Data-Type Access Control Tower for Third-Party API Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers face challenges in managing customer data and preferences across multiple platforms, leading to security risks and exposure of personal information due to multiple third-party access, cumbersome management processes, and increased vulnerability to data breaches.

Innovation Solution

A portal accessible via a user device allows users to manage and control access permissions, apply virtual rewards currency, and enable/disable transactions, while providing an interface to view and manage customer information and preferences, with features for location-based services and navigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customers share information with multiple third-party services, then the customer can access and manage information across different platforms, but the customer's information becomes exposed to additional security risks and may be accessed by unwanted parties

Engineering Contradiction:
Improveaccess across platformsVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data control tower as an intermediary system between the customer's financial institution data and third-party services. This mediator enables cross-platform information access while maintaining security by controlling what data is shared and with whom, thus resolving the contradiction between versatility and security risks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments customer information into different categories and controls access to specific segments rather than sharing all information broadly. This allows selective sharing with third parties, enabling platform versatility while minimizing security exposure by limiting access to only necessary data segments

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If customers manage access permissions at each third-party system individually, then the customer can control data access at each platform, but the management process becomes cumbersome when multiple third-parties are authorized

Engineering Contradiction:
Improvedata access controlVSAvoidmanagement time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent merges multiple individual data access control interfaces into a single centralized data control tower. This consolidation allows customers to manage permissions for multiple third-party services from one location, significantly reducing the time and effort required compared to managing each platform separately

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If customer information is stored in additional databases at third-party systems, then the customer can access information across multiple platforms, but the customer's information becomes more vulnerable to data breaches and intentional or unintentional leaks

Engineering Contradiction:
Improvecross-platform accessVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The data control tower acts as an intermediary that enables cross-platform access without requiring broad data distribution. By controlling data sharing at the source through this mediator, the system reduces the number of copies stored at third parties, thereby maintaining versatility while improving reliability and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250265371A1Control tower for defining access permissions based on data type
Publication Date: 2025.08.21 WELLS FARGO BANK NA
  • US20250265371A1 patent drawing
  • US20250265371A1 patent drawing
  • US20250265371A1 patent drawing

AI summary

Systems, methods, and apparatuses for defining access permissions based on data type are disclosed. A system provides an account listing via an internet portal accessed on a user device. The account listing can include a financial account linked with a service provider client application. The system provides, via the internet portal, an access permissions listing comprising one or more security settings attributable to the service provider client application. Upon receiving selection of security settings, the system determines whether an incoming application programming interface (API) call comprising an account request transmitted from a service provider computing system complies with the selected security settings. Upon determining that the request does not comply with the security settings, the system declines the account request.