Systems, methods, and computing platforms for performing credential-less network-based communication exchanges

The use of Universally Unique Ephemeral Keys in a secure intermediate computing platform addresses the vulnerabilities of persistent credentials in network transactions, enhancing security and efficiency in value exchanges.

JP7813915B2Active Publication Date: 2026-02-131080 NETWORK INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024568522
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-06-05
Filing Date
2023-08-03
Publication Date
2026-02-13
Estimated Expiration
2043-08-03

AI Technical Summary

Technical Problem

Existing network-based transaction processing technologies rely on persistent credentials, exposing users to fraud, regulatory risks, and reputational damage, and introduce security overhead without effectively addressing data security.

Method used

A secure intermediate computing platform uses Universally Unique Ephemeral Keys (UUEKs) to facilitate credential-free value exchanges, eliminating the need for persistent credentials and enabling flexible, secure network transactions.

Benefits of technology

This approach enhances network security, reduces computing resource requirements, and increases throughput by allowing seamless, secure value-based exchanges without exposing sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007813915000001
    Figure 0007813915000001
  • Figure 0007813915000002
    Figure 0007813915000002
  • Figure 0007813915000003
    Figure 0007813915000003
Patent Text Reader

Abstract

Various embodiments of the present disclosure provide techniques for facilitating credential-less exchange over a network using multiple identifier mappings and member interfaces. The techniques can include receiving an exchange request to perform a value-based exchange. The exchange request indicates a UUEK and one or more transaction attributes. The techniques can include identifying an exchange identifier based at least in part on the UUEK, where the exchange identifier corresponds to an exchange data object comprising an instrument identifier of a service provider instrument of the member platform. The techniques can include providing the exchange authorization request to the member platform, receiving an exchange authorization response indicating at least one of a transaction approval or a transaction denial, and providing an exchange response based at least in part on the exchange authorization response.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims the benefit of U.S. Provisional Patent Application No. 63 / 370,280, filed August 3, 2022, U.S. Provisional Patent Application No. 63 / 370,279, filed August 3, 2022, and U.S. Provisional Patent Application No. 18 / 329,107, filed June 5, 2023, each of which is incorporated by reference herein in its entirety, including any figures, tables, drawings, and addenda.

[0002] Embodiments of the present disclosure generally relate to credential-free exchange of value between multiple entities in a value system. [Background technology]

[0003] Various embodiments of the present disclosure address technical challenges related to network-based value transactions, taking into account the limitations of existing transaction processing technologies and architectures. Existing processes for conducting transactions over computing networks rely on the use of persistent credentials, such as payment credentials (e.g., card numbers, usernames, passwords, bank routing numbers, account numbers, etc.) and their powers of attorney, which expose the recipient of the credentials to fraud, regulatory and compliance costs, and reputational risk. Moreover, the static nature of traditional credentials requires users to accept the risk of financial loss, damaged credit scores, identity theft, and other consequences every time they provide their credentials to enable a transaction. The inherent dangers of persistent credentials are traditionally addressed using rigid communication protocols, data governance procedures, and authentication schemes, each of which introduces additional technical challenges by adding overhead and complicating network-based transactions without solving the underlying technical problem of data security.

[0004] For example, traditional service providers that manage user accounts can limit their disclosure using disclaimers that prevent users from providing their credentials to specific third parties. This leads to network congestion as a limited number of authorized parties are overwhelmed with requests for the entire population. Furthermore, authorized parties are required to enroll users by obtaining sensitive persistent credentials (e.g., usernames, passwords, routing / transit credentials, etc.) from them and then manage a robust number of persistent credentials across the entire population of registered users. This presents malicious parties with a single attack vector for obtaining sensitive user information about a user population. To counter such attacks, traditional transaction processing entities are required to employ expensive, resource-intensive, and robust data governance procedures and authentication schemes that are incomplete and still susceptible to penetration.

[0005] Other techniques for addressing data security include restricting exchange communications, such as those for financial transactions, to rigid messaging standards, such as ISO messaging standards, which are inflexible and, by design, do not provide contextual data about the transaction. Thus, such communication standards improve network security at the expense of transaction functionality.

[0006] Various embodiments of the present disclosure make important contributions to various existing network-based value transaction processing technologies by addressing each of these technical challenges. Summary of the Invention [Means for solving the problem]

[0007] Various embodiments of the present disclosure disclose a secure intermediate computing platform and computing services that facilitate credential-free execution of value-based exchanges that leverage Universally Unique Ephemeral Keys (UUEKs) to eliminate the use of persistent credentials. To do so, the intermediate computing platform can facilitate interactions between one or more member platforms to register user instruments in a value exchange system enhanced by a new ephemeral data structure, referred to herein as a UUEK. Unlike traditional registration systems, the intermediate computing platform does not receive or rely on persistent user or instrument credentials to register user instruments. This elimination of credentials enables the use of new, more flexible interfaces, such as the application programming interfaces (APIs) described herein, leveraged by the intermediate computing platform to communicate with different network members to register user instruments without disclosing user credentials at any step in the process. Once registered, the intermediate computing platform can issue a UUEK to the member platform that can replace a traditional persistent credential. The issued UUEK does not reflect the persistent credential or any other confidential user or instrument information.The interface between the member platform and the intermediary platform can (i) allow a user to present an issued UUEK from a member platform to the intermediary platform (without explicit reference to a persistent credential) and (ii) allow the intermediary platform to map the issued UUEK to an instrument key for the same or another member platform and provide the instrument key to the member platform to authorize the value-based exchange. In this way, network-based transactions can be authorized in a seamless process without exposing sensitive user or instrument information that could be susceptible to network attacks. Finally, this allows for greater flexibility (e.g., through the use of new interfaces) and security (e.g., through the elimination of persistent credentials) while reducing computing power requirements relative to prior art and enabling significantly greater network throughput for processing exchanges.

[0008] In some embodiments, a method includes initiating, by one or more processors and using a partner interface, presentation of a registration user interface via a user's client device, the registration user interface comprising an instrument registration screen indicating one or more service provider instruments associated with the user; receiving, by the one or more processors and using the partner interface, selection data indicating a selection of a service provider instrument from the registration user interface; generating, by the one or more processors, a matching code for authenticating the user; and identifying, by the one or more processors and using the service provider interface, a service provider instrument corresponding to the service provider instrument. providing a registration request to a partner platform, the registration request comprising service provider registration data indicating a matching code, a user identifier of the user, and an instrument identifier of the service provider instrument; receiving, by one or more processors and using a partner interface, an authentication message comprising the matching code; and in response to authenticating the user based at least in part on the matching code, (i) generating, by the one or more processors, a UUEK for the user, the UUEK corresponding to the user, the service provider instrument, and the partner platform; and (ii) providing, by the one or more processors and using the partner interface, the UUEK to the partner platform.

[0009] In some embodiments, a computing system includes a memory and one or more processors communicatively coupled to the memory, the one or more processors initiating, using a partner interface, the presentation of a registration user interface via a client device of a user, the registration user interface comprising an instrument registration screen indicating one or more service provider instruments associated with the user; receiving, using the partner interface, selection data indicating a selection of a service provider instrument from the registration user interface; generating a matching code to authenticate the user; and registering, using the service provider interface, the service provider instrument. the service provider instrument and the partner platform, and (ii) provide the UUEK to the partner platform using the partner interface.

[0010] When executed by the one or more processors, the method includes: initiating, using a partner interface, the presentation of a registration user interface via a user's client device, the registration user interface comprising an instrument registration screen indicating one or more service provider instruments associated with the user; receiving, using the partner interface, selection data indicating a selection of a service provider instrument from the registration user interface; generating a matching code to authenticate the user; and providing, using the service provider interface, a registration request to a service provider platform corresponding to the service provider instrument. one or more non-transitory computer-readable storage media comprising instructions that cause one or more processors to provide a registration request comprising service provider registration data indicating a matching code, a user identifier of the user, and an instrument identifier of the service provider instrument; receive, using a partner interface, an authentication message comprising the matching code; and in response to authenticating the user based at least in part on the matching code, (i) generate a UUEK for the user, the UUEK corresponding to the user, the service provider instrument, and the partner platform; and (ii) provide, using the partner interface, the UUEK to the partner platform.

[0011] Having thus generally described the present disclosure, reference is now made to the accompanying drawings, which are not necessarily drawn to scale. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is an exemplary diagram of a computing ecosystem in accordance with one or more embodiments of the present disclosure. [Figure 2]FIG. 1 is an exemplary schematic diagram of a computing platform in accordance with one or more embodiments of the present disclosure. [Figure 3] FIG. 1 is an illustrative schematic diagram of a client device in accordance with one or more embodiments of the present disclosure. [Figure 4] FIG. 1 is an example block diagram of an example credential-free exchange system for value, according to one or more embodiments of the present disclosure. [Figure 5] FIG. 1 is an exemplary data diagram for facilitating credential-less exchange of value, in accordance with one or more embodiments of the present disclosure. [Figure 6A] 1 is a process flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 6B] 1 is a process flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 6C] 1 is a process flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 7A] 1 is a messaging flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 7B] 1 is a messaging flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 7C] 1 is a messaging flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 7D] 1 is a messaging flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 8A] FIG. 10 is a diagram of an example interface for establishing cross-entity relationships, in accordance with one or more embodiments of the present disclosure. [Figure 8B] FIG. 10 is a diagram of an example interface for establishing cross-entity relationships, in accordance with one or more embodiments of the present disclosure. [Figure 8C] FIG. 10 is a diagram of an example interface for establishing cross-entity relationships, in accordance with one or more embodiments of the present disclosure. [Figure 8D] FIG. 10 is a diagram of an example interface for establishing cross-entity relationships, in accordance with one or more embodiments of the present disclosure. [Figure 8E] FIG. 10 is a diagram of an example interface for establishing cross-entity relationships, in accordance with one or more embodiments of the present disclosure. [Figure 8F] FIG. 10 is a diagram of an example interface for establishing cross-entity relationships, in accordance with one or more embodiments of the present disclosure. [Figure 9] 1 is a process flow for facilitating credential-less exchange of value, according to one or more embodiments of the present disclosure. [Figure 10] 1 is a first messaging flow for facilitating a credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 11] 1 is a second messaging flow for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 12A] FIG. 10 is a diagram of an example interface for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 12B] FIG. 10 is a diagram of an example interface for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 12C] FIG. 10 is a diagram of an example interface for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0013] Various embodiments of the present disclosure are described in more detail below with reference to the accompanying drawings, in which some, but not all, embodiments of the present disclosure are illustrated. Indeed, the present disclosure may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that the present disclosure will satisfy applicable legal requirements. The term "or" is used herein in both its alternative and conjunctive sense, unless otherwise indicated. The terms "exemplary" and "example" are used as examples without an indication of level of quality. Terms such as "computing," "determining," "generating," and / or similar words are used interchangeably herein to refer to the creation, modification, or identification of data. Furthermore, terms such as "based at least in part on," "based at least on," "based on," and / or similar words are used interchangeably herein in a broad manner, unless so indicated, so as not to necessarily indicate based at least in part on or solely on the referenced element or elements. Like numbers refer to like elements throughout.

[0014] I. Summary and Technical Advantages Various embodiments of the present disclosure provide technical solutions for managing network-based exchanges. In various embodiments, an exchange platform may be configured to facilitate credential-less exchanges of value between one or more member platforms. These exchanges may be facilitated in real time without persistent credentials that may expose members to financial, legal, reputational, or other risks. Thus, in various embodiments, client devices may buy, sell, and / or conduct value-based exchanges in real time over any network without exposing sensitive information that is susceptible to network-based attacks.

[0015] Embodiments of the present disclosure provide improved instrument registration and exchange processing techniques that leverage interfaces and data transformation and encryption technologies to improve data security while reducing computing resource expenditure requirements for protecting sensitive data over network communications. Some techniques of the present disclosure, for example, take a data object and convert it into a unique data key recognizable only to authorized entities. The data key may be provided and / or established by leveraging an exchange interface between the exchange platform and other member platforms. Once established, the data key may be mapped to sensitive credentials stored within the source platform (e.g., a service provider platform) without requiring network transmission of the sensitive credentials. Future communications to facilitate value-based exchanges may replace traditional persistent credentials with data keys to enable the source platform to identify the persistent credentials and / or perform one or more actions for a specific instrument associated with the persistent credentials. In this manner, the exchange platform may facilitate exchanges using keys (and / or other identifiers) that cannot themselves be traced back to the underlying sensitive information. This further enables the exchange platform to track, facilitate, and distribute network-based communications in their entirety without exposing members to network attacks. As such, the registration techniques of the present disclosure provide improved data and network security techniques that can be practically applied by network-based exchanges to securely register instruments with the exchange platform.

[0016] Further to the above, embodiments of the present disclosure present network-based exchange processing techniques for facilitating credential-free exchanges. To do so, some of the disclosed techniques utilize a new data structure, the UUEK, that can replace persistent credentials traditionally used to authorize value-based exchanges. Using the disclosed techniques, UUEKs can be securely issued across member platforms to allow users to conduct value-based exchanges using identifiers recognizable by a single party, the exchange platform. The UUEK can be mapped to a unique identifier that can reference sensitive information without directly identifying the sensitive information. The unique identifier can, for example, reference a mapping that can only be interpreted by the source platform, and thus the identifier is unusable to malicious parties not affiliated with the exchange platform. In this way, the exchange platform can distribute, track, and facilitate exchanges without exposing the member platform to data security risks. Moreover, the exchange platform can continuously update, modify, and / or redistribute the UUEK to member platforms to continuously adapt the UUEK in real time. In this way, exchange platforms can offer technological improvements to data and network security while reducing computing resource requirements (e.g., to securely encrypt persistent credentials) to facilitate value-based exchange.

[0017] Exemplary inventive and technically advantageous embodiments of the present disclosure include (i) data conversion, mapping, and processing schemes to facilitate network-based, credential-less registration of users; (ii) exchange interfaces and network-based communication schemes to improve network security for cross-platform communications; and (iii) ephemeral data structures and data management techniques for distributing ephemeral data structures to facilitate real-time, secure, and dynamic value-based exchange.

[0018] II. Illustrative Definitions In some embodiments, the term "exchange platform" refers to a computing entity configured to facilitate the credential-less exchange of value for one or more members in a network. The exchange platform may include one or more processing devices, memory devices, and / or the like, physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks to facilitate value system-agnostic exchange. In some examples, the exchange platform may include, define, and / or otherwise utilize one or more application programming interfaces (APIs) to facilitate communication (e.g., requests and responses) between multiple members. As described herein, APIs may be utilized to facilitate secure exchange between one or more members in any value system.

[0019] In some embodiments, the term “member” refers to an entity that collaborates with the exchange platform to participate in a value exchange. By way of example, a member may include (i) a partner that utilizes the exchange platform to receive value, (ii) a service provider that utilizes the exchange platform to provide value, and / or (iii) both a partner and a service provider. As used herein, a member may be referred to as a partner when receiving value through a value exchange and / or a service provider when providing value through a value exchange. Thus, depending on the member's role in the value exchange, the same member may be both a partner and a service provider. For example, a member may be a partner that receives value for a value exchange. The same member may be a service provider that provides value in another value exchange. In some examples, the same member may be both a partner and a service provider in the same value exchange, thus utilizing the exchange platform to provide value and then receive value in only one member's value exchange.

[0020] In some embodiments, a member is a partner when it utilizes a service provided by a service provider. A partner may include any value-seeking entity in any value system. By way of example, in a financial value system, a partner may include a merchant (e.g., a retailer, a brick-and-mortar establishment, etc.) that may utilize a service provider, such as a financial institution, to access funds for financial transactions. Additionally or alternatively, in an information value system, a partner may include a news publisher (e.g., a newspaper, a news organization, etc.) that may utilize a service provider, such as a news agency (e.g., a wire service, a news service, etc.), to access information for information transactions. Of course, the techniques of this disclosure may be applied to any value system, and a partner may include any value seeker for any respective value system.

[0021] In some embodiments, a member is a service provider when it provides a service to a partner. A service provider may include a source of value in any value system. By way of example, in a financial value system, a service provider may include a financial institution (e.g., a bank, an exchange platform, a credit union, etc.) that may provide access to funds for financial transactions between one or more entities. Additionally or alternatively, in an information value system, a service provider may include a news agency (e.g., a wire service, a news service, etc.) that may source information for publication by a news publisher. Of course, the techniques of this disclosure may be applied to any value system, and a service provider may include any source of value for any respective value system.

[0022] In some embodiments, the term “member platform” refers to a computing entity corresponding to a member. A member platform entity can include a partner computing platform acting on behalf of a partner, a service provider computing platform acting on behalf of a service provider, and / or both. In some examples, a member platform can be both a partner platform and a service provider platform. For example, the same member platform can be configured to operate on behalf of a partner for one value exchange and on behalf of a service provider for another value exchange. In some examples, the same member platform can be configured to operate on behalf of both a partner and a service provider in a single value exchange. It is noted that the term member platform can refer to a partner platform, a service provider platform, or both, and in some examples may depend on the role of the member platform in the value exchange (e.g., and / or the API(s) utilized by the member platform in the value exchange).

[0023] In some embodiments, a partner platform is a computing entity configured to perform one or more operations on behalf of a partner. A partner platform may include one or more processing devices, memory devices, and / or the like, physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks, for example, to request value in a value-system-agnostic exchange. In some examples, a partner platform may include, define, and / or otherwise utilize one or more APIs to facilitate communication (e.g., requests and responses) with the exchange platform. In some examples, a partner platform may be configured to host one or more user-facing applications (e.g., partner applications) for interacting with one or more users.

[0024] In some embodiments, a service provider platform is a computing entity configured to perform one or more operations on behalf of a service provider. A service provider platform may include one or more processing devices, memory devices, and / or the like, physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks to provide value in a value-system-agnostic exchange, for example. In some examples, a service provider platform may include, define, and / or otherwise utilize one or more APIs to facilitate communication (e.g., requests and responses) with an exchange platform. In some examples, a service provider platform may be configured to facilitate one or more service provider instruments. In some examples, a service provider platform may be configured to host one or more user-facing applications (e.g., service provider applications, etc.) for managing one or more service provider instruments.

[0025] In some embodiments, the term "exchange interface" refers to a set of instructions for facilitating communication between the exchange platform and one or more member platforms and / or internal services. The exchange interface may include an API, a file-based interface, a message queue-based interface, and / or the like. For example, the exchange interface may include an API, including, by way of example, one or more Simple Object Access Protocol (SOAP) APIs, one or more Remote Procedure Call (RPC) APIs, one or more WebSocket APIs, one or more Representational State Transfer (REST) ​​APIs, and / or the like. In some embodiments, the exchange interface may include one or more RPC APIs, such as one or more gRPC APIs.

[0026] An exchange platform may include, define, and / or otherwise utilize one or more different exchange interfaces to facilitate communication with one or more external platforms, such as one or more member platforms (e.g., partner platforms, service provider platforms, etc.). Each API may include multiple communication instructions, message definitions, and / or the like for exchanging requests and / or responses between the exchange platform and the entities participating in the value exchange. By way of example, an exchange interface may include a partner API for facilitating communication with a partner platform and / or a service provider API for facilitating communication with a service provider platform.

