Anonymous visit token

The third-party system generates a visit token for user devices entering a premise, enabling anonymous tracking and communication, addressing computational demands and privacy concerns in physical premise information exchange.

WO2025172199A1PCT designated stage Publication Date: 2025-08-21FASTER MOBILE ENGAGEMENT SWEDEN AB
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/053357
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-13
Filing Date
2025-02-10
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing methods for tracking user behavior in physical premises are computationally demanding and raise concerns about personal integrity, making it difficult to gather valuable information without revealing user identities.

Method used

A method involving a third-party system that generates a visit token for a user's device upon entry to a premise, allowing anonymous information exchange by detecting entry, determining an identifier, and sending the token to the premise's system, while maintaining user anonymity.

Benefits of technology

Enables the premise's system to track user presence and communicate without knowing the user's identity, facilitating anonymized statistical data collection and message delivery while respecting user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025053357_21082025_PF_FP_ABST
    Figure EP2025053357_21082025_PF_FP_ABST
Patent Text Reader

Abstract

A method performed in system of a third party for enabling information exchange between a system of an entity and a device of a user entering a premise of the entity without revealing the identity of the user of the device to the system of the entity is provided. The method comprises detecting that a user has entered the premise based on that a device of the user has entered the premise, and determining an identifier of the user, generating a visit token for the identifier, and sending the visit token to the system of the entity.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] ANONYMOUS VISIT TOKEN

[0002] Technical Field

[0003] The invention relates to a method performed in a system of a third party for enabling information exchange between a system of an entity and a device of a user entering a premise of the entity without revealing the identity of the user of the device to the system of the entity, and to a corresponding system and computer program.

[0004] Background

[0005] Gathering of information of potential customers or visitors on online platforms have been performed for quite some time via web browser cookies, tracking pixels and similar technologies. The gathered information may be very valuable to an organization or merchant when advertising their services, showcasing their products or designing their website. Furthermore, when a user is visiting a web site or using social media an organization may use targeting to communicate with or adjust adverts shown to the user.

[0006] However, tracking of potential customers or user behaviors is much more difficult in the physical world. Some organizations have tried using cameras to monitor their premise, such as shops, malls, grocery stores, etc., to determine what potential customers are doing. However, those methods are computationally demanding and there are issues with maintaining personal integrity.

[0007] Thus, there is a need for an improved method relating to physical premise and information exchange with potential users and statistical data gathering.

[0008] Summary

[0009] The present disclosure aims to provide improved methods for information exchange between a visitor of a premise and an entity associated with that premise.

[0010] In particular, according to an aspect of the present disclosure, there is provided a method performed in system of a third party for enabling information exchange between a system of an entity and a device of a user entering a premise of the entity without revealing the identity of the user of the device to the system of the entity. The method comprises detecting that a user has entered the premise based on that a device of the user has entered the premise, determining an identifier of the user, and generating a visit token for the identifier. The method further comprises sending the visit token to the system of the entity.

[0011] By having a third party creating a visit token for an identifier of a user of a device that enters a premise, and sending that visit token to a system of the entity associated with the premise, the user may stay anonymous to the entity while allowing the system of the entity to track that a user has entered the premise. The system of the entity may use the visit token for communicating with the user without the need to know the user's identity.

[0012] A premise may be a geographical physical area with which an entity is associated. For example, a premise may be a building, a plurality of buildings, a geographical area having buildings on it, or a part of a building.

[0013] An entity may be any type of entity. In some examples, the entity is a legal entity, such as a physical or legal person. The entity may be associated with the premise, for example by holding a right (direct or indirect) to the premise. For example, the entity may be an organization or a company. The entity may have a system configured to receive a visit token or other information from a third party system.

[0014] The third party may be any type of third party capable of detecting that a user has entered the premise based on that a device of the user has entered the premise, determining an identifier of the user, and generating a visit token for the identifier. In some examples, the third party is a service provider for the user and thus has access to information on the identity of the user. In that example, the identifier may be a device identifier or a subscriber identifier. In a specific example, the identifier is an MSISDN, or a phone number and the third party is a telecommunications provider.

[0015] The user may alternatively be referred to as a visitor of the premise. The visit token may be any type of unique token. For example, the token may be a unique random number generated by the third party or some other entity.

[0016] According to some embodiments, the method further comprises sending statistical information related to user for which the visit token is generated for to the system of the entity. In this way, the entity system may collect anonymized statistical data on visitors to the premise. In this example, the third party system may have access to information pertaining to the user, such as a gender, a birth year (or a birth year bracket), a zip code, or an income group.

[0017] According to some embodiments, the method further comprises receiving information on a geographical area of the premise of the entity, wherein detecting that the user has entered the premise is based on at least on the received information. In this way, the third party may have information on the definition of the premise. The information on a geographical area may, for example, be provided during configuration of the third party. The information on a geographical area may for example be provided via a detection unit or a mobile cell at the premise, or as a geofence outline. Alternatively, the detection unit may be arranged at a location separate from the premise and may be a unit probing data traffic or similar in order to detect that a device has entered the premise.

