Privacy-protected virtual email system
By generating virtual email addresses and using tokenization technology to protect data transmission, the problem of user email address privacy leakage is solved, achieving efficient data security and privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GOOGLE LLC
- Filing Date
- 2021-12-02
- Publication Date
- 2026-05-26
AI Technical Summary
In existing technologies, the widespread use of user email addresses leads to the leakage of privacy information and data abuse, and traditional cookies are not secure enough to effectively protect user privacy.
By generating virtual email addresses, the identity server detects and triggers events to automatically or manually create new virtual email addresses, and uses tokenization technology to protect data transmission, thereby achieving authentication and authorization and avoiding the direct exposure of user information.
It improves data security, reduces latency and computing resource consumption, provides users with control over data usage and privacy protection, and enables a seamless personalized experience.
Smart Images

Figure CN114945918B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims priority to U.S. Application No. 63 / 121,087, filed December 3, 2020, entitled PRIVACY-PRESERVING VIRTUAL EMAILSYSTEM, the disclosure of which is incorporated herein by reference. Technical Field
[0003] This specification relates to data processing and email addresses that are linked to user information and can be used as identifiers for authentication and / or authorization purposes. Background Technology
[0004] An email address provides a user with a means of communication over the internet. Typically, a user has one or more email addresses for various purposes. For example, a user might have a work email address for communicating with colleagues, and a personal email address for communicating with friends outside of work. Summary of the Invention
[0005] Typically, an innovative aspect of the subject matter described in this specification can be embodied in a method comprising receiving, from a user device and at an identity server, a login credential of a first email address mapped to a first set of user information values; the identity server detecting a triggering event; in response to detecting the triggering event, the identity server creating a new virtual email address separate from the first email address and mapped to a second set of user information values different from the first set of user information values; the identity server detecting a request for credentials from a requesting entity; and in response to detecting the request, the identity server transmitting the new virtual email address as a new login credential to the requesting entity.
[0006] Each of these and other implementations may optionally include one or more of the following features. In some implementations, the triggering event is one of user input and a predetermined condition defined by the identity server.
[0007] In some implementations, login credentials are provided in the form of text input, audio input, or visual input.
[0008] In some implementations, transmitting a new virtual email address as a login credential to the requesting entity includes transmitting data representing the new virtual email address via a tokenized API, wherein the data representing the new virtual email address is a token that cannot be traced back to the first email address.
[0009] In some implementations, the method includes updating a database by an identity server and based on the new virtual email address by creating database entries that map the new virtual email address to user information values. In some implementations, the method further includes receiving input from a user device indicating a change to the new virtual email address, and updating the database entries by the identity server and based on the input indicating the change to the new virtual email address.
[0010] In some implementations, the request for credentials includes data indicating that the user device has accessed a webpage with one or more text fields for entering credentials.
[0011] Other embodiments of this aspect include actions configured to perform methods, corresponding systems, apparatuses, and computer programs encoded on computer storage devices.
[0012] Users typically have a primary email address, which they use for a variety of purposes, including receiving emails and as an identifier to create third-party accounts, among others. The use of email addresses as identifiers is gaining popularity due to their convenience for users. By allowing the use of email addresses as identifiers for authentication and / or authorization purposes, users can simply enter their email address to grant applications, content providers, or other entities permission to access any requested user information.
[0013] However, because users typically use a single primary email address over many years, this primary email address may be associated with a large amount of user-specific information that accumulates throughout the time the user has had that email address. Users may not want to grant requesting entities access to the entire set of information associated with their primary email address. Requesting entities can include, for example, content providers or government organizations. Furthermore, users may want to create a temporary identity when asked and may not want their activities stored and accessed. For example, someone using a shared computer to plan a surprise trip, during which they plan to propose to their partner, might not want their partner to have access to their recent travel plans. In this case, using an email address as a temporary identifier instead of other types of identifiers (e.g., third-party cookies) can help prevent data or other information from being leaked to unintended parties.
[0014] The following description discusses various technologies and systems for protecting users' privacy while they browse the Internet or use native applications on their devices, while still enabling a personalized experience. These systems are more efficient by reducing the number of network requests that users must make to reach the online information they are looking for (reducing the required computing resources, server access, data transfer, and battery consumption of user devices).
[0015] A virtual email system allows users to create and manage virtual email addresses as identifiers in place of cookies. Virtual email addresses can be used as a convenient way for users to maintain their identity and provide them with a degree of control over what data is being collected, how it is being collected, and how it is being used. By using virtual email address identifiers separated from the user's primary identity by a protective layer, and by allowing users to control the information associated with a specific virtual email identifier, the described system provides users with a convenient solution that preserves or even improves the privacy available to them and allows requesting entities to access user information that the user has granted access to. Users can create new virtual email addresses and adjust privacy settings at any time. The described system allows users to control the data collected and the length of time that data can be maintained on a granular basis. For example, the described system allows users to create virtual email addresses with various security, privacy, and protection levels, thereby improving data security.
[0016] The described system is able to automatically detect situations where a new virtual email address should be generated, providing users with a seamless experience that gives them control over how and when they can use their data, without requiring users to manually implement measures every time they might want a new virtual email address.
[0017] The virtual email address can then be provided to a secure API, which performs actions such as tokenization of the virtual email address identifier to provide a layer of protection between the virtual email address and the requesting entity. This token can then be used for identification, authorization, and / or authentication purposes.
[0018] Specific embodiments of the subject matter described in this specification can be implemented to achieve one or more of the following advantages. For example, tokenization technology is used to protect user data from disclosure of user information available to entities participating in the process to other entities. Additionally, by implementing other layers of protection (including encryption), the architecture of a virtual email management system prevents entities from accessing any information beyond what is necessary for authentication or authorization. For example, a virtual email system can maintain the separation between virtual email addresses, ensuring that the primary email address cannot be accessed by an entity that has been granted access to a virtual email address mapped to the primary email address. The technologies discussed throughout this document also enable personalized content selection, internet browsing and application use, and other activities to be performed while preventing any system involving content delivery or requesting entities from tracking individual users across different websites, data integration platforms, time periods, etc.
[0019] The techniques discussed in this paper involve using coded data or tokens instead of actual data to transmit data for authentication and / or authorization purposes. This allows the computing systems involved in the processes discussed in this paper to perform procedural operations without access to the underlying data, but still using this code. Even if the data is compromised, for example, stolen or leaked to another entity, using code instead of actual data protects the data, thereby improving data security.
[0020] The system also automatically generates virtual email addresses for users based on trigger events, reducing the amount of input required and latency in content presentation. By automatically generating virtual email addresses, the system reduces the necessary central processing unit (CPU) cycles required to execute the process. For example, by eliminating the need to encrypt and decrypt large amounts of input from users, latency is reduced, which is crucial for implementations that use this process to select content for presentation on user devices and makes the entire process more efficient. Furthermore, data can be locally cached on a specific computing system, reducing latency for future requests for any cached data. Reduced latency also reduces the number of errors that occur on user devices while waiting for such content to arrive. Since content often needs to be delivered in milliseconds and to mobile devices connected via wireless networks, reducing latency in content selection and delivery based on user information is critical for preventing errors and minimizing user frustration. By automatically generating virtual email addresses and then using them for authentication and / or authorization, the system provides a seamless experience for users.
[0021] The described technology also provides a simplified process for maintaining a high level of privacy. By implementing a unified management system for various user identifiers mapped to a single master email address, the system provides a high standard of user privacy without requiring significant changes to the authentication and / or authorization processes for the input or requesting entities required by the user.