[0027] In some embodiments, the term “partner interface” refers to an exchange interface for facilitating one or more communications between a partner platform and an exchange platform. The partner interface may define one or more communication instructions, message definitions, and / or the like for facilitating one or more request and / or response messages between the partner platform and the exchange platform. The partner interface may include, for example, an API that defines (i) requests from a computing entity acting as a partner platform to the exchange platform and / or (ii) requests from the exchange platform to the partner platform. For example, the partner interface may define one or more registration messages, session messages, transaction messages, and / or the like for facilitating a value exchange for a partner. In some embodiments, the partner interface defines one or more identifiers for securely identifying one or more portions of a value exchange.

[0028] In some embodiments, the term “service provider interface” refers to an exchange interface for facilitating one or more communications between a service provider platform and an exchange platform. The service provider interface may define one or more communication instructions, message definitions, and / or the like for facilitating one or more request and / or response messages between the service provider platform and the exchange platform. The service provider interface may include, for example, an API that defines (i) requests from a computing entity functioning as the service provider platform to the exchange platform and / or (ii) requests from the exchange platform to the service provider platform. The service provider interface may define, for example, one or more registration messages, session messages, transaction messages, and / or the like for facilitating a value exchange using the service provider instrument. In some embodiments, the service provider interface defines one or more identifiers for securely identifying one or more portions of a value exchange.

[0029] In some embodiments, the term "entity partition" refers to a unique identifier for a computing entity. An entity partition may include a unique numeric, alphanumeric, and / or similar identifier that represents a particular computing entity. Entity partitions may include, for example, a member partition representing a member platform, a service provider partition representing a service provider platform, a partner partition representing a partner platform, and / or the like.

[0030] In some embodiments, the term "service provider partition" refers to a unique identifier for a service provider and / or the service provider's service provider platform. A service provider partition may include a series of numeric, alphanumeric, and / or any other characters or symbols that represent a service provider associated with (e.g., onboarded, registered, etc.) the exchange platform. An exchange platform, for example, may include multiple service provider partitions, each identifying a service provider platform attached to (e.g., onboarded, registered, etc.) the exchange platform. Each service provider partition may represent a service provider platform that has configured one or more exchange platform software development kits (SDKs) and / or the like to implement the exchange platform's service provider interfaces.

[0031] In some embodiments, a "partner partition" refers to a unique identifier for a partner and / or the partner's partner platform. A partner partition may include a series of numeric, alphanumeric, and / or any other characters or symbols that represent a partner associated with the exchange platform. An exchange platform may, for example, include multiple partner partitions, each identifying a partner platform attached (e.g., onboarded, registered, etc.) to the exchange platform. Each partner partition may represent a partner platform that has configured one or more exchange SDKs and / or the like to implement the exchange platform's partner interfaces.

[0032] In some embodiments, the term "user-facing application" refers to a computer program hosted by a computing entity for facilitating one or more user interactions. A user-facing application may include software (e.g., computer-readable instructions, etc.) designed to perform one or more computing tasks for a computing entity, such as a member platform. For example, a user-facing application may facilitate communication between a member and a user. By way of example, a user-facing application may be configured to present one or more user interfaces for interacting with a user on behalf of a member. In some examples, a user-facing application may be configured to receive user input (e.g., via one or more user interfaces) for receiving information from a user.

[0033] In some embodiments, the user-facing application is a partner application hosted by a partner platform (e.g., a member platform acting as a partner for a particular exchange) to facilitate functionality for the partner. The partner application may include software (e.g., computer-readable instructions, etc.) designed to perform one or more computing tasks for the partner. For example, the partner application may be configured to present one or more user interfaces for interacting (e.g., browsing, purchasing, reviewing, etc.) with one or more products offered by a retail-based partner, one or more units of information offered by an information-based partner, and / or the like. In some examples, the partner application may be configured to receive user input (e.g., via one or more user interfaces) to receive information from a user.

[0034] In some embodiments, the user-facing application is a service provider application hosted by a service provider platform (e.g., a member platform acting as a service provider for a particular exchange) to facilitate functionality for the service provider. The service provider application may include software (e.g., computer-readable instructions, etc.) designed to perform one or more computing tasks for the service provider. For example, the service provider application may be configured to present one or more user interfaces for interacting (e.g., reviewing, managing, inspecting, registering, etc.) with one or more service provider instruments facilitated by the service provider. As an example, in a financial value system, the service provider application may enable access to bank accounts, brokerage accounts, lines of credit, and / or the like for managing funds, assets, and / or the like handled by the respective accounts. In some examples, the service provider application may be configured to receive user input (e.g., via one or more user interfaces) for receiving information, authorizations, and / or the like from the user.

[0035] In some embodiments, the term "service provider instrument" refers to a mechanism utilized by a service provider to provide value on behalf of a particular user. A service provider instrument may depend on the value system and / or the service provider. In some examples, a service provider instrument may include an account at the service provider. For example, in a financial value system, a service provider instrument may include a bank account (e.g., checking, savings, etc.), a brokerage account, a line of credit, and / or the like. In an information value system, a service provider instrument may include a subscriber account and / or the like. In some examples, a service provider instrument may include a virtual instrument hosted by a service provider platform.

[0036] In some embodiments, the term "instrument data object" refers to a data entity that represents a service provider instrument. An instrument data object may include one or more instrument identifiers and / or one or more instrument attributes. In some examples, the one or more instrument identifiers and / or one or more instrument attributes may be based at least in part on the type of the instrument data object. By way of example, a service provider instrument may be represented in a member platform as a member instrument data object. Additionally or alternatively, a service provider instrument may be independently represented by a system instrument data object in an exchange platform. In some examples, a member instrument data object and a system instrument data object may include one or more of the same one or more instrument identifiers and / or one or more instrument attributes. By way of example, a member platform may register multiple service provider instruments with the exchange platform. During registration, the member platform may provide one or more of an instrument identifier and / or instrument attributes, and in some examples, the exchange platform may return another identifier.

[0037] In some embodiments, a member instrument data object is an internal representation of a service provider instrument within a member platform. The member instrument data object may include one or more instrument identifiers, such as a member instrument identifier, an instrument key from the exchange platform, and / or a user identifier. The user identifier may include, for example, a member user identifier. Additionally or alternatively, the member instrument data object may include one or more instrument attributes, such as an instrument type (e.g., credit-based instrument, debit-based instrument, information-based instrument, etc.), an instrument representation, and / or one or more context attributes. In some examples, the context attributes may depend on the value system. For example, in a financial value system, one or more context attributes may indicate (i) the currency associated with the service provider instrument, (ii) asset availability (e.g., balance, coverage, etc.) of the service provider instrument, (iii) one or more previous transactions with the service provider instrument, and / or the like.

[0038] In some embodiments, a system instrument data object is an external representation of a service provider instrument within an exchange platform. A system instrument data object may include one or more instrument identifiers, such as a member platform instrument reference, a system instrument identifier, and / or a user identifier. A user identifier may include, for example, a system user identifier. Additionally or alternatively, a system instrument data object may include one or more instrument attributes, such as an instrument type (e.g., a credit-based instrument, a debit-based instrument, an information-based instrument, etc.), an instrument representation, and / or one or more context attributes. In some examples, the context attributes may depend on the value system. For example, in a monetary value system, one or more context attributes may indicate the currency associated with the service provider instrument.

[0039] In some embodiments, the term "instrument identifier" refers to any representation of a service provider instrument. An instrument identifier may include an instrument identifier, an instrument reference, an instrument key, and / or the like, as described herein.

[0040] In some embodiments, the term "member instrument identifier" refers to a unique identifier for representing a service provider instrument within a member platform. A member instrument identifier may include, for example, a series of numeric, alphanumeric, and / or any other characters or symbols that represent the service provider instrument to the service provider platform.

[0041] In some embodiments, the term "instrument reference" refers to a unique identifier for referencing a member instrument identifier. An instrument reference may be generated and / or provided by a member platform to an exchange platform, for example, to allow the exchange platform to reference an instrument maintained at the member platform. In some examples, an instrument reference is the same value as the member instrument identifier. In some examples, an instrument reference is a different value mapped to the member instrument identifier.

[0042] In some embodiments, the term "system instrument identifier" refers to a unique identifier for representing a service provider instrument within an exchange platform. A system instrument identifier may include, for example, a series of numeric, alphanumeric, and / or any other characters or symbols that represent the service provider instrument to the exchange platform. In some examples, a system instrument identifier may include a UUID.

[0043] In some embodiments, the term "instrument key" refers to a unique identifier for referencing a system instrument identifier. The instrument key may be generated and / or provided by an exchange platform, for example, during the instrument registration process with the exchange platform. In some examples, the instrument key may include a wrapped system instrument identifier. For example, the instrument key may include a string of alphanumeric characters formatted according to a key format established by the exchange platform (and / or its one or more APIs). The key format may include any number of characters, such as 50 characters or more. In some examples, the characters may be case-sensitive. A first portion of the characters (e.g., the first six characters) may be reserved as a partition for identifying an entity associated with the key. In the case of an instrument key, the partition may include a service provider partition. A second portion of the characters may identify a system instrument identifier. The key formats described herein may include one or more different portions, each of which may be arranged in any order.

[0044] In some embodiments, the term "instrument representation" refers to a unique identifier for representing a service provider instrument to a user. An instrument representation may include, for example, a series of numeric, alphanumeric, or any other characters or symbols that outwardly represent a service provider instrument. The format and / or value of an instrument representation may be based at least in part on the type of service provider and / or service provider instrument. For example, in a financial value system, an instrument reference may include a portion (e.g., the last four digits, etc.) of a persistent credential, such as an account number (e.g., debit account, credit account, etc.), a financial account name, and / or the like. As another example, in an information value system, an instrument reference may include a portion (e.g., one or more digits, alphanumeric characters, etc.) of a persistent credential, such as a subscription account and / or the like. For example, an instrument expression may include a derivative of a persistent credential that may allow only entities with prior knowledge of the persistent credential to identify the persistent credential using the instrument expression. As another example, an instrument expression may include a nickname for the instrument that is assigned by a user and subsequently recognized.

[0045] In some embodiments, the term "user data object" refers to a data entity representing a user interacting with a member platform and / or exchange platform. A user may include, for example, an entity (e.g., a person, organization, group, etc.) that engages in a value exchange governed by the exchange platform. In some examples, a user may indirectly collaborate with the exchange platform by creating a registered service provider user account, registering (and / or providing permission to register) a service provider instrument, and / or the like. In some examples, the exchange platform may act on behalf of a user without the user directly interacting with the exchange platform. For example, the exchange platform may act as a hidden intermediary between a user-facing application and the user's service provider instrument.

[0046] In some embodiments, a user data object includes one or more user identifiers and / or one or more user attributes. In some examples, the one or more user identifiers and / or one or more user attributes may be based at least in part on the type of the user data object. For example, a user may be represented in a member platform as a member user data object. Additionally or alternatively, a user may be independently represented in an exchange platform by a system user data object. In some examples, a member user data object and a system user data object may include one or more of the same one or more user identifiers and / or user attributes. For example, a member platform may register multiple users with the exchange platform. During registration, the member platform may provide one or more of the user identifiers and / or user attributes, and in some examples, the exchange platform may return another identifier.

[0047] In some embodiments, a member user data object is an internal representation of a user within the member platform. The member instrument data object may include one or more user identifiers, such as a member user identifier, a user key from the exchange platform, and / or the like. Additionally or alternatively, the member user data object may include one or more user attributes. The one or more user attributes may indicate one or more contextual characteristics of the user. In some examples, the user attributes may indicate one or more identifiable characteristics of the user. By way of example, the user attributes may indicate the user's first name, last name, email, physical address (e.g., one or more of street, locality, region, zip code, country, etc.), date of birth (e.g., date of birth, age range, etc.), phone number, and / or the like. In some examples, the user attributes may include an encrypted, hashed, and / or otherwise secure representation of the user's identifiable characteristics. For example, the user attributes may include one or more hashed identifiers and / or the like of the user.

[0048] In some embodiments, a system user data object is an external representation of a member user within the exchange platform. The system user data object may include one or more user identifiers, such as a member platform user reference, a system user identifier, and / or the like. Additionally or alternatively, the system user data object may include one or more user attributes, such as those described herein. As an example, a member platform may register a user with the exchange platform. During registration, the member platform may provide the user's user reference and / or one or more user attributes. In some examples, the user attributes may include a hashed and / or encrypted identifier of the user.

[0049] In some embodiments, the term "user identifier" refers to a unique identifier of a user involved in a value-based exchange. A user identifier may include a series of numeric, alphanumeric, or any / all other characters or symbols that represent a user of the exchange platform and / or member platform. In some examples, a user identifier may include a user reference, a user key, a system user identifier, a member user identifier, and / or the like.

[0050] In some embodiments, the term "system user identifier" refers to a unique identifier for representing a user within an exchange platform. A system user identifier may include, for example, a series of numeric, alphanumeric, and / or any other characters or symbols that represent the user to the exchange platform. In some examples, a system user identifier may include a UUID unique to a particular user.

[0051] In some embodiments, the term "member user identifier" refers to a unique identifier for representing a user within a member platform. A member user identifier may include, for example, a series of numeric, alphanumeric, or any other characters or symbols that represent the user to the service provider platform.

[0052] In some embodiments, the term "user reference" refers to a unique identifier for referencing a member user identifier. A user reference may be generated and / or provided by a member platform to an exchange platform, for example, to allow the exchange platform to reference a user associated with the member platform. In some examples, a user reference is the same value as a member user identifier. In some examples, a user reference is a different value mapped to a member user identifier.

[0053] In some embodiments, the term "user key" refers to a unique identifier that references a system user identifier. The user key may be generated and / or provided by the exchange platform, for example, during the user's registration process with the exchange platform. In some examples, the user key may include a packaged system user identifier. For example, the user key may include a string of alphanumeric characters formatted according to a key format established by the exchange platform (and / or its one or more APIs). The key format may include, for example, a first portion of characters (e.g., the first six characters) that may be reserved as a partition for identifying an entity (e.g., a member, etc.) associated with the key. For example, in the case of a user key, the partition may include a service provider partition and / or a partner partition. The second portion of characters may identify the system user identifier.

[0054] In some embodiments, the term “exchange data object” refers to a data entity that represents an authorized value exchange between one or more members associated with an exchange platform. In some examples, an exchange data object may include one or more identifiers and / or one or more exchange attributes. For example, the one or more identifiers and / or one or more exchange attributes may be based at least in part on the type of the exchange data object. By way of example, an exchange may be represented in a member platform as a member exchange data object. Additionally or alternatively, an exchange may be independently represented in the exchange platform by a system exchange data object. In some examples, a member exchange data object and a system exchange data object may include one or more of the same one or more identifiers and / or exchange attributes. By way of example, using some of the techniques of this disclosure, an exchange platform may issue one or more unique identifiers to member platforms that may be used to authorize a value exchange.

[0055] In some embodiments, a system exchange data object is an internal representation of a value exchange mediated using an exchange platform. In some examples, a system exchange data object may include one or more different identifiers and / or exchange attributes depending on the system exchange data object's role in the value-based exchange.

[0056] For example, the system exchange data object may include a service provider-specific exchange data object corresponding to a service provider platform. The service provider-specific exchange data object may include one or more identifiers, such as an exchange identifier, a system user identifier, a system instrument identifier, a UUEK, and / or the like. Additionally or alternatively, the service provider-specific exchange data object may include one or more exchange attributes, such as an expiration date, a currency (e.g., for a monetary value system), and / or the like.

[0057] Additionally or alternatively, the system exchange data object may include a partner-specific exchange data object corresponding to the partner platform. The partner-specific exchange data object may include one or more identifiers, such as an exchange identifier, an instrument key, a UUEK, a member instrument reference (e.g., a partner-specific instrument reference), and / or the like. Additionally or alternatively, the partner-specific exchange data object may include one or more exchange attributes, such as an expiration date, a currency (e.g., in the case of a monetary value system), an instrument type, a previous UUEK identifier, and / or the like. In some embodiments, the member exchange data object is an external representation of a value exchange mediated using the exchange platform. The member exchange data object may include one or more identifiers, such as a member exchange identifier, a member instrument identifier, a UUEK from the exchange platform, and / or the like.

[0058] In some embodiments, the term “exchange identifier” refers to a unique identifier of a value exchange using an exchange platform. The exchange identifier may include a series of numeric, alphanumeric, and / or any other characters or symbols that represent at least a user and / or service provider instrument. In some examples, the unique exchange identifier may include a universally unique identifier (UUID) that may be mapped (e.g., through a series of identifiers, etc.) to a user, service provider instrument, and / or member registered with the exchange platform. In some examples, the exchange identifier may be randomly generated using one or more UUID generators. For example, the exchange identifier may include random 16 bytes of information generated according to one or more UUID formatting standards, such as UUID v4 and / or the like. Thus, while the exchange identifier may be utilized by the exchange platform and / or member platform for one or more functions, the same exchange identifier is useless to external parties without a prior association between the exchange identifier and one or more other identifiers. In some examples, the exchange identifier may be represented externally by a UUEK.

[0059] In some embodiments, a "universally unique ephemeral key" or "UUEK" refers to an external representation of an exchange identifier that may be issued (e.g., in place of a service provider exchange identifier and / or a partner exchange identifier) ​​to an external entity, such as a user, partner, and / or service provider, to initiate a transaction using the exchange platform. To do so, a UUEK may be generated and issued by the exchange platform to the external entity. Each UUEK may include multiple values ​​(e.g., up to 50 characters and / or more, which may be case-sensitive) that represent one or more aspects of the transaction. For example, the multiple values ​​may indicate an exchange identifier, a partition (e.g., identifying the recipient of the UUEK, etc.), an identifier type, and / or one or more flags. By way of example, a UUEK may include a partner-specific UUEK and / or a service provider-specific UUEK. The partner-specific UUEK may be correlated to a partner-specific exchange data object as described herein, while the service provider-specific UUEK may be correlated to a service provider-specific exchange data object.

[0060] By way of example, the UUEK may be generated according to a key format. The key format may include a plurality of characters, including, for example, 50 or more characters that may be case-sensitive. A first portion of the characters (e.g., the first six characters) may be reserved as a partition for identifying the recipient of the UUEK. The partition may include, for example, a partner partition, a service provider partition, and / or any other member partition. By way of example, the UUEK may be issued in response to a request from an authorized member, such as an attached partner and / or service provider.

[0061] Additionally or alternatively, at least one character (e.g., the seventh character) of the key format may identify the format of the UUEK. At least another character (e.g., the eighth character) may identify the type of UUEK. In some examples, the second portion of characters may identify an exchange identifier (e.g., a group of 22 characters following the eighth character). The third portion of characters may be reserved (e.g., a group of 20 characters following the first portion of characters). Exemplary representations are provided below: ppppppFiGGGGGGGGGGGGGGGGGGGGrrrrrrrrrrrrrrrrrrrr where p represents the partition character, F represents the format character, i represents the identifier type character, G represents the exchange identifier, and r represents the reserved character. The key format allows for up to 9.8 x 10^84 unique permutations, which is more than the number of atoms in the known observable universe. This allows for the generation and distribution of new UUEKs on demand without compromising the security of the underlying data to which the UUEK may be mapped, such as identifiers of users, instruments, and / or any other potentially sensitive information. The key formats described herein may contain one or more distinct parts, each of which may be arranged in any order.

