Privacy-focused methods and systems for data propagation between different domains.

By propagating information between first-party cookies using a propagation server, the method enables user identification and personalized content delivery across websites, addressing the limitations of disabling third-party cookies while ensuring privacy and security.

JP7894020B2Active Publication Date: 2026-07-23アドフィクサス ピーティーイー リミテッド
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
アドフィクサス ピーティーイー リミテッド
Filing Date
2021-06-30
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

The disabling of third-party cookies by web browsers negatively impacts legitimate online activities such as targeted advertising and user identification across different websites, while concerns about user privacy and security necessitate a mechanism to enable these functionalities without setting third-party cookies.

Method used

A method is provided to propagate recorded information from a second-party cookie to a first-party cookie using an intermediate means, such as a propagation server, allowing access to first-party cookies associated with different domains, thereby enabling user identification and personalized content delivery without relying on third-party cookies.

Benefits of technology

This approach allows for user identification and personalized content delivery across multiple websites, balancing user privacy and security by leveraging first-party cookies, thus maintaining functionality similar to third-party cookies without their drawbacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007894020000001
    Figure 0007894020000001
  • Figure 0007894020000002
    Figure 0007894020000002
  • Figure 0007894020000003
    Figure 0007894020000003
Patent Text Reader

Abstract

A method for recording information in a first-party cookie in a web browser includes propagating the recorded information from a second cookie associated with a second domain to a first cookie associated with a first domain, wherein the first cookie and the second cookie are each first-party cookies, and wherein a first web resource in the first domain and a second web resource in the second domain each have access to the recorded information via an associated first-party cookie and corresponding server and system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to a method of using first - party cookies instead of third - party cookies.

Background Art

[0002] Web browsing has evolved from simple hypertext links between static web pages to the dynamic interconnection of many static and dynamically generated websites that provide extensive content.

[0003] As web browsing has evolved, in order to address the need to be able to record information related to websites, web browsers have been made capable of setting "cookies", which are small pieces of data stored on the computer running the web browser, in response to instructions from the websites accessed by the web browser.

[0004] Cookies can be either "first - party cookies" or "third - party cookies". The former are set by a specific domain accessed by the web browser. For example, when a user moves their web browser to www.example.com and the web content accessed by the web browser at this domain contains data and instructs the recording of a cookie associated with the same domain (the origin of the term "first - party"). The latter are set by a domain different from the one the web browser is accessing. For example, a web page accessed at www.example.com may itself utilize resources from another domain, for example, www.addomain.com. If this resource itself sets a cookie, since it is associated with a different domain, the cookie is associated with the second domain. Thus, the cookie is a third - party cookie.

[0005] It is associated with a party other than the domain the web browser is accessing.

[0006] There is a tendency to dislike allowing third-party cookies to be set. For example, setting third-party cookies may be considered undesirable because users do not necessarily recognize the second domain. However, third-party cookies play an important role in modern online activity, for example, by providing a means to track activity across various websites and enable more efficient user identification (e.g., to provide targeted advertising). For example, a common owner of multiple websites (each associated with a different domain) may have a legitimate interest in identifying a user when that user visits their specific website.

[0007] Deleting third-party cookies, even for positive reasons such as improving user privacy and security, can have negative consequences in these situations.

[0008] For example, when a user accesses a known domain such as www.example.com (via a web browser), resources from a third-party domain such as www.addomain.com may be used to generate at least some of the user's content. Previously, www.addomain.com may have set third-party cookies (e.g., name=AdDomainID, value=12345). From a browser perspective, this cookie is associated with www.addomain.com and not www.example.com. If the user then moves to www.example01.com, a domain owned by a different company and completely unrelated to www.example.com, which also previously used resources from www.addomain.com, the browser automatically sends the www.addomain.com cookie to www.addomain.com. This means that the cookie previously set on www.example.com (name=AdDomainID, value=12345) is automatically sent from www.example01.com.

[0009] Therefore, several major web browser developers have recently announced plans to disable third-party cookies by default. Such actions are expected to negatively impact legitimate online activity.

[0010] It is desirable to provide a mechanism to enable the functionality provided by third-party cookies without requiring the user to configure third-party cookies. [Overview of the project]

[0011] The embodiments and aspects described herein generally aim to provide mechanisms for enabling functionality provided by third-party cookies without requiring the setting of third-party cookies. For example, certain embodiments described may be suitable for providing functionality that enables tracking of a particular user across several different websites associated with different domains, which can advantageously allow the different websites to identify the user in a manner invisible to the user. The advantage is that user identification can enable different websites to provide content appropriately tailored based on user identification, thereby potentially providing an improved user experience across various websites and domains. These and other advantages are generally achieved without setting third-party cookies that were previously used to provide such functionality. In order to balance legitimate tracking activity with the demands for user privacy and security, additional limitations are made in the particular embodiments described to the extent to which user identification information becomes available.

[0012] According to one aspect of the present invention, a method is provided for recording information in a first-party cookie in a web browser. For example, the web browser does not allow access to third-party cookies and includes propagating recorded information from a second cookie associated with a second domain to a first cookie associated with a first domain, wherein the first and second cookies are each first-party cookies, and each of the first web resource in the first domain and the second web resource in the second domain has access to the recorded information via the associated first-party cookie.

[0013] The recorded information may be propagated to the first cookie during the current communication instance between the web browser and the first web resource of the first domain. The recorded information may also be propagated to the first cookie in response to a determination that the first cookie does not exist.

[0014] The recorded information may be propagated via an intermediate means, the intermediate means being propagated information accessible from the web browser during the current communication instance.

[0015] According to one embodiment, the method includes the steps of: instructing the web browser to communicate with a propagation server associated with a propagation domain different from the first domain during the current communication instance; and receiving the propagation information from the propagation server so that the web browser can record the recorded information as the first cookie. The web browser may initiate the current communication instance by communicating with a first web server requesting content for display, the first web server being associated with a first domain server, both servers being associated with the first domain, and the instruction to the propagation server being received from the first domain server. The first web server may, after the recorded information has propagated from the second cookie to the first cookie, provide the web browser with the content for display according to the recorded information. As part of the instruction, the web browser may provide the propagation server with information stored in the propagation cookie, the propagation information may be based on information stored in the propagation cookie. The information stored in the propagation cookie and the propagation information may be the same, or the propagation information may be an encoded representation of the information stored in the propagation cookie. The propagation information may be generated according to propagation rules available to the propagation server, and the propagation rules may be applied to the information stored in the propagation cookie. The propagation rules may be stored in the propagation cookie and provided to the propagation server as part of the instruction. The propagation information may also be provided to the web browser in connection with an instruction received from the propagation server, thereby the web browser may communicate with the first domain server and provide the propagation information along with the instruction. In response to providing the propagation information to the first domain server, the web browser may receive an instruction from the first domain server to set the first cookie containing the recorded information.

[0016] According to one embodiment, the intermediate means is stored as webpage-specific data and includes the step of instructing the web browser to communicate with a first domain server, wherein the web browser provides the webpage-specific data to the first domain server along with the instruction, and receives from the first domain server an instruction to set the first cookie along with the recorded information, wherein the recorded information is equal to or derived from the webpage-specific data, and the instruction is received from the first web server in response to a request for content to be displayed by the web browser, the first web server is associated with the first domain server, and both servers are associated with the first domain. The webpage-specific data may be set during a previous instance of communication with the second domain server of the second domain. The webpage-specific data may not be accessible to executable code when executed in the web browser, but may be accessible to the first domain server when set by communication with the second domain, preferably only accessible by an external server. Before the command is sent to the web browser, the webpage-specific data may be stored in the ETag associated with the webpage provided to the web browser.

[0017] The first and second domains may be determined to be the relevant domains to which propagation is permitted before allowing the propagation of the recorded information from the second cookie to the first cookie.

[0018] The aforementioned web browser does not need to allow access to third-party cookies.

[0019] According to another aspect of the present invention, a domain server is provided which is configured to communicate with a web browser in order to facilitate the propagation of recorded information between first-party cookies associated with different domains, wherein the domain server is configured to receive communication from the web browser by a redirect command provided to the web browser from a web server associated with the domain, and to determine whether a first cookie is present in the communication, wherein the first cookie is associated with the first domain, and in response to determining that the first cookie is not present, the domain server is configured to obtain propagation information from the web browser, wherein the propagation information is derived from recorded information in a second cookie associated with a second domain, wherein the recorded information is derivable from the propagation information, to determine the recorded information from the propagation information, and to instruct the web browser to record the recorded information in the first cookie.

[0020] The domain server may be further configured to instruct the web browser to communicate with the first web server in order to enable the generation of content for the web browser using the recorded first cookie.

[0021] In one embodiment, the domain server is further configured to instruct the web browser to communicate with a propagation server associated with a propagation domain different from the first domain when acquiring intermediate information, the propagation information being provided to the web browser from the propagation server in response to the instruction, and the web browser receiving the propagation information after being instructed to communicate with the domain server again. The propagation information may be generated according to propagation rules available to the propagation server, and the propagation rules may be applied to the information stored in a propagation cookie. The propagation rules may be stored in a propagation cookie stored in the web browser.

[0022] In one embodiment, the intermediate means is stored as webpage-specific data, and the domain server is further configured to identify the webpage-specific data from the communication from the web browser and to communicate an instruction to set the first cookie together with the recorded information, wherein the recorded information is equal to or derived from the webpage-specific data. The webpage-specific data may be set during a previous instance of communication with a second domain server of a second domain. The webpage-specific data may not be accessible to executable code when executed in the web browser, but may be accessible to the first domain server when set by communication with the second domain, preferably only accessible by an external server. The webpage-specific data may be stored in an ETag associated with the webpage provided to the web browser before the instruction is communicated. The recorded information may be propagated from the second cookie to the first cookie only when the second domain is identified as being associated with the first domain.

