User Agreement Framework

Through the end-to-end user consent framework, users can centrally manage data collection and usage settings on client devices, solving the problem of users submitting consent repeatedly in multiple online domains, and achieving compliance and user control of data transmission.

CN114902259BActive Publication Date: 2025-07-08GOOGLE LLC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080091737.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-01-22
Publication Date
2025-07-08
Estimated Expiration
2040-01-22

AI Technical Summary

Technical Problem

In the prior art, users repeatedly submit consent settings in multiple online domains, resulting in data collection and use not meeting user preferences and lacking effective cross-domain management and audit mechanisms.

Method used

Provides an end-to-end user consent framework that allows users to centrally manage and specify data collection and usage settings, including digital signatures and audit mechanisms, to ensure that data transmission complies with user consent.

Benefits of technology

Centralized management of user data and effective cross-domain control are realized to ensure that data transmission complies with user consent, prevent unauthorized data transmission, and provide an audit mechanism to ensure compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114902259B_ABST
    Figure CN114902259B_ABST
Patent Text Reader

Abstract

Methods, systems, and apparatus are described, including apparatus for managing user data according to user consent settings. In some aspects, a method includes determining that a request for transmission by a client device to a recipient will include user data of a user of the client device. In response to determining that the request will include user data, the method includes: requesting, from a consent management module of the client device, current user consent settings specified by the user, the current user consent settings defining at least one of the following: (i) user data that can be transmitted from the client device, (ii) how user data transmitted from the client device can be used, or (iii) which recipients can receive and retain user data from the client device. The method further includes: receiving the current user consent settings from the consent management module, and generating request data according to the current user consent settings.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] User consent is an important part of online privacy protection. In some cases, users may want to ensure that their data is collected and used only according to their preferences. Respecting user consent and protecting the data of consenting users helps to gain user trust and improve the user's online experience. Summary of the Invention

[0002] This specification describes techniques related to an end-to-end user consent framework for systematically collecting, disseminating, and enforcing user consent across an online ecosystem.

[0003] Generally, one innovative aspect of the subject matter described in this specification can be embodied in a method that includes determining that a request for transmission from a client device to a recipient will include user data of a user of the client device. In response to determining that the request will include user data, the method includes requesting, from a consent management module of the client device, current user consent settings specified by the user, the user consent settings defining at least one of the following: (i) the user data that can be transmitted from the client device, (ii) how the user data transmitted from the client device can be used, or (iii) which recipients can receive and retain the user data from the client device. The method further includes receiving the current user consent settings from the consent management module and generating request data based on the current user consent settings. Generating the request data includes: including, in the request data, one or more portions of the user's user data that the user has consented to transmit to the recipient; and including, in the request data, at least a portion of the user consent settings that specify the consent given to the recipient for one or more portions of the user data, wherein the consent restricts the recipient's use of one or more portions of the user data. The method further includes transmitting the request data to the recipient. Other embodiments of this aspect include corresponding apparatuses, systems, and computer programs configured to perform the methods encoded on a computer storage device. Another aspect includes a non-transitory computer-readable medium including instructions that, when executed by one or more processors, cause the processors to perform the methods disclosed herein.

[0004] These and other embodiments can each optionally include one or more of the following features.

[0005] Some aspects include using a private key of a computing platform of a client device to generate a digital signature for a portion of a user consent setting that specifies consent given to a recipient for using one or more portions of user data. Transmitting request data to the recipient can include generating and transmitting a proof token that includes at least the request data, user consent data, and the digital signature. Some aspects can include providing a public key corresponding to the private key of the computing platform of the client device to a third party. The public key enables the third party to verify the user consent data. This implements a secure method for a third party to verify user consent data specified by the user.

[0006] Some aspects include receiving selection data that specifies a selection of a given consent management platform from a plurality of consent management platforms. The method further includes: obtaining a consent management module from the given consent management platform or an app store, and installing the consent management module on the client device.

[0007] Some aspects include presenting an interactive interface that enables a user to specify user consent settings and review current user consent settings. The aspect can include receiving data that specifies the user consent settings and storing the user consent settings at the client device. The aspect can also include presenting one or more recommended user consent settings in the interactive interface. The aspect can also include selecting one or more recommended user consent settings based at least on the current location of the client device or user activity on the client device. The user interface enables the user to effectively review and manage consent settings, thereby further facilitating improved control by the user over their user data consent settings. Additionally, presenting recommended user consent settings provides the user with an effective way to specify their user consent settings without having to manually select settings, but rather can adopt the recommended consent settings, which can be based on the current location of the client device or user activity on the client device.

[0008] Some aspects can include receiving a digital component for presentation at a client device and determining that the digital component is a personalized digital component selected based on one or more portions of the user's user data. In response to determining that the digital component is a personalized digital component selected based on one or more portions of the user's user data, the method includes: determining whether the current user consent settings allow presentation of the personalized digital component provided by a digital component distribution system that provided the personalized digital component; and in response to determining that the current user consent settings do not allow presentation of the personalized digital component provided by the digital component distribution system, preventing the client device from presenting the personalized digital component. In this way, the method uses the current user consent settings to prevent unwanted personalized digital components from being presented on the client device.

[0009] In some aspects, the consent management module includes a user consent plugin for the computing platform of the client device. In some aspects, the consent management module includes a user consent plugin for the operating system of the client device. In some aspects, the consent management module includes a user consent plugin for the web browser of the client device. Providing the consent management module in the form of these embodiments as a plugin allows the consent management module to be installed as a plugin into pre-existing applications or systems on the client device, thereby providing the additional functionality provided by the consent management module to these pre-existing applications or systems.

