Method and system for propagating data between different domains in a privacy-conscious manner
By using first-party cookies and intermediary servers in web browsers, the problem of third-party cookie restrictions is solved, enabling user tracking and personalized content delivery across different websites while protecting user privacy and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ADFIXUS PTE LTD
- Filing Date
- 2021-06-30
- Publication Date
- 2026-05-29
Smart Images

Figure CN115699706B_ABST
Abstract
Description
Technical Field
[0001] This invention generally relates to a method for using a first-party cookie to replace a third-party cookie. Background Technology
[0002] Web browsing has evolved from simple hypertext links between static web pages to a dynamic interconnection of many static and dynamically generated websites that offer a wide range of content.
[0003] As browsing has evolved, the need to record information associated with a website has been addressed by enabling websites to set "cookies"—small pieces of data stored on the computer running the web browser—in response to instructions made by the website accessed by the web browser.
[0004] Cookies can be either "first-party cookies" or "third-party cookies." First-party cookies are set by a specific domain being accessed by a web browser. For example, a user might direct their web browser to www.example.com, and the web content accessed by the web browser at this domain could indicate a cookie containing data and associated with the same domain (hence the term "first-party"). Third-party cookies are set by a domain different from the domain being accessed by the web browser. For example, a webpage being accessed at www.example.com might itself utilize resources from another domain, such as www.addomain.com. This resource could set its own cookie—however, because it is associated with a different domain, the cookie is associated with a second domain. Therefore, a cookie is a small piece of data downloaded to the device by a third party; it is associated with a party different from the domain being accessed by the web browser.
[0005] There is a growing tendency to disallow the setting of third-party cookies—for example, because users may not be aware of the second domain, setting third-party cookies can be considered unnecessary. However, third-party cookies play a significant role in modern online activity, providing a means of tracking activity across different websites (e.g., for targeted advertising) and allowing for more efficient user identification. For instance, a common owner of several websites (each associated with a different domain) might identify a user when they visit their single website; while there may be a legitimate interest in removing third-party cookies, there could be negative consequences in these situations for positive reasons of improving user privacy and security.
[0006] As an example, when a user (via a web browser) visits a known domain, such as www.example.com, it can generate at least some of the content for the user by utilizing resources from a third-party domain, such as www.addomain.com. In the past, www.addomain.com could set a third-party cookie (e.g., where name = AdDomainId and value = 12345). For browser functionality, this cookie was associated with www.addomain.com, not www.example.com. When the user further navigated to www.example01.com—a domain completely unrelated to www.example.com and owned by another company (which also utilizes resources from www.addomain.com)—the browser in the past would automatically send the cookie from www.addomain.com to www.addomain.com. This means that the cookie previously set on www.example.com (name = AdDomainId and value = 12345) is automatically sent from www.example01.com.
[0007] Therefore, several major web browser developers have recently announced plans to disable third-party cookies by default. This move is predicted to have adverse consequences for legitimate online activities.
[0008] A mechanism needs to be provided to enable functionality provided by third-party cookies without setting third-party cookies. Summary of the Invention
[0009] The embodiments and aspects described herein generally relate to providing mechanisms for implementing functionality provided by third-party cookies without requiring the setting of third-party cookies. For example, some described embodiments are suitable for providing functionality that enables tracking of a specific user across several different websites associated with different domains, which advantageously allows the user to be identified by the different websites in a manner invisible to the user. Advantageously, user identification can allow different websites to provide appropriately tailored content based on user identification, thereby providing an improved user experience across various websites and domains. These and other advantages are generally achieved without setting third-party cookies (which have previously been used to provide this functionality). To strike a balance between legitimate tracking activities and the need for user privacy and security, some described embodiments implement additional restrictions on the extent to which user identification information is available.
[0010] According to one aspect of the present invention, a method is provided for recording information in a first-party cookie on a web browser, for example, wherein the web browser does not allow access to third-party cookies, comprising propagating the recorded information from a second cookie associated with a second domain to a first cookie associated with a first domain, wherein the first cookie and the second cookie are each first-party cookies, such that a first web resource of the first domain and a second web resource of the second domain each access the recorded information via their associated first-party cookies.
[0011] The recorded information may be propagated to the first cookie during the current communication instance between the web browser and the first web resource of the first domain. The recorded information may also be propagated to the first cookie depending on the determination that the first cookie does not exist.
[0012] The recorded information may be disseminated via an intermediary, which is disseminated information accessible to a web browser during the current communication instance.
[0013] According to one embodiment, the method includes instructing a web browser to communicate with a propagation server associated with a propagation domain different from a first domain during a current communication instance, and receiving propagation information from the propagation server such that the web browser can record the recorded information as a first cookie. The web browser may initiate the current communication instance via communication with a first web server that requests content for display, the first web server being associated with a first domain server and both servers being associated with the first domain, and instructions to the propagation server being received from the first domain server. The first web server may provide content to the web browser for display depending on the recorded information after propagating the recorded information from a second cookie to a first cookie. As part of the instructions, the web browser may provide information stored in the propagation cookie to the propagation server, and the propagation information may be based on the information stored in the propagation cookie. The information stored in the propagation cookie may be the same as the propagation information, or the propagation information may be an encoded representation of the information stored in the propagation cookie. The propagation information may be generated according to propagation rules that can be used by the propagation server, and the propagation rules may be applied to the information stored in the propagation cookie. As part of the instructions, the propagation rules may be stored in the propagation cookie and provided to the propagation server. The propagation information can be provided to the web browser in association with instructions received from the propagation server, enabling the web browser to communicate with the first domain server and provide the propagation information along with the instructions. In response to providing the propagation information to the first domain server, the web browser can receive instructions from the first domain server to set a first cookie including the recorded information.
[0014] According to one embodiment, the intermediary is stored as webpage-specific data and includes: instructing a web browser to communicate with a first domain server, the web browser providing the webpage-specific data along with instructions to the first domain server; and receiving instructions from the first domain server to set a first cookie having recorded information, wherein the recorded information is equal to or derived from the webpage-specific data, wherein the instructions are received from the first web server in response to a request from the web browser for content to be displayed, wherein the first web server is associated with the first domain server, and wherein both servers are associated with the first domain. The webpage-specific data may be set during a previous communication instance with a second domain server of a second domain. The webpage-specific data is not accessible by executable code when running on the web browser and is accessible by the first domain server when set through communication with the second domain, and preferably only accessible by an external server. The webpage-specific data may be stored in an ETag associated with the webpage provided to the web browser before the instructions are sent to the web browser.
[0015] The first and second domains can be identified as the relevant domains that are allowed to be propagated before the recorded information is allowed to be propagated from the second cookie to the first cookie.
[0016] Web browsers may not allow access to third-party cookies.
[0017] According to another aspect of the invention, a domain server is provided configured to communicate with a web browser to facilitate the propagation of recorded information between first-party cookies associated with different domains. The domain server is configured to: receive communication from the web browser due to a reboot instruction provided to the web browser from a first web server associated with the first domain; and determine whether a first cookie, associated with the first domain, exists in the communication. In response to determining that the first cookie does not exist, the domain server is configured to: obtain propagation information from the web browser, the propagation information being derived from recorded information of a second cookie associated with a second domain, wherein the recorded information is derivable from the propagation information; determine the recorded information from the propagation information; and instruct the web browser to record the recorded information in the first cookie.
[0018] A domain server can be configured to instruct a web browser to communicate with a first web server so that content for the web browser can be generated using a re-encoded first cookie.
[0019] In one embodiment, the domain server is further configured to, upon receiving mediation information,: instruct the web browser to communicate with a propagation server associated with a propagation domain different from the first domain, wherein propagation information is provided from the propagation server to the web browser in response to the instruction; and receive the propagation information from the web browser after instructing the web browser to communicate with the domain server again. The propagation information can be generated according to propagation rules available to the propagation server, and the propagation rules can be applied to information stored in a propagation cookie. The propagation rules can be stored in a propagation cookie stored in the web browser.
[0020] In one embodiment, the intermediary is stored as webpage-specific data, and the domain server is further configured to: identify the webpage-specific data from communications from the web browser; and convey an instruction to set a first cookie with recorded information, wherein the recorded information is equal to or derived from the webpage-specific data. The webpage-specific data may be set during a previous instance of communication with the second domain server of the second domain. The webpage-specific data is not accessible by executable code when running on the web browser and is accessible by the first domain server when set via communications with the second domain, and preferably only by an external server. The webpage-specific data may be stored in an ETag associated with the webpage provided to the web browser before the instruction is conveyed. When the second domain is identified as being associated with the first domain, the recorded information may be propagated only from the second cookie to the first cookie.
[0021] Web browsers communicating with domain servers may not allow access to third-party cookies.
[0022] According to another aspect of the invention, a network system is provided for facilitating the propagation of recorded information between first-party cookies associated with different domains on a web browser communicating with a network system, the system comprising: one or more domain servers, wherein each domain server is configured to: receive communication from a web browser due to a reboot instruction provided to the web browser from a web server associated with the domain; determine whether a first cookie is present in the communication, the first cookie being associated with the domain; in response to determining that the first cookie is absent, obtain propagation information from the web browser, the propagation information being derived from recorded information of a second cookie associated with a second domain, the second domain being associated with another of the domain servers, wherein the recorded information is deriveable from the propagation information; determine the recorded information from the propagation information; and instruct the web browser to record the recorded information in the first cookie.
