IP Library › Granted Patent US 12,572,693
Granted Patent B2
US 12,572,693 · App. 18/742,646 · Granted Mar 10, 2026

Cryptographically secure data protection

Inventors: Shreedhar Madhavapeddi (Seattle, WA); Sergei Akulich (Seattle, WA); Stephen W. Rupp (Brooklyn, NY); Gang Wang (Frederick, MD)
Assignee: Google LLC
G06F21/6245G06F21/604H04L63/0428H04L67/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,572,693
App. No.
18/742,646
Granted
Mar 10, 2026
Kind
B2
Abstract

This disclosure relates to data security and cryptography. In one aspect, a method includes receiving a request for a subscription token for a given user by a data security system from a publisher computing system of a publisher. The request includes user identification information provided to the publisher by the given user when subscribing to electronic content of the publisher. The data security system generates the subscription token which includes a set of data that includes a first encrypted user identifier generated by encrypting a first user identifier for the given user using an encryption key of the data security system, and, for each of one or more content platforms, an attachment element that includes a second encrypted user identifier generated by encrypting a second user identifier for the given user using an encryption key of the content platform and transmitting the subscription token to the publisher computing system.

Claims (37)

1 . A computer-implemented method comprising:

receiving, from a client device, a request for content and subscription data comprising at least an e-mail address for a user of the client device, a phone number for the user, or both;

sending, to a data security system, a request for a subscription token for the user and a given publisher in response to receiving the subscription data, wherein the subscription token comprises (i) a set of data comprising a first encrypted user identifier that encrypts a first user identifier for the user with an encryption key of the data security system, wherein the first user identifier is used by the data security system to identify the user, and (ii) for each of one or more content platforms, a respective second encrypted user identifier that encrypts a second user identifier for the user with a respective encryption key of the respective content platform, wherein the second user identifier is used by the respective content platform to identify the user;

receiving, from the data security system, the subscription token for the user and the given publisher; and

causing the subscription token to be transmitted to the one or more content platforms that provide, to the client device, one or more digital components for presentation at the client device with content of the given publisher based on the subscription token.

2 . The computer-implemented method of claim 1 , wherein the data security system comprises a computing system of an e-mail provider and the subscription data comprises the e-mail address for the user and for an e-mail account of the user with the e-mail provider.

3 . The computer-implemented method of claim 2 , wherein the first user identifier for the user comprises one of (i) the e-mail address for the user for the e-mail account of the user with the e-mail provider or (ii) another user identifier corresponding to the e-mail address of the user.

4 . The computer-implemented method of claim 1 , wherein the subscription token further comprises: for each of the one or more content platform, a digital signature of the set of data and the second encrypted user identifier generated using a private key of the data security system.

5 . The computer-implemented method of claim 2 , wherein the subscription token comprises a digital signature of the set of data and each attachment element.

6 . The computer-implemented method of claim 1 , wherein the subscription token comprises an expiration time and consent data indicating how user data of the user data can be used by a recipient the given publisher.

7 . The computer-implemented method of claim 1 , further comprising:

sending, to the data security system, recurring renewal requests that are each for a renewed subscription token for the user, each renewal request comprising a respective first encrypted user identifier of a previous request; and

receiving, for each renewal request, the renewed subscription token to the given publisher computing system.

8 . The computer-implemented method of claim 7 , wherein the data security system is configured to, for renewal request, perform operations comprising:

generating an updated first encrypted user identifier different from the first encrypted user identifier of the previous request;

generating the renewed subscription token comprising an updated set of data comprising the updated first encrypted user identifier and each attachment element; and

transmitting the renewed subscription token to the given publisher computing system.

9 . The computer-implemented method of claim 7 , wherein each renewed subscription token further comprises updated data privacy settings that have been updated by the user since the subscription token was generated.

