Systems, methods, and computing platforms for managing network-enabled security codes

By using UUEK and dynamic security codes on the intermediate computing platform, the security and cost issues caused by credential dependence in existing technologies are resolved, credential-free and secure network exchange is achieved, and the flexibility and security of exchange processing are improved.

CN119384812BActive Publication Date: 2025-09-091080 NETWORK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202380040858.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2023-08-02
Filing Date
2023-08-03
Publication Date
2025-09-09
Estimated Expiration
2043-08-03

AI Technical Summary

Technical Problem

Existing network-based exchange processing technologies rely on permanent credentials, leading to increased fraud, regulatory and compliance costs, and exposing users to the risk of identity theft and damaged credit scores. Traditional security codes are vulnerable to brute force attacks, cannot be flexibly configured, and increase network traffic and exchange costs.

Method used

An intermediate computing platform is used to use UUEK (Universally Unique Temporary Key) instead of permanent credentials, communicate with member platforms through API interfaces, manage security codes to authorize exchanges, realize credential-free exchanges, and use UUEK's flexible interface and dynamic security codes to improve exchange security and network throughput.

Benefits of technology

It achieves seamless and secure value-based exchange, reduces computing resource requirements, reduces the risk of network attacks, and improves network throughput and the flexibility and security of exchange processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119384812B_ABST
    Figure CN119384812B_ABST
Patent Text Reader

Abstract

Various embodiments of the present disclosure provide techniques for facilitating cross-network credential-free exchanges using multiple identifier mappings, member interfaces, and security code element groups customized for ephemeral keys. These techniques may include receiving a secure interaction request and issuing or enabling a previously issued universally unique ephemeral key (UUEK) in response to the secure interaction request. These techniques may include authenticating a user, a tool, or the UUEK, and in response, storing a security event for the user, the tool, or the UUEK, and providing a secure interaction response indicating the security event. These techniques may include subsequently receiving an exchange request for performing a value-based exchange using the UUEK, and facilitating the exchange request based at least in part on the security event.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit of U.S. Provisional Patent Application Serial No. 63 / 370,278, filed on August 3, 2022, and U.S. Patent Application Serial No. 18 / 363,796, filed on August 2, 2023, the entire contents of both applications (including any figures, tables, drawings, and appendices) are incorporated herein by reference. Technical Field

[0003] Embodiments of the present disclosure generally relate to network-enabled security codes. Background Art

[0004] In view of the limitations of existing exchange processing technologies and architectures, various embodiments of the present disclosure address the technical challenges associated with network-based exchanges. Existing processes for performing exchanges over computing networks rely on the use of permanent credentials such as payment credentials (e.g., card numbers, usernames, passwords, bank routing numbers, account numbers, etc.) and their proxies, which expose recipients of the credentials to fraud, regulatory and compliance costs, and reputational risks. Furthermore, due to the static nature of traditional credentials, each time a user provides their credentials for an exchange, the user must accept the risk of financial loss, damaged credit score, identity theft, and other consequences. The inherent deficiencies in the security of permanent credentials are typically addressed using strict communication protocols, data management procedures, and authentication schemes, each of which introduces additional technical problems by increasing overhead and complicating network-based transactions without addressing the fundamental technical issues of data security.

[0005] For example, one technique involves using a vendor-managed personal identification number (PIN) and / or other security code that can be set by the user or the vendor and subsequently used to authenticate exchanges using a specific account. These codes can be encoded within the physical media and automatically authenticated each time an exchange is authorized using the physical media. Alternatively, the code can be provided to the vendor along with the exchange request to authorize each individual exchange.

[0006] Traditional codes lack flexibility and are insecure in many different ways. First, they are deployed as four-digit codes, which provides an attack vector for malicious parties because they can be subjected to brute-force attacks given the limited number of available combinations. Furthermore, to work effectively, traditional codes must be provided at the same time as the exchange is requested. This results in increased network traffic and increases the cost of the exchange even if the exchange is rejected. Furthermore, such codes are traditionally applied to all exchanges and cannot be configured to target specific characteristics of the request (e.g., exchange value, time, etc.), making changes cumbersome and increasing liability for users (e.g., in cases where the code is encoded on physical media) or vendors. These and other technical challenges limit the effectiveness of traditional security codes, which in turn creates security challenges for executing network-based exchanges.

[0007] Various embodiments of the present disclosure make significant contributions to various existing network-based value exchange processing technologies by addressing each of these technical challenges. Summary of the Invention

[0008] Various embodiments of the present disclosure disclose a secure intermediary computing platform and computing service that facilitates credential-free execution of value-based exchanges that utilize UUEKs (Universally Unique Ephemeral Keys) to eliminate the use of permanent credentials. To this end, the intermediary computing platform can facilitate interactions between one or more member platforms to register users and / or user tools in a value exchange system supported by a new, temporary data structure referred to herein as a UUEK. Unlike traditional exchange systems, the intermediary computing platform does not receive or rely on permanent user or tool credentials to register users and / or users' tools. Eliminating such credentials enables the use of new, more flexible interfaces, such as the application programming interfaces (APIs) described herein, which the intermediary computing platform leverages to communicate with different network members to register users, their tools, tool policies, and different security codes without exposing user credentials at any step in the process. Once registered, the intermediary computing platform can issue a UUEK to the member platform, which can replace traditional permanent credentials. The issued UUEK does not reflect permanent credentials or any other sensitive user or tool information. The interface between the member platform and the intermediary platform can allow (i) the user to present the UUEK issued by the member platform (without explicitly referencing the permanent credential) to the intermediary platform, and (ii) the intermediary platform to map the issued UUAK to the instrument key of the same or another member platform and provide the instrument key to the member platform to authorize the value-based exchange. In this way, network-based transactions can be authorized in a seamless process without exposing sensitive user or instrument information that may be vulnerable to network attacks.

[0009] Some of the techniques disclosed herein further enhance the security of network-based exchanges by leveraging flexible interfaces (e.g., APIs) between entities involved in value-based exchanges to establish security codes for UUEKs. The security codes can be used to enable and disable UUEKs used to authorize exchanges. In this way, the execution of value-based exchanges can be predicted based at least in part on decisions regarding the security codes for the UUEKs. Importantly, the security codes are network-managed and enable n-character codes of potentially varying complexity. As described herein, this allows tool-specific security measures to be enforced by an intermediary platform before exchange authorization is provided to a service provider (e.g., a financial institution) without the risk of exposing sensitive user or financial information. Ultimately, the techniques disclosed herein achieve additional flexibility (e.g., through the use of new interfaces, etc.) and security (e.g., via the elimination of permanent credentials, the introduction of new security codes, etc.) while reducing computing power requirements and significantly improving network throughput for exchange processing compared to conventional techniques.

[0010] In some embodiments, a computer-implemented method includes receiving, by one or more processors, a security interaction request indicating a security code input and a user identifier; identifying, by the one or more processors, a security code element group for the security code input based on the user identifier; verifying, by the one or more processors, the security code input based at least in part on a comparison between the security code input and a security code reference of the security code element group; in response to verifying the security code input, (i) storing, by the one or more processors, a security event for the user, and (ii) providing, by the one or more processors, a security interaction response indicating the security event, wherein the security interaction response indicates at least one of (a) a universally unique temporary key (UUEK) or (b) a security event for the UUEK; receiving, by the one or more processors, an exchange request for performing a value-based exchange using the UUEK; providing, by the one or more processors, an exchange authorization request to the member platform, wherein the exchange authorization request indicates the tool identifier and the security event; and receiving, by the one or more processors, an exchange authorization response indicating at least one of an exchange approval or an exchange rejection, wherein the exchange authorization response is based at least in part on the security event.

[0011] In some embodiments, a computing system includes a memory and one or more processors communicatively coupled to the memory, the one or more processors configured to receive a security interaction request indicating a security code input and a user identifier; identify a security code element group for the security code input based on the user identifier; verify the security code input based at least in part on a comparison between the security code input and a security code reference for the security code element group; in response to verifying the security code input, (i) store a security event for the user, and (ii) provide a security interaction response indicating the security event, wherein the security interaction response indicates at least one of (a) a universally unique temporary key (UUEK) or (b) a security event for the UUEK; receive an exchange request for performing a value-based exchange using the UUEK; provide an exchange authorization request to a member platform, wherein the exchange authorization request indicates a tool identifier and the security event; and receive an exchange authorization response indicating at least one of an exchange approval or an exchange rejection, wherein the exchange authorization response is based at least in part on the security event.

[0012] In some embodiments, one or more non-transitory computer-readable storage media include instructions that, when executed by one or more processors, cause the one or more processors to receive a security interaction request indicating a security code input and a user identifier; identify a security code element group for the security code input based on the user identifier; verify the security code input based at least in part on a comparison between the security code input and a security code reference for the security code element group; in response to verifying the security code input, (i) store a security event for the user, and (ii) provide a security interaction response indicating the security event, wherein the security interaction response indicates at least one of (a) a universally unique ephemeral key (UUEK) or (b) a security event for the UUEK; receive an exchange request for performing a value-based exchange using the UUEK; provide an exchange authorization request to a member platform, wherein the exchange authorization request indicates a tool identifier and the security event; and receive an exchange authorization response indicating at least one of an exchange approval or an exchange rejection, wherein the exchange authorization response is based at least in part on the security event. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Having generally described the present disclosure, reference will now be made to the accompanying drawings (which are not necessarily drawn to scale), and wherein:

[0014] Figure 1 is an example diagram of a computing ecosystem according to one or more embodiments of the present disclosure;

[0015] Figure 2 is an example schematic diagram of a computing platform according to one or more embodiments of the present disclosure;

[0016] Figure 3 is an example schematic diagram of a client device according to one or more embodiments of the present disclosure;

[0017] Figure 4 is an example block diagram of an example voucherless value exchange system according to one or more embodiments of the present disclosure;

[0018] Figure 5 is an example data graph for facilitating voucherless value exchange according to one or more embodiments of the present disclosure;

[0019] Figure 6 A process flow for facilitating network management security codes for users according to one or more embodiments of the present disclosure is provided;

[0020] Figure 7A -C provides a process flow for establishing a secure cross-entity relationship according to one or more embodiments of the present disclosure;

[0021] Figure 8A -B provides a process flow for facilitating secure credential-free interaction according to one or more embodiments of the present disclosure;

[0022] Figure 9A -C provides an example interface for facilitating voucherless value exchange according to one or more embodiments of the present disclosure. DETAILED DESCRIPTION

[0023] Various embodiments of the present disclosure will be described more fully below with reference to the accompanying drawings, which illustrate some, but not all, of the embodiments of the present disclosure. In fact, the present disclosure can be embodied in many different forms and should not be construed as limited to the embodiments described herein; rather, these embodiments are provided so that the present disclosure satisfies applicable legal requirements. Unless otherwise specified, the term "or" as used herein has both an alternative and a conjunction meaning. The terms "illustrative" and "example" are used as examples and do not indicate a level of quality. Words such as "calculate," "determine," "generate," and / or similar words are used interchangeably herein to refer to the creation, modification, or identification of data. In addition, "based at least in part on," "based at least on," "based on," and / or similar words are used interchangeably herein in an open manner, so unless otherwise specified, they do not necessarily mean based only at least in part on or based only on the referenced element. The same figure numbers always refer to the same elements.

[0024] I.Overview and Technical Advantages

[0025] Various embodiments of the present disclosure provide technical solutions for managing network-based exchanges. In various embodiments, an exchange platform can be configured to facilitate credential-free value exchanges between one or more member platforms. These exchanges can occur in real time without requiring permanent credentials that could expose members to financial, legal, reputational, or other risks. Thus, in various embodiments, client devices can buy, sell, and / or perform value-based exchanges in real time over any network without exposing sensitive information that could be vulnerable to network-based attacks.

[0026] Embodiments of the present disclosure provide improved tool-level verification and enablement techniques that utilize new interfaces, secure code management, and policy matching techniques to increase data security and communication flexibility while reducing the expenditure requirements for computing resources to protect sensitive data over network communications.

[0027] Some techniques of the present disclosure, for example, retrieve data objects and convert them into unique data keys that can only be identified by authorized entities. Data keys can be provided and / or established by utilizing an exchange interface between an exchange platform and other member platforms in an exchange network. Once established, the data keys can be mapped to sensitive credentials stored within a source platform (e.g., a service provider platform) without requiring network transmission of the sensitive credentials. To facilitate value-based exchanges, future communications may replace traditional permanent credentials with data keys to enable the source platform to identify the permanent credentials and / or perform one or more actions on specific tools associated with them. In this way, an exchange platform can facilitate exchanges using keys (and / or other identifiers) that themselves cannot be traced back to the underlying sensitive information. This, in turn, allows the exchange platform to comprehensively track, facilitate, and distribute network-based communications without exposing members to cyber attacks.

[0028] Some embodiments of the present disclosure propose network-based exchange processing techniques for facilitating credential-free exchanges. To this end, some of the techniques of the present disclosure utilize a new data structure, the UUEK, which can replace the permanent credentials traditionally used to authorize value-based exchanges. Using the techniques of the present disclosure, UUEKs can be securely issued across member platforms, allowing users to perform value-based exchanges using an identifier that is recognizable by a single party, the exchange platform. The UUEK can be mapped to a unique identifier that can reference sensitive information without directly identifying (and thereby exposing) the sensitive information. For example, the unique identifier can reference a mapping that can only be interpreted by the source platform, making it impossible for malicious parties unaffiliated with the exchange platform to use the identifier. In this way, the exchange platform can distribute, track, and facilitate exchanges without exposing member platforms to data security risks. Furthermore, the exchange platform can continuously update, modify, and / or redistribute the UUEK to member platforms to continuously adapt the UUEK in real time. In this way, the exchange platform can provide technical improvements to data and network security while reducing the computing resource requirements (e.g., for securely encrypting permanent credentials) to facilitate value-based exchanges.

[0029] Certain techniques of the present disclosure can utilize the disclosed credentialless exchange to enable the use of flexible exchange interfaces between members of an exchange network. Unlike traditional exchange interfaces, credentialless exchange allows for the use of n-character security codes tailored to the UUEK, which facilitates complex network management. Thus, an intermediate computing platform can receive the information necessary to establish a security code tailored to the UUEK. The security code can be used to validate the UUEK before an exchange is initiated. This allows for proactive filtering of exchanges based at least in part on the accuracy of the temporary data structure. This, in turn, limits network traffic to exchanges most likely to be authorized, thereby improving network performance for a robust network-based exchange ecosystem. Furthermore, network management of security codes can increase the achievable complexity of the actual code, for example, by enabling n-character codes of varying complexity. Even a simple n-character code can have over 14,776,336 possible combinations, which is significantly more secure than the 1,679,616 possible combinations of a traditional 4-character alphanumeric code.

[0030] Embodiments of example inventive and technical advantages of the present disclosure include (i) data conversion, mapping, and processing schemes for facilitating network-based credentialless exchange, (ii) exchange interfaces and network-based communication schemes for improving network security for cross-platform communications, (iii) temporary data structures and data management techniques for distributing temporary data structures to facilitate real-time, secure, and dynamic value-based exchange, and (iv) UUEK verification techniques for enabling and / or disabling UUEKs for exchange.

[0031] II. Example Definition

[0032] In some embodiments, the term "exchange platform" refers to a computing entity configured to facilitate voucherless value exchange among one or more members of an exchange network. The exchange platform may include one or more processing devices, storage devices, etc., which are physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks that facilitate value system-independent exchange. In some examples, the exchange platform may include, define, and / or otherwise utilize one or more APIs to facilitate communication (e.g., requests and responses, etc.) between multiple members. As described herein, the APIs may be utilized to facilitate secure exchanges between one or more members of any value system.

[0033] In some embodiments, the term "member" refers to an entity that collaborates with an exchange platform to participate in a value exchange. For example, a member may include (i) a partner that utilizes the exchange platform to receive value, (ii) a service provider that utilizes the exchange platform to provide value, and / or (iii) both a partner and a service provider. As used herein, when a member receives value through a value exchange, the member may be referred to as a partner; and / or when a member provides value through a value exchange, the member may be referred to as a service provider. Thus, depending on the member's role in the value exchange, the same member may be a partner or a service provider. For example, a member may be a partner that receives value through a value exchange. The same member may be a service provider that provides value in another value exchange. In some examples, the same member may be both a partner and a service provider in the same value exchange, such that the member may utilize the exchange platform to provide and subsequently receive value in a single member value exchange.

[0034] In one embodiment, when a member uses a service provided by a service provider, the member is a partner. Partners can include any value-seeking entity in any value system. For example, in a financial value system, partners can include merchants (such as retailers, physical stores, etc.) that can use service providers (such as financial institutions) to access funds for financial transactions. Additionally or alternatively, in an information value system, partners can include news publishers (e.g., newspapers, media organizations, etc.) that can use service providers such as news agencies (e.g., wire services, news services, etc.) to access information for information transactions. It should be understood that the technology of the present disclosure can be applied to any value system, and partners can include any value seeker for any corresponding value system.

[0035] In some embodiments, when a member provides a service to a partner, the member is a service provider. A service provider can include a value source in any value system. For example, in a financial value system, a service provider can include a financial institution (e.g., a bank, a currency exchange platform, a credit union, etc.) that can provide direction to funds for financial transactions between one or more entities. Additionally or alternatively, in an information value system, a service provider can include a news agency (e.g., a wire service, a news service, etc.) that can provide a source of information for publication by a news publisher. It should be understood that the technology of the present disclosure can be applied to any value system, and a service provider can include any value source of any corresponding value system.

[0036] In some embodiments, the term "service provider tool" refers to the mechanism used by a service provider to provide value on behalf of a particular user. The service provider tool may depend on the value system and / or the service provider. In some examples, the service provider tool may include an account at the service provider. For example, in a financial value system, the service provider tool may include a bank account (e.g., checking, savings, etc.), a brokerage account, a line of credit, etc. In an information value system, the service provider tool may include a subscriber account, etc. In some examples, the service provider tool may include a virtual tool hosted by the service provider platform.

[0037] In some embodiments, the services provided by the service provider are subject to one or more policies and / or security codes. For example, the service provider and / or service provider tool may be associated with a security code for verifying use of the service provider tool. Additionally or alternatively, the service provider may be associated with one or more member policies for authenticating the security code.

[0038] In some embodiments, the term "security code" refers to a data entity that defines a sequence of characters used to verify a user in an interaction (e.g., physical exchange, virtual exchange, registration, and / or the like). The security code may include a sequence of one or more different characters (e.g., six characters, eight characters, etc.) of dynamic length that may be set and / or provided to the user in advance by the user. The security code may be provided later by the user to verify the user's presence for the interaction (e.g., as described herein, by comparing the security code input with a security code reference). The one or more different characters may include any number of alphanumeric characters, emoticons, Chinese characters, winged fonts, and / or the like.

[0039] In some embodiments, the security code is a network-managed n-character PIN. As described herein, the security code can be managed as a service by a client device to (i) securely retrieve the UUEK, (ii) register the tool with the member platform, and / or (iii) enable or disable the use of the UUEK (and / or any other exchange credentials) prior to an exchange request. In this way, security codes can be deployed for any type of service provider tool by retrieving, registering, and / or enabling or disabling the corresponding UUEK. By managing security codes at the network level, members can benefit from faster exchanges because the possibility of authorization being denied due to an invalid PIN is eliminated. For example, the UUEK can be disabled until a security code is received to enable the UUEK. The exchange platform can prevent users from initiating exchanges before the UUEK is enabled, thereby ensuring that all exchange authorization requests provided to the service provider have been pre-verified based on the security code. This effectively reduces network traffic between members in the exchange network, thereby reducing network congestion in traditional high-traffic communication systems.

[0040] In some embodiments, the security code corresponds to the user. For example, the security code can be pre-set and / or provided to the user by the user through interaction with the exchange platform. For example, the security code can be set by the user through interaction with an exchange network widget embedded in a member software application. This allows the security code to be set without directly interacting with or sharing the security code with the corresponding member platform. In some examples, the security code can be tool-specific or member-specific. For example, the corresponding security code can be configured to retrieve and / or enable a service provider tool on a specific member platform and / or a UUEK for a specific member platform. Additionally or alternatively, the corresponding security code can be configured to register the member platform's account with the exchange network. Exemplarily, the exchange platform can manage the use of security codes to implement one or more security actions using multiple security code tuples, each security code tuple associating a security code with a corresponding user, member platform, and / or service provider tool.

[0041] In some embodiments, the term "security code element group" refers to a data entity that defines an association between a security code, a user, and one or more of a member platform and / or a service provider tool. A security code element group may include a data object, a record, and / or any other data structure (e.g., a link node, etc.) configured to represent an association between a security code and a user, and in some embodiments, an association with a member platform, a service provider tool, or both. For example, a security code element group may include a security code reference, a user identifier, one or more member identifiers, one or more tool identifiers, and / or contextual pairing data. The contextual pairing data may include one or more pairing attributes, such as one or more timing attributes. For example, a timing attribute may indicate a configuration time (e.g., indicating a time when the security code element group was set), an expiration time (e.g., a time when the security code must be reset), and / or the like. As described herein, an exchange platform may utilize a security code element group to identify a security code reference for a user and to perform a security action on the user's behalf (e.g., allowing exchange using a UUEK) based at least in part on a comparison between the security code reference and a security code input provided by the user.

[0042] In some embodiments, the term "security code reference" refers to a data entity that defines a security code for a record. A security code reference may include an internal representation of a security code for a user (eg, for an exchange platform, etc.).

[0043] In some embodiments, the term "security code input" refers to a data entity that defines a character sequence provided for performing a security action. As described herein, the security code input can include user input provided by a user. In some examples, if the security code input matches a security code reference, the security action can be performed for the user. As an example, if the security code input matches a security code reference for the user (e.g., defined by a security code tuple), the corresponding UUEK assigned to the user can be activated.

[0044] In some embodiments, the term "security code request" refers to a data entity defined as a request for a user to set, reset, and / or remove a security code. A security code request may be provided to an exchange platform from a member of an exchange network. The security code request may indicate the user's member user reference and, in some examples, a member tool reference for the user. Exemplarily, a security code request that includes only a member user reference may default to all service provider tools associated with the user and may, for example, initiate a security code set, reset, and / or removal operation applicable to all service provider tools maintained by the corresponding member platform for the user. Additionally or alternatively, a security code request that includes both a member user reference and a member tool reference may initiate a security code set, reset, and / or removal operation applicable to a specific service provider tool maintained by the corresponding member platform for the user. In addition to the reference, the security code request may include a code action attribute (indicating the desired set, reset, and / or removal operation) and a security code input (indicating a new, modified, or existing n-character PIN).

[0045] In some embodiments, the term "secure interaction request" refers to a data entity that defines a request to perform a secure interaction using a security code input. The secure interaction request can be provided to the exchange platform from a member of the exchange network. The secure interaction request can indicate (i) a user, a member platform and / or a service provider tool, and (ii) a security code input for the user. Additionally or alternatively, the secure interaction request can indicate one or more contextual security attributes. The one or more contextual security attributes may include one or more timing attributes. For example, the one or more timing attributes may indicate a provision time (e.g., indicating a time to send a secure interaction request, etc.), a request time (e.g., a request time for performing a secure interaction, etc.), and / or the like.

