Privacy management across multiple devices
Abstract
Problem to be solved.To provide a method, a system, and an apparatus including a computer program encoded on a computer-readable storage medium and a method of managing a user's privacy right related to distribution of contents. The method comprises providing a global privacy management interface that presents selection tools that allow users to consider privacy options and interests. Privacy options and interests include controls that present a list of users and interests associated with those identifiers. Each identifier is associated with the request source used by the user to access the content. The interface allows deselection of individual interests, either on an identifier basis or on a global basis. The method further comprises a step in the server system to determine the content to be delivered to the user in consideration of privacy choices. [Selection diagram] Fig. 2J

Term
11 yearsto projected expiry
Projected expiry 20 September 2037, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
27 claims: 3 independent, 24 dependent
- 1コンテンツの配信に関連するユーザのプライバシー権を管理するためのコンピュータ実装方法であって、前記方法は、 グローバルなプライバシー管理インターフェースを提供するステップを備え、 前記プライバシー管理インターフェースは、 ユーザがプライバシーオプションおよび関心を検討することを可能にするための選択ツールを提示し、ここで、前記プライバシーオプションおよび関心が、それらの識別子に関連付けられる前記ユーザおよび関心に関連付けられる識別子のリストを提示するための制御を含み、各識別子が、コンテンツにアクセスするために前記ユーザによって使用された要求ソースに関連付けられ、 前記プライバシー管理インターフェースは、 識別子単位で、またはグローバルベースで、個々の関心の選択解除を可能にし、 前記方法は、 サーバシステムで、プライバシー選択を考慮して前記ユーザに配信するべきコンテンツを決定するステップを備える、方法。
- 2ユーザが、所与のセッションについての、および前記ユーザに提示される特定のコンテンツアイテムに関連するプライバシー設定を管理することを可能にする、単一のコンテンツアイテムプライバシー管理インターフェースを提供するステップをさらに備え、 前記ユーザに配信するべきコンテンツを決定するステップが、前記プライバシー設定を考慮して前記ユーザに配信するべきコンテンツを決定するステップをさらに含む、請求項1に記載の方法。
- 3所与のユーザについてのグローバルなプライバシーポリシーを作成するステップであって、前記グローバルなプライバシーポリシーが、前記ユーザに関連付けられる複数のクッキーのマッピングを含み、要求ソースに関連付けられる各クッキーが、コンテンツにアクセスするために前記ユーザによって使用されているステップをさらに備え、 各クッキーが、セッション情報、および推測された、または明示的に定義された、任意の列挙された前記ユーザの嗜好を含み、前記嗜好が、前記ユーザから受信された要求に応答して前記ユーザに配信されるべきコンテンツを決定するために使用されており、 グローバルなプライバシーポリシーを作成するステップが、前記グローバルなプライバシーポリシーを形成するために、前記複数のクッキー内の各クッキーからプライバシーポリシー情報を集約するステップを含む、請求項1に記載の方法。
- 4前記プライバシーオプションおよび関心が、過去のユーザの行動に基づいて、前記ユーザに関連付けられるコンテンツの個々のカテゴリを含み、各カテゴリが、明示的に受信された、または推測された関心に関連付けられる要求ソースの特定の識別子に関連付けられており、また指示子とともに提示されており、前記グローバルなプライバシー管理インターフェースが、前記カテゴリのうちのいずれかを許可または拒否するための制御をさらに含む、請求項1に記載の方法。
- 5前記制御が、任意のカテゴリ、または単一の識別子に関連付けられる任意の情報の前記使用を、オプトインまたはオプトアウトするための制御をさらに含む、請求項4に記載の方法。
- 6前記制御が、前記ユーザに配信されるべきコンテンツの選択に使用される、さらなるカテゴリを追加するための制御をさらに含む、請求項4に記載の方法。
- 7供給システムが、前記プライバシー選択に基づいて、広告を前記ユーザに供給する、請求項1に記載の方法。
- 8ユーザから、所与のセッションに関連付けられるプライバシー選択の選択を受信するステップと、 前記ユーザのグローバルポリシーに関連付けられる前記プライバシー選択を格納するステップと、 供給システムによって前記ユーザに配信されるべきコンテンツを決定する際に有効である、前記ユーザとの様々なセッションにおいて受信されたすべてのプライバシー選択を前記ユーザに提示するステップとをさらに備える、請求項1に記載の方法。
- 9各識別子に関連付けられる要求ソースの名前を解決するステップと、 所与のクッキーに関連付けられるプライバシー選択を提示する際に、前記名前を提示するステップとをさらに備える、請求項1に記載の方法。
- 10ユーザが、ユーザのアカウント内の個々の識別子またはすべての識別子をアンリンクすることを可能にするための制御を提示して、それによって、前記ユーザが要求ソース単位で、または要求ソースのグループベースで、関心を隔離することを許可するステップをさらに備える、請求項1に記載の方法。
- 11前記識別子が、ディフィー-ヘルマン鍵プロトコルを使用してリンクされる、請求項10に記載の方法。
- 12前記識別子が、ユーザ固有のシードから導出される秘密鍵を使用してリンクされる、請求項11に記載の方法。
- 13識別子が、異なるデバイス、異なるブラウザ、または異なるアプリケーションからのクッキーを含む、請求項1に記載の方法。
- 14コンテンツを求める要求に応答して、コンテンツアイテムをユーザに提供するステップであって、前記コンテンツアイテムが、前記ユーザに関連付けられる複数の要求ソースのリンクされた識別子についての情報に少なくとも部分的に基づいて選択され、前記識別子が、個人を特定できる情報を格納することなしに、匿名でリンクされる、提供するステップと、 コンテンツアイテムの選択が実行された方法についての情報を明かすために、ユーザによる操作のための制御を提供するステップと、 前記制御の選択を受信するステップと、 前記選択情報に応答して、前記ユーザについて推測された、または前記ユーザから明示的に受信された前記選択を決定するために使用される嗜好情報を含む、前記コンテンツアイテムが選択された方法についての情報を前記ユーザに提供するステップであって、前記情報が、前記複数の要求ソースの識別を含む、提供するステップとを備える、コンピュータ実装方法。
- 15前記受信された選択に応答して、前記嗜好情報に関連付けられる要求ソースに関連付けられるインジケータを提示するステップをさらに備える、請求項14に記載の方法。
- 16嗜好マネージャにリンクするための制御を提示するステップであって、前記嗜好マネージャが、前記ユーザが、前記ユーザに配信するためのコンテンツアイテムを選択する際に、供給システムによって使用される前記ユーザに関連付けられる嗜好を変更することを可能にするステップをさらに備える、請求項14に記載の方法。
- 17前記嗜好マネージャが、複数の異なる要求ソースに関連付けられるユーザの嗜好を管理する、グローバルな嗜好マネージャである、請求項16に記載の方法。
- 18各要求ソースが、前記ユーザにマッピングされる一意の識別子に関連付けられる、請求項16に記載の方法。
- 19前記嗜好マネージャが、前記ユーザに配信するべきコンテンツアイテムを決定するために供給システムによって使用される要求ソースあたり1つの、リンクされた識別子のリストを含む、請求項17に記載の方法。
- 20ユーザが、ユーザのアカウント内の個々の識別子またはすべての識別子をアンリンクすることを可能にするための制御を提示して、それによって、ユーザが要求ソース単位で、または要求ソースのグループベースで、関心を隔離することを許可するステップをさらに備える、請求項19に記載の方法。
- 21前記識別子が、ディフィー-ヘルマン鍵プロトコルを使用してリンクされる、請求項19に記載の方法。
- 22前記識別子が、ユーザ固有のシードから導出される秘密鍵を使用してリンクされる、請求項21に記載の方法。
- 23前記コンテンツアイテムが広告である、請求項22に記載の方法。
- 24前記ユーザが、前記コンテンツアイテムに関連付けられるコンテンツプロバイダから、前記コンテンツアイテムをブロックする、または将来のすべてのコンテンツアイテムをブロックすることを可能にするための制御を提供するステップをさらに備える、請求項14に記載の方法。
- 25前記制御が、前記ユーザが識別子単位のブロッキング、またはグローバルなブロッキングを指定することを可能にする、請求項24に記載の方法。
- 26前記一意の識別子が、異なるブラウザ、または異なるアプリケーションからの識別子を含む、請求項18に記載の方法。
- 27前記要求ソースが、モバイルデバイス、デスクトップデバイス、タブレット、ブラウザ、アプリケーション、または他のデバイスを備えるグループから選択される、請求項14に記載の方法。
Independent claims27
146 paragraphs, as filed
0001Cross-reference of related applications This application is incorporated herein by reference in its entirety, U.S. Patent Application No. 13 / 538,782 filed June 29, 2012, and U.S. Patent Application filed April 27, 2012. It is a partial continuation application of No. 13 / 458,124 and claims its priority.
0002This specification relates to information display.
0003The Internet provides access to various resources. For example, you can access video and / or audio files, as well as web pages about a particular subject or a particular news article, over the Internet. Accessing these resources gives you the opportunity to serve other content (eg, advertising) along with the resources. For example, a web page can include slots that can display content. These slots may be defined within the web page, for example to be displayed on the web page along with the search results.
0004Content item slots can be assigned to content sponsors as part of the booking system or at auctions. For example, content sponsors can provide bid-specified amounts that sponsors each want to pay to display their content. This time, you can run an auction, among other things, associating their bid price and / or sponsored content with the content displayed on the page hosting the slot, or asking for sponsored content received. Slots can be assigned to sponsors upon request. Content can then be provided to the user on any device associated with the user, such as a personal computer (PC), smartphone, laptop computer, or any other user device.