[0022] Details of one or more embodiments of the subject matter described in this specification are set forth in the accompanying drawings and the following description. Other features, aspects, and advantages of the subject matter will become apparent from the description, drawings, and claims. Attached Figure Description
[0023] Figure 1 This is a block diagram of a sample environment for a virtual email address system used for privacy protection.
[0024] Figure 2 The data flow used to generate virtual email addresses is described.
[0025] Figure 3 The tree structure of email addresses generated and managed by the virtual email address system is depicted.
[0026] Figure 4 This is a flowchart of an example process for generating a virtual email address.
[0027] Figure 5 This is a block diagram of an example computer system.
[0028] The same reference numerals and names in different figures represent the same elements. Detailed Implementation
[0029] The following description relates to providing users with control over the generation and management of their email address identifiers. Because users typically retain the same primary email address for extended periods and generally do not delete it, it is often linked to a large amount of user information collected during that time. Furthermore, the primary email address can be used as credentials for logging into applications or websites, and users can use it as credentials to log into many of their accounts or access other data.
[0030] Users may not want to provide every requesting entity, such as a website, vendor, or content provider, with all data linked to their primary email address, or to allow such entities to collect user data based on their primary email address over time. However, creating new email addresses to use as credentials for each new requesting entity and managing that information can be tedious, time-consuming, and consumes more computing resources than automated technologies used to generate and use multiple email addresses.
[0031] To address this issue, the described system generates virtual email addresses that will be used as identifiers, for example, in situations where a user may wish to limit the amount or type of information provided to a requester and / or the amount of time a requester has access to that information. The system is capable of automatically detecting events or conditions that trigger the creation of a virtual email address for a user, and also allows the user to manually initiate the creation of a new virtual email address. Users are also able to access the system through their user devices, communicate with different applications and websites, and request entities via application programming interfaces (APIs).
[0032] A virtual email address is provided to a database that stores user profile information. This profile information is organized in the database by email address. For example, the profile information can be indexed by email address. Once the virtual email address is linked to the profile information in the database, the virtual email address can be used as an identifier or other credential for authentication and / or authorization purposes. As described further in detail below, users can manage the setting or deletion of their email address at any time.
[0033] Figure 1 This is a block diagram of an example environment 100 for a privacy-preserving virtual email address system 125. Example environment 100 includes a network 102, such as a local area network (LAN), a wide area network (WAN), the Internet, or a combination thereof. Network 102 connects to an electronic document server 104 (“Electronic Doc Servers”), user devices 106, a secure API 120, the virtual email address system 125 (which includes a privacy identity server 130 and an identity database 140), and a data integrator 150. Example environment 100 may include many different electronic document servers 104, user devices 106, and data integrators 150.
[0034] User equipment 106 is an electronic device capable of requesting and receiving resources (e.g., electronic documents) via network 102. Example user equipment 106 includes personal computers, wearable devices, smart speakers, tablet devices, mobile communication devices (e.g., smartphones), smart appliances, gaming systems, and other devices capable of sending and receiving data via network 102. In some embodiments, the user equipment may include a speaker that outputs audible information to a user and a microphone that receives audible input (e.g., spoken input) from the user. The user equipment may also include a digital assistant that provides an interactive voice interface for submitting input and / or receiving output in response to input. The user equipment may also include a display for presenting visual information (e.g., text, images, and / or video). User equipment 106 typically includes user applications, such as web browsers, to facilitate sending and receiving data via network 102, but native applications executed by user equipment 106 may also facilitate sending and receiving data via network 102.
[0035] User device 106 includes software such as a browser or operating system. In some embodiments, the software allows users to access information via a network such as network 102, retrieve information from a server, and display that information on a display of user device 106. In some embodiments, the software manages the hardware and software resources of user device 106 and provides public services to other programs on user device 106. The software can act as an intermediary between programs and the hardware of the user device. In this particular example, application 112 running on user device 106 is software that allows users to access information via network 102.
[0036] An electronic document is data that presents a collection of content at user device 106. Examples of electronic documents include web pages, word processing documents, portable document format (PDF) documents, images, videos, audio, search results pages, streaming video game content, and feed sources. Native applications (e.g., “apps”), such as those installed on mobile computing devices, tablet computing devices, or desktop computing devices, are also examples of electronic documents. Electronic document 105 (“Electronic Docs”) can be provided to user device 106 by electronic document server 104. For example, electronic document server 104 can include a server hosting a publisher’s website. In this example, user device 106 can initiate a request for a given publisher’s web page, and electronic document server 104 hosting the given publisher’s web page can respond to the request by sending machine hypertext markup language (HTML) code that initiates the rendering of the given web page at user device 106.
[0037] Electronic documents can include various types of content. For example, electronic document 105 can include static content (e.g., text or other specified content) that does not change over time and is inherent to the electronic document itself. Electronic documents can also include dynamic content that can change over time or based on each request. For example, the publisher of a given electronic document can maintain a data source used to populate portions of the electronic document. In this example, a given electronic document can include a tag or script that, when the given electronic document is processed (e.g., rendered or executed) by user device 106, causes user device 106 to request content from the data source. User device 106 integrates the content obtained from the data source into the presentation of the given electronic document to create a composite electronic document that includes content obtained from the data source. Media content referred to herein is digital content.
[0038] For each user, applications and content providers can maintain identification, authentication, and / or authorization information for each user accessing their data. Typically, this information is stored and categorized using a small piece of data called a cookie, which is stored on the user's device. However, cookies are usually created and stored by each application creator or content provider and can be used to compile a record of an individual's historical activity without input from the user regarding the type or amount of information that can be collected, the amount of time that information can be retained, or with whom that information can be shared. Furthermore, the security of cookies often depends on the security of the publishing website, which can vary. These attributes of cookies can introduce privacy and security risks to users.
[0039] Secure API 120 facilitates the transfer of sensitive data to third parties by replacing received data with non-sensitive placeholders. For example, Secure API 120 can perform tokenization to replace received data with a token. Secure API 120 can be used to protect and desensitize data by replacing received data with irrelevant values. For example, irrelevant values can have the same size and format. The token retains elements of the original data and is then provided for authentication or authorization processes, while the original data is stored in a secure token store. Tokenized data offers advantages over other forms of protection because it is unbreakable and irreversible. Since there is no mathematical relationship between the token and the original received data, the token cannot be reverted to its original form.
[0040] Identity server 130 is a server that allows the creation and management of email addresses. In some implementations, identity server 130 can be used to create and manage both virtual and physical email addresses. Identity server 130 includes an email management module 132 and a user interface 134. Identity server 130 can be implemented as one or more processors. In some implementations, identity server 130 can be a single server. Identity server 130 can also be implemented as a distributed system, with its components residing on different networked computers.
[0041] Email management module 132 implements an email management module that, for example, generates a virtual email address at a specific time. For example, email management module 132 can detect events that trigger the generation of a virtual email. These events, also called triggering events, can be specified by the user, identity server 130, and / or the requesting entity, as well as other entities. For example, email management module 132 can detect that the current user has navigated to a website they have never visited before, and that the website is requesting credentials. Email management module 132 can then determine that the website visit has not been previously accessed by the user, and that the credential request is a triggering event specified by identity server 130, and generate a new virtual email address linked to the user's main email address. This new virtual email address can be provided to a new website, for example, instead of the user's existing email address.