[0046] A secure interaction request can be received from a member platform. For example, a user can initiate a secure interaction request through a member application hosted by a member platform representing a member of the exchange network. In some examples, a secure interaction request can be generated and / or provided in response to a selection input indicating a service provider tool, a UUEK for a service provider tool, and / or the like. As an example, a user can select a tool representation, a UUEK representation, and / or the like (e.g., through a partner application associated with a partner platform, a service provider application associated with a service provider platform, etc.) to authorize a value-based exchange. In some examples, a secure interaction request can be automatically initiated if the user and / or the selected tool, UUEK, and / or the like is associated with a security code. For example, in response to the selection, the member platform (e.g., through a corresponding member application) can prompt the user to enter a security code. The user can type the security code input to provide the secure interaction request.

[0047] In some embodiments, the term "verification event" refers to a data entity that defines the verification of a security code input by a user. A verification event may include a secure event, which may indicate successful verification between the security code input and the security code reference. Additionally or alternatively, the verification event may include an unsecure event, which may indicate failed verification between the security code input and the security code reference. For example, a secure event may indicate a determination that the security code input matches the corresponding security code reference. In some examples, an unsecure event may indicate a determination that the security code input does not match the corresponding security code reference. In some examples, the exchange platform may generate a security event in response to a determination that the security code input matches the corresponding security code reference. Additionally or alternatively, the exchange platform may generate an unsecure event in response to a determination that the security code input does not match the corresponding security code reference. In some examples, a security event may be associated with a security time period, and the exchange platform may generate an unsecure event in response to determining that the security time period has expired.

[0048] In some embodiments, the verification event is stored in association with a security data entity (e.g., a UUEK, a service provider tool, and / or a user). For example, the verification event may be stored in an exchange data object corresponding to the UUEK, a system tool data object corresponding to the service provider tool, a system user data object corresponding to the user, and / or the like. Additionally or alternatively, the verification event may be stored in association with a security code element group. For example, a secure event may be stored in response to a successful verification of a user, while an unsecure event may be stored in response to a failed verification of a user.

[0049] In some embodiments, the verification event includes contextual verification data. For example, the contextual verification data may indicate a verification timing. The verification timing may include a timestamp corresponding to the sending, receiving, creation, and / or determination of the verification request. For example, the contextual verification data may include a verification timestamp indicating the time when the exchange platform determines that the security code input and the security code reference match or do not match. In some examples, the contextual verification data may indicate a security time period. In response to the security event, the security time period may indicate a subsequent timestamp, duration, and / or the like of the security of the UUEK, service provider tools, and / or the like.

[0050] In some embodiments, the term "secure interaction response" refers to a data entity that defines a response to a secure interaction request. In some embodiments, the secure interaction response is provided from the exchange platform to the member that provided the secure interaction request. The secure interaction response may indicate a verification event.

[0051] In some embodiments, the term "member policy" refers to a data entity that defines one or more validation requirements for a service provider tool. A member policy may correspond to a member and / or a member's service provider tool. For example, a member policy may define one or more validation requirements for use of a service provider tool based at least in part on one or more member-specific criteria. Additionally or alternatively, a member policy may define one or more validation requirements for use of a service provider tool based at least in part on one or more tool-specific criteria. Member-specific criteria may apply to multiple service provider tools associated with a member, while tool-specific criteria may apply to at least one of multiple service provider tools associated with a member.

[0052] The verification requirements may indicate one or more attributes of a value-based exchange that require a secure interaction. For example, a previously issued UUEK may be used without a security code to authorize a value-based exchange that does not include one or more attributes that require a secure interaction. If the value-based exchange includes at least one attribute that requires a secure interaction, the UUEK may be prevented from authorizing the value-based exchange unless a verified security code is provided.

[0053] In some examples, the policy attributes may include an object identifier, one or more object attributes, and / or one or more value exchange attributes that identify an object and / or one or more authorized / unauthorized amounts of an object. For example, a member policy may include multiple object identifiers. The multiple object identifiers may indicate multiple objects that are authorized / unauthorized to obtain (e.g., purchase, etc.) without a security code.

[0054] In some examples, the object identifier may be a global object identifier. For example, the global object identifier may be a stock keeping unit (SKU) code. Additionally or alternatively, the global object identifier may be a manufacturer part number (MPN), a global trade item number (GTIN), a product or service name, an international standard book number (ISBN), a universal product code (UPC), an international article number (EIN), and / or the like. In some examples, the object identifier may include a system object identifier. For example, the system object identifier may include an identifier (e.g., a table identifier, etc.) corresponding to a record data object representing an object within an exchange platform. In some embodiments, the system object identifier and the global object identifier are the same.

[0055] In some embodiments, the policy attributes include value exchange attributes corresponding to a particular value-based exchange and / or objects included in the value-based exchange. For example, the value exchange attributes may include a threshold exchange value without a security code. For example, one or more exchange attributes may indicate an exchange value, and one or more verification requirements may define an exchange value threshold at which a corresponding security event is required for the service provider tool.

[0056] In some embodiments, the term "record data object" refers to a data object that represents an object that can participate in a value-based exchange. In some examples, a record data object can be an internal representation of an object used in an exchange platform. For example, an object can include different elements of a value-based exchange for which value is being transferred. A record data object for an object can include a data object that records one or more aspects of the object (e.g., an object identifier, object attributes, etc.).

[0057] For example, a record data object may include an object identifier and / or one or more object attributes for a particular object associated with a value system. The object may be based at least in part on a value system. For example, in a financial value system, an object may be a tangible or intangible item, product, and / or the like that can be purchased in exchange for a unit of currency. In a healthcare value system, an object may be a healthcare procedure, and / or the like, that is covered by a healthcare policy.

[0058] In some examples, the exchange platform can maintain and / or access an object data store comprising a plurality of record data objects. As described herein, the object data store can include a plurality of record data objects at least partially from one or more members of the exchange network.

[0059] In some embodiments, the term "object attribute" refers to a data entity that describes a characteristic of an object. Object attributes may include object-based attributes and / or exchange-based attributes.

[0060] For example, object-based attributes may include spatial attributes, count attributes, value attributes, source attributes, composite attributes, categorical attributes, and / or any other attributes that describe characteristics of an object. For example, a spatial attribute may indicate one or more dimensions of an object (e.g., height, width, weight, etc.), a value attribute may indicate the value of the object (e.g., price, etc.), a composition attribute may indicate one or more ingredients, components, etc. of an object, a categorical attribute may indicate one or more categories (e.g., restricted substances, etc.), and / or the like. For example, one or more categorical attributes may indicate whether an object is associated with (i) one or more general store categories, such as vegetables, fruits, dairy products, meats, grains, seeds, alcohol, tobacco, in-store consumables, hot foods, pharmacies, pet food, and non-food products, (ii) one or more medical categories, such as dental, ophthalmology, general health, etc., (iii) one or more information categories, such as international sources, domestic sources, etc., and / or the like. In one example, the ingredient attribute may indicate one or more ingredients of the object, such as the volume percentage of alcohol within the object, one or more ingredients such as meat, dairy derivatives, peanut derivatives, tree nut derivatives, soy derivatives, and / or the like.

[0061] In some examples, object-based attributes can be based at least in part on a value system. For example, in at least one financial-based value system, object-based attributes can include one or more line item attributes, one or more line item adjustments, and / or the like. Line item attributes can include a sequence, a line item group, a product code, an item name, an item source (e.g., supplier, manufacturer, etc.), a description, a quantity, a mass (e.g., grams, kilograms, etc.), one or more spatial dimensions (e.g., length, width, height, volume, etc.), a unit amount, a unit tax amount, a line amount (e.g., the amount of the line item), a line tax amount, and / or the like. Line item adjustments can include an adjustment type (e.g., manufacturer discount, store discount, return, pay cash, pay gift card, pay other, and / or the like), an item, product, or service code, an item description, an item quantity, a unit item, an item mass (e.g., grams, kilograms, etc.), a unit amount, a unit tax amount, a line amount (e.g., the amount of the line item), a line tax amount, and / or the like.

[0062] In some embodiments, the term "exchange request" refers to a data entity that defines a request to perform a value exchange. An exchange request may be provided to an exchange platform from a member of an exchange network. The exchange request may include one or more request attributes. The one or more request attributes may include one or more object identifiers, object attributes, and / or the like.

[0063] For example, the one or more request attributes may include a plurality of object identifiers corresponding to a plurality of objects associated with the value-based exchange. Additionally or alternatively, the one or more request attributes may include one or more object attributes for the plurality of objects. For example, the one or more object attributes may include one or more object-based attributes (e.g., one or more line item attributes), one or more exchange-based attributes (e.g., the number of objects, the location of the objects), and / or the like. For example, the exchange request may indicate an exchange location from which the object is to be obtained.

[0064] In some embodiments, the term "exchange authorization request" refers to a data entity that defines a request to execute a value-based exchange with a member. In some embodiments, the exchange authorization request is provided from the exchange platform to a member of the exchange network. For example, in response to an exchange request from a partner of the exchange network, the exchange authorization request may be provided to a service provider of the exchange network. In some examples, the exchange authorization request may indicate a validation event associated with a UUEK. For example, the exchange authorization request may indicate the disabled and / or enabled state of the UUEK used to initiate the value exchange.

[0065] In some embodiments, the term "exchange authorization response" refers to a data entity that defines a response to an exchange authorization request. In some embodiments, the exchange authorization response is provided to the exchange platform from a member of the exchange network. For example, the exchange authorization response may be provided by a service provider of the exchange network in response to the exchange authorization request.

[0066] In some embodiments, the exchange authorization response indicates at least one of an exchange approval or an exchange rejection. The exchange authorization response may be based at least in part on a comparison between the exchange value, the asset availability of the service provider tool, and / or the verification event. For example, in response to receiving the exchange authorization request, the member may be configured to compare the exchange value with the asset availability of the identified service provider tool. If the asset availability exceeds the exchange value, the value-based exchange may be authorized (e.g., resulting in exchange approval, etc.), otherwise the value-based exchange may be rejected (e.g., resulting in exchange rejection). In some examples, if the exchange value is within an exchange value threshold, the value-based exchange may be authorized (e.g., resulting in exchange approval, etc.), otherwise the value-based exchange may be rejected unless the exchange authorization response indicates that the value exchange is initiated using an enabled UUEK.

[0067] In some embodiments, the exchange authorization response indicates one or more contextual response attributes. For example, the one or more contextual response attributes may indicate one or more influencing factors for the exchange authorization response. For example, influencing factors may include bad actor risk and / or fraud check, error, full approval, instrument closed, instrument-based risk and / or fraud check, insufficient value, invalid UUEK, limit exceeded (e.g., exceeded UUEK or instrument usage limit), missing line item (e.g., does not include a value exchange for a verified object), instrument not found, account not found, password required, partial approval, member not available, transaction risk and / or fraud check, unsupported operation, user contact member (e.g., the user may need to contact a member (e.g., a service provider) to resolve the issue), user risk and / or fraud check, and combinations thereof.

[0068] In some embodiments, the term "exchange response" refers to a data entity defining a response to an exchange request. In some embodiments, the exchange response is provided from the exchange platform to the member that provided the exchange request. The exchange response may indicate an exchange approval and / or an exchange rejection. Additionally or alternatively, the exchange response may indicate validated data objects, invalid data objects, and / or contextual response attributes. Exemplarily, the exchange response may indicate one or more validated objects and / or one or more invalid objects of the exchange request.

[0069] In some embodiments, the term "exchange record" refers to a data entity that provides contextual information for an exchange request. The contextual information may indicate one or more aspects of the exchange request, the exchange response, the exchange authorization request, and / or the exchange authorization request. For example, the exchange record may indicate one or more verified objects, invalid objects, the object status of each verified and / or invalid object, and / or any other information associated with a value-based exchange.

[0070] In some embodiments, the term "member platform" refers to a computing entity corresponding to a member. A member platform may include a partner computing platform representing a partner, a service provider computing platform representing a service provider, and / or both. In some examples, a member platform may be both a partner platform and a service provider platform. For example, the same member platform may be configured to operate on behalf of a partner in one value exchange and a service provider in another value exchange. In some examples, the same member platform may be configured to operate on behalf of both a partner and a service provider in a single value exchange. It should be noted that the term member platform may refer to a partner platform, a service provider platform, or both, and in some examples may depend on the member platform's role in the value exchange (e.g., and / or one or more APIs used by the member platform in the value exchange).

[0071] In some embodiments, the partner platform is a computing entity configured to perform one or more operations on behalf of the partner. For example, the partner platform may include one or more processing devices, storage devices, etc., which are physically and / or wirelessly coupled and configured to jointly (and / or individually) perform one or more computing tasks for requesting value in a value system-independent exchange. In some examples, the partner platform may include, define and / or otherwise utilize one or more APIs to facilitate communication with the exchange platform (e.g., requests and responses, etc.). In some examples, the partner platform may be configured to host one or more user-facing applications (e.g., partner applications, etc.) for interacting with one or more users.

[0072] In some embodiments, a service provider platform is a computing entity configured to perform one or more operations on behalf of a service provider. For example, a service provider platform may include one or more processing devices, storage devices, etc., which are physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks for providing value in a value system-independent exchange. In some examples, the service provider platform may include, define, and / or otherwise utilize one or more APIs to facilitate communication (e.g., requests and responses, etc.) with the exchange platform. In some examples, the service provider platform may be configured to facilitate one or more service provider tools. In some examples, the service provider platform may be configured to host one or more user-facing applications (e.g., service provider applications, etc.) for managing one or more service provider tools.

[0073] In some embodiments, the term "exchange interface" refers to a set of instructions for facilitating communication between an exchange platform and one or more member platforms and / or internal services. The exchange interface may include an API, a file-based interface, a message queue-based interface, and the like. For example, the exchange interface may include an API, such as one or more Simple Object Access Protocol (SOAP) APIs, one or more Remote Procedure Call (RPC) APIs, one or more websocket APIs, one or more Representational State Transfer (REST) ​​APIs, and the like. In some embodiments, the exchange interface may include one or more RPC APIs, such as one or more gRPC APIs.

[0074] The exchange platform may include, define, and / or otherwise utilize one or more different exchange interfaces to facilitate communication with one or more external platforms, such as one or more member platforms (e.g., partner platforms, service provider platforms, etc.). Each API may include a plurality of communication instructions, message definitions, etc., for exchanging requests and / or responses between the exchange platform and entities participating in the value exchange. Exemplarily, the exchange interface may include a partner API for facilitating communication with a partner platform and / or a service provider API for facilitating communication with a service provider platform.

[0075] In some embodiments, the term "partner interface" refers to an exchange interface for facilitating one or more communications between a partner platform and an exchange platform. The partner interface may define one or more communication instructions, message definitions, etc. for facilitating one or more request messages and / or response messages between the partner platform and the exchange platform. For example, the partner interface may include an API that defines (i) requests from a computing entity acting as a partner platform to the exchange platform, and / or (ii) requests from the exchange platform to the partner platform. For example, the partner interface may define one or more registration messages, session messages, transaction messages, etc. that facilitate a value exchange between partners. In some embodiments, the partner interface defines one or more identifiers for securely identifying one or more parts of a value exchange.

[0076] In some embodiments, the term "service provider interface" refers to an exchange interface for facilitating one or more communications between a service provider platform and an exchange platform. The service provider interface may define one or more communication instructions, message definitions, etc. for facilitating one or more request messages and / or response messages between the service provider platform and the exchange platform. For example, the service provider interface may include an API that defines (i) requests from a computing entity acting as a service provider platform to the exchange platform, and / or (ii) requests from the exchange platform to the service provider platform. For example, the service provider interface may define one or more registration messages, session messages, transaction messages, etc. that facilitate the use of service provider tools to facilitate a value exchange. In some embodiments, the service provider interface defines one or more identifiers for securely identifying one or more parts of a value exchange.

[0077] In some embodiments, the term "entity partition" refers to a unique identifier for a computing entity. An entity partition may include a unique number, alphanumeric character, or the like representing a particular computing entity. For example, an entity partition may include a member partition representing a member platform, a service provider partition representing a service provider platform, a partner partition representing a partner platform, and the like.

[0078] In some embodiments, the term "service provider partition" refers to a unique identifier for a service provider and / or a service provider platform of a service provider. A service provider partition may include a number, an alphanumeric number, any character or symbol, and / or any other sequence of characters or symbols representing a service provider associated with (e.g., joined, registered, etc.) an exchange platform. For example, an exchange platform may include multiple service provider partitions that each identify a service provider platform associated with (e.g., joined, registered, etc.) the exchange platform. Each service provider partition may represent a service provider platform that has been configured with one or more exchange platform software development kits (SDKs) or the like to implement a service provider interface for the exchange platform.

[0079] In some embodiments, the term "partner partition" refers to a unique identifier for a partner and / or a partner platform of a partner. A partner partition may include a number, an alphanumeric character, any character or symbol, or any other sequence of characters or symbols representing a partner associated with an exchange platform. For example, an exchange platform may include multiple partner partitions that each identify a partner platform associated with (e.g., joined, registered, etc.) the exchange platform. Each partner partition may represent a partner platform that has been configured with one or more exchange SDKs, etc., for implementing the partner interface of the exchange platform.

[0080] In some embodiments, the term "user-oriented application" refers to a computer program hosted by a computing entity for facilitating one or more user interactions. A user-oriented application may include software (e.g., computer-readable instructions, etc.) that is designed to perform one or more computing tasks for a computing entity (e.g., a member platform). For example, a user-oriented application may facilitate communication between members and users. Exemplarily, a user-oriented application may be configured to present one or more user interfaces to interact with users on behalf of members. In some examples, a user-oriented application may be configured to receive user input (e.g., through one or more user interfaces) to receive information from a user.

[0081] In some embodiments, the user-facing application is a partner application hosted by a partner platform (e.g., a member platform that acts as a partner for a particular exchange, etc.) to facilitate the functionality of the partner. The partner application may include software (e.g., computer-readable instructions, etc.) that is designed to perform one or more computing tasks for the partner. For example, the partner application may be configured to present one or more user interfaces for interacting with (e.g., browsing, purchasing, viewing, etc.) one or more products provided by a retail-based partner, one or more information units provided by an information-based partner, etc. In some examples, the partner application may be configured to receive user input (e.g., through one or more user interfaces) to receive information from a user.

[0082] In some embodiments, the user-facing application is a service provider application hosted by a service provider platform (e.g., a member platform of a service provider acting as a specific exchange, etc.) to facilitate the functionality of the service provider. The service provider application may include software (e.g., computer-readable instructions, etc.) designed to perform one or more computing tasks for the service provider. For example, the service provider application may be configured to present one or more user interfaces for interacting with one or more service provider tools provided by the service provider (e.g., viewing, managing, auditing, registering, etc.). For example, in a financial value system, the service provider application may enable access to bank accounts, brokerage accounts, credit lines, etc. to manage funds, property, etc. handled by the corresponding accounts. In some examples, the service provider application may be configured to receive user input (e.g., through one or more user interfaces) to receive information, authorization, etc. from the user.

[0083] In some embodiments, the term "tool data object" refers to a data entity representing a service provider tool. A tool data object may include one or more tool identifiers and / or one or more tool attributes. In some examples, the one or more tool identifiers and / or one or more tool attributes may be based at least in part on the type of the tool data object. Exemplarily, a service provider tool may be represented in a member platform as a member tool data object. Additionally or alternatively, a service provider tool may be independently represented by a system tool data object in an exchange platform. In some examples, a member tool data object and a system tool data object may include the same one or more tool identifiers and / or one or more tool attributes. For example, a member platform may register multiple service provider tools with an exchange platform. During registration, the member platform may provide one or more tool identifiers and / or tool attributes, and in some examples, the exchange platform may return another identifier.

[0084] In some embodiments, a member instrument data object is an internal representation of a service provider instrument within a member platform. The member instrument data object may include one or more instrument identifiers, such as a member instrument identifier, an instrument key from an exchange platform, and / or a user identifier. For example, the user identifier may include a member user identifier. Additionally or alternatively, the member instrument data object may include one or more instrument attributes, such as an instrument type (e.g., a credit-based instrument, a debit-based instrument, an information-based instrument, etc.), an instrument representation, and / or one or more contextual attributes. In some examples, the contextual attributes may depend on the value system. For example, in a financial value system, one or more contextual attributes may indicate (i) the currency associated with the service provider instrument, (ii) the asset availability of the service provider instrument (e.g., balance, coverage, etc.), (iii) one or more previous transactions with the service provider instrument, etc.

[0085] In some embodiments, a system instrument data object is an external representation of a service provider instrument within an exchange platform. The system instrument data object may include one or more instrument identifiers, such as an instrument reference for a member platform, a system instrument identifier, and / or a user identifier. For example, the user identifier may include a system user identifier. Additionally or alternatively, the system instrument data object may include one or more instrument attributes, such as an instrument type (e.g., a credit-based instrument, a debit-based instrument, an information-based instrument, etc.), an instrument representation, and / or one or more context attributes. In some examples, the context attributes may depend on the value system. For example, in a financial value system, one or more context attributes may indicate the currency associated with the service provider instrument.

[0086] In some embodiments, the term "tool identifier" refers to any representation of a service provider tool. As described herein, a tool identifier may include a tool identifier, a tool reference, a tool key, and the like.

[0087] In some embodiments, the term "member tool identifier" refers to a unique identifier used to identify a service provider tool within a member platform. For example, the member tool identifier may include a number, an alphanumeric character, any character or symbol, or any other sequence of characters or symbols that represents a service provider tool of a service provider platform.

[0088] In some embodiments, the term "tool reference" refers to a unique identifier used to reference a member tool identifier. For example, a tool reference may be generated by a member platform and / or provided to an exchange platform to allow the exchange platform to reference tools maintained on the member platform. In some examples, the tool reference is the same value as the member tool identifier. In some examples, the tool reference is a different value that is mapped to the member tool identifier.

[0089] In some embodiments, the term "system tool identifier" refers to a unique identifier used to identify a service provider tool within an exchange platform. For example, the system tool identifier may include a number, an alphanumeric character, any character or symbol, or any other sequence of characters or symbols that identifies the service provider tool to the exchange platform. In some examples, the system tool identifier may include a UUID.

[0090] In some embodiments, the term "instrument key" refers to a unique identifier used to reference a system instrument identifier. For example, during the process of registering an instrument with an exchange platform, the exchange platform may generate and / or provide an instrument key. In some examples, the instrument key may include an encapsulated system instrument identifier. For example, the instrument key may include an alphanumeric string formatted according to a key format established by the exchange platform (and / or one or more of its APIs). The key format may include any number of characters, such as fifty characters or more. In some examples, the characters may be case sensitive. The first portion of the characters (e.g., the first six characters) may be reserved for identifying a partition of the entity associated with the key. For an instrument key, the partition may include a service provider partition. The second portion of the characters may identify the system instrument identifier. The key format described herein may include one or more different parts, each of which may be arranged in any order.

