System and Method for Distributed Verification of Online Identity
The system addresses real-time online identity verification by using locally maintained verification keys for trusted third-party verifiers, reducing delays and network overhead while preventing replay attacks and protecting user privacy.
Patent Information
- Application Number
- JP2024111019
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-08-28
- Filing Date
- 2024-07-10
- Publication Date
- 2025-08-04
- Estimated Expiration
- 2040-04-15
AI Technical Summary
Existing systems face challenges in verifying the identity of online users in real-time while protecting user privacy and preventing replay attacks, especially for third-party content item distributors, due to the need for multiple queries to external verifiers, which causes delays and network overhead.
A system that includes an issuer generating and distributing digitally signed tokens to trusted third-party verifiers, enabling real-time identity verification by maintaining verification keys locally, thus reducing the need for external queries and minimizing network overhead.
Enables real-time identity verification with reduced network overhead and enhanced security by ensuring only trusted parties can decrypt and verify user identities, preventing replay attacks and maintaining user privacy.
Smart Images

Figure 0007717915000001 
Figure 0007717915000002 
Figure 0007717915000003
Abstract
Description
Technical Field
[0001] Cross - Reference to Related Applications This application claims priority to U.S. Patent Application No. 16 / 553,599, filed on August 28, 2019, and U.S. Provisional Application No. 62 / 840,204, filed on April 29, 2019, the contents of which are incorporated herein by reference.
Background Art
[0002] In a computer network environment such as the Internet, a user can interact with third - party content items. These third - party content items, such as advertisements, can be displayed on web pages associated with their respective publishers. These users can provide information indicating their interaction with the third - party content items to the publisher.
Summary of the Invention
Problems to be Solved by the Invention
[0003] One technical problem addressed by the present disclosure is the difficulty in determining the identity of an online user while protecting the privacy of the online user. Further, a third - party content item distributor may want to verify the identity of a user who visits a publisher's web page within a predefined short time frame (e.g., 100 milliseconds). However, accurately verifying the identity of a user requires many queries to an external source responsible for verifying the identity of the user. This results in an unacceptable delay for a particular third - party content item distributor platform.
[0004] The problem addressed in this disclosure relates to providing a system that enables distributed verification of the identity of online users while maintaining user privacy only for trusted third-party content item distributors and minimizing the number of queries to third-party verifiers. Public keys are issued only to trusted third-party content item distributors who can decrypt the digitally signed token data by a trusted issuer to verify the user's token data in real time. This minimizes the number of queries that verifiers need to make to verify the token data, reducing network overhead and verification time.
[0005] Cookie-based identity support does not support authentication by the issuer and does not prevent copying of browser sessions, also known as "replay attacks". As a result, browser cookies are labels rather than a trusted identity for online users. Similarly, on devices such as connected TVs, device identifiers provide only a weak layer of protection. Other parties cannot verify the authenticity of the device on behalf of the OEM. In these cases, replay attacks where copies of browser sessions are created to make requests for unauthorized content items cannot be detected, and identity verification cannot be performed in real time as required by many third parties. Therefore, the technical solution disclosed herein represents a significant improvement over existing techniques for identity verification and fraud detection.
Means for Solving the Problem
[0006] The present disclosure discusses a system that includes an issuer who knows the legitimate identity of an online user and is responsible for authenticating and generating digital signatures corresponding to token data associated with a particular user. The issuer can control, through encryption, which third-party content distributor platforms (third-party verifiers) can process the user's token data. The system further includes verifiers approved by the issuer to verify token information associated with a particular user. Since the verification keys are maintained locally by the verifiers, the verification process can be performed in real time without the need to access external parties. This enables real-time identity verification to be distributed between the issuer and third-party content item distribution platforms.
[0007] At least one aspect is directed to a method for providing a signed identity token. The method comprises the step of generating, by a party, a first party token associated with an issuer's domain. The method also comprises the step of transmitting, by the party, the first party token associated with the issuer's domain to the issuer. The method further comprises the step of receiving, by the issuer, the first party token associated with the issuer's domain and creating a timestamp corresponding to the first party token. The method further comprises the step of encrypting, by the issuer, the first party token and the timestamp using the issuer's private key to create a digitally signed token. The method further comprises the step of creating, by the issuer, a plurality of digitally signed tokens, each of the plurality of digitally signed tokens corresponding to a respective verifier. The method further comprises the step of encrypting each of the plurality of digitally signed tokens using a public key provided by a respective verifier. The method also comprises the step of generating, by the issuer, a composite token comprising each of the plurality of encrypted digitally signed tokens. The method further comprises the step of providing, by the issuer, the composite token to the party responsible for generating the first party token.
[0008] Another aspect of the present disclosure is directed to a method for verifying a user's identity. The method includes steps of receiving, by a verifier, a composite token and a timestamp, where the composite token comprises a plurality of encrypted tokens with digital signatures, and further includes steps of enumerating, by the verifier, each of the plurality of encrypted tokens with digital signatures within the composite token. The method also includes steps of determining, by the verifier, which of the enumerated encrypted tokens with digital signatures corresponds to the verifier. The method further includes steps of decrypting, by the verifier, the content of the encrypted signed token corresponding to the verifier using a private key belonging to the verifier to generate a signed token. The method further includes steps of verifying, by the verifier, the validity of the digital signature of the signed token using a public key corresponding to the issuer to generate a valid first-party token. The method further includes steps of processing, by the verifier, the valid first-party token generated from the signed token in response to the digital signature of the signed token being valid.
[0009] These and other aspects and implementations will be described in detail below. The foregoing information and the following detailed description include illustrative examples of various aspects and implementations, and provide an overview or framework for understanding the nature and characteristics of the claimed aspects and implementations. The drawings provide an explanation and further understanding of the various aspects and implementations, and are incorporated herein and form a part of this specification.
[0010] The accompanying drawings are not intended to be drawn to scale. Like reference numerals and designations in the various drawings indicate like elements. For clarity, not all components are labeled in every drawing.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
DETAILED DESCRIPTION OF THE INVENTION
[0012] The following is a more detailed description of various concepts related to methods, apparatuses, and systems for managing tamper-resistant content item operations, and their implementations. Since the above concepts are not limited to any specific implementation method, the various concepts introduced above and described in more detail below can be implemented in any of a number of ways.
[0013] FIG. 1 is a block diagram showing one implementation of an environment 100 for distributed real-time verification of online identities. The environment 100 includes at least one client computing system 105. The client computing system 105 can include at least one processor (or processing circuitry) and memory. The memory stores processor-executable instructions that, when executed on the processor, cause the processor to perform one or more of the operations described herein. The processor can include, for example, a microprocessor, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or combinations thereof. The memory can include, but is not limited to, an electronic, optical, magnetic, or any other storage or transmission device that can provide program instructions to the processor. The memory can further include, for example, a floppy disk, a CD-ROM, a DVD, a magnetic disk, a memory chip, an ASIC, an FPGA, a read only memory (ROM), a random access memory (RAM), an electrically erasable ROM (EEPROM), an erasable-programmable ROM (EPROM), a flash memory, an optical medium, or any other suitable memory from which the processor can read instructions. The instructions can include code from any suitable computer programming language. The client computing system 105 can include one or more computing devices or servers that can perform various functions.
