A method comprising: creating, on a server, an object corresponding to the transaction; tracking state of the object as the object transitions between a plurality of states, the object being in one state while waiting for a transfer for the transaction; and automatically associating with the object by matching a reference code received with the transfer.
G06Q 20/10 - Payment architectures specially adapted for electronic funds transfer [EFT] systemsPayment architectures specially adapted for home banking systems
G06Q 20/12 - Payment architectures specially adapted for electronic shopping systems
Methods and apparatuses for one or more processing systems reducing use of processing and networking resources for one or more electronic communications. The one or more processing systems receive, from a plurality of computing devices, transaction data of network transactions performed between the plurality of computing devices and a plurality of internet-enabled browsers and receive one or more external signals including an external signal over a network communication channel. The one or more processing systems execute, based on receiving the network response, an electronic transfer from the one or more processing systems to a different computer system that maintains an account associated with a computing system by exchanging the one or more electronic communications.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
H04L 41/147 - Network analysis or design for predicting network behaviour
H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
H04L 67/06 - Protocols specially adapted for file transfer, e.g. file transfer protocol [FTP]
3.
SYSTEM AND METHOD FOR NEAR FIELD COMMUNICATIONS PAYMENT
A card detection subsystem for control of a payment card reader, where the payment card reader comprises a magnetic stripe reader (MSR), an integrated circuit card (ICC) reader, and a near field communications (NFC) reader, and the NFC reader comprises an antenna. The card detection subsystem includes a processor, a storage, and one or more sensors. The one or more sensors detect a payment card and the antenna is either turned on or turned off based on the detection of the payment card.
G06Q 20/32 - Payment architectures, schemes or protocols characterised by the use of specific devices using wireless devices
G06K 7/10 - Methods or arrangements for sensing record carriers by electromagnetic radiation, e.g. optical sensingMethods or arrangements for sensing record carriers by corpuscular radiation
G06Q 20/34 - Payment architectures, schemes or protocols characterised by the use of specific devices using cards, e.g. integrated circuit [IC] cards or magnetic cards
36 - Financial, insurance and real estate services
42 - Scientific, technological and industrial services, research and design
Goods & Services
Financial services provided by a consortium of financial and technology enterprises, namely, establishing and providing interoperability frameworks and transaction protocols for the electronic transfer of virtual currency and transferable electronic cash equivalents; electronic funds transfer services, namely, facilitating the electronic transmission of digital currency among consortium participants via electronic communications networks; providing transactional compliance frameworks for electronic processing of electronic payments via a global computer network and cryptocurrencies. Platform as a service (PAAS) featuring computer software platforms for creating, managing, and connecting interoperable networks for account-to-account transfers of cryptocurrency; providing technological information in the field of cryptocurrency and blockchain standards; providing user authentication services using blockchain-based software technology for cross-network cryptocurrency transactions; application service provider featuring application programming interface (API) software for the integration and implementation of open-standard protocols for blockchain-based cryptocurrency transactions and uses.
36 - Financial, insurance and real estate services
42 - Scientific, technological and industrial services, research and design
Goods & Services
Financial services provided by a consortium of financial and technology enterprises, namely, establishing and providing interoperability frameworks and transaction protocols for the electronic transfer of virtual currency and transferable electronic cash equivalents; electronic funds transfer services, namely, facilitating the electronic transmission of digital currency among consortium participants via electronic communications networks; providing transactional compliance frameworks for electronic processing of electronic payments via a global computer network and cryptocurrencies. Platform as a service (PAAS) featuring computer software platforms for creating, managing, and connecting interoperable networks for account-to-account transfers of cryptocurrency; providing technological information in the field of cryptocurrency and blockchain standards; providing user authentication services using blockchain-based software technology for cross-network cryptocurrency transactions; application service provider featuring application programming interface (API) software for the integration and implementation of open-standard protocols for blockchain-based cryptocurrency transactions and uses.
36 - Financial, insurance and real estate services
42 - Scientific, technological and industrial services, research and design
Goods & Services
(1) Financial services provided by a consortium of financial and technology enterprises, namely, establishing and providing interoperability frameworks and transaction protocols for the electronic transfer of virtual currency and transferable electronic cash equivalents; electronic funds transfer services, namely, facilitating the electronic transmission of digital currency among consortium participants via electronic communications networks; providing transactional compliance frameworks for electronic processing of electronic payments via a global computer network and cryptocurrencies.
(2) Platform as a service (PAAS) featuring computer software platforms for creating, managing, and connecting interoperable networks for account-to-account transfers of cryptocurrency; providing technological information in the field of cryptocurrency and blockchain standards; providing user authentication services using blockchain-based software technology for cross-network cryptocurrency transactions; application service provider featuring application programming interface (API) software for the integration and implementation of open-standard protocols for blockchain-based cryptocurrency transactions and uses.
10.
SERVICE-AGNOSTIC POLICY ENFORCEMENT CONTROL ENGINE
A method of service-agnostic policy enforcement includes receiving a first request comprising information in a non-standardized format and converting the information into a data package comprising a plurality of attributes in a standardized format. An orchestrator receives a second request comprising the data package to generate a license token for executing an action. The orchestrator invokes a policy-based controls engine to validate the second request. The controls engine identifies one or more policies applicable to the second request based on one or more of the plurality of attributes in the data package. The policies are implemented as computational constraint expressions. The controls engine validates the second request based on the attributes satisfying each of the constraint expressions. The method further includes generating the license token based on successful validation of the second request and executing the action using the license token.
A server computer system is configured to forward secure data. The system stores secure data in a database. Each unit of secure data for which the system supports forwarding is associated with a respective token. The system receives from a first server, a request comprising at least: an indicator associated with a secure data, a destination indicator, a first API key, a second API key, and a body having a predefined data format. The system validates the request based on the first API key, references the database to obtain the secure data based on the indicator and the respective token, and populates the body with the secure data. Once populated, the system transmits a second request comprising the second API key and the populated body to a second server, based on the destination indicator.
A method and apparatus for fraud detection during transactions using identity graphs are described. The method may include receiving a document image for detecting whether an identity document depicted within the document image is fraudulent. The method may also include extracting data associated with the document image to generate extracted data comprising image data extracted from the document image, image file data extracted from an image file for the document image, or a combination thereof. The method may also include processing, by a set of machine learning models, corresponding subsets of the decoded image data used as input to each machine learning model of the set of machine learning models, and further by a second machine learning model that generates a final score indicative of whether the document image depicts a fraudulent identity document, at least one or more initial scores.
G06F 40/169 - Annotation, e.g. comment data or footnotes
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
G06V 10/774 - Generating sets of training patternsBootstrap methods, e.g. bagging or boosting
G06V 10/82 - Arrangements for image or video recognition or understanding using pattern recognition or machine learning using neural networks
36 - Financial, insurance and real estate services
Goods & Services
(1) Business consultation services to assist non-profit organizations in planning, managing, and conducting fundraising activities; Promoting the interests of organizations engaged in the research, development, production, and distribution of vaccines and broad-spectrum prophylactic treatments for respiratory diseases, and organizations developing non-pharmaceutical interventions for respiratory disease prevention by means of public advocacy; Promoting public awareness of the need for research, development, production, and distribution of vaccines and broad-spectrum prophylactic treatments for respiratory diseases, and the benefits of non-pharmaceutical interventions for respiratory disease prevention by means of public advocacy; Providing public policy information in the field of vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention; Public policy consultancy in the field of vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention.