[0091] In some embodiments, the term "tool representation" refers to a unique identifier used to represent a service provider tool to a user. For example, a tool representation may include a number, an alphanumeric character, any character or symbol, and / or any other sequence of characters or symbols that visually represents a service provider tool. The format and / or value of the tool representation may be based at least in part on the service provider and / or the type of service provider tool. For example, in a financial value system, a tool reference may include a portion of a permanent credential (e.g., the last four digits, etc.), such as an account number (e.g., a debit account, a credit account, etc.), a financial account name, etc. As another example, in an information value system, a tool reference may include a portion of a permanent credential (e.g., one or more numbers, alphanumeric characters, etc.) of a permanent credential, such as a subscription account. For example, a tool representation may include a derivative of the permanent credential that may only allow entities with prior knowledge of the permanent credential to identify the permanent credential using the tool representation. As another example, a tool representation may include a tool nickname assigned by a user and subsequently recognized by the user.

[0092] In some embodiments, the term "user data object" refers to a data entity representing a user interacting with a member platform and / or an exchange platform. For example, a user can include an entity (e.g., an individual, an organization, a group, etc.) that participates in the exchange of value managed by the exchange platform. In some examples, a user can indirectly cooperate with the exchange platform by creating a user account with a registered service provider, registering (and / or allowing registration) for a service provider tool, etc. In some examples, the exchange platform can act on behalf of the user without the user having to interact directly with the exchange platform. For example, the exchange platform can act as a hidden intermediary between user-facing applications and the user's service provider tools.

[0093] In some embodiments, a user data object includes one or more user identifiers and / or one or more user attributes. In some examples, the one or more user identifiers and / or one or more user attributes may be based at least in part on the type of the user data object. Exemplarily, a user may be represented in a member platform as a member user data object. Additionally or alternatively, a user may be independently represented by a system user data object in an exchange platform. In some examples, a member user data object and a system user data object may include the same one or more user identifiers and / or one or more user attributes. Exemplarily, a member platform may register multiple users with an exchange platform. During registration, the member platform may provide one or more user identifiers and / or user attributes, and in some examples, the exchange platform may return another identifier.

[0094] In some embodiments, a member user data object is an internal representation of a user within a member platform. A member user data object may include one or more user identifiers, such as a member user identifier, a user key from an exchange platform, and the like. Additionally or alternatively, a member user data object may include one or more user attributes. One or more user attributes may indicate one or more contextual features for a user. In some examples, a user attribute may indicate one or more identifiable features for a user. Exemplarily, a user attribute may indicate a user's first name, last name, email address, physical address (e.g., one or more of a street, region, zip code, country, etc.), birthday (e.g., date of birth, age group, etc.), phone number, etc. In some examples, a user attribute may include an encrypted, hashed, and / or other secure representation of a user's identifiable features. For example, a user attribute may include one or more hashed identifiers for a user, etc.

[0095] In some embodiments, a system user data object is an external representation of a user of a member within an exchange platform. The system user data object may include one or more user identifiers, such as a user reference for the member platform, a system user identifier, and the like. Additionally or alternatively, the system user data object may include one or more user attributes (such as those described herein). Exemplarily, a member platform may register a user with the exchange platform. During registration, the member platform may provide a user reference and / or one or more user attributes for the user. In some examples, the user attributes may include a hashed and / or encrypted identifier for the user.

[0096] In some embodiments, the term "user identifier" refers to a unique identifier for a user involved in a value-based exchange. A user identifier may include a number, alphanumeric characters, any character or symbol, or any other sequence of characters or symbols that represents a user of an exchange platform and / or a member platform. In some examples, a user identifier may include a user reference, a user key, a system user identifier, a member user identification, and the like.

[0097] In some embodiments, the term "system user identifier" refers to a unique identifier used to identify a user within an exchange platform. For example, a system user identifier may include a number, an alphanumeric character, any character or symbol, or any other sequence of characters or symbols that identifies the user to the exchange platform. In some examples, a system user identifier may include a UUID that is specific to a particular user.

[0098] In some embodiments, the term "member user identifier" refers to a unique identifier used to represent a user within a member platform. For example, a member user identifier may include a number, an alphanumeric character, any character or symbol, or a sequence of any other characters or symbols that represents the user to the service provider platform.

[0099] In some embodiments, the term "user reference" refers to a unique identifier used to reference a member user identifier. For example, a user reference may be generated by a member platform and / or provided to an exchange platform to allow the exchange platform to reference a user associated with the member platform. In some examples, the user reference is the same value as the member user identifier. In some examples, the user reference is a different value that is mapped to the member user identifier.

[0100] In some embodiments, the term "user key" refers to a unique identifier used to reference a system user identifier. The user key can be generated and / or provided by the exchange platform, for example, during the process of user registration with the exchange platform. In some examples, the user key can include an encapsulated system user identifier. For example, the user key can include an alphanumeric string formatted according to a key format established by the exchange platform (and / or one or more of its APIs). For example, the key format can include a first portion of characters (e.g., the first six characters), which can be reserved for a partition used to identify the entity associated with the key (e.g., a member, etc.). For example, for a user key, the partition can include a service provider partition and / or a partner partition. The second portion of characters can identify the system user identifier.

[0101] In some embodiments, the term "exchange data object" refers to a data entity that represents an authorized value exchange between one or more members associated with an exchange platform. In some examples, an exchange data object may include one or more identifiers and / or one or more exchange attributes. For example, the one or more identifiers and / or one or more exchange attributes may be based at least in part on the type of the exchange data object. Exemplarily, an exchange may be represented in a member platform as a member exchange data object. Additionally or alternatively, an exchange may be independently represented by a system exchange data object in the exchange platform. In some examples, a member exchange data object and a system exchange data object may include the same one or more identifiers and / or one or more exchange attributes. Exemplarily, using some techniques of the present disclosure, an exchange platform may issue one or more unique identifiers to a member platform, which may be used to authorize the value exchange.

[0102] In some embodiments, a system exchange data object is an internal representation of a value exchange intermediated using an exchange platform. In some examples, a system exchange data object may include one or more different identifiers and / or exchange attributes, depending on the role of the system exchange data object in the value-based exchange.

[0103] For example, the system exchange data object may include a service provider-specific exchange data object corresponding to a service provider platform. The service provider-specific exchange data object may include one or more identifiers, such as an exchange identifier, a system user identifier, a system tool identifier, a UUEK, etc. Additionally or alternatively, the service provider-specific exchange data object may include one or more exchange attributes, such as an expiration date, a currency (e.g., for a financial value system, etc.), and / or the like.

[0104] Additionally or alternatively, the system exchange data object may include a partner-specific exchange data object corresponding to the partner platform. The partner-specific exchange data object may include one or more identifiers, such as an exchange identifier, an instrument key, a UUEK, a member instrument reference (e.g., a partner-specific instrument reference, etc.), and / or the like. Additionally or alternatively, the partner-specific exchange data object may include one or more exchange attributes, such as an expiration date, a currency (e.g., for a financial value system, etc.), an instrument type, a previous UUEK identifier, etc. In some embodiments, a member exchange data object is an external representation of a value exchange using an exchange platform as an intermediary. The member exchange data object may include one or more identifiers, such as a member exchange identifier, a member instrument identifier, a UUEK from an exchange platform, etc.

[0105] In some embodiments, the term "exchange identifier" refers to a unique identifier used to exchange value using an exchange platform. The exchange identifier may include a sequence of numbers, alphanumeric characters, and / or any other characters or symbols representing at least a user and / or service provider tool. In some examples, the unique exchange identifier may include a universally unique identifier (UUID), which may be mapped (e.g., via a series of identifiers, etc.) to a user, service provider tool, and / or member registered with the exchange platform. In some examples, the exchange identifier may be randomly generated using one or more UUID generators. For example, the exchange identifier may include random sixteen bytes of information generated according to one or more UUID formatting standards (e.g., UUID v4 and / or the like). Thus, while the exchange identifier may be used by the exchange platform and / or member platform for one or more functions, the same exchange identifier may be useless to external parties if there is no prior association between the exchange identifier and one or more other identifiers. In some examples, the exchange identifier may be represented externally by a UUEK.

[0106] In some embodiments, a "Universally Unique Temporary Key" or "UUEK" refers to an external representation of an exchange identifier that can be issued to an external entity (e.g., a user, partner, and / or service provider) (e.g., in place of a service provider exchange identifier and / or a partner exchange identifier) ​​to initiate a transaction using an exchange platform. To this end, a UUEK can be generated by the exchange platform and issued to the external entity. Each UUEK can include multiple values ​​(e.g., up to fifty characters and / or more, which can be case sensitive) representing one or more aspects of the transaction. For example, the multiple values ​​can indicate an exchange identifier, a partition (e.g., identifying a recipient of the UUEK, etc.), an identifier type, and / or one or more flags. Exemplarily, a UUEK can include a partner-specific UUEK and / or a service provider-specific UUEK. As described herein, a partner-specific UUEK can be associated with a partner-specific exchange data object, while a service provider-specific UUEK can be associated with a service provider-specific exchange data object.

[0107] Exemplarily, a UUEK may be generated according to a key format. The key format may include a plurality of characters, including, for example, fifty or more characters (which may be case-sensitive). The first portion of the characters (e.g., the first six characters) may be reserved for identifying a partition of the recipient of the UUEK. For example, the partition may include a partner partition, a service provider partition, and / or any other member partition. For example, the UUEK may be issued in response to a request from an authorized member (e.g., associated with a partner and / or service provider).

[0108] Additionally or alternatively, at least one character of the key format (e.g., the seventh character) may identify the format of the UUEK. At least another character (e.g., the eighth character) may identify the type of the UUEK. In some examples, the second portion of characters may identify the exchange identifier (e.g., the group of twenty-two characters following the eighth character). The third portion of characters may be reserved (e.g., the group of twenty characters following the first portion of characters). An example representation is provided below:

[0109] ppppppFiGGGGGGGGGGGGGGGGGGGGGGGGGrrrrrrrrrrrrrrrrrrrr where p represents the partition character, F represents the format character, i represents the identifier type character, G represents the exchange identifier, and r represents a reserved character. The key format allows 9.8x1084 unique permutations, which is more than the number of atoms in the known observable universe. This enables the generation and distribution of new UUEKs on demand without compromising the security of the underlying data to which the UUEKs may be mapped, such as identifiers of users, tools, and / or any other potentially sensitive information. The key format described herein may include one or more distinct parts, each of which may be arranged in any order.

[0110] In some embodiments, a "UUEK representation" refers to a visual representation of the UUEK. The UUEK representation may include a digital representation of the UUEK that is visible to a user. For example, the UUEK representation may be represented in one or more different forms, such as a machine-readable optical image (e.g., a barcode, a quick response code, etc.), a keyword, a virtual widget, and / or the like. In some examples, the UUEK representation may include a scannable representation of the UUEK (e.g., a barcode, a QR code, a non-fungible token, a near-field communication sequence, etc.). The scannable representation may be saved to a member account of the member platform to enable the user to physically perform a value-based exchange using a service provider tool without having to reference permanent credentials to the service provider tool. For example, the UUEK representation may be scanned by a barcode scanner and / or the like to read the UUEK and initiate a value-based exchange with the UUEK.

[0111] In some embodiments, an "enabled UUEK representation" refers to a UUEK representation for a UUEK that was enabled by a previous security event. The enabled UUEK representation may include a status indicator indicating the enabled state of the UUEK and / or one or more other indicators. In some examples, the enabled UUEK representation may include a readable UUEK representation.

[0112] In some embodiments, a "disabled UUEK representation" refers to a UUEK representation for a UUEK that is not enabled by a previous security event. The disabled UUEK representation may include a status indicator indicating the disabled state of the UUEK and / or one or more other indicators. In some examples, the disabled UUEK representation may include an unreadable UUEK representation. For example, the unreadable UUEK representation may include a gray, obscured, partially covered, and / or similar, scannable representation that prevents the scannable representation from being read. III. Computer Program Products, Methods, and Computing Entities

[0113] Embodiments of the present disclosure may be implemented in various ways, including as a computer program product comprising an article of manufacture. Such a computer program product may include one or more software components, including, for example, software objects, methods, data structures, and / or the like. The software components may be encoded in any of a variety of programming languages. The declarative programming language may be a low-level programming language, such as an assembly language associated with a specific hardware architecture and / or operating system platform. Software components containing assembly language instructions may need to be converted by an assembler into executable machine code before execution on the hardware architecture and / or platform. Another example programming language may be a high-level programming language that is portable across multiple architectures. Software components containing high-level programming language instructions may need to be converted by an interpreter or compiler into an intermediate representation before execution.

[0114] Other examples of programming languages ​​include, but are not limited to, macro languages, shell or command languages, job control languages, scripting languages, database query or search languages, and / or report writing languages. In one or more example embodiments, a software component comprising instructions in one of the above-mentioned programming language examples can be executed directly by an operating system or other software component without first being converted to another form. Software components can be stored as files or other data storage structures. Software components of similar type or related functions can be stored together, for example, in a particular directory, folder, or library. Software components can be static (e.g., pre-established or fixed) or dynamic (e.g., created or modified at execution time).

[0115] A computer program product may include a non-transitory computer-readable storage medium (also referred to herein as executable instructions, execution instructions, computer program product, program code, and / or similar terms used interchangeably herein) that stores an application, program, program module, script, source code, program code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, etc. Such non-transitory computer-readable storage medium includes all computer-readable media (including volatile and non-volatile media).

[0116] In one embodiment, the non-volatile computer-readable storage medium may include a floppy disk, a flexible disk, a hard disk, a solid-state storage (SSS) (e.g., a solid-state drive (SSD), a solid-state card (SSC), a solid-state module (SSM), an enterprise flash drive, a magnetic tape, or any other non-transitory magnetic medium, etc. The non-volatile computer-readable storage medium may also include a punched card, a paper tape, an optical marker sheet (or any other physical medium with a pattern of holes or other optically identifiable markings), a compact disc read-only memory (CD-ROM), a rewritable compact disc (CD-RW), a digital versatile disc (DVD), a Blu-ray disc (BD), any other non-transitory optical medium, etc. Such non-volatile computer-readable storage medium may also include a read-only memory (ROM), a programmable read-only memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), flash memory (e.g., serial, NAND, NOR, etc.), multimedia memory card (MMC), secure digital (SD) memory card, smart media card, compact flash (CF) card, memory stick, etc. In addition, non-volatile computer-readable storage media may also include conductive bridging random access memory (CBRAM), phase change random access memory (PRAM), ferroelectric random access memory (FeRAM), non-volatile random access memory (NVRAM), magnetoresistive random access memory (MRAM), resistive random access memory (RRAM), silicon-oxide-nitride-oxide-silicon memory (SONOS), floating junction gate random access memory (FJG RAM), millipede memory, racetrack memory, etc.

[0117] In one embodiment, the volatile computer-readable storage medium may include random access memory (RAM), dynamic random access memory (DRAM), static random access memory (SRAM), fast page mode dynamic random access memory (FPM DRAM), extended data output dynamic random access memory (EDO DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), double data rate type two synchronous dynamic random access memory (DDR2 SDRAM), double data rate type three synchronous dynamic random access memory (DDR3 SDRAM), Rambus dynamic random access memory (RDRAM), two-transistor RAM (TTRAM), thyristor RAM (T-RAM), zero capacitor (Z-RAM), Rambus in-line memory module (RIMM), dual in-line memory module (DIMM), single in-line memory module (SIMM), video random access memory (VRAM), cache memory (including various levels), flash memory, register memory, etc. It should be understood that in the case of describing embodiments using computer-readable storage media, other types of computer-readable storage media in addition to the above-described computer-readable storage media may be used instead of or in place of the above-described computer-readable storage media.

[0118] It should be understood that various embodiments of the present disclosure may also be implemented as methods, apparatuses, systems, computing devices, computing entities, etc. Thus, embodiments of the present disclosure may take the form of data structures, apparatuses, systems, computing devices, computing entities, etc., which execute instructions stored on a computer-readable storage medium to perform certain steps or operations. Thus, embodiments of the present disclosure may also take the form of entirely hardware embodiments, entirely computer program product embodiments, and / or embodiments comprising a combination of computer program products and hardware that perform certain steps or operations.

[0119] The embodiments of the present disclosure are described below with reference to block diagrams, flow charts, message passing flows and other representations of data, operations and message passing schemes. It should be understood that each box, arrow, etc. in the diagram, flow chart, etc. can be embodied as a computer program product, a complete hardware embodiment, a combination of hardware and computer program product and / or a form of a device, system, computing equipment, computing entity, etc. that executes instructions, operations, steps and similar words that can be used interchangeably (e.g., executable instructions, instructions for execution, program code, etc.) on a computer-readable storage medium. For example, the retrieval, loading and execution of code can be performed sequentially so that an instruction is retrieved once, loaded and executed. In some embodiments, retrieval, loading and / or execution can be run in parallel so that multiple instructions can be retrieved, loaded or run together. Therefore, such an embodiment can produce a machine that performs a specific configuration of the steps or operations specified in the representation of the present disclosure. Therefore, the representation of the present disclosure supports various combinations of embodiments for executing specified instructions, operations or steps.

[0120] IV. Example System Architecture

[0121] Figure 1 An illustration of a computing ecosystem 100 that can be used in conjunction with various embodiments of the present disclosure is provided. Figure 1 As shown, the architecture can include an exchange platform 102, one or more client devices 104, a member platform network 110, one or more networks 120, and the like. The member platform network 110 can include a first member platform 112a, a second member platform 112b, a third member platform 112c, and the like that are associated with the exchange platform 102 (e.g., registered, etc.). For example, as described herein, the member platform network 110 can include partner platforms and / or service provider platforms. In some examples, the partner platform can include the first member platform 112a, and the service provider platform can include a second member platform 112b that is different from the first member platform 112. In some examples, the partner platform and / or the service provider platform can include a single member platform (e.g., the third member platform 112c). In some examples, the member platform network 110 can be configured for one or more different services.

[0122] For example, each component of the computing ecosystem 100 can electronically communicate with each other via the same or different wireless or wired networks 120, including, for example, wired or wireless personal area networks (PANs), local area networks (LANs), metropolitan area networks (MANs), wide area networks (WANs), and / or the like. For example, the networks 120 can include any network connections, including any type of network and / or across any geographic boundaries (e.g., inter-country connections involving one or more sovereign entities, etc.). Furthermore, while Figure 1Certain systems are illustrated as separate, independent entities, but the various embodiments are not limited to this particular architecture.

[0123] Although not explicitly illustrated, exchange platform 102 may be client device 104 and / or may be part of member platform network 110. Additionally or alternatively, member platforms 112a-c may be part of client device 104 and / or exchange platform 102. In some embodiments, exchange platform 102 and / or member platforms 112a-c may each comprise the same computing platform.

[0124] a. Example computing platform

[0125] Figure 2 is an example diagram of a computing platform 200 according to one or more embodiments of the present disclosure. The computing platform 200, for example Figure 1 The exchange platform 102, member platforms 112a-c, and / or the like may include or communicate with one or more processing elements 202 (also referred to as processors, processing circuits, and / or similar terms used interchangeably herein), for example, the one or more processing elements 202 communicating with other elements within the computing platform 200 via a bus. It will be appreciated that the processing element 202 may be implemented in many different ways.

[0126] For example, processing element 202 may be implemented as one or more complex programmable logic devices (CPLDs), microprocessors, multi-core processors, co-processing entities, application specific instruction set processors (ASIPs), microcontrollers, and / or controllers. Furthermore, processing element 202 may be implemented as one or more other processing devices or circuits. The term circuitry may refer to a fully hardware embodiment or a combination of hardware and a computer program product. Thus, processing element 202 may be implemented as an integrated circuit, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a programmable logic array (PLA), a hardware accelerator, other circuits, and / or the like.

[0127] Therefore, it can be understood that the processing element 202 can be configured for specific purposes, or configured to execute instructions stored in volatile or non-volatile media, or instructions that are otherwise accessible to the processing element 202. Therefore, whether configured by hardware or computer program products, or through a combination thereof, when the processing element 202 is configured accordingly, the processing element 202 can perform the steps or operations according to the embodiments of the present disclosure.

[0128] In some embodiments, computing platform 200 includes or communicates with non-volatile memory 204 (also referred to as non-volatile memory, medium, memory, memory circuit, and / or similar terms used interchangeably herein). In some examples, non-volatile memory 204 may include one or more non-volatile memories or storage media, including, but not limited to, a hard disk, ROM, PROM, EPROM, EEPROM, flash memory, MMC, SD memory card, memory stick, CBRAM, PRAM, FeRAM, NVRAM, MRAM, RRAM, SONOS, FJG RAM, Millipede memory, racetrack memory, and the like.

[0129] It should be appreciated that the non-volatile memory 204 may store data, databases, database instances, database management systems, files, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, etc. The terms database, database instance, database management system, and / or similar terms used interchangeably herein may refer to a collection of records or data stored in a computer-readable storage medium using one or more database models (e.g., a hierarchical database model, a network model, a relational model, an entity-relationship model, an object model, a document model, a semantic model, a graph model, etc.).

[0130] In some embodiments, computing platform 200 includes or communicates with volatile memory 206 (also referred to as volatile memory, medium, memory, memory circuit, and / or similar terms used interchangeably herein). In some examples, volatile memory 206 can include one or more volatile memories or storage media, including, but not limited to, RAM, DRAM, SRAM, FPM DRAM, EDO DRAM, SDRAM, DDR SDRAM, DDR2 SDRAM, DDR3 SDRAM, RDRAM, TTRAM, T-RAM, Z-RAM, RIMM, DIMM, SIMM, VRAM, cache memory, register memory, and the like.

[0131] It will be appreciated that volatile memory 206 may be used to store at least a portion of a database, database instance, database management system, data, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, etc., that is executed by, for example, processing element 202. Thus, databases, database instances, database management systems, data, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, etc. may be used to control certain aspects of the steps / operations of computing platform 200 with the assistance of processing element 202 and an operating system.

[0132] As described above, in one embodiment, the computing platform 200 may also include one or more network interfaces 208 for communicating with various computing entities (e.g., Figure 1 The system may communicate with one or more components of a network, for example, by sending data, content, information, and / or similar terms used interchangeably herein, which may be transmitted, received, manipulated, processed, displayed, stored, etc. Such communication may be performed using a wired data transmission protocol, such as Fiber Distributed Data Interface (FDDI), Digital Subscriber Line (DSL), Ethernet, Asynchronous Transfer Mode (ATM), Frame Relay, Data over Cable Service Interface Specification (DOCSIS), or any other wired transmission protocol. Similarly, the computing platform 200 can be configured to communicate via a wireless external communication network using any of a variety of protocols, such as General Packet Radio Service (GPRS), Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA2000), CDMA2000 1X (1xRTT), Wideband Code Division Multiple Access (WCDMA), Global System for Mobile Communications (GSM), Enhanced Data rates for GSM Evolution (EDGE), Time Division Synchronous Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), Evolved Universal Terrestrial Radio Access Network (E-UTRAN), Evolution Data Optimized (EVDO), High Speed ​​Packet Access (HSPA), High Speed ​​Downlink Packet Access (HSDPA), IEEE 802.11 (Wi-Fi), Wi-Fi Direct, 802.16 (WiMAX), Ultra Wideband (UWB), Infrared (IR) protocol, Near Field Communication (NFC) protocol, Wibree, Bluetooth protocol, wireless Universal Serial Bus (USB) protocol and / or any other wireless protocol.