[0023] Optionally, the network system includes a propagation server associated with a propagation domain different from the first domain, and each domain server is further configured to, upon receiving mediation information,: instruct a web browser to communicate with the propagation server associated with the propagation domain different from the first domain; and receive propagation information from the web browser after instructing the web browser to communicate with the domain server again through the propagation server, wherein the propagation server is configured to: determine the propagation information based on information provided from the web browser along with the instructions. If present, the information may include information stored in a propagation cookie that can be read by the propagation server. The propagation server may be configured to generate the propagation information according to propagation rules available to the propagation server, and the propagation rules may be applied to the information stored in the propagation cookie. The propagation rules may be stored in the propagation cookie stored in the web browser and thus may be received by the propagation server via communication from the web browser. In the absence of a propagation cookie, the propagation server may be configured to determine the value of the propagation cookie and transmit instructions to the web browser to set the value to the propagation cookie, and may generate the propagation information based on the latest determined value.
[0024] Optionally, each domain server is further configured to: identify webpage-specific data from communications with the web browser; and transmit an instruction to the web browser to set a first cookie containing the recorded information, wherein the recorded information is equal to or derived from the webpage-specific data. The webpage-specific data can be set during a previous instance of communication with the second domain server.
[0025] When the second domain is identified as being associated with the first domain, the recorded information can be propagated from the second cookie to the first cookie only.
[0026] The network system may further include a web server for each domain server, the web server being configured to instruct a web browser to communicate with its associated domain server, and each web server being able to share a domain with its associated domain server.
[0027] Web browsers that communicate with the system may be assumed to be disallowed or may indeed be disallowed from accessing third-party cookies.
[0028] As used herein, the word “comprising” or variations thereof, such as “comprises” or “comprising”, are used in an inclusive sense, that is, to specify the presence of the stated feature rather than to exclude the presence or addition of other features in the various embodiments of the invention. Attached Figure Description
[0029] To provide a clearer understanding of the invention, embodiments will now be described with reference to the accompanying drawings, in which:
[0030] Figure 1 A communication system according to one embodiment is shown;
[0031] Figure 2 This demonstrates the arrangement used for cookie propagation in some embodiments;
[0032] Figure 3 This demonstrates a method for distributing cookies according to one embodiment;
[0033] Figure 4A and 4B Display and utilization Figure 3 Specific implementation of the method;
[0034] Figure 5A and 5B A method for distributing cookies according to another embodiment is shown;
[0035] Figure 6 This demonstrates a method for generating domain cookies via a third-party content server.
[0036] Figures 7A to 7C This demonstrates an embodiment for generating user-identifying cookies and disseminating information; and
[0037] Figures 8A to 8E This involves using a proxy server to modify communication with third-party resources. Detailed Implementation
[0038] Figure 1 A communication system 10 according to one embodiment is illustrated. System 10 includes a client device 11, a web server 12, a domain server 13, and an optional (third-party) content server 14. The client device 11 is configured to communicate data with the web server 12, the domain server 13, and, where applicable, with the content server 14 via a network 15, typically including the Internet. In the illustrated embodiment, the client device 11 communicates data with the content server 14 via the domain server 13.
[0039] Figure 1System 10 should be understood as an exemplary representation of data connections between various elements; however, it should not be considered limiting. For example, some embodiments may utilize fewer elements than those shown, while other embodiments may utilize additional elements. Furthermore, unless otherwise stated, the various servers 12 to 14 should be understood as representing functional elements—although each server 12 to 14 may be embodied in separate physical hardware, two or more of the servers 12 to 14 may be embodied in the same physical hardware, for example, as logically distinct elements. Similarly, unless otherwise stated, client device 11 should be understood as a functional element that allows one user (or actually multiple users) to interact with system 11.
[0040] Client device 11 is configured to run an application suitable for requesting web content, typically a web browser (as assumed herein) (e.g., via the HTTP protocol). This enables the web browser to communicate with web server 12 hosting a specific website. For example, the web browser may perform this communication in response to user input (e.g., by selecting a hyperlink to the website or by entering the website's URL) or automatically in response to instructions executed by software on client device 11 (which may be the same web browser).
[0041] Client device 11 can be any suitable computing hardware for running applications suitable for requesting web content, such as a personal computer (PC) or smartphone. Other devices are also envisioned, such as smartwatches, tablet computers, and various form factors of PCs including desktop computers, laptop computers, and netbooks. A common attribute of the client device 11 is enabling data communication with network 15, such as wired (e.g., via Ethernet) or wireless (e.g., WiFi—e.g., one or more of various IEEE 802.11 standards). For the purposes of this disclosure, no particular data communication is assumed. Client device 11 can implement any number of operating systems, such as one or more of Microsoft Windows-compatible operating systems (OS), Apple OS X, and Linux distributions. Smartphones are known to implement, in particular, the Android or iOS operating systems.
[0042] Various servers 12 to 14 are available to suit different hardware implementations as needed. For example, each server 12 to 14 may be implemented with dedicated computing hardware. However, cloud-based implementations are also envisioned, such as those provided by Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform, and Oracle Cloud, where one or more servers 12 to 14 are implemented as virtual servers. Generally, each server 12 to 14 is associated with a processor and memory, where the processor executes code to implement the functionality of the server 12 to 14 and provides memory to store the code and provide working memory space. The memory may include both volatile and non-volatile memory. Depending on the requirements of a particular implementation, each server 12 to 14 may be able to access the network 15 and / or directly access one or more of the other servers 12 to 14.
[0043] Generally, Network 15 is flexible and can receive data communication via any number of protocols, such as Ethernet, 802.11, Worldwide Interoperability for Microwave Access (WiMAX), 3G, 4G, CDMA, and Digital Subscriber Line (DSL). Similarly, the networking protocols used on Network 15 can include any number of protocols, such as Multiprotocol Label Switching (MPLS), Transmission Control Protocol / Internet Protocol (TCP / IP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), Simple Mail Transfer Protocol (SMTP), and File Transfer Protocol (FTP). Data exchanged via Network 15 can be represented using technologies and / or formats, such as one or more of the following: Hypertext Markup Language (HTML), Extensible Markup Language (XML), and JavaScript Object Notation (JSON). In addition, all or some of the communication can be encrypted using conventional encryption techniques, such as Secure Sockets Layer (SSL), Transport Layer Security (TLS), and Internet Protocol Security (IPsec).
[0044] This document refers to "browser executable code," specifically JavaScript. JavaScript is a well-known technology of the World Wide Web and is itself an application running on the Internet. Although some estimates suggest that 97% of websites use JavaScript for client-side webpage behavior (i.e., generating webpage content and behavior via JavaScript executed by the web browser of client device 11), specific browser executable code and corresponding programming languages should not be considered restrictive unless the context or specific claims specify otherwise. Accordingly, browser executable code should be adapted to execute on the web browser of client device 11 to enable the web browser to perform communication functions, generate content, or perform other dynamic behaviors.
[0045] The following describes various embodiments for providing functionality without utilizing third-party cookies, which, in practice (at least from the perspective of a user of user device 11), may resemble certain known functionalities enabled by setting third-party cookies. Generally, the scenario described herein involves a web browser accessing an internet resource as a web page hosted by web server 12 (as assumed herein). The web browser is directed to the address of the web page, for example, specified by its Uniform Resource Locator (URL).
[0046] According to an embodiment, both web server 12 and domain server 13 are configured to receive requests from client device 11 and provide responses. For example, the request may be for content, and the response may include said content. Typically, as assumed herein, the request is a "GET" message according to the Hypertext Transfer Protocol (HTTP) (or an extended protocol, such as Hypertext Transfer Protocol Secure; HTTPS)), and the response includes an HTTP / HTTPS response message. Additionally, the response may include content containing Hypertext Markup Language (HTML) code that defines the appearance and functionality of a webpage. HTML code defines various different content fragments. The response also includes HTTP headers.
[0047] Generally, when a web browser on user device 11 accesses an internet resource, it can be configured to communicate webpage-specific data with requests that have been stored by the web browser due to previous accesses to the internet resource. An example is an ETag (with an ETag value). An ETag is defined as part of HTTP and is set by the resource on client device 11 in response to a request. That is, if the web browser has previously communicated with the resource, it may have stored an ETag value set during the previous communication. Generally, the ETag value is associated with a resource, for example, with its URL. The ETag value may be valid or invalid for a certain period of time. In another embodiment, webpage-specific data is stored in local storage accessible to the web browser, for example, by executing appropriate code. For convenience, certain embodiments are described herein that relate to using ETag as webpage-specific data, but it should be understood that this is not intended to be limiting.
[0048] The web browser operating on client device 11 is configured to store data in the form of cookies. Cookies can belong to various types known in this art. Accordingly, webpage-specific data is not equivalent to cookies—for example, for the purposes of this disclosure, webpage-specific data cannot be used for executable code.
[0049] refer to Figure 2 The diagram illustrates a topology relevant to certain embodiments, where multiple web servers 12a to 12c (typically any number of web servers 12) communicate with network 15. Domain server 13 is also shown communicating with network 15. (As...) Figure 1 The representative client device 11 is also shown communicating with network 15; thus enabling the client device 11 to communicate with each web server 12a to 12c and domain server 13 via network 15.