[0014] In some implementations, client computing system 105 can include an application such as a web browser configured to generate a browser token. In such an embodiment, the generated browser token can be associated with the domain of the issuer computing system 115 and can include information about the web browser executed by the client computing system 105. In some implementations, client computing system 105 is configured to generate a device token. In such an embodiment, the generated device token can be associated with the domain of the issuer computing system 115 and can include device information about the client computing system 105. Client computing system 105 can be configured to send the generated token to the issuer computing system 115 via network 110. In some implementations, client computing system 105 is configured to communicate with an advertising auction system via content item network 155.
[0015] Network 110 can include computer networks such as the Internet, local, wide, metro or other area networks, intranets, satellite networks, other computer networks such as voice or data mobile telephone communication networks, and combinations thereof. In some implementations, either the key distribution infrastructure 135 or the content item network 155 may be the same as or part of network 110. The client computing system 105 of environment 100 can communicate via network 110 with, for example, at least one issuer computing system 115. Network 110 can be any form of computer network that relays information between client computing system 105 and issuer computing system 115, and particularly one or more content sources such as web servers, advertising servers. For example, network 105 can include other types of data networks such as the Internet and / or local area network (LAN), wide area network (WAN), cellular network, satellite network, or other types of data networks. Network 110 can also include any number of computing devices (e.g., computers, servers, routers, network switches, etc.) configured to receive and / or transmit data within network 110. Network 110 can further include any number of hardwired and / or wireless connections. For example, client computing system 105 can communicate wirelessly with a transceiver hardwired (e.g., via fiber optic cable, CAT5 cable, etc.) to other computing devices within network 110.
[0016] The content item network 155 can include computer networks such as the Internet, local, wide, metro or other area networks, intranets, satellite networks, voice or data mobile telephone communication networks, and combinations thereof. In some implementations, the content item network 155 may be the same as or a part of the network 110. The client computing system 105 of the environment 100 can communicate with, for example, at least one verifier computing system 140 via the content item network 155. The content item network 155 can be any form of computer network that relays information between the client computing system 105 and at least one verifier computing system 140, and especially one or more content sources such as web servers, advertising servers, etc. For example, the content item network 155 can include the Internet and / or other types of data networks such as local area networks (LANs), wide area networks (WANs), cellular networks, satellite networks, or other types of data networks. The content item network 155 can also include any number of computing devices (e.g., computers, servers, routers, network switches, etc.) configured to receive and / or transmit data within the content item network 155. The content item network 155 can further include any number of hardwired and / or wireless connections. For example, the verifier computing system 140 can communicate wirelessly with a transceiver that is hardwired (e.g., via fiber optic cable, CAT5 cable, etc.) to other computing devices within the content item network 155.
[0017] The key distribution infrastructure network 135 can include other computer networks such as the Internet, local, wide, metro or other area networks, intranets, satellite networks, voice or data mobile telephone communication networks, and combinations thereof. In some implementations, the key distribution infrastructure network 135 may be the same as or a part of the network 110. The key manager computing system 130 of the environment 100 can communicate with, for example, at least one issuer computing system 115 and / or at least one verifier computing system 140 via the key distribution infrastructure network 135. The key distribution infrastructure network 135 can be any form of computer network that relays information between the key manager computing system 130 and at least one verifier computing system 140 or at least one issuer computing system 115, and particularly one or more content sources such as web servers, advertising servers, etc. For example, the key distribution infrastructure network 135 can include the Internet and / or other types of data networks such as local area networks (LANs), wide area networks (WANs), cellular networks, satellite networks, or other types of data networks. The key distribution infrastructure network 135 can also include any number of computing devices (e.g., computers, servers, routers, network switches, etc.) configured to receive and / or transmit data within the key distribution infrastructure network 135. The key distribution infrastructure network 135 can further include any number of hardwired and / or wireless connections.For example, the key manager computing system 130 can communicate wirelessly (e.g., via WiFi, cellular, wireless, etc.) with a transceiver that is hardwired to other computing devices within the key distribution infrastructure network 135 (e.g., via an optical fiber cable, a CAT5 cable, etc.).
[0018] The issuer computing system 115 can include a server or other computing device operated by an issuer entity to authenticate and / or digitally sign token information such as browser or device tokens received from the client computing system 105. The issuer computing device 115 can include a token signer component 120 and one or more cryptographic key components 125. In some implementations, the issuer computing system 115 can provide third-party content items or creatives (e.g., advertisements) for display on an information resource such as a website or web page that includes primary content. The issuer computing system 115 can also provide an information resource such as a web page that includes primary content. The issuer computing system 115 can include instructions or computing circuitry for generating a digital signature based on a token corresponding to information associated with the client computing system 105. The issuer computing system 115 can include instructions or computing circuitry for encrypting a digitally signed token corresponding to information associated with the client computing system 105. The issuer computing system 115 can generate a composite token based on one or more cryptographic key components 125 and a digital signature generated by the token signer component 120. The issuer computing system 115 can generate a composite token by concatenating each of the encrypted digitally signed tokens together into a single data structure. The issuer computing system 115 can provide the generated composite token to the client computing system 105 via the network 110. The issuer computing system 115 can receive, request, accept, or query both the token signer component 125 and / or the cryptographic key component 125 from the key manager 130 via the key distribution infrastructure 135.In some implementations, the key manager 130 may automatically send the token signer component 120 and / or one or more cryptographic key components 125 to the issuer computing system 115 via the key distribution infrastructure 135.
[0019] The verifier computing system 140 can include a server or other computing device operated by a content provider entity to provide verification of the authenticity of a signed token received from the client computing system 105 through the content item network 155. In some implementations, the signed token received from the content item network 155 can be a composite token. The verifier computing system 140 can include a token verifier component 145 and a decryption key component 150. The verifier computing system 140 can provide third-party content items or creatives (e.g., advertisements) for display on an information resource such as a website or web page including primary content via the content item network 155. The verifier computing system 140 can provide only content items in response to verifying a token associated with the client 105 using the decryption key component 150 and the token verifier component 145. One or more verifier computing systems 140 can receive a composite token corresponding to the client computing system 105 via the content item network 155. The composite token received from the content item network 155 can include one or more encrypted digital signatures, one of which can correspond to one of the verifier computer systems 140. Each of the verifier computing systems 140 that receives the composite token can parse the composite token to enumerate the plurality of encrypted digital signature tokens. Each of the verifier computing systems 140 can use the decryption key component 150 to decrypt the encrypted digital signature token corresponding to the verifier computing system 140. The encrypted digital signature token can be determined to correspond to the verifier computing system 140 if the decrypted digital signature within the encrypted digital signature token can be verified using the token verifier component 145.The token verifier component 145 can use the public key corresponding to the private key maintained by the issuer computing system 115 to verify the decrypted digital signature. In some embodiments, the verifier computing system 140 can receive, request, accept, or query both the token verifier and one or more decryption keys from the key manager computing system 130 via the key distribution infrastructure 135. In some implementations, the key manager component system 130 can automatically send the verifier component 145 and / or the decryption key component 150 to the verifier computing system 140 via the key distribution infrastructure 135.
