Enhanced user identification with privacy protection across multiple web servers
The privacy ID system addresses the challenge of tracking users without third-party cookies by generating unique IDs for third-party services, ensuring privacy and compliance with regulations, while maintaining effective user identification across visits.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- FANPLAYR INC
- Filing Date
- 2022-04-06
- Publication Date
- 2026-04-24
AI Technical Summary
The elimination of third-party cookies poses a challenge for advertising networks and third-party scripts, making it difficult to effectively track users across multiple visits, while maintaining user privacy and adhering to browser restrictions.
A privacy ID system that generates and maintains a unique user ID for each third-party API key, using server-side, HTTP, and same-site cookies to identify users across visits, while masking user identities across multiple websites.
Enables third-party services to accurately identify repeat users, maintain privacy, and reduce the website footprint of third-party apps, ensuring compliance with privacy regulations like GDPR and CCPA.
Smart Images

Figure 0007851325000001 
Figure 0007851325000002 
Figure 0007851325000003
Abstract
Description
Technical Field
[0001] <Priority Claim> This application claims the benefit of U.S. Provisional Patent Application No. 62 / 172,036, filed Apr. 7, 2021, entitled "Enhanced User Identification with Privacy Protection Across Multiple Web Servers" (Attorney Docket No.: FANP 1001-1), and claims priority to U.S. Patent Application No. 17 / 694,587, filed Mar. 14, 2022, entitled "Enhanced User Identification with Privacy Protection Across Multiple Web Servers" (Attorney Docket No.: FANP 1001-2). <Related Cases>
[0002] This application is related to U.S. Patent Application No. 17 / 195,475, filed Mar. 8, 2021, entitled "Methods and Systems for Segmentation as a Service" (Attorney Docket No.: FANP 1000-9).
[0003] This application is also related to U.S. Patent Application No. 17 / 195,475, filed Jun. 27, 2018, entitled "Methods and Systems for Segmentation as a Service" (now U.S. Patent No. 10,958,743, issued Mar. 23, 2021).
[0004] The related cases are hereby incorporated by reference in their entirety for all purposes.
Background Art
[0005] Browser vendors have started to focus on privacy. To ensure privacy and limit the tracking of users across the Internet, users have introduced restrictions on cookie lifetimes, third-party cookie expiration dates, URL decoration, and even completely blocking tracking scripts that are considered harmful to user privacy. Next year (2021), third-party cookie support will be removed. That is, most tracking services will face difficulties in tracking users in a meaningful way.
[0006] Numerous competing proposals have been made, with large advertising networks / solution providers proposing various identification mechanisms. Most proposals aim to track users across multiple sites, attempting to maintain the status quo of advertising networks. This approach relies on many networks and publishers, requiring users to sign up to be useful. A larger "standard" expects end users to create a single account on third-party sites and then use that account to log in on all publisher sites. This is equivalent to "Sign in with Google" or "Sign in with Facebook."
[0007] One of the biggest challenges facing advertising networks and third-party scripts on websites is the inability to track users using cookies. This means that it is no longer possible to effectively identify users across each visit.
[0008] This presents an opportunity to help sites continue to leverage third-party services while maintaining user privacy, in a manner that aligns with the intent behind changes made by browser vendors, including masking user IDs across multiple web servers. [Overview of the Initiative]
[0009] The disclosed technology relates to restricting the sharing of visitor identity information across multiple websites, following the elimination of third-party cookies. This includes a privacy script that runs within the visitor's browser and interfaces directly or indirectly with a privacy identity server, and includes receiving the visitor's browser web pages from the visited website's server, which include one or more third-party apps requesting the visitor's identification. The disclosed method also includes a privacy script that runs within the browser and retrieves a first-party cookie containing the visitor ID, which the privacy script directly or indirectly transfers at least a portion of the first-party cookie to a privacy identity server, which the privacy script receives a site-by-app unique ID from the privacy identity server for a visitor that is distinguishable and uncorrelated for different pairs of websites and third-party apps. Furthermore, it includes providing each third-party app with its own site-by-app unique ID from its respective server, without providing the visitor ID to the third-party app, thereby making it possible to track the visitor during repeated visits to a visited website, but not making it easier to identify the visitor across multiple websites. It also includes the ability to provide site visitors with services such as "Don't Track Me" or "Forget Me" that are effective for the site and any and all third-party apps on the site. The disclosed system further includes a user identification arbiter for any website, in addition to helping map services to ensure data exchange.
[0010] A system and method for masking user identity across multiple web servers includes a cryptographic identity script that runs in a browser and interfaces directly or indirectly with a cryptographic identity server, and further includes receiving a web page from the server that contains one or more applications. Also disclosed are a cryptographic identity script that runs in a browser to retrieve a cookie containing a user ID, a cryptographic identity script that directly or indirectly transfers at least a portion of the cookie to a cryptographic identity server, and a cryptographic identity script that receives from the cryptographic identity server a server-by-application-specific ID that is distinguishable and uncorrelated for a separate triplet of user, web server, and application. Furthermore, it is disclosed to provide each application with its own server-by-application-specific ID without providing the application with the user ID.
[0011] As used in this context, "website" refers not only to browsers on desktop machines, mobile devices, and IoT devices, but also to mobile apps on iOS and Android platforms.