[0010] The subject matter described in this specification can be implemented in particular embodiments so as to achieve one or more of the following advantages. The user consent platform described in this document enables a user to specify user consent settings for multiple recipients (e.g., domains) using a single consent management plugin (or other module) and / or a single user interface, thereby making it easier and more effective to control how user data is collected and used. In other words, the disclosed subject matter provides a means for users to centrally manage their user consent settings for their user data for multiple recipients, thereby providing users with improved control over their personal user data. The consent management plugin can also recommend customized user consent settings for the user, for example based on the user's geographical location, thereby further enhancing the efficiency and ease of managing consent settings and ensuring that the consent settings are appropriate based on the laws or rules of individual countries or regions. The client device can query the user consent settings before transmitting user data to prevent the transmission of user data that the user has not consented to transmit.

[0011] When user data is transmitted from the client device, the transmitted data can include digitally signed user consent settings that must be stored by the recipient. In this way, the use of the user and the user data can be audited to ensure compliance while preventing the recipient from fraudulently tampering with the received user consent settings.

[0012] The various features and advantages of the foregoing subject matter are described below with reference to the accompanying drawings. Additional features and advantages are apparent from the subject matter described in this document and the claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is a block diagram of an environment that provides a framework for managing user consent for data collection and use.

[0014] Figure 2 is a flowchart illustrating an example process for installing a user-selected consent management module on a client device.

[0015] Figure 3 is a flowchart illustrating an example process for enabling a user to specify user consent settings and store the user consent settings.

[0016] Figure 4 It is a flowchart showing an example process for transmitting requests according to user consent settings.

[0017] Figure 5 It is a block diagram of an example computer system that can be used to perform the above operations.

[0018] The same reference numerals and names in the various figures indicate the same elements. Detailed Description

[0019] Generally, the systems and techniques described herein provide an end-to-end user consent framework for systematically collecting, disseminating, and enforcing user consent across an online ecosystem (e.g., across completely separate domains). Many different companies and other organizations collect, share, and rely on user data for various purposes, such as customizing content for users. One way to manage user consent is for each organization to obtain the consent of each of its users, for example, by requesting user preferences when the user accesses a website or downloads an application. However, this can be frustrating for users, may require entering duplicate data, and does not ensure that user data is collected and / or used in accordance with those preferences. Accordingly, the disclosed subject matter relates to techniques for solving the technical problem of providing a simpler and more effective method for managing user consent data.

[0020] One or more technical solutions to this technical problem involve the disclosed user consent framework, which can be implemented as a system, method, apparatus, computer-readable medium, and computer program. The user consent framework described in this document enables users to select a consent management platform from multiple consent management platforms to manage their user consent settings. A user's user consent settings define, for example, what user data can be collected, who can receive the data, and how each recipient can use the data. In this way, users can centrally manage their privacy across the entire online ecosystem using a single platform. In other words, by using a consent management platform, users can submit their consent settings once and have those settings enforced when the user accesses multiple different domains (e.g., websites) and applications (e.g., mobile apps), without the user having to resubmit their consent settings.

[0021] The consent management platform can provide a consent management module to the user's client device. For example, a plugin for an operating system that enables the user to specify user consent settings. The consent management module can provide one or more interactive user interfaces that enable the user to specify user consent settings. When the client device is about to transmit a request that will include user data, the platform of the client device can query the current user consent settings to determine what (if any) user data can be included in the request and what restrictions on the data should be included in the request. The client device can then generate the request according to the current user consent settings and transmit the request to its recipient.

[0022] To ensure compliance with user consent settings, requests sent from the client device can include digitally signed user consent settings that can be stored by the recipient. In this way, an auditor can verify the user consent settings received by the recipient, and the recipient cannot change or forge the user consent settings.

[0023] The consent management module can also recommend user consent settings to the user to make it easier for the user to specify user consent settings. The consent management module can recommend user consent settings based on various factors, including for example the current geographical location of the user device, the contribution of the recipient to digital components presented at the user device, and / or user activity on the device.

[0024] Figure 1 FIG. 100 is a block diagram of an environment 100 that provides a framework for managing user consent for data collection and use. Example environment 100 includes a data communication network 105, such as a local area network (LAN), wide area network (WAN), the Internet, a mobile network, or a combination thereof. Network 105 connects client devices 110, publishers 130, websites 140, a digital component distribution system 150, and a consent management provider system 170. Example environment 100 can include many different client devices 110, publishers 130, websites 140, and consent management provider systems 170.

[0025] Website 140 is one or more resources 145 associated with a domain name and hosted by one or more servers. An example website is a collection of web pages formatted in HTML that can contain text, images, multimedia content, and programming elements, such as scripts. Each website 140 is maintained by a publisher 130, which is an entity that controls, manages, and / or owns one or more websites, including website 140. The domain can be a domain host, which can be a computer that hosts the corresponding domain name, such as a remote server.

[0026] Resource 145 is any data that can be provided over network 105. Resource 145 is identified by a resource address (e.g., a Uniform Resource Locator (URL)) associated with the resource 145. Resources include HTML pages, word processing documents, and Portable Document Format (PDF) documents, images, videos, and feeds, to name a few. A resource can include content that can include embedded information (such as meta information in a hyperlink) and / or embedded instructions (such as a script), such as words, phrases, images, and sounds.

[0027] Client device 110 is an electronic device capable of communicating over network 105. Example client devices 110 include personal computers, mobile communication devices (e.g., smart phones), and other devices capable of sending and receiving data over network 105. Client device 110 has a device platform 113, which is an environment in which software applications execute. Device platform 113 can include the hardware of client device 110 and / or the operating system of client device 110.

