple accounts, the second account owner must select an account to link. In some exemplary embodiments, token 107 may include a key associated with the first account owner. In some exemplary embodiments, transmission of token 107 to application 104 may occur in conjunction with (or in response to) a tapping action between short-range transceiver 105 and client device 103 (e.g., a tapping action at label 150). In some exemplary embodiments, transmission of token 107 to application 104 may occur when short-range transceiver 105 enters short-range communication range of client device 103, prior to a tapping action between short-range transceiver 105 and client device 103.

[0033] At label 156, application 104 may send token 107 to server 110 along with an account linking request to link a first account (associated with the first account holder) to a second account (associated with the second account holder). This may be performed in response to a tapping action between short-range transceiver 105 and client device 103 (e.g., a tapping action at label 150).

[0034] At label 158, processor 120 may receive the token and an account linking request (e.g., via server 110). Processor 120 may use the token to identify a first account associated with the first account owner. In some exemplary embodiments, identifying the first account may be performed by using the first account identifier in the token to look up account information in database 130. In some exemplary embodiments, at label 159, if the token includes a key associated with the first account owner, processor 120 may use the key in the token to authenticate the first account owner as the first account owner associated with short-range transceiver 105.

[0035] At label 160, processor 120 may send a link approval request to client device 101 (e.g., via server 110) requesting that a first account owner approve an account linking request by a second account owner to link the first account to the second account. The link approval request may include, for example, the name of the second account owner and information or instructions requested by the first account owner to review the request. The link approval request may include a notification that the first account owner may approve or deny the request. The link approval request may be sent to application 102 (via client device 101) as a push notification. In some exemplary embodiments, application 102 may display instructions on client device 101 prompting the first account owner to initiate a tapping action between short-range transceiver 105 and client device 101.

[0036] At label 162, there may be a tapping action between the short-range transceiver 105 and the client device 101. The tapping action may be in response to a link approval request (and / or a prompt displayed on the client device 101) and may indicate approval by the first account owner of the account linking request.

[0037] At label 164, application 102 may send a link approval message to the server indicating approval by the first account owner of the account linking request. This may be performed in response to a tapping action between short-range transceiver 105 and client device 101 (e.g., a tapping action at label 162, etc.). In an example embodiment, application 102 may instead send a denial message (not shown) to the server indicating denial by the first account owner of the account linking request.

[0038] At label 166, processor 120 may send a link confirmation message to client device 103 (e.g., via server 110) confirming approval of the request to link the first account to the second account. The link confirmation message may be sent to application 104 (via client device 103) as a push notification. In some exemplary embodiments, information for the first account and / or the second account in database 130 may be updated with the permission granted by the first account owner to link the first and second accounts.

[0039] In an example embodiment, the processor 120 may instead send a denial notice (not shown) to the client device 103 indicating the first account owner's denial of the account linking request.

[0040] At label 168, processor 120 may send instructions to client device 103 (e.g., via server 110) to obtain access to the first account data for the first account. The instructions to access the first account data may be included in the link confirmation message (label 166) or may be sent as part of a separate communication including a push notification to application 104.

[0041] Processor 120 may retrieve the requested first account data from database 130 and transmit the data to client device 103. Processor 120 may encrypt the requested first account data using any suitable encryption method, such as Triple DES, RSA public-private key encryption, asymmetric encryption, Blowfish encryption, TwoFish encryption, Advanced Encryption Standard (AES), Quantum Key Distribution, Honey encryption, etc., before transmitting to client device 103. In some embodiments, the requested first account data may already be encrypted as stored in database 130 prior to retrieval by processor 120.

[0042] Upon receiving the requested first account data, the client device 103 may decrypt the information if the information was encrypted before transmission by the processor 120. The client device 103 may receive a decryption key separately from the first communication of the encrypted first account data. The encryption may control access to the first account data according to data control parameters. For example, the first account data may be encrypted in a manner that requires a new key to be requested by the client device 103 from the processor 120 each time the client device 103 wishes to access the first account data, such that the data must be decrypted for each access by the client device 103. This procedure allows the processor 120 to ensure that the first account data is not tracked or accessed in a manner inconsistent with the data control parameters.

