Secure Financial Data Exchange Through Granular Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods are vulnerable to security risks and inefficiencies when third-parties access sensitive financial data, particularly due to unauthorized access and data scraping, which compromises user authentication information and overburdens data processing systems.
Innovation Solution
A computing device controls data exchange by allowing users to define permissions for data sharing with third-parties, using authorization data to authenticate and authorize access to specific types of financial account data, and employing blocking policies to deny unauthorized access, thus enhancing security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional user authentication methods are used, then users can access their financial data, but security risks increase due to vulnerability to unauthorized access and data scraping
Solution Approach 1:
The patent introduces an intermediary authentication system that mediates between users and third-party applications. Instead of third-parties directly accessing user data, the system uses authorized session units and blocking units as intermediaries to verify authentication credentials and control data access, thereby preventing unauthorized access and data scraping while maintaining secure user authentication
Solution Approach 2:
The authentication system is segmented into distinct functional components: authentication units that verify user credentials, authorized session units that manage authentication sessions, and blocking units that prevent unauthorized access. This segmentation allows each component to specialize in specific security functions, improving overall system reliability while addressing multiple security threats simultaneously
2Ease of operation
If third-parties can access user data freely, then data accessibility is improved, but data processing systems become overburdened
Solution Approach 1:
The system implements partial action by allowing third-parties to access only the specific data types and accounts explicitly authorized by the user through the authentication process. The authorized session units and blocking units filter and control data requests, enabling third-parties to access necessary data efficiently while preventing excessive or unauthorized data retrieval that would burden processing systems
3Productivity
If comprehensive data sharing is allowed, then data exchange efficiency is improved, but security risks increase due to broader access permissions
Solution Approach 1:
The authentication system implements local quality by allowing different levels and types of data access for different authorized third-parties. The blocking units and authorized session units control granular access permissions, enabling efficient data exchange for authorized applications while maintaining security through localized, differentiated access controls rather than blanket comprehensive sharing
Data Source
AI summary
In an example, a computer-implemented method includes determining a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with a user and held by a financial institution, and generating authorization data that authenticates the third-party and authorizes the third-party to access the types of account data specified by the set of permissions. The method also includes transmitting the authorization data to the third-party, receiving a request for authorization that includes the authorization data and a request for account data of the one or more financial accounts that conforms to the types of account data specified by the set of permissions, authorizing the third-party based on the authorization data, and transmitting the account data that conforms to the types of account data specified by the set of permissions.