[0018] According to some embodiments, the method further comprises storing an association between the identifier and the visit token. By storing the association between the identifier and the visit token, the identifier of the user may be retrieved later, for example, for communication or in a case where the user accepts being identified.

[0019] According to some embodiments, the identifier is not derivable from the visit token, and the identifier is obtainable by the system of the third party system using the stored association. As the system of the entity only has access to the visit token, and the identifier is not derivable from the visit token (i.e., the system of the entity cannot calculate or otherwise determine the identity of the user), the user is anonymous to the entity. According to some embodiments, the method further comprises receiving, from the entity, a message and the visit token and sending the message to the user for which the visit token was generated. In this way, the entity may send a message to the user using only the visit token, which allows the user to stay anonymous to the entity while still being able to receive messages from the entity.

[0020] According to some embodiments, the message comprises a reply-to address associated with the system of the organization. The method may further comprise receiving, from the user, a second message sent to the reply-to address and sending the second message to the entity for the visit token. In this way, the third party system acts as a relay for the messages, allowing the user to anonymously send messages to the system of the entity.

[0021] According to some embodiments, the message comprises a link to information, and the method further comprises receiving a request for the link to information from the device and forwarding the request for the link to information to the system of the entity. The entity system may thus include a link to information in the message to the user, for example comprising an offer, an invitation to join a customer club, a website link, etc. In this embodiment, the third party acts as a router for a request for the link to information, which allows the user to access the information while still being anonymous to the entity system. The link may, for example, be a URL or a link to an application on a mobile device.

[0022] According to some embodiments, the request comprises user identifying data, and the method further comprises filtering the user identifying data and forwarding the request to the system of the entity. In some examples, making a request may cause the device of the user to send user identifying data along with the request, which would stop the user from being anonymous to the entity. In those examples, the third party system, when relaying the request, may filter the user identifying data to remove any data that can be used to identify the user. In some examples, the request is an HTTP or HTTPS request and the user identifying information is browser cookies. According to some embodiments the method further comprises receiving, from the entity, a request for the identifier associated with the visit token, and sending the identifier associated with the visit token to the entity. In this way, the identity of the user may be revealed to the entity.

[0023] According to some embodiments, the method further comprises receiving, from the user during a visit to the premise, a temporary consent to reveal the identifier associated with the visit token to the entity, and on condition that the temporary consent is received, sending the identifier associated with the visit token to the entity. The user may thus temporarily consent to the third party system revealing the identity of the user to the entity. By temporary it may be meant that consent is given for a specific time period, such as 24 hours, or for a specific event, such as a specific visit. The temporary consent may be withdrawn by the user before the expiry of time period or the specific event, such as a specific visit, for which the consent is given.

[0024] According to some embodiments, the method further comprises receiving, from the user, a permanent consent to reveal in current and future visits to the premise the identifier associated with the visit token to the entity, the permanent consent being valid until withdrawn, and on condition that the permanent consent is received, sending the subscriber identifier associated with the visit token to the entity. In this way, the user may give permanent consent to the third party system revealing the identity of the user to the entity. By permanent consent it may be meant that the consent is valid unit withdrawn.

[0025] According to some embodiments, the method further comprises receiving, from the user, a subsequent message, and on condition that a temporary consent or a permanent consent is received, forwarding the subsequent message including an identifier associated with the visit token to the entity. The subsequent message may be a message sent after the first message, or in response to a message sent from the entity using the visit token. By providing the subsequent message and the identifier associated with the visit token and thereby the user, the user and the entity may have direct communication with each other using the identifier. According to some embodiments, the method further comprises determining that the user has left the premise based on that the device has left the premise, and sending a notification to the system of the entity that the user has left the premise. In this way, the entity is informed that the user has left the premise and may refrain from sending a message, or may send a message having information relevant for a user that has left the premise.

[0026] According to some embodiments, the method further comprises receiving information about a time interval in which visitors are allowed at the premise from the entity. The method may further comprise detecting that the device has entered the premise, determining that the user has entered the premise outside of the allowed time interval, and on condition that the user has entered the premise outside of the allowed time interval, sending a notification to the entity that a user has entered the premise outside of the allowed time interval. In this way, the entity may be notified in case a user enters the premise outside of the time interval in which visitors are allowed. This could, in some examples, indicate a security issue as the user entering the premise may not be authorized to do so.

[0027] According to some embodiments, the method further comprises receiving information on identities which are allowed at the premise outside of the time interval, and on condition that the identity of the user is comprised in the allowed identities, refraining from sending the security notification. The entity may thus be notified only when a user not allowed at the premise outside of the time interval has entered the premise.

[0028] According to some embodiments, the identifier is a subscriber identifier of the user, preferably the subscriber identity is an MSISDN, and the third party is a telecommunications operator.

