Container-Based Consent Verification for Secure Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing environments face challenges in securely managing consent and permissioning protocols for third-party applications accessing confidential data, particularly in open banking scenarios, where ensuring data integrity and user consent is critical but often not adequately addressed.

Innovation Solution

A system and method that utilizes container-based applications to manage consent and permissioning protocols, where a second digital token from an inaccessible memory portion is loaded and verified against a first digital token, presenting a verified digital signature within a digital interface to confirm access to confidential data elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party applications directly access confidential data in open banking environments, then data accessibility and functionality are improved, but data security and user consent control deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a container-based application as an intermediary layer between third-party applications and confidential data. This mediator manages consent and permissioning protocols, verifying digital tokens before allowing data access. The container application acts as a trusted intermediary that enables data accessibility while maintaining security controls, resolving the contradiction between ease of operation and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If digital tokens are stored in accessible memory for application use, then application functionality is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveapplication functionalityVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments memory into accessible and inaccessible portions, with digital tokens stored in the inaccessible portion. The container-based application selectively accesses only the necessary token information through controlled interfaces, maintaining application functionality while protecting tokens from unauthorized access. This segmentation resolves the contradiction between productivity and security against harmful factors.

Inventive Principle:
Principle #1Segmentation

3Speed

If consent protocols are simplified for faster processing, then processing speed is improved, but consent verification accuracy deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidconsent verification accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent implements preliminary consent verification by the container-based application before data access requests are processed. Digital tokens are pre-validated and consent status is determined in advance, allowing faster processing speeds while maintaining verification accuracy. This preliminary action ensures that consent protocols are both efficient and accurate, resolving the contradiction between speed and measurement precision.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250267011A1Dynamic management and implementation of consent and permissioning protocols using container-based applications
Publication Date: 2025.08.21 THE TORONTO DOMINION BANK
  • US20250267011A1 patent drawing
  • US20250267011A1 patent drawing
  • US20250267011A1 patent drawing

AI summary

The disclosed exemplary embodiments include computer-implemented systems, devices, apparatuses, and processes that dynamically implement and manage consent and permissioning protocols using container-based applications. By way of example, a device may receive a request for an element of data that includes a first digital token associated with an executed application program. The device may load a second digital token from a portion of the memory that is inaccessible to the executed application program, and when the first digital token is consistent with the second digital token, the device may present, within a digital interface, an interface element that confirms a verification of a digital signature associated with the data element.