Secure permissioning of access to user accounts, including secure deauthorization of access to user accounts
US10904239B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Nov 19, 2019 |
| Grant date | Jan 26, 2021 |
| Priority date | — |
| Expiry date | Nov 19, 2039 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L2463/102
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A permissions management system is disclosed for enabling a user to securely authorize a third-party system to access user account data and initiate transactions related to a user account, without disclosing to the third-party system account credentials. The system enables the user to also securely de-authorize the third-party system. For example, records may be automatically generated that securely store account information, including one or more permissions related to the account and/or the third-party. A token associated with a record may be shared with the third-party system, but neither the record itself, nor the user account credentials, may be shared with the third-party. Accordingly, the third-party may request user account data and/or initiate transactions by providing the token, but does not itself know, e.g., the user account credentials. Further, the user may set various permissions related to the token, and may also revoke the token (e.g., de-authorize the third-party), thus providing increased security to the user's account.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.