[0043] In an exemplary embodiment, a second account holder may log into the second account and gain access to the first account data via backend data sharing, subject to any data control parameters.

[0044] The application 104 executing on the client device 103 may send and receive messages and requests with the server 110 / processor 120 by using an application programming interface (API). The application 104 may be configured to receive, decrypt, and access the requested first account data. Through interaction with the application 104, the processor 120 may monitor access of the requested first account data by the client device 103, including in accordance with data control parameters. For example, through interaction with the application 104, the processor 120 may determine the number of times the client device 103 has obtained access to the requested first account data, or the period during which such access occurred. In some embodiments, the application 104 may be permitted to store the requested first account data based on a time-limited or limited number of uses.

[0045] In an exemplary embodiment, processor 120 may be configured to determine whether a first account is eligible to be linked with a second account. Eligibility for account linking may be based, for example, on the type of accounts involved (e.g., business accounts) or the identity of the account holders (e.g., family members or members of the same business entity). Eligibility may also be based on whether the first account holder has previously approved or revoked authorization for account linking, or whether the requested access violates data control parameters (discussed further below). Eligibility for account linking may be indicated, for example, in a flag stored in database 130 or in a memory of short-range transceiver 105.

[0046] In one or more exemplary embodiments, access to the first account data by the second account owner may be restricted according to the data control parameters. In an exemplary embodiment, the data control parameters may be stored in database 130 along with the first account information. Application 102 may provide an interface for the first account owner to select the data control parameters stored in database 130. The selected data control parameters may be stored in database 130 and applied to restrict access to the first account data by the second account owner. Application 102 may also transmit the selected data control parameters to short-range transceiver 105. In an exemplary embodiment, the data control parameters may be stored in memory of short-range transceiver 105. The data control parameters stored in memory of short-range transceiver 105 may be transmitted to application 104 and used by application 104 to restrict access to the first account data by the second account owner. Applet 106 may be configured to receive the data control parameters and store the data control parameters in memory of short-range transceiver 105. Applet 106 may be further configured to send the data control parameters to client device 103. In some exemplary embodiments, the first account holder may select the data control parameters when approving the request to link the accounts, and application 102 may send the selected data control parameters along with the link approval message to server 110. The selected data control parameters may be stored in database 130 and may be applied to restrict access to the first account data by the second account holder.

[0047] In one or more exemplary embodiments, the data control parameters may be used to restrict access to the first account data by the second account owner in one or more ways. For example, the data control parameters may allow access only for a specific or limited period of time. As another example, the data control parameters may allow access for a single use by the second account owner. As another example, the data control parameters may allow access for an unlimited period of time unless the first account owner revokes approval of the request to link the first account to the second account. As another example, the data control parameters may only allow access to portions of the first account data corresponding to predefined categories. As another example, the data control parameters may provide different access permissions based on the identity of the second account owner. As another example, the data control parameters may allow access only if a short-range transceiver 105 is detected within the short-range communication range of the client device 103. In some exemplary embodiments, after account linking approval is obtained, each time the second account owner attempts to access the first account data, the processor 120 may check to determine whether such access is allowed based on the data control parameters and the revocation by the first account owner.

[0048] In an exemplary embodiment, application 104 may be launched in response to a tapping action between short-range transceiver 105 and client device 103. In an exemplary embodiment, application 102 may be launched in response to a tapping action between short-range transceiver 105 and client device 101.

[0049] FIG. 2 illustrates components of a client device 200 used in a data access control system, according to one or more exemplary embodiments. In one or more exemplary embodiments, client device 200 may be one or more of client devices 101 and / or 103, described above with reference to FIGS. 1A and 1B. Client device 200 may include one or more applications 201, one or more processors 202, a short-range communications interface 203, and a network interface 204. Application 201 may include a software application or executable program code configured to execute on processor 202 and perform any of the functions described herein for any of the client devices, such as client devices 101 and / or 103, and / or any of the functions described herein with reference to application 102. Application 201 may be configured to send and / or receive data with other devices via client device 200, such as via short-range communications interface 203 and / or network interface 204. For example, application 201 may be configured to initiate one or more requests, such as a short-range data exchange request to a short-range transceiver (e.g., a contactless card). The application 201 may also be configured to provide a user interface to a user of the client device via a display (not shown). The application 201 may be stored in memory of the client device 200. The memory may include read-only memory, write-once-read-multiple memory, and / or read / write memory, such as RAM, ROM, and EEPROM.

