Cloud Financial Data Access Using Verified Authorization Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in enabling third-party applications to automatically access consumer financial data from a common mobile banking platform while ensuring secure authentication and authorization of the user's financial information.
Innovation Solution
A cloud-based platform that receives requests from third-party service providers, authenticates their authorization by both the financial service provider and the consumer, configures a software object (token) for authorized data access, and verifies the token to provide secure access to the consumer's financial data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If third-party applications are granted automatic access to consumer financial data, then ease of operation is improved, but security and authentication complexity increases
Solution Approach 1:
The system performs preliminary authentication and authorization actions by obtaining consumer consent and verifying credentials with the financial institution before granting access. This preliminary action establishes trust and security protocols in advance, allowing seamless data access without repeated authentication complexity during actual use.
Solution Approach 2:
The mobile device acts as an intermediary between the third-party application and the financial institution. It manages the authentication and authorization processes, handling credential verification and consent management, thereby shielding the application from direct exposure to complex security protocols while maintaining secure access.
2Reliability
If manual authentication processes are used for third-party access, then security is improved, but loss of time increases
Solution Approach 1:
Authentication and authorization are performed preliminarily during the initial connection phase between the third-party application and the financial institution. Consumer consent and credential verification are obtained in advance, so that subsequent data access operations occur without time-consuming manual authentication steps.
Solution Approach 2:
The system enables self-service authentication where the consumer's device automatically manages credentials and authorization tokens. The mobile device handles verification with the financial institution autonomously, eliminating the need for manual intervention and reducing time loss while maintaining security through automated credential management.
Data Source
AI summary
Systems and methods are disclosed for providing cloud-based access to consumer financial information. A cloud-based platform may receive a notification from a server, the notification comprising a request to access consumer data associated with a financial services account. After confirming authorization by both the associated financial services account provider and the consumer, the platform may configure a software object identifying the server and at least a portion of the consumer data that the server is authorized to access. After presentation of the configured software object by the third party server, the platform may verify the configured software object, and provide to the server access to the authorized consumer data. The server may then utilize the provided consumer data to perform a mobile service for the consumer.


