Cryptographic security request verification

By generating encrypted subscription tokens and interactive user interfaces through a data security system, the problems of information leakage and request imitation by client devices in public networks are solved, and transparent control and security protection of user data are achieved.

CN115066865BActive Publication Date: 2026-03-31GOOGLE LLC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-27
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

When client devices transmit requests and data over public networks, they face issues such as information leakage, malicious attacks, and request imitation, especially in the process of sharing and subscribing to user privacy information, where existing technologies lack effective protection mechanisms.

Method used

A data security system is used to generate encrypted subscription tokens, including encrypted user identifiers and attachment elements, to identify and authorize user interactions with the content platform. User data privacy settings are managed through an interactive user interface to ensure data security and transparent control.

Benefits of technology

It enables users to have transparent and fine-grained control over data usage, reduces data storage and bandwidth consumption, prevents the sharing of sensitive information, and enhances user privacy protection and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115066865B_ABST
    Figure CN115066865B_ABST
Patent Text Reader

Abstract

The present disclosure relates to data security and cryptography. In one aspect, a method includes updating a user interface of a client device to present user interface controls that enable a user to specify data privacy settings that define how entities collect, store, and use data of the user. Based on user interaction with one or more of the user interface controls, a data security system receives, from the client device, a request to modify the data privacy settings of one or more entities. The request includes a temporary user identifier and an attestation token of the user. The data security system verifies the request using at least the temporary user identifier and the attestation token. The data security system transmits, to each of the one or more entities, data that indicates the entity to modify usage of the user data based on the modified given data privacy setting.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This manual covers data security and cryptography. Background Technology

[0002] Client devices transmit requests and other data over public networks such as the Internet. These communications can be altered by other parties, such as interceptors of communications and / or intermediaries that receive communications and forward them to other parties. Client devices are also vulnerable to malicious attacks, such as viruses and malware that can send fraudulent requests without the user's knowledge or authorization. Furthermore, other parties can impersonate client devices to send requests that appear to originate from the client device but are actually from other parties' devices.

[0003] Users of client devices can use applications (e.g., web browsers or native applications) to obtain content from various content providers (e.g., search engines, social media platforms, website publishers, etc.). Communication between client devices and content provider servers can include the sharing of sensitive information such as names, email addresses, and phone numbers (e.g., a user's personally identifiable information (PII)) as an exchange of digital content. For example, subscription-based content delivery can use PII to deliver content to users. Summary of the Invention

[0004] This specification describes techniques related to protecting user privacy. Typically, an innovative aspect of the subject matter described herein can be embodied in a method comprising receiving a request for a subscription token for a given user from a publisher's computing system and a data security system. The request includes user identification information provided by the given user to the publisher when subscribing to the publisher's electronic content. In response to receiving the request for a subscription token, the data security system generates a subscription token for the publisher and the given user. The subscription token includes: (i) a dataset comprising a first encrypted user identifier generated by encrypting a first user identifier of the given user, which is used by the data security system to identify the given user using an encryption key of the data security system; and, for each of one or more content platforms, (ii) an appendix element comprising a second encrypted user identifier generated by encrypting a second user identifier of the given user, which is used by the content platform to identify the given user using an encryption key of the content platform and to transmit the subscription token to the publisher's computing system. Other embodiments of this aspect include corresponding apparatus, systems, and computer programs encoded on a computer storage device configured to perform aspects of the method.

[0005] These and other implementations may optionally include one or more of the following features. In some aspects, the data security system includes the email provider's computing system, and the user identification information includes the email address of a given user and the email account of the given user with respect to the email provider.

[0006] In some respects, a given user's first user identifier includes one of the following: (i) the given user's email address relating to the email provider's email account, or (ii) another user identifier corresponding to the given user's email address. In some respects, user identification information includes the given user's telephone number.

[0007] In some aspects, the attachment element of each content platform includes a digital signature of the dataset and a second encrypted user identifier generated using the private key of the data security system. In other aspects, the subscription token includes the digital signature of the dataset and each attachment element.

[0008] In some aspects, the publisher computing system receives recurring replacement requests, each replacement request for a replacement subscription token for a given user that includes the corresponding first encrypted user identifier from the previous request. In some aspects, for each replacement request, an updated first encrypted user identifier, different from the one previously requested, is generated. In some aspects, the replacement subscription token includes an updated dataset comprising the updated first encrypted user identifier and each appendix element. Each replacement subscription token is transmitted to the publisher computing system.

[0009] In some aspects, the replacement subscription token further includes updated data privacy settings that have been updated by the user since the subscription token was generated. In some aspects, generating a subscription token for the publisher and a given user includes identifying one or more content platforms, such that each content platform is designated as an eligible content platform by the publisher and the user, and each eligible content platform is a content platform eligible to select for use in digital components presented to a given user along with the publisher's electronic resources.

[0010] In some respects, generating subscription tokens for publishers and given users involves identifying one or more content platforms, such that each content platform is designated by the publisher and user as an eligible content platform, and each eligible content platform is a content platform that is qualified to collect, store, and use data from a given user.

[0011] In some aspects, an interactive user interface is provided to a given user's client device, enabling the given user to manage the use of the given user's data by a set of publishers and a set of content platforms. In some aspects, the interactive user interface includes identifying the data of content platforms that collaborate with publishers to select digital components for presentation alongside the publisher's content, and enabling the given user to select one or more content platforms eligible to access and store the given user's data. The interactive user interface further enables the user to select one or more publishers eligible to access and store the given user's data, and also to select one or more ways in which the given user's data is eligible to be used by each content platform and each publisher. The interactive user interface further enables the user to request one or more content platforms or one or more publishers to delete the given user's data.

[0012] In some aspects, the data security system detects that a given user has designated a publisher as ineligible to access and store the user's data based on data received from the user's client device. In other aspects, following the detection, the data security system receives a request from the publisher's computing system for a replacement subscription token for the given user. In response to detecting that a given user has designated a publisher as ineligible to access and store the user's data, the data security system determines not to provide the publisher's computing system with a replacement subscription token for the given user.

[0013] In some aspects, the data security system detects that a given user has designated a publisher as ineligible to access and store the given user's data based on data received from the given user's client device. In other aspects, following the detection, the data security system receives a request from the publisher's computing system for a replacement subscription token for the given user. In response to detecting that a given user has designated a given content platform as ineligible to access and store the given user's data, the data security system determines that the attached elements of the given content platform with the replacement subscription token are not included.

[0014] Typically, another aspect of the subject matter described in this specification can be embodied in a method comprising updating a user interface to present actions of user interface controls that enable a user to specify how a data privacy setting limits how an entity uses the user's data. Based on the user's interaction with one or more user interface controls, a request to modify the data privacy settings of one or more entities is received from a client device. This request includes the user's temporary user identifier and authentication token, wherein the temporary user identifier is based on the client device's telephone number. The request is verified using at least the user's temporary user identifier and authentication token, and in response to the verification request, data instructing each of the one or more entities to modify the use of the user data based on the modified given data privacy setting is transmitted to each entity. Other embodiments of this aspect include corresponding apparatus, systems, and computer programs coded on a computer storage device and configured to perform aspects of the method.

[0015] These and other implementations may optionally include one or more of the following features. In some aspects, prior to updating the user interface, a token request for a subscription token for the user's phone number is received from the publisher, and a message is transmitted to the client device including (i) a resource locator containing the electronic resource of the user interface and (ii) a temporary user identifier for the user.

[0016] In some aspects, the temporary user identifier includes an encrypted result generated by encrypting a user's phone number or email address. In some aspects, the request further includes the public key of the client device, and the verification request further includes verifying the association between the temporary user identifier and the public key of the client device.

[0017] In some respects, verifying a temporary user identifier involves attempting to decrypt the temporary user identifier and determining that the temporary user identifier has been successfully verified when it is successfully decrypted.

[0018] In some respects, the proof tokens and updated settings are stored in the audit log.

[0019] In some respects, the request includes a web cookie. In other respects, the verification request includes decrypting a temporary user identifier and using the temporary user identifier to verify the web cookie.

[0020] In some respects, a proof token includes a dataset and a digital signature of that dataset. In other respects, verifying a proof token involves determining the validity of the digital signature based on the dataset.

[0021] In some respects, the proof token includes a token creation timestamp indicating when the proof token was created, and verifying the proof token includes determining that the time the proof was created is within a threshold duration of the time the request was received.

[0022] In some respects, the proof token includes an integrity token, which includes a determination of the trustworthiness of the client device or the application running on the client device, and the verification proof token includes a verification integrity token.

[0023] The subject matter described in this specification can be implemented in specific embodiments to achieve one or more of the following advantages: Providing users with a platform for managing data privacy settings across an online ecosystem; offering users a transparent view of which online entities can access user data that may contain sensitive information; and enabling users to control which entities can store user data and how entities use it. This transparent and efficient control over privacy settings allows users to decide which online entities can access user data, which online entities cannot access user data, and how each entity stores and uses the data. Compared to existing technologies, the methods described in this document further prevent the sharing of sensitive user information with third-party entities, thereby maintaining user privacy.

[0024] This technology can include stored information, such as user privacy settings and user actions that modify those settings, to facilitate auditing of online entities that have access to user data to verify compliance with data distribution and user privacy agreements and to identify any potentially abusive entities. The technology involves using subscription tokens with one or more attachment elements, each for one or more recipients, and each attachment element can include data for its recipient (e.g., encrypted data). By including the attachment elements as separate data structures within the subscription token, rather than including each entity's data within the subscription token, the attachment elements can be removed from the overall message or other electronic communications without affecting the recipient's ability to verify the subscription token. This allows one recipient to receive the subscription token and all attachment elements, and for each other recipient, only the attachment elements of the recipient with the subscription token are forwarded.

[0025] Furthermore, this reduces the processing power and computational resources (e.g., CPU cycles) required to verify the proof token. For example, if each recipient's data is included in the proof token, the recipient's device would need to scan all of that data, in addition to scanning other data on the proof token to verify its digital signature. By generating an appendix element for each recipient, each recipient's device only needs to scan the other proof data to verify the signature; for example, there is no need to scan each recipient's data. Moreover, this better protects each recipient's data by not providing it to other recipients. Even if the data is encrypted in the proof token, encrypted data is vulnerable to attacks from another entity that finds a way to decrypt it.

[0026] In some implementations, the data size of the subscription token can be reduced by including a single digital signature on the entire subscription token, encompassing all attachment elements, instead of a separate digital signature for each attachment element. This reduces the data storage requirements of the subscription token and decreases bandwidth consumption when transmitting the subscription token from the client device. With thousands or millions of transmissions per day, this can result in significant data storage and bandwidth savings.

[0027] Email providers can act as a central authorizing body, providing mechanisms (such as platforms and / or user interfaces) that enable users to manage how their data is used by various online entities. In this way, users can more easily manage how their data is used in a central location by having their potentially sensitive data stored by entities they already trust.

[0028] Email providers or other central authorities can issue subscription tokens to publishers who work with content platforms that use user data to select content (such as digital components) for users based on that data. These tokens include encryption and privacy-preserving features to prevent other entities from tracking users, enable content platforms to demonstrate that they are using user data in accordance with their consent settings, and prevent the falsification of such data. Users can easily manage which entities can receive and / or use their data by interacting with a user interface provided by a central authority (such as an email provider), and if an entity is blocked, the central authority can prevent that entity from receiving subscription tokens and / or associating the token with the user (e.g., by not providing an attachment element that includes the user identifier of the entity holding the token).

[0029] Historically, third-party cookies (i.e., cookies from a domain different from the resource being presented by the client device) have been used to collect data from client devices across the internet. However, some browsers are blocking the use of third-party cookies, thus preventing data collection using them. This creates problems when trying to leverage the collected data to enhance the online browsing experience. In other words, without the use of third-party cookies, most of the previously collected data would no longer be available, preventing computing systems from using it. The subscription tokens described in this document achieve similar functionality, but in a way that is transparent to the user and gives them fine-grained control over how their data is collected and used.

[0030] Recipients of subscription tokens can reduce data storage requirements by removing attachment elements from other recipients. When a token provides user consent for the use of user data across multiple events, data storage requirements can be further reduced by storing a single token for each event. Alternatively, audit logs can include an identifier or a reference to the corresponding subscription token for each event. By issuing subscription tokens for each specific time period instead of including a subscription token with every request or other communication, the amount of computational resources required to generate tokens is reduced, the amount of bandwidth consumed in distributing subscription tokens to publishers is reduced, and the data storage requirements for storing subscription tokens by recipients are reduced.