[0050] Accordingly, web servers 12a to 12c differ in that they represent web resources (e.g., web pages) associated with different domains (represented by dashed boxes); that is, the first web server 12a is associated with a first web page on a first domain (e.g., www.example1.com), the second web server 12b is associated with a second web page on a second domain (e.g., www.example2.com), and the third web server 12a is associated with a third web page on a third domain (e.g., www.example3.com). Therefore, other web servers 12a to 12c cannot access the first-party cookie associated with each of web servers 12a to 12c.
[0051] One or more embodiments described herein can be used to “propagate” cookies between different domains. Here, “propagate” and “cookie propagation” refer to the creation of a first-party cookie on the client device 11 associated with each domain based on common information. For example, if information is created or determined and recorded in a first-party cookie by accessing a web resource in one domain (e.g., a first domain) via client device 11, then a subsequent access to a web resource in another domain (e.g., a second domain) causes the information to be recorded in a first-party cookie associated with this next accessed domain. Thus, common information is effectively stored in separate first-party cookies for each web resource in different domains.
[0052] The overall effect is that common information is "propagated" between cookies used for each domain, thereby enabling each web server 12a to 12c to generate consistent personalized information by being enabled to identify each access as coming from the same client device 11. In fact, any desired information can be propagated. It should also be understood that cookies for each domain may store different actual data (e.g., via domain-specific encryption and / or hashing) – however, common information should be deriveable from cookies for each domain.
[0053] Some embodiments utilize “related” web servers 12a to 12c, thereby establishing a common relationship between each of the individual web servers 12a to 12c. For example, each related web server 12a to 12c may be “owned” (i.e., at least operated) by a common entity but provides different services on different domains. In an illustrative example, a first domain references a car sales service (e.g., advertising and facilitating the sale of cars between individuals and / or companies), a second domain references a non-vehicle property sales service (e.g., an auction service), and a third domain references a content provision service (e.g., a news website). Each of these services is provided by a common entity (e.g., Company A) but under different brands and / or owned companies, and therefore, each service is associated with a unique domain.
[0054] In the prior art, third-party cookies are used to store common information (e.g., an identifier that is unique to a particular client device 11 and may also be unique to a particular web browser and / or the user of the web browser), which is then accessed by each web server 12a to 12c so that each service can serve personalized content to the user associated with the identifier, since third-party cookies can be accessed by each individual domain.
[0055] One or more embodiments described herein therefore relate to providing similar functionality that makes common information accessible but avoids the use of third-party cookies. Depending on the embodiments and implementations, the manner in which said information is utilized may be left to a specific web server 12a to 12c.
[0056] For the purposes of this disclosure, cookies set for a specific domain are referred to as "domain cookies." For example, labels such as "first" and "second" are used to distinguish different domains and their associated web server 12 and domain server 13. Similarly, a common lowercase suffix is used to identify different features of a graph associated with a specific domain. For instance, a first web server 12a and a first domain server 13a may be addressed in a first domain that can be associated with a first domain cookie, a second web server 12b and a second domain server 13b may be addressed in a second domain that can be associated with a second domain cookie, and a third web server 12c and a third domain server 13c may be addressed in a third domain that can be associated with a third domain cookie.
[0057] According to one embodiment, reference Figure 3 A and 3B describe a method relating to setting non-cookie webpage-specific data within a web browser on client device 11. An example known in this art is ETag. The method also describes setting a first domain cookie for a first webpage on the web browser of client device 11. The first domain cookie is a first-party cookie because it is set in association with the same domain (first domain) as the first webpage, but it is set by a first domain server 13a rather than a first web server 12a. Accordingly, the first domain cookie is accessible by executable code – for example, the first domain cookie does not have the "HttpOnly" attribute set. Accordingly, the webpage-specific data should be in a form inaccessible to code executed on client device 11 – for example, the ETag value is inaccessible by JavaScript. It is preferred that the webpage-specific data be accessible only by a web-based server, such as web server 12 and domain server 13.
[0058] At step 300, client device 11 communicates a request for content to first web server 12a, which is associated with a first domain (e.g., www.example1.com) as described above. The request typically specifies a particular webpage for the desired content—note that a default webpage (e.g., http: / / www.example1.com / index.html) can be selected. At step 301, a response is communicated from first web server 12a to client device 11, determined based on the request. The response includes domain server communication instructions (as executable code) to be executed by the web browser of client device 11 (e.g., in the form of JavaScript code) and typically includes content for display on the web browser.
[0059] The domain server communication instructions are for communication between the web browser of client device 11 and the first domain server 13a. Relatedly, domain server 13 and the first web server 12a reside in the same domain, but domain server 13 may be located at a different IP address than web server 12a. In a particular implementation, a subdomain of the first domain is used to address the first domain server 13a (e.g., http: / / processing.example1.com). Therefore, as discussed above, the first domain cookie set through communication with the first domain server 13a will be a first-party cookie (because it shares its domain with the first web server 12a).
[0060] Depending on the embodiment, the domain server communication instructions include first executable code configured to cause the web browser to communicate with the first domain server 13a. Alternatively, the domain server communication instructions include instructions for the web browser to obtain the first executable code from the domain server 13a. In either case, the web browser possesses the first executable code due to step 301.
[0061] At step 302, the web browser executes the first code. The first code is configured to perform a check in step 303. Here, the web browser checks the first domain cookie previously stored by the web browser. As previously discussed, if it exists, then the first domain cookie is accessible by the first code. Relatedly, as discussed, the first domain cookie is associated with the domain of the webpage (i.e., the first domain).
[0062] If the first domain cookie does not exist, then at step 310, the first code is configured to cause the web browser to forward the request to the first domain server 13a. If available, then the ETag value associated with the webpage (or other webpage-specific data, depending on the embodiment) is forwarded along with the request (for ETag, if it exists, then the ETag value will be forwarded as defined by the HTTP standard).
[0063] Next, in step 311, after receiving the request, the first domain server 13a is configured to determine whether the request has an ETag value.
[0064] In this scenario (where there is no first domain cookie), the presence of the ETag value indicates to the first domain server 13a that the web browser has previously visited a second website hosted on a different domain (e.g., a second domain) than the first website (e.g., associated with the second web server 12b), and has a second domain cookie set by the second domain server 13b regarding the second domain (therefore, the second domain cookie is a first-party cookie of the second domain, and thus inaccessible in communication with the first domain server 13a). In this scenario, at step 314, the first domain server 13a is configured to convey a response to the client device 11, thereby setting a domain cookie associated with the first domain that has a value derived from (e.g., including) the ETag value. Therefore, the web browser stores the "first-party" first domain cookie associated with the first domain, which records the same information as the second domain cookie associated with the second domain.
[0065] If no ETag value exists, then the first domain server 13a is configured at step 312 to determine data for storage in a first domain cookie and as an ETag value, and at step 313 to send a response to the web browser of the client device 11, instructing it to set both the first domain cookie and the ETag value. The specific way the first domain server 13a determines the data in step 312 depends on the implementation. However, in one particular instance, the data is obtained or exported from content server 14 (e.g., from a set cookie command issued by content server 14) – in this case, the first domain cookie and ETag value reflect information intended for storage obtained from content server 14. The set cookie command issued by content server 14 is actually an instruction to set a third-party cookie, since content server 14 is on a domain different from the first domain. In another instance, the first domain server 13a itself is configured to determine data for storage as a first domain cookie and ETag value – this could be, for example, a randomly or program-generated identifier or other data for future use by web servers 12a to 12c and / or domain servers 13a to 13c.
[0066] Now consider the result of step 303, which checks for the existence of a first domain cookie. The first code is configured at step 320, in response, to cause the web browser to forward a request to the first domain server 13a. The request is accompanied by information stored in the first domain cookie (thus making the information available to the first domain server 13a) and (if available) an ETag value (or, depending on the embodiment, other webpage-specific data).
[0067] At step 321, the first domain server 13a checks whether the request is accompanied by an ETag value.
[0068] If the request does not include an ETag value, then the first domain server 13a will transmit a response including an ETag setting instruction to the client device 11, wherein at step 322, the ETag is set to the value of the first domain cookie (or at least a value derived from the first domain cookie data). In this way, the web browser effectively stores the information recorded in the first domain cookie value in the ETag.
[0069] On the other hand, if the request is accompanied by an ETag value, then the first domain server 13a may, at step 323, convey a response to the client device 11 specifying that neither the ETag nor the domain cookie needs to be updated. Equivalently, the response may be an instruction to refresh either or both of the ETag value and the first domain cookie (e.g., this may be useful if either or both of the ETag and the domain cookie have a finite lifetime).
[0070] Figure 3 Therefore, a mechanism is defined that allows data from a first-party domain cookie associated with one webpage to be copied to a first-party domain cookie associated with another webpage. Thus, data only needs to be determined once for a webpage and then propagated to any other webpages associated with other domains. Figure 3 The method provides first-party domain cookies for each different domain to record the same information - therefore, in effect, a collection of first-party domain cookies can advantageously provide functionality similar to a single third-party cookie.
[0071] According to one embodiment, one or more of the associated domain cookies are modified relative to the original information. For example, the domain cookies may undergo an anonymization routine to obfuscate the original information. Preferably, the modification is reversible via the associated domain server 13—ensuring that the domain server 13 is accurately enabled to determine the original information from its associated domain cookies. For example, the domain name of the domain cookie may be used with an encryption key to associate each domain cookie with a different encrypted output derived from the same information. In another instance, a random prefix and / or suffix of a known size (i.e., known to the associated domain server 13) is appended.
