Systems and methods for protecting data across multiple users and devices

By using the data sharing licensing system in a privacy server, the challenge of service providers to protect data privacy between multiple users and devices is solved, and data sharing and different levels of sensitivity are achieved.

CN115398859BActive Publication Date: 2025-05-09JPMORGAN CHASE BANK NA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202080095355.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-12-01
Filing Date
2020-12-04
Publication Date
2025-05-09
Estimated Expiration
2040-12-04

AI Technical Summary

Technical Problem

Service providers face privacy challenges in protecting user identity and device data when processing data from multiple sources, channels, and partners.

Method used

By using a data sharing license system in a privacy server, data sharing is allowed between multiple user devices to be securely shared. The system includes receiving and transmitting data sharing licenses, encrypting data storage and transmission, and restoring data to its origin device under the license.

Benefits of technology

Data protection across multiple users and devices is realized, ensuring the secure sharing of data between multiple devices and users, and meeting the sensitivity protection needs of different data types.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115398859B_ABST
    Figure CN115398859B_ABST
Patent Text Reader

Abstract

A system and method for protecting data across multiple users and devices is disclosed. According to one embodiment, in a privacy server including at least one computer processor, a method for protecting data across multiple users and devices may include: (1) receiving a data sharing permission for a first user device and a data sharing permission for a second user device from a first user device, the first user device and the second user device being associated with the same user; (2) providing a data sharing permission for the second user device; (3) transmitting the provided data sharing permission to the second user device, wherein the second user device shares data with the first user device according to the provided data sharing permission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments generally relate to systems and methods for protecting data across multiple users and devices. Background Art

[0002] Service providers typically have access to data from multiple sources, channels, and partners. This creates a number of challenges in how data about user identities and devices that generate personal data is handled, especially in terms of protecting the privacy of such data. Summary of the invention

[0003] A system and method for protecting data across multiple users and devices is disclosed. According to one embodiment, in a privacy server including at least one computer processor, a method for protecting data across multiple users and devices may include: (1) receiving a data sharing permission for a first user device and a data sharing permission for a second user device from a first user device, the first user device and the second user device being associated with the same user; (2) providing a data sharing permission for the second user device; (3) transmitting the provided data sharing permission to the second user device, wherein the second user device shares data with the first user device according to the provided data sharing permission.

[0004] In one embodiment, the data sharing permissions may identify the type of data to be shared.

[0005] In one embodiment, the types of data may include account data, activity data, preference data, etc.

[0006] In one embodiment, a first user device may be associated with a first device key and a second user device may be associated with a second device key, and the second device may be identified to the privacy server via the second device key.

[0007] In one embodiment, the method may further include receiving encrypted data from the first user device or the second user device; and storing the encrypted data according to the data sharing permission.

[0008] In one embodiment, the method may further include transmitting the encrypted data to the first user device or the second user device according to the data sharing permission.

[0009] In one embodiment, the method may further include restoring the encrypted data to the same user device from which it originated.

[0010] According to another embodiment, in a privacy server including at least one computer processor, a method for sharing data between devices associated with multiple users may include: (1) receiving a registration of a first user from a first privacy application executed on a first electronic device, wherein the registration may include an identification of the first user device and an identification of a data owner for data on the first user device; (2) receiving data sharing preferences of the first user from the first privacy application; (3) saving the data sharing preferences of the first user; (4) receiving a registration of a second user from a second privacy application executed on a second electronic device, wherein the registration may include an identification of the second user device and an identification of a data owner for data on the second user device; (5) receiving a request from the second user to share data with the first user from the first privacy application; (6) transmitting the request to the second privacy application; (7) receiving a response to the request from the second privacy application, wherein the response approves or denies the request; (8) configuring data sharing permissions for the first device and the second device; and (9) transmitting the data sharing permissions to the first privacy application and the second privacy application, wherein at least one of the first privacy application and the second privacy application updates the data sharing permissions on the corresponding devices.