[0031] The various features and advantages of the foregoing subject matter are described below with reference to the accompanying drawings. Additional features and advantages will be apparent from the subject matter and claims described herein. Attached Figure Description

[0032] Figure 1 This is a block diagram of the data security system that manages the security and privacy of user data.

[0033] Figure 2 This is a block diagram of an example environment in which email providers and central authorities manage the security and privacy of user data.

[0034] Figure 3 This is a swimlane diagram of an example process for providing digital components using subscription tokens.

[0035] Figure 4 This is a flowchart of an example process for generating subscription tokens.

[0036] Figure 5 This is a flowchart of an example process for changing a subscription token.

[0037] Figure 6 This is a swimlane diagram of an example procedure for receiving temporary user identifiers using an application provided by a data security system.

[0038] Figure 7 This is a swimlane diagram of an example process for generating and providing a user interface that allows users to adjust data privacy settings.

[0039] Figure 8 This is a swimlane diagram of an example process for deleting user data using an application provided by a data security system.

[0040] Figure 9 This is a swimlane diagram of an example process for accessing a web-based user interface for a data security system.

[0041] Figure 10 This is a flowchart illustrating an example process for modifying the use of user data based on modified data privacy settings using user interface controls.

[0042] Figure 11 This is a block diagram of an example computer system.

[0043] The same reference numerals and names in the various figures indicate the same elements. Detailed Implementation

[0044] Typically, this document describes systems and technologies that enable users to manage data privacy settings across the online ecosystem in a secure and cryptographically provable manner from a central platform. These technologies allow each user to control (e.g., permit and / or revoke) permissions to online entities such as content platforms that define whether a user's data can be collected and / or stored, and if so, how that data is used and for what duration.

[0045] One or more data security systems can each act as a central platform for managing user data privacy (e.g., managing which entities can collect, store, and use user data) using subscription tokens. In some implementations, the data security system can be operated by an email provider, and each email provider can manage the data privacy of users who have email accounts with that email provider. The default data security system can manage the data privacy of users who do have email accounts with participating email providers.

[0046] Figure 1This is a block diagram of an environment 100 in which a data security system 180 manages the security and privacy of user data. Example environment 100 includes a data communication network 105, such as a local area network (LAN), a wide area network (WAN), the Internet, a mobile network, or a combination thereof. Network 105 connects client devices 110, digital component providers 170, demand-side platforms (DSPs) 160, supply-side platforms (SSPs) 150, data security system 180, publishers 140, and websites 142. Example environment 100 may include many different client devices 110, digital component providers 170, DSPs 160, SSPs 150, data security systems 180, publishers 140, and websites 142.

[0047] Client device 110 is an electronic device capable of communicating via network 105. Example client device 110 includes personal computers, mobile communication devices such as smartphones, and other devices capable of sending and receiving data via network 105. The client device may also include a digital assistant device that accepts audio input via a microphone and outputs audio via a speaker. When the digital assistant detects a “hot word” or “hot phrase” that activates the microphone to accept audio input, the digital assistant can be put into listening mode (e.g., ready to accept audio input). The digital assistant device may also include a camera and / or display to capture images and visually present information. The digital assistant can be implemented in various forms of hardware devices, including wearable devices (e.g., watches or glasses), smartphones, speaker devices, tablet devices, or other hardware devices. The client device may also include digital media devices, such as streaming devices that plug into a television or other display to stream video to the television.

[0048] Client device 110 typically includes applications 112, such as web browsers and / or native applications, to facilitate the sending and receiving of data over network 105. Native applications are applications developed for a specific platform or device (e.g., a mobile device with a specific operating system). Publisher 140 is able to develop and provide native applications to client device 110, for example, for download. For example, in response to a user of client device 110 entering a resource address of resource 145 in the address bar of a web browser or selecting a link referencing that resource address, the web browser is able to request resource 145 from a web server hosting website 142 of publisher 140. Similarly, native applications are able to request application content from a publisher's remote server.

[0049] Client device 110 may further include a trusted program 111. The trusted program 111 may include trusted code from a reliable source that is difficult to forge. For example, the trusted program 111 may be an operating system, part of an operating system, a web browser, etc. In some implementations, the trusted program 111 may also include a secure storage (e.g., a keystore 114) of client device 110 that can only be accessed by the trusted program 111 on client device 110.

[0050] Some resources, application pages, or other application content may include digital component slots for presenting digital components along with resource 145 or application pages. A digital component slot may be a digital component tag embedded in the resource that includes computer-readable code for requesting the digital component. As used throughout this document, the phrase "digital component" refers to a discrete unit of digital content or digital information (e.g., a video clip, audio clip, multimedia clip, image, text, or other content unit). Digital components may be stored electronically on a physical storage device as a single file or as a collection of files, and may take the form of a video file, audio file, multimedia file, image file, or text file and include notification information, such that a notification is a type of digital component. For example, a digital component may be content designed to complement the content of a webpage or other resource presented by application 112. More specifically, a digital component may include digital content related to the resource content (e.g., a digital component may relate to the same topic as the webpage content, or to a related topic). Thus, the provision of digital components can complement and generally enhance webpage or application content.

[0051] When application 112 loads resources (or application content) that include one or more digital component slots, application 112 can request digital components for each slot. In some implementations, the digital component slots can include code (e.g., scripts) that enables application 112 to request digital components to be presented to the user of client device 110.

[0052] Some publishers 140 use SSP 150 to manage the process of acquiring digital components for their resource 145 and / or application's digital component slots. SSP 150 is a technology platform implemented in hardware and / or software to automate the process of acquiring digital components for resources and / or applications. SSP 150 can interact with one or more DSPs 160 to obtain information that can be used to select digital components for digital component slots. Each publisher 140 can have a corresponding SSP 150 or multiple SSPs 150. Multiple publishers 140 can use the same SSP 150.

[0053] Digital component provider 170 is capable of creating (or otherwise distributing) digital components that are presented in digital component slots within the publisher's resources and applications. Digital component provider 170 can use DSP 160 to manage the supply of its digital components for presentation in the digital component slots. DSP 160 is a hardware and / or software-implemented technology platform that automates the process of distributing digital components for presentation with resources and / or applications. DSP 160 is capable of interacting on behalf of digital component provider 170 with multiple SSPs 150 to provide digital components for presentation with resources and / or applications from multiple different publishers 140. Typically, DSP 160 is capable of (e.g., directly from SSP 150 or through exchange) receiving requests for digital components, generating (or selecting) selection parameters for one or more digital components created by one or more digital component providers based on the requests, and providing SSP 150 with data related to the digital components (e.g., the digital components themselves) and the selection parameters.

[0054] In some cases, receiving digital components based on user interests is beneficial to the user. Some publishers 140 require users to subscribe to their website 142 or provide subscription information to download publisher 140's native application. In other cases, publisher 140 is able to offer subscribers additional services or features not provided to non-subscribers. To subscribe, users typically provide publisher 140 with a PII such as an email address or phone number, for example, via publisher 140's website 142 or application 112.

[0055] Typically, the code in the digital component slot of the publisher's resource 145 can send third-party cookies with requests for digital components. For example, suppose a user navigates to a website published by publisher 140 that provides news articles and other digital components from one or more DSPs 160-1…160-N. To receive the news articles, the user subscribes to the website using their email address. To provide the user with customized digital components, the code is able to provide a third-party cookie (which may be associated with user-related data such as browsing history) to SSP 150, which in turn can provide a third-party cookie to DSP 160. Since not all parties with access to user data are verified and / or trusted, this user data can be used for malicious activities by unverified and / or untrusted parties, and the user has little or no visibility into which entities receive the data or how such data is used. Instead, the user may have to delete various cookies from client device 110, for example, on their website or block recipients individually.

[0056] To protect user privacy and manage the security of user data, environment 100 includes one or more data security systems 180 that enable users to manage which entities receive their data, which entities are allowed to store their data, which entities are allowed to use their data, and / or for what duration entities are allowed to use their data. Other data privacy and / or user consent settings are also possible. Each data security system 180 is capable of managing the security and privacy of user data for a set of users. In some implementations, each data security system 180 is managed by an email provider, for example, a free email provider that offers users free email accounts. In this example, each email provider may include a data security system 180 that enables users with email accounts with the email provider to limit and adjust data privacy settings and issue subscription tokens based on the data privacy settings.

[0057] Environment 100 may include a data security system 180 for each participating email provider (e.g., each email provider participating in a data privacy protection program), as referenced below. Figure 2 As described. Furthermore, environment 100 can include a data security system 180 that enables users with email addresses from non-participating email providers or without email addresses to manage their user privacy settings. In some implementations, environment 100 can include a single (or multiple) data security systems 180 managed by a trusted party—such as an industry group or government agency.

[0058] Typically, data security system 180 can use subscription tokens to manage the security and privacy of user data. For each user, data security system 180 can issue a subscription token to an eligible publisher who requests a subscription token from data security system 180. An eligible publisher can be a publisher that the user has already subscribed to, for example, to receive the publisher's content. For example, as described below, when a user subscribes to a publisher, the publisher can request the user's subscription token from data security system 180. This request can indicate that the user has already subscribed to the publisher and can include the user's email address (or other PII used for subscription, for example, if data security system 180 is not an email provider). Unless or until the user indicates to data security system 180 that the user has not subscribed to the publisher, data security system 180 can change the subscription token for the publisher, as described in more detail below.

[0059] In some implementations, the data security system 180 can provide a user interface with interactive controls that enable users to manage user privacy settings across the entire (or at least a portion) online ecosystem. For example, the user interface could be a website or native application that presents the user with a list of all of the user's current (active) or past (expired) subscriptions. In a particular example, the user interface could include a list of publishers the user has subscribed to. In another example, the list could also include content platforms that select and / or provide digital components for presentation with the publisher's content. For each publisher, the list could include each content platform with which the publisher collaborates to obtain digital components for presentation with the publisher's content. In this way, the user has a transparent view of which online entities directly or indirectly provide the user with digital content and / or digital components and / or have access to the user's data. The user can use the user interface to identify any fraudulent subscriptions to the data security system 180, such as publishers the user has not subscribed to but from which the publisher has requested a subscription token, or publishers with which the user has unsubscribed because these publishers will be included in the user interface. The user interface can also include interactive controls, such as buttons or selectors, that allow the user to designate subscribers as fraudulent or unsubscribed, or to designate fraudulent or unsubscribed publishers as subscribed (e.g., qualified) publishers. In this way, the user has control over which publishers the data security system 180 provides subscription tokens to, and is therefore able to send subscription tokens to content platforms (e.g., SSP 150 and DSP 160) for use in selecting digital components based on the user's user data.

[0060] The user interface can also provide a list of content platforms, such as SSP 150, DSP 160, and digital component providers 170. For example, the user interface can include a list of eligible content platforms that are qualified to receive a user's subscription token. The user interface can include interactive controls, such as buttons or selectors, that allow the user to specify a content platform as eligible or unqualified (e.g., unable to receive a subscription token, and therefore not allowed to receive, store, or use the user's data). Initially, when a user subscribes to a publisher, the content platforms associated with the publisher can be added as eligible content platforms for that user. For example, a publisher can have a set of SSPs 150 that manage to obtain digital components for presentation with the publisher's content. In this example, after the user subscribes to the publisher, initially, this set of SSPs 150 can be added as eligible content platforms. Subsequently, the user can use the user interface to specify a content platform as unqualified.

[0061] In some implementations, the user interface enables users to specify which user data each entity (e.g., publisher, content platform, or digital component provider) can receive, how the data can be used by each entity, and / or for how long the data can be stored and used. For example, for each entity, the user interface can include a set of options regarding how the data is used. Users can select zero or more options for each eligible entity.

[0062] The data security system 180, which manages the security and privacy of user data, is capable of maintaining users' current data privacy settings and recording historical data privacy settings for users. Data privacy settings can include data instructing qualified and unqualified publishers, content platforms, and digital component providers 170, as well as the corresponding settings for each of these entities.

[0063] In some implementations, the data security system 180 can provide the client device 110 with an application 113 that provides a user interface and interactive controls 116 for viewing and / or managing user subscriptions and data privacy settings. In some implementations, the data security system 180 can provide a user interface within a browser, for example, as part of a webpage.