<p num="0005"> In general, an innovative aspect of the subject matter described herein can be implemented in a way that includes a computer implementation method for managing a user's privacy rights associated with the delivery of content. This method is a step that provides a global privacy management interface that presents a selection tool that allows users to consider privacy options and interests, in which privacy options and interests are associated with their identifiers. Each identifier comprises a step associated with the request source used by the user to access the content, including controls for presenting a list of identifiers associated with the user and interest. The interface allows deselection of individual interests, either on an identifier basis or on a global basis. The method further comprises a step in the server system to determine the content to be delivered to the user in consideration of privacy choices.</p><p num="0006"> These and other implementations may optionally include one or more of the following features, respectively. The method provides a single content item privacy management interface that allows the user to manage privacy settings for a given session and related to a particular content item presented to the user. The step of determining the content to be delivered to the user further includes the step of determining the content to be delivered to the user in consideration of the privacy setting. The method is a step of creating a global privacy policy for a given user, where the global privacy policy includes mapping of multiple cookies associated with the user, and each cookie associated with the request source contains content. It can further include the steps used by the user to access the, each cookie contains session information, and any enumerated user preferences that are inferred or explicitly defined. Preference is used to determine what content should be delivered to a user in response to a request received from the user, and the step of creating a global privacy policy is to form a global privacy policy. Includes steps to aggregate privacy policy information from each cookie within multiple cookies. Privacy options and interests can include individual categories of content associated with the user based on past user behavior, and each category is a request associated with an explicitly received or inferred interest. Associated with a particular identifier in the source and presented with directives, the global privacy management interface further includes controls for allowing or denying any of the categories. Control further controls to opt in or out of the use of any information associated with any category, or single identifier. Can include. Controls may further include controls for adding additional categories used in selecting content to be delivered to the user. The feeding system can serve the advertisement to the user based on the privacy choice. The method receives from the user the privacy choice choices associated with a given session, stores the privacy choices associated with the user's global policy, and the content to be delivered to the user by the supply system. It may further be provided with a step of presenting the user with all privacy choices received in various sessions with the user, which are useful in making a decision. The method may further comprise the step of resolving the name of the request source associated with each identifier and the step of presenting that name when presenting the privacy choice associated with a given cookie. The method presents controls to allow the user to unlink individual or all identifiers within the user's account, thereby allowing the user to unlink on a request source basis or on a request source basis. On a group basis, there may be additional steps to allow isolation of interest. Identifiers can be linked using the Diffie-Hellmann key protocol. Identifiers can be linked using a private key derived from a user-specific seed. The identifier can include cookies from different devices, different browsers, or different applications. It may further be provided with a step of presenting the user with all privacy choices received in various sessions with the user. The method may further comprise the step of resolving the name of the request source associated with each identifier and the step of presenting that name when presenting the privacy choice associated with a given cookie. The method presents controls to allow the user to unlink individual or all identifiers within the user's account, thereby allowing the user to unlink on a request source basis or on a request source basis. On a group basis, there may be additional steps to allow isolation of interest. Identifiers can be linked using the Diffie-Hellmann key protocol. Identifiers can be linked using a private key derived from a user-specific seed. The identifier can include cookies from different devices, different browsers, or different applications. It may further be provided with a step of presenting the user with all privacy choices received in various sessions with the user. The method may further comprise the step of resolving the name of the request source associated with each identifier and the step of presenting that name when presenting the privacy choice associated with a given cookie. The method presents controls to allow the user to unlink individual or all identifiers within the user's account, thereby allowing the user to unlink on a request source basis or on a request source basis. On a group basis, there may be additional steps to allow isolation of interest. Identifiers can be linked using the Diffie-Hellmann key protocol. Identifiers can be linked using a private key derived from a user-specific seed. The identifier can include cookies from different devices, different browsers, or different applications.</p><p num="0007"> In general, another innovative aspect of the subject matter described herein can be implemented in a way that includes another computer implementation method for providing content items. The method is a step of providing a content item to a user in response to a request for content, where the content item is at least partially informed about the linked identifiers of multiple request sources associated with the user. The identifier is selected based on and comprises a step of being linked anonymously without storing any personally identifiable information. The method further comprises providing control for user interaction to disclose information about how the content item selection was performed. The method further comprises the step of receiving control choices. The method provides information about how a content item was selected, including preference information used to determine a choice that was inferred about the user or was explicitly received from the user in response to the selection information. The step further comprises a step in which the information includes identification of a plurality of request sources.</p><p num="0008"> These and other implementations may optionally include one or more of the following features, respectively. The method may further comprise the step of presenting an indicator associated with the request source associated with the preference information in response to the received selection. The method is a step of presenting control for linking to a preference manager, which associates with the user used by the supply system when the preference manager selects a content item to deliver to the user. Further steps may be provided that allow the preference to be changed. The preference manager may be a global preference manager that manages user preferences associated with multiple different request sources. Each request source can be associated with a unique identifier that maps to the user. The preference manager may include a list of linked identifiers, one per request source used by the supply system to determine which content items should be delivered to the user. The method presents controls to allow the user to unlink individual or all identifiers within the user's account, thereby allowing the user to unlink on a request source basis or on a request source basis. On a group basis, there may be additional steps to allow isolation of interest. Identifiers can be linked using the Diffie-Hellmann key protocol. Identifiers can be linked using a private key derived from a user-specific seed. The content item may be an advertisement. The method may further comprise a step of providing control from the content provider associated with the content item to allow the user to block the content item or block all future content items. Control allows the user to specify blocking of identification units, or global blocking. Unique identifiers can include identifiers from different browsers or different applications. Request source is mobile device, death</p><p num="0009"> The particular implementation may not realize any of the following advantages, and may realize one or more. Content may be provided to a user based at least in part on previously delivered content, such as content previously delivered to a user on one of several different devices. Associations between anonymous identifiers can be used to allow content that is of interest to the user to be delivered. Content sponsors may be provided with a more accurate mechanism for delivering content to users.</p><p num="0010"> Details of one or more implementations of the subject matter described herein will be described in the accompanying drawings and in the following description. Other features, aspects, and advantages of the subject matter will become apparent from the description, drawings, and claims.</p>
0011<figref num="1">It is a block diagram of an exemplary environment for delivering content.</figref><figref num="2A">It is a figure which collectively shows an exemplary system for providing content to a user who is recognized when using a plurality of different devices.</figref><figref num="2B">It is a figure which collectively shows an exemplary system for providing content to a user who is recognized when using a plurality of different devices.</figref><figref num="2C">It is a figure which collectively shows an exemplary system for providing content to a user who is recognized when using a plurality of different devices.</figref><figref num="2D">It is a figure which collectively shows an exemplary system for providing content to a user who is recognized when using a plurality of different devices.</figref><figref num="2E">It is a figure which collectively shows an exemplary system for providing content to a user who is recognized when using a plurality of different devices.</figref><figref num="2F">It is a figure which shows the exemplary calculation of a public key, a private key, and a private key.</figref><figref num="2G">FIG. 5 illustrates an exemplary privacy interface for managing a user's privacy rights associated with content delivery.</figref><figref num="2H">FIG. 5 illustrates an exemplary privacy interface for managing a user's privacy rights associated with an opt-out option.</figref><figref num="2I">For example, it is a diagram illustrating an exemplary privacy interface that can be presented when a user selects multiple device opt-out controls.</figref><figref num="2J">FIG. 5 illustrates an exemplary privacy opt-out interface for managing privacy settings for multiple devices.</figref><figref num="2K">FIG. 5 illustrates exemplary transparency and control features associated with content items provided with the user's privacy settings in mind.</figref><figref num="3A">It is a flow diagram of an exemplary process for providing a content to a user on any plurality of devices associated with the user.</figref><figref num="3B">It is a flow diagram of an exemplary process for providing a content to a user on any plurality of devices associated with the user.</figref><figref num="3C">Public Key-An exemplary process flow diagram for providing content to users on any number of devices using a private key.</figref><figref num="3D">It is a flow diagram of an exemplary process for providing content to a user in consideration of privacy selection.</figref><figref num="3E">FIG. 6 is an exemplary process flow diagram for providing transparency regarding the selection of content items in consideration of the user's privacy settings.</figref><figref num="4">FIG. 6 is a block diagram of an exemplary computer system that can be used to implement the methods, systems, and processes described in this disclosure.</figref>
0012Similar reference numbers and names in various drawings indicate similar elements.
0013This document provides content to users associated with or associated with multiple devices and manages their privacy settings, without storing any personally identifiable information associated with the user. Describe the process and the system. For example, when a user logs on to a user service from a first device (eg, the user's home PC), the public / private key pair can be determined and the public key can be made public. The public key may be stored by the user service in association with the user's first device. Private keys can be stored locally. Then, when the user logs in to the service from a second different device (eg, a different physical device, browser, or application), the second different device can also determine the public / private key pair. .. Each device can then use the device's own private key and the other device's public public key to calculate the private key. The private key may be stored in combination with an anonymous identifier for each device (eg, an anonymous cookie), thus creating a link or association between the devices. Generally, different cookies are associated with different devices, but some different types of request sources used by users (browsers, applications (eg games, mobile apps), physical devices (eg desktop devices, mobiles). A different set of cookies associated with any of a device, tablet, smartphone, or other physical device), or any request source that requests and receives content) is described in more detail below. Can be linked as.
0014In some implementations, the anonymous identifier may be a cookie, a browser cookie, a device identifier, or any other identifier associated with a given device. As a result, the mapping can identify all devices associated with a user without storing personally identifiable information (PII) associated with the user. If the content is subsequently provided to the user on any of the devices, the information contained in the mapping can be used, for example, to assist in selecting relevant content to be provided to the user. The selection of related content may include decisions about how the content is delivered to the user, including, for example, restrictions on when or how the content is delivered. For example, you can limit the number of ad impressions to a fixed number of impressions per user and per time period, regardless of the number of devices your users use.
0015In some implementations, anonymous identifiers can be associated with different browsers or other applications on the same device. For example, the techniques described in the present disclosure may be used to link multiple identifiers of an application that may have different cookie regions on the same device, or applications on different devices, or a combination of both.
0016In some implementations, the step of linking anonymous identifiers can be used in handshaking between mobile applications or mobile application combinations, browsers, and other applications. For example, mobile applications may have their own cookie areas that can interfere with handshaking with other applications, even on the same device. Each mobile application, for example, to generate a private and public key, to publish the public key, to access the public key of another mobile application (or associated with another device), and The techniques described herein can be used to calculate the private key using the proprietary private and public keys of other mobile applications (or associated with other devices).
0017In some implementations, users are offered the opportunity to opt in / out programs or features that allow them to be discovered across multiple devices and / or provide content based on their discoveries. obtain.
0018In some implementations, the mapping process can be repeated on a regular basis to ensure that anonymous identifiers (eg cookies) are not out of date, thus keeping up-to-date user session history information. Keep up to date. For example, a cookie on your computer may expire over time, and you can delete the cookie and set a new cookie as a result. Cookies-By repeating the mapping process on a regular basis, it is possible to ensure that the current set of cookies belonging to the user is mapped correctly. While referencing the cookie, you can use other forms of anonymous identifiers that include or derive from the seed.
0019In some implementations, user session history information can be stored anonymously. For example, session history information can include a user's browsing history, the number of times a user has viewed a particular advertisement, or other session history information. Information can be stored in association with the anonymous identifiers described herein. In some implementations, session history information associated with a user's session on the first device can be stored in a table containing an anonymous identifier associated with the first device. The same table can be used to store session history information about a user's session on a second different device for the same user. In some implementations, different or same tables can be used to store associations between anonymous identifiers. In some implementations, for example, it is possible to store all of anonymous identifiers, associations (eg, links to advertisements), and session data, without any corresponding personally identifiable information about a given user. it can.