[0062] In some embodiments, the term "session identifier" refers to a unique identifier for identifying a series of related message exchanges between an exchange platform and an external platform.

[0063] In some embodiments, the term "matching code" refers to a session-specific identifier for authorizing a registration session between one or more entities. A matching code may include a series of numeric, alphanumeric, and / or similar characters that may be provided to multiple entities to ensure, for example, that each of the entities is participating in the same communication sequence. By way of example, a matching code may include an eight-character sequence that may be generated by an exchange platform, provided to a service provider platform, and then received from a partner platform to ensure that the exchange platform, service provider platform, and partner platform are each interacting with the same end user (e.g., by comparing the received matching code with a generated matching code as described herein).

[0064] III. COMPUTER PROGRAM PRODUCTS, METHODS, AND COMPUTING ENTITIES Embodiments of the present disclosure may be implemented in various ways, including as a computer program product comprising an article of manufacture. Such a computer program product may include one or more software components, including, for example, software objects, methods, data structures, or the like. The software components may be coded in any of a variety of programming languages. An exemplary programming language may be a low-level programming language, such as assembly language, associated with a particular hardware architecture and / or operating system platform. Software components comprising assembly language instructions may require conversion by an assembler into executable machine code before execution by the hardware architecture and / or platform. Another exemplary programming language may be a high-level programming language that may be portable across multiple architectures. Software components comprising high-level programming language instructions may require conversion to an intermediate representation by an interpreter or compiler before execution.

[0065] Other examples of programming languages ​​include, but are not limited to, macro languages, shell or command languages, job control languages, scripting languages, database query or search languages, and / or report writing languages. In one or more exemplary embodiments, a software component comprising instructions in one of the foregoing examples of programming languages ​​may be executed directly by an operating system or other software component without first having to be converted into another format. Software components may be stored as files or other data storage structures. Software components of similar types or that are functionally related may be stored together, for example, in a particular directory, folder, or library. Software components may be static (e.g., pre-established or fixed) or dynamic (e.g., created or modified at run time).

[0066] A computer program product may include a non-transitory computer-readable storage medium that stores applications, programs, program modules, scripts, source code, program code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, and / or the like (also referred to herein as executable instructions, instructions for execution, computer program product, program code, and / or similar terms used interchangeably herein). Such non-transitory computer-readable storage media includes all computer-readable media (including volatile and non-volatile media).

[0067] In one embodiment, the non-volatile computer-readable storage medium may include a floppy disk, a flexible disk, a hard disk, a solid-state storage (SSS) (e.g., a solid-state drive (SSD), a solid-state card (SSC), a solid-state module (SSM), an enterprise flash drive, a magnetic tape, or any other non-transitory magnetic medium, and / or the like. The non-volatile computer-readable storage medium may also include punch cards, paper tape, optical mark sheets (or any other physical medium with a pattern of holes or other optically recognizable indicia), a compact disk read-only memory (CD-ROM), a compact disk rewritable (CD-RW), a digital barcode reader (DBL), a digital video recorder (DVLC ... Such non-volatile computer-readable storage media may include DVDs, Blu-ray Discs (BDs), any other non-transitory optical media, and / or the like. Such non-volatile computer-readable storage media may also include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory (e.g., Serial, NAND, NOR, and / or the like), multimedia memory cards (MMC), secure digital (SD) memory cards, smart media cards, compact flash (CF) cards, memory sticks, and / or the like.Additionally, the non-volatile computer readable storage medium may also include conductive bridge random access memory (CBRAM), phase change random access memory (PRAM), ferroelectric random access memory (FeRAM), non-volatile random access memory (NVRAM), magnetoresistive random access memory (MRAM), resistive random access memory (RRAM), silicon-oxide-nitride-oxide-silicon memory (SONOS), floating junction gate random access memory (FJG RAM), millipede memory, racetrack memory, and / or the like.

[0068] In one embodiment, the volatile computer readable storage medium is a random access memory (RAM), dynamic random access memory (DRAM), static random access memory (SRAM), fast page mode dynamic random access memory (FPM DRAM), extended data out dynamic random access memory (EDO DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), double data rate type 2 synchronous dynamic random access memory (DDR2 SDRAM), double data rate type 3 synchronous dynamic random access memory (DDR3 SDRAM), or the like. The memory may include memory types such as SDRAM, Rambus Dynamic Random Access Memory (RDRAM), Twin Transistor RAM (TTRAM), Thyristor RAM (T-RAM), Zero-Capacitor RAM (Z-RAM), Rambus Inline Memory Modules (RIMM), Dual Inline Memory Modules (DIMM), Single Inline Memory Modules (SIMM), Video Random Access Memory (VRAM), cache memory (including various levels), flash memory, register memory, and / or the like. Where embodiments are described that utilize a computer-readable storage medium, it will be understood that other types of computer-readable storage media may be used in place of or in addition to the computer-readable storage media described above.

[0069] As will be recognized, various embodiments of the present disclosure may also be embodied as methods, apparatus, systems, computing devices, computing entities, and / or the like. Accordingly, embodiments of the present disclosure may take the form of a data structure, an apparatus, a system, a computing device, a computing entity, and / or the like that executes instructions stored on a computer-readable storage medium to perform certain steps or operations. Accordingly, embodiments of the present disclosure may also take the form of an entirely hardware embodiment, an entirely computer program product embodiment, and / or an embodiment comprising a combination of a computer program product and hardware that performs certain steps or operations.

[0070] Embodiments of the present disclosure are described below with reference to block diagrams, flowchart diagrams, messaging flows, and other representations of data, operations, and messaging schemes. It should be understood that each block, arrow, and / or the like of the diagrams, flowchart diagrams, etc. may be implemented in the form of a computer program product, an entirely hardware embodiment, a combination of hardware and computer program product, and / or an apparatus, system, computing device, computing entity, and / or the like that executes instructions, operations, steps, and similar terms used interchangeably (e.g., executable instructions, instructions for execution, program code, and / or the like) on a computer-readable storage medium for execution. For example, fetching, loading, and execution of code may be performed sequentially, such that one instruction is fetched, loaded, and executed at a time. In some exemplary embodiments, fetching, loading, and / or execution may be performed in parallel, such that multiple instructions are fetched, loaded, and / or executed together. Accordingly, such embodiments may produce a specifically configured machine that performs the steps or operations specified in the representations of the present disclosure. Thus, the expressions of this disclosure support various combinations of embodiments for implementing the specified instructions, acts, or steps.

[0071] IV. Exemplary System Architecture FIG. 1 provides an illustration of a computing ecosystem 100 that may be used with various embodiments of the present disclosure. As shown in FIG. 1, the architecture may include an exchange platform 102, one or more client devices 104, a network of member platforms 110, one or more networks 120, and / or the like. The network of member platforms 110 may include a first member platform 112a, a second member platform 112b, a third member platform 112c, and / or the like that are attached (e.g., registered, etc.) to the exchange platform 102. For example, as described herein, the network of member platforms 110 may include a partner platform and / or a service provider platform. In some examples, the partner platform may include a first member platform 112a, and the service provider platform may include a second member platform 112b that is different from the first member platform 112a. In some examples, a partner platform and / or a service provider platform may include a single member platform (e.g., third member platform 112c). In some examples, the network of member platforms 110 may be configured for one or more different services.

[0072] Each of the components of computing ecosystem 100 may be in electronic communication with one another, e.g., via the same or different wireless or wired networks 120, including, e.g., a wired or wireless personal area network (PAN), local area network (LAN), metropolitan area network (MAN), wide area network (WAN), or the like. Networks 120 may include, e.g., any type of network and / or any network connection spanning any geographic boundary (e.g., an inter-country connection involving one or more sovereign entities, etc.). Additionally, while FIG. 1 illustrates certain systems as separate, stand-alone entities, various embodiments are not limited to this particular architecture.

[0073] Although not explicitly illustrated, exchange platform 102 may be a client device 104 and / or may be part of network of member platforms 110. Additionally or alternatively, member platforms 112a-c may be part of client device 104 and / or exchange platform 102. In some embodiments, exchange platform 102 and / or each of member platforms 112a-c may comprise the same computing platform.

[0074] a. Exemplary Computing Platform 2 is an exemplary schematic diagram of a computing platform 200 in accordance with one or more embodiments of the present disclosure. A computing platform 200, such as exchange platform 102, member platforms 112a-c, and / or the like of FIG. 1, may include or be in communication with one or more processing elements 202 (also referred to as processors, processing circuitry, and / or similar terms used interchangeably herein) that communicate with other elements within computing platform 200 via, for example, a bus. Of course, processing elements 202 may be embodied in a number of different manners.

[0075] For example, processing element 202 may be embodied as one or more complex programmable logic devices (CPLDs), microprocessors, multicore processors, coprocessing entities, application-specific instruction set processors (ASIPs), microcontrollers, and / or controllers. Additionally, processing element 202 may be embodied as one or more other processing devices or circuitry. The term circuitry may refer to an entirely hardware embodiment or a combination of hardware and a computer program product. Thus, processing element 202 may be embodied as an integrated circuit, an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a programmable logic array (PLA), a hardware accelerator, other circuitry, and / or the like.

[0076] It will be appreciated, therefore, that processing element 202 may be configured for a particular use or configured to execute instructions stored on volatile or non-volatile media or otherwise accessible to processing element 202. Thus, whether configured by hardware or a computer program product, or a combination thereof, processing element 202 may be capable of performing steps or operations according to embodiments of the present disclosure when configured, as appropriate.

[0077] In some embodiments, computing platform 200 includes or is in communication with non-volatile memory 204 (also referred to as non-volatile storage, media, memory storage, memory circuitry, and / or similar terms used interchangeably herein). In some examples, non-volatile memory 204 may include one or more non-volatile storage or memory media, including, but not limited to, a hard disk, ROM, PROM, EPROM, EEPROM, flash memory, MMC, SD memory card, memory stick, CBRAM, PRAM, FeRAM, NVRAM, MRAM, RRAM, SONOS, FJG RAM, Millipede memory, Racetrack memory, and / or the like.

[0078] As will be appreciated, the non-volatile memory 204 may store data, databases, database instances, database management systems, files, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, and / or the like. The terms database, database instance, database management system, and / or similar terms used interchangeably herein may refer to a collection of records or data stored in a computer-readable storage medium using one or more database models, such as a hierarchical database model, a network model, a relational model, an entity-relationship model, an object model, a document model, a semantic model, a graph model, and / or the like.

[0079] In some embodiments, computing platform 200 includes or is in communication with volatile memory 206 (also referred to as volatile storage, media, memory storage, memory circuitry, and / or similar terms used interchangeably herein). In some examples, volatile memory 206 may also include one or more volatile storage or memory media, including, but not limited to, RAM, DRAM, SRAM, FPM DRAM, EDO DRAM, SDRAM, DDR SDRAM, DDR2 SDRAM, DDR3 SDRAM, RDRAM, TTRAM, T-RAM, Z-RAM, RIMM, DIMM, SIMM, VRAM, cache memory, register memory, and / or the like.

[0080] As will be appreciated, the volatile memory 206 may be used to store at least a portion of, for example, a database, a database instance, a database management system, data, an application, a program, a program module, a script, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, and / or the like, executed by the processing element 202. Thus, the database, the database instance, the database management system, data, an application, a program, a program module, a script, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, and / or the like may be used to control certain aspects of the steps / operations of the computing platform 200 with the assistance of the processing element 202 and the operating system.

[0081] As shown, in one embodiment, computing platform 200 also includes one or more network interfaces 208 for communicating with various computing entities (e.g., one or more components of FIG. 1 ), such as by communicating data, content, information, and / or similar terms used interchangeably herein, which may be transmitted, received, operated on, processed, displayed, stored, and / or the like. Such communication may be performed using a wired data transmission protocol, such as Fiber Distributed Data Interface (FDDI), Digital Subscriber Line (DSL), Ethernet, Asynchronous Transfer Mode (ATM), Frame Relay, Data Over Cable Service Interface Specification (DOCSIS), or any other wired transmission protocol. Similarly, computing platform 200 may communicate with other networks, such as General Packet Radio Service (GPRS), Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA2000), and other networks. The mobile station may be configured to communicate over a wireless external communications network using any of a variety of protocols, such as 1X (1xRTT), Wideband Code Division Multiple Access (WCDMA), Global System for Mobile Communications (GSM), Enhanced Data Rates for GSM Evolution (EDGE), Time Division Synchronous Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), Evolved Universal Terrestrial Radio Access Network (E-UTRAN), Evolution Data Optimized (EVDO), High Speed ​​Packet Access (HSPA), High Speed ​​Downlink Packet Access (HSDPA), IEEE 802.11 (Wi-Fi), Wi-Fi Direct, 802.16 (WiMAX), Ultra Wideband (UWB), Infrared (IR) protocol, Near Field Communication (NFC) protocol, Wibree, Bluetooth protocol, Wireless Universal Serial Bus (USB) protocol, and / or any other wireless protocol.

[0082] Although not shown, computing platform 200 may include or be in communication with one or more input elements, such as keyboard input, mouse input, touch screen / display input, motion input, movement input, audio input, pointing device input, joystick input, keypad input, and / or the like. Computing platform 200 may also include or be in communication with one or more output elements (not shown), such as audio output, video output, screen / display output, motion output, movement output, and / or the like.

[0083] As shown, computing platform 200 may be an example of one or more of the components of FIG. 1, such as exchange platform 102 and / or member platforms 112a-c.

[0084] b. Exemplary Client Device 3 is an example schematic diagram of a client device 104 in accordance with one or more embodiments of the present disclosure. The client device 104 may be operated by various entities, and an example computing ecosystem may include one or more client devices 104. For example, the client device 104 may be associated with, owned by, operated by, and / or performed by one or more end users. In various embodiments, an end user of the client device 104 may wish to engage in a value exchange between a partner and a service provider. As described herein, the user may do so by interacting with one or more functionalities provided by an exchange platform through user input using the client device 104.

[0085] For example, client device 104 may be a personal computing device, a smartphone, a tablet, a laptop, a personal digital assistant, and / or the like. In various embodiments, computing platform 200 may communicate with one or more client devices 104 and manage value exchanges with one or more client devices 104. As shown in FIG. 3 , client device 104 may include an antenna 312, a transmitter 304 (e.g., wireless), a receiver 306 (e.g., wireless), and a processing element 308 (e.g., a CPLD, a microprocessor, a multi-core processor, a co-processing entity, an ASIP, a microcontroller, and / or a controller) that provide signals to and receive signals from transmitter 304 and receiver 306, respectively.

[0086] The signals provided to and received from the transmitter 304 and receiver 306 may each include signaling information / data in accordance with the air interface standard of the applicable wireless system. In this regard, the client device 104 may be capable of operating with one or more air interface standards, communication protocols, modulation types, and access types. More particularly, the client device 104 may operate according to any of several wireless communication standards and protocols, such as those described above with respect to the computing platform 200. In particular embodiments, the client device 104 may operate according to numerous wireless communication standards and protocols, such as UMTS, CDMA2000, 1xRTT, WCDMA, GSM, EDGE, TD-SCDMA, LTE, E-UTRAN, EVDO, HSPA, HSDPA, Wi-Fi, Wi-Fi Direct, WiMAX, UWB, IR, NFC, Bluetooth, USB, and / or the like. Similarly, the client device 104 may operate, via the network interface 320, according to numerous wired communication standards and protocols, such as those described above with respect to the computing platform 200.

[0087] Through these communication standards and protocols, client device 104 may communicate with computing platform 200 using concepts such as Unstructured Supplementary Service Data (USSD), Short Message Service (SMS), Multimedia Messaging Service (MMS), Dual Tone Multi-Frequency Signaling (DTMF), and / or Subscriber Identity Module Dialer (SIM Dialer). Client device 104 may also download modifications, add-ons, and updates to its firmware, software (including, e.g., executable instructions, applications, program modules), and operating system, for example.

[0088] In some embodiments, the client device 104 includes location determination aspects, devices, modules, functions, and / or similar terms used interchangeably herein. For example, the client device 104 may include an outdoor positioning aspect, such as a location module adapted to acquire latitude, longitude, altitude, geocode, course, direction, orientation, speed, Universal Time (UTC), date, and / or various other information / data. In one embodiment, the location module may acquire data, sometimes known as ephemeris data, by identifying the number of satellites in view and their relative positions (e.g., using a Global Positioning System (GPS)). The satellites may be a variety of different satellites, including a Low Earth Orbit (LEO) satellite system, a Department of Defense (DOD) satellite system, the European Union Galileo Positioning System, the China Compass Navigation System, the Indian Regional Navigational Satellite System, and / or the like. This data may be collected using various coordinate systems, such as decimal degrees (DD), degrees, minutes, and seconds (DMS), Universal Transverse Mercator (UTM), Universal Polar Stereographic (UPS) coordinate system, and / or the like. Alternatively, location information / data may be determined by triangulating the position of the client device 104 relative to various other systems, including cellular towers, Wi-Fi access points, and / or the like. Similarly, the client device 104 may include indoor positioning aspects, such as a location module adapted to acquire latitude, longitude, altitude, geocode, heading, direction, orientation, speed, time, date, and / or various other information / data. Some indoor systems may use various position or location technologies, including RFID tags, indoor beacons or transmitters, Wi-Fi access points, cellular towers, nearby computing devices (e.g., smartphones, laptops), and / or the like.For example, such technologies may include iBeacons®, Gimbal proximity beacons, Bluetooth Low Energy (BLE) transmitters, NFC transmitters, and / or the like. These indoor positioning aspects may be used in a variety of environments to determine someone or something's location down to the inch or centimeter.

[0089] In some embodiments, the client device 104 may include a user interface 316 (e.g., a display screen, a speaker, haptic mechanization, etc., coupled to the processing element 308) and / or a user input interface 318 (e.g., a touch screen, a microphone, etc., coupled to the processing element 308). For example, the user interface 316 may be one or more current application screens presented by one or more computing platforms described herein. The user input interface 318 may include any of several devices or interfaces that enable the client device 104 to receive data, such as a keypad (hard or soft), a touch display, a voice / speech or motion interface, or other input device. In examples including a keypad, the keypad may include (or cause the display of) traditional numbers (0-9) and related keys (#, *), as well as other keys used to operate the client device 104, and may include a full set of alphabetic keys or a set of keys that can be activated to provide a full set of alphanumeric keys. In addition to providing input, the user input interface may be used to activate or deactivate certain features, such as a screen saver and / or sleep mode.

[0090] The client device 104 may also include volatile memory 322 and / or nonvolatile memory 324, which may be embedded and / or removable. For example, the nonvolatile memory 324 may be ROM, PROM, EPROM, EEPROM, flash memory, MMC, SD memory card, memory stick, CBRAM, PRAM, FeRAM, NVRAM, MRAM, RRAM, SONOS, FJG RAM, Millipede memory, Racetrack memory, and / or the like. The volatile memory 322 may be RAM, DRAM, SRAM, FPM DRAM, EDO DRAM, SDRAM, DDR SDRAM, DDR2 SDRAM, DDR3 SDRAM, RDRAM, TTRAM, T-RAM, Z-RAM, RIMM, DIMM, SIMM, VRAM, cache memory, registered memory, and / or the like. The volatile and non-volatile storage or memory may store databases, database instances, database management systems, data, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine language, executable instructions, and / or the like to implement the functionality of the client device 104. As shown, this may include partner applications, service provider applications, and / or the like that are resident on the client device 104 and / or accessible through a browser or other user interface to communicate with the computing platform 200.