[0028] Client device 110 typically includes applications 112 that run in device platform 113 and facilitate sending and receiving data over network 105, such as a web browser and / or native applications. A native application is an application developed for a specific platform or a specific device. Publisher 130 can develop native applications and make them available to client device 110, e.g., make the native applications available for download. In some embodiments, client device 110 is a digital media device, e.g., a streaming device that plugs into a television or other display to stream video to the television. The digital media device can also include a web browser and / or other applications that stream video and / or render resources.

[0029] A web browser can request resource 145 from a web server hosting website 140 of publisher 130, e.g., in response to a user of client device 110 entering the resource address of resource 145 in the address bar of the web browser or selecting a link that references the resource address. Similarly, a native application can request application content from a remote server of publisher 130.

[0030] Some resources 145, application pages, or other application content can include digital component slots for presenting digital components with the resource 145 or application page. As used throughout this document, the phrase "digital component" refers to discrete units of digital content or digital information (e.g., video clips, audio clips, multimedia clips, images, text, or another content unit). Digital components can be electronically stored in a physical memory device as a single file or as a collection of files, and digital components can take the form of video files, audio files, multimedia files, image files, or text files, and include advertising information, such that an advertisement is a type of digital component. For example, a digital component can be content that is intended to supplement the content of a web page or other resource presented by the application 112. More specifically, a digital component can include digital content related to the resource content (e.g., the digital component can relate to the same topic as the web page content or a related topic). Thus, the provision of digital components by the digital component distribution system 150 can supplement and generally enhance web page or application content.

[0031] When the application 112 loads a resource 145 (or application content) that includes one or more digital component slots, the application 112 can send a request 120 for digital components for each slot to the digital component distribution system 150 (which can include a proof token 122 as described below). The digital component distribution system 150 can then request digital components from the digital component provider 160. The digital component provider 160 is an entity that provides digital components for presentation with the resource 145.

[0032] In some cases, the digital component distribution system 150 can also request digital components from one or more digital component partners 157. The digital component partners 157 are entities that select digital components 129 on behalf of the digital component provider 160 in response to digital component requests.

[0033] The digital component distribution system 150 can select digital components 129 for each digital component slot based on various criteria. For example, the digital component distribution system 150 can select digital components from the digital components received from the digital component provider 160 and / or digital component partners 157 based on the relevance or association with the resource 145 (or application content), the performance of the digital component (e.g., the rate at which users interact with the digital component), etc. The digital component distribution system 150 can then provide the selected digital component(s) 129 to the client device 110 for presentation with the resource 145 or other application content.

[0034] The client device 110 can also include a consent management module 114 that enables a user of the client device 110 to manage user consent settings that define whether and / or how user data is collected and used. The consent management module 114 can be implemented as a plug-in to the device platform 113, e.g., as a plug-in to the operating system of the client device 110. A plug-in is a software component that provides additional features to an application. In some embodiments, the consent management module 114 can be implemented as a plug-in to a web browser or a native application.

[0035] The consent management module 114 can operate in a tightly controlled environment that isolates the consent management module 114 from other applications and / or resources of the client device 110. For example, the consent management module 114 can operate in a sandbox of the device platform 113. In this way, the consent management module 114 cannot communicate outside of the device platform 113 or interfere with the execution of other applications 112 on the same device.

[0036] The consent management module 114 enables the user to specify how user data is collected and used, such as the user's activities on the client device, web browsing history, native applications downloaded or accessed, demographic information, location information, interests, and / or other personal data. In some embodiments, the consent management module 114 enables the user to separately specify for all recipients and / or for each recipient whether the recipient can store and / or access information on the client device 110, use the user data to select digital components, use the user data to create one or more user profiles, use the user data (e.g., using the (one or more) profiles) to select personalized digital components, measure the performance of digital components or other content (e.g., based on whether the user interacts with the digital component or other content), and / or generate audience insights.

[0037] The consent management module 114 can provide one or more consent management user interfaces 116 that enable the user to specify user consent settings. For example, the user interface can present checkbox controls for each setting that allow the user to consent to the setting or reject the setting. In a particular example, the setting can be enabling the transmission of any user data from the client device 110. In this example, the user can select the checkbox for the setting (e.g., check it) or not select the checkbox (e.g., leave it unchecked) to reject the setting.

[0038] In another example, the user interface 116 enables a user to select from multiple options for settings. For example, the user interface 116 can present multiple buttons for each of a group of domain names (which can include websites of publishers, digital component providers 160, digital component distribution systems 150, and / or digital component partners 157) and / or native applications, with each button defining the type of data that can be sent by the application to that domain. The user can consent to the type of data by selecting the button and revoke consent by deselecting the button.

[0039] The consent management module 114 enables a user to specify user consent settings that define what data is transmitted from the client device 110, how the data can be used (e.g., customize the content of a web page or application, select digital components only over a secure channel in encrypted or unencrypted form), to which recipients the data can be sent, whether user data can be stored and for how long user data can be stored, and / or other appropriate consents regarding the use of user data. The consent management module 114 enables the user to specify settings for all recipients, e.g., a global setting, or to specify settings for each recipient. In this way, the user can have fine-grained control over how their data is collected and used.

[0040] The consent management module 114 can store the user consent settings specified by the user in the consent storage unit 117. The consent storage unit 117 can be isolated and / or encrypted to prevent access or modification by other devices or applications.