[0012] Specific aspects of the disclosed technology are described in the claims, specification, and drawings. [Brief explanation of the drawing]
[0013] The accompanying drawings are for illustrative purposes only and serve solely to provide examples of possible structures and processing operations for one or more embodiments of the present invention. These drawings do not limit any modifications in form and detail that a person skilled in the art could make without departing from the spirit and scope of this disclosure. A more complete understanding of the present invention can be obtained by referring to the detailed description and claims, in conjunction with the following drawings, where similar reference numerals refer to similar elements throughout the drawings.
[0014] [Figure 1]A block diagram of an exemplary embodiment of one of the disclosed technologies for restricting the sharing of visitor identity information and history across multiple websites, following the elimination of third-party cookies.
[0015] [Figure 2] Following the removal of third-party cookies, the following message diagram shows the process for restricting the sharing of visitor identity information and history across multiple websites.
[0016] [Figure 3] Following the removal of third-party cookies, a message diagram is shown illustrating alternative processing to restrict the sharing of visitor identity information and history across multiple websites.
[0017] [Figure 4] This message diagram illustrates another method of masking user identity across multiple websites using an encrypted ID script.
[0018] [Figure 5] A block diagram of an exemplary system suitable for implementing restrictions on the sharing of visitor identity information and history sharing across multiple websites, following the elimination of third-party cookies, is shown, based on one embodiment of the disclosed technology. [Modes for carrying out the invention]
[0019] The following detailed description will be made with reference to the drawings. Exemplary embodiments are provided to illustrate the disclosed art and are not intended to limit the scope defined by the claims. Those skilled in the art will recognize various equivalent variations of the following description.
[0020] Advertising networks and third - party scripts on the site can no longer use third - party cookies to track users, taking into account the current restrictions set by the browser. This means that it is no longer possible to effectively identify users across each visit. Due to many browser restrictions being set and planned, most third - party services struggle to identify users.
[0021] The disclosed technology for Enhanced User Identification (EUI) uses a privacy ID to provide a unique user ID to third - party services, enabling third - party services to better identify users and utilize first - party data within the browser and in real - time. EUI is implemented using server - side, HTTP, secure, and same - site cookies to effectively identify users across each visit. By generating and maintaining a privacy - ID - mapped unique ID for each third - party API key, the disclosed technology eliminates the need for third - party scripts to individually track visit histories. The disclosed technology can result in a reduction in the size of the web - site footprint of third - party apps, which can grow dramatically in a world without third - party cookies.
[0022] The disclosed privacy ID technology is an arbiter of user identification for any website and a system that aids in the mapping of services to guarantee data exchange between services. Using this system, third-party services on a site can continue to identify repeat users as needed to maintain those services without generating a single ID to track users across multiple sites, thus providing privacy to the user and ensuring that data remains first-party. Using the disclosed system, a website can focus on and improve the quality of its first-party data using a single integration that enables it to identify users, new and repeat, across multiple services integrated into the website while protecting the privacy of visitors.
[0023] The disclosed technology for privacy ID identifies users on a particular website and browser and maintains a unique service-specific version of the user ID to be shared with each service. This enables the website to control which services can access the user ID, respecting the privacy of the user by preventing Fanplayr from identifying users across multiple websites. Next, an exemplary system for restricting the sharing of visitor identity information across multiple websites and masking user identities across multiple web servers will be described. <Architecture>
[0024] Figure 1 illustrates a system 100 for restricting information sharing and controlling history sharing across multiple websites, following the deletion of third-party cookies. The disclosed system monitors and tracks users and data, identifies users in a first-party context while taking browser constraints into consideration, and utilizes a single service to ensure compliance with General Data Protection Regulations (GDPR), the California Consumer Privacy Act (CCPA), and "forget me" requests. Since Figure 1 is an architectural diagram, certain details have been intentionally omitted for clarity. The explanation of Figure 1 is structured as follows: First, the elements of the diagram are described, followed by their interconnections. Next, the use of the elements of this system is described in more detail.
[0025] System 100 includes a privacy ID server 106 having a user ID generator 116 for generating a user ID unique to a combination of service and site. The privacy ID server 106 also includes an analysis server 126 for retrieving the same unique user ID generated on the first visit, and a cache memory 136 for storing visitor data and account settings. The analysis server 126 can accumulate data across distributed computers as many visitors visit many websites. The analysis server 126 assigns tags to visitor sessions and transmits IDs via callback addresses registered on the web pages. The analysis server 126 accumulates data about the visitor's activity during a website session and analyzes metrics to track the progress of the session.
[0026] System 100 also has a privacy ID data store 144 for storing user data and analysis results, and a privacy ID interface script 146 for use by the customer's web server. The customer enables browser and privacy-compliant user identification for on-site services by uploading templates provided in a common programming language to the customer's web server 156 via the privacy ID server 106 to integrate the service. In another embodiment, the customer can use the templates as a blueprint for writing their own integration scripts to complete the integration of third-party applications by using JavaScript injection on the website. The process flow is described below in relation to Figure 2.
[0027] System 100 utilizes a web server 156 that delivers a web page 178 for user interaction via a browser 185. The web server 156 receives data from the web page via a network 145 using an identified callback address and an instrument code for callback registration. The web server 156 has a privacy script 166 to integrate the customer's browser experience over time. The web server 156 also has an Extended User Identification (EUI) / Privacy ID SID data store 168 for storing unique user IDs in a third-party service. The EUI is implemented using server-side, HTTP, secure, and same-site cookies to effectively identify the user across each visit. The Privacy ID server 106 receives a set of instruments from the user session with the web page 178, along with a callback API for delivering the results.
