Method for providing subscriber data from a first service provider network and method for receiving content at an authenticatable subscriber device - Patents.com

The method employs network identifiers in secure network requests to provide subscriber data to external entities, addressing the challenge of maintaining privacy and security in telecommunications networks by ensuring network requests remain inaccessible to the service provider network.

JP7807233B2Active Publication Date: 2026-01-27NOVATIQ TECHNOLOGIES LIMITED
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021529749
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-01-14
Filing Date
2021-01-14
Publication Date
2026-01-27
Estimated Expiration
2041-01-14

AI Technical Summary

Technical Problem

Existing methods in telecommunications networks do not effectively enable the provision of subscriber data to entities outside the service provider network without exposing the subscriber's identity or allowing network requests to be accessible to the service provider network.

Method used

A method involving the use of network identifiers generated by the subscriber device, which are included in secure network requests, allowing the service provider network to provide subscriber data to external entities while maintaining privacy and ensuring the network requests remain inaccessible to the service provider network.

Benefits of technology

Enables the secure provision of subscriber data to external entities without revealing the subscriber's identity, while ensuring that network requests remain confidential within the service provider network, thus enhancing privacy and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007807233000001
    Figure 0007807233000001
  • Figure 0007807233000002
    Figure 0007807233000002
  • Figure 0007807233000003
    Figure 0007807233000003
Patent Text Reader

Abstract

Data provided by service provider networks A method for providing subscriber data from a first service provider network to a content provider external to the service provider network includes receiving a first network identifier transmitted from a subscriber device authenticated to communicate through the first service provider network, the first network identifier being transmitted by the subscriber device in a first message to an entity external to the service provider network, receiving a second network identifier transmitted from the subscriber device to the first service provider network, performing a verification process using the first network identifier and the second network identifier to verify whether subscriber data stored in the service provider network is allowable to be provided to the content provider external to the service provider network, and providing the subscriber data to the entity external to the service provider network in response to a successful verification process. In response to a successful verification process, the subscriber data is provided to the entity external to the service provider network.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to network communications, and in particular, but not exclusively, to the processing of network requests in telecommunications networks to enable the provision of data. [Background technology]

[0002] Users wishing to access data stored at remote locations and / or remote computer-implemented services typically do so through a telecommunications network, such as the Internet. To send and receive data over the telecommunications network, users traditionally subscribe to telecommunications services offered by a telecommunications service provider. Telecommunications services typically provide access to a broader telecommunications network for a specific subscriber device, a group of subscriber devices, or a residential or commercial network associated with a specific subscriber. A service provider network typically includes a routing fabric for performing subscriber authentication and routing traffic between authenticated subscribers and the broader telecommunications network. A service provider may consist of a telecommunications operator, a mobile network operator (MNO), a wireless network operator, or an Internet service provider (ISP). Subscriber devices may include personal computers, laptop computers, mobile phones (including "smartphones"), tablet computers, personal digital assistants, smart TVs, etc.

[0003] FIG. 1 illustrates a simplified example of a telecommunications network 100. A subscriber device 102 may initially access a service provider network 110 of the telecommunications network 100, which includes various entities provisioned by the service provider. The service provider network 110 for a carrier or mobile network operator may include at least one of a Global System for Mobile Communications (GSM) network and a Universal Mobile Telecommunications System (UMTS) network, such as an implementation of the Long Term Evolution (LTE) standard. In certain cases, the service provider network 110 may include a radio access network and a core network, coupled by one or more service edge components. The radio access network may include one or more base stations (e.g., Node B—NB—or enhanced Node B—eNB). User equipment (e.g., mobile phones, so-called smartphones, laptops, tablets, etc.) can connect to the core network via the radio access network. The core network may include a serving gateway, a packet data network gateway, and a gateway general packet radio service (GPRS) support node. User equipment can connect to other public packet-switched networks, such as the Internet, through a service provider's core network. The service provider entity may be responsible for subscriber / subscriber device authentication, access management, billing, etc. This may be performed in conjunction with a home subscriber server or user profile server function (or authentication center in GSM) within the service provider network 110. In this way, the service provider network 110 typically acts as a gateway between the subscriber device 102 and a wider network 106, such as the public Internet. The wider network 106 is used, at least in part, to route data between the service provider network 110 and one or more server devices 108.

[0004] Telecommunications network 100 may also include several further network portions (not shown) and several border / gateway / caching entities (not shown) used to translate between the various network protocols used in each network portion as needed, cache and serve commonly accessed data to reduce load between the network portions, and / or manage access to each network portion.

[0005] Access to data and / or computer-implemented services over the telecommunications network 100 is typically enabled using browser software or other applications (hereinafter "browser") on the subscriber device 102. Other applications on the subscriber device 102 may include games or software utilities that also require access to content over the telecommunications network 100. For example, some applications generate revenue by displaying content to users. Such content is typically updated periodically and hosted on server devices within the telecommunications network 100. Thus, an application may require access to the server devices over the telecommunications network 100 to obtain the latest content for display to its users.

[0006] A browser enables a subscriber device 102 to participate in a browser session, which includes a series of one or more requests and responses made to and received from one or more remote entities, such as a server device 108, over the communications network 100. A browser can be used to display web pages, retrieve files, and perform services such as instant messaging over the communications network 100. The requests and responses of a browser session typically consist of one or more data packets. Such packetized data is formatted and transferred according to one or more network protocols used in a particular portion of the network.

[0007] Some browser sessions may include a series of multiple browser session requests and browser session responses. This is true, for example, when a subscriber sequentially browses multiple web pages in a particular browser session. Displaying a single web page often requires a series of multiple requests and responses. This is particularly true when different elements of the web page are hosted on different server entities and / or when the web page or service is dynamically implemented, e.g., when HyperText Markup Language (HTML) data is generated in real time by the server device 108 upon receipt of a request using one or more server functions. A common example occurs when a web page includes one or more advertising elements.

[0008] 1B , the service provider network 110 comprises an intermediate network device 111 that is the first entity introduced in the service provider network 110 between the subscriber device 102 and the wider network portion 106. The intermediate network device 111 may be physically located in the service provider network 110, or may be logically located in the service provider network 110 but physically located / hosted elsewhere, for example, by using a virtual or backhaul private network. The service provider network 110 may be adapted to route browser session traffic between the subscriber device 102 and the wider network portion 106 through the intermediate network device 111.