[0020] The client computing system 105, the issuer computing system 115, the verifier computing system 140, and the key manager computing system 130 can include a processor and a memory, i.e., a processing circuit. The memory stores machine instructions that, when executed on the processor, cause the processor to perform one or more of the operations described herein. The processor can include a microprocessor, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), etc., or a combination thereof. The memory can include, but is not limited to, an electronic, optical, magnetic, or any other storage or transmission device that can provide program instructions to the processor. The memory can further include a floppy disk, a CD-ROM, a DVD, a magnetic disk, a memory chip, an ASIC, an FPGA, a read only memory (ROM), a random access memory (RAM), an electrically erasable ROM (EEPROM), an erasable-programmable ROM (EPROM), a flash memory, an optical medium, or any other suitable memory from which the processor can read instructions. The instructions can include code from any suitable computer programming language.
[0021] The client computing system 105, the issuer computing system 115, the verifier computing system 140, and the key manager computing system 130 may also include one or more user interface devices. Generally, a user interface device generally refers to any electronic device (such as a keyboard, mouse, pointing device, touch screen display, microphone, etc.) that conveys data to a user by generating sensory information (such as visualizations on a display, one or more sounds, etc.) and / or converts sensory information received from the user into an electronic signal. According to various implementations, one or more user interface devices may be inside the housing of the client computing system 105, the issuer computing system 115, the verifier computing system 140, and the key manager system 130 (such as a built-in display, microphone, etc.), or may be outside the housing of the client computing system 105, the issuer computing system 115, the verifier computing system 140, and the key manager computing system 130 (such as a monitor connected to the client computing system 105, a speaker connected to the client computing system 105, etc.). For example, the client computing system 105, the issuer computing system 115, the verifier computing system 140, and the key manager computing system 130 may include an electronic display that visually displays a web page using web page data received from one or more content sources via the network 110, the content item network 155, or the key distribution infrastructure 135.
[0022] The issuer computing system 115 can include at least one server. For example, the issuer computing system 115 can include a plurality of servers disposed in at least one data center or server farm. In some implementations, the issuer computing system 115 can include information regarding the client computing system 105. The issuer computing system 115 can include at least one token signer component 120 and at least one cryptographic key component 125. The token signer component 120 and the cryptographic key component 125 can each include at least one processing unit, server, virtual server, circuit, engine, agent, appliance, or other logic device such as a programmable logic array configured to communicate with other computing devices (e.g., the client computing system 105, or the key manager computing system 130) via the network 110 and / or the key distribution infrastructure 135.
[0023] The token signer component 120 and the cryptographic key component 125 can include or execute at least one computer program or at least one script. The token signer component 120 and the cryptographic key component 125 can be separate components, a single component, or part of the issuer computing system 115. The token signer component 120 and the cryptographic key component 125 can include a combination of software and hardware such as one or more processors configured to execute one or more scripts.
[0024] The token signer component 120 can receive a first-party token from the client computing system 105 via the network 110. In some embodiments, the first-party token can be associated with the domain of the issuer computing system 115. In some embodiments, the first-party token can be generated by a browser running on the client computing system 105. In some other embodiments, the first-party token can be a device token generated by the client computing system 105. In some embodiments, the token signer component 120 can receive a request from the client computing system 105 via the network 110 to generate a first-party token. The request for the first-party token can include browser information corresponding to the browser running on the client computing system 105. The request for the first-party token can include device information corresponding to the client computing system 105. In some embodiments, the token signer component 120 can generate a first-party token in response to a request from the client computing system 105. The first-party token can correspond to the domain of the issuer computing system 115. The token signer component 120 can receive a request for a composite token from the client computing system 105 via the network 110. In some embodiments, the token signer component 120 can receive a request for a digitally signed token from the client computing system 105 via the network 110. The token signer component 120 can generate a timestamp corresponding to the receipt of the first-party token from the client computing system 105. The timestamp can be generated based on the current time maintained by the issuer computing system 115.The token signer component 120 can maintain one or more private keys corresponding to the issuer computing system 115. In some embodiments, the one or more private keys are received from the key manager computing system 130 via the key distribution infrastructure 135. The token signer component 120 can use the one or more private keys to generate a first-party token with a digital signature. The token signer component 120 can provide the first-party token with a digital signature to the encryption key component 125 to generate one or more encrypted tokens with digital signatures. The token signer component 120 can provide the first-party token with a digital signature to the encryption key component 125 to generate a composite token comprising one or more encrypted tokens with digital signatures.
[0025] The cryptographic key component 125 can receive a first-party token with a digital signature from the token signer component 120. In some embodiments, the cryptographic key component 125 can receive a request for a composite token from the client computing system 105 via the network 110. In some embodiments, the cryptographic key component 125 can receive a request for an encrypted token with a digital signature from the client computing system 105 via the network 110. The cryptographic key component 125 can maintain one or more cryptographic keys. In some embodiments, each of the one or more cryptographic keys is a public key corresponding to the verifier computing system 140. In such embodiments, the verifier computing system 140 can maintain a secret key associated with the corresponding public key maintained by the issuer computing system 115. The one or more cryptographic keys can be received from the key manager computing system 130 via the key distribution infrastructure 135. In some embodiments, the cryptographic key component 125 can receive a request from the token signer component 120 to generate one or more encrypted tokens with digital signatures. In such embodiments, the cryptographic key component 125 can generate an encrypted token with a digital signature for each of the one or more cryptographic keys maintained by the cryptographic key component 125. The cryptographic key component 125 can generate a composite token comprising one or more encrypted tokens with digital signatures. In such embodiments, the cryptographic key component 125 can generate the composite token by concatenating each of the one or more encrypted tokens with digital signatures into a single data structure. The cryptographic key component can provide the composite token to the client computing system 105. In some embodiments, the cryptographic key component can provide one or more encrypted tokens with digital signatures to the client computing system 105.
[0026] The verifier computing system 140 can include at least one server. For example, the verifier computing system 140 can include a plurality of servers disposed in at least one data center or server farm. In some implementations, the verifier computing system 140 can include information regarding the client computing system 105. The verifier computing system 140 can include at least one token verifier component 145 and at least one decryption key component 150. The token verifier component 145 and the decryption key component 150 can each include at least one processing unit, server, virtual server, circuit, engine, agent, appliance, or other logical device such as a programmable logic array configured to communicate with other computing devices (e.g., the client computing system 105, or the key manager computing system 130) via the content item network 155 and / or the key distribution infrastructure 135.
[0027] The token verifier component 145 and the decryption key component 150 can include or execute at least one computer program or at least one script. The token verifier component 145 and the decryption key component 150 can be separate components, a single component, or part of the verifier computing system 140. The token verifier component 145 and the decryption key component 150 can include a combination of software and hardware such as one or more processors configured to execute one or more scripts.
[0028] The decryption key component 150 can receive a composite token corresponding to the client computing system 105 via the content item network 155. The composite token can include one or more encrypted tokens with digital signatures. In some embodiments, the composite token can include a first-party token and a timestamp, and the first-party token is used to generate the encrypted and digitally signed portion of the composite token. In such embodiments, the decryption key component 150 can check whether the received timestamp of the composite token is recent to determine whether the composite token was sent as part of a replay attack. If the composite token is determined to be part of a replay attack, the decryption key component can ignore the composite token and stop further processing of the composite token by the verifier computing system 140. The decryption key component 150 can receive a request from the content item network 155 to verify the authenticity of the composite token. The decryption key component 150 can receive a request from the content item network 155 to verify one or more encrypted tokens with digital signatures. The decryption key component 150 can maintain a decryption key. In some embodiments, the decryption key is a private key corresponding to the verifier computing system 140. In such embodiments, the issuer computing system 115 maintains a public key associated with the corresponding private key maintained by the verifier computing system 140.
