IP Library › Granted Patent US 12,273,336
Granted Patent B2
US 12,273,336 · App. 17/795,918 · Granted Apr 8, 2025

Privacy-preserving virtual email system

Inventors: Karin Hennessy (Brooklyn, NY); Jeremy Joshua Phillips (New York, NY)
Assignee: Google LLC
H04L63/083H04L63/0421
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,336
App. No.
17/795,918
Granted
Apr 8, 2025
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for creating and using virtual email addresses for user privacy protection and data security are described. In one aspect, a method includes receiving, from a user device and at an identity server, login credentials for a first email address mapped to a first set of user information values, detecting, by the identity server, a trigger event, in response to detecting the trigger event, creating, by the identity server, a new virtual email address separate from the first email address and mapped to a second set of user information values different from the first set of user information values, detecting, by the identity server, a request for credentials from a requesting entity, and in response to detecting the request, transmitting, by the identity server, the new virtual email address as new login credentials to the requesting entity.

Claims (50)

1. A method, comprising:

receiving, from a user device and at an identity server, login credentials for a first email address mapped to a first set of user information values;

detecting, by the identity server, a trigger event;

in response to detecting the trigger event, creating, by the identity server, a new virtual email address separate from the first email address and mapped to a second set of user information values different from the first set of user information values, wherein the new virtual email address has a specified triggering event that initiates deletion of the new virtual email address;

detecting, by the identity server, a request for credentials from a requesting entity; and

in response to detecting the request, transmitting, by the identity server and to the requesting entity, (i) the new virtual email address as new login credentials for the requesting entity and (ii) the second set of user information values based on the new virtual email address being used as the new login credentials for the requesting entity.

2. The method of claim 1 , wherein the trigger event is one of: a user input and a predetermined condition defined by the identity server.

3. The method of claim 1 , wherein the login credentials are provided in the form of: text input, audio input, or visual input.

4. The method of claim 1 , wherein transmitting the new virtual email address as login credentials to the requesting entity comprises:

transmitting, through a tokenization application programming interface, data representing the new virtual email address through a tokenization application programming interface (API),

wherein the data representing the new virtual email address is a token that cannot be traced to the first email address.

5. The method of claim 1 , further comprising:

updating, by the identity server and based on the new virtual email address, a database by creating a database entry mapping the new virtual email address to the second set of user information values.

6. The method of claim 5 , further comprising:

receiving, from the user device, input that indicates a change to the new virtual email address; and

updating, by the identity server and based on the input that indicates a change to the new virtual email address, the database entry.

7. The method of claim 1 , wherein the request for credentials comprises data indicating that the user device has accessed a webpage having one or more text fields for entering credentials.

8. The method of claim 1 , wherein the specified triggering event comprises a specified time period following creation of the new virtual email address.

9. The method of claim 1 , wherein the trigger event comprises user navigation to a particular website during a browsing session and the specified triggering event comprises an end of the browsing session.

10. The method of claim 1 , wherein creating the new virtual email address comprises: obtaining one or more parameters from the user device; and generating the new virtual email address using the one or more parameters.

11. The method of claim 1 , further comprising determining the trigger event for a user of the user device based on online activity of the user.

12. The method of claim 1 , further comprising:

in response to detecting the request for credentials from the requesting entity, initiating display, at the user device, of a user interface that shows a set of virtual email addresses for a user of the user device; and

receiving data indicating selection of the new virtual email address by the user at the user device,

wherein the new virtual email address is transmitted to the requesting entity based on the selection of the new virtual email address by the user of the user device.

13. A system comprising:

one or more processors; and

one or more memory elements including instructions that, when executed, cause the one or more processors to perform operations including:

receiving, from a user device and at an identity server, login credentials for a first email address mapped to a first set of user information values;

detecting, by the identity server, a trigger event;

in response to detecting the trigger event, creating, by the identity server, a new virtual email address separate from the first email address and mapped to a second set of user information values different from the first set of user information values, wherein the new virtual email address has a specified triggering event that initiates deletion of the new virtual email address;

detecting, by the identity server, a request for credentials from a requesting entity; and

in response to detecting the request, transmitting, by the identity server and to the requesting entity, (i) the new virtual email address as new login credentials for the requesting entity and (ii) the second set of user information values based on the new virtual email address being used as the new login credentials for the requesting entity.