[0042] The email management module 132 can generate or modify virtual email addresses with specific parameters. For example, the email management module 132 can generate virtual email addresses with a specific privacy protection level, a specific set of user information, and linked to the user's primary email address. In some implementations, multiple layers of email addresses can exist between the specific virtual email address and the user's primary email address. The structure in which the email addresses linked to the user's primary email address are stored can be, for example, a tree structure. The following is about... Figure 3 Describe the tree structure and the connections between each email address in detail.
[0043] The user interface 134 of the identity server 130 allows users to provide input to the email management module 132. For example, the user interface 134 allows users to perform operations such as initiating the generation of a new virtual email address, initiating input creation parameters for a new virtual email address, changing parameters of an existing email address, and deleting an existing email address, among other operations. The identity server 130 is capable of providing the user interface 134 to the client device 106 and / or updating the user interface 134 at the user device 106. For example, the identity server 130 is capable of enabling the user device 106 to generate a user interface and display data to the user on the user device 106.
[0044] Identity database 140 uses users' personal identifiers to store user information. For example, identity database 140 could be an email-based information storage system where the information is user information linked to a specific email address. In this example, the personal identifier is the specific email address. This information could include metrics determined based on the user's authorized data provided to the requesting entity based on that specific email address. For example, this information could include the user's location information and the average amount of time the user spent visiting a particular coffee shop last month.
[0045] Data integrator 150 combines data from different sources and provides users with a unified view of the data that is more informative or useful than the original presentation of the data. Data integrator 150 merges different types of data and allows users to perform actions such as querying or analyzing the data. Within system 100, data integrator 150 receives and processes data for use by another user, such as requesting entities.
[0046] Figure 2 Describing the use of in Figure 1 The example environment provides a data flow 200 for the process of generating a virtual email address. The operation of data flow 200 is performed by various components of system 100. For example, the operation of data flow 200 can be performed by user device 106 communicating with identity server 130 via secure API 120.
[0047] The process begins in step A, where the user logs in to their primary email address. For example, a user can log in to their primary email address ExampleEmailAddress@exampledomain.com. The user can log in to their email address via user device 106. For example, the user can log in to their email address using an email client on user device 106. In some implementations, the user can log in to their email address via application 112. Application 112 can be an internet browser integrated with an email client, and application 112 can be, for example, a web browser through which the user can access a web-based email client.
[0048] The process continues to step B, where the user can log in to applications that facilitate internet browsing via an authorization standard. For example, the user can log in to application 112 using an authorization standard such as OAuth or the Open Authorization Standard. This standard allows users to log in to third-party applications, websites, or other destinations using their email address. For example, a user can log in to application 112, a web browser, using their primary email address, ExampleEmailAddress@exampledomain.com. The authorization standard can use, for example, Secure API 120, to perform token exchanges.
[0049] The process continues to step C, where users are able to use applications that facilitate internet browsing to visit websites and other destinations, and identify themselves to their browsing destinations using their primary email address. For example, a user can use application 112 to browse the internet and identify themselves to the Cute Bird News Example Website they are currently visiting using their primary email address, ExampleEmailAddress@exampledomain.com.
[0050] The process continues to step D, where a new virtual email address is generated for the user. Virtual email addresses can be created either as described with respect to step D-1, where the user manually initiates the generation of the new virtual email address, or as described with respect to step D-2, where the identity server 130 automatically initiates the generation of the new virtual address.
[0051] In step D-1, the user can initiate the generation of a unique email address and specify the parameters of the email address. For example, the user can click a button, icon, or other control within the user interface 134 and enter "NewsWebsitesEmailAddress" as a new local part into a text field, enter "News Websites" as its purpose into another text field, and select their name and location from a list of selectable items as information accessible to the requesting entity that the virtual email address is used as an identifier. In this way, the user can control which virtual email address is used for various different purposes. The user interface 134 provides an email generation and management UI that allows users to edit their information and indicate what data they wish to share with the requesting entity. Users can remove or change their email address and attributes at any time through the user interface 134.
[0052] For example, user interface 134 allows users to create, edit, and delete email addresses. User interface 134 is capable of providing users with an organized view of their email addresses, for example, categorized according to specific attributes of the email addresses. User interface 134 provides filtering and categorization options that allow users to view a subset of their email addresses. In some implementations, user interface 134 is capable of presenting users with a tree view of their email addresses. This structure will be referenced below. Figure 3 Detailed description.
[0053] In some implementations, a random local portion of a new virtual email address can be selected for the user and presented for approval. In some implementations, the user can create their own local portion, different from the local portion of their primary email address. The new virtual email address can be hosted by the same domain as the primary email address. In some implementations, the new virtual email address is hosted by a different domain than the domain hosting the primary email address.
[0054] User interface 134 allows users to select the view they want to use to display their email address management interface. For example, user interface 134 can provide users with options on how it presents the email address management interface elements. Users can switch between various email addresses and specify email address preferences and parameters through user interface 134. User interface 134 allows users to edit one or more email addresses simultaneously.
[0055] Users can manually access the user interface 134 by selecting a shortcut or activating the identity server 130. For example, a user can select the user interface 134 from their desktop on the user device 106. Users can access the user interface 134 through various other methods to launch or access applications, including via audio input, gestures, touch input, etc. For example, a user can speak a trigger word to a personal assistant device to launch the user interface 134.
[0056] In some implementations, the user interface 134 can be triggered for display to a user. The user interface 134 can be triggered for display based on a specific triggering event specified by the user, identity server 130, and / or data integrator 150, etc. For example, the user interface 134 can be triggered for display to the user when the user visits a shopping website from which credentials are requested. The user can access any creation and management functions provided by identity server 130 through the user interface 134 whenever it is presented. In some implementations, a specific view of the user interface 134 is presented in response to a specific triggering event. For example, when a user visits a website on a website blacklist maintained by identity server 130, the user can be provided with a specific, brief list of actions, including navigation to leave and locking all email addresses and user information to prevent access. In another example, when a user visits a non-blacklisted website, a list of virtual email addresses that can be used for the website can be presented. In this way, the user can select one email address to provide to the website in a simple and efficient manner.
[0057] In some implementations, the user interface 134 can display stored user information linked to a specific email address. The user interface 134 can also display a history of using a specific email address as an identifier. For example, the user interface 134 can display websites, destinations, and other requesting entities with access rights to a specific email address as a user.
[0058] In step D-2, the email management module, such as email management module 132, can automatically create new virtual email addresses with specific attributes for users. Email management module 132 can implement various default trigger events or conditions for creating new virtual email addresses. For example, email management module 132 can create default trigger conditions to create new virtual email addresses for one-time use, website use, data integrator use, etc. Email management module 132 can also specify when virtual email addresses containing any associated user data should be deleted. For example, if an email address is created for one-time use, email management module 132 can specify that the email address should be deleted immediately after use. Email management module 132 can specify the trigger event, time, conditions, etc., for initiating the deletion of email addresses. Email management module 132 can also edit the settings and attributes of email addresses. For example, email management module 132 can update email addresses to reduce access to user information or remove user information.
[0059] In some implementations, the email management module can use temporary email addresses that never collect, store, or provide user data. This type of temporary email address can be used in situations where it is insecure or where information is not intended to be collected or exchanged. In this example, it is impossible for any user information to be associated with this temporary email address.