[0029] The decryption key can be received from the key manager computing system 130 via the key distribution infrastructure 135. The decryption key component 150 can enumerate each of the encrypted tokens with digital signatures within the composite token received from the content item network 155. The decryption key component 150 can enumerate each of the encrypted tokens with digital signatures received from the content item network 155. The decryption key component 150 can attempt to decrypt each of the enumerated encrypted tokens with digital signatures using the private key maintained by the decryption key component 150 to generate a token with a digital signature corresponding to each encrypted token with a digital signature. In some embodiments, the decryption key component 150 can determine which of the enumerated tokens with digital signatures corresponds to the verifier computing system 140. In such embodiments, the decryption key component 150 can decrypt the encrypted token with a digital signature corresponding to the verifier computing system 150 using the private key to generate a token with a digital signature. The decryption key component 150 can provide the generated one or more tokens with digital signatures to the token verifier component 145.
[0030] The token verifier component 145 can receive one or more digitally signed tokens provided by the decryption key component 150. The token verifier component can receive first-party tokens and timestamps. The token verifier component 145 can maintain a public key corresponding to the private key maintained by the issuer computing system 115. In some embodiments, the token verifier component can receive the public key from the key manager computing system 130 via the key distribution infrastructure 135. The token verifier component 145 can verify the first-party tokens by verifying at least one of the digitally signed tokens using the public key. For example, the token verifier component 145 can use the public key to decrypt each of the digitally signed tokens received from the decryption key component 150 to generate a pair of one or more decrypted tokens and timestamps, and each pair of decrypted tokens and timestamps corresponds to each of the digitally signed tokens. Next, the token verifier component 145 can compare each pair of tokens and timestamps with the first-party tokens and timestamps received by the verifier computing system 140 as part of the composite token. If any of the pairs of tokens and timestamps match the first-party tokens and timestamps received as part of the composite token, the first-party tokens are considered verified. Since each of the encrypted digitally signed tokens corresponds to the verifier computing system 140 approved by the issuer computing system 115 to verify the authenticity of the first-party tokens, the composite token can include a plurality of encrypted digitally signed tokens. The digitally signed tokens can be used as digital signatures to verify the authenticity of the first-party tokens and timestamps.In some embodiments, the verifier computing system 140 can process the first party token in response to verification of the authenticity of the first party token.
[0031] FIG. 2 is a block diagram representing an exemplary implementation of the key manager computing system 130. The key manager computing system 130 can include a key management service 205, a token signer binary 210, a token verifier binary 215, a verifier cryptographic key 220, and a verifier decryption key 225. In some implementations, the key management service 205 can be executed by the operating system of the key manager computing system 130.
[0032] In some implementations, the key management service 205 can be an application programming interface provided by an operating system through which the issuer computing system 115 and the verifier computing system 140 can interface to request token signer data and token verifier data. In some implementations, the issuer computing system 115 can approve a decryption key for each verifier computing system 140 by interfacing with the key management service 205. In some implementations, the key management service can use the token signer binary 210 to provide the private key of the token signer component 120 to the issuer computing system 115. In such implementations, the private key can be provided to the issuer computing system 115 via the key distribution infrastructure 135. In some implementations, the key management service can use the token verifier binary 215 to provide the public key of the token verifier component 145 to the verifier computing system 140. In such implementations, the private key can be provided to the issuer computing system 115 via the key distribution infrastructure 135. The key management service 205 can approve a particular verifier computing system 140 by generating a particular verifier encryption key 220 and a verifier decryption key 225. For example, the key management service 205 can receive a request from the issuer computing system 115 to approve only a particular verifier computing system 140. The key management service 205 can then generate a verifier encryption key (e.g., a public key) and a verifier decryption key (e.g., a private key), each of the public key / private key pair corresponding to the verifier computing system 140 approved by the issuer computing system 115. The key management service 205 can provide all public (encryption) keys to the encryption key component 125 of the issuer computing system 115 via the key distribution infrastructure 135. The key management service 205 can distribute each private (decryption) key to the respective approved verifier computing system 140.
[0033] Figure 3 is a flowchart of an exemplary process 300 for generating an encrypted composite token. Process 300 includes a step (302) of generating a first-party token, a step (304) of sending the first-party token to an issuer, a step (306) of digitally signing the first-party token using a private key, a step (308) of selecting an i-th verifier encryption key, a step (310) of creating an encrypted token with a digital signature using the i-th verifier encryption key, a step (312) of determining whether i is equal to the number of verifier encryption keys, a step (314) of incrementing register i, a step (316) of generating a composite token from the encrypted token with a digital signature, and a step (318) of providing the composite token to the party responsible for generating the first-party token.
[0034] In further detail of step 302, a party generates a first-party token. In some implementations, the first-party token may be associated with the issuer's domain. In some implementations, the first-party token may include data from an application (e.g., a web browser). In some implementations, generating the first-party token includes device information from the device or system executing process 300. Generating the first-party token may include generating a request for an encrypted token with a digital signature from the issuing party. The issuing party may also be referred to as the issuer. Generating the first-party token may include generating a request for a composite token from the issuer. In some implementations, generating the first-party token may include generating a timestamp. In such implementations, the timestamp may be a high-resolution timestamp (e.g., at a millisecond or microsecond resolution).
[0035] In further detail of step 304, the party sends the first party token to the issuer. Sending the first party token to the issuer can include sending a timestamp generated by the party. In some implementations, sending the first party token can include sending a request for an encrypted digitally signed token to the issuer. In some embodiments, sending the first party token can include sending a request for a composite token to the issuer, where the composite token comprises at least one or more encrypted digitally signed tokens. Sending the first party token can include sending a request for a digitally signed token from the issuer.
[0036] In further detail of step 306, the issuer uses the private key to digitally sign the first-party token sent in step 304. In some embodiments, step 306 can include the issuer receiving a digitally signed token generated by the party in step 302. In some embodiments, the issuer receiving a digitally signed token can include receiving a timestamp generated in step 302 or step 304. In some embodiments, step 306 of the process can concatenate the first-party token and the timestamp into a token-timestamp pair. In step 306, the issuer can use a digital signature algorithm (e.g., DSA, RSA, etc.) to digitally sign the first-party token. In some embodiments, the issuer can generate a digitally signed token by using a digital signature algorithm on the token-timestamp pair. In some embodiments, a hash function (e.g., SHA-1, SHA-256, MD5, etc.) can be executed with the first-party token as input to generate a hash token. In some embodiments, the hash function can be executed with the token-timestamp pair as input to generate a hashed token-timestamp pair. The issuer of process 300 can generate a digitally signed token by using a digital signature algorithm on the hashed token. In some embodiments, the issuer of process 300 can generate a signed token by using a digital signature algorithm on the hashed token-timestamp pair.
