Revocable 1:1:1 Token for Granular Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data access request processing methods in open banking rely heavily on data aggregators, leading to inadequate control for financial institutions over data sharing access and lack of granular access management, making it difficult to track and revoke access permissions for third-party applications.
Innovation Solution
A computing platform and method that generate and manage revocable 1:1:1 tokens for specific combinations of third-party applications, aggregators, and financial institutions, allowing users to control data sharing access and revoke permissions through a dashboard, independent of the aggregator.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data aggregators manage data access centrally, then data sharing can be facilitated between financial institutions and third-party applications, but financial institutions lose granular control over access permissions and cannot independently track or revoke access
Solution Approach 1:
The patent segments the centralized aggregator control into distributed token-based access management. Each financial institution receives its own 1:1:1 tokens that independently authorize specific third-party applications, eliminating the need for centralized aggregator control while enabling granular per-institution, per-application access management.
Solution Approach 2:
The patent introduces 1:1:1 tokens as intermediaries between financial institutions and third-party applications. These tokens serve as self-contained authorization credentials that encode access permissions, allowing financial institutions to grant and revoke access without relying on aggregator intermediaries while maintaining secure data sharing.
2Device complexity
If tokens are issued per financial institution-aggregator pair, then data access management is simplified through centralized control, but granular access control for specific third-party applications is lost
Solution Approach 1:
The patent divides the broad financial institution-aggregator token relationship into finer-grained 1:1:1 tokens that specifically authorize individual third-party applications. This segmentation enables precise tracking of which application accesses which institution's data through the aggregator, providing both structural simplicity and permission granularity.
Solution Approach 2:
The patent applies local quality by making each token specific to a particular third-party application rather than generic for all applications. Each 1:1:1 token contains application-specific authorization information, allowing the system to maintain simple token issuance while achieving fine-grained control over which specific applications can access data.
3Productivity
If aggregators centrally manage all data access, then coordination between multiple financial institutions and applications is simplified, but the ability to independently track and revoke access for individual institutions is reduced
Solution Approach 1:
The patent implements feedback mechanisms where financial institutions receive notifications when their 1:1:1 tokens are issued or revoked. This enables institutions to independently track their data access permissions and take action to revoke access when needed, maintaining coordination efficiency through standardized token processes while preserving independent monitoring and control capabilities.
Data Source
AI summary
Computing platforms, methods, and storage media for processing a data access request are disclosed. Exemplary implementations may: generate, at the computing platform and based on a received data access request, a revocable 1:1:1 token that authorizes data sharing for a specific combination of third party application-aggregator-institution for a user associated with a communication device; and cause display of a user interface including a list of a plurality of third party applications for which data access is currently granted and for which a revocable 1:1:1 token is stored, the user interface enabling selective revocation of data access from among the listed plurality of third party applications. Exemplary implementations may generate an instruction to delete the stored revocable 1:1:1 token associated with the selected third party application, and may cause display of an access revocation selector, and may generate a selective revocation request associated with the selective revocation of data access.


