Cloud Financial Data Access Using Verified Authorization Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in enabling third-party applications to automatically access consumer financial data from a common mobile banking platform while ensuring secure authentication and authorization of the user's financial information.

Innovation Solution

A cloud-based platform that receives requests from third-party service providers, authenticates their authorization by both the financial service provider and the consumer, configures a software object (token) for authorized data access, and verifies the token to provide secure access to the consumer's financial data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party applications are granted automatic access to consumer financial data, then ease of operation is improved, but security and authentication complexity increases

Engineering Contradiction:
Improveease of access to financial dataVSAvoidauthentication and authorization complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication and authorization actions by obtaining consumer consent and verifying credentials with the financial institution before granting access. This preliminary action establishes trust and security protocols in advance, allowing seamless data access without repeated authentication complexity during actual use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device acts as an intermediary between the third-party application and the financial institution. It manages the authentication and authorization processes, handling credential verification and consent management, thereby shielding the application from direct exposure to complex security protocols while maintaining secure access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual authentication processes are used for third-party access, then security is improved, but loss of time increases

Engineering Contradiction:
Improvesecurity of financial dataVSAvoidtime for sign-up and authentication
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication and authorization are performed preliminarily during the initial connection phase between the third-party application and the financial institution. Consumer consent and credential verification are obtained in advance, so that subsequent data access operations occur without time-consuming manual authentication steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service authentication where the consumer's device automatically manages credentials and authorization tokens. The mobile device handles verification with the financial institution autonomously, eliminating the need for manual intervention and reducing time loss while maintaining security through automated credential management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12387191B2Cloud-based systems and methods for providing consumer financial data
Publication Date: 2025.08.12 FIDELITY INFORMATION SERVICES LLC
  • US12387191B2 patent drawing
  • US12387191B2 patent drawing
  • US12387191B2 patent drawing

AI summary

Systems and methods are disclosed for providing cloud-based access to consumer financial information. A cloud-based platform may receive a notification from a server, the notification comprising a request to access consumer data associated with a financial services account. After confirming authorization by both the associated financial services account provider and the consumer, the platform may configure a software object identifying the server and at least a portion of the consumer data that the server is authorized to access. After presentation of the configured software object by the third party server, the platform may verify the configured software object, and provide to the server access to the authorized consumer data. The server may then utilize the provided consumer data to perform a mobile service for the consumer.