[0037] Process 300 includes a step (308) of selecting the i-th verifier cryptographic key. This process step can be performed by the issuer computing system 115, for example, to encrypt a digitally signed token of all cryptographic keys maintained by the cryptographic key component 125. In some embodiments, step 308 can include receiving one or more cryptographic keys respectively corresponding to the verifiers, where n is equal to the number of cryptographic keys. In some embodiments, the cryptographic keys can be received from a key manager, such as the key manager computing system 130. In some embodiments, the cryptographic keys are public keys corresponding to the respective verifiers. In the first iteration of the loop created by process 300, step 308 can select the first cryptographic key (the i-th, i = 1). It should be understood that one or more cryptographic keys can be selected in any order.
[0038] In further detail of step 310, process 300 can create an encrypted digitally signed token using the i-th verifier cryptographic key. In some embodiments, process 300 uses an asymmetric encryption algorithm, the cryptographic key is a public key, and the private key belongs to the verifier. Process 300 can create an encrypted digitally signed token by encrypting the digitally signed token generated in step 306 with the i-th cryptographic key selected in step 308. In some embodiments, the cryptographic key can be the private key of a public key / private key pair, and the public key is maintained by the verifier. In some embodiments, step 310 does not encrypt the digitally signed token generated in step 306 and simply returns the digitally signed token.
[0039] Process 300 includes creating encrypted digital-signature tokens corresponding to all cryptographic keys maintained by the issuer. For example, the cryptographic key component 125 of the issuer computing system 115 can determine whether the currently created encrypted digital-signature token is the nth encrypted digital-signature token, where n corresponds to the number of cryptographic keys maintained by the cryptographic key component 125. If it is not the nth encrypted digital-signature token, the cryptographic key component 125 can increment the counter i 312 and select the next cryptographic key from the cryptographic keys maintained by the cryptographic key component 125. In this way, the issuer computing system 115 can create n encrypted digital-signature tokens, each of the n encrypted digital-signature tokens corresponding to a verifier, e.g., the verifier computing system 140.
[0040] In further detail of step 316, process 300 can generate a composite token from the encrypted digital signature tokens. The composite token can be generated by concatenating each of the encrypted digital signature tokens into a single data structure. An example of this concatenation is shown in FIG. 5. In this exemplary embodiment, 506a - n each represent one of the encrypted digital signature tokens created in step 310, and each of the n digital signature tokens corresponds to a verifier, such as one of the verifier computing systems 140. In some embodiments, the composite token can be generated by concatenating each of the encrypted digital signature tokens with the original first - party token and a timestamp into a single data structure. An exemplary embodiment of this concatenation is shown in FIG. 5, where 502 is the original first - party token, 504 is the timestamp corresponding to the original first - party token, and 506a - n are each of the n encrypted digital signature tokens. Although FIG. 5 shows the first - party token, the timestamp, and the encrypted digital signature tokens in a particular order, it should be understood that any of these components may be excluded from the composite token, and any of these elements may appear in the composite token in any order.
[0041] Describing step 318 in more detail, process 300 provides a composite token to the party responsible for generating the first party token. Process 300 can provide the composite token generated in step 316 to the party that generated the first party token in step 302. For example, the issuer computing system 115 can send the composite token generated by the cryptographic key component 125 to the client computing system 105 via the network 110. In some embodiments, the issuer can provide the composite token to the party responsible for generating the first party token through a web interface. For example, the issuer computing system 115 can send the generated composite token via the web interface, and the client computing system 105 can receive the composite token as part of a browser session.
[0042] Figure 4 is a flowchart of an exemplary process 400 for verifying the content of a composite token according to an exemplary implementation. Process 400 includes a step of receiving a composite token (402), a step of enumerating each of the encrypted digitally signed tokens within the composite token (404), a step of selecting the i-th encrypted digitally signed token (408), a step of decrypting the encrypted digitally signed token to generate a digitally signed token (410), a step of verifying the validity of the digitally signed token to generate a first party token (412), a step of determining whether the encrypted token corresponds to the verifier (414), a step of determining whether i is equal to the number of encrypted digitally signed tokens within the composite token n (416), a step of incrementing register i (418), a step of ignoring the composite token (420), and a step of processing a valid first party token (422).
[0043] In further detail of step 402, process 400 can receive a composite token comprising one or more encrypted digital-signature tokens. For example, one of the verifier computing systems 140 can receive the composite token from the content item network 155. The composite token can include one or more encrypted digital-signature tokens. The composite token can also include a first-party token and a timestamp. An exemplary schematic diagram of the composite token is shown in FIG. 5. Process 400 can be performed by a party that needs to verify the authenticity of the first-party token. In some embodiments, the composite token can be received as a single data structure. In some other embodiments, the composite token can be received as a series of data structures. For example, a verifier executing process 400 can receive the encrypted digital-signature tokens one at a time and use them to create the composite token. In some embodiments, the first-party token can include a timestamp corresponding to the creation of the first-party token. In such embodiments, the first-party token and the timestamp can be included in the composite token.
[0044] In further detail of step 404, process 400 enumerates each of the encrypted digital-signature tokens within the composite token received in step 402. In some embodiments, enumerating each of the encrypted digital-signature tokens includes extracting each of the encrypted digital-signature tokens. In such embodiments, the first-party token and the timestamp may also be extracted from the composite token. In such embodiments, a verifier executing process 400 can compare the timestamp within the composite token to a predefined value. The verifier executing process 400 can compare the timestamp to check if the composite token is recent and defend against potential replay attacks. In some embodiments, the composite token can be a predefined data structure known to the verifier executing process 400. In such embodiments, the verifier can extract and enumerate each of the encrypted digital-signature tokens based on known offsets within the data structure. In some embodiments, enumerating each of the encrypted digital-signature tokens can include assigning a numerical value corresponding to each of the encrypted digital-signature tokens. For example, referring to FIG. 5, numerical values corresponding to their order within the composite token can be assigned to each of the encrypted digital-signature tokens 506a through 506n. Further in this example, a value of 1 can be assigned to 506a, a value of 2 can be assigned to 506b, a value of 3 can be assigned to 506c, and so on. In some embodiments, a verifier executing step 404 can determine the number n of encrypted digital-signature tokens included in the composite token received in step 402.
[0045] Process 400 includes a step (408) of selecting the i-th encrypted digital-signature token. This process step can be performed, for example, by the verifier computing system 115 to decrypt each of the encrypted digital-signature tokens with composite tokens. In some embodiments, step 308 can include the received decryption key corresponding to the verifier executing process 400. In some embodiments, the decryption key can be received from a key manager, such as the key manager computing system 130. In some embodiments, the decryption key is a private key corresponding to the verifier executing process 400. In such embodiments, the corresponding public key is maintained by the issuer responsible for generating the composite token. In the first iteration of the loop created by process 400, step 408 can select the first encrypted digital-signature token (the i-th, i = 1). It should be understood that one or more cryptographic keys can be selected in any order.
[0046] In further detail of step 410, process 400 decrypts a selected encrypted token with a digital signature to generate a token with a digital signature. A verifier can decrypt the selected encrypted token with a digital signature in step 408 to generate a token with a digital signature. For example, one of the verifier computing systems 140 can execute step 410 of process 400 using the decryption key component 150. To further the example, the decryption key component 150 of the verifier computing system 140 executing process 400 can receive a decryption key from the key manager computing system 130 via the key distribution infrastructure 135. In some embodiments, step 410 of process 400 can include receiving a decryption key from a key manager. In some other embodiments, the decryption key can be maintained or received by a verifier executing process 400 prior to the execution of process 400. In some embodiments, the decryption of the encrypted token with a digital signature is performed using a decryption algorithm (e.g., elliptic curve, RSA, etc.).