[0011] In one embodiment, the second user's request to share data with the first user may identify the type of data to be shared.

[0012] In one embodiment, the types of data may include account data, activity data, preference data, etc.

[0013] In one embodiment, the method may further include receiving encrypted data from the first user device or the second user device; and storing the encrypted data in accordance with the data sharing permission.

[0014] In one embodiment, the method may further include transmitting the encrypted data to the first user device or the second user device according to the data sharing permission.

[0015] According to another embodiment, in a privacy server including at least one computer processor, a method for sharing data between devices associated with multiple users may include: (1) receiving a registration of a first user from a first privacy application executed on a first electronic device, wherein the registration may include an identification of the first user device and an identification of a data owner for data on the first user device; (2) receiving a data sharing preference of the first user from the first privacy application; (3) saving the data sharing preference of the first user; (4) receiving a registration of a second user from a second privacy application executed on a second electronic device, wherein the registration may include an identification of the second user device and an identification of a data owner for data on the second user device; (5) receiving a request from the second privacy application to share data with the first user; (6) configuring data sharing permissions for the first device and the second device; and (7) transmitting the data sharing permissions to the first privacy application and the second privacy application, wherein at least one of the first privacy application and the second privacy application updates the data sharing permissions on the corresponding devices.

[0016] In one embodiment, the second user's request to share data with the first user may identify the type of data to be shared.

[0017] In one embodiment, the types of data may include account data, activity data, preference data, etc.

[0018] In one embodiment, the method may further include receiving encrypted data from the first user device or the second user device; and storing the encrypted data according to the data sharing permission. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] For a more complete understanding of the present invention, its objects and advantages, reference is now made to the following description in conjunction with the accompanying drawings, in which:

[0020] Figure 1 A system for protecting data across multiple users and devices according to one embodiment is depicted;

[0021] Figure 2 depicts a personnel-level data view according to one embodiment;

[0022] Figure 3 depicts an exemplary device level view according to one embodiment;

[0023] Figure 4 depicts a diagram of sharing permissions with a group according to one embodiment;

[0024] Figure 5 A method for setting sharing permissions according to one embodiment is described; and

[0025] Figure 6A method for sharing data among multiple users according to one embodiment is described. DETAILED DESCRIPTION

[0026] Embodiments are directed to systems and methods for protecting data across multiple users and devices.

[0027] An embodiment may segment user data in a "personal data realm," which enables aggregation of data from devices that the owner may use. An embodiment may include a permission system for each device that allows the user to set access permissions for the data. Personal data and permissions may be stored (e.g., as a copy) on each device and may be encrypted. The provider's servers may act as a system of record and may store permission settings and encrypted data belonging to the user for all owned devices.

[0028] In an embodiment, the user's data may be encrypted with a key known only to the user; thus, the content is protected from being compromised by the provider's servers.

[0029] In one embodiment, permissions may allow segmentation of data, where different sharing (eg, access) permissions may be set for different types of data.

[0030] Embodiments may provide some or all of the following: (1) data sharing and protection between multiple devices that a user may own; (2) data sharing between multiple users (such as a family or circle of related people); (3) data protection at rest and in transit; (4) flexible protection of different levels of data sensitivity; (5) flexible protection of different levels of data sharing based on the trust or relationship between the owner and others; and (6) allowing data to be migrated from one device to another or in the event of data loss on a device (retrieval of data from a server).

[0031] In an embodiment, personal data (e.g., private data) is considered to be associated with a person and may be aggregated from data from devices that the person may own and / or control. The owner of the data may have overriding power to set permissions for content shared with any other entity or device. The privacy service provider may retain data and share data strictly in accordance with the permission settings of the data owner.

[0032] refer to Figure 1 , according to one embodiment, a diagram of a data domain is provided. Figure 1 Illustrated is the personal data of person 1 (owner), which may be aggregated from multiple devices, such as device 1 and device 2. Even though person 1 may own or control device 3, the owner may choose not to aggregate data from device 3 (indicated by an "X").

