SYSTEMS AND METHODS FOR DETECTING CHANGES IN DATA ACCESS PATTERN OF THIRD-PARTY APPLICATIONS

    公开(公告)号:US20210084070A1

    公开(公告)日:2021-03-18

    申请号:US16571394

    申请日:2019-09-16

    Abstract: A method for evaluating security of third-party application is disclosed. The method includes: in an automated test environment: launching a test instance of a first application; and obtaining a data access signature of the first application based on identifying at least one application state of the first application and account data retrieved by the first application from a user account at a protected data resource in the at least one application state; receiving, from a client device associated with the user account, an indication of access permissions for the first application to access the user account for retrieving account data; detecting a change in the data access signature of the first application; and in response to detecting the change in the data access signature of the first application, notifying the user of the detected change.

    ELECTRONIC ACCOUNT SETTLEMENT VIA DISTINCT COMPUTER SERVERS

    公开(公告)号:US20200090181A1

    公开(公告)日:2020-03-19

    申请号:US16132308

    申请日:2018-09-14

    Abstract: A server includes a processor that receives, from a first device, initiation message(s) each including a service identifier and a service value and, for each initiation message, saves in a database a record comprising the service identifier in association with the service value. The processor receives, from a second device, authorization message(s) each including one of the service identifiers and an authorization value, and for each authorization message, validates one of the initiation messages by (i) locating in the database the record comprising the one service identifier, and (ii) confirming that the service value in the located database record matches the authorization value. The processor updates a journal with an entry identifying a transfer between a first ledger and a second ledger in an amount equal to a sum of the service values of the validated initiation messages, and provides the first device with a message confirming the transfer.

    Distributed authentication at a physical premises

    公开(公告)号:US12131361B2

    公开(公告)日:2024-10-29

    申请号:US17824165

    申请日:2022-05-25

    CPC classification number: G06Q30/0609 G06Q50/265

    Abstract: According to an aspect there is provided an ambient commerce system. The ambient commerce system may include a sensor at an ambient commerce premises, a communication module, and a processor coupled to the sensor and the communication module. The ambient commerce system further includes a memory coupled to the processor. The memory stores processor-executable instructions which, when executed, cause the processor to: detect, based on an output of one or more of the sensors, an unauthenticated entity at an ambient commerce premises; receive, from a first independent trusted system and via the communication module, an indication that authentication has been performed by the first independent trusted system for the unauthenticated entity using a first authentication parameter; determine that the entity is an authenticated entity based on the indication that the authentication has been performed and at least a second authentication parameter; and perform an ambient commerce operation for the authenticated entity.

    Method and system for obtaining consent to perform an operation

    公开(公告)号:US11989278B2

    公开(公告)日:2024-05-21

    申请号:US18179517

    申请日:2023-03-07

    CPC classification number: G06F21/36 G06F3/0482 G06F21/6209 H04L9/0643 H04L9/50

    Abstract: A server comprises a communications module; a processor coupled with the communications module; and a memory coupled to the processor and storing processor-executable instructions which, when executed by the processor, configure the processor to receive, via the communications module and from a computing device, a signal representing a request to add an authorized user to an account of an entity hosted by a first institution associated with the server; send, via the communications module and to a second server associated with a second institution hosting an account of the authorized user, a signal that includes a unique key and an identifier of the entity, the signal causing the second server to store the unique key and the identifier in memory and associating the unique key and the identifier with the account of the authorized user; receive a signal representing a request to perform an operation for the entity; in response to receiving the request to perform the operation, send, via the communications module and to a digital identity network, a request for a unique key associated with the entity; receive, via the communications module and from the digital identity network, the unique key; and in response to receiving the unique key, perform the operation.

Patent Agency Ranking