10 . The computer-implemented method of claim 1 , wherein causing the subscription token to be transmitted to the one or more content platforms comprises sending the subscription token to the client device for inclusion in a digital component request sent to each of the one or more content platforms.

11 . The computer-implemented method of claim 10 , wherein the client device is configured to generate the request in response to processing a script of a digital component slot of a resource being presented by the client device, and wherein the script is configured to obtain the subscription token from a device of the given publisher.

12 . The computer-implemented method of claim 1 , wherein the data security system is configured to generate the subscription token for the user and the given publisher by identifying, as the one or more content platforms, each content platform designated as being an eligible content platform by the given publisher and the user, each eligible content platform being a content platform that is eligible to select digital components for presentation to the user with electronic resources of the given publisher.

13 . The computer-implemented method of claim 1 , wherein the data security system is configured to generate the subscription token for the user and the given publisher by identifying, as the one or more content platforms, each content platform designated as being an eligible content platform by the given publisher and the user, each eligible content platform being a content platform that is eligible to collect, store, and use data of the user.

14 . The computer-implemented method of claim 1 , further comprising querying a central authority for data indicating whether an e-mail provider of the e-mail address for the user is a participant in a subscription token service.

15 . A non-transitory computer-storage medium storing instructions that when executed by one or more processors cause the one or more processors to perform operations comprising:

receiving, from a client device, a request for content and subscription data comprising at least an e-mail address for a user of the client device, a phone number for the user, or both;

sending, to a data security system, a request for a subscription token for the user and a given publisher in response to receiving the subscription data, wherein the subscription token comprises (i) a set of data comprising a first encrypted user identifier that encrypts a first user identifier for the user with an encryption key of the data security system, wherein the first user identifier is used by the data security system to identify the user, and (ii) for each of one or more content platforms, a respective second encrypted user identifier that encrypts a second user identifier for the user with a respective encryption key of the respective content platform, wherein the second user identifier is used by the respective content platform to identify the user;

receiving, from the data security system, the subscription token for the user and the given publisher; and

causing the subscription token to be transmitted to the one or more content platforms that provide, to the client device, one or more digital components for presentation at the client device with content of the given publisher based on the subscription token.

16 . A system comprising:

one or more processors; and

one or more storage devices including instructions that, when executed, cause the one or more processors to perform operations comprising:

receiving, from a client device, a request for content and subscription data comprising at least an e-mail address for a user of the client device, a phone number for the user, or both;

sending, to a data security system, a request for a subscription token for the user and a given publisher in response to receiving the subscription data, wherein the subscription token comprises (i) a set of data comprising a first encrypted user identifier that encrypts a first user identifier for the user with an encryption key of the data security system, wherein the first user identifier is used by the data security system to identify the user, and (ii) for each of one or more content platforms, a respective second encrypted user identifier that encrypts a second user identifier for the user with a respective encryption key of the respective content platform, wherein the second user identifier is used by the respective content platform to identify the user;

receiving, from the data security system, the subscription token for the user and the given publisher; and

causing the subscription token to be transmitted to the one or more content platforms that provide, to the client device, one or more digital components for presentation at the client device with content of the given publisher based on the subscription token.

17 . The system of claim 16 , wherein the data security system comprises a computing system of an e-mail provider and the subscription data comprises the e-mail address for the user and for an e-mail account of the user with the e-mail provider.