[0072] Figure 4A and 4B exhibit Figure 3 This is an exemplary implementation of an embodiment. At step 400, the user of the web browser on client device 11 directs the web browser to a first webpage hosted by first web server 12a. At step 401, first web server 12a returns a response including HTML code, the HTML code defining content for display on client device 11. At step 402, the response further includes, as referenced... Figure 3 The first executable code of the instructions discussed. Alternatively, the response includes an instruction to obtain the first executable code from the first domain server 13a, and the web browser thus obtains the first executable code (again, at step 402).
[0073] At step 403, the web browser communicates with the first domain server 13a due to the execution of the first executable code and, when available, with the first domain cookie associated with the first domain server 13a. The first domain server 13a also obtains an ETag value (or more generally, webpage-specific data that is inaccessible to the executable code but accessible to the first domain server 13a, regardless of which domain server 13 initially set the webpage-specific data value (i.e., which domain was accessed when the webpage-specific data was set)). For example, the web browser of client device 11 accesses a web resource, such as an image, located on the first domain server 13a, and in doing so, conveys the ETag value (if available) to the first domain server 13a associated with the image. The first domain server 13a is thus configured to recognize the ETag value of a specific image. The first domain cookie will be available if it was previously set by the first domain server 13a due to previous communication. ETag will be available in the event of prior communication by any of the domain servers 13 (e.g., when an image is delivered to the client device 11, an ETag value is set in association with the image (according to the embodiment described herein)).
[0074] Figure 4AThis demonstrates a scenario where neither the first domain cookie nor the ETag determined in step 404 can be used to communicate to the first domain server 13a. In this case, Figure 3 The method generates step 313 (setting the values of the first domain cookie and ETag). The values of ETag and the first domain cookie can be generated by the first domain server 13a, the first web server 12a, or the content server 14 (depending on the implementation).
[0075] According to this specific instance, at step 405, a first domain cookie (first domain) is set in the first communication. The web browser is then configured to communicate with the first domain server 13a again, thereby sending the data of the first domain cookie (which is now set due to step 505) at step 406. Considering Figure 3 In this method, the first domain server 13a will terminate at step 322 and then transmit a response to the client device 11 at step 407, thereby instructing it to set an ETag equivalent to the first domain cookie (first domain). In this sense, the first executable code essentially runs twice - the first execution yields... Figure 3 The result of step 313 and the result of the second execution Figure 3 The result of step 322.
[0076] Figure 4B This demonstrates a scenario where the first domain cookie (first domain), determined at step 404, is unavailable, but the ETag can be used to communicate to the first domain server 13a. In this case, Figure 3 The method generates step 314 (setting the value of the first domain cookie based on ETag). This implies that the web browser has accessed a webpage hosted on a domain different from the current webpage, but utilizing the relevant domain server 13. Therefore, the other domain cookie has already been set relative to the different domain and can be used to set the first domain cookie for the first domain.
[0077] According to this example, at step 408, the first domain cookie (first domain) is set by the response transmitted from the first domain server 13a to the client device 11. Figure 3 Further execution of the method may occur during the current program, but will generate Figure 3 Step 323 - No action is required. Similarly, in this sense, the first executable code can run twice - the first execution yields... Figure 3 The result of step 314 and the result of the second execution Figure 3 The result of step 323.
[0078] Figure 3 Implementation examples (and) Figure 4A and 4B(For example) Therefore, non-cookie webpage-specific data stored on the web browser of client device 11 is used to effectively "signal" the existence of another domain cookie in another related domain when accessing a webpage of the first domain.
[0079] According to one embodiment, the propagation server 16 is associated with a propagator domain (e.g., www.exampleserver.com), such as Figure 5A As shown in the diagram, propagation server 16 is configured to facilitate the propagation of cookie information within domain cookies, each of which is associated with one of a plurality of domain servers 13a to 13c—that is, propagation server 16 can facilitate the exchange of data with each of the domain servers 13a to 13c. Propagation server 16 communicates data with network 15. It is possible that one or more of the domain servers 13 may embody the logical function of propagation server 16, but it is probably preferred that each domain server 13 is logically and / or physically different from propagation server 16. Figure 5A The document also showcases several web servers, 12a through 12c. (Similar to...) Figure 1 The representative client device 11 is also shown communicating with network 15; thus enabling client device 11 to communicate via network 15 with each web server 12a to 12c, each domain server 13a to 13c, and the propagation server 16. Accordingly, each domain server 13a to 13c can be addressed in the corresponding domain as one of the web servers 12a to 12c as described above.
[0080] In one implementation, each domain server 13 may be addressed via a subdomain of its associated domain. Subdomains may be labeled as needed, and relevantly, each subdomain may resolve to a network address (e.g., an IP address and optionally a TCP or UDP port number) of its associated domain server 13. Each domain server 13 may reside at the same or a different IP address as its associated web server 12, depending on the implementation.
[0081] Figure 5B The method of setting a first domain cookie associated with and thus accessible by the first web server 12a and the first domain server 13a depends on the presence and value of a common cookie (“propagator cookie”) associated with the propagator domain. For example, the common cookie may be an identifier associated with a specific client device 11 (in this case, referred to herein as “userID”).
[0082] At step 500, client device 11 communicates a request for content to first web server 12a. The request typically specifies a particular webpage for the desired content—note that a default webpage (e.g., http: / / www.example1.com / index.html) can be selected. At step 501, a response is communicated from first web server 12a to client device 11, determined based on the request. The response includes domain server communication instructions (as executable code) to be executed by the web browser of client device 11 (e.g., in the form of JavaScript code), configured to cause client device 11 to communicate with first domain server 13a. Typically, the response also includes content to be displayed on the web browser. Alternatively or additionally, first web server 12a may send reboot instructions (e.g., via a location header in the response) to first domain server 13a.
[0083] At step 503, the first domain server 13a receives communication from the client device 11 and analyzes the content to determine whether a previously set first domain cookie (typically in the header in the case of HTTP) exists.
[0084] In the presence of a first domain cookie (e.g., cookie propagation is not required), the method simply proceeds to webpage rendering step 512 (discussed below), which can be implemented by a first domain server 13a that transmits instructions to the client device 11 for further communication with the first web server 12a.
[0085] In the absence of a first domain cookie (e.g., cookie propagation or initial creation is required), at step 504, the first domain server 13a conveys a response from the first web server 12a to the client device 11. The response includes propagation server communication instructions (e.g., as executable code) to be executed by the web browser of the client device 11 (e.g., in the form of JavaScript code), which are configured to cause the client device 11 to communicate with the propagation server 16. Alternatively or additionally, the first domain server 13a may send a reboot instruction (e.g., via a location header in the response) to the propagation server 16. In response, at step 505, the client device 11 conveys a request to the propagation server 16, the request optionally including information identifying the first domain server 13a (e.g., the information may be in a URL or transmitted via a suitable network protocol).
[0086] At step 506, the propagation server 16 receives communication from the client device 11 and analyzes the content at step 505 to determine whether a propagator cookie (typically in the header in the HTTP case) exists. The presence of the propagator cookie indicates that the client device 11 has previously accessed the relevant domain (e.g., a second or third domain), thereby setting a domain cookie (e.g., a second domain cookie or a third domain cookie) relative to the relevant domain. The absence of the propagator cookie indicates that the client device 11 has not previously accessed the relevant domain and has a domain cookie set for the relevant domain.
[0087] In the absence of a propagator cookie, at step 507, the propagation server 16 is configured to determine information for recording in a new propagator cookie on the client device 11. This information may be randomly generated, programmatically generated, or alternatively generated via communication with the content server 14. Figure 5B (Not shown in the text).
[0088] In either case, at step 508, the propagation server 16 delivers a response to the client device 11. The response includes domain server communication instructions (e.g., as executable code) to be executed by the web browser of the client device 11 (e.g., in the form of JavaScript code), configured to cause the client device 11 to communicate with the original domain server 13 (i.e., the first domain server 13a in this example) at step 509. Alternatively or additionally, the propagation server 16 may directly implement a reboot to the first domain server 163 (e.g., via a location header in the response).
[0089] If step 507 is performed, the response further includes a set propagator cookie command to cause the client device 11 to set a propagator for information generated by records associated with the propagator domain.
[0090] In response, client device 11 then forwards a request to first domain server 13a at step 510. In response to the request, at step 511, first domain server 13a is configured to determine the information recorded in the propagator cookie and forward a response including a cookie-setting command to client device 11 so that client device 11 sets a first domain cookie associated with the recorded information of the first domain.
[0091] In one embodiment, domain server 13a obtains information from the web browser of client device 11. For example, the domain server communication instruction in step 508 includes information recorded in the propagator cookie and is configured to cause the web browser of client device 11 to transmit the information (preferably encrypted) to the first domain server 13a. For example, the information may be transmitted in a URL or via a suitable network protocol. Here, client device 11 effectively acts as an intermediary, which advantageously allows the method to avoid direct communication between propagation server 16 and domain server 13—this enables improved privacy and / or security (or at least improved awareness).
[0092] In an alternative embodiment, the propagation server 16 is configured to identify the first domain server 13a (more generally, the specific domain server 13 that initiates communication between the client device 11 and the propagation server 16, which can be derived from the request received by the propagation server 16), and to convey the information of the generated or previously recorded propagator cookie (or at least the data derived from the recorded information) along with information that typically identifies the specific client device 11 to the first domain server 13a.