[0028] System 100 further includes a user computing device 165 having a graphical user interface (GUI) implementation 175 that provides a display layer for user laptops or desktop computers 142 and mobile devices 164. User computing device 165 utilizes instrumentation code to generate an administration interface that an administrator uses to configure and manage the system. The administrator can provide additional information about third-party scripts and request the creation of a unique API key for each third-party service they wish to enable. One embodiment includes an extensive display toolkit that allows customers to easily create a wide range of message placements in the form of gap banners, interactive sliders, flyouts, and overlays. User computing device 165 includes a web browser 185 for displaying web pages 178 delivered by a web server 156 for visitors. Browser 185 delivers third-party applications such as advertising network 1 186, advertising network 2 188, and analytics providers 196 such as Google Analytics as third-party services available to customers along with web pages 178. Each third-party service has a unique user ID associated with the service, and a privacy script 176 obtains metrics from the user session with the web page 178 and the third-party service. In some embodiments, the browser may include Microsoft Edge, Google Chrome, Apple Safari, Mozilla Firefox, etc. In some embodiments, the user computing device 165 may be a personal computer, laptop computer, tablet computer, smartphone, Internet of Things (IoT) device, digital image capture device, personal digital assistant (PDA), etc. The administrative function may also include decommissioned services as needed. If decommissioned, a service that requests a user ID will not be given an ID, thereby giving the administrator complete control over the site when configuring and managing the system.Depending on the services using the system, sites can enable data exchange. For example, a company intending to leave can reply to the system with its email address, and the site can decide to share it with its Customer Data Platform (CDP) system. Privacy ID Interface Script 146 includes a repository of scripts on a website that can be used to provide website end users with “privacy settings” options. These settings allow users to turn on or off tracking for individual scripts or all scripts overall, and can be used as support for GDPR and CCPA. “Forget Me” requests (GDPR, CCPA) can be processed from one place because the user’s request can be easily broadcast to all services using the system and passed on their respective IDs to them. The disclosed system can also be integrated into privacy consent frameworks, such as the Interactive Advertising Bureau (IAB) Transparency and Consent Framework, so that end users can grant or revoke permission.
[0029] In some embodiments, network 145 may be any one or any combination of data networks with other suitable configurations, including local area networks (LANs), wide area networks (WANs), WiFi, WiMAX, telephone networks, wireless networks, point-to-point networks, star networks, token ring networks, hub networks, peer-to-peer connections such as Bluetooth, near-field communication (NFC), Z-wave, ZigBee, or the internet.
[0030] System 100 further includes a privacy ID master data store 104 that connects to a privacy ID server via a network 145. In some embodiments, the data store can store information from one or more tenants in a table of a common database image to form an on-demand database service (ODDS), which can be implemented in many ways, such as a multi-tenant database system (MTDS). The database image may contain one or more database objects. In other implementations, the database may be a relational database management system (RDBMS), an object-oriented database management system (OODBMS), a distributed file system (DFS), a no-schema database, or any other data storage system or computing device.
[0031] Figure 2 shows a message diagram of the process for restricting information sharing and history sharing across multiple websites, following the elimination of third-party cookies. The user requests a web page, and the browser 185 sends a web page request to the web server 156 to load a privacy ID script and optionally provides details to help re-identify repeat users. The web server 156 retrieves a secure HTTP cookie (216) and provides the secure cookie and details, including the cookie value, to help re-identify repeat users in order to request the privacy ID script from the privacy ID server 106 (236). The privacy ID server 106 retrieves the mapped service ID (SID) and details from the cache memory 136 and / or the privacy ID data store 144 (246). The privacy ID server 106 returns structured data with the SID map and script to the web server 156 (256). The web server 156 sends the privacy ID script along with the SID map to the web page 178 via the browser 185 (266).
[0032] The explanation of the message diagram in Figure 2 for restricting information and history sharing across multiple websites continues. Web page 178 loads a third-party service script (272). Third-party services 186, 188, and 196 request a Service ID (SID) from the Privacy ID script 176, which runs in browser 185 (276). Each service identifies itself using its assigned API key and provides other details that it voluntarily shares. Third-party services 186, 188, and 196 register callbacks for asynchronous responses. The Privacy ID script 176 in browser 185 searches the SID map received from web server 156 for the SID to request the service (286) and invokes each service callback using the SID (296). If a SID does not exist for the API key, a SID is generated, which is then updated in the next step. The web page runs and is visualized within browser 185. The disclosed privacy ID script is typically implemented in JavaScript, embedding code for the disclosed functionality onto a web page. The browser 185 configures a callback function that reflects a selection specified by the website operator. In one embodiment, the callback function may activate a chatbot, email service, SMS messenger service, survey service, or other desired response to a visitor to the website. The website operator exposes one or more callback functions that are visualized and executed later. In one embodiment of the disclosed technology, the website operator embeds code to register listeners for each of their website pages. They may register multiple listeners depending on how they want to handle events.
[0033] In one embodiment, the callback function may initiate a call to display a chat window using a third-party service, or to display a pop-up prompting the user to subscribe to a newsletter. In another embodiment, a third-party service protecting the integrity of sensitive and secure data, such as the user's personal information, may be implemented as the callback function. In yet another case, the callback function may initiate a call to a research software tool, a news media distribution service, or a credit calculator. Further embodiments may include a call to a set of insurance-related tools for assessing risk and calculating rates. Readers may conceive of additional software tools that can also be instantiated by the callback function.