(2) Accepting and administering monetary charitable contributions on behalf of organizations engaged in the research, development, production, and distribution of vaccines and broad-spectrum prophylactic treatments for respiratory diseases, and organizations developing non-pharmaceutical interventions for respiratory disease prevention; Investment of funds for others in the fields of vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention; Financial investment in the field of vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention; Financial management in the field of investment in vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention; Charitable fundraising to support research, development, production, and distribution of vaccines and broad-spectrum prophylactic treatments for respiratory diseases, and non-pharmaceutical interventions for respiratory disease prevention; Charitable fundraising services for promoting research, education, and related activities in the fields of vaccines, broad-spectrum prophylactic treatments for respiratory diseases, and non-pharmaceutical interventions for respiratory disease prevention.
36 - Financial, insurance and real estate services
45 - Legal and security services; personal services for individuals.
Goods & Services
Business consultation services to assist non-profit organizations in planning, managing, and conducting fundraising activities; promotional services for commercial purposes in the field of the research, development, production, and distribution of vaccines and broad-spectrum prophylactic treatments for respiratory diseases, and the development of non-pharmaceutical interventions for respiratory disease prevention. Accepting and administering monetary charitable contributions on behalf of organizations engaged in the research, development, production, and distribution of vaccines and broad-spectrum prophylactic treatments for respiratory diseases, and organizations developing non-pharmaceutical interventions for respiratory disease prevention; Investment of funds for others in the fields of vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention; Financial investment in the field of vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention; Financial management in the field of investment in vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention; Charitable fundraising to support research, development, production, and distribution of vaccines and broad-spectrum prophylactic treatments for respiratory diseases, and non-pharmaceutical interventions for respiratory disease prevention; Charitable fundraising services for promoting research, education, and related activities in the fields of vaccines, broad-spectrum prophylactic treatments for respiratory diseases, and non-pharmaceutical interventions for respiratory disease prevention. Providing information relating to public policy and political affairs in the field of vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention; consultancy relating to public policy and political affairs in the field of vaccine and broad-spectrum prophylactic research, development, production, and distribution, and non-pharmaceutical interventions for respiratory disease prevention.
A method and related systems may generate and use a machine learning model that determines multiple outcome values for multiple message routes. Some embodiments may then compare the multiple outcome values to select a target route for the message. Moreover, some embodiments may facilitate routing through one or more networks by mapping aggregated performance metrics through controlled nodes.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
A method and related systems may generate and use a machine learning model that determines multiple outcome values for multiple message routes, where the model may account for unknown node values in one or more nodes during model creation. Some embodiments may then compare the multiple outcome values to select a target route for the message. Moreover, some embodiments may facilitate efficient network route determination through an adaptive weight node network by selecting different dynamic routing protocols based on critical thresholds.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
H04L 45/028 - Dynamic adaptation of the update intervals, e.g. event-triggered updates
H04W 24/02 - Arrangements for optimising operational condition
17.
SYSTEMS AND METHODS FOR COMPROMISED CARD DETECTION DURING SERVICE REQUEST PROCESSING BY A DISTRIBUTED SERVICE SYSTEM
A method and apparatus for detecting compromised cards during service requests transmitted to a distributed services system are described. The method includes receiving a new service request associated with a card that authorizes the service request during a second time period that is after a first time period. The new service request is processed within a processing path executed by the server computer system. During processing of the new service request, an output generated by a machine learning model outside of the processing path and prior to the second time period is accessed, where the output indicates whether the card is compromised during the first time period. The output is applied to the new service within the processing path to indicate whether the card is compromised and initiating one or more remedial actions, in response to inferring that the card is compromised.
A server computer system receives handles a client request. The system determines a set of geographical coordinates associated with the request, and uses this coordinates as input into a traversable tree to determine a polygon identifier. The polygon identifier uniquely corresponds to and identifies one of second set of polygons that are non-overlapping versions of first set of polygons that are overlapping. The server computing system transmits a set of parameters that are associated with the one of the second set of polygons that corresponds to the polygon identifier retrieved through the traversable tree.
Aspects of the subject technology provide recursion detection and prevention for automated system calls which are automatically triggered based on events. An automation service can receive an automated request to execute an API call and determine if the automated request was called as a result of an action of a previously executed automated system call. If the automated request to execute the API call was based on a previously executed automated system call, the automated request can be terminated.
A server computer system may determine a set of data related to a set of jobs processed by a computing platform on behalf of subscribers to the computing platform as part of an attribute analysis to facilitate the detection of fraudulent activity on the computing platform. The set of data may include, for each job, a set of attribute-value pairs corresponding to a set of attributes utilized to parameterize each job in the set of jobs. An ML model may generate a ranked list of the set of attribute-value pairs based on predictive utility of each attribute-value pair for identifying jobs involving fraudulent activity. The server computer system may determine a set of statistics for a threshold number of top attribute-value pairs in the ranked list in. Further, the server computer system may present the set of statistics for the threshold number of top attribute-value pairs via a graphical user interface.
A method and server system for using secured secrets by distributed systems are disclosed. The method can include receiving, from a first user system, a request for a credential. The method can further include in response to the request, generating a credential blob and signature data of the credential blob. The credential blob can include encrypted secrets data and credential metadata. The method can further include sending, to the first user system, the credential blob and the signature data. The method can further include receiving, from the first user system, a service request with the credential blob and the signature data. The method can further include in response to the service request, building artifact data that includes the credential blob. The method can further include deploying the artifact data and the signature data to a second user system.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
An inline frame for transactions, or services, via a parent frame from a platform may maintains the same developer interface from the platform and isolating a transaction from the platform. A service provider receives and processes the transaction by requesting the parent frame open an inline frame, and then renders a user interface in the inline frame to, for example, provide additional transaction-based data or receive an account credential. The inline frame may appear to users as part of the parent frame. However, due to the user interface being rendered in the inline frame, the parent frame and the user interface are in different domains, and the platform or the parent frame cannot receive or surface data rendered or provided in the inline frame. The service provider server notifies the platform when the transaction is complete, allowing the service provider server to maintain loss liability without surfacing sensitive information.
A system for prevention of electrostatic discharge from a payment card to a point of sale (POS) device comprising an integrated circuit card (ICC) socket, includes a spring member comprising a first end electrically coupled to a second end. The first end is electrically coupled to an electrical ground, the first end is mechanically coupled to the POS device, and the second end is positioned for contact with a top edge of the payment card. When the payment card is inserted into the ICC socket and the top edge comes into contact with the second end, the first end and the second end form a first electrical path for electrostatic discharge between the payment card and the electrical ground.
G06K 7/00 - Methods or arrangements for sensing record carriers
G06K 19/02 - Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the selection of materials, e.g. to avoid wear during transport through the machine
24.
