System for managing tracking of user browsing website
The tracking permission management device centrally manages user tracking permissions across sites using unique tokens, addressing compliance and convenience issues by allowing site-specific settings without altering web servers.
Patent Information
- Application Number
- JP2024006177
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-18
- Publication Date
- 2025-07-31
- Estimated Expiration
- 2044-01-18
AI Technical Summary
Existing systems face challenges in managing user tracking permissions across multiple websites, leading to inconvenience and compliance issues due to the need for repeated login and token management, which complicates the handling of personal information.
A tracking permission management device that centrally manages tracking permissions for multiple sites by associating setting information with a unique token on the client terminal, allowing it to determine and communicate permission settings with web servers based on registered information.
Enables centralized management of tracking permissions across multiple sites, reducing user inconvenience and compliance burdens by allowing site-specific tracking settings and ensuring compliance with regulations without requiring changes to web servers.
Smart Images

Figure 2025112091000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a system for managing the tracking of users who browse websites.
Background Art
[0002] In recent years, the Internet has rapidly spread, and it has become possible to access various sites via the Internet. Among such sites, there are sites that require user registration in advance. However, since it is cumbersome to perform a login operation every time of access, for sites that have been logged in once, login information is stored on the user terminal side as a token unique to the user, such as a Cookie, so that it is not necessary to input the password or ID again (see Patent Document 1). Since such a token also corresponds to personal information, there are many examples in which regulations and restrictions have been formulated and implemented by various countries and organizations regarding the management of personal information.
[0003] In such an environment, when a service provider handles personal information, each website is required to install a modal or the like regarding the availability of tracking using a token for the scope of use and purpose of use. In addition to the end user being inconvenienced by being asked for permission regarding the availability of tracking using a token every time they visit a website, there is also a concern that it hinders sound business activities within the scope of compliance.
[0004] In addition, when tracking, collecting, using, and managing information regarding a user's access to a website, a mechanism is required to set at what level the user allows tracking and collect the tracked information within the allowed range.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
SUMMARY OF THE INVENTION
PROBLEMS TO BE SOLVED BY THE INVENTION
[0006] Therefore, an object of the present application is to provide a mechanism for registering information related to tracking permissions and centrally managing tracking permissions for multiple sites based on the registered information.
MEANS FOR SOLVING THE PROBLEMS
[0007] One form for solving the above problems is a tracking permission management device, an acquisition means for acquiring setting information regarding whether to permit tracking of the behavior of a web site accessed by the client terminal from the client terminal; a holding means for holding the acquired setting information as registration information in association with a first token for uniquely identifying the client terminal; a transmission means for transmitting the registration information to the client terminal together with the first token; comprising the registration information includes information specifying a format for permitting the tracking for each web site.
[0008] Another form for solving the above problems is a client terminal, means for receiving, from a tracking permission management device that manages permission settings for tracking the behavior of a web site accessed by the client terminal, registration information regarding the permission settings for tracking of the client terminal, the registration information including a first token for the tracking permission management device to uniquely identify the client terminal; means for receiving information of the web site from a web server that provides the web site together with a second token different from the first token; Determination means for determining whether to permit the web server to track the behavior of the client terminal on the website based on the received registration information; Means for transmitting a response to the received website information to the web server according to the determination result in the determination means; Comprising: When the determination means determines not to permit the tracking by the web server, the transmitting means transmits the response to the web server without including the second token.
Advantages of the Invention
[0009] According to the present invention, it is possible to provide a mechanism for registering information regarding tracking permission and centrally managing the tracking permissions of a plurality of sites based on the registered information.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5A
Figure 5B
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
MODE FOR CARRYING OUT THE INVENTION
[0011] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims, and not all combinations of the features described in the embodiments are essential for the invention. Two or more of the plurality of features described in the embodiments may be arbitrarily combined. Also, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.
[0012] [Embodiment 1] One embodiment will be described below with reference to the accompanying drawings. However, the components described in this embodiment are merely examples, and are not intended to limit the scope of the present invention thereto.
[0013] <System Configuration> FIG. 1 is a block diagram showing the overall configuration of the system corresponding to this embodiment. This system is configured by interconnecting a client terminal 101, a web server 103, and a cookie consent management device 104 via the Internet 102.
[0014] The client terminal 101 accesses the web server 103 via the Internet 102, acquires page information (web page) of the website provided by the web server 103, and can view it with a browser or the like. The client terminal 101 is an information processing device, including a notebook computer, a desktop computer, a portable information terminal, a mobile phone, a smartphone, a tablet terminal, and the like. It is assumed that so-called Internet browser software is installed in the client terminal 101.
[0015] In addition, the client terminal 101 can register information regarding the permission setting of tracking with the tracking permission management device 104 and store it as registered information in the registered information database 104A. Also, the registered information stored in the tracking permission management device 104 is provided from the tracking permission management device 104 to the client terminal 101 together with a token (first token) associated with the registered information. The first token can be generated as a unique and random character string (for example, "550e8400-e29b-41d4-a716-4466"). Further, the client terminal 101 holds a token (second token) provided from the web server 103 via the browser. The client terminal 101 can determine whether to discard or hold the second token provided from the website based on the content of the registered information.
[0016] The client terminal 101 is connected to the Internet 102 via a LAN which is an access means including a network cable such as Ethernet (registered trademark). Note that the access means to the network 102 is not limited to an Ethernet (registered trademark) cable and may be constituted by a wireless communication means such as a wireless LAN conforming to a protocol such as IEEE802.11. It is assumed that the tracking permission management device 104 described later also has a similar communication means.
[0017] The Internet 102 is a network in which networks around the world are connected to each other. However, for example, it may be a network that can be connected only within a specific organization like an intranet.
[0018] The web server 103 provides contents such as web pages stored in a predetermined site information database 103A in response to an access from the client terminal 101, and provides a second token (for example, a Cookie) to manage the access status of the client terminal 101. The second token includes ID information for identifying the user of the client terminal 101. For the second token itself, a known technique such as a Cookie may be used, and thus a more detailed description in this specification is omitted. However, the example of the second token is not limited to a Cookie, and any unique information for the user that can be used by the web server 103 to track the behavior of the client terminal 101 on the web site may be used.
