Techniques for time-controlled user data privacy

CN116569201BActive Publication Date: 2026-09-22TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
CN202080107808.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-08
Publication Date
2026-09-22
Estimated Expiration
2040-12-08

AI Technical Summary

Technical Problem

在许多情况下,对于4G/LTE或更早几代的移动技术实时上传数据并接收响应来说,这点时间太短了

Benefits of technology

[0046]·出于标识的目的为相同传输指配多个标识符(例如,1AdID、QuickID、LongID)。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116569201B_ABST
    Figure CN116569201B_ABST
Patent Text Reader

Abstract

The present disclosure relates to techniques for providing and facilitating time- controlled data for protecting privacy of data sources. Embodiments are provided herein for methods, procedures, apparatuses, network nodes, computer program products, and computer readable media. In some embodiments, a network node receives first data of a first data transaction assigned a unique identifier. In response, the network node enables transmission of second data and the unique identifier to one or more entities. In accordance with a determination that an indication of a time limit indicates a non-zero time limit for retaining the first data of the first data transaction, the node enables storage of one or more of the first data and the second data in accordance with the time limit. In accordance with a determination that the indication does not indicate a non-zero time limit, the node causes deletion of the first data and the second data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the collection and processing of data via a network, and in particular, to providing time-controlled data for the purpose of protecting the privacy of the data source. Background Technology

[0002] Generally, all terms used herein shall be interpreted according to their common meaning in the relevant technical field, unless a different meaning is implied and / or clearly given from the context in which they are used. All references to a / an / the element, device, component, part, step, etc. shall be interpreted openly as referring to at least one instance of that element, device, component, part, step, etc., unless otherwise expressly stated.

[0003] The steps of any method disclosed herein need not be performed in the exact order disclosed, unless a step is explicitly described as occurring after or before another step, and / or it implies that a step must occur after or before another step. Where appropriate, any feature of any embodiment of the examples disclosed herein may be applied to any other embodiment. Similarly, any advantage of any embodiment in the examples may be applied to any other embodiment, and vice versa. Further objects, features, and advantages of the appended embodiments will become apparent from the following description.

[0004] Individual-level data is the cornerstone of the global economy. Companies use this data to generate insights that inform business decisions and to make predictions that improve business processes. Many aspects of the global economy, as they are currently designed, cannot function without access to individual-level data on behavior, psychology, location, or purchasing. For example, telecommunications operators like Ericsson use individual-level location and behavioral data to optimize network design and rollout by deciding where to place cellular phone towers and what profiles to assign them. Similarly, digital advertisers use individual-level data to assign users to audiences, who then determine what ads users see. In this last example, transportation planners use individual-level data to understand the origin-destination matrix of transportation planning and to charge vehicles tolls or congestion charges.

[0005] Whether managing the entire production and sales process (vertical) or usage, these industries share common data architectures; they rely on access to historical data repositories. Companies such as Epsilon, Acxiom, and KBM operate these repositories, which constitute a significant portion of the data economy. They obtain their underlying data from multiple sources, including directly from the company's customer relationship management (CRM) software. The companies then enrich their first-party data with second- and third-party data purchased from aggregators to improve the performance of their statistical and / or AI models.

[0006] Analysts predict that 5G New Radio (NR) will fundamentally transform the data ecosystem in several ways. First, it will lead to a surge in new types of sensors and IoT devices. Unlike the historical nature of data held by aggregators, these sensors will generate extremely rich data in real time. Second, consumers will increasingly rely on 5G NR to connect their in-home devices and wearable sensors, thus centralizing data flows within mobile network operators (MNOs). This contrasts with today, where existing devices and sensors connect via Bluetooth, 4G / LTE, and / or WiFi, thus fragmenting data flows.

[0007] These changes have profound implications for end-user data privacy and management. If today's consumers are uneasy about their data being stored in persistent databases, they will likely refuse to share data from these new sources if business applications require permanent storage. Policymakers and legislators are imposing new legal requirements on the data ecosystem, such as California's Consumer Privacy Act (CCPA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and the European Union's General Data Protection Regulation (GDPR). In addition to restricting data aggregators, these new legal regimes impose hefty penalties for the mishandling of personally identifiable data. This underscores the need for architectural solutions for data privacy and management.

[0008] Besides the lack of a suitable architecture, latency and speed have historically been obstacles to processing real-time data. For example, according to the standards set by the Interactive Advertising Bureau, the maximum allowed time for the entire digital advertising process to complete is 200 milliseconds. In many cases, this time is too short for 4G / LTE or earlier mobile technologies to upload data and receive responses in real time. However, 5G NR and WiFi offer sufficiently high speeds and low latency to allow for real-time data upload and processing. Summary of the Invention

[0009] Improvements in latency and speed can be a key component in any architecture related to data privacy. For example, the applicant's previous work (PCT application number: PCT / IB2019 / 060191) involved techniques for end-user control over which data is uploaded to edge and / or cloud (hereinafter referred to as edge cloud) computing facilities via 5G NR / WiFi for data processing. A one-time-use ID (e.g., 1AdID) associates a data array with any user equipment (UE). Once a prediction and / or inference is returned, the underlying data array is deleted. Because the 1AdID is temporarily defined, the company can only send data back to the UE as long as the 1AdID remains valid. This creates an architecture where no user data is retained for more than a few seconds.

[0010] Several challenges exist. While the architecture described in earlier inventions considered complete end-user privacy, the near-instantaneous deletion of all user data severely limits data utility and creates problems from a user experience perspective. Consider digital advertising. Advertisers may benefit from using real-time data to send highly personalized and relevant coupons to users (e.g., due to lower costs achieved by avoiding data storage associated with big data lakes). However, once 1AdID is deleted, retailers cannot measure campaign effectiveness or retarget customers; there is simply no data to link advertising to consumer behavior. In a similar example, removing traffic managers' access to persistent data would mean that road toll authorities cannot determine whether a vehicle has paid congestion charges. These challenges will slow the adoption of AI-based systems and hinder their utility.

[0011] While previous work on this topic focused on consent management, it did not specifically incorporate network architecture elements such as mobile networks, edge computing, or allow preferences to be set via the UE and transmitted over the network. Furthermore, previous work did not allow the integration of data from nearby sensors, IoT devices, or wearable devices.

[0012] The problem with current solutions is twofold. Most solutions related to differential privacy have developed statistical techniques to maintain the underlying data distribution while corrupting the original data (see, for example: US Patent No. 20190065775A1, "Calculating differentially private queries using local sensitivity on time variant databases"; US Patent No. 10489605B2, "Differentially privatized sensitivity plots"; US Patent No. 10192069B2, "Differentially private processing and database storage"; US Patent No. 10366249B2, "System and method for privacy management of infinite data streams"; US9916472B2, "Obfuscation and protection of data rights"; US Patent No. 20180349636A1, "Differential privacy using a countmean sketch"; US Patent No. 20180349638A1, "User experience using privatized crowdsourced..."). The applicant's previous work considered complete privacy protection, but did not allow data to be retained for longer than a few milliseconds. This made inferences across larger time scales impossible. (See US9672364B2 "Differentially private linear queries on histograms" and US20170357820A1 "Efficient Implementation for differential privacy using cryptographic functions").

[0013] For example, the following features are missing in existing solutions:

[0014] • The ability for end users to set global preferences for how long data remains available in a graphical user interface (GUI).

[0015] • The ability for end users to change the length of time data remains available for different entities (e.g., companies) within the GUI.

[0016] • The ability of end users to change the length of time data remains available for different purposes within an entity in the GUI.

[0017] • The ability of end users to choose to immediately discard some data and transfer other original data fragments to the database for other purposes.

[0018] • Assign multiple identifiers to the same transmission for identification purposes (e.g., 1AdID, QuickID, LongID).

[0019] • The ability of a company to request access to user data from a centralized database via LongID or any other arbitrary identifier.

[0020] • The ability to delete lower-level data stored in a centralized database and send receipts confirming the deletion of that data based on retention rules set by the end user.

[0021] Therefore, there is a desire to permit technologies for obtaining and processing data from user devices in a time-controlled and privacy-preserving manner. Various embodiments are presented herein that aim to address one or more of the problems disclosed herein. For example, an architecture is proposed herein that allows data to be processed at the edge or in the cloud, and then deleted after a configured time limit.

[0022] In some embodiments, a method performed by a network node includes: receiving first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction. The method further includes: in response to receiving the first data from the device, enabling the transmission of second data and the unique identifier to one or more data receiving entities, wherein the second data is associated with an indication of a time limit for retaining the first data of the first data transaction, and wherein the second data is at least one of: an instance of the first data, data including the first data, and data generated using the first data. The method further includes: indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling the storage of one or more of the first data and the second data according to the time limit; and not indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, causing the deletion of the first data and the second data.

[0023] In some embodiments, a network node includes one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the network node to perform the following operations: receiving first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction. The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: in response to receiving the first data from the device, enabling the transmission of second data and the unique identifier to one or more data receiving entities, wherein the second data is associated with an indication of a time limit for retaining the first data of the first data transaction, and wherein the second data is at least one of: an instance of the first data, data including the first data, and data generated using the first data. The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling the storage of one or more of the first data and the second data according to the time limit; and not indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, causing the deletion of the first data and the second data.

[0024] In some embodiments, a non-transitory computer-readable medium includes instructions executable by one or more processors of a network node, the instructions including instructions for performing the following operations: receiving first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction. The instructions further include instructions for performing the following operations: in response to receiving the first data from the device, enabling the transmission of second data and the unique identifier to one or more data receiving entities, wherein the second data is associated with an indication of a time limit for retaining the first data of the first data transaction, and wherein the second data is at least one of: an instance of the first data, data including the first data, and data generated using the first data. The instructions further include instructions for performing the following operations: indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling the storage of one or more of the first data and the second data according to the time limit; and not indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, causing the deletion of the first data and the second data.

[0025] In some embodiments, a transient computer-readable medium includes instructions executable by one or more processors of a network node, the instructions including instructions for performing the following operations: receiving first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction. The instructions further include instructions for performing the following operations: in response to receiving the first data from the device, enabling the transmission of second data and the unique identifier to one or more data receiving entities, wherein the second data is associated with an indication of a time limit for retaining the first data of the first data transaction, and wherein the second data is at least one of: an instance of the first data, data including the first data, and data generated using the first data. The instructions further include instructions for performing the following operations: indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling the storage of one or more of the first data and the second data according to the time limit; and not indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, causing the deletion of the first data and the second data.

[0026] In some embodiments, a computer program includes program code to be executed by one or more processors of a network node, whereby execution of the program code causes the network node to perform operations including: receiving first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction. The operations further include: in response to receiving the first data from the device, enabling the transmission of second data and the unique identifier to one or more data receiving entities, wherein the second data is associated with an indication of a time limit for retaining the first data of the first data transaction, and wherein the second data is at least one of: an instance of the first data, data including the first data, and data generated using the first data. The operations further include: indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling the storage of one or more of the first data and the second data according to the time limit; and not indicating, according to the time limit indication, the determination of a non-zero time limit for retaining the first data of the first data transaction, causing the deletion of the first data and the second data.

[0027] In some embodiments, a method performed by an electronic device includes: presenting one or more options for configuring one or more data retention time limits for one or more categories of data, wherein the one or more categories of data are associated with one or more data transactions, the one or more data transactions relating to a user profile associated with the electronic device, wherein each of the one or more data retention time limits controls the length of time for which a remote user data collection system is permitted to retain certain data of the one or more categories of data associated with a corresponding data retention time limit of the one or more data retention time limits. The method further includes: receiving user input associated with the one or more options, the user input specifying a first data retention time limit for data of a first category. The method further includes: causing the first data retention time limit to be associated with a user profile associated with the electronic device. The method further includes: when the first data retention time limit is associated with a user profile, transmitting one or more datasets of data considered as a first category for storage at a remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data considered as a first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier.

[0028] In some embodiments, an electronic device includes one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the electronic device to perform the following operations: presenting one or more options for configuring one or more data retention time limits for one or more categories of data, wherein the one or more categories of data are associated with one or more data transactions relating to a user profile associated with the electronic device, wherein each of the one or more data retention time limits controls the length of time for which a remote user data collection system is permitted to retain certain data of the one or more categories of data associated with a corresponding data retention time limit of the one or more data retention time limits. The memory includes instructions executable by the one or more processors to cause the electronic device to perform the following operations: receiving user input associated with the one or more options, the user input specifying a first data retention time limit for data of a first category. The memory includes instructions executable by the one or more processors to cause the electronic device to perform the following operations: causing the first data retention time limit to be associated with a user profile associated with the electronic device. The memory includes instructions executable by the one or more processors to cause the electronic device to perform the following operations: when a first data retention time limit is associated with a user profile, transfer one or more datasets of data classified as a first category to be stored at a remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data classified as the first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier.

[0029] In some embodiments, a non-transitory computer-readable medium includes instructions executable by one or more processors of an electronic device, the instructions including instructions for performing the following: presenting one or more options for configuring one or more data retention time limits for one or more categories of data, wherein the one or more categories of data are associated with one or more data transactions relating to a user profile associated with the electronic device, wherein each of the one or more data retention time limits controls the length of time for which a remote user data collection system is permitted to retain certain data of the one or more categories of data associated with a corresponding data retention time limit of the one or more data retention time limits. The instructions further include instructions for performing the following: receiving user input associated with the one or more options, the user input specifying a first data retention time limit for data of a first category. The instructions further include instructions for performing the following: causing the first data retention time limit to be associated with a user profile associated with the electronic device. The instructions further include instructions for performing the following operations: when a first data retention time limit is associated with a user profile, transmitting one or more datasets of data classified as a first category for storage at a remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data classified as the first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier.

[0030] In some embodiments, a transient computer-readable medium includes instructions executable by one or more processors of an electronic device, the instructions including instructions for performing the following: presenting one or more options for configuring one or more data retention time limits for one or more categories of data, wherein the one or more categories of data are associated with one or more data transactions relating to a user profile associated with the electronic device, wherein each of the one or more data retention time limits controls the length of time for which a remote user data collection system is permitted to retain certain data of the one or more categories of data associated with a corresponding data retention time limit of the one or more data retention time limits. The instructions further include instructions for performing the following: receiving user input associated with the one or more options, the user input specifying a first data retention time limit for data of a first category. The instructions further include instructions for performing the following: causing the first data retention time limit to be associated with a user profile associated with the electronic device. The instructions further include instructions for performing the following operations: when a first data retention time limit is associated with a user profile, transmitting one or more datasets of data classified as a first category for storage at a remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data classified as the first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier.

[0031] In some embodiments, a computer program includes program code to be executed by one or more processors of an electronic device, whereby execution of the program code causes the electronic device to perform operations including: presenting one or more options for configuring one or more data retention time limits for one or more categories of data, wherein the one or more categories of data are associated with one or more data transactions relating to a user profile associated with the electronic device, wherein each of the one or more data retention time limits controls the length of time for which a remote user data collection system is permitted to retain certain data of the one or more categories of data associated with a corresponding data retention time limit of the one or more data retention time limits. The operation further includes: receiving user input associated with the one or more options, the user input specifying a first data retention time limit for data of a first category. The operation further includes: causing the first data retention time limit to be associated with a user profile associated with the electronic device. The operation further includes: when the first data retention time limit is associated with a user profile, transmitting one or more datasets of data considered as a first category for storage at a remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data considered as a first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier.

[0032] In some embodiments, a method is performed by a network node, the method comprising: receiving first data of a first data transaction associated with a user profile, wherein the first data includes: a first unique identifier that uniquely identifies the first data transaction involving a device associated with the user profile; an identifier of an external requesting entity other than the user profile that is permitted to access the first data; an indication of a first time limit for retaining the first data of the first transaction; and first person data provided by the device associated with the user profile. The method further includes storing the first data for access by the external requesting entity. The method further includes: providing the first unique identifier and the first person data to the external requesting entity other than the user profile. The method further includes: deleting at least a portion of the first data including the first unique identifier once the first time limit for retaining the first data of the first transaction expires.

[0033] In some embodiments, a network node includes one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the network node to perform the following operations: receiving first data of a first data transaction associated with a user profile, wherein the first data includes: a first unique identifier uniquely identifying the first data transaction involving a device associated with the user profile; an identifier of an external requesting entity other than the user profile that is permitted to access the first data; an indication of a first time limit for retaining the first data of the first transaction; and first person data provided by the device associated with the user profile. The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: storing the first data for access by the external requesting entity. The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: providing the first unique identifier and the first person data to the external requesting entity other than the user profile. The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: deleting at least a portion of the first data including the first unique identifier once the first time limit for retaining the first data of the first transaction expires.

[0034] In some embodiments, a non-transitory computer-readable medium includes instructions executable by one or more processors of a network node, the instructions including instructions for performing the following: receiving first data of a first data transaction associated with a user profile, wherein the first data includes: a first unique identifier uniquely identifying the first data transaction involving a device associated with the user profile; an identifier of an external requesting entity other than the user profile that is permitted to access the first data; an indication of a first time limit for retaining the first data of the first transaction; and first person data provided by the device associated with the user profile. The instructions further include instructions for performing the following: storing the first data for access by the external requesting entity. The instructions further include instructions for performing the following: providing the first unique identifier and the first person data to the external requesting entity other than the user profile. The instructions further include instructions for performing the following: deleting at least a portion of the first data including the first unique identifier once the first time limit for retaining the first data of the first transaction has expired.

