IP Library › Granted Patent US 12,105,843
Granted Patent B2
US 12,105,843 · App. 18/462,031 · Granted Oct 1, 2024

Verifiable consent for privacy protection

Inventors: Gang Wang (Jersey City, NJ); Marcel M. Moti Yung (New York, NY)
Assignee: Google LLC
G06F21/6245H04L9/30H04L9/3213H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,105,843
App. No.
18/462,031
Granted
Oct 1, 2024
Kind
B2
Abstract

Methods, systems, and apparatus, including a method for updating user consent in a verifiable manner. In some aspects, a method includes receiving, from a client device, a request including an attestation token. The attestation token includes a set of data that includes at least a user identifier that uniquely identifies a user of the client device, a token creation time that indicates a time at which the attestation token was created, user consent data specifying whether one or more entities that receive the attestation token are eligible to use data of the user, an action to be performed in response to the request. The attestation token also includes a digital signature of at least a portion of the set of data, including at least the user identifier and the token creation time. An integrity of the request is verified using the attestation token.

Claims (91)

1. A computer-implemented method comprising:

receiving, from a client device, a request including an attestation token, the attestation token including:

a set of data that includes at least:

a user identifier that uniquely identifies a user of the client device;

a token creation time that indicates a time at which the attestation token was created;

user consent data specifying whether one or more entities that receive the attestation token are eligible to use data of the user; and

an action to be performed in response to the request; and

a digital signature of at least a portion of the set of data, including at least the user identifier and the token creation time; and

verifying an integrity of the request using the attestation token, including:

determining whether the token creation time is within a threshold duration of a time at which the request was received;

determining, using the digital signature, whether the set of data was modified after the attestation token was created; and

determining that the integrity of the request is valid based at least on determination that the token creation time is within the threshold duration of the time at which the request was received and a determination that the set of data has not been modified since the attestation token was created; and

performing the action in response to determining that the integrity of the request is valid.

2. The computer-implemented method of claim 1 , wherein performing the action comprises:

determining that the user consent data indicates that the data of the user is to be deleted; and

deleting the data of the user.

3. The computer-implemented method of claim 1 , wherein performing the action comprises:

determining that the user consent data specifies one or more authorized actions that are authorized by the user to be performed by a given entity using the data of the user; and

preventing the given entity from using the data of the user for actions other than the specified one or more authorized actions.

4. The computer-implemented method of claim 1 , wherein:

the set of data includes payload data that includes the user consent data;

the payload data further comprises a domain to which the action applies; and

the method further comprises determining that the action is a user consent action to modify previous consent given by the user for the domain to use the data of the user.

5. The computer-implemented method of claim 1 , wherein the digital signature is a signature of the user identifier, the token creation time, and the user consent data.

6. The computer-implemented method of claim 1 , wherein the set of data further comprises at least one of a device integrity token or a browser integrity token.

7. The computer-implemented method of claim 1 , wherein:

the one or more entities comprises multiple recipient entities to which the request is provided; and

the user consent data includes, for each recipient entity, an encrypted consent element that includes user consent data specific to the recipient entity, wherein the encrypted consent element for each recipient entity is encrypted using a public key of the recipient entity.

8. The computer-implemented method of claim 1 , further comprising:

receiving a second request that includes a second user identifier and a second token creation time;

determining that the second user identifier of the second request matches the user identifier of the request;

determining that the second token creation time of the second request matches the token creation time of the request; and

in response to determining that the second user identifier of the second request matches the user identifier of the request and that the second token creation time of the second request matches the token creation time of the request, determining that either the second request is a duplicate of the request or a replay attack has occurred.