UNAUTHORIZED EVENT DETECTION USING AN APPLICATION PROGRAMMING INTERFACE (API)
A method and system partitioned machine learning feature generation and usage are described. The method can include a server system receiving event data generated by a platform system, the event data associated with a request. A network type associated with the request is determined, where the network type indicates a network through which the event data associated with the request are sent from the platform system to the server system. The server computer system computes feature data from a set of event data and outcome data associated with the network type, and then generates one or more prediction datasets based on the computed feature data indicative of whether the request is fraudulent.
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
25.
Techniques for Generating Structured Data from Unstructured Data
This disclosure describes techniques for generating structured data, such as for client system intelligence, based on unstructured data in an efficient, valuable, automated, and intelligent manner. Content may be extracted from unstructured data and then processed and stored in a manner to facilitate correlating the content with a query. For example, content may be embedded into a vector space. When a query is received, the query may similarly be embedded into the vector space in order to identify content that is relevant to the query. A prompt for a machine learning (ML) model (e.g., a large language model (LLM)) may then be automatically generated based on the query and the relevant content. The output of the ML model may then be validated and integrated into various downstream systems and subsystems, such as to recognize client development opportunities.
A server may include a plurality of services, where in response to receiving a first API call, a service generates a transit container in memory that is associated with a transit group ID. In response to receiving a second API call with the transit group ID, the service moves the resource to the transit container. When the resource is deemed to be properly received, the state of the transit container is set to a resource held state. The first service is configured to access the resource of the transit container in the resource held state in response to one or more additional API calls that comprise the transit group ID. The first service releases the transit container for garbage collection when a condition of the transit container is satisfied.
H04L 67/60 - Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
H04L 67/565 - Conversion or adaptation of application format or content
27.
DYNAMIC DASHBOARD GENERATION USING A LANGUAGE MODEL
A method and related system may generate an interactive dashboard by using a predicted language model context. The method may include generating a context of predicted prompts for a language model and generating queries for execution based on the predicted prompts.
A method and apparatus for executing a service of a server computer system for a client system are described. The method may include defining a client system descriptor file that includes a set of signals suitable for input into a large language machine learning model (LLM), and collecting data associated with a first client system that is representative of the set of signals. The data can then be compressed into the set of signals for a first client system descriptor file allocated for the client system. A query is executed using at least the first client system descriptor file as input into the LLM, and in response to an output obtained by the LLM, at least an action is executed by the service of the server computer system.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
G06F 16/14 - Details of searching files based on file metadata
29.
PAYLOAD ARRANGEMENT FOR EFFICIENT PAYLOAD RECEPTION FROM NETWORK STORAGE
A method and related systems may use a language model to generate queries or other commands to retrieve data from a set of databases. Some embodiments may incorporate data attribute descriptors or example commands in an input context of a model input for the language to improve the efficiency, accuracy, or reliability of the model-generated command.
H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
30.
SYSTEMS AND METHODS FOR GENERATING EMBEDDINGS OF NETWORK EVENT DATA TO DETECT FRAUDULENT BEHAVIOR IN NETWORKED ENVIRONMENTS
Presented herein are systems and methods of generating embeddings for network events to detect fraudulent activities in networked environments. A service may receive a request to execute a first network operation in a network environment. The service may identify an event dataset associated with the first network operation to be executed. The service may apply the first event dataset to a machine learning (ML) model comprising a plurality of weights. The ML model may be established using training data comprising (i) a first sample event dataset associated with a second network operation and (ii) a second sample event dataset corresponding to a modification of a portion of the first sample event dataset. The service may generate, based on applying the event dataset of the first network operation to the ML model, a plurality of embeddings indicative of fraudulence of the first network operation.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
31.
MACHINE LEARNING MODEL FOR NETWORK OPERATION EVALUATION
Disclosed herein are system and method for enhancing network operation evaluations using machine learning techniques. One embodiment features a server that processes network operation data from various electronic devices using a foundation machine learning model. The model, trained with categorical, numerical, and counter streaming features, generates embeddings capturing real-time and historical context. The embeddings predict risks or outcomes, such as fraud detection or authorization approval. The server transmits these embeddings to downstream models for specialized analysis. The disclosed modular structure supports real-time fraud prediction and network security assessment while maintaining centralized control.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
32.
SYSTEMS AND METHODS FOR GENERATING EMBEDDINGS OF NETWORK EVENT DATA TO DETECT FRAUDULENT BEHAVIOR IN NETWORKED ENVIRONMENTS
Presented herein are systems and methods of detecting fraudulent activities in networked environments using embeddings generated from network events. A service may receive, from a first machine learning (ML) model, a plurality of embeddings generated using an event dataset associated with a network operation. The plurality of embeddings may be indicative of fraudulence of the network operation. The service may apply the plurality of embeddings to a second ML model comprising a plurality of weights. The service may determine, based on applying the plurality of embeddings to the second ML model, a score indicating a likelihood of fraudulence in the network operation. The service may execute an action on the network operation in accordance with the score.
Disclosed herein are systems and methods for accurately determining a categorization of a network operation based on requestor information rather than network-operation-specific information. One embodiment of the systems and methods disclosed herein features a server configured to transmit an ordered set of prompts to a large language model (LLM) to cause the LLM to determine a general network service description of the requesting computing infrastructure that may be applied to many (if not all) network operation requests originating from the requesting computing infrastructure. The LLM may also output a confidence score corresponding to the previously determined general network service description. The server may compare the confidence score to a calibrated accuracy threshold to determine whether to use, store, and/or transmit the determined network service description
A notification manager can receive a request for a notification or alert from a user in a natural language interface and extract user intent and derive data sources from the request. The notification manager can store the request and execute the request periodically to determine if any conditions associated with the request are met and if so, generate an alert or notification to the user according to the request.
Methods and systems for disambiguating a user from a plurality of users within a computing infrastructure when the plurality of users utilize a common identifier are described. Disambiguation may occur through the user of subsequent verification of the identity of the user which generates an authentication token to be passed to the computing infrastructure during authentication requests using the common identifier.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
A user container corresponding to a user identity can include a user profile and secure object. A first user object can be added to the user container, where the first user object includes references to the user profile and secure object. One or more user roles can be established within the first user object where each role has different parameters. A reference to the first user object can be provided to a first entity. The first entity can use the reference to update the first user object in the user container directly from the first entity without updating the user profile.
A first application programming interface (API) can receive a request to create and/or modify a user object associated with a first organization. A set of additional APIs can be determined to drive the creation or make the modification. A set of requirements can be determined for executing the APIs, and information to satisfy the requirements received at least in part from the user object. Each API can be executed to create and/or modify the user object and a confirmation can be provided from the first API that the user object was created and/or modified.
In some embodiments, a server system may re-allocate a resource to a node from a shared pool of available resources and reschedule the added allocation. Some embodiments may use such operations to avoid triggering application-terminating thresholds and increase the efficiency and consistency of a networked computing system. In response to obtaining a result indicating whether an action will cause a resource allocation level of a node to fail to satisfy a threshold, some embodiments may delay the action by a buffer duration and allocate a set of resources from a resource pool to the node. As such, in some embodiments, the set of resources may be available to the node before an end of the buffer duration. Thus, at the end of the buffer duration or after the buffer duration, some embodiments may execute the action without triggering a failure condition related to the node.