[0064] As an example, suppose a user navigates to website 142 of publisher 140, which provides news articles. The user subscribes to website 142 by providing a User Identity Information (PII) such as an email address or phone number. After receiving the PII from the user, publisher 140 is able to contact data security system 180 to notify the user with that specific PII that they have subscribed to website 142. In response, data security system 180 may contact the user (e.g., by sending an email or a Short Message Service (SMS) text message to the user's device) to prompt the user with a link to data security system 180's website, from which the user can view and verify their recent subscriptions to website 142, manage other subscriptions, and adjust data privacy settings.

[0065] In some implementations, the data security system 180 is a technology platform implemented in hardware and / or software, provided by the user's email address provider or by any trusted third-party organization. In such implementations, communication between the data security system 180 and the client device 110 can use the same network security and authentication protocols used by the email provider to offer email services to the user.

[0066] In some implementations, when a user subscribes to publisher 140's website 142 (or other content), publisher 140 is able to generate a request for a subscription token and transmit that request to data security system 180 via network 105. Data security system 180 generates a subscription token for the user and transmits the subscription token to publisher 140 via network 105.

[0067] Typically, each subscription token is specific to both the user and the publisher, and is generated by a specific data security system 180. For example, data security system 180 is capable of generating a corresponding subscription token for each eligible publisher for a user. Data security system 180 is also capable of generating a subscription token for a publisher in response to a request from the publisher. For example, a publisher can request a subscription token from a user in response to the user subscribing to the publisher, and, for example, submit a request for a replacement subscription token before the current subscription token expires.

[0068] In some implementations, each subscription token includes a dataset and a set of attachment elements. The dataset includes a first encrypted user identifier (also known as a temporary user identifier). In some implementations, the user identifier of the first encrypted user identifier is a PII used by the user to register with the publisher. For example, the user identifier could be the user's email address or phone number, depending on what PII the user used to register, and is therefore included in the request from the publisher. In some implementations, the user identifier of the first encrypted user identifier is an internal identifier of the user maintained by the data security system 180. For example, the data security system 180 can map internal identifiers to PIIs, such that the PIIs are not even included in the subscription token in encrypted form to better protect user privacy and data security.

[0069] The first encrypted user identifier can be a user's email address (or internal identifier or other PII) encrypted using an encryption key known only to the data security system 180, thereby hiding the plaintext email address from all other entities receiving the subscription token. In this way, the user's PII is hidden from entities other than the publisher 140 to prevent any malicious activity using the PII by any untrusted and / or unverified entity. In some implementations, the data security system 180 generates a new encryption key or a new random number after each predetermined time interval (e.g., 24 hours, two days, one week, etc.) to encrypt the user's email address (or internal identifier or other PII) to generate a new first encrypted user identifier.

[0070] In some implementations, the data security system 180 generates a first encrypted user identifier by encrypting the PII or internal identifier using a probabilistic symmetric encryption algorithm, such as AES128-GCM, with a key (or random number) generated after a regular time interval. For example, the data security system 180 can generate a key (or random number) every 24 hours or other suitable time period. In some implementations, the probabilistic encryption algorithm generates a unique random number for each encryption process. In this way, the first encrypted user identifier included in each user's subscription token will change, even if the same identifier is being encrypted and the data security system 180 is still able to decrypt the first encrypted identifier. By changing the encryption result in this way, an entity receiving multiple subscription tokens for a particular user will not be able to associate the multiple subscription tokens together, or cannot determine that these tokens are for the same user.

[0071] The subscription token dataset can also include the subscription token's expiration date. Each subscription token can be used for a specific time period specified by the expiration time. For example, each subscription token can be used for a day, a week, a month, or other appropriate time period. The subscription token defines which entities are eligible to receive, store, or use the user's data during that time period and / or how each entity uses the user's data during that time period. Each entity receiving the subscription token can store the subscription token as verifiable evidence that the user has authorized that entity to receive, store, and / or use the user's data during that time period.

[0072] The subscription token dataset can include a confirmation status indicating whether a user has confirmed their subscription with the publisher. For example, an consent status could indicate whether the user has logged into the data security system 180, accessed the user interface for managing data privacy settings, and confirmed their subscription to the publisher 140.

[0073] The subscription token dataset can also include user consent data indicating the user's current data privacy settings. For example, user consent data can include user consent strings indicating which content platforms, publishers, and / or other entities have or do not have the user's consent to the acquisition, storage, access, or use of the user's data. In some implementations, the subscription token further includes data encoding the user's requests to exercise consumer rights, such as user access to and / or deletion of user data, such as browsing history. For example, the subscription token can be used to request an entity to delete all user data. The subscription token dataset can also include use case-specific data, such as specific types and scope of consumer rights.

[0074] In some implementations, the subscription token dataset includes the domain of publisher 140. For example, the subscription token could include the domain of website 142 to which the user has already subscribed. In other implementations, the subscription token dataset could also include the domain of the PII provider or data security system 180 that issued the subscription token. For example, if the PII provided to website 142 is the user's email address, the email provider's domain is included in the subscription token dataset. The domain of the PII provider and / or website could be in the form of eTLD+1. eTLD+1 is the valid top-level domain (eTLD) plus one more level than a public suffix. An example eTLD+1 is "example.com", where ".com" is the top-level domain.

[0075] In some implementations, the subscription token includes an appendix element for each eligible content platform that selects and / or provides digital components for presentation alongside the content published by publisher 140. For example, publisher 140 may maintain a list of content platforms, such as SSP 150 and / or DSP 160, that interact to select and provide digital components for presentation alongside website and / or application content published by publisher 140. In one example, the list of content platforms, along with a request for a subscription token, is transmitted to data security system 180. Upon receiving the list of content platforms, data security system 180 generates an appendix element for each content platform in the list. Depending on the implementation, the subscription token may include an appendix element for each entity eligible to receive and / or use user data (e.g., in addition to the publisher to whom the subscription token was issued).

[0076] As described above, users can choose which content platforms are eligible to receive, store, and / or use their data. In this example, data security system 180 only generates and includes attachment elements for eligible content platforms. In another example, a user can disallow content platforms from obtaining or storing user data, but can allow content platforms to provide non-personalized digital components. In such an implementation, the subscription token may still include attachment elements for the content platform that include the user's consent specific to the content platform (e.g., not being allowed to provide personalized digital components). Since the content platform is not allowed to use the user's data, the attachment elements for the content platform will not contain a valid second encrypted user identifier for the user (described below), thereby preventing the content platform from associating the subscription token with the user. Alternatively, the subscription token may not include attachment elements for the content platform. In this example, the subscription token may include the user's consent specific to the content platform.

[0077] The content platform's attachment element includes a second encrypted user identifier for the user. This user identifier can vary depending on the implementation, as described below. In any implementation, the user identifier used can be encrypted such that it can be decrypted using encryption and / or decryption keys known only to the content platform (and, if necessary, the data security system 180). In this way, each content platform can only decrypt its corresponding attachment element to obtain the plaintext value of the user identifier. This user identifier enables qualified content platforms to associate multiple subscription tokens with the same user identifier, similar to how first-party or third-party cookies can be used to associate user data.

[0078] If a content platform is later designated as unqualified by the user or the user blocks the content platform from providing personalized content, the user's subscription token will no longer include the content platform's attachment element (or will not include the content platform's second encrypted user identifier). Because the content platform will not be able to decrypt the first encrypted user identifier or any second encrypted user identifier of the attachment element, an unqualified content platform will not be able to associate any subsequent subscription tokens of the user with the user's previous subscription tokens.

[0079] In some implementations, the second encrypted user identifier in the appendix element is a hash value of the user's email address (or other PII, such as the user's phone number or a user identifier associated with a PII provided by the data security system 180) generated using an encrypted hash function such as SHA256 and then encrypted using the content platform's encryption key.

[0080] In some implementations, the second encrypted user identifier in the appendix element can be a user identifier assigned to the content platform by the data security system 180 and encrypted using the content platform's encryption key. The user identifier can be an anonymous identifier assigned to the content platform by the data security system 180. This user identifier can be fragmented or not fragmented by the receiving domain. For example, the data security system 180 can use an asymmetric key encryption algorithm to generate the public / private key pair. In this case, the user identifier can be a hash value of a public key truncated to a fixed length (e.g., 16 bytes) generated using a cryptographic hash function such as SHA256. The user identifier is then encrypted using the content platform's encryption key.

[0081] In some implementations, the data security system 180 can use an asymmetric key encryption algorithm to generate public / private key pairs for each entity associated with the data security system 180. In this case, the user identifier for a second encrypted user identifier for a particular entity can be, for example, a hash value of the public key generated for the particular entity that has been truncated to a fixed length using an encrypted hash function such as SHA256. In another example, the data security system 180 can generate public and private keys for each entity using a single private key (referred to as the master private key) and an encryption function for each user, instead of creating and storing public and private keys, thus saving data storage. For example, the private key for a particular entity can be generated using an encryption function g(master private key, field of particular entity), where the encryption function g is applied to the master private key and the field of particular entity represents the eTLD+1 of the particular entity (referred to as entity_eTLD+1). Similarly, the public key for a particular entity can be generated using an encryption function h(master private key, field of particular entity), where the encryption function h is applied to the master private key and the field of particular entity represents the eTLD+1 of the particular entity. In both cases, the user identifier of the second encrypted user identifier for a particular entity can be a hash value of a public key generated for the particular entity, truncated to a fixed length, using an encrypted hash function such as SHA256.

[0082] Content platforms such as the SSP 150, DSP 160, and digital component provider 170 can access user data to deliver customized digital components using a second encrypted user identifier, without requiring access to the user's PII. Furthermore, this allows users to reset their user identifier, for example, using a data-privacy user interface, and thus prevents association between the previous user identifier and the new user identifier.

[0083] In some implementations, each attachment element of the subscription token can also include a digital signature. This digital signature can be a digital signature of the dataset (or at least a portion of the dataset, such as a first encrypted user identifier) ​​and a second encrypted user identifier of the attachment element. That is, the data security system 180 can generate a digital signature for the attachment element by digitally signing the dataset of the subscription token and the second encrypted user identifier of the attachment element using the asymmetric private key of the data security system 180.

[0084] Each content platform can use digital signatures to verify that the content of the subscription token has not been altered after the subscription token was generated, for example, during transmission over network 105. The content platform can verify the digital signature using the asymmetric public key corresponding to the private key used to generate the signature. If any part of the subscription token's dataset or the second encrypted user identifier is altered after the digital signature is generated, the verification of the digital signature will fail.

[0085] In some implementations, the subscription token includes a digital signature generated by signing the remainder of the subscription token, which includes the dataset and all attachment elements. In this way, the subscription token comprises a single digital signature, but it can include many attachment elements. This reduces the data size of the subscription token, resulting in reduced data storage requirements and reduced network bandwidth consumption when transmitting the subscription token over network 105.

[0086] Therefore, subscription tokens allow each content platform to know whether it has consent to provide digital components to a particular user's client device. Specifically, a content platform only knows it has consent to provide digital components to a user identified by that second user identifier if it can decrypt the encrypted second user identifier of one of the attachment elements. Furthermore, it cannot decrypt the first or second user identifiers of any other content platform, and no unauthorized party can decrypt either the first or second user identifier. This helps provide enhanced security for user data. Moreover, since the subscription token includes the attachment element of each content platform, only a single subscription token (if applicable, within a given expiration time limit) needs to be used. This helps improve computational and network efficiency. This technology thus provides enhanced security for user data in a computationally and network-efficient manner. Furthermore, in embodiments where a digital signature is provided to each attachment element in the manner described, security is further enhanced because it helps to forge subscription tokens to be detected (even if parts of them—such as the encrypted first user identifier or one of the attachment elements—have been legitimately generated previously). Meanwhile, the efficiency associated with having a single subscription token is maintained. Such implementations thus further help to provide enhanced security for user data in a computationally and network-efficient manner.

[0087] In some implementations, each attachment element of the subscription token includes an identifier for the corresponding content platform. Depending on the specific implementation, the scope of the content platform identifier can vary. For example, a content platform may be issued a unique identifier different from its eTLD+1 by a data security system 180 (e.g., an email provider's), enabling each content platform to be uniquely identified within the data security system domain. In another example, one or more email providers or a central authority may jointly maintain a globally recognized registry of all content platforms and issue a unique identifier to each of the multiple content platforms, enabling each content platform to be globally identified across the Internet.

