IP Library Granted Patent US 12,231,513
Granted Patent B2
US 12,231,513 · App. 18/541,282 · Granted Feb 18, 2025

Systems and methods for securely using cloud services on on-premises data

Inventors: Niraj Deo (Sammamish, WA); Saurabh Pandey (San Jose, CA); Johanna Christina Brugman (Seattle, WA)
Assignee: Oracle International Corporation
H04L67/535H04L12/4641H04L41/0893H04L67/1001H04L67/133H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,513
App. No.
18/541,282
Granted
Feb 18, 2025
Kind
B2
Abstract

The present disclosure relates to systems and methods for providing cloud-based services securely to on-premises networks or other infrastructure. More particularly, the present disclosure relates to systems and methods for enriching first-party data (e.g., data collected directly by an on-premises server) stored within on-premises networks by enabling the on-premises networks to retrieve and process third-party data stored on cloud-based networks. As a technical benefit, cloud-based services can be performed on the first-party data within the on-premises networks.

Claims (61)

1. A computer-implemented method comprising:

receiving, by an on-premises network, an executable code corresponding to one or more cloud-based services;

configuring, by the on-premises network, a private pixel server and a first-party profile database within the on-premises network, based on the executable code, to track interactions between a web server associated with the on-premises network and one or more users within the on-premises network, wherein tracking the interactions enables the first-party profile database to:

collect first-party user data corresponding to each user of the one or more users within the on-premises network; and

generate a virtual private cloud that is accessible by the one or more users with the on-premises network;

storing, by the on-premises network, the first-party user data in the virtual private cloud;

accessing, by the on-premises network, the virtual private cloud to select portions from the first-party user data for which the one or more users have provided consent, wherein the consent enables the selected portions to be uploaded to a cloud-based network;

transmitting, by the on-premises network, the selected portions of the first-party user data to the cloud-based network;

receiving, by the on-premises network from the cloud-based network, third-party user data corresponding to the selected portions of the first-party user data;

enriching, by the on-premises network, the first-party user data with the received third-party user data; and

processing, by the on-premises network, the enriched first-party user data within the on-premises network.

2. The computer-implemented method of claim 1 , wherein the first-party user data is stored at the first-party profile database within the on-premises network in association with first-party user identifiers (IDs) corresponding to the one or more users.

3. The computer-implemented method of claim 1 , wherein the first-party user data cannot be transmitted outside the on-premises network without consent of a user associated with the first-party user data.

4. The computer-implemented method of claim 1 , wherein the third-party user data is collected by the cloud-based network includes aggregated and de-identified online behavior data of the one or more users.

5. The computer-implemented method of claim 1 , further comprising linking the first-party user data to the third-party user data.

6. The computer-implemented method of claim 5 , wherein the linking of the first-party user data to the third-party user data comprises:

determining a first-party user identifier (ID) associated with the first-party user data; and

determining using the first-party user identifier (ID) associated with the first-party user data, one or more third-party user identifiers (IDs) associated the third-party user data.

7. The computer-implemented method of claim 6 , wherein the linking is performed by using one of identity linkage techniques, probabilistic linkage techniques or deterministic linkage techniques.

8. The computer-implemented method of claim 1 , further comprising:

generating, based on the executable code, an interface with the cloud-based network, wherein the interface enables the one or more users within the on-premises network to:

generate access keys that provide the one or more users, access to the first-party user data stored within the on-premises network.

9. The computer-implemented method of claim 8 , wherein the access keys are not shared with users outside the on-premises network.

10. A system, comprising:

an on-premises network;

a cloud-based network; and

a non-transitory computer-readable storage medium containing instructions which, when executed on one or more processors, cause the one or more processors to perform operations including:

receiving, by the on-premises network from the cloud-based network, an executable code corresponding to one or more cloud-based services;

configuring, by the on-premises network, a private pixel server and a first-party profile database within the on-premises network, based on the executable code, to track interactions between a web server associated with the on-premises network and one or more users within the on-premises network, wherein tracking the interactions enables the first-party profile database to:

collect first-party user data corresponding to each user of the one or more users within the on-premises network; and

generate a virtual private cloud that is accessible by the one or more users with the on-premises network;

storing, by the on-premises network, the first-party user data in the virtual private cloud;

accessing, by the on-premises network, the virtual private cloud to select portions from the first-party user data for which the one or more users have provided consent, wherein the consent enables the selected portions to be uploaded to the cloud-based network;

transmitting, by the on-premises network, the selected portions of the first-party user data to the cloud-based network;

receiving, by the on-premises network from the cloud-based network, third-party user data corresponding to the selected portions of the first-party user data;

enriching, by the on-premises network, the first-party user data with the received third-party user data; and

processing, by the on-premises network, the enriched first-party user data within the on-premises network.

11. The system of claim 10 , wherein the first-party user data is stored at the first-party profile database within the on-premises network in association with first-party user identifiers IDs corresponding to the one or more users.

12. The system of claim 10 , wherein the first-party user data cannot be transmitted outside the on-premises network without consent of a user associated with the first-party user data.

13. The system of claim 10 , wherein the third-party user data is collected by the cloud-based network includes aggregated and de-identified online behavior data of the one or more users.

14. The system of claim 10 , wherein the operations further comprise linking the first-party user data to the third-party user data.