[0029] According to a second aspect, a system for enabling information exchange between a system of an entity and a device of a user entering a premise of the entity without revealing an identity of the user of the device to the system of the entity. The system comprises a system of third party configured to perform the method of any of the embodiments described above, a detection unit arranged at the premise of the entity, the detection unit being configured to detect that a device of a user enters the premise and send information of the entry to the third party, and a server comprised in the system of the entity for receiving data from the third party.

[0030] The system may have the same advantages as described for the method above.

[0031] The detection unit may be any unit configured to detect the presence of a device. For examples, the detection unit may be a node as described in patent application WO 2022 / 003153.

[0032] According to a third aspect, a computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the steps of the method of any one of the embodiments described above. The computer program may have the same advantages as described for the method above.

[0033] A feature described in relation to one aspect may also be incorporated in other aspects, and the advantage of the feature is applicable to all aspects in which it is incorporated. Other objectives, features and advantages of the present inventive concept will appear from the following detailed disclosure, from the attached claims as well as from the drawings.

[0034] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. Further, the use of terms "first", "second", and "third", and the like, herein do not denote any order, quantity, or importance, but rather are used to distinguish one element from another. All references to "a / an / the [element, device, component, means, step, etc.]" are to be interpreted openly as referring to at least one instance of said element, device, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated. Brief of the

[0035] The above, as well as additional objects, features and advantages of the present inventive concept, will be better understood through the following illustrative and non-limiting detailed description of the present inventive concept, with reference to the appended drawings, wherein:

[0036] Figure 1 schematically shows a system according to embodiments of the present disclosure;

[0037] Figure 2 shows a flow chart for a method according to embodiments of the present disclosure.

[0038] Figure 3 shows a flow chart for a method for a third party system according to embodiments of the present disclosure.

[0039] Figure 4 shows a flow chart for a method for receiving consent from a user by a third party system, according to embodiments of the present disclosure.

[0040] Figure 5 shows a flow chart for a method for notifying an entity of a user entering a premise outside of a time interval by a third party system, according to embodiments of the present disclosure.

[0041] The figures are not necessarily to scale, and generally only show parts that are necessary in order to elucidate the inventive concept, wherein other parts may be omitted or merely suggested.

[0042] Detailed

[0043] The present disclosure is described in the following by way of a number of illustrative examples. It will be appreciated that these examples are provided for illustration and explanation only and are not intended to be limiting on the scope of the present disclosure. Instead, the scope of the present disclosure is defined by the appended claims.

[0044] Furthermore, although embodiments be presented individually for the sake of focused discussion of particular features, it will be recognized that the present disclosure also encompasses combinations of the embodiments described herein. Figure 1 schematically shows a system according to an embodiment. The system comprises a third party system 100 and an entity system 200. The entity of the entity system 200 has or is associated with a premise 400. Data may be sent and / or received by the third party system 100 and / or the entity system 200 via means of an API, hosted at the third party system 100 and / or at the entity system 200.

[0045] An example of a third party system 100 is a provider of mobile services. A third party system (in other words, a system of a third party) may be a system of a telecommunications services provider.

[0046] An entity may, for example, be an organization or a legal entity holding a right to a premise 400. The entity system 200 may thus be a system associated with an organization or legal entity holding a right to a premise.

[0047] The entity has a premise 400 associated with it. The premise 400 may be defined by providing information 220 on the geographical area of the premise 400 to the third party system 100. In some examples, the information 220 is sent from an application 210 at the entity system 200 to the third party system 100.

[0048] The premise 400 may optionally comprise one or more interest point(s) 420, which may be a geographical boundary at the premise. That a user 300 enters an interest point may be detected similarly to how it is detected that the user 300 enters the premise. The premise may alternatively or in addition to the interest points 420 comprise one or more tap points 430. A tap point 430 may be a geographical point at the premise, and the user being at a tap point 430 may be detected by a user connecting with a mobile device to or otherwise engaging with the tap point 430.

[0049] The third party system 100 is configured to detect 150, or to receive information 150, that a user 300 has enter the entity's premise 400 based on that a device 310 associated with the user 300 has entered the entity's premise 400. The user 300 may alternatively be referred to as a visitor, and the entry referred to as a visit. The detection may, for example, be performed using a detection unit 410 arranged that the premise 400 and may be based on that a device 310 of the user 300 has entered the premise 400. As an example only, the detecting may be performed via a detection unit such as the node described in patent application W02022 / 003153. The detection unit 410 may, in some examples, be a cell in a mobile communications network. Alternatively, the premise may be defined by a geofencing area.

[0050] When the third party system 100 has detected that a user 300 has entered the premise, the third party system 100 may determine an identifier for the user 300. The identifier of the user may be determined based on a device identifier or a subscription identifier of the device. In some examples the user identifier is a subscription identifier, but also other identifiers may be used. As an example, the third party may be a telecommunications provider. The device may be a mobile device having a subscription, and the identifier may be determined from the subscription. The identifier may be a mobile phone number or an MSISDN for the subscription. In other examples, the third party may be an internet service provider, and the identifier may be determined based on an internet subscription for the device.