[0041] The consent management module 114 can be used to manage the collection and use of user data by each web browser and native application on the client device 110. When the client device 110 is about to send a request 120 that includes user data, e.g., on behalf of a web browser or native application, the device platform 113 can query the consent management module 114 for the current user consent settings. The device platform 113 can then generate a request that includes only the user data that the user has consented to and to the extent defined by the current user consent settings. In this way, a single consent module 114 can prevent the transmission of user data that the user has not consented to from multiple applications. Thus, in some embodiments, each client device 110 can have only one consent management module 114 installed on and / or active on the client device 110 at a given time.

[0042] In some cases, there may be multiple consent management provider systems 170 that operate to manage user data according to user consent settings. Each consent management provider can make the consent management module 114 available to users. In this example, each user can download or otherwise install their consent management module 114 from the consent management provider system 170 of their preferred consent management provider.

[0043] In some embodiments, the consent management module 114 can enable a user to specify whether audio, video, and / or image data is collected, transmitted to others, and / or used by others. For example, the consent management module 114 can enable a user to specify whether the client device 110 or another device (e.g., an auxiliary device (e.g., a smart speaker), another mobile device, etc.) can collect, receive, or use audio, video, or image data. In some embodiments, the consent management module 114 can enable a user to specify whether sensor information (e.g., from a smart thermostat or an Internet of Things (IoT) device) can be collected, transmitted, or used by others. In such an example, these devices can query the consent management module 114 to determine whether data can be sent to another device in a manner similar to the device platform 113.

[0044] The consent management module 114 can also include standard settings based on, for example, laws, regulations, or best practices that define whether user data can be collected and / or how user data can be used. These standard settings can include whether the device platform 113 should send user data or requests to a recipient (e.g., a specific network domain), whether requests to the recipient should include any user identifiers, whether the recipient can provide personalized content to the user, and / or other appropriate settings.

[0045] The consent management module 114 can periodically send a query 171 to the consent management provider system 170, for example, for updates to the standard settings, the logic for implementing the consent management module 114, and / or updates to the recommendation engine 115 (described below). In response, the consent management provider system 170 can provide the update 173 requested by the query 171. In this way, in response to changes in user privacy laws, regulations, or best practices, the consent management module 114 on each client device 110 can be updated.

[0046] The recommendation engine 115 can recommend user consent settings in the user interface(s) 116 to the user. The recommendation 115 can recommend user settings based on various factors, including, for example, the current geographic location of the client device 110, the recipient's contributions to the digital component presented at the client device 110, and / or user activity on the client device 110. The user activity can include, for example, web browsing history, location history, applications installed on the client device 110, and / or applications accessed by the user during a given time period. For example, the recommendation engine 115 can recommend user consent settings that comply with local laws, regulations, or best practices based on the user's current geographic location defined by a global positioning system (GPS) receiver of the client device 110 or based on the user's current geographic location inferred from the device's Internet Protocol (IP) address. In this way, users traveling internationally can be provided with recommended user consent settings that are appropriate for the current location.

[0047] As described above, the recommendation engine 115 can use the recipient's contribution to the digital component presented at the client device 110. The consent management module 114 or another application (e.g., a web browser or native application) can determine the contribution level of multiple domains to the presentation of the digital component at the client device 110 within a given time period. For example, the digital component can include metadata indicating one or more domains that contributed to the delivery of the digital component. In a specific example, the metadata can indicate that a first domain contributed certain graphics in the digital component and a second domain contributed text in the digital component. The consent management module 114 or application can determine the contribution level of each domain that contributed to at least one digital component presented at the client device 110.

[0048] The contribution level of a domain can be determined in a variety of ways. For example, the contribution level of a domain can be based on the number of digital components presented at client device 110 that the domain contributed, the percentage of digital components that were interacted with on client device 110 and that the domain contributed, the type or size of digital components presented at client device 110 that the domain contributed, and / or other appropriate factors.

[0049] The recommendation engine 115 can use the contribution level to recommend user consent settings to the user. For example, if a domain stores data on the client device 110 and / or receives user data from the client device 110, but does not contribute to the digital component presented at the client device 110, the recommendation engine 115 can recommend that the user block (e.g., disagree with) the domain from storing data on the client device 110 or receiving user data from the client device 110, because it may not know why the domain is collecting user data.

[0050] The recommendation engine 115 can compare the contribution level of a domain with a threshold. If the contribution level does not meet the threshold (e.g., is less than the threshold), the recommendation engine 115 can recommend that the user not consent to the domain storing data on the client device 110 or receiving user data from the client device 110. If the contribution level meets the threshold (e.g., meets or exceeds the threshold), the recommendation engine 115 can recommend that the user consent to the domain storing data on the client device 110 and / or receiving user data from the client device 110. The recommendation engine 115 can perform this recommendation process for each domain that contributes to at least one digital component presented at the client device 110.

[0051] The user can view the recommended user consent settings in the user interface(s) 116 and confirm or reject the recommended user consent settings. For example, the user interface 116 can present a set of recommended user consent settings that cover multiple domains and / or multiple types of consent (e.g., storing data, transmitting data, etc.), and the user can simply accept or reject the recommended user consent settings. This can make it easier and more efficient for the user to specify user consent settings relative to customizing each type of setting and / or for each domain.

[0052] In some embodiments, the device platform 113 sends a user consent setting with a request 120 that includes user data. Each recipient of the user data can be required to store the user consent setting, e.g., for auditing purposes. In this way, an auditor can audit the user data and user consent settings stored by the recipient to ensure that the recipient stores and uses each user's data in accordance with the user's consent settings.

[0053] To prevent fraud by the recipient, the device platform 113 (or the web browser or native app that sends the request) can digitally sign at least the user consent setting using a private key secretly maintained by the device platform 113 (or web browser or native app). The auditor can use the public key corresponding to (e.g., mathematically linked to) the private key and the stored used consent setting to verify the signature. If the signature cannot be verified using the public key and the stored user consent setting, the auditor can determine that the user consent setting has been changed.