[0088] By including the content platform's identifier for each attachment element as part of the subscription token, each content platform can easily locate its corresponding attachment element and decrypt the second encrypted user identifier. This saves computational resources that would otherwise be wasted trying to decrypt the second encrypted user identifier for each attachment element until the correct second encrypted user identifier is finally decrypted.

[0089] As described above, the first encrypted user identifier changes with each encryption based on a probabilistic symmetric encryption algorithm used to encrypt the user identifier. Therefore, this first encrypted user identifier is temporary and changes with each replacement subscription token, and can be different for each publisher if it is encrypted separately for each publisher. If the first encrypted user identifier is stable over time and identical for each publisher receiving the user's subscription token, this prevents the entity from tracking the user as it would otherwise be able to. The second encrypted user identifier can be stable because attachment elements for a given content platform may not be included in every subscription token for a given user. For example, a user can be subscribed to ten different publishers. Each publisher can use a different content platform. Therefore, attachment elements for a given content platform will only be included in the subscription token of one of the ten publishers. In this example, if the first encrypted user identifier changes over time, the entity cannot be associated with subscription tokens sent to different publishers.

[0090] In some implementations, after receiving a subscription token, publisher 140 transmits the subscription token to client device 110, for example, along with publisher 140's webpage or other resources. When a user of client device 110 navigates to website 142, which includes one or more digital component slots, client device 110 generates a request for a digital component for each of the one or more digital component slots. This request, along with the subscription token, is transmitted via network 105 to a content platform such as DSP 160. Upon receiving the request for the digital component, the content platform verifies the subscription token using the digital signature of the subscription token generated by data security system 180 and the public key of data security system 180. In another example, publisher 140 (or SSP 150) is able to generate a request for a digital component and transmit it along with the subscription token via network 105 to DSP 160 (or digital component provider 170).

[0091] In some implementations, publisher 140 maintains the subscription token after receiving it. When client device 110 generates a request for a digital component for each of one or more digital component slots in website 142 and transmits it to SSP 150 via network 105, SSP 150 is able to transmit the request for the digital component along with the subscription token via network 105 to a content platform such as DSP 160 or digital component provider 170.

[0092] After verifying the subscription token via digital signature, the content platform can choose to provide or not provide the digital component to client device 110 (or publisher 140, SSP 150) based on the validity of the subscription token. For example, if the subscription token has expired, DSP 160 may not provide the digital component to the client device. In another example, if DSP 160 cannot find an attachment element associated with a DSP 160 containing a unique identifier specific to DSP 160, then that specific DSP 160 may not provide the digital component to client device 110. If the subscription token is successfully verified, the content platform can decrypt the second encrypted user identifier according to the data privacy settings of the content platform specified by the user, and use the user data corresponding to the user identifier to select the digital component.

[0093] Content platforms that receive subscription tokens can store them, for example, to verify that the platform uses user data according to the data privacy settings of the subscription token. In some cases, a content platform may receive the same subscription token multiple times before its expiration date. For example, a publisher's subscription token could be set to expire after 24 hours. In this example, a user could navigate to the publisher's website multiple times a day. Each time, a request for a digital component can be generated, including the same subscription token. Instead of storing the subscription multiple times, for example, once for each request, the content platform can store each subscription token once. The content platform can maintain an event log indicating each event in which user data was used to select a digital component, and an identifier for the subscription token that allows the content platform to use the user data for each event. In this way, data storage requirements are reduced while still providing auditable verification that the content platform is acting within the user's consent provided to the platform by the user.

[0094] Figure 2 This is a block diagram of an example environment 200 in which email provider 240 and central authority 210 manage the security and privacy of user data. In this example, the email provider 240 and default data manager 213 of the central authority perform... Figure 1 The data security system has 180 functions.

[0095] The central authorizing body 210 can be a trusted party, such as an industry association or government agency. The central authorizing body 210 can manage the use of email addresses as identifiers for protecting the security and privacy of user data throughout the online ecosystem. For example, the central authorizing body 210 can manage which email providers participate in the data privacy protection scheme. The central authorizing body 210 can maintain an email provider registry 211 identifying each email provider 240 as a participant and a content platform registry 212 identifying each content platform (e.g., SSP and DSP) as a participant. Email providers and content platforms can sign off on participation in the data privacy protection scheme with the central authorizing body. The central authorizing body 210 can remove participants who do not comply with the rules of the data privacy protection scheme, such as those who use user data in ways other than those permitted by the user, or those who use user data based on expired subscription tokens when a replacement subscription token has already been refused.

[0096] Each publisher 220 can interact with the computing system of the central authority 210 to identify which email providers 240 and content platforms are participants. For example, when a user subscribes to publisher 220 using an email address from a domain that publisher 220 has not previously encountered, publisher 220 can query the central authority 210 to determine whether the email provider 240 for that domain is participating in a data privacy protection scheme. If so, publisher 220 can request the user's subscription token from the email provider. If not, publisher 220 can request the user's subscription token from the default data manager 213. The default data manager 213 can issue subscription tokens to publisher 220 for users with email addresses from non-participating email providers or who subscribe using other PIIs—such as phone number subscriptions.

[0097] Publishers can provide subscription tokens to participant content platforms. For example, publisher 220 can provide a user's subscription token to participant content platforms 230-1 to 230-N using a request for a digital component. Publisher 220 collaborates with participant content platforms 230-1 to 230-N to obtain digital components (e.g., web pages for application content) used to be presented alongside publisher 220's content. The subscription token can include a corresponding attachment element for each of the content platforms 230-1 to 230-N. Content platforms 230-1 to 230-N can also forward the subscription token to other participant content platforms, for example, if the subscription token identifies another participant content platform or includes attachment elements with identifiers of other participant content platforms. Publisher 220 may be prohibited from forwarding the subscription token to non-participant content platforms.

[0098] Figure 3This is a swimlane diagram illustrating an example process 300 for providing digital components using a subscription token. The operation of process 300 can be implemented, for example, by a data security system 180, a client device 110, a publisher 140, and an SSP 150. The operation of process 300 can also be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operation of process 300.

[0099] In this example, a user of client device 110 uses application 112, such as a web browser, to access website 142 hosted on a web server by publisher 140. To access website 142, client device 110 is able to initiate a request to website 142, and the web server hosting website 142 is able to respond to the request by sending computer-executable instructions and / or data that initiate the rendering of a webpage (or other electronic resource) at client device 110.

[0100] The user of client device 110 navigates to website 142 (302) of publisher 140. For example, the user of client device 110 can access website 142 by specifying a reference (e.g., a URL) using application 112 (e.g., a browser).

[0101] Client device 110 generates a request for content and transmits the request to the publisher (304) via network 105. For example, after a user of client device 110 navigates to website 142, application 112 generates a request and transmits the request to the web server hosting website 142 via network 105.

[0102] Requests for digital content can be transmitted, for example, via packetized network 105, and the content request itself can be formatted as packetized data with a header and payload data. The header can specify the destination of the packet, and the payload data can include any information discussed above.

[0103] Publisher 140, such as its web server or content server, responds using content (306). For example, after receiving a request for digital content (e.g., website 142) from client device 110, the web server can respond by transmitting computer-executable instructions and data initiating the rendering of resources (e.g., web pages) of website 142 at client device 110. The response can include data related to the website, for example, transmitted via packetized network 105, and the content itself can be formatted as packetized data.

[0104] The user of client device 110 provides their PII (308) and subscribes to publisher 140 of website 142. For example, suppose the publisher is a news organization and website 142 provides news articles. The user can subscribe to website 142 of publisher 140 to receive news articles daily. The user of client device 110 can provide the user's email address (or phone number or other PII) to publisher 140 of website 142 in exchange for the service of receiving news articles.

[0105] Publisher 140 transmits a request for a subscription token to data security system 180 (310). For example, after receiving an email address from a user on client device 110, publisher 140 identifies the domain of the email address, such as the email provider of the user's email account, and transmits the request for a subscription token to the email provider's data security system 180. If the PII is not an email address or if the email provider is not a participant, publisher 140 can transmit the request to another data security system 180, such as... Figure 2 The default data manager is 213.

[0106] Data security system 180 generates a subscription token (312). Upon receiving a request for a subscription token, data security system 180 generates a subscription token for publisher 140 and user. As described above, the subscription token includes a dataset, which in particular includes a first encrypted user identifier. In some embodiments, the first encrypted user identifier is an encrypted PII or internal identifier of the user encrypted using the encryption key of data security system 180, such that no party other than data security system 180 can extract the user's plaintext email address from the subscription token.

[0107] In some implementations, the subscription token includes an attachment element for each content platform within a content platform (e.g., an SSP and / or a DSP) that manages the supply of digital components for publisher 140. Each attachment element in the subscription token is designated for use by a specific content platform. As described above, each attachment element includes a second encrypted user identifier for the user and is capable of including a digital signature generated based on a dataset of the subscription token and the second encrypted user identifier. In other examples, the subscription token includes a single digital signature generated based on a dataset of the subscription token and all attachment elements of the subscription token.

[0108] To support the authorized use of subscription tokens, the appendix includes identifiers for the respective content platforms, such as DSP 160 or digital component provider 170 that provides digital components to publisher 140. The scope of the content platform identifiers can vary depending on the implementation. For example, data security system 180 can issue unique identifiers to content platforms, enabling each content platform to be uniquely identified within the domain of the data security system. In another example, one or more email providers or a central authorizing agency can jointly maintain a globally recognized registry of all content platforms and issue unique identifiers to each of the multiple content platforms, enabling each content platform to be identified across multiple domains.

[0109] The data security system 180 transmits the subscription token to the publisher 140 (314). The publisher 140 is able to store the subscription token for use in digital components that are presented to users along with the publisher's webpage or other content.

[0110] Client device 110 transmits a request for a digital component (316) to SSP 150. For example, after subscribing to publisher 140, a user can navigate back to the publisher's website 142, for example, to view more news articles. The publisher's webpage can include one or more digital component slots, which include scripts or other code that cause client device 110 to generate and transmit requests for digital components. The script can also obtain the user's subscription token from publisher 140 (or it can be part of the webpage) and include the subscription token in the request.

[0111] Client device 110 can send requests for digital components to SSP 150 of publisher 140. For example, application 112 can generate one or more requests for digital components based on one or more digital component slots. In a particular example, application 112 can generate a request for a digital component based on the tag of the digital component slot and transmit the request to SSP 150 via network 105.

[0112] Requests for digital components can be transmitted, for example, via packetized network 105, and the component request itself can be formatted as packetized data with a header and payload data. The header can specify the destination of the packet, and the payload data can include any information discussed above.

[0113] SSP 150 can transmit requests for digital components to one or more DSPs 160. As previously described, a content platform such as digital component provider 170 can use one or more DSPs 160 to automate the process of distributing digital components for presentation with the application. Upon receiving a request, SSP 150 can interact with one or more DSPs and transmit the corresponding request for the digital component.

[0114] In some implementations, a request for a digital component can include a subscription token generated by data security system 180 and transmitted to publisher 140 and SSP 150. For example, after receiving a request for a digital component from client device 110, SSP 150 generates a request for a digital component including a subscription token and transmits it to DSP 160 via network 105. The subscription token represents the user's preferences regarding user privacy and content platforms that are allowed to provide digital components to client device 110.

[0115] In some implementations, the subscription token may include a list of content platforms that can receive the subscription token, or a list of content platforms corresponding to each attachment element. The SSP 150 can use this data to identify the DSP 160 that submits a request to it. For example, the SSP 150 can send a request to each DSP 160 identified in the subscription token, but cannot send a request to content platforms not identified in the subscription token.

[0116] The DSP 160 can select digital components based on the user's subscription token and, optionally, previously received subscription tokens. (See previous reference...) Figure 1 The subscription token represents a user's preference for a content platform that is eligible to use the user's data in the digital components selected for provision to client device 110. For example, after verifying the subscription token via a digital signature, DSP 160 can choose to provide or not provide the digital components to client device 110 (or publisher 140, SSP 150) based on the content of the authentication token. For example, DSP 160 can verify the digital signature using an asymmetric public key corresponding to the private key used by data security system 180 to generate the signature. If any part of the subscription token or the dataset of the second encrypted user identifier is altered after the digital signature is generated by data security system 180, the verification of the digital signature will fail and DSP 160 will not provide the digital components to SSP 150. In another example, if the subscription token has expired, DSP 160 will not provide the digital components to SSP 150. In another example, if a particular DSP 160 cannot find an accessory element associated with a particular DSP 160 having a unique identifier, then the particular DSP 160 will not provide digital components to the SSP150.