[0019] The site information database 103A manages information on document files for publishing a web site on the Internet 102. The document files include HTML files, PDF files, and other files used in specific applications (for example, MS Word, etc.). The site information database 103A is updated at any time and stores the latest information. A web site refers to a group of web pages published as a whole. Examples of web sites include home pages of corporations and individuals.
[0020] The tracking permission management device 104 is a server that stores and manages registration information regarding tracking permissions for each client terminal 101. In response to an access from the client terminal 101, the tracking permission management device 104 accepts tracking permission settings for individual terminals or for each user, stores and manages them as registration information in the registration information database 104A, and issues a first token for uniquely identifying the client terminal 101 associated with the registration information to the client terminal 101. The information of the first token is stored in the registration information database 104A in association with the registration information. The registration information managed by the tracking permission management device 104 is also provided to the client terminal 101 in association with the first token, and is used for determining the holding / discard of a second token provided from the web server 103 at the client terminal 101.
[0021] In the present specification, for the sake of convenience, the web server 103 and the tracking permission management device 104 are described as being realized by physically independent information processing devices, respectively, but the embodiments of the present invention are not limited thereto. For example, these may be realized by a single information processing device. On the other hand, each of the devices such as the web server 103 and the tracking permission management device 104 may be redundantly configured or distributed by a plurality of information processing devices. Hereinafter, the details of the processing executed in this system will be described.
[0022] <Configuration of Information Processing Device> Next, an overview of each information processing device constituting the system corresponding to this embodiment will be described. FIG. 2 is a block diagram showing an example of the hardware configuration of the client terminal 101.
[0023] In FIG. 2, the CPU 200 executes application programs, an operating system (OS), control programs, etc. stored in a hard disk drive (hereinafter referred to as HD) 204, and performs control to temporarily store information, files, etc. necessary for program execution in the RAM 202. Note that the processing described later is also realized by the CPU 200 executing a corresponding processing program to control the entire apparatus.
[0024] The ROM 201 stores programs such as a basic I / O program, and various data such as font data and template data used during document processing. The RAM 202 temporarily stores various data and functions as the main memory and work area of the CPU 200. The interface (hereinafter referred to as I / F) 203 serves as a communication means for mediating data exchange with an external device.
[0025] In this embodiment, the external storage device 204 uses an HD (hard disk) that functions as a large-capacity memory. The HD 204 stores application programs, an OS, control programs, related programs, etc. Note that instead of the hard disk, a non-volatile storage device such as a flash (registered trademark) memory may be used.
[0026] The instruction input device 205 corresponds to a keyboard, a pointing device (such as a mouse), a touch panel, etc. Using the instruction input device 205, a user can input and instruct commands for controlling the client terminal 101. The display 206 displays commands input from the instruction input device 205, response outputs of the information processing apparatus thereto, etc. The system bus 207 controls the flow of data within the information processing apparatus.
[0027] Note that it can also be configured as a substitute for the hardware device by software that realizes functions equivalent to those of the above-described respective devices.
[0028] Each time the corresponding program is run to execute the processing corresponding to this embodiment, it may be loaded from the HD204 where the program is already installed into the RAM202. Further, the program according to this embodiment may be recorded in the ROM201, configured to form part of the memory map, and directly executed by the CPU200.
[0029] FIG. 3 is a block diagram showing the device configurations of the web server 103 and the tracking permission management device 104. The functions and uses of the CPU200, ROM201, RAM202, interface 203, HD204, instruction input device 205, display 206, and system bus 207, and furthermore, their relationships are the same as or equivalent to those described with reference to FIG. 2. Note that in FIG. 3, a database 301 is connected to the system bus 207. Here, the database 301 functions as a site information database 103A that manages content information such as web pages in the web server 103. Also, in the tracking permission management device 104, it functions as a registration information database 104A that manages by associating the first token of each client terminal 101 with the registration information.
[0030] Next, with reference to FIG. 4, an example of the functional configuration of each of the client terminal 101, web server 103, and tracking permission management device 104 that make up the system corresponding to this embodiment will be described. FIG. 4 is a diagram showing an example of the functional configuration of each device.
[0031] In FIG. 4, the client terminal 101 is configured to have at least a communication unit 401, a display unit 402, an input reception unit 403, a permission determination unit 404, and a storage unit 405 as its functional configuration. The web server 103 is configured to have at least a communication unit 411 and a second token issuance unit 412. The tracking permission management device 104 is configured to have at least a communication unit 421, an information registration unit 422, a first token issuance unit 423, and a permission information generation unit 424. Each functional block is realized by executing a predetermined program, application, or software in the hardware configuration shown in FIG. 2 or FIG. 3. The roles and functions played by each functional block will be described later with reference to FIGS. 5A and 5B. FIG. 5B describes the processing after S512 in FIG. 5A.
[0032] <Tracking Permission Management Process> Next, the tracking permission management process corresponding to the embodiment of the invention will be described with reference to the sequence diagrams of FIGS. 5A and 5B. FIGS. 5A and 5B show the flow of processing executed among the client terminal 101, the web server 103, and the tracking permission management device 104 corresponding to the embodiment of the invention. The processing corresponding to FIGS. 5A and 5B is realized by the CPU 200 executing the processing programs held in the HD204 or the database 301 by each device to perform the processing, or by controlling the operations of each hardware configuration to function as the corresponding functional block.
[0033] In FIG. 5A, in step S501, the communication unit 401 of the client terminal 101 transmits a registration request of the client terminal 101 (or its user, the same hereinafter) to the tracking permission management device 104. When the communication unit 421 of the tracking permission management device 104 receives the request, in S502, the first token issuance unit 423 issues a first token. Here, the first token does not need to be generated by referring to specific information and may be composed of a unique and random character string.
[0034] In subsequent S503, the communication unit 421 transmits the first token issued together with the screen information for registering information to the client terminal 101. The first token is used as identification information for identifying the user of the client terminal 101 that made the registration request.
[0035] In subsequent S504, on the client terminal 101, the display unit 402 displays the screen information received from the tracking permission management device 104 on the display 206, and accepts input of setting information regarding tracking permission from the user of the client terminal 101 via the input reception unit 403. An example of the screen displayed here will be described later with reference to FIG. 7.