0020As described in more detail below, after association and storage of session history information, a request for content (eg, an advertisement) from any of the devices associated with the user (anonymous associated with a given device). A request containing an identifier for) can be sent. In some implementations, the session history information stored in the table can be used, for example, in determining which advertisements the user may be interested in, depending on the request received. The decision can include inferences about the user based on the user's stored session history information. In some implementations, session history information about a user can be integrated, for example by joining tables using anonymous identifiers. For example, a request for content can be received, and the request can include an anonymous identifier associated with the user's desktop device. The anonymous identifier received can be used to look up other anonymous identifiers for the user (eg, the user's mobile device and other devices). The set of anonymous identifiers received can be used to access session history information (eg, user browsing history) in other tables. In some implementations, all session history information can be combined for each device that produces integrated information. In some implementations, some session history information may be aggregated with other information remaining separate. For example, the number of times an ad is viewed by a user can be aggregated (for example, along with other user information) and stored without aggregating the sites visited by the user. In some implementations, integrated session history information can be provided to the content management system to determine and select the target content to be delivered to the user in response to the received request. For example, session history information can include the number of times a user has viewed a particular ad, so content management
0021In some implementations, information integration can occur on demand, eg, in real time after a request for content occurs. For example, anonymous identifiers allow you to join user session history information stored individually in various tables. By integrating information in real time, for example, issues related to whether a user has opted out of being served content based on the device used by the user can be resolved. For example, session history information about a device that the user has opted out of is not integrated with other session history information. In some implementations, information about the user can be integrated and stored prior to any request for content. For example, all of the user session history information can be stored in a third table that contains, for example, all user session history information across linked devices for all users.
0022FIG. 1 is a block diagram of an exemplary environment 100 for delivering content. The exemplary environment 100 includes a content management system 110 for selecting and providing content in response to a request for content, and a privacy management system 115 for managing user privacy settings. The exemplary environment 100 includes a network 102, such as a local area network (LAN), a wide area network (WAN), the Internet, or a combination thereof. Network 102 connects to website 104, user device 106, content sponsor 108 (eg, advertiser), publisher 109, content management system 110, and privacy management system 115. An exemplary environment 100 can include a number of websites 104, user devices 106, content sponsors 108, and publishers 109.
0023The privacy management system 115 can generate several interfaces, each of which can be presented to the user if circumstances are guaranteed. For example, one or more interfaces are optional, using the user's anonymous identifier (eg, a cookie) to provide content that is personalized for the user and more interesting to the user (eg, advertising). It may be a global interface that controls how it is linked with other identifiers. Other interfaces may be session-generated and may be available, for example, when the user is performing an action such as browsing, or when the user is logged in through the user login service. Further interfaces may be presented, for example, when the content is provided to the user. For example, a description may be provided with some content that describes how the content was selected in light of the user's privacy settings and information that is inferred or otherwise known about the user. In some implementations, all such privacy-related interfaces allow users to change their privacy settings at any time to achieve a privacy balance while receiving personalized and interesting content. to enable. For example, FIGS. 2G to 2K described below show exemplary interfaces that can be generated and managed by the privacy management system 115.
0024In some implementations, the Illustrative Environment 100 can provide any particular user with access to a user's web services, email, social networks, business applications, or other resources, user login. Including service 120 further. For example, the user login service 120 can receive a login request from a user, such as through a web browser or other application running on any device associated with the user. The login request should include, for example, the user's login ID (eg, a unique identifier, email address, phone number, or any other identifier for the user that can be used to verify the user at login). Can be done. The user login service 120 can also retain information related to the device on which the user is currently logged on or recently logged in. The information can include, for example, mapping an anonymous identifier to the device by a session key that does not contain any personally identifiable information associated with the user. In some implementations, the mapping can be stored per user, in the data store of the linked anonymous identifier 122, or in some data structure.
0025In some implementations, the user login information 121 or some other data store can store the user login ID, public key, and initial seed. For example, the information may be used by a second device used by the user to access the public key published by the first device used by the same user. Similarly, the user's first device can access the public key exposed by the second device. At the same time, the seed value can be read from the user login information 121 by any of the user devices and used to determine the private key.
0026The user opt-out and privacy preference 142 data store may include information that the user has provided information about the time and method in which information about the user's different device may be used. For example, a user may access one or more user preference web pages that may be part of (or separate from) the user login service 120. In some implementations, the user can also set a preference to indicate "Don't link my different devices" and selectively choose which devices are allowed (or not allowed) to link. It can also be identified. The user's user opt-out and privacy preferences 142 may be checked and linking may only be performed if permitted by the user. In some implementations, the user can specify a setting that prohibits the provision of content based on linking. For example, a user may allow their smartphones and PCs to be linked, but the user may decide that no content (eg, advertising) should be served based on the linking.
0027Website 104 includes one or more resources 105 associated with a domain name and hosted by one or more servers. An exemplary website is a collection of web pages formatted in Hypertext Markup Language (HTML) that can contain programming elements such as text, images, multimedia content, and scripts. Each website 104 may be retained by a content publisher, the entity that controls, manages, and / or owns the website 104.
0028Resource 105 may be any data that can be provided via network 102. Resource 105 can be identified by the resource address associated with resource 105. Resources include HTML pages, word processing documents, portable document format (PDF) documents, images, videos, and news feed sources, to name a few. Resources may include content such as words, phrases, images, videos, and sounds that may contain embedded information (meta information hyperrings, etc.) and / or embedded instructions (JavaScript® scripts, etc.). ..
0029User device 106 is an electronic device under user control that can request and receive resources over network 102. An exemplary user device 106 is a personal computer (PC), a television with one or more processors embedded or coupled to it, a set-top box, a mobile communication device (eg, a smartphone), a tablet computer, and a network. Includes other devices that can send and receive data via 102. The user device 106 generally includes one or more user applications, such as a web browser, to facilitate the transmission and reception of data over the network 102.
0030User device 106 can request resource 105 from website 104. Data representing the resource 105 can then be provided to the user device 106 for display by the user device 106. The data representing resource 105 may also include data that specifies part of the resource or part of the user display, such as the location of a pop-up window that can display content or a slot on a third-party content site or web page. Can be done. These specified parts of a resource or user display are called slots (eg, advertising slots).
0031To facilitate the search for these resources, Environment 100 may include a search system 112 that identifies the resources by crawling and indexing the resources provided by the content publisher on website 104. .. Data about a resource can be indexed based on the resource to which the data corresponds. An indexed and optionally cached copy of the resource can be stored in the indexed cache 114.
0032The user device 106 can submit a search query 116 to the search system 112 over the network 102. Accordingly, the search system 112 accesses the indexed cache 114 to identify the resources associated with the search query 116. The search system 112 identifies the resource in the form of the search result 118 and returns the search result 118 to the user device 106 within the search result page. The search result 118 may be data generated by the search system 112 that identifies the resource in response to a particular search query and includes a link to the resource. In some implementations, search results 118 include the content itself, such as maps, answers, such as in response to a query for a store's merchandise, phone number, address, or business hours. In some implementations, the content management system 110 can use the information received from the search system 112 (eg, identified resources) to generate search results 118. An exemplary search result 118 can include a web page title, a piece of text or a portion of an image extracted from a web page, and a URL of the web page. The search results page can also contain one or more slots that can display other content items (eg ads). In some implementations, slots on search result pages or other web pages can include content slots for content items provided as part of the booking process. In the booking process, publishers and content item sponsors publish a given content item (or campaign) according to a schedule (for example, providing 1000 impressions by day X) or other publishing criteria. Conclude a contract that agrees with. In some implementations, the content selected to meet the request for a content slot, at least in part based on the priorities associated with the reservation process (eg, based on the urgency of fulfilling the reservation).
0033When the user device 106 requests resources 105, search results 118, and / or other content, the content management system 110 receives a request for content. The request for content can include the characteristics of the slot defined for the requested resource or search result page and may be provided to the content management system 110.
0034For example, a reference to the resource in which the slot is defined (eg, a URL), the size of the slot, and / or the type of medium available to display within the slot may be provided to the content management system 110. Similarly, to facilitate the identification of content related to a resource or search query 116, the keyword associated with the requested resource ("resource keyword"), or search query 116 that requires search results is also a content management system. Can be provided at 110.
0035Based at least in part on the data contained in the request, the content management system 110 can select the content to be provided in response to the request ("target content item"). For example, a targeted content item can include targeted ads that have characteristics that match the characteristics of the ad slot and are identified as related to the specified resource keyword or search query 116. In some implementations, the choice of content item of interest may further depend on user signals such as demographic and behavioral signals. Other information, such as the user identifier information associated with the mappings described above, can be used and / or evaluated when selecting content of interest.
0036Content management system 110 selects from eligible content items that should be provided for display within a slot of a resource or search results page, at least in part based on the results of the auction (or by some other selection process). Can be done. For example, for content items in question, the content management system 110 receives an offer from content sponsor 108 and is at least partially based on the received offer (for example, based on the highest bidder at the end of the auction). Slots can be allocated (or based on other criteria, such as those related to satisfying open reservations). An offer represents the amount that a content sponsor wants to pay to display (or select) their content along with a resource or search results page. For example, an offer can specify the amount that a content sponsor wants to pay for every 1000 impressions (ie, display) of a content item, called a CPM bid. Alternatively, the offer can specify the amount that the content sponsor wants to pay for the selection of the content item (ie, click-through), or the conversion that follows the selection of the content item (for example, the unit price per engagement). For example, the selected content item may be determined based solely on the offer and is multiplied by one or more factors such as quality score, landing page score, and / or other factors derived from content performance. It may be decided based on the offer of each content sponsor to be made.
0037Conversions can occur when a user performs a particular transaction or action related to a content item provided with a resource or search results page. What constitutes a conversion is different on a case-by-case basis and can be determined in a variety of ways. For example, conversions can occur when a user clicks on a content item called a web page (for example, an advertisement) to complete a purchase before leaving the web page. Conversions may also be made by the content provider by downloading a white paper, navigating to at least a given depth of the website, browsing at least a certain number of web pages, or at least pre-existing on the website or web page. Perform social actions related to content items (eg, ads), such as spending a set amount of time, registering on a website, experiencing the media, or republishing or sharing content items. It can be defined as any measurable or observable user behavior, such as. Other behaviors that make up the conversion may also be used.
0038Some implementations can improve the likelihood of conversions, for example, by recognizing a user when they access a resource using multiple devices. For example, if a content item (eg, an advertisement) is known to have already been viewed by the user on the first device (eg, the user's home PC), then on a different device (eg, the user's smartphone). Can make a decision (eg, via parameters) whether to serve the same content item to the same user. This will either repeat the ad impressions or avoid subsequent impressions, depending on whether multiple impressions of the ad to the same user are expected to lead to conversions in each case. Can increase the chances of conversion.
0039In situations where the systems discussed herein collect personal information about a user, the user may use personal information (eg, information about the user's social network, social actions or activities, user preferences, or the user's current location. ) May be offered the opportunity to opt in / out of programs or features that can be collected. In addition, data can be anonymized in one or more ways before it is stored or used so that personally identifiable information associated with the user is removed. For example, a user's identity may be anonymized to prevent personally identifiable information about the user from being determined, and the user from whom location information is obtained to prevent the user from being able to determine a particular location. Geographical location (city, zip code, or state level, etc.) may be generalized.