[0117] DSP 160 can select digital components based on multiple subscription tokens received by the user. For example, DSP 160 can decrypt a second encrypted user identifier of the DSP and use that user identifier to associate the current subscription token with previously received user data (e.g., from a previously received user's subscription token). DSP 160 can use this data, along with other data such as context data identifying publisher 140, the webpage, and information about the digital component slots on the webpage, to select one or more digital components to be presented with the webpage.

[0118] DSP 160 transmits data of one or more selected digital components to SSP 150. For example, one or more DSPs 160 selected based on a subscription token can respond to a request for a digital component from SSP 150 by transmitting one or more selected digital components or data identifying the digital component (e.g., creative elements including instructions for presenting the digital component). For each digital component, DSP 160 can also generate or select selection parameters for the digital component. DSP 160 can then transmit the selection parameters and data of the digital component to SSP 150.

[0119] SSP 150 selects a digital component (318) from the digital components identified by the DSP. For example, SSP 150 is able to select a digital component with the highest expected quantity of publisher 140, for example, based on the selection parameters of the digital component.

[0120] SSP 150 transmits the selected digital component data to client device 110 (322). For example, SSP 150 can transmit the digital component or the idea of ​​the digital component to application 112 running on client device 110 via network 105.

[0121] Application 112 presents the received digital component (324). For example, application 112 can present the digital component together with the webpage of publisher 140.

[0122] Figure 4 This is a flowchart illustrating the process 400 for generating a subscription token. The operation of process 400 can be performed, for example, by... Figure 1 The data security system 180 is used to implement this. The operation of process 400 can also be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operation of process 400. For simplicity, process 400 is based on... Figure 1 The data security system is described as 180.

[0123] A request for a subscription token for a given user is received (410). This request can include information provided by the given user when subscribing to an electronic content provider. For example, the user can navigate to a website 142 published by a publisher 140 that provides news articles. The user subscribes to the website by providing a user's PII, such as an email address. Upon receiving the user's PII, the website 142 of publisher 140 generates a request for the user's subscription token and transmits the request to the data security system 180 via network 105.

[0124] Data security system 180 generates a subscription token (420). Upon receiving a request for a subscription token, data security system 180 generates a subscription token including a first encrypted user identifier, which enables data security system 180 to associate the subscription token with a user but prevents other recipients of the subscription token from performing such association. In some embodiments, the first encrypted user identifier is the user's email address or other PII used by the subscription publisher, encrypted using an encryption key known only to data security system 180. As described above, the subscription token may further include an expiration date, confirmation status, user consent data, and / or the publisher's domain. The user consent data for each user's subscription token may indicate the user's current data privacy settings at the time the subscription token was generated.

[0125] The subscription token also includes one or more ancillary elements for each of the one or more eligible content platforms that cooperate with publisher 140 to provide digital components to publisher 140. Eligible content platforms can include only those that are participants in a data privacy protection scheme, those designated by the user as eligible (e.g., not blocked), and those that are collaborators of publisher 140 as instructed by publisher 140. Each ancillary element in the subscription token of a specific content platform includes a second encrypted user identifier generated by encrypting the PII (or cryptographically hashed PII) (e.g., the user's email address) or an anonymous identifier (different from the PII) used for subscribing to the publisher using an encryption scheme that only the specific content platform can decrypt (or optionally, data security system 180 can also decrypt). For example, the encryption scheme can be asymmetric encryption using the content platform's public key. In another example, data security system 180 and the specific content platform can create a shared key that enables data security system 180 to encrypt using a symmetric key encryption algorithm and enables the specific content platform to decrypt using a symmetric key encryption algorithm.

[0126] Each attachment element in a subscription token for a specific content platform can also include an identifier for the corresponding content platform. The scope of this identifier may vary depending on the specific implementation. In some implementations, the subscription token includes a list of content platforms in which attachment elements are included. In some implementations, each attachment element in the subscription token can also include a digital signature generated by digitally signing the dataset of the subscription token and a second encrypted user identifier of the attachment element using an asymmetric private key of a data security system.

[0127] Data security system 180 transmits subscription tokens to publisher 140 (430). For example, publisher 140 (or SSP 150) may be responsible for collecting digital components from DSP 160 (or digital component provider 170) for use in website 142 or publisher 140's applications. Subscription tokens are transmitted via network 105 to publisher 140 for distribution to SSP 150 and / or DSP 160 (or digital component provider 170). For example, publisher 140 may include a user's subscription token in the code for an electronic resource (e.g., a webpage) transmitted to the user's client device. In another example, the code for the digital component slot of the electronic resource may obtain the subscription token from publisher 140, for example, in response to code being executed by the client device. In this way, client device 110 may include the subscription token in a request for digital components transmitted from the client device to a content platform—e.g., to SSP 150 and DSP 160.

[0128] As previously described, data security system 180 can provide users of client device 110 with the ability to manage subscriptions to publisher 140 and provide access to or block (e.g., content platforms cooperating with publisher 140) user data, including PII, user browsing history, etc. In some implementations, subscription tokens have expiration dates, and publisher 140 must obtain replacement subscription tokens for each user to maintain a valid subscription token. For example, suppose a particular publisher 140 has already provided a user's subscription token to SSP 150. It is also assumed that, based on the subscription token's expiration date, the subscription token has expired (or is about to expire). In this case, publisher 140 must obtain replacement subscription tokens from data security system 180 to continue sending subscription tokens to the content platform, thereby enabling the content platform to use user data in selected digital components.

[0129] In some implementations, publisher 140 generates recurring replacement requests that are transmitted to data security system 180. For example, if a subscription token expires after 24 hours, publisher 140 can submit a request for a replacement subscription token every 24 hours. Other suitable time periods can also be used. In another example, publisher 140 can have a computing system configured to generate requests to users in response to their subscription tokens expiring within a threshold duration. Each of these requests can include a first encrypted user identifier generated by data security system 180 for the previous subscription token. Upon receiving a replacement request, data security system 180 generates a replacement subscription token for each recurring replacement request, including an updated first encrypted user identifier different from the first encrypted user identifier and the latest user consent status, and transmits the replacement subscription token to publisher 140. An example process for replacing a subscription token is referenced below. Figure 5 Further explanation.

[0130] Figure 5 This is a flowchart illustrating a process 500 for changing a subscription token. The operation of process 500 can be implemented, for example, by a data security system 180. The operation of process 500 can also be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operation of process 500.

[0131] Data security system 180 receives a replacement request (510) from the publisher's computing system. For example, suppose a user (subscriber) has subscribed to publisher 140's website 142 by providing a user's PII, such as an email address or phone number. Upon receiving the PII, publisher 140 generates a request for a subscription token and transmits it to data security system 180. Data security system 180 generates a subscription token valid for a specific time period, such as the next 24 hours or another suitable time period. In this example, the dataset in the subscription token includes an expiration date, which is 24 hours from the time the token was generated. After receiving the subscription token, publisher 140 distributes the subscription token along with the request for digital components to the registered entities that provided the digital components to publisher 140. Near the end of the expiration date (e.g., within a threshold amount of time of the expiration date), publisher 140 is able to request a replacement of the subscription token, which includes the current subscription token that is about to expire (or at least a first encrypted user identifier of the expired subscription token). The publisher can, for example, submit a request to the data security system 180 for a replacement subscription token before the current subscription token expires.

[0132] Data security system 180 generates an updated first encrypted user identifier (520). Upon receiving a replacement request including a current subscription token that is about to expire, data security system 180 uses the key used to generate the first encrypted user identifier to decrypt the first encrypted user identifier (temporary user identifier) ​​and simultaneously generates the current subscription token (or another encryption key corresponding to that key). Decrypting the first encrypted user identifier generates a plaintext user identifier, such as the user's PII or the user's internal account identifier. Data security system 180 uses the plaintext user identifier to identify the user for whom the current subscription token was generated by comparing the generated user identifier with a list of user identifiers of multiple users for whom data security system 180 has issued subscription tokens. After identifying the user and / or the user's identifier, data security system 180 uses a probabilistic symmetric encryption algorithm and a key that can be different from the key used to generate the first encrypted user identifier of the current subscription token to generate an updated first encrypted user identifier that is different from the first encrypted user identifier of the current subscription token. By changing the encryption result in this way, an entity receiving multiple subscription tokens for a particular user will not be able to associate the multiple subscription tokens together, or will not be able to determine that these tokens are for the same user based on the first encrypted user identifier. In this way, only recipients whose subscription tokens include an appendix containing a second encrypted user identifier that the recipient can decrypt can associate multiple subscription tokens of a user.

[0133] Data security system 180 generates a replacement subscription token (530). See reference... Figure 1 As described, the data security system 180 generates a replacement subscription token that includes an updated first encrypted user identifier and an updated dataset, such as an updated expiration date, updated user consent data (e.g., an updated user consent string) indicating whether one or more content platforms have or do not have user data from the user for providing digital components, etc. The updated consent settings can reflect any changes made by the user using the data privacy user interface since the previous subscription token was generated. For example, if a user blocks a specific content platform from using the user's data, the updated consent settings can reflect that change and the replacement subscription token will not include any attachments from that specific content platform.

[0134] Data security system 180 transmits the replaced subscription token to publisher 140 (540). For example, publisher 140 (or SSP 150) may be responsible for collecting digital components from DSP 160 (or digital component provider 170) for use in the digital component slots of website 142 or publisher 140's application. The replaced subscription token is transmitted via network 105 to publisher 140 for distribution to SSP 150 and / or DSP 160 (or digital component provider 170). For example, publisher 140 may include the user's replaced subscription token in the code for transmission to the user's client device in an electronic resource (e.g., a webpage). In another example, for example, in response to code being executed by the client device, the code for the digital component slot of the electronic resource may obtain the replaced subscription token from publisher 140. In this way, the client device may include the replaced subscription token in a request for digital components transmitted by the client device to the content platform—e.g., to SSP 150 and DSP 160.

[0135] In some implementations, when a user on a client device provides a PII such as an email address to a website 142 of publisher 140, a script in website 142 executing on client device 110 identifies the email provider of the corresponding email address provided by the user. In cases where the identified email provider does not implement the previously described techniques and methods (e.g., is not a participant), the script can retrieve the information from another data security platform 180—e.g., [other platform name missing]. Figure 2 The default data manager 213 requests a subscription token. In either case, the data security platform 180 is able to send an email containing a URL (or a link referencing the URL) to the website of the data security system 180, which provides a user interface for subscription and privacy settings to the user's email address to prompt the user to review the subscription and privacy settings. The URL included in the email can include a temporary user identifier, such as an email address encrypted using a probabilistic symmetric key encryption algorithm with the key of the data security system 180. After interacting with the URL, the data security system 180 provides computer-executable instructions and data of the website to the client device 110 to present the website to the user using application 112. In some implementations, a web cookie is placed in the cookie jar of application 112 to identify application 112 during any future communications with the data security system 180.

[0136] As mentioned earlier, PII (Personal Information Identity) is user-related information that can be sensitive. Unintentional sharing of such information can raise privacy concerns. Suppose a user on client device 110 navigates to a website published by a news publisher 140. To receive the news articles, the user can subscribe to the website using their phone number instead of their email address. When an email address is used, the email provider can provide authentication mechanisms to ensure the user is authentic when viewing or modifying data privacy settings. However, when a phone number is used as the PII for subscribing to a publisher, the same authentication mechanism may not exist.

[0137] After receiving the phone number of the user for subscription, publisher 140's website 142 generates a request for a subscription token and transmits the request to data security system 180 via network 105. Data security system 180 is able to send an SMS message to client device 110. In this example, client device 110 has telephone capabilities, such as cellular capabilities. For example, client device 110 can be a smartphone, tablet, laptop, or personal computer that can be accessed via network 105, which can include a cellular network or the Internet.