[0036] In subsequent S505, the communication unit 401 of the client terminal 101 transmits the registration information input in S504 to the tracking permission management device 104 together with the first token transmitted in S503. When the communication unit 421 of the tracking permission management device 104 receives the registration information, in S506, the information registration unit 422 stores the registration information in the registration information database 104A in association with the first token. In subsequent S507, the communication unit 421 of the tracking permission management device 104 transmits the registration information registered in the tracking permission management device 104 to the client terminal 101. In subsequent S508, the client terminal 101 stores the received registration information in the storage unit 405 in association with the first token.
[0037] In subsequent S509, the communication unit 401 of the client terminal 101 transmits an access request to the website provided by the web server 103 to the web server 103. When the communication unit 411 of the web server 103 receives the access request, in S510, the second token issuing unit 412 of the web server 103 issues a second token in response to the access request. The second token is information generated by the web server 103, which can be a Cookie as described above, but is not limited to this, as long as it is unique information for tracking used on the web server 103 side. The second token is not referred to or used on the tracking permission management device 104 side.
[0038] In subsequent S511, the communication unit 411 of the web server 103 transmits the web information (content file such as an HTML file) of the requested website to the client terminal 101 together with the second token. The web information includes the second token.
[0039] Next, in S512, the permission determination unit 404 of the client terminal 101 determines the permission status regarding the website provided by the web server 103 from which the web information is received based on the registration information held in the storage unit 405 of the client terminal 101, and depending on the determination result, shifts to any one of the following Option 1 to Option 3 of the processes shown in FIG. 5B. Details of the process of S512 will be described later with reference to FIG. 6.
[0040] <Option 1> In FIG. 5B, first, in Option 1, since tracking is not permitted for the website, in S513, the client terminal 101 accepts a tracking permission setting. Specifically, a screen 800 as shown in FIG. 8 to be described later is displayed, and a setting for whether to permit tracking for the website is accepted. In subsequent S514, the communication unit 401 transmits the accepted setting information as registration information together with the first token to the tracking permission management device 104.
[0041] On the side of the tracking permission management device 104, when the communication unit 421 receives the registration information from the client terminal 101, the information registration unit 422 updates the content of the registration information in the registration information database 104A associated with the first token. In subsequent S516, the communication unit 421 of the tracking permission management device 104 transmits the updated registration information associated with the first token to the client terminal 101.
[0042] On the side of the client terminal 101, based on the registration information received from the tracking permission management device 104, the content of the registration information registered in the storage unit 405 is updated. Then, the permission determination unit 404 re-determines the permission state regarding the above website based on the content of the registration information, and migrates to Option 2 or Option 3 according to the result of the determination. If tracking is permitted for the website in the registration information, it migrates to Option 2. On the other hand, if tracking is rejected for the website in the registration information, it migrates to Option 3.
[0043] <Option 2> In Option 2 of FIG. 5B, tracking is permitted for the website. In S518, the client terminal 101 receives, via the input reception unit 403, an operation from the user of the client terminal 101 for the web information transmitted in S511. When the operation is received, in S519, a request corresponding to the operation is transmitted to the web server 103 via the communication unit 401. At this time, the second token is transmitted to the web server 103. On the side of the web server 103, in S520, new web information corresponding to the request is transmitted. On the side of the web server 103, based on the received second token and the received request, the client terminal 101 can track the behavior on the website.
[0044] <Option 3> In Option 3 of FIG. 5B, tracking is rejected for the website. Therefore, the website cannot track the behavior of the client terminal 101 with respect to the website. The client terminal 101 discards the second token transmitted in S511 in S521, and in S522, accepts an operation from the user of the client terminal 101 with respect to the web information via the input reception unit 403. When an operation is accepted, a request corresponding to the operation is transmitted to the web server 103 via the communication unit 401 in S523. At this time, the second token is not included in the transmission information. On the web server 103 side, new web information corresponding to the request is transmitted in S524. On the web server 103 side, since the previously transmitted second token has not been returned, a new second token is included in the web information and transmitted. However, since the rejection setting is made for the website, the new second token is also discarded in the process of S521. Therefore, the user's behavior is not tracked by the web server 103. Note that the web server 103 will continue to issue new second tokens, but this itself is an operation according to the original specification of the web server 103, which is irrelevant to the introduction of the mechanism of this embodiment, so there is no problem. Also, the mechanism of this embodiment can be introduced without changing the specification.
[0045] Next, with reference to FIG. 7, the configuration of the display screen for inputting information regarding the permission setting of tracking in the client terminal 101 corresponding to this embodiment will be described. FIG. 7 is a diagram showing a configuration example of the tracking permission setting screen displayed in S504 of FIG. 5A.
[0046] In FIG. 7, the screen 700 shows the tracking permission setting screen. On the screen 700, setting items 710 to 730 are displayed, and for each, the user can select or input the setting content.
[0047] The setting item 710 is a setting for whether to permit tracking, and it is possible to set whether to permit all tracking, permit a part of it, or reject all of it. When permitting all, it is regarded as being permitted for all web servers 103 that provide the website that the user attempts to access.
[0048] When permitting a part, tracking is permitted for some web servers 103, and the permitted targets can be set in the setting item 720. In this case, the client terminal 101 only holds the "second token" issued from the websites set as the permitted targets. When rejecting all, the client terminal 101 discards all tokens after the "second token" issued from the website.
[0049] In the setting item 720, when "permit a part" is selected in the setting item 710, information (such as URL, etc.) for specifying the websites to be permitted is input. The user can input the URL of the website to be permitted in the input area 721. Also, by selecting the link 722 described as "refer to bookmarks", the URL of the site registered in the bookmarks can be selected and acquired. In addition, by referring to the browser history, the URL of the site browsed in the browser in the past can be acquired. In addition, the URL of the website can be input by any method.
[0050] Next, in the setting item 730, the handling of websites other than the sites specified as the sites to be permitted in the input area 721 can be set. When "reject" is selected, the second token is discarded for websites other than the sites specified as the sites to be permitted in the input area 721. On the other hand, when "get permission confirmation" is selected, the screen of FIG. 8 is displayed in the process of S512 in FIG. 5A, and a setting for whether to permit or reject tracking for the site is accepted.
