DYNAMIC SECURITY CONTROLS FOR DATA SHARING BETWEEN SYSTEMS

    公开(公告)号:US20210383019A1

    公开(公告)日:2021-12-09

    申请号:US17410532

    申请日:2021-08-24

    IPC分类号: G06F21/62 H04L29/06

    摘要: In an aspect, the present application may describe a method. The method may include: receiving, from a remote computing device, a first indication of consent for an authenticated entity to share data with a first third party server, the first indication of consent associated with a first sharing permission defining a first sharing scope; in response to receiving the first indication of consent: configuring a server to share data for the authenticated entity with the first third party server based on the sharing permission; identifying a first safety score, the first safety score associated with the first third party server; and updating a risk score for the authenticated entity based on the first safety score and the first sharing permission; and sending the updated risk score for the authenticated entity to the remote computing device for display thereon.

    SYSTEM AND METHOD FOR INITIATING DATA RECORD CREATION AT A THIRD PARTY SERVER

    公开(公告)号:US20230078168A1

    公开(公告)日:2023-03-16

    申请号:US17476863

    申请日:2021-09-16

    IPC分类号: G06F16/21 G06F9/54

    摘要: A server computer system comprises a processor; a communications module coupled to the processor; and a memory coupled to the processor, the memory storing instructions that, when executed, configure the processor to generate a recommendation to create a data record at least at one third party server; send, via the communications module and to a computing device, a signal causing the computing device to display the recommendation, the recommendation including a selectable option to create the data record at the at least one third party server; receive, via the communications module and from the computing device, a signal indicating selection of the selectable option to create the data record at the at least one third party server; engage, via the communications module, the third party server to initiate creation of the data record; retrieve previously-obtained identity data required to create the data record; and provide, via the communications module and to the at least one third party server, the previously-obtained identity data to create the data record.

    SYSTEM AND METHOD OF PROCESSING A DATA ACCESS REQUEST

    公开(公告)号:US20230101530A1

    公开(公告)日:2023-03-30

    申请号:US17490208

    申请日:2021-09-30

    摘要: Computing platforms, methods, and storage media for processing a data request are disclosed. Exemplary implementations may: receive a data transfer request including data transfer instructions associated with the data transfer; obtain an aggregator access profile specifying application programming interface (API) access to be granted to a data aggregator with respect to one or more APIs; obtain a user account authorization token specifying access to be granted to the data aggregator with respect to one or more user accounts; determine access permissions associated with the data transfer instructions based on a combination of the aggregator access profile and the user account authorization token; and transmit an access notification based on the determined access permissions, the access notification specifying the combination of the one or more APIs and the one or more user accounts to which the data aggregator is granted access. Application-specific account permissions and data type permissions may be specified.

    SYSTEM AND METHOD OF PROCESSING A DATA ACCESS REQUEST

    公开(公告)号:US20230096672A1

    公开(公告)日:2023-03-30

    申请号:US17490743

    申请日:2021-09-30

    IPC分类号: G06F21/62 G06Q40/02

    摘要: Computing platforms, methods, and storage media for processing a data access request are disclosed. Exemplary implementations may: receive, at an apparatus, a data access request from a communication device and via a network; and generate, at the apparatus and based on the received data access request, a revocable 1:1:1 token that authorizes data sharing for a specific combination of third party application-aggregator-institution. Exemplary implementations may transmit the revocable 1:1:1 token for storage in a token database, and may store the 1:1:1 tokens in a token database associated with an institution related to the data access request; this allows access to be managed by the user and controlled by the institution, without relying on the aggregator. Exemplary implementations may provide a dashboard enabling a user to individually remove apps from data sharing, based on management of the 1:1:1 tokens.

    DYNAMIC SECURITY CONTROLS FOR DATA SHARING BETWEEN SYSTEMS

    公开(公告)号:US20200311298A1

    公开(公告)日:2020-10-01

    申请号:US16367539

    申请日:2019-03-28

    IPC分类号: G06F21/62 H04L29/06

    摘要: In an aspect, the present application may describe a method. The method may include: receiving, from a remote computing device, a first indication of consent for an authenticated entity to share data with a first third party server, the first indication of consent associated with a first sharing permission defining a first sharing scope; in response to receiving the first indication of consent: configuring a server to share data for the authenticated entity with the first third party server based on the sharing permission; identifying a first safety score, the first safety score associated with the first third party server; and updating a risk score for the authenticated entity based on the first safety score and the first sharing permission; and sending the updated risk score for the authenticated entity to the remote computing device for display thereon.

    SYSTEM AND METHOD OF PROCESSING A DATA ACCESS REQUEST

    公开(公告)号:US20240362353A1

    公开(公告)日:2024-10-31

    申请号:US18764944

    申请日:2024-07-05

    IPC分类号: G06F21/62 G06Q40/02

    CPC分类号: G06F21/6218 G06Q40/02

    摘要: Computing platforms, methods, and storage media for processing a data access request are disclosed. Exemplary implementations may: generate, at the computing platform and based on a received data access request, a revocable 1:1:1 token that authorizes data sharing for a specific combination of third party application-aggregator-institution for a user associated with a communication device; and cause display of a user interface including a list of a plurality of third party applications for which data access is currently granted and for which a revocable 1:1:1 token is stored, the user interface enabling selective revocation of data access from among the listed plurality of third party applications. Exemplary implementations may generate an instruction to delete the stored revocable 1:1:1 token associated with the selected third party application, and may cause display of an access revocation selector, and may generate a selective revocation request associated with the selective revocation of data access.

    SYSTEMS AND METHODS FOR EVALUATING SECURITY OF THIRD-PARTY APPLICATIONS

    公开(公告)号:US20220147639A1

    公开(公告)日:2022-05-12

    申请号:US17585850

    申请日:2022-01-27

    IPC分类号: G06F21/57 G06F21/52

    摘要: A method for evaluating security of third-party application is disclosed. The method includes: receiving, from a first application, a request to obtain first account data for a user account associated with a protected data resource; generating fake data for at least a portion of the requested first account data; providing, to the first application, a first data set in response to the request, the first data set including at least the generated fake data; monitoring use of the first data set by the first application; detecting a trigger condition indicating misuse of account data based on monitoring use of the first data set by the first application; in response to detecting the trigger condition, generating a notification identifying the misuse of account data; and transmitting the notification to a computing device associated with an application user.

    SYSTEMS AND METHODS FOR EVALUATING SECURITY OF THIRD-PARTY APPLICATIONS

    公开(公告)号:US20210089657A1

    公开(公告)日:2021-03-25

    申请号:US16577185

    申请日:2019-09-20

    IPC分类号: G06F21/57 G06F21/52

    摘要: A method for evaluating security of third-party application is disclosed. The method includes: receiving, from a first application, a request to obtain first account data for a user account associated with a protected data resource; generating fake data for at least a portion of the requested first account data; providing, to the first application, a first data set in response to the request, the first data set including at least the generated fake data; monitoring use of the first data set by the first application; detecting a trigger condition indicating misuse of account data based on monitoring use of the first data set by the first application; in response to detecting the trigger condition, generating a notification identifying the misuse of account data; and transmitting the notification to a computing device associated with an application user.