[0035] In some embodiments, a transient computer-readable medium includes instructions executable by one or more processors of a network node, the instructions including instructions for performing the following: receiving first data of a first data transaction associated with a user profile, wherein the first data includes: a first unique identifier uniquely identifying the first data transaction involving a device associated with the user profile; an identifier of an external requesting entity other than the user profile that is permitted to access the first data; an indication of a first time limit for retaining the first data of the first transaction; and first person data provided by the device associated with the user profile. The instructions further include instructions for performing the following: storing the first data for access by the external requesting entity. The instructions further include instructions for performing the following: providing the first unique identifier and the first person data to the external requesting entity other than the user profile. The instructions further include instructions for performing the following: deleting at least a portion of the first data including the first unique identifier once the first time limit for retaining the first data of the first transaction has expired.

[0036] In some embodiments, a computer program includes program code to be executed by one or more processors of a network node, whereby execution of the program code causes the network node to perform operations including: receiving first data of a first data transaction associated with a user profile, wherein the first data includes: a first unique identifier that uniquely identifies the first data transaction involving a device associated with the user profile; an identifier of an external requesting entity other than the user profile that is permitted to access the first data; an indication of a first time limit for retaining the first data of the first transaction; and first personal data provided by the device associated with the user profile. The operation further includes storing the first data for access by the external requesting entity. The operation further includes: providing the first unique identifier and the first personal data to the external requesting entity other than the user profile. The operation further includes: deleting at least a portion of the first data including the first unique identifier once the first time limit for retaining the first data of the first transaction expires.

[0037] Certain aspects of this disclosure and its embodiments may provide solutions to these or other challenges. In this disclosure, the applicant proposes a novel architecture that uses low-latency and high-speed networks (such as 5G NR and / or WiFi) to protect the privacy of personal-level data. Low latency and high speed are important because inference is often required using real-time data paired with historical data in near real-time. Unlike prior art, the architecture described herein does not require the immediate deletion of all personal-level data. Instead, the techniques described herein utilizing the applicant's proposed architecture allow end-users to share predictions, inferences, and even raw data with business requesters and manage the length of time these fields can be matched with their UE. In some embodiments, to do this, whenever a UE uploads a data array to an edge cloud environment, the nodes or systems of the architecture assign one or more of three unique identifiers: 1AdID, QuickID, and LongID. In some embodiments, 1AdID is used to uniquely identify the UE. In some embodiments, QuickID allows for the immediate sharing of insights and / or predictions according to digital advertising. In some embodiments, LongID allows end-users to store results and predictions in a database maintained by an MNO or other data bank. For example, an entity (e.g., a company) can then request access to an end-user's data via its LongID. Crucially, the end-user can be a user who specifies the duration of validity for each LongID, meaning they can revoke the company's access to their data at any time or automatically. This allows end-users complete control over their data while granting the company access for longer than milliseconds.

[0038] Another difference between the technology described in this paper and existing technologies is that the architecture described in this paper can be incorporated (e.g., included or connected to) a second database (e.g., for third parties) where users can store insights, predictions, or raw data. Such a database is innovative because it incorporates some ongoing computer science and statistical research on differential privacy into the data and network architecture.

[0039] The technology described in this paper proposes a novel architecture that incorporates state-of-the-art differential privacy to allow end-users complete control over their personal data while potentially enabling companies to access predicted, inferred, or raw data for more than milliseconds. This latter observation is a key difference from the applicant's earlier work in the field, which did not allow any data to be retained longer than strictly necessary. While such stringent measures can ensure complete privacy, there are numerous use cases where companies require longer access to personal data.

[0040] In this new architecture, the applicant's technology benefits from the anticipated centralization of connectivity from 5G NR and WiFi. Unlike earlier generations of mobile networks where sensors, wearables, and IoT devices connected via various media, the applicant anticipates that in the near future, these devices will primarily connect to the network via 5G NR. In some embodiments, an initial step in the technology utilizing the proposed architecture is to incorporate user data into an array on the UE and upload it to an edge cloud environment (e.g., a server or processing environment located at or near the network edge) and identify it using its 1AdID. In some embodiments, as an alternative or supplementary initial step, relevant data from sensors, wearables, and IoT devices located at a distance from the UE (e.g., an arbitrary, predefined, or similar distance) may be included in the array (further details regarding physical distance are provided in the following detailed description). In some embodiments, as an alternative or supplementary initial step, relevant data from sensors, wearables, and IoT devices may be uploaded directly (e.g., without via the UE) to the edge cloud and associated with the UE data using 1AdID.

[0041] One or more embodiments of the architecture and technologies described herein may include or enable one or more of the following features:

[0042] • The ability for end users to set global preferences for how long data remains available in a graphical user interface (GUI).

[0043] • The ability for end users to modify data in the GUI for the length of time it remains available to different companies.

[0044] • The ability of end users to modify data in the GUI for the length of time it remains available for different purposes within a company.

[0045] • The ability of end users to choose to immediately discard some data and transfer other original data fragments to the database for other purposes.

[0046] • Assign multiple identifiers to the same transmission for identification purposes (e.g., 1AdID, QuickID, LongID).

[0047] • The ability of a company to request access to user data from a centralized database via LongID or any other arbitrary identifier.

[0048] • The ability to delete lower-level data stored in a centralized database and send receipts confirming the deletion of that data based on retention rules set by the end user.

[0049] Certain embodiments may offer one or more of the following technical advantages. In particular, the embodiments disclosed herein may include one or more advantages over earlier generations of privacy-preserving solutions. For example, some embodiments disclosed herein can eliminate this step while maintaining privacy, compared to earlier research and inventions that focused on protecting privacy by altering underlying data. Removing this step can reduce computation time and prevent the algorithm from inducing statistical errors. As another example, some embodiments described herein can allow commercial end-users to access predictions and inferences that take longer than a few seconds. This can reduce unnecessary repetitive computations in such predictions and inferences and improve their utility, which can help drive the commercialization of privacy-preserving architectures.

[0050] Certain embodiments described herein provide a novel architecture for handling end-user data with privacy concerns due to one or more of the following:

[0051] Process user data at the edge or in the cloud

[0052] • Allows end users to assign different retention rules to data.

[0053] · Store data with longer retention rules in a database.

[0054] • Assign a unique identifier to the data stored in the database, and this unique identifier shall not be allowed to re-identify the originating UE.

[0055] • Delete data from the database according to the retention rules set by the end user.

[0056] • Send a confirmation receipt for deletion from the edge cloud or database

[0057] Some embodiments related to the proposed architecture described in this paper can provide the following advantages:

[0058] • Speed: Using 5G, edge computing, and cloud computing will allow inference and prediction processes via machine learning, statistics, and AI to be completed much faster than current solutions.

[0059] • Scalability: The architecture is scalable because it is cloud and edge-ready.

[0060] • Flexibility: The architecture is flexible because all inference can be performed on the end-user's device, at the edge, or in the cloud.

[0061] • Privacy: By allowing true differential privacy, this solution is more private than previous solutions.

[0062] • Context: By including real-time data and making it available over a longer time period, the resulting inferences should be far superior.

[0063] Additional details are provided below. Attached Figure Description

[0064] Figure 1 An exemplary user interface according to some embodiments is shown.

[0065] Figure 2 An exemplary user interface according to some embodiments is shown.

[0066] Figure 3 An exemplary user interface according to some embodiments is shown.

[0067] Figure 4 Exemplary unique identifiers according to some embodiments are shown.

[0068] Figure 5 Exemplary unique identifiers according to some embodiments are shown.

[0069] Figure 6 Exemplary observations associated with unique identifiers according to some embodiments are shown.

[0070] Figure 7 Operation of an exemplary architecture according to some embodiments is shown.

[0071] Figure 8 Operation of an exemplary architecture according to some embodiments is shown.

[0072] Figure 9 Operation of an exemplary architecture according to some embodiments is shown.

[0073] Figure 10 Operation of an exemplary architecture according to some embodiments is shown.

[0074] Figure 11 Exemplary processes according to some embodiments.

[0075] Figure 12 Exemplary processes according to some embodiments.

[0076] Figure 13 Exemplary processes according to some embodiments.

[0077] Figure 14 An exemplary wireless network according to some embodiments is shown.

[0078] Figure 15 An exemplary user device according to some embodiments is shown.

[0079] Figure 16 An exemplary virtualization environment according to some embodiments is shown.

[0080] Figure 17 An exemplary telecommunications network is shown, which is connected to a host computer via an intermediate network according to some embodiments.

[0081] Figure 18 An exemplary host computer, according to some embodiments, communicates with an exemplary user equipment via a partial wireless connection through an exemplary base station. Detailed Implementation

[0082] Some embodiments of the ideas contemplated herein will now be described more fully with reference to the accompanying drawings. However, other embodiments are included within the scope of the subject matter disclosed herein, and the disclosed subject matter should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0083] 1. User Controls for Data Privacy

[0084] According to some embodiments, the ability of end-users to set global preferences on how long data remains available is a feature of the proposed architecture. This process can be accomplished in various ways, such as via a user interface that can receive direct input of user preferences or through an AI system that can learn and predict based on user actions and behaviors. In this disclosure, the applicant presents examples of hypothetical graphical user interfaces for handling those preferences.

[0085] Figure 1 An exemplary privacy settings user interface screen is shown, in which a user can select which devices can send data to be uploaded to the edge cloud for inference. Specifically, Figure 1 A physical model of an exemplary user interface 110 on an exemplary UE 100 (a smartphone with a touch-sensitive display surface) is depicted, wherein an end user selects which data to include in their initial data array for uploading to an edge cloud. The exemplary user interface 110 includes a user identifier 112 (associated with or otherwise representing a user account), a previous screen icon 114, a previous screen title 116 (“Privacy Settings”), a current screen title 118 (“Device Registered to This Account”), and device selectors 120, 122, 124, 126, 128, and 130. Figure 1 Each device selector in the device selector includes a selectable toggle icon (e.g., displayed as "on" or "off") for selecting which devices can send data to the edge cloud for inference (e.g., by clicking a toggle icon). Other arrangements and presentations of the user interface 110 for selecting devices are also possible and are intended to be within the scope of this disclosure.

[0086] In this example, besides Figure 1In addition to selecting the type of device data uploaded to one or more arrays in the edge cloud, as in the example above, end users can also be presented with the option to select the duration for which the data is available. In some embodiments, users set a default duration (e.g., a global default duration). In some embodiments, users set one or more individual duration lengths for different business requesters (e.g., each business requester has one or more associated configured durations). Figure 2 and Figure 3 An example of such a selection is shown in the figure.

[0087] Figure 2 An exemplary user interface 210 is shown on a UE for facilitating data sharing time limits. Using user interface 210, an end user can select how long specific data fields uploaded to the edge cloud are reserved for different entities (e.g., business requesters, companies, third-party users). In this example, the end user selects how long entities named "Mobile Phone Service Provider," "Public Transportation Operator," "City Service," and "Retailer" are entitled to access data fields. Exemplary user interface 210 includes a user identifier 112, a previous screen icon 214, a previous screen title 216 ("Privacy Settings"), a current screen title 218 ("Data Sharing Time Limits"), and entity selectors 220, 222, 224, and 226 (each selector corresponding to a specific entity, i.e., mobile phone service provider, public transportation operator, city service, and retailer). Figure 2 In the example, UE 100 can receive the selection from the entity selector and, in response, present the user with an interface for selecting a time limit (similar to...). Figure 3 (As shown in the image) (for example, displayed together with the current user interface or overlaid on the current user interface, or displayed on a new user interface screen).

[0088] In some use cases, end users may prefer to customize the duration for which data remains available for different use cases. These options are later documented in the LongID assigned to each array, and they can be customized based on... Figure 3 Configure the example user interface in [the example].

[0089] Figure 3An exemplary user interface 310 on a UE is shown for facilitating data sharing time limits. Using user interface 310, an end user can select how long to retain data uploaded to the edge cloud for different use cases within the same entity (e.g., a business requester). In this case, the end user has granted an entity named "Mobile Phone Service Provider" access to advertising data for 12 hours (indicated by selector 320), but access to billing data for 30 days (indicated by selector 322). Additionally, the entity has subsequently been granted access to service optimization data for 5 days (indicated by selector 324) and media data for 0 days (e.g., immediate deletion) (indicated by selector 326). The exemplary user interface 310 includes a user identifier 112, a previous screen icon 314, a previous screen title 316 ("Data Sharing Time Limit"), a current screen title 318 ("Mobile Phone Service Provider Data Sharing Time Limit"), and a time limit selector 328. In this example, the time limit selector 328 can be used to adjust the time limit by vertically scrolling the value in the corresponding box to increase the number of days, hours, and / or minutes, and by using the appropriate icon (labeled "Accept" in this example) to accept the selected time limit. Any other suitable time selection interface or input field can be used.

[0090] The applicant noted that Figure 1 , 2 The exemplary interfaces shown in Figures 3 and 4 are provided merely as examples, and these interfaces may include fewer elements than those shown, additional elements not shown, or different arrangements, while still providing the functionality intended to be within the scope of this disclosure. Any such deviation from the illustrated examples is intended to be within the scope of this disclosure.

[0091] 2. Assign QuickID and LongID

[0092] Continuing the example above, once in an edge cloud environment, the next step is to assign two additional identifiers to the array: QuickID and LongID. QuickID is for one-time use and can be configured to map to any industry-specific ID, such as Ad-ID in digital advertising. After a few milliseconds, QuickID can no longer be used to route traffic to the UE because, for example, the edge cloud (e.g., 716) removes any association between the UE's identifier and the UE's QuickID from its memory—therefore, any transmissions from the advertiser cannot be routed to the correct UE, as the advertiser only knows the QuickID and not the UE's identifier. Figure 4 The hypothetical QuickID is shown.

[0093] Figure 4An exemplary QuickID 400 is shown. The first 7 characters uniquely identify the entity (e.g., a company), and a 6-digit prefix code identifies the device. In some embodiments, the 6-digit prefix code is optional. For example, the 6-digit prefix code can be a unique ID (e.g., an industry-standard defined Ad-ID or some other unique identifier). The QuickID may also have a usage code for identifying one or more permitted uses of data in the array, such as... Figure 4 As shown in the diagram. According to some embodiments, for QuickIDs, the time limit in hours is always 0000 to ensure they are retained for no longer than a few milliseconds (e.g., no longer than the time required for processing or routing). A checksum is used to verify the QuickID. In this case, the resulting QuickID is [ABCDEFG001000001ABC123456700000001]. In some embodiments, the identifier (e.g., QuickID) may include one or more of the aforementioned fields (e.g., but less than all).

[0094] In contrast, LongID can be nearly identical in form to QuickID, but allows end users to set time limits for periods greater than 0 hours. LongIDs can be generated for each user and entity (e.g., a company) with whom the end user has agreed to share data. This allows end users to control how long an entity has the right to access different data fields.

[0095] Figure 5 An example LongID 500 is shown. The first seven characters uniquely identify the entity (e.g., a company), and a six-digit prefix code is used to identify the device. LongIDs can also have usage codes as described above with respect to QuickIDs. For LongIDs, the time limit in hours is the number of hours these data can be retained in the database. Of course, other time increments can also be used to set time limits within LongIDs or QuickIDs. A checksum is used to verify the LongID. In this case, the resulting LongID is [ABCDEFG001000001ABC123456700010001].

[0096] The time constraint field can default to a predefined value for each generated LongID, or it can be generated in a more complex way that takes into account one or more of the following: the sensitivity of the stored information, the potential need for that information, and user preferences. For example, in the case of sensitive medical information, such as when dispatching an ambulance, an accrediting authority should be able to request permanent access to certain LongIDs (e.g., blood pressure readings / predictions). In some embodiments, the identifier (e.g., LongID) may include one or more of the aforementioned fields (e.g., fewer than all).

[0097] As those skilled in the art will recognize, the data structures of QuickID and LongID may include the same fields, wherein the only distinguishing feature between the two is whether the time limit field is set to a zero or non-zero representation of the time limit (e.g., 0000 hours versus 0001 hours). As used herein, and unless otherwise stated, the term "QuickID" or "LongID" may be used to refer to a given identifier solely to inform the reader whether the time limit field has a zero or non-zero representation therein. Therefore, the terms "QuickID" or "LongID" are used in this disclosure to help the reader understand the time limit associated with the examples used herein, and these terms do not necessarily refer to different data structures. Nothing in this paragraph should be construed as an explicit or implicit statement that any two identifiers (e.g., QuickID and LongID) need to include fields of the same type and number as each other (e.g., use code, checksum, or the like). For example, QuickID may omit the use code field, while LongID of the same device or data may include a use code field, wherein the additional difference is that LongID has a non-zero time limit, while QuickID does not.

[0098] As a technician should further recognize, when referring to a zero time limit or, conversely, a non-zero time limit, the applicant intends that such representation of these concepts include (or exclude) any possible representation of the time limit, whether expressed numerically (e.g., as zero) or otherwise (e.g., as binary "yes" or "no").

[0099] 2.1 Assigning 1 AdID

[0100] This document mentions 1AdID. An exemplary 1AdID creation is included in PCT application number PCT / IB2019 / 060191, which is incorporated herein by reference. Below is a brief description of the exemplary 1AdID generation process.