[0133] Although not shown, the computing platform 200 may include or be in communication with one or more input elements, such as keyboard input, mouse input, touch screen / display input, motion input, movement input, audio input, pointing device input, joystick input, keypad input, etc. The computing platform 200 may also include or be in communication with one or more output elements (not shown), such as audio output, video output, screen / display output, motion output, movement output, etc.

[0134] As described above, computing platform 200 may be Figure 1 Examples of one or more components in , such as, exchange platform 102 and / or member platforms 112a - c .

[0135] b. Example client device

[0136] Figure 3 is an example schematic diagram of a client device 104 according to one or more embodiments of the present disclosure. Client device 104 can be operated by various entities, and an example computing ecosystem can include one or more client devices 104. For example, client device 104 can be associated with, owned by, operated by, and / or the like, one or more end users. In various embodiments, an end user of client device 104 may wish to participate in a value exchange between partners and service providers. As described herein, the user can do so by interacting with one or more functionalities provided by user input from client device 104.

[0137] For example, the client device 104 may be a personal computing device, a smartphone, a tablet computer, a laptop computer, a personal digital assistant, and / or the like. In various embodiments, the computing platform 200 may communicate with one or more client devices 104 and manage value exchanges for one or more client devices 104. Figure 3 As shown, the client device 104 may include an antenna 312, a transmitter 304 (e.g., a radio transmitter), a receiver 306 (e.g., a radio receiver), and a processing element 308 (e.g., a CPLD, a microprocessor, a multi-core processor, a co-processing entity, an ASIP, a microcontroller, and / or a controller) that provides signals to and receives signals from the transmitter 304 and the receiver 306, respectively.

[0138] The signals provided to and received from transmitter 304 and receiver 306, respectively, may include signaling information / data in accordance with the air interface standard of the applicable wireless system. In this regard, client device 104 may be capable of operating using one or more air interface standards, communication protocols, modulation types, and access types. More specifically, client device 104 may operate in accordance with any of a number of wireless communication standards and protocols, such as those described above with respect to computing platform 200. In certain embodiments, client device 104 may operate in accordance with a variety of wireless communication standards and protocols, such as UMTS, CDMA2000, 1xRTT, WCDMA, GSM, EDGE, TD-SCDMA, LTE, E-UTRAN, EVDO, HSPA, HSDPA, Wi-Fi, Wi-Fi Direct, WiMAX, UWB, IR, NFC, Bluetooth, USB, and the like. Similarly, client device 104 may operate in accordance with a variety of wired communication standards and protocols, such as those described above with respect to computing platform 200 via network interface 320.

[0139] Through these communication standards and protocols, the client device 104 can communicate with the computing platform 200 using concepts such as Unstructured Supplementary Service Data (USSD), Short Message Service (SMS), Multimedia Messaging Service (MMS), Dual Tone Multi-Frequency Signaling (DTMF), and / or a Subscriber Identity Module Dialer (SIM Dialer). The client device 104 can also download, for example, changes, add-ons, and updates to its firmware, software (e.g., including executable instructions, applications, program modules), and operating system.

[0140] In some embodiments, the client device 104 includes location determination aspects, devices, modules, functionality, and / or similar terms used interchangeably herein. For example, the client device 104 may include outdoor location determination aspects, such as a location module adapted to obtain information such as latitude, longitude, altitude, geocode, route, direction, heading, speed, Universal Time (UTC), date, and / or various other information / data. In one embodiment, the location module may obtain data, sometimes referred to as ephemeris data, by identifying the number of satellites in view and the relative positions of these satellites (e.g., using the Global Positioning System (GPS)). The satellites may be a variety of different satellites, including low earth orbit (LEO) satellite systems, Department of Defense (DOD) satellite systems, the European Union's Galileo positioning system, China's BeiDou navigation system, India's regional navigation satellite system, and the like. This data may be collected using various coordinate systems, such as decimal degrees (DD); degrees, minutes, seconds (DMS); Universal Transverse Mercator (UTM); Universal Polar Stereographic (UPS) coordinate systems, and the like. Alternatively, location information / data may be determined by triangulating the location of the client device 104 in conjunction with various other systems, including cellular towers, Wi-Fi access points, and the like. Similarly, the client device 104 may include indoor positioning aspects, such as a location module adapted to obtain information such as latitude, longitude, altitude, geocode, route, direction, heading, speed, time, date, and / or various other information / data. Some indoor systems may use various location or positioning technologies, including RFID tags, indoor beacons or transmitters, Wi-Fi access points, cellular towers, nearby computing devices (e.g., smartphones, laptops), and the like. For example, these technologies may include iBeacons, gimbaled proximity beacons, Bluetooth Low Energy (BLE) transmitters, NFC transmitters, and the like. These indoor positioning aspects may be used in a variety of settings to determine the location of a person or thing to within inches or centimeters.

[0141] In some embodiments, the client device 104 may include a user interface 316 (e.g., a display screen, speaker, tactile mechanization, etc. coupled to the processing element 308) and / or a user input interface 318 (e.g., a touch screen, microphone, etc. connected to the processing element 308). For example, the user interface 316 may be one or more application screens presented by one or more computing platforms described herein. The user input interface 318 may include any of a plurality of devices or interfaces that allow the client device 104 to receive data, such as a keyboard (hard or soft), a touch display, a voice / speech or motion interface, or other input devices. In an example including a keyboard, the keyboard may include (or cause to be displayed) traditional numbers (0-9) and related keys (#, *), as well as other keys for operating the client device 104, and may include a full set of alphabetic keys or a set of keys that may be activated to provide a full set of alphanumeric keys. In addition to providing input, the user input interface may also be used to, for example, activate or deactivate certain functions, such as a screen saver and / or sleep mode.

[0142] The client device 104 may also include volatile memory 322 and / or non-volatile memory 324, which may be embedded and / or removable. For example, the non-volatile memory 324 may be ROM, PROM, EPROM, EEPROM, flash memory, MMC, SD memory card, memory stick, CBRAM, PRAM, FeRAM, NVRAM, MRAM, RRAM, SONOS, FJG RAM, Millipede memory, racetrack memory, etc. The volatile memory 322 may be RAM, DRAM, SRAM, FPM DRAM, EDO DRAM, SDRAM, DDR SDRAM, DDR2 SDRAM, DDR3 SDRAM, RDRAM, TTRAM, T-RAM, Z-RAM, RIMM, DIMM, SIMM, VRAM, cache memory, register memory, etc. The volatile and non-volatile storage or memory may store databases, database instances, database management systems, data, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, and the like to implement the functionality of the client device 104. As indicated, this may include partner applications, service provider applications, and the like that reside on the client device 104 and / or are accessible via a browser or other user interface to communicate with the computing platform 200.

[0143] In some embodiments, client device 104 may include one or more components or functions that are the same or similar to those of computing platform 200, as described in more detail above. As will be appreciated, these architectures and descriptions are provided for example purposes only and are not limiting of the various embodiments.

[0144] In various embodiments, the client device 104 can be implemented as an artificial intelligence (AI) computing entity, such as Amazon Echo, Amazon Echo Dot, Amazon Show, Google Home, and / or the like. Thus, the client device 104 can be configured to provide and / or receive information / data from an end user via an input / output mechanism (e.g., a display, a camera, a speaker, a voice-activated input, and / or the like). In certain embodiments, the AI ​​computing entity can include one or more predefined and executable program algorithms stored in an onboard memory storage module and / or accessible via a network. In various embodiments, the AI ​​computing entity can be configured to retrieve and / or execute one or more predefined program algorithms upon the occurrence of a predefined triggering event.

[0145] c. Example network

[0146] In some embodiments, Figure 1 Any two or more of the illustrative components of computing ecosystem 100 can be configured to communicate with each other via respective communication couplings with one or more networks 120. Networks 120 can include, but are not limited to, any one or combination of different types of suitable communication networks, such as a wired network, a public network (e.g., the Internet), a private network (e.g., a frame relay network), a wireless network, a cellular network, a telephone network (e.g., a public switched telephone network), or any other suitable private and / or public network. Furthermore, networks 120 can have any suitable communication range associated therewith and can include, for example, a global network (e.g., the Internet), a MAN, a WAN, a LAN, or a PAN. Furthermore, networks 120 can include any type of medium capable of carrying network traffic, including, but not limited to, coaxial cable, twisted pair, optical fiber, hybrid fiber coaxial (HFC) medium, microwave terrestrial transceivers, radio frequency communication medium, satellite communication medium, or any combination thereof, as well as various network devices and computing platforms provided by network providers or other entities.

[0147] d. Example Value Exchange System

[0148] Figure 4is an example block diagram of an exemplary network-based exchange system 400 according to one or more embodiments of the present disclosure. The network-based exchange system 400 includes a new computing ecosystem and computing platform that provide an end-to-end value exchange solution to replace traditional exchange processing systems. As described herein, the network-based exchange system 400 can be value system agnostic and can be applied to any value-based exchange, including, for example, information-based exchanges, financial-based exchanges, reputation-based exchanges, healthcare-based exchanges, interest-based exchanges, and / or the like. In any value system, the network-based exchange system 400 can utilize intermediary entities and one or more defined communication interfaces to facilitate network-based exchanges between value-seeking entities (e.g., partners) and value-providing entities (e.g., service providers), which value-providing entities can be associated with one or more member platforms of the network-based transaction system 400.

[0149] As shown, the network-based exchange system 400 may include an exchange platform 102, a partner platform 420, and / or a service provider platform 440, which may be configured to communicate via one or more exchange interfaces. The partner platform 420 and / or the service provider platform 440 may include one or more member platforms 112a-c from the member platform network 110. For example, the partner platform 420 and the service provider platform 440 may include a single member platform (e.g., member platform 112c). Additionally or alternatively, the partner platform 420 and the service provider platform 440 may include one or more different member platforms (e.g., member platforms 112a and 112b). In some examples, a user may interact with one or more platforms via a client device 104.

[0150] In some embodiments, exchange platform 102 is a computing entity configured to facilitate voucherless value exchange between one or more members of a network. Exchange platform 102 may include one or more processing devices, storage devices, and / or the like, which are physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks that facilitate value system-independent exchange. In some examples, exchange platform 102 may include, define, and / or otherwise utilize one or more exchange interfaces to facilitate communication (e.g., requests, responses, etc.) between multiple members. As described herein, interfaces may be utilized to facilitate secure exchange between one or more members of any value system.

[0151] In some embodiments, members are entities that collaborate with the exchange platform 102 to participate in a value exchange. For example, members may include (i) partners that utilize the exchange platform 102 to receive value, (ii) service providers that utilize the exchange platform 102 to provide value, and / or (iii) both partners and service providers. As used herein, a member may be referred to as a partner when it receives value through a value exchange, and / or a member may be referred to as a service provider when it provides value through a value exchange. Thus, depending on the member's role in the value exchange, the same member may be a partner or a service provider. For example, a member may be a partner that receives value through a value exchange. The same member may be a service provider that provides value in another value exchange. In some examples, the same member may be both a partner and a service provider in the same value exchange, allowing the member to provide and subsequently receive value in a single member value exchange using the exchange platform 102.

[0152] In one embodiment, a member is a partner when it uses a service provided by a service provider. Partners may include any value seeking entity in any value system. For example, in a financial value system, partners may include merchants (such as retailers, physical stores, etc.) that can utilize service providers (such as financial institutions) to access funds for financial transactions. Additionally or alternatively, in an information value system, partners may include news publishers (e.g., newspapers, media organizations, etc.) that can utilize service providers such as news agencies (e.g., wire services, news services, etc.) to access information for information transactions. In a healthcare value system, partners may include healthcare providers that can access healthcare benefit administrators to access medical benefits to provide funding for medical procedures. It should be understood that the technology of the present disclosure can be applied to any value system, and partners may include any value seeker for any corresponding value system.

[0153] In some embodiments, when a member provides a service to a partner, the member is a service provider. A service provider can include a value source in any value system. For example, in a financial value system, a service provider may include a financial institution (e.g., a bank, a currency exchange platform, a credit union, etc.) that can provide access to funds for financial transactions between one or more entities. Additionally or alternatively, in an information value system, a service provider may include a news agency (e.g., a wire service, a news service, etc.) that can provide a source of information for publication by a news publisher. In a healthcare value system, a service provider may include a healthcare benefits administrator that can provide healthcare providers with access to healthcare benefits. It should be understood that the technology of the present disclosure can be applied to any value system, and a service provider can include any value source for any corresponding value system.

[0154] In some embodiments, a service provider tool is a mechanism utilized by a service provider to provide value on behalf of a particular user. The service provider tool may depend on the value system and / or the service provider. In some examples, the service provider tool may include an account with the service provider. For example, in a financial value system, the service provider tool may include a bank account (e.g., checking, savings, etc.), a brokerage account, a line of credit, and / or the like. In an information value system, the service provider tool may include a subscriber account and / or the like. In a healthcare value system, the service provider tool may include a healthcare benefit account and / or the like.

[0155] In some embodiments, the services provided by the service provider are subject to one or more policies and / or security codes. For example, the service provider and / or service provider tool may be associated with a security code for verifying use of the service provider tool. Additionally or alternatively, the service provider may be associated with one or more member policies for authenticating the security code.

[0156] In some embodiments, a security code is a data entity defining a sequence of characters for verifying a user in an exchange. The security code may include a sequence of one or more dynamic lengths of different characters (e.g., six characters, eight characters, etc.) that may be set and / or provided to the user in advance by the user. The security code may be provided later by the user to verify the user's presence for the exchange (e.g., as described herein, by comparing the security code input with a security code reference). The one or more different characters may include any number of alphanumeric characters, emojis, Chinese characters, winged fonts, and / or the like.

[0157] In some embodiments, the security code is a network-managed n-character PIN. As described herein, the security code can be managed by a client device as a microservice to enable and / or disable the UUEK (and / or any other exchange credential) prior to an exchange request. In this way, security codes can be deployed for any type of service provider tool by enabling and / or disabling the corresponding UUEK. By managing security codes at the network level, members can benefit from faster exchanges because the possibility of authorization being denied for an invalid PIN is eliminated. For example, the UUEK can be disabled until a security code is received to enable the UUEK. The exchange platform 102 can prevent a user from initiating an exchange before the UUEK is enabled, thereby ensuring that all exchange authorization requests provided to the service provider have been pre-verified based on the security code.

[0158] In some embodiments, the security code corresponds to a user. For example, the security code can be pre-set by the user and / or provided to the user for a UUEK accessible to the user. In some examples, each security code can be specific to a UUEK. For example, each corresponding security code can be configured to enable a single UUEK. Exemplarily, the exchange platform 102 can be configured to enable UUEKs using multiple security code element groups 424, each security code element group associating a security code with a corresponding UUEK.

[0159] In some embodiments, security code element group 424 is a data entity that defines the association between a UUEK and a security code. Security code element group 424 may include data objects, records, and / or any other data structure (e.g., a link node, etc.) configured to represent the association between a security code and a UUEK. Security code element group 424 may include, for example, a security code reference, a UUEK, one or more derivative identifiers of the UUEK (as described herein), and / or contextual pairing data. The contextual pairing data may include one or more pairing attributes, such as one or more timing attributes. For example, a timing attribute may indicate a configuration time (e.g., indicating the time when the security code element group was set), an expiration time (e.g., a time when the security code must be reset), and / or the like. As described herein, the exchange platform 102 may utilize security code element group 424 to identify the security code reference of the UUEK and enable (and / or disable) the UUEK based at least in part on a comparison between the security code reference and a security code input provided by a user.

[0160] In some embodiments, a security code reference is a data entity that defines a record security code. The security code reference may include an internal representation of a security code for a UUEK (eg, for exchange platform 102, etc.).

[0161] In some embodiments, member policy 422 defines one or more authentication requirements for a service provider tool. Member policy 422 may correspond to a member and / or a member's service provider tool. For example, member policy 422 may define one or more authentication requirements for use of a service provider tool based at least in part on one or more member-specific criteria. Additionally or alternatively, member policy 422 may define one or more authentication requirements for use of a service provider tool based at least in part on one or more tool-specific criteria. Member-specific criteria may apply to multiple service provider tools associated with a member, while tool-specific criteria may apply to at least one of multiple service provider tools associated with a member.

[0162] The validation requirement may indicate one or more policy attributes that require a value-based exchange of an enabled UUEK. For example, a disabled UUEK may be used to authorize a value-based exchange that does not include one or more attributes that require an enabled UUEK. If the value-based exchange includes at least one attribute that requires an enabled UUEK, the disabled UUEK may be prevented from authorizing the value-based exchange.

[0163] In some examples, the policy attributes may include an object identifier, one or more object attributes, and / or one or more value exchange attributes that identify an object and / or one or more authorized / unauthorized amounts of an object. For example, member policy 422 may include multiple object identifiers. The multiple object identifiers may indicate multiple objects that are authorized / unauthorized to obtain (e.g., purchase, etc.) with a disabled UUEK.

[0164] In some examples, the object identifier may be a global object identifier. For example, the global object identifier may be a stock keeping unit (SKU) code. Additionally or alternatively, the global object identifier may be a manufacturer part number (MPN), a global trade item number (GTIN), a product or service name, an international standard book number (ISBN), a universal product code (UPC), an international article number (EIN), and / or the like. In some examples, the object identifier may include a system object identifier. For example, the system object identifier may include an identifier (e.g., a table identifier, etc.) corresponding to a record data object representing an object within the exchange platform 102. In some embodiments, the system object identifier and the global object identifier are the same.

[0165] In some embodiments, the policy attributes include value exchange attributes corresponding to a particular value-based exchange and / or objects included in the value-based exchange. For example, the value exchange attributes may include a threshold exchange value for disabling a UUEK. For example, one or more exchange attributes may indicate an exchange value, and one or more verification requirements may define an exchange value threshold at which a corresponding security event is required for the service provider tool.

[0166] The service provider and the partner can communicate through one or more corresponding member platforms associated with the entities, respectively. As an example, the service provider can be associated with the service provider platform 440, and the partner can be associated with the partner platform 420.

[0167] In some embodiments, a member platform is a computing entity corresponding to a member associated with exchange platform 102. A member platform can include a partner platform 420 representing a partner, a service provider platform 440 representing a service provider, and / or both. In some examples, a member platform can be both a partner platform 420 and a service provider platform 440. For example, the same member platform can be configured to operate on behalf of a partner in one value exchange and a service provider in another value exchange. In some examples, the same member platform can be configured to operate on behalf of both a partner and a service provider in a single value exchange. It should be noted that the term member platform can refer to a partner platform 420, a service provider platform 440, or both, which in some examples may depend on the member platform's role in the value exchange (e.g., and / or one or more interfaces used by the member platform in the value exchange).

[0168] In some embodiments, partner platform 420 is a computing entity configured to perform one or more operations on behalf of a partner. For example, partner platform 420 may include one or more processing devices, storage devices, and / or the like that are physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks for requesting value in a value system-independent exchange. In some examples, partner platform 420 may include, define, and / or otherwise utilize one or more exchange interfaces to facilitate communication (e.g., requests, responses, etc.) with exchange platform 102. In some examples, partner platform 420 may be configured to host one or more user-facing applications (e.g., partner applications, etc.) for interacting with one or more users.

[0169] For example, in a financial value system, partner platform 420 may host an online marketplace for a partner that allows users to interact with one or more products or services offered by the partner (e.g., search, browse, purchase, return, etc.). In the case of purchasing products, partner platform 420 may work with one or more service providers to access funds for the purchase. Traditionally, users are required to use card numbers, account numbers, and / or other financial credentials to access funds from service providers, which may expose users to malicious parties. To address cybersecurity and data privacy issues of traditional financial systems (and / or other value-based systems), partner platform 420 may register with exchange platform 102 by configuring one or more software development kits (SDKs), APIs, and / or the like to facilitate communication with exchange platform 102. For example, partner platform 420 may include, define, and / or otherwise utilize one or more partner interfaces 402 to facilitate communication (e.g., requests, responses, etc.) with exchange platform 102.

[0170] In some embodiments, the service provider platform 440 is a computing entity configured to perform one or more operations on behalf of the service provider. For example, the service provider platform 440 may include one or more processing devices, storage devices, and / or the like that are physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks for providing value in a value system-independent exchange. In some examples, the service provider 440 may include, implement, and / or otherwise utilize one or more interfaces to facilitate communication (e.g., requests, responses, etc.) with the exchange platform 102. In some examples, the service provider platform 440 may be configured to facilitate one or more service provider tools. In some examples, the service provider platform 440 may be configured to host one or more user-facing applications (e.g., service provider applications, etc.) for managing one or more service provider tools.

[0171] In some examples, such as in a financial value system, service provider platform 440 may maintain one or more financial assets (e.g., a line of credit, a bank account, etc.) to allow a user to fund an exchange for purchasing a product from a partner. In the case of a product purchase, service provider platform 440 may collaborate with partner platform 420 to authorize the exchange and / or otherwise provide access to the purchase funds. Traditionally, access to funds at a service provider is facilitated by presenting a card number, account number, and / or another financial credential to service provider platform 440, which may expose the user, service provider, or partner to malicious parties, particularly when provided over an unsecured network (e.g., a public network, etc.). To address cybersecurity and data privacy issues of traditional financial systems (and / or other value-based systems), service provider platform 440 may register with exchange platform 102 by configuring one or more software development kits (SDKs), APIs, and / or the like to facilitate communication with exchange platform 102. For example, the service provider platform 440 can include, implement, and / or otherwise utilize one or more service provider interfaces 404 to facilitate communications (eg, requests, responses, etc.) with the exchange platform 102 .

[0172] As described herein, the service provider interface 404 can enable the exchange platform 102 to identify and request the use of service provider tools to facilitate transactions. For example, the service provider platform 440 can be configured to facilitate one or more service provider tools. In some examples, the service provider tools can include virtual tools (e.g., virtual accounts, credit lines, etc.) hosted by the service provider platform 440. For example, the service provider platform 440 can be configured to maintain multiple tool data objects that indicate multiple service provider tools for multiple affiliated entities.

[0173] In some embodiments, a tool data object is a data entity representing a service provider tool. A tool data object may include one or more tool identifiers and / or one or more tool attributes. In some examples, the one or more tool identifiers and / or one or more tool attributes may be based at least in part on the type of the tool data object. Exemplarily, a service provider tool may be represented as a member tool data object in a member platform (e.g., service provider platform 440). Additionally or alternatively, a service provider tool may be independently represented by a system tool data object in exchange platform 102. In some examples, a member tool data object and a system tool data object may include the same one or more tool identifiers and / or one or more tool attributes. For example, a member platform may register multiple service provider tools with exchange platform 102 (e.g., using service provider interface 404). During registration, a member platform (e.g., service provider platform 440) may provide one or more tool identifiers and / or tool attributes, and in some examples, exchange platform 102 may return another identifier.