[0054] In some embodiments, the device platform 113 generates a proof token 122 that is included in or implements the request 120. A proof token is a token that can include consent settings and a digital signature of the consent settings (using a private key) as well as other data, such that any modification to the user's consent settings after creation can be detected. For example, a proof token can be a complex message that includes consent settings and other data. The signature data can include a unique identifier of the user, such that the recipient of the proof token can verify that the proof token was sent from the user. The proof token can also include integrity tokens, such as a device integrity token and / or a browser integrity token, such that the recipient can verify that the proof token was received from a trusted device or a trusted web browser.

[0055] The proof token 120 can include data specifying the purpose or operation of the request (e.g., to change user consent settings or request a digital component), a user identifier that uniquely identifies the user (e.g., the public key of the client device 110), a proof token creation time indicating the time when the proof token 122 was created, an integrity token (e.g., a device integrity token and / or a browser integrity token), and a digital signature of at least a portion of the other data of the proof token 122.

[0056] The integrity token can be a device integrity token that enables an entity to determine whether the request 120 was sent by a trusted client device 110. For example, a device integrity token can be issued by a third-party device integrity system that evaluates fraud signals of the client device and assigns a credibility level to the client device based on that evaluation. The device integrity token of the client device 110 can include a judgment indicating the credibility (or integrity) level of the client device 110 at the time when the device integrity token was generated, a device integrity token creation time indicating the time when the device integrity token was generated, and a unique identifier of the client device 110 (e.g., the device public key 113B of the client device or a derivative thereof). The device integrity token can also include a digital signature of the data in the device integrity token using the private key of the device integrity system. For example, the device integrity system can sign the data using its private key, which the system maintains secretly. An entity receiving the proof token 122 can use the public key of the device integrity system to verify the signature of the device integrity token. Since the integrity of the client device 110 can change over time, each client device 110 can periodically request a new device integrity token. An entity receiving the proof token 122 can check the creation time of the device integrity token to identify an old device integrity token.

[0057] For a request sent on behalf of a web browser, the integrity token can be a browser integrity token that indicates the integrity of the web browser or the authenticity of the user's interaction with the website. Examples of non-authentic user interactions include interactions initiated by bots or the like rather than the user. The browser integrity token can be issued by a third-party browser integrity system based on fraud detection signals sent to the third browser integrity system. Fraud signals can include, for example, mouse movement speed, direction, intermittency, and other patterns, click patterns, and the like.

[0058] Similar to the device integrity token, the browser integrity token for a web browser can include a judgment indicating the level of trust (or integrity) of the web browser or the authenticity level of the user's interaction with the website at the time the browser integrity token was generated, a browser integrity token creation time indicating the time the browser integrity token was generated, and a unique identifier of the client device 110 (e.g., the public key of the client device or web browser). The browser integrity token can also include a digital signature of the data in the browser integrity token using the private key of the browser integrity system. For example, the browser integrity system can digitally sign the data using its private key, which the system secretly maintains. An entity receiving the proof token 122 can use the public key of the browser integrity system to verify the signature of the browser integrity token. The client device 110 can store the integrity token (e.g., the device integrity token and / or the browser integrity token) for inclusion in the proof token 122.

[0059] As described above, the client device 110 can request digital components from the digital component distribution system 150. Before an application (e.g., a web browser or a native application) presents a digital component, the application can ensure that the user has consented to the digital component being presented. The digital component can include data, such as metadata, that specifies the provider (e.g., the digital component distribution system 150, the digital component partner 157, and / or the digital component provider 160) and whether the digital component is a personalized digital component selected and / or customized based on user data (e.g., based on a user profile generated for the user).

[0060] Before rendering a digital component, an application (e.g., a web browser or a native application) can query the consent management module 114 to determine whether the provider has the appropriate user consent to show personalized content to the user. For example, the application can provide the consent management module 114 with the specified provider and previously extracted digital components or metadata indicating whether the digital component is personalized using the query. The consent management module 114 can determine whether the user has consented to the digital component being presented based on the current user consent settings and the received digital component or metadata. The consent management module 114 can then respond to the application with data specifying whether the digital component can be presented or not. The application can then render the digital component or block the digital component based on the response from the consent management module 114.

[0061] In some embodiments, the consent management module 114 can also enable the user to view which domains have the user's data and what data each domain has. The consent management module 114 can also enable the user to request that a domain delete the user's data, not transfer the user's data to another entity, correct the user's data, and / or export the user's data to, for example, the client device 110.

[0062] Figure 2 FIG. 7 is a flowchart illustrating an example process 200 for installing a consent management module selected by a user on a client device. The process 200 can be implemented, for example, by the client device 110. The operations of the process 200 can also be implemented as instructions stored on a non-transitory computer-readable medium, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operations of the process 200.

[0063] Receive a selection of a consent management platform (202). An application (e.g., a web browser or a native application) or the device platform of the client device can present a user interface to the user that enables the user to select from multiple consent management platforms. Each consent management platform can provide a way for the user to manage the user consent settings that control how the user's data is collected and used. For example, each consent management platform can provide a consent management module that enables the user to specify user consent settings at the client device and manage the collection and use of the user's data at the client device and at other locations (e.g., at a remote server or other entity).

[0064] A user interface can be presented in response to determining that an application is attempting to send user data from the client device to another entity and the consent management module is not currently installed or active on the client device. The user can select a consent management platform from the user interface or decline to select any consent management platform.