[0009] 1B, network requests sent from subscriber devices to the service provider network 110 are accessible by the service provider network 110, i.e., intermediate network device 111. For example, a network request sent from a subscriber device 102 may include an HTTP request, which may be directed to the service provider network 110 or may be directed elsewhere in the network 100 but routed through the service provider network 110. Because the service provider network 110 can read such network requests, in such an example, the intermediate network device 111 may modify the browser session request or browser session response it receives. This modification of the network request may include, for example, adding a network identifier to the network request before sending the modified request to the server device 108 or another entity outside the service provider network 110.

[0010] In the example, the network identifier added to the browser request modified by the intermediate network device 111 is sent to the server device 108, thereby causing the server device 108 to obtain the network identifier. The network identifier functions to authenticate subsequent communications between the server device 108 and the service provider network 110. For example, the server device 108 can send a subsequent network request including the network identifier to the service provider network 110, and the service provider network 110 can be configured to verify the returned network identifier. The service provider network 110 can be configured to perform an action contingent on the verification. In the example of FIG. 1B , the service provider network further includes a second entity, the data broker 114, configured to receive and process requests from the server device 108. The data broker 114 can receive the network identifier sent to the server device 108, perform a verification process, and perform an action, such as providing subscriber data to the server device 108, if the network identifier is successfully verified.

[0011] While the above examples outline methods and systems for handling browser sessions over telecommunications networks, it is an object of the present invention to provide improved methods and systems for communicating over telecommunications networks. Summary of the Invention

[0012] According to a first aspect of the present invention, there is provided a method for providing subscriber data from a first service provider network to a content provider external to the service provider network, as set forth in claim 1.

[0013] According to a second aspect of the present invention, there is provided a method for receiving content on a subscriber device that can be authenticated for communication via a first service provider network, as set forth in claim 11.

[0014] According to a third aspect of the present invention, there is provided a set of machine-readable instructions which, when executed by an apparatus, causes the apparatus to carry out a method according to the first aspect of the present invention.

[0015] According to a fourth aspect of the present invention, there is provided a set of machine-readable instructions which, when executed by a subscriber device, causes the device to carry out a method according to the second aspect of the present invention.

[0016] According to a fifth aspect of the present invention there is provided a non-transitory computer readable medium comprising a set of computer readable instructions according to the third or fourth aspect stored thereon.

[0017] According to a sixth aspect of the present invention, there is provided an apparatus configured to carry out a method according to the first aspect of the present invention.

[0018] According to a seventh aspect of the present invention, there is provided a subscriber device comprising a set of machine-readable instructions according to the fourth aspect of the present invention.

[0019] Further examples and variations of the above aspects of the invention are set out in the dependent claims.

[0020] Further features and advantages of the present invention will become apparent from the following description of preferred embodiments of the invention, given by way of example only, made with reference to the accompanying drawings. [Brief explanation of the drawings]

[0021] [Figure 1] 1A and 1B are schematic system diagrams illustrating a prior art telecommunications system. [Figure 2] FIG. 2 is a schematic system diagram illustrating components of an example telecommunications system. [Figure 3] FIG. 3 is a flow diagram illustrating a method of operation of a network according to an example. [Figure 4] FIG. 4 is a flow diagram illustrating further details of an exemplary method of operation of the network according to the example of FIG. [Figure 5] FIG. 5 is a flowchart illustrating an exemplary method according to the present disclosure. [Figure 6] FIG. 6 is a flowchart illustrating an exemplary method according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0022] Certain examples described herein enable subscriber data stored in a service provider network to be provided to an entity outside the service provider network. In certain examples, the subscriber data may be provided to an entity outside the service provider network without providing the subscriber's identity to the device. The entity outside the service provider network may be, for example, a content provider, such as a server device that performs the functionality of an advertising platform. The entity may, for example, respond to a request from a subscriber device or make a request based on such a request from the subscriber device. In certain examples, the methods described herein enable a service provider network to provide subscriber data to an entity outside the service provider network, such as a content provider, without the network request being accessible, e.g., readable, from the service provider network, even when the network request is sent from the subscriber device. For example, the network request may be received from the subscriber device at an entity outside the service provider network via a secure communication channel, e.g., via an HTTPS message.

[0023] A particular example described herein uses a network identifier inserted by the subscriber device in a network request sent by the subscriber device, which may include a random string of characters, e.g., alphanumeric characters, that does not itself constitute data obtained from within the service provider network.

[0024] FIG. 2 illustrates a telecommunications network 100 according to an example of the present disclosure. The telecommunications network 100 includes at least a service provider network 110 and a broader network portion 106. The telecommunications network 100 may further include additional network portions (not shown) and / or border / gateway / caching entities (not shown) for translating between various network protocols used in each network portion, caching and serving commonly accessed data, and / or managing access to each network portion to reduce load between the network portions. The telecommunications network 100 may include features as described with reference to FIGS. 1A and 1B. The service provider network 110 is responsible for providing telecommunications services to multiple subscriber devices, including at least a subscriber device 102. The subscriber device may be configured to communicate voice and data. Examples of subscriber devices may include personal computers, laptop computers, mobile phones (including "smartphones"), tablet computers, personal digital assistants, smart TVs, etc.

[0025] The telecommunications network 100 includes a content server 150 that is external to the service provider network 110. The content server 150 is in communication with a subscriber device 102, and the content server 150 and the subscriber device 102 exchange network requests and responses so that content is provided to the subscriber device 102. In this example, the network requests and responses between the subscriber device 102 and the content server 150 are communicated via the service provider network 110 and a wider network 106 (which may be, for example, the Internet). The subscriber device 102 may exchange browser session traffic with the content server 150 to, for example, receive web page content from the content server 150. In some cases, the network requests may not be browser-based and may relate, for example, to voice and / or data requests processed by the service provider network; location requests to a positioning system; and / or network requests sent by one or more applications or operating systems of the subscriber device 102, among others. The network requests, in one implementation, may include HTTPS requests sent between two entities within the network 100. Thus, a browser session may constitute an HTTPS session. An HTTPS request may include a call with a GET or POST method. In other implementations, a network request may include packets of data sent by another application layer protocol or by another protocol in a network communications stack.

[0026] The service provider network 110 includes an intermediate network device 111 and a data broker 114. In the example, the intermediate network device 111 receives network requests from a subscriber device 102, i.e., a subscriber device operated by a subscriber, where the subscriber and / or subscriber device is authenticated and authorized to use the service provider network 110.