H04L 41/0816 - Configuration setting characterised by the conditions triggering a change of settings the condition being an adaptation, e.g. in response to network events
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
39.
DYNAMICALLY RECALIBRATING MACHINE LEARNING MODEL PARAMETERS
Discussed herein are methods and systems for dynamically recalibrating machine learning model parameters. In one method, a server executes one or more prediction models to process network operations from various data feeds, in order to identify the likelihood of these operations being fraudulent or malicious. The server monitors performance data, such as the operation and execution metrics of network operations, and evaluates whether the performance values, like recall values, meet defined thresholds. If the performance data fails to meet these thresholds, the server employs a function-generation machine learning model to predict a threshold modification function. This modification function is then applied to adjust the relevant thresholds. Utilizing the modification function, the server dynamically revises one or more parameters of the prediction models to enhance their accuracy and efficacy.
Some embodiments involve systems and methods for facilitating authentication for an entity system to use a partner system using pooled identifiers (e.g., without requiring the entity system to first register with the partner system). In some embodiments, based on (i) a request, from a first entity system, indicating a first partner system to process at least a part of an operation and (ii) an indication that the first entity system is not registered for use of the first partner system, a platform system may link a first authentication identifier of the first identifier set with the first entity system. The platform system may process the operation using the first authentication identifier linked by the platform system with the first entity system, and the platform system may use platform authentication data established with the first partner system to authenticate the platform system to the first partner system for performing the operation.
Disclosed herein are methods and systems for secure, tenant-specific access control within a multi-tenant application infrastructure. A server can process a request from one tenant application and send it through one or more intermediary tenant applications before reaching its final destination. The server can create a data packet that includes information about the original sender, any intermediate applications it passed through, and details about the requested resource. This packet is then sent through a separate channel to the final tenant application so that the final tenant application can evaluate contextual data (in addition to the request itself) before determining whether to allow or block the request. This paradigm may enable tailored security protocols, improving both data protection and regulatory compliance, even when requests involve multiple disparate computing infrastructures.
A system may include a network infrastructure having a set of network component nodes, each network component node configured to communicate with at least one other network component node in accordance with a dependency protocol; and a server in communication with the network infrastructure and a fault injection server. The server can be configured to monitor outputs generated by the network infrastructure and attributes of data communication between the set of network component nodes; execute a computer model using the dependency protocol and the monitored attributes and outputs as input to predict a set of faults; in response to presenting the set of faults for display on a user interface, receive a selection of one or more of the set of faults; and instruct the fault injection server to execute a fault injection scenario simulating performance of the network infrastructure operating under the selected one or more faults.
H04L 41/06 - Management of faults, events, alarms or notifications
H04L 41/147 - Network analysis or design for predicting network behaviour
H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
43.
DETECTION AND MITIGATION OF AUTOMATED ACCOUNT GENERATION USING ARTIFICIAL INTELLIGENCE
Disclosed herein are systems and methods for detecting automated account generation requests. An example method includes receiving an application programming interface (API) request to generate a new user account. The method then includes executing a machine learning model to predict a likelihood of the API request having been generated automatically using one or more programming protocols. The machine learning model may be trained using historic requests known to have been generated using a machine or a programming/algorithm. When the machine learning model determines that the API request is likely to have been machine-made, the method includes executing an additional security protocol associated with the new user account.
A method comprising: creating, on a server, an object corresponding to the transaction; tracking state of the object as the object transitions between a plurality of states, the object being in one state while waiting for a transfer for the transaction; and automatically associating with the object by matching a reference code received with the transfer.
G06Q 20/10 - Payment architectures specially adapted for electronic funds transfer [EFT] systemsPayment architectures specially adapted for home banking systems
G06Q 20/12 - Payment architectures specially adapted for electronic shopping systems
The subject technology enables encryption key distribution when a processor is in offline mode. When offline, key distribution servers can distribute private/public key pairs in place of the processor. The servers can distribute a public key to a user device for encryption of data. The encrypted data can be provided to the processor, which can return a token in response to provide to the first server.
09 - Scientific and electric apparatus and instruments
36 - Financial, insurance and real estate services
42 - Scientific, technological and industrial services, research and design
45 - Legal and security services; personal services for individuals.
Goods & Services
(1) Computer e-commerce software to allow users to perform electronic business transactions via a global computer network; Electronic software updates, namely, downloadable computer software and associated data files for updating computer software in the fields of business and finance, provided via computer and communication networks; Downloadable middleware for software application integration; Software libraries, namely, downloadable electronic data files for use in software design (1) Merchant services, namely, payment transaction processing services; payment and funds verification services; credit card verification; currency exchange services; currency transfer services; financial services, namely, providing for the exchange of foreign currency via the internet and intranet systems; electronic funds transfer; Providing electronic processing of electronic funds transfer, ACH, credit card, debit card, electronic check and electronic payments; Financial transaction services, namely, providing secure commercial transactions and payment options
(2) Providing temporary use of non-downloadable computer software for allowing users to perform electronic business transactions via a global computer network; electronic data storage; electronic storage of files and documents; Design and development of computer software for the enablement of accepting purchases from within mobile apps and software that perform other non-purchasing functions; Application service provider featuring application programming interface (API) software for enabling a mobile app to accept purchases and payments directly; Application service provider featuring application programming interface (API) software for integrating ecommerce, business, transactional, financial, and analytics information and functionality into other software and platforms; authentication in the field of financial transaction, namely, providing user authentication using technology for electronic funds transfer, credit and debit card and electronic check transactions via a global computer network; Providing user authentication services in e-commerce transactions; Providing user authentication of electronic funds transfer, credit and debit card and electronic check transactions via a global computer network
09 - Scientific and electric apparatus and instruments
36 - Financial, insurance and real estate services
42 - Scientific, technological and industrial services, research and design
Goods & Services
Computer e-commerce software to allow users to perform electronic business transactions via a global computer network; Electronic software updates, namely, downloadable computer software and associated data files for updating computer software in the fields of business and finance, provided via computer and communication networks; Downloadable middleware for software application integration; Software libraries, namely, downloadable electronic data files for use in software design Merchant services, namely, payment transaction processing services; payment and funds verification services; credit card verification; currency exchange services; currency transfer services; financial services, namely, providing for the exchange of foreign currency via the internet and intranet systems; electronic funds transfer; Providing electronic processing of electronic funds transfer, ACH, credit card, debit card, electronic check and electronic payments; Financial transaction services, namely, providing secure commercial transactions and payment options Providing temporary use of non-downloadable computer software for allowing users to perform electronic business transactions via a global computer network; electronic data storage; electronic storage of files and documents; Design and development of computer software for the enablement of accepting purchases from within mobile apps and software that perform other non-purchasing functions; Application service provider featuring application programming interface (API) software for enabling a mobile app to accept purchases and payments directly; Application service provider featuring application programming interface (API) software for integrating ecommerce, business, transactional, financial, and analytics information and functionality into other software and platforms; authentication in the field of financial transaction, namely, providing user authentication using technology for electronic funds transfer, credit and debit card and electronic check transactions via a global computer network; Providing user authentication services in e-commerce transactions; Providing user authentication of electronic funds transfer, credit and debit card and electronic check transactions via a global computer network
A method and system for defining and executing a workflow are described. the method comprises presenting, on a first section of a user interface (UI), a plurality of UI components associated with a plurality of tasks to be performed, where each UI component is associated with one task. The method further comprises, in response to one or more UI components of the plurality of UI components associated with one or more tasks of the plurality of tasks being moved from the first section of the UI to a second section of the UI, dynamically creating the workflow based on the one or more UI components and an order in which the one or more UI components being positioned in the second section of the UI, and executing the workflow to perform the one or more tasks of the plurality of tasks.