[0034] Examples of how to represent Fanplayr User IDs (FIDs) and Service User IDs (SIDs) are shown below. FIDs are unique to each user, and SIDs are unique to each service. Sample FID: 5.bwsmcrcIGkPY4yE8LoO.1574662629 Sample SID: PID.1.aND59wuPDpDZoFRBVZ8.1598301024
[0035] The following is an example of a script embedded on a website page. <script> / *** FanplayrプライバシIDキュー(Google Analyticの「dataLayer」と同様)* ウェブサイトは、これをページ上に可能な限り高く配置する必要がある。* / window._fpidq = window._fpidq|| [];
[0036] ウェブページによって規定されるこの便利な方法では、サードパーティ·サービスによって使用されるプライバシIDの詳細は抽象化されるので、サードパーティ·サービスはプライバシIDがどのように機能するかを知る必要がない。サードパーティ·サービスは、APIキーとコールバックを単に渡すことができる。function getIdentifiedUser(apiKey, callback) {window._fpidq.push({method: 'identify',apiKey: apiKey,callback: callback})}< / script>
[0037] The following is an example of a third-party script that calls the Privacy ID API. getIdentifiedUser('DzvOVJQH91TumGL2urPHPQSxUbf67vs0', function(sid) { console.log('Google Analytics received SID : ', sid); });
[0038] Examples of FID cookie content are shown below. 5.bwsmcrcIGkPY4yE8LoO.1574662629
[0039] Next, an example of a script on a customer web server is shown. In this document, the Fanplayr server is also referred to as Privacy ID Server 106. The account key is a JavaScript string that serves as a customer ID, identifying the customer website from which data is collected and specifying the current attributes associated with the user on the web page. / / The account key uniquely identifies the website to the Fanplayr service. const accountKey = 'd78978e96ac813947382f21ed7324228'; / / Cookie name to be used const userKeyCookieName = 'fanplayr'; / / Retrieve the user key cookie from the browser request. const userKey = req.cookies[userKeyCookieName]; / / Search for users and services from a remote Fanplayr server. const result = await lookupUserAndServices( Account Key, userKey ); / / Update User Key Cookie const expires = new Date(); expires.setFullYear(expires.getFullYear() + 1); res.cookie(userKeyCookieName, result.userKey, { expires, path: ' / ', httpOnly: true, secure: true, sameSite: 'strict' }); / / Outputs a script that incorporates the service. / / Note: The script content returned by the Fanplayr service includes a sidMap. res .header('content-type', 'application / javascript; charset=utf-8') .header('cache-control', 'must-revalidate') .send(result.scriptContent);
[0040] Examples of the returned FID and script content are shown below. { "fid": "5.bwsmcrcIGkPY4yE8LoO.1574662629", "scriptContent": "(function(){const SERVICE_USERS={\"DzvOVJQH91TumGL2urPHPQSxUbf67vs0\":\"PID.1.aND59wuP DpDZoFRBVZ8.1598301024\"};const queue=window._fpidq=window._fpidq||[];const handlers={identify(event){const userKey=SERVICE_USERS[event.apiKey]||null;if(event.callback){event.callback(userKey) }}};function processEvent(event){const handler=handlers[event.method];if(handler){handler(event)}} queue.push=function(event){processEvent(event)};for(const event of queue){processEvent(event)}}())" }
[0041] The following are example JavaScript scripts for invoking each service callback with its respective SID, using a more readable version of the "Script Content" property returned in the example above. Different scripting languages may also be used to provide the disclosed functionality. (function() { / / This is a sidMap containing one sid for each API key. const SERVICE_USERS = { "DzvOVJQH91TumGL2urPHPQSxUbf67vs0": "PID.1.aND59wuPDpDZoFRBVZ8.1598301024" }; const queue = window._fpidq = window._fpidq || []; const handlers = { identify(event) { const userKey = SERVICE_USERS[event.apiKey] || null; if (event.callback) { event.callback(userKey); } } }; function processEvent(event) { const handler = handlers[event.method]; if (handler) { handler(event); } } / / Redefine the native array "push" method so that new elements can be detected. / / addition. queue.push = function(event) { processEvent(event);}; }; / / Process the first event that was queued. for (const event of queue) { processEvent(event); } }());
[0042] In one embodiment, two sets of server clusters (one on the East Coast and one on the West Coast) provide faster responses to browsers, so their data can be redirected to w1.fanplayr.com or e1.fanplayr.com depending on the website visitor's geographical location, where w1 is West and e1 is East. In one embodiment, the analysis is processed in the cloud.
[0043] Figure 3 shows a message diagram of an alternative process for masking user identity across multiple web servers and controlling the sharing of information and history across multiple websites, following the elimination of third-party cookies. The user requests a web page, and the browser 185 loads a Privacy ID script within the web page 178 (305), optionally providing details that help re-identify repeat users. The web page 178 loads a third-party service script (324). The Privacy ID script 176 fetches a secure FID cookie from the web server 156 (336), which either returns an FID value or nothing (346). If nothing is returned, the user of web page 178 needs to establish a secure connection with the Privacy ID server 106.
[0044] The explanation of the alternative process for masking user identification across multiple web servers, as shown in Figure 3, continues. After the FID is returned from web server 156, third-party services 186, 188, and 196 request a Service ID (SID) from the Privacy ID script 176, which is executed in browser 185 (354). Each service identifies itself using its assigned API key and optionally provides other details to share. Third-party services 186, 188, and 196 register callbacks for asynchronous responses. The Privacy ID script 176 passes information to the Privacy ID server 106 (358). This may or may not include the FID, web push notification information, customer ID, email, SMS, etc. The Privacy ID server 106 returns the FID and the API key for the SID to the Privacy ID script 176 (368). The privacy ID server 106 within the browser 185 updates the secure FID cookie in the web server 156 (376) and invokes each service callback using the respective SID (384). If the API key's SID does not exist, a SID is generated and updated in the next step. The privacy ID script 176 executed in the browser 185 stores any newly generated SIDs of the API key in the privacy ID server 176 (398).