[0051] FIG. 8 is a diagram showing a configuration example of a tracking permission setting screen displayed in the process of S512 in FIG. 5A. On the screen of FIG. 8, if tracking is permitted, the client terminal 101 holds a "second token" issued from the web server 103 set as the permission target. On the other hand, if tracking is rejected, the second token of the website is discarded. The input result in FIG. 8 is transmitted to the tracking permission management device 104, and the registration information stored in association with the first token of the client terminal 101 in the registration information database 104A is updated.
[0052] Here, the configuration of the tracking permission setting screen 800 shown in FIG. 8 will be described. Here, since the site itself for which tracking permission is to be set is specified, the screen 800 is configured as a screen for receiving a setting as to whether to permit tracking for the site.
[0053] In the setting item 801, it is possible to select either "permit" 803 or "reject" 804 as to whether to permit tracking of the website shown in the site information 802. When the registration button 805 is selected in a state where either one is selected, the content is transmitted to the tracking permission management device 104 as registration information.
[0054] Here, with reference to FIG. 6, an example of the permission state determination process in S512 of FIG. 5A will be described. First, the permission determination unit 404 of the client terminal 101 determines in S601 whether the registration information of the user of the client terminal 101 stored in the storage unit 405 is set to permit all. If it is determined that it is set to permit all, the process proceeds to the process of option 2. If it is not set to permit all, the process proceeds to S602. In the subsequent S602, it is determined whether the registration information is set to reject all. If it is determined that it is set to reject all, the process proceeds to the process of option 3. If it is not set to reject all, the process proceeds to S603.
[0055] In subsequent S603, it is determined whether the website to be determined in the registration information is registered as a permitted site. If it is registered, it is determined that the process proceeds to the process of Option 2. If it is not registered, the process proceeds to S604.
[0056] In subsequent S604, it is determined whether the website to be determined in the registration information is registered as a rejected site. If it is registered, it is determined that the process proceeds to the process of Option 3. If it is not registered, the process proceeds to S605.
[0057] In S605, the permission determination unit 404 determines whether the permission confirmation setting is enabled in the registration information. If the permission confirmation setting is not enabled, that is, if it is set to reject for sites other than the registered sites, it is determined that the process proceeds to the process of Option 3. On the other hand, in S605, if the permission confirmation setting is enabled, it is determined that the process proceeds to the process of Option 1. Thereafter, the processes of Options 1 to 3 described in FIG. 5A are executed.
[0058] FIG. 9 is a diagram showing an example of the data configuration of the registration information of the client terminal 101 managed by the tracking permission management device 104 in the registration information database 104A. In addition, in the storage unit 405 of the client terminal 101, information having the same content as the registration information associated with the first token assigned to the client terminal 101 is stored in association with the first token. When a plurality of users use the client terminal 101 and the first token is assigned to each user, the registration information is stored in the storage unit 405 in association with the first token for each user.
[0059] The registration information 900 has information regarding permission settings registered for each first token issued to the client terminal 101. The first token 910 has the first token issued from the tracking permission management device 104 to the client terminal 101 registered. In the tracking permission management device 104, the client terminal 101 is identified based on the first token. Also, when one or more users use the client terminal 101, the first token may be issued on a per-user basis. In that case, the first token for each user is registered.
[0060] The permission format 920 registers information specifying the permission format set in the setting item 710 on the registration screen 700 of FIG. 7. In the permission format 920, any one of the three formats of "fully permitted", "partially permitted", and "fully rejected" is registered.
[0061] The permitted site information 930 registers the site information specified in the setting item 720 of FIG. 7 when the permission format 920 is "partially permitted". For example, for token 3 and token 4 of the first token 910, the URLs of a plurality of sites are registered. When information such as web page information is sent from these sites to the client terminal 101 in S511 of FIG. 5A, the permission determination unit 404 refers to the permitted site information 930 in S603 of FIG. 6 to confirm whether the web site is registered as a permitted site.
[0062] The rejected site information 940 registers information on sites where tracking permission has been rejected. Specifically, when "request permission confirmation" is selected in the setting item 730 of the screen 700 of FIG. 7 and "reject" 804 is selected in the screen 800 of FIG. 8, the information on the site is registered. The permission determination unit 404 refers to the registration information of the rejected site information 940 so that permission confirmation is no longer performed for sites where the user has once rejected tracking permission. The permission determination unit 404 checks the content of the rejected site information 940 when determining whether it is a rejected site in S604 of FIG. 6.
[0063] The permission confirmation 950 registers information on whether permission confirmation is required. In this embodiment, the permission confirmation refers to asking the client terminal 101 whether to permit tracking for sites other than the site specified by the permission site information 930. In the setting item 730 of FIG. 7, when "Get permission confirmation" is selected, "Required" is registered in the permission confirmation 950, and when "Reject" is selected, "Not required" is registered. The information of the permission confirmation 950 can be referred to when the permission determination unit 404 determines whether it is the permission confirmation setting of S605 in FIG. 6. When the permission confirmation 950 is set to "Required", the permission determination unit 404 displays the screen of FIG. 8 and accepts the setting of whether to permit tracking for the site or to reject it. When the permission confirmation 950 is set to "Not required", the permission determination unit 404 does not display the screen of FIG. 8.
[0064] According to the above embodiment, the setting regarding the permission of tracking can be managed only between the client terminal 101 and the tracking permission management device 104, and there is no need to share information with the web server 103. Therefore, it is possible to introduce a mechanism for managing the permission of tracking without requiring a design change to the web server 103.
[0065] Also, according to this embodiment, the registration information regarding the tracking permission management is held in the tracking permission management device 104, and the client terminal 101 holds it, and when accessing the website, the client terminal 101 itself can determine whether to permit tracking based on the registration information. In the registration information, in addition to uniformly rejecting or permitting tracking, it is also possible to set to confirm the availability of tracking permission each time. Therefore, a mechanism for centrally managing the tracking permissions of multiple sites can be provided.
[0066] In addition, since the registration information is synchronized between the client terminal 101 and the tracking permission management device 104, even when a client terminal 101 is added for the same user or when the terminal device is changed, the previous setting contents can be carried over.