In embodiments, methods and systems for implementing configuration management are provided. A configuration management system facilitates processing and preserving configurations associated with a software infrastructure. The software infrastructure operates as a co-located environment, high availability environment, disaster recovery environment or migration environment. The configuration management system specifically maintains implementation of firewall configurations for a source computing environment and a destination computing environment. The source computing environment communicates with the destination computing environment using a communication channel via an untrusted network. The configuration management system includes a leader component that accesses the firewall configurations, from the source computing environment, transforms the firewall configurations to a transformed version and communicates the transformed version to the destination computing environment. The configuration management system also includes a follower component that accesses and restores the transformed version into a restored version of the firewall configurations and implements the restored version at the destination computing environment.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
H04L 41/0859 - Retrieval of network configurationTracking network configuration history by keeping history of different configuration generations or by rolling back to previous configuration versions
H04L 67/51 - Discovery or management thereof, e.g. service location protocol [SLP] or web services
Systems and methods for silent verification of entities accessing a service are disclosed. One method may include receiving a first input identifying an entity engaged in a flow for accessing a service and utilizing the information to evaluate a risk score of the entity using a machine learning (ML) model. The machine learning model takes as input associations of the entity that are based on an access history of the entity for a second service that is stored in the server, and a type of access to the service. The method then determines a second input using the risk score of the entity as an input to an ML model. The second input is later transmitted to the service to update the flow to access the service.
Presented herein are systems and methods of authenticating clients to access data via proxy layers. A gateway on a proxy layer may receive a request from a client to access data in a compartment on the database layer. The request may include a token based at least on an encryption of an identifier of the compartment responsive to successful authentication of the request at an application layer. The gateway may, responsive to identifying the identifier as referencing the compartment, determine that the client is authorized to access the data in the compartment on the database layer through the proxy layer. The gateway may select a permission for the client to access the compartment through the proxy layer based on the context of the request. The gateway may generate an indication that the client is authorized to access the data in accordance with the permission.
Presented herein are systems and methods of evaluating network operations associated with computing systems. A server may receive, from a computing system, an electronic request to execute a first network operation using a plurality of attributes provided by an end user device to the computing system. The first network operation may be initiated via the end user device. The server may retrieve (i) a digital fingerprint associated with an identity of the computing system and (ii) a plurality of network operation metrics associated with the computing system. The server may execute, using the digital fingerprint and the plurality of network operation metrics, a machine learning (ML) model to generate a likelihood of fraud caused by the computing system. The server may, in response to the likelihood of fraud satisfying a threshold, execute a second network operation using the plurality of attributes, instead of executing the first network operation.
Presented herein are systems and methods of training machine learning (ML) models to determine likelihoods of fraud in network operations caused by computing systems. A server may generate training data to include (i) a digital fingerprint associated with an identity of a computing system of a plurality of computing systems and (ii) a plurality of network operation metrics associated with the computing system. The server may label the training data to indicate whether fraudulence is caused by the computing system. The server may execute, using the training data, a ML model having a plurality of weights to generate a likelihood of fraud caused by the computing system. The server may compare the likelihood of fraud with labeled training data to determine an error metric in accordance with a loss function. The server may update at least one of the plurality of weights using the error metric.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
A method and system for a secured data transaction are disclosed. The method can include receiving, by a server system, transaction data and a data descriptor. The data descriptor includes information about the transaction data and a digital signature of the data descriptor. The method can further include looking up, by the server system, a public key based on the data descriptor. The method can further include determining, by the server system, whether the digital signature of the data descriptor was signed by a private key corresponding to the public key. The method can further include in response to determining that the digital signature of the data descriptor was signed by the private key corresponding to the public key, allowing, by the server system, the receipt of the transaction data.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
H04L 9/14 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms
58.
USER INTERFACE STATE PRESERVATION DURING ASYNCHRONOUS UPDATE
A records request from a search database can result in a set of records displayed at a device, when one or more records are updated at a record database, record identifiers are maintained at the device. Another records request provides the record identifiers. A search is provided based on the records request and point reads are performed on the record database based on the record identifiers. The results may be combined to remove stale data provided by the search database and use the point reads data. The combination records may be provided to the device for updating the display of the device to reflect the updated records while the search database is not yet up to date.
G06F 16/27 - Replication, distribution or synchronisation of data between databases or within a distributed database systemDistributed database system architectures therefor
Disclosed herein are methods and system for improved entity state-quantity value verification for asynchronous operations. In one example, a request for an asynchronous operation corresponding to an entity object may be identified. The entity object may include a set of state-quantity values and each state-quantity value may include a quantity associated with a possible stage in a lifecycle of the corresponding entity. A proposed state-quantity value may be determined based on the request for the asynchronous operation corresponding to the entity object. Additionally, an available state-quantity value may be generated based on at least a portion of the set of state-quantity values of the entity object. The asynchronous operation may be performed when a condition based on the proposed state-quantity value and the available state-quantity value is satisfied.
A server computer system is configured to forward secure data. The system stores secure data in a database. Each unit of secure data for which the system supports forwarding is associated with a respective token. The system receives from a first server, a request comprising at least: an indicator associated with a secure data, a destination indicator, a first API key, a second API key, and a body having a predefined data format. The system validates the request based on the first API key, references the database to obtain the secure data based on the indicator and the respective token, and populates the body with the secure data. Once populated, the system transmits a second request comprising the second API key and the populated body to a second server, based on the destination indicator.
Disclosed herein are methods and systems for improved service system configuration during distributed services execution by a distributed services system. In one example, different sets of machine learning models respectively generate signals indicative of predicted risk and expected values associated with execution of a service by the distributed services system. Next, expected values associated with actions, where each action corresponds to a configuration of the service, are determined so that an action that maximizes the expected value associated with the execution of the service based on the predicted risk can be selected. The action is then executed configuring the execution of the service for a user in the distributed services system.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
62.
Dynamically recalibrating machine learning model parameters
Discussed herein are methods and systems for dynamically recalibrating machine learning model parameters. In one method, a server executes one or more prediction models to process network operations from various data feeds, in order to identify the likelihood of these operations being fraudulent or malicious. The server monitors performance data, such as the operation and execution metrics of network operations, and evaluates whether the performance values, like recall values, meet defined thresholds. If the performance data fails to meet these thresholds, the server employs a function-generation machine learning model to predict a threshold modification function. This modification function is then applied to adjust the relevant thresholds. Utilizing the modification function, the server dynamically revises one or more parameters of the prediction models to enhance their accuracy and efficacy.