[0060] The email management module improves the user experience by automatically detecting opportunities and circumstances under which new virtual email addresses can or should be used as user identifiers. In addition to providing a seamless and simple user experience, the identity server 130 and user interface 134 allow users to exercise control over automatically created email addresses by offering them the option to continue using the newly created email addresses, and to edit the attributes of one or more email addresses, etc.
[0061] The email management module uses signals about users, their activities, and destinations to determine triggering events. These triggering events can be predetermined or detected as they occur. For example, the module could determine that a new virtual email address should be created each time a user enters a combination of search terms like "best," "surprise," "holiday," or "location," and should be deleted after the session ends, based on the user's history. In another example, the module could determine based on user activity, such as visiting various jewelry store websites and clicking on different types of engagement rings. Email creation could then create a new virtual email address to be used whenever a user is detected visiting a jewelry store website, ensuring that this type of activity is only linked to the virtual email address created specifically for this purpose.
[0062] The email management module can trigger the display of user interface 134 to the user when a new virtual email address and its parameters are created, for approval or for the user's information. For example, when identity server 130 detects that the user has entered search terms such as "best," "surprise," "vacation," and "location" through application 112, a web browser, and the triggered display of user interface 134 including the newly created email address and its parameters, the email management module can create a new virtual email address. The user can then approve the creation and continue using the newly created virtual email address, dismiss user interface 134 to continue using the existing default email address for the triggering situation, select a different email address to use, exit the search navigation, etc.
[0063] Trigger events can be time-based. For example, the email management module can specify a trigger event to delete email addresses with a specific set of attributes weekly. Trigger conditions can be access to a specific website or destination. For example, the email management module can specify a trigger event to create a new virtual email address when visiting the Shopping For Cute Bird Stuff website, if the user is not already mapped to that website. Trigger events can be the closing of a browsing session. For example, the email management module can specify a trigger event to create a new virtual email address when opening a new browsing session and delete the current email address when closing the browsing session. Trigger events can be launching a specific application. For example, when launching a web browsing application 112 that the user logged into with their primary email address in step 1, the email management module can specify a trigger event to create a new virtual email address. Trigger conditions can be based on the characteristics of the user device 106. For example, when the user has logged in using a user device 106 that they do not normally use or have never used, the email management module can specify a trigger event to create a new virtual email address.
[0064] Time-based triggering events can be used to reclaim and / or update email addresses at a specified frequency. That is, it's possible to remove an email address from use and return it to the service at a specified frequency. This limits the possibility of an entity using a combination of email address attributes and other user-identifying information, such as cookies associated with the user or user group identifiers that include the user's interest groups as a member.
[0065] In some implementations, the frequency with which email addresses are reclaimed can be determined and / or adjusted based on user-related information. For example, frequency can be based on metrics of a user's online activity (e.g., how often or how much time a user spends online), the amount of third-party content provided to the user, the size of databases containing information about the user, and so on. For instance, the email addresses of more active users may be reclaimed more frequently than those of less active users because a larger number of entities are more likely to have access to email addresses and other information related to more active users compared to less active users. Therefore, without more frequent reclamation, entities would have a better chance of identifying more active users than less active users.
[0066] Email addresses can also be updated after they have been used by a user. For example, a user can choose to use a specific email address when visiting a particular website. In response, the email management module can prevent the use of the email address for a specified period and then update the email address for further use by the user after the period expires. The email management module can integrate with the database of request entities to detect when an email address is used and record it. Alternatively, the user can provide the email management module with data indicating that a specific email address is being used, for example, using user interface 134. In another example, user interface 134 can report to the email management module when a user selects a specific email address for a request entity.
[0067] In some implementations, multiple users can share an email address. Each user can have sub-accounts within that email address. This protects individual user privacy by preventing the email address from being linked to a specific user who accessed the website using the shared email address.
[0068] Multiple users can be grouped, for example, assigned to an email address based on their email address's interest categories and user information indicating their interest in those categories. For instance, a user's online activity can be analyzed, such as using privacy and security technologies on the user's device, to determine one or more categories the user is interested in. The email management module can receive one or more interest categories from the user's device and compare these categories with the interest categories of various email addresses. If a match is found, the email management module can assign an email address to the user and include that email address in the list of email addresses the user can use when visiting the website.
[0069] For example, each user identified as interested in puppies could be assigned the email address "puppies@example.com". Each of these users could then use that email address to access the website and / or other electronic resources. In this way, the website would not be able to identify individual users, but would be able to customize content for them, for example, by providing puppies-related content or other content that users interested in puppies would also find interesting.
[0070] In some implementations, the email management module can maintain a list of websites for which trigger events are defined. For example, the email management module can maintain a blacklist of websites for which creating new, virtual email addresses with no user-accessible information is recommended. In some implementations, the email management module can generate a score for each website based on attributes such as the category of content provided, a third-party generated trust score, the number of visitors over a period of time, and the credibility of the visitors. For example, the email management module can implement a rating mechanism ranging from 0 to 100, where 100 is the most trustworthy. In this example, the email management module can assign 10 points to a website where users frequently order goods but have posted complaints that they have not received the goods and where they have started receiving spam at the email address they use as credentials for the website. User visits to websites with scores that meet a threshold, for example, by being less than or equal to a threshold, can be trigger events.
[0071] In some implementations, the email management module can be triggered by other inputs or events, such as user-defined audio input. For example, if a user claps their hands to switch to a different email address identity or creates a new virtual email address. Triggering events can include visual input from the user, when the user has granted access to their device's camera and / or defined a gesture as a triggering event. For example, if a user blinks twice rapidly or performs a specific gesture such as waving their hand in a particular manner, the email management module can detect these gestures and trigger the generation of a new virtual email address.
[0072] In some implementations, the email management module for gamer users can create new virtual email addresses for each game to maintain anonymity in online settings. For example, users can use their email address as an identifier to log in to a streaming game platform. The email management module can create different virtual email addresses for each type of game the user is playing (e.g., role-playing games (RPGs), puzzle games, strategy games, etc.).
[0073] Because the user's primary email address and all linked virtual email addresses are masked from third-party request entities but visible to identity server 130, identity server 130 is able to use the stored structure, such as regarding Figure 3 The description details how to defend against malicious or fraudulent activities carried out by users disguised under a surface-anonymous email address, which is a virtual email address created by the system.
[0074] In addition, the system provides users with flexibility, allowing them to access resources anonymously. For example, users can create separate email accounts to send emails. A user can have one email account for sending personal emails and another for sending emails to work colleagues and for applying for jobs. Because some email accounts can have different settings and restrictions, such as limits on the number of emails that can be sent per day, users have more flexibility by having different email accounts, since the number of personal emails sent does not affect the number of work emails a user can send.
[0075] In some implementations, the email management module 132 uses machine learning to analyze the aggregated behavior of users of the identity server 130. For example, the email management module 132 can determine that users of the identity server 130 typically create new virtual email addresses upon their first visit to certain types of websites, such as blogs, and reuse the same virtual email addresses for subsequent visits and similar websites. In another example, the email management module 132 can determine that regular users delete all virtual email addresses monthly while retaining their primary email address. The email management module 132 uses these learned behaviors to specify triggering events and conditions.
[0076] The email management module can detect and analyze email address-specific activity, parsing and categorizing interactions and actions performed using a specific email address as an identifier. For example, when a user logs in to their primary email address and visits a travel website suggesting popular nearby activities, the email management module can initiate an update to the user's information to update their location.
