Computer execution method, computing system, and computer-readable storage medium
Patent Information
- Application Number
- JP2024568486
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-06-05
- Filing Date
- 2023-08-03
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2043-08-03
AI Technical Summary
【0007】 本開示の様々な実施形態は、永続的クレデンシャルの使用をなくすためにUUEK(汎用一意的な一時キー;Universally Unique Ephemeral Key)を活用する、価値ベース交換(exchange)のクレデンシャル不要な実行を容易にする、セキュアな中間コンピューティング·プラットフォームおよびコンピューティング·サービスを開示する。そうするために、中間コンピューティング·プラットフォームは、本明細書でUUEKと呼ばれる新しい一時的なデータ構造によって強化された価値交換システムにユーザインストルメント(instrument)を登録するための、1つまたは複数のメンバ·プラットフォーム間の対話を容易にすることができる。従来の登録システムと違い、中間コンピューティング·プラットフォームは、ユーザのインストルメントを登録するために、永続的なユーザまたはインストルメントクレデンシャルを受け取ることも、これに依存することもない。このようなクレデンシャルの排除は、プロセスにおけるどのステップでもユーザクレデンシャルを公開することなく、ユーザのインストルメントを登録するために異なるネットワーク·メンバと通信するための中間コンピューティング·プラットフォームによって活用される、本明細書で説明されるアプリケーション·プログラミング·インターフェース(API:application programming interface)などの、新しくより柔軟なインターフェースの使用を可能にする。登録されると、中間コンピューティング·プラットフォームは、従来の永続的クレデンシャルを置き換え得るUUEKを、メンバ·プラットフォームに発行することができる。発行されたUUEKは、永続的クレデンシャル、または何らかの他の極秘のユーザもしくはインストルメント情報を反映したものではない。メンバ·プラットフォームと中間プラットフォームとの間のインターフェースは、(i)ユーザが、発行されたUUEKを(永続的クレデンシャルへの明示的な言及がなくても)メンバ·プラットフォームから中間プラットフォームに提示することと、(ii)中間プラットフォームが、発行されたUUEKを同じまたは別のメンバ·プラットフォーム用のインストルメントキーにマッピングし、価値ベース交換の権限を付与するためにインストルメントキーをメンバ·プラットフォームに提供することとを、可能にすることができる。このように、ネットワーク·ベース取引は、ネットワーク攻撃の影響を受けやすくなり得る極秘のユーザまたはインストルメント情報を公開することなく、シームレスなプロセスで権限を付与され得る。最後に、これは、従来技術に対してコンピューティング電力要件を低減させ、交換処理のための著しく大きなネットワーク·スループットを可能にしつつ、(例えば、新しいインターフェースの使用などを通じた)さらなる柔軟性、および(例えば、永続的クレデンシャルの排除などを通じた)セキュリティを可能にする。
Smart Images

Figure 0007914239000001 
Figure 0007914239000002 
Figure 0007914239000003
Abstract
Description
Technical Field
[0001] Cross-Reference to Related Applications This application claims the benefit of U.S. Provisional Patent Application No. 63 / 370,280 filed on August 3, 2022, U.S. Provisional Patent Application No. 63 / 370,279 filed on August 3, 2022, and U.S. Patent Application No. 18 / 329,101 filed on June 5, 2023, each of which is incorporated herein by reference in its entirety, including any drawings, tables, figures, and addenda.
[0002] Embodiments of the present disclosure generally relate to credential-free exchange of value between multiple entities in a value system.
Background Art
[0003] Various embodiments of the present disclosure address technical problems related to network-based value transactions, taking into account the limitations of existing transaction processing technologies and architectures. Existing processes for executing transactions over computing networks rely on the use of persistent credentials, such as payment credentials (e.g., card numbers, usernames, passwords, bank branch codes, account numbers, etc.) and their power of attorney, which expose credential recipients to fraud, regulatory and compliance costs, and reputational risks. Furthermore, due to the static nature of conventional credentials, users must accept the risk of financial loss, damaged credit scores, identity theft, and other consequences every time they provide their credentials to validate a transaction. The inherent risks of persistent credentials have traditionally been addressed using strict communication protocols, data governance procedures, and authentication schemes, each of which introduces additional technical problems by adding overhead and complicating network-based transactions without solving the underlying technical problem of data security.
[0004] For example, a traditional service provider managing user accounts can restrict their disclosure by using disclaimers that prevent users from providing their credentials to specific third parties. This leads to network congestion, as a limited number of authorized parties become overloaded with requests from the entire population. Furthermore, authorized parties are required to enroll users by obtaining highly confidential persistent credentials (e.g., username, password, routing / transit credentials) from them, and then manage a robust number of persistent credentials across the entire number of registered users. This presents a single attack vector for a malicious party to obtain highly confidential user information about the user population. To counter such attacks, traditional transaction processing entities are required to employ imperfect, still vulnerable, expensive, resource-intensive, and robust data governance procedures and authentication schemes.
[0005] Other techniques to address data security include restricting exchanged communications, such as those for financial transactions, to rigid messaging standards, such as ISO messaging standards, which are inflexible and, by design, unable to provide contextual data about transactions. Thus, such communication standards improve network security at the expense of transactional functionality.
[0006] The various embodiments of this disclosure make significant contributions to various existing network-based value transaction processing technologies by addressing each of these technical challenges. [Overview of the project] [Means for solving the problem]
[0007] Various embodiments of this disclosure disclose a secure intermediate computing platform and computing services that facilitate credential-free execution of value-based exchanges by leveraging a Universally Unique Ephemeral Key (UUEK) to eliminate the use of persistent credentials. To do so, the intermediate computing platform can facilitate interaction between one or more member platforms for registering user instruments in a value exchange system enhanced by a new temporary data structure called UUEK as described herein. Unlike conventional registration systems, the intermediate computing platform does not receive or rely on persistent user or instrument credentials to register user instruments. This elimination of credentials enables the use of new and more flexible interfaces, such as application programming interfaces (APIs) described herein, which are leveraged by the intermediate computing platform to communicate with different network members to register user instruments without exposing user credentials at any step in the process. Upon registration, the intermediate computing platform can issue a UUEK to the member platform, which can replace traditional persistent credentials. The issued UUEK does not reflect persistent credentials or any other highly confidential user or instrument information.The interface between the member platform and the intermediate platform can enable (i) a user to present an issued UUEK from the member platform to the intermediate platform (without explicit reference to persistent credentials), and (ii) the intermediate platform to map the issued UUEK to an instrument key for the same or a different member platform and provide the instrument key to the member platform to authorize value-based exchange. In this way, network-based transactions can be authorized in a seamless process without exposing highly sensitive user or instrument information that could be vulnerable to network attacks. Finally, this reduces computing power requirements compared to conventional technologies and enables significantly higher network throughput for exchange processing, while also enabling greater flexibility (e.g., through the use of new interfaces) and security (e.g., through the elimination of persistent credentials).
[0008] In some embodiments, the method involves initiating the presentation of a registration user interface via a user's client device using one or more processors and a partner interface, wherein the registration user interface comprises an instrument registration screen showing one or more service provider instruments associated with the user; receiving selection data from the registration user interface indicating the selection of service provider instruments from the registration user interface using one or more processors and a partner interface; generating a matching code for authenticating the user using one or more processors; and providing a service corresponding to the service provider instrument using one or more processors and a service provider interface. Providing a registration request to a provider platform, wherein the registration request comprises service provider registration data indicating a matching code, a user identifier for a user, and an instrument identifier for a service provider instrument; receiving an authentication message comprising a matching code by one or more processors and using a partner interface; and in response to authentication of a user based on the matching code, (i) generating a user UUEK by one or more processors, wherein the UUEK corresponds to the user, the service provider instrument, and the partner platform; and (ii) providing the UUEK to the partner platform by one or more processors and using a partner interface.
[0009] In some embodiments, the computing system includes memory and one or more processors communicatively coupled to the memory, wherein one or more processors initiate the presentation of a registration user interface via a user's client device using a partner interface, the registration user interface comprising an instrument registration screen showing one or more service provider instruments associated with the user, the partner interface receiving selection data indicating the selection of service provider instruments from the registration user interface, generating a matching code for authenticating the user, and the service provider interface providing the service provider The system provides a registration request to a service provider platform corresponding to a Dynstrum, wherein the registration request comprises service provider registration data indicating a matching code, a user identifier for the user, and an instrument identifier for the service provider instrument; the system uses a partner interface to receive an authentication message containing a matching code; and in response to user authentication based on the matching code, the system generates a user UUEK, the UUEK corresponding to the user, the service provider instrument, and the partner platform; and (ii) provides the UUEK to the partner platform using the partner interface.
[0010] When executed by one or more processors, the process involves using a partner interface to initiate the presentation of a registration user interface via the user's client device, wherein the registration user interface includes an instrument registration screen indicating one or more service provider instruments associated with the user; using the partner interface to receive selection data indicating the selection of service provider instruments from the registration user interface; generating a matching code for authenticating the user; and using the service provider interface to provide a registration request to the service provider platform corresponding to the service provider instrument. One or more non-temporary computer-readable storage media comprising instructions causing one or more processors to: provide a registration request comprising service provider registration data indicating a matching code, a user identifier for a user, and an instrument identifier for a service provider instrument; receive an authentication message comprising a matching code using a partner interface; and, in response to authentication of a user based on the matching code, (i) generate a user UUEK, the UUEK corresponding to a user, a service provider instrument, and a partner platform; and (ii) provide the UUEK to the partner platform using a partner interface.
[0011] Having explained this disclosure in general terms, I will now refer to the attached drawings, but these drawings are not necessarily drawn to scale. [Brief explanation of the drawing]
[0012] [Figure 1] This is an illustrative diagram of a computing ecosystem according to one or more embodiments of the present disclosure. [Figure 2]This is an illustrative schematic diagram of a computing platform according to one or more embodiments of the present disclosure. [Figure 3] This is an illustrative schematic diagram of a client device according to one or more embodiments of the present disclosure. [Figure 4] This is an exemplary block diagram of an exemplary value credential-free exchange system according to one or more embodiments of the present disclosure. [Figure 5] This is an exemplary data diagram illustrating how to facilitate value credential-free exchange according to one or more embodiments of the present disclosure. [Figure 6A] This is a process flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 6B] This is a process flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 6C] This is a process flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 7A] A messaging flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 7B] A messaging flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 7C] A messaging flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 7D] A messaging flow for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 8A] This is a diagram illustrating an exemplary interface for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 8B] This is a diagram illustrating an exemplary interface for establishing a cross-entity relationship according to one or more embodiments of the present disclosure. [Figure 8C] It is a diagram of an exemplary interface for establishing cross-entity relationships in accordance with one or more embodiments of the present disclosure. [Figure 8D] It is a diagram of an exemplary interface for establishing cross-entity relationships in accordance with one or more embodiments of the present disclosure. [Figure 8E] It is a diagram of an exemplary interface for establishing cross-entity relationships in accordance with one or more embodiments of the present disclosure. [Figure 8F] It is a diagram of an exemplary interface for establishing cross-entity relationships in accordance with one or more embodiments of the present disclosure. [Figure 9] It is a process flow for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 10] It is a first messaging flow for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 11] It is a second messaging flow for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 12A] It is a diagram of an exemplary interface for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 12B] It is a diagram of an exemplary interface for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. [Figure 12C] It is a diagram of an exemplary interface for facilitating credential-less exchange of value in accordance with one or more embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0013] Various embodiments of this disclosure are described in more detail below with reference to the accompanying drawings, which illustrate some, but not all, embodiments of this disclosure. In practice, this disclosure may be embodied in many different forms and should not be construed as an limitation to the embodiments described herein, but rather these embodiments are provided so as to satisfy the applicable legal requirements of this disclosure. The term “or” is used herein in both an alternative and conjunctive sense unless otherwise indicated. The terms “exemplary” and “example” are used herein as examples without indication of a quality level. Terms such as “computing,” “determining,” “generating,” and / or similar words are used herein without distinction to refer to the creation, modification, or identification of data. Furthermore, “at least in part on,” “based on,” and / or similar words are used herein without distinction in a broadly interpretable manner, unless otherwise indicated, so as not necessarily to indicate that it is at least in part on or based on only one or more of the elements referenced. Similar numbers refer to similar elements throughout.
[0014] I. Summary and Technical Advantages Various embodiments of this disclosure provide technical solutions for managing network-based exchanges. In various embodiments, an exchange platform may be configured to facilitate credential-free exchanges of value between one or more member platforms. These exchanges can be facilitated in real time without persistent credentials that could expose members to financial, legal, reputational, or other risks. Thus, in various embodiments, client devices can buy, sell, and / or execute value-based exchanges in real time over any network without disclosing highly confidential information that is vulnerable to network-based attacks.
[0015] Embodiments of this disclosure provide improved instrument registration and exchange processing technologies that leverage interfaces and data transformation and encryption technologies to enhance data security while reducing computing resource expenditure requirements for protecting highly sensitive data over network communications. Some technologies of this disclosure, for example, extract data objects and transform them into unique data keys that are recognizable only to authorized entities. Data keys may be provided and / or established by leveraging exchange interfaces between the exchange platform and other member platforms. Once established, data keys may be mapped to highly sensitive credentials stored within the source platform (e.g., a service provider platform) without requiring the network transmission of highly sensitive credentials. Future communications to facilitate value-based exchanges may replace traditional persistent credentials with data keys to enable the source platform to identify persistent credentials and / or perform one or more actions for a particular instrument associated with those persistent credentials. Thus, exchange platforms can facilitate exchanges using keys (and / or other identifiers) that cannot be traced back to the underlying highly sensitive information. This further enables the exchange platform to track, facilitate, and distribute network-based communications holistically without exposing members to network attacks. Thus, the registration technology of this disclosure provides improved data and network security techniques that can be practically applied for network-based exchanges to securely register instruments with the exchange platform.
[0016] In addition to the above, embodiments of this disclosure present network-based exchange processing technology for facilitating credential-free exchanges. To do so, some of the technology of this disclosure leverages a new data structure called UUEK, which can replace the persistent credentials traditionally used to authorize value-based exchanges. Using the technology of this disclosure, UUEK can be securely issued across member platforms to enable users to perform value-based exchanges using identifiers recognizable by a single-party exchange platform. UUEK can be mapped to a unique identifier that can refer to confidential information without directly identifying the confidential information. The unique identifier can, for example, refer to a mapping that can only be interpreted by the source platform, and therefore the identifier is unusable by a malicious party not associated with the exchange platform. In this way, the exchange platform can distribute, track, and facilitate exchanges without exposing member platforms to data security risks. Furthermore, the exchange platform can continuously update, modify, and / or redistribute UUEK to member platforms in order to continuously adapt UUEK in real time. Thus, exchange platforms can provide technical improvements to data and network security while reducing computing resource requirements (for example, for securely encrypting persistent credentials) to facilitate value-based exchange.
[0017] Exemplary inventive and technically advantageous embodiments of this disclosure include (i) data transformation, mapping, and processing schemes for facilitating network-based, credential-free registration of users; (ii) exchange interfaces and network-based communication schemes for improving network security for cross-platform communications; and (iii) temporary data structures and data management techniques for distributing temporary data structures for facilitating real-time, secure, and dynamic value-based exchanges.
[0018] II. Exemplary Definitions In some embodiments, the term “exchange platform” refers to a computing entity configured to facilitate credential-free exchange of value for one or more members in a network. The exchange platform may include one or more processing devices, memory devices, and / or similar, physically and / or wirelessly coupled and configured to perform one or more computing tasks collectively (and / or individually) to facilitate value system-independent exchanges. In some examples, the exchange platform may include, define, and / or otherwise utilize one or more application programming interfaces (APIs) to facilitate communication (e.g., requests and responses) between multiple members. As described herein, APIs may be utilized to facilitate secure exchanges between one or more members in any value system.
[0019] In some embodiments, the term “member” refers to an entity that collaborates with the exchange platform to participate in a value exchange. For example, a member may include (i) a partner that utilizes the exchange platform to receive value, (ii) a service provider that utilizes the exchange platform to provide value, and / or (iii) both a partner and a service provider. As used herein, a member may be called a partner when receiving value through a value exchange, and / or a service provider when providing value through a value exchange. Thus, depending on the member’s role in the value exchange, the same member may be both a partner and a service provider. For example, a member may be a partner that receives value for a value exchange. The same member may be a service provider that provides value in another value exchange. In some examples, the same member may be both a partner and a service provider in the same value exchange, and thus the member utilizes the exchange platform to provide value in a value exchange of only one member, and then to receive value.
[0020] In some embodiments, a member is a partner when using services provided by a service provider. A partner can include any value-seeking entity in any value system. For example, in a financial value system, a partner can include a merchant (e.g., a retailer, a storefront, etc.) who may use a service provider, such as a financial institution, to access funds for financial transactions. Additionally or alternatively, in an information value system, a partner can include a news publisher (e.g., a newspaper, a press organization, etc.) who may use a service provider, such as a news agency (e.g., a wire service, a news service, etc.), to access information for information transactions. Naturally, the technology of this disclosure may be applied to any value system, and a partner can include any value-seeking entity for any respective value system.
[0021] In some embodiments, a Member is a Service Provider when providing services to a Partner. A Service Provider can include a source of value in any value system. For example, in a financial value system, a Service Provider can include a financial institution (e.g., a bank, a foreign exchange platform, a credit union, etc.) that can provide access to funds for financial transactions between one or more entities. Additionally or alternatively, in an information value system, a Service Provider can include a news agency (e.g., a wire service, a news service, etc.) from which news publishers can source information for publication. Naturally, the technology of this disclosure may be applied to any value system, and a Service Provider can include any source of value for any respective value system.
[0022] In some embodiments, the term “member platform” refers to a computing entity corresponding to a member. A member platform entity may include a partner computing platform acting on behalf of a partner, a service provider computing platform acting on behalf of a service provider, and / or both. In some examples, a member platform can be both a partner platform and a service provider platform. For example, the same member platform may be configured to act on behalf of a partner for one value exchange and on behalf of a service provider for another value exchange. In some examples, the same member platform may be configured to act on behalf of both a partner and a service provider in a single value exchange. It should be noted that the term member platform can refer to a partner platform, a service provider platform, or both, and in some examples, it may depend on the role of the member platform in the value exchange (e.g., and / or one or more APIs utilized by the member platform in the value exchange).
[0023] In some embodiments, the partner platform is a computing entity configured to perform one or more actions on behalf of the partner. The partner platform may include one or more processing devices, memory devices, and / or similar, physically and / or wirelessly coupled and configured to perform, for example, one or more computing tasks collectively (and / or individually) for requesting value in a value system-independent exchange. In some examples, the partner platform may include, define, and / or otherwise utilize one or more APIs to facilitate communication with the exchange platform (e.g., requests and responses). In some examples, the partner platform may be configured to host one or more user-facing applications (e.g., partner applications) for interacting with one or more users.
[0024] In some embodiments, the service provider platform is a computing entity configured to perform one or more actions on behalf of a service provider. The service provider platform may include one or more processing devices, memory devices, and / or similar, physically and / or wirelessly coupled and configured to perform, for example, one or more computing tasks collectively (and / or individually) to deliver value in a value system-independent exchange. In some examples, the service provider platform may include, define, and / or otherwise leverage one or more APIs to facilitate communication (e.g., requests and responses) with the exchange platform. In some examples, the service provider platform may be configured to facilitate one or more service provider instruments. In some examples, the service provider platform may be configured to host one or more user-facing applications (e.g., service provider applications) for managing one or more service provider instruments.