[0174] In some embodiments, a member instrument data object is an internal representation of a service provider instrument within a member platform (e.g., service provider platform 440). The member instrument data object may include one or more instrument identifiers, such as a member instrument identifier, an instrument key from exchange platform 102, and / or a user identifier. As described herein, for example, the user identifier may include a member user identifier. Additionally or alternatively, the member instrument data object may include one or more instrument attributes, such as an instrument type (e.g., a credit-based instrument, a debit-based instrument, an information-based instrument, etc.), an instrument representation, and / or one or more contextual attributes. In some examples, the contextual attributes may depend on the value system. For example, in a financial value system, one or more contextual attributes may indicate (i) the currency associated with the service provider instrument, (ii) the asset availability of the service provider instrument (e.g., balance, coverage, etc.), (iii) one or more previous transactions with the service provider instrument, etc.

[0175] In some embodiments, a system instrument data object is an external representation of a service provider instrument within the exchange platform 102. The system instrument data object may include one or more instrument identifiers, such as an instrument reference for the member platform, a system instrument identifier, and / or a user identifier. As described herein, for example, the user identifier may include a system user identifier. Additionally or alternatively, the system instrument data object may include one or more instrument attributes, such as an instrument type (e.g., a credit-based instrument, a debit-based instrument, an information-based instrument, etc.), an instrument representation, and / or one or more context attributes. In some examples, the context attributes may depend on the value system. For example, in a financial value system, one or more context attributes may indicate the currency associated with the service provider instrument.

[0176] As described herein, a service provider tool may be associated with one or more usage restrictions, such as a security code and / or member policy 422. In some examples, the exchange platform 102 may include a verification service 408 configured to adjudicate secure interaction requests and / or exchange requests based, at least in part, on valid security code input and / or member policy 422. To this end, the exchange platform 102 (and / or its verification service 408) may access a security code element set 424 for the service provider tool and / or member policy 422. For example, a member platform may register a security code with the exchange platform 102 (e.g., using the service provider interface 404 and / or the partner interface 402). Upon registration, the security code may be stored as a security code reference in the security code element set 424, which associates the security code reference with a user, member, service provider tool, and / or a UUEK associated therewith. Additionally or alternatively, the member platform may register the member policy 422 with the exchange platform 102 (e.g., using the service provider interface 404). During registration, a member platform (e.g., service provider platform 440) may provide one or more policy attributes, attribute updates, and / or the like for verifying secure interaction and / or exchange requests that reference one or more service provider tools and / or the like maintained by the member platform. In some examples, the member platform may continuously update member policy 422 when one or more policy attributes are modified, added, and / or removed.

[0177] As described herein, the exchange platform 102 (e.g., authentication service 408, etc.) can authenticate users, service provider tools, UUEKs, and / or exchange requests using security codes and / or member policies 422. In some examples, authentication of the exchange request can be based at least in part on the recorded data object.

[0178] In some embodiments, a recorded data object is a data object that represents an object that can participate in a value-based exchange. In some examples, a recorded data object can be an internal representation of an object for exchange platform 102. For example, an object can include different elements of a value-based exchange for which value is being transferred. A recorded data object for an object can include a data object that records one or more aspects of the object (e.g., an object identifier, object attributes, etc.).

[0179] For example, a recorded data object may include an object identifier and / or one or more object attributes for a particular object associated with a value system. The object may be based at least in part on a value system. For example, in a financial value system, an object may be a tangible or intangible item, product, and / or the like that can be purchased in exchange for a unit of currency. In a healthcare value system, an object may be a healthcare procedure, and / or the like, that is covered by a healthcare policy.

[0180] In some examples, exchange platform 102 can maintain and / or access an object data store comprising a plurality of recorded data objects. As described herein, the object data store can include a plurality of recorded data objects at least partially from one or more members of an exchange network.

[0181] In some embodiments, an object attribute is a data entity that describes a characteristic of an object. Object attributes may include object-based attributes and / or exchange-based attributes.

[0182] For example, object-based attributes may include spatial attributes, count attributes, value attributes, source attributes, composite attributes, classification attributes, and / or any other attributes that describe characteristics of an object. For example, a spatial attribute may indicate one or more dimensions of an object (e.g., height, width, weight, etc.), a value attribute may indicate the value of the object (e.g., price, etc.), a composition attribute may indicate one or more ingredients, components, etc. of an object, a classification attribute may indicate one or more categories (e.g., restricted substances, etc.), and / or the like. For example, one or more classification attributes may indicate whether an object is associated with (i) one or more general store categories, such as vegetables, fruits, dairy products, meats, grains, seeds, alcohol, tobacco, in-store consumables, hot foods, pharmacies, pet food, and non-food products, (ii) one or more medical categories, such as dental, ophthalmology, general health, etc., (iii) one or more information categories, such as international sources, domestic sources, etc., and / or the like. In one example, the ingredient attribute may indicate one or more ingredients of the object, such as the volume percentage of alcohol within the object, one or more ingredients such as meat, dairy derivatives, peanut derivatives, tree nut derivatives, soy derivatives, and / or the like.

[0183] In some examples, object-based attributes can be based at least in part on a value system. For example, in at least one financial-based value system, object-based attributes can include one or more line item attributes, one or more line item adjustments, and / or the like. Line item attributes can include a sequence, a line item group, a product code, an item name, an item source (e.g., supplier, manufacturer, etc.), a description, a quantity, a mass (e.g., grams, kilograms, etc.), one or more spatial dimensions (e.g., length, width, height, volume, etc.), a unit amount, a unit tax amount, a line amount (e.g., the amount of the line item), a line tax amount, and / or the like. Line item adjustments can include an adjustment type (e.g., manufacturer discount, store discount, return, pay cash, pay gift card, pay other, and / or the like), an item, product, or service code, an item description, an item quantity, a unit item, an item mass (e.g., grams, kilograms, etc.), a unit amount, a unit tax amount, a line amount (e.g., the amount of the line item), a line tax amount, and / or the like.

[0184] In some examples, member platforms, such as partner platform 420 and / or service provider platform 440 , may be associated with user-facing applications to facilitate one or more interactions with the user and / or other affiliated entities (eg, via client device 104 ).

[0185] In some embodiments, the user-oriented application is a computer program for facilitating one or more user interactions hosted by a computing entity. The user-oriented application may include software (e.g., computer-readable instructions, etc.) that is designed to perform one or more computing tasks for a computing entity (e.g., a member platform). For example, the user-oriented application may facilitate communication between members and users. Exemplarily, the user-oriented application may be configured to present one or more user interfaces 406 (e.g., through client devices 104) for interacting with users on behalf of members. In some examples, the user-oriented application may be configured to receive user input (e.g., through one or more user interfaces 406) to receive information from the user. For example, user input may include a security code input for ensuring user interaction security.

[0186] In some embodiments, the user-facing application is a partner application 416 hosted by a partner platform 420 (e.g., a member platform that acts as a partner for a particular exchange, etc.) to facilitate functionality for the partner. Partner application 416 may include software (e.g., computer-readable instructions, etc.) that is designed to perform one or more computing tasks for the partner. In some examples, partner application 416 may be configured with one or more devices (e.g., point-of-sale terminals, etc.) from an independent partner institution (e.g., a physical bank, etc.). For example, partner application 416 may be configured to present one or more user interfaces 406 for interacting (e.g., browsing, purchasing, viewing, etc.) with one or more products provided by a retail-based partner, one or more units of information provided by an information-based partner, and / or the like. In some examples, partner application 416 may be configured to receive user input (e.g., through one or more user interfaces 406) to receive information from a user.

[0187] In some embodiments, the service provider platform 440 is configured to host one or more service provider applications 418 for managing one or more service provider tools. For example, a user-facing application may be a service provider application 418 hosted by the service provider platform 440 (e.g., acting as a membership platform for a service provider for a particular exchange, etc.) to facilitate functionality for the service provider. In some examples, the service provider application 418 may be configured with one or more devices from an independent service provider institution (e.g., a brick-and-mortar bank, etc.). The service provider application 418 may include software (e.g., computer-readable instructions, etc.) designed to perform one or more computing tasks for the service provider. For example, the service provider application 418 may be configured to present one or more user interfaces for interacting with one or more service provider tools facilitated by the service provider (e.g., viewing, managing, auditing, registering, etc.). For example, in a financial value system, the service provider application 418 may provide access to bank accounts, brokerage accounts, lines of credit, and / or the like to manage funds, assets, and / or the like handled by each account. In some examples, service provider application 418 may be configured to receive user input (eg, through one or more user interfaces 406 ) to receive information, authorization, etc. from a user.

[0188] In some embodiments, the partner application 416 and / or the service provider application 418 are configured to maintain, update, and / or register membership policies 422 for users and service provider tools and / or security codes corresponding to the UUEKs. For example, the partner platform 420 and / or the service provider platform 440 can enable users, organizations, and / or any other entities to configure security codes for initiating secure interactions. Additionally or alternatively, the service provider platform 440 can enable users, organizations, and / or any other entities to configure membership policies 422 for managing the use of the service provider tools.

[0189] In some examples, user input can be provided and / or received via service provider application 418 and / or partner application 416. For example, the user input can include a security code input for initiating a secure interaction. For example, the security code input can be provided to exchange platform 102 via an input into a user interface of service provider application 418 and / or partner application 416. In some embodiments, exchange platform 102 facilitates communication between partner platform 420 and service provider platform 440 using one or more exchange interfaces.

[0190] In some embodiments, the exchange interface is a set of instructions for facilitating communication between the exchange platform 102 and one or more member platforms and / or internal services. The exchange interface may include an API, a file-based interface, a message queue-based interface, and / or the like. For example, the exchange interface may include an API, such as one or more Simple Object Access Protocol (SOAP) APIs, one or more Remote Procedure Call (RPC) APIs, one or more WebSocket APIs, one or more Representational State Transfer (REST) ​​APIs, and / or the like. In some embodiments, the exchange interface may include one or more RPC APIs, such as one or more gRPC APIs.

[0191] The exchange platform 102 may include, define, and / or otherwise utilize one or more different exchange interfaces to facilitate communication with one or more external platforms, such as one or more member platforms (e.g., partner platform 420, service provider platform 440, etc.). Each interface may include a plurality of communication instructions, message definitions, and / or the like for exchanging requests and / or responses between the exchange platform 102 and entities participating in a value exchange. For example, the exchange interfaces may include a partner interface 402 for facilitating communication with the partner platform 420 and / or a service provider interface 404 for facilitating communication with the service provider platform 440.

[0192] In some embodiments, partner interface 402 is an exchange interface for facilitating one or more communications between partner platform 420 and exchange platform 102. Partner interface 402 may define one or more communication instructions, message definitions, and / or the like for facilitating one or more request messages and / or response messages between partner platform 420 and exchange platform 102. For example, partner interface 402 may include an API that defines (i) requests from a computing entity acting as partner platform 420 to exchange platform 102, and / or (ii) requests from exchange platform 102 to partner platform 420. For example, partner interface 402 may define one or more registration messages, session messages, transaction messages, and / or the like to facilitate a value exchange between partners. In some embodiments, partner interface 402 defines one or more identifiers for securely identifying one or more components of a value exchange.

[0193] In some embodiments, service provider 404 is an exchange interface for facilitating one or more communications between service provider platform 440 and exchange platform 102. Service provider interface 404 may define one or more communication instructions, message definitions, and / or the like for facilitating one or more request messages and / or response messages between service provider platform 440 and exchange platform 102. For example, service provider interface 404 may include an API that defines (i) requests from a computing entity acting as service provider platform 440 to exchange platform 102, and / or (ii) requests from exchange platform 102 to service provider platform 440. For example, service provider interface 404 may define one or more registration messages, session messages, transaction messages, and / or the like to facilitate value exchange using service provider tools. In some embodiments, service provider interface 404 defines one or more identifiers for securely identifying one or more components of a value exchange.

[0194] The exchange platform 102 can facilitate communication between member platform networks. For example, a member network can include multiple entities that have joined the exchange platform 102, for example, by registering with the exchange platform 102, configuring corresponding interfaces for communicating with the exchange platform 102, and so on. In some examples, the exchange platform 102 can implement one or more separate services for interacting with each joined entity. For example, each service can include one or more partner services 410 and / or service provider services 412.

[0195] In some embodiments, exchange platform 102 instantiates a separate partner-specific service, namely partner service 410, for each member network. Additionally or alternatively, for example, in a multi-tenant environment, partner service 410 can be instantiated for one or more partners from a member network. Partner service 410 can be configured to perform one or more exchange operations to resolve exchange requests from partner platform 420. In some embodiments, exchange platform 102 instantiates a separate service provider-specific service, namely service provider service 412, for each member network. Additionally or alternatively, for example, in a multi-tenant environment, service provider service 412 can be instantiated for one or more service providers from a member network. Service provider service 412 can be configured to perform one or more exchange operations to obtain and resolve exchange requests from partner platform 420. Exchange operations can include any of the steps and / or operations described herein.

[0196] In some embodiments, partner service 410 and / or service provider service 412 interact with each other and / or one or more other components of exchange platform 102 via one or more local communication mechanisms to perform exchange operations. For example, exchange platform 102 may include verification service 408. Verification service 408 may be configured to perform one or more verification operations disclosed herein to verify the UUEK. In this manner, exchange platform 102 may pre-process exchange requests and authorization credentials for exchange requests on behalf of member platforms to enforce their member policies 422.

[0197] By performing one or more exchange operations, partner service 410 and / or service provider service 412 can generate and utilize multiple non-traditional identifiers to reference a user, service provider tool, and / or one or more aspects of a value exchange. At least some of these identifiers can include a universally unique identifier, such as a UUEK, which can be used to provide a credential-free value exchange. Each identifier can be at least temporarily stored in platform database 414. Platform database 414 can include any type of memory device described herein. In some examples, each service and / or one or more groups of services can be associated with a single portion of platform database 414.

[0198] As described herein, one or more identifiers may be stored in association with one another to form an identifier mapping that the exchange platform 102 (and / or one or more of its services) may utilize to reference users, service provider tools, and / or any other aspects of a value exchange from communications between partner platforms 420, service provider platforms 440, and / or any other member platforms, without including user credentials. Figure 5 Examples of non-traditional identifiers are further described.

[0199] e. Example data structure

[0200] Figure 5 1 is an example data graph 500 for facilitating credential-free value exchange, according to one or more embodiments of the present disclosure. Data graph 500 illustrates multiple related identifiers of different types. As shown, each identifier can be associated with at least one related identifier to form an identifier mapping within one or more platforms (e.g., exchange platform 102 and / or service provider platform 440). The identifier mapping enables communication between exchange platform 102 and service provider platform 440 that references service provider tools 518 without exposing permanent credentials 514 (e.g., usernames, passwords, card numbers, etc.) associated with service provider tools 518, which are susceptible to fraud, abuse, and exploitation by malicious parties. As shown, using some techniques of the present disclosure, permanent credentials 514 may never need to be transmitted outside of service provider platform 440. Data graph 500 illustrates only some of the multiple identifiers that can be generated, stored, and / or utilized by various embodiments of the present disclosure. It should be understood that the illustrated identifiers are not an exhaustive list and may include other identifiers not shown. Each identifier may be labeled as an identifier, a reference, a key, and / or other similar terms. These terms are used interchangeably herein to refer to units of information used to identify data structures, entities and / or any other components described herein.

[0201] As shown, some of the multiple related identifiers in various embodiments of the present disclosure may include, for example, (i) one or more user references 502, which can be mapped to a member user identifier 522 of the service provider platform 440, (ii) one or more service provider partitions 504, which correspond to the network of the joined service provider platform (such as the service provider platform 440), (iii) one or more partner partitions 506, which correspond to the joined partner platform network, (iv) one or more tool references 520, which can be mapped to the member tool identifier 508 of the service provider platform 440, (v) one or more keys 516 and / or system identifiers 512 that can be associated with the user reference 502 and / or the tool reference 520, (vi) one or more exchange identifiers 510, which can be mapped to the system identifier 512 and / or the key 516, and / or (vii) one or more UUEKs 524, which can be mapped to at least one of the exchange identifier 510 and / or the partner partition 506 and / or the service provider partition 504.

[0202] In some embodiments, the service provider platform 440 may store one or more identifiers that may be mapped to one or more identifiers of the service provider tool 518 and / or the exchange platform 102 to enable the service provider platform 440 to reference the service provider tool 518 based at least in part on the identifiers, which identifiers themselves do not indicate any aspect of the service provider tool 518, including its permanent credentials 514.

[0203] For example, the service provider platform 440 can store, maintain, and / or otherwise access one or more keys 516 that are mapped to (e.g., are copies, derivatives, etc. of) one or more system identifiers 512 of the exchange platform 102. For example, the keys 516 can include the system identifier 512 as part of the keys 516. The keys 516 can be mapped to the member tool identifier 508 and / or the member user identifier 522, which can internally reference a user of the service provider platform and / or the service provider tool 518. For example, the keys 516 can be provided during a registration process between the service provider platform 440 and / or the exchange platform 102.

[0204] As another example, the exchange platform 102 can store, maintain, and / or otherwise access one or more references, such as tool references 520 and / or user references 502, that are mapped to (e.g., are copies, derivatives, etc. of) one or more member identifiers, such as the member tool identifier 508 and / or the member user identifier 522 of the service provider platform 440. For example, the references can be provided during a registration process between the service provider platform 440 and / or the exchange platform 102.

[0205] In some embodiments, the exchange platform 102 uses one or more entity partitions to reference each member platform of the member platform network. In some embodiments, an entity partition is a unique identifier for a computing entity. An entity partition may include a unique number, alphanumeric number, and / or the like representing a particular computing entity. For example, an entity partition may include a member partition representing a member platform, a service provider partition 504 representing a service provider platform 440, a partner partition 506 representing a partner platform 420, and / or the like.

[0206] In some embodiments, a service provider partition 504 is a unique identifier for a service provider and / or a service provider's service provider platform 440. A service provider partition 504 may include a number, an alphanumeric number, any character or symbol, or any other sequence of characters or symbols that represents a service provider associated with (e.g., joined, registered, etc.) the exchange platform 102. For example, the exchange platform 102 may include multiple service provider partitions that each identify a service provider platform 440 associated with (e.g., joined, registered, etc.) the exchange platform 102. Each service provider partition 504 may represent a service provider platform 440 that has been configured with one or more exchange platform software development kits (SDKs) or the like to implement a service provider interface for the exchange platform 102.

[0207] In some embodiments, partner partition 506 is a unique identifier for a partner and / or a partner's partner platform. Partner partition 506 may include a number, an alphanumeric character, any character or symbol, or any other sequence of characters or symbols representing a partner associated with exchange platform 102. For example, exchange platform 102 may include multiple partner partitions that each identify a partner platform associated with (e.g., joined, registered, etc.) exchange platform 102. Each partner partition 506 may represent a partner platform that has been configured with one or more exchange SDKs, etc., for implementing a partner interface of exchange platform 102.

[0208] In some embodiments, when a member platform joins the exchange platform 102, an entity partition is generated to identify the member. In some examples, after joining the exchange platform, the member platform can utilize one or more exchange interfaces to register one or more service provider tools with the exchange platform 102. The service provider tool 518 registers with the exchange platform 102 by exchanging one or more tool identifiers with the exchange platform 102.

[0209] In some embodiments, the tool identifier comprises any representation of the service provider tool 518 that identifies the service provider tool without exposing the permanent credentials 514 of the service provider tool 518. As described herein, the tool identifier may comprise a member tool identifier 508, a system tool identifier, a tool reference 520, a tool key, and / or the like.

[0210] In some embodiments, the member tool identifier 508 is a unique identifier used to represent a service provider tool 518 within a member platform, such as the service provider platform 440. For example, the member tool identifier 508 may include a number, an alphanumeric character, any character or symbol, or any other sequence of characters or symbols used to represent the service provider tool 518 to the service provider platform 440. In some examples, the member tool identifier 508 may include a table identifier for a member tool data object.

[0211] In some embodiments, tool reference 520 is a unique identifier used to reference member tool identifier 508. For example, tool reference 520 can be generated by a member platform and / or provided to exchange platform 102 to allow exchange platform 102 to reference service provider tools 518 maintained on the member platform. In some examples, tool reference 520 is the same value as member tool identifier 508. In some examples, tool reference 520 is a different value that maps to member tool identifier 508.

[0212] In some embodiments, the system tool identifier is a unique identifier used to represent the service provider tool 518 within the exchange platform 102. For example, the system tool identifier can include a number, an alphanumeric number, any character or symbol, or any other sequence of characters or symbols that represents the service provider tool 518 to the exchange platform 102 without exposing the permanent credentials 514 of the service provider tool 518. In some examples, the system tool identifier can include a UUID. In some examples, the system tool identifier can include at least one of the system identifiers 512.

[0213] In some embodiments, a tool key is a unique identifier used to reference a system tool identifier. For example, during the registration process of a service provider tool 518 with the exchange platform 102, the exchange platform 102 may generate and / or provide a tool key. In some examples, the tool key may include an encapsulated system tool identifier. For example, the tool key may include an alphanumeric string formatted according to a key format established by the exchange platform 102 (and / or one or more of its APIs). The key format may include any number of characters, such as fifty or more. In some examples, the characters may be case-sensitive. The first portion of the characters (e.g., the first six characters) may be reserved as a partition for identifying the entity associated with the key. For example, for a tool key, the partition may include the service provider partition 504. The second portion of the characters may identify the system tool identifier. In some examples, the tool key may include at least one of the keys 516. The key format described herein may include one or more distinct parts, each of which may be arranged in any order.

[0214] In some embodiments, after joining the exchange platform 102, the member platform may utilize one or more exchange interfaces to register one or more users with the exchange platform 102. The user may be registered on the exchange platform 102 by exchanging one or more user identifiers with the exchange platform 102. For example, the user identifiers may be utilized to generate, maintain, and / or update one or more user data objects reflecting the user of the member platform and / or the exchange platform 102.

[0215] In some embodiments, a user data object is a data entity representing a user interacting with a member platform and / or exchange platform 102. For example, a user can include an entity (e.g., an individual, an organization, a group, etc.) that participates in a value exchange managed by exchange platform 102. In some examples, a user can indirectly engage with exchange platform 102 by creating a user account with a registration service provider, registering (and / or granting registration permission) with service provider tools 518, and / or the like. In some examples, exchange platform 102 can act on behalf of a user without requiring the user to directly interact with exchange platform 102. For example, exchange platform 102 can act as a hidden intermediary between user-facing applications and the user's service provider tools 518.

[0216] In some embodiments, a user data object includes one or more user identifiers and / or one or more user attributes. In some examples, the one or more user identifiers and / or one or more user attributes may be based at least in part on the type of the user data object. For example, a user may be represented in a member platform as a member user data object. Additionally or alternatively, a user may be independently represented by a system user data object in an exchange platform. In some examples, a member user data object and a system user data object may include the same one or more user identifiers and / or one or more user attributes. For example, a member platform may register multiple users with exchange platform 102. During registration, the member platform may provide one or more user identifiers and / or user attributes, and in some examples, exchange platform 102 may return another identifier.