[0051] The third party system 100 generates a visit token 120 for the visit and sends a notification of the visit to the entity system 200 along with the visit token 120. The generation of the visit token 120 may be performed by an integrity filter 140 at the third party system 100. The visit token 120 may be any type of token, for example a random string of characters or numbers. The visit token is generated such that the identifier is not derivable from the visit token. The visit token should be unique over the time period in which the visit token is valid. That is, two users should not be associated with the same visit token at the same time. In some embodiments, the third party system 100 stores an association between the identifier of the user 300 and the visit token 120.

[0052] The third party system 100 may be further configured to store or be able to retrieve statistical data 110 related to the user 300. The statistical data may, for example, be related to a visitor statistical group such as a gender, birth year group (for example in 5-year intervals), a zip code or a zip code group, an income group (such as Low / Medium / High). The statistical data may be such that the user may not be identified from it. For example, the statistical data may be such that more than a predetermined number of persons will be in the group defined by the statistical data. The statistical data may comprise information on whether the user 300 is a member of customer club or similar of the organization; an associated organization; a site; a membership status; time and or position of visit; a timestamp; website / browser cookies; and / or an event (e.g., Receipt of purchase). The visitor statistical groups may be configured during setup of the system or at a later stage. The third party system 100 may be configured to send statistical data related to the visit or to the user to the entity system 200. The statistical data may be received by an application 210 at the entity system 200.

[0053] As will be described in further detail below with reference to the method, the entity system 200 may send a message to the user 300 via the third party system 100. To send the message, the entity system 200 may send the message along with the visit token 120 to which user 300 the message is intended to the third party system 100 along with the visit token. The third party may then retrieve the user identifier based on the visit token and the stored association between the visit token and the user identifier and send the message via service provider 500 to the user. The message may be sent from the third party system 100 to the service provider 500 via an API. The message may be any type of message, for example, but not limited to: SMS, MMS, voice, video, web, and social media. The service provider 500 may, for example, be a provider of a mobile service, provider of a payment service, provider of receipts for purchase, a provider of a messaging service, or a provider of another service. The service provider 500 may be configured to provide information to the third party system 100 that an event has occurred, such as a purchase, a delivered message, the user viewing a message, a receipt of a purchase, or other events. The message may, for example, comprise information related to the premise, an offer, a link to information or any other information. When the message comprises a link to information, the request for the information may be made to the third party system 100. The third party system 100 may filter the request from any user identifying data, such as browser cookies, and forward the request to the entity system 200. Alternatively, the request may be made directly from the device of the user to an application of the entity system 200.

[0054] The third party system 100 may be further configured to store user 300 consent information. A user 300 may give a temporary or a permanent consent to be identified to the entity (i.e., that the entity system 200 will receive the user identifier associated with a visit token 120). In case that the user has given a consent to be identified, the third party system 100 may send the user identifier to the entity system 200. The entity system 200 may use the identifier to communicate directly with the user 500.

[0055] The third party system 100 may be further configured to blocking some or all features relating to the entity system 200 and the user / visitor 300.

[0056] Blocking may for example be performed the third party, such as a provider of a mobile service, because an organization is considered as not reliable and therefore it should be restricted partially or fully from the service. Alternatively or additionally, a visitor may consider an organization as not suitable to receive communication from during visits, or the visitor may want to reject all organizations from providing communication during visits and therefore want to restrict them partially or fully from the service. Hence, blocking may be initiated by the third party or by the user / visitor 300 and these are performed independently such that blocking can only be removed by the entity that initiated the blocking. For example, if a visitor / user 300 has initiated blocking, this blocking can only be removed by the user, e.g. by the user giving consent to the removal of the blocking.

[0057] Blocking by the third party may be performed for an entity system 200 or for a complete organization or legal entity associated with the entity system 200, i.e. also for other entity systems 200 associated with the organization or legal entity. The blocking is in relation to all visitors 300. The organization or legal entity may hold a right to the premise 400.

[0058] Blocking by the third party may be total for an entity system 200 or for the organization or legal entity associated with the entity system 200. In such a case, no information is provided to the entity system 200 or for the organization or legal entity associated with the entity system 200. Specifically, no visit token 120 and no statistical data related to any visit or to any user / visitor 300 are provided to the entity system 200 or to the organization or legal entity associated with the entity system 200. Consequently, the entity system 200 and the organization or legal entity associated with the entity system 200 will not be able to communicate with any user / visitor 300 based on any visit token 120.

[0059] In alternative, blocking by the third party may be partial. In such a case, the entity system 200 or the organization or legal entity associated with the entity system 200 may be blocked from one or more of receiving any visit token 120, receiving any statistical data related to any visit, receiving statistical data relating to any user, and communicating with the user based on the visit token 120.

[0060] Blocking by the third party may alternatively or additionally be partial in that that an organization or legal entity associated with a plurality of premises 400 may be blocked in relation to a subset of the plurality of premises 400.