[0067] <Summary of Embodiment 1> The above-described Embodiment 1 discloses at least the following tracking permission management device, client terminal, and computer program. (Item 1) A tracking permission management device, an acquisition means for acquiring, from a client terminal, setting information regarding whether to permit tracking of the behavior of the client terminal on a website accessed by the client terminal; a holding means for holding the acquired setting information as registration information in association with a first token for uniquely identifying the client terminal; a transmission means for transmitting the registration information to the client terminal together with the first token; comprising a tracking permission management device, wherein the registration information includes information specifying a format for permitting the tracking for each website. (Item 2) The information for specifying a format for permitting the tracking for each website is information for specifying a permission format for permitting tracking for all websites, information for specifying a permission format for denying tracking for all websites, or information for specifying a permission format for permitting tracking for a specified website The tracking permission management device according to Item 1, including any one of the above. (Item 3) The registration information further includes information on the specified website. The tracking permission management device according to Item 2. (Item 4) The tracking permission management device according to item 3, wherein the registration information further includes information regarding whether it is necessary to confirm whether to permit tracking for other websites other than the designated website. (Item 5) When the information regarding whether confirmation is necessary indicates that confirmation is necessary, The tracking permission management device according to item 4, wherein the registration information further includes information on websites for which tracking has been rejected in the confirmation of whether to permit tracking for the other websites. (Item 6) When a registration request is received from the client terminal, it further comprises means for issuing the first token, The transmission means transmits screen information for inputting the setting information to the client terminal together with the first token, The acquisition means acquires the setting information from the client terminal together with the first token. The tracking permission management device according to any one of items 1 to 5. (Item 7) A client terminal, Means for receiving, from a tracking permission management device that manages the permission setting for tracking the behavior of the website accessed by the client terminal, registration information regarding the tracking permission setting of the client terminal, the registration information including a first token for the tracking permission management device to uniquely identify the client terminal; Means for receiving information of the website from a web server that provides the website together with a second token different from the first token; Judgment means for judging whether to permit the web server to track the behavior of the client terminal on the website based on the received registration information; Means for transmitting a response to the received website information to the web server according to the judgment result in the judgment means; Comprising When the determination means determines not to permit the tracking by the web server, the transmitting means transmits the response to the web server without including the second token, a client terminal. (Item 8) The client terminal according to item 7, further comprising means for discarding the second token in response to the determination means determining not to permit the tracking of the client terminal by the web server. (Item 9) The client terminal according to item 7 or 8, wherein when the determination means determines to permit the tracking of the client terminal by the web server, the transmitting means transmits the response to the web server including the second token. (Item 10) When the content of the determination result by the determination means is to confirm at the client terminal whether the web server is permitted to track the behavior of the client terminal on the website, the client terminal further comprises means for receiving a setting of whether to permit tracking for the website, when the receiving means receives a setting for rejecting tracking for the website, the transmitting means transmits the response without including the second token, the client terminal according to any one of items 7 to 9, wherein when the receiving means receives a setting for permitting tracking for the website, the transmitting means transmits the response including the second token. (Item 11) The client terminal according to item 10, further comprising means for transmitting to the tracking permission management device a setting of whether to permit tracking for the website received by the receiving means. (Item 12) A computer program for causing a computer to function as each means of the tracking permission management device according to any one of items 1 to 6. (Item 13) A computer program for causing a computer to function as each means of the client terminal described in any one of Items 7 to 11.
[0068] [Embodiment 2] The second embodiment will be described below with reference to the accompanying drawings. However, the components described in this embodiment are merely examples, and are not intended to limit the scope of the present invention thereto.
[0069] <System Configuration> FIG. 10 is a block diagram showing the overall configuration of the system corresponding to this embodiment. This system is configured by interconnecting an administrator terminal 1001, a license management device 1002, a web server 1003, and a client terminal 104 via a network 1005.
[0070] The administrator terminal 1001 is a terminal operated by an administrator who manages the web server 1003.
[0071] The license management device 1002 is a device that manages tracking conditions when tracking, collecting, using, and managing information regarding access from a user to the web content of the web server 1003. The web server 1003 is a server that is managed by the administrator terminal 1001 and manages a website. The registration information database 1002A is a database for managing information including the tracking conditions set in the administrator terminal 1001.
[0072] The web server 1003 is a server device that manages websites. In response to access from the client terminal 1004, it provides web content such as web pages that make up the website, which is stored in the site information database 1003A. The site information database 1003A manages information on web content such as document files, images, and moving images for publishing the website on the network 1005. The document files include HTML files, PDF files, and other files used in specific applications (such as MS Word, etc.). The site information database 1003A is updated at any time and stores the latest information. A website refers to a group of web pages that are published together. Examples of websites include the home pages of corporations and individuals.
[0073] The client terminals 1004A to 1004C (hereinafter collectively referred to as the client terminal 1004) are terminals operated by users who access the website to view information. The client terminal 1004 individually accesses the web server 1003 via the network 1005, obtains the page information (web page) of the website provided by the web server 1003, and can view it using a browser or the like. The client terminal 1004 can be a device equivalent to the client device 101 described in Embodiment 1.
[0074] The network 1005 can be a network in which networks around the world are connected to each other, such as the Internet. Alternatively, it can be a network that can only be connected within a specific organization, such as an intranet.
[0075] Hereinafter, for the sake of convenience, the license management device 1002 and the web server 1003 will be described as being realized by physically independent information processing devices, respectively. However, the embodiments are not limited to this. For example, they may be realized by a single information processing device. On the other hand, each of the license management device 1002 and the web server 1003 may be redundantly configured or distributed by a plurality of information processing devices.
[0076] <Configuration of Information Processing Device> Next, an overview of each device constituting the system corresponding to the present embodiment will be described. The configuration of each device can be the same as that shown with reference to FIG. 2 or FIG. 3 in Embodiment 1. Hereinafter, details of the processing executed in this system will be described.