[0093] The response also includes web server communication instructions (e.g., as executable code) for execution by the web browser of client device 11 (e.g., in the form of JavaScript code), which are configured to cause client device 11 to communicate with the original web server 12 (i.e., the first web server 12a in this example). Alternatively or additionally, the first domain server 13a may send reboot instructions (e.g., via a location header in the response) to the first web server 12a.
[0094] The method then proceeds to webpage rendering step 512 (which may also be reached after step 503). At this step, the first web server 12a communicates with the client device 11 (which may include multiple separate instances of communication) and can generate personalized content using the content of the first domain cookie—the first domain cookie is accessible by the first web server 12a because it shares the first domain with the first domain server 13a.
[0095] therefore, Figure 5BThis method can be used to efficiently propagate cookies across various web servers 12a to 12c (or more generally, the information recorded in a cookie can be propagated across different domain cookies). The propagator cookie signals to the propagator server 16 whether a client device accessing a particular web server 12 (by its presence or absence) has previously accessed another related web server 12 on a different domain, and therefore whether previously accessed previously generated information that is generally available to the plurality of related web servers 12 (e.g., all web servers 12a to 12c). For example, this information may be a UserID suitable for identifying a particular client device 11 (or a specific user of the client device 11) that has previously accessed related websites on different domains. Where the information re-encoded in the propagator cookie is an identifier such as a UserID, the domain cookie may record the UserID or information derived from the UserID as a DomainID (i.e., each DomainID is for a specific domain, but is related in a way that allows identification of the user). Therefore, a collection of domain cookies with related DomainIDs can be used by the related web server 12 to generate personalized information for the client device 11. Effective propagation is achieved through direct communication between domain server 1 and propagation server 16.
[0096] According to one embodiment, reference Figures 7A to 7C The propagation server 16 interfaces with the rules module 18 (see...). Figure 7A Rule module 18 may be a logical function of propagation server 16 (assumed herein) or may be implemented as a different physical or logical server communicating with propagation server 16. Four web servers 12a to 12d are also shown, wherein web servers 12a and 12b are associated with a first group 20a and web servers 12c and 12d are associated with a second group 20b. Although web servers 12 may be grouped according to any particular relationship, for the purposes of this invention, it is assumed that the first group 20a includes web servers 12a and 12b in domains managed (e.g., owned) by a first entity, and the second first group 20b includes web servers 12c and 12d in domains managed (e.g., owned) by a second entity different from the first entity. Accordingly, according to this embodiment, propagation server 16 is configured to manage cookie propagation for all web servers 12a to 12d (more generally, web servers 12 belonging to different groups 20).
[0097] The rules module 18 is configured to apply propagation rules before a response including a domain cookie is delivered to the client device 11 and / or the domain server 13 (depending on the embodiment). The propagation rules are used to determine whether a domain cookie is set, and if a domain cookie is set, to determine what specific data is used (e.g., the specific data may record information common to other domain cookies and / or propagation cookies in different formats, such as due to unique encryption that can be associated with a specific domain).
[0098] In one embodiment, the propagation rules for generating domain-specific cookies are stored within the associated propagation cookie itself; therefore, in this embodiment, the propagation rules are stored in the user's web browser, which advantageously avoids the central location of propagation rules from several different users. In this embodiment, the propagation rules are typically recorded in encrypted form so that direct reading of the propagation cookie does not reveal the propagation rules stored in the propagation cookie.
[0099] In one embodiment, the rules module 18 is alternatively or further configured to maintain a data structure that identifies known (i.e., previously determined) propagation cookies and related information—for example, as a database (hereinafter referred to as the "ID database"). The data structure can be updated when a new propagation cookie is determined and when the related information changes. For each user, the related information includes propagation rules (which may be default or customized).
[0100] Figure 7B This demonstrates a method for determining a response via a propagation server 16 according to one embodiment. Figure 7B The method assumes that a propagation cookie already exists associated with a specific client device 11 (or more specifically, the web browser of client device 11) - that is, the web browser has previously accessed any of the web servers 12, regardless of group 20, or in the implementation Figure 7B Previously, a propagation cookie was generated. A propagation cookie effectively represents a user (or a specific client device 11 or a web browser on a specific client device 11) and can therefore be considered an identifier. Therefore, for interpretable purposes, the content of a specific propagation cookie records the UserID.
[0101] In one embodiment, Figure 7B The method is executed as Figure 5B The part of step 508. In this case, the propagation server 16 is configured to distinguish between information stored in the propagation cookie and information stored in the domain cookie.
[0102] At step 700, the rules module 18 receives the re-encoded information in the propagation cookie (here assumed to be the UserID), and at step 701, it receives information identifying the domain of the web server 12 being accessed by the client device 11 (this information may be provided simultaneously).
[0103] At step 702, the rules module 18 then determines a specific propagation rule associated with the user (or more particularly, the propagation of the cookie). For example, depending on the embodiment, the rules module 18 may obtain the propagation rule from the actual propagation of the cookie.
[0104] In another embodiment, the UserID is compared with a record in the ID database to check if the UserID has been previously stored in the ID database. As in other embodiments, the UserID may be stored in an exported format within the actual propagation cookie, for example, using an encryption algorithm. Accordingly, the UserID may be derived from the propagation cookie.
[0105] If the rules module 18 cannot determine a specific propagation rule (e.g., depending on the embodiment, not stored in the propagation cookie or not present in the ID database), then the method proceeds to step 703, where the rules module 18 determines and selects a default rule set to apply to subsequent step 706. A single default rule set or multiple default rule sets may exist, and the rules module 18 is configured to determine one of the default rule sets as needed (e.g., based on the relevant domain, information about the client device 11, or other factors).
[0106] Additionally, at step 704, the rules module 18 stores the selected rule set as a propagation rule associated with the propagation of the cookie. For example, in a relevant embodiment, the propagation rule can be set by setting or updating the propagation cookie on the client device 11 to contain the content of the propagation cookie. For embodiments utilizing an ID database, the rules module 18 stores the selected rule set in its ID database by referencing the propagation cookie information and a user-specific rule set that may simply be the same as the selected default rule set. However, it is possible to... Figure 7B During the process, methods such as providing users with options to customize the default rule set, such as through website redirection or "pop-ups," are used, and then recorded as a user-specific rule set.
[0107] On the other hand, if the UserID does exist in the propagation cookie or ID database (where appropriate), then the method proceeds to step 705. Rule module 18 selects a specific propagation rule associated with the UserId (more specifically, the propagation cookie). The method then proceeds to step 706.
[0108] At step 706, the rules module 18 applies the selected rule set to determine the value of the domain cookie (DomainID) for communication with the relevant domain server 13 (e.g., as determined by...). Figure 5B (As used in step 508). Relatedly, the DomainID stored in the domain cookie may be different from the UserID. It should also be understood that, in one embodiment, the rules module 18 may determine not to set the DomainID if the rules set produces this determination—that is, because the embodiment does not generate a domain cookie.
[0109] In one implementation, the rule set is configured to identify domains that allow cookie propagation and domains that do not. For example, a specific propagation rule could define certain domains where the user has consented to allow cookie propagation and / or certain domains where the user has not consented to allow cookie propagation.
[0110] In the case of a user-specific rule set, a user of client device 11 that has generated a propagation cookie can, in one embodiment, access a dashboard (or other interface) associated with a specific propagation cookie to set a specific domain as either disabled or allowed. Similarly, it may be possible for a user to allow or disallow certain categories of domains (e.g., all sales domains, all news domains, etc.). The dashboard may be provided as a website associated with propagation server 16 (directly hosted on propagation server 16 or via a separate web server (not shown)).
[0111] Return to reference Figure 7A In one embodiment, the rules module 18 is further configured to determine a domain cookie based on a specific domain being accessed by the client device 11. For example, a first group 20a may be associated with a first group domain cookie and a second group 20b with a second group domain cookie—thus, the resulting specific domain cookie depends on the specific group 20. In this example, the domain cookie is set to the value of the first group domain cookie when the client device 11 communicates with web servers 12a or 12b and to the value of the second group domain cookie when the client device 11 communicates with web servers 12c or 12d.
[0112] This embodiment can be advantageous in that the propagation server 16 and domain server 13 are part of a service provided by a service provider for several different entities (and therefore groups 20). Thus, in practice, cookies are only propagated within the domains of a specific group 20—therefore, one entity does not have cookie information associated with another entity. This embodiment can also be advantageous when combined with user controls (e.g., via dashboards) based on user-specific rule sets, since the user is given control over several different groups 20 of the relevant domain. For example, if a user selects a website category to disallow propagation, this selection is applied across many different entities. For example, if a user disallows propagation in "news websites," this can apply to news websites of entity A and news websites of entity B.
[0113] It is also anticipated that some implementations will allow users to consent to having a common domain cookie on two or more groups 20, but it is possible that such cross-group propagation will generally not be allowed by default.
[0114] Figure 7B The method is suitable for execution as Figure 3 The portion of step 313 or 314 – i.e., when it is determined that a domain cookie will be set on client device 11. This subsequent situation requires the separation of webpage-specific data (e.g., ETag) from the value of the domain cookie, where ETag can play a role in propagating the cookie.