[0025] In some embodiments, the term “exchange interface” refers to a set of instructions for facilitating communication between an exchange platform and one or more member platforms and / or internal services. An exchange interface may include APIs, file-based interfaces, message queue-based interfaces, and / or similar. For example, an exchange interface may include APIs, such as one or more Simple Object Access Protocol (SOAP) APIs, one or more Remote Procedure Call (RPC) APIs, one or more WebSocket APIs, one or more Representational State Transfer (REST) APIs, and / or similar. In some embodiments, an exchange interface may include one or more RPC APIs, such as one or more gRPC APIs.
[0026] An exchange platform may include, define, and / or otherwise utilize one or more different exchange interfaces to facilitate communication with one or more external platforms, such as one or more member platforms (e.g., partner platforms, service provider platforms, etc.). Each API may include multiple communication instructions, message definitions, and / or similar for exchanging requests and / or responses between the exchange platform and entities participating in value exchange. For example, an exchange interface may include a partner API to facilitate communication with a partner platform and / or a service provider API to facilitate communication with a service provider platform.
[0027] In some embodiments, the term “Partner Interface” refers to an exchange interface for facilitating one or more communications between a Partner Platform and an Exchange Platform. The Partner Interface may define one or more communication instructions, message definitions, and / or similar for facilitating one or more request messages and / or response messages between the Partner Platform and the Exchange Platform. The Partner Interface may include, for example, APIs that define (i) requests from a computing entity acting as a Partner Platform to the Exchange Platform, and / or (ii) requests from the Exchange Platform to the Partner Platform. For example, the Partner Interface may define one or more registration messages, session messages, transaction messages, and / or similar for facilitating value exchange for a Partner. In some embodiments, the Partner Interface defines one or more identifiers for securely identifying one or more parts of a value exchange.
[0028] In some embodiments, the term “service provider interface” refers to an exchange interface for facilitating one or more communications between a service provider platform and an exchange platform. A service provider interface may define one or more communication instructions, message definitions, and / or similar for facilitating one or more request messages and / or response messages between the service provider platform and the exchange platform. A service provider interface may include, for example, APIs that define (i) requests from a computing entity acting as a service provider platform to the exchange platform, and / or (ii) requests from the exchange platform to the service provider platform. A service provider interface may define, for example, one or more registration messages, session messages, transaction messages, and / or similar for facilitating value exchange using a service provider instrument. In some embodiments, a service provider interface may define one or more identifiers for securely identifying one or more parts of a value exchange.
[0029] In some embodiments, the term “entity partition” refers to a unique identifier for a computing entity. An entity partition may include a unique number, alphanumeric character, and / or similar that represents a particular computing entity. Entity partitions may include, for example, member partitions representing member platforms, service provider partitions representing service provider platforms, partner partitions representing partner platforms, and / or similar.
[0030] In some embodiments, the term “service provider partition” refers to a unique identifier for a service provider and / or a service provider’s service provider platform. A service provider partition may include a series of numbers, alphanumeric characters, or any other characters or symbols representing a service provider associated with the exchange platform (e.g., onboard, registered, etc.). An exchange platform may include multiple service provider partitions, each identifying a service provider platform attached to the exchange platform (e.g., onboard, registered, etc.). Each service provider partition may represent a service provider platform comprising one or more exchange platform software development kits (SDKs) and / or similar for implementing the exchange platform’s service provider interface.
[0031] In some embodiments, “Partner Partition” refers to a unique identifier for a partner and / or a partner's partner platform. A Partner Partition may include a series of numbers, alphanumeric characters, or any / or other characters or symbols representing a partner associated with an exchange platform. An exchange platform may include multiple Partner Partitions, each identifying a Partner Platform associated with the exchange platform (e.g., installed, registered, etc.). Each Partner Partition may represent a Partner Platform comprising one or more Exchange SDKs and / or similar for implementing the exchange platform’s Partner Interface.
[0032] In some embodiments, the term “user application” refers to a computer program hosted by a computing entity that facilitates one or more user interactions. A user application may include software (e.g., computer-readable instructions) designed to perform one or more computing tasks for a computing entity, such as a member platform. For example, a user application can facilitate communication between a member and a user. As an example, a user application may be configured to present one or more user interfaces for interacting with a user on behalf of a member. In some examples, a user application may be configured to receive user input (e.g., via one or more user interfaces) to receive information from the user.
[0033] In some embodiments, the user-facing application is a partner application hosted by a partner platform (e.g., a member platform that acts as a partner for a particular exchange) to facilitate functionality for the partner. The partner application may include software (e.g., computer-readable instructions) designed to perform one or more computing tasks for the partner. For example, the partner application may be configured to present one or more user interfaces for interacting with one or more products offered by a retail-based partner, one or more units of information offered by an information-based partner, and / or similar (e.g., browsing, purchasing, scrutinizing, etc.). In some examples, the partner application may be configured to receive user input (e.g., via one or more user interfaces) to receive information from the user.
[0034] In some embodiments, the user-facing application is a service provider application hosted by a service provider platform (e.g., a member platform acting as a service provider for a particular exchange) to facilitate functionality for the service provider. The service provider application may include software (e.g., computer-readable instructions) designed to perform one or more computing tasks for the service provider. For example, the service provider application may be configured to present one or more user interfaces for interacting with one or more service provider instruments (e.g., scrutiny, management, inspection, registration, etc.) facilitated by the service provider. As an example, in a financial value system, the service provider application may enable access to bank accounts, securities accounts, credit limits, and / or similar for managing funds, assets, and / or similar handled by each account. In some examples, the service provider application may be configured to receive user input (e.g., via one or more user interfaces) to receive information, authorizations, and / or similar from the user.
[0035] In some embodiments, the term “service provider instrument” refers to a mechanism utilized by a service provider to deliver value on behalf of a particular user. A service provider instrument may depend on the value system and / or the service provider. In some examples, a service provider instrument may include the service provider’s accounts. For example, in a financial value system, a service provider instrument may include bank accounts (e.g., checking accounts, savings accounts, etc.), securities accounts, credit limits, and / or similar. In an information value system, a service provider instrument may include subscriber accounts and / or similar. In some examples, a service provider instrument may include virtual instruments hosted by the service provider platform.
[0036] In some embodiments, the term “instrument data object” refers to a data entity representing a service provider instrument. An instrument data object may contain one or more instrument identifiers and / or one or more instrument attributes. In some examples, one or more instrument identifiers and / or one or more instrument attributes may be based on the type of instrument data object. For example, a service provider instrument may be represented as a member instrument data object in a member platform. Additionally or alternatively, a service provider instrument may be independently represented by a system instrument data object in an exchange platform. In some examples, member instrument data objects and system instrument data objects may contain one or more of the same one or more instrument identifiers and / or one or more instrument attributes. For example, a member platform may register multiple service provider instruments with the exchange platform. During registration, member platforms may provide one or more instrument identifiers and / or instrument attributes, and in some cases, exchange platforms may return a different identifier.
[0037] In some embodiments, a member instrument data object is an internal representation of a service provider instrument within the member platform. A member instrument data object may include one or more instrument identifiers, such as a member instrument identifier, an instrument key from the exchange platform, and / or a user identifier. The user identifier may include, for example, a member user identifier. Additionally or alternatively, a member instrument data object may include one or more instrument attributes, such as an instrument type (e.g., credit-based instrument, debit-based instrument, information-based instrument), an instrument representation, and / or one or more contextual attributes. In some examples, the contextual attributes may depend on the value system. For example, in a financial value system, one or more contextual attributes may indicate (i) the currency associated with the service provider instrument, (ii) the asset availability of the service provider instrument (e.g., balance, coverage, etc.), or (iii) one or more previous transactions and / or similar transactions at the service provider instrument.
[0038] In some embodiments, a system instrument data object is an external representation of a service provider instrument within the exchange platform. A system instrument data object may include one or more instrument identifiers, such as a member platform instrument reference, a system instrument identifier, and / or a user identifier. The user identifier may include, for example, a system user identifier. Additionally or alternatively, a system instrument data object may include one or more instrument attributes, such as an instrument type (e.g., credit-based instrument, debit-based instrument, information-based instrument), an instrument representation, and / or one or more contextual attributes. In some examples, the contextual attributes may depend on a value system. For example, in a financial value system, one or more contextual attributes may indicate the currency associated with the service provider instrument.
[0039] In some embodiments, the term “instrument identifier” refers to any representation of a service provider instrument. An instrument identifier may include an instrument identifier, instrument reference, instrument key, and / or similar, as described herein.
[0040] In some embodiments, the term “member instrument identifier” refers to a unique identifier for representing a service provider instrument within a member platform. A member instrument identifier may include, for example, a series of numbers, alphanumeric characters, or any other characters or symbols representing a service provider instrument for a service provider platform.
[0041] In some embodiments, the term “instrument reference” refers to a unique identifier for referencing a member instrument identifier. An instrument reference may be generated and / or provided by a member platform to an exchange platform, for example, to enable the exchange platform to reference instruments maintained on the member platform. In some examples, the instrument reference is the same value as the member instrument identifier. In some examples, the instrument reference is a different value mapped to the member instrument identifier.
[0042] In some embodiments, the term “system instrument identifier” refers to a unique identifier used to represent a service provider instrument within the exchange platform. A system instrument identifier may include, for example, a series of numbers, alphanumeric characters, or any other characters or symbols that represent a service provider instrument for the exchange platform. In some examples, a system instrument identifier may include a UUID.
[0043] In some embodiments, the term “instrument key” refers to a unique identifier for referencing a system instrument identifier. An instrument key may be generated and / or provided by the exchange platform, for example, during the process of registering an instrument with the exchange platform. In some examples, the instrument key may include a wrapped system instrument identifier. For example, the instrument key may include a string of alphanumeric characters formatted according to a key format established by the exchange platform (and / or one or more of its APIs). The key format may include any number of characters, such as 50 or more. In some examples, the characters may be case-sensitive. A first part of the characters (e.g., the first six characters) may be reserved as a partition for identifying the entity associated with the key. In the case of an instrument key, the partition may include a service provider partition. A second part of the characters may identify the system instrument identifier. The key formats described herein may include one or more distinct parts, each of which may be arranged in any order.
[0044] In some embodiments, the term “instrument representation” refers to a unique identifier used to represent a service provider instrument for a user. An instrument representation may include, for example, a series of numbers, alphanumeric characters, or any other characters or symbols that visually represent a service provider instrument. The format and / or value of an instrument representation may be based at least in part on the type of service provider and / or service provider instrument. For example, in a financial value system, an instrument reference may include a portion of persistent credentials (e.g., the last four digits) such as an account number (e.g., a direct debit account, a credit account), a financial account name, and / or similar. Alternatively, in an information value system, an instrument reference may include a portion of persistent credentials (e.g., one or more digits, alphanumeric characters) such as a subscription account and / or similar. For example, an instrument representation may include derivatives of persistent credentials, allowing only entities with prior knowledge of the persistent credentials to use the instrument representation to identify the persistent credentials. As another example, an instrument representation may include a nickname for the instrument, which is assigned and subsequently recognized by the user.
[0045] In some embodiments, the term “user data object” refers to a data entity representing a user interacting with the Member Platform and / or Exchange Platform. A user may include, for example, entities engaged in value exchanges governed by the Exchange Platform (e.g., people, organizations, groups, etc.). In some examples, a user may indirectly interact with the Exchange Platform by creating user accounts for registered service providers, registering (and / or granting permission to register) service provider instruments, and / or similar. In some examples, the Exchange Platform may function on behalf of a user without the user's direct interaction with the Exchange Platform. For example, the Exchange Platform may act as a hidden intermediary between a user-facing application and the user’s service provider instruments.
[0046] In some embodiments, a user data object includes one or more user identifiers and / or one or more user attributes. In some examples, one or more user identifiers and / or one or more user attributes may be based on the type of the user data object. For example, a user may be represented as a member user data object in a member platform. Additionally or alternatively, a user may be independently represented by a system user data object in an exchange platform. In some examples, member user data objects and system user data objects may include one or more of the same one or more user identifiers and / or user attributes. For example, a member platform may register multiple users with an exchange platform. During registration, the member platform may provide one or more of the user identifiers and / or user attributes, and in some examples, the exchange platform may return a different identifier.
[0047] In some embodiments, a member user data object is an internal representation of a user within the member platform. A member instrument data object may include one or more user identifiers, such as a member user identifier, a user key from the exchange platform, and / or similar. Additionally or alternatively, a member user data object may include one or more user attributes. One or more user attributes may represent one or more contextual characteristics of the user. In some examples, a user attribute may represent one or more identifiable characteristics of the user. For example, a user attribute may represent the user's first name, last name, email, actual address (e.g., one or more of street, local, region, zip code, country, etc.), date of birth (e.g., birth date, age group, etc.), telephone number, and / or similar. In some examples, a user attribute may include encrypted, hashed, and / or otherwise secure representations of the user's identifiable characteristics. For example, a user attribute may include one or more hashed identifiers and / or similar of the user.
[0048] In some embodiments, a system user data object is an external representation of a member user within the exchange platform. A system user data object may include one or more user identifiers, such as a member platform user reference, a system user identifier, and / or similar. Additionally or alternatively, a system user data object may include one or more user attributes, such as those described herein. For example, a member platform may register a user with the exchange platform. During registration, the member platform may provide the user's user reference and / or one or more user attributes. In some examples, user attributes may include the user's hashed and / or encrypted identifier.
[0049] In some embodiments, the term “user identifier” refers to a unique identifier of a user involved in a value-based exchange. A user identifier may include a series of numbers, alphanumeric characters, or any other characters or symbols representing a user of the exchange platform and / or member platform. In some examples, a user identifier may include a user reference, user key, system user identifier, member user identifier, and / or similar.
[0050] In some embodiments, the term “system user identifier” refers to a unique identifier used to represent a user within the exchange platform. The system user identifier may include, for example, a series of numbers, alphanumeric characters, or any other characters or symbols that represent a user to the exchange platform. In some examples, the system user identifier may include a UUID unique to a particular user.
[0051] In some embodiments, the term “member user identifier” refers to a unique identifier used to represent a user within the member platform. A member user identifier may include, for example, a series of numbers, alphanumeric characters, or any other characters or symbols representing a user to a service provider platform.
[0052] In some embodiments, the term “user reference” refers to a unique identifier for referencing a member user identifier. User references may be generated and / or provided by a member platform to an exchange platform, for example, to allow the exchange platform to reference users associated with the member platform. In some examples, the user reference is the same value as the member user identifier. In some examples, the user reference is a different value mapped to the member user identifier.
[0053] In some embodiments, the term “user key” refers to a unique identifier for referencing a system user identifier. A user key may be generated and / or provided by the exchange platform, for example, during the user registration process with the exchange platform. In some examples, a user key may include a packaged system user identifier. For example, a user key may include a string of alphanumeric characters formatted according to a key format established by the exchange platform (and / or one or more of its APIs). The key format may include, for example, a first part of the characters (e.g., the first six characters) which may be reserved as a partition for identifying entities associated with the key (e.g., members). For example, in the case of a user key, the partition may include a service provider partition and / or a partner partition. A second part of the characters may identify the system user identifier.
[0054] In some embodiments, the term “exchange data object” refers to a data entity that represents an authorized value exchange between one or more members associated with an exchange platform. In some examples, an exchange data object may include one or more identifiers and / or one or more exchange attributes. For example, one or more identifiers and / or one or more exchange attributes may be based on the type of the exchange data object. For example, an exchange may be represented as a member exchange data object in a member platform. Additionally or alternatively, an exchange may be independently represented by a system exchange data object in an exchange platform. In some examples, member exchange data objects and system exchange data objects may include one or more of the same one or more identifiers and / or exchange attributes. For example, using some of the technology of this disclosure, an exchange platform may issue one or more unique identifiers to member platforms that may be used to authorize value exchanges.
[0055] In some embodiments, a system exchange data object is an internal representation of a value exchange mediated using an exchange platform. In some examples, a system exchange data object may include one or more different identifiers and / or exchange attributes, depending on the role of the system exchange data object in a value-based exchange.
[0056] For example, a system exchange data object may include a service provider-specific exchange data object corresponding to a service provider platform. A service provider-specific exchange data object may include one or more identifiers, such as an exchange identifier, a system user identifier, a system instrument identifier, a UUEK, and / or similar. Additionally or alternatively, a service provider-specific exchange data object may include one or more exchange attributes, such as an expiration date, currency (e.g., for a financial value system), and / or similar.
[0057] Additionally or alternatively, a system exchange data object may include a partner-specific exchange data object corresponding to a partner platform. A partner-specific exchange data object may include one or more identifiers, such as an exchange identifier, instrument key, UUEK, member instrument reference (e.g., a partner-specific instrument reference), and / or similar. Additionally or alternatively, a partner-specific exchange data object may include one or more exchange attributes, such as an expiration date, currency (e.g., in the case of a financial value system), instrument type, previous UUEK identifier, and / or similar. In some embodiments, a member exchange data object is an external representation of a value exchange mediated using the exchange platform. A member exchange data object may include one or more identifiers, such as a member exchange identifier, member instrument identifier, UUEK from the exchange platform, and / or similar.
[0058] In some embodiments, the term “exchange identifier” refers to a unique identifier for value exchange using the exchange platform. An exchange identifier may include a set of numbers, alphanumeric characters, or any other character or symbol representing at least a user and / or service provider instrument. In some examples, a unique exchange identifier may include a universally unique identifier (UUID) that can be mapped (e.g., through a set of identifiers) to users, service provider instruments, and / or members registered on the exchange platform. In some examples, an exchange identifier may be randomly generated using one or more UUID generators. For example, an exchange identifier may include 16 bytes of random information generated according to one or more UUID format standards, such as UUID v4 and / or similar. Thus, an exchange identifier may be leveraged by the exchange platform and / or member platforms for one or more functions, but the same exchange identifier will be useless to external parties without a prior association between the exchange identifier and one or more other identifiers. In some examples, an exchange identifier may be represented externally by a UUEK.
[0059] In some embodiments, a “universally unique ephemeral key” or “UUEK” refers to an external representation of an exchange identifier that can be issued (e.g., instead of a service provider exchange identifier and / or partner exchange identifier) to external entities, such as users, partners, and / or service providers, in order to initiate a transaction using the exchange platform. To do so, a UUEK can be generated and issued by the exchange platform to external entities. Each UUEK may contain multiple values (e.g., up to 50 case-sensitive characters and / or more) that represent one or more aspects of a transaction. For example, the multiple values may represent an exchange identifier, a partition (e.g., identifying the recipient of the UUEK), an identifier type, and / or one or more flags. As an example, a UUEK may include a partner-specific UUEK and / or a service provider-specific UUEK. Partner-specific UUEKs may be correlated to partner-specific exchange data objects as described herein, while service provider-specific UUEKs may be correlated to service provider-specific exchange data objects.
[0060] For example, a UUEK may be generated according to a key format. The key format may include multiple characters, for example, more than 50 characters that are case-sensitive. The first part of the characters (e.g., the first six characters) may be reserved as a partition to identify the recipient of the UUEK. The partition may include, for example, a partner partition, a service provider partition, and / or any other member partition. For example, a UUEK may be issued in response to a request from an authorized member, such as an attached partner and / or service provider.
[0061] As an addition or alternative, at least one character of the key format (e.g., the seventh character) may identify the format of the UUEK. At least another character (e.g., the eighth character) may identify the type of the UUEK. In some examples, the second part of the character may identify an exchange identifier (e.g., a group of 22 characters following the eighth character). The third part of the character may be reserved (e.g., a group of 20 characters following the first part of the character). Exemplary representations are provided below, ppppppFiGGGGGGGGGGGGGGGGGGGGrrrrrrrrrrrrrrrrrrrr Here, p represents the partition character, F represents the format character, i represents the identifier type character, G represents the exchange identifier, and r represents the reserved character. The key format allows for up to 9.8 × 10^84 unique sortings, which is more than the number of atoms in the known observable universe. This enables the generation and distribution of new UUEKs on demand without compromising the security of the underlying data to which the UUEK can be mapped, such as identifiers for users, instruments, and / or any other potentially confidential information. The key format described herein may contain one or more different parts, each of which may be arranged in any order.