[0033] Within each individual data domain (e.g., data scope for individual 1, individual 2, individual 3, etc.), the owner of the data (e.g., individual 1, individual 2, individual 3) decides whether to aggregate the data and behavior of each device. Data on unaggregated devices may be analyzed separately. Such analysis does not combine data on unaggregated devices with data from any other device, any other person, or any other source.

[0034] Each person can have a key, such as PerKey (personal key) 1, PerKey2, PerKey3, and each device can have a key, such as DevKey (device key) 1, DevKey2, DevKey3.

[0035] Individual 2 and Individual 3 may also have multiple devices, and data may be aggregated from their devices, as shown. Data may be filtered across individual data domains (e.g., from Individual 2 to the owner), but the source set is the aggregated set of all participating devices. Data owners can set sharing permissions, and such permissions can be directed (asymmetric). As shown, both Individual 2 and Individual 3 choose to share data with Individual 1. By Individual 2 granting permission to share data with Individual 1, Individual 1's data is not shared with Individual 2 without separate permission from Individual 1. Individual 2 has not decided to share data with Individual 3, and vice versa.

[0036] Figure 2 A person-level data view according to an embodiment is illustrated. Device sharing permissions may only involve allowing data from (one or more) specific devices (e.g., Device 1 232 and Device 2 234) to be shared with the privacy server 210 for the purpose of calculating the person-level data view using, for example, the calculation module 215. For any devices (e.g., Device3 236) for which the owner chooses to disable sharing, data originating from these devices may not be transmitted through the privacy server 210. Any privacy reports and scores for such devices (e.g., Device3 236) may be calculated locally on the device (e.g., Device 3 236). This means that information from other devices that support sharing (e.g., Device1 232 and Device 2 234) belonging to the same owner and other non-private information are not part of such calculations.

[0037] In one embodiment, the privacy server 210 may provide a separate cloud-based engine to compute analyses, reports, or scores based on data sets that users choose to submit for such computations. The user may instruct the privacy server 210 whether to compute on a data set alone, combine or aggregate a data set with other data, and whether to retain or delete the data set and computation results after computation.

[0038] In one embodiment, person-to-person sharing permissions may only be related to sharing of data aggregated at the person level. This means that data from a device (e.g., device 3 236) that is not shared with the privacy server 210 is not shared with another device (e.g., device 1 232 or device 2 234).

[0039] In one embodiment, the privacy server 210 may ingest non-private data such as transaction history, financial profiles, etc. from one or more non-private data sources 225 to add intelligence to the algorithms executed by the computation module 215 .

[0040] For example, the privacy server 210 may ingest data that can be used to facilitate business transactions based on the expected user experience. In another embodiment, the computing module 215 may provide data that can be used to facilitate business transactions based on the expected user experience. The disclosures of U.S. Patent Application Serial Nos. 62 / 833,417, 16 / 844,560, and 16 / 845,937 are incorporated herein by reference in their entirety.

[0041] refer to Figure 3 , an exemplary device-level view is provided according to one embodiment. Each device may include a set of permissions that may apply to different types of data (e.g., type 1, type 2, ... type n). Examples of different data types may include accounts on the device (e.g., status, qualifications, permissions, etc.), activities (e.g., a list of domains visited), and preferences (e.g., alerts, whitelists, VPNs, device fingerprint obfuscation, aliases, ratings, etc.). These data types are exemplary only, and different data types may be used as needed and / or desired.

[0042] Each data type (e.g., Type 1, Type 2, ... Type n) can be further decomposed into more fine-grained subtypes. For example, activities can be further decomposed into activities that apply to a specific set of domains, such as a user can choose to share all data with a privacy server except data associated with healthcare providers, the IRS, etc.

[0043] Entities may identify owners (eg, individual 1), servers (eg, privacy servers), and relationship groups, such as members of the same family. A relationship group may be a user convenience feature that can be used to assign permissions to a group of entities of the same relationship.

