Control Tower for Centralized Third-Party Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers face challenges in managing access permissions for their information across multiple platforms, leading to security risks and inefficiencies, as well as cumbersome processes when dealing with multiple third-parties accessing their financial institution data.

Innovation Solution

A centralized control system, or 'control tower', allows customers to manage access permissions and data sharing through a single interface, enabling them to control what information is shared, with whom, and how it is used, while providing a mechanism to delete data from third-party systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If customers manage access permissions at each third-party system individually, then each system can be controlled separately, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
Improveease of managing access permissionsVSAvoidtime to manage access permissions
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent combines multiple access permission management functions into a single centralized control interface. Customers can view and manage all their access permissions across different third-party systems from one location, eliminating the need to log into each system separately and significantly reducing the time and effort required to manage permissions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The control interface is designed to be universal, allowing customers to manage access permissions for multiple different types of third-party systems (financial health monitoring services, mobile wallet services, retailers, etc.) through a single unified system, making the management process adaptable to various platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If customer information is shared with multiple third-party systems, then the customer can access various services, but security risks increase and information exposure to unauthorized parties increases

Engineering Contradiction:
Improveability to access various servicesVSAvoidsecurity of customer information
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a control interface as an intermediary layer between the customer's information and third-party systems. This intermediary allows customers to selectively grant and revoke access permissions, ensuring that information is only shared with authorized parties while still enabling access to various services. The intermediary maintains security control without preventing legitimate service access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access permission system is designed to be dynamic, allowing customers to easily modify their permissions in real-time. Customers can grant access when needed and revoke it when no longer required, enabling the system to adapt to changing security requirements while maintaining service accessibility.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If customer information is stored in additional databases at third-party systems, then service functionality is enhanced, but the customer's information becomes more vulnerable to security breaches and data leaks

Engineering Contradiction:
Improveservice functionalityVSAvoidvulnerability to security breaches
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The control interface serves as a mediating system that manages the flow of customer information to third-party databases. It enables service functionality by allowing controlled access to information while simultaneously reducing vulnerability through centralized permission management and the ability to quickly revoke access if security concerns arise.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by obtaining customer consent and establishing access permissions before any information is shared with third-party systems. This preliminary control mechanism ensures that information is only exposed to authorized parties, reducing the risk of security breaches before they can occur.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250252414A1Control tower for prospective transactions
Publication Date: 2025.08.07 WELLS FARGO BANK NA
  • US20250252414A1 patent drawing
  • US20250252414A1 patent drawing
  • US20250252414A1 patent drawing

AI summary

Systems, methods, and apparatuses for providing a customer a central location to manage permissions provided to third-parties and devices to access and use customer information maintained by a financial institution are described. The central location serves as a central portal where a customer of the financial institution can manage all access to account information and personal information stored at the financial institution. Accordingly, the customer does not need to log into each individual third-party system or customer device to manage previously provided access to the customer information or to provision new access to the customer information. A user additionally is able to have user data and third-party accounts of the user deleted from devices, applications, and third-party systems via a central portal. Restrictions on how user data is used by devices, applications, and third-party systems can be imposed via a central portal.