[0050] Processor 202 may include one or more processing devices, such as a microprocessor, a RISC processor, an ASIC, etc., and may include associated processing circuitry. Processor 202 may include or be connected to memory that stores executable instructions and / or data as may be necessary or appropriate to control, operate, or interface with other functions of client device 200, including application 201. Processor 202 (including associated processing circuitry) may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware, as needed to perform the functions described herein.

[0051] The short-range communication interface 203 may support communication over a short-range wireless communication range, such as NFC, RFID, or Bluetooth. The short-range communication interface 203 may include a reader, such as a mobile device NFC reader. The short-range communication interface 203 may be incorporated into the network interface 204 or may be provided as a separate interface.

[0052] The network interface 204 may include wired or wireless data communication capabilities that support data communication with wired or wireless communication networks, including the Internet, a cellular network, a wide area network, a local area network, a wireless personal area network, a wide body area network, other wired or wireless networks for transmitting and receiving data signals, or any combination thereof. Such networks may include, but are not limited to, telephone lines, optical fiber, IEEE Ethernet 902.3, a wide area network, a local area network, a wireless personal area network, a wide body area network, or a global network such as the Internet.

[0053] Client device 200 may also include a display (not shown). Such a display may be any type of device for presenting visual information, such as a computer monitor, a flat panel display, or a mobile device screen, including liquid crystal displays, light emitting diode displays, plasma panels, and cathode ray tube displays.

[0054] Client device 200 may also include one or more device inputs (not shown). Such inputs may include any device for inputting information into client device 300 that is available and supported by client device 200, such as a touchscreen, keyboard, mouse, cursor control device, touchscreen, microphone, digital camera, video recorder, or camcorder. The device inputs may be used to input information and interact with client device 200 and, in turn, the system described herein.

[0055] 3 illustrates components of a short-range transceiver 300 for use in a data access control system according to one or more exemplary embodiments. In one or more exemplary embodiments, the short-range transceiver 300 may be one or more of the short-range transceivers 105 described above with reference to FIGS. 1A and 1B. The short-range transceiver 300 may include, for example, a contactless card or devices having various form factors, such as a fob, pendant, or other device configured to communicate within a short-range communication range. The short-range transceiver 300 may include a processor 302, a memory 302, and a short-range communication interface 305.

[0056] Processor 301 may include one or more processing devices, such as a microprocessor, a RISC processor, an ASIC, etc., and may include associated processing circuitry. Processor 301 may include or be connected to memory that stores executable instructions and / or data as may be necessary or appropriate to control, operate, or interface with other functions of short-range transceiver 300, including applet 303. Processor 301 (including associated processing circuitry) may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware, as needed to perform the functions described herein.

[0057] The memory 302 may be read-only memory, write-once-read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM. The memory 302 may be configured to store one or more applets 303 and one or more tokens 304. The applet 303 may comprise one or more software applications configured to execute on the processor 302, such as a Java Card applet that may be executable on a contactless card. However, it is understood that the applet 303 is not limited to a Java Card applet and may instead be any software application operable on a contactless card or other memory-limited device. The applet 303 may be configured to respond to one or more requests, such as a near-field data exchange request, from a client device, including a request from a device having a reader, such as a mobile device NFC reader. The applet 303 may be configured to read (or write) data, including the token 304, from (or to) the memory 302 and provide the data, including the token 304, in response to a request.

[0058] The token 304 may include a unique alphanumeric identifier assigned to the user of the short-range transceiver 300, which may distinguish the user of the short-range transceiver 300 from other users of other short-range transceivers (e.g., other contactless card users). In some exemplary embodiments, the token 304 may identify both a customer and an account assigned to that customer, and may further identify the short-range transceiver (e.g., a contactless card) associated with the customer's account. In some exemplary embodiments, the token 304 may include a key unique to the user or customer with whom the short-range transceiver is associated.

[0059] The short-range communication interface 305 may support communication over a short-range wireless communication range, such as NFC, RFID, or Bluetooth. The short-range transceiver 300 may also include one or more antennas (not shown) connected to the short-range communication interface 305 to provide connection with the short-range wireless communication range.