[0027] In addition to the content server 150, the telecommunications network 100 includes further entities outside the service provider network. The network 100 comprises a first entity 120, a second entity 130, and a further entity 140, referred to in this example as a server 140.

[0028] In one example, intermediate network device 111 may include an additional server, or an adapted function of an existing server, coupled to or within the core network, where packet-based network traffic is routed through intermediate network device 111. In one case, intermediate network device 111 may include multiple servers in parallel, and a load balancing entity may be configured to receive network requests from client subscriber devices and distribute these network requests among the multiple servers. In one example, intermediate network device 111 may include a multi-core server blade including at least one processor and at least one memory.

[0029] The intermediate network device 111 is configured to process or route network requests, such as browser session traffic, as described above for the content server 150. In certain cases, the network request may relate to a portion of a requested web page. For example, it may be a request for content (e.g., advertising data / content) from an entity other than the entity providing the web page. That is, in this example, the intermediate network device 111 may route a network request for a first entity 120 from a subscriber device 102 requesting content from the first entity 120. The content requested by the device 102 from the first entity 120 may relate to content received from the content server 150. For example, the network request sent to the first entity 120 may include a request for a portion of a web page provided by the content server 150. In one example, the first entity 120 is an advertising entity, and the network request sent from the subscriber device 102 includes a request for an advertisement to be displayed with the content provided by the content server 150.

[0030] In an example, the subscriber device 102 and the first entity 120 communicate over a secure communication channel such that the intermediate network device 111 can route messages between the device 102 and the first entity 120 but cannot read the messages. For example, the subscriber device 102 and the first entity 120 can communicate by exchanging messages using a suitable secure Layer 7 communication protocol, e.g., HTTPS. Routing through the intermediate network device 111 described herein can be implemented using policy-based routing based on the IP address of the network request. Policy-based routing can be applied to predefined network traffic types (e.g., HTTPS only) and configured to route data through the IP address of the intermediate network device 111 and / or load balancers associated with multiple intermediate network devices. The intermediate network device 111 can operate as a transparent proxy in network communications. The intermediate network device 111 can be configured using a managed network within the service provider network 104.

[0031] The data broker 114 may comprise a server, i.e., a computing device configured to process computer program code that implements server functionality, adapted to access subscriber data stored in data storage 113 accessible to the service provider network 110. In some examples, the data storage 113 is located within the service provider network 110; in other examples, the data storage 113 is located outside the service provider network 110 but is accessible only by the service provider network 110, e.g., via secure communications between the data broker 114 and the data storage 113. In examples, the data broker 114 is securely coupled to the service provider network 110, e.g., via a virtual or backhaul private network, and is also accessible from outside the service provider network 110, e.g., via an Internet connection and / or a public IP address or uniform resource locator. The data broker 114 is communicatively coupled to a server 140 outside the service provider network 110. In examples, the data broker 114 and the server 140 are communicatively coupled via the wider network 106. Server 140 may be a cloud-based server. Data broker 114 may have a trust relationship with server 140 and may communicate with server 140, for example, via a secure communication channel. Like intermediate network device 111, data broker 114 may be implemented in one or more server devices, for example, multi-core server blades including at least one processor and at least one memory. Such server devices may implement one or more operating systems, for example, a Linux®-based operating system, one or more web servers, and one or more data storage management systems.

[0032] According to an example, the service provider network 110 includes a carrier network operated by a carrier. The carrier network may provide wired and / or wireless network access. According to an example, the service provider network 110 comprises a mobile network (which may be in the form of a cellular network) operated by a mobile network operator (MNO). The mobile network operator provides wireless network access, for example, via a radio access network and a core network, as described above. According to an example, the service provider network 110 includes an internet service provider network operated by an internet service provider (ISP). The ISP may provide wired network access, for example, via dial-up, (asymmetric) digital subscriber line, cable modem, integrated services digital network, and / or fiber optic line. The carrier network may include a mobile network and / or an ISP. In certain cases, the service provider network 110 may alternatively or additionally provide telecommunications services in the form of wireless network (e.g., "Wi-Fi") access to at least one subscriber device 102. This may occur instead of or in addition to mobile access (e.g., by an MNO) and / or ISP functionality. The wider network portion 106 is responsible for routing traffic (e.g., packetized data traffic encoded in the Hypertext Transfer Protocol (HTTP) or a secure extension of HTTP such as HTTPS) between one or more entities accessible via the wider network portion 106, e.g., between a first entity 120 and a second entity 130. The wider network portion may also route traffic to a server 140, the functionality of which is discussed in more detail below. If the service provider network 110 is an MNO, the data broker 114 may be a telephony application server (TAS).

[0033] 3 illustrates an exemplary method of the network 100 in the context of a usage session taking place at a subscriber device 102. The subscriber device 102 of FIG. 3 is in a usage session in which browser requests are sent to and received from a content server 150, as in the example described above with reference to FIG. 2. At action 3a, the subscriber device 102 receives a network response from the content server 150. For example, the network response may be a web page received as an HTTP or HTTPS message from the content server 150. For clarity, the content server 150 is shown to the left of the subscriber device 102 in FIG. 3, but in this example, messages between the content server 150 and the subscriber device 102 are transmitted over the service provider network 110, as described with respect to FIG. 2.

[0034] The network response received by the device 102 from the content server 150 in action 3a includes, in this example, content, such as web page content, as well as a set of machine-readable instructions for execution by the subscriber device. The machine-readable instructions, in one example, may include a portion of JavaScript included in the network response, e.g., an HTTP or HTTPS response, which, when executed by a processor (not shown) of the subscriber device 102, causes the method described herein to be performed by the subscriber device 102. In this example, the subscriber device in action 3a receives the machine-readable instructions from the content server 150 via the service provider network 110.

[0035] In block 311, upon execution of the instructions by the subscriber device 102, the subscriber device 102 is caused to generate a first network request to send to an entity external to the service provider network, in this example, the first entity 120. The first network request may be a browser request for a portion of a web page, e.g., a request for an advertisement to be rendered on the web page received from the content server 150. In this example, the subscriber device 102 is configured to communicate with the first entity 120 over a secure communication channel, e.g., via HTTPS messages. Because the first network request is sent over the secure communication channel between the subscriber device 102 and the first entity 120, the service provider network 110 cannot read the first network request, even though the first network request is routed through the service provider network 110. Thus, the service provider network 110 cannot modify the first network request.