[0091] In some embodiments, client device 104 may include one or more components or functionality that are the same as or similar to those of computing platform 200, as described in more detail above. It should be recognized that these architectures and descriptions are provided for purposes of example only and are not limiting of various embodiments.

[0092] In various embodiments, the client device 104 may be embodied as an artificial intelligence (AI) computing entity, such as an Amazon Echo, an Amazon Echo Dot, an Amazon Show, a Google Home, and / or the like. Accordingly, the client device 104 may be configured to provide and / or receive information / data from an end user via input / output mechanisms, such as a display, a camera, a speaker, voice-activated input, and / or the like. In particular embodiments, the AI ​​computing entity may comprise one or more predefined and executable program algorithms stored within an on-board memory storage module and / or accessible over a network. In various embodiments, the AI ​​computing entity may be configured to retrieve and / or execute one or more of the predefined program algorithms upon the occurrence of a predefined trigger event.

[0093] c. Exemplary Network 1 may be configured to communicate with one another via respective communicative couplings to one or more networks 120. Networks 120 may include any one or combination of different types of suitable communications networks, such as, but not limited to, a cable network, a public network (e.g., the Internet), a private network (e.g., a frame relay network), a wireless network, a cellular network, a telephone network (e.g., the Public Switched Telephone Network), or any other suitable private and / or public network. Furthermore, networks 120 may have any suitable communications range associated with them and may include, for example, a global network (e.g., the Internet), a MAN, a WAN, a LAN, or a PAN. Additionally, network 120 may include any type of medium over which network traffic may be carried, including, but not limited to, coaxial cable, twisted pair wire, optical fiber, hybrid fiber coaxial (HFC) medium, microwave terrestrial transceiver, radio frequency communication medium, satellite communication medium, or any combination thereof, as well as various network devices and computing platforms provided by network providers or other entities.

[0094] d. Exemplary Value Exchange System FIG. 4 is an exemplary block diagram of an exemplary network-based exchange system 400 in accordance with one or more embodiments of the present disclosure. The network-based exchange system 400 includes a new computing ecosystem and computing platform that provides an end-to-end value exchange solution to replace traditional exchange processing systems. As described herein, the network-based exchange system 400 may be value-system agnostic and may be applied to any value-based exchange, including, by way of example, an information-based exchange, a financial-based exchange, a reputation-based exchange, a healthcare-based exchange, a benefit-based exchange, and / or the like. In any value system, the network-based exchange system 400 may utilize an intermediary entity and one or more predefined communication interfaces to facilitate network-based exchanges between value-seeking entities (e.g., partners) and value-providing entities (e.g., service providers), which may be associated with one or more member platforms of the network-based exchange system 400.

[0095] As depicted, network-based exchange system 400 may include exchange platform 102, partner platform 420, and / or service provider platform 440, which may be configured to communicate through one or more exchange interfaces. Partner platform 420 and / or service provider platform 440 may include one or more member platforms 112a-c from network of member platforms 110. For example, partner platform 420 and service provider platform 440 may include a single member platform (e.g., member platform 112c). Additionally or alternatively, partner platform 420 and service provider platform 440 may include one or more different member platforms (e.g., member platforms 112a and 112b). In some examples, a user may interact with one or more of the platforms through a client device 104.

[0096] In some embodiments, the exchange platform 102 is a computing entity configured to facilitate the credential-less exchange of value for one or more members in a network. The exchange platform 102 may include one or more processing devices, memory devices, and / or the like, physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks to facilitate a value system-agnostic exchange. In some examples, the exchange platform 102 may include, define, and / or otherwise utilize one or more exchange interfaces for facilitating communication (e.g., requests, responses, etc.) between multiple members. As described herein, the interfaces may be utilized to facilitate secure exchange between one or more members in any value system.

[0097] In some embodiments, members are entities that collaborate with the exchange platform 102 to participate in a value exchange. By way of example, members may include (i) partners that utilize the exchange platform 102 to receive value, (ii) service providers that utilize the exchange platform 102 to provide value, and / or (iii) both partners and service providers. As used herein, members may be referred to as partners when they receive value through a value exchange and / or service providers when they provide value through a value exchange. Thus, depending on the member's role in the value exchange, the same member may be both a partner and a service provider. For example, a member may be a partner that receives value for a value exchange. The same member may be a service provider that provides value in another value exchange. In some examples, the same member may be both a partner and a service provider in the same value exchange; thus, the member may provide value in only one member's value exchange and then utilize the exchange platform 102 to receive value.

[0098] In some embodiments, a member is a partner when it utilizes a service provided by a service provider. A partner may include any value-seeking entity in any value system. By way of example, in a financial value system, a partner may include a merchant (e.g., a retailer, a brick-and-mortar establishment, etc.) that may utilize a service provider, such as a financial institution, to access funds for financial transactions. Additionally or alternatively, in an information value system, a partner may include a news publisher (e.g., a newspaper, a news organization, etc.) that may utilize a service provider, such as a news agency (e.g., a wire service, a news service, etc.), to access information for information transactions. Of course, the techniques of this disclosure may be applied to any value system, and a partner may include any value seeker for any respective value system.

[0099] In some embodiments, a member is a service provider when it provides a service to a partner. A service provider can include a source of value in any value system. By way of example, in a financial value system, a service provider can include a financial institution (e.g., a bank, exchange, credit union, etc.) that can provide access to funds for financial transactions between one or more entities. Additionally or alternatively, in an information value system, a service provider can include a news agency (e.g., a wire service, news service, etc.) that can source information for publication by news publishers. Of course, the techniques of this disclosure may be applied to any value system, and a service provider can include any source of value for any respective value system.

[0100] Service providers and partners may communicate through one or more respective member platforms each associated with the entity. As one example, a service provider may be associated with service provider platform 440, and a partner may be associated with partner platform 420.

[0101] In some embodiments, a member platform is a computing entity corresponding to a member associated with the exchange platform 102. A member platform may include a partner platform 420 acting on behalf of a partner, a service provider platform 440 acting on behalf of a service provider, and / or both. In some examples, a member platform may be both a partner platform 420 and a service provider platform 440. For example, the same member platform may be configured to operate on behalf of a partner for one value exchange and a service provider for another value exchange. In some examples, the same member platform may be configured to operate on behalf of both a partner and a service provider in a single value exchange. It is noted that the term member platform may refer to the partner platform 420, the service provider platform 440, or both, and in some examples may depend on the role of the member platform in the value exchange (e.g., and / or the interface or interfaces utilized by the member platform in the value exchange).

[0102] In some embodiments, partner platform 420 is a computing entity configured to perform one or more operations on behalf of a partner. Partner platform 420 may include one or more processing devices, memory devices, and / or the like, physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks, for example, to request value in a value-system-agnostic exchange. In some examples, partner platform 420 may include, define, and / or otherwise utilize one or more exchange interfaces to facilitate communication (e.g., requests, responses, etc.) with exchange platform 102. In some examples, partner platform 420 may be configured to host one or more user-facing applications (e.g., partner applications, etc.) for interacting with one or more users.

[0103] In a financial value system, for example, the partner platform 420 may host an online marketplace for partners, allowing users to interact (e.g., search, browse, purchase, return, etc.) with one or more products or services offered by the partners. In the case of a product purchase, the partner platform 420 may collaborate with one or more service providers to access funds for the purchase. Traditionally, access to funds from service providers is facilitated using card numbers, account numbers, and / or other financial credentials that may expose users to malicious parties. To address network security and data privacy concerns for traditional financial systems (and / or other value-based systems), the partner platform 420 may register with the exchange platform 102 by configuring one or more software development kits (SDKs), APIs, and / or the like to facilitate communication with the exchange platform 102. For example, the partner platform 420 may include, define, and / or otherwise utilize one or more partner interfaces 402 to facilitate communication (e.g., requests, responses, etc.) with the exchange platform 102.

[0104] In some embodiments, service provider platform 440 is a computing entity configured to perform one or more operations on behalf of a service provider. Service provider platform 440 may include one or more processing devices, memory devices, and / or the like, physically and / or wirelessly coupled and configured to collectively (and / or individually) perform one or more computing tasks for providing value in a value-system-agnostic exchange, for example. In some examples, service provider platform 440 may include, implement, and / or otherwise utilize one or more interfaces for facilitating communication (e.g., requests, responses, etc.) with exchange platform 102. In some examples, service provider platform 440 may be configured to facilitate one or more service provider instruments. In some examples, service provider platform 440 may be configured to host one or more user-facing applications (e.g., service provider applications, etc.) for managing one or more service provider instruments.

[0105] In some examples, the service provider platform 440 may maintain one or more financial assets (e.g., a line of credit, a bank account, etc.) that allow a user to fund a transaction to purchase a product from a partner, for example, in a financial value system. In the case of a product purchase, the service provider platform 440 may collaborate with the partner platform 420 to authorize the transaction and / or otherwise provide access to the funds for the purchase. Traditionally, access to funds from a service provider is facilitated by submitting a card number, account number, and / or another financial credential to the service provider platform 440, which may expose the user, service provider, or partner to malicious parties, especially when provided over an insecure network (e.g., a public network, and / or the like). To address network security and data privacy concerns for traditional financial systems (and / or other value-based systems), service provider platform 440 may register with exchange platform 102 by configuring one or more software development kits (SDKs), APIs, and / or the like to facilitate communication with exchange platform 102. For example, service provider platform 440 may include, implement, and / or otherwise utilize one or more service provider interfaces 404 to facilitate communication (e.g., requests, responses, etc.) with exchange platform 102.

[0106] As described herein, the service provider interface 404 may enable the exchange platform 102 to identify and request the use of service provider instruments to facilitate transactions. For example, the service provider platform 440 may be configured to facilitate one or more service provider instruments.

[0107] In some embodiments, a service provider instrument is a mechanism utilized by a service provider to provide value (e.g., on behalf of a particular user, organization, etc.). The service provider instrument may depend on the value system and / or the service provider. In some examples, the service provider instrument may include a service provider account. For example, in a financial value system, the service provider instrument may include a bank account (e.g., checking, savings, etc.), a brokerage account, a line of credit, and / or the like. In an information value system, a benefit value system, and / or the like, the service provider instrument may include a member account and / or the like. In some examples, the service provider instrument may include a virtual instrument (e.g., a virtual account, a line of credit, etc.) hosted by the service provider platform 440. For example, the service provider platform 440 may be configured to maintain multiple member instrument data objects representing multiple service provider instruments for multiple attached entities.

[0108] In some embodiments, an instrument data object is a data entity that represents a service provider instrument. The instrument data object may include one or more instrument identifiers and / or one or more instrument attributes. In some examples, the one or more instrument identifiers and / or one or more instrument attributes may be based at least in part on the type of the instrument data object. By way of example, a service provider instrument may be represented in a member platform (e.g., service provider platform 440) as a member instrument data object. Additionally or alternatively, a service provider instrument may be independently represented by a system instrument data object in the exchange platform 102. In some examples, the member instrument data object and the system instrument data object may include one or more of the same instrument identifier(s) and / or instrument attribute(s). As an example, a member platform may register multiple service provider instruments with the exchange platform 102 (e.g., using the service provider interface 404). During registration, the member platform (e.g., the service provider platform 440) may provide one or more of the instrument identifiers and / or instrument attributes, and in some examples, the exchange platform 102 may return another identifier.

[0109] In some embodiments, a member instrument data object is an internal representation of a service provider instrument within a member platform, such as service provider platform 440. The member instrument data object may include one or more instrument identifiers, such as a member instrument identifier, an instrument key from exchange platform 102, and / or a user identifier. The user identifier may include, for example, a member user identifier, as described herein. Additionally or alternatively, the member instrument data object may include one or more instrument attributes, such as an instrument type (e.g., credit-based instrument, debit-based instrument, information-based instrument, etc.), an instrument representation, and / or one or more context attributes. In some examples, the context attributes may depend on the value system. For example, in a financial value system, one or more context attributes may indicate (i) the currency associated with the service provider instrument, (ii) asset availability (e.g., balance, coverage, etc.) of the service provider instrument, (iii) one or more previous transactions with the service provider instrument, and / or the like.

[0110] In some embodiments, a system instrument data object is an external representation of a service provider instrument within the exchange platform 102. A system instrument data object may include one or more instrument identifiers, such as a member platform instrument reference, a system instrument identifier, and / or a user identifier. A user identifier may include, for example, a system user identifier, as described herein. Additionally or alternatively, a system instrument data object may include one or more instrument attributes, such as an instrument type (e.g., a credit-based instrument, a debit-based instrument, an information-based instrument, etc.), an instrument representation, and / or one or more context attributes. In some examples, the context attributes may depend on the value system. For example, in a monetary value system, one or more context attributes may indicate a currency associated with the service provider instrument.

[0111] In some examples, a member platform, such as partner platform 420 and / or service provider platform 440, may be associated with user-facing applications to facilitate one or more interactions with users and / or other attached entities (e.g., through client devices 104).

[0112] In some embodiments, a user-facing application is a computer program hosted by a computing entity for facilitating one or more user interactions. A user-facing application may include software (e.g., computer-readable instructions, etc.) designed to perform one or more computing tasks for a computing entity, such as a member platform. For example, a user-facing application may facilitate communication between a member and a user. As an example, a user-facing application may be configured to present one or more user interfaces 406 (e.g., via a client device 104) for interacting with a user on behalf of the member. In some examples, a user-facing application may be configured to receive user input (e.g., via one or more user interfaces 406) for receiving information from a user.

[0113] In some embodiments, the user-facing application is a partner application 416 hosted by a partner platform (e.g., a member platform acting as a partner for a particular exchange) to facilitate functionality for the partner. The partner application may include software (e.g., computer-readable instructions, etc.) designed to perform one or more computing tasks for the partner. In some examples, the partner application 416 may consist of one or more devices (e.g., point-of-sale terminals, etc.) from a stand-alone partner establishment (e.g., a brick-and-mortar bank, etc.). For example, the partner application 416 may be configured to present one or more user interfaces 406 for interacting (e.g., browsing, purchasing, reviewing, etc.) with one or more products offered by a retail-based partner, one or more units of information offered by an information-based partner, and / or the like. In some examples, the partner application 418 may be configured to receive user input (e.g., via one or more user interfaces 406) to receive information from a user.

[0114] In some embodiments, the service provider platform 440 is configured to host one or more service provider applications 418 for managing one or more service provider instruments. For example, a user-facing application may be a service provider application 418 hosted by the service provider platform 440 (e.g., a member platform acting as a service provider for a particular exchange) to facilitate functionality for the service provider. In some examples, the service provider application 418 may consist of one or more devices from a stand-alone service provider facility (e.g., a brick-and-mortar bank). The service provider application 418 may include software (e.g., computer-readable instructions, etc.) designed to perform one or more computing tasks for the service provider. For example, the service provider application 418 may be configured to present one or more user interfaces for interacting (e.g., probing, managing, inspecting, registering, etc.) with one or more service provider instruments facilitated by the service provider. By way of example, in a financial value system, the service provider application 418 may enable access to bank accounts, brokerage accounts, lines of credit, and / or the like to manage funds, assets, and / or the like handled by the respective accounts. In some examples, the service provider application 418 may be configured to receive user input (e.g., via one or more user interfaces 406) to receive information, authorizations, and / or the like from the user.

[0115] In some embodiments, the exchange platform 102 facilitates communication between the partner platform 420 and the service provider platform 440 using one or more exchange interfaces.

[0116] In some embodiments, the exchange interface is a set of instructions for facilitating communication between the exchange platform 102 and one or more member platforms and / or internal services. The exchange interface may include an API, a file-based interface, a message queue-based interface, and / or the like. For example, the exchange interface may include an API, including, by way of example, one or more Simple Object Access Protocol (SOAP) APIs, one or more Remote Procedure Call (RPC) APIs, one or more WebSocket APIs, one or more Representational State Transfer (REST) ​​APIs, and / or the like. In some embodiments, the exchange interface may include one or more RPC APIs, such as one or more gRPC APIs.

[0117] Exchange platform 102 may include, define, and / or otherwise utilize one or more different exchange interfaces to facilitate communication with one or more external platforms, such as one or more member platforms (e.g., partner platform 420, service provider platform 440, etc.). Each interface may include multiple communication instructions, message definitions, and / or the like for exchanging requests and / or responses between exchange platform 102 and entities participating in the value exchange. By way of example, the exchange interface may include partner interface 402 for facilitating communication with partner platform 420 and / or service provider interface 404 for facilitating communication with service provider platform 440.

[0118] In some embodiments, partner interface 402 is an exchange interface for facilitating one or more communications between partner platform 420 and exchange platform 102. Partner interface 402 may define one or more communication instructions, message definitions, and / or the like for facilitating one or more request and / or response messages between partner platform 420 and exchange platform 102. Partner interface 402 may include, for example, an API that defines (i) requests from a computing entity functioning as partner platform 420 to exchange platform 102 and / or (ii) requests from exchange platform 102 to partner platform 420. For example, partner interface 402 may define one or more registration messages, session messages, transaction messages, and / or the like for facilitating a value exchange for a partner. In some embodiments, partner interface 402 defines one or more identifiers for securely identifying one or more portions of a value exchange.

[0119] In some embodiments, service provider interface 404 is an exchange interface for facilitating one or more communications between service provider platform 440 and exchange platform 102. Service provider interface 404 may define one or more communication instructions, message definitions, and / or the like for facilitating one or more request and / or response messages between service provider platform 440 and exchange platform 102. Service provider interface 404 may include, for example, an API that defines (i) requests from a computing entity functioning as service provider platform 440 to exchange platform 102 and / or (ii) requests from exchange platform 102 to service provider platform 440. Service provider interface 404 may define, for example, one or more registration messages, session messages, transaction messages, and / or the like for facilitating value exchange using service provider instruments. In some embodiments, service provider interface 404 defines one or more identifiers for securely identifying one or more portions of a value exchange.

[0120] The exchange platform 102 can facilitate communication among a network of member platforms. For example, the member network can include multiple entities that are on-boarded with the exchange platform 102, such as by registering with the exchange platform 102, configuring their respective interfaces for communicating with the exchange platform 102, and / or the like. In some examples, the exchange platform 102 can execute one or more individual services to interact with each on-board entity. The individual services can include, for example, one or more partner services 410 and / or service provider services 412.

[0121] In some embodiments, exchange platform 102 instantiates a separate, partner-specific service, partner service 410, for each of the member's networks. Additionally or alternatively, for example, in a multi-tenant environment, partner service 410 may be instantiated for one or more partners from a network or member. Partner service 410 may be configured to perform one or more exchange operations for resolving exchange requests from partner platform 420. In some embodiments, exchange platform 102 instantiates a separate, service-provider-specific service, service provider service 412, for each of the member's networks. Additionally or alternatively, for example, in a multi-tenant environment, service provider service 412 may be instantiated for one or more service providers from a network or member. Service provider service 412 may be configured to perform one or more exchange operations for obtaining and resolving exchange requests from partner platform 420. The exchange operations may include any of the steps and / or actions described herein.