[0101] In step 1, the end user (e.g., by accessing or launching an application with display advertising opportunities, such as a website, app, or video game) triggers a data transaction opportunity (e.g., an advertising opportunity). In the case of extended reality (XR) advertising, the user can input a physical location to cause such a trigger. The physical location can be obtained via a location service that uses Global Positioning System (GPS), Bluetooth, Wi-Fi, or cellular (e.g., 5G) radio signals to estimate the location of the user's device (e.g., 100).

[0102] In step 2, the user's device can automatically generate a 1AdID that uniquely identifies the context (e.g., device, accessed application, or physical location). The 1AdID may include, or otherwise be considered, a unique identifier for the user's device (e.g., because it includes a value unique to identify the user's device, such as for an edge cloud server or privacy service provider). In some embodiments, the 1AdID also includes associated advertising opportunities. In this sense, the 1AdID is a collection of data (e.g., a group, an array) that includes both the unique identifier of the user's device and accompanying data. Other configurations are also possible and intended to be within the scope of this disclosure—for example, where the 1AdID uniquely identifies the user's device but does not include accompanying contextual data (but is logically associated with such accompanying context). Those skilled in the art will understand the functional equivalence of these various possibilities.

[0103] In step 3, if the user has consented to such data sharing, the user device (e.g., 100) may optionally attach real-time IoT and sensor data from devices directly connected to the device to the 1AdID. Potential examples of such data to be included with the 1AdID include heart rate monitors, eye trackers, wearable sensors, etc.

[0104] In step 3, the end user can optionally select to include standard groups of demographic information with their 1AdID. Grouping can be controlled via an application on the user's device (e.g., 100). Grouping may include fields such as age, gender, and brand affinity.

[0105] In step 4, the 1AdID is then uploaded to an edge or cloud computing facility network node (e.g., 716).

[0106] In step 5, after the 1AdID packet arrives at the edge or cloud computing facility, it is optionally enriched by combining it with real-time data from sensors and detectors located near the end user. This can be performed in parallel in the edge or cloud computing environment. Examples of IoT data that may enrich the 1AdID include ambient temperature, light, sound, odor, the proximity of people, or the total number of nearby devices.

[0107] In step 6, the complete 1AdID grouping may optionally be processed at the edge or in the cloud (e.g., to assign end users to their (one or more) relevant audiences, or other such predictions or inferences). This processing can be accomplished using machine learning and artificial intelligence. The specific algorithms used for audience assignment may be proprietary to advertisers (e.g., unique for an advertising opportunity), mobile operators (e.g., unique for all mobile phone service customers), physical locations (e.g., unique for all visitors to an amusement park), or any combination thereof. For example, predefined, human-interpretable tags (such as “business traveler” or “stay-at-home parent”) may be used to qualitatively define the potential audience segment. They may also be assigned via AI, whereby the audience may not have easily interpretable tags.

[0108] In step 7, after processing, the resulting observations (e.g., audience) and 1AdID are used to generate one or more of QuickID and LongID, and cause them to be stored in a database (e.g., 722) if permitted. The 1AdID or QuickID can be sent as a bid request to the ad exchange along with a bid request payload for identifying the device and corresponding opportunity.

[0109] In step 8, the data used to generate 1AdID is removed from the edge or cloud environment.

[0110] 3. Using data for inference

[0111] Continuing with the example above, once in the edge cloud, the next step is to use the data for inference / prediction based on the end-user's privacy settings (note: the ways of processing data at the edge / in the cloud are well understood and are beyond the scope of this application, and therefore will not be discussed further).

[0112] Once inference is complete, the underlying data array and any resulting inferences and / or predictions are processed according to the end-user's privacy settings. If the end-user has A) specified that no fields can be retained for long-term use, the array and any resulting predictions and / or inferences are deleted / purged from the edge cloud environment (note: methods for purging data from the edge / cloud are well understood and are beyond the scope of this application, and therefore will not be discussed further). If the end-user has B) allowed storage of at least one field of the raw data, predictions, or inferences, those fields are forwarded from the edge cloud to the database for storage.

[0113] Figure 6 An exemplary dataset contained within a database is shown. Stage (1) 600 shows one observation (e.g., a prediction) associated with a LongID, while stage (2) 602 shows multiple such observations (e.g., multiple predictions). As used herein, the terms “observation,” “prediction,” and “inference” are used differently to refer to supplementary data generated by one or more operations performed on the data associated with the LongID. While such terms may refer to creation through different types of operations on the initial data, they are used interchangeably herein and should therefore be interpreted as such unless otherwise explicitly stated or logically prevented. For example, although in Figure 6 The examples use predictions, but a skilled technician will see that the values ​​shown could be changed to observations, inferences, or a combination of more than one of these three. Furthermore, the terms “observation,” “prediction,” and “inference” are not intended to limit the type of additional data produced by one or more operations performed on the data associated with LongID, but are merely descriptive terms.

[0114] Forwarding data or arrays from the edge cloud to a database for storage is well understood and is outside the scope of this disclosure, and therefore will not be discussed further in detail. Any suitable components for two devices, nodes, computers, servers, or the like can be used. Furthermore, the applicant notes that the techniques described herein are sufficiently general to make the details and configuration of the database (e.g., cloud-based, on-premises, relational, etc.) irrelevant to understanding or enabling the implementation of the embodiments described herein.

[0115] In this example, data is stored in the database based on LongID according to the edge cloud retention policy. In its privacy settings, each end user can specify how long to retain data for each [company] or for each [company] + [use code] pair. For example, as... Figure 2 As shown, end users can choose to allow data storage for thirty (30) days for all mobile phone service providers' use cases, or alternatively as... Figure 3 As shown, the subset of use cases for mobile phone service providers is instead specified as twelve (12) hours for advertising, thirty (30) days for billing, five (5) days for service optimization, and five (5) days for media.

[0116] Figure 7 An exemplary schematic diagram of an architecture according to certain embodiments is shown. A deletion instruction 728 (large "X") from database 722 indicates that relevant data is deleted from the database in a time-controlled manner, while a deletion instruction 726 from the edge cloud indicates that data is deleted from the edge immediately after processing.

[0117] According to some embodiments, data is always deleted from the database based on a user-set time limit. According to some embodiments, as a failover protection, the only field linking entries in the database to the original UE is the 1AdID, and the 1AdID is deleted at least based on the user-set time limit. If the 1AdID is changed or deleted, the link between the end user and the data is broken. Furthermore, commercial applications and services use LongID to request data, meaning they do not obtain personally identifiable information about the end user, such as their UE's MSISDN, IMEI, or IMSI.

[0118] exist Figure 7 In the example, data 710 exists on UE 100 or is otherwise accessible to UE 100. UE 100 may include data (e.g., combined with such data) received from external sensors 712 and transmitted to edge cloud 716 (e.g., part of a mobile network operator's network). Edge cloud 716 processes data array 714 as appropriate (e.g., generating QuickIDs, generating LongIDs, performing inference / prediction / observation). For example, QuickIDs (and / or AdIDs) and associated observations may be sent to an advertiser identified by a unique advertiser ID 718 (e.g., for receiving served advertisements to be displayed on the UE). If a non-zero time limit is set for the data, LongID 720 and associated data (e.g., observations) may be sent to database 722 for storage according to the time limit. In some embodiments, one or more of user data (e.g., raw data) and processed user data (e.g., observations, predictions, or inferences) are sent to a database for storage. As described above, once the edge cloud 716 has completed forwarding the data to the advertiser and database 722, the data is deleted from the edge cloud 716 (as indicated by deletion instruction 726). This further ensures that unnecessary copies of user data are stored. Figure 7In the example, one or more of the LongID and associated data (e.g., data from the UE or observations based thereon) may be provided to the requesting entity, such as 724A (“City Services”), 724B (“Public Transport Operator”), and 724C (“Mobile Phone Service Provider”), based on the time constraints in the LongID.

[0119] 4. Geofencing

[0120] In Section 3 above, data from sensors (e.g., 712, 812, 816, 906, 908) located in any physical area near the device can be combined with data from 1AdID (e.g., 710) to enrich the data. This area can be defined by a dynamically or statically generated geofence. Static geofences (e.g., Figure 8 Geofencing parameters 802, 810, and 814 can be predefined by the geofencing operator and defined as boundaries, such as mall floors or shops, city areas, etc. Dynamically generated geofencing (e.g., Figure 9 902, 904) can be defined as the radius (or other shape) around a point or location, such as around a moving device. Figure 9 The circular area of ​​UE 100 in the middle.

[0121] By definition, dynamically generated geofences require a flexible definition of the maximum distance for integrating data. Setting this distance too far physically will mean enriching 1AdID with a large amount of data, while setting it too small will mean including too little data. The maximum distance can be dynamically defined depending on factors such as the availability of IoT data, indoor or outdoor location.

[0122] Figure 8 Three exemplary static geofences (802, 810, and 814) are shown in map area 800 of an enterprise campus, with the end-user's mobile device 100 located within one of the perimeters (814). Each circular icon with three wavy lines (e.g., 812, 816) represents an example sensor, IoT device, or detector located within the corresponding arbitrary static geofence. Data 820 from one or more sensors within geofence 814 belonging to the current location of the mobile UE 100 is included in or together with IAdID 822 (e.g., including data from 816 as well as data from other sensors within 814). Data from different geofences (e.g., 802 and 810) is excluded, even if some IoT devices are closer to the mobile device (e.g., if the UE 100 is near the top edge of 814, it is closer to the sensor in 802 than the farthest sensor in 814 located near the bottom of area 814 shown in the map). (The text abruptly ends here, likely due to an incomplete translation or source material.) Figure 7 Similar to the description, data is sent to the edge cloud 716 for processing. In this example, 1AdID 822 is deleted (according to deletion instruction 824). The LongID is forwarded to database 722 for storage based on a time limit, and then deleted after the time limit (according to deletion instruction 728).

[0123] Figure 9 Exemplary dynamically generated geofences 902 and 904 are shown, with the end-user's mobile device at their center. Each circular icon with three wavy lines (e.g., 906, 908) represents a hypothetical sensor, IoT device, or detector located at any physical distance from the mobile device and whose data is in or with 1AdID. If the distance parameter is set to d, only data from the three sensors contained within the circle 902 with radius d (e.g., including 906 but not 908) is included. If the distance parameter is set to d', three additional sensors are included (e.g., 908 in 904, which is not within 902, and two other sensors). (Regarding...) Figure 7 and Figure 8 Similarly, as described, UE 100 sends the 1AdID to the edge cloud 716, where it is processed and deleted, and sends the LongID to the database 722. A deletion instruction 728 from the database 722 indicates time-controlled deletion of the associated data, while a deletion instruction 824 from the edge environment 716 indicates near-immediate deletion of data contained within or accompanying the 1AdID.

[0124] Once the data from the associated device is uploaded to the edge / cloud computing center, the LongID and QuickID are generated only once using the 1AdID. As detailed in Section 3 above, data is deleted from the database according to a user-defined time period. The LongID is sent to the database, which can be accessed by authorized entities during the specified time period.

[0125] 5. Move

[0126] For static geofences, the collection of possible sensors, detectors, and IoT devices will also be updated as end users move within the space. When a mobile device (e.g., 100) moves from one geofence to another, data from devices located within the new geofence will be included, and data from devices within the previous geofence will not be requested. If they are received by the edge or cloud computing center in some way, they will be discarded and deleted. Devices from overlapping boundaries will continue to be included.

[0127] For dynamically generated geofences, the invention also includes the idea that a possible collection of sensors, detectors, and IoT devices will be updated as the end user moves within the space. After setting a maximum permissible distance d, data from devices located outside the maximum value of d will not be requested during the 1AdID generation process. If such data is received by the edge or cloud computing center in some way, it will be discarded and deleted.

[0128] Figure 10 Three identical overlapping circles 902, 910, and 912 are shown, along with the end-user device UE 100. Each circle 902, 910, and 912 represents a (dynamic or static) geofence. A dynamic geofence can be defined by any distance d from the end-user device. Each circular icon (e.g., 906, 908) represents a hypothetical sensor, detector, or IoT device. Only devices located within the same geofence are included in the 1AdID group. As the end-user moves through space, the set of potential sensors, detectors, or IoT devices within the geofence also changes. A sensor can also be part of more than one geofence (e.g., 906 is within 910 and 902, while 908 is within 902 and 912).

[0129] 6. Distance

[0130] As used in this paper, one possible metric for distance (e.g., d) is the Minkowski distance, which is a generalization of both Euclidean and Manhattan distances. The Minkowski distance between points X and Y is defined as:

[0131]

[0132] The technology described in this article may be unaware of the origin of the maximum distance allowed for computation. It can be set by the end user, by the mobile operator as a general privacy setting, or by the facility administrator to separate different spaces.

[0133] 7. Algorithm

[0134] In some embodiments, network nodes (e.g., edge cloud, database) may use one or more algorithms to perform observation, inference, and / or prediction. Any suitable algorithm may be used. Below, examples of algorithms using the marshalling assignment module are provided. The marshalling assignment module is the main module in which machine learning and artificial intelligence are used to perform optimal audience selection given data contained in 1AdID groups. For example, such audience selection may be considered as inference or prediction, or may be used for inference or prediction.

[0135] 7.1. Input

[0136] According to certain embodiments, various inputs may be used, including one or more of the following:

[0137] • Data from devices (one or more) of the end user: Shared according to local privacy settings. If a user chooses not to share their location, location data will not be used in the 1AdID generation process. Depending on the end user's privacy settings, this may also potentially deactivate the inclusion of data from nearby sensors, detectors, and IoT devices.

[0138] • Environmental data: Data about the consumer's environment collected from connected IoT devices, sensors, and detectors located at any physical distance from the end-user's UE.

[0139] • Strategy: The audience assignment process may include configured strategies. For example, it can be configured to prioritize assignment to specific types of audiences.

[0140] 7.2. Output

[0141] The exemplary marshalling assignment module outputs a list of marshalling(s) assigned to each 1AdID. Depending on the underlying data, this list may include one or more marshallings. As mentioned above, this is an exemplary model operating via the architecture described above; it is not the only model type that can be used with the proposed architecture.

[0142] 7.3. Model Details

[0143] The following describes a high-level description of the example implementation and formulates it as a matching problem. An exemplary algorithm is as follows, where the input is a list L of 1AdIDs with associated user and environment data; and an initial candidate set N (a subset of L) of the audience; and where the output is a set of groups partitioned from L:

[0144] 1) Let N be the set of possible groupings (a subset of L).

[0145] 2) Let n i Grouping N defined for AI i The set of possible permutations.

[0146] 3) Let G be an empty graph.

[0147] 4) For each element n of N i :

[0148] a) Add node n to G i .

[0149] b) For each node vertex n j ,

[0150] i) n will be grouped if and only if, as determined by oracle, it is a suitable grouping. i Connect to all node vertices; otherwise, make n i The connection remains unconnected.

[0151] ii) Give each edge (n i ,n j Assigning c(n) i ,n j The capacity of w(n) is assigned, and the existing flow w(n) is assigned. i ,n j )<=c(n) i ,n j ).

[0152] 5) For all n in G i Add source S, which is accessed via c(S,n) i )=∞,w(S,n i An edge with 1 is connected outward to every node in G.

[0153] 6) For each node n in G\S i Add edges for (n) i The pool node T of the edge (T, T); the capacity of each edge should be max(c(n)). i ,n j )).

[0154] 7) Solve for maximum flow by applying algorithms such as the Ford-Fulkerson algorithm.

[0155] 8) Output the solution flow, which is the optimal grouping choice (Note: the flow must be non-negative, because there is no optimal solution for a negative flow without a DAG).

[0156] 8. Sample Data Format

[0157] This section provides examples of the requested data. The data examples below are represented as XML objects, but they can also be represented as JSON or other formats. In the examples below, the data sample comes from female end-users wearing heart rate monitors entering a bookstore equipped with sound monitors. These examples are not exhaustive in terms of content.

[0158] 8.1. IoT Data

[0159]

[0160] 8.2. Demographic Group Data

[0161]

[0162] 8.3. Sensor Data

[0163]

[0164]

[0165] Figure 11 An exemplary process 1100 for managing data subjects according to retention time limits is illustrated according to some embodiments. Process 1100 can be performed by one or more network nodes, electronic devices, and systems (e.g., 716, 1460, 1600, 1730, 1810, 1820) as described herein. The techniques and embodiments described with respect to process 1100 can be performed or embodied in: computer-implemented methods; systems (e.g., systems of one or more devices) including (e.g., when executed by one or more processors) instructions for performing the process; computer-readable media including (e.g., when executed by one or more processors) instructions for performing the process (e.g., transient or non-transitory); computer programs including instructions for performing the process; and / or computer program products including instructions for performing the process. Additionally, the various embodiments, elements, or operations described below with respect to process 1100 can be combined with each other in any combination, or can be omitted from such combinations, and any such combinations are within the scope of this disclosure.

[0166] A network node (e.g., 716, 1460, 1600, 1730, 1810, 1820) receives (1102) first data (e.g., location data, transaction data, or other user data) (e.g., 400, 500, 714, 820, 822, 820) of a first data transaction (e.g., an interaction involving data exchange between the UE and the network node) from a device (e.g., 100) associated with a user profile (e.g., including account settings, preferences, or other privacy control data) (e.g., an account identified by 112). This first data (e.g., by the network node, by an external device, or by a server) is assigned a unique identifier (e.g., IAdID, QuickID, LongID) to uniquely identify the first data transaction. As used herein, unless otherwise stated, "unique identifier" can refer to an identifier without accompanying data (e.g., personal data, data transaction context data) or an identifier included with accompanying data (e.g., IAdID, QuickID, LongID). When referring separately to unique identifiers and accompanying data (e.g., personal data, primary data), such statements should not be construed as preventing such elements from being interpreted as being included in the same data structure / container (e.g., 1AdID, QuickID, LongID).