[0217] In some embodiments, a member user data object is an internal representation of a user within a member platform (e.g., a service provider platform 440). A member tool data object may include one or more user identifiers, such as the member user identifier 522, a user key from the exchange platform 102, and / or the like. Additionally or alternatively, a member user data object may include one or more user attributes. One or more user attributes may indicate one or more contextual features for a user. In some examples, a user attribute may indicate one or more identifiable features for a user. For example, a user attribute may indicate a user's first name, last name, email address, physical address (e.g., one or more of street, region, zip code, country, etc.), birthday (e.g., date of birth, age group, etc.), phone number, and / or the like. In some examples, a user attribute may include an encrypted, hashed, and / or otherwise secure representation of a user's identifiable features. For example, a user attribute may include one or more hashed identifiers and / or the like for a user.

[0218] In some embodiments, a system user data object is an external representation of a member user within the exchange platform 102. The system user data object may include one or more user identifiers, such as a user reference 502 for the member platform, a system user identifier, and / or the like. Additionally or alternatively, the system user data object may include one or more user attributes (such as those described herein). For example, a member platform may register a user with the exchange platform 102. During registration, the member platform may provide the user with a user reference 502 and / or one or more user attributes. In some examples, the user attributes may include a hashed and / or encrypted identifier for the user.

[0219] In some embodiments, the user identifier comprises a unique identifier for a user participating in a value-based exchange. The user identifier may comprise a number, an alphanumeric number, any character or symbol, or any other sequence of characters or symbols representing a user of the exchange platform 102 and / or the member platform. In some examples, the user identifier may comprise a user reference 502, a user key, a system user identifier, a member user identification, and / or the like.

[0220] In some embodiments, the system user identifier is a unique identifier used to represent a user within exchange platform 102. For example, the system user identifier can include a number, an alphanumeric character, any character or symbol, and / or any other character or symbol that represents the user to exchange platform 102. In some examples, the system user identifier can include a UUID that is specific to a particular user. In some examples, the system user identifier can include at least one of system identifiers 512.

[0221] In some embodiments, the member user identifier 522 is a unique identifier for representing a user within the member platform. For example, the member user identifier may include a number, alphanumeric characters, any character or symbol, or any other sequence of characters or symbols that represents the user to the service provider platform 440.

[0222] In some embodiments, user reference 502 can be a unique identifier used to reference member user identifier 522. For example, user reference 502 can be generated by a member platform and / or provided to exchange platform 102 to allow exchange platform 102 to reference a user associated with the member platform. In some examples, user reference 502 is the same value as member user identifier 522. In some examples, user reference 502 is a different value that is mapped to member user identifier 522.

[0223] In some embodiments, the user key is a unique identifier used to reference the system user identifier. For example, during the registration process of the user with the exchange platform 102, the exchange platform 120 can generate and / or provide the user key. In some examples, the user key can include an encapsulated system user identifier. For example, the user key can include an alphanumeric string formatted according to a key format established by the exchange platform (and / or one or more APIs thereof). For example, the key format can include a first portion of characters (e.g., the first six characters), which can be reserved for a partition used to identify the entity associated with the key (e.g., a member, etc.). For example, for the user key, the partition can include a service provider partition 504 and / or a partner partition. The second portion of the characters can identify the system user identifier.

[0224] like Figure 5 As shown, keys 516, such as the user and tool keys described herein, can be shared between the exchange platform 102 and the service provider platform 440. Additionally, in some examples, references such as the tool reference 520 and the user reference 502 can be shared across entities. These identifiers and the mapping schemes described herein allow the exchange platform 102 to reference the service provider tool 518 without having to know the permanent credentials 514 (e.g., card number, etc.) for the service provider tool 518. As described herein, one or more of the keys 516 and / or the references can be provided to the service provider platform 440 individually or in any combination. In some examples, each of the keys 516 and the references can be provided to the service provider platform 440 in a redundant process that allows the service provider platform to verify that the communication was provided by the exchange platform 102 (e.g., an entity with access to a particular set of keys and references, etc.).

[0225] In some embodiments, the permanent credentials 514 of a service provider tool 518 include sensitive user and / or tool credentials, such as card numbers, account numbers, subscription numbers, and / or the like, which may put users, members, and / or intermediary entities at risk. When a user applies for, is authorized, and / or is otherwise able to open a new service provider tool 518, the service provider platform 440 can generate, access, and / or otherwise provide the user with the permanent credentials 514. Traditionally, the user then uses the permanent credentials 514 to initiate a value exchange through the service provider tool. By doing so, each time the service provider tool 518 is used, the user is forced to expose sensitive credentials that are directly bound to the service provider tool 518. The disclosed key 516, reference, and identifier mapping scheme overcomes these technical deficiencies.

[0226] In some examples, each identifier is interpretable to a computing platform, such as exchange platform 102 and / or service provider platform 440, but not to a user. To enable a user to select a service provider tool 518 while maintaining the enhanced security features of the present disclosure, in some examples, Figure 5 The identifiers can be further enhanced with tool representations.

[0227] In some embodiments, the tool representation ( Figure 5 (not shown) is a unique identifier of the permanent credential 514 used to represent the service provider tool 518 to the user without exposing the service provider tool 518's credential. For example, the tool representation may include a sequence of numbers, alphanumeric characters, and / or any other characters or symbols that extrinsically represents the service provider tool 518 only to entities with prior knowledge of the service provider tool 518. The format and / or value of the tool representation may be based at least in part on the type of service provider and / or service provider tool 518. For example, in a financial value system, the tool representation may include a portion of the permanent credential 514 (e.g., the last four digits, etc.), such as a card number (e.g., debit card, credit card, etc.), a financial account number, and / or the like. As another example, in an information value system, the tool representation may include a portion of the permanent credential 514 (e.g., one or more numbers, alphanumeric characters, etc.), such as a subscription account number and / or the like. For example, the tool representation may include a derivative of the permanent credential 514 that may only allow entities with prior knowledge of the permanent credential 514 to identify the permanent credential 514 using the tool representation. As another example, a tool representation may include a tool nickname assigned by a user and subsequently recognized by the user.

[0228] In some embodiments, a tool representation may be provided to the exchange platform 102 (e.g., during the registration process) in place of the permanent credentials 514. In this manner, the exchange platform 102 may use the tool representation to represent the service provider tool 518 without needing to know the permanent credentials 514 from which the tool representation was derived. For example, unlike conventional network-based exchange platforms, the exchange platform 102 may not require the permanent credentials 514 corresponding to the service provider tool 518 to implement the various computing tasks disclosed herein. This, in turn, allows the exchange platform 102 to operate more flexibly while storing previously unrecorded contextual data, not only reducing operational computing costs but also increasing the ability of users and the platform to defend against penetration attacks by malicious computing entities.

[0229] In some embodiments, the identifier mapping scheme is supplemented by unique, temporary keys issued to member platforms to facilitate secure, real-time value exchange. For example, the exchange platform 102 can facilitate an additional layer of network and data security by implementing an exchange identifier 510 that represents aspects of a value-based exchange. Some examples of exchange identifiers 510 include service provider-specific exchange identifiers and / or partner-specific exchange identifiers. A service provider-specific exchange identifier can include a temporary, unique exchange identifier that temporarily represents both a service provider tool 518 and a service provider platform 440. For example, a service provider-specific exchange identifier can be mapped to a system identifier 512 for a service provider tool 518. A partner-specific exchange identifier can include a temporary, unique exchange identifier that temporarily represents both a service provider tool 518 and a partner platform. For example, a partner-specific exchange identifier can be mapped to a key 516 for a service provider tool 518, which can be used to identify the service provider platform 440. In some examples, this mapping can be defined by an exchange data object.

[0230] In some embodiments, an exchange data object is a data entity representing an authorized value exchange between one or more members associated with exchange platform 102. In some examples, an exchange data object may include one or more identifiers and / or one or more exchange attributes. For example, the one or more identifiers and / or one or more exchange attributes may be based at least in part on the type of the exchange data object. Exemplarily, an exchange may be represented in a member platform as a member exchange data object. Additionally or alternatively, an exchange may be independently represented by a system exchange data object in exchange platform 102. In some examples, a member exchange data object and a system exchange data object may include the same one or more identifiers and / or one or more exchange attributes. Exemplarily, using some techniques of the present disclosure, exchange platform 102 may issue one or more unique identifiers to a member platform, which may be used to authorize the value exchange.

[0231] In some embodiments, a system exchange data object is an internal representation of a value exchange intermediated using the exchange platform 102. In some examples, a system exchange data object may include one or more different identifiers and / or exchange properties, depending on the role of the system exchange data object in the value-based exchange.

[0232] For example, the system exchange data object may include a service provider-specific exchange data object corresponding to the service provider platform 440. The service provider-specific exchange data object may include one or more identifiers, such as an exchange identifier 510, a system identifier 512 (e.g., a system user identifier and / or a system tool identifier), a UUEK 524, and / or the like. Additionally or alternatively, the service provider-specific exchange data object may include one or more exchange attributes, such as an expiration date, a currency (e.g., for a financial value system, etc.), and / or the like.

[0233] Additionally or alternatively, the system exchange data object may include a partner-specific exchange data object corresponding to the partner platform. The partner-specific exchange data object may include one or more identifiers, such as an exchange identifier 510, one or more keys 516 (e.g., tool keys), a UUEK 524, a member tool reference (e.g., a partner-specific tool reference, etc.), and / or the like. Additionally or alternatively, the partner-specific exchange data object may include one or more exchange attributes, such as an expiration date, a currency (e.g., for a financial value system, etc.), an instrument type, and / or the like.

[0234] In some embodiments, a member exchange data object is an external representation of a value exchange intermediated using the exchange platform 102. The member exchange data object may include one or more identifiers, such as a member exchange identifier, a member tool identifier 508, a UUEK 524 from the exchange platform 102, and / or the like.

[0235] In some embodiments, exchange identifier 510 is a unique identifier used for value exchange using exchange platform 102. Exchange identifier 510 may include a number, an alphanumeric character, any character, or symbol, or any other sequence of characters or symbols that represents at least a user and / or service provider tool 518. In some examples, exchange identifier 510 may include a universally unique identifier (UUID), which may be mapped (e.g., via a series of identifiers, etc.) to a user, service provider tool 518, and / or member registered with exchange platform 102. In some examples, exchange identifier 510 may be generated using one or more UUID generators. For example, exchange identifier 510 may include sixteen bytes of information generated according to one or more UUID formatting standards (e.g., UUID v4 and / or the like). Thus, while exchange identifier 510 may be used by exchange platform 102 and / or member platforms for one or more functions, the same exchange identifier 510 may be useless to external parties if there is no prior association between exchange identifier 510 and one or more other identifiers. In addition to prior identifier associations, exchange identifier 510 may also be associated with exchange platform 102. Therefore, even if the exchange identifier 510 is recognized by the counterparty, the counterparty still needs to impersonate the exchange platform 102 in order to use the exchange identifier 510. Furthermore, before the exchange identifier 510 can be used detrimentally, the counterparty needs to update the settlement account to an account owned by the counterparty, among many other tasks. Each of these tasks increases the effort required to overcome the enhanced security layer added by the exchange identifier 510. When coupled with the temporary nature of the exchange identifier 510, these tasks can become prohibitively expensive.

[0236] In some examples, the exchange identifier 510 can be represented externally by a UUEK 524. Exemplarily, to facilitate credential-free exchange, the exchange platform 102 can issue one or more UUEKs 524 to one or more member platforms. As described herein, the UUEK 524 can eliminate the reliance on traditional permanent credentials 514 by identifying aspects of the value exchange conducted through previously mapped data entities.

[0237] In some embodiments, the UUEK 524 is an external representation of the exchange identifier 510 that can be issued (e.g., in place of the exchange identifier 510) to an external entity (e.g., a user, a partner platform, and / or a service provider platform, and / or the like) to initiate a value-based exchange using the exchange platform 102. To this end, the UUEK 524 can be generated by the exchange platform and issued to the external entity. Each UUEK 524 can include multiple values ​​(e.g., up to fifty characters and / or more, which may or may not be case-sensitive) representing one or more aspects of the value-based exchange. For example, the multiple values ​​can indicate the exchange identifier 510, a partition (e.g., identifying the recipient of the UUEK 524, etc.), an identifier type, and / or one or more flags. Exemplarily, the UUEK 524 can include a partner-specific UUEK and / or a service provider-specific UUEK. As described herein, a partner-specific UUEK may be associated with a partner-specific exchange data object and may include a partner partition 506 , while a service provider-specific UUEK may be associated with a service provider-specific exchange data object and may include a service provider partition 504 .

[0238] For example, the UUEK 524 can be generated according to a key format. The key format can include a plurality of characters, including, for example, fifty or more characters, which can be case-sensitive or insensitive. The first portion of the characters (e.g., the first six characters) can be reserved for a partition used to identify the recipient of the UUEK 524. For example, the partition can include a partner partition 506, a service provider partition 504, and / or any other member partition. For example, the UUEK 524 can be issued in response to a request from an authorized member (e.g., associated with a partner and / or a service provider).

[0239] Additionally or alternatively, at least one character of the key format (e.g., the seventh character) may identify the format of the UUEK 524. At least another character (e.g., the eighth character) may identify the type of the UUEK 524. In some examples, the second portion of characters may identify the exchange identifier 510 (e.g., the group of twenty-two characters following the eighth character). The third portion of characters may be reserved (e.g., the group of twenty characters following the first portion of characters). An example representation is provided below:

[0240] ppPpppFiGGGGGGGGGGGGGGGGGGGGGGrrrrrrrrrrrrrr

[0241] Where p represents a partition character, F represents a format character, i represents an identifier type character, G represents an exchange identifier 510, and r represents a reserved character. The key format allows for 9.8x1084 unique permutations, which is more than the number of atoms in the known observable universe. This enables the generation and distribution of new UUEKs 524 on demand without compromising the security of the underlying data to which the UUEKs 524 may be mapped, such as identifiers of users, tools, and / or any other potentially sensitive information.

[0242] In some embodiments, the exchange platform 102 maintains multiple security code element groups 424 for one or more users, member platforms, service provider tools, and / or the like registered with the exchange platform 102. A security code element group 424 may be a data entity that defines the association between a security code, a user, and one or more of a member platform and / or service provider tool. A security code element group 424 may include a data object, a record, and / or any other data structure (e.g., a link node, etc.) configured to represent an association between a security code and a user, and in some embodiments, between a member platform, a service provider tool, or both. A security code element group 424 may include, for example, a security code reference, one or more system identifiers 512 (e.g., a user identifier), one or more member identifiers, one or more tool identifiers, and / or the like, and / or contextual pairing data. The contextual pairing data may include one or more pairing attributes, such as one or more timing attributes. For example, a timing attribute may indicate a configuration time (e.g., indicating a time when the security code element group was set), an expiration time (e.g., a time when the security code must be reset), and / or the like. As described herein, the exchange platform 102 can utilize the security code element group 424 to identify a security code reference for a user to perform a security action on behalf of the user (e.g., allowing exchange using a UUEK, etc.) based at least in part on a comparison between the security code reference and a security code input provided by the user.

[0243] In some embodiments, a security code reference is a data entity that defines a security code for a record. A security code reference may include an internal representation of a security code for a user (eg, for exchange platform 102, etc.).

[0244] In some embodiments, a security code is a data entity that defines a sequence of characters used to verify a user in an interaction (e.g., physical exchange, virtual exchange, registration, and / or the like). The security code may include a sequence of one or more dynamic lengths of different characters (e.g., six characters, eight characters, etc.) that may be set and / or provided to the user in advance by the user. The security code may be provided later by the user to verify the presence of the interactive user (e.g., as described herein, by comparing the security code input with a security code reference). The one or more different characters may include any number of alphanumeric characters, emoticons, Chinese characters, winged fonts, and / or the like.

[0245] In some embodiments, the security code is a network-managed n-character PIN. As described herein, the security code can be managed as a service by a client device to (i) securely retrieve the UUEK, (ii) register the tool with the member platform, and / or (iii) enable or disable the use of the UUEK (and / or any other exchange credentials) prior to an exchange request. In this way, security codes can be deployed for any type of service provider tool by retrieving, registering, and / or enabling or disabling the corresponding UUEK. By managing security codes at the network level, members benefit from faster exchanges because the possibility of authorization being denied due to an invalid PIN is eliminated. For example, the UUEK can be disabled until the security code for enabling the UUEK is received. The exchange platform can prevent users from initiating exchanges before the UUEK is enabled, thereby ensuring that all exchange authorization requests provided to the service provider have been pre-verified based on the security code. This effectively reduces network traffic between members in the exchange network, thereby reducing network congestion in traditional high-traffic communication systems.

[0246] In some embodiments, the security code corresponds to the user. For example, the security code can be pre-set and / or provided to the user by the user through interaction with the exchange platform 102. For example, the security code can be set by the user through interaction with an exchange network widget embedded in a member software application. This allows the security code to be set without directly interacting with or sharing the security code with the corresponding member platform (e.g., service provider platform 440). In some examples, the security code can be tool-specific or component-specific. For example, the corresponding security code can be configured to retrieve and / or enable the UUEK of a specific member platform and / or the service provider tool on a specific member platform. Additionally or alternatively, the corresponding security code can be configured to register the member platform's account with the exchange network. Exemplarily, the exchange platform 102 can manage the use of security codes to implement one or more security actions using multiple security code tuples, each of which associates a security code with a corresponding user, member platform, and / or service provider tool.

[0247] V. Example System Operation

[0248] Figure 6 A process flow for facilitating network management of security codes for users according to one or more embodiments of the present disclosure is provided. The process flow describes a network process 600 for establishing network-managed security codes for performing secure interactions between users and third parties. Process 600 can be utilized to overcome various limitations of conventional exchange systems that rely on limited PIN mechanisms that are unable to adequately protect network interactions due to the limited sophistication of conventional PINs and the party managing the PINs as described herein. Process 600 can be implemented by one or more computing devices, entities, and / or systems described herein. For example, through the various steps / operations of process 600, an exchange platform can utilize various communication and authentication technologies to overcome various limitations of conventional network exchange mechanisms by improving the management of security codes used to protect network-based interactions.

[0249] Figure 6 An example process 600 is shown for explanation purposes. Although example process 600 depicts a particular order of steps / operations, this order may be changed without departing from the scope of this disclosure. For example, some of the steps / operations described may be performed in parallel or in a different order without materially affecting the functionality of process 600. In other examples, different components of an example device or system implementing process 600 may perform functions substantially simultaneously or in a particular order.

[0250] In some embodiments, process 600 includes establishing a security code session at step / operation 602. For example, an exchange platform (e.g., its partner service, service provider, etc.) can establish a security code session. In some examples, process 602 can begin on a member application, such as a partner application (e.g., a partner website, a user application, etc.) and / or a service provider application, where the member platform can allow a user to manage (e.g., set, reset, remove, etc.) a network-managed security code. The member platform can enable management of the network-managed security code by initiating a security code session with the exchange platform.

[0251] For example, as described herein, a user may access a member application via a client device through a portal (e.g., a browser, a web application, and / or the like). The user's browser, web application, mobile application, etc. may retrieve a platform connection widget from a content delivery network (CDN) and issue a communication session request to the member platform to establish a secure code session. In response to the request, the member platform may generate (e.g., using one or more exchange interfaces, etc.) a communication session request to the exchange platform (e.g., its member service). The communication session request may include an API request provided via a partner interface to initiate a secure code management widget for establishing a secure code session for the user.

[0252] In some embodiments, process 600 includes receiving a security code request at step / operation 604. For example, the exchange platform (e.g., its partner service, service provider, etc.) can receive the security code request via a communication session established with the member platform. For example, a security code management widget can provide a user prompt with information about network-managed security codes. The user can respond to the prompt via a client device to generate a security code request and provide the security code request to the exchange platform. The security code request is generated and provided by a widget running in a member application. In this way, the member application can serve as an interface between the exchange platform and the user, while the member platform never has access to the security code information provided by the user.

[0253] In some embodiments, a security code request is a data entity defined as a request for a user to set, reset, and / or remove a security code. A security code request can be provided to an exchange platform from a member of an exchange network. The security code request can indicate the user's member user reference and, in some examples, a member tool reference for the user. For example, a security code request that includes only the member user reference can default to all service provider tools associated with the user and can, for example, initiate a security code element group action (e.g., one or more set, reset, and / or remove operations, etc.) applicable to all service provider tools maintained for the user by the corresponding member platform. Additionally or alternatively, a security code request that includes both a member user reference and a member tool reference can initiate a security code element group action (e.g., one or more set, reset, and / or remove operations, etc.) applicable to a specific service provider tool maintained for the user by the corresponding member platform. In addition to the reference, a security code request can include a code action attribute (indicating the desired set, reset, and / or remove operation) and a security code input (indicating a new, modified, or existing n-character PIN) to replace, modify, or remove the user's security code.

[0254] In this manner, the security code widget can be configured to interact with a user to set, reset, and / or remove a specific security code, which allows the security code to be set, reset, and / or removed without directly interacting with the member platform. This improves network security by providing an access point (the switching platform) for modifying multiple different security codes for a single user across multiple different member platforms.

[0255] In some embodiments, process 600 includes verifying the user at step / operation 606. For example, the exchange platform (e.g., its partner service, service provider, etc.) can verify the user by comparing the user reference from the security code request with a plurality of pre-registered user identifiers. If the user reference corresponds to the user identifier, the user may be verified. If the user is verified, process 600 may continue to step / operation 610 to perform a security code tuple action on behalf of the identified user. Otherwise, process 600 may continue to step / operation 612 to provide a security code response indicating a failure to verify the user.

[0256] In some embodiments, process 600 includes optionally verifying the service provider tool at step / operation 608. For example, if the security code request includes a tool reference, the exchange platform (e.g., its partner service, service provider, etc.) may verify the service provider tool. If the tool reference corresponds to a pre-registered tool identifier, the tool may be verified. If the tool is verified, process 600 may continue to step / operation 610 to perform a security code tuple action on behalf of the identified user. Otherwise, process 600 may continue to step / operation 612 to provide a security code response indicating a failure to verify the tool.

[0257] In some embodiments, process 600 includes performing a security code element group action at step / operation 610. For example, the exchange platform (e.g., its partner service, service provider, etc.) may perform a security code element group action by setting a new security code for the user, resetting the security code for the user, and / or removing the security code for the user. To do so, the exchange platform may (i) generate a new security code element group including a user identifier and a new security code for the user, (ii) modify an existing security code element group corresponding to the user identifier to update the security code for the user, and / or (iii) remove an existing security code element group corresponding to the user.

[0258] In some embodiments, process 600 includes providing a security code response at step / operation 612. For example, the exchange platform (e.g., its partner services, service providers, etc.) may provide a security code response indicating completion and / or failure of a security code tuple action.

[0259] Figure 7A -C provides a process flow for establishing a secure cross-entity relationship according to one or more embodiments of the present disclosure. The process flow illustrates one or more stages of a registration process 700 for registering a user and / or service provider tool with another member platform to facilitate credential-free value exchange between the two member platforms. Figure 7AFIG1-C shows an example process 700 for explanation purposes. Although example process 700 depicts a specific order of steps / operations, this order may be changed without departing from the scope of this disclosure. For example, some of the steps / operations described may be performed in parallel or in a different order without materially affecting the functionality of process 700. In other examples, different components of an example device or system implementing process 700 may perform functions substantially simultaneously or in a specific order.