[0045] Next, following the elimination of third-party cookies used to mask user IDs across multiple web servers, we will describe an example of a system use case that leverages disclosed controls over information and history sharing across multiple web servers. <Example Use Cases>
[0046] Analytics Services: Data and analytics have become a crucial aspect of website and online business operations. Building analytics for a website is expensive, and therefore, websites choose to use third-party services to help understand their traffic. Most analytics services, such as Google Analytics and Mixpanel, require easy integration into a website using JavaScript injection. These scripts capture the data they deem necessary and pass the captured data to the server. For an effective and superior service to website operators, it is essential that the analytics service can accurately identify visitor traffic. Privacy policies, browser limitations, and other technical constraints make it difficult for such services to do so.
[0047] By using Fanplayr's Privacy ID, third-party analytics services can more accurately identify users, and the data services they provide become more meaningful for websites and businesses.
[0048] The following list shows examples of how disclosed Fanplayr Privacy IDs may be used to identify users in Google Analytics. This assumes that the Fanplayr Privacy ID script is available on the webpage. / / This line inserts the Google Analytics script into the site. <script async src="https: / / www.googletagmanager.com / gtag / js?id=G- KMQ6G8H6N7">< / script> / / This block is necessary for Google Analytics to initialize its service. <script>window.dataLayer = window.dataLayer || [];function gtag(){dataLayer.push(arguments);}}gtag('js', new Date());gtag('config', 'G-XXXXXXXXXX');< / script> / / This is additional code required for GA to use Fanplayr privacy IDs. <script>getIdentifiedUser('<PRIVACY-ID-API-KEY-FOR-GA>', function(sid) {window.dataLayer.push({'userId' : sid});});});});< / script>
[0049] Website Chat Services: In today's world, a key feature of chat services is providing users with the ability to find answers to any questions they may have. Sites integrate with AI services to offer chatbots that help answer questions. While highly useful, it is a very impersonal service, and even when users receive answers to their questions, they don't feel connected to the site.
[0050] By using Fanplayr's Privacy ID, third-party chatbot services can more accurately identify users, making the services they provide more meaningful and personalized to website users. For example, when identifying a returning visitor, the chatbot can start with a simple yet personal message such as, "Hi, welcome back!" To extend this use case, it is also possible for chatbots to use accurately identified users to access user history on the website, making interactions more contextual and relevant to the user.
[0051] The following list shows examples of how disclosed Fanplayr Privacy IDs may be used to identify users of a chatbot service. This assumes that the Fanplayr Privacy ID script is available on the webpage. / / This line injects the chatbot service into the site. <script async src="https: / / www.chatbotservices... ">< / script> / / This is additional code required for the service to use the privacy ID. <script>getIdentifiedUser('<PRIVACY-ID-API-KEY-FOR-CHATBOT>', function(sid) {window.dataLayer.push({'userId' : sid});});});});< / script>
[0052] Linked Service List Request: When performing the User ID Arbiter role, the Privacy ID is in a unique position so that it can provide information about scripts on the site to website users, and those scripts have requested the Service ID and the specific user's Service ID provided to each script / service. This can help websites provide transparency to users. Combined with Fanplayr's targeted solution, services can be listed and a widget can be displayed to users that allows them to enable / disable specific Service IDs.
[0053] Linked Service Data Requests: GDPR, CCPA, and other local privacy laws establish a set of rules that websites must follow. One common requirement of such regulations is that website users can request information collected by the website or by third-party services acting on their behalf. Most websites provide mechanisms detailed in their privacy policies. In most cases, such data requests must be submitted via email or postal mail. While the website can then provide the user with the information it has collected, the drawback is that the third-party service lacks the means to identify the user and extract the data. Without a unified identification mechanism between the website and the various services used, data requests cannot be fulfilled by third-party services. By acting as an ID arbiter, a disclosed privacy ID can enable such data requests to be made on-site by the user and generate a single report containing all user-specific service IDs. Such a report can then be used by the website to obtain data from all services and provide it to the user.
[0054] Linked Services "Forget Me" Requests: Similar to the linked services data requests described above, privacy laws require websites to provide a mechanism that allows website users to request that all data remembered about them be deleted and forgotten. Again, without a unified identification mechanism, third-party services cannot recognize users and delete the collected data. By acting as an arbiter of IDs, PrivacyID can enable such "Forget Me" requests to be made on-site by users and generate a single report containing all user-specific service IDs. Such a report can then be used by websites to make such requests to individual third-party services.
[0055] Figure 4 illustrates another method of masking user identity across multiple web servers using a cryptographic identity script. In this process, browser 185 receives a web page 178 from web server 156 which includes a cryptographic identity script 404 that runs within browser 185 and interfaces directly or indirectly with cryptographic identity server 408, and further includes one or more third-party services 186, 188, 196, also called third-party apps. Web page 178 loads the cryptographic identity script (415) and the third-party service scripts (424). The cryptographic identity script 404, running in browser 185, fetches a secure user ID cookie (446). The cryptographic identity script 404 passes information directly or indirectly (458) and transfers at least a portion of the cookie to cryptographic identity server 408. The cryptographic ID script 404 receives from the cryptographic ID server 408 a server-by-app unique ID that is distinct and uncorrelated for each of the user, web server, and app triplets (468). The cryptographic ID script 404 provides each app with its respective server-by-app unique ID without providing the app with a user ID (484).