[0036] The set of instructions executed in block 311 enable the service provider network to provide the client device 102 with a network response that is contingent on subscriber data stored in the service provider network 110 without modifying the first network request. That is, in addition to causing the generation of the first network request, the set of instructions when executed in block 311 cause the subscriber device 102 to generate first and second network identifiers. Execution of the instructions causes the first network identifier to be included in the first network request sent from the subscriber device 102 to the first entity 120 in action 3b. Execution of the instructions also causes the second network identifier to be included in the second network request sent to the service provider network in action 3e, which is readable by the service provider network 110 and makes the second network identifier accessible to the service provider network 110. The first network identifier and the second network identifier are configured to be used in performing a verification process to verify that subscriber data associated with the subscriber device and stored in the service provider network is acceptable for provision to an entity of network 100 external to service provider network 110, such as a content provider, such as second entity 130.

[0037] In some examples, the first and second network identifiers are created as identical copies of each other. In other examples, the first and second network identifiers may be different from each other but may be configured to be compared or verified with each other.

[0038] A network identifier includes any data, e.g., in the form of a token, used to link a network request to the subscriber device 102 or a particular request sent therefrom. In some cases, the network identifier may include a series of characters from a character encoding scheme, e.g., American Standard Code for Information Interchange (ASCII). The network identifier may be of a predefined length, e.g., a defined number of characters. The predefined length is configurable, e.g., based on estimated network request load. If the network request includes an HTTPS request, the network identifier may be inserted into a Uniform Resource Locator (URL) by the subscriber device requesting the network, e.g., as a parameter value in the query string " / serverdevice / resource.html?nid=d5VWn9LKoz." Alternatively and / or additionally, the network identifier may be added to the HTTPS request as a request header field, e.g., as the value of a standard or non-standard request field such as "X-NID:d5VWn9LKoz." In some cases, the network identifier may be inserted into a user-agent field, e.g., a mutable user-agent field of the HTTPS request. In other examples, the network identifier may be transmitted by any suitable means that allows for linking the network identifier to the associated network request. In examples, the network identifier transmitted from the subscriber device 102 does not include subscriber data, e.g., is not an encrypted version or hash of that data. This means that it cannot be used to track the subscriber. The hashed or encrypted version of the data has a set value for the set data item. For example, an age of "18" has the same encrypted or hashed value and can therefore be decoded.

[0039] In examples, the first and / or second network identifiers include universally unique identifiers (UUIDs). In some embodiments, each network identifier is generated based on high-quality randomness, for example, using Linux / Unix / dev / urandom data generation. In some embodiments, each network identifier is generated based on one or more of the current time, the local Ethernet Media Access Control (MAC) address, and data generated using a pseudo-random generator.

[0040] In some instances, when using quality randomization, there is no separable seed (such as time or MAC address). A sample log containing an exemplary network identifier is as follows:

[0041] [Thu Aug 20 19:27:20.338477 2015] [hee:trace2] [pid 2445:tid 140063197697792] mod_hee.c(3918): AH03067: sp_id=dbbd46fb-aabe-4be4-bad0-0ce6a428fbb0;

[0042] The components of the sample log above can be explained as follows: -[Thu Aug 20 2015 19:27:20.338477]=log entry time; -[hee:trace2] = verbosity level of the log. This part mentions the source of the entry, in this case from the engine itself (HEE). -[pid 2445:tid 140063197697792] = process ID (pid) and thread ID (tid); - mod_hee.c(3918):= The source file and line number where the log entry was triggered. -AH03067=Error (debug) code. -sp_id=dbbd46fb-aabe-4be4-bad0-0ce6a428fbb0 = The actual network identifier associated with the key named "sp_id".

[0043] Returning to FIG. 3 , at action 3b, the subscriber device 102 sends a first network request including a first network identifier to the first entity 120. The first network request including the first network identifier is sent through the service provider network 110, but in the example, is inaccessible by the service provider network 110. For example, the request may be sent over a secure communication channel between the device 102 and the first entity 120, as described above. The first network request in the example is, for example, a request for an advertisement as part of a web page being accessed in a browser session of the subscriber device 102. In this example, in response to receiving the first network request, the first entity 120 is configured to extract the first network identifier. That is, in the example, the first entity 120 receives the first network request for the first network identifier as an HTTPS message, configured to decrypt the message, and parses the first network request for the first network identifier. In an example where the first network request received from the subscriber device 102 is a request for an advertisement, the first entity 120 is an advertisement platform server, and the first entity 120 is a serving platform (SSP). The first entity 120 generates and sends a network request in block 321 to the second entity 130, requesting that the second entity 130 provide content to the first entity 120 in response to the first network request from the subscriber device 102. In an example, the second entity 130 is a demand-side platform (DSP). In this example, upon receiving the request for an advertisement, the SSP 120 generates a bid request to send to the DSP 130 to fulfill the original advertisement request from the device 102.In some examples, the SSP may send the request to multiple DSPs and may determine to which of the multiple DSPs to send the request for an advertisement depending, for example, on the content of the request for an advertisement received from the subscriber device 102. The first network identifier is included in the request for a network generated in block 321.

[0044] In action 3c, the first entity 120 sends a network request to the second entity 130, including the first network identifier generated in block 321. In this example, the network request sent from the SSP 120 to the second DSP 130 may be a real-time bidding (RTB) request. For example, details of the web page associated with the advertisement request and details of the advertisement, such as its location or size within the web page, may be provided to the second entity 130.

[0045] The second entity 130 is configured to provide a response to the request received from the first entity 120, and in an example, functions as a content provider for providing content to be transmitted to the subscriber device 102. In an example, the second entity 130 may process the network request received from the first entity 120 to determine an action to take. For example, if the received network request is a bid request, the second entity in block 322 may determine whether to send the network request to the server 140 to seek subscriber data that notifies that a bid has been placed in response to the bid request. In block 322, the second entity 130 may determine to obtain details about the subscriber device 102 and / or subscriber or user-related data related to the advertisement request. For example, the subscriber data may allow the second entity 130 to more accurately determine a price it is willing to pay to fulfill the advertisement request. However, neither the first entity 120 nor the second entity 130 is provided with the data originating from the service provider network 110 via the first network request, because at least the first network request is not accessible by the service provider network 110 and was sent by the subscriber device 102 via a secure connection to the first entity 120. Accordingly, to obtain such data, the second entity 130, in action 3d, requests subscriber data associated with the received network request from the server 140. The request for data may be a request for a portion of the subscriber data accessible by the service provider network 110. For example, the second entity 130 may request details of the subscriber's age and nationality. The second entity 130 includes a first network identifier with the request for subscriber data.