[0167] In response to receiving first data from the device, it is enabled (1104) to transmit second data (e.g., 1AdID, QuickID, LongID, observation / inference / prediction) and a unique identifier (e.g., directly to the advertiser via 1AdID or QuickID through a network node (edge ​​cloud), or via LongID through a server) to one or more data receiving entities (e.g., companies) (e.g., 724A, 724B, 724C). According to some embodiments, the second data (e.g., 400, 500) is associated with a time limit for retaining the first data in the first data transaction (e.g., ...). Figure 4 or Figure 5 The second data is associated with an instruction (e.g., including such an instruction) regarding a time limit in hours (e.g., deleting data when the time limit expires). According to some embodiments, the second data is at least one of the following: an instance of the first data (e.g., a copy or the original raw data), data including the first data (e.g., the first data plus additional data), and data generated using the first data (e.g., inferences or predictions based on the first data).

[0168] The determination of a non-zero time limit for retaining the first data of the first data transaction, according to the time limit indication, enables (1106) storage (e.g., storage, or permission for a remote server to store) one or more of the first and second data (e.g., LongID, observations / inferences / predictions associated with LongID) according to the time limit (e.g., storage, or permission for a remote server to store).

[0169] By using an architecture that utilizes network nodes (e.g., 716) between the user's device (e.g., 100) and the database (e.g., 722) to process personal or other privacy-sensitive user data, along with processes and / or data containers for strictly enforcing deletion policies, it is possible to prevent the database and / or any data requesting entity from discovering the user's true identity and / or aggregating data from such users indefinitely.

[0170] The determination of a non-zero time limit for retaining the first data in the first data transaction, as indicated by the time limit instruction, causes (1108) (e.g., after enabling the transmission of the second data and the unique identifier to the one or more data receiving entities) (e.g., from the network node itself) to delete the first and second data. For example, the edge cloud causes the deletion of the database by including a time limit in the LongID, after which the database must (e.g., according to 728) delete the associated data. As a further example, the edge cloud deletes the second data from its own storage (e.g., according to 726) after transmitting the LongID to the database.

[0171] In some embodiments, a unique identifier is assigned by a device (e.g., 100) or a network node (e.g., 716). For example, AdID, LongID, or QuickID may be generated by the end-user's device or by the edge cloud.

[0172] In some embodiments, a network node performs one or more processes on the first data to generate second data. For example, an edge cloud may perform data processing (e.g., inference, prediction, or other algorithms) on the first data to generate the second data. As a further example, the generation of the second data may be to generate a LongID from 1AdID as well as data from the user's UE and any associated sensor data.

[0173] In some embodiments, a unique identifier (e.g., QuickID, LongID) includes one or more of the following: a usage code that identifies at least one permitted use of the second data (e.g., as in 400 or 500); and an entity identifier that identifies at least one entity that is permitted to access the second data (e.g., as in the [Company] field in 400 or 500).

[0174] In some embodiments, a unique identifier (e.g., AdID, QuickID, LongID) maintains the anonymity of the receiving entity (e.g., 724A, 724B, 724C) and user profile for receiving or accessing the transmission of second data (e.g., LongID). For example, from the perspective of the receiving entity, the unique identifier maintains the anonymity (privacy) of the receiving entity and any user associated with the user profile (e.g., third-party companies do not receive personally identifiable information with one or more unique identifiers).

[0175] In some embodiments, a unique identifier (e.g., AdID, QuickID, LongID) is a one-time-use identifier, such that a different unique identifier is used for a second data transaction involving a device (e.g., 100) associated with a user profile (e.g., even if the second data transaction involves the same or similar data, or the same or different entities). For example, a LongID is deleted and no longer used after its corresponding time limit, or an AdID or QuickID is deleted and no longer used after the data transaction is completed (e.g., an end user provides a response or an edge cloud node performs analytics).

[0176] In some embodiments, enabling the storage of one or more of the first and second data according to a time constraint (e.g., storing or allowing a remote server to store) includes one or more of the following: storing the second data in a data storage device by a network node (e.g., 716) according to a time constraint; and transmitting the second data by the network node to one or more database nodes (e.g., 722) (e.g., within an operator's network or located outside the network) for storage according to the time constraint. In some embodiments, in conjunction with enabling the network node (e.g., an edge cloud node) to store one or more of the first and second data (e.g., transmitting all or part of it) (e.g., simultaneously or close in time), the network node deletes one or more of the first data (e.g., AdID) and the second data (e.g., QuickID, LongID, observation / inference / prediction) from its own storage device (e.g., 726) (e.g., after processing and / or before the time constraint expires). For example, an edge cloud node can process first data to generate second data, and then cause the result of this processing to be stored in a database (e.g., 722) for access by authorized entities (e.g., 724A, 724B, 724C). To protect user privacy, such generated data (e.g., second data) and source data (e.g., first data) are deleted from the edge cloud node after processing and transmission, so that authorized entities will need to access the processed data from the database. Therefore, the edge cloud node can delete the second data (and the first data) before any time limit expires (e.g., 726). This further protects user privacy by reducing the number of unnecessary concurrent data instances.

[0177] In some embodiments, the network node further causes one or more of the first and second data to be deleted before or upon the expiration of the time limit (e.g., immediately after expiration). For example, after processing the first data to generate the second data, but before the time limit expires, the network node deletes (e.g., 726) one or more of the first and second data from its own memory, but causes the second data to be stored (e.g., transmitted 720) in a database (e.g., 722).

[0178] In some embodiments, the time constraint is a first time constraint, and the second data is data of a first type that conforms to the first time constraint. In some embodiments, third data received from a device (e.g., 100) or generated by a network node (e.g., 716) based on data received from the device is data of a second type that is different from the first type of data, and the third data conforms to a second time constraint that is different from the first time constraint, at least because the third data is data of a second type. For example, different types of data from the same user / profile (e.g., location data, purchase data, advertising data, billing data, media data, etc.) may have different time constraints.

[0179] In some embodiments, the method of any of claims 1-9, wherein the user profile includes one or more user-configured time limits containing time constraints. For example, a user may use interfaces 110, 210, and / or 310 to configure one or more time limits subsequently associated with the user's profile and used when creating a LongID.

[0180] In some embodiments, the time limit of the one or more user configurations is specified according to one or more of the following: the identifier of the receiving entity (e.g., by a company), the type of use (e.g., using a usage code), or the type of data (e.g., location data, purchase data).

[0181] Figure 12 An exemplary process 1200 for managing data subjects according to retention time limits is illustrated according to some embodiments. Process 1200 can be performed by one or more network nodes, electronic devices, and systems (e.g., 100, 1410, 1500, 1600, 1791, 1792, 1830) as described herein. The techniques and embodiments described with respect to process 1200 can be performed or embodied in: computer-implemented methods; systems (e.g., systems of one or more devices) including (e.g., when executed by one or more processors) instructions for performing the process; computer-readable media including (e.g., when executed by one or more processors) instructions for performing the process (e.g., transient or non-transitory); computer programs including instructions for performing the process; and / or computer program products including instructions for performing the process. Additionally, the various embodiments, elements, or operations described below with respect to process 1200 can be combined with each other in any combination, or can be omitted from such combinations, and any such combinations are within the scope of this disclosure.

[0182] Electronic devices (e.g., 100, 1410, 1500, 1600, 1791, 1792, 1830) present (1202) one or more data retention time limits (e.g., for one or more categories of data (e.g., data from a specific device; data specified for a specific third-party requester (e.g., an entity such as a company); data usage type (e.g., billing, advertising, service optimization, media); data type (e.g., location, fitness, transaction data)) to configure one or more data retention time limits (e.g., Figure 4 or Figure 5 One or more options (e.g., 120, 122, 124, 126, 128, 130, 220, 222, 224, 226, 320, 322, 324, 326, 328) of the [time limit in hours] are available. In some embodiments, one or more categories of data are associated with one or more data transactions (e.g., opportunities or requests to provide data) involving a user profile (e.g., including account settings, preferences or other privacy control data) (e.g., the profile identified by 112), the user profile being associated with an electronic device (e.g., 100) (e.g., the electronic device is logged into the user profile or stored as an electronic device associated with the profile). In some embodiments, each of the one or more data retention time limits controls the length of time for which a remote user data collection system (e.g., 716, 722) is permitted to retain one or more categories of data, associated with the corresponding data retention time limit of the one or more data retention time limits (e.g., unique identifiers such as AdID, QuickID, or LongID, and / or all lower-level data).

[0183] An electronic device (e.g., via a user input device such as a touch-sensitive surface / screen, mouse, keyboard, microphone, etc.) receives (1204) user input associated with one or more of the options (e.g., touch input at the touchscreen of UE 100), the user input specifying a first data retention time limit (e.g., no data retention, 1 day, 7 days, 1 month, 1 year, etc.) for a first category of data (e.g., data from Company A). For example, as Figure 2 As shown, UE 100 receives user input on user interface 210 to select a 30-day time limit for data from a mobile phone service provider (exemplary first category data). As another example, the first category data could be billing data, which uses... Figure 3 Configure the user interface 310 in the middle.

[0184] The electronic device causes (1206) a first data retention time limit (e.g., Figure 3The 30-day period is associated with the user profile of the electronic device (e.g., causing it to be sent to the edge cloud or server, such as 716).

[0185] When a first data retention period is associated with a user profile, the electronic device transmits (1208) one or more datasets (e.g., 714) that are considered data of a first category (e.g., data from Company A) for storage at a remote user data collection system for no longer than the first data retention period (e.g., 30 days). In some embodiments, the one or more datasets that are considered data of the first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier (e.g., AdID, QuickID, LongID). As described above, the one or more datasets and their corresponding unique identifiers can be included together in a single group or construct such as AdID, QuickID, or LongID.

[0186] In some embodiments, an electronic device (e.g., 100) (e.g., via a user input device such as a touch-sensitive surface / screen, mouse, keyboard, microphone, etc.) receives user input associated with one or more options, the user input specifying a second data retention time limit (e.g., no data retention, 1 day, 7 days, 1 month, 1 year, etc.) for a subset of data of a first category (e.g., billing data for Company A). Figure 3 As shown, a user uses user interface 310 to provide user input for setting a 30-day time limit for billing data. In this example, the first category of data is data from a mobile phone service provider, and a subset of the first category of data is billing data. The electronic device causes a second data retention time limit to be associated with a user profile associated with the electronic device (e.g., causing it to be sent to an edge cloud or server such as 716). When the second data retention time limit is associated with a user profile, the electronic device transmits one or more datasets (e.g., 714) that constitute a subset of the data in the first category (e.g., data from Company A) for storage at a remote user data collection system (e.g., 722) for a period not longer than either the first or second data retention time limit (e.g., not longer than the shorter of the first and second data retention time limits; the second data retention time limit may also override the first data retention time limit, making the use of the second data retention time limit because it is defined in a more granular way (e.g., for subtypes)). For example, if the first data retention time limit for the first category of data is set to 30 days, and the second data retention time limit for a subset of the first category of data is set to 5 days, then the data in that subset will be deleted after 5 days, even if it belongs to the first category of data, because the 5-day limit is stricter than the 30-day limit.

[0187] In some embodiments, an electronic device (e.g., 100) (e.g., via a user input device such as a touch-sensitive surface / screen, mouse, keyboard, microphone, etc.) receives user input associated with one or more options, the user input specifying a third data retention time limit (e.g., no data retention, 1 day, 7 days, 1 month, 1 year, etc.) for a second category of data (e.g., data from Company B, billing data). In some embodiments, the third data retention time limit differs from a first data retention time limit (e.g., 5 days differs from 30 days). In some embodiments, the second category of data differs from the first category of data (e.g., the second category of data is data from Company B, while the first category of data is data from Company A). In some embodiments, the electronic device causes the third data retention time limit to be associated with a user profile associated with the electronic device (e.g., causes it to be sent to an edge cloud or server). In some embodiments, when a third data retention time limit is associated with a user profile, the electronic device transmits one or more datasets (e.g., 714) of data classified as a second category for storage at a remote user data collection system (e.g., 722) for no longer than the third data retention time limit, wherein the one or more datasets of data classified as the second category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier. For example, as... Figure 2 As shown, electronic device 100 (e.g., via a user interface such as 210 and 310) receives user input establishing a third data retention period of 5 days associated with physical city services (224), which differs from the 30-day limit imposed by physical mobile phone service providers.

[0188] In some embodiments, a given category of data (e.g., a first category, a second category) is defined according to one or more of the following: an identifier of an originating device (e.g., UE 100) of one or more electronic devices associated with a user profile, which is the source of the corresponding data (e.g., 714); a destination receiving entity (e.g., Company A) (e.g., 724A, 724B, 724C) to which access to the corresponding data is to be provided (e.g., receiving a transmission of the corresponding data); and the usage type of the corresponding data (e.g., advertising, billing, service optimization, media) (e.g., such as...). Figure 4 or Figure 5 The usage code (in the text); and the type of the corresponding data (e.g., health, location, transaction data). In some embodiments, the usage type of the corresponding data includes one or more of the following: advertising, billing, service optimization, and media. In some embodiments, the type of the corresponding data includes one or more of the following: health data, location data, and financial transaction data.

[0189] A piece of data can be divided into multiple categories (e.g., it can be related to billing and specified for use by Company A) and will be subject to the strictest retention policy applicable (e.g., Company A is allowed to retain user data for no more than 30 days, but for billing, it is only allowed to retain it for 7 days, which means that after 7 days Company A cannot access the information used for billing).

[0190] In some embodiments, data may be classified into one or more categories. In some embodiments, data classified into more than one of the one or more categories is subject to the shortest data retention time limit for the corresponding category among the more than one category. For example, data classified into both a first category and a second category will be deleted according to the shorter data retention time limit of the corresponding first and second categories.

[0191] Figure 13 An exemplary process 1300 for managing data subjects according to retention time limits is illustrated according to some embodiments. Process 1300 can be performed by one or more network nodes, electronic devices, and systems (e.g., 716, 722, 1460, 1600, 1730, 1740, 1810, 1820) as described herein. The techniques and embodiments described with respect to process 1300 can be performed or embodied in: computer-implemented methods; systems (e.g., systems of one or more devices) including (e.g., when executed by one or more processors) instructions for performing the process; computer-readable media including (e.g., when executed by one or more processors) instructions for performing the process (e.g., transient or non-transitory); computer programs including instructions for performing the process; and / or computer program products including instructions for performing the process. Additionally, the various embodiments, elements, or operations described below with respect to process 1300 can be combined with each other in any combination, or can be omitted from such combinations, and any such combinations are within the scope of this disclosure.

[0192] A network node (e.g., 716, 722, 1460, 1600, 1730, 1740, 1810, 1820) (e.g., from another network node such as network edge node 716) receives (1302) first data (e.g., location data, transaction data, or other user data) (e.g., 720) of a first data transaction associated with a user profile (e.g., including account settings, preferences, or other privacy control data) (e.g., identified by 112), wherein the first data includes: a first unique identifier (e.g., AdID, LongID) uniquely identifying the device involved in the first data transaction associated with the user profile (e.g., a one-time identifier or a persistent identifier of the device); and an identifier of an external requesting entity other than the user profile that is authorized to access the first data (e.g., such as...). Figure 4 and Figure 5 The [Company] code field (e.g., company code); a first time limit for retaining the first data of the first transaction (e.g., such as...). Figure 4 and Figure 5 The instructions (in hours) and the first person data (e.g., data in 1AdID, 710) provided by a device (e.g., 100) associated with the user profile. For example, database 722 receives a LongID that includes 1AdID and personal data associated with the user profile (e.g., predictions or inferences based on user data, or actual user data (such as location information)).

[0193] The network node stores (1304) the first data for access by external requesting entities (e.g., 724A, 724B, 724C) (e.g., third-party devices / systems / users that are not users or servers).

[0194] Network nodes provide (1306) a first unique identifier and first person data to external requesting entities other than user profiles. For example, database 722 provides 1AdID or LongID and associated personal data (e.g., inference) to one or more entities among entities 724A, 724B, and 724C.

[0195] Once the first time limit for retaining the first data of the first transaction expires, the network node (e.g., as shown by 728) deletes (1308) at least a portion of the first data including the first unique identifier (e.g., at least 1AdID, the entire LongID, and all lower-level data associated with the first transaction). For example, by deleting at least 1AdID, the connection to the user's device 100 is disconnected, and the database cannot connect any remaining data to the user's profile.

[0196] In some embodiments, a network node (e.g., from another network node such as a network edge node) receives second data (e.g., location data, transaction data, or other user data) associated with a second data transaction of a user profile (e.g., including account settings, preferences, or other privacy control data). The second data includes: a second unique identifier (e.g., AdID, LongID) uniquely identifying the second data transaction involving a device associated with the user profile (e.g., a one-time identifier or a persistent identifier of the device); an identifier (e.g., a company code) of an external requesting entity other than the user profile, who is permitted to access the second data (e.g., at least a portion thereof); an indication of a second time limit for retaining the second data of the second transaction; and second personal data provided by the device associated with the user profile, wherein the first personal data is data of a first type, and the second personal data is data of a second type different from the first type, wherein the first type of data is subject to a first time limit for retention, and the second type of data is subject to a second time limit for retention, and wherein the second time limit is different from the first time limit. The network node stores the second data for access by the external requesting entity. A network node provides a second unique identifier and second personal data to an external requesting entity other than the user profile (e.g., a third-party device / system that is not a user or server). Once the second time limit for retaining the second data for the second transaction expires, the network node deletes at least a portion of the second data, including the second unique identifier. For example, database 722 receives second data from a user profile, the second data including different time limits for data of the same type (e.g., different uses of the same type of data (e.g., based on usage codes) subject to different time limits), and stores a second instance of that data.