[0115] In one embodiment, the domain cookie for a specific domain can be modified. For example, a user previously allowed to propagate to a specific domain can be changed to be disallowed from exporting information using the domain's UserID. Similarly, a user can decide to cancel or delete all references to the UserID and DomainID—the cookie on client device 11 should be updated to reflect this.
[0116] Figure 7C Showing Figure 5B The method is modified – the previously described and unchanged steps are based on the previous discussion herein. Modified steps are suffixed with “A”. Step 502 always proceeds to step 504 – if a domain cookie is identified, then at step 505A, information indicating the presence of the domain cookie is conveyed to the propagation server 16. This can be achieved by causing the client device 11 to convey a propagation server communication instruction as part of a request, for example, the information may be conveyed in a URL or via a suitable network protocol. In one embodiment, the client device 11 conveys a flag indicating the presence of the domain cookie (e.g., if the presence of the domain cookie is relevant but the actual content is irrelevant for the propagation server 16 to determine and proceed to modified step 506A).
[0117] The modified step 506A checks whether propagation cookies and domain cookies exist on client device 11. However, propagation server 16 performs a predefined action after determining that propagation cookies and domain cookies do not exist. In one implementation, the absence of propagation cookies means that the user no longer wants the information available—in fact, a "delete cookie" command should be propagated.
[0118] Therefore, at step 507A, the propagation server 16 generates a delete domain cookie instruction, which is contained within the domain server communication instruction communicated at step 508A (e.g., as executable code executed by the web browser of client device 11) and is configured to cause client device 11 to communicate with the original domain server 13 (i.e., the first domain server 13a in this example). Alternatively or additionally, the propagation server 16 may directly implement a reboot to the first domain server 163 (e.g., via a location header in a response). The domain server communication instruction contains instructions that can be understood by domain server 13 to delete the domain cookie.
[0119] In response, the client device 11 then forwards the request to the first domain server 13a at step 510. In response to the request, at step 511, the first domain server 13a is configured to respond to the client device 11 at step 511A with a delete cookie instruction to delete the domain cookie based on the instruction contained in the domain server communication instruction (or, in another implementation, to set it to a null or random value), thereby effectively removing the transmitted information.
[0120] The response also includes web server communication instructions (e.g., as executable code) for execution by the web browser of client device 11 (e.g., in the form of JavaScript code), which are configured to cause client device 11 to communicate with the original web server 12 (i.e., the first web server 12a in this example). Alternatively or additionally, the first domain server 13a may send reboot instructions (e.g., via a location header in the response) to the first web server 12a.
[0121] The method then proceeds to the webpage rendering step 512. At this step, the first web server 12a communicates with the client device 11 (which may include multiple separate instances of communication), however, the generated content is not based on information previously stored in a first domain cookie.
[0122] about Figure 7CIt should be noted that in the presence of both a propagator cookie and a domain cookie, the propagation server 16 can continue by effectively resetting the domain cookie and / or the propagator cookie to their same values or by not sending a cookie setting command.
[0123] The method can also be modified relative to the case where the first domain cookie actually exists. In this case, the propagation server 16 checks whether the first domain cookie contains data that conforms to the current propagation rules. If the first domain cookie information is inconsistent with the propagation cookie information (the comparison involves the application of propagation rules), then the propagation server 16 is configured to determine an update to the first domain cookie. For example, if the user does not allow propagation to the associated domain, then the propagation server 16 can convey a delete cookie command to the web browser of the client device 11, thereby deleting the domain cookie. If the value of the domain cookie should be changed, this can also be conveyed as a new set domain cookie (equivalent to overwrite) command.
[0124] refer to Figures 7A to 7C The described embodiments can advantageously achieve a balance between privacy by allowing users to choose which domains are allowed to spread cookies and e-commerce functionality by enabling content providers to deliver customized content based on consistent identification of specific users.
[0125] It may be necessary to provide a way to notify the web browser on client device 11 of specific redirection trusts between web resources of different domains (e.g., the domain of the web server (and domain server) and the propagation domain). Similarly, it may be necessary to provide trust for web page-specific data (especially ETag) that can be associated with different domains. In each case, the technology involved avoids certain privacy and security issues of third-party cookies, but may still be considered undesirable from a trust perspective.
[0126] In one embodiment, a trust signal is defined that a web browser can be configured to recognize. The trust signal should be data accessible to the web browser and potentially (if uncertain) controlled by the same entity controlling a particular domain. For example, for an entity, it might be necessary to enable domain server 12 to redirect to or access webpage-specific data (e.g., ETag) associated with the propagation domain or another second domain, because the entity trusts the other domain due to intentionally implementing services using the embodiments described herein. A suitable trust signal can notify the web browser to allow interaction with the other domain, even if the web browser would otherwise block such interaction. For example, some web browsers have recently stopped providing ETag access across domains.
[0127] In the particular embodiment considered, the DNS of the domains of domain server 12 (i.e., the entity) is modified—in particular, the input records (here assumed to be TXT records) identifying each trusted domain are modified (e.g., as a plaintext list). For example, in the case of a first domain, a second domain, a third domain, and a propagating domain, the TXT records of the DNS entries for the first domain, the second domain, and the third domain are modified to refer to each of the other domains (including the propagating domain).
[0128] DNS TXT records can be reliably assumed to be controlled by the same entity that controls the domain, and can therefore be considered trusted. Furthermore, a web browser will likely cache DNS information during a user's session accessing the domain on client device 11. Therefore, the records are available to the web browser (potentially in cache memory) and are thus easily inspectable.
[0129] Therefore, when instructing a web browser to reboot (JavaScript, location headers, etc.) or access information from another domain, it compares that domain with the DNS TXT record to determine if the domain exists. When a web browser stores ETags (cached), for example, it can use the same logic to segment the cache based on those domains, allowing the same resource to be cached across the entire set and information and cache to be shared. This DNSTXT record method is also envisioned as a signal for "second-party cookies" or "web cookies," allowing server-side cookies to be set for those domains. That is, in practice, third-party cookies (accessed from other domains) are implemented without inherent privacy and security issues. This means that if, for example, example.com calls a resource from example01.com, then example01.com can set a cookie within a browser belonging to example01.com, even though the user is on example.com (i.e., this typically implies a third-party cookie).
[0130] Some advantages of this method may include one or more of the following: (1) only the domain owner can control the trust, meaning that JS, browsers or anyone else cannot manipulate this information; (2) even if someone reads the TXT record, it is meaningless to them; and (3) if a company adds or removes a domain from its network, the change can be propagated immediately and effectively without requiring updates to the website or any other components.
[0131] According to one embodiment, reference Figure 6A method is provided for determining the value of a domain cookie using a cookie (“content cookie”) associated with a content server 14. Similarly, the method describes using a domain cookie present on a client device 11 to determine a content cookie for transmission to a third-party server 14. This embodiment can advantageously allow the third-party content server 14 to continue using third-party cookies while avoiding setting such cookies on the client device 11.
[0132] In this case, content server 14 is associated with a domain different from both web server 12 and its associated domain server 13, and is therefore prohibited from directly setting cookie values on the web browser in response to a web browser accessing a web page on web server 12 (or at least it is expected that content server 14 will not set third-party cookies).
[0133] Therefore, domain server 13 effectively converts cookie values between those (domain cookies) existing on client device 11 and those (content cookies) used by content server 14. Figure 6 The method can be found Figure 3 In step 312, the domain cookie is not associated with the second webpage. In practice, domain server 13 converts between the content cookie (actually a third-party cookie) set on content server 14 and the first-party cookie (domain cookie) set on client device 11.
[0134] Content cookies can be associated with different functionalities. For example, content cookies can enable tracking across different web pages or improve identification and recognition.
[0135] According to this embodiment, the web browser forwards a request for information provided by content server 14 to domain server 13. This embodiment further utilizes domain server 13 as a proxy for content server 14. It should be understood that different proxy technologies can be used to utilize the described embodiment. It should also be understood that the web content of content server 14 is directly accessible; however, it is important that cookie-related information is transmitted between client device 11 and content server 14 via domain server 13.
[0136] In a specific, non-limiting instance, content server 14 may be configured to serve advertising content to a web browser in conjunction with content provided by web server 12. As is known in the art, the advertising content is served dynamically and (where available) at least in part based on identifying information associated with the web browser (or more particularly, the user of client device 11). In the prior art, this identifying information may be stored in a third-party cookie stored on the web browser—thus, targeted advertising can be served regardless of the specific domain being visited during web browsing.
[0137] At step 600, the web browser forwards a request for content from content server 14 to domain server 13 (typically, the request will identify content server 14, but in some cases, domain server 13 may automatically identify content server 14). It should be understood that the request may be one that only expects to return instructions to set content cookies associated with content server 14, but typically a response with content for display on the web browser is expected.
[0138] Domain server 13 then checks at step 601 whether a previously set domain cookie exists, which was set by domain server 13 on behalf of content server 14. Step 601 may include implementation Figure 3 The method (e.g., involving the execution of first code on the web browser) – therefore, if a domain cookie has already been set associated with another webpage on a different domain, then it is propagated to the domain cookie associated with the current webpage's domain and thus makes it available to the domain server 13 associated with the current webpage and is therefore determined to exist. Of course, if a domain cookie associated with the current webpage already exists, then it will also be determined to exist.