[0047] In further detail of step 412, the digitally signed token is verified to generate a first party token. In some embodiments, the digitally signed token is verified to generate a hash of the first party token. A verifier executing process 400 can use a digital signature algorithm (e.g., elliptic curve, DSA, RSA, etc.) to decrypt the content of the digitally signed token generated in step 410, and the decrypted content of the digitally signed token is a first party token and a timestamp that can be used to verify the validity of the first party token received in the composite token in step 402 of process 400. In some embodiments, the decrypted content of the digitally signed token is a hash of the first party token and the timestamp. In some embodiments, the digital signature algorithm uses the issuer's public key to decrypt the content of the digitally signed token. For example, the key management computing system 130 can distribute the private key to the issuer computing system 115 and the corresponding public key to the verifier computing system 140. The issuer computing system 115 can use process 300 to generate a composite key provided to the client computing system 105. The client computing system 105 can provide the composite token to the content item network 155, and the content item network 155 can provide the composite token to one or more verifier computing systems 140. The verifier computing system can use process 400 to attempt to process the first party token included in the composite token.In this example, the verifier computing system 140 can use the public key corresponding to the private key maintained by the issuer computing system 115 to generate the first party token and timestamp, or in some embodiments, to generate the hash of the first party token and timestamp, and to decrypt the digitally signed token in step 412.
[0048] In further detail of step 414, process 400 determines whether the decrypted content of the digitally signed token corresponds to the verifier executing process 400. For example, a composite token can include multiple encrypted digitally signed tokens. Each encrypted digitally signed token can be decrypted only by an approved verifier. In this example, approval is controlled by the distribution of decryption keys. Each decryption key can only normally decrypt the content of up to one of the encrypted digitally signed tokens included in the composite token. The verifier can determine whether the encrypted digitally signed token corresponds to the verifier executing process 400 by checking whether the digital signature (i.e., the digitally signed token generated in step 410) matches the first-party token and timestamp included in the composite token received in step 402. The verifier can check whether the first-party token and timestamp generated in step 412 match the first-party token and timestamp received as part of the composite token. In some embodiments, step 412 can return the hash of the first-party token and timestamp. In such embodiments, step 414 calculates the hash of the first-party token and timestamp received as part of the composite token using a cryptographic hash function (e.g., SHA-1, SHA-256, MD5, etc.) and compares it with the value returned from the decryption of the digitally signed token in step 412. If the two values match, the encrypted digitally signed token corresponds to the verifier, and in step 422, the first-party token can be processed by the verifier. If the two values do not match, the verifier executing process 400 can determine whether the current encrypted digitally signed token is the nth encrypted digitally signed token (416).If it is not a digitally signed token, the verifier executing process 400 can increment counter i 418 and select the next encrypted digitally signed token (408). If the current encrypted digitally signed token is the nth encrypted digitally signed token, none of the encrypted digitally signed tokens within the composite token correspond to the verifier executing process 400, and the composite token is ignored (420).
[0049] In further detail of step 422, the verifier executing process 400 can process the verified first party token. In some embodiments, verification process 400 can be executed in real time without accessing an external server or database. In some embodiments, processing the first party token includes consuming the token's data content. For example, the token can include browser information. By verifying the authenticity of the first party token, the verifier can associate the browser information included in the first party token with the party responsible for generating the first party token, such as client computing system 105. Verification process 400 enables a verifier that may require very low latency token authentication to verify the authenticity of the first party token in a predefined time, such as under 100 milliseconds.
[0050] FIG. 6 shows an exemplary computer system 600 (including components such as client computing system 105, issuer computing system 115, token signer component 120 and cryptographic key component 125, verifier computing system 140, token verifier component 145 and decryption key component 150, and key manager computing system and its components) that can be employed to implement any of the computer systems discussed herein according to some implementations. The computer system 600 can be used to provide information via network 110, content item network 155, or key distribution infrastructure 135 for display. The computer system 600 of FIG. 6 includes one or more processors 620 communicatively coupled to a memory 625, one or more communication interfaces 605, and one or more output devices 610 (e.g., one or more display units) and one or more input devices 615. The processor 620 can be included in the client computing system 115. The processor 620 can be included in the issuer computing system 115, or other components of the issuer computing system 115 such as the token signer component 120 and the cryptographic key component 125. The processor 620 can be included in the verifier computing system 140, or other components of the verifier computing system 140 such as the token verifier component 145 and the decryption key component 150. The processor 620 can be included in the key manager computing system 130, or other components of the key manager computing system 130 such as the key management service 205.
[0051] In the computer system 600 of FIG. 6, the memory 625 may comprise any computer-readable storage medium and may store computer instructions, such as processor-executable instructions for implementing the various functions described herein for each system, as well as any associated data generated thereby or received via a communication interface or input device (if present). Referring to the key manager computing system 130 of FIG. 2, the key manager computing system 130 may include, among other things, a memory 625 for storing information related to the prover cryptographic key 220 and the prover decryption key 225. The processor 620 shown in FIG. 6 is used to execute the instructions stored in the memory 625, and may also read from or write to the memory various information processed and / or generated in accordance with the execution of the instructions.
[0052] The processor 620 of the computer system 600 shown in FIG. 6 may also be communicatively coupled to a communication interface 605 and may control the communication interface 605 to transmit or receive various information in accordance with the execution of instructions. For example, the communication interface 605 may be coupled to a wired or wireless network, a bus, or other communication means, thus enabling the computer system 600 to transmit information to or receive information from other devices (e.g., other computer systems). Although not explicitly shown in the system of FIG. 6, one or more communication interfaces facilitate the flow of information between the components of the system 600. In some implementations, the communication interface may be configured to provide a website as an access portal to at least some aspects of the computer system 600 (e.g., via various hardware or software components). Examples of the communication interface 605 include a user interface (e.g., a web page) through which a user can communicate with the data processing system 600.
[0053] The output device 610 of the computer system 600 shown in FIG. 6 can be provided, for example, to enable viewing or otherwise perceiving various information related to the execution of instructions. The input device 615 can be provided, for example, to enable a user to make manual adjustments, make selections, input data, or interact with the processor in any of various ways during the execution of instructions. Additional information regarding general computer system architectures that can be used in the various systems discussed herein is further provided herein.
[0054] The implementations of the subject matter and the operations described in this specification can be implemented in digital electronic circuitry, or in tangible media including the structures disclosed in this specification and their structural equivalents, firmware, or software on a hardware, or in combinations of one or more of them. The implementations of the subject matter described in this specification can be implemented as one or more computer programs, i.e., as one or more components of one or more computer program instructions, encoded on a computer storage medium for execution by, or to control the operation of, a data processing apparatus. The program instructions can be encoded in an artificially generated propagated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal generated to encode information for transmission to a suitable receiver apparatus for execution by a data processing apparatus. The computer storage medium can be, or can be included in, a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination of one or more of them. Further, the computer storage medium is not a propagated signal, but the computer storage medium can include the source or destination of computer program instructions encoded in an artificially generated propagated signal. The computer storage medium can also be, or can be included in, one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices).