[0023] The web browser communicating with the aforementioned domain server does not need to allow access to third-party cookies.

[0024] According to yet another aspect of the present invention, a network system is provided for facilitating the propagation of recorded information between first-party cookies associated with different domains in a web browser communicating with the network system, the network system comprising one or more domain servers, each domain server configured to receive communications from the web browser by a redirect command provided to the web browser from a web server associated with the domain, determine whether a first cookie is present in the communications, that the first cookie is associated with the domain, and, in response to the determination that the first cookie is not present, obtain propagation information from the web browser, that the propagation information is derived from recorded information in a second cookie associated with a second domain, the second domain being associated with another domain server, the recorded information being derivable from the propagation information, determine the recorded information from the propagation information, and instruct the web browser to record the recorded information in the first cookie.

[0025] Selectively, the network system further comprises propagation servers associated with propagation domains different from the first domain, each domain server further configured to instruct the web browser to communicate with the propagation server associated with the propagation domain different from the first domain when obtaining intermediate information, and to receive the propagation information from the web browser after the web browser has been instructed by the propagation server to communicate with the domain server again, the propagation server being configured to determine the propagation information based on information provided by the web browser along with the instruction. The information may include information stored in a propagation cookie readable by the propagation server, if present. The propagation server may be configured to generate the propagation information according to propagation rules available to the propagation server, the propagation rules may be applied to the information stored in the propagation cookie. The propagation rules may be stored in a propagation cookie stored in the web browser and therefore may be received by the propagation server via the communication from the web browser. If no propagation cookie exists, the propagation server may be configured to determine the value of a propagation cookie and communicate a command to the web browser to set the value as a propagation cookie, and the propagation information may be generated according to the newly determined value.

[0026] Selectively, each domain server is further configured to identify webpage-specific data from the communication from the web browser and to communicate to the web browser an instruction to set the first cookie together with the recorded information, wherein the recorded information is equal to or derived from the webpage-specific data. The webpage-specific data may be set during a previous communication instance with the second domain server.

[0027] The recorded information may be propagated only from the second cookie to the first cookie when the second domain is identified as being related to the first domain.

[0028] The network system may further include a web server for each domain server, the web server may be configured to instruct a web browser to communicate with the associated domain server, and each web server may share a domain with the associated domain server.

[0029] The web browser communicating with the system may be assumed to permit access to third - party cookies or may not permit access.

[0030] As used herein, the word "comprising" or variations such as "comprises" or "includes" are used in an inclusive sense, that is, used to specify the presence of the recited features, but do not preclude the presence or addition of further features in various embodiments of the present invention.

[0031] To more clearly understand the present invention, embodiments will be described below by way of example with reference to the accompanying drawings.

Brief Description of the Drawings

[0032] [Figure 1] Shows a communication system according to an embodiment. [Figure 2] Shows an arrangement of cookie propagation for a particular embodiment. [Figure 3] Shows a method of propagating cookies according to an embodiment. [Figure 4A] Shows a particular implementation using the method of FIG. 3. [Figure 4B] Shows a particular implementation using the method of FIG. 3. [Figure 5A] Shows a method of propagating cookies according to another embodiment. [Figure 5B]A method for propagating cookies according to another embodiment is shown. [Figure 6] This demonstrates how to generate domain cookies via a third-party content server. [Figure 7A] This document describes an embodiment for generating user identification cookies and propagating information. [Figure 7B] This document describes an embodiment for generating user identification cookies and propagating information. [Figure 7C] This document describes an embodiment for generating user identification cookies and propagating information. [Figure 8A] This relates to using a proxy server to modify communication to third-party resources. [Figure 8B] This relates to using a proxy server to modify communication to third-party resources. [Figure 8C] This relates to using a proxy server to modify communication to third-party resources. [Figure 8D] This relates to using a proxy server to modify communication to third-party resources. [Figure 8E] This relates to using a proxy server to modify communication to third-party resources. [Modes for carrying out the invention]

[0033] Figure 1 shows a communication system 10 according to one embodiment. The system 10 comprises a client device 11, a web server 12, a domain server 13, and an optional (third-party) content server 14. The client device 11 is configured for data communication with the web server 12, the domain server 13, and, if applicable, the content server 14, via a network 15, which typically includes the Internet. In the illustrated embodiment, the client device 11 communicates with the content server 14 via the domain server 13.

[0034] System 10 in Figure 1 should be understood as an illustrative representation of data connections between various elements, but not as an extension.

[0035] For example, a particular embodiment may utilize fewer elements than those illustrated, while other embodiments may utilize additional elements. Furthermore, the various servers 12-14 should be understood as representing functional elements unless otherwise specified. Each server 12-14 may be embodied in separate physical hardware, but two or more servers 12-14 may be embodied in the same physical hardware, for example, as logically distinct elements. Similarly, unless otherwise specified, the client device 11 should be understood as a functional element that enables a user (or, in fact, multiple users) to interact with the system 11.

[0036] The client device 11 is configured to run an application suitable for requesting web content (for example, via the HTTP protocol), and is typically a web browser (as assumed herein). The web browser is capable of communicating with a web server 12 that hosts a particular website. For example, the web browser may perform such communication in response to user input (for example, selecting a hyperlink that leads to a website, or entering the URL address of a website), or it may perform such communication automatically in response to instructions from software running on the client device 11.

[0037] The client device 11 may be any computing hardware suitable for running applications suitable for requesting web content, such as a personal computer (PC) or a smartphone. Other devices, such as smartwatches, tablets, and various form factors of PCs including desktops, laptops, and netbooks, are also envisioned. A common characteristic of the client device 11 is its ability to communicate network data with a network 15, such as via wired (e.g., Ethernet®) or wireless (e.g., Wi-Fi, such as one or more of the various IEEE 802.11 standards). No specific data communication is envisioned for the purposes of this disclosure. The client device 11 can implement any number of operating systems, such as Microsoft Windows-compatible operating systems (OS), Apple OS X, and Linux distributions. Smartphones are known to implement, in particular, the Android or iOS operating systems.

[0038] The various servers 12-14 can be implemented with appropriate hardware as needed. For example, each server 12-14 can be implemented with dedicated computing hardware. However, cloud-based implementations in which one or more servers 12-14 are implemented as virtual servers are also envisioned, such as those provided by Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform, and Oracle Cloud. Generally, each server 12-14 is associated with a processor and memory, where the processor executes code that implements the functionality of the server 12-14, and the memory is provided to store that code and to provide a working memory space. The memory may include both volatile and non-volatile memory. Each server 12-14 is provided with access to the aforementioned network 15 and / or direct access to one or more other servers 12-14, depending on the requirements of the particular implementation.

[0039] In general, network 15 is flexible and may receive data communications via any number of protocols, such as Ethernet®, 802.11, WiMAX (worldwide interoperability for microwave access), 3G, 4G, CDMA, and Digital Subscriber Line (DSL). Similarly, network protocols used in network 15 may include any number of protocols, such as Multiprotocol Label Switching (MPLS), Transmission Control Protocol / Internet Protocol (TCP / IP), User Datagram Protocol (UDP), Hypertext Transport Protocol (HTTP), Simple Mail Transfer Protocol (SMTP), and File Transfer Protocol (FTP). Data exchanged over network 15 may be represented using one or more of the following technologies and / or formats: Hypertext Markup Language (HTML), Extended Markup Language (XML), and JSON (JavaScript Object Notation). Furthermore, all or part of the communications can be encrypted using conventional encryption technologies such as Secure Sockets Layer (SSL), Transport Layer Security (TLS), and Internet Protocol Security (IPsec).

[0040] In this specification, “browser executable code” refers to JavaScript, the primary example being JavaScript. JavaScript is a widely known technology of the World Wide Web and is itself an application that operates on the Internet. One estimate suggests that 97% of websites use JavaScript for the operation of client-side web pages (i.e., the generation of web page content and operation by the execution of JavaScript in the web browser of the client device 11), but unless the context or a particular claim indicates otherwise, specific browser executable code and corresponding programming languages ​​should not be considered limiting. In this regard, browser executable code needs to be suitable for execution in the web browser of the client device 11 in order to cause the web browser to perform communication functions, content generation, or other dynamic operations.

[0041] The following describes various embodiments for providing functionality without using third-party cookies, which may be substantially similar (at least from the perspective of the user of the user device 11) to certain functions known to be enabled by setting third-party cookies. Generally, the scenarios described herein involve a web browser accessing an Internet resource, which is a web page (as assumed herein) hosted by a web server 12. The web browser is directed, for example, to the address of a web page specified by a URL (Uniform Resource Locator).

[0042] According to several embodiments, both the web server 12 and the domain server 13 are configured to receive requests from the client device 11 and provide responses. For example, a request may be for content, and a response may include that content. Typically, as assumed herein, a request is based on an HTTP (Hypertext Transfer Protocol) (or an extended protocol such as HTTPS (Hypertext Transfer Protocol Secure)) "GET" message, and a response includes an HTTP / HTTPS response message. Furthermore, a response may include content containing hypertext markup language (HTML) code that defines the appearance and functionality of the web page. The HTML code defines various different content components. A response also includes HTTP headers.

