Patent · US Active

Secure permissioning of access to user accounts, including secure deauthorization of access to user accounts

US10904239B2 · kind B2 · utility

22Cited by
140References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateNov 19, 2019
Grant dateJan 26, 2021
Priority date
Expiry dateNov 19, 2039

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/102
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A permissions management system is disclosed for enabling a user to securely authorize a third-party system to access user account data and initiate transactions related to a user account, without disclosing to the third-party system account credentials. The system enables the user to also securely de-authorize the third-party system. For example, records may be automatically generated that securely store account information, including one or more permissions related to the account and/or the third-party. A token associated with a record may be shared with the third-party system, but neither the record itself, nor the user account credentials, may be shared with the third-party. Accordingly, the third-party may request user account data and/or initiate transactions by providing the token, but does not itself know, e.g., the user account credentials. Further, the user may set various permissions related to the token, and may also revoke the token (e.g., de-authorize the third-party), thus providing increased security to the user's account.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.