[0062] In some embodiments, the term “session identifier” refers to a unique identifier for identifying a set of related message exchanges between the exchange platform and an external platform.
[0063] In some embodiments, the term “matching code” refers to a session-specific identifier for authorizing a registration session between one or more entities. A matching code may include, for example, a sequence of digits, alphanumeric characters, and / or similar characters provided to multiple entities to ensure that each entity is involved in the same communication sequence. As an example, a matching code may include a sequence of eight characters, generated by the exchange platform, provided to the service provider platform, and then received from the partner platform, to ensure that the exchange platform, service provider platform, and partner platform are each interacting with the same end user (for example, by comparing an received matching code with a generated matching code, as described herein).
[0064] III. Computer Program Products, Methods, and Computing Entities Embodiments of the present disclosure may be implemented in various ways, including as a computer program product comprising a product. Such a computer program product may include one or more software components, for example, software objects, methods, data structures, or the like. Software components may be encoded in any of various programming languages. An illustrative programming language may be a low-level programming language, such as an assembly language associated with a particular hardware architecture and / or operating system platform. A software component comprising assembly language instructions may require conversion to executable machine code by an assembler before execution by the hardware architecture and / or platform. Another illustrative programming language may be a high-level programming language that may be portable across multiple architectures. A software component comprising high-level programming language instructions may require conversion to an intermediate representation by an interpreter or compiler before execution.
[0065] Other examples of programming languages include, but are not limited to, macro languages, shell or command languages, job control languages, scripting languages, database query or search languages, and / or reporting languages. In one or more exemplary embodiments, a software component comprising instructions in one of the aforementioned examples of programming languages may be executed directly by an operating system or other software component without first being converted into another form. Software components may be stored as files or other data storage structures. Software components of similar types or functionally related types may be stored together, for example, in a particular directory, folder, or library. Software components may be static (e.g., pre-established or fixed) or dynamic (e.g., created or modified at runtime).
[0066] A computer program product may include non-temporary computer-readable storage media that store applications, programs, program modules, scripts, source code, program code, object code, byte code, compiled code, interpreted code, machine language, executable instructions, and / or similar terms used herein without distinction. Such non-temporary computer-readable storage media include all computer-readable media (including volatile and non-volatile media).
[0067] In one embodiment, the non-volatile computer-readable storage medium may include floppy disks, flexible disks, hard disks, solid-state storage (SSS) (e.g., solid-state drives (SSDs), solid-state cards (SSCs), solid-state modules (SSMs), enterprise flash drives, magnetic tape, or any other non-transient magnetic medium and / or similar). The non-volatile computer-readable storage medium may also include punch cards, paper tape, optical mark sheets (or any other physical medium with a pattern of holes or other optically recognizable markings), compact disk read-only memory (CD-ROM), compact disk rewritable (CD-RW), digital barcodes, etc. This may include non-volatile optical media such as DVDs, Blu-ray discs (BDs), any other non-volatile optical media, and / or similar. Such non-volatile computer-readable storage media may also include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory (e.g., Serial, NAND, NOR, and / or similar), multimedia memory cards (MMCs), secure digital (SD) memory cards, SmartMedia cards, CompactFlash® (CF) cards, Memory Sticks, and / or similar.Furthermore, non-volatile computer-readable memory media may also include conductive bridge random-access memory (CBRAM), phase-change random-access memory (PRAM), ferroelectric random-access memory (FeRAM), non-volatile random-access memory (NVRAM), magnetoresistive random-access memory (MRAM), resistive random-access memory (RRAM), silicon oxide-nitride-oxide-silicon memory (SONOS), floating junction-gate random-access memory (FJG RAM), millipede memory, racetrack memory, and / or similar.
[0068] In one embodiment, the volatile computer-readable storage medium is Random Access Memory (RAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Fast Page Mode Dynamic Random Access Memory (FPM DRAM), Extended Data-Out Dynamic Random Access Memory (EDO DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDR SDRAM), Double Data Rate Type 2 Synchronous Dynamic Random Access Memory (DDR2 SDRAM), Double Data Rate Type 3 Synchronous Dynamic Random Access Memory (DDR3 SDRAM). This may include SDRAM, Rambus Dynamic Random Access Memory (RDRAM), Twin Transistor RAM (TTRAM), Thyristor RAM (T-RAM), Zero Capacitor (Z-RAM), Rambus Inline Memory Module (RIMM), Dual Inline Memory Module (DIMM), Single Inline Memory Module (SIMM), Video Random Access Memory (VRAM), Cache Memory (including various levels), Flash Memory, Register Memory, and / or similar. When embodiments for using computer-readable storage media are described, it will be understood that other types of computer-readable storage media may be used in place of or in addition to the computer-readable storage media described above.
[0069] As recognized, various embodiments of the present disclosure may also be implemented as methods, apparatus, systems, computing devices, computing entities, and / or similar. Accordingly, embodiments of the present disclosure may take the form of data structures, apparatus, systems, computing devices, computing entities, and / or similar that execute instructions stored in a computer-readable storage medium for performing a particular step or operation. Accordingly, embodiments of the present disclosure may also take the form of entirely hardware embodiments, entirely computer program product embodiments, and / or embodiments comprising a combination of a computer program product and hardware for performing a particular step or operation.
[0070] Embodiments of the present disclosure are described below with reference to block diagrams, flowcharts, messaging flows, and other representations of data, operations, and messaging schemes. It should be understood that each block, arrow, and / or similar, such as in diagrams and flowcharts, may be implemented in the form of a computer program product, an entirely hardware embodiment, a combination of hardware and a computer program product, and / or a device, system, computing device, computing entity, and / or similar that execute instructions, operations, steps, and similar terms used indiscriminately on a computer-readable storage medium for execution (e.g., executable instruction, execution instruction, program code, and / or similar). For example, code retrieval, loading, and execution may be performed sequentially so that one instruction is retrieved, loaded, and executed at a time. In some exemplary embodiments, retrieval, loading, and / or execution may be performed in parallel so that multiple instructions are retrieved, loaded, and / or executed together. Thus, such embodiments can produce a specifically configured machine that performs the steps or operations specified in the representations of the present disclosure. Accordingly, the representations in this disclosure support various combinations of embodiments for carrying out specified instructions, actions, or steps.
[0071] IV. Exemplary System Architecture Figure 1 provides an illustration of a computing ecosystem 100 that may be used with various embodiments of the present disclosure. As shown in Figure 1, the architecture may include a switching platform 102, one or more client devices 104, a network of member platforms 110, one or more networks 120, and / or similar. The network of member platforms 110 may include a first member platform 112a, a second member platform 112b, a third member platform 112c, and / or similar that are attached to (e.g., registered with) the switching platform 102. For example, as described herein, the network of member platforms 110 may include a partner platform and / or a service provider platform. In some examples, the partner platform may include a first member platform 112a, and the service provider platform may include a second member platform 112b that is different from the first member platform 112a. In some examples, the partner platform and / or service provider platform may include a single member platform (e.g., a third member platform 112c). In some examples, the member platform's network 110 may be configured for one or more different services.
[0072] Each component of the computing ecosystem 100 may be electronically communicating with one another via the same or different wireless or wired networks 120, for example, including wired or wireless personal area networks (PANs), local area networks (LANs), metropolitan area networks (MANs), wide area networks (WANs), or similar. Network 120 may include any network connectivity (e.g., international connectivity including one or more sovereign entities) that includes any of the types of networks and / or span any geographical boundaries. Additionally, while Figure 1 illustrates a particular system as a separate, independent entity, various embodiments are not limited to this particular architecture.
[0073] Although not explicitly illustrated, the exchange platform 102 may also be a client device 104 and / or part of the member platform network 110. Additionally or alternatively, member platforms 112a-c may also be a client device 104 and / or part of the exchange platform 102. In some embodiments, each of the exchange platform 102 and / or member platforms 112a-c may include the same computing platform.
[0074] a. Exemplary computing platform Figure 2 is an exemplary schematic diagram of a computing platform 200 according to one or more embodiments of the present disclosure. The computing platform 200, such as the exchange platform 102, member platforms 112a-c, and / or similar in Figure 1, may include, or be communicating with, one or more processing elements 202 (also called processors, processing circuitry, and / or similar terms used herein without distinction) that communicate with other elements within the computing platform 200, for example, via a bus. Naturally, the processing elements 202 may be embodied in several different ways.
[0075] For example, the processing element 202 may be embodied as one or more complex programmable logic devices (CPLDs), microprocessors, multicore processors, coprocessing entities, application-specific instruction set processors (ASIPs), microcontrollers, and / or controllers. Furthermore, the processing element 202 may be embodied as one or more other processing devices or circuit equipment. The term circuit equipment can refer entirely to a hardware embodiment or a combination of hardware and computer program products. Thus, the processing element 202 may be embodied as an integrated circuit, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a programmable logic array (PLA), a hardware accelerator, other circuit equipment, and / or similar.
[0076] Therefore, naturally, the processing element 202 may be configured to execute instructions configured for a specific use, stored in a volatile or non-volatile medium, or otherwise accessible to the processing element 202. Thus, whether configured by hardware or computer program products, or a combination thereof, the processing element 202 may have the ability to perform steps or operations according to embodiments of the present disclosure as appropriate when configured.
[0077] In some embodiments, the computing platform 200 includes or communicates with non-volatile memory 204 (also known as non-volatile storage, media, memory storage, memory circuitry, and / or similar terms used herein without distinction). In some examples, the non-volatile memory 204 may include one or more non-volatile storage or memory media, including but not limited to hard disks, ROMs, PROMs, EPROMs, EEPROMs, flash memory, MMCs, SD memory cards, memory sticks, CBRAMs, PRAMs, FeRAMs, NVRAMs, MRAMs, RRAMs, SONOS, FJG RAMs, millipede memory, racetrack memory, and / or similar.
[0078] As recognized, non-volatile memory 204 can store data, databases, database instances, database management systems, files, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine language, executable instructions, and / or similar. The terms database, database instance, database management system, and / or similar terms used herein without distinction can refer to a collection of records or data stored on a computer-readable storage medium using one or more database models, such as a hierarchical database model, a network model, a relational model, an entity-relationship model, an object model, a document model, a semantic model, a graph model, and / or similar.
[0079] In some embodiments, the computing platform 200 includes or communicates with volatile memory 206 (also referred to as volatile storage, media, memory storage, memory circuitry, and / or similar terms used herein without distinction). In some examples, the volatile memory 206 may also include, but not limited to, RAM, DRAM, SRAM, FPM DRAM, EDO DRAM, SDRAM, DDR SDRAM, DDR2 SDRAM, DDR3 SDRAM, RDRAM, TTRAM, T-RAM, Z-RAM, RIMM, DIMM, SIMM, VRAM, cache memory, register memory, and / or similar.
[0080] As recognized, volatile memory 206 may be used to store at least a portion of databases, database instances, database management systems, data, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, and / or similar items, which are executed, for example, by processing element 202. Thus, databases, database instances, database management systems, data, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, and / or similar items may be used, with the assistance of processing element 202 and the operating system, to control specific aspects of the steps / operations of the computing platform 200.
[0081] As shown, in one embodiment, the computing platform 200 may also include one or more network interfaces 208 for communicating with various computing entities (e.g., one or more components in Figure 1) by transmitting, receiving, operating, processing, displaying, storing, and / or similar data, content, information, and / or similar terms used herein without distinction. Such communication may be performed using wired data transmission protocols such as Fiber Distributed Data Interface (FDDI), Digital Subscriber Line (DSL), Ethernet, Asynchronous Transfer Mode (ATM), Frame Relay, Data Over Cable Service Interface Specification (DOCSIS), or any other wired transmission protocol. Similarly, the computing platform 200 may also use General-Purpose Packet Radio Services (GPRS), Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA2000), and CDMA2000 It can be configured to communicate over a wireless external communication network using any of the following protocols: 1X (1xRTT), Wideband Code Division Multiple Access (WCDMA®), Global System for Mobile Communications (GSM), GSM Evolution High Speed Data Rate (EDGE), Time Division Synchronous Code Division Multiple Access (TD-SCDMA), Long-Term Evolution (LTE), Evolved Universal Terrestrial Radio Access Network (E-UTRAN), Evolution Data Optimized (EVDO), High Speed Packet Access (HSPA), High Speed Downlink Packet Access (HSDPA), IEEE 802.11 (Wi-Fi), Wi-Fi Direct, 802.16 (WiMAX), Ultra Wideband (UWB), Infrared (IR) Protocol, Near Field Communication (NFC) Protocol, Wibree, Bluetooth Protocol, Wireless Universal Serial Bus (USB) Protocol, and / or any other wireless protocol.
[0082] Although not shown, the computing platform 200 may include or be communicating with one or more input elements, such as keyboard input, mouse input, touchscreen / display input, motion input, motion input, audio input, pointing device input, joystick input, keypad input, and / or similar. The computing platform 200 may also include or be communicating with one or more output elements (not shown), such as audio output, video output, screen / display output, motion output, motion output, and / or similar.
[0083] As shown, the computing platform 200 may be one or more examples of the components in Figure 1, such as the exchange platform 102 and / or member platforms 112a-c.
[0084] b. Exemplary client devices Figure 3 is an exemplary schematic diagram of a client device 104 according to one or more embodiments of the present disclosure. The client device 104 may be operated by various entities, and the exemplary computing ecosystem may include one or more client devices 104. For example, the client device 104 may be associated with one or more end users, owned by one or more end users, operated by one or more end users, and / or similarly performed by one or more end users. In various embodiments, the end user of the client device 104 may want to engage in a value exchange between a partner and a service provider. As described herein, the user can do so by mutually leveraging one or more functionalities provided by the exchange platform through user input using the client device 104.
[0085] For example, the client device 104 may be a personal computing device, smartphone, tablet, laptop, personal digital assistant, and / or similar. In various embodiments, the computing platform 200 can communicate with one or more client devices 104 and manage value exchanges with one or more client devices 104. As shown in Figure 3, the client device 104 may include an antenna 312, a transmitter 304 (e.g., wireless), a receiver 306 (e.g., wireless), and a processing element 308 (e.g., a CPLD, microprocessor, multicore processor, coprocessing entity, ASIP, microcontroller, and / or controller), respectively, which provide signals to and receive signals from the transmitter 304 and receiver 306.
[0086] The signals provided to and received by the transmitter 304 and receiver 306 may each contain signaling information / data according to the applicable wireless system air interface standard. In this regard, the client device 104 may have the ability to operate with one or more air interface standards, communication protocols, modulation types, and access types. More specifically, the client device 104 may operate according to any of several wireless communication standards and protocols, such as those described above with respect to the computing platform 200. In certain embodiments, the client device 104 may operate according to a number of wireless communication standards and protocols, such as UMTS, CDMA2000, 1xRTT, WCDMA, GSM, EDGE, TD-SCDMA, LTE, E-UTRAN, EVDO, HSPA, HSDPA, Wi-Fi, Wi-Fi Direct, WiMAX, UWB, IR, NFC, Bluetooth, USB, and / or similar. Similarly, the client device 104 can operate via the network interface 320 in accordance with numerous wired communication standards and protocols, such as those described above with respect to the computing platform 200.
[0087] Through these communication standards and protocols, the client device 104 can communicate with the computing platform 200 using concepts such as Unstructured Supplementary Service Data (USSD), Short Message Service (SMS), Multimedia Messaging Service (MMS), Dual-Tone Multi-Frequency Signaling (DTMF), and / or Subscriber Identification Module Dialer (SIM Dialer). The client device 104 can also download changes, add-ons, and updates to, for example, its firmware, software (including, for example, executable instructions, applications, and program modules), and operating system.
[0088] In some embodiments, client device 104 includes location determination modes, devices, modules, functions, and / or similar terms used herein without distinction. For example, client device 104 may include outdoor positioning modes, such as a location module adapted to acquire, for example, latitude, longitude, altitude, geocode, course, direction, orientation, speed, Universal Time (UTC), date, and / or various other information / data. In one embodiment, the location module may acquire data, sometimes known as ephemeris data, by identifying the number of satellites in the field of view and the relative positions of these satellites (for example, using a Global Positioning System (GPS)). The satellites may be various different satellites, including Low Earth Orbit (LEO) satellite systems, Department of Defense (DOD) satellite systems, European Union Galileo Positioning System, China Compass Navigation System, Indian Regional Navigational Satellite System, and / or similar. This data can be collected using a variety of coordinate systems, such as Decimal Angle (DD), Degrees, Minutes, Seconds (DMS), Universal Transverse Mercator (UTM), Universal Polar Centered Transverse (UPS) coordinate system, and / or similar. Alternatively, location information / data may be determined by triangulation of the position of the client device 104 relative to various other systems, including cellular towers, Wi-Fi access points, and / or similar. Similarly, the client device 104 may include indoor positioning configurations, such as location modules adapted to acquire, for example, latitude, longitude, altitude, geocode, course, direction, orientation, speed, time, date, and / or various other information / data. Some indoor systems may use a variety of positioning or location technologies, including RFID tags, indoor beacons or transmitters, Wi-Fi access points, cellular towers, nearby computing devices (e.g., smartphones, laptops), and / or similar.For example, such technologies may include iBeacons®, Gimbal proximity beacons, Bluetooth Low Energy (BLE) transmitters, NFC transmitters, and / or similar. These indoor positioning methods can be used in a variety of environments to determine the location of someone or something to the nearest inch or centimeter.
[0089] In some embodiments, the client device 104 may include a user interface 316 (e.g., a display screen, speaker, tactile mechanization, etc., coupled to the processing element 308) and / or a user input interface 318 (e.g., a touch screen, microphone, etc., coupled to the processing element 308). For example, the user interface 316 may be one or more current application screens presented by one or more computing platforms as described herein. The user input interface 318 may include any of several devices or interfaces that enable the client device 104 to receive data, such as a keypad (hard or soft), a touch display, a voice / speech or motion interface, or other input devices. In an example including a keypad, the keypad may include (or trigger the display of) conventional numerals (0-9) and associated keys (#, *), as well as other keys used to operate the client device 104, and may include a set of keys that can be activated to provide a complete set of alphabet keys or a complete set of alphanumeric keys. In addition to providing input, user input interfaces can be used to activate or deactivate specific functions, such as screen savers and / or sleep modes.
[0090] The client device 104 may also include volatile memory 322 and / or non-volatile memory 324, which may be built-in and / or removable. For example, non-volatile memory 324 may be ROM, PROM, EPROM, EEPROM, flash memory, MMC, SD memory card, memory stick, CBRAM, PRAM, FeRAM, NVRAM, MRAM, RRAM, SONOS, FJG RAM, millipede memory, racetrack memory, and / or similar. Volatile memory 322 may be RAM, DRAM, SRAM, FPM DRAM, EDO DRAM, SDRAM, DDR SDRAM, DDR2 SDRAM, DDR3 SDRAM, RDRAM, TTRAM, T-RAM, Z-RAM, RIMM, DIMM, SIMM, VRAM, cache memory, register memory, and / or similar. Volatile and non-volatile storage or memory can store databases, database instances, database management systems, data, applications, programs, program modules, scripts, source code, object code, byte code, compiled code, interpreted code, machine code, executable instructions, and / or similar items in order to perform the functions of the client device 104. As shown, this may include partner applications, service provider applications, and / or similar items that reside on the client device 104 and / or are accessible through a browser or other user interface to communicate with the computing platform 200.