[0043] Generally, when a user device 11's web browser accesses an Internet resource, it is configured to communicate webpage-specific data that has requests previously stored by the web browser for previous accesses of the Internet resource. An example is an ETag (which has an ETag value). An ETag is defined as part of HTTP and is set on the client device 11 by the resource when responding to a request. That is, if the web browser has communicated with the resource before, it may have remembered the ETag value set during the previous communication. Generally, an ETag value is specifically associated with a resource, for example, with a URL. An ETag value may or may not be valid for time limits. In another embodiment, webpage-specific data is stored in local storage accessible from the web browser, for example, through the execution of appropriate code. For convenience, this specification describes specific embodiments relating to the use of ETag as webpage-specific data, but it should be understood that this is not intended to be limiting.

[0044] The web browser operating on client device 11 is configured to store data in the form of cookies. Cookies can be of various types known in the art. In this regard, webpage-specific data is not equivalent to cookies. For example, for the purposes of this disclosure, webpage-specific data cannot be used in executable code.

[0045] Referring to Figure 2, a topology related to a specific embodiment in which multiple web servers 12a-12c (typically any number of web servers 12) communicate with network 15 is shown. A domain server 13 communicating with network 15 is also shown. Similar to Figure 1, a typical client device 11 communicating with network 15 is also shown.

[0046] Therefore, the client device 11 can communicate with each web server 12a-12c and the domain server 13 via the network 15.

[0047] Relatedly, web servers 12a-12c are distinguished in that they represent web resources (e.g., web pages) associated with different domains (represented by dashed boxes).

[0048] In other words, the first web server 12a is associated with the first web page of the first domain (e.g., www.example1.com), the second web server 12b is associated with the second web page of the second domain (e.g., www.example2.com), and the third web server 12a is associated with the third web page of the third domain (e.g., www.example3.com). Therefore, first-party cookies associated with each web server 12a-12c cannot be accessed by the other web servers 12a-12c.

[0049] One or more embodiments described herein can be used to “propagate” cookies between different domains. Here, “propagation” and “cookie propagation” mean creating first-party cookies on client devices 11 associated with each domain based on common information. For example, if information is created or determined and recorded in a first-party cookie when client device 11 visits a web resource in one domain (e.g., a first domain), a subsequent visit to a web resource in another domain (e.g., a second domain) will result in the information being recorded in a first-party cookie associated with this next visited domain. Thus, common information is effectively stored in separate first-party cookies for each web resource in different domains.

[0050] The overall effect is that common information is "propagated" between the cookies of each domain, allowing each web server 12a-12c to consistently generate personalized information by identifying each visit as coming from the same client device 11. In practice, any necessary information can be propagated. It should also be understood that each domain's cookie can store different actual data (e.g., via domain-specific encryption and / or hashing). However, the common information must be derivable from each domain's cookie.

[0051] In certain embodiments, “related” web servers 12a-12c are utilized, each having a common relationship with the other individual web servers 12a-12c. For example, each related web server 12a-12c may be “owned” (i.e., at least operated) by a common entity, but may provide different services in different domains. In one example, the first domain refers to an automobile sales service (e.g., advertising and promotion of automobiles between individuals and / or companies), the second domain refers to a non-vehicle sales service (e.g., an auction service), and the third domain refers to a content delivery service (e.g., a news site). Each of these services is provided by a common entity (e.g., Company A) under different brands and / or owning companies, so each service is associated with a unique domain.

[0052] Conventional technologies use third-party cookies to store common information (for example, a unique identifier for a particular client device 11, which may also be unique to a particular web browser and / or the user of that web browser), which is accessed by each web server 12a-12c so that each service can provide individual content to the user associated with that identifier, because third-party cookies can be accessed from each individual domain.

[0053] Therefore, one or more embodiments described herein aim to provide similar functionality that allows access to common information while avoiding the use of third-party cookies. Depending on the embodiment and implementation, the manner in which such information is used may be left to specific web servers 12a-12c.

[0054] For the purposes of this disclosure, cookies set in relation to a specific domain are referred to as “domain cookies.” Labels such as “First” and “Second” are used to distinguish different domains from the web servers 12 and domain servers 13 associated with them. Similarly, common lowercase subscripts are used to identify different features of graphics associated with a particular domain. For example, the first web server 12a and the first domain server 13a are addressable in a first domain that may be associated with a first domain cookie; the second web server 12b and the second domain server 13b are addressable in a second domain that may be associated with a second domain cookie; and the third web server 12c and the third domain server 13c are addressable in a third domain that may be associated with a third domain cookie.

[0055] According to one embodiment, with reference to Figures 3A and 3B, a method relating to setting non-cookie webpage-specific data in the web browser of a client device 11 is described. One example known in the art is ETag. This method also describes setting a first domain cookie in the web browser of the client device 11 in relation to a first webpage. The first domain cookie is a first-party cookie in that it is set in association with the same domain as the first webpage (first domain), but it is set by the first domain server 13a, not the first web server 12a. In relation to this, the first domain cookie is accessible by executable code. For example, the first domain cookie does not have the "httpOnly" attribute set. In relation to this, the webpage-specific data must be in a format that is not accessible from code executed on the client device 11. For example, the ETag value is not accessible from JavaScript. Preferably, the webpage-specific data is accessible only from web-based servers such as the web server 12 and the domain server 13.

[0056] In step 300, the client device 11 communicates a content request to the first web server 12a associated with the first domain (e.g., www.example1.com) as described above. The request typically specifies a particular web page on which the content is needed. Note that a default web page may be selected (e.g., http: / / www.example1.com / index.html). In step 301, a response is communicated from the first web server 12a to the client device 11. This response is determined according to the request. The response comprises a domain server communication command (as executable code) that is executed by the web browser of the client device 11 (e.g., in the form of JavaScript code), and content that is typically displayed in the web browser.

[0057] The domain server communication command is a command for the web browser of the client device 11 to communicate with the first domain server 13a. In this context, the domain server 13 resides in the same domain as the first web server 12a, but the domain server 13 may be located at a different IP address than the web server 12. In certain implementations, the first domain server 13a is addressed using a subdomain of the first domain (for example, http: / / processing.example1.com). Therefore, as mentioned above, the first domain cookie set by communication with the first domain server 13a becomes a first-party cookie (because it shares a domain with the first web server 12a).

[0058] Depending on the implementation, the domain server communication instruction includes first executable code configured to cause the web browser to communicate with a first domain server 13a. Alternatively, the domain server communication instruction includes instructions for the web browser to obtain the first executable code from the domain server 13a. In either case, the first executable code is provided to the web browser as a result of step 301.

[0059] In step 302, the web browser executes the first code. The first code is configured to execute the verification step 303, where the web browser performs a verification of the first domain cookie that was previously stored by the web browser. As previously mentioned, the first domain cookie can access the first code if it exists. In connection with this, as previously mentioned, the first domain cookie is associated with the domain of the web page (i.e., the first domain).

[0060] If the first domain cookie does not exist, the first code is configured in step 310 to cause the web browser to communicate a request to the first domain server 13a. If available, the ETag value associated with the web page (or, depending on the embodiment, other web page-specific data) is communicated with the request (if an ETag exists, the ETag value is communicated as defined by the HTTP standard).

[0061] Next, in step 311, the first domain server 13a is configured to determine whether an ETag value exists with the request when it receives a request.

[0062] In this situation (where a first domain cookie exists), the presence of an ETag value indicates to the first domain server 13a that the web browser has previously accessed a second website (e.g., associated with the second web server 12b) and that the first website is hosted on a different domain (e.g., the second domain), and that the second domain cookie has been set by the second domain server 13b in relation to the second domain (therefore, the second domain cookie is a first-party cookie for the second domain and is therefore inaccessible in communication with the first domain server 13a). In this scenario, the first domain server 13a is configured in step 314 to communicate a response to the client device 11 that sets a domain cookie associated with the first domain using a value derived from (e.g., including) the ETag value. As a result, the web browser remembers the "first-party" first domain cookie associated with the first domain and records the same information as the second domain cookie associated with the second domain.

[0063] If an ETag value does not exist, the first domain server 13a is configured to determine in step 312 the data to be stored together in the first domain cookie and as the ETag value, and in step 313 send a response to the web browser of the client device 11 instructing it to set both the first domain cookie and the ETag value. With respect to step 312, the specific means by which the first domain server 13a determines the data varies depending on the implementation. However, in one particular example, the data is obtained or derived from the content server 14 (for example, from a set cookie command issued by the content server 14). In this case, the first domain cookie and the ETag value reflect the storage information obtained from the content server 14. The set cookie command issued by the content server 14 is, in effect, a command to set a third-party cookie, since the content server 14 is on a different domain than the first domain. In another example, the first domain server 13a itself is configured to determine the data to be stored as the first domain cookie and the ETag value. This could be, for example, a randomly or procedurally generated identifier, or other data for future use by web servers 12a-12c and / or domain servers 13a-13c.

[0064] Next, we examine the result of step 303, which checks for the existence of the first domain cookie. In step 320, the first code is configured in response to cause the web browser to communicate a request to the first domain server 13a. The request is accompanied by information 13 stored in the first domain cookie (which makes that information available to the first domain server 13a), and, if available, an ETag value (or, depending on the embodiment, other webpage-specific data).

[0065] In step 321, the first domain server 13a checks whether an ETag value is attached to the request.

[0066] If the request does not include an ETag value, the first domain server 13a communicates a response to the client device 11 in step 322 that includes a set ETag command, where the ETag is set to the value of the first domain cookie (or at least a value derived from the first domain cookie data). In this way, the web browser effectively stores the information recorded in the first domain cookie value in the ETag.

[0067] On the other hand, if an ETag value is attached to the request, in step 323, the first domain server 13a may communicate a response to the client device 11 specifying that neither the ETag nor the domain cookie needs updating. Similarly, the response may be an instruction to refresh either or both of the ETag value and the first domain cookie (this may be useful, for example, if either or both of the ETag and the domain cookie have a finite validity period).

