Secure Financial Data Exchange Through Granular Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods are vulnerable to security risks and inefficiencies when third-parties access sensitive financial data, particularly due to unauthorized access and data scraping, which compromises user authentication information and overburdens data processing systems.

Innovation Solution

A computing device controls data exchange by allowing users to define permissions for data sharing with third-parties, using authorization data to authenticate and authorize access to specific types of financial account data, and employing blocking policies to deny unauthorized access, thus enhancing security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional user authentication methods are used, then users can access their financial data, but security risks increase due to vulnerability to unauthorized access and data scraping

Engineering Contradiction:
Improveauthentication securityVSAvoidunauthorized access and data scraping
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between users and third-party applications. Instead of third-parties directly accessing user data, the system uses authorized session units and blocking units as intermediaries to verify authentication credentials and control data access, thereby preventing unauthorized access and data scraping while maintaining secure user authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional components: authentication units that verify user credentials, authorized session units that manage authentication sessions, and blocking units that prevent unauthorized access. This segmentation allows each component to specialize in specific security functions, improving overall system reliability while addressing multiple security threats simultaneously

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If third-parties can access user data freely, then data accessibility is improved, but data processing systems become overburdened

Engineering Contradiction:
Improvedata accessibility for third-partiesVSAvoiddata processing system efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system implements partial action by allowing third-parties to access only the specific data types and accounts explicitly authorized by the user through the authentication process. The authorized session units and blocking units filter and control data requests, enabling third-parties to access necessary data efficiently while preventing excessive or unauthorized data retrieval that would burden processing systems

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If comprehensive data sharing is allowed, then data exchange efficiency is improved, but security risks increase due to broader access permissions

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The authentication system implements local quality by allowing different levels and types of data access for different authorized third-parties. The blocking units and authorized session units control granular access permissions, enabling efficient data exchange for authorized applications while maintaining security through localized, differentiated access controls rather than blanket comprehensive sharing

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12443987B1Secure data exchange
Publication Date: 2025.10.14 WELLS FARGO BANK NA
  • US12443987B1 patent drawing
  • US12443987B1 patent drawing
  • US12443987B1 patent drawing

AI summary

In an example, a computer-implemented method includes determining a set of permissions that specifies types of account data of one or more financial accounts to share with a third-party, the one or more financial accounts being associated with a user and held by a financial institution, and generating authorization data that authenticates the third-party and authorizes the third-party to access the types of account data specified by the set of permissions. The method also includes transmitting the authorization data to the third-party, receiving a request for authorization that includes the authorization data and a request for account data of the one or more financial accounts that conforms to the types of account data specified by the set of permissions, authorizing the third-party based on the authorization data, and transmitting the account data that conforms to the types of account data specified by the set of permissions.