[0138] In some implementations, the SMS message sent by the data security system 180 to the user's client device 110 includes a resource locator, such as the URL of the data security platform 180's dashboard or website, and the user's temporary user identifier. The user's temporary user identifier is generated by the data security system 180 by encrypting the user's phone number (or the user's internal identifier) ​​using a probabilistic symmetric encryption algorithm and a key known to the data security system 180.

[0139] In some implementations, after receiving an SMS message and after the user interacts with a URL (or a link referencing the URL), the user can be redirected to an application (e.g., application 113) provided by the data security system 180 in client device 110, or redirected to the website of data security system 180 via a browser-based application (e.g., application 112) on client device 110. In either case, the user is presented with an interactive user interface to manage data privacy settings. For example, the user can designate a subscription as fraudulent, block content platforms, or specify how recipients of user data can use the data, as described above.

[0140] In some implementations, the temporary user identifier provided to client device 110 via an SMS message is stored on client device 110. For example, suppose that after interacting with a URL provided to client device 110 via an SMS message, the user is redirected to application 113 provided by a data security system 180 running on client device 110. Application 113 parses the SMS message and extracts the user's temporary user identifier and stores the temporary user identifier in client device 110. This will refer to... Figure 6 Further explanation.

[0141] Figure 6 This is a swimlane diagram illustrating an example process 600 in which a client device receives a temporary user identifier. The operation of process 600 can be implemented, for example, by the client device 110, the publisher 140's computing system, or the data security system 180. The operation of process 600 can be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operation of process 600. Although this process 600 is described in relation to downloading a webpage using a web browser, native applications can use similar processes.

[0142] The user of client device 110 navigates to website 142 (602) of publisher 140. For example, the user of client device 110 can access website 142 using browser application 112 by specifying a resource locator (e.g., URL) or by selecting a link in the search results.

[0143] Client device 110 generates a request for content and transmits the request to the publisher (604) via network 105. For example, after a user of client device 110 specifies website 142 by using a reference (e.g., a URL), application 112, i.e., a web browser running on client device 110, generates a request for digital content (i.e., website 142) and transmits it to the web server of publisher 140 hosting website 142 via network 105.

[0144] Requests for digital content can be transmitted, for example, via packetized network 105, and the content request itself can be formatted as packetized data with a header and payload data. The header can specify the destination of the packet, and the payload data can include any information discussed above.

[0145] Publisher 140, such as its web server or content server, responds using content (606). For example, after receiving a request for content (i.e., a request for website 142) from client device 110, the web server hosting website 142 can respond by transmitting computer-executable instructions and data that initiate the rendering of the webpage at client device 110. The response can include data related to the webpage transmitted, for example, via packetized network 105, and the content itself can be formatted as packetized data.

[0146] The user of client device 110 provides their phone number (608) and subscribes to publisher 140 of website 142. For example, suppose website 142 provides news articles. The user can subscribe to publisher 140 of website 142 to receive news articles daily. The user of client device 110 provides their phone number to publisher 140 of website 142 in exchange for the service of receiving news articles.

[0147] Publisher 140 transmits a token request (610) to data security system 180. For example, after receiving a phone number from a user on client device 110, publisher 140 generates a token request and sends it to data security system 180, for example... Figure 2 The default data manager is 213.

[0148] Data security system 180 transmits SMS messages to client device 110 (612). For example, data security system 180 can send SMS messages to smartphones corresponding to phone numbers, such as smartphones that have that phone number. SMS messages sent by data security system 180 to the user's client device 110 can include a resource locator (e.g., URL) of the dashboard or website of data security platform 180 and the user's temporary user identifier. The user's temporary user identifier is generated by data security system 180 by encrypting the user's phone number (or internal identifier) ​​using a probabilistic symmetric key encryption algorithm and a key known to data security system 180. Therefore, for practical purposes, the temporary user identifier is encrypted and changes over time based on the encryption algorithm used to generate the temporary user identifier. The temporary user identifier can be included as a parameter of the URL.

[0149] The user is redirected to application 113 (614). For example, after receiving an SMS and after the user interacts with a URL, the user is redirected to an application (e.g., application 113) provided by data security system 180 and installed or otherwise running on client device 110. Application 113 is able to receive information from data security system 180 about user subscriptions and privacy settings and provide a user interface to present that information to the user. Application 113 may further include controls for the user to select and manage personal subscriptions and data privacy settings.

[0150] Application 113 parses the temporary user identifier (616). After being redirected to application 113, application 113 parses the SMS message and extracts the user's temporary user identifier and stores the temporary user identifier at client device 110 (618). In some implementations, application 113 stores the temporary user identifier in the keystore 114 (or key chain) of a trusted program 111 (e.g., the operating system) of client device 110 or in other secure storage at client device 110.

[0151] When a user is redirected to application 113, provided by data security system 180, for accessing and modifying subscription settings, application 113 accesses the user's subscription data from data security system 180. In such cases, to verify that application 113 executing on client device 110 has not been compromised, the client device implements additional security measures while communicating with data security system 180. For example, application 111 can interact with trusted program 111 to generate a verification token that can be verified by data security system 180. Typically, trusted program 111 is difficult to penetrate, and malicious actors would need extremely high time and effort to tamper with trusted program 111. Furthermore, because trusted program 111 is provided and maintained by a reliable source, any vulnerabilities that arise can be addressed at the source. This will refer to... Figure 7 To further explain, users can modify their data privacy settings solely based on their phone numbers. Phone numbers are a small amount of digital data that has been uniquely assigned to a user. This provides users with increased convenience (e.g., they do not need to generate additional identifying data, such as a unique username). Furthermore, processing small amounts of digital data is computationally efficient. Additionally, the use of proof tokens and the use of encryption, digital signatures, and / or public keys in some implementations, as described, helps improve the security of user data. Therefore, a more computationally efficient and secure way to allow users to modify their data privacy settings is provided.

[0152] Figure 7This is a swimlane diagram illustrating an example process 700 for generating and providing a user interface that allows a user to adjust data privacy settings. Operation of process 700 can be implemented, for example, by a client device 110 or a data security system 180. Operation of process 700 can be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operation of process 700.

[0153] A user on client device 110 opens (e.g., launches) application 113 (702). As previously described, application 113 may be provided by data security system 180 and installed or otherwise run on client device 110. Application 113 may receive information about user subscriptions and privacy settings from data security system 180 and provide a user interface to present that information to the user. Application 113 may further include interactive controls that enable the user to select and manage personal subscriptions and privacy settings. To view subscription and privacy settings, the user opens application 113 on client device 110. Because this information may be sensitive, additional authentication technologies are used, as described below, to ensure that client device 110, application 113, and / or the user are valid and not misused.

[0154] Application 113, running on the client device, obtains a temporary user identifier (704). See previous references. Figure 6 The temporary user identifier is stored at the client device 110. For example, application 113 can store the temporary user identifier in the keystore 114 of the trusted program 111 on the client device 110 or in other secure storage at the client device 110. After initiating application 113, application 113 retrieves the temporary user identifier from the keystore 114 of the trusted program 111 on the client device 110 or from other secure storage at the client device 110. For example, application 113 can generate a request for the temporary user identifier to the trusted program 111 through one or more application programming interface (API) calls, and the trusted program 111 provides a response including the temporary user identifier.

[0155] Application 113 obtains the public key (706). In some implementations, application 113 creates a public / private key pair during installation or during its first execution on client device 110 to facilitate secure communication with data security system 180. Because application 113, executing on client device 110, generates the public / private key pair, the public key distributed to other receiving entities can be used as a unique identifier for client device 110. Typically, the public / private key pair can be used for asymmetric encryption of communication between two parties over an unverified network. For example, a sender can encrypt a plaintext message into ciphertext using a public key available to all parties. After receiving the message, the receiver can use the private key to decrypt the ciphertext to obtain the plaintext message. The private key is a key and is known only to the receiver (e.g., data security system 180). After creating the public / private key pair, application 113 securely stores the private key in the keystore 114 of a trusted program 111 on client device 110 or in other secure storage at client device 110. When a user initiates application 113, application 113 obtains the public key of client device 110, which can be stored in an insecure data storage location of client device 110.

[0156] Application 113 obtains a proof token (708) from a trusted program of client device 110. Typically, the client device is capable of generating communications, such as electronic messages or requests that include a proof token that can be used by the recipient of the communication to verify the integrity of the communication. The proof token can include a payload and a digital signature generated using a private key based on the dataset. In this way, the recipient can verify that the payload has not been modified, for example, during transmission or by an intermediary, by verifying the digital signature using the received dataset and the public key corresponding to the private key used to generate the digital signature. If trusted program 111 supports proof, trusted program 111 can generate a public / private key pair for the proof token. If not, application 113 can generate a public / private key pair for the proof token.

[0157] Payload data can include a token creation time indicating when the proof token was created, payload data, and / or one or more integrity tokens provided by one or more integrity systems. The token creation time can be a high-resolution timestamp (e.g., accurate to seconds, milliseconds, or microseconds). This timestamp allows the recipient of the proof token to ensure that the proof is not old, for example, by determining that the token creation time is within a threshold duration of the time the proof token was received.

[0158] One or more integrity tokens of the proof token indicate whether the client device 110 transmitting the proof token and / or the application 113 running on the client device 110 initiating the transmission are trustworthy. For example, the integrity token can include a determination of the trustworthiness of the client device 110 or the application 113. This enables the recipient of the proof token (data security system 180) to verify that the data comes from a trusted client device 110 and a trusted application 113, for example, and not from an emulator or a stolen device or a stolen application 113. The integrity token can be generated and digitally signed by a trusted analyzer (e.g., a third-party analyzer), enabling the recipient of the proof token to verify that the client device 110 was evaluated by the trusted analyzer and that the data in the integrity token has not been modified after it was created by the trusted analyzer.

[0159] Application 113 submits a request to trusted program 111 executing on client device 110 to generate a proof token using one or more API calls to trusted program 111. The proof token includes a temporary user identifier (which is the encrypted result of encrypting the user's identifier as described above) and the public key of client device 110 as payload data. That is, the temporary user identifier and the public key of client device 110 can be included in the payload data of the proof token. Trusted program 111 generates the proof token and provides it to application 113. The proof token can include payload data, one or more integrity tokens, a digital signature of the payload data, the integrity token, and other data included in the proof token, such as a token creation timestamp and the temporary user identifier. In some implementations, trusted program 111 uses the Elliptic Curve Digital Signature Algorithm (ECDSA) to generate the digital signature, but other signature techniques (e.g., RSA) can also be used.

[0160] Application 113 generates a request for user subscription information (710). After obtaining the temporary user identifier, public key, and proof token, application 113 generates a request for user subscription information and transmits it to data security system 180. The request includes a proof token that can include the temporary user identifier and public key as payload data. In some implementations, the temporary user identifier, public key, and proof token are encrypted using the public key of data security system 180, for example, by encrypting the proof token that includes the temporary user identifier and public key. As mentioned above, the proof token can include a digital signature of other data of the proof token, such as the temporary user identifier, public key, token creation timestamp, and any integrity token. The request for user subscription data can be transmitted, for example, via packetized network 105, and the content request itself can be formatted as packetized data with a header and payload data. The header can specify the destination of the packet, and the payload data can include any information discussed above.

[0161] Data security system 180 verifies the temporary user identifier (712). Upon receiving a request for user subscription information, data security system 180 can verify the temporary user identifier by attempting to decrypt it using a key known only to data security system 180. If data security system 180 successfully decrypts the temporary user identifier, it can determine that the temporary user identifier has been successfully verified. If not, it can determine that the temporary user identifier has not been verified.

[0162] Data security system 180 verifies the proof token (714). To verify that the payload data has not been tampered with and that the sender of the request for user subscription information is application 113, data security system 180 verifies the proof token included in the request for user subscription information. For example, data security system 180 can verify the proof token using the token creation time (e.g., by ensuring the token creation time is within a threshold duration of the current time), the digital signature (using the public key of the proof token), and / or the integrity token included in the proof token. Verification of each integrity token can be similar to the way the proof token is verified (e.g., based on the digital signature of the integrity token and the token creation timestamp of the integrity token). In some implementations, all three verifications are performed, but in other implementations fewer verifications can be performed. Furthermore, verifications can be performed in different orders or in parallel.