[0055] The functions disclosed herein can be implemented on a smart TV module (or a connected TV module, hybrid TV module, etc.), and may include a processing module configured to integrate an Internet connection with more traditional TV program sources (e.g., received via cable, satellite, wireless, or other signals). The smart TV module may be physically incorporated into the TV, or may include a separate device such as a set-top box, Blu-ray or other digital media player, game console, hotel TV system, and other companion devices. The smart TV module may be configured to allow viewers to search for and discover videos, movies, photos, and other content stored on the web, local cable TV channels, satellite TV channels, or local hard drives. A set-top box (STB) or set-top unit (STU) includes a tuner, can be connected to a TV set and an external signal source, converts the signal into content, and may include an information device device on which the content is then displayed on a TV screen or other display device. The smart TV module may be configured to provide a home screen or top-level screen that includes icons for a plurality of different applications, such as a web browser and a plurality of streaming media services, a connected cable or satellite media source, other web "channels", etc. The smart TV module may be further configured to provide an electronic program guide to the user. Companion applications to the smart TV module are operable on a mobile computing device to provide additional information about available programs to the user and to allow the user to control the smart TV module. In an alternative implementation, this functionality may be implemented on a laptop computer or other personal computer, smartphone, other mobile phone, handheld computer, tablet PC, or other computing device.
[0056] The operations described in this specification can be implemented as operations executed by a data processing apparatus on data stored in one or more computer-readable storage devices or received from other sources.
[0057] The terms "data processing apparatus", "data processing system", "user device" or "computing device" include, by way of example, any kind of apparatus, device, and machine for processing data, including the programmable processors, computers, system-on-chips, or multiple processors, or combinations thereof, described above. The apparatus can include, for example, dedicated logic circuits such as FPGAs (Field Programmable Gate Arrays) or ASICs (Application Specific Integrated Circuits). The apparatus can also include, in addition to the hardware, code that creates an execution environment for the relevant computer program, such as processor firmware, protocol stack, database management system, operating system, cross-platform runtime environment, virtual machine, or code that constitutes one or more combinations thereof. The apparatus and execution environment can implement various different computing model infrastructures such as web services, distributed computing, and grid computing infrastructures. The content request component, content selection component, and attribute component can include or share one or more data processing apparatuses, computing devices, or processors.
[0058] A computer program (also known as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and can be deployed in any form, such as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program does not necessarily have to, but can correspond to a file in a file system. The program can be stored as part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), a single file dedicated to the relevant program, or multiple coordinated files (e.g., files that store one or more modules, subprograms, or portions of code). A computer program can be deployed to be executed on one computer or on multiple computers located at one site or distributed across multiple sites and interconnected by a communication network.
[0059] The processes and logical flows described herein can be executed by one or more programmable processors that execute one or more computer programs to perform actions by operating on input data to generate output. The processes and logical flows can also be executed by, and embodied as, special purpose logic circuits, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit).
[0060] Processors suitable for the execution of a computer program include, by way of example, both general and special purpose microprocessors, as well as any one or more processors of any kind of digital computer. In general, a processor receives instructions and data from a read only memory or a random access memory or both. Essential elements of a computer are a processor for performing actions in accordance with instructions and one or more memory devices for storing the instructions and data. In general, a computer also includes or is operatively coupled to one or more mass storage devices for storing data, such as, for example, magnetic, magneto-optical disks, or optical disks, for receiving data therefrom, or for transferring data thereto, or both. However, a computer need not have such devices. Further, a computer can be incorporated in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device (e.g., a universal serial bus (USB) flash drive). Devices suitable for storing computer program instructions and data include, for example, semiconductor memory devices such as EPROM, EEPROM, and flash memory devices, magnetic disks such as internal hard disks or removable disks, magneto-optical disks, and all forms of nonvolatile memory, media, and memory devices including CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented or incorporated by dedicated logic circuitry.
[0061] To provide for interaction with a user, implementations of the subject matter described herein can be implemented on a computer having a display device, such as a CRT (cathode ray tube), plasma, or LCD (liquid crystal display) monitor for displaying information to the user, a keyboard with which the user can provide input to the computer, and a pointing device, such as a mouse or trackball. Other kinds of devices can be used to provide for interaction with a user as well, for example, feedback provided to the user can include any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback, and input received from the user can be in any form including acoustic, speech, or tactile input. Further, the computer can interact with the user by sending and receiving documents between the devices used by the user, for example, by sending a web page to a web browser of the user's client device in response to a request received from the web browser.
[0062] Implementations of the subject matter described herein can be implemented in a computing system that includes a back-end component, such as a data server, or includes a middleware component, such as an application server, or includes a front-end component, such as a client computer having a graphical user interface or a web browser through which a user can interact with an implementation of the subject matter described herein, or in any combination of one or more such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication, such as a communication network. Examples of communication networks include local area networks (“LANs”) and wide area networks (“WANs”), the Internet (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks).
[0063] Computing systems such as the issuer computing system 115, the verifier computing system 140, the client computing system 105, and the key manager computing system 130 can include clients and servers. For example, the issuer computing system 115, the verifier computing system 140, the client computing system 105, and the key manager computing system 130 can include one or more servers in one or more data centers or server farms. The client and server are typically remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs that run on their respective computers and have a client-server relationship with each other. In some implementations, the server sends data (e.g., an HTML page) to the client device (e.g., for the purpose of displaying the data and receiving user input from a user interacting with the client device). Data generated at the client device (e.g., the result of a user interaction) can be received at the server from the client device.
[0064] This specification includes details of many specific implementations, which should not be construed as limitations on the scope of the invention or what may be claimed, but rather as descriptions of features specific to particular implementations of the systems and methods described herein. The specific features described in the context of individual implementations herein may also be implemented in combination within a single implementation. Conversely, the various features described in the context of a single implementation may also be implemented individually in multiple implementations or in any suitable sub-combination. Additionally, although features are described above as operating in a particular combination and initially claimed as such, one or more features from the claimed combination may in some cases be excluded from the combination, and the claimed combination may be directed to a sub-combination or variation of a sub-combination.
[0065] Similarly, although operations are shown in the drawings in a particular order, it should not be understood that such operations must be performed in that particular order or in a sequential order, or that all of the illustrated operations are required to achieve a desirable result. In some cases, the actions recited in the claims may be performed in a different order and still achieve a desirable result. Additionally, the processes shown in the accompanying drawings do not necessarily require the particular or sequential order shown to achieve a desirable result.
[0066] In certain situations, multitasking and parallel processing may be advantageous. Further, the separation of the various system components in the implementation forms described above should not be understood as being required in all implementation forms, and it should be understood that the program components and systems described can generally be integrated into a single software product or packaged into multiple software products. For example, the token signer component 120 and the cryptographic key component 125 can be part of the issuer computing system 115, a single module, a logical device having one or more processing modules, one or more servers, or part of a search engine.
[0067] Here, although some exemplary implementation forms and implementation forms have been described, the foregoing is illustrative rather than limiting, and it is clear that it has been presented as an example. In particular, many of the examples presented herein involve specific combinations of method acts or system elements, but those acts and those elements can be combined in other ways to achieve the same purpose. Acts, elements, and functions described only in relation to one implementation form are not intended to be excluded from other implementation forms or similar roles in implementation forms.
