Verifiable consent for privacy protection
Methods, systems, and apparatus, including a method for updating user consent in a verifiable manner. In some aspects, a method includes receiving, from a client device, a request including an attestation token. The attestation token includes a set of data that includes at least a user identifier that uniquely identifies a user of the client device, a token creation time that indicates a time at which the attestation token was created, user consent data specifying whether one or more entities that receive the attestation token are eligible to use data of the user, an action to be performed in response to the request. The attestation token also includes a digital signature of at least a portion of the set of data, including at least the user identifier and the token creation time. An integrity of the request is verified using the attestation token.
1 . A computer-implemented method comprising:
receiving, at a client device of a user, updated user consent data specifying at least one of (i) whether one or more entities are eligible to use data of the user or (ii) how the one or more entities are allowed to use the data of the user;
in response to receiving the updated user consent data,
generating, by the client device, an attestation token comprising:
a set of data comprising an identifier for the user and the user consent data; and
a digital signature of the set of data; and
sending, by the client device, the attestation token to each of the one or more entities,
wherein the one or more entities comprise multiple entities to which a request comprising the attestation token is provided, and
wherein the user consent data includes, for each entity, an encrypted consent element that includes user consent data specific to the entity, wherein the encrypted consent element for each entity is encrypted using an encryption key of the entity.
2 . The computer-implemented method of claim 1 , further comprising:
determining that a confirmation from a given entity of the one or more entities was not received; and
generating an alert.
3 . The computer-implemented method of claim 2 , wherein generating the alert comprises sending the alert to an auditing system in response to determining that the confirmation was not received.
4 . The computer-implemented method of claim 1 , further comprising:
determining that a confirmation from a given entity of the one or more entities was received; and
storing the confirmation at the client device.
5 . The computer-implemented method of claim 1 , wherein the set of data comprises a token creation time that indicates a time at which the attestation token was created.
6 . The computer-implemented method of claim 1 , wherein the set of data comprises an action to be performed by at least one of the one or more entities based on the user consent data.
7 . The computer-implemented method of claim 6 , wherein the action comprises deleting, by the at least one entity, the data of the user.
8 . The computer-implemented method of claim 1 , wherein the user consent data comprises one or more authorized actions that are authorized by the user to be performed by a given entity of the one or more entities using the data of the user.
9 . A system, comprising:
one or more processors of a client device of a user; and
one or more memories having stored thereon computer readable instructions configured to cause the one or more processors to perform operations comprising:
receiving, at the client device of the user, updated user consent data specifying at least one of (i) whether one or more entities are eligible to use data of the user or (ii) how the one or more entities are allowed to use the data of the user;
in response to receiving the updated user consent data,
generating, by the client device, an attestation token comprising:
a set of data comprising an identifier for the user and the user consent data; and
a digital signature of the set of data; and
sending, by the client device, the attestation token to each of the one or more entities,
wherein the one or more entities comprise multiple entities to which a request comprising the attestation token is provided, and
wherein the user consent data includes, for each entity, an encrypted consent element that includes user consent data specific to the entity, wherein the encrypted consent element for each entity is encrypted using an encryption key of the entity.
10 . The system of claim 9 , wherein the operations comprise:
determining that a confirmation from a given entity of the one or more entities was not received; and
generating an alert.
11 . The system of claim 10 , wherein generating the alert comprises sending the alert to an auditing system in response to determining that the confirmation was not received.
12 . The system of claim 10 , wherein the operations comprise:
determining that a confirmation from a given entity of the one or more entities was received; and
storing the confirmation at the client device.
13 . The system of claim 10 , wherein the set of data comprises a token creation time that indicates a time at which the attestation token was created.
14 . The system of claim 10 , wherein the set of data comprises an action to be performed by at least one of the one or more entities based on the user consent data.
15 . The system of claim 14 , wherein the action comprises deleting, by the at least one entity, the data of the user.
16 . The system of claim 10 , wherein:
the one or more entities comprises multiple recipient entities to which a request comprising the attestation token is provided; and
the user consent data includes, for each recipient entity, an encrypted consent element that includes user consent data specific to the recipient entity, wherein the encrypted consent element for each recipient entity is encrypted using an encryption key of the recipient entity.
17 . The system of claim 10 , wherein the user consent data comprises one or more authorized actions that are authorized by the user to be performed by a given entity of the one or more entities using the data of the user.
18 . A non-transitory computer readable medium storing instructions that upon execution by one or more computers cause the one or more computers to perform operations comprising:
receiving, at a client device of a user, updated user consent data specifying at least one of (i) whether one or more entities are eligible to use data of the user or (ii) how the one or more entities are allowed to use the data of the user;
in response to receiving the updated user consent data,
generating, by the client device, an attestation token comprising:
a set of data comprising an identifier for the user and the user consent data; and
a digital signature of the set of data; and
sending, by the client device, the attestation token to each of the one or more entities,
wherein the one or more entities comprise multiple entities to which a request comprising the attestation token is provided, and
wherein the user consent data includes, for each entity, an encrypted consent element that includes user consent data specific to the entity, wherein the encrypted consent element for each entity is encrypted using an encryption key of the entity.
19 . The non-transitory computer readable medium of claim 18 , wherein the operations comprise:
determining that a confirmation from a given entity of the one or more entities was not received; and
generating an alert.
20 . The non-transitory computer readable medium of claim 19 , wherein generating the alert comprises sending the alert to an auditing system in response to determining that the confirmation was not received.
21 . The non-transitory computer readable medium of claim 18 , wherein the operations comprise:
determining that a confirmation from a given entity of the one or more entities was received; and
storing the confirmation at the client device.