System and method for loading secure data in multiparty secure computing environment
A computational approach is proposed herein for controlling a user interface for rendering of interactive graphical control elements representing offers and coupons that are inserted into a computational payment process. In particular, the offers and coupons can interact with stored payment information resident (or tokens thereof) on a digital wallet data structure. The approach can be implemented as a computing system, a computing method operable on a computing system, or a computer program product affixed in the form of a non-transitory computer readable medium storing machine-interpretable instructions.
1 . A computer system for controlling a user interface for rendering of interactive graphical control elements representing offers or coupons that are inserted into a computational payment process privacy preserving cross-data table analysis, the computer system comprising:
a processor operating in conjunction with computer memory and storing data on a non-transitory computer readable storage medium, the processor configured to:
receive, through a network from a computing device, a query message request representing a set of logical conditions for establishing eligibility for one or more promotional offers or coupons, said logical conditions requiring cross-table connections between at least two tables of a plurality of data tables associated with at least two different data sources or entities, each logical condition of the set of logical conditions representing a user characteristic, each data table of the plurality of data tables including at least a field representing unique user identifiers used as a primary key for identifying a user across the plurality of data tables, a first corresponding field representing the user characteristic for each unique user identifier of the unique user identifiers, and a second corresponding field representing a consent field for each unique user identifier of the unique user identifiers;
aggregate the at least two data tables of the plurality of data tables for the cross-table connections, wherein the aggregated at least two data tables of the plurality of data tables is not accessible external to a trusted execution environment;
in response to receiving the query message request, generate an audience list representing one or more users within the aggregated at least two data tables satisfying the set of logical conditions;
validate or compare the query message request in accordance with or for adherence to one or more privacy policy requirements by validating or comparing the query message request against the second corresponding field representing the consent field of the one or more users in the audience list and modifying the audience list in adherence to the one or more privacy policy requirements without use of cookies on a webpage or computing device;
in response to a detected triggering event associated with a user in the modified audience list, transmit, across the network to a computing device corresponding to the user, one or more promotional offers or coupons of the promotional offers or coupons in accordance or in adherence with the privacy policy requirements;
wherein the audience list is maintained on an always protected database system encrypted using one or more encryption keys and configured for interaction through a limited application programming interface having sole access to the one or more encryption keys, and the computing device does not have direct access to the audience list or the aggregated data tables.
2 . The computer system of claim 1 , wherein the set of logical conditions includes a threshold score established through a plurality of weighted logical conditions to be met, and wherein the computing device is not provided individual scores contributing to the threshold score.
3 . The computer system of claim 1 , wherein the at least two data tables of the plurality of data tables is joined together in a temporal aggregate data table for processing the query message request, and the temporal aggregate data table is discarded after processing the query message request.
4 . The computer system of claim 1 , wherein the query message request is communicated by the computing device along with a consent data structure representing consent tokens provided by at least one of a user or data sources corresponding to the plurality of data tables to be loaded, and wherein the validation of the query message request for adherence to one or more privacy policy requirements includes validating the consent data structure.
5 . The computer system of claim 4 , wherein the consent data structure includes cryptographic keys, each corresponding to at least one of the at least one of a user or data sources corresponding to the plurality of data tables to be loaded, and each of the cryptographic keys are validated against a corresponding cryptographic key validation portion stored on or accessible by an always protected database system.
6 . The computer system of claim 1 , wherein the audience list is utilized for automatic provisioning of offers or promotions and a list of users of the audience list is not otherwise accessible.
7 . The computer system of claim 1 , wherein the audience list is utilized for coordinating eligibility for multiple campaigns to prevent provisioning overlapping promotions to a same user on the audience list.
8 . The computer system of claim 1 , wherein the audience list is utilized for automatic eligibility for promotions based on user attributes.
9 . The computer system of claim 1 , wherein the computer system is a computing server appliance residing within a data center, the computing server appliance connected through a message bus to receive the query message request across a network from the campaign management process coupled through an interface.
