Linked Account Data Scrubbing for Token-Controlled Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers face challenges in managing customer data across multiple platforms, leading to security risks and cumbersome access control, as well as inefficiencies in using virtual rewards currencies and managing preferences across different services.
Innovation Solution
A portal is provided via a network, allowing users to manage customer data and preferences, enable or disable virtual rewards currencies, and control access permissions through graphical interfaces, with features like location-based services and navigation options, while enabling secure transactions and data scrubbing across platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If customers share account information with multiple third-party services, then the customer can access and manage information across multiple platforms, but the customer is exposed to additional security risks and the information becomes more vulnerable to unauthorized access
Solution Approach 1:
The patent introduces a token as an intermediary that mediates between the customer's account information and third-party services. Instead of directly sharing sensitive account data, the system generates tokens that represent access permissions. These tokens can be selectively provided to third parties, allowing platform versatility while maintaining security control through the token intermediary layer.
Solution Approach 2:
The patent segments access control by dividing account information access into discrete token units. Each token represents a specific permission or access level, allowing customers to granularly control which third-party services receive which permissions. This segmentation enables selective sharing without exposing all account information to all services.
2Ease of operation
If customers manage access permissions at each third-party system individually, then the customer can control access to information, but the process becomes cumbersome and time-consuming
Solution Approach 1:
The patent merges multiple access control operations into a single centralized interface. Instead of requiring customers to manage permissions at each third-party system separately, the system provides a unified portal where customers can create, manage, and revoke tokens across all connected services from one location, significantly reducing the time and effort required for permission management.
Solution Approach 2:
The patent creates a universal token management system that works across multiple platforms and service types. The token mechanism provides a standardized way to control access regardless of which third-party service is involved, allowing customers to manage all their permissions through a single multi-functional interface rather than learning different systems for each service.
3Adaptability or versatility
If account information is stored in additional databases at third-party systems, then the customer can access information across platforms, but the information becomes more vulnerable to hacking and data breaches
Solution Approach 1:
The patent uses token copying instead of data duplication. Instead of copying sensitive account information to third-party databases, the system creates and distributes token copies that represent access permissions. These tokens can be stored at third parties without exposing the actual account information, maintaining cross-platform access while protecting the reliability and security of the original data.
Data Source
AI summary
Systems, methods, and apparatuses for scrubbing account data accessed via links to applications or devices are disclosed. A system receives, from a financial institution computing system, a security access token granting access to account data of a user account administered by the financial institution. The system transmits an API request including the security access token to retrieve account data, receives the requested account data, and stores the account data locally. The system provides stored account data to a client application upon request. Upon receiving a scrub command from the financial institution computing system instructing deletion of the stored account data, the system deletes the account data from local storage and transmits an indication back to the financial institution confirming deletion.


