IP Library Granted Patent US 12670294
Granted Patent B2
US 12670294 · App. 18/811,166 · Granted Jun 30, 2026

Verifiable consent for privacy protection

Inventors: Gang Wang (Frederick, MD); Marcel M. Moti Yung (New York, NY)
Assignee: Google LLC
G06F21/6245H04L9/30H04L9/3213H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12670294
App. No.
18/811,166
Granted
Jun 30, 2026
Kind
B2
Abstract

Methods, systems, and apparatus, including a method for updating user consent in a verifiable manner. In some aspects, a method includes receiving, from a client device, a request including an attestation token. The attestation token includes a set of data that includes at least a user identifier that uniquely identifies a user of the client device, a token creation time that indicates a time at which the attestation token was created, user consent data specifying whether one or more entities that receive the attestation token are eligible to use data of the user, an action to be performed in response to the request. The attestation token also includes a digital signature of at least a portion of the set of data, including at least the user identifier and the token creation time. An integrity of the request is verified using the attestation token.

Claims (61)

1 . A computer-implemented method comprising:

receiving, at a client device of a user, updated user consent data specifying at least one of (i) whether one or more entities are eligible to use data of the user or (ii) how the one or more entities are allowed to use the data of the user;

in response to receiving the updated user consent data,

generating, by the client device, an attestation token comprising:

a set of data comprising an identifier for the user and the user consent data; and

a digital signature of the set of data; and

sending, by the client device, the attestation token to each of the one or more entities,

wherein the one or more entities comprise multiple entities to which a request comprising the attestation token is provided, and

wherein the user consent data includes, for each entity, an encrypted consent element that includes user consent data specific to the entity, wherein the encrypted consent element for each entity is encrypted using an encryption key of the entity.

2 . The computer-implemented method of claim 1 , further comprising:

determining that a confirmation from a given entity of the one or more entities was not received; and

generating an alert.

3 . The computer-implemented method of claim 2 , wherein generating the alert comprises sending the alert to an auditing system in response to determining that the confirmation was not received.

4 . The computer-implemented method of claim 1 , further comprising:

determining that a confirmation from a given entity of the one or more entities was received; and

storing the confirmation at the client device.

5 . The computer-implemented method of claim 1 , wherein the set of data comprises a token creation time that indicates a time at which the attestation token was created.

6 . The computer-implemented method of claim 1 , wherein the set of data comprises an action to be performed by at least one of the one or more entities based on the user consent data.

7 . The computer-implemented method of claim 6 , wherein the action comprises deleting, by the at least one entity, the data of the user.

8 . The computer-implemented method of claim 1 , wherein the user consent data comprises one or more authorized actions that are authorized by the user to be performed by a given entity of the one or more entities using the data of the user.

9 . A system, comprising:

one or more processors of a client device of a user; and

one or more memories having stored thereon computer readable instructions configured to cause the one or more processors to perform operations comprising:

receiving, at the client device of the user, updated user consent data specifying at least one of (i) whether one or more entities are eligible to use data of the user or (ii) how the one or more entities are allowed to use the data of the user;

in response to receiving the updated user consent data,

generating, by the client device, an attestation token comprising:

a set of data comprising an identifier for the user and the user consent data; and

a digital signature of the set of data; and

sending, by the client device, the attestation token to each of the one or more entities,

wherein the one or more entities comprise multiple entities to which a request comprising the attestation token is provided, and

wherein the user consent data includes, for each entity, an encrypted consent element that includes user consent data specific to the entity, wherein the encrypted consent element for each entity is encrypted using an encryption key of the entity.

10 . The system of claim 9 , wherein the operations comprise:

determining that a confirmation from a given entity of the one or more entities was not received; and

generating an alert.

11 . The system of claim 10 , wherein generating the alert comprises sending the alert to an auditing system in response to determining that the confirmation was not received.

12 . The system of claim 10 , wherein the operations comprise:

determining that a confirmation from a given entity of the one or more entities was received; and

storing the confirmation at the client device.

13 . The system of claim 10 , wherein the set of data comprises a token creation time that indicates a time at which the attestation token was created.

14 . The system of claim 10 , wherein the set of data comprises an action to be performed by at least one of the one or more entities based on the user consent data.

15 . The system of claim 14 , wherein the action comprises deleting, by the at least one entity, the data of the user.

16 . The system of claim 10 , wherein:

the one or more entities comprises multiple recipient entities to which a request comprising the attestation token is provided; and

the user consent data includes, for each recipient entity, an encrypted consent element that includes user consent data specific to the recipient entity, wherein the encrypted consent element for each recipient entity is encrypted using an encryption key of the recipient entity.

17 . The system of claim 10 , wherein the user consent data comprises one or more authorized actions that are authorized by the user to be performed by a given entity of the one or more entities using the data of the user.

18 . A non-transitory computer readable medium storing instructions that upon execution by one or more computers cause the one or more computers to perform operations comprising:

receiving, at a client device of a user, updated user consent data specifying at least one of (i) whether one or more entities are eligible to use data of the user or (ii) how the one or more entities are allowed to use the data of the user;

in response to receiving the updated user consent data,

generating, by the client device, an attestation token comprising:

a set of data comprising an identifier for the user and the user consent data; and

a digital signature of the set of data; and

sending, by the client device, the attestation token to each of the one or more entities,

wherein the one or more entities comprise multiple entities to which a request comprising the attestation token is provided, and

wherein the user consent data includes, for each entity, an encrypted consent element that includes user consent data specific to the entity, wherein the encrypted consent element for each entity is encrypted using an encryption key of the entity.

19 . The non-transitory computer readable medium of claim 18 , wherein the operations comprise:

determining that a confirmation from a given entity of the one or more entities was not received; and

generating an alert.

20 . The non-transitory computer readable medium of claim 19 , wherein generating the alert comprises sending the alert to an auditing system in response to determining that the confirmation was not received.

21 . The non-transitory computer readable medium of claim 18 , wherein the operations comprise:

determining that a confirmation from a given entity of the one or more entities was received; and

storing the confirmation at the client device.