[0122] In some embodiments, partner services 410 and / or service provider services 412 interact with each other and / or one or more other components of exchange platform 102 through one or more local communication mechanisms to conduct exchange operations. For example, exchange platform 102 may include connectivity service 408 configured to establish, maintain, and verify secure network sessions with member platforms, such as partner platform 420. In some examples, connectivity service 408 and / or partner services 410 may operate collaboratively to register users (and / or their service provider instruments) with exchange platform 102. Additionally or alternatively, partner services 410 and / or service provider services 412 may operate collaboratively to register users (and / or their service provider instruments) and / or facilitate value exchanges between partner platform 420 and service provider platform 440. In some examples, the connection service 408 may be part of a partner service 410 .

[0123] Through the performance of one or more exchange operations, partner services 410 and / or service provider services 412 may generate and utilize multiple non-traditional identifiers to reference users, service provider instruments, and / or one or more aspects of the value exchange. At least some of these identifiers may include universally unique identifiers, such as UUEKs, that may be utilized to provide a credential-less exchange of value. Each identifier may be at least temporarily stored in platform data vault 414. Platform data vault 414 may include any type of memory device as described herein. In some examples, each service and / or one or more sets of services may be associated with a respective portion of platform data vault 414.

[0124] As described herein, one or more identifiers may be associated with one another and stored to form an identifier mapping that may be utilized by exchange platform 102 (and / or one or more services thereof) to reference users, service provider instruments, and / or any other aspects of a value exchange from communications between partner platform 420, service provider platform 440, and / or any other member platform that do not include user credentials. Examples of non-traditional identifiers will now be further described with reference to FIG. 5.

[0125] e. Exemplary Data Structures FIG. 5 is an example data diagram 500 for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. Data diagram 500 illustrates multiple relational identifiers of different types. As depicted, each identifier may be associated with at least one relational identifier to form an identifier mapping within one or more platforms, such as exchange platform 102 and / or service provider platform 440. The identifier mapping enables communication between exchange platform 102 and service provider platform 440 referencing service provider instrument 518 without exposing persistent credentials 514 (e.g., username, password, card number, etc.) associated with service provider instrument 518, which may be susceptible to fraud, abuse, and exploitation by malicious parties. As illustrated, using some of the techniques of the present disclosure, persistent credentials 514 may not need to be communicated outside of service provider platform 440. Data diagram 500 illustrates only a few of the identifiers that may be generated, stored, and / or utilized by various embodiments of the present disclosure. It will be understood that the illustrated identifiers are not an exhaustive list and may include other non-illustrated identifiers. Each of the identifiers may be labeled as an identifier, reference, key, and / or other similar term. These terms are used interchangeably herein to refer to a unit of information for identifying a data structure, entity, and / or any other component described herein.

[0126] As illustrated, some of the relevant identifiers in various embodiments of the present disclosure may include, by way of example, (i) one or more user references 502 that may be mapped to member user identifiers 522 of the service provider platform 440; (ii) one or more service provider partitions 504 that correspond to a network of onboard service provider platforms, such as the service provider platform 440; (iii) one or more partner partitions 506 that correspond to a network of onboard partner platforms; (iv) one or more member instrument identifiers 522 of the service provider platform 440; The user reference 502 may include one or more instrument references 520 that may be mapped to the user reference 502 and / or instrument identifier 508, (v) one or more keys 516 and / or system identifiers 512 that may be associated with the user reference 502 and / or instrument reference 520, (vi) one or more exchange identifiers 510 that may be mapped to either the system identifiers 512 and / or the keys 516, and / or (vii) one or more UUEKs 524 that may be mapped to the exchange identifiers 510 and / or at least one of the partner partitions 506 and / or service provider partitions 504.

[0127] In some examples, the service provider platform 440 may store one or more identifiers that can be mapped to the service provider instrument 518 and / or one or more identifiers of the exchange platform 102 to enable the service provider platform 440 to reference the service provider instrument 518 based at least in part on an identifier that does not indicate any aspect of the service provider instrument 518, including the persistent credential 514, by the identifier itself.

[0128] As an example, the service provider platform 440 may store, maintain, and / or otherwise access one or more keys 516 mapped to one or more system identifiers 512 of the exchange platform 102 (e.g., being copies, derivatives, etc. of the one or more system identifiers 512). The keys 516 may, for example, include the system identifiers 512 as part of the key 516. The keys 516 may be mapped to member instrument identifiers 508 and / or member user identifiers 522, which may internally reference users of the service provider platform and / or service provider instruments 518. The keys 516 may be provided, for example, during a registration process between the service provider platform 440 and / or the exchange platform 102.

[0129] As another example, the exchange platform 102 may store, maintain, and / or otherwise access one or more references, such as instrument reference 520 and / or user reference 502, that map to (e.g., are copies, derivatives, etc. of) one or more member identifiers, such as member instrument identifier 508 and / or member user identifier 522 of the service provider platform 440. The references may be provided, for example, during a registration process between the service provider platform 440 and / or the exchange platform 102.

[0130] In some embodiments, the exchange platform 102 uses one or more entity partitions to refer to each member platform in the network of member platforms. In some embodiments, an entity partition is a unique identifier for a computing entity. An entity partition may include a unique numeric, alphanumeric, and / or similar identifier that represents a particular computing entity. An entity partition may include, for example, a member partition representing a member platform, a service provider partition 504 representing a service provider platform 440, a partner partition 506 representing a partner platform 420, and / or the like.

[0131] In some embodiments, the service provider partition 504 is a unique identifier for a service provider and / or the service provider's service provider platform 440. The service provider partition 504 may include a series of numeric, alphanumeric, or any / all other characters or symbols that represent a service provider associated (e.g., onboarded, registered, etc.) with the exchange platform 102. The exchange platform 102 may, for example, include multiple service provider partitions, each identifying a service provider platform 440 associated (e.g., onboarded, registered, etc.) with the exchange platform 102. Each service provider partition 504 may represent a service provider platform 440 that has configured one or more exchange platform software development kits (SDKs) and / or the like to implement the service provider interfaces of the exchange platform 102.

[0132] In some embodiments, partner partition 506 is a unique identifier for a partner and / or the partner's partner platform. Partner partition 506 may include a series of numeric, alphanumeric, and / or any other characters or symbols that represent a partner associated with exchange platform 102. Exchange platform 102 may include multiple partner partitions, each identifying a partner platform attached (e.g., installed, registered, etc.) to exchange platform 102, for example. Each partner partition 506 may represent a partner platform that has configured one or more exchange SDKs and / or the like to implement the partner interface of exchange platform 102.

[0133] In some embodiments, an entity partition is generated to identify a member platform when the member platform is onboarded to the exchange platform 102. In some examples, after onboarding to the exchange platform, the member platform may utilize one or more exchange interfaces to register one or more service provider instruments with the exchange platform 102. A service provider instrument 518 may be registered with the exchange platform 102 by exchanging one or more instrument identifiers with the exchange platform 102.

[0134] In some embodiments, the instrument identifier includes any representation of the service provider instrument 518 that identifies the service provider instrument without revealing the persistent credentials 514 of the service provider instrument 518. The instrument identifier may include a member instrument identifier 508, a system instrument identifier, an instrument reference 520, an instrument key, and / or the like, as described herein.

[0135] In some embodiments, member instrument identifier 508 is a unique identifier for representing service provider instrument 518 within a member platform, such as service provider platform 440. Member instrument identifier 508 may include, for example, a series of numeric, alphanumeric, or any / or other characters or symbols that represent service provider instrument 518 to service provider platform 440. In some examples, member instrument identifier 508 may include a table identifier of a member instrument data object.

[0136] In some embodiments, instrument reference 520 is a unique identifier for referencing member instrument identifier 508. Instrument reference 520 may be generated and / or provided by a member platform to exchange platform 102, for example, to enable exchange platform 102 to reference service provider instruments 518 maintained at the member platform. In some examples, instrument reference 520 is the same value as member instrument identifier 508. In some examples, instrument reference 520 is a different value mapped to member instrument identifier 508.

[0137] In some embodiments, the system instrument identifier is a unique identifier for representing the service provider instrument 518 within the exchange platform 102. The system instrument identifier may include, for example, a series of numeric, alphanumeric, or any / or other characters or symbols that represent the service provider instrument 518 to the exchange platform 102 without revealing the persistent credentials 514 of the service provider instrument 518. In some examples, the system instrument identifier may include a UUID. In some examples, the system instrument identifier may include at least one of the system identifiers 512.

[0138] In some embodiments, an instrument key is a unique identifier for referencing a system instrument identifier. The instrument key may be generated and / or provided by the exchange platform 102, for example, during the registration process of the service provider instrument 518 to the exchange platform 102. In some examples, the instrument key may include a packaged system instrument identifier. For example, the instrument key may include a string of alphanumeric characters formatted according to a key format established by the exchange platform 102 (and / or its one or more APIs). The key format may include any number of characters, such as 50 characters or more. In some examples, the characters may be case-sensitive. A first portion of the characters (e.g., the first six characters) may be reserved as a partition for identifying the entity associated with the key. In the case of an instrument key, for example, the partition may include the service provider partition 504. A second portion of the characters may identify the system instrument identifier. In some examples, the instrument key may include at least one of the keys 516. The key formats described herein may contain one or more different parts, each of which may be arranged in any order.

[0139] In some embodiments, after onboarding to the exchange platform 102, the member platform may utilize one or more exchange interfaces to register one or more users with the exchange platform 102. A user may register with the exchange platform 102 by exchanging one or more user identifiers with the exchange platform 102. The user identifiers may be utilized, for example, to create, maintain, and / or update one or more user data objects reflecting users of the member platform and / or exchange platform 102.

[0140] In some embodiments, a user data object is a data entity representing a user interacting with a member platform and / or the exchange platform 102. A user may include, for example, an entity (e.g., a person, an organization, a group, etc.) that engages in a value exchange governed by the exchange platform 102. In some examples, a user may indirectly collaborate with the exchange platform 102 by creating a user account with a registered service provider, registering (and / or granting permission to register) a service provider instrument 518, and / or the like. In some examples, the exchange platform 102 may act on behalf of a user without the user directly interacting with the exchange platform 102. For example, the exchange platform 102 may act as a hidden intermediary between a user-facing application and the user's service provider instrument 518.

[0141] In some embodiments, a user data object includes one or more user identifiers and / or one or more user attributes. In some examples, the one or more user identifiers and / or one or more user attributes may be based at least in part on the type of user data object. By way of example, a user may be represented in a member platform as a member user data object. Additionally or alternatively, a user may be independently represented in an exchange platform by a system user data object. In some examples, a member user data object and a system user data object may include one or more of the same one or more user identifiers and / or user attributes. By way of example, a member platform may register multiple users with the exchange platform 102. During registration, the member platform may provide one or more of the user identifiers and / or user attributes, and in some examples, the exchange platform 102 may return another identifier.

[0142] In some embodiments, the member user data object is an internal representation of a user within a member platform, such as the service provider platform 440. The member instrument data object may include one or more user identifiers, such as the member user identifier 522, a user key from the exchange platform 102, and / or the like. Additionally or alternatively, the member user data object may include one or more user attributes. The one or more user attributes may indicate one or more contextual characteristics of the user. In some examples, the user attributes may indicate one or more identifiable characteristics of the user. By way of example, the user attributes may indicate the user's first name, last name, email, physical address (e.g., one or more of street, locality, region, zip code, country, etc.), date of birth (e.g., date of birth, age range, etc.), phone number, and / or the like. In some examples, the user attributes may include an encrypted, hashed, and / or otherwise secure representation of the user's identifiable characteristics. For example, the user attributes may include one or more hashed identifiers and / or the like of the user.

[0143] In some embodiments, a system user data object is an external representation of a member user within the exchange platform 102. The system user data object may include one or more user identifiers, such as a member platform user reference 502, a system user identifier, and / or the like. Additionally or alternatively, the system user data object may include one or more user attributes, such as those described herein. By way of example, a member platform may register a user with the exchange platform 102. During registration, the member platform may provide the user's user reference 502 and / or one or more user attributes. In some examples, the user attributes may include a hashed and / or encrypted identifier for the user.

[0144] In some embodiments, the user identifier comprises a unique identifier of a user involved in a value-based exchange. The user identifier may comprise a series of numeric, alphanumeric, or any / all other characters or symbols representing a user of the exchange platform 102 and / or member platform. In some examples, the user identifier may comprise a user reference 502, a user key, a system user identifier, a member user identifier, and / or the like.

[0145] In some embodiments, a system user identifier is a unique identifier for representing a user within exchange platform 102. A system user identifier may include, for example, a series of numbers, alphanumeric characters, and / or any other characters or symbols that represent a user to exchange platform 102. In some examples, a system user identifier may include a UUID that is unique to a particular user. In some examples, a system user identifier may include at least one of system identifiers 512.

[0146] In some embodiments, the member user identifier 522 is a unique identifier to represent the user within the member platform. The member user identifier may include, for example, a series of numbers, alphanumeric characters, or any other characters or symbols that represent the user to the service provider platform 440.

[0147] In some embodiments, the user reference 502 may be a unique identifier for referencing the member user identifier 522. The user reference 502 may be generated and / or provided by the member platform to the exchange platform 102, for example, to allow the exchange platform 102 to reference a user associated with the member platform. In some examples, the user reference 502 is the same value as the member user identifier 522. In some examples, the user reference 502 is a different value mapped to the member user identifier 522.

[0148] In some embodiments, a user key is a unique identifier that references a system user identifier. The user key may be generated and / or provided by the exchange platform 102, for example, during the user's registration process with the exchange platform 102. In some examples, the user key may include a packaged system user identifier. For example, the user key may include a string of alphanumeric characters formatted according to a key format established by the exchange platform (and / or its one or more APIs). The key format may include, for example, a first portion of characters (e.g., the first six characters) that may be reserved as a partition for identifying an entity (e.g., a member, etc.) associated with the key. For example, in the case of a user key, the partition may include a service provider partition 504 and / or a partner partition. The second portion of characters may identify the system user identifier.

[0149] 5, keys 516, such as the user and instrument keys described herein, may be shared across the exchange platform 102 and the service provider platform 440. Additionally, in some examples, references, such as instrument references 520 and user references 502, may be shared across entities. These identifiers, and the mapping scheme described herein, allow the exchange platform 102 to reference the service provider instrument 518 without knowledge of the persistent credentials 514 (e.g., card number, etc.) of the service provider instrument 518. As described herein, one or more of the keys 516 and / or references may be provided to the service provider platform 440 individually or in any combination. In some examples, each of the keys 516 and references may be provided to the service provider platform 440 in a redundant process that allows the service provider platform to verify that the communication is provided by the exchange platform 102 (e.g., an entity with access to a unique set of keys and references).

[0150] In some embodiments, the persistent credentials 514 for the service provider instrument 518 include confidential user and / or instrument credentials, such as card numbers, account numbers, subscription numbers, and / or the like, that may expose users, members, and / or intermediary entities to risk. The persistent credentials 514 may be generated, accessed, and / or otherwise provided to a user by the service provider platform 440 when the user applies for a new service provider instrument 518, is authorized for a new service provider instrument 518, and / or is otherwise enabled to open a new service provider instrument 518. Traditionally, the persistent credentials 514 are then used by the user to initiate value exchanges using the service provider instrument. By doing so, the user is forced to reveal confidential credentials directly tied to the service provider instrument 518 each time the service provider instrument 518 is used. The key 516, reference, and identifier mapping scheme of the present disclosure overcomes these technical deficiencies.

[0151] In some examples, each of the identifiers is interpretable not to a user but to a computing platform, such as the exchange platform 102 and / or the service provider platform 440. To allow a user to select a service provider instrument 518 while maintaining the enhanced security features of the present disclosure, in some examples, the identifiers of FIG.

[0152] In some embodiments, the instrument representation (not depicted by FIG. 5 ) is a unique identifier for representing the service provider instrument 518 to a user without revealing the service provider instrument's 518 persistent credential 514. The instrument representation may include, for example, a series of numeric, alphanumeric, or any / all other characters or symbols that ostensibly represent the service provider instrument 518 only to entities with prior knowledge of the service provider instrument 518. The format and / or value of the instrument representation may be based at least in part on the type of service provider and / or service provider instrument 518. For example, in a financial value system, the instrument representation may include a portion of the persistent credential 514 (e.g., the last four digits), such as a card number (e.g., debit card, credit card, etc.), a financial account number, and / or the like. As another example, in a value-of-information system, an instrument representation may include a portion (e.g., one or more digits, alphanumeric characters, etc.) of a persistent credential 514, such as a subscription account and / or the like. For example, an instrument representation may include a derivative of a persistent credential 514 that may allow only entities with prior knowledge of the persistent credential 514 to identify the persistent credential 514 using the instrument representation. As another example, an instrument representation may include a nickname for an instrument that is assigned by a user and subsequently recognized.

[0153] In some embodiments, the instrument representation may be provided to the exchange platform 102 (e.g., during the registration process) in place of the persistent credential 514. In this manner, the exchange platform 102 can use the instrument representation to represent the service provider instrument 518 without knowledge of the persistent credential 514 from which the instrument representation may be derived. For example, unlike conventional network-based exchange platforms, the exchange platform 102 may not require the persistent credential 514 corresponding to the service provider instrument 518 to implement various computing tasks of the present disclosure. This allows the exchange platform 102 to operate more flexibly while still storing previously unrecorded context data, lowering the computing cost of operations, and improving user and platform protection from intrusion attacks by malicious computing entities.

[0154] In some embodiments, the identifier mapping scheme is supplemented by unique, temporary keys issued to member platforms to facilitate secure, real-time value exchanges. For example, the exchange platform 102 can facilitate an additional layer of network and data security by implementing an exchange identifier 510 to represent aspects of the value-based exchange. Some examples of the exchange identifier 510 can include a service provider-specific exchange identifier and / or a partner-specific exchange identifier. The service provider-specific exchange identifier can include a temporary, unique exchange identifier that temporarily represents the service provider instrument 518 and the service provider platform 440. The service provider-specific exchange identifier can be mapped, for example, to the system identifier 512 of the service provider instrument 518. The partner-specific exchange identifier can include a temporary, unique exchange identifier that temporarily represents the service provider instrument 518 and the partner platform. The partner-specific exchange identifier can be mapped, for example, to the key 516 of the service provider instrument 518, which can be used to identify the service provider platform 440. In some cases, such mappings may be defined by exchange data objects.

[0155] In some embodiments, an exchange data object is a data entity that represents an authorized value exchange between one or more members associated with the exchange platform 102. In some examples, an exchange data object may include one or more identifiers and / or one or more exchange attributes. For example, the one or more identifiers and / or one or more exchange attributes may be based at least in part on the type of the exchange data object. By way of example, an exchange may be represented in a member platform as a member exchange data object. Additionally or alternatively, an exchange may be independently represented in the exchange platform 102 by a system exchange data object. In some examples, a member exchange data object and a system exchange data object may include one or more of the same one or more identifiers and / or exchange attributes. By way of example, using some of the techniques of this disclosure, the exchange platform 102 may issue one or more unique identifiers to member platforms that may be used to authorize value exchanges.

[0156] In some embodiments, a system exchange data object is an internal representation of a value exchange mediated using the exchange platform 102. In some examples, a system exchange data object may include one or more different identifiers and / or exchange attributes depending on the system exchange data object's role in the value-based exchange.

