Patent · US Active

Secure permissioning of access to user accounts, including secure deauthorization of access to user accounts

US11050729B2 · kind B2 · utility

20Cited by
142References
15Claims
0Family size

Assignee

Inventors

Key dates

Filing dateNov 19, 2019
Grant dateJun 29, 2021
Priority date
Expiry dateJan 2, 2040

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/102
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A permissions management system is disclosed for enabling a user to securely authorize a third-party system to access user account data and initiate transactions related to a user account, without disclosing to the third-party system account credentials. The system enables the user to also securely de-authorize the third-party system. For example, records may be automatically generated that securely store account information, including one or more permissions related to the account and/or the third-party. A token associated with a record may be shared with the third-party system, but neither the record itself, nor the user account credentials, may be shared with the third-party. Accordingly, the third-party may request user account data and/or initiate transactions by providing the token, but does not itself know, e.g., the user account credentials. Further, the user may set various permissions related to the token, and may also revoke the token (e.g., de-authorize the third-party), thus providing increased security to the user's account.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.