[0077] In some implementations, the user can specify a set of automated actions that the identity server 130 should perform upon detecting a triggering event via user interface 134. For example, the user can provide input via user interface 134 instructing that a new virtual email address should be created daily and automatically used for identification, authentication, and / or authorization purposes during the day on which the requesting entity requests credentials or information from the user. The user can also specify that the new virtual email address should be deleted at the end of that day.
[0078] The process continues to step E, where identity server 130 provides a new email address identity to identity database 140. For example, identity server 130 can use the user's new virtual email address identity to transmit specified information or information types that are made available to the requesting entity to identity database 140.
[0079] Identity database 140 stores the user information in user profiles organized by email addresses. The user of user device 106 can access, edit, and / or delete information within identity database 140 via user interface 134. In some embodiments, the user can directly access the data stored in identity database 140 via user interface 134. In other embodiments, the user can perform operations via user interface 134 that cause identity server 130 to access, edit, and / or delete information within identity database 140.
[0080] The process continues to step F, where identity server 130 passes the user-selected email address identity and associated user information to the requesting entity. The email address identity can be passed to the requesting entity, such as a content provider as described in step F-1 or a data integrator as described in step F-2. The email address identity can be a new virtual email address identity created in step D or a different email address identity specified by the user.
[0081] In step F-1, identity server 130 transmits the user-selected email address identity to the requesting entity via secure API 120. In this particular example, the requesting entity is, for example, an electronic document server 104 that is a content provider or publisher. For instance, the requesting entity could be an online store that maintains a website through which users can create accounts and purchase goods.
[0082] In step F-2, identity server 130 transmits the user-selected email address identity to the requesting entity via secure API 120. In this particular example, the requesting entity is a data integrator 150 capable of integrating and compiling data and performing data analysis on the data.
[0083] By transmitting the user-selected email address identity to the requesting entity, the identity server 130 is able to perform authentication and / or authorization processes to provide the requesting entity with user information and / or credentials.
[0084] For example, identity server 130 can transmit specified information or information types that are available to the requesting entity via a user's email address. Communication can be performed using the entity, regardless of the platform and / or format used by the requesting entity through a security system such as security API 120. Communication can also be performed using the entity, regardless of the platform and / or format used by the requesting entity through security API 120, which is capable of performing security token exchange.
[0085] Figure 3 It describes a virtual email address system, for example, Figure 1A virtual email address system 125, and a tree structure 300 for generating and managing email addresses. For example... Figure 1 and Figure 2 The description states that the email addresses within the tree structure 300 are the email addresses of users belonging to the user device 106 of the system. The tree structure 300 can be stored, for example, in an identity database 140.
[0086] Tree structure 300 is a structure that depicts the links and relationships between the user's primary email address and the virtual email addresses associated with the user's primary email address.
[0087] Email address 302 is the user's primary email address, ExampleEmailAddress@exampledomain.com. Email address 302 is the user's oldest email address and is the top-level email address. The virtual email address is generated from this top-level email address and is linked to it.
[0088] Email address 310 is a virtual email address created for the news website NewsWebsites.ExampleEmailAddress@exampledomain.com. Email address 320 is a virtual email address for the month, MMYYYYEmail.ExampleEmailAddress@exampledomain.com. For example, email address 320 can be created and used for a specific month of a specific year. Email addresses 310 and 320 are second-level email addresses directly linked to the main email address 302, and are at a lower level than the top-level email address 302.
[0089] Email addresses 312 and 314 are dummy email addresses used for specific news websites: Site1.NewsWebsites.ExampleEmailAddress@exampledomain.com and Site2.NewsWebsites.ExampleEmailAddress@exampledomain.com. Email addresses 322 and 324 are dummy email addresses used for specific dates.
[0090] D1.MMYYYY.ExampleEmailAddress@exampledomain.com and D2.MMYYYY.ExampleEmailAddress@exampledomain.com. Email addresses 312, 314, 322, and 324 are third-level email addresses linked to the main email address 302 through second-level email addresses 310 and 320, and are at a lower level than second-level email addresses 310 and 320.
[0091] Email address 326 is a one-time virtual email address for a specific date: ontime.D2.MMYYYY.ExampleEmailAddress@exampledomain.com. Email address 326 is a fourth-level email address linked to the main email address 302 via third-level email address 324 and second-level email address 320. In this particular example, email address 326 is a low-level email address and is at a lower level than third-level email addresses 312, 314, 322, and 324.
[0092] There are protection and encryption layers at each level of the email address. For example, while the tree structure 300 clearly shows the relationships between each email address and between email address levels, and these relationships are maintained by the virtual email address system, the system only provides the requesting entity with the email address specified by the user, for example, for that entity or for purposes associated with that entity (e.g., the requesting entity's news website purpose is a news website). There may be no mechanism for the requesting party to receive the user's email address through a tokenization process or exchange. By preventing requesting entities such as corporate entities, government entities, or data integrators from tracking the email address identifier to the master email address 302 at any level other than the top level, this method of storing email addresses protects the privacy of users of the virtual email address system.
[0093] By creating a hierarchy where each email address protects the others, the virtual email address system cuts off lower-level email addresses from the top-level master email address 302. Each email address protects the others, making the user data associated with each email address inaccessible to lower-level email addresses. That is, the user data associated with email address 310 and email address 310 itself will not be provided to the requesting entity that will receive a request from email address 312 or email address 314.
[0094] Identity server 130 can update tree structure 300 when a user accesses, creates, edits, and / or deletes data in identity database 140 through user interface 134. Users can access emails within tree structure 300 one by one, or they can access more than one email at a time. For example, a user can periodically delete each lower-level email linked to their primary email address.
[0095] In some implementations, virtual email addresses can be recycled. For example, deleted virtual email addresses can be released back into a pool of available email addresses. As mentioned above, virtual email addresses can be recycled at a specified frequency, which can be dynamically adjusted.
[0096] Figure 4 This is a flowchart of an example process 400 for generating a virtual email address. In some implementations, process 400 can be executed by one or more systems. For example, process 400 can be performed by... Figures 1 to 3 The identity server 130 and / or user equipment 106 are implemented. In some embodiments, process 400 can be implemented as instructions stored on a computer-readable medium, which may be non-transitory, and when executed by one or more servers, the instructions can cause one or more servers to perform the operations of process 400.
[0097] Process 400 begins by receiving login credentials (402) from the user device and at the identity server for a first email address mapped to a first set of user information values. For example, identity server 130 may receive login credentials from user device 106 for a master email address mapped to a set of user profile information.
[0098] In some implementations, login credentials are provided in the form of text input, audio input, or visual input. For example, a user of user equipment 106 can enter their login credentials through a text field, provide a voice sample, perform a gesture, etc.
[0099] Process 400 continues with the identity server detecting triggering events (404). For example, identity server 130 is able to detect triggering events such as a threshold number of visits to the same website.
[0100] In some implementations, the triggering event can be user input or a predetermined condition defined by the identity server. For example, the identity server 130 can detect a user's click on a user interface element via the user interface 134 to indicate that the user wishes to initiate the creation of a new virtual email address.
[0101] In response to the detection of a triggering event, process 400 continues by the identity server creating a new virtual email address (406) that is separate from the first email address and mapped to a second set of user information values that is different from the first set of user information values. For example, identity server 130 is capable of creating a new virtual email address that is separate from the primary email address. The new virtual email address is linked to the primary email address within identity server 130, but this relationship cannot be determined by a third party such as the requesting entity, as mentioned above. Figure 2 and Figure 3 As described.