[0157] For example, the system exchange data object may include a service provider-specific exchange data object corresponding to the service provider platform 440. The service provider-specific exchange data object may include one or more identifiers, such as an exchange identifier 510, a system identifier 512 such as a system user identifier and / or a system instrument identifier, a UUEK 524, and / or the like. Additionally or alternatively, the service provider-specific exchange data object may include one or more exchange attributes, such as an expiration date, a currency (e.g., for a monetary value system), and / or the like.

[0158] Additionally or alternatively, the system exchange data object may include a partner-specific exchange data object corresponding to the partner platform. The partner-specific exchange data object may include one or more identifiers, such as an exchange identifier 510, one or more keys 516, such as an instrument key, a UUEK 524, a member instrument reference (e.g., a partner-specific instrument reference), and / or the like. Additionally or alternatively, the partner-specific exchange data object may include one or more exchange attributes, such as an expiration date, a currency (e.g., for a monetary value system), an instrument type, and / or the like.

[0159] In some embodiments, a member exchange data object is an external representation of a value exchange mediated using the exchange platform 102. The member exchange data object may include one or more identifiers, such as a member exchange identifier, a member instrument identifier 508, a UUEK 524 from the exchange platform 102, and / or the like.

[0160] In some embodiments, the exchange identifier 510 is a unique identifier for a value exchange using the exchange platform 102. The exchange identifier 510 may include a series of numeric, alphanumeric, and / or any other characters or symbols that represent at least a user and / or a service provider instrument 518. In some examples, the exchange identifier 510 may include a universally unique identifier (UUID) that may be mapped (e.g., via a series of identifiers, etc.) to a user, a service provider instrument 518, and / or a member registered with the exchange platform 102. In some examples, the exchange identifier 510 may be generated using one or more UUID generators. For example, the exchange identifier 510 may include 16 bytes of information generated according to one or more UUID formatting standards, such as UUID v4, and / or the like. Thus, while an exchange identifier 510 may be utilized by the exchange platform 102 and / or a member platform for one or more functions, the same exchange identifier 510 is useless to an outside party without a prior association between the exchange identifier 510 and one or more other identifiers. In addition to the prior identifier association, the exchange identifier 510 may be associated with the exchange platform 102. Thus, even if an exchange identifier 510 is identified by a harmful party, the harmful party would still be required to impersonate the exchange platform 102 in order to use the exchange identifier 510. Moreover, the harmful party would need to update the settlement account to an account owned by the harmful party, among several other tasks, before the exchange identifier 510 could be used adversely. Each of these tasks increases the amount of work required to overcome the enhanced layer of security added by the exchange identifier 510. When paired with the temporary nature of the exchange identifier 510, these tasks can become prohibitively expensive.

[0161] In some examples, the exchange identifier 510 may be externally represented by a UUEK 524. By way of example, to facilitate credential-less exchanges, the exchange platform 102 may issue one or more UUEKs 524 to one or more member platforms. As described herein, the UUEK 524 may remove reliance on traditional persistent credentials 514 by identifying aspects of the value exchange through previously mapped data entities.

[0162] In some embodiments, the UUEK 524 is an external representation of the exchange identifier 510 that may be issued (e.g., in place of the exchange identifier 510) to an external entity, such as a user, a partner platform, and / or a service provider platform, and / or the like, to initiate a value-based exchange using the exchange platform 102. To do so, the UUEK 524 may be generated and issued by the exchange platform 102 to the external entity. Each UUEK 524 may include multiple values ​​(e.g., up to 50 characters and / or more, which may or may not be case-sensitive) that represent one or more aspects of the value-based exchange. For example, the multiple values ​​may indicate the exchange identifier 510, a partition (e.g., identifying the recipient of the UUEK 524), an identifier type, and / or one or more flags. By way of example, the UUEK 524 may include a partner-specific UUEK and / or a service provider-specific UUEK. The partner-specific UUEK may be correlated to a partner-specific exchange data object as described herein and may include the partner partition 506, while the service provider-specific UUEK may be correlated to a service provider-specific exchange data object and may include the service provider partition 504.

[0163] By way of example, the UUEK 524 may be generated according to a key format. The key format may include a number of characters, e.g., including 50 or more characters, that may be case-sensitive. A first portion of the characters (e.g., the first six characters) may be reserved as a partition for identifying the recipient of the UUEK 524. The partition may include, for example, the partner partition 506, the service provider partition 504, and / or any other member partition. By way of example, the UUEK 524 may be issued in response to a request from an authorized member, such as an attached partner and / or service provider.

[0164] Additionally or alternatively, at least one character (e.g., the seventh character) of the key format may identify the format of the UUEK 524. At least another character (e.g., the eighth character) may identify the type of UUEK 524. In some examples, a second portion of characters may identify the exchange identifier 510 (e.g., the group of 22 characters following the eighth character). A third portion of characters may be reserved (e.g., the group of 20 characters following the first portion of characters). Exemplary representations are provided below: ppppppFiGGGGGGGGGGGGGGGGGGGGrrrrrrrrrrrrrrrrrrrr where p represents the partition character, F represents the format character, i represents the identifier type character, G represents the exchange identifier 510, and r represents the reserved character. The key format allows for up to 9.8 x 10^84 unique permutations, which is more than the number of atoms in the known observable universe. This allows for the generation and distribution of new UUEKs 524 on demand without compromising the security of the underlying data to which the UUEK 524 may be mapped, such as identifiers for users, instruments, and / or any other potentially sensitive information.

[0165] As described herein, the unique sequence of identifiers and the mapping scheme between the identifiers can facilitate a credential-less exchange of value system for registered and / or unregistered entities. In some examples, one or more of the identifiers may be generated through a registration or enrollment process configured to establish cross-entity relationships between user, partner, and service provider entities. An exemplary process for establishing cross-entity relationships is now further described with reference to Figures 6A-6C.

[0166] V. Exemplary System Operation 6A-6C provide a process flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. The process flow illustrates one or more stages of a registration process 600 for registering a user and / or a service provider instrument with an exchange platform to facilitate a credential-less exchange of value between a partner platform and a service provider platform. FIGS. 6A-6C illustrate an exemplary process 600 for illustrative purposes. Although the exemplary process 600 depicts a particular sequence of steps / actions, the sequence may be varied without departing from the scope of the present disclosure. For example, some of the depicted steps / actions may be performed in parallel or in a different sequence without substantially impacting the functionality of the process 600. In other examples, different components of an exemplary device or system implementing the process 600 may perform functions substantially simultaneously or in a unique sequence.

[0167] Various embodiments of process 600 address technical challenges related to data security and efficiency of network-based exchanges of value between one or more computing entities. Traditional systems address these challenges using registration mechanisms that require users to disclose confidential and persistent credentials to a third-party registration service. These traditional registration services then validate the user's account ownership and provide the persistent credentials to a partner platform for storage and subsequent processing. By doing so, user credentials are transmitted and disclosed to numerous different entities during and after network communications during the traditional registration process, ultimately increasing the risk of disclosure to malicious parties. Various embodiments of process 600 provide improved network communication, data encryption, and data management techniques to enable credential-less exchange registration capabilities, reducing the data security risks imposed by traditional processes.

[0168] One or more embodiments of process 600 may be implemented by one or more computing devices, entities, and / or systems described herein. For example, through the various steps / operations of process 600, the exchange platform 102 can leverage credential-less registration techniques to overcome various limitations associated with traditional registration mechanisms by registering a service provider instrument with a partner platform without access to the service provider instrument's persistent credentials. By doing so, the sensitive information underlying the service provider instrument for engaging in value exchange is never exposed to potentially malicious parties or partner platforms that may be susceptible to network-based attacks. For example, unlike traditional techniques, the exchange platform 102 never receives a user's identifiable or actionable account information, while the service provider managing the account is engaged in the registration process rather than being disintermediated by a potentially insecure registration service. This further eliminates the need to enforce resource data governance standards across each device involved in the registration process, ultimately resulting in improved computing resource utilization while enhancing network and data security.

[0169] 6A is a flowchart illustrating an example of a first stage of a registration process 600 for registering a user with an exchange platform without disclosing persistent credentials associated with the user and / or service provider instruments. The flowchart depicts communication techniques for overcoming various limitations of conventional registration systems by bypassing the conventional systems' reliance on confidential and persistent credentials. The communication techniques may be performed by one or more computing devices, entities, and / or systems described herein, such as an exchange platform, for establishing a secure communication session with a user through a partner application.

[0170] In some embodiments, process 600 includes, at step / operation 602, establishing a registration session for a user and a partner platform. For example, registration process 600 may begin with a partner application (e.g., a partner website, a user application, etc.), at which point the partner platform may enable the user to register a partner account on the partner application with the exchange platform to facilitate access to service provider instruments. The partner platform may enable the user's registration by initiating a registration session with the exchange platform.

[0171] For example, a user may access a partner application through a portal via a client device, such as a browser, web application, and / or the like, as described herein. The user's browser, web application, mobile application, and / or the like may fetch a platform connection widget from a content delivery network (CDN) and issue a communication session request to the partner platform to establish a registration session. In response to the request, the partner platform may generate a communication session request (e.g., using one or more exchange interfaces, etc.) to an exchange platform (e.g., its partner service). The communication session request may include an API request provided through the partner interface to initiate a registration widget to establish a registration session for the user.

[0172] In some embodiments, the communication session request includes one or more registration attributes, such as user data, a user identifier, a user hash, a time stamp, a device identifier, a partner identifier, and / or the like. As described herein, some techniques of the present disclosure enable a computing entity to identify a service provider instrument using an identifier that does not include the service provider instrument's persistent credentials along with the communication session request. For example, a partner platform may be configured to obtain user data for a user (e.g., through user input on a user interface screen, pre-recorded data from a partner account, etc.) and provide the user data to the exchange platform to begin the registration process. In some examples, the user data may be provided by the partner platform (e.g., through one or more API calls of a partner interface, etc.) along with the communication session request to the exchange platform (e.g., its partner service) to initialize a widget session. In some examples, the user data may be encrypted, hashed, and / or the like before transmission to the exchange platform. In some examples, the user data may include one or more user attributes as described herein.

[0173] In some embodiments, an exchange platform (e.g., its partner service) receives a communication session request using a partner interface to initialize a registration session at a user's client device. In some examples, the communication session request may include user data for the user. Additionally or alternatively, the registration initialization request may include one or more user attributes for the user. In some examples, the user attributes may be encrypted and / or hashed as described herein.

[0174] In some embodiments, process 600 includes setting user and partner data at step / operation 604. For example, the exchange platform (e.g., its connectivity service, partner service, etc.) may identify and / or generate user and / or partner data from data provided in the communication session request. In some examples, the user data may include one or more user attributes. In some examples, the user data may include one or more encrypted and / or hashed user attributes. In some examples, the partner data may include a shared identifier between the exchange platform and the partner platform, such as a partner partition, as described herein.

[0175] In some embodiments, process 600 includes, at step / operation 606, generating a session identifier for the registration session. For example, the exchange platform (e.g., its connection service, partner service, etc.) can generate a session identifier for the communication session between the partner platform and the exchange platform for tracking communications exchanged during the registration session. The session identifier can include, for example, a unique number, a string of characters, and / or the like for authenticating messages exchanged during the registration session. The exchange platform can use the connection service and / or the partner service to establish the registration session. For example, in response to the registration initialization request, the partner service can invoke another service, such as the connection service, to establish a communication session that can be used by a client-side widget to provide an interface between the user and the partner service to complete the user registration. The connection service can generate a session identifier and return the session identifier to the partner service. The partner service can return the session identifier to the partner platform, which can utilize the session identifier to initialize the client-side widget through an instance of the partner application on the client device. Once the partner application receives the session identifier, the partner application can launch (e.g., run, initialize, etc.) the client-side widget. The user can then interact with the widget to complete the registration process 600.

[0176] In some embodiments, process 600 includes, at step / operation 608, determining and providing a member list for the user. The member list may be a service provider list. For example, an exchange platform (e.g., its connectivity service, partner service, etc.) may determine the user's service provider list from a network of service providers attached (e.g., registered, etc.) to the exchange platform. In some examples, the service provider list may include each service provider platform attached to the exchange platform. Additionally or alternatively, the service provider list may include a subset of attached service provider platforms tailored to the user.

[0177] For example, the exchange platform may determine one or more service provider platforms based at least in part on user attributes of the registration session and align the service provider list with the one or more service provider platforms. By way of example, the exchange platform may include multiple system user data objects and / or system instrument data objects, as described herein. In some examples, the exchange platform may identify one or more system user data objects corresponding to a user based at least in part on the user attributes. In some examples, each system user data object may identify a service provider platform associated with the user. In this manner, the exchange platform may determine one or more service providers associated with a user based at least in part on the one or more system user data objects.

[0178] Additionally or alternatively, the exchange platform (e.g., its one or more service provider services) can provide a presence request for user presence data (e.g., via a service provider interface) from each of the service provider platforms in the network of member platforms. The user presence request can include one or more user attributes (e.g., encrypted attributes, hashed attributes, etc.) of the user that can be leveraged by the service provider platform to determine whether the user has an instrument on the service provider platform. In response to the request, the exchange platform (e.g., its one or more service provider services) can receive presence data from one or more of the service provider platforms indicating the presence of the instrument on the respective service provider platform. The exchange platform (e.g., its partner service) can determine one or more service providers based at least in part on the presence data.

[0179] In some examples, the exchange platform (e.g., its connectivity service, partner service, etc.) can initiate the presentation of a pre-registration screen based at least in part on one or more service providers using a partner interface provided by a partner application and via a registration user interface. A client device can be configured to access a partner application hosted by the partner platform, for example. The registration user interface can be presented to a user on the client device through a widget within the partner application. The widget can be defined internally by the partner or can be provided by the exchange platform. The pre-registration screen can present multiple selectable icons showing a list of service providers.

[0180] The registration process 600 can then proceed to a second stage in which an instrument identifier corresponding to the user is identified through interactions between the exchange platform, the user, and the service provider platform, as described in further detail with reference to FIG. 6B.

[0181] Referring now to FIG. 6B, FIG. 6B is a flowchart illustrating an example of a second stage of a registration process 600 for registering a service provider instrument with a partner platform without disclosing persistent credentials associated with the user and / or the service provider instrument. The flowchart depicts communication techniques for overcoming various limitations of conventional registration systems by bypassing the conventional systems' reliance on persistent credentials, such as card numbers and / or the like, provided by the user. The communication techniques may be performed by one or more computing devices, entities, and / or systems described herein, such as an exchange platform, for establishing connections between the user, the partner platform, and the service provider instrument.

[0182] In some embodiments, process 600 includes, at step / operation 610, determining and providing a user's service provider instrument list. The service provider instrument list may be determined based at least in part on a service provider selection from a pre-registration screen. For example, in some examples, the exchange platform (e.g., its connectivity service, partner service, etc.) may use a partner interface to receive pre-selection data indicating a selection of a particular service provider from one or more service providers presented by the pre-registration screen. For example, a widget may receive the pre-selection data from a partner application and provide an instrument registration request (e.g., via a partner interface) to the exchange platform (e.g., its connectivity service, partner service, etc.). The instrument registration request may include a session identifier and / or a service provider identifier indicating the selected service provider.

[0183] In response to the request, the exchange platform (e.g., its connectivity service, partner service, etc.) can receive service provider instrument data based at least in part on the preselection data. The service provider instrument data may indicate one or more service provider instruments for the user that are facilitated by the selected service provider platform. For example, the service provider instrument data may include one or more system instrument identifiers and / or corresponding instrument representations from one or more instrument data objects corresponding to the service provider and the user. Each of the instrument data objects may include, for example, a system user identifier corresponding to the user.

[0184] Additionally or alternatively, the exchange platform (e.g., its one or more service provider services) may provide an instrument request for service provider instrument data from a selected service provider platform (e.g., via a service provider interface). The instrument request may include, for example, a user reference corresponding to a member user identifier of the service provider platform. In response to the request, the service provider platform may identify one or more member instrument data objects that include the member user identifier, identify one or more instrument references that correspond to the one or more member instrument data objects, and provide the service provider instrument data to the exchange platform indicating the one or more instrument references and / or one or more corresponding instrument representations.

[0185] The exchange platform (e.g., its connectivity service, partner service, etc.) can use the partner interface and, via the registration user interface, initiate the presentation of an instrument registration screen through the user's client device based at least in part on the service provider instrument data. The instrument registration screen can be internally defined by the partner and / or provided by the exchange platform. The instrument registration screen may, for example, show one or more service provider instruments associated with the user and the selected service provider. By way of example, the instrument registration screen may show a respective instrument representation for each of the one or more service provider instruments. In some examples, for example, only when the user has subscribed to a single service provider instrument, the instrument registration screen may include a confirmation prompt to confirm the user's intent to register the service provider instrument.

[0186] In some embodiments, process 600 includes receiving selection data at step / operation 612. The selection data may indicate, for example, a selection of a service provider instrument from a registration user interface. By way of example, the selection data may identify a service provider instrument from a list of service provider instruments attached to the user. Additionally or alternatively, the selection data may indicate identification of a single service provider instrument attached to the user.

[0187] For example, the exchange platform may use a partner interface to receive a registration instrument along with an account request from a client-side widget. The request may include selection data and / or a session identifier. The selection data may indicate a selection of a service provider instrument from the registration user interface. For example, the selection data may indicate an instrument representation (e.g., the last four digits of the account, a nickname for the account, etc.) of the selected service provider instrument. In some examples, the selection data may include at least one of an instrument type, a currency type (e.g., in a monetary value system), and / or an instrument identifier (e.g., an instrument representation, etc.) corresponding to the selection.

[0188] In some embodiments, the client-side widget may be configured to authenticate a user before initiating a registration instrument with an account request. For example, the client-side widget may be configured to generate a user verification prompt based at least in part on the user data. The user verification prompt indicates a request for confirmation of at least one portion of the user data. In some examples, the widget may be configured to present the user verification prompt to the user. In some embodiments, the exchange platform may initiate the presentation of the user verification prompt using a partner interface. In response to user input indicating confirmation of at least a portion of the user data (e.g., one or more user attributes), the widget may provide a registration instrument with an account request to the exchange platform.

[0189] In some embodiments, process 600 includes generating a matching code at step / operation 614. In some examples, the exchange platform (e.g., its connection service, partner service, etc.) may generate the matching code. In some examples, the matching code may be generated in response to a user input indicating confirmation of at least one portion of user data and / or a registration instrument with an account request indicating confirmation. The exchange platform (e.g., its connection service, partner service, etc.) may generate the matching code to authenticate the user.

[0190] In some embodiments, the matching code is a session-specific identifier for authorizing a registration session between one or more entities. The matching code may include a series of numeric, alphanumeric, and / or similar characters that may be provided to multiple entities to ensure, for example, that each of the entities is participating in the same communication sequence. By way of example, the matching code may include a sequence of one or more different characters of dynamic length (e.g., six, eight characters, etc.) that may be generated by the exchange platform, provided to the service provider platform, and then received from the partner platform to ensure that the exchange platform, service provider platform, and partner platform are each interacting with the same end user (e.g., by comparing the received matching code with a generated matching code as described herein). The one or more different characters may include one or more alphanumeric characters, emojis, kanji characters, wingdings, and / or the like.