[0060] FIG. 4 illustrates an interaction 400 between a client device 401 and a short-range transceiver 420 used in a data access control system, according to one or more exemplary embodiments, including those described above with reference to FIGS. 1A-1B. The client device 401 may be the client device 103 described above with reference to FIGS. 1A and 1B. The client device 401 may be associated with a second account holder. The user interface 402 may be generated by the application 104 described above with reference to FIG. 1B. The short-range transceiver 420 may be the short-range transceiver 105 described above with reference to FIGS. 1A and 1B. When the short-range transceiver 420 comes within short-range communication range of the client device 401 (e.g., via a tapping action), the client device 401 may communicate with the short-range transceiver 420. The client device 401 may transmit data or commands to the short-range transceiver 420 via a transmit signal 431 and may receive data from the short-range transceiver 420, including the token 422, via a receive signal 432. Communications between client device 401 and short-range transceiver 420 may proceed as described above with reference to FIG. 1B (eg, client device 101 or 103 and short-range transceiver 105).

[0061] The user interface 402 may present on the client device 401 a screen display of an account linking request 410, which may include a field 411 and a field 412. If necessary, the second account owner may enter a username in field 411 and a password in field 412. The screen display may include instructions 414 prompting the second account owner to tap a short-range transceiver 420 (in the shown example, the short-range transceiver 420 may be a contactless card) to initiate an account linking request to link the first account to the second account. The instructions 414 may be a push notification from the server 110 (shown in FIGS. 1A and 1B). In response to the tapping action, the client device 401 may send an account linking request to the server 110 (shown in FIGS. 1A and 1B).

[0062] FIG. 5 illustrates an interaction 500 between a client device 501 and a short-range transceiver 520 used in a data access control system, according to one or more exemplary embodiments, including those described above with reference to FIGS. 1A-1B. The client device 501 may be the client device 101 described above with reference to FIGS. 1A and 1B. The client device 501 may be associated with a first account holder. The user interface 502 may be generated by the application 102 described above with reference to FIG. 1B. The short-range transceiver 520 may be the short-range transceiver 105 described above with reference to FIGS. 1A and 1B. When the short-range transceiver 520 comes within short-range communication range of the client device 501 (e.g., via a tapping action), the client device 501 may communicate with the short-range transceiver 520. Client device 501 may transmit data or commands to short-range transceiver 520 via transmit signal 531 and may receive data from short-range transceiver 520, including token 522, via receive signal 532. Communication between client device 501 and short-range transceiver 520 may proceed as described above with reference to FIG. 1B (e.g., client device 101 or 103 and short-range transceiver 105).

[0063] User interface 502 may present on client device 501 a screen display of account linking request 510, which may include field 511 and field 512. If necessary, the first account owner may enter a username in field 511 and a password in field 512. The screen display may include instructions 514 notifying the first account owner that a second account owner (named 2_Acc_Hldr as shown in the example) has requested to link the first account to the second account and prompting the first account owner to tap short-range transceiver 520 (in the example shown, short-range transceiver 520 may be a contactless card) to approve the account linking request to link the first account to the second account. Instructions 514 may result from a push notification from server 110 (shown in FIGS. 1A and 1B ). Client device 501 may send an account linking approval message to server 110 in response to the tapping action. In some exemplary embodiments, user interface 502 may provide the first account owner with the option to select data control parameters when approving a request to link the accounts. Client device 501 may send the selected data control parameters along with a link approval message to server 110. As described above, the selected data control parameters may be stored and applied to restrict access to the first account data by the second account owner.

[0064] 6 is a flowchart illustrating a method of data access control 600 according to one or more exemplary embodiments, with reference to the components and features described above, including but not limited to the figures and associated descriptions. The data access control method 600 may be performed by an application 104 executing on a client device 103 associated with a second account holder. A short-range transceiver 105 is associated with a first account holder.

[0065] At block 610, the application 104 may cause the client device 103 to display an account linking request screen (as shown in and described above with reference to FIG. 4). The account linking request screen may include instructions for tapping the short-range transceiver 105 with / against the client device 103 to initiate the account linking request. As described above with reference to FIG. 4, the short-range transceiver 420 (and thus the short-range transceiver 105) may be a contactless card.