[0197] In some embodiments, the external requesting entity is a first external requesting entity (e.g., 724A), and a network node (e.g., from another network node such as a network edge node) receives third data (e.g., location data, transaction data, or other user data) associated with a third data transaction related to a user profile (e.g., including account settings, preferences, or other privacy control data), wherein the third data includes: a third unique identifier (e.g., AdID, LongID) uniquely identifying the third data transaction involving the device associated with the user profile (e.g., a one-time identifier or a persistent identifier of the device); an identifier (e.g., a company code) of a second external requesting entity other than the user profile, which is authorized to access at least a portion of the third data, wherein the first external requesting entity (e.g., 724A) is different from the second external requesting entity (e.g., 724B); an indication of a third time limit for retaining the third data of the third transaction, wherein the data access permission of the first external requesting entity is subject to a first time limit for retention, and the data access permission of the second external requesting entity is subject to a third time limit for retention, and wherein the third time limit is different from the first time limit; and third person data provided by the device associated with the user profile. A network node stores third data for access by a second external requesting entity. The network node provides a third unique identifier and third person data to the second external requesting entity (e.g., a third-party device / system that is not a user or server), in addition to the user profile. When a third time limit for retaining the third data for a third transaction expires, the network node (e.g., as shown by 728) deletes at least a portion of the third data, including the third unique identifier. For example, the network node receives third data for a user profile that includes different time limits for different requesting entities (e.g., Company B), even if the third data is the same as the first data.

[0198] In some embodiments, before the first time limit expires, a network node receives a request from an external requesting entity (e.g., 724A) for access to data from a first data source, which includes at least a first unique identifier and first person data. In response to receiving the request, the first unique identifier and first person data are provided. For example, database 722 receives a request for data from external entity 724A and, in response, provides an AdID or LongID and associated personal data. In some embodiments, the first data includes a permitted use code, wherein the request (e.g., via 724A) includes a requested use code (e.g., a use code indicating how the requester will use the requested data), and the network node determines that the permitted use code matches the requested use code before providing the first unique identifier and first person data to the external requesting entity. For example, the first data includes a permitted use code, and the requested data is provided to the requesting entity based on a request including the permitted use code.

[0199] In some embodiments, deleting the first data at least in part includes deleting the first person's data. For example, the database deletes personal data (as part of, or appended to, a unique identifier such as AdID or LongID).

[0200] In some embodiments, the first unique identifier maintains the anonymity (privacy) of the device and user profile for the external requesting entity. For example, even if the requesting entity knows the AdID or LongID, it cannot (alone) use such information to derive the identifier of the user profile and / or device.

[0201] Furthermore, the various embodiments, elements, or operations described below with respect to processes 1100, 1200, and / or 1300 may be combined with each other in any combination, or may be omitted from such combinations, and any such combinations are within the scope of this disclosure.

[0202] While the subjects described herein can be implemented using any suitable components in any appropriate type of system, the embodiments disclosed herein are related to, for example, Figure 14 The example wireless network shown is used to describe wireless networks. For simplicity, Figure 14The wireless network depicted only includes network 1406, network nodes 1460 and 1460b, and WDs 1410, 1410b, and 1410c. In practice, the wireless network may further include any additional elements suitable for supporting communication between wireless devices or between a wireless device and another communication device, such as a landline telephone, a service provider, or any other network node or end device. Among the components shown, network node 1460 and wireless device (WD) 1410 are depicted in additional detail. The wireless network may provide communication and other types of services to one or more wireless devices to facilitate access to and / or use of services provided by or via the wireless network.

[0203] Wireless networks may include any type of communications, telecommunications, data, cellular and / or radio networks or other similar systems and / or be connected to them via an interface. In some embodiments, a wireless network may be configured to operate according to a specific standard or other type of predefined rules or procedures. Thus, specific embodiments of a wireless network may implement communication standards such as Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, or 5G standards; wireless local area network (WLAN) standards such as the IEEE 802.11 standard; and / or any other suitable wireless communication standards such as Global Microwave Access Interoperability (WiMax), Bluetooth, Z-Wave, and / or ZigBee standards.

[0204] Network 1406 may include one or more backhaul networks, core networks, IP networks, public switched telephone networks (PSTN), packet data networks, optical networks, wide area networks (WAN), local area networks (LAN), wireless local area networks (WLAN), wired networks, wireless networks, metropolitan area networks, and other networks that enable communication between devices.

[0205] Network node 1460 and WD 1410 include various components described in more detail below. These components work together to provide the functionality of the network node and / or wireless device, such as providing wireless connectivity in a wireless network. In various embodiments, the wireless network may include any number of wired or wireless networks, network nodes, base stations, controllers, wireless devices, relay stations, and / or any other components or systems that may facilitate or participate in the transmission of data and / or signals, whether via wired or wireless connections.

[0206] As used herein, a network node refers to a device capable of, configured to, arranged to, and / or operable to communicate directly or indirectly with a wireless device and / or with other network nodes or devices in a wireless network to enable and / or provide wireless access to the wireless device and / or perform other functions (e.g., management) in the wireless network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points) and base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs), and NRNode Bs (gNBs)). Base stations may be classified based on the coverage they provide (or, in other words, their transmission power levels) and may then be referred to as femtocells, picocells, microcells, or macrocells. A base station may be a relay node or a relay donor node that controls a relay. A network node may also include one or more (or all) portions of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU) sometimes referred to as a remote radio headend (RRH). Such a remote radio unit may or may not be integrated with an antenna as a radio device with an integrated antenna. A portion of a distributed radio base station can also be referred to as a node in a distributed antenna system (DAS). Other examples of network nodes include multi-standard radio (MSR) equipment (such as an MSR BS), network controllers (such as a radio network controller (RNC) or base station controller (BSC)), base transceiver stations (BTS), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), core network nodes (e.g., MSC, MME), O&M nodes, OSS nodes, SON nodes, location nodes (e.g., E-SMLC), and / or MDTs. As another example, a network node can be a virtual network node, as described in more detail below. However, more generally, a network node can refer to any suitable device (or group of devices) capable of, configured to, arranged to, and / or operable to enable and / or provide access to a wireless network for wireless devices or to provide some service to wireless devices already connected to the wireless network.

[0207] exist Figure 14 In the network node 1460, processing circuitry 1470, device-readable medium 1480, interface 1490, auxiliary equipment 1484, power supply 1486, power circuitry 1487, and antenna 1462 are included. Although in Figure 14The network node 1460 shown in the example wireless network may represent an apparatus including a combination of the illustrated hardware components, but other embodiments may include network nodes with different combinations of components. It should be understood that a network node includes any suitable combination of hardware and / or software required to perform the tasks, features, functions, and methods disclosed herein. Furthermore, while the components of network node 1460 are depicted as a single box within a larger box or nested within multiple boxes, in practice, a network node may include multiple different physical components that make up a single illustrated component (e.g., apparatus-readable medium 1480 may include multiple separate hard disk drives and multiple RAM modules).

[0208] Similarly, network node 1460 may consist of multiple physically separate components (e.g., NodeB components and RNC components, or BTS components and BSC components, etc.), each of which may have its own respective components. In some scenarios where network node 1460 includes multiple individual components (e.g., BTS and BSC components), one or more of these individual components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such scenarios, each unique NodeB and RNC pair may be considered a single, separate network node in some instances. In some embodiments, network node 1460 may be configured to support multiple Radio Access Technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate device-readable media 1480 for different RATs), and some components may be reused (e.g., the same antenna 1462 may be shared by RATs). Network node 1460 may also include multiple sets of various illustrated components for integrating different wireless technologies (such as, for example, GSM, WCDMA, LTE, NR, WiFi, or Bluetooth wireless technologies) into network node 1460. These wireless technologies can be integrated into the same or different chips or chipsets and other components within network node 1460.

[0209] Processing circuitry 1470 is configured to perform any determination, calculation, or similar operation (e.g., certain acquisition operations) described herein as being provided by a network node. These operations performed by processing circuitry 1470 may include processing information acquired by processing circuitry 1470, for example by: converting the acquired information into other information, comparing the acquired or converted information with information stored in the network node, and / or performing one or more operations based on the acquired or converted information, and determining the result of said processing.

[0210] Processing circuitry 1470 may include a combination of one or more of the following: a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field-programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic operable to provide the functionality of network node 1460, either alone or in combination with other network node 1460 components (such as device-readable medium 1480). For example, processing circuitry 1470 may execute instructions stored in device-readable medium 1480 or in memory stored within processing circuitry 1470. Such functionality may include any of the various wireless features, functions, or benefits discussed herein. In some embodiments, processing circuitry 1470 may include a system-on-a-chip (SoC).

[0211] In some embodiments, the processing circuitry 1470 may include one or more of a radio frequency (RF) transceiver circuitry 1472 and a baseband processing circuitry 1474. In some embodiments, the RF transceiver circuitry 1472 and the baseband processing circuitry 1474 may be on separate chips (or chipsets), boards, or units (such as radio units and digital units). In alternative embodiments, some or all of the RF transceiver circuitry 1472 and the baseband processing circuitry 1474 may be on the same chip or chipset, board, or unit.

[0212] In some embodiments, some or all of the functionality described herein as being provided by a network node, base station, eNB, or other such network device may be performed by processing circuitry 1470, which executes instructions stored in memory or on device-readable medium 1480 within processing circuitry 1470. In alternative embodiments, some or all of the functionality may be provided by processing circuitry 1470 (e.g., hardwired) without executing instructions stored on separate or discrete device-readable media. In any of those embodiments, processing circuitry 1470 may be configured to perform the described functionality regardless of whether instructions stored on device-readable storage media are executed. The benefits provided by such functionality are not limited to processing circuitry 1470 alone or to other components of network node 1460, but are enjoyed by network node 1460 as a whole, and / or generally by end users and the wireless network.

[0213] Device-readable medium 1480 may include any form of volatile or non-volatile computer-readable storage, including but not limited to permanent storage devices, solid-state storage, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disk), removable storage media (e.g., flash drives, CDs, or DVDs)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions usable by processing circuitry 1470. Device-readable medium 1480 may store any suitable instructions, data, or information, including computer programs, software, applications including one or more of logic, rules, codes, tables, etc., and / or other instructions executable by processing circuitry 1470 and usable by network node 1460. Device-readable medium 1480 may be used to store any calculations performed by processing circuitry 1470 and / or any data received via interface 1490. In some embodiments, the processing circuitry 1470 and the device-readable medium 1480 may be considered integrated.

[0214] Interface 1490 is used for wired or wireless transmission of signaling and / or data between network node 1460, network 1406, and / or WD 1410. As shown, interface 1490 includes one or more ports / terminals 1494 for sending and receiving data to and from network 1406 via a wired connection, for example. Interface 1490 also includes radio front-end circuitry 1492 that may be coupled to or is part of antenna 1462 in some embodiments. Radio front-end circuitry 1492 includes a filter 1498 and an amplifier 1496. Radio front-end circuitry 1492 may be connected to antenna 1462 and processing circuitry 1470. Radio front-end circuitry 1492 may be configured to modulate the signal transmitted between antenna 1462 and processing circuitry 1470. Radio front-end circuitry 1492 may receive digital data to be transmitted to other network nodes or WDs via a wireless connection. The radio front-end circuit 1492 may use a combination of filter 1498 and / or amplifier 1496 to convert digital data into radio signals with appropriate channel and bandwidth parameters. The radio signals can then be transmitted via antenna 1462. Similarly, when data is received, antenna 1462 may collect radio signals, which are then converted into digital data by the radio front-end circuit 1492. The digital data can be passed to processing circuitry 1470. In other embodiments, the interface may include different components and / or different combinations of components.

[0215] In some alternative embodiments, network node 1460 may not include a separate radio front-end circuitry 1492; instead, processing circuitry 1470 may include radio front-end circuitry and may be connected to antenna 1462 without a separate radio front-end circuitry 1492. Similarly, in some embodiments, all or some of the RF transceiver circuitry 1472 may be considered part of interface 1490. In other embodiments, interface 1490 may include one or more ports or terminals 1494, radio front-end circuitry 1492, and RF transceiver circuitry 1472 as part of a radio unit (not shown), and interface 1490 may communicate with baseband processing circuitry 1474, which is part of a digital unit (not shown).

[0216] Antenna 1462 may include one or more antennas or antenna arrays configured to transmit and / or receive wireless signals. Antenna 1462 may be coupled to radio front-end circuitry 1490 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, antenna 1462 may include one or more omnidirectional, fan-shaped, or planar antennas operable to transmit / receive radio signals, for example, between 2 GHz and 66 GHz. Omnidirectional antennas can be used to transmit / receive radio signals in any direction, fan-shaped antennas can be used to transmit / receive radio signals from devices within a specific area, and planar antennas can be line-of-sight antennas used to transmit / receive radio signals along a relatively straight line. In some instances, the use of more than one antenna may be referred to as MIMO. In some embodiments, antenna 1462 may be separate from network node 1460 and may be connected to network node 1460 via an interface or port.

[0217] Antenna 1462, interface 1490, and / or processing circuitry 1470 may be configured to perform any receive operation and / or certain acquire operation described herein as being performed by a network node. Any information, data, and / or signals may be received from a wireless device, another network node, and / or any other network device. Similarly, antenna 1462, interface 1490, and / or processing circuitry 1470 may be configured to perform any transmit operation described herein as being performed by a network node. Any information, data, and / or signals may be transmitted to a wireless device, another network node, and / or any other network device.

[0218] Power circuit 1487 may include or be coupled to power management circuitry and is configured to supply power to the components of network node 1460 for performing the functionality described herein. Power circuit 1487 may receive power from power source 1486. ​​Power source 1486 and / or power circuit 1487 may be configured to supply power to the respective components of network node 1460 in a manner suitable for each component (e.g., at the voltage and current levels required by each respective component). Power source 1486 may be included in power circuit 1487 and / or network node 1460, or may be external to power circuit 1487 and / or network node 1460. For example, network node 1460 may be connected to an external power source (e.g., an electrical outlet) via input circuitry or an interface (such as a cable), whereby the external power source supplies power to power circuit 1487. As another example, power source 1486 may include a power source in the form of a battery or battery pack, which is connected to or integrated into power circuit 1487. The battery can provide backup power if the external power source fails. Other types of power sources, such as photovoltaic devices, can also be used.

[0219] Alternative embodiments of network node 1460 may include, in addition to Figure 14 In addition to those shown, additional components may be responsible for providing certain aspects of the functionality of the network node, including any functionality described herein and / or any functionality necessary to support the topics described herein. For example, network node 1460 may include a user interface device to allow information to be input into and output from network node 1460. This allows users to perform diagnostic, maintenance, repair, and other management functions on network node 1460.

[0220] As used herein, a wireless device (WD) means a means capable of, configured to, arranged to, and / or operable to wirelessly communicate with network nodes and / or other wireless devices. Unless otherwise indicated, the term WD may be used interchangeably with User Equipment (UE) herein. Wireless communication may involve transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for transmitting information through the air. In some embodiments, a WD may be configured to transmit and / or receive information without direct human interaction. For example, a WD may be designed to transmit information to the network according to a predetermined schedule when triggered by an internal or external event, or in response to a request from the network. Examples of WDs include, but are not limited to, smartphones, mobile phones, cellular phones, Voice over IP (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, game consoles or devices, music storage devices, return dischargers, wearable terminal devices, wireless endpoints, mobile stations, tablets, laptops, laptop embedded devices (LEEs), laptop-mounted devices (LMEs), smart devices, wireless customer premises equipment (CPEs), vehicle-mounted wireless terminal devices, etc. For example, by implementing 3GPP standards for pass-through communication, vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), and vehicle-to-everything (V2X), a WD can support device-to-device (D2D) communication, and in this case, the WD can be referred to as a D2D communication device. As yet another specific example, in the Internet of Things (IoT) scenario, a WD can represent a machine or other device that performs monitoring and / or measurement and transmits the results of such monitoring and / or measurement to another WD and / or network node. In this case, the WD can be a machine-to-machine (M2M) device, which in the 3GPP context can be referred to as an MTC device. As a specific example, a WD can be a UE implementing the 3GPP Narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices (such as power meters), industrial machinery, or household or personal appliances (e.g., refrigerators, televisions, etc.) and personal wearable devices (e.g., watches, health trackers, etc.). In other scenarios, a WD can refer to a vehicle or other device capable of monitoring and / or reporting its operational status or other functions associated with its operation. As described above, a WD can represent a wirelessly connected endpoint, in which case the device may be referred to as a wireless terminal. Furthermore, as described above, a WD can be mobile, in which case it may also be referred to as a mobile device or mobile terminal.