[0077] <Management of Tracking> Next, the management of tracking corresponding to the embodiment of the invention will be described with reference to FIGS. 11 to 14. In the present embodiment, tracking or tracking processing refers to processing for collecting information on the behavior of a user on a specific website. Specifically, when the client terminal 1004 receives a web page including a link to a control program for tracking (for example, JavaScript) from the web server 1003, the client terminal 1004 acquires and executes the control program from the link to collect information on the behavior of the user. Since a terminal identification ID (an ID generated by a program or a Finger Print assigned to the terminal in advance) is assigned to the client terminal 1004, it is possible to identify each client terminal 1004. Further, the collected tracking information is transmitted to the web server that transmitted the web page. The tracking information collected in this way can be aggregated for a plurality of users and used as statistical information, or used for customizing a website corresponding to the behavior of each user.
[0078] First, FIG. 11 shows the flow of processing executed among the administrator terminal 1001, the license management device 1002, and the web server 1003 corresponding to the embodiment of the invention. The processing corresponding to FIG. 11 is realized by each device executing a processing program held in the HD 204 or the database 301 with the CPU 200 to perform processing or controlling the operations of each hardware configuration, thereby functioning as a corresponding functional block.
[0079] In FIG. 11, in step S1101, the administrator terminal 1001 transmits a registration request regarding the tracking of the website managed by the web server 1003 to the license management device 1002. The registration request includes the FQDN (Fully Qualified Domain Name) of the web page to be registered and the information of the reference URL to the privacy policy. The FQDN is represented in a description format that specifies all of the host name, domain name (sub-domain name), etc. without omission, such as www.abc.co.jp, www.efg.com. Also, the reference URL of the privacy policy is indicated by, for example, www.abc.co.jp / privacy / index.html, etc. The privacy policy is a regulation regarding the handling of personal information in the administrator terminal 1001 and the web server 1003, and is used as the link destination of the detailed information of the registration screen displayed when setting the tracking availability information in the client terminal 1004. These pieces of information are hereinafter referred to as "registration information".
[0080] When a registration request is sent in S1101, in S1102, the permission management device 1002 saves the above-mentioned registration information in the registration information database 1002A. In the subsequent S1103, the permission management device 1002 sends information (reference information) required for tracking control to the administrator terminal 1001. When the administrator terminal 1001 receives the reference information, in S1104, it enables the web server 1003 to perform tracking control based on the reference information. Here, as one of the methods for performing tracking control, a control program is provided as JavaScript such as track.js. Also, the setting is to embed a predetermined description to refer to the control program for each HTML page of the website managed by the web server 1003 so that the tracking process is executed when the page is displayed on the client terminal. Specifically, the following HTML description can be added within the header of the website page.
[0081] <script src="https: / / trackermars.com / track.js">< / script> When the setting is made in this way, in S1105, the web server 1003 saves the set web content in the site information database 1003A. Note that the reference information setting may be performed for a predetermined page including the top page of the website.
[0082] According to the above, the administrator terminal 1001 can set each web content managed by the web server 1003 so that the tracking process is executed when the page is displayed on the client terminal. After that, when it is desired to change the setting content, the processing after S1106 is executed.
[0083] In S1106, the administrator terminal 1001 sends a request for content update of the registration information to the permission management device 1002. The update request can include the FQDN of the web page for additional registration and the information of the reference URL to the privacy policy. In subsequent S1107, the permission management device 1002 saves the registration information included in the update request to the registration information database 1002A. In subsequent S1108, the permission management device 1002 sends new reference information for referring to a new control program associated with the update of the registration information to the administrator terminal 1001. At the administrator terminal 1001, when receiving the new reference information, in S1109, settings are made to the web server 1003 so that tracking control can be executed based on the new reference information.
[0084] Due to the update of the reference information, for the client terminal 1004 that registered the setting information regarding the availability of tracking in the previous reference information, the setting information becomes invalid, and it is necessary to newly register the setting information. For example, the setting information can be associated with the version information and registration date and time of the reference information. When the version or registration date and time of the reference information changes, the registered setting information can be made invalid and a re-registration of the setting information can be requested.
[0085] Next, with reference to FIG. 12, the processing flow executed among the client terminal 1004, the permission management device 1002, and the web server 1003 corresponding to the embodiment of the invention will be described. The processing corresponding to FIG. 12 is realized by each device executing the processing program held in the HD204 or the database 301 by the CPU200 to perform processing or controlling the operations of each hardware configuration, and functioning as the corresponding functional block.
[0086] First, in S1201, the client terminal 1004 sends a request for a web page (or web content) to the web server 1003. The request is made by specifying the URL of the web page that the client terminal 1004 wishes to view. In S1202, the web server 1003 sends the information of the web page with the specified URL to the client terminal 1004.
[0087] In S1203, the client terminal 1004 displays the web page based on the received URL. At this time, the control program (JavaScript) described in the header of the web page of the website is obtained from the permission management device 1002 and executed. By executing this control program, the client terminal 1004 first obtains terminal information in S1204. The terminal information includes the terminal identification ID issued by the permission management device 1002 and the setting information regarding the availability of tracking for the web server 1003. The terminal information is the information stored in the client terminal 1004 when the client terminal 1004 registers the setting information with the permission management device 1002, and the terminal identification ID is an identifier for uniquely identifying the client terminal 1004 in relation to the permission management device 1002.
[0088] The setting information is the setting information referred to in the client terminal 1004 to determine whether to permit the execution of the control program at the link destination indicated by the reference information embedded in the web page when displaying the web page received from the web server 1003 and thus determine whether to permit tracking. Therefore, the setting information includes the information of the associated website. The setting information is the information set for each website. Therefore, the content of the setting information can be made different for each website. On the other hand, the setting information may be common or identical for a plurality of websites.
[0089] In FIG. 12, the processing will be described by dividing it into Option 1 to Option 3 according to the setting status of this setting information. In Option 1, the case where there is no terminal information, that is, the setting information is not set, will be described. In this case, it is assumed that the client terminal 1004 acquires web content (herein referred to as web content A) from the web server 1003 for the first time. The client terminal 1004 displays a registration screen on the terminal and accepts the input of registration information.
[0090] An example of the display screen is shown in FIG. 14. In FIG. 14, screen 1400 shows an example of a registration screen. The registration screen includes the uses of tracking information and notifications about situations that may occur if the user does not consent to the registration screen in order to accept permission to use tracking information.