[0066] At block 620 , a tapping action may be detected between the short-range transceiver 105 and the client device 103 .

[0067] At block 630, the token 107 may be received from the short-range transceiver 105. Receiving the token 107 may be in response to the tapping action of block 620. The token 107 may include a first account identifier. In some exemplary embodiments, the token 107 may include a key associated with the first account holder.

[0068] At block 640, the token 107 may be transmitted to the server 110 along with an account linking request to link the first account to the second account. The transmission of the token 107 and the account linking request to the server 110 may be in response to the tapping action of block 620.

[0069] At block 650, an account link confirmation message may be received from server 110 along with instructions for accessing the first account data. As noted above, the instructions may be part of the account link confirmation message or may be part of another message.

[0070] At block 660, the second account holder may access the first account data in accordance with the received instructions. As discussed above, in some exemplary embodiments, access to the first account data may be provided only in accordance with the data control parameters. In some exemplary embodiments, the data control parameters are stored in database 130 along with the first account information, and data access is restricted by processor 120. In some exemplary embodiments, the data control parameters are stored in a memory of short-range transceiver 105 and received from short-range transceiver 105 by application 104. In some exemplary embodiments, the first account data may be encrypted prior to receiving the instructions to access the first account data. Decryption of the encrypted first account data may be performed using a key associated with the first account holder.

[0071] 7 is a flowchart illustrating a method of data access control 700 according to one or more exemplary embodiments, with reference to the components and features described above, including but not limited to the figures and associated descriptions. The data access control method 700 may be performed by an application 102 executing on a client device 101 associated with a first account holder. A short-range transceiver 105 is associated with the first account holder.

[0072] At block 710, a link approval request may be received from server 110 seeking approval to link a first account to a second account.

[0073] At block 720, the application 102 may cause the client device 101 to display an account linking request screen (as shown in and described above with reference to FIG. 5). The account linking request screen may include instructions for tapping the short-range transceiver 105 with / against the client device 101 to approve the account linking request. As described above with reference to FIG. 5, the short-range transceiver 520 (and thus the short-range transceiver 105) may be a contactless card.

[0074] At block 730, a tapping action may be detected between the short-range transceiver 105 and the client device 101 indicating approval of the link approval request. The tapping action may be in response to the link approval request. In an example embodiment, approval may be indicated in other ways (e.g., by selecting a button, etc.).

[0075] At block 740, the token 107 may be received from the short-range transceiver 105. The token 107 may include a first account identifier. In some exemplary embodiments, the token 107 may include a key associated with the first account holder.

[0076] At block 750, a link approval message may be sent to the server 110 indicating approval of the request to link the first account to the second account.

[0077] 8 is a flowchart illustrating a method of data access control 800 according to one or more exemplary embodiments, with reference to the components and features described above, including but not limited to the figures and associated descriptions. The data access control method 800 may be performed by a processor 120 in communication with a client device 101 associated with a first account holder and / or a client device 103 associated with a second account holder via a server 110.

[0078] At block 810, an account linking request may be received from a client device 103 associated with a second account owner, along with a token 107, requesting to link the first account to the second account. The token 107 may include a first account identifier. In some exemplary embodiments, the token 107 may include a key associated with the first account owner.

[0079] At block 820, the sender of the account linking request may be identified as the second account owner.

[0080] At block 830, the first account may be identified based on the received token 107. In some example embodiments, if the token 107 includes a key associated with the first account owner, the key associated with the first account owner may be used to authenticate the first account owner.

[0081] At block 840, the processor may verify that the first account is eligible to be linked to the second account. As discussed above with reference to FIG. 1B, eligibility for account linking may be based, for example, on the type of accounts involved (e.g., business accounts) or the identity of the account holders (e.g., family members or members of the same business entity).

[0082] At block 850, a link approval request may be sent to a client device 101 associated with the first account owner seeking approval to link the first account to the second account.

[0083] At block 860, a link approval message may be received from the client device 101 indicating approval of the request to link the first account to the second account.