[0046] Returning to operation of the subscriber device 102 upon execution of the machine-readable instructions, in action 3e, the subscriber device 102 sends a second network request to the service provider network 110, the second network request including the second network identifier. In block 331, the service provider network 110 processes the received network request. In some examples, the second network request is a synchronization request, requesting synchronization of processing of the network request by the service provider network 110.

[0047] Referring now to FIG. 4, in block 331a, the intermediate network device 111 processes the received second network request and second network identifier. The second network request, including the second network identifier, is received at the intermediate network device 111 via a secure communication channel between the subscriber device 102 and the intermediate network device 111. The intermediate network device 111 may have means for decrypting the second network request and second network identifier, and performs this decryption in block 331a. In an example, the intermediate network device 111 possesses security credentials for reading the second network request received from the subscriber device 102 via HTTPS communication. In this example, in block 331a, the intermediate network device 111 obtains a subscriber identifier associated with the subscriber device 102, for example, by using network data accessible within the service provider network 110. For example, one or more of an International Portable Equipment Subscriber Identity and an International Mobile Equipment Identity number may be used as the subscriber identifier for determining the subscriber identity.

[0048] In action 4a, the intermediate network device 111 decodes the message received from the subscriber device in block 331a and sends a second network request including the second network identifier to the data broker 114. The intermediate network device 111 further sends the subscriber identifier obtained in block 331a to the data broker 114. In some examples, action 4a may include sending a message including the second network identifier, the second network request, and the subscriber identifier to the data broker 114. For example, such a message may be an Internet Content Application Protocol (ICAP) request. In other examples, the message may be an HTTP message, or in a further example, the message may be a User Datagram Protocol (UDP) request. In some examples, the method includes action 4b, in which the data broker 114 sends a response to the message received in action 4a. For example, if action 4a includes sending an ICAP request, action 4b includes sending a status response to the intermediate network device 111. In another example, action 4a includes sending an HTTP request, and action 4b includes sending an HTTP status response, e.g., HTTP status response 200, to the intermediate network device 111. In another example, for example, if action 4a includes sending a UDP request to the data broker 114, the data broker 114 may not send a response to the intermediate network device 111.

[0049] In an example where data broker 114 is configured to receive ICAP requests from intermediate network device 111, data broker 114 may include a segment cache, an ICAP router, and an ICAP server. In an example where data broker 114 is configured to receive HTTP or HTTPS requests from intermediate network device 111, data broker 114 may include a segment cache and an HTTP or HTTPS proxy server. In an example where data broker 114 is configured to receive UDP requests from intermediate network device 111, data broker 114 may include a segment cache, a UDP proxy server, and an HTTP proxy server.

[0050] At block 331b, the data broker 114 processes the request received from the intermediate network device 111. Thus, at block 331b, the data broker 114 receives a second network request including a subscriber identifier as well as a second network identifier. The data broker 114 is configured to use the subscriber identifier to obtain data from the service provider network 110 associated with the subscriber identifier. At action 4c, the data broker 114 submits a request for data associated with the subscriber identifier to the data storage 113 that includes the data from the service provider network 110.

[0051] The data storage device 113 is accessible to the data broker 114 from within the service provider network (but not from one or more public networks) and stores subscriber profile data including one or more pieces of information related to subscriber devices and information related to one or more subscribers. In this case, a subscriber identifier (e.g., an International Mobile Subscriber Identity Number) may be mapped to a user equipment identifier (e.g., an International Mobile Station Equipment Identity). For example, the mapping may consist of rows in a lookup table or equivalent pairings in an associative array. In this case, one or more data indexes may be used to identify data records within data originating from the service provider network. The data storage 113 may comprise a cache, random access memory, or a persistent storage device such as a magnetic hard disk or solid-state storage device.

[0052] In the examples herein, subscriber data within service provider network 110 may include any data accessible to service provider network 110, such as data stored in data storage 113. For example, it may consist of one or more of: personal information associated with the subscriber, such as name, date of birth, home or postal address, email address, International Mobile Subscriber Identity Number, gender, and employment details; information related to the subscriber device registered to the subscriber, such as make and model, device specifications and characteristics (storage capabilities, screen size, available memory, processor, etc.); network usage history, such as telephone call logs, short messaging service logs, and browser session logs (including URLs and subscriber search history); and geographic location data, such as records of base stations used to access the service provider network and / or global positioning system data transmitted by user equipment as part of the operation of the service provider network. Data originating from the service provider network may include one or more raw data and processed data. For example, in the latter case, the data may include the results of one or more processing and / or analytical functions, such as the results of behavioral profiling based on subscriber data. The data originating from the service provider network may further include one or more user-generated preferences, such as declared interest in one or more services offered by the server device 130 .

[0053] In action 4d, the data requested by the data broker 114 is returned from the data storage 113, providing the data broker 114 with the requested subscriber data associated with the subscriber identifier. Returning now to Figure 3, in block 331 the data broker 114 thus becomes in possession of the second network identifier, the subscriber identifier, and the subscriber data associated with that subscriber identifier.

[0054] According to some examples, block 331 further includes anonymizing the subscriber data, or a portion thereof, by the data broker 114. The anonymization may include processing the data originating from the service provider network so that a given data value can be applied to at least a (predefined) number of subscribers in the subscriber profile data storage. For example, a data value indicating a subscriber's gender may be considered an anonymized value because many other subscribers also share the same gender value. However, address data may not be considered anonymous. Thus, the anonymization process may include selecting the first m zip code values ​​of an address, e.g., to identify an anonymized region that may include many subscribers. If the data originating from the service provider network includes multiple different data items associated with a particular subscriber, the anonymization may include processing one or more of the data items so that a combined set of the data items applies to at most X% of subscribers. For example, a range of values ​​can be configured to anonymize a data item. For example, a date of birth may be shared by less than 1% of subscribers, while an age range can be configured to be shared by at least 15% of subscribers, where “15%” is considered to anonymize the subscriber. In this case, the start and end of the range may be provided as a data item by the data broker. In one case, anonymization may involve replacing a subscriber or subscriber device identifier with a data value, e.g., demographic information and / or device parameters that cannot be used to determine the identity of the subscriber and / or subscriber device. The anonymized data item may be stored in a lookup table along with the network identifier. In other cases, anonymization may be performed by the data broker 114 before transmission to the server device 108. In either case, anonymization may be performed before the data is transmitted over a public network.