[0065] Obtain a consent management module (204) from a selected consent management platform, or obtain the consent management module from another location such as an app store where users can download apps and add-ons for apps. For example, the app store can ensure that the consent management module meets some minimum quality standards and complies with some policies. In response to the selection of the consent management platform, the client device can send a request to the consent management provider system of the selected consent management platform. In response, the system can send the consent management module (or an executable file for installing the consent management module) to the client device.

[0066] Install the consent management module on the client device (206). As described above, the consent management module can be implemented in the form of a plug-in for the operating system. In this example, the operating system installs the plug-in. The installation of the consent management module can also include configuring the app to interact with the consent management module when sending requests and presenting digital components.

[0067] Figure 3 FIG. is a flowchart illustrating an example process 300 for enabling a user to specify user consent settings and store the user consent settings. Process 300 can be implemented, for example, by the consent management module of the client device. The operations of process 300 can also be implemented as instructions stored on a non-transitory computer-readable medium, and the execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operations of process 300.

[0068] Present an interactive interface (302). The interactive interface can enable the user to specify user consent settings that define, for example, what user data can be collected, who can receive the data, the data retention policy (e.g., automatically delete after 30 days or another appropriate time period), and how each recipient can use the data. In some embodiments, the interactive interface can include a set of user consent settings, and for each user consent setting, include a user interface control that enables the user to consent or refuse consent. For example, the interactive interface can include a setting that globally controls whether any user data can be transferred from the user device to any domain. The interactive interface can also include a checkbox control (or other type of control) that enables the user to consent to transfer user data or refuse consent (which would prevent any user data from being transferred from the client device). The interactive interface can present similar user consent settings for other types of user consent, for each domain, and / or for each app installed on the client device. As described above, the interactive interface can also present recommended settings. The consent management module executing on the client device can generate the recommended settings and present the interactive interface.

[0069] Receive data (304) with the consent settings specified by the user. The user interface can pass the user consent settings specified by the user to the consent management module.

[0070] Store the user consent settings on the client device (306). The consent management module can store the user consent settings in a secure storage device, e.g., stored within the sandbox of the device platform of the client device, to prevent access from outside the sandbox. In some embodiments, with appropriate user consent, the consent management module can store the user consent settings in a secure storage device on the Internet managed by the consent management platform. If the user logs in from multiple devices, such Internet storage devices can be beneficial for backup / restore purposes and for a consistent user experience across multiple devices.

[0071] Figure 4 FIG. is a flowchart illustrating an example process 400 for transmitting a request according to user consent settings. Process 400 can be implemented, for example, by the consent management module of a client device. The operations of process 400 can also be implemented as instructions stored on a non-transitory computer-readable medium, and the execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operations of process 400.

[0072] Making a request will involve determining (402) whether it includes user data. For example, the device platform of the client device can transmit requests on behalf of applications such as web browsers and native apps. The application can provide the data for the request and data indicating whether the request includes user data. In another example, the device platform can evaluate the data received from the application and determine that the request will include user data. In another example, the browser or native app will query the user consent settings before generating and sending the request.

[0073] For example, when a browser sends a Hypertext Transfer Protocol (HTTP) request to a domain, if the domain has a cookie in the browser cookie jar and the cookie value has sufficient entropy to identify the user (e.g., beyond a simple boolean value), the browser will query the plugin to see if the domain has user consent to collect user data. The browser will insert the cookie into the HTTP header if and only if the answer is "yes".

[0074] In another example, if it is known that the domain to which the browser will send a request uses passive fingerprinting (i.e., depends on the IP address and browser user agent in the HTTP request and other signals) to track the user, the browser will route the HTTP request to the network and, if the plugin replies that the domain does not have user consent to collect user data, reject the browser user agent.

[0075] Make a request (404) for the current user's consent settings. The device platform can submit a query for the user's consent settings to the consent management module. The query can request (e.g., ask for) specific user consent settings, such as, for the domain to which the request will be sent, or all user consent settings.

[0076] Receive the current user's consent settings (406). The consent management module can provide the current user's consent settings in response to the query. These current user consent settings can include user consent settings specified by the user and / or standard / default user consent settings of the consent management module. For example, the standard / default user consent settings can be settings that block the transmission of that type of user data based on the user's current location indicating that the user is in a country with regulations that do not permit the collection of specific user data. If the query requests specific user consent settings, the consent management module can provide only those user consent settings.

[0077] Generate request data (408) based on the current user's consent settings. The device platform can use the user consent settings to identify the portions (if any) of the user data that can be included in the request and the portions (if any) of the user data that cannot be included in the request. For example, the device platform can evaluate the user consent settings to determine if there are settings for the recipient of the request. If so, the device platform can use those user consent settings to identify the portions of the user data that can be included in the request. If not, the consent management module can use the general user consent settings to identify the portions of the user data that can be included in the request.

[0078] In a specific example, the user can consent to send location data to a specific digital component distribution system but not consent to send web browsing history to the specific digital component distribution system. In this example, the device platform can determine if the request includes location data or web browsing history data. If the request includes web browsing history data, the device platform can remove the web browsing history data from the request. The device platform can include the user-consented location data in the request data to be transmitted from the client device.

[0079] The request data can also include the user consent settings. The request can include only the user consent settings that apply to the request, such as, the user consent settings for the recipient of the request and / or any global user consent settings that allow the user data to be included in the request. In another example, the request can include the user consent settings for the recipient and any user consent settings that apply to all recipients. As described above, a digital signature of at least the user consent settings can be generated and included in the request so that the user consent settings can be verified later, for example, in an audit.

[0080] Transmit request data (410). The device platform is capable of transmitting the request data to the request recipient, e.g., to a digital component distribution system. As described above, the request can include or be in the form of a proof token.