0040FIGS. 2A-2E collectively show an exemplary system 200 for providing content to a recognized user when using a plurality of different devices. In some implementations, recognition of a user across multiple devices can be achieved by linking the anonymous identifiers of multiple different devices of the user. As an example, the anonymous identifier 206a of the first device 106a (eg, the desktop computer of user 202) can be linked to the anonymous identifier 206b of the second different device 106b (eg, the laptop computer of user 202). In some implementations, the system 200 may be part of the environment 100 described above with reference to FIG. An exemplary sequence of events (eg, numbered steps 0, and 1a-8) follows to associate the anonymous identifiers 206a and 206b and provide content based on the association. However, other sequences may also be used to link devices 106a, 106b, and additional device 106 associated with user 202. In some implementations, devices 106a, 106b, and additional device 106 can be linked using the association stored in the linked anonymous identifier 122. The association may be stored, for example, without storing any personally identifiable information about user 202.
0041Before any link occurs that uses an anonymous identifier associated with the user's different device, the user login service 120 (or content management system 110) checks to see if the user has opted out of such a link. For this purpose, the user's user opt-out and privacy preferences 142 may be checked. For example, if the user specifies that the user's device is not allowed to be linked (or use that information), steps 2a-6b will not occur and the content provided in step 8 may be different. is there.
0042In some implementations, for example, when user 202 logs in to first device 106a (eg, user's desktop computer) using a login service (not shown in Figures 2A-2D), a sequence of steps. The first step 1a of (for example, as permitted by the user) can occur. For example, a login service or some other component may receive a login request 208a from the first device 106a. The login request 208a may be associated with an anonymous identifier 206a (eg, a cookie or device identifier) associated with the first device 106a. In some implementations, the login request 208a and / or other login request may be a request to log in to a social service.
0043In some implementations, the user login information 121 can store a user login ID 210, a seed 212, and a public key 214 associated with multiple users. User login information 121 can, for example, act as a directory containing one or more entries, where each entry is an identifier associated with a given user (eg, user login identifier, email address, or other). Indexed by some identifier). For example, when user 202 logs in to device 106a using the login service, the information about the user stored in user login information 121 is available to login ID 210a, seed 212a (for example, available to all user devices, A pair of generator primes such as 7, 11 (generator-prime) Pair)), and may include public key 214, as described in more detail below. At the current stage of the sequence of steps, the current user's public key 214 has not yet been determined. In some implementations, the seed 212 may vary from user to user, eg, the seed 212b for a second user (eg, generator prime pairs 7, 13) may differ from the seed 212a.
0044In step 2a, the first device 106a reads the seed (eg, generator prime pairs 7, 11 from the user login information 121) (216a) and is associated with the user 202 using the first device 106a. You can create a private key-public key pair. In some implementations, the step of creating a private key-public key pair involves step 3a, step 218a, which calculates the private key (eg, 9) and the public key (eg, 4). obtain. In some implementations, public and private key generation can use generator G, prime P pairs (eg 7, 11), G <P, see Figure 2F for an example. Will be explained. In step 4a, the public key stored, for example as public key 214a, is published (220a). The private key n and the public key 4 form a private key-public key pair, but they are generally stored in different locations. For example, the private key n may be stored locally on the first device 106a, for example in local storage 219. The public key (eg, 4) may be stored in the user login information 121 as the public key 214a. In some implementations, the public key 214a may be stored on line 222 containing user login information for user 202 on one or more devices (eg, devices 106a and 106b in the current example). For example, line 222 can serve as a directory entry associated with user 202. Each of the other lines can be used to store information about different users.
0045Then, referring to FIG. 2B, in step 2b, after the user logs in to the second different device 106b, the seed 216b (eg, generator prime pairs 7, 11) is read (eg, from the user login information 121). ), A second private key-public key pair associated with the user can be created. The second private key-public key pair is associated with user 202 using the second device 106b. For example, the second private key-public key pair is different from the private key-public key pair associated with user 202 logging in to the first device 106a. In some implementations, the step of creating a second private key-public key pair is step 3b, step 218b to calculate the private key (eg m), and the second public key (eg 8). ) Can be included. In step 4b, the second public key is exposed, for example, by adding the second public key to the set of public keys stored as public key 214a (220b). The private key m and public key 8 make up a second private key-public key pair (eg <m, 8>) whose value is the first device 106a (eg <n, 4>). Different from the value of the private key-public key pair calculated for. In some implementations, the private key m may be stored locally on a second different device 106b, for example in local storage 221b. The public key (eg, 8) may be stored in the user login information 121, for example, along with the public key 4 from the first device 106a. As a result, the directory entry stored on line 222 (and associated with user 202) has been updated to now contain two public keys.
0046Then, referring to Figure 2C, in step 5a, the second different device 106b has the public key from the first device 106a (eg 4) and the second private key (eg the private key from local storage 221b). You can use m) to create a private key (for example, 3) (226a). In step 6a, the second different device 106b can also associate a second anonymous identifier (eg, "device ID 2") with the private key (eg, 3) (228a). In some implementations, the association may include, for example, a step of storing the association in a linked anonymous identifier 122. For example, the linked anonymous identifier 122 may include the same user's private key 230 and the anonymous identifier 232. For example, line 234 is the private key 230a (for example, a hashed representation of 3, or 3), and the anonymous identifier 232b (for example, "device ID" that corresponds to the association that occurred in step 6a. 2 ") can be included. Following the release of the second public key (eg 8), and after the private key 3 has been calculated and the association stored with the second different device 106b (eg as a hashed representation). The user may log in again on the first device 106a. As a result, the first device 106a may receive a login request 208c from the user (eg, by the login service). For example, login request 208c may be similar to login request 208a described above. However, in this case, for example, the login service can determine that there is a public key for another device associated with the user, eg, a second different device 106. Further public keys can be used to link or associate between the two devices 106a and 106b, as described in more detail below. In some implementations, whenever the private key is stored, the stored value may be a hashed version of the private key, for example using a one-way hash function.
0047Then, referring to FIG. 2D, in step 5b, in response to the login request 208c, the first device 106a is the public key (eg, 8) from the second different device 106b, and the first private key (eg, 8). For example, the private key n) from local storage 221a can be used to create the private key 226b (eg 3). For example, the private key can match the private key calculated by the second different device 106b. In step 6b, the first device 106a can also associate a second anonymous identifier (eg, device ID 2) with a private key (eg, 3) (228b). In some implementations, the association may include, for example, a step of storing the association in a linked anonymous identifier 122. For example, line 234 containing the private key 230a (for example, 3) and the anonymous identifier 232b (for example, "device ID 2") is the anonymous identifier 232a (for example, "device ID 2"). It can be updated to include 1 "). As a result of the step of storing the association, the anonymous identifiers 206a and 206b, as well as the devices 106a and 106b, are now linked. Moreover, the association between the user's various devices is achieved without storing any personally identifiable information associated with the user.
0048In some implementations, one or more anonymous identifiers, such as anonymous identifier 232a or anonymous identifier 232b, appear on multiple lines (eg, three or more) within the linked anonymous identifier 122. Is possible. This may be, for example, an indication that the device associated with the anonymous identifier is a shared device (eg, in a library or Internet cafe). In this example, logins by a plurality of different users (eg, 3 or more) will result in multiple rows being created within the anonymous identifier 122, each having the same anonymous identifier. In some implementations, if advanced shared devices are detected in this way, the advanced shared devices may be unlinked and others may be taken into account. For example, if a threshold can be established and a cookie or other anonymous identifier appears within three or more lines, the association can be considered a shared machine.
0049Referring to FIG. 2E, in step 7, the content management system 110 makes a request for content 240a or 240b (eg, a request for advertising content) from either the first device 106a or the second different device 106b. Can be received. For example, the content request 240a may be a request for advertisement to fill the advertisement slot 242a on the web page 244a displayed on the first device 106a. In another example, content request 240b may be a request for advertisement to fill ad slot 242b on web page 244b displayed on a second different device 106b. If the request for content 240a is from the first device 106a, for example, the request for content may include a first anonymous identifier 232a. Alternatively, if the request for content 240b is from a second different device 106b, for example, the request for content may include a second different anonymous identifier 232b.
0050In step 8, the content management system 110 responds to the request and maps the user 202 to multiple devices (eg, the linked anonymous identifier 122, regardless of where the request for content originates). Content items (eg, content item 246a or 246b) can be served using associations (from). For example, the association can be represented by the information in line 234, which associates the anonymous identifiers 232a and 232b, for example, based on the same private key 230a. Using this information, the content management system 110 can treat, for example, regardless of a particular user device, as if the request for content came from the same user. In some implementations, the step of identifying the target content item for a request for content 240b may depend, for example, on content already provided to the same user 202 on the first device 106a. As a result, for example, an ad for a California vacation intended for one impression per user can be displayed on the first device 106a and will not repeat again on the second different device 106b. In some implementations, it may be beneficial to serve the same advertisement to each of a user's devices only once at a time.
0051Devices 106a and 106b are two examples of devices that can be used by user 202 . For example, user 202 can use a third different device 106c (eg, a smartphone). When user 202 uses a third different device 106c to log in, for example user login service 120 can store another third anonymous identifier 232 in the linked anonymous identifier 122. As a result, all three devices 106a-106c can be associated with user 202, for example using the private key 230a.
0052Similarly, other users can use the user login service 120 to log in from a number of different devices. As a result of the second user login to the fourth and fifth devices 106, for example, the user login service 120 may store the fourth and fifth different anonymous identifiers in the linked anonymous identifier 122. Can (for example, stored in relation to a second user who uses a private key 230 that is different from the private key 230a).
0053Figure 2F shows an exemplary calculation of public, private, and private keys. Device A Calculator 250 provides an example for calculating public, private, and private keys on a first device, eg, first device 106a. Device B calculation 252 provides an example for calculating public, private, and private keys on a second different device, eg, a second different device 106b. Other methods may also be used to determine the public key, private key, and private key.
0054In some implementations, the calculation can occur in steps, such as steps 254a-254e. For example, at 254a in step 1, both devices A and B can swap the prime P (eg 11) and the generator G (eg 7). In some implementations, prime numbers and generators may be stored in user login information 121 as described above. For example, user-specific prime numbers and generators (and devices associated with users) can be determined and stored when one or more entries in user login information 121 are created and stored.
0055At 254b in step 2, each device can generate its own private key, for example using random numbers or in some other way. For example, device A may have a private key of 6 and device B may have a private key of 9. These private keys can be used in combination with at least generators and prime numbers from 254a in step 1 to determine public and private keys in the following steps.