18 . The system of claim 17 , wherein the first user identifier for the user comprises one of (i) the e-mail address for the user for the e-mail account of the user with the e-mail provider or (ii) another user identifier corresponding to the e-mail address of the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2024
From: MADHAVAPEDDI, SHREEDHAR; AKULICH, SERGEI; RUPP, STEPHEN W.; WANG, GANG
To: GOOGLE LLC
Reel/Frame 067721/0656 →
Continuity (2)
Continuation 17617358
Related Publication 20240370585A1 · Nov 7, 2024
References Cited (86)
US 7444519B2 · Laferriere et al. · 2008 [cited by applicant]
US 7478434B1 · Hinton et al. · 2009 [cited by applicant]
US 8555075B2 · Kessler · 2013 [cited by examiner]
US 8977853B2 · Bassu · 2015 [cited by examiner]
US 10311240B1 · Nissler et al. · 2019 [cited by applicant]
US 10757250B1 · Quilici et al. · 2020 [cited by applicant]
US 11081214B1 · Whitaker et al. · 2021 [cited by applicant]
US 11233772B1 · Dinan et al. · 2022 [cited by applicant]
US 11652813B2 · Patel et al. · 2023 [cited by applicant]
US 11902289B2 · Dunjic et al. · 2024 [cited by applicant]
US 12423475B2 · Wang · 2025 [cited by examiner]
US 20050097348A1 · Jakubowski et al. · 2005 [cited by applicant]
US 20050223412A1 · Nadalin et al. · 2005 [cited by applicant]
US 20060002556A1 · Paul · 2006 [cited by applicant]
US 20070043945A1 · Choi et al. · 2007 [cited by applicant]
US 20070073817A1 · Gorty · 2007 [cited by applicant]
US 20070186277A1 · Loesch et al. · 2007 [cited by applicant]
US 20080083024A1 · Glazer et al. · 2008 [cited by applicant]
US 20080240447A1 · Zhu et al. · 2008 [cited by applicant]
US 20110055909A1 · Dowlatkhah · 2011 [cited by applicant]
US 20110145907A1 · Chua · 2011 [cited by applicant]
US 20110161474A1 · Gannon et al. · 2011 [cited by applicant]
US 20120036360A1 · Bassu et al. · 2012 [cited by applicant]
US 20120102329A1 · Mittal et al. · 2012 [cited by applicant]
US 20120109882A1 · Bouse et al. · 2012 [cited by applicant]
US 20120151077A1 · Finster · 2012 [cited by applicant]
US 20130036304A1 · Lin et al. · 2013 [cited by applicant]
US 20140067940A1 · Li et al. · 2014 [cited by applicant]
US 20140086397A1 · Febonio et al. · 2014 [cited by applicant]
US 20140120905A1 · Kim · 2014 [cited by applicant]
US 20140282962A1 · Harrison · 2014 [cited by applicant]
US 20150074259A1 · Ansari et al. · 2015 [cited by applicant]
US 20150106881A1 · Wharton et al. · 2015 [cited by applicant]
US 20150112864A1 · Wallaja et al. · 2015 [cited by applicant]
US 20150304110A1 · Oberheide et al. · 2015 [cited by applicant]
US 20160164680A1 · Liao et al. · 2016 [cited by applicant]
US 20160277261A9 · Ansari et al. · 2016 [cited by applicant]
US 20170063840A1 · Krishnaiah · 2017 [cited by applicant]
US 20170076277A1 · Zhou et al. · 2017 [cited by applicant]
US 20170132431A1 · Blanco et al. · 2017 [cited by applicant]
US 20180060989A1 · Hietanen et al. · 2018 [cited by applicant]
US 20190199530A1 · Reitsma et al. · 2019 [cited by applicant]
US 20190207953A1 · Klawe et al. · 2019 [cited by applicant]
US 20200067903A1 · Yegorin · 2020 [cited by applicant]
US 20200160388A1 · Sabeg et al. · 2020 [cited by applicant]
US 20210099444A1 · Nagaraja et al. · 2021 [cited by applicant]
US 20210344484A1 · Pasquali et al. · 2021 [cited by applicant]
US 20210350021A1 · Wang et al. · 2021 [cited by applicant]
US 20210377263A1 · Law · 2021 [cited by applicant]
US 20220385738A1 · Circosta et al. · 2022 [cited by applicant]
US 20230050222A1 · Wang et al. · 2023 [cited by applicant]
US 20230161902A1 · Dong et al. · 2023 [cited by applicant]