[0091] In some embodiments, the client device 104 may include one or more components or functions that are the same as or similar to those of the computing platform 200, as described in more detail above. As recognized, these architectures and descriptions are provided for illustrative purposes only and are not limited to various embodiments.
[0092] In various embodiments, the client device 104 may be embodied as an artificial intelligence (AI) computing entity, such as an Amazon Echo, Amazon Echo Dot, Amazon Show, Google Home, and / or similar. Thus, the client device 104 may be configured to provide and / or receive information / data from an end user via input / output mechanisms, such as a display, camera, speaker, voice-activated input, and / or similar. In certain embodiments, the AI computing entity may comprise one or more predefined and executable program algorithms stored in an onboard memory storage module and / or accessible via a network. In various embodiments, the AI computing entity may be configured to retrieve and / or execute one or more of the predefined program algorithms upon the occurrence of a predefined trigger event.
[0093] c. Exemplary Network In some embodiments, two or more of the illustrative components of the computing ecosystem 100 in Figure 1 may be configured to communicate with one another via their respective communicable connections to one or more networks 120. Network 120 may include, but is not limited to, one or a combination of different types of suitable communication networks, such as cable networks, public networks (e.g., the Internet), private networks (e.g., Frame Relay networks), wireless networks, cellular networks, telephone networks (e.g., public switched telephone networks), or any other suitable private and / or public networks. Furthermore, network 120 may have any suitable communication range associated with network 120, which may include, for example, a global network (e.g., the Internet), a MAN, WAN, LAN, or PAN. In addition, network 120 may include any type of medium on which network traffic can be carried, including but not limited to coaxial cables, twisted pair wires, optical fibers, hybrid fiber coaxial (HFC) media, microwave telescopic transceivers, radio frequency communication media, satellite communication media, or any combination thereof, as well as various network devices and computing platforms provided by network providers or other entities.
[0094] d. Exemplary Value Exchange System Figure 4 is an exemplary block diagram of an exemplary network-based exchange system 400 according to one or more embodiments of the present disclosure. The network-based exchange system 400 includes a new computing ecosystem and computing platform that provides an end-to-end value exchange solution for replacing conventional exchange processing systems. As described herein, the network-based exchange system 400 may be value system independent and can be applied to any value-based exchange, including, for example, information-based exchange, finance-based exchange, reputation-based exchange, healthcare-based exchange, profit-based exchange, and / or similar. In any value system, the network-based exchange system 400 can leverage intermediate entities and one or more predefined communication interfaces to facilitate network-based exchange between value-seeking entities (e.g., partners) and value-providing entities (e.g., service providers), which may be associated with one or more member platforms of the network-based exchange system 400.
[0095] As described, the network-based switching system 400 may include a switching platform 102, a partner platform 420, and / or a service provider platform 440, which may be configured to communicate through one or more switching interfaces. The partner platform 420 and / or service provider platform 440 may include one or more member platforms 112a-c from the network 110 of member platforms. For example, the partner platform 420 and service provider platform 440 may include a single member platform (e.g., member platform 112c). In addition or alternatively, the partner platform 420 and service provider platform 440 may include one or more different member platforms (e.g., member platforms 112a and 112b). In some examples, a user may interact with one or more of the platforms through a client device 104.
[0096] In some embodiments, the exchange platform 102 is a computing entity configured to facilitate credential-free exchange of value for one or more members in a network. The exchange platform 102 may include one or more processing devices, memory devices, and / or similar, physically and / or wirelessly coupled and configured to perform one or more computing tasks collectively (and / or individually) to facilitate exchanges independent of the value system. In some examples, the exchange platform 102 may include, define, and / or otherwise utilize one or more exchange interfaces to facilitate communication (e.g., requests, responses, etc.) between multiple members. As described herein, interfaces may be utilized to facilitate secure exchanges between one or more members in any value system.
[0097] In some embodiments, a member is an entity that collaborates with the exchange platform 102 to participate in a value exchange. For example, a member may include (i) a partner that utilizes the exchange platform 102 to receive value, (ii) a service provider that utilizes the exchange platform 102 to provide value, and / or (iii) both a partner and a service provider. As used herein, a member may be called a partner when receiving value through a value exchange, and / or a service provider when providing value through a value exchange. Thus, depending on the member's role in the value exchange, the same member may be both a partner and a service provider. For example, a member may be a partner that receives value for a value exchange. The same member may be a service provider that provides value in another value exchange. In some examples, the same member may be both a partner and a service provider in the same value exchange, and thus the member utilizes the exchange platform 102 to provide value in a single member value exchange and then receive value.
[0098] In some embodiments, a member is a partner when using services provided by a service provider. A partner can include any value-seeking entity in any value system. For example, in a financial value system, a partner can include a merchant (e.g., a retailer, a storefront, etc.) who may use a service provider, such as a financial institution, to access funds for financial transactions. Additionally or alternatively, in an information value system, a partner can include a news publisher (e.g., a newspaper, a press organization, etc.) who may use a service provider, such as a news agency (e.g., a wire service, a news service, etc.), to access information for information transactions. Naturally, the technology of this disclosure may be applied to any value system, and a partner can include any value-seeking entity for any respective value system.
[0099] In some embodiments, a Member is a Service Provider when providing services to a Partner. A Service Provider can include a source of value in any value system. For example, in a financial value system, a Service Provider can include a financial institution (e.g., a bank, foreign exchange, credit union, etc.) that can provide access to funds for financial transactions between one or more entities. Additionally or alternatively, in an information value system, a Service Provider can include a news agency (e.g., a wire service, news service, etc.) from which news publishers can provide information for publication. Naturally, the technology of this disclosure may be applied to any value system, and a Service Provider can include any source of value for any respective value system.
[0100] Service providers and partners can communicate through one or more member platforms associated with the entity, respectively. For example, a service provider may be associated with service provider platform 440, and a partner may be associated with partner platform 420.
[0101] In some embodiments, the member platform is a computing entity corresponding to a member associated with the exchange platform 102. The member platform may include a partner platform 420 that acts on behalf of a partner, a service provider platform 440 that acts on behalf of a service provider, and / or both. In some examples, the member platform may be both the partner platform 420 and the service provider platform 440. For example, the same member platform may be configured to act on behalf of a partner for one value exchange and a service provider for another value exchange. In some examples, the same member platform may be configured to act on behalf of both a partner and a service provider in a single value exchange. It should be noted that the term member platform may refer to the partner platform 420, the service provider platform 440, or both, and in some examples, it may depend on the role of the member platform in the value exchange (e.g., and / or one or more interfaces utilized by the member platform in the value exchange).
[0102] In some embodiments, the partner platform 420 is a computing entity configured to perform one or more actions on behalf of the partner. The partner platform 420 may include one or more processing devices, memory devices, and / or similar, physically and / or wirelessly coupled and configured to perform, for example, one or more computing tasks collectively (and / or individually) for requesting value in a value system-independent exchange. In some examples, the partner platform 420 may include, define, and / or otherwise utilize one or more exchange interfaces to facilitate communication (e.g., requests, responses, etc.) with the exchange platform 102. In some examples, the partner platform 420 may be configured to host one or more user-facing applications (e.g., partner applications) for interacting with one or more users.
[0103] The Partner Platform 420 can host an online marketplace for Partners, for example in a financial value system, enabling users to interact with one or more products or services offered by Partners (e.g., search, browse, buy, return, etc.). In the case of product purchases, the Partner Platform 420 can work with one or more service providers to access funds for the purchase. Traditionally, access to funds from service providers is facilitated using card numbers, account numbers, and / or other financial credentials, which can expose users to malicious parties. To address network security and data privacy concerns for traditional financial systems (and / or other value-based systems), the Partner Platform 420 can register with the Exchange Platform 102 by configuring one or more software development kits (SDKs), APIs, and / or similar to facilitate communication with the Exchange Platform 102. For example, the partner platform 420 may include, define, and / or otherwise utilize one or more partner interfaces 402 to facilitate communication (e.g., requests, responses, etc.) with the exchange platform 102.
[0104] In some embodiments, the service provider platform 440 is a computing entity configured to perform one or more operations on behalf of the service provider. The service provider platform 440 may include one or more processing devices, memory devices, and / or similar, physically and / or wirelessly coupled and configured to perform one or more computing tasks collectively (and / or individually) to deliver value in a value system-independent exchange. In some examples, the service provider platform 440 may include, implement, and / or otherwise utilize one or more interfaces to facilitate communication (e.g., requests, responses, etc.) with the exchange platform 102. In some examples, the service provider platform 440 may be configured to facilitate one or more service provider instruments. In some examples, the service provider platform 440 may be configured to host one or more user-facing applications (e.g., service provider applications, etc.) for managing one or more service provider instruments.
[0105] In some examples, the service provider platform 440 may maintain one or more financial assets (e.g., credit limits, bank accounts, etc.) that enable a user to fund a transaction to purchase a product from a partner, for example, in a financial value system. In the case of a product purchase, the service provider platform 440 may work with the partner platform 420 to authorize the transaction and / or otherwise provide access to funds for the purchase. Traditionally, access to funds from a service provider has been facilitated by presenting card numbers, account numbers, and / or other financial credentials to the service provider platform 440, which could expose the user, service provider, or partner to a malicious party, especially when provided over an insecure network (e.g., a public network, and / or similar). To address network security and data privacy concerns with respect to conventional financial systems (and / or other value-based systems), the service provider platform 440 may register with the exchange platform 102 by configuring one or more software development kits (SDKs), APIs, and / or similar to facilitate communication with the exchange platform 102. For example, the service provider platform 440 may include, implement, and / or otherwise utilize one or more service provider interfaces 404 to facilitate communication (e.g., requests, responses, etc.) with the exchange platform 102.
[0106] As described herein, the service provider interface 404 can enable the exchange platform 102 to identify and request the use of service provider instruments to facilitate transactions. For example, the service provider platform 440 may be configured to facilitate one or more service provider instruments.
[0107] In some embodiments, a service provider instrument is a mechanism leveraged by a service provider to deliver value (e.g., on behalf of a specific user, organization, etc.). A service provider instrument may depend on the value system and / or the service provider. In some examples, a service provider instrument may include the service provider's accounts. For example, in a financial value system, a service provider instrument may include bank accounts (e.g., checking accounts, savings accounts, etc.), securities accounts, credit limits, and / or similar. In information value systems, profit value systems, and / or similar, a service provider instrument may include member accounts and / or similar. In some examples, a service provider instrument may include virtual instruments (e.g., virtual accounts, credit limits, etc.) hosted by the service provider platform 440. For example, the service provider platform 440 may be configured to maintain multiple member instrument data objects representing multiple service provider instruments for multiple associated entities.
[0108] In some embodiments, an instrument data object is a data entity representing a service provider instrument. An instrument data object may contain one or more instrument identifiers and / or one or more instrument attributes. In some examples, the one or more instrument identifiers and / or one or more instrument attributes may be based on the type of the instrument data object. For example, a service provider instrument may be represented as a member instrument data object in a member platform (e.g., service provider platform 440). Alternatively, a service provider instrument may be independently represented by a system instrument data object in exchange platform 102. In some examples, member instrument data objects and system instrument data objects may contain one or more of the same one or more instrument identifiers and / or one or more instrument attributes. For example, a member platform can register multiple service provider instruments with the exchange platform 102 (for example, using the service provider interface 404). During registration, the member platform (for example, the service provider platform 440) can provide one or more instrument identifiers and / or instrument attributes, and in some examples, the exchange platform 102 can return a different identifier.
[0109] In some embodiments, the Member Instrument Data Object is an internal representation of a Service Provider Instrument within a Member Platform, such as the Service Provider Platform 440. The Member Instrument Data Object may include one or more instrument identifiers, such as a Member Instrument Identifier, an Instrument Key from the Exchange Platform 102, and / or a User Identifier. The User Identifier may include, for example, a Member User Identifier, as described herein. Additionally or alternatively, the Member Instrument Data Object may include one or more instrument attributes, such as an Instrument Type (e.g., a Credit-Based Instrument, a Debit-Based Instrument, an Information-Based Instrument), an Instrument Representation, and / or one or more contextual attributes. In some examples, the contextual attributes may depend on the Value System. For example, in a financial value system, one or more contextual attributes may indicate (i) the currency associated with the service provider instrument, (ii) the asset availability of the service provider instrument (e.g., balance, coverage, etc.), or (iii) one or more previous transactions and / or similar transactions at the service provider instrument.
[0110] In some embodiments, a system instrument data object is an external representation of a service provider instrument within the exchange platform 102. The system instrument data object may include one or more instrument identifiers, such as a member platform instrument reference, a system instrument identifier, and / or a user identifier. The user identifier may include, for example, a system user identifier, as described herein. Additionally or alternatively, the system instrument data object may include one or more instrument attributes, such as an instrument type (e.g., credit-based instrument, debit-based instrument, information-based instrument), an instrument representation, and / or one or more contextual attributes. In some examples, the contextual attributes may depend on a value system. For example, in a financial value system, one or more contextual attributes may indicate the currency associated with the service provider instrument.
[0111] In some examples, member platforms, such as the partner platform 420 and / or the service provider platform 440, may be associated with user-facing applications to facilitate one or more interactions with users and / or other associated entities (e.g., through client device 104).
[0112] In some embodiments, a user application is a computer program hosted by a computing entity to facilitate one or more user interactions. A user application may include software (e.g., computer-readable instructions) designed to perform one or more computing tasks for a computing entity, such as a member platform. For example, a user application can facilitate communication between a member and a user. As an example, a user application may be configured to present one or more user interfaces 406 (e.g., via a client device 104) for interacting with the user on behalf of the member. In some examples, a user application may be configured to receive user input (e.g., via one or more user interfaces 406) for receiving information from the user.
[0113] In some embodiments, the user application is a partner application 416 hosted by a partner platform (e.g., a member platform that acts as a partner for a particular exchange) to facilitate functionality for the partner. The partner application may include software (e.g., computer-readable instructions) designed to perform one or more computing tasks for the partner. In some examples, the partner application 416 may consist of one or more devices (e.g., point-of-sale terminals) from a standalone partner facility (e.g., a bank with a physical store). For example, the partner application 416 may be configured to present one or more user interfaces 406 for interacting with (e.g., browsing, purchasing, scrutinizing, etc.) one or more products offered by a retail-based partner, one or more units of information offered by an information-based partner, and / or similar. In some examples, the partner application 418 may be configured to receive user input (e.g., via one or more user interfaces 406) for receiving information from the user.
[0114] In some embodiments, the service provider platform 440 is configured to host one or more service provider applications 418 for managing one or more service provider instruments. For example, the user application may also be a service provider application 418 hosted by the service provider platform 440 (e.g., a member platform acting as a service provider for a particular exchange) to facilitate functionality for the service provider. In some examples, the service provider application 418 may consist of one or more devices from a standalone service provider facility (e.g., a bank with a physical branch). The service provider application 418 may include software (e.g., computer-readable instructions) designed to perform one or more computing tasks for the service provider. For example, the service provider application 418 may be configured to present one or more user interfaces for interacting with one or more service provider instruments (e.g., scrutinizing, managing, inspecting, registering, etc.) facilitated by the service provider. For example, in a financial value system, the service provider application 418 may enable access to bank accounts, securities accounts, credit limits, and / or similar entities to manage funds, assets, and / or similar entities handled by each account. In some examples, the service provider application 418 may be configured to receive user input (e.g., via one or more user interfaces 406) to receive information, permissions, and / or similar entities from the user.
[0115] In some embodiments, the exchange platform 102 facilitates communication between the partner platform 420 and the service provider platform 440 using one or more exchange interfaces.
[0116] In some embodiments, the exchange interface is a set of instructions for facilitating communication between the exchange platform 102 and one or more member platforms and / or internal services. The exchange interface may include APIs, file-based interfaces, message queue-based interfaces, and / or similar. For example, the exchange interface may include APIs, such as one or more Simple Object Access Protocol (SOAP) APIs, one or more Remote Procedure Call (RPC) APIs, one or more WebSocket APIs, one or more Representational State Transfer (REST) APIs, and / or similar. In some embodiments, the exchange interface may include one or more RPC APIs, such as one or more gRPC APIs.
[0117] The exchange platform 102 may include, define, and / or otherwise utilize one or more different exchange interfaces to facilitate communication with one or more external platforms, such as one or more member platforms (e.g., partner platform 420, service provider platform 440, etc.). Each interface may include multiple communication instructions, message definitions, and / or similar for exchanging requests and / or responses between the exchange platform 102 and entities participating in value exchange. For example, an exchange interface may include a partner interface 402 to facilitate communication with partner platform 420, and / or a service provider interface 404 to facilitate communication with service provider platform 440.
[0118] In some embodiments, the partner interface 402 is an exchange interface for facilitating one or more communications between the partner platform 420 and the exchange platform 102. The partner interface 402 may define one or more communication instructions, message definitions, and / or similar for facilitating one or more request messages and / or response messages between the partner platform 420 and the exchange platform 102. The partner interface 402 may include, for example, APIs that define (i) requests from a computing entity acting as the partner platform 420 to the exchange platform 102, and / or (ii) requests from the exchange platform 102 to the partner platform 420. For example, the partner interface 402 may define one or more registration messages, session messages, transaction messages, and / or similar for facilitating value exchange for partners. In some embodiments, the partner interface 402 defines one or more identifiers for securely identifying one or more parts of a value exchange.
[0119] In some embodiments, the service provider interface 404 is an exchange interface for facilitating one or more communications between the service provider platform 440 and the exchange platform 102. The service provider interface 404 may define one or more communication instructions, message definitions, and / or similar for facilitating one or more request messages and / or response messages between the service provider platform 440 and the exchange platform 102. The service provider interface 404 may include, for example, APIs that define (i) requests from a computing entity acting as the service provider platform 440 to the exchange platform 102, and / or (ii) requests from the exchange platform 102 to the service provider platform 44. The service provider interface 404 may define one or more registration messages, session messages, transaction messages, and / or similar for facilitating value exchange using the service provider instrument. In some embodiments, the service provider interface 404 defines one or more identifiers for securely identifying one or more parts of a value exchange.
[0120] The exchange platform 102 can facilitate communication between member platform networks. For example, a member network may include multiple entities that have the exchange platform 102 installed, for example, by registering with the exchange platform 102, configuring their respective interfaces for communicating with the exchange platform 102, and / or similar means. In some examples, the exchange platform 102 may run one or more individual services to interact with each installed entity. Individual services may include, for example, one or more partner services 410 and / or service provider services 412.
[0121] In some embodiments, the exchange platform 102 exemplified a partner service 410, which is a separate partner-specific service for each of the member networks. Additional or alternative, for example in a multi-tenant environment, the partner service 410 may be exemplified for one or more partners from the network or members. The partner service 410 may be configured to perform one or more exchange operations to resolve exchange requests from the partner platform 420. In some embodiments, the exchange platform 102 exemplified a service provider service 412, which is a separate service provider-specific service for each of the member networks. Additional or alternative, for example in a multi-tenant environment, the service provider service 412 may be exemplified for one or more service providers from the network or members. The service provider service 412 may be configured to perform one or more exchange operations to acquire and resolve exchange requests from the partner platform 420. The exchange operations may include any of the steps and / or operations described herein.
[0122] In some embodiments, partner service 410 and / or service provider service 412 interact with each other and / or with one or more other components of the exchange platform 102 through one or more local communication mechanisms to perform exchange operations. For example, the exchange platform 102 may include connectivity service 408 configured to establish, maintain, and verify secure network sessions with member platforms such as partner platform 420. In some examples, connectivity service 408 and / or partner service 410 may work together to register users (and / or the users' service provider instruments) with the exchange platform 102. Additionally or alternatively, partner service 410 and / or service provider service 412 may work together to register users (and / or the users' service provider instruments) and / or to facilitate value exchange between partner platform 420 and service provider platform 440. In some examples, connection service 408 may be part of partner service 410.