[0068] Therefore, Figure 3 defines a mechanism that allows data from a first-party domain cookie associated with one webpage to be copied to a first-party domain cookie associated with another webpage. Thus, the data only needs to be determined once for one webpage and then propagated between other webpages associated with other domains. As a result, the method in Figure 3 provides a first-party domain cookie for each different domain that records the same information, so in effect, a collection of first-party domain cookies can advantageously provide the same functionality as a single third-party cookie.

[0069] According to one embodiment, one or more associated domain cookies are modified with respect to the original information. For example, the domain cookies may undergo an anonymization routine to obfuscate the original information. Preferably, the modification is reversible by the associated domain server 13 so that the domain server 13 can accurately determine the original information from the associated domain cookies. For example, an encryption key can be used with the domain name of the domain cookie, so that each domain cookie is associated with a different encrypted output derived from the same information. In another example, a random prefix or suffix of a known size (i.e., known to the associated domain server 13) is added.

[0070] Figures 4A and 4B show an implementation of the embodiment shown in Figure 3. In step 400, the user of a web browser on the client device 11 directs the web browser to a first web page hosted by a first web server 12a. In step 401, the first web server 12a returns a response containing HTML code that defines the content to be displayed on the client device 11. In step 402, this response also includes first executable code containing instructions as described with reference to Figure 3. Alternatively, the response may include instructions (again in step 402) to retrieve the first executable code from a first domain server 13a, and the web browser subsequently retrieves the first executable code.

[0071] In step 403, the web browser communicates with the first domain server 13a by executing the first executable code and, if available, communicates the first domain cookie associated with the first domain server 13a. Furthermore, the first domain server 13a obtains webpage-specific data that is not accessible to the executable code but is accessible to the first domain server 13a, regardless of the ETag value (or, more generally, which domain server initially set the webpage-specific data value (i.e., which domain was accessed when the webpage-specific data was set)). For example, the web browser of the client device 11 accesses a web resource such as an image on the first domain server 13a and communicates the ETag value associated with the image to the first domain server 13a (if available). Thus, the first domain server 13a is configured to identify the ETag value of a particular image. The first domain cookie becomes available if it was previously set by the first domain server 13a for a previous communication. The ETag becomes available if it was previously set by any of the domain servers 13 for a previous communication (for example, when an image is communicated to the client device 11, an appropriate ETag value is set in relation to the image (according to the embodiment described here)).

[0072] Figure 4A shows the situation determined in step 404 where neither the first domain cookie nor the ETag can be used for communication with the first domain server 13a. In this case, the method in Figure 3 results in step 313 (setting the values ​​of the first domain cookie and ETag). The values ​​of the first domain cookie and ETag can be generated by the first domain server 13a, the first web server 12a, or the content server 14 (depending on the implementation).

[0073] In this particular example, the first domain cookie (first domain) is set in the first communication in step 405. Next, the web browser is configured to communicate again with the first domain server 13a and sends the data of the first domain cookie (now set by step 505) in step 406. Considering the method in Figure 3, the first domain server 13a terminates in step 322. In step 407, a response is communicated to the client device 11 instructing it to set an ETag equivalent to the first domain cookie (first domain). In this sense, the first executable code is executed essentially twice. The first execution results in step 313 in Figure 3, and the second execution results in step 322 in Figure 3.

[0074] Figure 4B shows a situation where the first domain cookie (first domain), determined in step 404, is unavailable, but the ETag can be used to communicate with the first domain server 13a. In this case, the method in Figure 3 results in step 314 (setting the value of the first domain cookie based on the ETag). This means that the web browser has visited a webpage hosted on a different domain than the current webpage, but is using the associated domain server 13. Therefore, a different domain cookie has been set in relation to the different domain and can be used to set the first domain cookie for the first domain.

[0075] In this example, the first domain cookie (first domain) is set in step 408 by a response communicated from the first domain server 13a to the client device 11. Further execution of the method in Figure 3 may occur during the current process, but will result in step 323 of Figure 3, and no action is required. In this sense, the first executable code may be executed twice, with the first execution resulting in step 314 of Figure 3 and the second execution resulting in step 323 of Figure 3.

[0076] Therefore, the embodiment shown in Figure 3 (and the examples in Figures 4A and 4B) effectively "notifies" whether another domain cookie from another related domain exists when accessing a web page of the first domain, by utilizing non-cookie webpage-specific data stored in the web browser of the client device 11.

[0077] According to one embodiment, as shown in Figure 5A, the propagation server 16 is associated with a propagation domain (e.g., www.exampleserver.com). The propagation server 16 is configured to facilitate the propagation of cookie information between domain cookies, each associated with one of several domain servers 13a-13c, meaning that the propagation server 16 can easily exchange data with each domain server 13a-13c. The propagation server 16 is capable of data communication with the network 15. While it may be desirable for each domain server 13 to be logically and / or physically distinct from the propagation server 16, it is also possible to embody one or more domain servers 13 as logical functions of the propagation server 16. Figure 5A also shows several web servers 12a-12c. Similar to Figure 1, a typical client device 11 communicating with the network 15 is also shown.

[0078] Therefore, the client device 11 can communicate with each web server 12a-12c, each domain server 13a-13c, and the propagation server 16 via this network 15. In connection with this, each domain server 13a-13c can be addressed in its respective domain as one of the web servers 12a-12c as described above.

[0079] In one implementation, each domain server 13 is addressable via a subdomain of the associated domain. The subdomain may be labeled as needed, and each is related to being resolvable to the network address (e.g., an IP address, optionally a TCP or UDP port number) of the associated domain server 13. Depending on the implementation, each domain server 13 may be located at the same IP address as the associated web server 12 or at a different IP address.

[0080] Figure 5B illustrates a method relating to setting a first domain cookie associated with a first domain, depending on the existence and value of a common cookie ("propagation cookie") associated with the propagation domain, thereby enabling access to the first web server 12a and the first domain server 13a. The common cookie may be, for example, an identifier associated with a particular client device 11 (in this case, referred to herein as the "user ID").

[0081] In step 500, the client device 11 communicates a content request to the first web server 12a. The request typically specifies a particular web page on which the content is required. Note that a default web page may be selected (e.g., http: / / www.example1.com / index.html). In step 501, a response is communicated from the first web server 12a to the client device 11. This response is determined according to the request. The response includes a domain server communication command that is executed (as executable code) by the web browser of the client device 11 (e.g., in the form of JavaScript code) and is configured to cause the client device 11 to communicate with the first domain server 13a. The response also typically includes content that is displayed in the web browser. Alternatively or additionally, the first web server 12a may send a redirect command to the first domain server 13a (e.g., via the Location header in the response).

[0082] In step 503, the first domain server 13a receives communication from the client device 11, analyzes the content, and determines whether a previously set first domain cookie exists (usually in the header in the case of HTTP).

[0083] If a first domain cookie exists (for example, if cookie propagation is not required), the method simply proceeds to the web page rendering step 512 (described later), which can be performed by the first domain server 13a communicating instructions to the client device 11 to make further communication with the first web server 12a.

[0084] If a first domain cookie does not exist (for example, if cookie propagation or initial creation is required), the first domain server 13a communicates a response from the first web server 12a to the client device 11 in step 504. The response includes a propagation server communication command (for example, in the form of JavaScript code) that is executed by the web browser of the client device 11 (for example, as executable code) to cause the client device 11 to communicate with the propagation server 16. Alternatively or additionally, the first domain server 13a may send a redirect command to the propagation server 16 (for example, via the Location header in the response). In response, the client device 11 communicates a request to the propagation server 16 in step 505, the request selectively including information that identifies the first domain server 13a (for example, the information may be passed via a URL or an appropriate network protocol).

[0085] In step 506, the propagation server 16 receives communication from the client device 11, analyzes the content, and determines in step 505 whether a propagation cookie exists (usually in the header in the case of HTTP). The presence of a propagation cookie indicates that the client device 11 has previously visited the relevant domain (e.g., a second or third domain), and as a result, a domain cookie (e.g., a second or third domain cookie) is set in relation to the relevant domain. If no propagation cookie exists, it indicates that the client device 11 has not previously visited the relevant domain and a domain cookie has been set for the relevant domain.

[0086] If no propagation cookie exists, in step 507, the propagation server 16 is configured to determine the information to record in a new propagation cookie on the client device 11. The information may be generated randomly, procedurally, or alternatively, via communication with the content server 14 (not shown in Figure 5B).

[0087] In either case, in step 508, the propagation server 16 communicates a response to the client device 11. The response includes a domain server communication instruction that is executed (e.g., as executable code) by the web browser of the client device 11 (e.g., in the form of JavaScript code) and is configured in step 509 to cause the client device 11 to communicate with the original domain server 13 (i.e., the first domain server 13a in this example). Alternatively or additionally, the propagation server 16 may directly redirect to the first domain server 163 (e.g., via the Location header in the response).

[0088] If step 507 is performed, the response also includes a set propagator cookie command that causes the client device 11 to set up propagation associated with the propagation domain that records the generated information.

[0089] In response, in step 510, the client device 11 communicates a request to the first domain server 13a. In response to the request, in step 511, the first domain server 13a is configured to determine the information recorded in the propagated cookie and communicates a response including a set cookie command to the client device 11, causing the client device 11 to set a first domain cookie associated with the first domain on which the information is recorded.