15. The system of claim 14 , wherein the linking of the first-party user data to the third-party user data comprises:

determining a first-party user identifier (ID) associated with the first-party user data; and

determining using the first-party user identifier (ID) associated with the first-party user data, one or more third-party user identifiers (IDs) associated the third-party user data.

16. The system of claim 14 , wherein the linking is performed by using identity one of linkage techniques, probabilistic linkage techniques or deterministic linkage techniques.

17. The system of claim 10 , wherein the operations further comprises:

generating, based on the executable code, an interface with the cloud-based network, wherein the interface enables the one or more users within the on-premises network to:

generate access keys that provide the one or more users, access to the first-party user data stored within the on-premises network.

18. The system of claim 17 , wherein the access keys are not shared with users outside the on-premises network.

19. One or more non-transitory computer-readable media having computer-executable instructions stored thereon that, when executed by a processing system, cause the processing system to perform operations comprising:

receiving, by an on-premises network, an executable code corresponding to one or more cloud based services;

configuring, by the on-premises network, a private pixel server and a first-party profile database within the on-premises network, based on the executable code, to track interactions between a web server associated with the on-premises network and one or more users within the on-premises network, wherein tracking the interactions enables the first-party profile database to:

collect first-party user data corresponding to each user of the one or more users within the on-premises network; and

generate a virtual private cloud that is accessible by the one or more users with the on-premises network;

storing, by the on-premises network, the first-party user data in the virtual private cloud;

accessing, by the on-premises network, the virtual private cloud to select portions from the first-party user data for which the one or more users have provided consent, wherein the consent enables the selected portions to be uploaded to a cloud-based network;

transmitting, by the on-premises network, the selected portions of the first-party user data to the cloud-based network;

receiving, by the on-premises network from the cloud-based network, third-party user data corresponding to the selected portions of the first-party user data;

enriching, by the on-premises network, the first-party user data with the received third-party user data; and

processing, by the on-premises network, the enriched first-party user data within the on-premises network.

20. The computer-readable media of claim 19 , wherein the first-party user data is stored at the first-party profile database within the on-premises network in association with first-party user IDs corresponding to the one or more users.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2023
From: DEO, NIRAJ; PANDEY, SAURABH; BRUGMAN, JOHANNA CHRISTINA
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 065882/0783 →
Continuity (4)
Continuation 17549734 · Dec 13, 2021
Continuation 17065238 · Oct 7, 2020
Provisional Application 62912013 · Oct 7, 2019
Related Publication 20240129377A1 · Apr 18, 2024
References Cited (36)
US 8805946B1 · Glommen · 2014 [cited by applicant]
US 10546315B2 · Mitchell · 2020 [cited by applicant]
US 10567479B2 · Tal et al. · 2020 [cited by applicant]
US 10965547B1 · Esposito et al. · 2021 [cited by applicant]
US 11201932B2 · Deo et al. · 2021 [cited by applicant]
US 20130073400A1 · Heath · 2013 [cited by applicant]
US 20130159274A1 · Silberstein et al. · 2013 [cited by applicant]
US 20130268357A1 · Heath · 2013 [cited by examiner]
US 20140006125A1 · Meegan · 2014 [cited by applicant]
US 20140096215A1 · Hessler · 2014 [cited by applicant]
US 20140137273A1 · Workman · 2014 [cited by examiner]
US 20150082396A1 · Theebaprakasam et al. · 2015 [cited by applicant]
US 20150294633A1 · Jung et al. · 2015 [cited by applicant]
US 20160210578A1 · Raleigh et al. · 2016 [cited by applicant]
US 20170041381A1 · Tal et al. · 2017 [cited by applicant]
US 20170063989A1 · Langouev · 2017 [cited by examiner]
US 20170185723A1 · McCallum et al. · 2017 [cited by applicant]
US 20170223093A1 · Peterson · 2017 [cited by examiner]
US 20170230293A1 · Meredith et al. · 2017 [cited by applicant]
US 20170318096A1 · Wade et al. · 2017 [cited by applicant]
US 20170330278A1 · Radulescu · 2017 [cited by applicant]
US 20170353564A1 · Zhou et al. · 2017 [cited by applicant]
US 20180144153A1 · Pead · 2018 [cited by applicant]
US 20190116172A1 · Caldwell · 2019 [cited by applicant]
US 20190158646A1 · Nelson et al. · 2019 [cited by applicant]
US 20200117690A1 · Tran et al. · 2020 [cited by applicant]
US 20200125582A1 · O'Shaughnessy · 2020 [cited by applicant]
US 20200193483A1 · Lee et al. · 2020 [cited by applicant]
US 20200394154A1 · Blackshear et al. · 2020 [cited by applicant]
US 20200394159A1 · Hurley et al. · 2020 [cited by applicant]
Zheng et al., “Blockchain-based Personal Health Data Sharing System Using Cloud Storage”, Sep. 1, 2018, IEEE, 2018 IEEE 20th International Conference on e-Health Networking, Applications and Services (Healthcom) (2018, … [cited by examiner]
Non-Final Office Action for U.S. Appl. No. 17/065,228, dated Mar. 15, 2022. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/065,238, dated Aug. 11, 2021. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/549,734, dated Sep. 7, 2023. [cited by applicant]
Office Action for U.S. Appl. No. 17/549,734, dated Jun. 23, 2023. [cited by applicant]
Skachek, V. et al., “Subspace Synchronization: A Network-Coding Approach to Object Reconciliation”, 2014 IEEE International Symposium on Information Theory, pp. 2301-2305, 2014. [cited by applicant]