10 . A computer method for controlling a user interface for rendering of interactive graphical control elements representing offers or coupons that are inserted into a computational payment process, the computer method comprising:
receiving, through a network from a computing device, a query message request representing a set of logical conditions for establishing eligibility for one or more offers or coupons, said logical conditions requiring cross-table connections between at least two tables of a plurality of data tables associated with at least two different data sources or entities, each logical condition of the set of logical conditions representing a user characteristic, each data table of the plurality of data tables including at least a field representing unique user identifiers used as a primary key for identifying a user across the plurality of data tables, a first corresponding field representing the user characteristic for each unique user identifier of the unique user identifiers, and a second corresponding field representing a consent field for each unique user identifier of the unique user identifiers;
aggregate the at least two data tables of the plurality of data tables for the cross-table connections, wherein the aggregated at least two data tables of the plurality of data tables is not accessible external to a trusted execution environment;
in response to receiving the query message request, generate an audience list representing one or more users within the aggregated at least two data tables satisfying the set of logical conditions;
validating or comparing the query message request in accordance with or for adherence to one or more privacy policy requirements by validating or comparing the query message request against the second corresponding field representing the consent field of the one or more users in the audience list and modifying the audience list in adherence to the one or more privacy policy requirements without use of cookies on a webpage or computing device,
in response to a detected triggering event associated with a user in the modified audience list, transmitting, across the network to a computing device corresponding to the user, one or more promotional offers or coupons of the promotional offers or coupons in accordance or in adherence with the privacy policy requirements;
wherein the audience list is maintained on an always protected database system encrypted using one or more encryption keys and configured for interaction through a limited application programming interface having sole access to the one or more encryption keys, and the computing device does not have direct access to the audience list or the aggregated data tables.
11 . The computer method of claim 10 , wherein the set of logical conditions includes a threshold score established through a plurality of weighted logical conditions to be met, and wherein the computing device is not provided individual scores contributing to the threshold score.
12 . The computer method of claim 10 , wherein the at least two data tables of the plurality of data tables are joined together in a temporal aggregate data table for processing the query message request, and the temporal aggregate data table is discarded after processing the query message request.
13 . The computer method of claim 10 , wherein the query message request is communicated by the computing device along with a consent data structure representing consent tokens provided by at least one of a user or data sources corresponding to the plurality of data tables to be loaded, and wherein the validation of the query message request for adherence to one or more privacy policy requirements includes validating the consent data structure.
14 . The computer method of claim 13 , wherein the consent data structure includes cryptographic keys, each corresponding to at least one of the at least one of a user or data sources corresponding to the plurality of data tables to be loaded, and each of the cryptographic keys are validated against a corresponding cryptographic key validation portion stored on or accessible by an always protected database system.
15 . The computer method of claim 10 , wherein the audience list is utilized for automatic provisioning of offers or promotions and a list of users of the audience list is not otherwise accessible.
16 . The computer method of claim 10 , wherein the audience list is utilized for coordinating eligibility for multiple campaigns to prevent provisioning overlapping promotions to a same user on the audience list.
17 . The computer method of claim 15 , wherein the audience list is utilized for automatic eligibility for promotions based on user attributes.
18 . A non-transitory computer readable medium storing machine interpretable instruction sets, which when executed by a processor, cause the processor to perform a method for controlling a user interface for rendering of interactive graphical control elements representing offers or coupons that are inserted into a computational payment process, the method comprising:
receiving, through a network from a computing device, a query message request representing a set of logical conditions for establishing eligibility for one or more promotional offers or coupons, said logical conditions requiring cross-table connections between at least two tables of a plurality of data tables associated with at least two different data sources or entities, each logical condition of the set of logical conditions representing a user characteristic, each data table of the plurality of data tables including at least a field representing unique user identifiers used as a primary key for identifying a user across the plurality of data tables, a first corresponding field representing the user characteristic for each unique user identifier of the unique user identifiers, and a second corresponding field representing a consent field for each unique user identifier of the unique user identifiers;
aggregate the at least two data tables of the plurality of data tables for the cross-table connections, wherein the aggregated at least two data tables of the plurality of data tables is not accessible external to a trusted execution environment;
in response to receiving the query message request, generate an audience list representing one or more users within the aggregated at least two data tables satisfying the set of logical conditions; and
validating or comparing the query message request in accordance with or for adherence to one or more privacy policy requirements by validating or comparing the query message request against the second corresponding field representing the consent field of the one or more users in the audience list and modifying the audience list in adherence to the one or more privacy policy requirements without use of cookies on a webpage or computing device;
in response to a detected triggering event associated with a user in the modified audience list, transmitting, across the network to a computing device corresponding to the user, one or more promotional offers or coupons of the promotional offers or coupons in accordance or in adherence with the privacy policy requirements;
wherein the audience list is maintained on an always protected database system encrypted using one or more encryption keys and configured for interaction through a limited application programming interface having sole access to the one or more encryption keys, and the computing device does not have direct access to the audience list or the aggregated data tables.