Encrypted User Profile Data Protection for Online Advertising
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The online advertising environment faces significant privacy concerns as user profiles are easily accessible to government entities and malicious parties, with users finding it difficult to opt out of intrusive tracking and profiling methods, and there is a need to protect user data without reducing utility or impacting content delivery.
Innovation Solution
Implementing methods and systems where user profiles are encrypted, with decryption keys transmitted to client devices, ensuring that user profile data is accessible only when the client and host server are connected, thereby preventing unauthorized decryption and enhancing data privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If user profiles are stored in plain text on servers for easy access and targeted advertising, then advertising utility and content delivery performance are improved, but user data becomes vulnerable to unauthorized access by government entities and malicious parties
Solution Approach 1:
The patent extracts the decryption key from the server environment and places it exclusively on the client device. This separation removes the vulnerability of storing sensitive data in plain text on servers while maintaining advertising utility, as the server can still store encrypted profiles and serve ads when the client provides the key temporarily.
Solution Approach 2:
The patent performs encryption of user profiles before storing them on servers, and pre-configures the client device with decryption capabilities. This preliminary protection ensures data is secured before any potential access occurs, while the system remains ready to deliver targeted advertising when needed.
2Speed
If decryption keys are stored on servers for quick decryption during ad delivery, then content delivery speed is improved, but unauthorized access and data breaches become more likely
Solution Approach 1:
The patent introduces the client device as an intermediary that holds and controls the decryption key. The server communicates ad requests to the client, which then provides the key temporarily for decryption. This intermediary role maintains fast delivery while preventing server-side unauthorized access.
Solution Approach 2:
The patent makes the decryption key dynamic rather than static - it is transmitted temporarily during active communication sessions and then deleted or invalidated. This dynamic approach allows fast decryption when needed while automatically revoking access to prevent breaches.
3Productivity
If user tracking and profiling data is collected and stored centrally for targeted advertising, then advertising effectiveness is improved, but user privacy intrusion and difficulty to opt-out increase
Solution Approach 1:
The patent inverts the traditional model where servers control user data by giving control to the client device. The client now holds the decryption key and can choose when to share it with servers for ad delivery. This inversion maintains advertising effectiveness while giving users direct control over their data.
Solution Approach 2:
The patent enables users to manage their own privacy through the client device that stores their decryption keys. Users can control which sessions receive keys and thus which ads are delivered, allowing them to opt-in or opt-out of targeted advertising without needing external authorization mechanisms.
Data Source
AI summary
Systems and methods are disclosed for protecting user privacy in, for example, online advertising environments. The method includes receiving data related to a user in a first communication session between a host server and a client device, and generating a user profile associated with the user. The method further may include encrypting the user profile to produce encrypted user profile data and generating a decryption key for decrypting the encrypted user profile data. Thereafter, either the decryption key or a portion of the encrypted user profile data may be transmitted to the client device and then deleted from host server before ending the first communication session. The method further may include establishing a second communication session between the host server and the client device and retrieving the transmitted content. Then targeted advertising may be provided by decrypting the encrypted user profile data.