[0056] In some embodiments, the cryptographic ID script 404 running in the browser 185 forwards at least a portion of the cookie to the web server 156 for forwarding to the cryptographic ID server 408, and receives the server-by-app unique ID generated by the cryptographic ID server from the server 408. In other embodiments, the cryptographic ID script 404 running in the browser 185 forwards at least a portion of the cookie to the cryptographic ID server 408, and receives the server-by-app unique ID from the cryptographic ID server 408.
[0057] Next, following the elimination of third-party cookies, we will describe a computer system for gaining control over the sharing of information and history across multiple websites. <Computer System>
[0058] Figure 5 shows a block diagram of an exemplary system 500 suitable for implementing system 100 of Figure 1 to restrict the sharing of information and history across multiple websites, following the elimination of third-party cookies. Generally, system 500 illustrated in Figure 5 includes a server 504 that dynamically supports virtual applications 516 and 518 based on data 522 from a common database 532 shared among multiple tenants, also referred to herein as the “multitenant database”. Data and services generated by virtual applications 516 and 518, including GUI clients, are provided to any number of client devices 548 or 558 via the network 545 as desired.
[0059] As used herein, “tenant” or “organization” refers to a group of one or more users who share access to a common subset of data in the multitenant database 532. In this regard, each tenant includes one or more users associated with, assigned to, or otherwise belonging to that tenant. In other words, each user in system 500 is associated with, assigned to, or otherwise belonging to a particular tenant among several tenants supported by system 500. A tenant may represent a user, a user department, a work or legal organization, and / or any other entity that maintains data for a particular set of users in system 500. Multiple tenants may share access to server 504 and database 532, but the specific data and services provided from server 504 to each tenant can be securely separated from those provided to other tenants. Thus, the multitenant architecture allows different sets of users to share functionality and hardware resources without necessarily sharing any data 522 that belongs to or is otherwise related to other tenants.
[0060] The multitenant database 532 is any kind of repository or other data storage system capable of storing and managing data 522 related to any number of tenants. The database 532 can be implemented using any type of conventional database server hardware. In various embodiments, the database 532 shares processing hardware with the server 504. In other embodiments, the database 532 is implemented using separate physical and / or virtual database server hardware that communicates with the server 504 to perform the various functions described herein. The multitenant database 532 may be referred to herein as an on-demand database service, in that it provides (or makes available for provision) data at runtime to on-demand virtual applications 516 or 518 generated by the application platform 517, while securely isolating tenant 1 metadata 512 and tenant 2 metadata 514.
[0061] In practice, the data 522 can be organized and formatted in any way to support the application platform 522. In various embodiments, conventional data relationships are established using any number of lookup tables 513 to establish indexing, uniqueness, relationships between entities, and / or other aspects of conventional database organization as desired.
[0062] Server 504 is implemented using one or more real and / or virtual computing systems that collectively provide a dynamic application platform 517 for generating virtual applications. For example, Server 504 may be implemented using a cluster of real and / or virtual servers operating in relation to each other, typically with respect to conventional network communication, cluster management, load balancing, and other features as needed. Server 504 operates on any kind of conventional processing hardware, such as a processor 536, memory 538, and input / output devices 534. Input / output devices 534 generally represent interfaces to networks (e.g., network 545, or any other local area, wide area, or other network), mass storage devices, display devices, data input devices, and / or similar. User interface input devices 534 may include a keyboard, pointing devices such as a mouse, trackball, touchpad, or graphics tablet, a scanner, a touchscreen integrated into a display, audio input devices such as a speech recognition system and microphone, and other types of input devices. In general, the use of the term “input device” is intended to include possible types of devices and methods for inputting information into the application platform 517.
[0063] The user interface output device may include a display subsystem, a printer, a fax machine, or a non-visual display such as an audio output device. The display subsystem may include a light-emitting diode (LED) screen, a flat panel device such as a liquid crystal display (LCD), a cathode ray tube (CRT), a projection device, or any other mechanism for generating a visible image. The display subsystem may also provide a non-visual display such as an audio output device. In general, the use of the term “output device” is intended to include all possible types of devices and methods for outputting information from the processor 536 to a user or another machine or computer system.
[0064] The processor 536 may be implemented using any suitable processing system, such as one or more processors, controllers, microprocessors, microcontrollers, processing cores, and / or other computing resources spread across any number of distributed or integrated systems, including any number of “cloud-based” or other virtual systems. Memory 538 represents any non-temporary short-term or long-term storage device or other computer-readable medium capable of storing program instructions for execution on the processor 536, including any kind of random access memory (RAM), read-only memory (ROM), flash memory, magnetic or optical mass storage device, etc. Once the computer-executable program instructions are read and executed by the server 504 and / or the processor 536, they cause the server 504 and / or the processor 536 to create, generate, or otherwise facilitate the application platform 517 and / or virtual applications 516 and 518, and to perform one or more additional tasks, operations, functions, and / or processes described herein. It should be noted that memory 538 represents one preferred embodiment of such computer-readable media, and alternatively or additionally, server 504 may accept and cooperate with external computer-readable media, such as portable or mobile components or application platforms, which may be implemented as portable hard drives, USB flash drives, optical discs, etc.