[0055] In action 3f, service provider network 110, i.e., data broker 114 in this example, provides at least a portion of the subscriber data retrieved from data storage 113 and the second network identifier to server 140. In the example, server 140 and data broker 114 are configured to communicate with each other over a secure communication channel, for example, using HTTPS messages. The portion of the subscriber data is then sent as an HTTPS message in action 3f, with the second network identifier included in the message. Server 140 thereby receives the subscriber data and the second network identifier from service provider network 110.

[0056] In block 341, the server 140 receives from the data broker 114 the subscriber data retrieved by the service provider network 110 (in block 331) and a second network identifier. The server 140 also receives a request for the first network identifier and the subscriber data from the second entity 130. The server 140 in this example is configured to process the request for data from the second entity 130 in block 341 to determine whether the subscriber data is allowed to be provided to the second entity 130. The server 140 is configured to perform a verification process using the first network identifier and the second network identifier to determine whether the subscriber data is allowed to be provided to the second entity 130.

[0057] In one example, the verification process may include verifying that the first network identifier and the second network identifier originated from the subscriber device 102. The server 140 may also verify that the network identifiers originated from the same pair of network requests (i.e., the first network request and the second network request) and therefore are associated with the same instructions executed at 310. As noted above, each network identifier may be provided as part of the network request, for example, forming part of a header of the HTTP network request. Accordingly, the server device 140 may be configured to analyze the received network request for the presence of a network identifier. This may include determining whether a particular query parameter or header field is present in the HTTP request. In an example, the first network identifier and the second network identifier are copies of the same network identifier generated by the subscriber device 102. Thus, in such an example, the server 140 may compare the first network identifier with the second network identifier and determine that they are identical. If they are determined to be identical, the server 140 may determine that the subscriber data is allowed to be provided to the second entity 130.

[0058] 3, in block 341, server 140 determines that it is permissible to provide subscriber data to second entity 130. Accordingly, in action 3g, server 140 sends a network response to second entity 130, the network response including at least a portion of the subscriber data requested by second entity 130. In one example, if server 140 cannot verify the first and second network identifiers, or, for example, if it determines that the network identifiers do not both originate from the subscriber device or are not associated with the same set of network requests from the subscriber device, server 140 determines that it is not permissible to provide subscriber data to second entity 130. Server 140 can then send an error message to second entity 130 instead of sending the subscriber data.

[0059] In the above example, the server 140 is configured to receive a request for subscriber data and a first network identifier from the second entity 130 and to receive the first network identifier and subscriber data from the service provider network 110. Thus, in the above example, the server 140 is configured to perform a verification process using the network identifier. However, in an alternative example, the server 140 is configured to receive a request for data and the first network identifier from the second platform and, in response, transmit the request for data and the first network identifier to the data broker 114. Thus, in this alternative example, the data broker 114 is provided with the first network identifier from the server and the second network identifier from the subscriber device 102 via the intermediate device 111 (as in the previous example). The data broker 114 can then perform a verification process using the network identifier to determine whether the subscriber data is allowable to be provided to the second entity 130. In such an example, the data broker 114 may provide the subscriber data to the server 140 subject to this verification, or may, for example, provide the data to the server 140 and provide a message to the server 140 indicating that it is acceptable to provide the data to the second entity 130.

[0060] The above method thus enables an entity external to the service provider network 110, in the above example, the second entity 130, to be provided with subscriber data originating within the service provider network 110. As noted above, in the example, the subscriber data is anonymized by an entity within the service provider network 110, such as the data broker 114. The second entity 130 is thus provided with anonymous subscriber data that it can use to determine a response to a network request originating from the subscriber device 102, without knowing the subscriber's identity. The method enables the above to be accomplished even when the first network request and the first network identifier are inaccessible by the service provider network 110 because they are transmitted from the client device to the first entity 120 over a secure communications channel.

[0061] Returning to FIG. 3 , in a step after the second entity 130 receives the response from the server 140 including the subscriber data, the second entity 130 processes the response from the server 140 in block 342. In processing the response, the second entity 130 determines a browser response to send to the first entity 120. The response sent from the second entity 130 to the first entity 120 includes content that depends on the subscriber data received from the server 140. For example, the second entity 130 may use the obtained subscriber data to determine a price to bid on a request for an advertisement and / or to determine characteristics of the advertisement to respond to. In action 3h, the second entity sends such a response to the first entity in response to the request made by the first entity to the second entity in action 3c.

[0062] The first entity 120 in block 343 processes the response from the second entity 130 and prepares a response to the network request sent from the subscriber device in action 3b. In action 3i, the first entity 120 sends a response to the subscriber device 102 that includes content that depends on the subscriber data provided from the server 140 to the second entity 130. Thus, the subscriber device 102 has been provided with a browser response from the first entity 120 that is directed to the subscriber device 102 and can send a response to the telecommunications network 100. In an example, the response includes content based on the subscriber data provided to the second entity 130. In the example of FIG. 3, the response in action 3i is also routed through the intermediate network device 111, which forwards the response 3i to the subscriber device 102. In other examples, the response need not be routed through the intermediate network device 111, but can use a different routing path (e.g., a default or normal path) within the service provider network 110.

[0063] While in the examples described with reference to the figures, the method is described as operating in a network including a first entity and a second entity, it should be understood that in other exemplary methods, subscriber data may be provided to a different entity from the server 140. For example, in another exemplary method, the first entity 120 may be omitted, and the subscriber device 102 may send second network requests to the second entity 130. In other examples, more than two entities may operate to process second network requests, i.e., there may be additional intermediate entities between the first entity 120 and the second entity 130.

[0064] FIG. 5 is a flow diagram illustrating an exemplary method for providing subscriber data stored in a first service provider network. The method includes, at block 500, receiving a first network identifier transmitted from a subscriber device authenticated to communicate through the first service provider network, the first network identifier being transmitted by the subscriber device in a first message to an entity external to the service provider network. At block 502, the method includes receiving a second network identifier transmitted from the subscriber device to the first service provider network. At block 504, the method includes performing a verification process using the first network identifier and the second network identifier to verify whether the subscriber data stored in the service provider network is allowed to be provided to a content provider external to the service provider network. At block 506, the method includes providing the subscriber data stored in the service provider network to an entity external to the service provider network in response to a successful verification process. The method of FIG. 5 may be performed by an entity such as server 140 in one example, or may be performed by multiple entities such as server 140 and data broker 114 in another example.