[0221] As shown in the figure, the wireless device 1410 includes an antenna 1411, an interface 1414, processing circuitry 1420, a device-readable medium 1430, a user interface device 1432, auxiliary devices 1434, a power supply 1436, and a power circuit 1437. WD 1410 may include multiple sets of components shown for one or more of the different wireless technologies supported by WD 1410, such as, for example, GSM, WCDMA, LTE, NR, WiFi, WiMAX, or Bluetooth wireless technologies, to name just a few. These wireless technologies may be integrated into chips or chipsets that are the same as or different from other components within WD 1410.

[0222] Antenna 1411 may include one or more antennas or antenna arrays configured to transmit and / or receive wireless signals and is connected to interface 1414. In some alternative embodiments, antenna 1411 may be separate from WD 1410 and may be connected to WD 1410 via an interface or port. Antenna 1411, interface 1414, and / or processing circuitry 1420 may be configured to perform any receive or transmit operations described herein as performed by a WD. Any information, data, and / or signals may be received from network nodes and / or another WD. In some embodiments, radio front-end circuitry and / or antenna 1411 may be considered as an interface.

[0223] As shown in the figure, interface 1414 includes radio front-end circuitry 1412 and antenna 1411. Radio front-end circuitry 1412 includes one or more filters 1418 and amplifiers 1416. Radio front-end circuitry 1414 is connected to antenna 1411 and processing circuitry 1420 and is configured to modulate the signal transmitted between antenna 1411 and processing circuitry 1420. Radio front-end circuitry 1412 may be coupled to antenna 1411 or a portion thereof. In some embodiments, WD 1410 may not include separate radio front-end circuitry 1412; instead, processing circuitry 1420 may include radio front-end circuitry and may be connected to antenna 1411. Similarly, in some embodiments, some or all of RF transceiver circuitry 1422 may be considered part of interface 1414. Radio front-end circuitry 1412 may receive digital data to be transmitted wirelessly to other network nodes or WD. The radio front-end circuit 1412 may use a combination of filter 1418 and / or amplifier 1416 to convert digital data into radio signals with appropriate channel and bandwidth parameters. The radio signals can then be transmitted via antenna 1411. Similarly, when data is received, antenna 1411 may collect radio signals, which are then converted into digital data by the radio front-end circuit 1412. The digital data can be passed to processing circuitry 1420. In other embodiments, the interface may include different components and / or different combinations of components.

[0224] Processing circuitry 1420 may include a combination of one or more of the following: a microprocessor, controller, central processing unit, digital signal processor, application-specific integrated circuit, field-programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic operable to provide WD 1410 functionality, either alone or in combination with other WD 1410 components (such as device-readable medium 1430). Such functionality may include any of the various wireless features or benefits discussed herein. For example, processing circuitry 1420 may execute instructions stored in device-readable medium 1430 or in memory within processing circuitry 1420 to provide the functionality disclosed herein.

[0225] As shown in the figure, the processing circuit 1420 includes one or more of an RF transceiver circuit 1422, a baseband processing circuit 1424, and an application processing circuit 1426. In other embodiments, the processing circuit may include different components and / or different combinations of components. In some embodiments, the processing circuit 1420 of the WD 1410 may include a System-on-a-Chip (SoC). In some embodiments, the RF transceiver circuit 1422, the baseband processing circuit 1424, and the application processing circuit 1426 may be on a separate chip or chipset. In alternative embodiments, some or all of the baseband processing circuit 1424 and the application processing circuit 1426 may be combined into a single chip or chipset, and the RF transceiver circuit 1422 may be on a separate chip or chipset. In still alternative embodiments, some or all of the RF transceiver circuit 1422 and the baseband processing circuit 1424 may be on the same chip or chipset, and the application processing circuit 1426 may be on a separate chip or chipset. In other alternative embodiments, some or all of the RF transceiver circuitry 1422, baseband processing circuitry 1424, and application processing circuitry 1426 may be combined on the same chip or chipset. In some embodiments, the RF transceiver circuitry 1422 may be part of interface 1414. The RF transceiver circuitry 1422 may modulate the RF signal used for processing circuitry 1420.

[0226] In some embodiments, some or all of the functionality described herein as being performed by WD may be provided by processing circuitry 1420 executing instructions stored on device-readable medium 1430, which may be a computer-readable storage medium in some embodiments. In alternative embodiments, some or all of the functionality may be provided by processing circuitry 1420 (e.g., hardwired) without executing instructions stored on a separate or discrete device-readable storage medium. In any of those particular embodiments, processing circuitry 1420 may be configured to perform the described functionality regardless of whether instructions stored on a device-readable storage medium are executed. The benefits provided by such functionality are not limited to processing circuitry 1420 alone or to other components of WD 1410, but are enjoyed by WD 1410 as a whole, and / or generally by end users and wireless networks.

[0227] Processing circuitry 1420 may be configured to perform any determination, calculation, or similar operation (e.g., certain acquisition operations) described herein as being performed by WD. Such operations performed by processing circuitry 1420 may include processing information acquired by processing circuitry 1420, which may be done, for example, by: converting the acquired information into other information, comparing the acquired or converted information with information stored by WD 1410, and / or performing one or more operations based on the acquired or converted information, and determining the result of said processing.

[0228] Device-readable medium 1430 may be operable to store computer programs, software, applications including one or more of logic, rules, code, tables, etc., and / or other instructions executable by processing circuitry 1420. Device-readable medium 1430 may include computer memory (e.g., random access memory (RAM) or read-only memory (ROM)), mass storage media (e.g., hard disk), removable storage media (e.g., CD or DVD), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory means that stores information, data, and / or instructions usable by processing circuitry 1420. In some embodiments, processing circuitry 1420 and device-readable medium 1430 may be considered integrated.

[0229] User interface device 1432 provides components that take into account human user interaction with WD 1410. Such interaction can take many forms, such as visual, auditory, tactile, etc. User interface device 1432 can be operated to produce output to the user and allow the user to provide input to WD 1410. The type of interaction can vary depending on the type of user interface device 1432 installed in WD 1410. For example, if WD 1410 is a smartphone, interaction can be performed via a touchscreen; if WD 1410 is a smart meter, interaction can be performed via a screen that provides usage information (e.g., gallons used) or a speaker that provides audible alarms (e.g., if smoke is detected). User interface device 1432 may include input interfaces, means, and circuitry, as well as output interfaces, means, and circuitry. User interface device 1432 is configured to allow information to be input into WD 1410 and is connected to processing circuitry 1420 to allow processing circuitry 1420 to process the input information. User interface device 1432 may include, for example, a microphone, proximity sensor or other sensor, buttons / buttons, a touch display, one or more cameras, a USB port, or other input circuitry. User interface device 1432 is also configured to allow information output from WD 1410 and to allow processing circuitry 1420 to output information from WD 1410. User interface device 1432 may include, for example, a speaker, display, vibration circuitry, a USB port, a headphone jack, or other output circuitry. Using one or more input and output interfaces, devices, and circuitry of user interface device 1432, WD 1410 can communicate with end users and / or wireless networks, allowing them to benefit from the functionality described herein.

[0230] The auxiliary device 1434 is operable to provide more specific functionality that is generally not performed by the WD. This may include dedicated sensors for measurements for various purposes, interfaces for additional types of communication such as wired communication, etc. The inclusion and type of components of the auxiliary device 1434 may vary depending on the embodiment and / or scenario.

[0231] In some embodiments, power supply 1436 may take the form of a battery or battery pack. Other types of power sources may also be used, such as an external power source (e.g., an electrical outlet), a photovoltaic device, or a power battery. WD 1410 may further include power circuitry 1437 for delivering power from power supply 1436 to various parts of WD 1410 that require power from power supply 1436 to perform any functionality described or indicated herein. In some embodiments, power circuitry 1437 may include power management circuitry. Power circuitry 1437 may additionally or alternatively be operable to receive power from an external power source; in this case, WD 1410 may be connected to an external power source (e.g., an electrical outlet) via input circuitry or an interface (e.g., a power cable). In some embodiments, power circuitry 1437 may also be operable to deliver power from an external power source to power supply 1436. For example, this can be used for charging power supply 1436. Power circuitry 1437 may perform any formatting, conversion, or other modifications on the power from power supply 1436 to suit the appropriate components of WD 1410 to which power is supplied.

[0232] Figure 15 An embodiment of a UE according to the various aspects described herein is illustrated. As used herein, a user equipment or UE may not necessarily have a user in the sense of a human user who owns and / or operates the associated device. Instead, a UE may represent a device intended to be sold to or operated by a human user, but which may not be associated with or initially not associated with a particular human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device not intended to be sold to or operated by an end user, but which may be associated with or operated for the benefit of a user (e.g., a smart power meter). UE 15200 can be any UE identified by the 3rd Generation Partnership Project (3GPP), including NB-IoT UEs, Machine Type Communication (MTC) UEs, and / or Enhanced MTC (eMTC) UEs. Figure 15 The UE 1500 shown is an example of a WD configured to communicate according to one or more communication standards published by the 3rd Generation Partnership Project (3GPP), such as 3GPP's GSM, UMTS, LTE, and / or 5G standards. As mentioned earlier, the terms WD and UE can be used interchangeably. Therefore, although... Figure 15 It is a UE, but the components discussed in this article also apply to WD, and vice versa.

[0233] exist Figure 15In this embodiment, UE 1500 includes processing circuitry 1501 operatively coupled to an input / output interface 1505, a radio frequency (RF) interface 1509, a network connectivity interface 1511, a memory 1515 including random access memory (RAM) 1517, read-only memory (ROM) 1519, and storage medium 1521, a communication subsystem 1531, a power supply 1533, and / or any other components or any combination thereof. Storage medium 1521 includes an operating system 1523, application programs 1525, and data 1527. In other embodiments, storage medium 1521 may include other similar types of information. Some UEs may utilize... Figure 15 All components shown, or only a subset of components, can be used. The integration level between components can vary from one UE to another. Additionally, some UEs may contain multiple instances of components, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0234] exist Figure 15 In this embodiment, processing circuitry 1501 can be configured to process computer instructions and data. Processing circuitry 1501 can be configured to implement any sequential state machine operable to execute machine instructions stored in memory as a machine-readable computer program, such as one or more hardware-implemented state machines (e.g., in discrete logic, FPGA, ASIC, etc.); programmable logic together with appropriate firmware; one or more stored programs, a general-purpose processor (such as a microprocessor or digital signal processor (DSP)) together with appropriate software; or any combination of the foregoing. For example, processing circuitry 1501 may include two central processing units (CPUs). Data may be information in a form suitable for use by a computer.

[0235] In the depicted embodiments, the input / output interface 1505 may be configured to provide a communication interface to an input device, an output device, or both input and output devices. The UE 1500 may be configured to use an output device via the input / output interface 1505. The output device may use an interface port of the same type as the input device. For example, a USB port may be used to provide input to and output from the UE 1500. The output device may be a speaker, sound card, video card, display, monitor, printer, actuator, transmitter, smart card, another output device, or any combination thereof. The UE 1500 may be configured to use an input device via the input / output interface 1505 to allow a user to capture information into the UE 1500. The input device may include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, digital camcorder, web camera, etc.), a microphone, a sensor, a mouse, a trackball, a steering wheel, a scroll wheel, a smart card, etc. A presence-sensitive display may include a capacitive or resistive touch sensor to sense input from the user. Sensors can be, for example, accelerometers, gyroscopes, tilt sensors, force sensors, magnetometers, light sensors, proximity sensors, other similar sensors, or any combination thereof. Input devices can be, for example, accelerometers, magnetometers, digital cameras, microphones, and light sensors.

[0236] exist Figure 15 In this configuration, RF interface 1509 can be configured to provide a communication interface to RF components (such as transmitters, receivers, and antennas). Network connectivity interface 1511 can be configured to provide a communication interface to network 1543a. Network 1543a may include wired and / or wireless networks, such as local area networks (LANs), wide area networks (WANs), computer networks, wireless networks, telecommunications networks, another similar network, or any combination thereof. For example, network 1543a may include a Wi-Fi network. Network connectivity interface 1511 can be configured to include receiver and transmitter interfaces for communicating with one or more other devices over the communication network according to one or more communication protocols (such as Ethernet, TCP / IP, SONET, ATM, etc.). Network connectivity interface 1511 can implement receiver and transmitter functionality suitable for communication network links (e.g., optical, electrical, etc.). Transmitter and receiver functionality may share circuit components, software, or firmware, or alternatively may be implemented separately.

[0237] RAM 1517 may be configured to interface with processing circuitry 1501 via bus 1502 to provide storage or cache of data or computer instructions during the execution of software programs such as operating systems, applications, and device drivers. ROM 1519 may be configured to provide computer instructions or data to processing circuitry 1501. For example, ROM 1519 may be configured to store invariant low-level system code or data for basic system functions (such as basic input and output (I / O), booting, or receiving keystrokes from a keyboard) stored in non-volatile memory. Storage medium 1521 may be configured to include memory such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), disk, optical disk, floppy disk, hard disk, removable magnetic tape, or flash drive. In one example, storage medium 1521 may be configured to include operating system 1523, application program 1525 (such as a web browser application, widget or utility engine, or another application), and data file 1527. Storage medium 1521 can store any of a variety of operating systems or combinations of operating systems for use by UE 1500.

[0238] Storage medium 1521 may be configured to include multiple physical drive units, such as a Redundant Array of Independent Disks (RAID), a floppy disk drive, flash memory, a USB flash drive, an external hard disk drive, a thumb drive, a pen drive, a key drive, a high-density digital multifunction disc (HD-DVD) optical disc drive, an internal hard disk drive, a Blu-ray disc drive, a holographic digital data storage (HDDS) optical disc drive, an external micro dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), an external micro DIMM SDRAM, smart card memory (such as a subscriber identification module or a removable subscriber identity (SIM / RUIM) module), other memory, or any combination thereof. Storage medium 1521 may allow UE 1500 to access computer-executable instructions, applications, etc., stored on a transient or non-transient storage medium to offload or upload data. Articles of manufacture (such as an article utilizing a communication system) may be tangibly embodied in storage medium 1521, which may include a device-readable medium.

[0239] exist Figure 15In this embodiment, processing circuitry 1501 can be configured to communicate with network 1543b using communication subsystem 1531. Networks 1543a and 1543b can be the same one or more networks or different one or more networks. Communication subsystem 1531 can be configured to include one or more transceivers for communicating with network 1543b. For example, communication subsystem 1531 can be configured to include one or more transceivers for communicating with one or more remote transceivers of another device (such as another WD, UE, or radio access network (RAN) base station) capable of wireless communication according to one or more communication protocols (such as IEEE 802.11, CDMA, WCDMA, GSM, LTE, UTRAN, WiMax, etc.). Each transceiver can include transmitter 1533 and / or receiver 1535 to respectively implement transmitter or receiver functionality suitable for the RAN link (e.g., frequency allocation, etc.). Additionally, the transmitter 1533 and receiver 1535 of each transceiver can share circuit components, software, or firmware, or alternatively can be implemented separately.

[0240] In the illustrated embodiment, the communication functions of the communication subsystem 1531 may include data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication such as using a Global Positioning System (GPS) to determine location, another similar communication function, or any combination thereof. For example, the communication subsystem 1531 may include cellular communication, Wi-Fi communication, Bluetooth communication, and GPS communication. The network 1543b may include wired and / or wireless networks, such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a telecommunications network, another similar network, or any combination thereof. For example, the network 1543b may be a cellular network, a Wi-Fi network, and / or a near-field network. The power supply 1513 may be configured to provide alternating current (AC) or direct current (DC) power to the components of the UE 1500.

[0241] The features, benefits, and / or functions described herein may be implemented in one of the components of UE 1500 or partitioned across multiple components of UE 1500. Alternatively, the features, benefits, and / or functions described herein may be implemented using any combination of hardware, software, or firmware. In one example, communication subsystem 1531 may be configured to include any of the components described herein. Additionally, processing circuitry 1501 may be configured to communicate with any of such components via bus 1502. In another example, any component of such a component may be represented by program instructions stored in memory that perform the corresponding functions described herein when executed by processing circuitry 1501. In yet another example, the functionality of any component of such a component may be partitioned between processing circuitry 1501 and communication subsystem 1531. In yet another example, non-computationally intensive functions of any component of such a component may be implemented using software or firmware, and computationally intensive functions may be implemented using hardware.

[0242] Figure 16 This is a schematic block diagram illustrating a virtualized environment 1600 in which functionality implemented by some embodiments can be virtualized. In this context, virtualization means creating a virtual version of a device or apparatus that may include a virtualized hardware platform, storage devices, and networking resources. As used herein, virtualization can be applied to nodes (e.g., virtualized base stations or virtualized radio access nodes) or to apparatuses (e.g., UEs, wireless devices, or any other type of communication device) or components thereof, and relates to at least a portion of its functionality (e.g., via one or more applications, components, functions, virtual machines, or containers executed on one or more physical processing nodes in one or more networks) being implemented as one or more virtual components.

[0243] In some embodiments, some or all of the functionality described herein may be implemented as virtual components executed by one or more virtual machines, which are implemented in one or more virtual environments 1600 hosted by one or more hardware nodes 1630. Additionally, in embodiments where the virtual node is not a radio access node or does not require radio connectivity (e.g., a core network node), the network node may then be fully virtualized.

[0244] These functionalities can be implemented by one or more applications 1620 (which may alternatively be referred to as software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) operable to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. Application 1620 runs in a virtualization environment 1600, which provides hardware 1630 including processing circuitry 1660 and memory 1690. Memory 1690 contains instructions 1695 executable by the processing circuitry 1660, thereby enabling application 1620 to operate to provide one or more of the features, benefits, and / or functions disclosed herein.