[0084] At block 870, an account link confirmation message may be sent to the client device 103 associated with the second account owner along with instructions for accessing the first account data. As described above, the instructions may be part of the account link confirmation message or may be part of another message. In some exemplary embodiments, access to the first account data may be restricted according to data control parameters. In some exemplary embodiments, the processor 120 may encrypt the first account data before providing the client device 103 instructions for accessing the first account data. The encryption of the first account data may be performed using a key associated with the first account owner.

[0085] The description of the embodiments in this disclosure provides non-limiting representative examples that refer to figures and numbers to particularly explain the features and teachings of different aspects of the present disclosure. It should be recognized that the described embodiments can be implemented separately or in combination with other embodiments from the description of the embodiments. Those skilled in the art who review the description of the embodiments should be able to learn and understand the different described aspects of the present disclosure. The description of the embodiments is intended to facilitate understanding of the present disclosure to the extent that other implementations not specifically described but within the knowledge of those skilled in the art who read the description of the embodiments are understood to be consistent with the application of the present disclosure.

[0086] Throughout the specification and claims, the following terms shall have at least the meaning expressly associated therewith, unless the context clearly dictates otherwise. The term "or" is intended to mean an inclusive "or." Furthermore, the terms "a," "an," and "the" are intended to mean one or more unless otherwise specified or clearly directed to the singular from the context.

[0087] In this description, many specific details have been set forth. However, it should be understood that implementations of the disclosed technology may be practiced without these specific details. In other instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure an understanding of this description. References to "some examples," "other examples," "one example," "examples," "various examples," "one embodiment," "embodiments," "some embodiments," "exemplary embodiments," "various embodiments," "one implementation," "implementation," "exemplary implementation," "various implementations," "some implementations," etc., indicate that implementations of the disclosed technology so described may include particular features, structures, or characteristics, but not all implementations necessarily include the particular feature, structure, or characteristic. Furthermore, repeated use of the phrase "in one example," "in one embodiment," or "in one implementation" does not necessarily refer to the same example, embodiment, or implementation, although it may.

[0088] As used herein, unless otherwise specified, the use of ordinal adjectives "first," "second," "third," etc. to describe a common object merely indicates that different instances of a similar object are being referred to, and does not imply that the objects so described need be in any particular order, whether temporally, spatially, ranked, or otherwise.

[0089] While particular implementations of the disclosed technology have been described in connection with what are presently considered to be the most practical various implementations, it is to be understood that the disclosed technology is not to be limited to the disclosed implementations, but on the contrary, is intended to cover various modifications and equivalent arrangements included within the scope of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

[0090] This written description uses examples to disclose particular implementations of the disclosed technology, including the best mode, and also enables any person skilled in the art to practice particular implementations of the disclosed technology, including making and using any device or system, and performing any incorporated methods. The patentable scope of particular implementations of the disclosed technology is defined in the claims, and may include other examples that occur to those skilled in the art. Such other examples are intended to be within the scope of the claims if they have structural elements that do not differ from the literal language of the claims, or if they include equivalent structural elements that are substantially different from the literal language of the claims.

Claims

1. a processor; a memory, The processor: Receive the account linking request and token, the account linking request links a first account associated with a first account holder and a first client device to a second account associated with a second account holder and a second client device; the first account holder and the second account holder are different from one another; the account linking request and the token are received from the second client device; the token includes a key associated with the first account holder; The processor: Identifying a first account based on the key; In response to identifying the first account, sending a link approval request to the first client device to approve the account linking request; receiving a link approval message from the first client device approving the account linking request; configured to send an account link confirmation message to the second client device, the message including instructions for accessing the first account data; server.

2. The processor communicates data with a database that stores information for multiple accounts; The database comprises: a first account identifier and first account data for the first account associated with the first account holder; a second account identifier for the second account associated with the second account holder; The server of claim 1 .

3. The processor is further configured to determine whether the first account is eligible to be linked to the second account. The server of claim 2.

4. The processor further comprises: obtaining at least a portion of the first account data from the database; encrypting at least a portion of the first account data to generate encrypted first account data; configured to transmit the encrypted first account data to the second client device after transmitting the account link confirmation message. The server of claim 2.

5. the processor is further configured to transmit a decryption key to the second client device in a separate communication from the encrypted first account data. The server of claim 4.

6. the decryption key is a key associated with the first account holder; The server of claim 5.