[0061] Alternatively or additionally, blocking may be performed in relation to a visitor 300. Such blocking is typically initiated by the visitor 300 themselves.

[0062] Blocking in relation to the visitor 300 may be total. In such a case, no information in relation to the visitor 300 is provided to any entity system 200 or to any organization or legal entity associated with any entity system 200. Specifically, no visit token 120 and no statistical data related to the visit or to the user are provided to any entity system 200 or to any organization or legal entity associated with the entity system 200. Consequently, no entity system 200 and no organization or legal entity associated with any entity system 200 will be able to communicate with the user based on the visit token 120. In alternative, blocking in relation to the visitor 300 may be partial for all entity systems 200 and for all organizations or legal entities associated with all entity systems 200. In such a case, all entity systems 200 or all organizations or legal entities associated with all entity systems 200 may be blocked from one or more of receiving the visit token 120, receiving statistical data related to the visit, receiving statistical data relating to the user, and communicating with the user based on the visit token 120.

[0063] Blocking in relation to the visitor 300 may also be partial in that blocking in relation to the visitor 300 is for a subset of all entity systems 200 or for a subset of all organizations or legal entities associated with all entity systems 200.

[0064] Blocking in relation to the visitor 300 may also be partial in that blocking in relation to the visitor 300 is for a subset of a plurality of premises 400 of an organization or legal entity.

[0065] Blocking may for example be implemented by setting of suitable flags in the third party system indicating the relevant total or partial blocking for an entity system 200 or for a complete organization or legal entity associated with the entity system 200, or in relation to a visitor 300 as described hereinabove. Removing blocking may then be implemented by resetting the suitable flags in the third party system. As indicated hereinabove, blocking can only be removed by the entity that initiated the blocking. For example, if a visitor / user 300 has initiated blocking, this blocking can only be cancelled by the user, e.g. by the user giving consent to removing the blocking. Similarly, blocking initiated by the third party can only be removed by the third party.

[0066] The system described with reference to Figure 1 may be configured to perform any embodiment of the method below described with reference to Figure 2.

[0067] Figure 2 shows a flow chart of a method 2000 for enabling information exchange between an entity system 200 and a device of a user 300 entering a premise of the entity without revealing the identity of the user 300 of the device to the system of the entity. The method may comprise the entity system 200 providing S2010 information on the premise, such as geofence or an identifier of the premise. For example, the entity system 200 may provide a detection unit identifier or a mobile cell identifier for the premise, any interest point(s), and / or any tap point(s) to the third party system 100. The third party system 100 may as an alternative or in addition provide a geofence for the premise outline, any interest point(s), and / or any tap point(s) to the third party system 100. The providing S2010 may, for example, be performed during configuring of the third party system 100.

[0068] Optionally, the entity system 200 may provide a membership status for a device identifier or a subscriber identifier to the third party system 100 in order for the third party system 100 to be able to provide a membership status along with the visit token at a later step.

[0069] Optionally, the third party system 100 or the entity system 200 may define visitor statistics groups at the third party system 100 that the third party system 100 may use to provide statistics for a user 300 visiting the premise.

[0070] The user 300 may enter S2020 the premise of the entity, which may alternatively be referred to as a visit to the premise. The user 300 entering S2020 the premise may be detected by the third party system 100, either directly or indirectly. The detecting S2030 may be performed as described with reference to Figure 1. In some examples the device of the user 300 is positioned 150 by the third party system 100 using a detection unit or a mobile cell at the entity system 200 premise 400 (i.e., relative positioning). In some examples the device is positioned by the third party system 100 inside a geofenced area (i.e., absolute positioning). In connection with the detecting S2030, the third party system 100 may, in some examples, obtain a user consent 130 for using location information from the user's 300 device 310. The user consent may be obtained, for example, as specified in 3GPP TS 23.273 V16.9.0 (2021-12).

[0071] The third party system 100 determines an identifier of the user 300 of the device entering the premise and generates a visit token for the identifier. The third party system 100 may store an association between the visit token and the identifier for later user. In some examples, the third party system creates S2040 a visit record of the visit. Such a visit record may, for example comprise the association between the identifier and the visit token. The visit record may comprise statistical information such as a timestamp, an entity identifier, a position, any tap point or point of interest visited during the visit, a profile of the user, and / or a membership status. In some examples, where the user has given a consent (as will be described below), the consent may be stored in or in connection to the visit record. The visit token may be used for either, or both, statistical insights for the entity system 200 or anonymous communication between the entity system 200 and the user 300.

[0072] After generating S2040 a visit token, the third party system 100 sends S2050 the visit token and optionally the visit record to the entity system 200.

[0073] As the entity after step S2040 has the visit token, information exchange between the system of the entity system 200 and the device of the user may be performed without revealing the identity of the user 300 of the device to the system of the entity, as will now be described.