[0090] In one embodiment, the domain server 13a obtains information from the web browser of the client device 11. For example, the domain server communication command in step 508 includes information recorded in a propagating cookie and is configured to cause the web browser of the client device 11 to communicate that information (preferably encrypted) to the first domain server 13a. For example, the information may be transmitted via a URL or an appropriate network protocol. Here, the client device 11 is effectively used as an intermediary, which can advantageously enable a method to avoid direct communication between the propagating server 16 and the domain server 13. This can result in improved privacy and / or security (or at least a perceived improvement).

[0091] In another embodiment, the propagation server 16 is configured to identify a first domain server 13a (more generally, a specific domain server 13 that initiated communication from the client device 11 to the propagation server 16, which can be derived from a request received by the propagation server 16), and to communicate to the first domain server 13a information generated or previously recorded (or at least data derived from recorded information) regarding the propagation cookie, generally along with information identifying the specific client device 11.

[0092] The response also includes a web server communication command (for example, as executable code) that is executed by the web browser of the client device 11 (for example, in the form of JavaScript code) to cause the client device 11 to communicate with the original web server 12 (i.e., the first web server 12a in this example). Alternatively or additionally, the first domain server 13a may send a redirect command to the first web server 12a (for example, via the Location header in the response).

[0093] Next, the method proceeds to the web page rendering step 512 (which may be reached after step 503). In this step, the first web server 12a communicates with the client device 11 (which may include multiple separate communication instances) and can utilize the content of the first domain cookie for the generated personalized content. The first domain cookie is accessible from the first web server 12a because it shares the first domain with the first domain server 13a.

[0094] Therefore, the method shown in Figure 5B can be used to effectively propagate cookies to various web servers 12a-12c (more generally, to propagate information recorded in cookies between different domain cookies). Propagation cookies are used to inform the propagation server 16 (through whether or not) that a client device accessing a particular web server 12 has previously accessed another related web server 12 on a different domain, and therefore, that previously generated information is intended to be commonly available to multiple related web servers 12 (e.g., all web servers 12a-12c). For example, this information may be a user ID suitable for identifying that a particular client device 11 (or a particular user of said client device 11) has previously visited a related website on a different domain. If the information recorded in the propagation cookie is an identifier such as a user ID, a domain cookie can record the user ID or information derived from the user ID as a domain ID (i.e., each domain ID corresponds to a specific domain, but is associated in a way that enables user identification). Therefore, a related web server 12 can utilize a collection of domain cookies with relevant domain IDs to generate personalized information for the client device 11. Direct communication between domain server 1 and propagation server 16 enables effective propagation.

[0095] In one embodiment, referring to Figures 7A-7C, the propagation server 16 is interfaced with a rule module 18 (see Figure 7A). The rule module 18 may be a logical function of the propagation server 16 (assumed here) and may be implemented as a separate physical or logical server for data communication with the propagation server 16. Also shown are four web servers 12a-12d, where web servers 12a and 12b are associated with a first group 20a and web servers 12c and 12d are associated with a second group 20b. The web servers 12 can be grouped according to specific relationships, but for the purposes of the present invention, the first group 20a includes web servers 12a and 12b of a domain managed (e.g., owned) by a first entity, and the second first group 20b, unlike the first, includes web servers 12c and 12d of a domain managed (e.g., owned) by a second entity. In relation to this, according to this embodiment, the propagation server 16 is configured to manage cookie propagation for all web servers 12a-12d (more generally, web servers 12 belonging to different groups 20).

[0096] The rule module 18 is configured to apply propagation rules before communicating a response containing a domain cookie (depending on the embodiment) to the client device 11 and / or the domain server 13. The propagation rules are used to determine whether a domain cookie is set, and if so, what specific data it contains (for example, for unique encryption that may be associated with a particular domain, the specific data may record information common to other domain cookies and / or propagation cookies in a different format).

[0097] In one embodiment, the propagation rules used to generate data for a specific domain cookie are stored in the associated propagation cookie itself.

[0098] Therefore, the propagation rules of this embodiment are stored in the user's web browser and can advantageously avoid the central location of propagation rules for many different users. In this embodiment, the propagation rules are typically recorded in an encrypted form so that the propagation rules stored in the propagation cookie cannot be revealed by directly reading the propagation cookie.

[0099] In one embodiment, the rule module 18 is configured to maintain, alternatively or similarly, a data structure, such as a database (here, the "ID database"), that identifies known (i.e., previously determined) propagation cookies and associated information. When a new propagation cookie is determined and the associated information changes, the data structure may be updated. The associated information includes the propagation rules for each user (which may be default or customized).

[0100] Figure 7B illustrates a method for determining a response by the propagation server 16 according to one embodiment. The method in Figure 7B assumes that a propagation cookie already exists associated with a particular client device 11 (more specifically, the web browser on client device 11). That is, the web browser has either previously visited one of the web servers 12 regardless of group 20, or a new propagation cookie was generated before Figure 7B was implemented. The propagation cookie effectively represents a user (or a particular client device 11 or the web browser on a particular client device 11) and can therefore be considered an identifier. Thus, for illustrative purposes, the content of a particular propagation cookie records the user ID.

[0101] In one embodiment, the method shown in Figure 7B is performed as part of step 508 in Figure 5B. In this case, the propagation server 16 is configured to distinguish between information stored in propagation cookies and information stored in (multiple) domain cookies.

[0102] In step 700, the rule module 18 receives information recorded in the propagation cookie (assuming here is a user ID), and in step 701, it receives information identifying the domain of the web server 12 being accessed by the client device 11 (this information may be provided at the same time).

[0103] Next, the rule module 18 determines a specific propagation rule associated with the user (more specifically, the propagation cookie) in step 702. For example, depending on the embodiment, the rule module 18 may obtain the propagation rule from the actual propagation cookie.

[0104] In another embodiment, the user ID is compared with a record in the ID database to determine whether the user ID has been previously stored in the ID database. As in other embodiments, the user ID may be stored in a derived form within the actual propagation cookie, for example, using an encryption algorithm. In connection therewith, the user ID is derivable from the propagation cookie.

[0105] If the rule module 18 is unable to determine a particular propagation rule (for example, it is not stored in the propagation cookie or does not exist in the ID database, depending on the embodiment), the method proceeds to step 703, in which the rule module 18 determines and selects a default rule set to be applied in the subsequent step 706. There may be a single default rule set or multiple default rule sets, and the rule module 18 is configured to determine which of the applicable default rule sets is appropriate as needed (for example, based on the relevant domain, information about the client device 11, or other factors).

[0106] Furthermore, in step 704, the rule module 18 stores the selected rule set as propagation rules associated with the propagation cookie. For example, in a relevant embodiment, the propagation rules can be set as the content of the propagation cookie by setting or updating the propagation cookie in the client device 11. In embodiments where an ID database is used, the rule module 18 stores the selected rule set in an ID database reference to the propagation cookie information, along with a user-specific rule set that may simply be the same as the selected default rule set. However, to customize the default rule set before it is recorded as a user-specific rule set, the user may be provided with an option during the method in Figure 7B, for example, by a website redirect or a "popup".

[0107] On the other hand, if the user ID is indeed present in the propagation cookie or ID database (if applicable), the method proceeds to step 705. The rule module 18 selects a specific propagation rule associated with the user ID (more specifically, the propagation cookie). The method then proceeds to step 706.

[0108] In step 706, the rule module 18 applies the selected rule set to determine the value of a domain cookie (domain ID) for communicating with the associated domain server 13 (for example, as used in step 508 of Figure 5B). In relation to this, the domain ID stored in the domain cookie may be different from the user ID. It should also be understood that in one embodiment, if this determination is made by a rule set, the rule module 18 may decide not to set a domain ID. In other words, no domain cookie is generated as a result of the embodiment.

[0109] In one implementation, the rule set is configured to identify which domains are allowed to propagate cookies and which are not. For example, a particular propagation rule might define which specific domains the user has consented to allow cookie propagation to, and / or which specific domains the user has not consented to allow cookie propagation to.

[0110] In the case of a user-specific rule set, the user of the client device 11 that generated the propagation cookie may, in one embodiment, access a dashboard (or other interface) associated with the specific propagation cookie to configure whether to allow or deny specific domains. Similarly, the user may allow or deny domain categories (e.g., all sales domains, all news domains, etc.). The dashboard may be provided as a website associated with the propagation server 16 (either hosted directly on the propagation server 16 or via another web server (not shown)).

[0111] Referring again to group 20 shown in Figure 7A, in one embodiment, the rule module 18 is further configured to determine a domain cookie based on whether a particular domain is accessed by the client device 11. For example, a first group 20a may be associated with a first group domain cookie, and a second group 20b may be associated with a second group domain cookie. Thus, a particular domain cookie generated depends on a particular group 20. In this example, if the client device 11 is communicating with web server 12a or 12b, it is set to the value of the first group domain cookie, and if the client device 11 is communicating with web server 12c or 12d, it is set to the value of the second group domain cookie.

[0112] This embodiment may be advantageous when the propagation server 16 and domain server 13 are provided by a service provider as part of a service to a large number of different entities (and thus groups 20). Thus, cookies are propagated substantially only between domains of a particular group 20; that is, one entity is not provided with cookie information associated with another entity. This embodiment may also be advantageous when combined with user control (e.g., via a dashboard) of a user-specific set of rules, as it gives the user control over a large number of different groups 20 of the relevant domains. For example, if a user selects a category of websites for which propagation is not permitted, this selection applies to many different entities. For example, if a user does not permit propagation between "news websites," this may apply to news websites of entity A and news websites of entity B.

[0113] Furthermore, while certain implementations may allow users to consent to having common domain cookies for multiple groups 20, such inter-group propagation is generally unlikely to be permitted by default.

[0114] The method in Figure 7B may be suitable to be performed as part of step 313 or 314 in Figure 3, that is, when determining the domain cookie to be set on the client device 11. In the latter case, it is necessary to separate the value of web page-specific data (e.g., ETag) from the domain cookie in which the ETag may act as a propagating cookie.