[0044] A device can identify devices with which data can be shared, and those devices can be identified by device keys (e.g., DevKey1, DevKey2, etc.) Any data shared from a device for a personal-level aggregate view can be accessed by other devices.

[0045] Any access to data generally requires adequate permissions.

[0046] refer to Figure 4 , according to one embodiment, an illustration of sharing permissions with a group is provided. In an embodiment, any data that a user chooses to share must pass through a privacy server. Thus, the user can be the only entity that sets sharing permissions, and the privacy server can be the only facilitator of data sharing based on the permissions set by the user.

[0047] As shown, the owner can identify where the data is stored (eg, a server), with whom the data is shared, and with which devices the data is shared.

[0048] refer to Figure 5 According to an embodiment, an exemplary method for setting sharing permission is disclosed.

[0049] In step 505, the data owner may set permissions for data sharing using, for example, a data privacy application or program executing on one of the data owner's electronic devices.

[0050] In step 510, the permission may be transmitted to the privacy server.

[0051] In step 515, the privacy server may configure permissions for (one or more) electronic devices and may transmit the configured permissions to the relevant electronic devices. For example, if the data owner sets permissions for device 3 to share data with device 1, the privacy server configures permissions for device 1 and device 3 and transmits the configured permissions to these devices. The privacy server may not transmit the configured permissions to device 2 because device 2 has not changed.

[0052] In step 520, data from one or more data owner devices may be acquired and stored at the privacy server. For example, if the user chooses to share data with the privacy server (e.g., for backup and aggregation purposes), the privacy server may save the data, which may be encrypted according to the sharing permissions set by the data owner. The key for decryption may be generated and retained only on the device, preventing the privacy server from viewing the content if the data owner chooses not to allow the privacy server to view the content.

[0053] The key may be stored in a secure storage device (e.g., a keychain or EET) separate from other data storage devices in the privacy mobile application.

[0054] Account data (such as permissions) may be stored by the privacy server as a system of record because this data is not private data.

[0055] Activity data (such as browsing history) can only be stored by the privacy server if the user chooses to do so. If stored on the server, the user can retrieve / restore the data in the event of a device change or accidental data loss.

[0056] In step 525, data may be transferred from the privacy server to the device as needed and / or desired. For example, if a user needs to restore data on an electronic device, the encrypted data may be migrated to the electronic device, decrypted, and stored on the electronic device.

[0057] refer to Figure 6 According to one embodiment, a method for sharing data between devices associated with multiple users is provided. In step 605, a first user (e.g., a data owner) may register or sign up for a privacy application executed on a first user electronic device. In one embodiment, the user may identify (one or more) of the user's devices, whether the user is the owner of the data, etc.

[0058] In one embodiment, a user may identify family members, team members, etc. to whom to send invitations to share data.

[0059] In step 610, the first user can set data sharing preferences in the privacy application. For example, the first user can identify devices, users, data, etc. that the user wishes to share or not share data with, services to use (e.g., VPN, device fingerprint obfuscation, whitelist, alert, alias, rating, etc.), etc.

[0060] In step 615 , the data sharing preference of the first user may be transmitted to the privacy server and stored with the privacy server.

[0061] In step 620, the second user may register a privacy application on the second user electronic device. The second user may provide any necessary and / or desired information.

[0062] In step 625 , a second user in the first user's group may inherit the first user's data sharing preference.

[0063] In step 630, the third user may register a privacy application on the third user electronic device. The third user may provide any necessary and / or desired information.

[0064] In step 635, the first user may request permission from the third user to share data with the first user. In one embodiment, the first user may make the request using a privacy application.

[0065] Alternatively, the third user can use, for example, a privacy application to authorize sharing data with the first user. In this case, no additional permission or authorization is required.

[0066] In step 640, the third user may receive notification (such as a push notification, in-application message, etc.) that the first user has requested permission, and the third user may grant or deny permission.

