IP Library › Granted Patent US 12,192,377
Granted Patent B2
US 12,192,377 · App. 17/916,194 · Granted Jan 7, 2025

Secure network communications that limit information access

Inventors: Alex Daniel Jacobson (Mountain View, CA); Gang Wang (Frederick, MD); Marcel M. Moti Yung (New York, NY)
Assignee: Google LLC
H04L9/3247H04L9/0825H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,377
App. No.
17/916,194
Granted
Jan 7, 2025
Kind
B2
Abstract

This disclosure describes systems and techniques for using controlling access to user information using ephemeral user identifiers. In one aspect, a method includes determining, for a given domain, engagement by a user with content provided by the given domain for display by an application at a client device of the user. A determination is made, based on the engagement by the user, to extend, for the given domain, a linkage between user identifiers for a user of the application. In response to determining to extend, for the given domain, the linkage between the user identifiers for the user of the application, one or more future domain-specific ephemeral user identifiers for the user and the given domain are obtained. An attestation record that includes a current domain-specific ephemeral user identifier and the one or more is generated and sent to the given domain.

Claims (66)

1. A computer-implemented method comprising:

determining, for a given domain, engagement by a user with content provided by the given domain for display by an application at a client device of the user;

determining, based on the engagement by the user, to extend, for the given domain, a linkage between different user identifiers for a user of the application for a duration of time such that the given domain is capable of identifying the user using any of the different user identifiers during the duration of time;

in response to determining to extend, for the given domain, the linkage between the user identifiers for the user of the application for the duration of time:

obtaining one or more future domain-specific ephemeral user identifiers for the user and the given domain, wherein each future domain-specific ephemeral user identifier is a user identifier that the application will use to identify the user to the given domain during a future time period after a current time period lapses;

generating an attestation record comprising:

a set of data comprising payload data;

a digital signature of the set of data;

a current domain-specific ephemeral user identifier for the user and the given domain; and

the one or more future domain-specific ephemeral user identifiers for the user and the given domain; and

sending the attestation record to the given domain.

2. The computer-implemented method of claim 1 , wherein the set of data comprises a timestamp indicating a time at which the attestation record is generated and a signed redemption record.

3. The computer-implemented method of claim 1 , wherein the payload data comprises the one or more future domain-specific user identifiers for the user and the given domain.

4. The computer-implemented method of claim 1 , wherein the engagement by the user comprises a level of user engagement by the user with the content provided by the given domain for display by the application at the client device of the user, the method further comprising selecting a quantity of the one or more future domain-specific user identifiers for the user and the given domain based on the level of user engagement for the given domain.

5. The computer-implemented method of claim 1 , wherein the current domain-specific user identifier and the one of more future domain-specific user identifiers are encrypted using an encryption key of the given domain.

6. The computer-implemented method of claim 1 , wherein the attestation record comprises, for each of multiple domains including the given domain, a respective current user identifier for the domain.

7. The computer-implemented method of claim 1 , wherein:

the current domain-specific ephemeral user identifier for the user and the given domain comprises a current public key for the user and the given domain; and

each of the one or more future domain-specific user identifiers comprises a future public key for the user and the given domain.

8. The computer-implemented method of claim 1 , wherein:

the given domain is a domain of a publisher of electronic resources; and

determining, for the given domain, the user engagement by the user with content provided by the given domain for display by the application at the client device of the user comprises determining a level of user engagement based on the user navigating to an electronic resource of the publisher.

9. The computer-implemented method of claim 1 , wherein:

the given domain is a domain of a content platform that distributes digital components or of a content platform that facilitates distribution of digital components by another content platform; and

determining, for the given domain, the engagement by the user with content provided by the given domain for display by the application at the client device of the user comprises determining a level of user engagement based on the content platform providing one or more digital components for presentation at the client device.

10. The computer-implemented method of claim 1 , wherein:

the given domain is a domain of a digital component provider that creates digital components that include content of the digital component provider; and

determining, for the given domain, the engagement by the user with content provided by the given domain for display by the application at the client device of the user comprises determining a level of user engagement based on the user interacting with a digital component created by the digital component provider.

11. A system comprising:

one or more processors; and

one or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processor to perform operations comprising:

determining, for a given domain, engagement by a user with content provided by the given domain for display by an application at a client device of the user;

determining, based on the engagement by the user, to extend, for the given domain, a linkage between different user identifiers for a user of the application for a duration of time such that the given domain is capable of identifying the user using any of the different user identifiers during the duration of time;

in response to determining to extend, for the given domain, the linkage between the user identifiers for the user of the application for the duration of time:

obtaining one or more future domain-specific ephemeral user identifiers for the user and the given domain, wherein each future domain-specific ephemeral user identifier is a user identifier that the application will use to identify the user to the given domain during a future time period after a current time period lapses;

generating an attestation record comprising:

a set of data comprising payload data;

a digital signature of the set of data;

a current domain-specific ephemeral user identifier for the user and the given domain; and

the one or more future domain-specific ephemeral user identifiers for the user and the given domain; and

sending the attestation record to the given domain.

12. The system of claim 11 , wherein the set of data comprises a timestamp indicating a time at which the attestation record is generated and a signed redemption record.

13. The system of claim 11 , wherein the payload data comprises the one or more future domain-specific user identifiers for the user and the given domain.

14. The system of claim 11 , wherein the engagement by the user comprises a level of user engagement by the user with the content provided by the given domain for display by the application at the client device of the user, the operations further comprising selecting a quantity of the one or more future domain-specific user identifiers for the user and the given domain based on the level of user engagement for the given domain.