[0081] In addition to the above description, controls can be provided to the user that allow the user to make choices regarding whether and when the systems, programs, or features described herein can enable the collection of user information (e.g., information about the user's social network, social actions or activities, occupation, user preferences, or the user's current location) and whether personalized content or communications are sent from the server to the user. Additionally, specific data can be processed in one or more ways before it is stored or used so that personally identifiable information is removed. For example, the user's identity can be processed so that the user's personally identifiable information cannot be determined, or the geographical location of the user from whom location information is obtained can be generalized (such as to the city, zip code, or state level) so that the user's specific location cannot be determined. Thus, the user can control what information about the user is collected, how that information is used, the information retention policy, and what information is provided to the user.

[0082] Figure 5 is a block diagram of an example computer system 500 that can be used to perform the operations described above. System 500 includes a processor 510, a memory 520, a storage device 530, and an input / output device 540. Each of the components 510, 520, 530, and 540 can be interconnected, for example, using a system bus 550. The processor 510 is capable of processing instructions for execution within the system 500. In some embodiments, the processor 510 is a single-threaded processor. In another embodiment, the processor 510 is a multi-threaded processor. The processor 510 is capable of processing instructions stored in the memory 520 or on the storage device 530.

[0083] The memory 520 stores information within the system 500. In one embodiment, the memory 520 is a computer-readable medium. In some embodiments, the memory 520 is a volatile memory unit. In another embodiment, the memory 520 is a non-volatile memory unit.

[0084] The storage device 530 can provide mass storage for the system 500. In some embodiments, the storage device 530 is a computer-readable medium. In various different embodiments, the storage device 530 can include, for example, a hard disk device, an optical disk device, a storage device shared by multiple computing devices over a network (e.g., a cloud storage device), or some other mass storage device.

[0085] The input / output device 540 provides input / output operations for the system 500. In some embodiments, the input / output device 540 can include one or more of a network interface device (e.g., an Ethernet card), a serial communication device (e.g., an RS-232 port), and / or a wireless interface device (e.g., an 802.11 card). In another embodiment, the input / output device can include a driver device configured to receive input data and send output data to other input / output devices such as a keyboard, a printer, and the display device 560. However, other embodiments can also be used, such as mobile computing devices, mobile communication devices, set-top box TV client devices, etc.

[0086] Although example processing systems have been described in Figure 5 this specification, embodiments of the subject matter and functional operations described in this specification can be implemented in other types of digital electronic circuits, or in computer software, firmware, or hardware (including the structures disclosed in this specification and their structural equivalents), or in a combination of one or more of them.

[0087] Embodiments of the subject matter and operations described in this specification can be implemented in digital electronic circuits, or in computer software, firmware, or hardware (including the structures disclosed in this specification and their structural equivalents), or in a combination of one or more of them. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions, encoded on a computer storage medium (or media) for execution by, or to control the operation of, a data processing apparatus. Alternatively or additionally, the program instructions can be encoded on an artificially generated propagated signal (e.g., a machine-generated electrical, optical, or electromagnetic signal) that is generated to encode information for transmission to a suitable receiver apparatus for execution by the data processing apparatus. A computer storage medium can be a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination of one or more of them, or be included in a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination of one or more of them. Further, although a computer storage medium is not a propagated signal, a computer storage medium can be a source or destination of computer program instructions encoded in an artificially generated propagated signal. A computer storage medium can also be one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices) or be included in one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices).

[0088] The operations described in this specification can be implemented as operations performed by a data processing apparatus on data stored on one or more computer-readable storage devices or received from other sources.

[0089] The term “data processing apparatus” encompasses all kinds of apparatus, devices, and machines for processing data, including, for example, programmable processors, computers, system-on-chips, or multiple or combinations of the foregoing. The apparatus can include dedicated logic circuitry, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit). In addition to hardware, the apparatus can also include code that creates an execution environment for the computer program in question, for example, code that constitutes processor firmware, a protocol stack, a database management system, an operating system, a cross-platform runtime environment, a virtual machine, or a combination of one or more of them. The apparatus and the execution environment can implement various different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.

[0090] A computer program (also referred to as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may or may not correspond to a file in a file system. The program can be stored as part of a file that holds other programs or data (for example, one or more scripts stored in a markup language document), stored in a single file dedicated to the program in question, or stored in multiple cooperating files (for example, files that store one or more modules, subroutines, or portions of code). A computer program can be deployed to execute on one computer or on multiple computers located at one site or distributed across multiple sites and interconnected by a communication network.

[0091] The processes and logical flows described in this specification can be performed by one or more programmable processors executing one or more computer programs to perform actions by operating on input data and generating output. The processes and logical flows can also be performed by dedicated logic circuitry, and the apparatus can also be implemented as dedicated logic circuitry, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit).

[0092] Processors suitable for executing computer programs include, for example, both general and special purpose microprocessors. Generally, a processor will receive instructions and data from a read only memory or a random access memory or both. The basic elements of a computer are a processor for performing actions in accordance with instructions and one or more memory devices for storing the instructions and data. Generally, a computer will also include one or more mass storage devices for storing data, or be operatively coupled to receive data from or transfer data to one or more mass storage devices for storing data or both, the one or more mass storage devices such as magnetic disks, magneto-optical disks or optical disks. However, a computer need not have such devices. In addition, a computer can be embedded in another device (such as, for example, a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver or a portable storage device (such as, for example, a universal serial bus (USB) flash drive), to name just a few). Devices suitable for storing computer program instructions and data include all forms of non-volatile memory, media and memory devices, including, for example, semiconductor memory devices such as EPROM, EEPROM and flash memory devices; magnetic disks such as internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special purpose logic circuitry.