[0091] Also, for the uses of tracking information, five items are displayed as item 1401, and the purposes for which the tracking information is used are described respectively. The purposes include "Essential" which is essential for the operation of the website, "User Setting Information" for saving user-specific settings, "Statistics" for improving the quality of the website, "Marketing" for providing the most suitable content for the user, and "Unclassified" which does not fall under any of the above.
[0092] Specifically, "Essential" enables important functions such as page navigation and access to secure areas of the website, making the website usable. Since the website will not operate properly if "Essential" is not selected, it is basically recommended to select it. "User Setting Information" is used to hold information related to the operation and appearance of the website, such as the user's preferred language and the region of the access source. "Statistics" anonymously collects and reports the actions taken by users on the website and is used to improve the quality of the website. "Marketing" is used to track users across the website and enhance the advertising value for publishers and third-party advertisers by displaying relevant and interesting ads to users. "Unclassified" refers to classifications that do not fall under the above.
[0093] Among them, the user of the client terminal 1004 can check the items permitted for the purpose of using the tracking information in the check box 1402, click the consent button 1404, or click the disagreement button 1403 if the use of the tracking information is not permitted. If the disagreement button 1403 is clicked, or if none of the items are checked and the consent button 1404 is clicked, the control of the information included in the web content is not executed. However, there is no guarantee that the website will operate properly unless "required" is selected as described above.
[0094] On the other hand, if any item is checked and the consent button 1404 is clicked, the control program included in the web content for the corresponding item is executed on the client terminal 1004. The tracking information collected by the execution of the control program is transmitted to the web server 1003. The transmission of the tracking information corresponding to the unchecked item is not performed, or the tracking process itself corresponding to the item is not performed.
[0095] The detailed information 1405 is associated with link information to the reference URL of the privacy policy transmitted in the registration request of S1101. When the user clicks the detailed information 1405, a page showing the regulations regarding the handling of personal information in this service is displayed.
[0096] Returning to the description of FIG. 12, in S1204, if it is determined that the setting information is not set, in S1205, a registration screen as shown in FIG. 14 is displayed to accept the registration of the setting information, and in the subsequent S1206, the registration request is transmitted to the permission management device 1002. The registration request includes the content of the setting information input in S1205 and a request for generating a new terminal identification ID.
[0097] The license management device 1002 processes the registration request in S1207. Specifically, if a request to create a new terminal identification ID is included, a terminal identification ID is generated to uniquely identify the client terminal 1004 in the license management device 1002. The license management device 1002 also registers the setting information received from the client terminal 1004 in the registration information database 1002A, in association with the terminal identification ID and the version information or registration date and time of the control information of the target web server 1003. Once registration is complete, in S1208, the license management device 1002 transmits a registration confirmation response to the client terminal 1004. The registration confirmation response includes the terminal identification ID generated in S1207. Upon receiving the registration confirmation response, the client terminal 1004 associates the setting information entered on the registration screen with the terminal identification ID and stores it as terminal information in the terminal in S1209. Alternatively, the license management device 1002 may transmit the terminal identification ID and tracking availability information to the client terminal 1004, and these may be stored in the client terminal 1004 as terminal information in association with each other.
[0098] Next, a case where the setting information is set to reject in option 2 will be described. This corresponds to the case where, when entering the registration information in S1205 described above, the disagree button 1403 is clicked, or the agree button 1404 is clicked without checking any items. In this case, if the setting information is set to reject in S1210, the transmission of tracking information to web server 1003 is suppressed in S1211. At this time, the client terminal may execute a control program to collect tracking information and suppress transmission in accordance with the rejection setting, or may not collect tracking information at all.
[0099] Next, in Option 3, the case where the setting information is a permission setting will be described. In this case, it corresponds to the situation where the consent button 1404 is clicked in the input of the registration information in S1205 described above. In this case, in S1212, if it is determined that the tracking availability information is set to permitted, in S1213, the tracking information corresponding to the permitted items is transmitted to the web server 1003. At this time, on the client terminal, the control program may be executed to collect the tracking information and perform transmission only for the permitted items, or the collection of the tracking information itself may not be performed for the non-permitted items. The web server stores the tracking information received in S1214 in the site information database 1003A and returns a confirmation response to the client terminal in S1215.
[0100] Next, with reference to FIG. 13, the processing flow executed between the client terminal 1004 and the permission management device 1002 corresponding to the embodiment of the invention will be described. In this processing, the content of the setting information registered in the permission management device 1002 is updated or changed. This processing can be performed when the user wants to change the content of the setting information, or when the registration information is updated by the administrator terminal 1001 of the website and the content of the previous setting information is invalidated.
[0101] The processing corresponding to FIG. 13 is realized by each device executing the processing program held in the HD204 or the database 301 by the CPU 200 to perform the processing, or controlling the operation of each hardware configuration, and functioning as the corresponding functional block.
[0102] In S1301, the client terminal 1004 acquires a terminal identification ID. In the subsequent S1302, the client terminal 1004 sends a request for information managed by the permission management device 1002 to the permission management device 1002 in association with the terminal identification ID. In the permission management device 1002, in accordance with the information request sent from the client terminal 1004, in S1303, the information (particularly, tracking availability information) stored in association with the terminal identification ID is read from the registration information database 1002A and sent to the client terminal 1004 in S1304. If there are multiple pieces of information stored in association with the terminal identification ID, a list of the information may be sent.
[0103] When the client terminal 1004 receives information from the permission management device 1002, in S1305, it selects the setting information included therein, displays a registration screen as shown in FIG. 14, and accepts a change operation of the setting information. At this time, the check state of the check box follows the content of the setting information included in the information received from the permission management device 1002. When the setting information is updated, in the subsequent S1306, the client terminal 1004 sends an update request to the permission management device 1002. The update request includes the setting information updated in S1305 and the terminal identification ID. In S1307, the permission management device 1002 updates the old setting information registered in the registration information database 1002A in association with the terminal identification ID with the received setting information. The permission management device 1002 sends a registration update response to the client terminal 1004 in S1308.
[0104] When the client terminal 1004 receives a registration update response from the permission management device 1002, in S1309, it stores the new setting information in the terminal as terminal information in association with the terminal identification ID.