0056At 254c in step 3, each device can calculate the public key. In some implementations, the step of calculating the public key can use an expression that contains a generator raised to the power of the device's private key, and modulo P can be performed on the result. Using the generator, prime number, and device private key, respectively, the resulting device public key may be 4 and 8, respectively.
0057Once the public keys have been determined in step 4 254d, the device can share those public keys, for example by exposing the keys in the user login information 121 as described above. As a result, device A can know the public key of device B (for example, 8), and device B can know the public key of device A (for example, 4).
0058In step 5 254e, for example, the private key can be calculated using the formula that powers the public key of another device with the private key of the current device, and the result can receive a modulus P (prime number). .. As a result of the calculation, the private key of the first and second devices may be 3. Once the private key is determined, the value can be used by any device to update the row in the linked anonymous identifier 122 with the device's anonymous identifier. This can be repeated for any other device associated with the same user that calculates the private key using its own private and public keys from one of the other devices.
0059Figure 2G shows an exemplary privacy interface 256a for managing a user's privacy rights associated with content delivery. The privacy interface 256a allows users to consider privacy options and interests. The privacy interface can be generated and managed by the privacy management system 115 (Figure 1). For example, the privacy interface 256a is provided by a global privacy management interface (eg, privacy management system 115) that is presented to the user when the user selects option 258a from the preference menu 260, or is presented in some other way. It is fine. In some implementations, in the privacy interface 256a (and privacy interfaces 256b-256c), the information presented and / or entered by the user may reside in the user opt-out and privacy preference 142. As such, the user privacy settings are available and accessible for consideration through all aspects of presenting the content to the user, as described above with reference to FIGS. 1-2E.
0060The information presented to Privacy Interface 256a is determined and / or for the user, at least in part, based on the user's various linked cookies, for example, using the anonymous identifier linking technique described herein. It may contain inferred information. Other techniques for linking multiple identifiers for the same user may be used, and information from those techniques may also be used in providing information to the privacy interface 256a. The privacy interface 256a can provide information related to the category, demographic, and linked cookie information that the user is interested in, providing the user with transparency. This transparency allows the user to see information that can be used to personalize the content presented to the user, such as advertisements selected and presented to the user based on the user's interests and demographics. Become. The privacy interface 256a can also control this information and provide control for its use.
0061The privacy interface 256a can present a category of interest 262 (eg, travel, sports, sea, games) that is determined and / or inferred about the user from, for example, multiple linked devices of the user. For example, travel and sports interests are inferred from user activity on the user's home personal computer (eg, inferred from web searches, etc.), and sea interest is inferred from user activity on the user's mobile phone. Interest in the game being played can arise, for example, from a mobile game app on the user's mobile phone. In these examples, the various devices, browsers, and applications are request sources of different types and instances, each of which may have its own unique identifier. In addition, multiple request sources (eg, browsers, applications, or other cookie generators) may be on the same user device.
0062The category of interest 262 presented to the user may include the category of interest associated with each currently linked device (or, more generally, a different request source). Also, the list of categories of interest may include any particular interest that the user has explicitly added to the list, and may exclude any interest that the user has chosen to exclude. In some implementations, the user can change the list of categories of interest at any time. For example, using control 264a, the user may be presented with an interface on which changes can be made to the user's guessed / determined category of interest, including the category of interest that the user has explicitly added. In some implementations, for each category 262 of interest, for example, one or more anonymous identifiers (eg, cookie ID or other identifying information) associated with the user device for which the category 262 of interest has been determined. Can also be displayed.
0063The inferred demographic 266 can list various demographics (eg, gender, age, income, etc.) inferred about the user, for example through an anonymously linked identifier associated with the user. The inferred demographic 266 may also include, for example, information that the user may have explicitly provided to a user profile, online registration, or social network. Control 264b allows the user to change the current demographic settings, for example to exclude the user's gender and / or age as the demographic associated with the user. For example, a user who retired at the age of 70 but doesn't want to see endlessly personalized ads for seniors can use Control 264b to keep his age private. The privacy interface 256a allows the user to see what information is known or inferred about the user and how that information is used (or not used). Other controls may be included. Some implementations may also display for each inferred demographic 266, for example, one or more anonymous identifiers associated with the determined user device in which the inferred demographic 266 is determined.
0064The category 262 of interest and the inferred demographic 266 are just two types of information that can be displayed on the privacy interface 256a. It may also contain other information that may be relevant to or of interest to you. For example, the information is the number of times a user has been shown a particular different ad over a particular time frame (for example, 50 impressions of a brand XYZ shoe ad over the last 30 days) or content from a particular source. May include.
0065Information area 268 can list all identifiers associated with a user (eg, cookies), for each particular identifier to access content, including user devices, browsers, and applications associated with the user. Can be associated with different request sources used by the user. The list of anonymously linked identifiers 268a may include, for example, all of the user's currently linked identifiers, linked using, for example, the anonymous identifiers described above, or otherwise linked. Description Control 270, when selected by the user, can provide information on how identifiers are linked anonymously, so that, for example, none of the personally identifiable information (PII) is controlled by the user, and / Or not stored in a location that is private to the user. In some implementations, at any time, the user removes one or more specific identifiers from the list (for example, temporarily or permanently) or unlinks one or more specific identifiers. Control 272 can be selected for either. For example, the list of unlinked identifiers 268b can include the user's browser XYZ, which may be the browser that the user uses at work or elsewhere. For example, a user may want to unlink a browser at work to prevent work-related concerns from being used to personalize received content, for example, in a home, mobile device, or gaming app.
0066The information area 268 provides the transparency of the linked identifier, and the control 272 controls the linking and provides the user with the ability to use the identifier. For example, content (eg, advertising, etc.) may be personalized based on the user's linked device, depending on the identifier that the user decides to keep in the list of anonymously linked identifiers 268a. As a result, the server system can deliver content to the user, taking into account the user's current privacy choices and / or settings, as well as the user's currently linked identifier.
0067In some implementations, the controls available (or accessible from) the privacy interface 256a allow users to select categories and demographics of individual interest, either on an identifier-by-identifier basis or on a global basis. It becomes possible to execute deselection. For example, the user can specify that one or more categories or demographics of interest should not be used in combination with a particular identifier.
0068Figure 2H shows an exemplary privacy interface 256b for managing the user's privacy rights associated with the opt-out option. For example, the privacy interface 256b may be presented to the user when the user selects option 258b from the preference setting menu 260, or may be presented in some other way.
0069The information presented in the privacy interface 256b may include an explanatory area 274a explaining that the opt-out step can be achieved with respect to the user's preferences in order to present the user with personalized content (eg, an advertisement). For example, as explained to the user by the description box 278a, the user disables local cookies to no longer associate the user's interests (eg categories of interest) and demographics with the user's current browser. The opt-out control 276a can be selected for this purpose. Some implementations may provide another control (eg, an opt-in control not shown in Figure 2H) that allows the user to regain receipt of personalized content. For example, a user may decide to opt in again after realizing that the ad is less relevant or less interested than it was before it opted out.
0070Multiple device opt-out controls 281 can provide a way for a user to opt out on all request sources associated with the user (eg, devices, browsers, applications). The included request source can be viewed using, for example, non-shared control 282. Public devices (eg, shared computers in libraries) are generally not linked, so non-shared devices are included herein, and their use by users generally results in the need to provide opt-out options. Absent.
0071FIG. 2I is a diagram illustrating an exemplary privacy interface 256c that may be presented, for example, when the user selects multiple device opt-out controls 281. Explain area 274b can be explained to be achieved by opting out across non-shared devices. The user can select opt-out control 276b to enable opt-out on linked non-shared devices. In some implementations, another control (eg, not shown in Figure 2I) allows the user to opt back to the use of linking on various devices of the user in order to receive more personalized content. Multiple device opt-in controls) may be provided. For example, a user may decide to opt in again after noticing that an ad is less relevant or less interested in the light of a user's multiple linked devices.
0072FIG. 2J illustrates an exemplary privacy opt-out interface 279 for managing the privacy settings of multiple devices, provided by, for example, the privacy management system 115. For example, if the user selects one or more controls from the other privacy settings interfaces described above, the privacy opt-out interface 279 may be presented to the user or in some other way.
0073The information presented in the privacy opt-out interface 279 provides a privacy settings area 280 that allows users to view and control the privacy settings of one or more devices, or to provide other settings on a per-identifier basis. Can include. In some implementations, the privacy setting area 280 may include controls 282a-282c, and / or other controls that the user can use to specify privacy settings. User selection made using controls 282a-282c may also affect the information and settings presented in the per-device configuration area 284. In some implementations, the per-device configuration area 284 is an entry organized by columns, including cookie / device 286a, interest 286b, demographic 286c, per-cookie link configuration 286d, and customized advertising configuration 286e. Can contain one line 284a-284d for each request source, including. For example, by looking at the cookie / device 286a, the user can see at a glance which of the user's identifiers is known by the system (eg, by the privacy management system 115) in relation to the privacy settings. it can. By looking at interest 286b (and demographic 286c), for example, the user can see which interest (and demographic) is associated with the user and which interest (and demographic) is associated with the user, based on the position of the row in the privacy settings area 280. And demographics) can be seen to be associated with each identifier (eg cookie / device). In addition, per-cookie link settings 286d and customized ad settings 286e allow devices to be linked so that customized content (eg, ads) can be served based on anonymous links. , Shows the user's current settings and preferences. The information in the per-device configuration area 284 is the activity between controls 282a and 282c and / or.
0074For example, unlink control 282a allows the user to select a single checkbox to unlink all cookies (eg, anonymously linked by the techniques described herein or otherwise). It can be made possible to check. By checking the unlink control 282a, the user avoids the presentation of any subsequent content that can be personalized based on the knowledge of the user's various linked request sources, including different devices, browsers, applications, etc. be able to. Unchecking the unlink control 282a may be a signal that the user is allowed to link the user's identifier, and then the linking is repeated stepwise as described above. In some implementations, checking unlink control 282a may uncheck the link setting 286d for each identifier. If the identifier is unlinked, for example, it can be removed from the linked anonymous identifier 122 and / or the linking information can be invalidated in some other way.
0075The interest removal control 282b can, for example, be checked by the user to remove all interests associated with the user's identifier. By checking the interest removal control 282b, the user effectively "from my cookies, and therefore from consideration, to provide personalized content in the light of my linked cookies, all current interests. I'll delete it. " By checking the interest deletion control 282b, the information in the interest 286b may be deleted. The user can also change the interest of a particular device / identifier (for example, a particular row in the per-device configuration area 284) separately by editing the interest using the corresponding edit control 287b. it can.
0076The demographic erasure control 282c can, for example, be checked by the user to remove all demographic information associated with the user's identifier. By checking Demographic Erase Control 282c, users can effectively "from my cookies, and therefore from consideration, in providing personalized content in the light of my linked cookies, all current demos. Delete the graphic. " By checking the demographic erase control 282c, the information in the demographic 286c may be erased. The user can also change the demographic of a particular device / identifier (for example, a row in the per-device configuration area 284) separately by editing the demographic using the corresponding edit control 287c. it can. For example, the inferred user's age demographic may not be accurate (for example, "age 35-44" in line 284c), and the user corrects this information using the corresponding edit control 287c. be able to.