Systems and methods provide for security event detection using machine learning. Event data items are processed using a first machine-learning model to generate an encoding for each corresponding event data item. Each encoding is processed using a second machine learning model to generate a classification indicating whether the corresponding event is fraudulent. A security event is determined based on some of the generated classifications. In response to detecting the security event, an event processing rate is adjusted.
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
64.
LOAD BALANCER AND SHUFFLE SHARDING FOR CLOUD-HOSTED SERVICES
Embodiments include hardware and software resources of a distributed computing system for routing user data traffic to computing resources organized using a shuffle sharding arrangement. Layer 3 (L3) network load balancers proxy or route user data traffic requests to layer 4 (L4) transport load balancers. A L4 transport load balancer proxies and routes the requests to certain ingress cells that are assigned or mapped to the hosted computing services of the user requests according to proxy or routing functions and mapping data. The assignments between cells and computing services may be implemented by a cell manager program when onboarding the computing services in accordance with the shuffle sharding arrangement and configuration. The transport load-balancer may impose and enforce the shuffle sharding by routing user data to ingress cells assigned to the computing services using previously determined mappings data stored in a mappings database (or data file).
An entity can be associated to another entity through an association with an organization. An authorized user in a first entity can request via an interface associated with the organization that an identifier of another entity be added to an organization data structure of the organization. The organization can verify the request and submit a request to the other entity. The other entity may become associated with the first entity. Aggregated functions may then be performed across all entities in the organization according to the organization data structure.
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
A server can adjust access privileges of a customer object of a first entity to provide access to the customer object to a second entity that is associated with the first entity in an organizational data structure, resulting in a shared customer object. An operation request can be received which is associated with the second entity with regard to the shared customer object. An option to associate at least one account object of the first entity to the shared customer object may be provided. After receiving an indication to associate the at least one account object to the shared customer object, the operation request may be executed using the at least one account object.
Systems and methods for classifying a user and issuing actions are disclosed. One method may include receiving a first score for a first characteristic associated with a user and a second score for a second characteristic associated with the user. The first and second scores may be evaluated for determining a first metric for the user. A criterion may be detected for reevaluating the first metric. Based on detecting the criterion, a first action and a timing of the first action may be selected for obtaining information associated with the user. The first action and timing of the first action may be configured to maximize accuracy of a prediction of a second metric and minimize a cost associated with the first action. The second metric may be generated based on the information obtained via the first action. A second action may be performed based on the second metric.
A method includes: computing a feature vector representing a user of a platform, the platform providing access to one or more products among a plurality of available products from a provider; and computing an estimated revenue based on the platform adopting a product of the plurality of available products including: computing a user adoption propensity of the product based on supplying the feature vector to a first machine learning model; computing a usage of the product by the user based on supplying the feature vector to a second machine learning model; computing an overall revenue growth of the user from the one or more products of the platform due to adoption of the product by the user based on supplying the feature vector to a third machine learning model; and computing a retention of the user based on supplying the feature vector to a fourth machine learning model.
G06Q 30/0202 - Market predictions or forecasting for commercial activities
G06Q 10/0637 - Strategic management or analysis, e.g. setting a goal or target of an organisationPlanning actions based on goalsAnalysis or evaluation of effectiveness of goals
Discussed herein are methods and systems to train customized machine learning models in a more efficient manner (e.g., using fewer labeled data points). In one example, a method may include using a first machine learning to generate likelihoods of fraudulent activity for an aggregated series of data associated with a series of computing systems. Based on the calculated likelihoods, a server can generate a training dataset that includes fraudulent data associated with a first computing system, fraudulent data associated with any other computing system within the series of computing systems other than the first computing system, non-fraudulent data associated with the first computing system, and non-fraudulent data associated with any other computing system within the series of computing systems other than the first computing system. The server may then train a second machine learning model using the training data, e.g., using a contrastive learning method.
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
A method for generating a chain of machine learning models includes: receiving a data sample including one or more features and a target property; identifying, by a processor of a computer system, an unsupervised machine learning model trained to classify data samples based on the one or more features, independently of the target property, into a plurality of clusters; classifying the data sample based on the one or more features using the unsupervised machine learning model to compute a cluster; identifying, by the processor, a supervised machine learning model corresponding to the cluster; and computing a value for the target property by supplying the data sample to the supervised machine learning model.
Disclosed herein are systems and methods for monitoring network traffic to identify cyberattacks. An example method includes obtaining a first plurality of data packets transmitted over a network during at least one period of time; determining a plurality of feature values based on the plurality of data packets, each feature corresponding to execution of a protocol by the first system; generating an embedding based on the plurality of feature values and an encoder, the encoder configured to generate embeddings based on pluralities of feature values, the embeddings corresponding to a period of time; and determining that at least one data packet of the plurality of data packets is involved in a cyberattack based on the embedding. The method can include causing an execution of a remedial protocol in association with the first system.
Presented herein are systems and methods of controlling access to values in electronic documents. A first service may receive an electronic document comprising a corresponding plurality of values associated with a corresponding plurality of fields to be provided to at least one of a plurality of client devices. The first service may identify, from the electronic document, a field of the plurality of fields associated with a corresponding value of the plurality of values is to be encrypted. The first service may select, from a plurality of first encryption keys, a first encryption key based on a field type of the field. The first service may generate a token using the value and the first encryption key for the field. The first service may send to a client device of the plurality of client devices, the electronic document comprising the token replacing the value associated with the corresponding field.
A method includes receiving one or more features characterizing; a first user; one or more features characterizing a geographic region; and a selection of product offerings offered by a platform; computing specific predictions for the selection of product offerings to be adopted by the first user, each specific prediction being computed for a corresponding product offering of the selection of product offerings by: selecting a specific model for the corresponding product offering corresponding to the one or more features characterizing the geographic region, trained based on training data collected by the platform; and supplying the one or more features characterizing the first user to the specific model to compute the specific prediction; and computing an aggregated prediction from adopting the selection of product offerings based on the specific predictions, the aggregated prediction being smaller than the sum of the specific predictions for the selection of product offerings.
In some embodiments, a multi-model approach may be utilized to produce predictions with greater accuracy, which may then be used to generate content for one or more entities. In some embodiments, such models may include one or more machine learning models, heuristic models, exponential smoothing models, and/or other models. As an example, based on a processing volume corresponding to user data associated with a user, a first model may be selected for processing the user data over use of a second model for processing the user data. As such, based on the selection of the first machine learning model, the user data may be inputted into the first machine learning model to obtain a predicted result related to the user. Based on the predicted result, content for the user may be generated for display on a user device associated with the user.
One method includes detecting a condition associated with an event stream of a first plurality of event streams associated with a first system; determining that the event stream is associated with a second system; identifying a second plurality of event streams associated with the second system; generating, based on the condition, an event data structure comprising a first set of events identified from the first plurality of event streams and a second set of events identified from the second plurality of event streams; converting the event data structure into at least two feature vectors corresponding to the first system and the second system for one or more machine-learning models; and executing the one or more machine-learning models using the at least two feature vectors as input and outputting a likelihood of fraud for the first system or the second system.