[0102] Process 400 continues with the identity server detecting requests for credentials from the requesting entity (408). For example, identity server 130 is able to detect requests for credentials, such as an email address used to register for updates from the blog.
[0103] In some implementations, the request for credentials can be data indicating that the user device has accessed a webpage with one or more text fields for entering credentials. For example, identity server 130 can simply detect that user device 106 has navigated to a webpage with one or more text fields or other user interface elements through which credentials such as contact information can be entered.
[0104] In response to the detection of the request, process 400 continues with the identity server transmitting a new virtual email address as login credentials to the requesting entity (410). For example, identity server 130 provides a new virtual email address to the requesting entity, such as a business that owns a website that users visit.
[0105] In some implementations, transmitting a new virtual email address as a login credential to the requesting entity includes: transmitting data representing the new virtual email address via a tokenized API, and a token indicating that the new virtual email address is untraceable to the first email address, through a tokenized application programming interface (API). For example, identity server 130 can transmit the new virtual email address as an identifier to the requesting entity via secure API 120.
[0106] The identity server function updates the database based on the new virtual email address by creating database entries that map the new virtual email address to a second set of user information values. For example, identity server 130 can update identity database 140 based on the new virtual email address by creating database entries that map the new virtual email address to a set of user information values that are made available to requesting entities that provide the new virtual email address as an identifier to the user.
[0107] In some implementations, process 400 includes receiving input from a user device indicating a change to a new virtual email address, and then updating a database entry by an identity server based on the input indicating a change to the new virtual email address. For example, identity server 130 may receive input from user device 106 via user interface 134 indicating that the user wants to delete a new virtual email address, and identity server 130 may delete an entry in identity database 140.
[0108] Figure 5 This is a block diagram of an example computer system 500 capable of performing the operations described above. System 500 includes a processor 510, memory 520, storage device 530, and input / output device 540. Each of components 510, 520, 530, and 540 can be interconnected, for example, using a system bus 550. Processor 510 is capable of processing instructions for execution within system 500. In one embodiment, processor 510 is a single-threaded processor. In another embodiment, processor 510 is a multi-threaded processor. Processor 510 is capable of processing instructions stored in memory 520 or storage device 530.
[0109] Memory 520 stores information within system 500. In one embodiment, memory 520 is a computer-readable medium. In one embodiment, memory 520 is a volatile memory cell. In another embodiment, memory 520 is a non-volatile memory cell.
[0110] Storage device 530 provides high-capacity storage for system 500. In one embodiment, storage device 530 is a computer-readable medium. In various other embodiments, storage device 530 may include, for example, a hard disk drive, an optical disk drive, a storage device shared by multiple computing devices over a network (e.g., a cloud storage device), or some other high-capacity storage device.
[0111] Input / output device 540 provides input / output operations for system 500. In one embodiment, input / output device 540 may include one or more network interface devices, such as an Ethernet card, a serial communication device, such as an RS-232 port, and / or a wireless interface device, such as an 802.11 card. In another embodiment, input / output device may include a driver device configured to receive input data and send output data to other input / output devices, such as a keyboard, printer, and display device 560. However, other embodiments, such as mobile computing devices, mobile communication devices, set-top box television client devices, etc., may also be used.
[0112] Although already Figure 5An example processing system is described herein, but the implementation of the subjects and functions described herein can be realized in other types of digital electronic circuits or in computer software, firmware or hardware, including the structures disclosed herein and their structural equivalents, or combinations thereof.
[0113] Media does not necessarily correspond to a document. Media can be stored as part of a file that contains other documents, as a single file dedicated to the document in question, or as multiple harmonizing files.
[0114] In the context of the technical collection and / or use of information about users discussed throughout this document, users (such as end users, content creators or content providers, and other types of users) may be given control over whether and when the systems, programs, or features described herein may collect user information (e.g., information about a user's social networks, social behavior, or activities, occupation, user preferences, or user's current location), and whether to send content or communications to the user from a server. Additionally, certain data may be processed in one or more ways before being stored or used, such that personally identifiable information is removed. For example, a user's identity may be processed so that any personally identifiable information about the user cannot be determined, or the user's geographic location may be generalized (e.g., at the city, zip code, or state level) when location information is obtained, making the user's specific location undeterminable. Therefore, users may have control over what information about themselves is collected, how that information is used, and what information is provided to them.
[0115] The embodiments of the subject matter and operation described in this specification can be implemented in digital electronic circuits or computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or combinations thereof. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on one or more computer storage media for execution by a data processing device or for controlling the operation of a data processing device. Alternatively or additionally, the program instructions can be encoded on artificially generated propagating signals, such as machine-generated electrical, optical, or electromagnetic signals, which are generated to encode information for transmission to a suitable receiver device for execution by the data processing device. The computer storage medium can be, or be included in, a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or combinations thereof. Furthermore, although the computer storage medium is not a propagating signal, it can be a source or destination of computer program instructions encoded in artificially generated propagating signals. The computer storage medium can also be, or be included in, one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices). The methods described in this specification can be computer-implemented.
[0116] The operations described in this specification can be implemented as operations performed by a data processing device on data stored on one or more computer-readable storage devices or received from other sources.
[0117] The term "data processing apparatus" encompasses all types of devices, apparatuses, and machines used for processing data, including, for example, programmable processors, computers, systems-on-a-chip, or a combination thereof. The apparatus can include special-purpose logic circuitry, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits). In addition to hardware, the apparatus can also include code for creating an execution environment for the computer program in question, such as code constituting processor firmware, protocol stacks, database management systems, operating systems, cross-platform runtime environments, virtual machines, or combinations thereof. The apparatus and execution environment can implement a variety of different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.
[0118] A computer program (also referred to as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and can be deployed in any form, including as a standalone program or as a module, component, subroutine, object, or other unit suitable for a computing environment. A computer program may, but must, correspond to a file in a file system. A program can be stored as a portion of a file holding other programs or data (e.g., one or more scripts stored in a markup language document), a single file dedicated to the program in question, or multiple coordinating files (e.g., a file storing one or more modules, subroutines, or portions of code). A computer program can be deployed to be executed on one or more computers located on a website or distributed across multiple websites and interconnected by a communications network.
[0119] The processes and logic flows described in this specification can be executed by one or more programmable processors, which execute one or more computer programs to perform actions by manipulating input data and generating output. The processes and logic flows can also be executed by special-purpose logic circuits, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits), and the devices can also be implemented as special-purpose logic circuits, such as FPGAs or ASICs.
[0120] Processors suitable for executing computer programs include, for example, both general-purpose and special-purpose microprocessors. Typically, a processor receives instructions and data from read-only memory or random access memory, or both. The basic components of a computer are a processor for performing actions according to instructions and one or more memory devices for storing instructions and data. Typically, a computer will also include, or be operatively coupled to, one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, to receive data from or transfer data to, or both. However, a computer does not necessarily have to have such devices. Furthermore, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device (e.g., a universal serial bus (USB) flash drive), to name a few. Devices suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and storage devices, including, for example, semiconductor storage devices, such as EPROM, EEPROM, and flash memory devices; magnetic disks, such as internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. Processors and memory can be supplemented by or integrated into dedicated logic circuits.