[0067] In step 645, if the third user grants the request, the server updates the data sharing permissions as needed.

[0068] If the third user denies the request, the data sharing permissions may not be updated (eg, they may remain unchanged). In another embodiment, the data sharing permissions may be updated to reflect that the third user's data is not to be shared with the first user.

[0069] In step 650 , the privacy server may configure data sharing permissions for the first user and the third user, and may transmit the configured data sharing permissions to the first device and the third device as needed.

[0070] In one embodiment, device-level settings for data sharing permissions can override user-level preferences. For example, while general preferences and / or permissions can be set for all of a user's devices, specific preferences on a device can override general preferences and / or permissions.

[0071] In one embodiment, another user may request a change of ownership from the current owner.

[0072] Any user using a device owned by someone else will inherit the privacy services and abide by the sharing permissions set by the owner.

[0073] The disclosures of U.S. Patent Application Serial No. 16 / 598,734 and U.S. Provisional Patent Application Serial Nos. 62 / 856,491 and 62 / 874,240 are incorporated herein by reference in their entirety.

[0074] While multiple embodiments have been disclosed, it should be appreciated that these embodiments are not mutually exclusive and that features from one embodiment may be used with other embodiments.

[0075] In the following, general aspects of implementation of the systems and methods of the embodiments will be described.

[0076] Embodiments of the system or parts of the system may take the form of a "processing machine" such as a general-purpose computer. As used herein, the term "processing machine" should be understood to include at least one processor using at least one memory. At least one memory stores a set of instructions. These instructions may be permanently or temporarily stored in one or more memories of the processing machine. The processor executes the instructions stored in the one or more memories to process data. This set of instructions may include various instructions for performing one or more specific tasks (such as those described above). Such a set of instructions for performing specific tasks may be characterized as a program, a software program, or just software.

[0077] In one embodiment, the processing machine may be a special purpose processor.

[0078] As described above, the processing machine executes instructions stored in one or more memories to process data. Such processing of data may, for example, be in response to commands of one or more users of the processing machine, in response to previous processing, in response to a request from another processing machine, and / or any other input.

[0079] As described above, the processing machine used to implement the embodiments may be a general-purpose computer. However, the processing machine may also utilize any of a variety of other technologies, including a special-purpose computer, a computer system (including, for example, a microcomputer, a minicomputer, or a mainframe), a programmed microprocessor, a microcontroller, a peripheral integrated circuit element, a CSIC (customer-specific integrated circuit) or an ASIC (application-specific integrated circuit) or other integrated circuit, a logic circuit, a digital signal processor, a programmable logic device (such as an FPGA, a PLD, a PLA, or a PAL), or any other device or device arrangement capable of implementing the processing steps disclosed herein.

[0080] The processing machine used to implement the embodiments may utilize a suitable operating system. Thus, the embodiments may include running the iOS operating system, the OS X operating system, the Android operating system, the Microsoft Windows TM Operating system, Unix operating system, Linux operating system, Xenix operating system, IBM ATX TM Operating system, Hewlett-Packard UX TM Operating system, Novell Netware TM Operating system, Sun Microsystems Solaris TM Operating system, OS / 2 TM Operating system, BeOS TM Operating system, Macintosh operating system, Apache operating system, OpenStepTM operating system or other operating system or platform of the processing machine.

[0081] It should be understood that in order to practice the method of the embodiment as described above, the processor and / or memory of the processing machine need not be actually located at the same geographical location. That is, each processor and memory used by the processing machine can be located at geographically different locations and connected to communicate in any suitable manner. In addition, it should be understood that each of the processor and / or memory can be composed of different multiple physical devices. Therefore, the processor does not have to be a single device located at one location, and the memory does not have to be another single device located at another location. In other words, it is contemplated that the processor can be two devices located at two different physical locations. Two different devices can be connected in any suitable manner. In addition, the memory can include two or more memory parts at two or more physical locations.