Disclosed herein are methods and systems for a memory and network bandwidth efficient processes for managing the movement of assets during distributed services execution by a distributed services system. In one example, an event message is received that specifies configurations of an asset movement. Next, different aggregation processes are performed at different time periods based on the event message configurations, to group and net asset movements to reduce the frequency and number of resulting asset movements, and to enable freeing of distributed services system memory used to store events after aggregation is performed. Next, a planning system of the distributed services system generates a planned action to move assets between accounts based on the aggregation process results. An action executor of the distributed services system executes the planned action causing the movement of the assets.
A method and system for updating a topology on router nodes in a distributed storage system are described. The method can include obtaining, by a first service of a control plane service, topology information from an inventory data store by querying a second service of the control plane service that manages the inventory data store for the topology information. The method can further include generating, by the first service of the control plane service, a topology payload based on the obtained topology information. The method can also include sending, by the first service of the control plane service, a request comprising the topology payload to a router node.
The methods and systems disclosed herein allow for faster and more efficient authentication using a partial cookie instead of a full cookie (or other data structure). In one example, a server receives, during the first browser session at the first time, a first request for authorization from an electronic device along with authentication information. Responsive to generating a profile using the authentication information, the server transmits to the electronic device a first data source configured to grant access to the profile to the electronic device, via a first authentication protocol; and receives, at a second browser session at a second time, from the electronic device, a second request for authorization to access the profile; responsive to a determination that the electronic device includes the first data source, the server executes a secondary authentication protocol.
A method and apparatus for executing data access requests in a distributed storage system are described. The method can include receiving, by a router node from a service application, a data access request to read data from one of a plurality of data storage nodes, the data access request comprising a key associated with the data, and generating a hash value from the key. The method can further include determining a data storage node of the plurality of data storage nodes that can satisfy the data access request based at least in part on the hash value generated from the key. The method further includes transmitting, to the data storage node, the data access request with the hash value, and receiving the data, the data storage node accessing the data using the hash value. The method can also include transmitting the data to the service application.
G06F 16/27 - Replication, distribution or synchronisation of data between databases or within a distributed database systemDistributed database system architectures therefor
80.
SYSTEMS AND METHODS FOR IDENTIFYING AND ADDRESSING MALICIOUS NETWORK TRAFFIC BASED ON NETWORK TRAFFIC LANE ACTIVITY
Disclosed herein are systems and methods for identifying and addressing malicious network traffic based on network traffic lane activity. An example method includes receiving data associated with a plurality of messages transmitted via a network, determining a first network traffic lane associated with a first set of messages of the plurality of messages and a second network traffic lane associated with a second set of messages of the plurality of messages, and determining that the first set of messages is associated with an increased probability of being involved in a distributed denial of service (DDoS) attack. In examples, the method includes causing at least one remedial action to be performed for at least a portion of messages associated with the first network traffic lane. Non-transitory machine-readable mediums are also disclosed.
A server computer system includes a decentralized architecture that receives at a central server, parameter values provided by one or more parameter servers. The parameter values are associated with a first parameter. The central server determines a global parameter value based on the parameter values, and persists the global parameter value to a database. The central server transmits the global parameter value to one or more second servers that each determine a local parameter value also corresponding to the first parameter. Each of the one or more second servers transmits the local parameter to a client and insulates the central server from interactions with the client.
H04L 67/10 - Protocols in which an application is distributed across nodes in the network
H04L 67/1014 - Server selection for load balancing based on the content of a request
H04L 67/1097 - Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
82.
Payment processing method and apparatus with advanced funds
A payment processing method and apparatus with advanced funds are disclosed. In one embodiment, the method comprises generating, using a revenue forecasting engine of a payment processing system, a probabilistic forecast of revenue for a plurality of merchants for a period of time in the future; determining, using a pricing engine of the payment processing system, one or more potential cash advances for each of the plurality of merchants; automatically generating one or more offers for advances for each of the plurality of merchants; electronically sending a notification containing the one or more offers to the plurality of merchants for display on a graphical user interface (GUI) with information about availability of an advance and terms to enable selection of at least one of the one or more offers.
G06N 7/01 - Probabilistic graphical models, e.g. probabilistic networks
G06Q 20/02 - Payment architectures, schemes or protocols involving a neutral third party, e.g. certification authority, notary or trusted third party [TTP]
G06Q 30/0202 - Market predictions or forecasting for commercial activities
83.
METHODS AND SYSTEMS FOR MULTI-FACTOR AUTHENTICATION
Disclosed herein are methods and systems for multi-platform authentication of electronic devices. One method involves a processor monitoring data related to the execution of an initial authentication request for a user via a first electronic platform. Subsequently, the processor receives, via the first platform, a request to complete a second authentication request by a second electronic platform, which corresponds to a multi-factor authentication. Upon receiving a first factor authentication purportedly authenticating the identity of the user, the processor generates second factor authentication information based on the monitored data. A message containing both first and second factor authentication details is then generated and transmitted to the second electronic platform. Upon receiving a positive authentication result from the second electronic platform, confirming the user's identity authentication.
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
84.
Systems and methods for providing an end-to-end customer portal
Methods and systems for providing an end-to-end full stack customer portal are provided. A customer portal may be configured by a commerce platform based on configuration settings received from a merchant, the configuration settings indicating a set of functions to be provided by the customer portal. Upon receiving a request to generate a portal session, the commerce platform may generate the portal session and a portal session object, the portal session object comprising a uniform resource locator (URL) to provide access to the portal session. The portal session object may be transmitted to the merchant. In response to a portal access request made via the URL, the commerce platform may provide access to the customer portal via the portal session, to a customer who made the portal access request.
A method is disclosed for assessing the health of a cluster within a distributed data storage system. The method involves a first service receiving a request related to the health status of a cluster. The first service validates the received request. A second service transmits a message to the first service to obtain data associated with the cluster. The second service receives the requested data from the first service. Based on the received data and through communication with the cluster, the second service determines the health of the cluster.
G06F 16/27 - Replication, distribution or synchronisation of data between databases or within a distributed database systemDistributed database system architectures therefor
G06Q 10/0631 - Resource planning, allocation, distributing or scheduling for enterprises or organisations
In an example embodiment, a solution is provided wherein a machine learning model is to determine a likelihood that a transaction is fraudulent, but also a separate machine learning model is used to determine a suitable threshold for a merchant. This predicted suitable threshold can either be automatically applied to the merchant, or can be recommended to the merchant (allowing the merchant to accept or reject it).
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
A user scans a payment card while setting up an account on a merchant's website, or while completing a check out to purchase an item or service for the first time. The subject system stores signals from the card scan (e.g., device ID, verified card, location, last time scanned and used, etc.). The next time a transaction is requested for the card at another merchant, the subject system can reference the last data it has on the card. If the transaction is being requested from the same device or a reasonably close physical location within a reasonable timeframe, the subject system can be highly confident that this is a legitimate transaction, without requiring the customer to scan their payment card again.
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
G06Q 20/12 - Payment architectures specially adapted for electronic shopping systems
88.