0077For each line 284a to 284d, a setting for each identifier can be specified. In some implementations, edit control 287a may be used to modify the displayed information, or other information associated with an identifier. For example, a user may change the displayed alias (for example, "home PC" or "my cell phone") for each identifier, for example to label cookies to facilitate the management of privacy settings. be able to.
0078The user can also check or uncheck the per-cookie link setting 286d to control whether a particular cookie should be linked. As shown, for example, on lines 284a, 284b, and 284d, the user may want to link those cookies anonymously, but the user may want to keep the browser XYZ (eg, in line 284c) unlinked. is there.
0079The user selects, for example, the content to be provided to the specified request source (eg, device, browser, application) using the information associated with the linking (ie, the content is of current interest). You can also select and deselect the customized ad settings 286e by identifier to control whether it is personalized against an anonymous link for a category, demographic, and a particular cookie). You can also do it.
0080FIG. 2K illustrates exemplary transparency and control features associated with content items provided with the user's privacy settings in mind. For example, a user may use the browser XYZ to browse content on web page 288, which may result in a request for content to fill ad slot 290. Content items (eg, Oceanside Beach Resort Ads 292) may be offered in response to the request. For example, the content management system 110 may select advertisement 292, at least in part, based on information about linked identifiers of multiple request sources associated with the user. In this example, the selection of Oceanside Beach Resort Ad 292 is based on the user's current linked identifier, the corresponding interest (eg, travel, sea), and the demographic associated with the identifier. It may be in the light of the privacy settings of (eg, obtained from user opt-out and privacy preferences 142).
0081In some implementations, transparency control 294 may be provided, for example, if the content is provided and the content selection is based on, for example, a linked identifier according to the user's privacy settings. In some implementations, transparency control 294 can provide an indication of why a particular content item was selected for presentation to a given user. For example, Transparency Control 294 can present a message that says "You received this ad because ...", or some other message. In some implementations, the transparency control 294 may not include any text and / or may include a symbol (eg, "I" or question mark) or control for retrieving information. Other transparency controls may also be used. In some implementations, the type of control presented may vary depending on how the content item was selected. For example, different controls may be offered when multiple identifiers are used to select content and when only one identifier is used (ie, the identifier associated with the request source). In some implementations, it is better if the user adjusts (eg, relaxes) privacy settings while ensuring that the identifier is anonymous and linked without storing personally identifiable information. Different controls can be provided to communicate or notify the user that interesting and personalized content may be provided.
0082In some implementations, the user can manipulate (eg, select) the transparency control 294 to reveal information about how the content item selection was performed. For example, by clicking Transparency Control 294, the user can generate a Transparency Pop-up 296, or other display that contains information about how the content item was selected. The information can identify preference information used to make a choice, including information inferred about the user or explicitly received from the user. The information may also include identification of multiple request sources. In the current example, the transparent pop-up 296 was selected for Oceanside Beach Resort Ads 292, at least partially based on the user's linked home PCs and mobile phones, as well as interests including travel and ocean. Can be shown.
0083In some implementations, a privacy setting control 298 may be presented to the user, which allows the user to change the privacy setting. For example, the user selection of privacy setting control 298 may result in the display of the privacy opt-out interface 279, or some other interface.
0084FIG. 3A is a flow chart of an exemplary process 300 for providing content to a user on any of a plurality of devices associated with the user. In some implementations, the content management system 110 and / or the user login service 120 can perform steps 300 using instructions executed by one or more processors. FIGS. 1 to 2F are used to provide an exemplary structure for performing the steps of process 300.
0085A first login request is received from the first device used by the user to log in to the service, and the first login request is associated with the first anonymous identifier associated with the first device ( 302). For example, referring to FIG. 2A, the user login service 120 can receive a login request 208a from a first device 106a (eg, a personal computer) used by user 202. The login request can be, for example, associated with the anonymous identifier 206a (eg, "device ID 1") associated with the first device 106a.
0086The seed is read to create a first private-public key pair that is associated with the user when using the first device (304). As an example, the user login service 120 can read the seed 212a (eg, generator prime pairs 7, 11) and provide the seed 212a to the first device 106a. The seed can be used by the first device 106a to determine the private key (eg, 9) and public key (eg, 4) associated with the first device 106a.
0087First Private Key-The first private key associated with the public key pair is stored locally on the first device and the first public key is exposed in the directory entry associated with the user (306). .. The first device 106a can, for example, store the private key in the local storage 221a. The first device 106a can also provide the user login service 120 with a public key (eg, 4) to store in the user login information 121.
0088A second login request is received from a second different device used by the user, and the second login request is associated with a second different anonymous identifier associated with the second different device (308). ). As an example, referring to Figure 2B, the same user 202 can log in to a second different device (eg, a laptop computer). The user login service 120 can receive, for example, login request 208b. The login request can be, for example, associated with an anonymous identifier 206b (eg, "device ID 2") associated with a second different device 106b.
0089In response to a second login request received (310), the seed is read and the second private key associated with the user when using a second different device that contains a second different public key- A public key pair is created (312). As an example, the user login service 120 can read the seed 212a (eg, generator prime pairs 7, 11) and provide the seed 212a to a second different device 106b. The seed can be used by the second different device 106b to determine its private key (eg, 6) and public key (eg, 8).
0090Second Private Key-The second private key associated with the public key pair is stored locally on the second different device and the second public key is exposed in the directory entry associated with the user ( 314). The second different device 106b can, for example, store the private key in local storage 221b. The second different device 106b can also provide the user login service 120 with a public key (eg, 8) for storage in the user login information 121.
0091The private key is created using the first public key (316). For example, referring to Figure 2C, a second different device 106b uses a public key from the first device (eg 4) and a private key unique to the second different device (eg 6). 230a (eg 3) can be calculated. Device B calculation 502, shown in Figure 2F, provides exemplary steps and equations for calculating the private key.
0092A second anonymous identifier is associated with the private key (318). For example, a second different anonymous identifier (for example, device ID 2) can be stored with a private key (for example, a hashed version) in, for example, a linked anonymous identifier 122, user login information 121. It is stored separately.
0093Following the release of the second public key, a login request is received from the user (320) when accessing the first device, and the second public key is used in response to the received request. The private key is created (322). As an example, user 202 can log in to the first device 106a again. The login request 208a may be received, for example, by the user login service 120. At this time, the first device 106a also calculates the private key 3 using the private key of the first device (for example, 9) and the public key from the second different device 106b (for example, 8). be able to. Device A Calculator 500, shown in Figure 2F, provides exemplary steps and equations for calculating the private key.
0094A first anonymous identifier is associated with the private key (324). For example, a first anonymous identifier (eg, device ID 2) may be stored in the linked anonymous identifier 122, along with a hashed version of the private key. As a result, both anonymous identifiers are currently linked. For example, the private key, the first anonymous identifier, and the second different anonymous identifier are stored as entries in the table, such as row 234. In some implementations, the association maps the private key to both a first anonymous identifier and a second different anonymous identifier. In some implementations, one or more associations are deleted (eg, from the linked anonymous identifier 122) after the expiration of the first period (eg, 24 hours, 48 hours, or some other period). Can be deleted). In some implementations, the time period can be associated with the amount of time after the user is expected to log out of either the first device or the second different device.
0095A request for content is received from either a first device that contains a first anonymous identifier or a second different device that contains a second different anonymous identifier (326). In one example, referring to FIG. 2E, the content management system 110 can receive a request 240a from the first device 106a for content containing the anonymous identifier device ID 1. In another example, the content management system 110 can receive a request 240b from a second different device 106b for content containing the anonymous identifier device ID 2.
0096In response to the request, the content is served using the association (328). For example, depending on which device sent the request for content 240a or 240b, the content management system 110 may place the content item 246a or 246b on either the first device 106a or the second different device 106b. Can be provided to each.
0097In some implementations, the step of providing content in response to a request may further include the step of identifying the user based on the association and the step of providing content of interest to the user. For example, using information provided by the user in the user profile (eg, interested in sports) (or other information provided by the user and / or known about the user) that is of interest to the user. You can select such content.
0098Some implementations of Process 300 may include additional devices, such as a third device, and / or steps for linking additional devices. For example, a login request can be received from a third different device used by the user, and the login request is associated with a third different anonymous identifier associated with the third different device. You can create a third different public / private key pair, including a third public key. The third private key can be stored locally on the third device and the third public key can be exposed (for example, with user login information 121). In addition to the private key of the third different device, for example, using the steps and formulas shown in Figure 2F, secret using either the first public key or the second public key. You can create a key. The association between the private key, the first anonymous identifier, the second different anonymous identifier, and the third different anonymous identifier can be stored, for example, in the linked anonymous identifier 122. Subsequently, either the first device containing the first anonymous identifier, the second different device containing the second different anonymous identifier, or the third different device containing the third different anonymous identifier. From this, a request for content can be received. In response to a request, the association may be used to serve content (for example, content item 246a or 246b, or content item on a third different device).
0099FIG. 3B is a flow diagram of an exemplary process 340 for providing content to a user on any plurality of linked devices associated with the user. In some implementations, the content management system 110 and / or the user login service 120 can use instructions executed by one or more processors to perform the steps of process 340. FIGS. 1 to 2F are used to provide an exemplary structure for performing the steps of process 340.
0100Multiple anonymous identifiers associated with a user are linked by a service that uses a key exchange protocol without storing any personally identifiable information associated with the user when linking (342). For example, anonymous identifiers for the first device 106a and the second different device 106b (eg, a browser cookie, or device ID 1 and device ID 2) may be linked by the user login service 120, respectively. The linking step can occur, for example, using the key exchange technique described above, and includes the steps using public key calculation, private key calculation, and private key calculation shown in FIG. 2E. In some implementations, the public key can be exposed on the user login service 120, the private key can be stored on the corresponding local device, and the private key can be stored in a third location (eg, linked). It can be stored in the anonymous identifier 122). Other techniques can be used to link the devices, and multiple devices can be linked.
0101In some embodiments, the step of linking multiple anonymous identifiers is the step of receiving a login request from a user (eg, login request 208a or 208b) from multiple different devices, and another that is associated with the user. The steps to determine the private key using the public key information published by the device (the private key does not contain any personally identifiable information associated with the user) and the anonymous key associated with each login request. It may include a step of mapping to an identifier. For example, the private key may be the private key stored in the linked anonymous identifier 122 and does not contain information about the user that can be traced back to the user (ie, information from user login information 121, linked anonymous). No access to the identifier 122, and private keys stored on various user devices).
