Linked Account Data Scrubbing Through Centralized Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers face challenges in managing and securing their financial information across multiple platforms, leading to increased security risks and exposure due to multiple third-party access, which can result in data breaches and unauthorized access.

Innovation Solution

A portal and computing system that allows users to manage and control access permissions, apply virtual rewards currencies, and enable/disable transactions, while providing an interface to view and control linked accounts and data access, with features for scrubbing and deleting customer data from third-party systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If customers share account information with multiple third-party services, then the convenience of managing preferences and accessing services is improved, but the security risk and exposure of customer data increases

Engineering Contradiction:
Improveconvenience of managing preferencesVSAvoidsecurity risk of customer data
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a centralized access control system that acts as an intermediary between customers and multiple third-party services. This system allows customers to manage all their data access permissions through a single interface, eliminating the need to manually manage preferences at each third-party service individually. The intermediary maintains a centralized record of which data elements are shared with which services, providing both convenience and security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is designed to work universally across multiple third-party services and platforms. A single customer account and preference set can control access to data across numerous different services, whether they are financial institutions, retailers, or other entities. This multi-functional approach allows customers to manage all their data sharing preferences from one centralized location rather than visiting each service separately.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If customer information is stored in additional databases at third-party systems, then the functionality and service capability are improved, but the vulnerability to data breaches and unauthorized access increases

Engineering Contradiction:
Improveservice capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The centralized access control system serves as an intermediary layer between customer data and multiple third-party databases. Rather than allowing direct, unmanaged access to data at each third-party system, the intermediary maintains centralized control over what data is accessed and by whom. This allows services to function across multiple platforms while maintaining a single point of control for security and access management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments customer data access by creating distinct, controlled connections between the customer's central account and specific third-party services. Each data element can be individually managed and authorized, allowing fine-grained control over what information is shared with which service. This segmentation reduces the attack surface by preventing broad, uncontrolled access to all customer data across all platforms.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If customers manually manage access permissions at each third-party system, then the precision of access control is improved, but the time and effort required increases

Engineering Contradiction:
Improveprecision of access controlVSAvoidtime to manage preferences
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent combines multiple separate access control functions into a single centralized system. Instead of requiring customers to log into and manage permissions at each third-party service separately, all access control functions are merged into one unified interface. This consolidation maintains precise control over data access while eliminating the repetitive time and effort of managing each service individually.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized access control system provides universal functionality across all third-party services through a single customer account. This multi-functional approach allows the same interface and authentication mechanism to control access to data at numerous different services, dramatically reducing the time and effort required while maintaining the same level of precise access control that would be achieved through manual management at each service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250265370A1Scrubbing account data accessed via links to applications or devices
Publication Date: 2025.08.21 WELLS FARGO BANK NA
  • US20250265370A1 patent drawing
  • US20250265370A1 patent drawing
  • US20250265370A1 patent drawing

AI summary

Systems and methods for scrubbing account data accessed via links to applications or devices are disclosed. A service provider computing system can transmit, to a financial institution computing system, an application programming interface (API) call comprising a request for account data associated with a user account. The system can receive, in response to the API call, the account data according to security access granted to the service provider, and store the account data in non-volatile memory. Upon receiving a data request from a client application executing on a user device, the system can transmit the stored account data to the user device. In response to receiving a scrub command from the financial institution computing system instructing deletion of the account data, the system can delete the account data from memory and transmit an indication to the financial institution computing system confirming deletion of the account data.