[0139] If no domain cookie is set (either previously or via propagation), then at step 602, domain server 13 then forwards a request for the relevant third-party content to third-party server 14. The request is not accompanied by a content cookie for use by content server 14—that is, domain server 13 does not generate a content cookie based on an existing domain cookie. At step 603, content server 14 returns the content (either back to domain server 13 or directly to the web browser of client device 11). Additionally, the response from content server 14 includes instructions to set a content cookie containing some data. In the case of advertising content, content server 14 may generate a new identifier to accompany the content cookie used to identify client device 11.
[0140] At step 604, domain server 13 generates a domain cookie based on the value of the content cookie set by content server 14. For example, the domain cookie may be generated based on an encryption algorithm or hash algorithm applied to the data of the content cookie. The domain cookie can be considered a converted "third-party" cookie because the content cookie is associated with a domain different from the domain cookie (and additionally, the domain of web server 12). At step 605, domain server 13 generates and sends instructions for the web browser of client device 11 to set the domain cookie (e.g., having attributes that make processing the server cookie available for executable code, such as by not setting HttpOnly). At step 606 (which typically occurs simultaneously with step 605), content is transmitted from domain server 13 to client device 11.
[0141] As a result of step 605, a domain cookie has been set on client device 11, and information derived from the domain cookie set by content server 14 is recorded in the content cookie. However, as discussed, the domain cookie is a first-party cookie. The domain cookie can be modified in the future based on, for example... Figure 3 The method is propagated and therefore available when client device 11 accesses other related web pages associated with different domains.
[0142] Returning to step 601, if a domain cookie is set, then at step 610, domain server 13 then forwards a request for relevant content provided by server 14 to content server 14. The request is accompanied by content from or derived from the domain cookie used by content server 14—that is, domain server 13 conveys the cookie (or the information) based on the domain cookie. At step 611, content server 14 returns the content (either back to processing server 13 or directly back to the web browser of client device 11). Content server 14 does not need to generate a new content cookie. Typically, content is generated at least in part based on cookie information (derived from the domain cookie) conveyed to content server 14 (e.g., targeted advertising). At step 612, this content is then forwarded to the web browser of client device 11, for example, via domain server 13 acting as a proxy.
[0143] Advantageously, Figure 3 and 6The methods can be operated together to achieve an effect similar to that provided by third-party cookies, while setting first-party cookies only on client device 11. That is, multiple first-party domain cookies can record the same information derived from content cookies, each of which is associated with a specific domain. Each domain cookie can then be used to generate cookie information for transmission to content server 14. From the perspective of content server 14, receiving the same value, even though a particular web resource is being accessed by a web browser on client device 11, and thus the web browser (or a particular user in combination with a particular web browser) can be identified - content server 14 does not need to modify to provide content and cookies to client device 11 because the conversion between third-party cookies and first-party cookies is handled by domain server 13.
[0144] In one variant, regarding Figure 5B In this method, the propagation server 16 can act as the domain server 13 by transcribing content cookies from the content server 14 between the content cookies and the domain cookies of each web page domain.
[0145] In one embodiment, a helper cookie needs to be set for each domain cookie. Each helper cookie may record the same information as its associated domain cookie, or at least information that can be derived from (or from) the domain cookie. In practice, each helper cookie setting will include a representation of the same information, but typically, the domain cookie is a modified version of the helper cookie, or vice versa. Each helper cookie setting has attributes that prevent executable code executed on a web browser from accessing it—that is, an HttpOnly attribute may be set, for example. Such embodiments offer the advantage that domain cookies set due to interactions with the third-party content server 14 can be set without the HttpOnly attribute—therefore, domain cookies can be read by executable code such as JavaScript, but helper cookies cannot.
[0146] According to this embodiment, whenever a domain cookie is set, a secondary cookie is also set. However, instead of reading the value of the domain cookie to generate information for communication to the content server 14, the associated secondary cookie is accessed.
[0147] In one embodiment, the helper cookie is valued equal to the content cookie, and the domain cookie is an anonymized equivalent of the content cookie. This embodiment can be useful, wherein it is preferred to set a cookie that cannot be accessed by executable code (e.g., with HttpOnly set) that may include unencrypted information (e.g., in plaintext) – that is, when set in the prior art, the helper cookie performs a function similar to a third-party cookie. However, anonymizing the domain cookie using encryption – therefore, setting it to be accessible by executable code (e.g., without HttpOnly set) carries a lower risk because the contained data is not easily readable. The helper cookie can have the effect of converting the content cookie into a first-party cookie – it appears to have exactly the same content, only set by a web page domain rather than a different domain.
[0148] The embodiments described herein can be used in various implementations. The previously discussed examples are for ad tracking. Another example is for user identification for website access purposes. In the prior art, third-party cookies are used to identify a particular web browser, as is known with different websites hosted on different domains—in this way, a particular user can avoid identifying themselves whenever they visit one of these websites. The embodiments described herein can be used to provide the same effect as third-party cookies, while setting a first-party cookie only on the client device.
[0149] Generally, in many cases where third-party cookies are used in the prior art to provide access to the same cookie data on websites on different domains, certain embodiments may be suitable for providing a similar effect while setting the first-party cookie only on the client device 11.
[0150] Figure 8A and 8B Demonstration for implementation Figure 8C and Figure 8D The topology of the embodiment shown includes a proxy server 19 configured to intercept requests for web servers 12a and 12b that are different from those for client device 11. Web servers 12a and 12b are associated with different domains (e.g., a first domain for a first web server 12a and a second domain for a second web server 12b), making a first-party cookie of one domain unreadable by web servers 12a, 12b, etc., of another domain. The proxy server 19 may be a logical function of a proxy server 19 or a domain server 13, or may be implemented as a different physical or logical server.
[0151] This can be achieved in different ways, for example, by referring to Figure 8AProxy server 19 may be associated with the domain of web server 12 via appropriately configured DNS records, and proxy server 19 is configured to communicate directly with web server 12 (e.g., via network 15, or within the same physical hardware, or in direct data communication separate from network 15, implementing different logical functions). Proxy server 19 is configured to identify the appropriate web server 12 for a particular received request based on the content of the request or the content associated with the request.
[0152] In another instance, such as Figure 8B As shown, a request is received by the relevant web server 12, which is then configured to forward the request to a proxy server 19 (e.g., via network 15, or implemented as a different logical function within the same physical hardware, or in direct data communication separate from network 15), the request being modified and returned to the relevant web server 12. Similarly, a response from web server 12 is first forwarded to proxy server 19, which can modify the response and return it to web server 12, which then transmits the modified response to client device 11.
[0153] In any instance, proxy server 19 is configured to modify, in some cases, communications from client device 11 intended for use with the relevant web server 12, and in other cases, communications from web server 12 intended for use with client device 11.
[0154] Accordingly, web server 12 is configured to convey a cookie-setting command for setting third-party cookies. Figures 8A to 8C An embodiment is configured to modify the command to cause the setting of a first-party cookie while retaining information intended for use with a third-party cookie.
[0155] At step 800, client device 11 conveys a request for content (e.g., via a webpage request), which is received by proxy server 19 at step 801. The request is associated with a first domain (e.g., www.example.com). The request typically specifies a particular webpage for the desired content—note that a default webpage (e.g., http: / / www.example.com / index.html) can be selected. Accordingly, the requested content is at least partially stored and / or generated by first web server 12a. At step 802, proxy server 19 identifies the desired web server 12 for the request (in this example, assumed to be first web server 12a).
[0156] Optionally, at step 803, the proxy server 19 generates a modified request based on the received request. The modified request includes information from the received request or information derived from the request to enable the web server 12 to provide the requested content. The information may include some or all of the header information of the request. In one embodiment, step 803 includes copying the header and body information of the request when generating the modified request. The modified request may include information that enables the original client device 11 to be identified when a response is received from the web server 12.
[0157] At step 804, proxy server 19 then forwards the modified request to the first web server 12; that is, web server 12a identified at step 802. Accordingly, the modified request identification proxy server 19 is used to receive a response to the modified request, which is generated by and received from the first web server 12a. In other words, from the perspective of the first web server 12a, the modified request originates from proxy server 19.
[0158] At step 805, proxy server 19 receives a response generated by first web server 12a. For illustrative purposes, the response includes one or more "set cookie" commands, which are instructions to set cookies for the web browser of user device 11.
[0159] Proxy server 19 is configured to analyze the received response to determine at step 806 whether one or more cookie-setting commands are associated with a domain other than the first domain—any such domain is referred to as a "third-party domain". If one or more of these commands exist, the method proceeds to step 807. Otherwise, the method proceeds to step 808.
[0160] In the presence of one or more cookie-setting commands, proxy server 19 is configured at step 807 to replace the reference to the first or each third-party domain with a new reference to the first domain. Proxy server 19 is typically configured to parse the response to identify and replace the reference to the third-party domain with the domain of the first web server 12a, thereby creating a first-party cookie. The content of the first-party cookie may be the same as the third-party cookie.
[0161] At step 808, if processed, the response is then sent to the web browser of the client device.
[0162] Figure 8D Involving optional and Figure 8C The embodiments implemented together with the embodiments. Steps 800 to 804 are equivalent to Figure 8C The steps.
[0163] as Figure 8C At step 805, proxy server 19 receives a response generated by first web server 12a. For the purpose of illustrating the present method, the response includes executable code (e.g., JavaScript) that includes instructions for the web browser of client device 11 to communicate with one or more instances of one or more content servers 14 (assuming one here) – referred to herein as content server communication instructions. The response typically also includes executable code (e.g., JavaScript) intended for use with content rendered by the receiving web browser and / or for execution by the web browser.