[0123] Through the performance of one or more exchange operations, Partner Service 410 and / or Service Provider Service 412 may generate and utilize a number of unconventional identifiers for referring to users, service provider instruments, and / or one or more aspects of value exchange. At least some of these identifiers may include universally unique identifiers, such as UUEKs, which may be utilized to provide value credential-free exchanges. Each identifier may be stored at least temporarily in the platform data vault 414. The platform data vault 414 may include any type of memory device as described herein. In some examples, each service, and / or one or more sets of services, may be associated with individual parts of the platform data vault 414.
[0124] As described herein, one or more identifiers may be stored in association with each other to form an identifier mapping that can be utilized by the exchange platform 102 (and / or one or more of its services) to refer to users, service provider instruments, and / or any other aspect of value exchange from communications between the partner platform 420, the service provider platform 440, and / or any other member platform that does not include user credentials. Examples of unconventional identifiers will be described further herewith reference to Figure 5.
[0125] e. Exemplary data structure Figure 5 is an exemplary data diagram 500 for facilitating value credential-free exchange according to one or more embodiments of the present disclosure. Data diagram 500 illustrates several related identifiers of different types. As depicted, each identifier may be associated with at least one related identifier to form an identifier mapping within one or more platforms, such as exchange platform 102 and / or service provider platform 440. The identifier mapping enables communication between exchange platform 102 and service provider platform 440 that references service provider instrument 518 without disclosing persistent credentials 514 (e.g., username, password, card number, etc.) associated with the service provider instrument 518, which are susceptible to fraud, abuse, and exploitation by malicious parties. Using some of the technology of the present disclosure as illustrated, persistent credentials 514 may not need to be communicated outside of service provider platform 440. Data Figure 500 illustrates only a fraction of the identifiers that may be generated, stored, and / or utilized by various embodiments of this disclosure. It will be understood that the exemplified identifiers are not exhaustive and may include other identifiers not exemplified. Each identifier may be labeled as an identifier, reference, key, and / or other similar term. These terms are used herein without distinction to refer to units of information for identifying data structures, entities, and / or any other components described herein.
[0126] As illustrated, some of the multiple related identifiers in various embodiments of the present disclosure may, for example, be: (i) one or more user references 502 which can be mapped to member user identifiers 522 of the service provider platform 440; (ii) one or more service provider partitions 504 corresponding to the network of an installed service provider platform, such as the service provider platform 440; (iii) one or more partner partitions 506 corresponding to the network of an installed partner platform; and (iv) member instrumentation of the service provider platform 440. (v) one or more instrument references 520 which can be mapped to instrument identifier 508, (v) one or more keys 516 and / or system identifiers 512 which can be associated with user reference 502 and / or instrument reference 520, (vi) one or more exchange identifiers 510 which can be mapped to either system identifier 512 and / or key 516, and / or (vii) one or more UUEKs 524 which can be mapped to at least one of exchange identifiers 510 and / or partner partitions 506 and / or service provider partitions 504.
[0127] In some examples, the service provider platform 440 may store one or more identifiers that can be mapped to the service provider instrument 518, and / or one or more identifiers of the exchange platform 102, to enable the service provider platform 440 to refer to the service provider instrument 518, at least in part on identifiers that do not indicate any aspect of the service provider instrument 518, including the persistent credentials 514, by themselves.
[0128] For example, the service provider platform 440 may store, maintain, and / or otherwise access one or more keys 516 that are mapped to one or more system identifiers 512 of the exchange platform 102 (e.g., copies, derivatives, etc., of one or more system identifiers 512). A key 516 may, for example, include a system identifier 512 as part of the key 516. A key 516 may be mapped to a member instrument identifier 508 and / or a member user identifier 522 that may internally reference users and / or service provider instruments 518 of the service provider platform. A key 516 may be provided, for example, during a registration process between the service provider platform 440 and / or the exchange platform 102.
[0129] As another example, exchange platform 102 may store, maintain, and / or otherwise access one or more references, such as instrument reference 520 and / or user reference 502, which are mapped to one or more member identifiers (e.g., duplicates, derivatives, etc.) such as member instrument identifier 508 and / or member user identifier 522 of service provider platform 440. The references may be provided, for example, during the registration process between service provider platform 440 and / or exchange platform 102.
[0130] In some embodiments, the exchange platform 102 uses one or more entity partitions to refer to each member platform in the network of member platforms. In some embodiments, the entity partition is a unique identifier for a computing entity. The entity partition may include a unique number, alphanumeric character, and / or similar that represents a particular computing entity. The entity partition may include, for example, a member partition representing a member platform, a service provider partition 504 representing a service provider platform 440, a partner partition 506 representing a partner platform 420, and / or similar.
[0131] In some embodiments, the service provider partition 504 is a unique identifier for the service provider and / or the service provider's service provider platform 440. The service provider partition 504 may include a series of numbers, alphanumeric characters, or any other characters or symbols representing a service provider associated with (e.g., installed, registered, etc.) the exchange platform 102. The exchange platform 102 may include multiple service provider partitions, each identifying a service provider platform 440 that is attached to (e.g., installed, registered, etc.) the exchange platform 102. Each service provider partition 504 may represent a service provider platform 440 comprising one or more exchange platform software development kits (SDKs) and / or similar for implementing the service provider interface of the exchange platform 102.
[0132] In some embodiments, the partner partition 506 is a unique identifier for the partner and / or the partner's partner platform. The partner partition 506 may include a series of numbers, alphanumeric characters, or any / or other characters or symbols representing the partner associated with the exchange platform 102. The exchange platform 102 may include multiple partner partitions, each identifying a partner platform that is attached to the exchange platform 102 (e.g., mounted, registered, etc.). Each partner partition 506 may represent a partner platform that constitutes one or more exchange SDKs and / or similar for implementing the partner interface of the exchange platform 102.
[0133] In some embodiments, entity partitions are generated to identify members when member platforms are installed on exchange platform 102. In some examples, after being installed on the exchange platform, member platforms can leverage one or more exchange interfaces to register one or more service provider instruments with exchange platform 102. Service provider instruments 518 may register with exchange platform 102 by exchanging one or more instrument identifiers with exchange platform 102.
[0134] In some embodiments, the instrument identifier includes any representation of the service provider instrument 518 that identifies the service provider instrument without disclosing the service provider instrument's persistent credentials 514. The instrument identifier may include a member instrument identifier 508, a system instrument identifier, an instrument reference 520, an instrument key, and / or similar, as described herein.
[0135] In some embodiments, the member instrument identifier 508 is a unique identifier for representing the service provider instrument 518 within a member platform, such as the service provider platform 440. The member instrument identifier 508 may include, for example, a series of numbers, alphanumeric characters, or any other characters or symbols that represent the service provider instrument 518 for the service provider platform 440. In some examples, the member instrument identifier 508 may include a table identifier for a member instrument data object.
[0136] In some embodiments, the instrument reference 520 is a unique identifier for referencing the member instrument identifier 508. The instrument reference 520 may be generated and / or provided to the exchange platform 102 by the member platform, for example, to allow the exchange platform 102 to reference a service provider instrument 518 maintained on the member platform. In some examples, the instrument reference 520 is the same value as the member instrument identifier 508. In some examples, the instrument reference 520 is a different value mapped to the member instrument identifier 508.
[0137] In some embodiments, the system instrument identifier is a unique identifier for representing the service provider instrument 518 within the exchange platform 102. The system instrument identifier may include a series of numbers, alphanumeric characters, or any other characters or symbols that represent the service provider instrument 518 to the exchange platform 102 without disclosing the service provider instrument 518's persistent credentials 514. In some examples, the system instrument identifier may include a UUID. In some examples, the system instrument identifier may include at least one of the system identifiers 512.
[0138] In some embodiments, the instrument key is a unique identifier for referencing a system instrument identifier. The instrument key may be generated and / or provided by the exchange platform 102, for example, during the registration process of a service provider instrument 518 to the exchange platform 102. In some examples, the instrument key may include a packaged system instrument identifier. For example, the instrument key may include a string of alphanumeric characters formatted according to a key format established by the exchange platform 102 (and / or one or more of its APIs). The key format may include any number of characters, such as 50 or more. In some examples, the characters may be case-sensitive. A first part of the characters (e.g., the first six characters) may be reserved as a partition for identifying the entity associated with the key. In the case of an instrument key, for example, the partition may include a service provider partition 504. A second part of the characters may identify the system instrument identifier. In some examples, the instrument key may include at least one of the keys 516. The key formats described herein may include one or more different parts, each of which may be arranged in any order.
[0139] In some embodiments, after being deployed on the exchange platform 102, the member platform may utilize one or more exchange interfaces to register one or more users with the exchange platform 102. Users may register with the exchange platform 102 by exchanging one or more user identifiers with the exchange platform 102. User identifiers may be used, for example, to generate, maintain, and / or update one or more user data objects that reflect users of the member platform and / or the exchange platform 102.
[0140] In some embodiments, a user data object is a data entity representing a user interacting with the member platform and / or exchange platform 102. The user may include entities (e.g., people, organizations, groups, etc.) engaged in value exchanges governed by the exchange platform 102. In some examples, the user may indirectly interact with the exchange platform 102 by creating user accounts for registered service providers, registering (and / or granting permission to register) service provider instruments 518, and / or similar actions. In some examples, the exchange platform 102 may function on behalf of the user without the user directly interacting with the exchange platform 102. For example, the exchange platform 102 may act as a hidden intermediary between a user application and the user's service provider instrument 518.
[0141] In some embodiments, a user data object includes one or more user identifiers and / or one or more user attributes. In some examples, one or more user identifiers and / or one or more user attributes may be based on the type of the user data object. For example, a user may be represented as a member user data object in a member platform. Additionally or alternatively, a user may be independently represented by a system user data object in an exchange platform. In some examples, member user data objects and system user data objects may include one or more of the same one or more user identifiers and / or user attributes. For example, a member platform may register multiple users with the exchange platform 102. During registration, the member platform may provide one or more of the user identifiers and / or user attributes, and in some examples, the exchange platform 102 may return a different identifier.
[0142] In some embodiments, a member user data object is an internal representation of a user within a member platform, such as the service provider platform 440. A member instrument data object may include one or more user identifiers, such as a member user identifier 522, a user key from the exchange platform 102, and / or similar. Additionally or alternatively, a member user data object may include one or more user attributes. One or more user attributes may represent one or more contextual characteristics of the user. In some examples, a user attribute may represent one or more identifiable characteristics of the user. For example, a user attribute may represent the user's first name, last name, email, actual address (e.g., one or more of street, local, region, zip code, country, etc.), date of birth (e.g., birth date, age group, etc.), telephone number, and / or similar. In some examples, a user attribute may include encrypted, hashed, and / or otherwise secure representations of the user's identifiable characteristics. For example, a user attribute may include one or more hashed identifiers and / or similar of the user.
[0143] In some embodiments, a system user data object is an external representation of a member user within the exchange platform 102. The system user data object may include one or more user identifiers, such as a member platform user reference 502, a system user identifier, and / or similar. Additionally or alternatively, the system user data object may include one or more user attributes, such as those described herein. For example, a member platform may register a user with the exchange platform 102. During registration, the member platform may provide the user's user reference 502 and / or one or more user attributes. In some examples, the user attributes may include the user's hashed and / or encrypted identifier.
[0144] In some embodiments, the user identifier includes a unique identifier for a user involved in value-based exchange. The user identifier may include a series of numbers, alphanumeric characters, or any other characters or symbols representing a user of the exchange platform 102 and / or a member platform. In some examples, the user identifier may include a user reference 502, a user key, a system user identifier, a member user identifier, and / or similar.
[0145] In some embodiments, the system user identifier is a unique identifier for representing a user within the exchange platform 102. The system user identifier may include, for example, a series of numbers, alphanumeric characters, or any / or other characters or symbols that represent a user to the exchange platform 102. In some examples, the system user identifier may include a UUID specific to a particular user. In some examples, the system user identifier may include at least one of the system identifiers 512.
[0146] In some embodiments, the member user identifier 522 is a unique identifier for representing a user within the member platform. The member user identifier may include, for example, a series of numbers, alphanumeric characters, any / or any other characters or symbols that represent a user to the service provider platform 440.
[0147] In some embodiments, the user reference 502 may also be a unique identifier for referring to the member user identifier 522. The user reference 502 may be generated and / or provided to the exchange platform 102 by the member platform, for example, so that the exchange platform 102 can refer to users associated with the member platform. In some examples, the user reference 502 is the same value as the member user identifier 522. In some examples, the user reference 502 is a different value mapped to the member user identifier 522.
[0148] In some embodiments, the user key is a unique identifier for referencing a system user identifier. The user key may be generated and / or provided by the exchange platform 102, for example, during the user registration process with the exchange platform 102. In some examples, the user key may include a packaged system user identifier. For example, the user key may include a string of alphanumeric characters formatted according to a key format established by the exchange platform (and / or one or more of its APIs). The key format may include, for example, a first part of the characters (e.g., the first six characters) which may be reserved as a partition for identifying entities associated with the key (e.g., members). For example, in the case of a user key, the partition may include a service provider partition 504 and / or a partner partition. The second part of the characters may identify the system user identifier.
[0149] As illustrated by Figure 5, keys 516, such as user and instrument keys described herein, may be shared across the exchange platform 102 and the service provider platform 440. In addition, in some examples, references, such as instrument references 520 and user references 502, may be shared across entities. These identifiers and the mapping scheme described herein enable the exchange platform 102 to refer to the service provider instrument 518 without knowledge of the service provider instrument 518's persistent credentials 514 (e.g., card number). As described herein, one or more of the keys 516 and / or references may be provided to the service provider platform 440 individually or in any combination. In some examples, each of the key 516 and the reference may be provided to the service provider platform 440 in a redundant process that allows the service provider platform to verify that communication is provided by the exchange platform 102 (for example, an entity with access rights to a specific set of keys and references).
[0150] In some embodiments, the persistent credentials 514 for the service provider instrument 518 include highly sensitive user and / or instrument credentials, such as card numbers, account numbers, subscription numbers, and / or similar, which could expose users, members, and / or intermediate entities to risk. The persistent credentials 514 may be generated, accessed, and / or otherwise provided to the user by the service provider platform 440 when the user applies for a new service provider instrument 518, is authorized to use the new service provider instrument 518, and / or is otherwise enabled to open the new service provider instrument 518. Traditionally, the persistent credentials 514 are then used by the user to initiate a value exchange using the service provider instrument. By doing so, the user is compelled to disclose highly sensitive credentials directly linked to the service provider instrument 518 each time the service provider instrument 518 is used. The key 516, reference, and identifier mapping scheme of this disclosure overcomes these technical shortcomings.
[0151] In some examples, each identifier is interpretable not by the user, but by a computing platform such as the exchange platform 102 and / or the service provider platform 440. To allow the user to select the service provider instrument 518 while maintaining the enhanced security features of this disclosure, in some examples, the identifiers in Figure 5 may be further enhanced by instrument representations.
[0152] In some embodiments, the instrument representation (not depicted in Figure 5) is a unique identifier for representing the service provider instrument 518 to a user without exposing the persistent credentials 514 of the service provider instrument 518. The instrument representation may include a series of numbers, alphanumeric characters, or any other characters or symbols that visually represent the service provider instrument 518 only to entities that have prior knowledge of the service provider instrument 518. The format and / or value of the instrument representation may be based at least in part on the type of service provider and / or service provider instrument 518. For example, in a financial value system, the instrument representation may include a portion of the persistent credentials 514 (e.g., the last four digits), such as a card number (e.g., debit card, credit card, etc.), a financial account number, and / or similar. As another example, in an information value system, an instrument representation may include a portion of a persistent credential 514 (e.g., one or more digits, alphanumeric characters, etc.), such as a subscription account and / or similar. For example, an instrument representation may include a derivative of a persistent credential 514, which may allow only entities with prior knowledge of the persistent credential 514 to use the instrument representation to identify the persistent credential 514. As yet another example, an instrument representation may include a nickname for the instrument, which is assigned and subsequently recognized by the user.
[0153] In some embodiments, the instrument representation may be provided to the exchange platform 102 (for example, during the registration process) instead of the persistent credentials 514. Thus, the exchange platform 102 can use the instrument representation to represent the service provider instrument 518 without knowledge of the persistent credentials 514 from which the instrument representation may be derived. For example, unlike conventional network-based exchange platforms, the exchange platform 102 does not need to require the persistent credentials 514 corresponding to the service provider instrument 518 to implement the various computing tasks of this disclosure. This further allows the exchange platform 102 to operate more flexibly while storing previously unrecorded contextual data, reducing the computing cost of operations, and improving user and platform protection from intrusion attacks by malicious computing entities.
[0154] In some embodiments, the identifier mapping scheme is supplemented by unique ephemeral keys issued to member platforms to facilitate secure real-time value exchange. For example, exchange platform 102 can facilitate an additional layer of network and data security by implementing exchange identifiers 510 to represent aspects of value-based exchange. Some examples of exchange identifiers 510 may include service provider-specific exchange identifiers and / or partner-specific exchange identifiers. A service provider-specific exchange identifier may include an ephemeral unique exchange identifier that ephemerally represents a service provider instrument 518 and a service provider platform 440. A service provider-specific exchange identifier may, for example, be mapped to a system identifier 512 of a service provider instrument 518. A partner-specific exchange identifier may include an ephemeral unique exchange identifier that ephemerally represents a service provider instrument 518 and a partner platform. A partner-specific exchange identifier may, for example, be mapped to a key 516 of a service provider instrument 518 that can be used to identify a service provider platform 440. In some cases, such mappings can be defined by exchange data objects.
[0155] In some embodiments, an exchange data object is a data entity that represents an authorized value exchange between one or more members associated with the exchange platform 102. In some examples, an exchange data object may include one or more identifiers and / or one or more exchange attributes. For example, one or more identifiers and / or one or more exchange attributes may be based on the type of the exchange data object. For example, an exchange may be represented as a member exchange data object in a member platform. Additionally or alternatively, an exchange may be independently represented by a system exchange data object in the exchange platform 102. In some examples, member exchange data objects and system exchange data objects may include one or more of the same one or more identifiers and / or exchange attributes. For example, using some of the technology of this disclosure, the exchange platform 102 may issue one or more unique identifiers to member platforms that can be used to authorize value exchanges.
[0156] In some embodiments, a system exchange data object is an internal representation of a value exchange mediated using the exchange platform 102. In some examples, a system exchange data object may include one or more different identifiers and / or exchange attributes, depending on the role of the system exchange data object in a value-based exchange.
[0157] For example, a system exchange data object may include a service provider-specific exchange data object corresponding to a service provider platform 440. The service provider-specific exchange data object may include one or more identifiers, such as an exchange identifier 510, a system identifier 512 (e.g., a system user identifier and / or a system instrument identifier), UUEK 524, and / or similar identifiers. Additionally or alternatively, the service provider-specific exchange data object may include one or more exchange attributes, such as an expiration date, currency (e.g., for a financial value system), and / or similar identifiers.
[0158] Additionally or alternatively, a system exchange data object may include a partner-specific exchange data object corresponding to a partner platform. A partner-specific exchange data object may include one or more identifiers, such as an exchange identifier 510, one or more keys 516 (e.g., an instrument key), UUEK 524, a member instrument reference (e.g., a partner-specific instrument reference), and / or similar. Additionally or alternatively, a partner-specific exchange data object may include one or more exchange attributes, such as an expiration date, currency (e.g., in the case of a financial value system), instrument type, and / or similar.