[0082] For further explanation, as described above, processing is performed by various components and various memories. However, it should be understood that, according to another embodiment, the processing performed by two different components as described above can be performed by a single component. In addition, the processing performed by one different component as described above can be performed by two different components.

[0083] In a similar manner, according to another embodiment, the memory storage performed by two distinct memory portions as described above can be performed by a single memory portion. In addition, the memory storage performed by one distinct memory portion as described above can be performed by two memory portions.

[0084] In addition, various techniques may be used to provide communication between various processors and / or memories, as well as to allow the processors and / or memories to communicate with any other entity; for example, to obtain additional instructions or to access and use remote memory storage. Such techniques for providing such communication may include, for example, a network, the Internet, an intranet, an extranet, a LAN (local area network), Ethernet, wireless communication via a cellular tower or satellite, or any client server system that provides communication. Such communication techniques may use any suitable protocol such as TCP / IP, UDP, or OSI.

[0085] As described above, a set of instructions may be used in the processing of an embodiment. The set of instructions may be in the form of a program or software. The software may be in the form of, for example, system software or application software. The software may also be in the form of, for example, a collection of independent programs, a program module in a larger program, or a portion of a program module. The software used may also include modular programming in the form of object-oriented programming. The software tells the processing machine what to do with the data being processed.

[0086] In addition, it should be understood that the instructions or instruction sets used in the implementation and operation of the embodiments may have a suitable form so that the processing machine can read these instructions. For example, the instructions forming the program may take the form of a suitable programming language, which is converted into a machine language or object code to allow one or more processors to read the instructions. That is, a compiler, assembler or interpreter is used to convert a programming code line or a source code line written in a specific programming language into a machine language. Machine language is a binary-coded machine instruction, and these binary-coded machine instructions are dedicated to a specific type of processing machine, that is, for example, a specific type of computer. The computer understands the machine language.

[0087] According to various embodiments, any suitable programming language may be used. For example, the programming language used may include, for example, assembly language, Ada, APL, Basic, C, C++, COBOL, dBase, Forth, Fortran, Java, Modula-2, Pascal, Prolog, REXX, Visual Basic, and / or JavaScript. In addition, it is not necessary that the operation of the combined systems and methods utilize a single type of instructions or a single programming language. Instead, any number of different programming languages ​​may be used as needed and / or desired.

[0088] Likewise, the instructions and / or data used in the practice of the embodiments may utilize any compression or encryption techniques or algorithms as needed. An encryption module may be used to encrypt data. In addition, for example, a suitable decryption module may be used to decrypt files or other data.

[0089] As described above, the embodiment can be illustratively embodied in the form of a processing machine including, for example, a computer or a computer system, which includes at least one memory. It should be understood that the instruction set (i.e., software, for example) that enables the computer operating system to perform the above-mentioned operations can be included in any of various media as needed. In addition, the data processed by the instruction set can also be included in any of various media. That is to say, the specific medium (i.e., the memory in the processing machine) for maintaining the instruction set and / or data used in the embodiment can, for example, take any of a variety of physical forms or transmission forms. For example, the medium can be paper, transparent paper, optical disk, DVD, integrated circuit, hard disk, floppy disk, optical disk, magnetic tape, RAM, ROM, PROM, EPROM, wire, cable, optical fiber, communication channel, satellite transmission, memory card, SIM card or other remote transmission and any other medium or data source that can be read by the processor.

[0090] In addition, one or more memories used in the processing machine implementing the embodiment can be any of a variety of forms to allow the memory to hold instructions, data or other information as needed. Therefore, the memory can take the form of a database to hold data. For example, the database can use any desired file arrangement such as a flat file arrangement or a relational database arrangement.

