Revocable 1:1:1 Token for Granular Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data access request processing methods in open banking rely heavily on data aggregators, leading to inadequate control for financial institutions over data sharing access and lack of granular access management, making it difficult to track and revoke access permissions for third-party applications.

Innovation Solution

A computing platform and method that generate and manage revocable 1:1:1 tokens for specific combinations of third-party applications, aggregators, and financial institutions, allowing users to control data sharing access and revoke permissions through a dashboard, independent of the aggregator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data aggregators manage data access centrally, then data sharing can be facilitated between financial institutions and third-party applications, but financial institutions lose granular control over access permissions and cannot independently track or revoke access

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidcontrol over access permissions
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the centralized aggregator control into distributed token-based access management. Each financial institution receives its own 1:1:1 tokens that independently authorize specific third-party applications, eliminating the need for centralized aggregator control while enabling granular per-institution, per-application access management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces 1:1:1 tokens as intermediaries between financial institutions and third-party applications. These tokens serve as self-contained authorization credentials that encode access permissions, allowing financial institutions to grant and revoke access without relying on aggregator intermediaries while maintaining secure data sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If tokens are issued per financial institution-aggregator pair, then data access management is simplified through centralized control, but granular access control for specific third-party applications is lost

Engineering Contradiction:
Improvetoken management structureVSAvoidaccess permission granularity
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent divides the broad financial institution-aggregator token relationship into finer-grained 1:1:1 tokens that specifically authorize individual third-party applications. This segmentation enables precise tracking of which application accesses which institution's data through the aggregator, providing both structural simplicity and permission granularity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making each token specific to a particular third-party application rather than generic for all applications. Each 1:1:1 token contains application-specific authorization information, allowing the system to maintain simple token issuance while achieving fine-grained control over which specific applications can access data.

Inventive Principle:
Principle #3Local quality

3Productivity

If aggregators centrally manage all data access, then coordination between multiple financial institutions and applications is simplified, but the ability to independently track and revoke access for individual institutions is reduced

Engineering Contradiction:
Improvecoordination efficiencyVSAvoidaccess tracking capability
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where financial institutions receive notifications when their 1:1:1 tokens are issued or revoked. This enables institutions to independently track their data access permissions and take action to revoke access when needed, maintaining coordination efficiency through standardized token processes while preserving independent monitoring and control capabilities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240362353A1System and method of processing a data access request
Publication Date: 2024.10.31 THE TORONTO DOMINION BANK
  • US20240362353A1 patent drawing
  • US20240362353A1 patent drawing
  • US20240362353A1 patent drawing

AI summary

Computing platforms, methods, and storage media for processing a data access request are disclosed. Exemplary implementations may: generate, at the computing platform and based on a received data access request, a revocable 1:1:1 token that authorizes data sharing for a specific combination of third party application-aggregator-institution for a user associated with a communication device; and cause display of a user interface including a list of a plurality of third party applications for which data access is currently granted and for which a revocable 1:1:1 token is stored, the user interface enabling selective revocation of data access from among the listed plurality of third party applications. Exemplary implementations may generate an instruction to delete the stored revocable 1:1:1 token associated with the selected third party application, and may cause display of an access revocation selector, and may generate a selective revocation request associated with the selective revocation of data access.