[0065] 6 is a flow diagram illustrating an example method from the perspective of a subscriber device, such as subscriber device 102, that is authenticated to communicate through a first service provider network. At block 600, the method includes generating a first network identifier and a second network identifier. At block 602, the method includes sending a first message including the first network identifier to an entity external to the service provider network. At block 604, the method includes sending the second network identifier to the first service provider network. At block 606, the method includes receiving a network response at the subscriber device from the entity external to the service provider network, where the network response includes content included in the network response that depends on subscriber data stored in the service provider network being provided to a content provider external to the first service provider network in response to the first network identifier and the second network identifier being used in a process to verify that the subscriber data stored in the service provider network is acceptable to be provided to the content provider.

[0066] Because the data broker and server are configured to provide data originating from within the service provider network as a computing service to the requesting entity, certain examples described herein can be considered to relate to providing subscriber data to the requesting entity as a service. For example, the requesting entity acts as a client of the services provided by the server and data broker, with the data broker acting as the server. In one exemplary application of this functionality, the server can provide subscriber data to the requesting entity, which could be, for example, an advertisement server requesting subscriber data to inform a response to a request for an advertisement.

[0067] The above examples should be understood as illustrative examples of the present invention. Further examples of the present invention are contemplated. For example, although some of the above examples are described in the context of packetized data traffic such as HTTPS data, it should be understood that the methods and systems disclosed herein are applicable to any similar or equivalent protocol, and in particular any request / response-based protocol. For example, requests described in examples herein that are transmitted via HTTPS could be transmitted via HTTP.

[0068] It should be understood that any feature described in connection with any one example may be used alone or in combination with other features described, and may also be used in combination with one or more features of any other example, or in any combination of any other example. Furthermore, equivalents and modifications not described above may also be employed without departing from the scope of the invention as defined in the appended claims. [Item of invention] [Item 1] 1. A method for providing subscriber data from a first service provider network to a content provider external to said service provider network, comprising: receiving a first network identifier sent from a subscriber device authenticated to communicate via the first service provider network, the first network identifier being sent by the subscriber device in a first message to an entity outside the service provider network; receiving a second network identifier sent from the subscriber device to the first service provider network; performing a verification process using the first network identifier and the second network identifier to verify whether subscriber data stored in the service provider network can be allowed to be provided to the content provider outside the service provider network; and providing the subscriber data to an entity external to the service provider network in response to a successful verification process; A method comprising: [Item 2] Item 10. The method of item 1, wherein the first network identifier in the first message is not accessible by the first service provider network. [Item 3] the subscriber data is provided in response to a request for the subscriber data originating from the content provider; 3. The method of claim 1 or claim 2, wherein the request from the content provider is made due to the first network message sent by the subscriber device. [Item 4] the entity outside the first service provider network that receives the first message from the subscriber device is a first entity, and the method comprises: receiving the second network identifier from the first service provider network at a further entity external to the first service provider network; and receiving the first network identifier at the further entity; Including, 4. The method of any one of items 1 to 3, wherein the verification process is performed by the further entity, which in response to the verification process being successful provides the subscriber data to an entity external to the service provider network. [Item 5] The method comprises: receiving, at the first service provider network, the first network identifier; Including, 4. The method of claim 1, wherein the verification process is performed within the first service provider network, and the first service provider network provides the subscriber data stored at the first service provider to an entity external to the service provider network in response to the verification process being successful. [Item 6] 6. The method of any one of items 1 to 5, wherein the subscriber data provided to the entity outside the service provider network is anonymized. [Item 7] 7. The method of any one of items 1 to 6, wherein each network identifier comprises a random, fixed-length string that is inserted into application protocol requests. [Item 8] determining, by the first service provider network, a subscriber identifier for the subscriber using network data accessible within the service provider network; and using said subscriber identifier to retrieve said subscriber data from at least one data storage accessible to said service provider network; 8. The method according to any one of items 1 to 7, comprising: [Item 9] the first service provider network includes a first entity within the first service provider network and a second entity within the first service provider network; Receiving the second network identifier at the first service provider network includes receiving the second network identifier at the first entity within the service provider network, the first entity within the service provider network determining the subscriber identifier, and the method further includes: transmitting the second network identifier and the subscriber identifier from the first entity in the service provider network to the second entity in the service provider network; and retrieving, by the second entity in the service provider network, the subscriber data from the at least one data storage using the subscriber identifier; Item 9. The method according to item 8, comprising: [Item 10] Item 10. The method of item 9, wherein the second network identifier and the subscriber identifier are transmitted from the first entity to the second entity in the form of an Internet Content Application Protocol (ICAP) request, an HTTP request, an HTTPS request, or a User Datagram Protocol (UDP) request. [Item 11] 1. A method for receiving content at a subscriber device that is authenticated for communication over a first service provider network, the method comprising: generating a first network identifier and a second network identifier; sending a first message including the first network identifier to an entity external to the service provider network; transmitting the second network identifier to the first service provider network; receiving, at the subscriber device, a network response from the entity external to the service provider network, the network response including content included in the network response that depends on the subscriber data being provided to the content provider external to the first service provider network in response to the first network identifier and the second network identifier being used in a process of verifying that subscriber data is acceptable to be provided to a content provider; A method comprising: [Item 12] Item 12. The method of item 11, wherein the first network identifier in the first message is not accessible by the first service provider network. [Item 13] 13. The method of claim 11, wherein the first network identifier is transmitted to the entity outside the first service provider network via a secure communication channel between the subscriber device and the entity outside the first service provider network. [Item 14] 14. The method of any one of items 11 to 13, wherein the second network identifier is transmitted over a secure communication channel between the subscriber device and the first service provider network. [Item 15] 15. The method of any one of items 11 to 14, wherein the second network identifier is transmitted in a second message containing the second network identifier. [Item 16] Item 16. The method of item 15, wherein the second network request is a synchronization request to request synchronization of the processing of the network request by the service provider network. [Item 17] 17. The method of any one of items 11 to 16, wherein the first network request is a network request for an advertisement to be served via the entity external to the first service provider network. [Item 18] 18. The method of any one of items 11 to 17, wherein the first network request is an HTTPS network request. [Item 19] 19. The method of any one of items 15 to 18, wherein the second network request is an HTTPS network request. [Item 20] A set of machine-readable instructions that, when executed by a device, causes the device to perform the method of any one of items 1 to 10. [Item 21] A set of machine-readable instructions that, when executed by a subscriber device, causes said device to perform the method of any one of items 11 to 19. [Item 22] 22. A non-transitory computer-readable medium comprising a set of computer-readable instructions according to item 20 or item 21 stored on the non-transitory computer-readable medium. [Item 23] 11. An apparatus configured to carry out the method according to any one of items 1 to 10. [Item 24] 22. A subscriber device including the set of machine-readable instructions of item 21. [Item 25] The first service provider network Carrier network, Mobile networks, cellular networks, and Internet Service Provider Network 25. The apparatus of claim 23 or the subscriber device of claim 24, comprising one or more of:

Claims

1. 1. A method for providing subscriber data from a first service provider network to a content provider external to the first service provider network, comprising: receiving a first network identifier sent from a subscriber device authenticated to communicate via the first service provider network, the first network identifier being sent by the subscriber device in a first message to an entity outside the first service provider network, the first network identifier being inaccessible by the first service provider network; receiving a second network identifier sent from the subscriber device to the first service provider network; performing a verification process using the first network identifier and the second network identifier to verify whether subscriber data stored in the first service provider network can be allowed to be provided to the content provider outside the first service provider network; and providing the subscriber data to an entity external to the first service provider network in response to a successful verification process; A method comprising:

2. the subscriber data is provided in response to a request for the subscriber data originating from the content provider; The method of claim 1 , wherein the request from the content provider is made due to the first message sent by the subscriber device.

3. the entity outside the first service provider network that receives the first message from the subscriber device is a first entity, and the method comprises: receiving the second network identifier from the first service provider network at a further entity external to the first service provider network; and receiving the first network identifier at the further entity; Including, 3. The method of claim 1, wherein the verification process is performed by the further entity, and the further entity provides the subscriber data to an entity external to the first service provider network in response to the verification process being successful.

4. The method comprises: receiving, at the first service provider network, the first network identifier; Including, 3. The method of claim 1, wherein the verification process is performed within the first service provider network, and the first service provider network provides the subscriber data stored at the first service provider to an entity external to the first service provider network in response to the verification process being successful.

5. The method of any one of claims 1 to 4, wherein the subscriber data provided to the entity external to the first service provider network is anonymized.

6. A method according to any preceding claim, wherein each network identifier comprises a random, fixed-length string that is inserted into application protocol requests.

7. determining, by the first service provider network, a subscriber identifier for the subscriber using network data accessible within the first service provider network; and using the subscriber identifier to retrieve the subscriber data from at least one data storage accessible to the first service provider network; The method according to any one of claims 1 to 6, comprising:

8. the first service provider network includes a first entity within the first service provider network and a second entity within the first service provider network; Receiving the second network identifier at the first service provider network comprises receiving the second network identifier at the first entity within the first service provider network, the first entity within the first service provider network determining the subscriber identifier, and the method further comprises: transmitting the second network identifier and the subscriber identifier from the first entity in the first service provider network to the second entity in the first service provider network; and retrieving, by the second entity in the first service provider network, the subscriber data from the at least one data storage using the subscriber identifier; The method of claim 7, comprising:

9. 9. The method of claim 8, wherein the second network identifier and the subscriber identifier are transmitted from the first entity to the second entity in the form of an Internet Content Application Protocol (ICAP) request, an HTTP request, an HTTPS request, or a User Datagram Protocol (UDP) request.

10. 1. A method for receiving content at a subscriber device that is authenticated for communication over a first service provider network, the method comprising: generating a first network identifier and a second network identifier; sending a first message including the first network identifier to an entity external to the first service provider network, the first network identifier in the first message being inaccessible by the first service provider network; transmitting the second network identifier to the first service provider network; receiving, at the subscriber device, a network response from the entity external to the first service provider network, the network response including content included in the network response that depends on subscriber data from the first service provider network that was provided to the content provider external to the first service provider network in response to the first network identifier and the second network identifier being used in a process of verifying that subscriber data is acceptable to be provided to a content provider; A method comprising:

11. 11. The method of claim 10, wherein the first network identifier is transmitted to the entity outside the first service provider network via a secure communication channel between the subscriber device and the entity outside the first service provider network.

12. The method of claim 10 or 11, wherein the second network identifier is transmitted over a secure communication channel between the subscriber device and the first service provider network.

13. The method according to any one of claims 10 to 12, wherein the second network identifier is transmitted in a second message containing the second network identifier.

14. 14. The method of claim 13, wherein the second message is a synchronization request to request synchronization of processing of a network request by the first service provider network.

15. The method of any one of claims 10 to 14, wherein the first message is a network request for an advertisement to be served via the entity external to the first service provider network.

16. The method according to any one of claims 10 to 15, wherein the first message is a HTTPS network request.

17. 17. The method of claim 13 or 14, or claim 15 or 16 when dependent on claim 13 or 14, wherein the second message is a HTTPS network request.

18. A set of machine-readable instructions which, when executed by an apparatus, causes said apparatus to perform the method of any one of claims 1 to 9.

19. A set of machine-readable instructions which, when executed by a subscriber device, causes said device to perform the method of any one of claims 10 to 17.

20. 20. A non-transitory computer readable medium comprising a set of computer readable instructions according to claim 18 or claim 19 stored on said non-transitory computer readable medium.

21. Apparatus configured to carry out the method according to any one of claims 1 to 9.

22. 20. A subscriber device comprising the set of machine-readable instructions of claim 19.

23. The first service provider network comprises: Carrier network, Mobile networks, cellular networks, and Internet Service Provider Network 23. The apparatus of claim 21 or the subscriber device of claim 22, comprising one or more of:

Citation Information

Patent Citations

  • Information providing apparatus, information providing method and information providing program

    JP2014102853A

  • Distribution device, distribution method, and distribution program

    JP2017049623A

  • Identifier synchronization system, advertisement distribution system, and program

    JP2018097824A

  • Location blocking service from a web advertiser

    US20020077084A1

  • Systems and methods for providing real time anonymized marketing information

    US20100094758A1