SYSTEMS AND METHODS FOR RECONCILING ELECTRONIC TRANSACTIONS FACILITATED BY A COMMERCE PLATFORM
A method and apparatus for reconciling electronic transactions facilitated by a commerce platform are described. The method may include receiving, the commerce platform, requests from a merchant system to authorize a plurality of financial transactions. The method may also include transmitting an authorization to the merchant system authorizing the merchant system to perform the financial transaction. The authorization may include a unique transaction identification (ID) corresponding to the request. The method may also include receiving from the merchant system, for each transaction ID, an order number associated with the transaction ID. The method may also include generating a settlement file comprising the transaction IDs. Each transaction ID may be arranged in an order in the settlement file according to its associated order number. The method may also include transmitting the settlement file to the merchant device.
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
G06Q 20/02 - Payment architectures, schemes or protocols involving a neutral third party, e.g. certification authority, notary or trusted third party [TTP]
G06Q 20/10 - Payment architectures specially adapted for electronic funds transfer [EFT] systemsPayment architectures specially adapted for home banking systems
G06Q 20/12 - Payment architectures specially adapted for electronic shopping systems
The disclosure generally describes one or more techniques for authenticating a webhook endpoint with a webhook server. Some techniques include a webhook server sending a seed with a webhook endpoint after the webhook endpoint is registered with the webhook server. In some examples, the webhook server generates the seed to send to the webhook endpoint and stores the seed with a key associated with the webhook endpoint. In such examples, the webhook server does not send data associated with the particular events to the webhook endpoint until the webhook endpoint acknowledges receipt of the seed while the seed is still valid.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
A method and apparatus for a commerce platform providing proof of application ownership of a network distributable application are described. The method may include receiving a request to approve an application developed by a merchant system. The method may also include generating a unique identifier (ID) for the application to be included as metadata within the application. Furthermore, the method may include obtaining, from an application information system, data describing the application, and extracting an ID from metadata in the data obtained by the application information system. Then, the method may include that in response to determining that the ID extracted from the metadata matches the unique ID, associating the merchant with the application in a merchant account at the commerce platform and approving the application for interacting with the commerce platform.
Methods, systems, and computer readable medium are provided for generating, by a secure processor, a plurality of configurable data entry elements configured into a webpage, receiving sensitive data entered via the plurality of configurable data entry elements during a user data entry session, generating a hidden controller iframe in the webpage, aggregating, by the hidden controller iframe, the sensitive data across the plurality of configurable data entry elements, and directing aggregated sensitive data to the secure processor hosted by a first server separate from a second server hosting the webpage.
In an example embodiment, rate limiting is performed at the instance level (i.e., locally), but utilizing throughput statistics of other instances. These statistics may be measured locally by each instance and then transmitted to a central store, where they are aggregated. Each instance is then able to asynchronously request the aggregated statistics from the central store and use this information to manage the parameters of its own local rate limiter.
Described herein are systems and methods to use modeling techniques to identify gradual changes in various metrics identified as a result of analyzing an aggregated transaction dataset. In one method, a computer model dynamically slice the data using an attribute, calculates an entropy value for using a rolling time window, and uses the entropy value to identify anomalous behavior. The model may use information gain to determine whether to further segmented the data slice into smaller data slices. The model may iteratively slice and analyze the data until a data slice corresponding to the root cause is determined. The model may then traverse the hierarchy of data slices and combine the data slices until an optimized combined data slice. The model may train a machine learning component, such as a booted tree algorithm, to optimize its traversal of the hierarchy of data slices.
Disclosed herein are methods and systems for multi-platform authentication of electronic devices. One method involves a processor monitoring data related to the execution of an initial authentication request for a user via a first electronic platform. Subsequently, the processor receives, via the first platform, a request to complete a second authentication request by a second electronic platform, which corresponds to a multi-factor authentication. Upon receiving a first factor authentication purportedly authenticating the identity of the user, the processor generates second factor authentication information based on the monitored data. A message containing both first and second factor authentication details is then generated and transmitted to the second electronic platform. Upon receiving a positive authentication result from the second electronic platform, confirming the user's identity authentication.
G06Q 20/40 - Authorisation, e.g. identification of payer or payee, verification of customer or shop credentialsReview and approval of payers, e.g. check of credit lines or negative lists
96.
ASSETS INTERFACE OF A DISTRIBUTED ASSETS MANAGEMENT PLATFORM
Disclosed here are methods and systems for managing the movement of assets between accounts on a distributed digital platform. In one embodiment, a specialized interface in the distributed digital platform receives a message about an asset transfer request that includes various data fields and an identifier. The interface then queries the specific configuration for the type of asset transfer (based on the data included within the received message), which might involve multiple steps or “legs.” Next, the digital platform converts the original message into one or more new messages, each corresponding to a step in the transfer process. Finally, the digital platform sends at least one of these new messages to a system responsible for actually causing/facilitating the movement, thereby completing the transfer.
Aspects of the subject technology include obtaining a transfer request event associated with a transaction, the transfer request event indicating a request day of week and time of day, and, when the request time of day is past a pre-determined cutoff time, adjusting the request day of week to be a subsequent day. Aspects also include determining, using the transfer request event and based on a machine learning model trained on historical transaction data, a predicted transfer delay for the transaction, obtaining a set of relevant non-transfer days based on a comparison between the historical transaction data and a set of past non-transfer days, and, when one or more non-transfer days from the set of relevant non-transfer days occur within a time period from the request day of week and over the predicted transfer delay, adjusting the predicted transfer delay based on the one or more non-transfer days.
G06Q 20/10 - Payment architectures specially adapted for electronic funds transfer [EFT] systemsPayment architectures specially adapted for home banking systems
Aspects of the subject technology include providing, from a sever to a first device, balance information for a plurality of accounts of an organization. For a first selected account, information for first expected sweeps which are to be received within a first time period, information for second expected sweeps for a second time period, and information for reconciled sweeps for the second time period are received. The first expected sweeps or the second expected sweeps include a first portion of expected sweeps which are automatically initiated by a service. When an anomaly is detected in the first account, the service may schedule an automated event to resolve the anomaly, and the automated event is reported. The service may not schedule an automated event and an input is received to resolve the anomaly.
A method for performing search system upgrades is described. The method may include processing a software upgrade for a search system cluster distributed over one or more nodes, the one or more nodes comprising current search system data nodes. The method may include allocating at least a set of one or more search system data nodes for the software upgrade including at least one upgraded search system data node. The method may include receiving, during the software upgrade, transaction data for a transaction, and receiving search requests to be executed by the search system cluster. The method may include performing ingestion of received transaction data in both the current search system data nodes and the at least one upgraded search system data node, and processing the search requests by the search system cluster against the current search system data nodes until the software upgrade is determined to be complete.
G06F 11/14 - Error detection or correction of the data by redundancy in operation, e.g. by using different operation sequences leading to the same result
Aspects of the subject technology allow an entity to aggregate transaction data for safeguarding. Aspects include obtaining a set of data items associated with a set of transactions, and, for each respective data item, determining a funding type corresponding to the respective data item based at least in part on a respective attribute and augmenting the respective data item based on the determined funding type and an attribute estimation. Aspects also include aggregating the set of data items into respective groups based on the funding type, the merchant identifier, and/or the jurisdiction identifier, and transmitting a respective group to a service for determining whether a respective bank account includes a threshold amount of funds based on the amounts of data items in the respective group.