7. a new decryption key is required for each transmission of the encrypted first account data; The server of claim 5.

8. the first account data includes one or more data control parameters; the processor is further configured to restrict access to the first account data by the second account holder according to the data control parameters. The server of claim 2.

9. The one or more data control parameters are: permitting the second account holder to access the first account data for only a limited period of time; permitting the second account holder to access the first account data only once; permitting the second account holder to access the first account data for an unlimited period of time unless the first account holder revokes approval of the request to link the first account with the second account; permitting the second account holder to access only a portion of the first account data corresponding to a predefined category; At least one selected from the group consisting of: The server of claim 8.

10. the processor is further configured to authenticate the first account holder associated with the access token as being associated with a contactless card. The server of claim 1 .

11. the key is unique to the first account holder; The server of claim 1 .

12. A method, comprising: a server receiving an account linking request accompanied by a token; the account linking request links a first account associated with a first account holder and a first client device to a second account associated with a second account holder and a second client device; the first account holder and the second account holder are different from one another; the account linking request is received from the second client device; the token includes a key associated with the first account holder; The method comprises: the server identifying the first account based on the key; the server, in response to identifying the first account, sending a link approval request to the first client device to approve the account linking request; receiving, by the server, from the first client device, a link approval message generated in response to an indication that the first account holder approves the account linking request; the server sending an account link confirmation message to the second client device; the account link confirmation message confirms approval of the account link request and provides instructions for accessing the first account data. method.

13. the server is in data communication with a database storing information for a plurality of accounts; the database includes, for the first account associated with the first account holder, a first account identifier and the first account data, and for the second account associated with the second account holder, a second account identifier; The method of claim 12.

14. the first account data includes one or more data control parameters; The one or more data control parameters are: permitting the second account holder to access the first account data for only a limited period of time; permitting the second account holder to access the first account data only once; permitting the second account holder to access the first account data for an unlimited period of time unless the first account holder revokes approval of the request to link the first account with the second account; permitting the second account holder to access only portions of the first account data corresponding to predefined categories; At least one selected from the group consisting of: The method of claim 13.

15. the data control parameters include different data access permissions based on the identity of the second account holder; 15. The method of claim 14.

16. A server; a contactless card associated with a first account holder, the contactless card comprises a communication interface, a processor, and a memory; The contactless card has a memory that stores an applet and a token; the contactless card is configured to, after being input into a communication field of a first client device, transmit an account linking request and a token to the first client device via the communication field; The account linking request links a first account associated with the first account holder and the first client device to a second account associated with a second account holder and a second client device. the first account holder and the second account holder are different from one another; the account linking request and the token are received from the second client device; the token includes a key associated with the first account holder; The server receiving the token and the account linking request from the contactless card via the first client device; Identifying the first account based on the key; In response to identifying the first account, sending a link approval request to the first client device approving the account linking request; receiving a link approval message from the first client device approving the account linking request; configured to send an account link confirmation message to the second client device, the message including instructions for accessing the first account data; system.

17. The system comprises: a client application including instructions for execution on at least one selected from the group consisting of the first client device and the second client device; The client application When executed on the first client device, receiving the token from the contactless card in response to a tap operation between the contactless card and the first client device, and transmitting the token and the account link request to the server to link the first account to the second account; configured to receive, from the server, the account link confirmation message including instructions to access the first account data; When executed on the second client device, configured to, in response to a link approval request from the server approving the account link request, send the link approval message to the server approving the account link request; 17. The system of claim 16.

18. the contactless card memory further stores one or more data control parameters for the first account; The client application When executed by the first client device, the method further comprises: receiving one or more data control parameters for the first account from the contactless card; configured to restrict access to the first account data by the first client device according to the received one or more data control parameters; 20. The system of claim 17.

19. the one or more data control parameters include different data access permissions based on the first account; 20. The system of claim 18.

20. receiving the link acknowledgement message by the server following a tap operation between the contactless card and the first client device; 20. The system of claim 17.

Citation Information

Patent Citations

  • Payment system using IC card

    JP2004199534A

  • Linking Network Accounts

    JP2007516513A

  • Game system server, game system, game system control method, and game system server control program

    JP2012147945A

  • Mediation method of network service and mediation system

    JP2014211873A