[0191] In some embodiments, process 600 includes, at step / operation 616, providing a registration request with the matching code to a service provider platform corresponding to the service provider instrument. For example, an exchange platform (e.g., its service provider service) can use a service provider interface to provide a registration request corresponding to the service provider instrument to the service provider platform. The registration request can include service provider registration data indicating the matching code, one or more user identifiers of the user, and / or one or more instrument identifiers of the service provider instrument. In response to the registration request, the service provider platform can validate the service provider instrument using the one or more identifiers.

[0192] The service provider registration data may include, for example, one or more identifiers for referencing the service provider instrument during communication between the exchange platform, the service provider platform, and / or the partner platform without using the service provider instrument's persistent credentials (e.g., card number, account number, etc.). The one or more identifiers may include various combinations of user identifiers and / or instrument identifiers, for example, for validating the user and / or instrument through one or more redundancy checks. For example, a user identifier for a user may include a user reference for the service provider platform and / or a user key from the exchange platform corresponding to the user reference. As another example, an instrument identifier for a service provider instrument may include an instrument reference for the service provider platform and / or an instrument key from the exchange platform corresponding to the instrument reference.

[0193] The service provider registration data may include any combination of references, keys, and / or identifiers described herein. In one example, the service provider registration data may include one of an instrument reference, an instrument key, a user reference, and / or a user key. Additionally or alternatively, the service provider registration data may include a corresponding combination of instrument references, instrument keys, user references, and user keys for inherent redundancy. In some examples, the identifier combination may be specified by an interface call. The combination may be service provider-specific and / or may change dynamically according to a communication scheme. In this manner, the specific combination of identifiers provided in the registration request may be utilized as an additional validation check to ensure that the registration request is received from an attached platform, such as an exchange platform.

[0194] The service provider may compare the identifier from the registration request with one or more member data objects (e.g., member instrument data objects, member user data objects, etc.) to identify the service provider instrument that corresponds to the registration request without exposing the service provider instrument's persistent credentials.

[0195] In some embodiments, process 600 includes receiving a matching code from a partner platform at step / operation 618. For example, the exchange platform may use a partner API to receive an authentication message including the matching code and / or a session identifier. The authentication message may be received from the partner platform in response to user input to a registration user interface.

[0196] The exchange platform can compare the matching code with previously generated matching codes to authenticate the user. For example, the service provider platform can be configured to provide the matching code to the user through one or more pre-existing communication protocols between the service provider platform and the user (e.g., via a service provider application, a registered phone number, an email address, etc.). When the exchange platform receives the matching code from the partner platform, the exchange platform can verify that the user interacting with the partner platform is an authorized user of the service provider.

[0197] In some examples, the exchange platform can initiate presentation of an authentication user screen using the partner interface and via the registration user interface. At substantially the same time, the service provider platform can provide a matching code to the user (e.g., via the client device and / or other pre-configured means). The user can enter the matching code (e.g., received from the service provider platform) through the authentication user screen, and the partner platform can forward the matching code to the exchange platform. The exchange platform can use the partner interface to receive an authentication message based at least in part on the user input to the authentication user screen.

[0198] In some embodiments, the exchange platform authorizes the registration session in response to authenticating the user based at least in part on the matching code. As described in further detail with reference to Figure 6C, upon successful registration, control is returned to the partner application running on the client device, which requests the UUEK.

[0199] Referring now to FIG. 6C, FIG. 6C is a flowchart illustrating an example of a third stage of a registration process 600 for issuing a UUEK to facilitate credential-less exchange of value. The flowchart depicts communication techniques for overcoming various limitations of conventional registration systems by bypassing the conventional systems' reliance on an instrument reference, such as a card number and / or the like, provided by a user. The communication techniques may be performed by one or more computing devices, entities, and / or systems described herein, such as an exchange platform, to establish a user instrument record for registering the user with the exchange platform.

[0200] In some embodiments, process 600 includes, at step / operation 620, validating a registration session based at least in part on the session identifier. For example, the exchange platform may receive a session exchange request via a partner interface to exchange session identifiers for UUEKs. The session exchange request may include a session identifier and a member instrument reference for the service provider instrument. The member instrument reference may include a partner-specific reference for the service provider instrument. The exchange platform (e.g., its partner service) may receive the session exchange request, validate the session identifier (e.g., via its connectivity service, partner service, etc.) by comparing the session identifier with a previously generated session identifier, and, in response to a match, validate the registration session.

[0201] In some embodiments, process 600 includes generating a UUEK at step / operation 622. For example, the exchange platform may generate the UUEK in response to validating a registration session. By way of example, the exchange platform may generate UUEKs corresponding to a user, a service provider instrument, and a partner platform. The exchange platform may store the UUEK in a partner-specific exchange data object that associates the UUEK with an exchange identifier, an instrument key, and a partner-specific instrument reference, as described herein.

[0202] In some embodiments, process 600 includes providing the UUEK to a partner platform at step / operation 624. For example, the exchange platform may use a partner interface to provide data indicative of the UUEK to the partner platform. In some examples, the partner platform may provide the UUEK and / or a representation thereof to a user (e.g., for storage in a virtual wallet, etc.). By way of example, the UUEK may be represented in one or more different forms, such as a machine-readable optical image (e.g., a barcode, a quick response code, etc.), a keyword, a virtual widget, and / or the like.

[0203] 7A-7D provide message flow diagrams illustrating steps / actions for establishing cross-entity relationships with respect to FIGS. 6A-6C. As will be appreciated, these may be performed and accomplished by corresponding steps / actions in FIGS. 6A-6C. In general, the steps / actions for establishing a secure communication session with a user through a partner application, as illustrated in FIGS. 7A-7B, may be applicable and / or related to the steps / actions in FIG. 6A. For example, the steps / actions illustrated in FIGS. 7A-7B may correspond to and / or relate to certain actions in the first phase of registration process 600 for registering a service provider instrument with a partner platform without disclosing persistent credentials associated with the user and / or the service provider instrument.

[0204] In step / action 702, partner application 416 fetches a widget (e.g., a set of instructions such as a JavaScript widget) from connection service 408. In step / action 704, connection service 408 returns the widget and creates a session. In various embodiments, step / action 704 is performed in response to step / action 702.

[0205] In step / action 706, the partner application 416 starts the widget with the partner platform 420 (e.g., a host, etc.). In step / action 708, the partner platform 420 initializes the widget by calling a widget initialization function of the partner service 410 using a partner interface (e.g., an Initialize-widget call, etc.). In some examples, the widget initialization call can include user data, such as one or more user attributes. In step / action 710, the partner service 410 retrieves and initializes the widget by calling the connection service 408 using a partner interface (e.g., an Initialize-widget call, etc.). In various embodiments, step / action 710 is performed in response to step / action 708.

[0206] In step / action 712, the connection service 408 stores a partner identifier for the corresponding partner in the partner platform 420. In step / action 714, the connection service 408 stores user data for the user. In step / action 716, the connection service 408 generates a session identifier for identifying the communication session between the partner and the exchange platform. In step / action 718, the connection service 408 provides the session identifier to the partner service 410. In step / action 720, the partner service 410 returns the session identifier to the partner platform 420. In step / action 722, the partner platform 420 returns the session identifier to the partner application 416. In various embodiments, a communication session may be initialized during step / action 722.

[0207] 7B, in step / action 728, the partner application 416 executes the widget 724 and hands over control to the widget 724 to continue the registration process. The widget 724 is provided with a session identifier and user data. In step / action 730, the widget 724 sets the session identifier. In step / action 732, the widget 724 sets the user data. In step / action 734, the widget 724 uses the partner interface to request a public key from the connectivity service 408. In step / action 736, the connectivity service 408 returns the public key to the widget 724. In step / action 738, the widget 724 uses the partner interface to request a service provider list from the connectivity service 408. In step / action 740, the connectivity service 408 returns the service provider list. In some examples, in step / operation 742, the widget 724 returns the service provider list to the partner application 416 for presentation to the user (eg, via the client device).

[0208] Turning to Figure 7C, after establishing a secure communication session with the partner application, the registration process may proceed to a second phase, illustrated by the steps / actions of Figure 7C. In general, the steps / actions illustrated in Figure 7C may be applicable and / or related to the steps / actions of Figure 6B. For example, the steps / actions illustrated in Figure 7C may correspond to and / or relate to certain actions of the second phase of registration process 600 for registering a service provider instrument with a partner platform without disclosing persistent credentials associated with the user and / or the service provider instrument.

[0209] In step / action 744, the partner application 416 receives input indicating a service provider from the service provider list and sends the service provider identifier to the widget 724. In step / action 746, the widget 724 sends a request to the connectivity service 408 using a partner interface (e.g., a widget register instrument initiate call) to initiate registration of the service provider instrument with the service provider platform. The request may include a service provider identifier (e.g., a service provider partition). In step / action 748, the connectivity service 408 requests an instrument list corresponding to the user and the service provider using a partner interface (e.g., a widget register instrument initiate call). In step / action 750, the service provider service 412 returns the instrument list to the connectivity service 408. In step / action 752, the connection service 408 returns the instrument list to the widget 724, which may provide the user with a pre-registration screen showing the instrument list (e.g., one or more instrument representations thereof).

[0210] In step / action 754, the widget 724 receives input indicating a service provider instrument (e.g., an instrument expression, etc.). In step / action 756, the widget 724 verifies user data for the user (e.g., via one or more user verification screens, etc.). In step / action 758, the widget 724 provides a request to register the service provider instrument to the connectivity service 408 using a partner interface (e.g., a widget registration instrument with account call, etc.). In various embodiments, step / action 758 is performed in response to the verification of the user data in step / action 756.

[0211] In step / action 760, the connectivity service 408 generates a matching code. In step / action 762, the connectivity service 408 provides a request to the service provider service 412 to register the service provider instrument using a partner interface (e.g., a widget registration instrument with account call, etc.). The request may include the matching code and a session identifier. In step / action 764, the service provider service 412 provides a request to the service provider platform 440 to register the service provider instrument using a service provider interface (e.g., an enroll user instrument call, etc.). The request may include an instrument reference, a user reference, a user key, an instrument key, and / or the matching code. The service provider platform 440 registers the service provider instrument and, in step / action 766, may provide a successful registration response to the service provider service 412 using the service provider interface. In step / action 768, the service provider service 412 provides data indicative of the successful registration response to the connectivity service 408. In step / action 770, the connectivity service 408 provides data indicative of the successful registration response to the widget 724.

[0212] Meanwhile, in step / operation 772, service provider platform 440 provides a matching code to the user using one or more pre-existing communication channels, and the user can access the matching code and enter it into a verification interface presented by widget 724 in step / operation 774.

[0213] In step / action 776, the widget 724 uses the partner interface to provide a registration completion response to the connectivity service 408. In various embodiments, step / action 776 is performed in response to verifying the matching code provided in step / action 774.

[0214] At step / action 778, the connectivity service 408 provides a response indicating successful registration to the widget 724. At step / action 780, the widget 724 provides data indicating the response to the partner application 416.

[0215] Turning to Figure 7D, after authorizing the user based at least in part on verifying the matching code as described above, the registration process may proceed to a third phase, exemplified by the steps / actions of Figure 7D. In general, the steps / actions illustrated in Figure 7D may be applicable and / or related to the steps / actions of Figure 6C. For example, the steps / actions illustrated in Figure 7D may correspond to and / or relate to certain actions of the third phase of registration process 600 for registering a service provider instrument with a partner platform without disclosing persistent credentials associated with the user and / or the service provider instrument.

[0216] In step / action 782, the partner application 416 provides data to the partner platform 420 indicating successful registration. In step / action 784, the partner platform 420 provides a key request to the partner service 410 using the partner interface. The partner service 410 activates the communication session by providing a session identifier to the connection service 408 in step / action 786. The connection service 408 compares the session identifier with the identifier issued to initiate the communication session, and if the identifiers match, in step / action 788, provides data indicative of the activated session to the partner service 410.

[0217] In step / action 790, the partner service 410 generates a UUEK for the partner and exchanges a session identifier for the UUEK. In step / action 792, the partner service 410 provides the UUEK to the partner platform 420 using the partner interface. In step / action 794, the partner platform 420 can provide an indication that the registration was successful to the partner application 416. In some examples, the indication of successful registration can include a representation of the UUEK, such as a barcode, QR code, and / or the like, to represent the UUEK to the user.

[0218] Thus, having described various operations, processes, methods, functions, and / or the like for enrolling a user for credential-less transactions, various user interface screens are provided and described for controlling, initiating, executing, and / or the like such steps / operations. In various embodiments, the user interface screens provided and described in this disclosure are configured to be provided via a user interface of a client device 104.

[0219] 8A-8F provide example user interface flows configured for a client device 104. The user interface flow may include multiple user interface screens that may be configured to guide a user through a credential-less registration process to facilitate a credential-less exchange between a partner platform and a service provider platform. In some examples, these transactions may be managed through a user account with the partner platform. For example, user interface screen 802 of FIG. 8A includes an account setup screen for entering user attributes 804 for a user account. User interface screen 802 may include a selectable account creation icon 806 for initiating the account creation process. Additionally or alternatively, a user may register with the partner platform through an exchange screen. For example, user interface screen 808 of FIG. 8B includes a registration setup screen for entering one or more user attributes 804 through a widget executed by a partner application. User interface screen 808 of FIG. 8B may include a selectable registration navigation 810 for proceeding to the next step in the registration process.

[0220] A step in the registration process may include a user selecting a service provider with a service provider instrument, which may be registered with the partner platform. User interface screen 812 of FIG. 8C may facilitate service provider selection by providing a service provider list 814 of selectable icons. In some examples, service provider list 814 may be automatically matched to user attributes available to the user (e.g., provided through one or more previous user interface screens). Service provider list 814 may, for example, be tailored to the user or, in some examples, may be proactively limited to service providers with which the user is affiliated. As illustrated by user interface screen 812, service providers may include financial institutions, such as banks, and / or the like, for financial-based value exchange. This is provided as one example only. As described herein, the techniques of the present disclosure may be applicable to any value exchange system.

[0221] Upon selecting a service provider, the user may be directed to another user interface screen (not shown) to select the service provider's service provider instrument. Once selected, the exchange platform may execute a registration process to register the service provider instrument with the partner platform. During the registration process, the user may be transitioned to user interface screen 816 of FIG. 8D, which may include a validation prompt 818 for entering a matching code. As shown, user interface screen 820 of FIG. 8E may automatically provide the matching code to the user through a message 822 from the service provider platform. The user can respond to validation prompt 818 by entering the matching code and select submit icon 824 to complete the registration process. The next screen, user interface screen 826 of FIG. 8F, may display a UUEK representation 828 of the user's UUEK. The UUEK representation 828 may include, for example, a scannable representation of the UUEK (e.g., a barcode, a QR code, a non-fungible token, a near field communication sequence, etc.) The scannable representation may be stored in a partner account on a partner platform to enable a user to perform value-based transactions using a service provider instrument without referencing a persistent credential in the service provider instrument.

[0222] FIG. 9 provides a process flow for facilitating credential-less exchange of value according to one or more embodiments of the present disclosure. The process flow depicts a communication and data encryption process 900 for securely authorizing exchanges in a value-agnostic exchange by leveraging a UUEK. Process 900, as described herein, can be utilized to overcome various limitations of traditional exchange systems that expose confidential and persistent credentials to numerous third parties. Process 900 can be implemented by one or more computing devices, entities, and / or systems described herein. For example, through the various steps / operations of process 900, an exchange platform can leverage communication and data encryption techniques to overcome various limitations associated with traditional mechanisms of exchange by removing the reliance on static confidential credentials.

[0223] 9 illustrates an illustrative example process 900. Although the example process 900 depicts a particular sequence of steps / actions, the sequence may be varied without departing from the scope of the present disclosure. For example, some of the depicted steps / actions may be performed in parallel or in a different sequence without substantially impacting the functionality of the process 900. In other examples, different components of the example device or system performing the process 900 may perform functions substantially simultaneously or in a particular sequence.

[0224] In some examples, process 900 begins after registration process 600 of FIGS. 6A-6C, where a user and / or partner platform can receive a UUEK for facilitating a credential-less exchange of value. Nevertheless, process 900 may also be performed before registration process 600. For example, a user can obtain a UUEK directly from a service provider platform instead of completing a registration process for the partner platform. If registration process 600 is completed, value-based exchange may be facilitated by the partner platform using a partner interface and a UUEK specific to the partner platform; otherwise, value-based exchange may be facilitated by the partner platform using a UUEK specific to and provided by the service provider platform.

[0225] For example, when a user wishes to conduct a value-based exchange with a partner with whom the user has a registered partner account, the partner platform may search the registered partner accounts and identify the user's issued UUEK from the partner account for use in authorizing the value-based exchange. When a user wishes to conduct a value-based exchange with a partner with whom the user does not have a registered partner account, the user may present a previously issued UUEK (e.g., issued to a service provider platform) to the partner platform (e.g., through a partner application), and the partner platform may use the UUEK to authorize the value-based exchange.

[0226] The partner platform can generate an exchange request data object for performing a value-based exchange based at least in part on the UUEK for a particular use case (e.g., a partner UUEK when the user has a registered account, a service provider UUEK when the user does not have a registered account, etc.). The exchange request data object can include request data identifying the UUEK and transaction attributes of the requested value-based exchange. Process 900 can begin when the partner platform issues an exchange request based at least in part on the exchange request data object.

[0227] In some embodiments, process 900 includes receiving an exchange request with a UUEK at step / operation 902. For example, an exchange platform (e.g., its partner services, etc.) may receive an exchange request to conduct a value-based exchange using a partner interface. The exchange request may indicate the UUEK and / or one or more transaction attributes.

[0228] The trade attributes may indicate one or more characteristics of the requested exchange. For example, the one or more trade attributes may include at least one trade attribute indicating a trade value (e.g., a basket amount, etc.). The trade value may include, for example, the sum of one or more line items in a financial exchange, including one or more modifiers, such as taxes, discounts, and / or the like. Continuing with the example of a financial-based value system, in some examples, the transaction attributes may include (i) an order number, (ii) one or more line item attributes including a sequence, a line item group, a product code, a description, a quantity, a unit-item, gram, kilogram, etc., a unit quantity, a unit tax amount, a line quantity (e.g., a line item quantity), a line tax amount, etc., and / or (iii) one or more line item adjustments including a sequence, an adjustment type (e.g., a manufacturing discount, a store discount, a return, a pay cash, a pay gift card, a pay other, etc.), a product code, a description, a quantity, a unit-item, gram, kilogram, etc., a unit quantity, a unit tax amount, a line quantity (e.g., a line item quantity), a line tax amount, and / or the like.

[0229] Additionally or alternatively, the transaction attributes may include a request approval type (e.g., full or partial), a partner transaction reference (e.g., a reference to the partner platform for the transaction), a channel (e.g., a type of exchange in the case of a financial value system such as push or pull value transfer, real-time payment, etc.), a currency (e.g., in the case of a financial value system), an organization key (e.g., a platform identifier for the partner organization), an organization category (e.g., airline, apparel, etc.), a facility key (e.g., a platform identifier for a retail location, etc.), a store associate identifier, and / or any other traceable information for a value-based exchange.

[0230] In some embodiments, process 900 includes validating the UUEK at step / operation 904. For example, the exchange platform (e.g., its partner service) can look up the UUEK to identify a matching identifier from the platform data vault 414. For example, the UUEK can include an exchange identifier corresponding to an exchange data object. The exchange platform can identify the exchange identifier based at least in part on the UUEK and utilize the exchange identifier to identify the corresponding exchange data object.