[0163] Data security system 180 verifies the association (716) between the temporary user identifier and the public key of the public / private key pair generated by application 113 for secure communication with data security system 180. After verifying the temporary user identifier, data security system 180 is able to authenticate client device 110 to prevent any possible impersonation. For example, data security system 180 can look up the history of the client device 110's phone number and its association with the public key of the proof token to verify whether the client device 110 has been associated with a past public key, such as being linked to a past public key. For example, data security system 180 can maintain a log that, for each successfully verified proof token, links the proof token's public key to the proof token's temporary user identifier. If so, the current public key was previously linked to the temporary user identifier, as reflected in the log, and data security system 180 can determine that the temporary user identifier was successfully verified.

[0164] If not, data security system 180 can send an SMS message to client device 110 containing a code that the user can enter on application 113, or application 113 can automatically extract from the SMS message to verify that the request for subscription information was initiated by the user from client device 110. In another example, the SMS message can include a URL that can redirect the user to the website of data security system 180 to verify the user's authenticity. This provides additional security to ensure that the new public key is associated with a temporary user identifier and therefore belongs to client device 110. Data security system 180 can send this SMS message in the event of any verification failure.

[0165] Data security system 180 prepares a response (718) to a request for a user subscription token. After verifying the authenticity of the application 113 running on client device 110, the user of client device 110, and the request for user subscription information, data security system 180 generates a response that includes information required by application 113 to be presented to the client. For example, data security system 180 may be able to extract data from a secure and encrypted user database maintained by data security system 180.

[0166] Data security system 180 encrypts the response before transmitting it to application 113 (720). Data security system 180 uses the public key of the public / private key pair of application 113 or the public key of client device 110, such as embedded in a proof token, to encrypt the user subscription information into ciphertext, so that only application 113, which is executed on client device 110, can use the private key to decrypt the ciphertext and access the plaintext user subscription information.

[0167] Data security system 180 transmits user subscription information to application 110 (722). For example, encrypted user information is transmitted from data security system 180 to application 113 running on client device 110 to be presented to the user via packetized network 105, and the content itself can be formatted as packetized data with header and payload data. The header can specify the destination of the packet, and the payload data can include any information discussed above. The user subscription information can include the user's data privacy settings, which can include a list of publishers that have requested the user's subscription token, for example, in response to the user's subscription publisher.

[0168] Upon receiving a response containing encrypted user subscription data, application 113, executed on client device 110, uses a private key to decrypt the data into plaintext (724) and presents the plaintext user subscription data to the user of client device 110 (726).

[0169] As previously mentioned, application 113 can further include interactive controls for users to select and manage personal subscriptions and privacy settings. This is mentioned in the previous reference. Figure 8 An explanation was provided.

[0170] Figure 8 This is a swimlane diagram illustrating an example process 800 for modifying data privacy settings. The operation of process 800 can be implemented, for example, by a client device 110, a content platform, and a data security system 180. The operation of process 800 can be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operation of process 800. For illustrative purposes, process 800 will be described with reference to an example scenario in which a user of the client device interacts with application 113 to select one or more content platforms and provides instructions to delete user data from the selected one or more content platforms via a user interface of application 112.

[0171] A user of client device 110 interacts with application 113 to delete user data from one or more content platforms (802). As previously described, application 113 is provided by data security system 180 and is installed or otherwise runs on client device 110. Application 113 is able to receive information about a user's subscription, including data privacy settings, from data security system 180 and provide a user interface to present that information to the user. Application 113 may further include interactive controls for the user to select and modify personal subscriptions and privacy settings. For example, a user opens application 113 on client device 110, views the current subscription and privacy settings via example process 700, and is provided with instructions to delete user data from one or more selected content platforms via the user interface. While this example is based on deleting user data at a DSP, similar processes can be used to perform other modifications, such as how user data is used by the DSP. Therefore, more generally, requests to delete user data (810) and (820) may be requests to modify data privacy settings of one or more entities (e.g., content platforms), deletion of user data (822) may be a modification of data privacy settings, and confirmation (824) may be confirmation of the modification of data privacy settings.

[0172] Application 113, running on the client device, obtains a temporary user identifier (804). See previous references. Figure 6The temporary user identifier is stored at the client device 110. For example, after receiving the temporary user identifier, the client device 110 can securely store the identifier in the keystore 114 of its trusted program 111. After initiating application 113, application 113 obtains the temporary user identifier from the trusted program 111 of the client device 110. For example, application 113 can generate a request for the temporary user identifier, and the trusted program 111 provides a response to the request including the temporary user identifier. As described above, the temporary user identifier is an encrypted result generated by encrypting the user's user identifier (e.g., phone number, email address, or internal identifier).

[0173] Application 113 obtains the public key (806). As described above, application 113 creates a public / private key pair during installation or during its first execution on client device 110 for secure communication with data security system 180. After creating the public / private key pair, application 113 securely stores the private key in the keystore 114 of trusted program 111 on client device 110 or in other secure storage on client device 110. When a user initiates application 113, application 113 obtains the public key of client device 110, for example, from another insecure data storage location on client device 110.

[0174] Application 113 obtains a proof token (808) from trusted program 111 of client device 110. Similar to step 708 of process 700, application 113 submits a request to trusted program 111, which executes within client device 110, to generate a proof token using one or more API calls to trusted program 111 as payload data, including a temporary user identifier and application 113's public key. Trusted program 111 generates the proof token and provides it to application 113. The proof token can include payload data and a digital signature of the payload data. In some implementations, trusted program 111 uses the Elliptic Curve Digital Signature Algorithm (ECDSA) to generate the digital signature, but other signature techniques (e.g., RSA) can also be used.

[0175] Application 113 generates a request to delete user data (810). After obtaining a temporary user identifier, public key, and authentication token, application 113 generates a request to delete user data and transmits it to data security system 180. The request includes the temporary user identifier, public key, and authentication token. The request to delete user data may also include a list of one or more content platforms or DSPs 160 for deleting user data selected by the user via a user interface. The request to delete user data may be transmitted, for example, via packetized network 105, and the content request itself may be formatted as packetized data with a header and payload data. The header may specify the destination of the packet, and the payload data may include any information discussed above.

[0176] Data security system 180 verifies the temporary user identifier (812). Upon receiving a request to delete user data, data security system 180 can verify the temporary user identifier (812) as described above. Figure 7 The same method described is used to verify temporary user identifiers.

[0177] Data security system 180 verifies the proof token (814). For example, data security system 180 can verify the proof token using the token creation time, digital signature, and / or integrity token included in the proof token, as referenced above. Figure 7 As described.

[0178] The data security system 180 verifies the association between the temporary user identifier and the public key (816). For example, as referenced above. Figure 7 As described, data security system 180 can look up the history of the phone number of client device 110 and its association with the public key of the authentication token to verify whether client device 110 is actually associated with the public key. In another example, data security system 180 can send an SMS message to client device 110 containing a code that a user can enter on application 113, or application 113 can read the SMS message to extract the code to verify that the request for subscription information was initiated by the user from client device 110. In yet another example, the SMS message can include a URL that can redirect the user to the website of data security system 180 to verify the user's authenticity.

[0179] Data security system 180 stores a proof token (818). The data security system is capable of maintaining a log for each request received from client device 110 to modify user subscription / privacy settings. For example, data security system 180 can store a proof token included in a request to delete user data, enabling auditing to check whether all entities associated with the user of client device 110 and data security system 180 comply with the protocol set by the user and data security system 180. In some implementations, data security system 180 can remove attachment elements of the proof token to save storage space within data security system 180.

[0180] Data security system 180 transmits a request to delete user data to the content platform (820) to which the user requested the deletion. For example, after authenticating the request to delete user data and client device 110, data security system 180 can transmit the request to delete user data to each of one or more content platforms selected and associated with data security system 180. If the request is to modify data privacy settings, the request can instead specify the requested modification.

[0181] Content platforms delete user data (822). In response to receiving a request to delete user data transmitted by data security system 180, one or more selected content platforms delete the user data of the user identified by a second user identifier included in the request to delete user data. The content platforms are able to store a proof token along with data describing the event—such as a data deletion event. If the event is a modification of data privacy settings, such as granting the content platform permission to use the user data, the proof token can be used as cryptographically verifiable evidence that the content platform is authorized to use the user data.

[0182] Data security system 180 receives confirmation (824) from the content platforms. In response to the deletion of user data by each of the selected one or more content platforms, each of the selected one or more content platforms transmits an confirmation notification to data security system 180 via network 105. Data security system 180, in turn, transmits confirmation (826) to application 113 of client device 105 to notify the user that the user's request has been processed. In some embodiments, application 113 may transmit the request to delete user data directly to one or more DSPs 160.

[0183] In some implementations, when the user of client device 110 does not have access to application 113 (e.g., when application 113 is not installed on client device 110), the user can use browser-based application 112 to access a website provided by data security system 180 and perform all the tasks described above. This scenario is referenced... Figure 9 Further explanation.

[0184] Figure 9 This is a swimlane diagram illustrating an example process 900 for generating and providing a user interface that enables users to adjust data privacy settings using a browser application. Operation of process 900 can be implemented, for example, by a client device 110 or a data security system 180. Operation of process 900 can be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operation of process 900.

[0185] Data security system 180 sends an SMS message (902) to client device 110. For example, suppose a user of client device 110 uses browser application 112 to navigate to website 142 of publisher 140. Further suppose the user provides their phone number to subscribe to publisher 140. In such a scenario, publisher 140 will notify data security system 180, which will then send an SMS message to client device 110 to which the phone number belongs. In some implementations, the SMS message sent by data security system 180 to the user's client device 110 includes a resource locator, such as the URL of the dashboard or website of data security platform 180, and an encrypted temporary user identifier for the user. The temporary user identifier is generated by data security system 180 by encrypting the user's phone number using a probabilistic symmetric key encryption algorithm and a key known only to data security system 180.

[0186] An SMS message is notified to the user of the client device (904), and the user interacts with the SMS message (906). For example, after receiving an SMS message from the data security system 180, the user is notified of the SMS message. After being notified of the SMS message by a trusted program 111 (e.g., the operating system) of the client device 110, the user interacts with the URL provided in the SMS message and is redirected to a website provided by the data security system 180 using browser application 112 (908).

[0187] Browser application 112 generates and transmits a request for digital content (910). For example, after a user of client device 110 specifies a website by clicking a reference (e.g., a URL) in an SMS message, application 112, such as a web browser running on client device 110, generates a request for digital content (i.e., a request for the website of data security system 180) and transmits it to data security system via network 105. In some implementations, the request for digital content may include proof. In this example, the proof token may be in the form of a trust token issued by a trusted third party. For example, a trusted third party may issue a trust token to client device 110 after evaluating a fraud detection signal obtained from client device 110. In some implementations, the request for digital components may include a cookie of data security system 180 placed on client device 110 during previous communication with data security system 180.

[0188] Data security system 180 verifies the proof record (912) of the trust token. The proof record can include a signed redemption record. For example, a script or other code on a webpage can request a browser to redeem the trust token from a trusted third party. If the trust token is valid, the trusted third party can return the signed redemption record to the browser. Data security system 180 receives requests for digital content (i.e., requests to the website of data security system 180) with attached proof records. The proof record can include a dataset that includes the token identifier of the trust token, the token creation timestamp, and the signed redemption record. The proof record can also include a digital signature of the dataset generated using the private key of the trusted third party. Data security system 180 can verify the signed redemption record by verifying that the token creation time is within a threshold duration of the current time and by verifying the digital signature using the public key corresponding to the private key of the trusted third party.

[0189] Data security system 180 verifies the temporary user identifier (914). Data security system 180 uses its private key to decrypt the encrypted temporary user identifier, public key, and authentication token. Data security system 180 further verifies the temporary user identifier, public key, and authentication token using a digital signature included in the request for digital content, utilizing the public key of client device 110 or application 113. If any part of the data in the request for digital content is altered after the digital signature is generated, the verification of the digital signature will fail.

[0190] Data security system 180 verifies the cookie (916) received along with the request for the digital component. For example, assume that data security system 180 has already placed a cookie in application 112 during a previous visit to the website of data security system by browser application 112. It is also assumed that the cookie value is a temporary user identifier (which is the result of encryption as described above). After receiving the cookie included in the request for the digital component, data security system 180 verifies any signs of cookie impersonation.