[0065] The application platform 517 is any kind of software application or other data processing engine that generates virtual applications 516 and 518 that provide data and / or services to client devices 548 and 558. In a typical embodiment, the application platform 517 can use any kind of conventional or proprietary operating system 528 to access processing resources, communication interfaces, and other features of processing hardware. The virtual applications 516 and 518 are typically generated at runtime in response to input received from client devices 548 and 558.
[0066] Continuing to refer to Figure 5, the data and services provided by the server 504 can be accessed using any type of personal computer, mobile phone, tablet, or other network-enabled client device 548, 558, and IoT device 544 on the network 545. In exemplary embodiments, client devices 548, 558 include display devices, such as monitors, screens, or other conventional electronic displays, that can graphically present the data and / or information retrieved from the multitenant database 532.
[0067] In some embodiments, network 545 may be any one or any combination of other suitable data networks, including local area networks (LANs), wide area networks (WANs), WiMAX, Wi-Fi, telephone networks, wireless networks, point-to-point networks, star networks, token ring networks, hub networks, mesh networks, peer-to-peer connections such as Bluetooth®, near-field communications (NFC), Z-Wave, Zigbee, or the Internet.
[0068] The foregoing description is essentially illustrative and is not intended to limit the embodiments of the invention or the application and use of such embodiments. Furthermore, it is not intended to be bound by any express or implied theories presented in the technical field, background, or detailed description. As used herein, the term “exemplary” means “serving as an example, illustration, or illustration.” Any embodiment described herein as illustrative should not necessarily be construed as being preferable or advantageous to other embodiments, and the exemplary embodiments described herein are not intended to limit in any way the scope or availability of the invention.
[0069] The disclosed technology is implemented in any computer implementation system, including database systems, multitenant environments, or relational database embodiments such as Oracle®-compatible database embodiments, IBM DB2 Enterprise Server®-compatible relational database embodiments, MySQL® or PostgreSQL®-compatible relational database embodiments, or Microsoft SQL Server®-compatible relational database embodiments, or NoSQL non-relational database embodiments such as Vampire®-compatible non-relational database embodiments, Apache Cassandra®-compatible non-relational database embodiments, BigTable®-compatible non-relational database embodiments, or HBase® or DynamoDB®-compatible non-relational database embodiments.
[0070] Furthermore, the disclosed technology can be implemented using two or more separate computer implementation systems that communicate with each other in cooperation. The disclosed technology can be implemented in numerous ways, including processes, methods, apparatus, systems, devices, computer-readable media such as computer-readable storage media for storing computer-readable instructions or computer program code, or computer program products comprising computer-usable media in which computer-readable program code is embodied. <Specific Embodiments>
[0071] Following the elimination of third-party cookies, we describe various embodiments for restricting the sharing of visitor identity information across multiple websites.
[0072] One embodiment of the disclosed method for restricting the sharing of visitor identity information across multiple websites includes receiving a webpage from the visited website server in the visitor's browser that includes a privacy script running in the visitor's browser and interfaceing directly or indirectly with a privacy identity server, and that includes one or more third-party apps that seek to identify the visitor. The method also includes the privacy script running in the browser extracting a first-party cookie containing the visitor ID, the privacy script directly or indirectly transferring at least a portion of the first-party cookie to the privacy identity server, and the privacy script receiving from the privacy identity server a site-by-app unique ID for the visited website and one of the third-party apps, the site-by-app unique ID for the visitor being distinguishable and uncorrelated between different pairs of the website and the third-party app. The disclosed method further includes the privacy script providing each third-party app with its own site-by-app unique ID without providing the third-party app with the visitor ID, thereby enabling tracking of visitors upon revisiting a visited website but not facilitating the identification of visitors across multiple websites.
[0073] This method and other embodiments of the disclosed technology may include one or more of the following features and / or features described in relation to the additional methods disclosed. For brevity, the combinations of features disclosed herein are not listed individually and are not repeated for each basic set of features.
[0074] One method disclosed further includes a privacy script running in a browser transferring at least a portion of a cookie to a privacy identity server for transfer to the server, and receiving a site-by-app unique identity generated by the privacy identity server from the server.
[0075] Some embodiments of the disclosed method further include a privacy script running in a browser transferring at least a portion of a cookie to a privacy identity server and receiving a server-by-app unique identity from the privacy identity server.
[0076] In many embodiments of the disclosed methods, the sharing of visitor identity information across multiple websites follows the deletion of third-party cookies.
[0077] One embodiment of the disclosed method for masking user identity across multiple web servers includes a cryptographic identity script that runs in a browser and interfaces directly or indirectly with a cryptographic identity server, and further includes receiving a web page from the server that includes one or more apps. The method also includes the cryptographic identity script running in the browser retrieving a cookie containing the user ID, the cryptographic identity script directly or indirectly transferring at least a portion of the cookie to the cryptographic identity server, and the cryptographic identity script receiving from the cryptographic identity server a server-by-app unique identity for the visited website and one of the apps, the server-by-app unique identity being distinguishable and uncorrelated with respect to different triplets of user, web server, and app. The disclosed method further includes the cryptographic identity server providing the server-by-app unique identity to each app without providing the app with the user ID.
[0078] In one embodiment of the disclosed method, a cryptographic identity script running in a browser transfers at least a portion of a cookie to a cryptographic identity server for transfer to the server, and receives a server-by-app unique identity generated by the cryptographic identity server from the server.