[0159] In some embodiments, the member exchange data object is an external representation of a value exchange mediated using the exchange platform 102. The member exchange data object may include one or more identifiers, such as a member exchange identifier, a member instrument identifier 508, a UUEK 524 from the exchange platform 102, and / or similar.
[0160] In some embodiments, the exchange identifier 510 is a unique identifier for value exchange using the exchange platform 102. The exchange identifier 510 may include a series of numbers, alphanumeric characters, or any other characters or symbols that represent at least a user and / or a service provider instrument 518. In some examples, the exchange identifier 510 may include a universally unique identifier (UUID) that is registered with the exchange platform 102 and can be mapped (e.g., through a series of identifiers) to a user, a service provider instrument 518, and / or a member. In some examples, the exchange identifier 510 may be generated using one or more UUID generators. For example, the exchange identifier 510 may include 16 bytes of information generated according to one or more UUID format standards, such as UUID v4, and / or similar. Therefore, while the exchange identifier 510 can be leveraged by the exchange platform 102 and / or member platforms for one or more functions, the same exchange identifier 510 becomes useless to an external party without a prior association between the exchange identifier 510 and one or more other identifiers. In addition to the prior identifier association, the exchange identifier 510 can be associated with the exchange platform 102. Therefore, even if the exchange identifier 510 is identified by a malicious party, the malicious party should still be required to impersonate the exchange platform 102 in order to use the exchange identifier 510. Moreover, the malicious party should have to update the settlement account to an account owned by the malicious party, among several other tasks, before the exchange identifier 510 can be used to their advantage. Each of these tasks increases the amount of work required to overcome the enhanced layer of security added by the exchange identifier 510. When paired with the transient nature of the exchange identifier 510, these tasks can become incredibly uneconomical.
[0161] In some examples, the exchange identifier 510 may be represented by a UUEK 524. For example, to facilitate credential-free exchanges, the exchange platform 102 may issue one or more UUEK 524s to one or more member platforms. As described herein, the UUEK 524 can eliminate the reliance on traditional persistent credentials 514 by identifying the mode of value exchange through previously mapped data entities.
[0162] In some embodiments, UUEK524 is an external representation of the exchange identifier 510, which can be issued (for example, instead of the exchange identifier 510) to external entities such as users, partner platforms, and / or service provider platforms, and / or similar, in order to initiate a value-based exchange using the exchange platform 102. To do so, UUEK524 can be generated and issued by the exchange platform 102 to external entities. Each UUEK524 may contain multiple values (e.g., up to 50 characters and / or more, case-insensitive or insensitive) that represent one or more aspects of a value-based exchange. For example, the multiple values may represent the exchange identifier 510, a partition (e.g., identifying the recipient of the UUEK524), an identifier type, and / or one or more flags. As an example, UUEK524 may contain a partner-specific UUEK and / or a service provider-specific UUEK. A partner-specific UUEK may be correlated with a partner-specific exchange data object, as described herein, and may include a partner partition 506, while a service provider-specific UUEK may be correlated with a service provider-specific exchange data object, and may include a service provider partition 504.
[0163] For example, a UUEK524 may be generated according to a key format. The key format may contain multiple characters, including, for example, more than 50 characters, and may be case-insensitive. The first part of the characters (for example, the first six characters) may be reserved as a partition to identify the recipient of the UUEK524. The partition may include, for example, a partner partition 506, a service provider partition 504, and / or any other member partition. For example, a UUEK524 may be issued in response to a request from an authorized member, such as an attached partner and / or service provider.
[0164] As an addition or alternative, at least one character of the key format (e.g., the seventh character) may identify the format of UUEK524. At least another character (e.g., the eighth character) may identify the type of UUEK524. In some examples, the second part of the character may identify the exchange identifier 510 (e.g., a group of 22 characters following the eighth character). The third part of the character may be reserved (e.g., a group of 20 characters following the first part of the character). Exemplary representations are provided below: ppppppFiGGGGGGGGGGGGGGGGGGGGrrrrrrrrrrrrrrrrrrrr Here, p represents the partition character, F represents the format character, i represents the identifier type character, G represents the exchange identifier 510, and r represents the reserved character. The key format allows for up to 9.8 × 10^84 unique sortings, which is more than the number of atoms in the known observable universe. This enables the on-demand generation and distribution of new UUEK524s without compromising the security of the underlying data to which the UUEK524 can be mapped, such as identifiers for users, instruments, and / or any other potentially confidential information.
[0165] As described herein, unique sequences of identifiers and mapping schemes between identifiers can facilitate a value credential-free exchange system for registered and / or unregistered entities. In some examples, one or more identifiers may be generated through a registration or registration process configured to establish cross-entity relationships between user, partner, and service provider entities. Exemplary processes for establishing cross-entity relationships are described further herewith reference to Figures 6A–6C.
[0166] V. Exemplary System Operation Figures 6A–6C provide process flows for establishing cross-entity relationships according to one or more embodiments of the present disclosure. The process flows illustrate one or more stages of a registration process 600 for registering user and / or service provider instruments with an exchange platform to facilitate the credential-free exchange of value between a partner platform and a service provider platform. Figures 6A–6C illustrate exemplary process 600 for illustrative purposes. While exemplary process 600 describes a particular sequence of steps / actions, the sequence may be modified without departing from the scope of the present disclosure. For example, some of the steps / actions described may be performed in parallel or in different sequences that do not substantially impact the functionality of process 600. In other examples, different components of an exemplary device or system performing process 600 may perform their functions substantially simultaneously or in separate sequences.
[0167] Various embodiments of Process 600 address the technical challenges of data security and efficiency in network-based exchanges in value exchanges between one or more computing entities. Traditional systems address these challenges using registration mechanisms that require users to expose highly confidential and persistent credentials to third-party registration services. These traditional registration services then activate the user's account ownership and provide persistent credentials to the partner platform for storage and subsequent processing. In doing so, user credentials are transmitted to and exposed to numerous different entities during the traditional registration process, ultimately increasing the risk of exposure to malicious parties during and after network communication. Various embodiments of Process 600 provide improved network communication, data encryption, and data management technologies to enable credential-free exchange registration capabilities that reduce the data security risks imposed by traditional processes.
[0168] One or more embodiments of Process 600 may be implemented by one or more computing devices, entities, and / or systems described herein. For example, through various steps / operations of Process 600, the exchange platform 102 can leverage credential-free registration technology to overcome various limitations associated with conventional registration mechanisms by registering service provider instruments with the partner platform without accessing the service provider instruments' persistent credentials. In doing so, the highly confidential information underlying the service provider instruments for engaging in value exchange is never exposed to potentially malicious parties or partner platforms that may be vulnerable to network-based attacks. For example, unlike traditional technologies, the exchange platform 102 never receives user-identifiable or actionable account information, while service providers managing accounts are engaged in the registration process rather than being excluded by potentially insecure registration services. This further eliminates the need to implement resource data governance standards across each device involved in the registration process, resulting in improved computing resource utilization while ultimately enhancing network and data security.
[0169] Figure 6A is a flowchart illustrating an example of the first stage of a registration process 600 for registering a user on an exchange platform without disclosing persistent credentials associated with the user and / or service provider instrument. The flowchart depicts a communication technique for overcoming various limitations of conventional registration systems by bypassing the conventional system's reliance on confidential and persistent credentials. The communication technique may be performed by one or more computing devices, entities, and / or systems described herein, such as an exchange platform, for establishing a secure communication session with the user through a partner application.
[0170] In some embodiments, process 600 includes establishing registration sessions for the user and partner platform in step / operation 602. For example, the registration process 600 may begin with a partner application (e.g., a partner website, a user application, etc.), at which point the partner platform may allow the user to register their partner account on the partner application with the exchange platform to facilitate access to service provider instruments. The partner platform may enable user registration by initiating a registration session with the exchange platform.
[0171] For example, a user can access a partner application through a portal, such as a browser, web application, and / or similar, via a client device, as described herein. The user's browser, web application, mobile application, and / or similar can issue a communication session request to the partner platform, requesting that it fetch a platform connection widget from a Content Delivery Network (CDN) and establish a registration session. In response to the request, the partner platform can generate a communication session request to the exchange platform (e.g., its partner services) (e.g., using one or more exchange interfaces). The communication session request may include an API request, provided through the partner interface, requesting that the registration widget be initiated to establish a registration session for the user.
[0172] In some embodiments, a communication session request includes one or more registration attributes, such as user data, a user identifier, a user hash, a timestamp, a device identifier, a partner identifier, and / or similar. As described herein, some of the technologies of this disclosure enable a computing entity to identify a service provider instrument using an identifier that does not include the service provider instrument's persistent credentials, along with the communication session request. For example, a partner platform may be configured to retrieve a user's user data (e.g., through user input to a user interface screen, pre-recorded data from a partner account, etc.) and provide the user data to the exchange platform to initiate the registration process. In some examples, user data may be provided by the partner platform (e.g., through one or more API calls to the partner interface, etc.) along with the communication session request to the exchange platform (e.g., its partner service) to initialize a widget session. In some examples, user data may be encrypted, hashed, and / or similar before being transmitted to the exchange platform. In some examples, user data may include one or more user attributes, as described herein.
[0173] In some embodiments, the exchange platform (e.g., its partner service) receives a communication session request using the partner interface, requesting that a registration session be initialized on the user's client device. In some examples, the communication session request may include the user's user data. Additionally or alternatively, the registration initialization request may include one or more user attributes of the user. In some examples, the user attributes may be encrypted and / or hashed, as described herein.
[0174] In some embodiments, process 600 includes setting user and partner data in step / operation 604. For example, an exchange platform (e.g., its connection service, partner service, etc.) can identify and / or generate user and / or partner data from data provided in a communication session request. In some examples, user data may include one or more user attributes. In some examples, user data may include one or more encrypted and / or hashed user attributes. In some examples, partner data may include a shared identifier between the exchange platform and a partner platform, such as a partner partition, as described herein.
[0175] In some embodiments, process 600 includes generating a session identifier for the registration session in step / operation 606. For example, an exchange platform (e.g., its connection service, partner service, etc.) may generate a session identifier for a communication session between the partner platform and the exchange platform for tracking communications exchanged during the registration session. The session identifier may include, for example, a unique number, a string of characters, and / or similar for authenticating messages exchanged during the registration session. The exchange platform may utilize the connection service and / or partner service to establish the registration session. For example, in response to a registration initialization request, the partner service may call another service, such as the connection service, to establish a communication session that can be used by a client-side widget to provide an interface between the user and the partner service for completing user registration. The connection service may generate a session identifier and return it to the partner service. The partner service may return the session identifier to the partner platform, which can utilize the session identifier to initialize a client-side widget through an instance of the partner application on a client device. Once the partner application receives the session identifier, it can launch the client-side widget (e.g., run it, initialize it, etc.). The user can then interact with the widget to complete registration process 600.
[0176] In some embodiments, process 600 includes determining and providing a user member list in step / operation 608. The member list may also be a service provider list. For example, an exchange platform (e.g., its connectivity services, partner services, etc.) can determine a user's service provider list from a network of service providers associated with the exchange platform (e.g., registered, etc.). In some examples, the service provider list may include each service provider platform associated with the exchange platform. Additionally or alternatively, the service provider list may include a subset of associated service provider platforms tailored to the user.
[0177] For example, an exchange platform can determine one or more service provider platforms based at least partially on the user attributes of a registration session and match the service provider list to one or more service provider platforms. As an example, an exchange platform may include multiple system user data objects and / or system instrument data objects, as described herein. In some examples, the exchange platform can identify one or more system user data objects corresponding to a user based on user attributes. In some examples, each system user data object can identify the service provider platform associated with the user. Thus, an exchange platform can determine one or more service providers associated with a user based on one or more system user data objects.
[0178] As an addition or alternative, an exchange platform (e.g., one or more of its service provider services) may provide existence requests for user existence data from each of the service provider platforms in the network of member platforms (e.g., via a service provider interface). A user existence request may include one or more user attributes of a user (e.g., encrypted attributes, hashed attributes, etc.) that can be utilized by the service provider platform to determine whether the user possesses an instrument of that service provider platform. In response to the request, the exchange platform (e.g., one or more of its service provider services) may receive existence data from one or more of the service provider platforms indicating the presence of an instrument of each respective service provider platform. The exchange platform (e.g., its partner services) may determine one or more service providers based at least in part on the existence data.
[0179] In some cases, an exchange platform (e.g., its connectivity services, partner services, etc.) may initiate the presentation of a pre-registration screen based at least partially on one or more service providers, using a partner interface provided by a partner application and via a registration user interface. A client device may be configured to access, for example, a partner application hosted by the partner platform. The registration user interface may be presented to the user on the client device through a widget within the partner application. The widget may be defined internally by the partner or provided by the exchange platform. The pre-registration screen may present multiple selectable icons indicating a list of service providers.
[0180] Next, the registration process 600 can proceed to a second stage, in which an instrument identifier corresponding to the user is identified through interaction between the exchange platform, the user, and the service provider platform, as will be described in more detail with reference to Figure 6B.
[0181] Referring here to Figure 6B, Figure 6B is a flowchart illustrating an example of the second stage of registration process 600 for registering a service provider instrument with a partner platform without disclosing persistent credentials associated with the user and / or service provider instrument. The flowchart depicts communication techniques for overcoming various limitations of conventional registration systems by bypassing the conventional system's reliance on persistent credentials, such as card numbers and / or similar, provided by the user. The communication techniques may be performed by one or more computing devices, entities, and / or systems described herein, such as an exchange platform, for establishing a connection between the user, the partner platform, and the service provider instrument.
[0182] In some embodiments, process 600 includes determining and providing a user's service provider instrument list in step / operation 610. The service provider instrument list may be determined at least in part based on the selection of service providers from a pre-registration screen. For example, in some examples, an exchange platform (e.g., its connection service, partner service, etc.) may receive pre-selection data indicating a selection of a particular service provider from one or more service providers presented by the pre-registration screen, using a partner interface. For example, a widget may receive pre-selection data from a partner application and provide an instrument registration request to the exchange platform (e.g., its connection service, partner service, etc.) (e.g., via a partner interface). The instrument registration request may include a session identifier and / or service provider identifier indicating the selected service provider.
[0183] In response to a request, the exchange platform (e.g., its connection service, partner service, etc.) may receive service provider instrument data that is at least partially based on pre-selected data. The service provider instrument data may indicate one or more service provider instruments of the user, facilitated by the selected service provider platform. For example, the service provider instrument data may include one or more system instrument identifiers and / or corresponding instrument representations from one or more instrument data objects corresponding to the service provider and the user. Each of the instrument data objects may include, for example, a system user identifier corresponding to the user.
[0184] As an addition or alternative, an exchange platform (e.g., one or more of its service provider services) may provide instrument requests for service provider instrument data from a selected service provider platform (e.g., via a service provider interface). An instrument request may include, for example, a user reference corresponding to a member user identifier of the service provider platform. In response to a request, the service provider platform may identify one or more member instrument data objects containing member user identifiers, identify one or more instrument references corresponding to one or more member instrument data objects, and provide the service provider instrument data to the exchange platform, indicating one or more instrument references and / or one or more corresponding instrument representations.
[0185] An exchange platform (e.g., its connection service, partner service, etc.) may initiate the presentation of an instrument registration screen via a user's client device, at least partially based on service provider instrument data, using a partner interface and via a registration user interface. The instrument registration screen may be defined internally by the partner and / or provided by the exchange platform. The instrument registration screen may, for example, show one or more service provider instruments associated with the user and the selected service provider. As an example, the instrument registration screen may show each of the instrument representations of one or more service provider instruments. In some examples, for example, when the user is associated with a single service provider instrument, the instrument registration screen may include a confirmation prompt to confirm the user's intention to register the service provider instrument.
[0186] In some embodiments, process 600 includes receiving selection data in step / operation 612. The selection data may indicate, for example, the selection of a service provider instrument from a registration user interface. For example, the selection data may identify a service provider instrument from a list of service provider instruments associated with the user. Additionally or alternatively, the selection data may indicate confirmation of a single service provider instrument associated with the user.
[0187] For example, an exchange platform can use a partner interface to receive registration instruments along with account requests from client-side widgets. The request may include selection data and / or a session identifier. The selection data may indicate a selection of service provider instruments from the registration user interface. For example, the selection data may indicate the instrument representation of the selected service provider instrument (e.g., the last four digits of the account, the account nickname, etc.). In some examples, the selection data may include at least one of the following: instrument type, currency type (e.g., in a financial value system), and / or instrument identifier (e.g., instrument representation, etc.), corresponding to the selection.
[0188] In some embodiments, the client-side widget may be configured to authenticate the user before initiating a registration instrument with an account request. For example, the client-side widget may be configured to generate a user verification prompt based on at least part of the user data. The user verification prompt indicates a request for confirmation of at least one part of the user data. In some examples, the widget may be configured to present the user verification prompt to the user. In some embodiments, the exchange platform can use a partner interface to initiate the presentation of the user verification prompt. In response to user input indicating confirmation of at least part of the user data (e.g., one or more user attributes), the widget may provide the exchange platform with a registration instrument with an account request.
[0189] In some embodiments, process 600 includes generating a matching code in step / operation 614. In some examples, an exchange platform (e.g., its connection service, partner service, etc.) may generate a matching code. In some examples, a matching code may be generated in response to a registration instrument accompanied by user input indicating confirmation of at least one portion of user data and / or an account request indicating confirmation. An exchange platform (e.g., its connection service, partner service, etc.) may generate a matching code to authenticate a user.
[0190] In some embodiments, the matching code is a session-specific identifier for authorizing a registration session between one or more entities. The matching code may include a series of numbers, alphanumeric characters, and / or similar characters, which may be provided to multiple entities to ensure, for example, that each entity is involved in the same communication sequence. For example, the matching code may include a sequence of one or more different characters of dynamic length (e.g., six, eight characters, etc.), which may be generated by the exchange platform, provided to the service provider platform, and then received from the partner platform (for example, by comparing the received matching code with the generated matching code, as described herein), to ensure that the exchange platform, the service provider platform, and the partner platform are interacting with the same end user, respectively. The one or more different characters may include one or more alphanumeric characters, emojis, kanji, wingdings, and / or similar characters.
[0191] In some embodiments, process 600 includes, in step / operation 616, providing a registration request with a matching code to a service provider platform corresponding to a service provider instrument. For example, an exchange platform (e.g., its service provider service) may use a service provider interface to provide a registration request to the service provider platform corresponding to a service provider instrument. The registration request may include service provider registration data indicating a matching code, one or more user identifiers of a user, and / or one or more instrument identifiers of a service provider instrument. In response to the registration request, the service provider platform may verify the service provider instrument using one or more identifiers.
[0192] Service provider registration data may include one or more identifiers for referencing service provider instruments without using persistent credentials (e.g., card number, account number, etc.) for service provider instruments during communication between the exchange platform, the service provider platform, and / or partner platforms. One or more identifiers may include various combinations of user identifiers and / or instrument identifiers for enabling users and / or instruments through one or more redundant checks. For example, a user identifier for a user may include a user reference on the service provider platform and / or a user key from the exchange platform corresponding to the user reference. As another example, an instrument identifier for a service provider instrument may include an instrument reference on the service provider platform and / or an instrument key from the exchange platform corresponding to the instrument reference.