[0260] Various embodiments of process 700 address technical challenges related to data security and efficiency of network-based exchanges in value exchanges between one or more computing entities. Traditional systems address these challenges using registration mechanisms that require users to disclose sensitive and permanent credentials to a third-party registration service. These traditional registration services then verify the user's account ownership and provide the permanent credentials to the partner platform for storage and subsequent processing. By doing so, during the traditional registration process, user credentials are transmitted and exposed to multiple different entities, ultimately increasing the risk of exposure to malicious parties during and after network communications. Various embodiments of process 700 provide improved network communication, data encryption, and data management technologies to enable credential-free exchange registration capabilities, thereby reducing the data security risks posed by traditional processes.

[0261] One or more embodiments of process 700 may be implemented by one or more computing devices, entities, and / or systems described herein. For example, through the various steps / operations of process 700, exchange platform 102 may utilize credentialless registration techniques to overcome various limitations of traditional registration mechanisms by registering a service provider tool with a partner platform without accessing the service provider tool's permanent credentials. By doing so, sensitive information behind the service provider tool used to participate in the value exchange is never exposed to potentially malicious parties or partner platforms that may be vulnerable to network-based attacks. For example, unlike traditional techniques, exchange platform 102 never receives identifiable or actionable account information for the user, and the service provider managing the account participates in the registration process rather than being disintermediated by a potentially insecure registration service. This, in turn, eliminates the need to enforce resource data governance standards on every device involved in the registration process, ultimately improving computing resource utilization while enhancing network and data security.

[0262] Figure 7Ais a flow chart illustrating an example of the first stage of a registration process 700 for registering a user with an exchange platform without exposing permanent credentials associated with the user and / or service provider tools. The flow chart describes a communication technique that overcomes various limitations of traditional registration systems by circumventing their reliance on sensitive and permanent credentials. The communication technique can be implemented by one or more computing devices, entities, and / or systems described herein, such as an exchange platform establishing a secure communication session with a user through a partner application.

[0263] In some embodiments, process 700 includes establishing a registration session for the user and the partner platform at step / operation 702. For example, the registration process 700 may begin on a partner application (e.g., a partner website, a user application, etc.), where the partner platform may allow the user to register a partner account on the partner application using an exchange platform to facilitate access to service provider tools. The partner platform may enable the user's registration by initiating a registration session with the exchange platform.

[0264] For example, as described herein, a user may access a partner application through a client device via a portal (e.g., a browser, a web application, and / or the like). The user's browser, web application, mobile application, etc. may retrieve a platform connection widget from a content delivery network (CDN) and issue a communication session request to the partner platform to establish a registration session. In response to the request, the partner platform may generate (e.g., using one or more exchange interfaces, etc.) a communication session request to the exchange platform (e.g., its partner service). The communication session request may include an API request provided via the partner interface to initiate a registration widget for establishing a registration session for the user.

[0265] In some embodiments, the communication session request includes one or more registration attributes, such as user data, a user identifier, a user hash, a timestamp, a device identifier, a partner identifier, and / or the like. As described herein, some techniques of this disclosure enable a computing entity to use an identifier to identify a service provider tool without requiring the service provider tool's permanent credentials to be included in the communication session request. For example, the partner platform can be configured to obtain user data for a user (e.g., through user input on a user interface screen, pre-recorded data from a partner account, etc.) and provide the user data to the exchange platform to initiate the registration process. In some examples, the partner platform can provide the user data to the exchange platform (e.g., its partner service) along with the communication session request (e.g., through one or more API calls to a partner interface, etc.) to initiate the widget session. In some examples, the user data can be encrypted, hashed, etc. before being transmitted to the exchange platform. In some examples, the user data can include one or more user attributes (as described herein).

[0266] In some embodiments, an exchange platform (e.g., a partner service thereof) receives a communication session request using a partner interface to initiate a registration session on a user's client device. In some examples, the communication session request may include user data for the user. Additionally or alternatively, the registration initiation request may include one or more user attributes for the user. In some examples, the user attributes may be encrypted and / or hashed as described herein.

[0267] In some embodiments, process 700 includes setting user and partner data at step / operation 704. For example, the exchange platform (e.g., its connection service, partner service, etc.) can identify and / or generate user and / or partner data from data provided in the communication session request. In some examples, the user data can include one or more user attributes. In some examples, the user data can include one or more encrypted and / or hashed user attributes. In some examples, the partner data can include a shared identifier between the exchange platform and the partner platform (such as the partner partition described herein).

[0268] In some embodiments, process 700 includes generating a session identifier for the registration session at step / operation 706. For example, the exchange platform (e.g., its connection service, partner service, etc.) may generate a session identifier for the communication session between the partner platform and the exchange platform to track communications exchanged during the registration session. For example, the session identifier may include a unique number, string, and / or the like that is used to authenticate messages exchanged during the registration session. The exchange platform may utilize the connection service and / or the partner service to establish the registration session. For example, in response to a registration initiation request, the partner service may call another service, such as the connection service, to establish a communication session that the client-side widget may use to provide an interface between the user and the partner service to complete user registration. The connection service may generate a session identifier and return the session identifier to the partner service. The partner service may return the session identifier to the partner platform, which may use the session identifier to launch the client-side widget through an instance of a partner application on the client device. Once the partner application receives the session identifier, the partner application may launch (e.g., execute, initiate, etc.) the client-side widget. The user may interact with the widget to complete the registration process 700.

[0269] In some embodiments, process 700 includes determining and providing a member list for the user at step / operation 708. The member list can be a list of service providers. For example, the exchange platform (e.g., its connection services, partner services, etc.) can determine a list of service providers for the user from a network of service providers associated with the exchange platform (e.g., registered with it, etc.). In some examples, the list of service providers can include each service provider platform associated with the exchange platform. Additionally or alternatively, the list of service providers can include a subset of related service provider platforms tailored for the user.

[0270] For example, the exchange platform may determine one or more service provider platforms based at least in part on user attributes of a registration session and customize a service provider list for the one or more service provider platforms. As described herein, the exchange platform may, for example, include multiple system user data objects and / or system utility data objects. In some examples, the exchange platform may identify one or more system user data objects corresponding to the user based on the user attributes. In some examples, each system user data object may identify a service provider platform associated with the user. In this manner, the exchange platform may determine one or more service providers associated with the user based on one or more system user data objects.

[0271] Additionally or alternatively, the exchange platform (e.g., one or more of its service provider services) may provide a presence request for user presence status data from each service provider platform in the member platform network (e.g., via a service provider interface). The user presence request may include one or more user attributes (e.g., encrypted attributes, hashed attributes, etc.) for the user, which the service provider platform may utilize to determine whether the user has a tool on the service provider platform. In response to the request, the exchange platform (e.g., one or more of its service provider services) may receive presence status data representing the presence tools on each service provider platform from the one or more service provider platforms. The exchange platform (e.g., its partner services) may determine one or more service providers based, at least in part, on the presence status data.

[0272] In some examples, the exchange platform (e.g., its connection service, partner service, etc.) can use a partner interface and a registration user interface provided by the partner application to initiate the presentation of a pre-registration screen based at least in part on one or more service providers. For example, a client device can be configured to access a partner application hosted by the partner platform. The registration user interface can be presented to the user on the client device via a widget within the partner application. The widget can be defined internally by the partner or provided by the exchange platform. The pre-registration screen can present a plurality of selectable icons indicating a list of service providers.

[0273] Next, as reference Figure 7B As described in further detail, the registration process 700 may proceed to a second stage, wherein a tool identifier corresponding to the user is identified through interaction between the exchange platform, the user, and the service provider platform.

[0274] Now refer to Figure 7B , Figure 7B is a flow chart illustrating an example of the second stage of a registration process 700 for registering a service provider tool with a partner platform without exposing permanent credentials associated with the user and / or the service provider tool. The flow chart describes communication techniques that overcome various limitations of conventional registration systems by circumventing the conventional system's reliance on permanent user-supplied credentials (e.g., card numbers and / or the like). The communication techniques may be implemented by one or more computing devices, entities, and / or systems described herein (e.g., an exchange platform) to establish a connection between a user, a partner platform, and a service provider tool.

[0275] In some embodiments, process 700 includes determining and providing a service provider tool list for the user at step / operation 710. The service provider tool list can be determined at least in part based on selecting a service provider from a pre-registration screen. For example, in some examples, the exchange platform (e.g., its connection service, partner service, etc.) can use a partner interface to receive pre-selection data that indicates a selection of a particular service provider from one or more service providers presented on the pre-registration screen. For example, the widget can receive pre-selection data from a partner application and provide a tool registration request to the exchange platform (e.g., its connection service, partner service, etc.) (e.g., via the partner interface). The tool registration request can include a session identifier and / or a service provider identifier indicating the selected service provider.

[0276] In response to the request, the exchange platform (e.g., its connection service, partner service, etc.) may receive service provider-tool data based at least in part on the pre-selected data. The service provider-tool data may indicate one or more service provider tools for the user facilitated by the selected service provider platform. For example, the service provider-tool data may include one or more system tool identifiers and / or corresponding tool representations from one or more tool data objects corresponding to the service provider and the user. For example, each tool data object may include a system user identifier corresponding to the user.

[0277] Additionally or alternatively, the exchange platform (e.g., one or more service provider services thereof) may provide a tool request for service provider-tool data from a selected service provider platform (e.g., via a service provider interface). For example, the tool request may include a user reference corresponding to a member user identifier of the service provider platform. In response to the request, the service provider platform may identify one or more member tool data objects including the member user identifier, identify one or more tool references corresponding to the one or more member tool data objects, and provide the exchange platform with service provider-tool data indicating the one or more tool references and / or one or more corresponding tool representations.

[0278] The exchange platform (e.g., its connection service, partner service, etc.) may initiate presentation of a tool registration screen via a user's client device using a partner interface and via a registration user interface, based at least in part on the service provider-tool data. The tool registration screen may be internally defined by the partner and / or provided by the exchange platform. For example, the tool registration screen may indicate one or more service provider tools associated with the user and the selected service provider. Exemplarily, the tool registration screen may indicate a corresponding tool representation for each of the one or more service provider tools. In some examples, such as when the user is only associated with a single service provider tool, the tool registration screen may include a confirmation prompt to confirm the user's intent to register the service provider tool.

[0279] In some embodiments, process 700 includes receiving a secure interaction request at step / operation 712. For example, the exchange platform may receive the secure interaction request from a member platform using a member interface. In some embodiments, the secure interaction request is a data entity that defines a request to perform a secure interaction using a security code input. The secure interaction request may be provided to the exchange platform from a member of the exchange network. The secure interaction request may indicate (i) a user, a member platform, and / or a service provider tool, and (ii) a security code input for the user. In some examples, the secure interaction request may indicate a service provider tool selected by the user from a list of service provider tools.

[0280] In some examples, the secure interaction request may indicate one or more contextual security attributes. The one or more contextual security attributes may include one or more timing attributes. For example, the one or more timing attributes may indicate a provision time (e.g., indicating a time to send the secure interaction request, etc.), a request time (e.g., a request time for performing the secure interaction, etc.), and / or the like.

[0281] The secure interaction request may be received from the member platform. For example, a user may initiate a secure interaction request via a member application hosted by the member platform on behalf of a member of the exchange network. In some examples, the secure interaction request may be generated and / or provided in response to a selection input indicating a service provider tool, a UUEK for a service provider tool, and / or the like. As an example, a user may select a tool representation, a UUEK representation, and / or the like (e.g., via a partner application associated with a partner platform, a service provider application associated with a service provider platform, etc.) to register a service provider tool, authorize a value-based exchange, and / or the like. In some examples, the secure interaction request may be automatically initiated if the user and / or the selected tool, UUEK, and / or the like is associated with a security code. For example, in response to the selection, the member platform (e.g., via the corresponding member application) may prompt the user to enter a security code. The user may enter the security code input to provide the secure interaction request.

[0282] In some examples, the exchange platform may use a partner interface to receive a secure interaction request from a client-side widget. The request may include selection data and / or a security code input. The selection data may indicate a selection of a service provider tool from a registration user interface. For example, the selection data may indicate an instrument representation (e.g., an account nickname, etc.) for the selected service provider tool. In some examples, the selection data may include at least one of an instrument type, a currency type (e.g., in a financial value system), and / or an instrument identifier (e.g., an instrument representation, etc.) corresponding to the selection.

[0283] In some embodiments, process 700 includes verifying the security code input of the security interaction request at step / operation 714. In some examples, the exchange platform (e.g., its connection service, partner service, etc.) can compare the security code input with the security code tuple corresponding to the security interaction request to verify the user's presence status. The exchange platform can generate a verification event indicating that the security code input has been verified and / or invalid. If the verification is successful, process 700 can proceed to step / operation 718, where the exchange platform provides a valid security interaction response. If the verification is invalid, the exchange platform can proceed to step / operation 716, where the exchange platform provides an invalid security interaction response, and then return to step / operation 712 to receive another security interaction request.

[0284] In some embodiments, a verification event is a data entity that defines the verification of a user's security code input. The verification event may include a secure event, which may indicate successful verification between the security code input and the security code reference. Additionally or alternatively, the verification event may include an unsecure event, which may indicate failed verification between the security code input and the security code reference. For example, a secure event may indicate a determination that the security code input matches the corresponding security code reference. In some examples, an unsecure event may indicate a determination that the security code input does not match the corresponding security code reference. In some examples, the exchange platform may generate a security event in response to a determination that the security code input matches the corresponding security code reference. Additionally or alternatively, the exchange platform may generate an unsecure event in response to a determination that the security code input does not match the corresponding security code reference. In some examples, the security event may be associated with a security time period, and the exchange platform may generate an unsecure event in response to determining that the security time period has expired.

[0285] In some embodiments, the verification event is stored in association with a security data entity (e.g., a UUEK, a service provider tool, and / or a user). For example, the verification event may be stored in an exchange data object corresponding to the UUEK, a system tool data object corresponding to the service provider tool, a system user data object corresponding to the user, and / or the like. Additionally or alternatively, the verification event may be stored in association with a security code element group. For example, a secure event may be stored in response to a successful verification of a user, while an unsafe event may be stored in response to a failed verification of a user.

[0286] In some embodiments, the verification event includes contextual verification data. For example, the contextual verification data may indicate a verification timing. The verification timing may include a timestamp corresponding to the sending, receiving, creation, and / or decision of the verification request. For example, the contextual verification data may include a verification timestamp indicating the time when the switching platform determined that the security code input and the security code reference matched or did not match. In some examples, the contextual verification data may indicate a security time period. The security time period may indicate a subsequent timestamp, duration, and / or the like during which the UUEK, service provider tools, and / or the like may be secure in response to the security event.

[0287] In some embodiments, process 700 includes providing a valid secure interaction response to the partner platform at step / operation 718. For example, the exchange platform may provide a valid secure interaction response to the partner platform. The secure interaction response may define a response to the secure interaction request. In some embodiments, the secure interaction response is provided from the exchange platform to the member providing the secure interaction request. The secure interaction response may indicate a verification event. The valid secure interaction response may indicate a successful verification event.

[0288] In some embodiments, process 700 includes, at step / operation 720, providing a registration request to a service provider platform corresponding to the service provider tool in response to the network-level authentication of the user. For example, an exchange platform (e.g., its service provider service, etc.) may provide a registration request to a service provider platform corresponding to the selected service provider tool using a service provider interface. The registration request may include service provider registration data indicating one or more user identifiers of the user and / or one or more tool identifiers for the service provider tool. In response to the registration request, the service provider platform may authenticate the service provider tool using the one or more identifiers.

[0289] For example, the service provider registration data may include one or more identifiers for referencing the service provider tool in communications between the exchange platform, the service provider platform, and / or the partner platform, without using permanent credentials for the service provider tool (e.g., card number, account number, etc.). For example, the one or more identifiers may include various combinations of user identifiers and / or tool identifiers to authenticate the user and / or device through one or more redundancy checks. For example, a user identifier for a user may include a user reference for the service provider platform and / or a user key from the exchange platform corresponding to the user reference. As another example, a tool identifier for a service provider tool may include a tool reference for the service provider platform and / or a tool key from the exchange platform corresponding to the tool reference.

[0290] The service provider registration data may include any combination of references, keys, and / or identifiers as described herein. In one example, the service provider registration data may include one of a tool reference, a tool key, a user reference, and / or a user key. Additionally or alternatively, the service provider registration data may include a combination of a tool reference, a tool key, a user reference, and a user key corresponding to built-in redundancy. In some examples, the combination of identifiers may be specified by an interface call. The combination may be service provider specific and / or dynamically changeable based on the communication scheme. Thus, the specific combination of identifiers provided in the registration request may be used as an additional validation check to ensure that the registration request is received from the relevant platform (e.g., an exchange platform).

[0291] The service provider can compare the identifier from the registration request with one or more member data objects (e.g., member tool data object, member user data object, etc.) to identify the service provider tool corresponding to the registration request without exposing the permanent credentials of the service provider tool.

[0292] Now refer to Figure 7C , Figure 7Cis a flow chart illustrating an example of the third stage of a registration process 700 for issuing a UUEK to facilitate credential-free value exchange. The flow chart describes a communication technique that overcomes various limitations of conventional registration systems by circumventing their reliance on user-provided instrument references (such as card numbers and / or the like). The communication technique can be implemented by one or more computing devices, entities, and / or systems described herein (e.g., an exchange platform) to establish a user instrument record for registering a user with the exchange platform.

[0293] In some embodiments, process 700 includes receiving a registration response from the service provider platform at step / operation 722. For example, the exchange platform may receive a registration response indicating a success or failure of the registration.

[0294] In some embodiments, process 700 includes determining whether the service provider tool is successfully registered at step / operation 724. If the service provider tool is successfully registered, process 700 may proceed to step / operation 728. Otherwise, the process may proceed to step / operation 726, where the exchange platform provides a failure response.

[0295] In some embodiments, process 700 includes generating a UUEK in response to a successful registration at step / operation 728. For example, the exchange platform may generate the UUEK in response to verification of the registered user and / or tool by the exchange network (e.g., using a security code) and / or the service provider platform. Exemplarily, the exchange platform may generate UUEKs corresponding to the user, the service provider tool, and the partner platform. As described herein, the exchange platform may store the UUEK in a partner-specific exchange data object that associates the UUEK with the exchange identifier, the tool key, and the partner-specific tool reference.

[0296] In some embodiments, process 700 includes providing the UUEK to the partner platform at step / operation 730. For example, the exchange platform may provide data indicating the UUEK to the partner platform using a partner interface. In some examples, the partner platform may provide the UUEK and / or a representation thereof to the user (e.g., for storage in a virtual wallet, etc.). Exemplarily, the UUEK may be represented in one or more different forms, such as a machine-readable optical image (e.g., a barcode, a Quick Response code, etc.), a keyword, a virtual widget, and / or the like.

[0297] Figure 8A-B provides a process flow for facilitating secure interactions without credentials in accordance with one or more embodiments of the present disclosure. The process flow describes a network process 800 for establishing a network-managed UUEK to securely verify the presence of a user for value exchange. As described herein, process 800 can be utilized to overcome various limitations of traditional exchange systems that expose sensitive and permanent credentials to multiple third parties and rely on limited PIN mechanisms that do not adequately protect value-based exchanges. Process 800 can be implemented by one or more computing devices, entities, and / or systems described herein. For example, through the various steps / operations of process 800, an exchange platform can utilize various communication and verification technologies to overcome various limitations of traditional exchange mechanisms by improving the management of security codes used to protect network-based exchanges.

[0298] Figure 8A FIG-B shows an example process 800 for explanation purposes. Although example process 800 depicts a specific order of steps / operations, this order may be changed without departing from the scope of this disclosure. For example, some of the steps / operations described may be performed in parallel or in a different order without materially affecting the functionality of process 800. In other examples, different components of an example device or system implementing process 800 may perform functions substantially simultaneously or in a specific order.

[0299] In some examples, process 800 begins after a registration and / or security code process (e.g., process 600), in which a user can manage a network-managed security code to facilitate secure, credential-free interactions. For example, as described herein, one or more registration processes can be pre-performed between one or more member platforms and / or an exchange platform to register multiple service provider tools with the exchange platform. Thereafter, the exchange platform can generate and issue a UUEK to the registered service provider platform to issue value-based exchanges using the registered service provider tool without reference to the service provider tool's permanent credentials. Additionally or alternatively, a registration process can be performed to register the registered service provider tool maintained by the service provider platform with the partner platform. In some examples, the exchange platform can facilitate the registration process and, in response to a successful registration, generate and issue a UUEK to the partner platform to initiate future value-based exchanges. In some examples, once registered, the user can establish a network-managed security code with the exchange platform to facilitate the distribution of UUEKs and / or activate previously issued UUEKs.

[0300] Thus, using some of the communication techniques of the present disclosure, a member platform can enhance the security of a UUEK by establishing one or more security codes for a user. For example, by replacing the permanent credentials of a service provider tool with a UUEK, the communication techniques of the present disclosure can manage access to a service provider tool by issuing new UUEKs and / or enabling or disabling previously issued UUEKs to enforce standards on behalf of the member. In some examples, this includes enforcing the use of security codes to verify the user's presence for secure interactions. For example, using some of the techniques of the present disclosure, an exchange platform can act as a ruling engine to verify the user's presence before issuing a UUEK and / or verify a previously issued UUEK on behalf of a member platform. According to the steps / operations of process 800, an exchange platform can enforce security codes for users, service provider tools, and / or their UUEKs, which can be used to enforce member policies on behalf of the member platform without the member platform's continued involvement. In this way, network-managed security codes can be established that extend the security provided by UUEKs in credential-free exchanges.

[0301] refer to Figure 8A In some embodiments, process 800 includes receiving a secure interaction request at step / operation 802. For example, an exchange platform (e.g., its partner service, service provider, etc.) may receive a secure interaction request from a member platform. As described herein, the secure interaction request may include a security code input, a user identifier, and / or a tool identifier.

[0302] In some embodiments, process 800 includes identifying a security code element set at step / operation 804. For example, the exchange platform (e.g., its authentication service, etc.) may identify a security code element set corresponding to the user identifier and / or the tool identifier.

[0303] In some embodiments, process 800 includes determining whether the security code input is valid at step / operation 806. For example, the exchange platform (e.g., its verification service, etc.) can verify the security code input based at least in part on a comparison between the security code input and a corresponding security code reference. Exemplarily, the user identifier and / or tool identifier can be associated with a security code element group that includes the security code reference and the corresponding user and / or tool identifier. For example, as described herein with reference to Figure 6 As described in AC, the security code tuple may be previously generated in response to a security code request from a member platform.

[0304] In some embodiments, the security code reference includes an n-character sequence of one or more different characters. The one or more different characters may include one or more alphanumeric characters and / or any other characters. The security code input may include a second n-character sequence of one or more different characters. If the security code input matches (e.g., an exact match, a partial match, etc.) the character sequence of the security code reference, the input may be verified.