[0068] The syntax and terminology used herein are for the purpose of description and should not be regarded as limiting. The terms "including", "comprising", "having", "containing", "involving", "characterized by", "characterized in that" and their variations herein mean including the items listed thereafter, their equivalents, and additional items, as well as alternative implementation forms consisting of the items listed exclusively thereafter. In one implementation form, the systems and methods described herein consist of one, two or more, or all of the elements, acts, or components described.
[0069] References to implementations or elements or acts of systems and methods referred to in the singular in this specification can also include implementations that include multiple elements of these, and references in the plural to any implementation or element or act in this specification can also encompass implementations that include only a single element. References in the singular or plural are not intended to limit the presently disclosed systems or methods, their components, acts, or elements to a single or multiple configurations. References to acts or elements based on information, acts, or elements can include implementations in which the act or element is at least partially based on the information, act, or element.
[0070] The implementations disclosed in this specification can be combined with other implementations, and references to "an implementation", "some implementation", "an alternate implementation", "various implementation", "one implementation", etc. are not necessarily mutually exclusive, and are intended to indicate that the particular functions, structures, or characteristics described in connection with the implementation can be included in at least one implementation. Such terms used in this specification do not necessarily all refer to the same implementation. Any implementation can be combined, inclusively or exclusively, with any other implementation in any way consistent with the aspects and implementations disclosed in this specification.
[0071] References to "or" can be interpreted as inclusive such that any term described using "or" can indicate any of the single, plural, and all of the terms being described.
[0072] If reference signs are attached after a technical feature in the drawings, the detailed description, or any claim, the reference signs are included only for the purpose of enhancing the clarity of the drawings, the detailed description, and the claims. Therefore, neither the reference signs nor their absence shall have a limiting effect on the scope of the elements of the claims.
[0073] The systems and methods described herein can be implemented in other specific forms without departing from their characteristics. The examples provided herein relate to controlling the display of the content of information resources, but the systems and methods described herein can include being applied to other environments. The foregoing implementations are not limiting of the described systems and methods, but are illustrative. Therefore, the scope of the systems and methods described herein is indicated by the appended patent claims rather than the foregoing description, and changes that fall within the meaning and equivalent scope of the patent claims are included therein.
Description of Reference Signs
[0074] 100 Environment 105 Client Computing System 110 Network 115 Issuer Computing System 120 Token Signer Component 125 Encryption Key Component 130 Key Manager 130 Key Manager Computing System 135 Key Distribution Infrastructure 135 Key Distribution Infrastructure Network 140 Verifier Computing System 145 Token Verifier Component 150 Decryption Key Component 155 Content Item Network 205 Key Management Service 210 Token Signer Binary 215 Token Verifier Binary 220 Verifier's cryptographic key 225 Verifier's decryption key 300 Process 400 Process 600 Computer system 600 Data processing system 605 Communication interface 610 Output device 615 Input device 620 Processor 625 Memory
Claims
1. A method comprising: receiving, by a first server, data identifying device information of the client device from the client device; digitally signing, by the first server, the data using a private key of the first server to create a digitally signed token; encrypting, by the first server, multiple instances of the digitally signed token to create multiple encrypted versions of the digitally signed token, wherein different instances of the encrypted versions of the digitally signed token are each encrypted with a different public key of a different third-party server; generating, by the first server, a composite token comprising the multiple encrypted versions of the digitally signed token; transmitting, by the first server, the composite token comprising the multiple encrypted versions of the digitally signed token to the client device and including a method.
2. The method according to claim 1, wherein the data includes a first-party token generated by the client device.
3. The method according to claim 2, wherein the first-party token is associated with the domain of the first server.
4. The method according to claim 2, wherein the first-party token is generated based at least in part on browser information associated with the client device.
5. The method according to claim 2, wherein the data further includes a timestamp corresponding to the first-party token generated by the client device.
6. The method according to claim 5, wherein the timestamp includes at least a 64-bit high-resolution timestamp.
7. A system comprising: receiving, by a first server, data identifying device information of the client device from the client device; digitally signing, by the first server, the data using a private key of the first server to create a digitally signed token; To create a plurality of encrypted versions of the digital signature token, the first server encrypts a plurality of instances of the digital signature token, wherein different instances of the encrypted versions of the digital signature token are each encrypted with a different public key of a different third-party server; generating, by the first server, a composite token including the plurality of encrypted versions of the digital signature token; transmitting, by the first server, the composite token including the plurality of encrypted versions of the digital signature token to the client device; A system comprising one or more hardware processors configured to perform the above. The system according to claim 7, wherein the data includes a first-party token generated by the client device. The system according to claim 8, wherein the first-party token is associated with the domain of the first server. The system according to claim 8, wherein the first-party token is generated based at least in part on browser information associated with the client device. The system according to claim 8, wherein the data further includes a timestamp corresponding to the first-party token generated by the client device. The system according to claim 11, wherein the timestamp includes at least a 64-bit high-resolution timestamp. A method comprising: receiving, by a verifier, a composite token and a timestamp, wherein the composite token includes a plurality of encrypted versions of a digital signature token; determining, by the verifier, one of the plurality of encrypted versions of the digital signature token corresponding to the verifier; decrypting, by the verifier, the determined encrypted version of the digital signature token corresponding to the verifier using the private key of the verifier; To generate a first-party token, verifying, by the verifier, the validity of the digital signature of the digitally signed token using the public key corresponding to the first server; processing, by the verifier, the first-party token; A method comprising: **Claim 14** The step of determining, by the verifier, one of the plurality of encrypted versions of the digitally signed token corresponding to the verifier includes: enumerating two or more of the plurality of encrypted versions of the digitally signed token within the composite token; The method according to claim 13, comprising: **Claim 15** The step of receiving, by the verifier, the composite token and the timestamp includes receiving at least a 64-bit high-resolution timestamp. The method according to claim 13. **Claim 16** The method according to claim 13, wherein the first-party token includes a valid first-party device token. **Claim 17** The method according to claim 13, wherein the first-party token includes a valid first-party browser token. **Claim 18** To generate a first-party token, the step of verifying, by the verifier, the validity of the digital signature of the digitally signed token using the public key corresponding to the first server includes: comparing the digitally signed token and the timestamp with the unencrypted token within the composite token; The method according to claim 13, comprising: **Claim 19** To generate a first-party token, the step of verifying, by the verifier, the validity of the digital signature of the digitally signed token using the public key corresponding to the first server includes: comparing the timestamp of the composite token with the timestamp of the digitally signed token; The method according to claim 13, comprising: **Claim 20** A system, comprising: receiving, by a verifier, a composite token and a timestamp, wherein the composite token includes a plurality of encrypted versions of a digitally signed token; The verifier determines one of the plurality of encrypted versions of the digitally signed token corresponding to the verifier; The verifier uses the private key of the verifier to decrypt the encrypted version of the digitally signed token corresponding to the determined verifier; To verify the validity of the digital signature of the digitally signed token by the verifier using the public key corresponding to the first server to generate a first party token; The verifier processes the first party token A system comprising one or more hardware processors configured to perform.
Citation Information
Patent Citations
Enciphering device, decoding device, information sharing device, enciphering method, decoding method, information processing method, and recording medium
JP1999143359A
Electronic signature system, electronic signature method, and electronic signature program
JP2014022920A
Multi-Factor Zero-Knowledge Authentication Using Pairing
JP2016526342A