[0121] To provide interaction with the user, embodiments of the subject matter described in this specification can be implemented on a computer with a display device, such as a CRT (cathode ray tube) or LCD (liquid crystal display) monitor, for displaying information to the user, and a keyboard and pointing device, such as a mouse or trackball, through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback, such as visual, auditory, or tactile feedback; input from the user can also be received in any form, including sound, speech, or tactile input. Additionally, the computer can interact with the user by sending and receiving documents from the device used by the user; for example, by sending web pages to a web browser on the user's client device in response to a request received from the web browser.
[0122] Embodiments of the subject matter described in this specification can be implemented in a computing system that includes backend components, such as a data server, or middleware components, such as an application server, or frontend components, such as a client computer with a graphical user interface or a web browser, through which a user can interact with embodiments of the subject matter described in this specification, or any combination of one or more such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium, such as a communication network. Examples of communication networks include local area networks (“LANs”) and wide area networks (“WANs”), interconnected networks (e.g., the Internet) and peer-to-peer networks (e.g., self-organizing peer-to-peer networks).
[0123] A computing system can include clients and servers. Clients and servers are typically geographically separated and usually interact via a communication network. The client-server relationship is established by means of computer programs running on respective computers and having a client-server relationship with each other. In some embodiments, the server transmits data (e.g., HTML pages) to the client device (e.g., for the purpose of displaying data to a user interacting with the client device and receiving user input from the user interacting with the client device). Data generated at the client device (e.g., the result of user interaction) can be received from the client device at the server.
[0124] While this specification contains numerous specific details of implementation, these should not be construed as limiting the scope of any invention or what may be claimed, but rather as descriptions of features specific to particular embodiments of a particular invention. Some features described in this specification within the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented individually or in any suitable sub-combination in multiple embodiments. Furthermore, while features may be described above as functioning in certain combinations, and even initially claimed in this way, in some cases one or more features from the claimed combination can be removed from the combination, and the claimed combination may involve sub-combinations or variations of sub-combinations.
[0125] Similarly, although operations are depicted in a specific order in the accompanying drawings, this should not be construed as requiring such operations to be performed in the specific order shown or sequentially, or to perform all shown operations to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system components in the above embodiments should not be construed as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated into a single software product or packaged into multiple software products.
[0126] Therefore, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the following claims. In some cases, the actions stated in the claims can be performed in a different order and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific order or sequential sequence shown to achieve the desired result. In some embodiments, multitasking and parallel processing may be advantageous.
[0127] The following is a list of non-limiting aspects of this disclosure:
[0128] Aspect 1. A computer-implemented method, comprising:
[0129] Login credentials are received from the user device and from the identity server, which are mapped to a first set of user information values, via a first email address.
[0130] The event is triggered by the identity server.
[0131] In response to the detection of the triggering event, the identity server creates a new virtual email address that is separate from the first email address and mapped to a second set of user information values that are different from the first set of user information values;
[0132] The identity server detects requests for credentials from the requesting entity; and
[0133] In response to the detection of the request, the identity server transmits the new virtual email address as a new login credential to the requesting entity.
[0134] Aspect 2. The method according to aspect 1, wherein the triggering event is one of the following: user input and a predetermined condition defined by the identity server.
[0135] Aspect 3. The method according to aspect 1 or aspect 2, wherein the login credentials are provided in the form of text input, audio input or visual input.
[0136] Aspect 4. The method according to any one of Aspects 1 to 3, wherein transmitting the new virtual email address as a login credential to the requesting entity comprises:
[0137] Data representing the new virtual email address is transmitted via a tokenized application programming interface (API).
[0138] The data representing the new virtual email address is a token that cannot be traced back to the first email address.
[0139] Aspect 5. The method according to any one of Aspects 1 to 3, wherein transmitting the new virtual email address as a login credential to the requesting entity comprises:
[0140] Data representing the new virtual email address is transmitted via a tokenized application programming interface (API) such that the data representing the new virtual email address is a token that cannot be traced back to the first email address.
[0141] Aspect 6. The method according to any one of aspects 1 to 5, further comprising:
[0142] The database is updated by the identity server and based on the new virtual email address by creating database entries that map the new virtual email address to user information values in the second set.
[0143] Aspect 7. The method according to aspect 6 further includes:
[0144] Receive input from the user equipment indicating a change to the new virtual email address; and
[0145] The database entry is updated by the identity server based on the input indicating a change to the new virtual email address.
[0146] Aspect 8. The method according to any one of Aspects 1 to 7, wherein the request for credentials includes data indicating that the user equipment has accessed a webpage having one or more text fields for entering credentials.
[0147] Aspect 9. A system comprising:
[0148] One or more processors; and
[0149] One or more memory elements, the one or more memory elements including instructions that, when executed, cause the one or more processors to perform operations, the operations including:
[0150] Login credentials are received from the user device and from the identity server, which are mapped to a first set of user information values, via a first email address.
[0151] The event is triggered by the identity server.
[0152] In response to the detection of the triggering event, the identity server creates a new virtual email address that is separate from the first email address and mapped to a second set of user information values that is different from the first set of user information values;
[0153] The identity server detects requests for credentials from the requesting entity; and
[0154] In response to the detection of the request, the identity server transmits the new virtual email address as a new login credential to the requesting entity.
[0155] Aspect 10. The system according to aspect 9, wherein the triggering event is one of the following: user input and a predetermined condition defined by the identity server.
[0156] Aspect 11. The system according to aspect 9 or 10, wherein the login credentials are provided in the form of text input, audio input, or visual input.
[0157] Aspect 12. The system according to any one of Aspects 9 to 11, wherein transmitting the new virtual email address as a login credential to the requesting entity comprises:
[0158] Data representing the new virtual email address is transmitted via a tokenized application programming interface (API), wherein the data representing the new virtual email address is a token that cannot be traced back to the first email address.
[0159] Aspect 13. The system according to any one of Aspects 9 to 11, wherein transmitting the new virtual email address as a login credential to the requesting entity comprises:
[0160] Data representing the new virtual email address is transmitted via a tokenized application programming interface (API).
[0161] This makes the data representing the new virtual email address a token that cannot be traced back to the first email address.
[0162] Aspect 14. The system according to any one of aspects 9 to 13, wherein the operation further comprises:
[0163] The database is updated by the identity server and based on the new virtual email address by creating database entries that map the new virtual email address to user information values in the second set.
[0164] Aspect 15. The system according to aspect 14, wherein the operation further includes:
[0165] Receive input from the user equipment indicating a change to the new virtual email address; and
[0166] The database entry is updated by the identity server based on the input indicating a change to the new virtual email address.
[0167] Aspect 16. The system according to any one of Aspects 9 to 15, wherein the request for credentials includes data indicating that the user equipment has accessed a webpage having one or more text fields for entering credentials.
[0168] Aspect 17. A computer storage medium utilizing instruction encoding, which, when executed by a distributed computing system, causes the distributed computing system to perform an operation, the operation comprising:
[0169] Login credentials are received from the user device and from the identity server, which are mapped to a first set of user information values, via a first email address.
[0170] The event is triggered by the identity server.
[0171] In response to the detection of the triggering event, the identity server creates a new virtual email address that is separate from the first email address and mapped to a second set of user information values that is different from the first set of user information values;
[0172] The identity server detects requests for credentials from the requesting entity; and
[0173] In response to the detection of the request, the identity server transmits the new virtual email address as a new login credential to the requesting entity.
[0174] Aspect 18. The computer storage medium according to aspect 17, wherein the triggering event is one of the following: user input and predetermined conditions defined by the identity server.