[0093] To provide for interaction with a user, embodiments of the subject matter described in this specification can be implemented on a computer having a display device (such as, for example, a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (such as, for example, a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback, such as visual feedback, auditory feedback or tactile feedback; and input from the user can be received in any form, including voice, speech or tactile input. Additionally, a computer can interact with the user by sending documents to and receiving documents from the device used by the user (such as, for example, by sending a web page to a web browser on a client device of the user in response to a request received from the web browser).

[0094] Embodiments of the subject matter described in this specification can be implemented in a computing system that includes a backend component (e.g., as a data server), or includes a middleware component (e.g., an application server), or includes a frontend component (e.g., a client computer having a graphical user interface or a web browser through which a user can interact with an implementation of the subject matter described in this specification), or any combination of one or more such backend, middleware, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include local area networks (“LANs”) and wide area networks (“WANs”), the Internet (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks).

[0095] The computing system can include clients and servers. The clients and servers are typically remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. In some embodiments, the server transmits data (e.g., an HTML page) to the client device (e.g., for purposes of displaying data to and receiving user input from a user interacting with the client device). Data generated at the client device (e.g., results of user interactions) can be received at the server from the client device.

[0096] Although this specification contains many specific implementation details, these should not be construed as limitations on the scope of any invention or of what can be claimed, but rather as descriptions of features specific to particular embodiments of particular inventions. Certain features that are described in this specification in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented separately or in any suitable sub-combination in multiple embodiments. Moreover, although the features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be deleted from the combination, and the claimed combination may refer to a sub-combination or variation of a sub-combination.

[0097] Similarly, although the operations are depicted in the drawings in a particular order, this should not be understood as requiring that the operations be performed in the particular order shown or in sequential order, or that all of the illustrated operations be performed, to achieve desirable results. In some cases, multitasking and parallel processing may be advantageous. Additionally, the separation of various system components in the above embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.

[0098] Accordingly, particular embodiments of the subject matter have been described. Other embodiments are within the scope of the following claims. In some cases, the acts recited in the claims can be performed in a different order and still achieve the desired result. In addition, the processes depicted in the figures do not necessarily require the particular order or sequence shown to achieve the desired result. In certain implementations, multitasking and parallel processing may be advantageous.

Claims

1. A computer-implemented method, comprising: Determining that a request for transmission by a client device to a recipient will include user data of a user of the client device; In response to determining that the request will include the user data: Requesting, from a consent management module of the client device, current user consent settings specified by the user, wherein the user consent settings define at least one of the following: (i) user data that can be transmitted from the client device, (ii) how the user data transmitted from the client device can be used, or (iii) which recipients can receive and retain user data from the client device; Receiving the current user consent settings from the consent management module; and Generating request data according to the current user consent settings, the generating including: Including, in the request data, one or more portions of the user data of the user that the user has consented to transmit to the recipient; and Including, in the request data, at least a portion of the user consent settings that specify consent given to the recipient for the one or more portions of the user data, wherein the consent restricts the recipient's use of the one or more portions of the user data; and Using a private key of a computing platform of the client device to generate a digital signature for the portion of the user consent settings that specify consent given to the recipient for using the one or more portions of the user data; and Generating a proof token and transmitting the proof token to the recipient, the proof token including at least the request data, user consent data, and the digital signature.

2. The method according to claim 1, further comprising: Providing a public key corresponding to the private key of the computing platform of the client device to a third party, wherein the public key enables the third party to verify the user consent data.

3. The method according to claim 1, further comprising: Receiving selection data specifying a selection of a given consent management platform from a plurality of consent management platforms; Obtaining the consent management module from the given consent management platform or an app store; And Installing the consent management module on the client device on the client device.

4. The method according to claim 1, further comprising: Presenting an interactive interface that enables the user to specify the user consent settings and review current user consent settings; Receiving data specifying the user consent settings; And Storing the user consent settings at the client device.

5. The method according to claim 4, further comprising: Presenting one or more recommended user consent settings in the interactive interface.

6. The method according to claim 5, further comprising: Selecting the one or more recommended user consent settings based at least on a current location of the client device or user activity on the client device.

7. The method according to claim 1, wherein The consent management module includes a user consent plugin of the computing platform of the client device.

8. The method according to claim 1, wherein The consent management module includes a user consent plugin of an operating system of the client device.

9. The method according to claim 1, wherein The consent management module includes a user consent plugin of a web browser of the client device.

10. The method according to claim 1, further comprising: Receive digital components for presentation at the client device; Determine that the digital components are personalized digital components selected based on one or more portions of the user's user data; In response to determining that the digital components are personalized digital components selected based on one or more portions of the user's user data: Determine whether the current user consent setting allows the presentation of personalized digital components provided by a digital component distribution system that provides the personalized digital components; And In response to determining that the current user consent setting does not allow the presentation of personalized digital components provided by a digital component distribution system, prevent the client device from presenting the personalized digital components.

11. One or more non-transitory computer-readable media comprising instructions that, when executed by one or more processors, cause the one or more processors to perform the method according to any one of claims 1 to 10.

12. A system for providing a user consent framework, comprising: One or more processors; And One or more storage media comprising instructions that, when executed by the one or more processors, cause the processors to perform the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Techniques for a messaging agent platform

    CN109219793A

  • System and Method for Multi-Tiered, Rule-Based Data Sharing and Ontology Mapping

    US20160070758A1

  • Method and system for protecting internet users' privacy by evaluating web site platform for privacy preferences policy

    US6959420B1