[0305] If the security code input is valid, process 800 may proceed to step / operation 808 where a security event is recorded. If the security code input is invalid (e.g., one or more characters do not match the security code reference, etc.), process 800 may proceed to step / operation 810 where an unsafe event is recorded.

[0306] In some embodiments, process 800 includes storing the authentication event at step / operation 812. For example, the exchange platform (e.g., its authentication service) may store data indicating the authentication event with reference to the user, tool, and / or security code element set for the user and / or service provider tool.

[0307] In some embodiments, a verification event is a data entity that defines the verification of a user's security code input. A verification event may include a secure event, which may indicate successful verification between the security code input and the security code reference. Additionally or alternatively, the verification event may include an unsecure event, which may indicate failed verification between the security code input and the security code reference. For example, a secure event may indicate a determination that the security code input matches the corresponding security code reference. In some examples, an unsecure event may indicate a determination that the security code input does not match the corresponding security code reference. In some examples, the exchange platform may generate a security event in response to a determination that the security code input matches the corresponding security code reference. Additionally or alternatively, the exchange platform may generate an unsecure event in response to a determination that the security code input does not match the corresponding security code reference. In some examples, a security event may be associated with a security time period, and the exchange platform may generate an unsecure event in response to determining that the security time period has expired.

[0308] In some embodiments, the verification event is stored in association with a security data entity (e.g., a UUEK, a service provider tool, and / or a user). For example, the verification event may be stored in an exchange data object corresponding to the UUEK, a system tool data object corresponding to the service provider tool, a system user data object corresponding to the user, and / or the like. Additionally or alternatively, the verification event may be stored in association with a security code element group. For example, a secure event may be stored in response to a successful user verification, while an unsecure event may be stored in response to a failed user verification.

[0309] In some embodiments, the verification event includes contextual verification data. For example, the contextual verification data may indicate a verification timing. The verification timing may include a timestamp corresponding to the sending, receiving, creation, and / or decision of the verification request. For example, the contextual verification data may include a verification timestamp indicating the time when the switching platform determined that the security code input and the security code reference matched or did not match. In some examples, the contextual verification data may indicate a security time period. The security time period may indicate a subsequent timestamp, duration, and / or the like during which the UUEK, service provider tools, and / or the like may be secure in response to the security event.

[0310] In some embodiments, if the security code is valid, process 800 includes storing a security event at step / operation 808. For example, the exchange platform can store a security event for the user in response to validating the UUEK. In some examples, the exchange platform can generate a security event in response to determining that the security code input matches the corresponding security code reference. For example, the security event can be stored in response to validating the security code input.

[0311] In some embodiments, if the security code is invalid, process 800 includes storing an unsafe event at step / operation 810. For example, the exchange platform may store an unsafe event for the user in response to a failure to authenticate the user. In some examples, the exchange platform may generate an unsafe event in response to a determination that the security code input does not match the corresponding security code reference. For example, the unsafe event may be stored in response to a failure to authenticate the user. In some examples, the security event may be associated with a security time period, and the exchange platform may generate the unsafe event in response to a determination that the security time period has expired.

[0312] In some embodiments, process 800 includes providing a secure interaction response at step / operation 814. For example, an exchange platform (e.g., its service provider service, etc.) may provide a secure interaction response indicating a verification event to a member platform (and / or client device) associated with a secure interaction request. In some embodiments, the secure interaction response defines a response to the secure interaction request. In some embodiments, the secure interaction response is provided from the exchange platform to the member providing the secure interaction request. The secure interaction response may indicate a verification event. In some examples, the secure interaction response may include a UUEK and / or service provider tool for the user.

[0313] In some examples, the security code input may correspond to a previously established UUEK for the user. For example, as described herein, one or more registration processes may be pre-performed between one or more service provider platforms and an exchange platform to register multiple service provider tools with the exchange platform. Thereafter, the exchange platform may generate and issue a UUEK to the registered service provider platform to initiate value-based exchanges using the registered service provider tool without reference to the service provider tool's permanent credentials. Additionally or alternatively, a registration process may be performed to register the registered service provider tool maintained by the service provider platform with the partner platform. In some examples, the exchange platform may facilitate a security code registration process for the issued UUEK to generate a security code tuple. Upon generating the security code tuple for the UUEK, the exchange platform may perform one or more steps / operations of process 800 on behalf of the member platform to enable and / or disable the UUEK. In this manner, a security code for network management may be provided that proactively prevents the use of UUEKs for invalid exchanges.

[0314] In some embodiments, the interaction request may include an activation request for activating a previously issued UUEK for the user. In this case, the secure interaction request may indicate the UUEK and a security code input for the UUEK and / or one or more contextual security attributes, such as a configuration time (e.g., indicating the time when the secure interaction request was sent, etc.), a request time (e.g., a request time for permission to use the UUEK, etc.), and / or the like.

[0315] In some examples, in response to a selection input indicating a disabled UUEK, a secure interaction request can be generated and / or provided. For example, a user can select a UUEK (e.g., via a partner application associated with a partner platform, a service provider application associated with a service provider platform, etc.) to authorize a value-based exchange. In some examples, if the selected UUEK is a disabled UUEK, a secure interaction request can be automatically initiated. For example, in response to the selection, the member platform (e.g., via a corresponding member application) can prompt the user to enter a security code. The user can enter the security code input to provide the secure interaction request.

[0316] In some embodiments, the UUEK representation is a visual representation of the UUEK. The UUEK representation may include a digital representation of the UUEK that is visible to the user. For example, the UUEK representation may be represented in one or more different forms, such as a machine-readable optical image (e.g., a barcode, a quick response code, etc.), a keyword, a virtual widget, and / or the like. In some examples, the UUEK representation may include a scannable representation of the UUEK (e.g., a barcode, a QR code, a non-fungible token, a near-field communication sequence, etc.). The scannable representation may be saved to a member account of the member platform to enable the user to perform value-based exchanges using the service provider tool without having to refer to the permanent credentials of the service provider tool. For example, the UUEK representation may be scanned by a barcode scanner and / or the like to read the UUEK and initiate a value-based exchange with the UUEK.

[0317] In some embodiments, the disabled UUEK representation is a UUEK representation for a disabled UUEK. The disabled UUEK representation may include a status indicator indicating the disabled state of the UUEK and / or one or more other indicators. In some examples, the disabled UUEK representation may include an unreadable UUEK representation. For example, the unreadable UUEK representation may include a grayed-out, obscured, partially covered, and / or similar scannable representation that prevents the scannable representation from being read.

[0318] In some examples, the secure interaction response may initiate activation of the UUEK. For example, the activated UUEK may be associated with an activated UUEK representation. The activated UUEK representation may include a status indicator indicating the activation status of the UUEK and / or one or more other indicators. In some examples, the activated UUEK representation may include a readable UUEK representation.

[0319] Go to Figure 8B In response to the security event, process 800 includes receiving an exchange request with a UUEK (e.g., issued through a secure interaction, etc.) at step / operation 816. For example, an exchange platform may receive an exchange request for performing a value-based exchange. The exchange request may indicate the UUEK and / or one or more exchange attributes. In some examples, the exchange request may be contingent on a previous secure interaction. For example, the UUEK may be issued through a secure interaction and / or enabled through a secure interaction. In this manner, the request may be filtered by the exchange platform before being transmitted to the exchange platform, and the request may be filtered again by the exchange platform before being transmitted to another member platform. In this manner, exchange requests may be minimized to pre-verified exchanges, which may reduce network congestion between multiple parties in a high-traffic exchange network.

[0320] The exchange attributes may indicate one or more characteristics of the requested exchange. For example, the one or more exchange attributes may include at least one exchange attribute indicating an exchange value, such as a monetary value, a reward value, and / or the like.

[0321] In some embodiments, process 800 includes identifying an exchange data object indicating an exchange identifier at step / operation 818. For example, an exchange platform (e.g., its partner service, service provider service, etc.) can use some of the techniques described herein to identify an exchange identifier for a UUEK. As described herein, the exchange identifier can be associated with an exchange data object corresponding to the UUEK. The exchange data object (and / or one or more identifiers thereof) can be associated with a security code element group and / or one or more verification events for the UUEK.

[0322] In some embodiments, process 800 includes determining at step / operation 820 whether the exchange request requires verification. For example, the exchange platform (e.g., its verification service, etc.) can determine whether the exchange request requires verification. The exchange platform can determine whether verification is required based at least in part on a member policy and / or one or more exchange attributes for the exchange request. Exemplarily, the member platform can be associated with a member policy that defines one or more verification requirements for a service provider tool. In some examples, the exchange request can indicate one or more exchange attributes. The one or more verification requirements can correspond to the one or more exchange attributes. The exchange platform (e.g., its verification service, etc.) can compare the one or more exchange attributes with the one or more verification requirements to determine whether the UUEK of the exchange request requires verification.

[0323] As an example, one or more exchange attributes may indicate an exchange value, and one or more verification requirements may define an exchange value threshold at which a corresponding security event is required for the service provider tool. When the exchange value of the exchange request satisfies the exchange value threshold, the exchange request in the aforementioned case may be verified.

[0324] As another example, the one or more verification requirements may define one or more objects (e.g., object identifiers, object attributes, etc.) for which the service provider tool requires a corresponding security event. When the exchange request includes one or more exchange attributes that identify at least one of the one or more objects, then verification of the exchange request in the above case may be required.

[0325] In some embodiments, process 800 includes determining whether the UUEK is enabled at step / operation 822. For example, the exchange platform (e.g., its partner service, service provider service, etc.) may determine whether the UUEK is enabled (or disabled) based at least in part on member policies, exchange requests, and / or one or more verification events associated with the UUEK (e.g., secure events, unsecure events, etc.). For example, the exchange platform may determine whether the UUEK is enabled based at least in part on the presence of secure events, unsecure events, and / or one or more timing attributes thereof.

[0326] In some embodiments, the exchange platform determines that the UUEK is enabled based at least in part on the latest time attribute for multiple verification events. For example, if the security event is later than any unsafe event, the UUEK can be enabled. Additionally or alternatively, the exchange platform determines that the UUEK is enabled based at least in part on a comparison between a safe time period and a time for the exchange request (e.g., a receipt time, a response time, a processing time, etc.). For example, if a time, such as a receipt time of the exchange request, is within the enablement time period, the UUEK can be enabled.

[0327] In some embodiments, process 800 includes providing an exchange authorization request at step / operation 824. For example, an exchange platform (e.g., its service provider service, etc.) may provide the exchange authorization request to a member platform. In some examples, the exchange authorization request may be provided to the service provider platform using a service provider interface. The exchange authorization request may indicate a tool identifier and / or a security event. In some examples, the exchange authorization request may indicate an enabled time period for the security event and / or a time when the exchange request was received.

[0328] For example, an exchange platform (e.g., its service provider's service) can request exchange permission from a service provider platform of a service provider tool associated with a UUEK. In some examples, an exchange platform (e.g., its partner service) can identify a member platform based at least in part on the UUEK (e.g., its entity partition). Additionally or alternatively, an exchange platform (e.g., its service provider service) can identify a service provider tool based at least in part on the UUEK (e.g., its exchange identifier).

[0329] The exchange platform (e.g., its service provider service) may provide an exchange authorization request to the member platform using the service provider interface. The exchange authorization request may indicate at least one of one or more request attributes, a tool identifier for a service provider tool, and / or a security event. Exemplarily, the exchange platform may generate the exchange authorization request based at least in part on a system tool data object identified from one or more aspects of the UUEK. The exchange authorization request may include a tool key and / or a tool reference from the system tool data object.

[0330] In some examples, the exchange authorization request may indicate a user identifier associated with the service provider tool. For example, the exchange platform may generate the exchange authorization request based at least in part on a system user data object identified from one or more aspects of the UUEK. In some examples, the system user data object may be identified based at least in part on a user identifier of the exchange data object (e.g., a system user identifier). Additionally or alternatively, the system user data object may be identified based at least in part on a user identifier of a system tool data object (e.g., a system user identifier). In some examples, the exchange authorization request may include a user key and / or a user reference from the system user data object.

[0331] Additionally or alternatively, the exchange authorization request may indicate an exchange identifier. Exemplarily, the exchange platform may generate an exchange identifier for representing a value-based exchange and provide the exchange identifier to the member platform.

[0332] In some embodiments, process 800 includes receiving an exchange authorization response at step / operation 826. For example, the exchange platform (e.g., its partner service, service provider service, etc.) may receive the exchange authorization response indicating at least one of an exchange approval and / or an exchange rejection. In some examples, the exchange authorization response may be received from the service provider platform using a service provider interface.

[0333] In some embodiments, the exchange authorization response is based at least in part on the security event.For example, the exchange authorization response can be based at least in part on the security event, the time of receipt of the exchange request, member policies, and / or the like.

[0334] In some embodiments, an exchange platform (e.g., a service of a service provider) may use a service provider interface to receive an exchange authorization response indicating at least one of a transaction approval and / or a transaction rejection. In some embodiments, the exchange authorization response is based at least in part on a comparison between the transaction value and the asset availability of the service provider tool. For example, in response to receiving an exchange authorization request, the member platform may be configured to compare the transaction value with the asset availability of the identified service provider tool. If the asset availability exceeds the transaction value, the value-based exchange may be authorized (e.g., resulting in transaction approval, etc.); otherwise, the exchange may be rejected (e.g., resulting in transaction rejection).

[0335] In some examples, the exchange authorization response may indicate one or more response attributes. The response attributes may include one or more error codes and / or the like that characterize the exchange authorization response.

[0336] The exchange platform may generate an exchange record for the value-based exchange based at least in part on the exchange authorization request and / or the exchange authorization response. In some examples, the exchange record may indicate an exchange identifier, one or more exchange attributes, one or more response attributes, the exchange authorization response, one or more instrument and / or user identifiers, and / or any other data related to the value-based exchange. In some examples, the exchange platform may store the exchange record in association with the one or more instrument and / or user identifiers in a platform database.

[0337] In some embodiments, process 800 includes providing an exchange response at step / operation 828. For example, the exchange platform (e.g., its partner service, service provider service, etc.) can provide the exchange response based at least in part on the exchange authorization response. In some examples, the exchange platform can provide the exchange response to the partner platform using a partner interface. The exchange response can indicate an exchange approval or an exchange rejection.

[0338] The exchange response may be based at least in part on the exchange authorization response. For example, the exchange response may indicate a transaction approval and / or a transaction rejection. In some examples, the exchange response may indicate a replacement UUEK (if generated), one or more exchange attributes, an exchange identifier, and / or one or more response attributes. In some examples, the member platform may be configured to replace the UUEK with the replacement UUEK. For example, the exchange response may be provided to the partner platform. The partner platform may receive the exchange response and replace the UUEK with the replacement UUEK.

[0339] Having thus described various operations, processes, methods, functions, and / or the like for processing exchanges on behalf of a user, various user interface screens for controlling, initiating, executing, and / or resembling these steps / operations are provided and described. In various embodiments, the user interface screens provided and described herein are configured to be provided via a user interface of a client device 104.

[0340] Figure 9A -D provides an example user interface flow configured for a client device 104. The user interface can be configured to guide a user through a credential-free exchange process to facilitate a value-based exchange between one or more member platforms without exposing sensitive, permanent credentials to a service provider tool used to perform the value-based exchange. Figure 9A As shown, the no-credentials exchange process may begin when the user selects a payment method from the exchange processing screen 902 of the partner application. Figure 9BAs shown, after selecting a payment method provided by the exchange platform, the user can switch to a tool selection screen 904. The tool selection screen 904 may include a plurality of selectable tool icons 906, each of which may be associated with a UUEK issued by the exchange platform using the various techniques described herein. The user may execute the exchange by selecting one or more selectable tool icons 906.

[0341] In some examples, in response to this selection, a scan screen 908 may be provided for an in-store exchange. The scan screen 908 may present an enabled and / or disabled UUEK representation 910 corresponding to the UUEK. The user may scan the UUEK representation 910 to complete the value-based exchange. If the UUEK is a disabled UUEK, the user may be transitioned to a verify user screen 912 to provide a security code associated with the UUEK. The user may enter the security code to enable the UUEK and complete the exchange.

[0342] VI. Conclusion

[0343] Many modifications and other embodiments will occur to those skilled in the art having the benefit of the teachings presented in the foregoing description and the associated drawings. Therefore, it should be understood that the present disclosure is not limited to the specific embodiments disclosed, and that modifications and other embodiments are intended to be included within the scope of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

1. A computer-implemented method for managing network-enabled security codes, comprising: receiving, by one or more processors in the exchange platform, from a member platform, a security interaction request indicating a security code input and a user identifier; identifying, by the one or more processors, a set of security code elements for the security code input based on the user identifier, wherein the set of security code elements defines a security code reference for comparison with the security code input; verifying, by the one or more processors, the security code input based at least in part on a comparison between the security code input and a security code reference of the set of security code elements; In response to the security code input being verified successfully, (i) storing, by the one or more processors, security events for the user, and (ii) providing, by the one or more processors, a security interaction response indicative of the security event, wherein the security interaction response indicates at least one of (a) a universally unique temporary key (UUEK) or (b) a security event for enabling the UUEK, wherein the security event is stored in association with the UUEK; receiving, by the one or more processors, an exchange request for performing a value-based exchange using the UUEK; providing, by the one or more processors, an exchange authorization request to a member platform, wherein the exchange authorization request indicates a tool identifier and the security event; and receiving, by the one or more processors, an exchange authorization response indicating at least one of an exchange approval or an exchange denial, wherein the exchange authorization response is provided based at least in part on the security event, wherein (i) the member platform is a service provider platform, (ii) the exchange request is received from a partner platform different from the service provider platform using a partner interface, (iii) the exchange authorization request is provided to the service provider platform using a service provider interface, and (iv) the exchange authorization response is received from the service provider platform using a service provider interface. 2 . The computer-implemented method of claim 1 , wherein the secure interaction request is received using a partner interface corresponding to a partner platform in response to a selection input of a disabled UUEK representation corresponding to the UUEK.

3. The computer-implemented method of claim 2, wherein (i) presenting, via a user interface, a representation of the disabled UUEK, and (ii) In response to the security interaction response, modifying the exchange interface to present the enabled UUEK representation.

4. The computer-implemented method of claim 1 , further comprising: An exchange response is provided using the partner interface based at least in part on the exchange authorization response, wherein the exchange response indicates an exchange approval or an exchange denial. The computer-implemented method of claim 1 , wherein the security code reference comprises an n-character sequence of one or more different characters. The computer-implemented method of claim 5 , wherein the one or more different characters comprise one or more alphanumeric characters.

7. The computer-implemented method of claim 1, wherein the security code tuple comprises the security code reference and a user identifier and is previously generated in response to a security code request from the member platform.

8. The computer-implemented method of claim 1, wherein the security event is associated with a security time period, and the exchange authorization response is provided based at least in part on a time of receipt of the security event and the exchange request.

9. The computer-implemented method of claim 1 , wherein the member platform is associated with a member policy, the member policy defining one or more authentication requirements for a service provider tool, and wherein the computer-implemented method comprises: The UUEK is determined to be enabled based at least in part on the member policy, the exchange request, and the security event.

10. The computer-implemented method of claim 9, wherein the exchange request indicates one or more exchange attributes, and the one or more authentication requirements correspond to the one or more exchange attributes.

11. The computer-implemented method of claim 10, wherein the one or more exchange attributes indicate an exchange value, and the one or more verification requirements define an exchange value threshold at which a corresponding security event is required for a service provider tool.

12. A computing system for managing network-enabled security code, comprising a memory and one or more processors communicatively coupled to the memory in a switching platform, the one or more processors configured to: receiving a security interaction request indicating a security code input and a user identifier from a member platform; identifying a security code element set for the security code input based on the user identifier, wherein the security code element set defines a security code reference for comparison with the security code input; verifying the security code input based at least in part on a comparison between the security code input and a security code reference of the set of security code elements; In response to the security code input being verified successfully, (i) store security events for users, and (ii) providing a security interaction response indicative of the security event, wherein the security interaction response indicates at least one of (a) a universally unique temporary key UUEK or (b) a security event for enabling the UUEK, wherein the security event is stored in association with the UUEK; receiving an exchange request for performing a value-based exchange using the UUEK; providing an exchange authorization request to the member platform, wherein the exchange authorization request indicates the tool identifier and the security event; and receiving an exchange authorization response indicating at least one of an exchange approval or an exchange denial, wherein the exchange authorization response is provided based at least in part on the security event, wherein (i) the member platform is a service provider platform, (ii) the exchange request is received from a partner platform different from the service provider platform using a partner interface, (iii) the exchange authorization request is provided to the service provider platform using a service provider interface, and (iv) the exchange authorization response is received from the service provider platform using a service provider interface. 13 . The computing system of claim 12 , wherein the secure interaction request is received using a partner interface corresponding to a partner platform in response to a selection input of a disabled UUEK representation corresponding to the UUEK.

14. The computing system of claim 12, wherein (i) presenting, via a user interface, a representation of the disabled UUEK, and (ii) In response to the security interaction response, modifying the exchange interface to present the enabled UUEK representation.

15. The computing system of claim 12, wherein the one or more processors are further configured to: An exchange response is provided using the partner interface based at least in part on the exchange authorization response, wherein the exchange response indicates an exchange approval or an exchange denial.

16. The computing system of claim 12, wherein the security event is associated with a security time period, and the exchange authorization response is provided based at least in part on a time of receipt of the security event and the exchange request.

17. One or more non-transitory computer-readable storage media for managing network-enabled security code, comprising instructions that, when executed by one or more processors in a switching platform, cause the one or more processors to: receiving a security interaction request indicating a security code input and a user identifier from a member platform; identifying a security code element set for the security code input based on the user identifier, wherein the security code element set defines a security code reference for comparison with the security code input; verifying the security code input based at least in part on a comparison between the security code input and a security code reference of the set of security code elements; In response to the security code input being verified successfully, (i) store security events for users, and (ii) providing a security interaction response indicative of the security event, wherein the security interaction response indicates at least one of (a) a universally unique temporary key UUEK or (b) a security event for enabling the UUEK, wherein the security event is stored in association with the UUEK; receiving an exchange request for performing a value-based exchange using the UUEK; providing an exchange authorization request to the member platform, wherein the exchange authorization request indicates the tool identifier and the security event; and receiving an exchange authorization response indicating at least one of an exchange approval or an exchange denial, wherein the exchange authorization response is provided based at least in part on the security event, wherein (i) the member platform is a service provider platform, (ii) the exchange request is received from a partner platform different from the service provider platform using a partner interface, (iii) the exchange authorization request is provided to the service provider platform using a service provider interface, and (iv) the exchange authorization response is received from the service provider platform using a service provider interface.

18. The one or more non-transitory computer-readable storage media of claim 17, wherein the security code reference comprises an n-character sequence of one or more different characters, and the one or more different characters comprise one or more alphanumeric characters.

Citation Information

Patent Citations

  • Single interaction authenticated key agreement protocol of identity-based cryptosystem

    CN106209369A

  • Trusted ephemeral identifier to create a group for a serivce and / or to provide the service

    US20160182497A1