0102In some implementations, the steps to determine the private key are, on each device, the step of creating a public key-private key pair, the step of exposing the public key of the public key-private key pair, and the public key. -May include the private key of a private key pair and the step of calculating the private key using the public key of another device.
0103The service receives requests for content from the client device associated with the user, and each request contains one of the anonymous identifiers (344). For example, referring to FIG. 2E, the content management system 110 can receive a request 240a for content containing the anonymous identifier device ID 1 corresponding to the first device 106a. In another example, the content management system 110 can receive a request 240b for content containing the anonymous identifier device ID 2 corresponding to the second different device 106b.
0104Content associated with the user is provided in response to the request received and based on the linking (346). For example, depending on which device sent the request for content 240a or 240b, the content management system 110 may place the content item 246a or 246b on either the first device 106a or the second different device 106b. Can be provided to each.
0105FIG. 3C is a flow diagram of an exemplary process 360 for providing content to users on any number of linked devices using a public / private key. In some implementations, the content management system 110 and / or the user login service 120 can perform steps 360 using instructions executed by one or more processors. Figures 1 and 2F are used to provide an exemplary structure for performing the steps in process 360.
0106Each time a user logs in to the service from a different device, a public / private key pair is created for the user, including exposing each user's public key in the directory entry associated with the user (362). .. For example, FIGS. 2A-2D show a sequence of operations that use a public / private key pair to link a first device 106a and a second different device 106b. The public key in this example is stored in the user login information 121.
0107Each device creates a private key using the public key of another device stored in the directory (364). For example, FIGS. 2C-2D show a sequence of operations that use the public keys of other devices to determine the private key for each of the first device 106a and the second different device 106b.
0108The private key is associated with multiple anonymous identifiers, each anonymous identifier being assigned to the user during a session associated with each different device (366). As an example, the private key is stored in the linked anonymous identifier 122. The steps and formulas for calculating the private key are shown in Figure 2E.
0109Content is provided that is associated with the user and is at least partially based on the association (346). For example, depending on which device sent the request for content 240a or 240b, the content management system 110 may place the content item 246a or 246b on either the first device 106a or the second different device 106b. Can be provided to each.
0110FIG. 3D is a flow diagram of an exemplary process 370 for providing content to a user in consideration of privacy choices. In some implementations, the content management system 110 and the privacy management system 115 can perform the steps of process 370 using instructions executed by one or more processors. Figures 2G-2K are used to provide an exemplary structure / interface associated with the steps in process 370.
0111A global privacy management interface is provided (372). As an example, as mentioned above, interfaces 256a-256c, and 279 may be provided to the user.
0112Selection tools are presented to allow users to consider privacy options and interests (374). Controls are included to present a list of identifiers associated with the user and the interests associated with those identifiers. Each identifier is associated with the request source used by the user to access the content. For example, on interface 256a, controls 264a and 264b can be provided that allow the user to view individual identifiers as well as corresponding interests and demographics. Choosing a control may present, for example, an interface 279 that allows the user to make the selection on an identifier-by-identifier basis and / or on a global basis.
0113Some implementations may link identifiers using the Diffie-Hellmann key protocol or in some other way. For example, as mentioned above, identifiers can be linked using a private key derived from a user-specific seed. Identifiers can include identifiers from different devices, different browsers, different applications (eg mobile apps and games), or other types of request sources.
0114In some implementations, privacy options and interests are based on past user behavior, for example, individual historical information for each user, including visited web pages and other behavior, for individual content associated with the user. Can include categories. For example, referring to Figure 2J, if a user visits several sports-related websites, the category of "sports" displayed in interest 286b can be determined as the individual category associated with the user. When the user is presented with a privacy option, each category may be associated with a particular identifier associated with an indication of interest (explicit or inferred) and may be presented with an indicator. For example, the "Sports" category is presented in line 284a and associated with the user's home PC. The global privacy management interface may further include controls for allowing or denying any of the categories. For example, the user can use control 287b to edit any interests associated with a particular identifier.
0115In some implementations, the control may include one or more controls to opt in or out of the use of any information associated with any category, or single identifier. For example, controls may include controls for adding additional categories that are used in selecting content to be delivered to users (eg, to allow content to be personalized based on interests). , If the user wants to specify an interest in art).
0116Deselection of individual interests is possible on an identifier-by-identifier basis or on a global basis (376). As an example, the user can use controls 282a-282c to make global selections, or can use controls within the identifier unit configuration area 280 to make identifier unit selections. For example, a user can remove individual concerns about a particular device (eg, a home PC).
0117In some implementations, the combined identifier may be presented to the user so that all interests and all demographics are listed on a single line. The user can then select a particular category of interest and specify that the category of interest be removed from all identifiers. Other uses of the combined identifier are possible, for example, modifying the demographic, unlinking or linking the identifier, or specifying that the content should be personalized based on privacy settings.
0118The server system determines what content should be delivered to the user, taking into account privacy choices (378). For example, the content management system 110 may serve advertisement 292 for an oceanside beach resort in response to a request for content to fill content item slot 290. The choice of advertisement 292 by the content management system 110 may, at least in part, depend on the user's current privacy settings (eg, from user opt-out and privacy preferences 142). For example, a delivery system (eg, a content management system 110) can serve an advertisement to a user based on the privacy choices made by the user using the privacy management system 115.
0119In some implementations, process 370 allows a user to manage privacy settings for a given session and related to a particular content item presented to the user, a single content item. A step of providing a privacy management interface can be further included, and the step of determining the content to be delivered to the user may further include the step of determining the content to be delivered to the user in consideration of the privacy setting. For example, the user can determine that the privacy settings for the current device (eg, associated with the currently running browser or application) should be changed based on the content received.
0120In some implementations, process 370 may further include the step of creating a global privacy policy for a given user. The global privacy policy can include mapping of multiple identifiers associated with the user, and each identifier associated with the request source is used by the user to access the content. Each identifier can include session information and any enumerated user preferences that are inferred or explicitly defined, and the preferences are delivered to the user in response to a request received from the user. Used to determine what content should be done. The step of creating a global privacy policy involves aggregating privacy policy information from / for each device / identifier within multiple identifiers in order to form a global privacy policy. For example, using the privacy opt-out interface 279, users can make global changes across all identifiers and / or individual changes on an identifier-by-identifier basis, with a full set of privacy settings and user preferences. , Can establish a global privacy policy for users.
0121In some implementations, session-based information can be stored in a global profile. For example, the privacy choices associated with a given session may be received from the user and may store the privacy choices associated with the user's global policy. All privacy choices received in various sessions with the user may be presented to the user in order to present the privacy choices that are effective in determining the content to be delivered to the user by the delivery system. For example, the user opt-out and privacy preference 142 may store the user's current global profile and be kept up to date based on any changes the user makes to the privacy settings over time.
0122In some embodiments, it presents controls that allow the user to unlink individual or all identifiers within the user's account, thereby allowing the user to request per request source or source of request. Group-based, can be allowed to isolate interests. For example, unlink control 282a, when checked, unlinks all of the user's identifiers across all request sources, such as the request sources listed in identifier / device 286a.
0123In some implementations, the user can decide to link the identifier to different linked groups. For example, users can link work-related identifiers within one linked group, personal and home identifiers within a second linked group, and games and mobile apps with a third link. You can decide to link to the group that was created.
0124FIG. 3E is a flow diagram of an exemplary process 380 for providing transparency regarding the selection of content items, taking into account the user's privacy settings. In some implementations, the content management system 110 and the privacy management system 115 can perform the steps of process 380 using instructions executed by one or more processors. FIG. 2K is referenced in connection with the steps of process 380.
0125Content items are provided to the user in response to a request for content (382). For example, content management system 110 may serve advertisement 292 (eg, an advertisement for an oceanside beach resort) in response to a request for content received from web page 288 to fill ad slot 290. ..
0126Controls for user interaction are provided to reveal information about how the content item selection was performed (384). As an example, advertisement 292 may be provided with transparency control 294. In some implementations, Transparency Control 294 provides a description (eg, "You received this ad because ..." or other message), and / or other information, or components. Can include.
0127Control choices are received (386). For example, the user may select Transparency Control 294 to determine why the Oceanside Beach Resort ad was selected.
0128In response to the selection, the user is provided with information about how the content item was selected, including preference information used to determine the selection that was inferred about the user or was explicitly received from the user. (388). For example, after the user selects Transparency Control 294, a Transparency pop-up 296 can be displayed to provide information about the user's privacy settings. The information can identify interests (eg, travel and sea), and the corresponding identifiers to which the interests are associated. The transparency pop-up 296 may also include a privacy setting control 298, which the user can select to access an interface whose privacy settings can be changed, such as the interface associated with the privacy management system 115.
0129FIG. 4 is a block diagram of a computing device 400, a computing device 450 that can be used to implement the systems and methods described herein as a client, or server or servers. The computing device 400 is intended to represent various forms of digital computers such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other suitable computers. The computing device 400 is further intended to represent any other typical non-mobile device, such as a television or other electronic device with one or more processors embedded or connected to it. There is. The computing device 450 is intended to represent various forms of mobile devices such as personal digital assistants, cellular phones, smartphones, and other computing devices. The components shown herein, their connections and relationships, and their functionality are merely exemplary and are meant to limit the implementation of the invention described and / or claimed herein. It's not a thing.
0130The computing device 400 includes a processor 402, a memory 404, a storage device 406, a high speed interface 408 connected to the memory 404 and the fast expansion port 410, and a slow interface 412 connected to the slow bus 414 and the storage device 406. .. The respective components 402, 404, 406, 408, 410, and 412 are interconnected using various buses and can be mounted on a common motherboard or otherwise as needed. Processor 402 processes instructions for execution within the computing device 400, including instructions stored in memory 404 or storage 406, and external input / output devices such as display 416 coupled to high-speed interface 408. Graphical information for the GUI can be displayed above. In other implementations, multiple processors and / or multiple buses can be used with multiple memory and memory types, if desired. It can also connect multiple computing devices 400, each providing some of the required operations (for example, as a server bank, a group of blade servers, or a multiprocessor system).
0131The memory 404 stores information in the computing device 400. In one implementation, the memory 404 is a computer-readable medium. In one implementation, the memory 404 is a volatile memory unit. In another implementation, memory 404 is a non-volatile memory unit.
0132The storage device 406 can provide a large capacity storage device for the computing device 400. In one implementation, the storage device 406 is a computer-readable medium. In a variety of different implementations, the storage device 406 may be a floppy (registered trademark) disk device, hard disk device, optical device, or tape device, flash memory or other similar solid state memory device, or a storage area network. Alternatively, it may be an array of devices including devices in other configurations. In one implementation, the computer program product is explicitly embodied in an information carrier. A computer program product contains instructions that, when executed, perform one or more methods, such as those described above. The information carrier is a computer-readable or machine-readable medium such as memory 404, storage 406, or memory on processor 402.
