IP Library Granted Patent US 12,316,621
Granted Patent B1
US 12,316,621 · App. 17/571,891 · Granted May 27, 2025

Authenticating anonymous information

Inventors: Payman Mohassel (San Jose, CA); Shuangying Huang (Sunnyvale, CA); Subodh Iyengar (Palo Alto, CA); Sundararaman Jeyaraman (Hayward, CA); Chen-Kuei Lee (Sunnyvale, CA); Zutian Luo (Pasadena, CA); Ananth Raghunathan (Mountain View, CA); Shaahid Shaik (Fremont, CA); Yen-Chieh Sung (Cupertino, CA); Liuqing Albert Zhang (Redwood City, CA); Xian Xu (Menlo Park, CA)
Assignee: WhatsApp, LLC
H04L63/08H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,621
App. No.
17/571,891
Granted
May 27, 2025
Kind
B1
Abstract

A system and method comprising collecting analytics data or other types of analytics-related information from client devices in an anonymous and authenticated manner. A client device may use or provide a token or token-relation information, which may have been obtained from system servers beforehand, with a request to log the analytics data to the system servers in order to authenticate the analytics data being logged. The system servers may then authenticate the token or the token-related information, and in response to successful authentication, process the analytics data. Advantageously, the use of the token or token-related information allows the analytics data to be logged by client devices anonymously to preserve privacy, but also in a highly secure manner.

Claims (54)

1. A computer-implemented method comprising:

receiving a payload requesting to log analytics data, the payload including a token;

authenticating the token, wherein the token is configured for multiple uses during a time period;

generating at least one pseudo-anonymous identifier associated with a user;

receiving a token request from a client device associated with the user;

verifying an identity of the user associated with the client device based on the at least one pseudo-anonymous identifier;

periodically rotating the at least one pseudo-anonymous identifier associated with the user; and

processing the request to log the analytics data in response to successful authentication of the token.

2. The method of claim 1 , wherein the authenticating of the token further comprises:

determining whether the token is valid; and

determining whether the token was previously issued.

3. The method of claim 1 , wherein the token comprises: a message authentication code (MAC) that includes a secret cryptographic hash algorithm or function.

4. The method of claim 3 , wherein authenticating the token further includes:

determining a result of the secret cryptographic hash algorithm or function using information contained in the payload; and

determining whether the result and the token match.

5. The method of claim 3 , further comprising:

sending the token to the client device associated with the user based on successful verification of the user.

6. At least one non-transitory computer-readable storage medium comprising instructions that, when executed, cause at least one processor to:

receive a payload requesting to log analytics data, the payload including a first token;

authenticate the first token, wherein the first token is configured for multiple uses during a time period;

generate at least one pseudo-anonymous identifier associated with a user;

receive a token request from a client device associated with the user;

verify an identity of the user associated with the client device based on the at least one pseudo-anonymous identifier;

periodically rotate the at least one pseudo-anonymous identifier associated with the user;

and

process the request to log the analytics data in response to successful authentication of the first token.

7. The medium of claim 6 , wherein the authentication of the first token further comprises the instructions further causing the at least one processor to:

determine whether the first token is valid; and

determine whether the first token was previously issued.

8. The medium of claim 6 , wherein the token comprises: a message authentication code (MAC) that includes a secret cryptographic hash algorithm or function.

9. The medium of claim 8 , further comprising authentication of the first token which includes the instructions causing the at least one processor to:

determine a result of the secret cryptographic hash algorithm or function using information contained in the payload; and

determine whether the result and the first token match.

10. The medium of claim 6 , the instructions further causing the at least one processor to:

send a second token to the client device based on successful verification of the user.

11. An apparatus comprising:

memory; and

at least one processor operable to execute stored instructions that, when executed, causes the at least one processor to:

receive a payload requesting to log analytics data, payload including a first token;

authenticate the first token, wherein the first token is configured for multiple uses during a time period;

generate at least one pseudo-anonymous identifier associated with a user;

receive a token request from a client device associated with the user;

verify an identity of the user associated with the client device based on the at least one pseudo-anonymous identifier;

periodically rotate the at least one pseudo-anonymous identifier associated with the user; and

process the request to log the analytics data in response to successful authentication of the first token.

12. The apparatus of claim 11 , wherein the authentication of the first token further causes the at least one processor to:

determine whether the first token is valid; and

determine whether the first token was previously issued.

13. The apparatus of claim 11 , wherein the first token comprises a message authentication code (MAC) that includes a secret cryptographic hash algorithm or function.

14. The apparatus of claim 13 , further comprising authentication of the first token which includes the instructions causing the at least one processor to:

determine a result of the secret cryptographic hash algorithm or function using information contained in the payload; and

determine whether the result and the first token-related information match.

15. The apparatus of claim 11 , the at least one processor further caused to:

send a second token to the client device based on successful verification of the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2022
From: MOHASSEL, PAYMAN; HUANG, SHUANGYING; IYENGAR, SUBODH; JEYARAMAN, SUNDARARAMAN; LEE, CHEN-KUEI; LUO, ZUTIAN; RAGHUNATHAN, ANANTH; SHAIK, SHAAHID; SUNG, YEN-CHIEH; ZHANG, LIUQING ALBERT; XU, XIAN
To: WHATSAPP LLC
Reel/Frame 061412/0208 →
Continuity (1)
Provisional Application 63136783 · Jan 13, 2021
References Cited (15)
US 10643001B2 · Guglani et al. · 2020 [cited by applicant]
US 20050125378A1 · Kawada · 2005 [cited by applicant]
US 20100058454A1 · Neystadt · 2010 [cited by examiner]
US 20140082366A1 · Engler · 2014 [cited by examiner]
US 20150244681A1 · Blumenfeld · 2015 [cited by examiner]
US 20180212956A1 · Sanganabhatla · 2018 [cited by examiner]
US 20200117831A1 · Eckhard et al. · 2020 [cited by applicant]
WO 2010025075A2 · 2010 [cited by applicant]
WO 2014081494A1 · 2014 [cited by applicant]
WO WO2015013548A1 · 2015 [cited by examiner]
Wikipedia entry for HMAC—Archived on Dec. 11, 2020, retrieved on Dec. 11, 2023 from https://web.archive.org/web/20201211212934/https://en.wikipedia.org/wiki/HMAC. [cited by examiner]
Davidson A., et al., “Privacy Pass: Bypassing Internet Challenges Anonymously,” Proceedings on Privacy Enhancing Technologies, Jun. 1, 2018, vol. 2018, No. 3, pp. 164-180, Retrieved from the Internet: https://www.betsym… [cited by applicant]
European Search Report for European Patent Application No. 22151251.0, mailed May 11, 2022, 7 pages. [cited by applicant]
Rahman S.U., et al., “Secure Crash Reporting in Vehicular Ad hoc Networks,” Security and Privacy in Communications Networks and the Workshops, Sep. 17, 2007, pp. 443-452. [cited by applicant]
EPO—Office Action mailed Nov. 26, 2024 for European Patent Application No. 22151251.0, filed on Jan. 13, 2022, 5 pages. [cited by applicant]
Cited By (2)
US 12,574,232 US 12,592,825