14. The system of claim 13 , wherein the trigger event is one of: a user input and a predetermined condition defined by the identity server.

15. The system of claim 13 , wherein the login credentials are provided in the form of: text input, audio input, or visual input.

16. The system of claim 13 , wherein transmitting the new virtual email address as login credentials to the requesting entity comprises:

transmitting, through a tokenization application programming interface, data representing the new virtual email address through a tokenization application programming interface (API),

wherein the data representing the new virtual email address is a token that cannot be traced to the first email address.

17. The system of claim 13 , the operations further comprising:

updating, by the identity server and based on the new virtual email address, a database by creating a database entry mapping the new virtual email address to the second set of user information values.

18. The system of claim 17 , the operations further comprising:

receiving, from the user device, input that indicates a change to the new virtual email address; and

updating, by the identity server and based on the input that indicates a change to the new virtual email address, the database entry.

19. The system of claim 13 , wherein the request for credentials comprises data indicating that the user device has accessed a webpage having one or more text fields for entering credentials.

20. A non-transitory computer storage medium encoded with instructions that when executed by a distributed computing system cause the distributed computing system to perform operations comprising:

receiving, from a user device and at an identity server, login credentials for a first email address mapped to a first set of user information values;

detecting, by the identity server, a trigger event;

in response to detecting the trigger event, creating, by the identity server, a new virtual email address separate from the first email address and mapped to a second set of user information values different from the first set of user information values, wherein the new virtual email address has a specified triggering event that initiates deletion of the new virtual email address;

detecting, by the identity server, a request for credentials from a requesting entity; and

in response to detecting the request, transmitting, by the identity server and to the requesting entity, (i) the new virtual email address as new login credentials for the requesting entity and (ii) the second set of user information values based on the new virtual email address being used as the new login credentials for the requesting entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2022
From: HENNESSY, KARIN; PHILLIPS, JEREMY JOSHUA
To: GOOGLE LLC
Reel/Frame 060686/0718 →
Continuity (2)
Provisional Application 63121087 · Dec 3, 2020
Related Publication 20230074364A1 · Mar 9, 2023
References Cited (21)
US 9582802B2 · Bachenheimer · 2017 [cited by examiner]
US 10511493B1 · McCown · 2019 [cited by examiner]
US 10698701B1 · Jong et al. · 2020 [cited by applicant]
US 20020138581A1 · MacIntosh et al. · 2002 [cited by applicant]
US 20100198928A1 · Almeida · 2010 [cited by examiner]
US 20120317222A1 · Almeida · 2012 [cited by examiner]
US 20200067869A1 · Jouan · 2020 [cited by applicant]
US 20200120047A1 · Adams · 2020 [cited by examiner]
US 20210097534A1 · Kurian · 2021 [cited by examiner]
KR 1020120004891 · 2012 [cited by applicant]
KR 1020190001875 · 2019 [cited by applicant]
WO WO2016007763 · 2016 [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2021/061,525, mailed on Jun. 15, 2023, 7 pages. [cited by applicant]
Gabber et al., “How to make personalized web browsing simple, secure, and anonymous.” International Conference on Financial Cryptography. Springer, Berlin, Heidelberg, Feb. 1997, 17-31. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2021/061,525, dated Feb. 24, 2022, 12 pages. [cited by applicant]
Office Action in Japanese Appln. No. 2022-543559, mailed on Sep. 11, 2023, 6 pages (with English translation). [cited by applicant]
Notice of Allowance in European Appln. No. 21836674.8, dated Mar. 1, 2023, 8 pages. [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2022-543559, mailed on Nov. 20, 2023, 5 pages (with English translation). [cited by applicant]
Office Action in Korean Appln. No. 10-2022-7023818, mailed on Feb. 15, 2024, 13 pages (with English translation). [cited by applicant]
Notice of Allowance in Korean Appln. No. 10-2022-7023818, mailed on Oct. 17, 2024, 4 pages (with English translation). [cited by applicant]
Office Action in Indian Appln. No. 202227035330, mailed on Feb. 7, 2025, 6 pages (with English translation). [cited by applicant]