[0115] In one embodiment, a domain cookie pre-configured for a specific domain can be modified. For example, a user who previously allowed propagation to a specific domain may change their settings to no longer allow the use of UserID derivation information with respect to that domain. Similarly, a user may decide to cancel or delete all references to UserID and DomainID. The cookies in the client device 11 should be updated to reflect this change.

[0116] Figure 7C shows a modification of the method in Figure 5B. Steps that have been previously described and remain unchanged are as previously described here. Modified steps are denoted by the suffix "A". Step 502 always proceeds to step 504, then in step 505A, when the domain cookie is identified, information indicating the presence of the domain cookie is communicated to the propagation server 16. This is done, for example, by the client device 11 communicating the information as part of a request, in response to a communication command from the propagation server. For example, the information may be passed via a URL or an appropriate network protocol. In one embodiment, the client device 11 communicates a flag indicating the presence of the domain cookie (for example, when the presence of the domain cookie is relevant, but the actual content is not, in order for the propagation server 16 to decide whether to proceed to the modified step 506A).

[0117] The modified step 506A checks whether the propagation cookie and domain cookie exist on the client device 11. However, if the propagation server 16 determines that the propagation cookie and domain cookie do not exist, it performs a predefined action. In one implementation, the absence of the propagation cookie means that the user no longer intends to make the information available, and in effect, the "deletecookie" command needs to be propagated.

[0118] Therefore, in step 507A, the propagation server 16 generates a delete domain cookie instruction (as executable code to be executed, for example, in the web browser of the client device 11) which is contained within the domain server communication instruction communicated in step 508A, and is configured to cause the client device 11 to communicate with the original domain server 13 (i.e., the first domain server 13a in this example). Alternatively or additionally, the propagation server 16 may directly redirect to the first domain server 163 (for example, via the Location header in the response). The domain server communication instruction contains an instruction understandable by the domain server 13 for deleting the domain cookie.

[0119] In response, in step 510, the client device 11 communicates a request to the first domain server 13a. In response to this request, in step 511, the first domain server 13a is configured to respond to the client device 11 in step 511A with a delete cookie command that deletes the domain cookie based on the command contained in the domain server communication command (or, in another implementation, sets it to null or a random value), thereby effectively deleting the propagated information.

[0120] The response also includes a web server communication command (for example, as executable code) to be executed by the web browser of the client device 11 (for example, in the form of JavaScript code), which is configured to cause the client device 11 to communicate with the original web server 12 (i.e., the first web server 12a in this example). Alternatively or additionally, the first domain server 13a may send a redirect command to the first web server 12a (for example, via the Location header in the response).

[0121] The method then proceeds to the web page rendering step 512. In this step, the first web server 12a communicates with the client device 11 (which may include multiple separate communication instances), but the generated content is not based on information previously stored in the first domain cookie.

[0122] Regarding Figure 7C, it should be noted that if both propagation cookies and domain cookies exist, the propagation server 16 may proceed by effectively resetting the domain cookie and / or propagation cookie to the same value, or by not sending a cookie set command.

[0123] This method can also be modified in relation to the existence of a first domain cookie. In this case, the propagation server 16 checks whether the first domain cookie contains data that matches the current propagation rule. If the first domain cookie information does not match the information in the propagation cookie (the comparison involves applying the propagation rule), the propagation server 16 is configured to decide to update the first domain cookie. For example, if a user has not allowed propagation to the associated domain, the propagation server 16 can delete the domain cookie by communicating a delete cookie command to the web browser of the client device 11. If it is necessary to change the value of the domain cookie, this can also be communicated as a new set domain cookie (equivalent to overwrite) command.

[0124] The embodiments described with reference to Figures 7A-7C can favorably provide a balance between privacy, by allowing users to select the domains to which cookies are permitted to propagate, and e-commerce functionality, by enabling content providers to deliver customized content based on consistent identification of specific users.

[0125] It may be desirable to provide a means to inform the web browser on the client device 11 that certain redirects between web resources of different domains are trusted (e.g., the domain of the web server (and domain server) and the propagation domain). Similarly, it may be desirable to provide trust in relation to webpage-specific data that may be associated with different domains (in particular, ETag). In either case, the relevant technologies circumvent certain privacy and security issues of third-party cookies, but they may still be considered undesirable from a trust perspective.

[0126] In one embodiment, a trust signal is defined that can be configured to be identified by a web browser. The trust signal should be data that is accessible by the web browser and is likely, though not certain, to be controlled and originated from the same entity that controls a particular domain. For example, it may be desirable for a domain server 12 on a first domain to be able to do so because it is trusting the other domain on the grounds that the entity has intentionally implemented a service that utilizes the embodiments described herein, and it is possible to redirect or access webpage-specific data (e.g., ETag) associated with a propagation domain or another second domain. A suitable trust signal can inform the web browser to allow such interaction even if the web browser would otherwise block such interaction with the other domain. For example, a particular web browser has recently stopped providing ETag access between domains.

[0127] In the particular embodiment considered, the DNS of the domain of the domain server 12 (i.e., the entity) is modified, and in particular, records identifying each trusted domain (assumed to be TXT records here) are entered (e.g., as a list in plain text). For example, in the case of a first domain, a second domain, a third domain, and a propagation domain, the TXT records in the DNS entries of the first domain, the second domain, and the third domain are modified to refer to each other's domains (including the propagation domain).

[0128] DNS TXT records can be considered reliable because they can be reliably assumed to be controlled by the same entity that controls the domain. Furthermore, web browsers may cache DNS information during a session in which a user is accessing the domain on client device 11. Therefore, the records are available to the web browser (likely in the cache) and can be easily verified.

[0129] Therefore, when a web browser is instructed to redirect (JavaScript, Location header, etc.) or access information from another domain, it compares the DNS TXT record with that domain to determine if that domain exists. For example, if a web browser remembers (caches) ETags, the same logic can be used to partition the cache based on those domains, so that the same resource can be cached across the entire collection, and information and cache can be shared. It is also envisioned that this DNS TXT record approach can be used as a "second-party cookie" or "network cookie" signal to allow server-side cookies to be set on those domains. This is essentially a third-party cookie effect (access from another domain) but without inherent privacy and security issues. This means, for example, if example.com calls a resource on example01.com, example01.com can set a cookie within a browser belonging to example01.com, even if the user is on example.com (i.e., this usually means a third-party cookie).

[0130] Specific advantages of this approach may include one or more: (1) only the domain owner can control trust, meaning that JS, browsers, or anyone else cannot manipulate this information; (2) even if someone reads the TXT records, they mean nothing to them; and (3) if a company adds or removes a domain from its network, the changes propagate effectively and quickly, requiring no updates to the website or other components.

[0131] In one embodiment, with reference to Figure 6, a method is provided for determining the value of a domain cookie using a cookie associated with the content server 14 ("content cookie"). Similarly, this method describes a method for determining a content cookie to communicate with a third-party server 14 using a domain cookie present on the client device 11. This embodiment may be advantageous in that it allows the third-party content server 14 to continue using third-party cookies while avoiding setting third-party cookies on the client device 11.

[0132] In this case, since the content server 14 is associated with a different domain for both the web server 12 and its associated domain server 13, it is prohibited (or at least preferable that the content server 14 does not set third-party cookies) for the web browser to directly set cookie values ​​in response to the web browser accessing a web page on the web server 12.

[0133] Therefore, the domain server 13 effectively converts cookie values ​​between the cookie values ​​present on the client device 11 (domain cookies) and the cookie values ​​used by the content server 14 (content cookies). The method in Figure 6 can be applied to step 312 in Figure 3, where there are no domain cookies associated with the existing second web page. In effect, the domain server 13 performs the conversion between the content cookies of the content server 14 (which are essentially third-party cookies) and the first-party cookies (domain cookies) set on the client device 11.

[0134] Content cookies can be associated with different functions. For example, content cookies can enable tracking across different web pages or improve identifiability recognition.

[0135] In this embodiment, the web browser communicates requests for information provided by the content server 14 to the domain server 13. Thus, this embodiment utilizes the domain server 13 as a proxy to the content server 14. It should be understood that the described embodiment can be used with different proxy technologies. It should also be understood that direct access to the web content of the content server 14 is possible.

[0136] However, importantly, cookie-related information is passed between the client device 11 and the content server 14 via the domain server 13.

[0137] In certain non-exclusive examples, the content server 14 may be configured to provide advertising content to a web browser to be attached to content provided by the web server 12. According to known technology, the advertising content is provided dynamically and, if available, is provided at least in part based on identification information associated with the web browser (or, more specifically, the user of the client device 11). In prior art, this identification information may be stored in a third-party cookie stored in the web browser. Therefore, targeted advertisements can be provided even when visiting a specific domain during web browsing.

[0138] In step 600, the web browser communicates a request for content from content server 14 to domain server 13 (typically the request identifies content server 14, although domain server 13 may be able to automatically identify content server 14). The request is generally expected to provide a response containing content to display in the web browser, but it should be understood that it may also be a request that is only expected to return an instruction to set a content cookie associated with content server 14.

[0139] Next, in step 601, the domain server 13 checks for the existence of a previously set domain cookie, which was set by the domain server 13 on behalf of the content server 14. Step 601 may include implementing the method shown in Figure 3 (for example, including the execution of the first code on a web browser). Thus, if a domain cookie is set in association with another web page on a different domain, it is propagated to the domain cookie in association with the domain of the current web page, and therefore becomes available to the domain server 13 in association with the current web page, and is therefore determined to exist. Of course, if a domain cookie already exists in association with the current web page, it is also determined to exist.