[0091] In the system and method, various "user interfaces" can be utilized to allow the user to interact with one or more processing machines for implementing the embodiment. As used herein, the user interface includes any hardware, software or combination of hardware and software used by the processing machine that allows the user to interact with the processing machine. The user interface can be, for example, in the form of a dialogue screen. The user interface can also include a mouse, a touch screen, a keyboard, a keypad, a voice reader, a voice recognizer, a dialogue screen, a menu box, a list, a check box, a toggle switch, a button or any other device that allows the user to receive information about the operation of the processing machine when the processing machine processes a group of instructions and / or provide information to the processing machine. Therefore, the user interface is any device that provides communication between the user and the processing machine. The information that the user provides to the processing machine through the user interface can be, for example, the selection of commands, data or some other input form.

[0092] As mentioned above, the processing machine utilizes a user interface, and the processing machine executes a group of instructions so that the processing machine processes data for the user. The user interface is usually used by the processing machine to interact with the user to convey information or receive information from the user. But, it should be understood that, according to some embodiments of the system and method, the human user does not actually have to interact with the user interface used by the processing machine. On the contrary, it can also be expected that the user interface can interact with another processing machine instead of the human user (i.e., convey and receive information). Therefore, another processing machine can be characterized as a user. In addition, it can be expected that the user interface used in the system and method can partially interact with another one or more processing machines, and also partially interact with the human user.

[0093] Those skilled in the art will readily appreciate that the embodiments are susceptible to widespread utilization and application. In addition to what is described herein, many embodiments and adaptations of the invention and many variations, modifications and equivalent arrangements will be apparent or reasonably suggested by the invention and the foregoing description thereof without departing from the spirit or scope of the invention.

[0094] Therefore, although the present invention has been described in detail herein with respect to its exemplary embodiments, it should be understood that the present disclosure is only an illustrative and exemplary disclosure of the present invention and is intended to provide a feasible disclosure of the present invention. Therefore, the foregoing disclosure is not intended to be interpreted as any other such embodiment, adaptation, variation, modification or equivalent arrangement or to limit the present invention to any other such embodiment, adaptation, variation, modification or equivalent arrangement or otherwise exclude any other such embodiment, adaptation, variation, modification or equivalent arrangement.

Claims

1. A method for protecting data across multiple users and devices, comprising: In a privacy server comprising at least one computer processor: receiving, from a first user device, a data sharing permission for the first user device and an initial data sharing permission for a second user device, the first user device and the second user device being associated with the same user; providing the data sharing permission for the second user device; transmitting the provided data sharing permission to the second user device, wherein the second user device shares data with the first user device according to the provided data sharing permission; receiving, from the first user device, an updated data sharing permission for the second user device; determining that updated data sharing permissions for the second user device are different from the initial data sharing permissions; responsive to the determination, transmitting the updated data sharing permission to the second user device; receiving, from the first user device, a third data sharing permission for the second user device and a third user device, wherein the first user device and the third user device are associated with the same user; determining that the third data sharing permission does not change the updated data sharing permission for the second user device; as well as The third data sharing permission is transmitted to the third user device but not to the second user device.

2. The method of claim 1, wherein the data sharing permission identifies the type of data to be shared. 3 . The method according to claim 2 , wherein the type of data includes at least one of account data, activity data, and preference data.

4. The method of claim 1, wherein the first user device is associated with a first device key, and the second user device is associated with a second device key, and the second user device is identified to the privacy server by the second device key.

5. The method according to claim 1, further comprising: receiving encrypted data from the first user device or the second user device; as well as The encrypted data is stored in accordance with the data sharing permission.

6. The method according to claim 5, further comprising: The encrypted data is transmitted to the first user device or the second user device according to the data sharing permission.

7. The method according to claim 5, further comprising: The encrypted data is restored to the same user device from which it originated.