15. The system of claim 11 , wherein the current domain-specific user identifier and the one of more future domain-specific user identifiers are encrypted using an encryption key of the given domain.

16. The system of claim 11 , wherein the attestation record comprises, for each of multiple domains including the given domain, a respective current user identifier for the domain.

17. The system of claim 11 , wherein:

the current domain-specific ephemeral user identifier for the user and the given domain comprises a current public key for the user and the given domain; and

each of the one or more future domain-specific user identifiers comprises a future public key for the user and the given domain.

18. The system of claim 11 , wherein:

the given domain is a domain of a publisher of electronic resources; and

determining, for the given domain, the user engagement by the user with content provided by the given domain for display by the application at the client device of the user comprises determining a level of user engagement based on the user navigating to an electronic resource of the publisher.

19. The system of claim 11 , wherein:

the given domain is a domain of a content platform that distributes digital components or of a content platform that facilitates distribution of digital components by another content platform; and

determining, for the given domain, the engagement by the user with content provided by the given domain for display by the application at the client device of the user comprises determining a level of user engagement based on the content platform providing one or more digital components for presentation at the client device.

20. A non-transitory computer readable storage medium carrying instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

determining, for a given domain, engagement by a user with content provided by the given domain for display by an application at a client device of the user;

determining, based on the engagement by the user, to extend, for the given domain, a linkage between different user identifiers for a user of the application for a duration of time such that the given domain is capable of identifying the user using any of the different user identifiers during the duration of time;

in response to determining to extend, for the given domain, the linkage between the user identifiers for the user of the application for the duration of time:

obtaining one or more future domain-specific ephemeral user identifiers for the user and the given domain, wherein each future domain-specific ephemeral user identifier is a user identifier that the application will use to identify the user to the given domain during a future time period after a current time period lapses;

generating an attestation record comprising:

a set of data comprising payload data;

a digital signature of the set of data;

a current domain-specific ephemeral user identifier for the user and the given domain; and

the one or more future domain-specific ephemeral user identifiers for the user and the given domain; and

sending the attestation record to the given domain.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2023
From: JACOBSON, ALEX DANIEL; WANG, GANG; YUNG, MARCEL M. MOTI
To: GOOGLE LLC
Reel/Frame 063415/0474 →
Priority Claims (1)
IL 280116 · Jan 12, 2021 · national
Continuity (1)
Related Publication 20230141428A1 · May 11, 2023
References Cited (30)
US 7716077B1 · Mikurak · 2010 [cited by examiner]
US 8468244B2 · Redlich · 2013 [cited by examiner]
US 9111098B2 · Smith · 2015 [cited by examiner]
US 10453319B2 · Jarvis · 2019 [cited by examiner]
US 11757662B2 · Le Saint · 2023 [cited by examiner]
US 11882118B2 · Larson · 2024 [cited by examiner]
US 11936772B1 · Kumar · 2024 [cited by examiner]
US 11936942B2 · Bastable · 2024 [cited by examiner]
US 11995194B1 · Shea · 2024 [cited by examiner]
US 20100325441A1 · Laurie et al. · 2010 [cited by applicant]
US 20140359782A1 · Golic · 2014 [cited by applicant]
US 20160234024A1 · Mozer · 2016 [cited by applicant]
CN 111684448 · 2020 [cited by applicant]
JP 2013218575 · 2013 [cited by applicant]
WO WO2008126180 · 2008 [cited by applicant]
WO WO2013047534 · 2013 [cited by applicant]
WO WO2018123190 · 2018 [cited by applicant]
Office Action in Israel Appln. No. 280116, dated Jun. 11, 2023, 4 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2021/063,477, mailed on Jul. 27, 2023, 10 pages. [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2022-566204, mailed on Apr. 22, 2024, 5 pages (with English translation). [cited by applicant]
Office Action in Indian Appln. No. 202227056349, mailed on Dec. 29, 2023, 6 pages (with English translation). [cited by applicant]
Office Action in Japanese Appln. No. 2022-566204, mailed on Jan. 9, 2024, 4 pages (with English translation). [cited by applicant]
Aslam et al., “Distributed certificate and application architecture for VANETs.” MILCOM 2009-2009 IEEE Military Communications Conference. IEEE, Oct. 18, 2009, 1-7. [cited by applicant]
Developers.google.com [online], “Cookie Matching” Jun. 2019, retrieved on Dec. 13, 2022, retrieved from URL <https://developers.google.com/authorized-buyers/rtb/cookie-guide>, 29 pages. [cited by applicant]
Github.com [online], “Trust Token Api” Aug. 2019, retrieved on Dec. 13, 2022, retrieved from URL <https://github.com/WICG/trust-token-api#trust-token-redemption>, 13 pages. [cited by applicant]
Github.com [online], “Trust Token” Oct. 2017, retrieved on Dec. 13, 2022, retrieved from URL <https://github.com/trusttoken>, 3 pages. [cited by applicant]
Iabtechlab.com [online], “Ads.Txt—Authorized Digital Sellers” May 2017, retrieved on Dec. 13, 2022, retrieved from URL <https://iabtechlab.com/ads-txt/>, 5 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2021/063,477, dated Apr. 4, 2022, 16 pages. [cited by applicant]
Wikipedia.org [online], “Initialization vector” created on Oct. 2002, retrieved on Dec. 13, 2022, retrieved from URL <https://en.wikipedia.org/wiki/Initialization_vector>, 5 pages. [cited by applicant]
Office Action in Chinese Appln. No. 202180030995.4, mailed on Aug. 26, 2024, 19 pages (with English translation). [cited by applicant]