9. A system, comprising:

one or more processors; and

one or more memories having stored thereon computer readable instructions configured to cause the one or more processors to perform operations comprising:

receiving, from a client device, a request including an attestation token, the attestation token including:

a set of data that includes at least:

a user identifier that uniquely identifies a user of the client device;

a token creation time that indicates a time at which the attestation token was created;

user consent data specifying whether one or more entities that receive the attestation token are eligible to use data of the user; and

an action to be performed in response to the request; and

a digital signature of at least a portion of the set of data, including at least the user identifier and the token creation time; and

verifying an integrity of the request using the attestation token, including:

determining whether the token creation time is within a threshold duration of a time at which the request was received;

determining, using the digital signature, whether the set of data was modified after the attestation token was created; and

determining that the integrity of the request is valid based at least on determination that the token creation time is within the threshold duration of the time at which the request was received and a determination that the set of data has not been modified since the attestation token was created; and

performing the action in response to determining that the integrity of the request is valid.

10. The system of claim 9 , wherein performing the action comprises:

determining that the user consent data indicates that the data of the user is to be deleted; and

deleting the data of the user.

11. The system of claim 9 , wherein performing the action comprises:

determining that the user consent data specifies one or more authorized actions that are authorized by the user to be performed by a given entity using the data of the user; and

preventing the given entity from using the data of the user for actions other than the specified one or more authorized actions.

12. The system of claim 9 , wherein:

the set of data includes payload data that includes the user consent data;

the payload data further comprises a domain to which the action applies; and

the operations comprise determining that the action is a user consent action to modify previous consent given by the user for the domain to use the data of the user.

13. The system of claim 9 , wherein the digital signature is a signature of the user identifier, the token creation time, and the user consent data.

14. The system of claim 9 , wherein the set of data further comprises at least one of a device integrity token or a browser integrity token.

15. The system of claim 9 , wherein:

the one or more entities comprises multiple recipient entities to which the request is provided; and

the user consent data includes, for each recipient entity, an encrypted consent element that includes user consent data specific to the recipient entity, wherein the encrypted consent element for each recipient entity is encrypted using a public key of the recipient entity.

16. The system of claim 9 , wherein the operations comprise:

receiving a second request that includes a second user identifier and a second token creation time;

determining that the second user identifier of the second request matches the user identifier of the request;

determining that the second token creation time of the second request matches the token creation time of the request; and

in response to determining that the second user identifier of the second request matches the user identifier of the request and that the second token creation time of the second request matches the token creation time of the request, determining that either the second request is a duplicate of the request or a replay attack has occurred.

17. A non-transitory computer readable medium storing instructions that upon execution by one or more computers cause the one or more computers to perform operations comprising:

receiving, from a client device, a request including an attestation token, the attestation token including:

a set of data that includes at least:

a user identifier that uniquely identifies a user of the client device;

a token creation time that indicates a time at which the attestation token was created;

user consent data specifying whether one or more entities that receive the attestation token are eligible to use data of the user; and

an action to be performed in response to the request; and

a digital signature of at least a portion of the set of data, including at least the user identifier and the token creation time; and

verifying an integrity of the request using the attestation token, including:

determining whether the token creation time is within a threshold duration of a time at which the request was received;

determining, using the digital signature, whether the set of data was modified after the attestation token was created; and

determining that the integrity of the request is valid based at least on determination that the token creation time is within the threshold duration of the time at which the request was received and a determination that the set of data has not been modified since the attestation token was created; and

performing the action in response to determining that the integrity of the request is valid.

18. The non-transitory computer readable medium of claim 17 , wherein performing the action comprises:

determining that the user consent data indicates that the data of the user is to be deleted; and

deleting the data of the user.

19. The non-transitory computer readable medium of claim 17 , wherein performing the action comprises:

determining that the user consent data specifies one or more authorized actions that are authorized by the user to be performed by a given entity using the data of the user; and

preventing the given entity from using the data of the user for actions other than the specified one or more authorized actions.

20. The non-transitory computer readable medium of claim 17 , wherein:

the set of data includes payload data that includes the user consent data;

the payload data further comprises a domain to which the action applies; and

the operations comprise determining that the action is a user consent action to modify previous consent given by the user for the domain to use the data of the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2023
From: WANG, GANG; YUNG, MARCEL M. MOTI
To: GOOGLE LLC
Reel/Frame 065332/0699 →
Continuity (3)
Continuation 17286626
Provisional Application 62924059 · Oct 21, 2019
Related Publication 20240111895A1 · Apr 4, 2024