8. A method for sharing data between devices associated with a plurality of users, comprising: In a privacy server comprising at least one computer processor: receiving, from a first privacy application executing on a first user device, a registration of a first user, wherein the registration includes an identification of the first user device and an identification of a data owner for data on the first user device; receiving a data sharing preference of the first user from the first privacy application; saving the data sharing preference of the first user; receiving, from a second privacy application executing on a second user device, a registration of a second user, wherein the registration includes an identification of the second user device and an identification of a data owner for data on the second user device; receiving, from the first privacy application, a request from the second user to share data with the first user; transmitting the request to the second privacy application; receiving a response to the request from the second privacy application, wherein the response approves or denies the request; configuring data sharing permission for the first user equipment and the second user equipment; as well as transmitting the data sharing permission to the first privacy application and the second privacy application, wherein at least one of the first privacy application and the second privacy application updates the data sharing permission on a corresponding device; receiving, from the first privacy application, updated data sharing preferences for the first user; determining that the updated data sharing preference changes the data sharing permissions with the second user device; In response to the determination, updating the data sharing permission with the second user device; transmitting the updated data sharing permission to the second privacy application; receiving data sharing permissions from the privacy application for the second user device and a third device, wherein the first user device and the third device are associated with the same user; determining that the data sharing permissions do not change the updated data sharing permissions for the second user device; as well as The data sharing permission is transmitted to the third device but not to the second user device.

9. The method of claim 8, wherein the request by the second user to share data with the first user identifies a type of data to be shared.

10. The method of claim 9, wherein the type of data comprises at least one of account data, activity data, and preference data.

11. The method according to claim 8, further comprising: receiving encrypted data from the first user device or the second user device; as well as The encrypted data is stored in accordance with the data sharing permission.

12. The method according to claim 11, further comprising: The encrypted data is transmitted to the first user device or the second user device according to the data sharing permission.

13. The method according to claim 8, further comprising: receiving, from the first privacy application, a second updated data sharing preference of the first user; determining that the second updated data sharing preference does not change the data sharing permission with the second user device; as well as In response to the determination, the second updated data sharing preference is denied to be transmitted to the second privacy application.

14. A method for sharing data between devices associated with a plurality of users, comprising: In a privacy server comprising at least one computer processor: receiving, from a first privacy application executing on a first user device, a registration of a first user, wherein the registration includes an identification of the first user device and an identification of a data owner for data on the first user device; receiving a data sharing preference of the first user from the first privacy application; saving the data sharing preference of the first user; receiving, from a second privacy application executing on a second user device, a registration of a second user, wherein the registration includes an identification of the second user device and an identification of a data owner for data on the second user device; receiving, from the second privacy application, a request from the second user to share data with the first user; configuring data sharing permission for the first user equipment and the second user equipment; transmitting the data sharing permission to the first privacy application and the second privacy application, wherein at least one of the first privacy application and the second privacy application updates the data sharing permission on a corresponding device; receiving updated data sharing preferences of the first user from the first privacy application; determining that the updated data sharing preference changes the data sharing permissions with the second user device; In response to the determination, updating the data sharing permission with the second user device; transmitting the updated data sharing permission to the second privacy application; receiving data sharing permission from the first privacy application for the second user device and a third device, the first user device and the third device being associated with the same first user; determining that the data sharing permissions do not change the updated data sharing permissions for the second user device; as well as The data sharing permission is transmitted to the third device but not to the second user device.

15. The method of claim 14, wherein the request by the second user to share data with the first user identifies a type of data to be shared.

16. The method of claim 15, wherein the type of data comprises at least one of account data, activity data, and preference data.

17. The method according to claim 14, further comprising: receiving encrypted data from the first user device or the second user device; as well as The encrypted data is stored in accordance with the data sharing permission.

18. The method of claim 14, further comprising: receiving, from the first privacy application, a second updated data sharing preference of the first user; determining that the second updated data sharing preference does not change the data sharing permission with the second user device; as well as In response to the determination, the second updated data sharing preference is denied to be transmitted to the second privacy application.

Citation Information

Patent Citations

  • Method and system for facilitating commercial transactions based on intended user experience

    US20200327574A1

  • Systems and methods for facilitating intent-based advertising and offers

    US20200327575A1

  • Systems, methods, and devices for obfuscation of browser fingerprint data on the world wide web

    US20200380165A1

  • Sharing User Context And Preferences

    US20180007099A1