[0193] Service provider registration data may include any combination of references, keys, and / or identifiers as described herein. In one example, service provider registration data may include one of the following: instrument reference, instrument key, user reference, and / or user key. Additional or alternative, service provider registration data may include corresponding combinations of instrument reference, instrument key, user reference, and user key for inherent redundancy. In some examples, the identifier combination may be specified by an interface call. The combination may be service provider-specific and / or may change dynamically according to the communication scheme. Thus, a particular combination of identifiers provided in a registration request may be used as an additional verification check to ensure that the registration request is received from an associated platform, such as an exchange platform.
[0194] A service provider can compare an identifier from a registration request with one or more member data objects (e.g., a member instrument data object, a member user data object, etc.) to identify a service provider instrument that responds to a registration request without disclosing the persistent credentials of the service provider instrument.
[0195] In some embodiments, process 600 includes receiving a matching code from the partner platform in step / operation 618. For example, the exchange platform may receive an authentication message containing a matching code and / or a session identifier using the partner API. The authentication message may be received from the partner platform in response to user input to the registration user interface.
[0196] The exchange platform can compare a matching code with a previously generated matching code to authenticate a user. For example, a service provider platform may be configured to provide a matching code to a user through one or more prior communication protocols between the service provider platform and the user (e.g., via a service provider application, registered phone number, email address, etc.). When the exchange platform receives a matching code from the partner platform, the exchange platform can verify that the user interacting with the partner platform is an authorized user of the service provider.
[0197] In some cases, the exchange platform can initiate the presentation of an authentication user screen using the partner interface and via the registration user interface. Substantially simultaneously, the service provider platform can provide the user with a matching code (e.g., via a client device and / or other pre-configured means). The user can enter the matching code (e.g., received from the service provider platform) through the authentication user screen, and the partner platform can forward the matching code to the exchange platform. The exchange platform can receive an authentication message using the partner interface, which is at least partially based on the user input to the authentication user screen.
[0198] In some embodiments, the exchange platform authenticates the registration session in response to user authentication based at least in part on a matching code. As will be described in more detail with reference to Figure 6C, upon successful registration, control is returned to the partner application running on the client device requesting the UUEK.
[0199] Referring here to Figure 6C, Figure 6C is a flowchart illustrating an example of the third stage of the registration process 600 for issuing a UUEK to facilitate value credential-free exchange. The flowchart depicts communication techniques to overcome various limitations of conventional registration systems by bypassing the conventional system's reliance on instrument references, such as card numbers and / or similar, provided by the user. The communication techniques may be performed by one or more computing devices, entities, and / or systems described herein, such as an exchange platform, for establishing a user instrument record for registering the user on the exchange platform.
[0200] In some embodiments, process 600 includes, in step / operation 620, activating a registered session based at least in part on a session identifier. For example, an exchange platform may receive a session exchange request via a partner interface to exchange session identifiers of a UUEK. The session exchange request may include a session identifier and a member instrument reference of a service provider instrument. The member instrument reference may include a partner-specific reference of the service provider instrument. The exchange platform (e.g., its partner service) may receive the session exchange request, activate the session identifier (e.g., via its connection service, partner service, etc.) by comparing it with a previously generated session identifier, and activate the registered session in response to the match.
[0201] In some embodiments, process 600 includes generating a UUEK in step / operation 622. For example, an exchange platform may generate a UUEK in response to the activation of a registration session. As an example, an exchange platform may generate UUEKs corresponding to a user, a service provider instrument, and a partner platform. The exchange platform may store the UUEK in a partner-specific exchange data object that associates the UUEK with an exchange identifier, an instrument key, and a partner-specific instrument reference, as described herein.
[0202] In some embodiments, process 600 includes providing the UUEK to the partner platform in step / operation 624. For example, the exchange platform may provide the partner platform with data representing the UUEK using the partner interface. In some examples, the partner platform may provide the UUEK and / or a representation thereof to a user (for example, for storage in a virtual wallet). For example, the UUEK may be represented in one or more different forms, such as a machine-readable optical image (e.g., a barcode, quick-response code, etc.), a keyword, a virtual widget, and / or similar.
[0203] Figures 7A–7D provide message flow diagrams illustrating the steps / actions for establishing cross-entity relationships related to Figures 6A–6C. As recognized, these can be performed and executed by the corresponding steps / actions in Figures 6A–6C. In general, the steps / actions for establishing a secure communication session with a user through a partner application, as illustrated in Figures 7A–7B, may be applicable to and / or related to the steps / actions in Figure 6A. For example, the steps / actions illustrated in Figures 7A–7B may correspond to and / or related to specific actions in the first stage of registration process 600 for registering a service provider instrument with the partner platform without disclosing persistent credentials associated with the user and / or service provider instrument.
[0204] In step / action 702, the partner application 416 fetches a widget (for example, a set of instructions such as a JavaScript widget) from the connection service 408. In step / action 704, the connection service 408 returns the widget and creates a session. In various embodiments, step / action 704 is performed in response to step / action 702.
[0205] In step / action 706, the partner application 416 starts the widget using the partner platform 420 (e.g., a host). In step / action 708, the partner platform 420 initializes the widget by calling the widget initialization function of the partner service 410 using the partner interface (e.g., an Initialize-widget call). In some examples, the widget initialization call may include user data, such as one or more user attributes. In step / action 710, the partner service 410 retrieves and initializes the widget using the partner interface (e.g., an Initialize-widget call) by calling the connection service 408. In various embodiments, step / action 710 is performed in response to step / action 708.
[0206] In step / operation 712, the connection service 408 stores the partner identifier of the partner corresponding to the partner platform 420. In step / operation 714, the connection service 408 stores the user's user data. In step / operation 716, the connection service 408 generates a session identifier to identify the communication session between the partner and the exchange platform. In step / operation 718, the connection service 408 provides the session identifier to the partner service 410. In step / operation 720, the partner service 410 returns the session identifier to the partner platform 420. Also, in step / operation 722, the partner platform 420 returns the session identifier to the partner application 416. In various embodiments, the communication session may be initialized when step / operation 722 is executed.
[0207] Moving to Figure 7B, in step / operation 728, the partner application 416 executes the widget 724 and hands over control to the widget 724 to continue the registration process. The widget 724 is provided with a session identifier and user data. In step / operation 730, the widget 724 sets the session identifier. In step / operation 732, the widget 724 sets the user data. In step / operation 734, the widget 724 uses the partner interface to request a public key from the connection service 408. In step / operation 736, the connection service 408 returns the public key to the widget 724. In step / operation 738, the widget 724 uses the partner interface to request a service provider list from the connection service 408. Also, in step / operation 740, the connection service 408 returns the service provider list. In some examples, in step / operation 742, the widget 724 returns a list of service providers to the partner application 416 for presentation to the user (for example, via a client device).
[0208] Moving to Figure 7C, the registration process can proceed to a second stage, illustrated by the steps / actions in Figure 7C, after establishing a secure communication session with the partner application. In general, the steps / actions illustrated in Figure 7C may be applicable to and / or related to the steps / actions in Figure 6B. For example, the steps / actions illustrated in Figure 7C may correspond to and / or related to specific actions in the second stage of the registration process 600 for registering a service provider instrument with the partner platform without disclosing persistent credentials associated with the user and / or service provider instrument.
[0209] In step / operation 744, partner application 416 receives input indicating a service provider from the service provider list and sends the service provider identifier to widget 724. In step / operation 746, widget 724 sends a request to connection service 408 to initiate registration of service provider instruments for the service provider platform using the partner interface (e.g., widget register instrument initiate call). The request may include a service provider identifier (e.g., service provider partition). In step / operation 748, connection service 408 requests an instrument list corresponding to the user and service provider using the partner interface (e.g., widget register instrument initiate call). In step / operation 750, service provider service 412 returns the instrument list to connection service 408. In step / operation 752, the connection service 408 returns the instrument list to the widget 724, which can then provide the user with a pre-registration screen displaying the instrument list (e.g., one or more instrument representations thereof).
[0210] In step / operation 754, widget 724 receives an input indicating a service provider instrument (e.g., an instrument representation). In step / operation 756, widget 724 verifies the user's user data (e.g., through one or more user verification screens). In step / operation 758, widget 724 provides the connected service 408 with a request to register the service provider instrument using a partner interface (e.g., a widget registration instrument with account call). In various embodiments, step / operation 758 is performed in response to the verification of user data in step / operation 756.
[0211] In step / operation 760, connection service 408 generates a matching code. In step / operation 762, connection service 408 uses a partner interface (e.g., a widget registration instrument with account call) to provide a request to service provider service 412 to register the service provider instrument. The request may include a matching code and a session identifier. In step / operation 764, service provider service 412 uses a service provider interface (e.g., an enroll user instrument call) to provide a request to service provider platform 440 to register the service provider instrument. The request may include an instrument reference, a user reference, a user key, an instrument key, and / or a matching code. Service provider platform 440 registers the service provider instrument and, in step / operation 766, can provide a registration success response to service provider service 412 using the service provider interface. In step / operation 768, the service provider service 412 provides the connection service 408 with data indicating a successful registration response. In step / operation 770, the connection service 408 provides the widget 724 with data indicating a successful registration response.
[0212] On the other hand, in step / operation 772, the service provider platform 440 provides the user with a matching code using one or more prior communication channels. The user can access the matching code and, in step / operation 774, enter the matching code into the verification interface presented by the widget 724.
[0213] In step / operation 776, the widget 724 uses the partner interface to provide a registration completion response to the connection service 408. In various embodiments, step / operation 776 is performed in response to confirmation of the matching code provided in step / operation 774.
[0214] In step / operation 778, the connection service 408 provides a response to the widget 724 indicating that registration was successful. In step / operation 780, the widget 724 provides data indicating the response to the partner application 416.
[0215] Moving to Figure 7D, the registration process can proceed to a third stage, as illustrated by the steps / actions in Figure 7D, after granting user authorization at least in part based on the verification of the matching code as described above. In general, the steps / actions illustrated in Figure 7D may be applicable to and / or related to the steps / actions in Figure 6C. For example, the steps / actions illustrated in Figure 7D may correspond to and / or related to a specific action in the third stage of the registration process 600 for registering a service provider instrument with the partner platform without disclosing persistent credentials associated with the user and / or the service provider instrument.
[0216] In step / operation 782, the partner application 416 provides the partner platform 420 with data indicating that registration was successful. In step / operation 784, the partner platform 420 provides the partner service 410 with a key request using the partner interface. In step / operation 786, the partner service 410 activates the communication session by providing the session identifier to the connection service 408. The connection service 408 compares the session identifier with the identifier issued to initiate the communication session, and if the identifiers match, in step / operation 788, provides the partner service 410 with data indicating the activated session.
[0217] In step / operation 790, the partner service 410 generates the partner's UUEK and exchanges the session identifier for the UUEK. In step / operation 792, the partner service 410 provides the UUEK to the partner platform 420 using the partner interface. In step / operation 794, the partner platform 420 may provide the partner application 416 with an indication that registration was successful. In some examples, the indication of successful registration may include a UUEK representation, such as a barcode, QR code®, and / or similar, to represent the UUEK to the user.
[0218] Having described various actions, processes, methods, functions, and / or similar for registering a user for credential-free transactions, various user interface screens for controlling, initiating, executing, and / or similar steps / actions are provided and described. In various embodiments, the user interface screens provided and described herein are configured to be provided via the user interface of client device 104.
[0219] Figures 8A to 8F provide exemplary user interface flows configured for a client device 104. The user interface flow may include multiple user interface screens configured to guide the user through a credential-free registration process to facilitate credential-free exchange between the partner platform and the service provider platform. In some examples, these transactions may be managed through a user account on the partner platform. For example, user interface screen 802 in Figure 8A includes an account setup screen for entering user attributes 804 for a user account. User interface screen 802 may include a selectable account creation icon 806 for initiating the account creation process. Additionally or alternatively, the user may register with the partner platform through an exchange screen. For example, user interface screen 808 in Figure 8B includes a registration setup screen for entering one or more user attributes 804 through a widget executed by the partner application. User interface screen 808 in Figure 8B may include a selectable registration navigation 810 for proceeding to the next step in the registration process.
[0220] Steps in the registration process may include a user selecting a service provider with a service provider instrument that can be registered on the partner platform. The user interface screen 812 in Figure 8C can facilitate the selection of a service provider by providing a service provider list 814 of selectable icons. In some examples, the service provider list 814 may automatically match user attributes available to the user (e.g., provided through one or more previous user interface screens). The service provider list 814 may, for example, be tailored to the user, and in some examples, may be proactively limited to the service providers to which the user is associated. As shown by the user interface screen 812, the service provider may include financial institutions such as banks and / or similar entities for financial-based value exchange. This is provided as only one example. As described herein, the technology of this disclosure may be applicable to any value exchange system.
[0221] When selecting a service provider, the user may be directed to another user interface screen (not shown) to select the service provider instrument of the service provider. Once selected, the exchange platform can perform a registration process to register the service provider instrument with the partner platform. During the registration process, the user may be transitioned to user interface screen 816 in Figure 8D, which may include a verification prompt 818 for entering a matching code. As shown, the matching code may be automatically provided to the user via a message 822 from the service provider platform by user interface screen 820 in Figure 8E. The user can respond to the verification prompt 818 by entering the matching code and select the submission icon 824 to complete the registration process. The next screen, user interface screen 826 in Figure 8F, may display the user's UUEK representation 828. The UUEK representation 828 may include, for example, a scannable representation of the UUEK (e.g., a barcode, QR code, non-fungible token, or near-field communication sequence). The scannable representation may be stored in the partner account of the partner platform to enable users to perform value-based transactions using the service provider instrument without referring to the service provider instrument's persistent credentials.
[0222] Figure 9 provides a process flow for facilitating value credential-free exchange according to one or more embodiments of the present disclosure. The process flow depicts a communication and data encryption process 900 for securely granting exchange authority in value-independent exchanges, leveraging UUEK. Process 900 can be leveraged to overcome various limitations of traditional exchange systems that expose highly confidential and persistent credentials to numerous third parties, as described herein. Process 900 can be implemented by one or more computing devices, entities, and / or systems as described herein. For example, through various steps / operations of Process 900, an exchange platform can leverage communication and data encryption techniques to overcome various limitations associated with traditional exchange mechanisms by eliminating reliance on statically confidential credentials.
[0223] Figure 9 illustrates an exemplary process 900 for illustrative purposes. While the exemplary process 900 depicts a particular sequence of steps / actions, the sequence may be modified without departing from the scope of this disclosure. For example, some of the steps / actions described may be performed in parallel or in different sequences that do not substantially affect the functionality of process 900. In other examples, different components of an exemplary device or system performing process 900 may perform their functions substantially simultaneously or in a particular sequence.
[0224] In some examples, process 900 begins after the registration process 600 in Figures 6A-6C, where the user and / or partner platform can receive a UUEK to facilitate value credential-free exchange. Nevertheless, process 900 may also be performed before the registration process 600. For example, a user can obtain a UUEK directly from the service provider platform instead of completing the registration process for the partner platform. If the registration process 600 is completed, the value-based exchange may be facilitated by the partner platform using the partner interface and a UUEK specific to the partner platform; otherwise, the value-based exchange may be facilitated by the partner platform using a UUEK specific to the service provider platform and provided by the service provider platform.
[0225] For example, if a user wants to conduct a value-based exchange with a partner with whom they have a registered partner account, the partner platform can search for the registered partner account and identify the user's issued UUEK from that partner account to use when granting authorization for the value-based exchange. If a user wants to conduct a value-based exchange with a partner with whom they do not have a registered partner account, the user can present previously issued UUEK (for example, issued to a service provider platform) to the partner platform (for example, through a partner application), and the partner platform can use the UUEK to grant authorization for the value-based exchange.
[0226] The partner platform can generate an exchange request data object to perform a value-based exchange at least partially based on the UUEK for a specific use case (e.g., the partner UUEK when the user has a registered account, or the service provider UUEK when the user does not have a registered account). The exchange request data object may include request data that identifies the UUEK and transaction attributes of the requested value-based exchange. Process 900 can be initiated when the partner platform issues an exchange request based on the exchange request data object.
[0227] In some embodiments, process 900 includes receiving an exchange request accompanied by a UUEK in step / operation 902. For example, an exchange platform (e.g., its partner service) may receive an exchange request to perform a value-based exchange using its partner interface. The exchange request may include a UUEK and / or one or more transaction attributes.
[0228] Transaction attributes may indicate one or more characteristics of the requested exchange. For example, one or more transaction attributes may include at least one transaction attribute indicating a transaction value (e.g., basket amount). The transaction value may include the sum of one or more line items in a financial exchange, including one or more modifiers such as tax, discount, and / or similar. Continuing with the example of a finance-based value system, in some examples, transaction attributes may include (i) order number, (ii) one or more line item attributes, including sequence, line item group, product code, description, quantity, unit item, grams, kilograms, etc., unit quantity, unit tax amount, line quantity (e.g., line item quantity), line tax amount, etc., and / or (iii) one or more line item adjustments, including sequence, adjustment type (e.g., manufacturing discount, store discount, return, cash payment, gift card payment, other payment, etc.), product code, description, quantity, unit item, grams, kilograms, etc., unit quantity, unit tax amount, line quantity (e.g., line item quantity), line tax amount, and / or similar.
[0229] Additionally or alternatively, transaction attributes may include request approval type (e.g., full or partial), partner transaction reference (e.g., partner platform reference for the transaction), channel (e.g., type of exchange in the case of financial value systems such as push or pull value transfer, real-time payment, etc.), currency (e.g., in the case of financial value systems, etc.), organization key (e.g., platform identifier for the partner organization), organization category (e.g., airline, clothing, etc.), facility key (e.g., platform identifier for a retail location, etc.), clerk identifier, and / or any other traceable information for value-based exchange.
[0230] In some embodiments, process 900 includes verifying the UUEK in step / operation 904. For example, an exchange platform (e.g., its partner service) can look up the UUEK to identify a matching identifier from the platform data vault 414. For example, the UUEK may contain an exchange identifier corresponding to an exchange data object. The exchange platform can identify the exchange identifier at least in part based on the UUEK and leverage the exchange identifier to identify the corresponding exchange data object.
[0231] As described herein, a UUEK may correspond to a partner platform and / or a service provider platform. For example, a UUEK may include a partner partition that identifies the partner platform when the UUEK is issued to a partner platform. In such a case, the UUEK includes an exchange identifier corresponding to a partner exchange data object. Alternatively, a UUEK may include a service provider partition that identifies the service provider platform when the UUEK is issued to a service provider platform. In such a case, the UUEK includes an exchange identifier corresponding to a service provider exchange data object. In some examples, the exchange platform may process the UUEK based on entity partitions.
[0232] In some embodiments, an exchange platform (e.g., its partner service) receives a UUEK containing a partner partition that identifies the partner platform. The exchange platform can use the exchange identifier to identify partner-specific exchange data objects. Partner-specific exchange data objects may include instrument keys corresponding to the service provider instruments of member platforms. The exchange platform can identify system instrument data objects based on the instrument keys. For example, the exchange platform can identify member platforms based on the entity partition of the instrument key and provide instrument keys to services corresponding to member platforms (e.g., service provider services). The services can identify system instrument data objects based on the instrument keys. System instrument data objects can then be used to identify one or more identifiers (e.g., user identifiers, instrument identifiers, etc.) for processing exchange requests.
[0233] In some embodiments, an exchange platform (e.g., its partner service) receives a UUEK that includes a service provider partition identifying a service provider platform. The exchange platform (e.g., its partner service) may determine that a partner-specific exchange data object is unavailable. In response to this determination, the exchange platform may identify a member platform based on the service provider partition and provide the UUEK to the service corresponding to the member platform (e.g., a service provider service). The service may identify a service provider-specific exchange data object based at least partially on the exchange identifier in the UUEK. The service provider-specific exchange data object may be used to identify a system instrument data object based on the member platform and the exchange identifier. The system instrument data object may then be used to identify one or more identifiers (e.g., a user identifier, an instrument identifier, etc.) for processing the exchange request.