0133The fast controller 408 manages the bandwidth-intensive operations of the computing device 400, and the slow controller 412 manages the slower bandwidth-intensive operations. Such duty assignments are only exemplary. In one embodiment, the high speed controller 408 is coupled to a memory 404, a display 416 (eg, through a graphics processor or accelerator), and a high speed expansion port 410 that can accept various expansion cards (not shown). In an implementation, the slow controller 412 is coupled to storage 406 and slow expansion port 414. A slow expansion port that can include various communication ports (eg, USB, Bluetooth®, Ethernet®, Wireless Ethernet®) is a keyboard, pointing device, scanner, or switch, for example through a network adapter. Or it can be coupled to one or more input / output devices such as networking devices such as routers.
0134As shown in the drawing, the computing device 400 can be implemented in several different formats. For example, it may be implemented as a standard server 420, or it may be implemented multiple times within a group of such servers. It may also be implemented as part of the rack server system 424. In addition, it may be implemented in a personal computer such as laptop computer 422. Alternatively, components from the computing device 400 may be combined with other components within a mobile device (not shown), such as device 450. Each such device can include one or more computing devices 400, computing devices 450, and the entire system is a plurality of computing devices 400, computing devices 450 communicating with each other. It may be configured.
0135The computing device 450 includes, among other components, input / output devices such as a processor 452, a memory 464, a display 454, a communication interface 466, and a transceiver 468. To provide additional storage, device 450 may also include storage devices such as microdrives or other devices. The respective components 450, 452, 464, 454, 466, and 468 are interconnected using various buses, some of which are on a common motherboard or, as needed, others. Can be mounted in a way.
0136Processor 452 can process instructions for execution within the computing device 450, including instructions stored in memory 464. The processor can also include other analog and digital processors. The processor can provide applications run by the device 450 and wireless communication by the device 450 for tuning other components of the device 450, for example controlling the user interface.
0137The processor 452 can communicate with the user through the control interface 458 and the display interface 456 coupled to the display 454. The display 454 may be, for example, a TFT LCD display or OLED display, or other suitable display technology. The display interface 456 may include suitable circuitry for driving the display 454 to display graphical and other information to the user. The control interface 458 can receive commands from the user and translate those commands for submission to processor 452. In addition, an external interface 462 that communicates with processor 452 may be provided to allow short-range communication between device 450 and other devices. External interface 462 can, for example, provide wired communication (eg, via a docking procedure) or wireless communication (eg, via Bluetooth or other such technology).
0138Memory 464 stores information in computing device 450. In one implementation, memory 464 is a computer-readable medium. In one implementation, memory 464 is a volatile memory unit. In another implementation, memory 464 is a non-volatile memory unit. Extended memory 474 may be provided and connected to device 450 through extended interface 472, which may include, for example, a subscriber identification module (SIM) card interface. Such extended memory 474 can provide extra storage space for device 450 and can also store applications or other information for device 450. Specifically, the extended memory 474 can include instructions for executing or complementing the above-mentioned processing, and can also include secure information. Thus, for example, extended memory 474 may be provided as a security module for device 450 and may be programmed with instructions that allow safe use of device 450. In addition, secure applications may be provided via the SIM card, such as placing identification information on the SIM card in a non-hacking manner, along with further information.
0139As described below, the memory may include, for example, flash memory and / or MRAM memory. In one implementation, the computer program product is explicitly embodied in an information carrier. A computer program product contains instructions that, when executed, perform one or more methods, such as those described above. The information carrier is a computer-readable or machine-readable medium such as memory 464, extended memory 474, or memory on processor 452.
0140The device 450 can communicate wirelessly through a communication interface 466, which may optionally include a digital signal processing circuit. Communication interface 466 specifically provides communication such as GSM® voice call, SMS, EMS, or MMS messaging, CDMA, TDMA, PDC, WCDMA®, CDMA2000, or GPRS under various modes or protocols. can do. Such communication can occur, for example, through the radio frequency transceiver 468. In addition, short-range communications can occur using Bluetooth, Wi-Fi, or other such transceivers (not shown). In addition, the GPS receiver module 470 can provide the device 450 with additional wireless data that can be used as needed by the application running on the device 450.
0141The device 450 can also communicate audibly using a voice codec 460 that can receive verbal information from the user and convert that information into usable digital information. The voice codec 460 can likewise generate audible sound for the user, for example through a speaker in the handset of device 450. Such voice can include voice from a voice call, can include recorded voice (eg, voice messages, music files, etc.) and is generated by an application running on device 450. Can also include audio.
0142As shown in the drawings, the computing device 450 can be implemented in several different forms. For example, the computing device 450 can be implemented as a cellular phone 480. The computing device 450 may also be implemented as part of a smartphone 482, a personal digital assistant, or other mobile device.
0143Various implementations of the systems and techniques described herein include digital electronic circuits, integrated circuits, specially designed ASICs (application specific integrated circuits), computer hardware, firmware, software, and / or theirs. It can be realized by combination. These various implementations have been combined to receive data and instructions from the storage system, at least one input device, and at least one output device, and have been combined to send data and instructions there. It may include implementations in one or more computer programs that are executable and / or interpretable on a programmable system that includes at least one programmable processor, dedicated or general purpose.
0144These computer programs (also known as programs, software, software applications, or code) include machine instructions for programmable processors, in high-level procedural and / or object-oriented programming languages, and / or assembly. Can be implemented in a language / machine language. As used herein, the terms "machine-readable medium", "computer-readable medium", transfer machine instructions and / or data to a programmable processor that includes a machine-readable medium that receives machine instructions as a machine-readable signal. Refers to any computer program product, device, and / or device used to provide (eg, magnetic disk, optical disk, memory, programmable logical device (PLD)). The term "machine readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.
0145To provide user interaction, the systems and techniques described herein are used in display devices (eg, CRT (Brown Tube) or LCD (Liquid Display) monitors) for displaying information to the user, and thereby. It can be implemented on a computer that has a keyboard and pointing device (eg, a mouse or trackball) that allows the user to provide input to the computer. Other types of devices can also be used to provide user interaction. For example, the feedback provided to the user may be any form of sensory feedback (eg, visual feedback, auditory feedback, or tactile feedback), and the user input may be any, including acoustic, audio, or tactile input. May be received in the form of.
0146The systems and techniques described herein include back-end components (eg, as a data server), middleware components (eg, application servers), or front-end components (eg, the user, as described herein). A computing system that includes a client computer with a graphical user interface or web browser that can interact with the implementations of the systems and techniques described), or any combination of such back-end, middleware, or front-end components. Can be implemented in. The components of the system can be interconnected by digital data communication of any form or medium (eg, a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), and the Internet.
0147A computing system can include clients and servers. In general, clients and servers are separated from each other and generally interact through a communication network. The client-server relationship arises from the effectiveness of computer programs that are running on their respective computers and have a client-server relationship with each other.
0148Although the present specification includes details of many specific implementations, these should not be construed as a limitation of the scope of any invention or claims, but rather a particular implementation of a particular invention. Should be interpreted as an explanation of the unique function of. Also, certain features described herein in the context of individual implementations can be implemented in combination with a single implementation. Conversely, the various features described in the context of a single implementation may be implemented separately in multiple implementations or in any suitable subcombination. In addition, the features are described above as working in a particular combination, initially claimed as such, but in some cases from a combination of one or more features from the claimed combination. It can be deleted and the claims can cover sub-combinations or variations of sub-combinations.
0149Similarly, the operations are shown in the drawings in a particular order, but to achieve the desired result, such operations are performed in the particular order or sequential order shown, or illustrated. It should not be understood as requiring all actions to be performed. In certain situations, multitasking and parallelism may be advantageous. Moreover, the separation of the various system components in the implementations described above should not be understood as requiring such separation in all implementations, and the program components and systems described are generally single. It should be understood that it may be integrated into a software product or packaged into multiple software products.
0150So far, we have described specific implementations of this subject. Other implementations are within the scope of the following claims. In some cases, the actions described in the claims may be performed in a different order, yet the desired result can be achieved. Moreover, the processes shown in the accompanying drawings do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain implementations, multitasking and parallelism may be advantageous.
0151102 network 104 website 105 resources 106 User device 106 Fourth device 106 Fifth device 106a First device 106b Second different device 106c Third different device 108 Content Sponsor 109 Issuer 110 Content management system 112 Search system 114 Indexed cache 115 Privacy management system 116 search query 118 Search results
19 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US2009018904A1 | Cites | United States of America | X | Search report | 14-16,24-27 |
| JP2011003155A | Cites | Japan | X | Search report | 1,7 |
| JP6215309B2 | Cites | Japan | X | Search report | 2,7,17-23,26 |
32 members in 6 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 13458124 | United States of America | – | |
| 201213458124 | United States of America | A | |
| 13538782 | United States of America | – | |
| 201213538782 | United States of America | A |
Members32
| Document | Office | Kind | |
|---|---|---|---|
| US2013290503A1 | United States of America | A1 | |
| US2013290711A1 | United States of America | A1 | |
| US2013291123A1 | United States of America | A1 | |
| WO2013163575A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013163578A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013163593A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US8688984B2 | United States of America | B2 | |
| CA2871785A1 | Canada | A1 | |
| AU2013251347A1 | Australia | A1 | |
| US8892685B1 | United States of America | B1 | |
| KR20150008881A | Republic of Korea | A | |
| US8966043B2 | United States of America | B2 | |
| US8978158B2 | United States of America | B2 | |
| JP2015517163A | Japan | A | |
| US2015170200A1 | United States of America | A1 | |
| US2015242896A1 | United States of America | A1 | |
| US9147200B2 | United States of America | B2 | |
| US9258279B1 | United States of America | B1 | |
| US9514446B1 | United States of America | B1 | |
| US2017017804A1 | United States of America | A1 | |
| AU2013251347B2 | Australia | B2 | |
| US2017206552A1 | United States of America | A1 | |
| AU2017232043A1 | Australia | A1 | |
| JP6215309B2 | Japan | B2 | |
| JP2017228317AThis record | Japan | A | |
| US9881301B2 | United States of America | B2 | |
| US9940481B2 | United States of America | B2 | |
| US2018114035A1 | United States of America | A1 | |
| AU2017232043B2 | Australia | B2 | |
| US10114978B2 | United States of America | B2 | |
| KR102038637B1 | Republic of Korea | B1 | |
| JP6629804B2 | Japan | B2 |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2017228317
- Application
- 179951
Titles2
- Japanese
- 数のデバイスにわたるプライバシー管理
- English
- Privacy management across multiple devices
Classification
- CPC, 12
- G06Q30/0255
- G06F21/105
- G06F21/6245
- H04L63/0227
- H04L63/0407
- G06Q30/0257
- G06Q30/0269
- H04L63/20
- H04L63/06
- H04L67/535
- G06F21/00
- G06Q30/00
- IPC, 3
- G06Q30 06
- H04L9 08
- G06F21 62