[0245] The virtualization environment 1600 includes general-purpose or special-purpose network hardware devices 1630, which include a collection of one or more processors or processing circuits 1660. The processors or processing circuits 1660 may be commercial off-the-shelf (COTS) processors, specialized application-specific integrated circuits (ASICs), or any other type of processing circuitry including digital or analog hardware components or a special-purpose processor. Each hardware device may include a memory 1690-1, which may be a non-permanent memory for temporarily storing software or instructions 1695 executed by the processing circuits 1660. Each hardware device may include one or more network interface controllers (NICs) 1670 (also referred to as network interface cards), which include a physical network interface 1680. Each hardware device may also include a non-transitory, permanent, machine-readable storage medium 1690-2 in which instructions and / or software 1695 executable by the processing circuits 1660 are already stored. Software 1695 may include any type of software, including software for instantiating one or more virtualization layers 1650 (also known as hypervisors), software for executing virtual machine 1640, and software that allows it to perform the functions, features, and / or benefits described in conjunction with some of the embodiments described herein.

[0246] Virtual machine 1640 includes virtual processing, virtual memory, virtual networking or interfaces, and virtual storage devices, and can be run by a corresponding virtualization layer 1650 or hypervisor. Different embodiments of instances of virtual appliance 1620 may be implemented on one or more virtual machines in virtual machine 1640, and this implementation may be carried out in different ways.

[0247] During operation, the processing circuitry 1660 executes software 1695 to instantiate the hypervisor or virtualization layer 1650, which may sometimes be referred to as a virtual machine monitor (VMM). The virtualization layer 1650 can present a virtual operating platform to the virtual machine 1640 that appears to be networked hardware.

[0248] like Figure 16As shown, hardware 1630 can be a standalone network node with general or specific components. Hardware 1630 may include antenna 16225 and may implement some functions via virtualization. Alternatively, hardware 1630 may be part of a larger hardware cluster (e.g., such as in a data center or customer premises equipment (CPE)) in which many hardware nodes work together and are managed via management and orchestration (MANO) 16100, which, among other things, oversees the lifecycle management of application 1620.

[0249] Hardware virtualization is sometimes referred to as Network Functions Virtualization (NFV). NFV can be used to consolidate many types of network devices into industry-standard high-capacity server hardware, physical switches, and physical storage devices, which can reside in data centers and customer premises.

[0250] In the context of NFV, virtual machine 1640 can be a software implementation of a physical machine, where programs run as if they were executing on a physical, non-virtualized machine. Each virtual machine in 1640, along with the portion of hardware 1630 that executes that virtual machine (whether it is hardware dedicated to that virtual machine and / or hardware shared by that virtual machine and other virtual machines in 1640), forms a separate virtual network element (VNE).

[0251] Within the context of NFV, a Virtual Network Function (VNF) is responsible for handling specific network functions running in one or more virtual machines 1640 on top of the hardware networking infrastructure 1630, and corresponds to Figure 16 Application 1620.

[0252] In some embodiments, one or more radio units 16200, each including one or more transmitters 16220 and one or more receivers 16210, may be coupled to one or more antennas 16225. The radio unit 16200 may communicate directly with the hardware node 1630 via one or more suitable network interfaces and may be used in combination with virtual components to provide radio capabilities to the virtual node, such as a radio access node or base station.

[0253] In some embodiments, signaling may be implemented by means of a control system 16230, which may alternatively be used for communication between hardware node 1630 and radio unit 16200.

[0254] refer to Figure 17According to an embodiment, the communication system includes a telecommunications network 1710, such as a 3GPP-type cellular network, which includes an access network 1711 (such as a radio access network) and a core network 1714. The access network 1711 includes multiple base stations 1712a, 1712b, 1712c, such as NBs, eNBs, gNBs, or other types of wireless access points, for each custom-defined coverage area 1713a, 1713b, 1713c. Each base station 1712a, 1712b, 1712c can be connected to the core network 1714 via a wired or wireless connection 1715. A first UE 1791 located in coverage area 1713c is configured to wirelessly connect to or be paged by the corresponding base station 1712c. A second UE 1792 located in coverage area 1713a can wirelessly connect to the corresponding base station 1712a. Although multiple UEs 1791 and 1792 are shown in this example, the disclosed embodiments are equally applicable to situations where only one UE is in the coverage area or where only one UE is connected to the corresponding base station 1712.

[0255] Telecommunications network 1710 is itself connected to host computer 1730, which may be embodied in the hardware and / or software of a standalone server, a cloud-implemented server, a distributed server, or as processing resources in a server farm. Host computer 1730 may be under the ownership or control of a service provider, or may be operated by or on behalf of the service provider. Connections 1721 and 1722 between telecommunications network 1710 and host computer 1730 may extend directly from core network 1714 to host computer 1730, or may be made via optional intermediate network 1720. Intermediate network 1720 may be one or more of public, private, or hosted networks; intermediate network 1720 (if any) may be a backbone network or the Internet; in particular, intermediate network 1720 may include two or more subnets (not shown). Host computer 1730 may be connected to database 1740. The connection between host computer 1730 and database 1740 can be a local connection (e.g., each is part of the same local network) or a remote connection (e.g., each is part of a different network). The connection between host computer 1730 and database 1740 can be via an intermediate network (e.g., 1720, a network satisfying the description of 1720 above, etc.). In the example implementation, database 1740 includes a server.

[0256] Figure 17The communication system as a whole enables connectivity between the connected UEs 1791 and 1792 and the host computer 1730. This connectivity can be described as an over-the-top (OTT) connection 1750. The host computer 1730 and the connected UEs 1791 and 1792 are configured to transmit data and / or signaling via the OTT connection 1750, using access network 1711, core network 1714, any intermediate network 1720, and possibly other infrastructure (not shown) as intermediaries. The OTT connection 1750 can be transparent in the sense that the participating communication devices are unaware of the routes of uplink and downlink communications. For example, it may not be necessary or required to inform the base station 1712 about the past routes of incoming downlink communications containing data originating from the host computer 1730 to be forwarded (e.g., transferred) to the connected UE 1791. Similarly, base station 1712 does not need to know the future route of outgoing uplink communication originating from UE 1791 toward host computer 1730.

[0257] According to the embodiments, reference will now be made to Figure 18 Example implementations of the UE, base station, and host computer discussed in the preceding paragraphs are described. In the communication system 1800, the host computer 1810 includes hardware 1815, which includes a communication interface 1816 configured to establish and maintain wired or wireless connections with interfaces to different communication devices of the communication system 1800. The host computer 1810 further includes processing circuitry 1818, which may have storage and / or processing capabilities. In particular, the processing circuitry 1818 may include one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The host computer 1810 further includes software 1811, which is stored in or accessible by the host computer 1810 and executable by the processing circuitry 1818. The software 1811 includes a host application 1812. Host application 1812 may be operable to provide services to remote users, such as UE1830 connected via OTT connection 1850 terminated between UE 1830 and host computer 1810. When providing services to remote users, host application 1812 may provide user data transmitted using OTT connection 1850.

[0258] The communication system 1800 further includes a base station 1820, which is provided in the telecommunications system and includes hardware 1825 enabling it to communicate with a host computer 1810 and a UE 1830. Hardware 1825 may include a communication interface 1826 for establishing and maintaining wired or wireless connections to different communication devices of the communication system 1800, and for establishing and maintaining connections with at least the coverage area served by the base station 1820. Figure 18 The radio interface 1827 of the UE 1830 (not shown) is for the wireless connection 1870. The communication interface 1826 can be configured to facilitate a connection 1860 to the host computer 1810. Connection 1860 can be direct, or it can be via the core network of the telecommunications system (…). Figure 18 (Not shown) and / or via one or more intermediate networks outside the telecommunications system. In the illustrated embodiment, the hardware 1825 of the base station 1820 further includes processing circuitry 1828, which may include one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The base station 1820 further has internally stored or externally accessible software 1821.

[0259] The communication system 1800 further includes the previously mentioned UE 1830. Its hardware 1835 may include a radio interface 1837 configured to establish and maintain a wireless connection 1870 with a base station serving the coverage area currently in which the UE 1830 is located. The hardware 1835 of the UE 1830 further includes processing circuitry 1838, which may include one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or combinations thereof (not shown) adapted to execute instructions. The UE 1830 further includes software 1831, which is stored in or accessible by the UE 1830 and executable by the processing circuitry 1838. The software 1831 includes a client application 1832. The client application 1832 may be operable to provide services to human or non-human users via the UE 1830, supported by a host computer 1810. In host computer 1810, a running host application 1812 can communicate with a running client application 1832 via an OTT connection 1850 terminated between UE 1830 and host computer 1810. When providing services to a user, client application 1832 can receive requested data from host application 1812 and provide user data in response to the requested data. OTT connection 1850 can transmit both the requested data and the user data. Client application 1832 can interact with the user to generate the user data it provides.

[0260] Notice, Figure 18 The host computer 1810, base station 1820, and UE 1830 shown may be similar to or equivalent to the following: Figure 17 The host computer 1730, one of base stations 1712a, 1712b, and 1712c, and one of UEs 1791 and 1792. That is to say, the internal operation of these entities can be as follows: Figure 18 As shown, and independently, the surrounding network topology can be Figure 17 The network topology.

[0261] exist Figure 18 In this diagram, OTT connection 1850 is abstractly depicted to illustrate communication between host computer 1810 and UE 1830 via base station 1820, without explicitly mentioning any intermediate devices or the precise routing of messages via these devices. The network infrastructure can determine the route, which can be configured to either the service provider operating host computer 1810 or hide the route from both. When OTT connection 1850 is active, the network infrastructure can further make decisions, through which it dynamically changes the route (e.g., based on network reconfiguration or load balancing considerations).

[0262] The wireless connection 1870 between UE 1830 and base station 1820 is consistent with the teachings of the embodiments described throughout this disclosure. One or more embodiments in various embodiments improve the performance of OTT services provided to UE 1830 using OTT connection 1850, wherein wireless connection 1870 forms the final segment.

[0263] The measurement process can be provided for the purpose of monitoring data rates, latency, and other factors improved by one or more embodiments. Optional network functionality may further exist for reconfiguring the OTT connection 1850 between host computer 1810 and UE 1830 in response to changes in measurement results. The measurement process and / or network functionality for reconfiguring the OTT connection 1850 can be implemented using software 1811 and hardware 1815 of host computer 1810, or software 1831 and hardware 1835 of UE 1830, or both. In embodiments, sensors (not shown) may be deployed in or associated with communication devices traversed by the OTT connection 1850; the sensors may participate in the measurement process by supplying values ​​of the monitored quantities illustrated above, or by supplying values ​​of other physical quantities from which software 1811, 1831 can calculate or estimate the monitored quantities. Reconfiguration of the OTT connection 1850 may include message formats, retransmission settings, preferred routing, etc.; reconfiguration does not need to affect base station 1820, and it may be unknown or imperceptible to base station 1820. Such processes and functionalities are likely known and practiced in the art. In some embodiments, the measurement may involve proprietary UE signaling that facilitates the host computer 1810 in measuring throughput, propagation time, latency, etc. Measurements can be made such that software 1811 and 1831, while monitoring propagation time, errors, etc., use OTT connection 1850 to enable the transmission of messages (particularly empty or 'virtual' messages).

Claims

1. A method executed by network nodes (716, 1460, 1600, 1730, 1810, 1820), the method comprising: (1102) Receive first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction; In response to receiving the first data from the device, it is possible (1104) to transmit the second data and the unique identifier to one or more data receiving entities; Wherein, the second data is associated with an indication of a time limit for retaining the first data in the first data transaction, and Wherein, the second data is at least one of the following: an instance of the first data, data including the first data, and data generated using the first data; The indication of the time limit indicates the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling (1106) storage of one or more of the first data and the second data according to the time limit; and The indication based on the time limit does not indicate the determination of a non-zero time limit for retaining the first data in the first data transaction, causing (1108) the first data and the second data to be deleted. The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

2. The method as described in claim 1, wherein, The unique identifier is assigned by the device or the network node.

3. The method of claim 1 or 2, further comprising: One or more processes are performed on the first data to generate the second data.

4. The method as described in claim 1 or 2, wherein, The unique identifier maintains the anonymity of the device and the user profile for the one or more data receiving entities that receive the transmission of the second data or access the second data.

5. The method as described in claim 1 or 2, wherein, The unique identifier is a one-time use identifier, which allows for the use of a different unique identifier for a second data transaction involving the device associated with the user profile.

6. The method as described in claim 1 or 2, wherein, This enables the storage of one or more of the first data and the second data according to the time constraint, including one or more of the following steps: The network node stores the second data in the data storage device according to the time limit; as well as The network node transmits the second data to one or more database nodes for storage according to the time limit.

7. The method of claim 1 or 2, further comprising: This causes one or more of the first and second data to be deleted before or when the time limit expires.

8. The method as claimed in claim 1 or 2, wherein, The time limit mentioned is the first time limit; Wherein, the second data is data of the first type that conforms to the first time limit; Wherein, the third data received from the device or generated by the network node based on data received from the device is a second type of data, different from the first type of data; and Specifically, at least because the third data is data of the second type, the third data is subject to a second time constraint that is different from the first time constraint.

9. The method as claimed in claim 1 or 2, wherein, The user profile includes time limits for one or more user profiles that contain the time limit.

10. The method of claim 9, wherein, The time limit for the one or more user configurations may be specified by one or more of the following: the identifier of the receiving entity, the type used, or the type of data.

11. A method performed by an electronic device (100, 1410, 1500, 1600, 1791, 1792, 1830), the method comprising: Presenting (1202) one or more options for configuring one or more data retention time limits for one or more categories of data, wherein the one or more categories of data are associated with one or more data transactions involving user profiles associated with the electronic device; Each of the one or more data retention time limits controls the length of time for which the remote user data collection system is permitted to retain certain data of the one or more categories of data, which is associated with the corresponding data retention time limit of the one or more data retention time limits. Receive (1204) user input associated with one or more of the options, the user input specifying a first data retention time limit for data of a first category; This causes (1206) the first data retention time limit to be associated with the user profile associated with the electronic device; and When the first data retention time limit is associated with the user profile, one or more datasets of data classified as the first category are transmitted (1208) for storage at the remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data classified as the first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier. The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The corresponding unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

12. The method of claim 11, further comprising: Receive user input associated with one or more of the options, the user input specifying a second data retention time limit for a subset of the data in the first category; This causes the second data retention time limit to be associated with the user profile associated with the electronic device; as well as When the second data retention time limit is associated with the user profile, one or more datasets of the subset of data that constitute the first category are transmitted so as to be stored at the remote user data collection system for no longer than the first data retention time limit or the second data retention time limit.

13. The method of claim 11 or 12, further comprising: Receive user input associated with one or more of the options, wherein the user input specifies a third data retention time limit for the second category of data; The third data retention time limit differs from the first data retention time limit, and The data in the second category differs from the data in the first category; This causes the third data retention time limit to be associated with the user profile associated with the electronic device; and When the third data retention time limit is associated with the user profile, one or more datasets of data classified as the second category are transmitted for storage at the remote user data collection system for no longer than the third data retention time limit, wherein the one or more datasets of data classified as the second category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier.

14. The method of claim 11 or 12, wherein, Define a given category of data based on one or more of the following: The identifier of the originating device of one or more electronic devices associated with the user profile, the originating device being the source of the corresponding data; A destination receiving entity, which is to be provided with access to the corresponding data; The usage type of the corresponding data; as well as The type of the corresponding data.

15. The method of claim 14, wherein, The usage types of the relevant data include one or more of the following: advertising, billing, service optimization, and media.

16. The method of claim 14, wherein, The types of the corresponding data include one or more of the following: health data, location data, and financial transaction data.

17. A method performed by network nodes (716, 722, 1460, 1600, 1730, 1740, 1810, 1820), the method comprising: Receive (1302) first data of a first data transaction associated with a user profile, wherein the first data includes: The unique identifier relates to the first unique identifier of the first data transaction of the device associated with the user profile; Identifiers of external requesting entities other than the user profile that are granted access to the first data; An indication of a first time limit for retaining the first data of the first transaction; and First-person data provided by a device associated with the user profile; Store (1304) the first data for access by the external requesting entity; Provide (1306) the first unique identifier and the first personal data to the external requesting entity other than the user profile; and Once the first time limit for retaining the first data of the first transaction expires, at least a portion of the first data including the first unique identifier is deleted (1308). The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The first unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

18. The method of claim 17, further comprising: Receive second data of a second data transaction associated with the user profile, wherein the second data includes: The unique identifier relates to a second unique identifier for the second data transaction of the device associated with the user profile; The identifier of the external requesting entity other than the user profile that is granted access to the second data; An indication of a second time limit for retaining the second data of the second transaction; and Second-person data provided by the device associated with the user profile. Wherein, the first personal data is a first type of data, while the second personal data is a second type of data that is different from the first type of data; Wherein, the first type of data is subject to the first time limit for retention, and the second type of data is subject to the second time limit for retention, and Wherein, the second time limit is different from the first time limit; Store the second data for access by the external requesting entity; Provide the second unique identifier and the second personal data to the external requesting entity other than the user profile; and Once the second time limit for retaining the second data for the second transaction expires, at least a portion of the second data, including the second unique identifier, is deleted.