[0234] In some examples, the exchange platform can perform one or more validation actions on a UUEK. For example, an exchange data object may include one or more exchange attributes indicating an expiration status. In some examples, the expiration status may indicate (i) whether the UUEK has been previously used to grant authorization for value-based exchange, and / or (ii) the validity period during which the UUEK may be valid. A validation action may include identifying the expiration status corresponding to the UUEK and validating the UUEK based at least in part on the expiration status. For example, the exchange platform may validate a UUEK if the expiration status indicates that (i) the UUEK has not been previously used to grant authorization for value-based exchange, and / or (ii) the UUEK was presented within its validity period.
[0235] In some examples, the verification action may include verifying that the sender of the UUEK is associated with the original entity from which the UUEK was issued. In some examples, the UUEK may include an entity partition that identifies the original entity from which the UUEK was issued (e.g., a member platform, such as a partner or service provider platform). The exchange platform can leverage the entity partition of the UUEK to determine the entity corresponding to the UUEK (e.g., the original entity). In some examples, the verification action may include verifying that the sender of the exchange request matches and / or is associated with the original entity of the UUEK. In response to the determination that the sender is the original entity, the exchange platform can verify the UUEK.
[0236] If UUEK is validated, process 900 can proceed to step / operation 906. Otherwise, process 900 can proceed to step / operation 914, where the exchange platform provides an error response to the partner platform using the partner interface.
[0237] In some embodiments, process 900 includes requesting exchange authorization from a member platform in step / operation 906. For example, an exchange platform (e.g., its service provider service) may request exchange authorization from the service provider platform for a service provider instrument correlated with a UUEK. In some examples, an exchange platform (e.g., its partner service) may identify a member platform at least partially based on a UUEK (e.g., its entity partition). Alternatively, an exchange platform (e.g., its service provider service) may identify a service provider instrument at least partially based on a UUEK (e.g., an exchange identifier).
[0238] An exchange platform (for example, its service provider service) can use a service provider interface to provide an exchange authorization request to a member platform. An exchange authorization request may specify at least one of one or more transaction attributes and / or instrument identifiers of a service provider instrument. For example, an exchange platform can generate an exchange authorization request based on a system instrument data object identified from one or more aspects of a UUEK. The exchange authorization request may include an instrument key and / or instrument reference from the system instrument data object.
[0239] In some examples, an exchange authorization request may indicate a user identifier associated with a service provider instrument. For example, an exchange platform may generate an exchange authorization request based on a system user data object identified from one or more aspects of the UUEK. In some examples, a system user data object may be identified based on the user identifier of the exchange data object (e.g., system user identifier). Additionally or alternatively, a system user data object may be identified based on the user identifier of the system instrument data object (e.g., system user identifier). In some examples, an exchange authorization request may include a user key and / or user reference from a system user data object.
[0240] Alternatively, a transaction authorization request may include a transaction identifier. For example, an exchange platform may generate a transaction identifier to represent a value-based exchange and provide the transaction identifier to a member platform.
[0241] In some embodiments, process 900 includes receiving an exchange authorization response in step / operation 908. For example, an exchange platform (e.g., its service provider service) may receive an exchange authorization response indicating at least one of transaction approval and / or transaction rejection using a service provider interface. In some embodiments, the exchange authorization response is at least in part based on a comparison between the value of the transaction and the asset availability of the service provider instrument. For example, in response to receiving an exchange authorization request, a member platform may be configured to compare the value of the transaction with the asset availability of the identified service provider instrument. A value-based exchange may be authorized (e.g., resulting in transaction approval) if the asset availability exceeds the value of the transaction, or the exchange may be denied (e.g., resulting in transaction rejection) otherwise.
[0242] In some examples, an exchange authorization response may include one or more response attributes. These response attributes may include one or more error codes and / or similar to characterize the exchange authorization response.
[0243] The exchange platform can generate a transaction record for a value-based exchange based at least partially on the exchange authorization request and / or the exchange authorization response. In some examples, the transaction record may include a transaction identifier, one or more transaction attributes, one or more response attributes, the exchange authorization response, one or more instrument and / or user identifiers, and / or any other data relating to the value-based exchange. In some examples, the exchange platform can store the transaction record in a platform data vault in relation to one or more instrument and / or user identifiers.
[0244] In some embodiments, process 900 optionally includes generating a replacement UUEK in step / operation 910. For example, the exchange platform can automatically generate a replacement UUEK to replace the received UUEK.
[0245] In some cases, this may include (i) invalidating a received UUEK for future authorization requests, and / or (ii) generating a replacement UUEK. For example, an exchange platform may modify the expiration status of a UUEK to invalidate it for subsequent value exchanges. Additionally or alternatively, an exchange platform may transfer, delete, and / or otherwise modify the exchange data object corresponding to a UUEK to invalidate it. A replacement UUEK may include a new unique exchange identifier (e.g., a different generic unique identifier) corresponding to the service provider instrument to replace the invalidated exchange identifier. In this way, UUEKs may be continuously modified and changed as users complete exchanges across different platforms, thereby limiting user and platform exposure to malicious parties.
[0246] In some embodiments, process 900 includes providing an exchange response to a member platform in step / operation 912. For example, an exchange platform (e.g., its partner service) may provide an exchange response to a member platform, such as a partner platform, using a partner interface. The exchange response may be based at least in part on an exchange authorization response. For example, the exchange response may indicate a transaction approval and / or transaction rejection. In some examples, the exchange response may indicate a replacement UUEK (if generated), one or more transaction attributes, a transaction identifier, and / or one or more response attributes. In some examples, a member platform may be configured to replace the UUEK with the replacement UUEK. For example, the exchange response may be provided to a partner platform. The partner platform can receive the exchange response and replace the UUEK with the replacement UUEK.
[0247] Figures 10 and 11 provide message flow diagrams illustrating steps / operations related to Figure 9 for facilitating credential-free exchange of value according to one or more embodiments of the present disclosure. As recognized, these may be performed and executed in the corresponding steps / operations of Figure 9. Figure 10 may illustrate, for example, a first message flow for facilitating credential-free exchange through a registered partner account, while Figure 11 may illustrate a second message flow for facilitating credential-free transactions without a registered partner account.
[0248] In the first message flow, in step / action 1004, the user initiates a transaction through a registered partner account. In step / action 1006, the partner platform 420 retrieves the user's UUEK to execute the transaction on the user's behalf. In step / action 1008, the partner platform 420 uses the partner interface to submit an exchange request to at least one of several partner services 410 of the exchange platform corresponding to the partner platform 420. The exchange request may specify a UUEK for a value-based exchange and / or one or more transaction attributes.
[0249] In step / operation 1010, partner service 410 searches for partner-specific transaction tokens (e.g., in partner-specific data stores, such as a portion of the platform data vault) to determine the member platform corresponding to the UUEK (e.g., through mapping to a service provider partition). In step / operation 1012, partner service 410 provides data indicating the exchange request to the service provider service 412 of the exchange platform corresponding to the member platform.
[0250] In step / operation 1014, service provider service 412 verifies the UUEK (and / or its exchange identifier). In step / operation 1016, service provider service 412 uses the service provider interface to submit an exchange authorization request to service provider platform 440. The exchange authorization request may include one or more keys (e.g., user key, instrument key), references (e.g., instrument reference, user reference), and / or one or more transaction attributes.
[0251] In step / operation 1018, the service provider platform 440 approves the transaction and provides an exchange authorization response to the service provider service 412 using the service provider interface. In step / operation 1020, the service provider service 412 records the value-based exchange in relation to one or more keys (e.g., user key, instrument key, etc.), references (e.g., instrument reference, user reference, etc.), and / or similar. In step / operation 1022, the service provider service 412 provides the exchange authorization response to the partner service 410. In step / operation 1024, the partner service 410 provides the exchange response to the partner platform 420 using the partner interface.
[0252] In the second message flow, in step / action 1102, user 1002 initiates a transaction by presenting a UUEK (and / or its UUEK representation) to partner platform 420. In step / action 1104, partner platform 420 uses the partner interface to provide an exchange request to partner service 410 of the exchange platform corresponding to partner platform 420. The exchange request may identify a UUEK for a value-based exchange and / or one or more transaction attributes.
[0253] In step / operation 1106, partner service 410 searches for an exchange identifier (for example, in a partner-specific data store, such as a portion of the platform data vault) to determine whether an exchange data object exists. If an exchange identifier does not exist, in step / operation 1108, partner service 410 provides the UUEK to the exchange platform service provider service 412 corresponding to the service provider platform identified from the UUEK.
[0254] In step / operation 1110, service provider service 412 verifies the exchange identifier of the UUEK. In step / operation 1112, service provider service 412 uses the service provider interface to provide an exchange authorization request to service provider platform 440. The exchange authorization request may include one or more keys (e.g., user key, instrument key), references (e.g., instrument reference, user reference), and / or one or more transaction attributes.
[0255] In step / operation 1114, the service provider platform 440 authorizes the exchange and provides an exchange authorization response to the service provider service 412 using the service provider interface. In step / operation 1116, the service provider service 412 records the transaction in relation to one or more keys (e.g., user key, instrument key, etc.), references (e.g., instrument reference, user reference, etc.). In step / operation 1118, the service provider service 412 provides the exchange authorization response indicating the response to the partner service 410. In step / operation 1120, the partner service 410 provides the exchange response to the partner platform 420 using the partner interface.
[0256] Having described various actions, processes, methods, functions, and / or similar for handling exchanges on behalf of the user, various user interface screens for controlling, initiating, executing, and / or similar steps / actions are provided and described. In various embodiments, the user interface screens provided and described herein are configured to be provided via the user interface of the client device 104.
[0257] Figures 12A–12D provide exemplary user interface flows configured for a client device 104. The user interface may be configured to guide the user through a credential-free exchange process to facilitate value-based exchanges between one or more member platforms without disclosing confidential and persistent credentials of service provider instruments used to perform value-based exchanges. The credential-free exchange process can be initiated when the user selects a payment method from the transaction processing screen 1202 of the partner application, as shown in Figure 12A. Upon selecting a payment method facilitated by the exchange platform, the user may transition to an instrument selection screen 1204, as shown in Figure 12B. The instrument selection screen 1204 may include a plurality of selectable instrument icons 1206, each of which may accompany a UUEK issued by the exchange platform using the various technologies described herein. The user can perform an exchange by selecting one or more of the selectable instrument icons 1206.
[0258] In some cases, in response to a selection, a scan screen 1208 may be provided for in-store transactions. The scan screen 1208 may present a scannable UUEK representation 1210 corresponding to the UUEK. The user can scan the scannable UUEK representation 1210 to complete the value-based exchange. Additionally or alternatively, in an online environment, the user may be directed to a verification user screen 1212 to provide a Personal Identification Number (PIN) associated with the service provider instrument. The user can enter the PIN and complete the transaction.
[0259] VI. Conclusion Those skilled in the art will likely envision numerous modifications and other embodiments that benefit from the teachings presented in the foregoing description and accompanying drawings. Therefore, it should be understood that this disclosure is not limited to the specific embodiments disclosed, and that modifications and other embodiments are intended to be included within the scope of the appended claims. Certain terms are used herein, but these terms are used only in a general and descriptive sense and not for limitation.
Claims
1. Steps include: initiating the presentation of a registration user interface via a user's client device using one or more processors and a partner interface connected to a partner platform, wherein the registration user interface includes an instrument registration screen showing one or more service provider instruments associated with the user; The steps include receiving selection data indicating the selection of a service provider instrument from the registered user interface via the client device using one or more processors and the partner interface, The steps include: In response to receiving the aforementioned selection data, one or more processors generate a first matching code for authenticating the user; The steps of providing a registration request to a service provider platform corresponding to the service provider instrument using one or more processors and a service provider interface, wherein the registration request comprises service provider registration data indicating the first matching code, the user identifier of the user, and the instrument identifier of the service provider instrument, and the service provider platform provides the first matching code to the client device. The steps include: using one or more processors and the partner interface to initiate the presentation of the authentication user screen of the client device via the registration user interface; The steps include receiving an authentication message from the registration user interface, comprising a second matching code, via the partner platform, by one or more processors and using the partner interface, in response to user input to the authentication user screen, In accordance with the authentication of the user based on a comparison between the first matching code generated and the second matching code received from the registration user interface, (i) A step of generating the user's UUEK using one or more processors, wherein the UUEK corresponds to the user, the service provider instrument, and the partner platform, and (ii) the step of providing the UUEK to the partner platform by one or more processors and using the partner interface; A computer execution method performed by a platform, including the method itself.
2. The user identifier of the user comprises the user reference of the service provider platform and the user key corresponding to the user reference. The computer execution method according to claim 1.
3. The instrument identifier of the service provider instrument comprises the instrument reference of the service provider platform and the instrument key corresponding to the instrument reference. The computer execution method according to claim 1.
4. The selected data indicates an instrument representation corresponding to the instrument reference. The computer execution method according to claim 3.
5. The step of initiating the presentation of the registered user interface is The steps include: using the partner interface and via the registration user interface, initiating the presentation of a pre-registration screen showing one or more service providers associated with the exchange platform; The steps include using the partner interface to receive pre-selection data indicating the selection of a specific service provider from one or more service providers, A step of receiving service provider instrument data that is at least partially based on the pre-selected data, wherein the service provider instrument data indicates the user's one or more service provider instruments; Using the partner interface and via the registration user interface, the presenting of the instrument registration screen based at least in part on the service provider instrument data includes the step of the instrument registration screen showing the respective instrument representation for each of the one or more service provider instruments. The computer execution method according to claim 1.
6. The step of starting the presentation of the pre-registration screen is, A step of receiving a communication session request for the user through the partner interface, wherein the communication session request comprises one or more user attributes. The steps include generating a session identifier for a communication session between the partner platform and the exchange platform, The steps include determining one or more service providers based at least partially on one or more user attributes, The steps include: using the partner interface and via the registration user interface to initiate the presentation of the pre-registration screen to one or more service providers, at least in part; including, The computer execution method according to claim 5.
7. The matching code comprises a sequence of one or more different characters. The computer execution method according to claim 1.
8. The client device is configured to access a partner application hosted by the partner platform, and the registration user interface is presented to the user using the partner application. The computer execution method according to claim 1.
9. The UUEK includes a partition for identifying the recipient of the UUEK. The computer execution method according to claim 1.
10. The platform generates the replacement UUEK in order to cause the partner platform to replace the received UUEK with the replacement UUEK. The computer execution method according to claim 1.
11. The platform invalidates the received UUEK, The substituted UUEK includes a new exchange identifier corresponding to the service provider instrument in order to replace the invalidated exchange identifier. The computer execution method according to claim 10.
12. A computing system comprising memory and one or more processors communicatively coupled to the memory, wherein the one or more processors Initiating the presentation of a registration user interface via a user's client device using a partner interface connected to the partner platform, wherein the registration user interface includes an instrument registration screen that displays one or more service provider instruments associated with the user. Using the partner interface, the client device receives selection data indicating the selection of a service provider instrument from the registered user interface, In response to receiving the aforementioned selection data, a first matching code for authenticating the user is generated, The service provider interface provides a registration request to a service provider platform corresponding to the service provider instrument, wherein the registration request comprises service provider registration data indicating the first matching code, the user identifier of the user, and the instrument identifier of the service provider instrument, and the service provider platform provides the first matching code to the client device. Using the partner interface, the authentication user screen of the client device is initiated via the registration user interface. In response to user input to the authentication user screen, the partner interface is used to receive an authentication message containing a second matching code from the registration user interface via the partner platform, In accordance with the authentication of the user based on a comparison between the first matching code generated and the second matching code received from the registration user interface, (i) generating the user's UUEK, the UUEK being generated to correspond to the user, the service provider instrument, and the partner platform, and (ii) Providing the UUEK to the partner platform using the partner interface Configured to perform, Computing system.
13. The user identifier of the user comprises the user reference of the service provider platform and the user key corresponding to the user reference. The computing system according to claim 12.
14. The instrument identifier of the service provider instrument comprises the instrument reference of the service provider platform and the instrument key corresponding to the instrument reference. The computing system according to claim 12.
15. The selected data indicates an instrument representation corresponding to the instrument reference. The computing system according to claim 14.
16. Initiating the presentation of the registered user interface is Using the partner interface and via the registration user interface, the system initiates the presentation of a pre-registration screen showing one or more service providers associated with the exchange platform. Using the partner interface, receive pre-selection data indicating the selection of a specific service provider from one or more service providers, Receiving service provider instrument data that is at least partially based on the aforementioned pre-selected data, wherein the service provider instrument data indicates the user's one or more service provider instruments. Using the partner interface and via the registration user interface, initiate the presentation of the instrument registration screen based at least in part on the service provider instrument data, including initiating the instrument registration screen to display the respective instrument representation for each of the one or more service provider instruments. The computing system according to claim 12.
17. To begin the presentation of the aforementioned pre-registration screen, Receiving a communication session request for the user through the partner interface, wherein the communication session request includes one or more user attributes. To generate a session identifier for a communication session between the partner platform and the exchange platform, Determining one or more service providers based at least partially on one or more user attributes, Using the Partner Interface and via the Registration User Interface, to initiate the presentation of the pre-registration screen based at least partially on the one or more service providers. including, The computing system according to claim 16.
18. The matching code comprises a sequence of one or more different characters. The computing system according to claim 12.
19. The client device is configured to access a partner application hosted by the partner platform, and the registration user interface is presented to the user using the partner application. The computing system according to claim 12.
20. When executed by one or more processors, Initiating the presentation of a registration user interface via a user's client device using a partner interface connected to the partner platform, wherein the registration user interface includes an instrument registration screen that displays one or more service provider instruments associated with the user. Using the partner interface, the client device receives selection data indicating the selection of a service provider instrument from the registered user interface, In response to receiving the aforementioned selection data, a first matching code for authenticating the user is generated, The service provider interface provides a registration request to a service provider platform corresponding to the service provider instrument, wherein the registration request comprises service provider registration data indicating the first matching code, the user identifier of the user, and the instrument identifier of the service provider instrument, and the service provider platform provides the first matching code to the client device. Using the partner interface, the authentication user screen of the client device is initiated via the registration user interface. In response to user input to the authentication user screen, the partner interface is used to receive an authentication message containing a second matching code from the registration user interface via the partner platform, In accordance with the authentication of the user based on a comparison between the first matching code generated and the second matching code received from the registration user interface, (i) generating the user's UUEK, the UUEK being generated to correspond to the user, the service provider instrument, and the partner platform, and (ii) Providing the UUEK to the partner platform using the partner interface The instruction includes causing one or more processors to perform the following: One or more non-temporary computer-readable storage media.
21. The client device is configured to access a partner application hosted by the partner platform, and the registration user interface is presented to the user using the partner application. One or more non-temporary computer-readable storage media according to claim 20.
22. The service provider platform is configured to provide the matching code to the user and to receive the authentication message. Using the aforementioned partner interface and via the aforementioned registration user interface, the presentation of the authentication user screen is initiated. Using the aforementioned partner interface, the authentication message is received, which is at least partially based on user input to the authentication user screen. including, One or more non-temporary computer-readable storage media according to claim 20.
Citation Information
Patent Citations
Communication device, settlement method, communication method, program and computer-readable recording medium
JP2004102484A
Facilitating the sending and receiving of peer-to-business payments
JP2018506103A
SYSTEM AND METHOD FOR TRANSMITTING INFORMATION USING A MOBILE TERMINAL - Patent application
JP2022524474A
Facilitating sending and receiving of peer-to-business payments
US20160180325A1