[0140] If a domain cookie has not been set (either previously or through propagation), in step 602, the domain server 13 communicates a request for the relevant third-party content to the third-party server 14. The request does not include a content cookie to be used by the content server 14. In other words, the domain server 13 does not generate a content cookie based on an existing domain cookie. In step 603, the content server 14 returns the content (either to the domain server 13 or directly to the web browser on the client device 11). The response from the content server 14 also includes an instruction to set a content cookie containing some data. In the example of advertising content, the content server 14 could generate a new identifier to attach to the content cookie to identify the client device 11.

[0141] In step 604, the domain server 13 generates a domain cookie based on the value of the content cookie set by the content server 14. For example, the domain cookie may be generated according to an encryption algorithm or hash algorithm applied to the data of the content cookie. The domain cookie can be considered a transformed "third-party" cookie in that the content cookie is associated with a different domain than the domain cookie (and furthermore, the domain of the web server 12). In step 605, the domain server 13 generates and sends an instruction to the web browser of the client device 11 to set the domain cookie (using attributes that make the processing server cookie available to executable code, for example, by not setting httpOnly). In step 606 (which usually occurs simultaneously with step 605), the content is communicated from the domain server 13 to the client device 11.

[0142] As a result of step 605, a domain cookie is set on the client device 11, and information derived from what was set on the content cookie by the content server 14 is recorded. However, as mentioned above, the domain cookie is a first-party cookie. The domain cookie may be propagated in the future, for example, according to the method in Figure 3, and thus become available when the client device 11 visits other relevant web pages associated with different domains.

[0143] Returning to step 601, if a domain cookie is set, in step 610, the domain server 13 communicates a request to the content server 14 for the relevant content provided by the server 14. The request includes the content of the domain cookie for use by the content server 14, or content derived from the domain cookie. In other words, the domain server 13 communicates the cookie (or its information) based on the domain cookie. In step 611, the content server 14 returns the content (to the processing server 13, or directly to the web browser of the client device 11). The content server 14 does not need to generate a new content cookie. Typically, the content is generated at least partially based on the cookie information (derived from the domain cookie) communicated to the content server 14 (e.g., targeted advertising). This content is then communicated in step 612, for example, to the web browser of the client device 11 via the domain server 13 acting as a proxy.

[0144] Advantageously, the methods in Figures 3 and 6 can work together to achieve the same effect as that provided by third-party cookies simply by setting a first-party cookie on the client device 11. That is, multiple first-party domain cookies can record the same information derived from the content cookie, each associated with a specific domain. Each domain cookie can then be used to generate cookie information for communication with the content server 14. From the content server 14's perspective, it can identify the web browser (or a specific user in combination with a specific web browser) because it receives the same values ​​even though a specific web resource is accessed by the web browser of the client device 11. In other words, since the conversion between third-party and first-party cookies is handled by the domain server 13, the content server 14 does not need to make any changes to provide content and cookies to the client device 11.

[0145] As a variation, in relation to the method shown in Figure 5B, the propagation server 16 can perform the role of the domain server 13 by rewriting content cookies from the content server 14 with domain cookies for each web page domain.

[0146] In one embodiment, it is desirable to set an auxiliary cookie for each domain cookie. Each auxiliary cookie can record the same information as the associated domain cookie, or at least information that can be derived from the domain cookie (or the source from which the domain cookie is derived). In practice, each set of auxiliary cookies contains a representation of the same information, but typically the domain cookie is a modified version of the auxiliary cookie, or vice versa. Each auxiliary cookie has an attribute set to prohibit access by executable code running on the web browser. That is, for example, the httpOnly attribute may be set. Such an embodiment can offer the advantage that domain cookies set by interaction with a third-party content server 14 can be set without the httpOnly attribute. Thus, domain cookies are readable by executable code such as JavaScript, but auxiliary cookies are not.

[0147] According to this embodiment, whenever a domain cookie is set, an auxiliary cookie is also set. However, instead of reading the value of the domain cookie to generate information communication to the content server 14, the associated auxiliary cookie is accessed.

[0148] In one embodiment, the auxiliary cookie has the same value as the content cookie, and the domain cookie is an anonymized equivalent of the content cookie. This embodiment may be useful when it is desirable to set a cookie that may contain unencrypted (e.g., plaintext) information and is inaccessible to executable code (e.g., with httpOnly set). In other words, the auxiliary cookie performs a similar function to a third-party cookie when set in the prior art. However, because the domain cookie is anonymized using encryption, the data it contains is not easily readable, thus reducing the risk of setting it to allow access to executable code (e.g., without the httpOnly setting). The auxiliary cookie may have the effect of converting a content cookie into a first-party cookie, which appears to have exactly the same content but is set simply by the domain of the web page, rather than a different domain.

[0149] The embodiments described herein can be used in a variety of implementations. The examples given above are for advertising tracking. Another example is user identification for website access. In the prior art, third-party cookies can be used to identify a particular web browser known to be on different websites hosted on different domains. In this way, a particular user can avoid being identified each time they visit any of these websites. The embodiments described herein can be used to provide the same effect as third-party cookies by simply setting a first-party cookie on the client device.

[0150] In general, in many situations where prior art uses third-party cookies to allow websites on different domains to access the same cookie data, certain embodiments may be suitable for providing a similar effect by simply setting a first-party cookie on the client device 11.

[0151] Figures 8A and 8B show topologies for implementing the embodiments shown in Figures 8C and 8D, where the proxy server 19 is configured to intercept requests directed from the client device 11 to different web servers 12a and 12b. The web servers 12a and 12b are associated with different domains (e.g., a first domain to the first web server 12a and a second domain to the second web server 12b) so that, for example, first-party cookies from one domain are not read by the web server 12 of the other domain. The proxy server 19 may be a logical function of the proxy server 19 or the domain server 13, and may be implemented as a different physical or logical server.

[0152] This can be done in various ways; for example, referring to Figure 8A, the proxy server 19 may be associated with the domain of the web server 12 via a properly configured DNS record, and the proxy server 19 may be configured to communicate directly with the web server 12 (for example, via the network 15, or implemented as a different logical function within the same physical hardware and implemented with direct data communication separate from the network 15). The proxy server 19 is configured to identify the appropriate web server 12 for a particular incoming request based on the content of the request or the content associated with the request.

[0153] In another example, as shown in Figure 8B, a request is received by the associated web server 12, which is then configured to forward the request to a proxy server 19 (for example, via network 15, or implemented as a different logical function within the same physical hardware, or implemented via direct data communication separate from network 15), where the request is modified and returned to the associated web server 12. Similarly, the response from the web server 12 is first forwarded to the proxy server 19, which may modify the response and return it to the web server 12, and then communicate the modified response to the client device 11.

[0154] In each example, the proxy server 19 is configured to, in certain cases, modify communication from the client device 11 to the associated web server 12, and in certain cases, modify communication from the web server 12 to the client device 11.

[0155] In connection with this, the web server 12 is configured to communicate a set cookie command to set a third-party cookie. Embodiments in Figures 8A-8C are configured to modify the above command, for example, to trigger the setting of a first-party cookie while retaining information for the third-party cookie.

[0156] In step 800, the client device 11 communicates the request for content received by the proxy server 19 in step 801 (for example, via a web page request). The request is associated with a first domain (e.g., www.example.com). The request typically specifies a particular web page on which the content is needed. Note that a default web page may also be selected (e.g., http: / / www.example.com / index.html). In connection with this, the requested content is at least partially stored and / or generated by the first web server 12a. In step 802, the proxy server 19 identifies the intended web server 12 for the request (in this example, the first web server 12a is assumed).

[0157] Selectively, in step 803, the proxy server 19 generates a modified request based on the received request. The modified request includes information about the received request, or information derived from that request, for example, so that the web server 12 can provide the requested content. This information may include some or all of the information in the request's header. In one embodiment, when generating the modified request, step 803 includes copying the request's header and body information. The modified request may include information that allows the original client device 11 to be identified when a response is received from the web server 12.

[0158] In step 804, the proxy server 19 communicates the modified request to the first web server 12.

[0159] This is the web server 12a identified in step 802. In connection with this, the modified request is the response to the modified request, which is generated by the first web server 12a and identifies the proxy server 19 to receive the response received therefrom. In other words, from the perspective of the first web server 12a, the modified request originates from the proxy server 19.

[0160] In step 805, the proxy server 19 receives a response generated by the first web server 12a. The response includes, for illustrative purposes, one or more "set cookie" commands, which are instructions to the web browser of the user device 11 to set a cookie.

[0161] The proxy server 19 is configured to analyze the received response in step 806 to determine whether one or more set cookie commands exist associated with a domain different from the first domain, and such domains are referred to as "third-party domains". If one or more of the above commands exist, the method proceeds to step 807. Otherwise, the method proceeds to step 808.

[0162] If one or more set cookie commands exist, the proxy server 19 is configured in step 807 to replace the third-party domains or references to each third-party domain with new references to the first domain. The proxy server 19 is typically configured to parse the response to identify references to third-party domains and replace them with the domains of the first web server 12a, thereby creating a first-party cookie. The content of the first-party cookie may be the same as that of the third-party cookie.

[0163] Next, the processed response is communicated to the web browser of the client device in step 808.

[0164] Figure 8D relates to an embodiment that can be optionally implemented along with that in Figure 8C. Steps 800-804 are equivalent to those in Figure 8C.