[0231] As described herein, the UUEK may correspond to a partner platform and / or a service provider platform. As an example, the UUEK may include a partner partition that identifies the partner platform if the UUEK is issued to the partner platform. In such a case, the UUEK includes an exchange identifier corresponding to the partner exchange data object. As another example, the UUEK may include a service provider partition that identifies the service provider platform if the UUEK is issued to the service provider platform. In such a case, the UUEK includes an exchange identifier corresponding to the service provider exchange data object. In some examples, the exchange platform may process the UUEK based at least in part on the entity partition.

[0232] In some embodiments, the exchange platform (e.g., its partner service) receives a UUEK that includes a partner partition that identifies the partner platform. The exchange platform can use the exchange identifier to identify a partner-specific exchange data object. The partner-specific exchange data object can include an instrument key corresponding to a service provider instrument of the member platform. The exchange platform can identify a system instrument data object based at least in part on the instrument key. For example, the exchange platform can identify the member platform based at least in part on the entity partition of the instrument key and provide the instrument key to a service (e.g., a service provider service, etc.) corresponding to the member platform. The service can identify a system instrument data object based at least in part on the instrument key. The system instrument data object can then be utilized to identify one or more identifiers (e.g., a user identifier, an instrument identifier, etc.) for processing the exchange request.

[0233] In some embodiments, an exchange platform (e.g., its partner service, etc.) receives a UUEK that includes a service provider partition that identifies a service provider platform. The exchange platform (e.g., its partner service, etc.) can determine that the partner-specific exchange data object is unavailable. In response to this determination, the exchange platform can identify a member platform based at least in part on the service provider partition and provide the UUEK to a service (e.g., service provider service, etc.) corresponding to the member platform. The service can identify a service provider-specific exchange data object based at least in part on the exchange identifier in the UUEK. The service provider-specific exchange data object can be utilized to identify a system instrument data object based at least in part on the member platform and exchange identifier. The system instrument data object can then be utilized to identify one or more identifiers (e.g., a user identifier, an instrument identifier, etc.) for processing the exchange request.

[0234] In some examples, the exchange platform may perform one or more validation actions on the UUEK. For example, the exchange data object may include one or more exchange attributes that indicate a revocation status. In some examples, the revocation status may indicate (i) whether the UUEK has previously been used to authorize a value-based exchange and / or (ii) a validity period during which the UUEK may be valid. The validation action may include identifying a revocation status corresponding to the UUEK and validating the UUEK based at least in part on the revocation status. As an example, the exchange platform may validate the UUEK if the revocation status indicates that (i) the UUEK has not previously been used to authorize a value-based exchange and / or (ii) the UUEK was presented within the validity period.

[0235] In some examples, the validation action may include verifying that the originator of the UUEK accompanies the original entity to which the UUEK was issued. In some examples, the UUEK may include an entity partition indicating the original entity to which the UUEK was issued (e.g., a member platform, such as a partner or service provider platform). The exchange platform may utilize the entity partition of the UUEK to determine the entity (e.g., the original entity) corresponding to the UUEK. In some examples, the validation action may include verifying that the originator of the exchange request matches and / or accompanies the original entity of the UUEK. In response to determining that the originator is the original entity, the exchange platform may validate the UUEK.

[0236] If the UUEK is verified, process 900 may proceed to step / action 906. Otherwise, process 900 may proceed to step / action 914, where the exchange platform provides an error response to the partner platform using the partner interface.

[0237] In some embodiments, process 900 includes, at step / operation 906, requesting exchange authorization from a member platform. For example, the exchange platform (e.g., its service provider service) may request exchange authorization from the service provider platform for a service provider instrument correlated to the UUEK. In some examples, the exchange platform (e.g., its partner service) may identify the member platform based at least in part on the UUEK (e.g., its entity partition). Additionally or alternatively, the exchange platform (e.g., its service provider service) may identify the service provider instrument based at least in part on the UUEK (e.g., exchange identifier).

[0238] The exchange platform (e.g., its service provider service) can provide an exchange authorization request to a member platform using a service provider interface. The exchange authorization request may indicate at least one of one or more transaction attributes and / or an instrument identifier of a service provider instrument. By way of example, the exchange platform can generate an exchange authorization request based at least in part on a system instrument data object identified from one or more aspects of the UUEK. The exchange authorization request can include an instrument key and / or an instrument reference from the system instrument data object.

[0239] In some examples, the exchange authorization request may indicate a user identifier associated with the service provider instrument. For example, the exchange platform may generate an exchange authorization request based at least in part on a system user data object identified from one or more aspects of the UUEK. In some examples, the system user data object may be identified based at least in part on a user identifier (e.g., a system user identifier) ​​of the exchange data object. Additionally or alternatively, the system user data object may be identified based at least in part on a user identifier (e.g., a system user identifier) ​​of the system instrument data object. In some examples, the exchange authorization request may include a user key and / or a user reference from the system user data object.

[0240] Additionally or alternatively, the transaction authorization request may indicate a transaction identifier. By way of example, the exchange platform may generate a transaction identifier to represent the value-based exchange and provide the transaction identifier to the member platform.

[0241] In some embodiments, process 900 includes, at step / operation 908, receiving an exchange authorization response. For example, the exchange platform (e.g., its service provider service) can use a service provider interface to receive the exchange authorization response indicating at least one of transaction approval and / or transaction denial. In some embodiments, the exchange authorization response is based at least in part on a comparison between the value of the transaction and asset availability of the service provider instrument. For example, in response to receiving an exchange authorization request, the member platform can be configured to compare the value of the transaction with asset availability of the identified service provider instrument. The value-based exchange may be authorized (e.g., resulting in transaction approval) if asset availability exceeds the value of the transaction; otherwise, the exchange may be denied (e.g., resulting in transaction denial).

[0242] In some examples, the replacement authority response may indicate one or more response attributes, which may include one or more error codes and / or the like, for characterizing the replacement authority response.

[0243] The exchange platform may generate a transaction record for the value-based exchange based at least in part on the exchange authority request and / or the exchange authority response. In some examples, the transaction record may indicate a transaction identifier, one or more transaction attributes, one or more response attributes, the exchange authority response, one or more instruments and / or user identifiers, and / or any other data related to the value-based exchange. In some examples, the exchange platform may store the transaction record in a platform data vault in association with the one or more instruments and / or user identifiers.

[0244] In some embodiments, process 900 optionally includes generating a replacement UUEK at step / action 910. For example, the exchange platform may automatically generate a replacement UUEK to replace the received UUEK.

[0245] In some examples, this may include (i) invalidating the received UUEK for future authorization requests and / or (ii) generating a replacement UUEK. For example, the exchange platform may modify the revocation status of the UUEK to invalidate the UUEK for subsequent value exchanges. Additionally or alternatively, the exchange platform may transfer, delete, and / or otherwise modify the exchange data object corresponding to the UUEK to invalidate the UUEK. The replacement UUEK may include a new unique exchange identifier (e.g., a different universally unique identifier) ​​corresponding to the service provider instrument to replace the invalidated exchange identifier. In this manner, the UUEK may be continually modified and changed as users complete exchanges across different platforms, thereby limiting user and platform exposure to malicious parties.

[0246] In some embodiments, process 900 includes, at step / operation 912, providing an exchange response to a member platform. For example, the exchange platform (e.g., its partner service) can provide the exchange response to a member platform, such as a partner platform, using a partner interface. The exchange response can be based at least in part on the exchange authorization response. For example, the exchange response may indicate transaction approval and / or transaction denial. In some examples, the exchange response may indicate a replacement UUEK (if generated), one or more transaction attributes, a transaction identifier, and / or one or more response attributes. In some examples, the member platform can be configured to replace the UUEK with the replacement UUEK. For example, the exchange response can be provided to the partner platform. The partner platform can receive the exchange response and replace the UUEK with the replacement UUEK.

[0247] 10 and 11 provide message flow diagrams illustrating steps / actions with respect to FIG. 9 for facilitating a credential-less exchange of value in accordance with one or more embodiments of the present disclosure. As will be appreciated, these may be performed and accomplished with corresponding steps / actions in FIG. 9. FIG. 10 may, for example, illustrate a first message flow for facilitating a credential-less exchange through a registered partner account, while FIG. 11 may illustrate a second message flow for facilitating a credential-less transaction without a registered partner account.

[0248] In the first message flow, at step / action 1004, a user initiates a transaction through a registered partner account. At step / action 1006, partner platform 420 retrieves the user's UUEK to execute the transaction on the user's behalf. At step / action 1008, partner platform 420 uses a partner interface to provide an exchange request to at least one of a plurality of partner services 410 of an exchange platform corresponding to partner platform 420. The exchange request may indicate the UUEK for the value-based exchange and / or one or more transaction attributes.

[0249] In step / action 1010, the partner service 410 looks up the partner-specific transaction token (e.g., in a partner-specific data store, such as a portion of a platform data vault) to determine the member platform that corresponds to the UUEK (e.g., via a mapping to a service provider partition, etc.). In step / action 1012, the partner service 410 provides data indicative of the exchange request to the service provider service 412 of the exchange platform that corresponds to the member platform.

[0250] In step / action 1014, the service provider service 412 verifies the UUEK (and / or its exchange identifier). In step / action 1016, the service provider service 412 uses a service provider interface to provide an exchange authorization request to the service provider platform 440. The exchange authorization request can include one or more keys (e.g., user keys, instrument keys, etc.), references (e.g., instrument references, user references, etc.), and / or one or more transaction attributes.

[0251] In step / action 1018, the service provider platform 440 approves the transaction and provides an exchange authorization response to the service provider service 412 using a service provider interface. In step / action 1020, the service provider service 412 records the value-based exchange in association with one or more keys (e.g., user keys, instrument keys, etc.), references (e.g., instrument references, user references, etc.), and / or the like. In step / action 1022, the service provider service 412 provides the exchange authorization response to the partner service 410. The partner service 410 provides the exchange response to the partner platform 420 using a partner interface in step / action 1024.

[0252] In the second message flow, in step / action 1102, the user 1002 initiates a transaction by presenting the UUEK (and / or a representation of the UUEK) to the partner platform 420. In step / action 1104, the partner platform 420 uses a partner interface to provide an exchange request to the partner service 410 of the exchange platform corresponding to the partner platform 420. The exchange request may identify the UUEK for the value-based exchange and / or one or more transaction attributes.

[0253] In step / action 1106, partner service 410 looks up the exchange identifier (e.g., in a partner-specific data store, such as part of a platform data vault) to determine whether an exchange data object exists. If the exchange identifier does not exist, in step / action 1108, partner service 410 provides the UUEK to exchange platform service provider service 412 that corresponds to the service provider platform identified from the UUEK.

[0254] In step / action 1110, the service provider service 412 verifies the exchange identifier of the UUEK. In step / action 1112, the service provider service 412 uses a service provider interface to provide an exchange authorization request to the service provider platform 440. The exchange authorization request can include one or more keys (e.g., user keys, instrument keys, etc.), references (e.g., instrument references, user references, etc.), and / or one or more transaction attributes.

[0255] In step / act 1114, the service provider platform 440 approves the exchange and provides an exchange authorization response to the service provider service 412 using the service provider interface. In step / act 1116, the service provider service 412 records the transaction in association with one or more keys (e.g., user keys, instrument keys, etc.), references (e.g., instrument references, user references, etc.), etc. In step / act 1118, the service provider service 412 provides an exchange authorization response indicating the response to the partner service 410. The partner service 410 provides the exchange response to the partner platform 420 using the partner interface in step / act 1120.

[0256] Thus, having described various operations, processes, methods, functions, and / or the like for handling exchanges on behalf of a user, various user interface screens are provided and described for controlling, initiating, executing, and / or the like such steps / operations. In various embodiments, the user interface screens provided and described in this disclosure are configured to be provided via a user interface of a client device 104.

[0257] 12A-12D provide exemplary user interface flows configured for a client device 104. The user interface may be configured to guide a user through a credential-less exchange process to facilitate a value-based exchange between one or more member platforms without disclosing the confidential and persistent credentials of the service provider instruments used to execute the value-based exchange. The credential-less exchange process may begin when a user selects a payment method from a partner application's transaction processing screen 1202, as illustrated by FIG. 12A. Upon selection of a payment method facilitated by the exchange platform, the user may be transitioned to an instrument selection screen 1204, as illustrated by FIG. 12B. The instrument selection screen 1204 may include multiple selectable instrument icons 1206, each of which may be associated with a UUEK issued by the exchange platform using various techniques described herein. The user may execute the exchange by selecting one or more of the selectable instrument icons 1206.

[0258] In some examples, in response to a selection, a scan screen 1208 may be provided for in-store transactions. The scan screen 1208 may present a scannable UUEK representation 1210 corresponding to the UUEK. The user may scan the scannable UUEK representation 1210 to complete the value-based exchange. Additionally or alternatively, in an online environment, the user may be transitioned to a verification user screen 1212 to provide a personal identification number (PIN) associated with the service provider instrument. The user may enter the PIN to complete the transaction.

[0259] VI. Conclusion Many modifications and other embodiments will come to mind to one skilled in the art to which this disclosure pertains having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. It is to be understood, therefore, that the disclosure is not limited to the particular embodiments disclosed, and that modifications and other embodiments are intended to be included within the scope of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

Claims

1. receiving, by one or more processors and using a partner interface, an exchange request for conducting a value-based exchange, said exchange request indicating a universally unique ephemeral key (UUEK) and one or more transaction attributes; identifying, by the one or more processors, an exchange identifier based at least in part on the UUEK, the exchange identifier corresponding to an exchange data object comprising an instrument identifier of a service provider instrument of a member platform; providing, by the one or more processors and using a service provider interface, an exchange authorization request to the member platform, the exchange authorization request indicating the one or more trading attributes and the instrument identifier; receiving, by the one or more processors and using the service provider interface, an interchange authorization response indicating at least one of transaction approval or transaction denial; providing, by the one or more processors and using the partner interface, an interchange response based at least in part on the interchange authorization response, the interchange response indicating the transaction approval or the transaction denial; 20. A computer-implemented method comprising:

2. the UUEK comprises a partner partition that identifies a partner platform, the instrument identifier comprises an instrument key of the member platform, and the computer-implemented method comprises: identifying a system instrument data object based at least in part on said instrument key; generating the exchange authorization request based at least in part on the system instrument data object; The computer-implemented method of claim 1 further comprising:

3. The UUEK comprises a service provider partition that identifies a service provider platform, and the computer-implemented method comprises: identifying the member platforms based at least in part on the service provider partition; identifying a system instrument data object based at least in part on the member platform and the exchange identifier; generating the exchange authorization request based at least in part on the system instrument data object; The computer-implemented method of claim 1 , comprising:

4. The exchange data object comprises one or more exchange attributes indicating a revocation status, and the computer-implemented method comprises: Validating the UUEK based at least in part on the revocation status. The computer-implemented method of claim 1 further comprising:

5. modifying the revocation status to invalidate the UUEK. The computer-implemented method of claim 4 further comprising:

6. 2. The computer-implemented method of claim 1, wherein the exchange authorization request indicates a user identifier corresponding to the exchange data object.

7. 7. The computer-implemented method of claim 6, wherein the user identifier comprises a user key corresponding to a system user identifier, and the instrument identifier comprises an instrument key corresponding to a system instrument identifier.

8. generating a transaction record of said value-based exchange; storing said transaction record in a platform data vault in association with said instrument identifier and said user identifier; The computer-implemented method of claim 6 further comprising:

9. 9. The computer-implemented method of claim 8, wherein the transaction record indicates a transaction identifier, the one or more transaction attributes, and the exchange authorization response.

10. 2. The computer-implemented method of claim 1, wherein the one or more transaction attributes comprise at least one transaction attribute indicative of a transaction value, and wherein the exchange authorization response is based at least in part on a comparison between the transaction value and asset availability of the service provider instrument.

11. generating a replacement UUEK for the service provider instrument, wherein the exchange response indicates the replacement UUEK; The computer-implemented method of claim 1 further comprising:

12. 12. The computer-implemented method of claim 11, wherein the exchange response is provided to a partner platform, the partner platform configured to replace the UUEK with the replacement UUEK.

13. 13. The computer-implemented method of claim 12, wherein the UUEK comprises a universally unique identifier and the replacement UUEK comprises a different universally unique identifier.

14. 1. A computing system comprising: a memory; and one or more processors communicatively coupled to the memory, the one or more processors: receiving, using a partner interface, an exchange request for conducting a value-based exchange, the exchange request indicating a universally unique ephemeral key (UUEK) and one or more transaction attributes; identifying an exchange identifier based at least in part on the UUEK, the exchange identifier corresponding to an exchange data object comprising an instrument identifier of a service provider instrument of a member platform; providing an exchange authorization request to the member platform using a service provider interface, the exchange authorization request indicating the one or more trading attributes and the instrument identifier; receiving, using the service provider interface, an interchange authorization response indicating at least one of a transaction approval or a transaction denial; providing an interchange response based at least in part on the interchange authorization response using the partner interface, the interchange response indicating the transaction approval or the transaction denial; 1. A computing system configured to:

15. the UUEK comprises a partner partition that identifies a partner platform, the instrument identifier comprises an instrument key of the member platform, and the one or more processors: identifying a system instrument data object based at least in part on said instrument key; generating the exchange authorization request based at least in part on the system instrument data object; 15. The computing system of claim 14, further configured to:

16. the UUEK comprises a service provider partition that identifies a service provider platform, and the one or more processors: identifying the member platforms based at least in part on the service provider partition; identifying a system instrument data object based at least in part on the member platform and the exchange identifier; generating the exchange authorization request based at least in part on the system instrument data object; 15. The computing system of claim 14, further configured to:

17. the exchange data object comprises one or more exchange attributes indicating a revocation status, and the one or more processors: Validating the UUEK based at least in part on the revocation status.

15. The computing system of claim 14, further configured to:

18. 20. The computing system of claim 17, wherein the one or more processors are further configured to modify the revocation status to invalidate the UUEK.

19. When executed by one or more processors, receiving, using a partner interface, an exchange request for conducting a value-based exchange, the exchange request indicating a universally unique ephemeral key (UUEK) and one or more transaction attributes; identifying an exchange identifier based at least in part on the UUEK, the exchange identifier corresponding to an exchange data object comprising an instrument identifier of a service provider instrument of a member platform; providing an exchange authorization request to the member platform using a service provider interface, the exchange authorization request indicating the one or more trading attributes and the instrument identifier; receiving, using the service provider interface, an interchange authorization response indicating at least one of a transaction approval or a transaction denial; providing an interchange response based at least in part on the interchange authorization response using the partner interface, the interchange response indicating the transaction approval or the transaction denial; one or more non-transitory computer-readable storage media comprising instructions that cause the one or more processors to:

20. 20. The one or more non-transitory computer-readable storage media of claim 19, wherein the exchange authority request indicates a user identifier corresponding to the exchange data object.

Citation Information

Patent Citations

  • Settlement system and settlement method

    JP2008204248A

  • Authentication system, authentication server and authentication method using one-time password

    JP2011107791A

  • Settlement method using onetime response code and settlement server for executing the same method and undertaker terminal

    JP2013171580A