[0079] In some embodiments of the disclosed method, a cryptographic identity script running within a browser transfers at least a portion of the cookies to a cryptographic identity server and receives a server-by-app unique identity from the cryptographic identity server.
[0080] As used in this context, "website" refers not only to mobile apps on iOS and Android platforms, but also to browsers on desktop machines and mobile devices. Those skilled in the art will understand that code can be reused between browser pages and web apps by following HTML and JavaScript developer guidelines for specific platforms.
[0081] The disclosed technology can be practiced as a system, method, or product. One or more features of an embodiment can be combined with the basic embodiment. Non-exclusive embodiments are taught to be combinable. One or more features of an embodiment can be combined with other embodiments. This disclosure periodically reminds the user of these options. The omission of repetitive descriptions of these options from some embodiments should not be construed as limiting the combinations taught in the previous section. These descriptions are incorporated by reference to each of the following embodiments.
[0082] One disclosed embodiment may include a tangible, non-volatile, computer-readable storage medium on which program instructions causing a computer to perform any of the aforementioned methods are loaded when executed on a server.
[0083] Another disclosed embodiment may include a server system comprising one or more processors and memory coupled to the processors, the memory being loaded with instructions that, when executed on the processors, cause the server system to perform any of the methods described above.
[0084] This system embodiment and other disclosed systems may optionally include features described in relation to the disclosed method. For brevity, alternative combinations of system features are not individually listed. Features applicable to systems, methods, and products are not repeated for each statutory class set of basic features. The reader will understand how the features identified in this section can be readily combined with the basic features of other statutory classes.
[0085] The disclosed technology is disclosed by reference to the preferred embodiments and examples detailed above, but it should be understood that these embodiments are intended to be illustrative rather than restrictive. Modifications and combinations will be readily conceivable to those skilled in the art, and these modifications and combinations are considered to fall within the spirit of the invention and the scope of the following claims.
Claims
1. A method for restricting the sharing of visitor identity information across multiple websites, The visitor's browser receives a web page from a website server it has visited, which includes a privacy script that runs within the visitor's browser and interfaces directly or indirectly with a privacy ID server, and which includes one or more third-party applications that request the identification of the visitor. The privacy script executed within the browser retrieves a first-party cookie containing the visitor ID. The privacy script transfers at least a portion of the first-party cookies directly or indirectly to the privacy ID server. The privacy script is a site-by-app unique ID for the visitor that is distinguishable and uncorrelated for different pairs of the website and the third-party app, and receives the site-by-app unique ID for one of the visited website and the third-party app from the privacy ID server, and The privacy script includes providing each third-party app with its own site-by-app unique ID without providing the visitor ID to the third-party app, thereby enabling tracking of the visitor upon repeated visits to the visited website, but not facilitating the identification of the visitor across multiple websites. A method characterized by the following:
2. The method according to claim 1, wherein the privacy script executed in the browser transfers at least a portion of the cookie to the visited website server for transfer to the privacy ID server, and receives the site-by-app unique ID generated by the privacy ID server from the visited website server.
3. The method according to claim 1, wherein the privacy script executed in the browser transfers at least a portion of the cookie to the privacy ID server and receives the site-by-app unique ID from the privacy ID server.
4. The method according to claim 1, wherein the sharing of visitor identity information across multiple websites is performed following the deletion of third-party cookies.
5. A server system comprising one or more processors and memory coupled to the processors, wherein the memory is loaded with computer program instructions that, when executed on the processors, cause the server system to perform the method described in any one of claims 1 to 4.
6. A tangible, non-volatile, computer-readable storage medium characterized in that, when executed on a server, it is loaded with computer program instructions that cause one or more processors constituting the server to execute the method described in any one of claims 1 to 4.
7. A method for masking user identity across multiple web servers, Receiving a web page from a web server that includes an encrypted ID script that runs within a browser and interfaces directly or indirectly with an encrypted ID server, and further includes one or more applications. The cryptographic ID script executed within the browser retrieves a cookie containing the user ID. The cryptographic ID script transfers at least a portion of the cookie directly or indirectly to the cryptographic ID server. The cryptographic ID script receives from the cryptographic ID server a server-by-app unique ID that is distinguishable and uncorrelated for a separate triplet of the user, the web server, and the app, including the server-by-app unique ID for the visited website and one of the apps, and The aforementioned cryptographic ID script includes providing each application with its own server-by-application-specific ID without providing the application with the user ID. A method characterized by the following:
8. The method according to claim 7, wherein the cryptographic ID script executed within the browser transfers at least a portion of the cookie to the web server for transfer to the cryptographic ID server, and receives the server-by-app unique ID generated by the cryptographic ID server from the web server.
9. The method according to claim 7, wherein the cryptographic ID script executed within the browser transfers at least a portion of the cookie to the cryptographic ID server and receives the server-by-application-specific ID from the cryptographic ID server.
10. A server system comprising one or more processors and memory coupled to the processors, wherein the memory is loaded with computer program instructions that, when executed on the processors, cause the server system to perform the method described in any one of claims 7 to 9.
11. A tangible, non-volatile, computer-readable storage medium characterized in that, when executed on a server, it is loaded with computer program instructions that cause one or more processors constituting the server to execute the method described in any one of claims 7 to 9.
Citation Information
Patent Citations
Method and system for segmentation as a service
JP2020530172A
Tracking user conversions across mobile applications and browsers
US10019731B1
First-party cookie for tracking web traffic
US20060265495A1
System and method for generating and reporting cookie values at a client node
WO2002044869A2