[0164] The proxy server 19 is configured to analyze the received response in order to identify one or more instances of third-party server communication instructions at step 816 (e.g., by parsing the response) – that is, instructions to contact another web server 12, such as a second web server 12b.
[0165] At step 817, proxy server 19 is configured to replace references to specific web resources for each of the third-party server communication instructions with references to virtual web resources, wherein the domain of the first web server 12a is utilized, causing proxy server 19 to receive communications for virtual web resources. At step 809, if processed, a response is then delivered to the web browser of the client device.
[0166] In one embodiment, the proxy server 19 maintains a mapping database in memory, wherein mapping records (i.e., the targets of associated content server communication instructions) are maintained between the generated dummy web resources and the original web resources.
[0167] Figure 8E (which includes) Figure 8D The following procedure is described in steps 820: where the client device 11 receives... Figure 8D After the executable code is executed, it communicates with proxy server 19 via a virtual web resource. At step 821, proxy server 19 compares the virtual web resource with its mapping database to identify the actual third-party web resource (e.g., at the second web server 12b). At step 822, proxy server 19 determines whether any cookies associated with the virtual web resource exist on client device 11 (and is therefore recorded as a first-party cookie for the first domain). Any such cookies, along with requests for content, are communicated to the third-party web resource (e.g., the second web server 12b) based on the mapped resource. If a response is received, its content is transmitted to client device 11, and the content is repeated as needed. Figure 8C and 8D The steps.
[0168] In this way, proxy server 19 can advantageously hide third-party web resources from client device 11, while still enabling content to be delivered from third-party web resources to client device 11.
[0169] Further modifications may be made without departing from the spirit and scope of this specification.
Claims
1. A method for recording information in a first-party cookie on a web browser, comprising: The recorded information is propagated from a second cookie associated with a second domain to a first cookie associated with a first domain, wherein both the first cookie and the second cookie are first-party cookies, enabling a first web resource addressable in the first domain and a second web resource addressable in the second domain to access the recorded information via their associated first-party cookies, wherein the web browser does not allow access to third-party cookies. During the current communication instance between the web browser and the first web resource, the recorded information is propagated to the first cookie and then propagated via an intermediary, the intermediary being propagated information accessible to the web browser during the current communication instance. The propagation includes: during the current communication instance, instructing the web browser to communicate with a propagation server associated with a propagation domain different from the first domain, and receiving the propagation information from the propagation server so that the web browser can record the recorded information as a first cookie; and The web browser initiates the current communication instance via communication with a first web server that requests content for display, the first web server being associated with a first domain server, wherein both the first domain server and the first web server are addressable in a first domain, and wherein instructions to be transmitted to the propagation server are received from the first domain server.
2. The method of claim 1, wherein the recorded information is propagated to the first cookie depending on whether the first cookie is determined to be absent.
3. The method of claim 1, wherein the first web server, after propagating the recorded information from the second cookie to the first cookie, provides the content to the web browser for display based on the recorded information.
4. The method according to any one of claims 1 to 3, wherein, as part of the instructions, the web browser provides information stored in the propagation cookie to the propagation server, and wherein the propagation information is based on the information stored in the propagation cookie.
5. The method according to claim 4, wherein the information stored in the propagation cookie and the propagation information are the same, or wherein the propagation information is an encoded representation of the information stored in the propagation cookie.
6. The method of claim 4, wherein the propagation information is generated according to propagation rules available to the propagation server, wherein the propagation rules are applied to the information stored in the propagation cookie.
7. The method of claim 6, wherein, as part of the instructions, the propagation rules are stored in the propagation cookie and provided to the propagation server.
8. The method according to any one of claims 1 to 3, wherein the propagation information is provided to the web browser in association with an instruction received from the propagation server, such that the web browser communicates with the first domain server and provides the propagation information together with the instruction.
9. The method of claim 8, wherein in response to providing the propagation information to the first domain server, the web browser receives an instruction from the first domain server to set a first cookie including the recorded information.
10. The method according to any one of claims 1 to 3, wherein the first field and the second field are determined as relevant fields that are permitted to be propagated before the recorded information is allowed to be propagated from the second cookie to the first cookie.
11. The method according to any one of claims 1 to 3, wherein, The recorded information is recorded as the first cookie data of the first cookie, wherein the first cookie data is different from the recorded information, and wherein the recorded information can be derived from the first cookie data.
12. The method according to claim 11, wherein, The second cookie includes second cookie data, wherein the record information can be derived from the second cookie data, and wherein the first cookie data and the second cookie data are different from each other.
13. A domain server capable of addressing in a first domain and configured to communicate with a web browser to facilitate the propagation of recorded information between first-party cookies associated with different domains, said domain server being configured to: Instructions are provided from a first web server, which is capable of addressing in the first domain, to the web browser to receive communications for communicating with the domain server; and Determine whether the communication contains a first cookie, which is associated with the first domain. Furthermore, in response to determining that the first cookie does not exist, the domain server is configured to: The web browser is instructed to communicate with a propagation server that can be addressed in a propagation domain different from the first domain. in, In response to the instruction, the propagation information is provided from the propagation server to the web browser; and After the web browser is instructed to communicate with the domain server again, the propagation information is received from the web browser, the propagation information being derived from recorded information of a second cookie associated with a second domain different from the first domain and the propagation domain, wherein the recorded information can be derived from the propagation information; The recorded information is determined from the propagated information; as well as The web browser is instructed to record the information in a first cookie, wherein the first cookie is associated with the first domain; The web browser communicating with the domain server is not allowed to access third-party cookies.
14. The domain server of claim 13, further configured to instruct the web browser to communicate with the first web server to enable the web browser to generate content using a re-encoded first cookie.
15. The domain server of claim 13 or 14, wherein the propagation information is generated according to propagation rules available to the propagation server, wherein the propagation rules are applied to information stored in a propagation cookie.
16. The domain server of claim 15, wherein the propagation rules are stored in a propagation cookie stored in the web browser.
17. The domain server according to claim 13 or 14, wherein, The web browser is instructed to record the recorded information as first cookie data of a first cookie, wherein the first cookie data is different from the recorded information, and wherein the recorded information can be derived from the first cookie data.
18. The domain server according to claim 17, wherein, The second cookie includes second cookie data, wherein the record information can be derived from the second cookie data, and wherein the first cookie data and the second cookie data are different.
19. The domain server of claim 13 or 14, wherein when the second domain is identified as being associated with the first domain, the recorded information is propagated only from the second cookie to the first cookie.
20. A network system for facilitating the propagation of recorded information between first-party cookies associated with different domains on a web browser communicating with the network system, the system comprising: Two or more domain servers, each domain server having associated domains, wherein the associated domains are complementary, and wherein each domain server is addressable within its associated domain. A propagation server associated with a propagation domain, wherein the propagation domain is different from the domain of the domain server. Each domain server is configured as follows: Instructions are received from the web browser by the web server associated with the domain. Determine whether the communication contains a first cookie, which is associated with the domain. In response to determining that the first cookie does not exist: The instruction directs the web browser to communicate with a propagation server capable of addressing a propagation domain different from the first domain, wherein, in response to the instruction, propagation information is provided from the propagation server to the web browser; and After the web browser is instructed to communicate with the domain server again, the propagation information is received from the web browser. The propagation information is derived from recorded information of a second cookie associated with a second domain that is different from the first domain and the propagation domain. The second domain is associated with another of the domain servers, wherein the recorded information can be derived from the propagation information. Determine the recorded information from the propagated information; and The web browser is instructed to record the information in a first cookie. The first cookie is associated with the first domain, and The propagation server is configured to determine the propagation information based on information provided from the web browser along with the instruction; The web browser communicating with the system is assumed to be either not allowed or actually not allowed to access third-party cookies.
21. The network system of claim 20, wherein, if present, the information provided from the web browser includes information stored in a propagation cookie that can be read by the propagation server.
22. The network system of claim 21, wherein the propagation server is configured to generate the propagation information according to propagation rules available to the propagation server, wherein the propagation rules are applied to the information stored in the propagation cookie.
23. The network system of claim 22, wherein the propagation rules are stored in a propagation cookie stored in the web browser and are therefore received by the propagation server via the communication from the web browser.
24. The network system according to any one of claims 21 to 23, wherein in the absence of a propagation cookie, the propagation server is configured to determine the value of the propagation cookie and transmit an instruction to the web browser to set the value as the propagation cookie, and wherein the propagation information is generated based on the latest determined value.
25. The network system according to any one of claims 20 to 23, wherein, The propagation information is an encoded representation of the information stored in the propagation cookie.
26. The network system according to any one of claims 20 to 23, wherein when the second domain is identified as being associated with the first domain, the recorded information is propagated only from the second cookie to the first cookie.
27. The network system according to any one of claims 20 to 23, wherein, For each domain server, the recorded information is stored as cookie data of an associated cookie, wherein the recorded information can be derived from the cookie data associated with each domain server, and wherein the cookie data of at least one domain server is different from the cookie data of at least one other domain server.
28. The network system according to any one of claims 20 to 23, further comprising a web server for each domain server, wherein each web server is configured to instruct a web browser to communicate with its associated domain server, and wherein each web server is capable of addressing within the same domain as its associated domain server.