[0191] Data security system 180 transmits digital content to browser application 112 (918). For example, data security system 180 can respond by transmitting computer-executable instructions and data of a website to browser application 112, which is executed on client device 110. The response can include website-related data being transmitted, such as via packetized network 105, and the content itself can be formatted as packetized data. In some embodiments, the response with digital content can also include a cookie to be placed in a cookie jar of browser application 112 to identify browser application 112 during any future communication with data security system 180. After receiving the website content, browser application 112 presents the website to the user (920).

[0192] Figure 10 This is a flowchart illustrating a process 1000 for modifying the use of user data based on modified data privacy settings using user interface controls. The operation of process 1000 can be implemented, for example, by client device 110 and / or data security system 180. The operation of process 1000 can also be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operation of process 1000.

[0193] The user interface is updated to present user interface controls (1010) that allow the user to specify data privacy settings. For example, application 113 accesses user subscription data from data security system 180. After accessing the user subscription data, application 113 presents the user subscription data to the user and provides the user with interface controls. The user interacts with the interface controls to delete user data from one or more content platforms, or modify given data privacy settings of one or more entities.

[0194] A request to modify a given data privacy setting for one or more entities is received (1020). For example, after a user selects one or more content platforms, application 113 obtains a temporary user identifier, public key, and authentication token from client device 110. The application then generates a request to update or modify the user's data privacy settings and transmits it to data security system 180.

[0195] Data security system 180 attempts to verify the request using at least a temporary user identifier (1030). For example, upon receiving a request to modify data privacy settings, data security system 180 verifies the request by verifying the temporary user identifier, a proof token (which can be in the form of a proof record with a signed redemption record), and / or the association between the temporary user identifier and the public key, as referenced above. Figure 7 and Figure 8 As described.

[0196] If the request is successfully verified, the data security system 180 transmits data instructing each of the one or more entities affected by the modified data privacy settings to modify the use of data according to the modified data privacy settings (1050). For example, after verifying a request to modify data privacy settings from client device 110, the data security system 180 can transmit a request to each affected entity to modify the collection, storage, and / or use of user data based on that entity's modified data privacy settings. This request can include the user's temporary user identifier.

[0197] If the request is not successfully verified, the data security system 180 does not transmit data (1040) instructing each of the one or more entities to modify the use of data. For example, if any verification fails, the data security system 180 does not transmit the request to modify the use of user data to the affected entity.

[0198] Figure 11 This is a block diagram of an example computer system 1100 capable of performing the operations described above. System 1100 includes a processor 1110, memory 1120, storage device 1130, and input / output device 1140. Each of components 1110, 1120, 1130, and 1140 can be interconnected, for example, using a system bus 1150. Processor 1110 is capable of processing instructions for execution within system 1100. In some embodiments, processor 1110 is a single-threaded processor. In another embodiment, processor 1110 is a multi-threaded processor. Processor 1110 is capable of processing instructions stored in memory 1120 or on storage device 1130.

[0199] Memory 1120 stores information within system 1100. In one embodiment, memory 1120 is a computer-readable medium. In some embodiments, memory 1120 is a volatile memory cell. In another embodiment, memory 1120 is a non-volatile memory cell.

[0200] Storage device 1130 provides high-capacity storage for system 500. In some embodiments, storage device 1130 is a computer-readable medium. In various embodiments, storage device 1130 may include, for example, a hard disk drive, an optical disk drive, a storage device shared by multiple computing devices over a network (e.g., a cloud storage device), or some other high-capacity storage device.

[0201] Input / output device 1140 provides input / output operations for system 1100. In some embodiments, input / output device 1140 may include one or more network interface devices, such as an Ethernet card, a serial communication device, for example, an RS-232 port, and / or a wireless interface device, for example, an 802.11 card. In another embodiment, input / output device may include a driver device configured to receive input data and send output data to an external device 1160—such as a keyboard, printer, and display device. However, other embodiments may also be used, such as mobile computing devices, mobile communication devices, set-top box television client devices, etc.

[0202] Although the example processing system already exists Figure 11 The subject matter and functional operations described herein can be implemented in other types of digital electronic circuits or in computer software, firmware, or hardware—including the structures disclosed herein and their equivalents—or combinations thereof.

[0203] The embodiments of the subject matter and operation described in this specification can be implemented in digital electronic circuits or in computer software, firmware, or hardware—including the structures disclosed in this specification and their structural equivalents—or combinations thereof. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs encoded on a computer storage medium (or media) for execution by or control of the operation of a data processing device, i.e., one or more modules of computer program instructions. Alternatively or additionally, the program instructions can be encoded on artificially generated propagating signals, such as machine-generated electrical, optical, or electromagnetic signals, which are generated to encode information for transmission to a suitable receiver device for execution by the data processing device. The computer storage medium can be a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or combinations thereof, or be included in a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or combinations thereof. Furthermore, although the computer storage medium is not a propagating signal, it can be a source or destination of computer program instructions encoded in artificially generated propagating signals. Computer storage media can also be or be included in one or more separate physical components or media (e.g., multiple CDs, disks or other storage devices).

[0204] The operations described in this specification can be implemented as operations performed by a data processing device on data stored on one or more computer-readable storage devices or received from other sources.

[0205] The term "data processing apparatus" encompasses all kinds of devices, apparatuses, and machines used for processing data, including, for example, programmable processors, computers, systems-on-a-chip, or a combination thereof. Apparatus can include special-purpose logic circuitry, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits). In addition to hardware, apparatus can also include code that creates an execution environment for the computer program in question, such as code constituting processor firmware, protocol stacks, database management systems, operating systems, cross-platform runtime environments, virtual machines, or combinations thereof. Apparatus and execution environments can implement a variety of different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.

[0206] A computer program (also known as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and can be deployed in any form, including as a standalone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may, but does not need to, correspond to a file in a file system. A program can be stored as part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), a single file dedicated to the program in question, or multiple co-located files (e.g., a file storing one or more modules, subroutines, or code sections). A computer program can be deployed to execute on a single computer, at a single site, or distributed across multiple sites and interconnected via a communication network.

[0207] The processes and logic flows described in this specification can be accomplished by one or more programmable processors executing one or more computer programs to perform actions by manipulating input data and generating output. The processes and logic flows can also be executed by dedicated logic circuits, and the devices can be implemented as dedicated logic circuits, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits).

[0208] Processors suitable for executing computer programs include, for example, both general-purpose microprocessors and special-purpose microprocessors. Typically, a processor receives instructions and data from read-only memory or random access memory, or both. The basic components of a computer are a processor for performing actions according to instructions and one or more memory devices for storing instructions and data. Typically, a computer will also include, or be operatively coupled to, receiving data from or transferring data to, or both to, one or more mass storage devices (e.g., hard disks, magneto-optical disks, or optical disks) for storing data. However, a computer does not need to have such devices. Furthermore, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device (e.g., a universal serial bus (USB) flash drive), to name a few. Devices suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and storage devices, including, for example, semiconductor memory devices such as EPROM, EEPROM, and flash memory devices; hard disks, such as internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. Processors and memory can be supplemented by dedicated logic circuits or incorporated into dedicated logic circuits.

[0209] To provide interaction with the user, embodiments of the subject matter described in this specification can be implemented on a computer having a display device for displaying information to the user, such as a CRT (cathode ray tube) or LCD (liquid crystal display) monitor, and a keyboard and pointing device, such as a mouse or trackball, through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback; and input from the user can be received in any form, including sound, speech, or tactile input. Furthermore, the computer can interact with the user by sending documents to and receiving documents from the device used by the user; for example, by sending web pages to a web browser on the user's client device in response to a request received from a web browser.

[0210] Embodiments of the subject matter described in this specification can be implemented in a computing system that includes back-end components, such as a data server, or middleware components, such as an application server, or front-end components, such as a client computer having a graphical user interface or web browser that a user can interact with through embodiments of the subject matter described in this specification, or any combination of one or more such back-end components, middleware components, or front-end components. The components of the system can be interconnected via digital data communication (e.g., a communication network) of any form or medium. Examples of communication networks include local area networks (“LANs”) and wide area networks (“WANs”), interconnected networks (e.g., the Internet) and peer-to-peer networks (e.g., self-organizing peer-to-peer networks).

[0211] A computing system can include clients and servers. Clients and servers are generally geographically separated and typically interact via a communication network. The client-server relationship is established by computer programs running on respective computers and having a client-server relationship with each other. In some embodiments, the server transmits data (e.g., HTML pages) to the client device (e.g., to display data to a user interacting with the client device and to receive user input from the user interacting with the client device). Data generated at the client device (e.g., the result of user interaction) can be received from the client device at the server.

[0212] Although this specification contains numerous specific implementation details, these should not be construed as limiting the scope of any invention or what may be claimed, but rather as descriptions of features specific to particular embodiments of a particular invention. Some features described in this specification within the context of individual embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented individually or in any suitable sub-combination in multiple embodiments. Furthermore, although features may be described above as functioning in certain combinations, and even initially claimed in this way, one or more features from a claimed combination can be removed from the combination in some cases, and the claimed combination may involve sub-combinations or variations thereof.

[0213] Similarly, although the operations are depicted in a specific order in the accompanying drawings, this should not be construed as requiring these operations to be performed in the specific order shown or sequentially, or that all shown operations be performed to achieve the desired result. In some cases, multitasking and parallel processing can be advantageous. Furthermore, the separation of the various system components in the above embodiments should not be construed as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.

[0214] Therefore, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the following claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired result. Furthermore, the processes described in the drawings do not necessarily require the specific order or sequence shown to achieve the desired result. In some embodiments, multitasking and parallel processing can be advantageous.

[0215] The content that needs protection is...

Claims

1. A computer-implemented method comprising: generating a temporary user identifier by encrypting a phone number of a user; transmitting a message to a client device addressed by the phone number, the message including (i) the temporary user identifier encrypting the phone number and (ii) a resource locator referencing an electronic resource; updating a user interface of the client device to present a user interface control enabling a user to specify data privacy settings, the user interface control qualifying how entities collect, store, and use data of the user; receiving, from the client device, a request to modify data privacy settings of one or more entities based on user interaction with one or more of the user interface controls, the request including the temporary user identifier received from the message and an attestation token; validating the request using at least the temporary user identifier and the attestation token of the user; and in response to validating the request, transmitting data to each particular entity of the one or more entities indicating that the particular entity modify use of data of the user based on a given data privacy setting as modified.

2. The computer-implemented method of claim 1, further comprising, prior to updating the user interface: receiving, from a publisher, a token request requesting a subscription token of the phone number of the user; and the message further including the resource locator for the electronic resource including the user interface. wherein, 3. The computer-implemented method of claim 1, wherein: the request further includes a public key of the client device; and validating the request further includes verifying an association between the temporary user identifier and the public key of the client device. verifying the temporary user identifier includes:

4. The computer-implemented method of claim 3, wherein, attempting to decrypt the temporary user identifier; and determining that the temporary user identifier is successfully verified when the temporary user identifier is successfully decrypted.

5. The computer-implemented method of claim 1, further comprising storing the attestation token and the modified data privacy settings in an audit log.

6. The computer-implemented method of claim 1, wherein: the request includes a web cookie; and validating the request includes: decrypting the temporary user identifier; and verifying the web cookie using the temporary user identifier.

7. The computer-implemented method of any one of claims 1-6, wherein: the attestation token includes: a data set; and a digital signature of the data set; and verifying the attestation token includes determining that the digital signature is valid based on the data set.

8. The computer-implemented method of any one of claims 1-6, wherein: the attestation token includes a token creation timestamp indicating a time at which the attestation token was created; and verifying the attestation token includes determining that the time at which the attestation token was created is within a threshold duration of a time at which the request was received.

9. The computer-implemented method of any one of claims 1-6, wherein: ​ ​ ​ The attestation token includes an integrity token that includes a determination of trustworthiness of the client device or an application running on the client device; and Verifying the attestation token includes verifying the integrity token.

10. A system comprising: one or more processors; and one or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processors to perform the method of any of claims 1-9.

11. A computer-readable storage medium carrying instructions that, when executed by one or more processors, cause the one or more processors to perform the method of any of claims 1-9.

12. A computer program product comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method of any of claims 1-9.

Citation Information

Patent Citations

  • Method and system for realizing secure login

    CN105933353A

  • Share cookie on native platform in mobile device without having to ask for the user's login information

    US20130036304A1

  • Security management for cloud services

    US20150106881A1

  • Authentication and authorization protocol for secure web-based access to a protected resource

    US7478434B1