[0074] The entity system 200 may use the visit token for communicating with the anonymous (to the entity) user. To that regard, the entity system 200 may send S2060 the visit token and a message intended for the user 300 to the third party system 100. The entity system 200 may also indicate what type of service the message should be sent through (such as voice, SMS, MMS, social medica, etc.). In some example, step S2060 may be omitted and the entity system 200 may instead pre-configured a message to be sent to all visitors (or all visitors meeting a criteria). In that case, the third party system 100 may send a notification to the entity system 200 that a message has been sent to a user associated with a visitor token without any further involvement from the entity system 200.

[0075] The third party system 100 may retrieve S2070 the identifier of the user using the visit token and forward S2080 the message and the identifier of the user to a service provider 500 for delivery to the user 300. The service provide may provide S2090a the message to the user 300 and optionally receive S2090b a response to the message. The service provider 500 then forwards S2100 the response to the third party system 100.

[0076] The message may, for example, comprise a link to information, a request for consent to receive the identifier of the user, an offer, or other information that the entity system 200 wants to send to the user 300.

[0077] The response may, for example, comprise a temporary consent for the entity to receive the identifier of the user, a permanent consent for the entity to receive the identifier of the user, a request for more information, among others.

[0078] In response to receiving S2100 the response from the user 300, the third party may retrieve the visit token using the user identifier (as comprise in the response or retrieved by the service provider or by the third party being a service provider for the user). The response (which may be filtered to remove any user identifying information) and the visit token may then be forwarded S2120 to the entity system 200.

[0079] In some examples, the response is a request for the link to information. In those examples, the service used for sending the message may be different from the service used when requesting the information. For example, the message may be sent using SMS or MMS, and the link for information may comprise a URL or a link to a social media application or mobile application. In the example where the link comprises a URL, the third party system 100 may act as a relay for the request for the URL from the user device. The user device thus requests the URL from the third party system 100, the third party system 100 accesses the URL (which in some examples is an address to a website or the like provided by the entity system 200) and forwards the contents to the device of the user 300. In this example, the request for the URL may be filtered such that no user identifying information is sent to the entity system 200, for example browser cookies, an IP address or other user identifying information.

[0080] While steps S2060-S2120 are shown as occurring once in Fig. 2, steps S2060- S2120 may be repeated, in full or only some of the steps. In some embodiments, steps S2060-S2120 may be performed similarly when a user 300 visits a point of interest or a tap point.

[0081] The user 300 may give consent to the third party system 100 sending or revealing the user identifier to the entity system 200. The consent may be given at any time, for example, before at visit, in response to the message sent to the user 300 in steps S2060-S2090a, or after the visit. The consent may be temporary, i.e., for a specific time period, such as 24 hours, or for a specific visit, or the consent may be permanent, i.e., valid until it is withdrawn. The temporary consent may be withdrawn by the user before the expiry of time period or the specific event, such as a specific visit, for which the consent is given.

[0082] After the user 300 has given consent to the third party system 100 sending or revealing the user identifier to the entity system 200, the third party system 100 may send the user identifier to the entity system 200. The user identifier may, for example, be sent to the entity system 200 in any of the steps between the third party system 100 and the entity system 200 shown in Figure 2, or in a separate notification. Alternatively, the user 300 can send its identifier to the organization by accessing a link sent S2090a to the user 300 from the entity system 200 in a message. After the third party system 100 has received consent from the user to reveal the user identifier, any communication relayed by the third party system 100 between the user 300 and the entity system 200 may no longer be filtered to remove user identifying material. Optionally, the entity system 200 may provide web browser statistics for a web user identifying information. If the web browser statistics comprise user identifying information, they may not be sent unless the user has provided a consent.

[0083] The third party system 100 may detect S2130 or determine that the user 300 has left the premise. The detection S2130 or determination may be based on that the user's 300 device has not been detected by a detection unit for a predetermined time period, or that the user's 300 device has been detected by another detection unit outside of the premise. The third party system 100 may then notify S2130 the entity system 200 that the user 300 has left the premise. The third party system 100 may thereafter delete S2140 the visit token along with any visit record. The deletion S2140 may be performed in conjunction with the detecting S2130 but may also be performed at a later time. In some examples, the visit token may be valid for a predetermined amount of time (such as 1 hour, 12 hours, 24 hours) during which time the user can re-enter the premise and the third party system 100 may re-use the already created visit token. During the validity of the token, the user 300 may initiate communication with the entity system 200 using the visit token, even after the user 300 last left the premise. The communication may be performed as described above, using the visit token to send a message between the user 300 and the entity system 200. The entity system 200 may in response send a message to the user 300 using the visit token, as described above.

[0084] Alternatively, or in combination, the visit token may be used by the entity system 200 to communicate with the user 300 after the user 300 has left the premise for the predetermined amount of time. The entity system 200 may use the visit token to communicate with the user 300 after it has been determined that the user 300 has left the premise during a shorter time period than the validity of the visit token. For example, the entity system 200 may use the visit token to communicate with the user 300 for 30 minutes, 1 hour, or 2 hours after it has been determined that the user 300 has left the premise.

