Systems and methods for automatically securing and validating multi-server electronic communications over a plurality of networks
In one embodiment, a method includes transmitting, by a privacy component, to a first server, a privacy communication request consisting of device data and server data associated with a second server, receiving, by the privacy component, from the first server, a privacy communication string tagged to the second server, wherein the privacy communication string and a privacy communication string record are generated in response to the privacy communication request identifying the second server based on the server data, transmitting, by the privacy component to the second server the privacy communication string, configured to be transmitted to the first server as an approval request, identifying the second server as a requesting server associated with the secure exchange, and receiving, by the privacy component, from the second server, an indication that the approval request was validated based on the requesting server matching the second server identified in the privacy communication string record.
1 . A method comprising, by a privacy component application configured to communicate with a first server of a privacy payment platform system associated with the privacy component application, when executed on a user device associated with a user:
detecting, by the privacy component application, based on one or more user operations associated with a merchant system, an initiation of a transaction associated with the user and the merchant system;
extracting, by the privacy component application, responsive to the detection of the initiation of the transaction, device data associated with the user device and server data associated with a second server, wherein the user device is configured to be in active communication with the second server, wherein the second server is associated with the merchant system;
generating, by the privacy component application, a privacy communication request comprising the device data and the server data associated with the second server;
transmitting, by the privacy component application, to the first server associated with the privacy payment platform system, via a communication network, the privacy communication request;
receiving, by the privacy component application, from the first server, via the communication network, a privacy communication string tagged to the second server, wherein the privacy communication string corresponds to a privacy communication string record associated with the first server, wherein the privacy communication string and the privacy communication string record are based on the privacy communication request, and wherein the privacy communication string record identifies the second server based on the server data;
transmitting, by the privacy component application, to the second server, the privacy communication string, wherein the privacy communication string is configured to be included in an approval request for a secure exchange, wherein the approval request further comprises identifying information associated with the second server, and wherein the approval request is associated with a card network; and
receiving, by the privacy component application, from the second server, an indication corresponding to a successful approval request for the secure exchange, wherein the successful approval request is based on the second server identified in the privacy communication string record being the same as the second server associated with the identifying information in the approval request.
2 . The method of claim 1 , wherein the privacy communication request is associated with the transaction for an exchange of secure data between the user device and the second server.
3 . The method of claim 2 , wherein the privacy communication request further comprises transaction data associated with the exchange of secure data between the user device and the second server.
4 . The method of claim 3 , wherein the transaction data is configured to indicate that the privacy communication request is an authentic privacy communication request associated with the user device and the second server.
5 . The method of claim 1 , wherein the server data associated with the second server is configured to identify an entity associated with the second server.
6 . The method of claim 5 , wherein the server data comprises one or more server properties associated with the second server.
7 . The method of claim 6 , wherein the entity associated with the second server is determined to be a valid entity based on the server properties associated with the second server.
8 . The method of claim 1 , wherein the device data comprises device data associated with a location of the user device.
9 . The method of claim 8 , wherein the device data associated with a location of the user device is configured to indicate whether the location of the user device is greater than a specified distance from one or more previous locations of the user device transmitted in one or more previous communication requests, and wherein the location of the user device being greater than the specified distance causes the user device to receive a prompt to authenticate the privacy communication request.
10 . The method of claim 1 , wherein the privacy communication string is associated with a privacy payment card, and wherein the privacy communication string record identifies the second server as being associated with the privacy payment card.
11 . The method of claim 10 , wherein an external funding account is linked to the privacy payment card, and wherein the privacy payment card is configured to access the external funding account for payment transactions with the second server.
12 . The method of claim 10 , wherein the approval request for a secure exchange is for a payment transaction associated with the privacy payment card.
13 . The method of claim 10 , wherein the privacy communication string record further comprises one or more authorization parameters for the privacy payment card.
14 . The method of claim 13 , wherein one or more of the authorization parameters are specified in the privacy communication request.
15 . The method of claim 14 , wherein the authorization parameters are configured to determine at least in part whether the payment transaction should be authorized.
16 . The method of claim 15 , wherein the one or more authorization parameters specify one or more transaction thresholds for the privacy payment card.
17 . The method of claim 16 , wherein the transaction thresholds include one or more of a total number of authorized transactions, a total number of authorized transactions in a specified time period, a value for a single authorized transaction, a total value of all authorized transactions, and a total value of all authorized transactions over a specified time period.
18 . The method of claim 1 , further comprising:
receiving, by the privacy component application, from the first server, an indication that the approval request requires user input to authorize the approval request; and
transmitting, from the privacy component application, user input authorizing the approval request, wherein the user input indicates that the requesting server matches the second server.
19 . One or more computer-readable non-transitory storage media embodying software that is operable when executed by a processor to:
detect, by a privacy component application configured to communicate with a first server of a privacy payment platform system associated with the privacy component application when executed on a user device associated with a user, based on one or more user operations associated with a merchant system, an initiation of a transaction associated with the user and the merchant system;
extract, by the privacy component application, responsive to the detection of the initiation of the transaction, device data associated with the user device and server data associated with a second server, wherein the user device is configured to be in active communication with the second server, wherein the second server is associated with the merchant system;
generate, by the privacy component application, a privacy communication request comprising the device data and the server data associated with the second server;
transmit, by the privacy component application, to the first server associated with the privacy payment platform system, via a communication network, the privacy communication request;
receive, by the privacy component application, from the first server, via the communication network, a privacy communication string tagged to the second server, wherein the privacy communication string corresponds to a privacy communication string record associated with the first server, wherein the privacy communication string and the privacy communication string record are based on the privacy communication request, and wherein the privacy communication string record identifies the second server based on the server data;
transmit, by the privacy component application, to the second server, the privacy communication string, wherein the privacy communication string is configured to be included in an approval request for a secure exchange, wherein the approval request further comprises identifying information associated with the second server, and wherein the approval request is associated with a card network; and
receive, by the privacy component application, from the second server, an indication corresponding to a successful approval request for the secure exchange, wherein the successful approval request is based on the second server identified in the privacy communication string record being the same as the second server associated with the identifying information in the approval request.
20 . A system comprising: one or more processors associated with a user device; and a non-transitory memory coupled to the processors comprising instructions executable by the processors, the processors operable when executing the instructions to:
detect, by a privacy component application configured to communicate with a first server of a privacy payment platform system associated with the privacy component application when executed on a user device associated with a user, based on one or more user operations associated with a merchant system, an initiation of a transaction associated with the user and the merchant system;
extract, by the privacy component application, responsive to the detection of the initiation of the transaction, device data associated with the user device and server data associated with a second server, wherein the user device is configured to be in active communication with the second server, wherein the second server is associated with the merchant system;
generate, by the privacy component application, a privacy communication request comprising the device data and the server data associated with the second server;
transmit, by the privacy component application, to the first server associated with the privacy payment platform system, via a communication network, the privacy communication request;
receive, by the privacy component application, from the first server, via the communication network, a privacy communication string tagged to the second server, wherein the privacy communication string corresponds to a privacy communication string record associated with the first server, wherein the privacy communication string and the privacy communication string record are based on the privacy communication request, and wherein the privacy communication string record identifies the second server based on the server data;
transmit, by the privacy component application, to the second server, the privacy communication string, wherein the privacy communication string is configured to be included in an approval request for a secure exchange, wherein the approval request further comprises identifying information associated with the second server, and wherein the approval request is associated with a card network; and
receive, by the privacy component application, from the second server, an indication corresponding to a successful approval request for the secure exchange, wherein the successful approval request is based on the second server identified in the privacy communication string record being the same as the second server associated with the identifying information in the approval request.