[0175] Aspect 19. The computer storage medium according to aspect 17 or 18, wherein the login credentials are provided in the form of text input, audio input, or visual input.
[0176] Aspect 20. The computer storage medium according to any one of Aspects 17 to 19, wherein transmitting the new virtual email address as a login credential to the requesting entity comprises:
[0177] Data representing the new virtual email address is transmitted via a tokenized application programming interface (API).
[0178] The data representing the new virtual email address is a token that cannot be traced back to the first email address.
[0179] Aspect 21. The computer storage medium according to any one of Aspects 17 to 19, wherein transmitting the new virtual email address as a login credential to the requesting entity comprises:
[0180] Data representing the new virtual email address is transmitted via a tokenized application programming interface (API) such that the data representing the new virtual email address is a token that cannot be traced back to the first email address.
[0181] Aspect 22. The computer storage medium according to any one of aspects 17 to 21, wherein the operation further comprises:
[0182] The database is updated by the identity server and based on the new virtual email address by creating database entries that map the new virtual email address to user information values in the second set.
[0183] Aspect 23. The computer storage medium according to aspect 22, wherein the operation further comprises:
[0184] Receive input from the user equipment indicating a change to the new virtual email address; and
[0185] The database entry is updated by the identity server based on the input indicating a change to the new virtual email address.
Claims
1. A method for creating and using virtual email addresses that protect user privacy and ensure data security, comprising: Login credentials are received from the user device and from the identity server, which are mapped to a first set of user information values, via a first email address. The event is triggered by the identity server. In response to the detection of the triggering event, the identity server creates a new virtual email address that is separate from the first email address and mapped to a second set of user information values that is different from the first set of user information values, wherein the new virtual email address has a specified triggering event that initiates the deletion of the new virtual email address; The identity server detects requests for credentials from the requesting entity. as well as In response to the detection of the request, (i) the identity server transmits the new virtual email address to the requesting entity as a new login credential for the requesting entity and (ii) based on the new virtual email address being used as a new login credential for the requesting entity, the identity server transmits a second set of the user information values to the requesting entity.
2. The method according to claim 1, wherein, The triggering event is one of the following: user input and a predetermined condition defined by the identity server.
3. The method according to claim 1, wherein, The login credentials are provided in the following forms: text input, audio input, or visual input.
4. The method according to claim 1, wherein, Transmitting the new virtual email address as login credentials to the requesting entity includes: Data representing the new virtual email address is transmitted via a tokenized application programming interface (API). The data representing the new virtual email address is a token that cannot be traced back to the first email address.
5. The method of claim 1, further comprising: The database is updated by the identity server and based on the new virtual email address by creating database entries that map the new virtual email address to the user information values in a second set.
6. The method of claim 5, further comprising: Receive input from the user equipment indicating a change to the new virtual email address; as well as The database entry is updated by the identity server based on the input indicating a change to the new virtual email address.
7. The method according to claim 1, wherein, The request for credentials includes data indicating that the user equipment has accessed a webpage with one or more text fields for entering credentials.
8. The method according to claim 1, wherein, The specified triggering event includes a specified time period after the creation of the new virtual email address.
9. The method according to claim 1, wherein, The triggering events include user navigation to a specific website during a browsing session and the specified triggering event includes the end of the browsing session.
10. The method according to claim 1, wherein, Creating the new virtual email address includes: obtaining one or more parameters from the user device; and generating the new virtual email address using the one or more parameters.
11. The method of claim 1, further comprising: The triggering event for the user's device is determined based on the user's online activity.
12. The method of claim 1, further comprising: In response to detecting a request for credentials from the requesting entity, an initiation is made to display a user interface on the user equipment, the user interface showing a set of virtual email addresses for the user of the user equipment; as well as The user receives an instruction at the user equipment to select the new virtual email address. The new virtual email address is transmitted to the requesting entity based on the user's selection of the new virtual email address on the user device.
13. A system for creating and using virtual email addresses for user privacy protection and data security, comprising: One or more processors; as well as One or more memory elements, the one or more memory elements including instructions that, when executed, cause the one or more processors to perform operations, the operations including: Login credentials are received from the user device and from the identity server, which are mapped to a first set of user information values, via a first email address. The event is triggered by the identity server. In response to the detection of the triggering event, the identity server creates a new virtual email address that is separate from the first email address and mapped to a second set of user information values that is different from the first set of user information values, wherein the new virtual email address has a specified triggering event that initiates the deletion of the new virtual email address; The identity server detects requests for credentials from the requesting entity; and In response to the detection of the request, (i) the identity server transmits the new virtual email address to the requesting entity as a new login credential for the requesting entity and (ii) based on the new virtual email address being used as a new login credential for the requesting entity, the identity server transmits a second set of the user information values to the requesting entity.
14. The system according to claim 13, wherein, The triggering event is one of the following: user input and a predetermined condition defined by the identity server.
15. The system according to claim 13, wherein, The login credentials are provided in the following forms: text input, audio input, or visual input.
16. The system according to claim 13, wherein, Transmitting the new virtual email address as login credentials to the requesting entity includes: Data representing the new virtual email address is transmitted via a tokenized application programming interface (API). The data representing the new virtual email address is a token that cannot be traced back to the first email address.
17. The system of claim 13, wherein the operation further comprises: The database is updated by the identity server and based on the new virtual email address by creating database entries that map the new virtual email address to the user information values in a second set.
18. The system of claim 17, wherein the operation further comprises: Receive input from the user equipment indicating a change to the new virtual email address; as well as The database entry is updated by the identity server based on the input indicating a change to the new virtual email address.
19. The system according to claim 13, wherein, The request for credentials includes data indicating that the user equipment has accessed a webpage with one or more text fields for entering credentials.
20. A non-transitory computer storage medium encoded with instructions, said instructions causing the distributed computing system to perform operations when executed by the distributed computing system, said operations including: Login credentials are received from the user device and from the identity server, which are mapped to a first set of user information values, via a first email address. The event is triggered by the identity server. In response to the detection of the triggering event, the identity server creates a new virtual email address that is separate from the first email address and mapped to a second set of user information values that is different from the first set of user information values, wherein the new virtual email address has a specified triggering event that initiates the deletion of the new virtual email address; The identity server detects requests for credentials from the requesting entity. as well as In response to the detection of the request, (i) the identity server transmits the new virtual email address to the requesting entity as a new login credential for the requesting entity and (ii) based on the new virtual email address being used as a new login credential for the requesting entity, the identity server transmits a second set of the user information values to the requesting entity.
21. The non-transitory computer storage medium according to claim 20, wherein, The triggering event is one of the following: user input and a predetermined condition defined by the identity server.
22. The non-transitory computer storage medium according to claim 20, wherein, The login credentials are provided in the following forms: text input, audio input, or visual input.
23. The non-transitory computer storage medium according to claim 20, wherein, Transmitting the new virtual email address as login credentials to the requesting entity includes: Data representing the new virtual email address is transmitted via a tokenized application programming interface (API). The data representing the new virtual email address is a token that cannot be traced back to the first email address.
24. The non-transitory computer storage medium of claim 20, wherein the operation further comprises: The database is updated by the identity server and based on the new virtual email address by creating database entries that map the new virtual email address to the user information values in a second set.
25. The non-transitory computer storage medium of claim 24, wherein the operation further comprises: Receive input from the user equipment indicating a change to the new virtual email address; as well as The database entry is updated by the identity server based on the input indicating a change to the new virtual email address.