[0085] If the user 300 initiates communication with the entity system 200, the entity system 200 may be allowed use the visit token to communicate with the user 300, even if the shorter time period has expired.

[0086] The method 2000 described in relation to Fig. 2 may further include method steps corresponding to the features for blocking disclosed in relation to the third party system 100 described in relation to Fig. 1 hereinabove.

[0087] Figure 3 shows a flow chart for a method 3000 for a third party system for enabling information exchange between a system of an entity and a device of a user entering a premise of the entity without revealing the identity of the user of the device to the system of the entity according to embodiments of the present disclosure. Optional steps are indicated by dashed lines. The method 3000 described with reference to Fig. 3 may be combined with the method 2000 described in Fig. 2, and the system 100 described with reference to Fig. 1 may be configured to perform any steps of the method 3000.

[0088] The method comprises detecting S3020 that a user has entered the premise based on that a device of the user has entered the premise and determining S3030 an identifier of the user. The method further comprises generating S3040 a visit token for the identifier and sending S3050 the visit token to the system of the entity.

[0089] The method may further comprise sending S3060 statistical information related to user for which the visit token is generated for to the system of the entity.

[0090] The method may further comprise receiving S3010 information on a geographical area of the premise of the entity, wherein detecting that the user has entered the premise is based on at least on the received information.

[0091] The method may further comprise storing S3070 an association between the identifier and the visit token.

[0092] In some examples, the method further comprises receiving S3080, from the entity system 200, a message and the visit token, and sending the message to the user for which the visit token was generated.

[0093] In some examples, wherein the message comprises a reply-to address associated with the system of the organization, the method further comprises receiving S3090, from the user, a second message sent to the reply-to address and sending the second message to the entity for the visit token.

[0094] In some examples, the message comprises a link to information, and the method further comprises receiving S3100 a request for the link to information from the device and forwarding the request for the link to information to the system of the entity. In this example, when the request comprises, user identifying data, the method may further comprise filtering S3110 the user identifying data and forwarding the request to the system of the entity.

[0095] The method may further comprise determining S3120 that the user has left the premise based on that the device has left the premise and sending a notification to the system of the entity that the user has left the premise. The method may further comprise determining if there is any blocking applied in relation to the user or the entity as described in relation to Fig. 1. One or more of the steps S3O1O-S312O of the method may be performed only on condition that no relevant applied block has been determined.

[0096] Figure 4 shows a flow chart for a method 4000 for receiving consent from a user, the method being performed in a third party system, according to embodiments of the present disclosure. The method shown in Fig. 4 may be comprised in any one of the methods described with reference to Figs. 2 or 3, and the system disclosed in Fig. 1 may be configured to perform any steps of the method shown in Fig. 4.

[0097] The method may comprise, receiving S4010, from an entity system, a request for an identifier associated with the visit token and sending the identifier associated with the visit token to the entity.

[0098] The method may further comprise receiving S4020, from the user during a visit to a premise, a temporary consent to reveal the identifier associated with the visit token to the entity, and on condition that the temporary consent is received, sending the identifier associated with the visit token to the entity.

[0099] The method may further comprise receiving S4030, from the user, a permanent consent to reveal in current and future visits to the premise the identifier associated with the visit token to the entity system, the permanent consent being valid until withdrawn, and on condition that the permanent consent is received, sending the subscriber identifier associated with the visit token to the entity system.

[0100] The method may further comprise receiving S4050, from the user a subsequent message, and on condition that a temporary consent or a permanent consent is received, forwarding the subsequent message including the identifier associated with the visit token to the entity.

[0101] The method may further comprise determining if there is any blocking applied in relation to the user or the entity as described in relation to Fig. 1. One or more of the steps S4010-S4050 of the method may be performed only on condition that no relevant applied block has been determined.

[0102] Figure 5 shows a flow chart for a method 5000 for notifying an entity of a user entering a premise outside of a time interval by a third party system according to embodiments of the present disclosure. The method 5000 shown in Fig. 5 may be comprised in the any of the methods 2000, 3000, 4000 described with reference to Figs. 2, 3 or 4, and the system disclosed in Fig. 1 may be configured to perform any steps of the method 5000 shown in Fig. 5. Optional method steps are indicated by dashed lines.

[0103] The method 5000 comprises receiving S5010 information about a time interval in which visitors are allowed at a premise from an entity system. The receiving S5010 may be performed during a configuration of the third party system. The method further comprises detecting S5030 that a device of a user has entered the premise, determining S5040 that the user has entered the premise outside of the allowed time interval, and on condition that the user has entered the premise outside of the allowed time interval, sending S5050 a notification to the entity that a user has entered the premise outside of the allowed time interval.

[0104] In an alternative, steps S5010, S5040 and S5050 may comprise receiving information about a time in which visitors are not allowed at the premise from the entity system, determining that the user has entered the premise in the time interval in which visitors are not allowed at the premise, and sending a notification to the entity that a user has entered the premise in the time interval in which visitors are not allowed.