[0105] According to the process corresponding to the above-described embodiment, when tracking information regarding a user's browsing behavior on a predetermined website, it is possible to permit restricting the purpose of use of the information tracked on the user. The user can continuously restrict the purpose of use of the tracking information by performing a single setting operation. On the other hand, the update can be performed arbitrarily.
[0106] <Summary of Embodiment 2> Embodiment 2 discloses at least the following system. (Item 101) A system including a web server that manages a website, an administrator terminal of the web server, and a permission management device that manages settings related to tracking information regarding a user who browses the website, The administrator terminal acquires link information of a control program for tracking information regarding the user from the permission management device, is configured to set the acquired link information in the page information of the website, The permission management device transmits the link information to the administrator terminal in response to a request from the administrator terminal, is configured to receive settings related to tracking from a client terminal operated by the user, The web server transmits the page information in which the link information is set to the client terminal in response to a request from the client terminal, The control program is executed according to the content of the settings related to tracking in the client terminal that has received the page information in which the link information is set, and the tracking information obtained by the execution of the control program is configured to be received from the client terminal. (Item 102) The permission management device The system according to item 101, further configured to transmit the control program requested based on the link information from the client terminal that has received the page information with the link information set thereto to the client terminal. (Item 103) The license management device transmits screen information for inputting the setting related to the tracking to the client terminal, receives the setting related to the tracking via the screen information, and saves the content of the received setting related to the tracking in association with the client terminal. The system according to item 101 or item 102, further configured as described above. (Item 104) The license management device is further configured to receive a change in the content of the setting saved in association with the client terminal from the client terminal, the system according to item 103. (Item 105) The screen information for inputting the setting related to the tracking is configured to be able to individually set whether to permit the use of tracking information for a plurality of items, and the web server is further configured to receive the tracking information obtained when the control program is executed according to the setting content of each of the plurality of items, the system according to item 103 or item 104. (Item 106) The administrator terminal is further configured to obtain the link information from the license management device in response to a request for registering registration information including information on a web page to be tracked in the license management device, the registration information is updatable, and the license management device is configured to invalidate the setting related to the tracking received from the client terminal when the registration information is updated, the system according to any one of items 101 to 105. (Item 107) The system according to item 106, wherein the administrator terminal is configured to receive again the setting related to the tracking from the client terminal after invalidating the setting related to the tracking. (Item 108) The registration information includes reference information of a privacy policy. The system according to item 106 or item 107, wherein the reference information is used when the client terminal inputs a setting related to the tracking.
[0107] By storing the above processing (for example, the processing according to FIGS. 11 to 13 above, etc.) in a computer program in a predetermined storage medium and causing the computer to read (install or copy) the program stored in this storage medium, the computer can perform the above processing. Therefore, it is obvious that the computer program and the storage medium are also within the scope of the present invention.
[0108] The invention is not limited to the above embodiments, and various modifications and changes are possible within the scope of the gist of the invention.
Claims
1. A tracking permission management device, comprising: an acquisition means for acquiring, from a client terminal, setting information regarding whether to permit tracking of the behavior of the client terminal on the website accessed by the client terminal; a holding means for holding the acquired setting information as registration information in association with a first token for uniquely identifying the client terminal; a transmission means for transmitting the registration information to the client terminal together with the first token; wherein the registration information includes information specifying a format for permitting the tracking for each website, and the tracking permission management device.
2. The information for specifying the format for permitting the tracking for each website includes information for specifying a permission format for permitting the tracking for all websites, information for specifying a permission format for rejecting the tracking for all websites, or information for specifying a permission format for permitting the tracking for a specified website The tracking permission management device according to claim 1, including any one of the above.
3. The tracking permission management device according to claim 2, wherein the registration information further includes information on the specified website.
4. The tracking permission management device according to claim 3, wherein the registration information further includes information regarding the necessity of confirmation as to whether to permit tracking for other websites other than the specified website.
5. When the information regarding the necessity of confirmation indicates that confirmation is required, The tracking permission management device according to claim 4, wherein the registration information further includes information on websites for which tracking has been rejected in the confirmation of whether to permit tracking for the other websites.
6. When a registration request is received from the client terminal, the tracking permission management device further comprises means for issuing the first token, the transmission means transmits screen information for inputting the setting information to the client terminal together with the first token, and the acquisition means acquires the setting information from the client terminal together with the first token. The tracking permission management device according to claim 1.
7. A client terminal, comprising: Means for receiving, from a tracking permission management device that manages permission settings for tracking the behavior of the client terminal on the website accessed by the client terminal, registration information regarding the permission setting for tracking the client terminal, the registration information including a first token for the tracking permission management device to uniquely identify the client terminal; Means for receiving information of the website from a web server that provides the website together with a second token different from the first token; Determination means for determining whether to permit the web server to track the behavior of the client terminal on the website based on the received registration information; Means for transmitting a response to the received website information to the web server according to the determination result in the determination means; Comprising; When the determination means determines not to permit the tracking by the web server, the transmitting means transmits the response to the web server without including the second token, a client terminal.
8. The client terminal according to claim 7, further comprising means for discarding the second token in response to the determination means determining not to permit the web server to track the client terminal.
9. The client terminal according to claim 7, wherein when the determination means determines to permit the web server to track the client terminal, the transmitting means transmits the response to the web server including the second token in the response.
10. When the determination result by the determination means is to obtain confirmation on the client terminal as to whether to permit the web server to track the behavior of the client terminal on the website, The client terminal further comprises means for receiving a setting on whether to permit tracking for the website, When the receiving means receives a setting for rejecting tracking for the website, the transmitting means transmits the response without including the second token, The client terminal according to claim 7, wherein when the receiving means receives a setting permitting tracking for the website, the transmitting means transmits the response including the second token.
11. The client terminal according to claim 10, further comprising means for transmitting to the tracking permission management device a setting as to whether or not to permit tracking for the website received by the receiving means.
12. A computer program for causing a computer to function as each means of the tracking permission management device according to any one of claims 1 to 6.
13. A computer program for causing a computer to function as each means of the client terminal according to any one of claims 7 to 11.
Citation Information
Patent Citations
Terminal device, server device, network system, communication method and communication program
JP2013084063A
Individual medical information processing system
JP2017068479A
System for controlling user interaction via an application with remote servers
US20210243262A1
Information processing device, information processing method, and program
JP2021015585A