CN 1505309 · 2004 [cited by applicant]
CN 105897424 · 2016 [cited by applicant]
CN 105933353 · 2016 [cited by applicant]
CN 108463982 · 2018 [cited by applicant]
CN 110958119 · 2020 [cited by applicant]
JP 2006048653 · 2006 [cited by applicant]
JP 2008525863 · 2008 [cited by applicant]
JP 2012137995 · 2012 [cited by applicant]
JP 2020068388 · 2020 [cited by applicant]
KR 1020170022842 · 2017 [cited by applicant]
KR 1020180022921 · 2018 [cited by applicant]
KR 1020180083843 · 2018 [cited by applicant]
KR 1020190064792 · 2019 [cited by applicant]
KR 1020200023485 · 2020 [cited by applicant]
WO WO2006041462 · 2006 [cited by applicant]
T. Y. Cheng, W. Gao, X. Jia, J. He and S. Liu, “Privacy-preserving publish/subscribe service in untrusted third-party platform,” 2016 IEEE International Conference on Communications (ICC), Kuala Lumpur, Malaysia, 2016, … [cited by examiner]
Onica, Emanuel, et al. “Confidentiality-preserving publish/subscribe: A survey.” ACM computing surveys (CSUR) 49.2 (2016): 1-43. (Year: 2016). [cited by examiner]
Nabeel, Mohamed, Ning Shang, and Elisa Bertino. “Efficient privacy preserving content based publish subscribe systems.” Proceedings of the 17th ACM symposium on Access Control Models and Technologies. 2012, pp. 133-144.… [cited by examiner]
M. M. Abur, S. B. Junaidu, A. A. Obiniyi and S. E. Abdullahi, “Privacy Token Technique for Protecting User's Attributes in a Federated Identity Management System for the Cloud Environment,” 2019 2nd International Confer… [cited by examiner]
Emanuel et al., “Efficient key updates through subscription re-encryption for privacy-preserving publish/subscribe” Proceedings of the 16th Annual Middleware Conference, 2015, 12 pages. [cited by applicant]
Esposito et al., “On Security in Publish/Subscribe Services: A Survey” in IEEE Communications Surveys & Tutorials, vol. 17, No. 2, 2015, 33 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2020/057546, mailed on May 11, 2023, 9 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2020/057554, mailed on May 11, 2023, 8 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln No. PCT/US2020/057546, mailed on Jun. 23, 2021, 14 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2020/057554, mailed on Jun. 23, 2021, 13 pages. [cited by applicant]
Marco Scaceres, “Trust-Token-API” submitted on Oct. 3, 2019, <https://github.com/WICG/trust-token-api>, 13 pages. [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2022-548001, mailed on Oct. 2, 2023, 5 pages (with English translation). [cited by applicant]
Office Action in Chinese Appln. No. 202080046324.2, mailed on Dec. 26, 2023, 12 pages (with English translation). [cited by applicant]
Office Action in Indian Appln. No. 202127056847, mailed on Oct. 6, 2023, 7 pages (with English translation). [cited by applicant]
Office Action in Korean Appln. No. 10-2022-7026990, mailed on Sep. 9, 2024, 14 pages (with English translation). [cited by applicant]
Wikipedia.org [online], “HTTP cookie” Jul. 24, 2020, retrieved on Jul. 29, 2020, retrieved from URL <https://en.wikipedia.org/wiki/HTTP_cookie#Http-only_cookie>, 26 pages. [cited by applicant]
Notice of Allowance in Korean Appln. No. 10-2022-7026990, mailed on May 8, 2025, 5 pages (with English translation). [cited by applicant]
Office Action in Chinese Appln. No. 202080095596.1, mailed on Jun. 27, 2025, 15 pages (with English translation). [cited by applicant]
Office Action in Chinese Appln. No. 202080095596.1, mailed on Dec. 17, 2024, 20 pages (with English translation). [cited by applicant]