[0165] Similar to Figure 8C, in step 805, the proxy server 19 receives a response generated by the first web server 12a. For the purpose of illustrating this method, this response includes executable code (e.g., JavaScript) containing instructions for the web browser of the client device 11 to perform one or more instances of communication with one or more content servers 14 (here, one), and here it includes (multiple) content server communication instructions. The response also typically includes content intended for rendering by the receiving web browser, and / or executable code (e.g., JavaScript) for execution by the web browser.

[0166] In step 816, the proxy server 19 is configured to analyze the received response in order to identify (multiple) third-party server communication commands, i.e., commands to contact another web server 12, such as a second web server 12b, by parsing the response.

[0167] In step 817, the proxy server 19 is configured to replace references to specific web resources in the third party or each third party's server communication command with references to dummy web resources, in which case the domain of the first web server 12a is used so that the proxy server 19 receives communications directed to the dummy web resources. The processed response is communicated to the web browser of the client device in step 809.

[0168] In one embodiment, the proxy server 19 maintains in memory a mapping database that holds mapping records between the generated dummy web resource and the original web resource (i.e., the target of the associated content server communication command).

[0169] Figure 8E (including the steps in Figure 8D) illustrates the process by which, upon receiving the executable code in Figure 8D, the client device 11 communicates with the proxy server 19 via (multiple) dummy web resources in step 820. In step 821, the proxy server 19 compares the (multiple) dummy web resources with its mapping database to identify the actual third-party web resources (e.g., in a second web server 12b). In step 822, the proxy server 19 determines whether there are cookies associated with the dummy web resources on the client device 11 (and thus recorded as first-party cookies for the first domain). Such cookies are communicated to the third-party web resource (e.g., the second web server 12b) along with a request for content, according to the mapped resource. Assuming a response has been received, its content is passed to the client device 11, and the steps in Figures 8C and 8D are repeated for this returned content, if necessary.

[0170] In this way, the proxy server 19 has the advantage of being able to conveniently hide third-party web resources from the client device 11, while at the same time being able to deliver content from the third-party web resources to the client device 11.

[0171] Further modifications may be made without departing from the spirit and scope of this specification.

Claims

1. A method for recording information in a first-party cookie in a web browser of a client device, comprising the steps of propagating recorded identification information stored in a second cookie associated with a second domain from the second cookie associated with the second domain to a first cookie associated with a first domain, wherein the first cookie and the second cookie are each first-party cookies, and each of a first web resource of a first web server addressable in the first domain and a second web resource of a second web server addressable in the second domain has access to the recorded identification information via the associated first-party cookie, the web browser does not allow access to third-party cookies, and the recorded identification information is propagated to the first cookie during the current communication instance between the web browser and the first web resource, and propagated to the web browser via the propagated information during the current communication instance. The aforementioned propagation is During the current communication instance, the web browser is instructed to communicate with a propagation server associated with a propagation domain different from the first and second domains, and The web browser receives the propagation information from the propagation server so that it can record the recorded identification information as the first cookie. Includes, The method wherein the web browser initiates the current communication instance through communication with the first web server requesting content for display, the first web server is associated with a first domain server, both servers are associated with the first domain, and the instruction to the propagation server is received from the first domain server.

2. The method according to claim 1, wherein the recorded identification information is propagated to the first cookie in response to the determination that the first cookie does not exist.

3. The method according to claim 1 or 2, wherein the first web server provides the content for display to the web browser in accordance with the recorded identification information after the recorded identification information has been propagated from the second cookie to the first cookie.

4. The method according to any one of claims 1 to 3, wherein, as part of the instruction, the web browser provides the propagation server with information stored in a propagation cookie, and the propagation information is based on the information stored in the propagation cookie.

5. The method according to claim 4, wherein the information stored in the propagation cookie and the propagation information are the same, or the propagation information is an encoded representation of the information stored in the propagation cookie.

6. The method according to claim 4, wherein the propagation information is generated according to propagation rules available to the propagation server, and the propagation rules are applied to the information stored in the propagation cookie.

7. The method according to claim 6, wherein the propagation rule is stored in the propagation cookie and provided to the propagation server as part of the instruction.

8. The method according to any one of claims 1 to 7, wherein the propagation information is provided to the web browser in relation to an instruction received from the propagation server, and the web browser communicates with the first domain server and provides the propagation information together with the instruction.

9. The method according to claim 8, wherein the web browser receives an instruction from the first domain server to set the first cookie containing the recorded identification information in response to providing the propagation information to the first domain server.

10. The method according to any one of claims 1 to 9, wherein the first domain and the second domain are determined to be relevant domains to which propagation is permitted before permitting the propagation of the recorded identification information from the second cookie to the first cookie.

11. The method according to any one of claims 1 to 10, wherein the recorded identification information is recorded as first cookie data of the first cookie, the first cookie data is different from the recorded identification information, and the recorded identification information is derivable from the first cookie data.

12. The method according to claim 11, wherein the second cookie includes second cookie data, the recorded identification information is derivable from the second cookie data, and the first cookie data and the second cookie data are different.

13. A domain server configured to communicate with a web browser of a client device in order to facilitate the propagation of recorded identification information between first-party cookies associated with different domains, and which is addressable in a first domain, In order to communicate with the domain server, the web browser receives communications from the web browser based on commands provided to the web browser by a first web server that can be addressed in the first domain, and Determining whether a first cookie exists in the communication, wherein the first cookie is associated with the first domain. It is configured to do the following: In response to determining that the first cookie does not exist, the domain server: The web browser is instructed to communicate with a propagation server that can be addressed in a propagation domain different from the first domain, and in response to the instruction, the propagation server provides propagation information to the web browser, and The web browser is instructed to communicate with the domain server again, and the propagation information is received from the web browser, wherein the propagation information is derived from recorded identification information of a second cookie associated with a second domain different from both the first domain and the propagation domain, and the recorded identification information is derivable from the propagation information. Determining the recorded identification information from the propagated information, and To instruct the web browser to record the recorded identification information in the first cookie. The web browser, which is configured to do so and is communicating with the domain server, does not allow access to third-party cookies.

14. The domain server according to claim 13, further configured to instruct the web browser to communicate with the first web server in order to enable the web browser to generate content using the recorded first cookie.

15. The aforementioned propagation information is generated according to the propagation rules available to the propagation server, The domain server according to claim 13 or 14, wherein the propagation rule is applied to information stored in the propagation cookie.

16. The domain server according to claim 15, wherein the propagation rule is stored in a propagation cookie stored in the web browser.

17. The domain server according to any one of claims 13 to 16, wherein the web browser is instructed to record the recorded identification information as first cookie data of the first cookie, the first cookie data being different from the recorded identification information, and the recorded identification information being derivable from the first cookie data.

18. The domain server according to claim 17, wherein the second cookie includes second cookie data, the recorded identification information is derivable from the second cookie data, and the first cookie data and the second cookie data are different.

19. The domain server according to any one of claims 13 to 17, wherein the recorded identification information is propagated from the second cookie to the first cookie only when the second domain is identified as being associated with the first domain.

20. A network system for facilitating the propagation of recorded identification information between first-party cookies associated with different domains in the web browser of a client device communicating with the network system, A domain server comprising two or more domain servers, each having an associated domain, the associated domains being different, and each domain server being addressable within its associated domain, A propagation server associated with a propagation domain, wherein the propagation domain is different from the domain of the domain server. Each domain server is equipped with, To receive communications from the web browser in accordance with the instructions provided to the web browser by the web server associated with the domain, Determining whether a first cookie exists in the communication, wherein the first cookie is associated with the domain. In response to the determination that the first cookie does not exist, The web browser is instructed to communicate with a propagation server that can be addressed in a propagation domain different from the first domain, and in response to the instruction, the propagation server provides propagation information to the web browser, and The web browser is instructed to communicate with the domain server again, and the propagation information is obtained from the web browser, wherein the propagation information is derived from the recorded identification information of a second cookie associated with a second domain different from both the first domain and the propagation domain, the second domain is associated with another domain server, and the recorded identification information can be derived from the propagation information. To determine the identification information recorded from the propagated information, and The web browser is instructed to record the recorded identification information in a first cookie, wherein the first cookie is associated with the first domain. It is configured to do the following: The propagation server is configured to determine the propagation information based on the information provided from the web browser along with the command. A web browser communicating with the aforementioned network system is expected to allow access to third-party cookies, or does not allow access to the network system.

21. The network system according to claim 20, wherein the information provided from the web browser includes, if present, information stored in a propagation cookie readable by the propagation server.

22. The network system according to claim 21, wherein the propagation server is configured to generate the propagation information in accordance with propagation rules available to the propagation server, and the propagation rules are applied to the information stored in the propagation cookie.

23. The network system according to claim 22, wherein the propagation rule is stored in a propagation cookie stored in the web browser and is received by the propagation server via the communication from the web browser.

24. The network system according to any one of claims 21 to 23, wherein if no propagation cookie exists, the propagation server is configured to communicate a command to the web browser to determine the value of the propagation cookie and set the value as the propagation cookie, and the propagation information is generated according to the newly determined value.

25. The network system according to any one of claims 21 to 24, wherein the propagated information is an encoded representation of the information stored in the propagated cookie.

26. The network system according to any one of claims 20 to 25, wherein the recorded identification information is propagated from the second cookie to the first cookie only when the second domain is identified as being associated with the first domain.

27. ​​For each domain server, the recorded identification information is recorded as cookie data of an associated cookie, the recorded identification information can be derived from the cookie data associated with each domain server, and the cookie data of at least one domain server is different from the cookie data of at least one other domain server, according to any one of claims 20 to 26.

28. The network system according to any one of claims 20 to 27, further comprising a web server for each domain server, each web server configured to instruct a web browser to communicate with its associated domain server, and each web server being addressable in the same domain as its associated domain server.