[0105] The notification may comprise information related to the entry to the premise. In some examples, the third party entity 100 may, on request, provide the user identifier to the entity system (as described with reference to Figs 1 and 2) when it has been determined that the user has entered the premise outside of the allowed time interval, so that the entity may identify the user.

[0106] The method 5000 may further comprise receiving S5020 information on identities which are allowed at the premise outside of the time interval. The method may further comprise, on condition that the identity of the user is comprised in the allowed identities, refraining S5060 from sending the security notification.

[0107] While the present disclosure is susceptible to various modifications and alternative forms, specific embodiments are shown and described above by way of example in relation to the drawings, with a view to clearly explaining the various advantageous aspects of the present disclosure. It should be understood, however, that the detailed description herein and the drawings attached hereto are not intended to limit the disclosure to the particular form disclosed. Rather, the intention is to cover all modifications, equivalents, and alternatives falling within the scope of the following claims.

Claims

CLAIMS1. A method performed in system of a third party for enabling information exchange between a system of an entity and a device of a user entering a premise of the entity without revealing the identity of the user of the device to the system of the entity, the method comprising: detecting that a user has entered the premise based on that a device of the user has entered the premise, and determining an identifier of the user; generating a visit token for the identifier; and sending the visit token to the system of the entity.

2. The method according to the preceding claim, further comprising: sending statistical information related to user for which the visit token is generated for to the system of the entity.

3. The method according to any one of the preceding claims, further comprising: receiving information on a geographical area of the premise of the entity; wherein detecting that the user has entered the premise is based on at least on the received information.

4. The method according to any one of the preceding claims, further comprising: storing an association between the identifier and the visit token.

5. The method according to claim 4, wherein the identifier is not derivable from the visit token, and wherein the identifier is obtainable by the system of the third party using the stored association.

6. The method according to any one of the preceding claims, further comprising: receiving, from the entity, a message and the visit token; sending the message to the user for which the visit token was generated.

7. The method according to any one of the preceding claims, wherein the message comprises a reply-to address associated with the system of the organization, further comprising: receiving, from the user, a second message sent to the reply-to address; and sending the second message to the entity for the visit token.

8. The method according to claim 7, wherein the message comprises a link to information, and the method further comprises: receiving a request for the link to information from the device; and forwarding the request for the link to information to the system of the entity.

9. The method according to claim 8, wherein the request comprises user identifying data, and the method further comprises: filtering the user identifying data and forwarding the request to the system of the entity.

10. The method according to any one of the preceding claims, further comprising: receiving, from the entity, a request for the identifier associated with the visit token; and sending the identifier associated with the visit token to the entity.

11. The method according to any one of the preceding claims, further comprising: receiving, from the user during a visit to the premise, a temporary consent to reveal the identifier associated with the visit token to the entity; and on condition that the temporary consent is received, sending the identifier associated with the visit token to the entity.

12. The method according to any one of the preceding claims, further comprising: receiving, from the user, a permanent consent to reveal in current and future visits to the premise the identifier associated with the visit token to the entity, the permanent consent being valid until withdrawn; and on condition that the permanent consent is received, sending the subscriber identifier associated with the visit token to the entity.

13. The method according to any one of claims 11 and 12, further comprising: receiving, from the user a subsequent message; and on condition that a temporary consent or a permanent consent is received, forwarding the subsequent message including the identifier associated with the visit token to the entity.

14. The method according to any one of the preceding claims, further comprising: determining that the user has left the premise based on that the device has left the premise; and sending a notification to the system of the entity that the user has left the premise.

15. The method according to any one of the preceding claims, further comprising: receiving information about a time interval in which visitors are allowed at the premise from the entity; detecting that a device has entered the premise; determining that the user has entered the premise outside of the allowed time interval; and on condition that the user has entered the premise outside of the allowed time interval, sending a notification to the entity that a user has entered the premise outside of the allowed time interval.

16. The method according to claim 15, further comprising: receiving information on identities which are allowed at the premise outside of the time interval; and on condition that the identity of the user is comprised in the allowed identities, refraining from sending the security notification.

17. The method according to any one of the preceding claims, wherein the identifier is a subscriber identifier of the user, preferably the subscriber identity is an MSISDN and the third party is a telecommunications operator.

18. A system for enabling information exchange between a system of an entity and a device of a user entering a premise of the entity without revealing an identity of the user of the device to the system of the entity, comprising: a system of third party configured to perform the method of claims 1-17; a detection unit arranged at the premise of the entity, the detection unit being configured to detect that a device of a user enters the premise and send information of the entry to the third party; and a server comprised in the system of the entity for receiving data from the third party.

19. A computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the steps of the method of any one of claims 1-17.

Citation Information

Patent Citations

  • Node for use in positioning of a wireless unit, and related methods and systems

    WO2022003153A1

  • Method and apparatus for private token communication services

    US20140025753A1

  • Time-bound secure access

    US20190312737A1

  • System and method for enriching consumer management records using hashed mobile signaling data

    WO2020097519A1