19. The method of claim 17 or 18, wherein, The external request entity is a first external request entity, and the method further includes: Receive third data of a third data transaction associated with the user profile, wherein the third data includes: The unique identifier relates to the third unique identifier of the third data transaction of the device associated with the user profile; The identifier of a second external request entity other than the user profile that is granted access to at least a portion of the third data, wherein the first external request entity is different from the second external request entity; An indication of a third time limit for retaining the third data of the third transaction; Wherein, the data access permission of the first external requesting entity is subject to the first time limit for retention, while the data access permission of the second external requesting entity is subject to the third time limit for retention, and Wherein, the third time limit is different from the first time limit; and Third-person data provided by a device associated with the user profile; The third data is stored for access by the second external requesting entity; Provide the third unique identifier and the third person data to the second external requesting entity other than the user profile; and Once the third time limit for retaining the third data for the third transaction expires, at least a portion of the third data containing the third unique identifier is deleted.

20. The method of claim 17 or 18, further comprising: Before the first time limit expires, a request for access to data from the first data, which includes at least the first unique identifier and the first personal data, is received from the external requesting entity, wherein, in response to receiving the request, the first unique identifier and the first personal data are provided.

21. The method of claim 20, wherein, The first data includes an authorized usage code, wherein the request includes a requested usage code, and wherein the method further includes: Before providing the first unique identifier and the first personal data to the external requesting entity, it is determined that the permitted use code matches the requested use code.

22. The method of claim 17 or 18, wherein, Deleting at least a portion of the first data includes deleting the first personal data.

23. The method of claim 17 or 18, wherein, The first unique identifier maintains the anonymity of the device and the user profile for the external requesting entity.

24. A network node (716, 1460, 1600, 1730, 1810, 1820) includes one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the network node to perform the following operations: (1102) Receive first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction; In response to receiving the first data from the device, it is possible (1104) to transmit the second data and the unique identifier to one or more data receiving entities; in, The second data is associated with an indication of a time limit for retaining the first data in the first data transaction, and Wherein, the second data is at least one of the following: an instance of the first data, data including the first data, and data generated using the first data; The indication of the time limit indicates the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling (1106) storage of one or more of the first data and the second data according to the time limit; and The indication based on the time limit does not indicate the determination of a non-zero time limit for retaining the first data in the first data transaction, causing (1108) the first data and the second data to be deleted. The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

25. The network node as described in claim 24, wherein, The unique identifier is assigned by the device or the network node.

26. The network node as described in claim 24 or 25, wherein, The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: One or more processes are performed on the first data to generate the second data.

27. The network node as described in claim 24 or 25, wherein, The unique identifier maintains the anonymity of the device and the user profile for the one or more data receiving entities that receive the transmission of the second data or access the second data.

28. The network node as described in claim 24 or 25, wherein, The unique identifier is a one-time use identifier, which allows for the use of a different unique identifier for a second data transaction involving the device associated with the user profile.

29. The network node as described in claim 24 or 25, wherein, This enables the storage of one or more of the first data and the second data according to the time constraint, including one or more of the following steps: The network node stores the second data in the data storage device according to the time limit; as well as The network node transmits the second data to one or more database nodes for storage according to the time limit.

30. The network node as described in claim 24 or 25, wherein, The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: This causes one or more of the first and second data to be deleted before or when the time limit expires.

31. The network node as described in claim 24 or 25, wherein, The time limit mentioned is the first time limit; Wherein, the second data is data of the first type that conforms to the first time limit; Wherein, the third data received from the device or generated by the network node based on data received from the device is a second type of data, different from the first type of data; and Specifically, at least because the third data is data of the second type, the third data is subject to a second time constraint that is different from the first time constraint.

32. The network node as described in claim 24 or 25, wherein, The user profile includes time limits for one or more user profiles that contain the time limit.

33. The network node as described in claim 32, wherein, The time limit for the one or more user configurations may be specified by one or more of the following: the identifier of the receiving entity, the type used, or the type of data.

34. A network node (716, 1460, 1600, 1730, 1810, 1820) includes one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the network node to perform the method as described in any one of claims 1-10.

35. A computer program product comprising program code to be executed by one or more processors of a network node (716, 1460, 1600, 1730, 1810, 1820), wherein execution of the program code causes the network node to perform operations, the operations including: (1102) Receive first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction; In response to receiving the first data from the device, it is possible (1104) to transmit the second data and the unique identifier to one or more data receiving entities; Wherein, the second data is associated with an indication of a time limit for retaining the first data in the first data transaction, and Wherein, the second data is at least one of the following: an instance of the first data, data including the first data, and data generated using the first data; The indication of the time limit indicates the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling (1106) storage of one or more of the first data and the second data according to the time limit; and The indication based on the time limit does not indicate the determination of a non-zero time limit for retaining the first data in the first data transaction, causing (1108) the first data and the second data to be deleted. The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

36. A computer program product comprising program code to be executed by one or more processors of a network node (716, 1460, 1600, 1730, 1810, 1820), wherein execution of the program code causes the network node to perform the method as described in any one of claims 1-10.

37. A non-transitory computer-readable medium comprising instructions executable by one or more processors of a network node (716, 1460, 1600, 1730, 1810, 1820), the instructions including instructions for performing the following operations: (1102) Receive first data of a first data transaction from a device associated with a user profile, the first data being assigned a unique identifier that uniquely identifies the first data transaction; In response to receiving the first data from the device, it is possible (1104) to transmit the second data and the unique identifier to one or more data receiving entities; in, The second data is associated with an indication of a time limit for retaining the first data in the first data transaction, and Wherein, the second data is at least one of the following: an instance of the first data, data including the first data, and data generated using the first data; The indication of the time limit indicates the determination of a non-zero time limit for retaining the first data of the first data transaction, enabling (1106) storage of one or more of the first data and the second data according to the time limit; and The indication based on the time limit does not indicate the determination of a non-zero time limit for retaining the first data in the first data transaction, causing (1108) the first data and the second data to be deleted. The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

38. A non-transitory computer-readable medium comprising instructions executable by one or more processors of a network node (716, 1460, 1600, 1730, 1810, 1820), the instructions including instructions for performing the method as claimed in any one of claims 1-10.

39. An electronic device (100, 1410, 1500, 1600, 1791, 1792, 1830) includes one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the electronic device to perform the following operations: Presentation (1202) provides one or more options for configuring one or more data retention time limits for one or more categories of data, wherein, The data categories are associated with one or more data transactions, which relate to user profiles associated with the electronic device; Each of the one or more data retention time limits controls the length of time for which the remote user data collection system is permitted to retain certain data of the one or more categories of data, which is associated with the corresponding data retention time limit of the one or more data retention time limits. Receive (1204) user input associated with one or more of the options, the user input specifying a first data retention time limit for data of a first category; This causes (1206) the first data retention time limit to be associated with the user profile associated with the electronic device; and When the first data retention time limit is associated with the user profile, one or more datasets of data classified as the first category are transmitted (1208) for storage at the remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data classified as the first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier. The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The corresponding unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

40. The electronic device of claim 39, wherein, The memory further includes instructions executable by the one or more processors to cause the electronic device to perform the following operations: Receive user input associated with one or more of the options, the user input specifying a second data retention time limit for a subset of the data in the first category; This causes the second data retention time limit to be associated with the user profile associated with the electronic device; as well as When the second data retention time limit is associated with the user profile, one or more datasets of the subset of data that constitute the first category are transmitted so as to be stored at the remote user data collection system for no longer than the first data retention time limit or the second data retention time limit.

41. The electronic device as claimed in claim 39 or 40, wherein, The memory further includes instructions executable by the one or more processors to cause the electronic device to perform the following operations: Receive user input associated with one or more of the options, wherein the user input specifies a third data retention time limit for the second category of data; The third data retention time limit differs from the first data retention time limit, and The data in the second category differs from the data in the first category; This causes the third data retention time limit to be associated with the user profile associated with the electronic device; and When the third data retention time limit is associated with the user profile, one or more datasets of data classified as the second category are transmitted for storage at the remote user data collection system for no longer than the third data retention time limit, wherein the one or more datasets of data classified as the second category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier.

42. The electronic device as claimed in claim 39 or 40, wherein, Define a given category of data based on one or more of the following: The identifier of the originating device of one or more electronic devices associated with the user profile, the originating device being the source of the corresponding data; A destination receiving entity, which is to be provided with access to the corresponding data; The usage type of the corresponding data; as well as The type of the corresponding data.

43. The electronic device of claim 42, wherein, The usage types of the relevant data include one or more of the following: advertising, billing, service optimization, and media.

44. The electronic device of claim 42, wherein, The types of the corresponding data include one or more of the following: health data, location data, and financial transaction data.

45. An electronic device (100, 1410, 1500, 1600, 1791, 1792, 1830) comprising one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the electronic device to perform the method as claimed in any one of claims 11-16.

46. ​​A computer program product comprising program code to be executed by one or more processors of an electronic device (100, 1410, 1500, 1600, 1791, 1792, 1830), wherein execution of the program code causes the electronic device to perform operations, the operations including: Presenting (1202) one or more options for configuring one or more data retention time limits for one or more categories of data, wherein the one or more categories of data are associated with one or more data transactions involving user profiles associated with the electronic device; Each of the one or more data retention time limits controls the length of time for which the remote user data collection system is permitted to retain certain data of the one or more categories of data, which is associated with the corresponding data retention time limit of the one or more data retention time limits. Receive (1204) user input associated with one or more of the options, the user input specifying a first data retention time limit for data of a first category; This causes (1206) the first data retention time limit to be associated with the user profile associated with the electronic device; and When the first data retention time limit is associated with the user profile, one or more datasets of data classified as the first category are transmitted (1208) for storage at the remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data classified as the first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier. The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The corresponding unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

47. A computer program product comprising program code to be executed by one or more processors of an electronic device (100, 1410, 1500, 1600, 1791, 1792, 1830), wherein execution of the program code causes the electronic device to perform the method as described in any one of claims 11-16.

48. A non-transitory computer-readable medium comprising instructions executable by one or more processors of an electronic device (100, 1410, 1500, 1600, 1791, 1792, 1830), the instructions including instructions for performing the following operations: Presentation (1202) provides one or more options for configuring one or more data retention time limits for one or more categories of data, wherein, The data categories are associated with one or more data transactions, which relate to user profiles associated with the electronic device; Each of the one or more data retention time limits controls the length of time for which the remote user data collection system is permitted to retain certain data of the one or more categories of data, which is associated with the corresponding data retention time limit of the one or more data retention time limits. Receive (1204) user input associated with one or more of the options, the user input specifying a first data retention time limit for data of a first category; This causes (1206) the first data retention time limit to be associated with the user profile associated with the electronic device; and When the first data retention time limit is associated with the user profile, one or more datasets of data classified as the first category are transmitted (1208) for storage at the remote user data collection system for no longer than the first data retention time limit, wherein the one or more datasets of data classified as the first category are associated with one or more data transactions, each data transaction being identified by a corresponding unique identifier. The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The corresponding unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

49. A non-transitory computer-readable medium comprising instructions executable by one or more processors of an electronic device (100, 1410, 1500, 1600, 1791, 1792, 1830), the instructions including instructions for performing the method as claimed in any one of claims 11-16.

50. A network node (716, 722, 1460, 1600, 1730, 1740, 1810, 1820) includes one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the network node to perform the following operations: Receive (1302) the first data of the first data transaction associated with the user profile, wherein, The first data includes: The unique identifier relates to the first unique identifier of the first data transaction of the device associated with the user profile; Identifiers of external requesting entities other than the user profile that are granted access to the first data; An indication of a first time limit for retaining the first data of the first transaction; and First-person data provided by a device associated with the user profile; Store (1304) the first data for access by the external requesting entity; Provide (1306) the first unique identifier and the first personal data to the external requesting entity other than the user profile; and Once the first time limit for retaining the first data of the first transaction expires, at least a portion of the first data including the first unique identifier is deleted (1308). The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The first unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

51. The network node as described in claim 50, wherein, The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: Receive second data of a second data transaction associated with the user profile, wherein the second data includes: The unique identifier relates to a second unique identifier for the second data transaction of the device associated with the user profile; The identifier of the external requesting entity other than the user profile that is granted access to the second data; An indication of a second time limit for retaining the second data of the second transaction; and Second-person data provided by the device associated with the user profile. Wherein, the first personal data is a first type of data, while the second personal data is a second type of data that is different from the first type of data; Wherein, the first type of data is subject to the first time limit for retention, and the second type of data is subject to the second time limit for retention, and Wherein, the second time limit is different from the first time limit; Store the second data for access by the external requesting entity; Provide the second unique identifier and the second personal data to the external requesting entity other than the user profile; and Once the second time limit for retaining the second data for the second transaction expires, at least a portion of the second data, including the second unique identifier, is deleted.

52. The network node as described in claim 50 or 51, wherein, The external request entity is a first external request entity, and wherein the memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: Receive third data of a third data transaction associated with the user profile, wherein the third data includes: The unique identifier relates to the third unique identifier of the third data transaction of the device associated with the user profile; The identifier of a second external request entity other than the user profile that is granted access to at least a portion of the third data, wherein the first external request entity is different from the second external request entity; An indication of a third time limit for retaining the third data of the third transaction; Wherein, the data access permission of the first external requesting entity is subject to the first time limit for retention, while the data access permission of the second external requesting entity is subject to the third time limit for retention, and Wherein, the third time limit is different from the first time limit; and Third-person data provided by a device associated with the user profile; The third data is stored for access by the second external requesting entity; Provide the third unique identifier and the third person data to the second external requesting entity other than the user profile; and Once the third time limit for retaining the third data for the third transaction expires, at least a portion of the third data containing the third unique identifier is deleted.

53. The network node as described in claim 50 or 51, wherein, The memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: Before the first time limit expires, a request for access to data from the first data, which includes at least the first unique identifier and the first personal data, is received from the external requesting entity, wherein, in response to receiving the request, the first unique identifier and the first personal data are provided.

54. The network node as described in claim 53, wherein, The first data includes permitted usage code, wherein the request includes requested usage code, and wherein the memory further includes instructions executable by the one or more processors to cause the network node to perform the following operations: Before providing the first unique identifier and the first personal data to the external requesting entity, it is determined that the permitted use code matches the requested use code.

55. The network node as described in claim 50 or 51, wherein, Deleting at least a portion of the first data includes deleting the first personal data.

56. The network node as described in claim 50 or 51, wherein, The first unique identifier maintains the anonymity of the device and the user profile for the external requesting entity.

57. A network node (716, 722, 1460, 1600, 1730, 1740, 1810, 1820) includes one or more processors and a memory, the memory including instructions executable by the one or more processors to cause the network node to perform the method of any one of claims 17-23.

58. A computer program product comprising program code to be executed by one or more processors of a network node (716, 722, 1460, 1600, 1730, 1740, 1810, 1820), wherein execution of the program code causes the network node to perform operations, the operations including: Receive (1302) first data of a first data transaction associated with a user profile, wherein the first data includes: The unique identifier relates to the first unique identifier of the first data transaction of the device associated with the user profile; Identifiers of external requesting entities other than the user profile that are granted access to the first data; An indication of a first time limit for retaining the first data of the first transaction; and First-person data provided by a device associated with the user profile; Store (1304) the first data for access by the external requesting entity; Provide (1306) the first unique identifier and the first personal data to the external requesting entity other than the user profile; and Once the first time limit for retaining the first data of the first transaction expires, at least a portion of the first data including the first unique identifier is deleted (1308). The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The first unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

59. A computer program product comprising program code to be executed by one or more processors of a network node (716, 722, 1460, 1600, 1730, 1740, 1810, 1820), wherein execution of the program code causes the network node to perform the method as described in any one of claims 17-23.

60. A non-transitory computer-readable medium comprising instructions executable by one or more processors of a network node (716, 722, 1460, 1600, 1730, 1740, 1810, 1820), the instructions including instructions for performing the following operations: Receive (1302) the first data of the first data transaction associated with the user profile, wherein, The first data includes: The unique identifier relates to the first unique identifier of the first data transaction of the device associated with the user profile; Identifiers of external requesting entities other than the user profile that are granted access to the first data; An indication of a first time limit for retaining the first data of the first transaction; and First-person data provided by a device associated with the user profile; Store (1304) the first data for access by the external requesting entity; Provide (1306) the first unique identifier and the first personal data to the external requesting entity other than the user profile; and Once the first time limit for retaining the first data of the first transaction expires, at least a portion of the first data including the first unique identifier is deleted (1308). The first data is considered as data belonging to one or more categories. Wherein, when the first data is counted as data from more than one of the one or more categories of data, the first data is subject to the minimum data retention time limit of the corresponding category of the more than one category of data, and The first unique identifier includes one or more of the following: A usage code that identifies at least one permitted use of the second data; and An entity identifier that identifies at least one entity that is permitted to access the second data.

61. A non-transitory computer-readable medium comprising instructions executable by one or more processors of a network node (716, 722, 1460, 1600, 1730, 1740, 1810, 1820), the instructions including instructions for performing the method as described in any one of claims 17-23.

Citation Information

Patent Citations

  • Differentially private processing and database storage

    US10192069B2

  • System and method for privacy management of infinite data streams

    US10366249B2

  • Differentially private density plots

    US10489605B2

  • Efficient implementation for differential privacy using cryptographic functions

    US20170357820A1

  • Differential privacy using a count mean sketch

    US20180349636A1