IP Library › Granted Patent US 12,438,850
Granted Patent B2
US 12,438,850 · App. 18/744,187 · Granted Oct 7, 2025

Privacy-preserving techniques for content selection and distribution

Inventors: Gang Wang (Frederick, MD); Marcel M. Moti Yung (New York, NY)
Assignee: Google LLC
H04L63/0421G06F21/6254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,850
App. No.
18/744,187
Granted
Oct 7, 2025
Kind
B2
Abstract

This document describes systems and techniques for improving the integrity and protecting the security of information in content selection and distribution. In one aspect, a method includes receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selection value. In response to receiving the request, the first server conducts, in collaboration with a second server of the secure MPC system, a privacy-preserving selection process and a counterfactual selection process. The first server transmits a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process and receives, from the application on the client device, a notification indicating that a digital component corresponding to the winning selection value from the privacy-preserving selection process was presented at the client device.

Claims (44)

1. A computer-implemented method comprising:

receiving, by a first computer and from an application of a client device, a request for a digital component;

in response to receiving the request:

conducting, by the first computer in collaboration with a second computer, a privacy-preserving selection process using a secure multi-party computation (MPC) protocol to select a first digital component from among a set of digital components by evaluating each rule of a set of selection rules for each digital component, including a privacy-preserving anonymity enforcement rule for each digital component; and

conducting, by the first computer in collaboration with the second computer, a counterfactual selection process using the secure MPC protocol to select a second digital component from among the set of digital components by evaluating each rule of the set of selection rules for each digital component, except for the privacy-preserving anonymity enforcement rule for each digital component;

sending, by the first computer and to the client device, a selection result defining the first digital component; and

updating, by the first computer, a privacy-preserving data structure to indicate that the second digital component was selected by the counterfactual selection process.

2. The computer-implemented method of claim 1 , wherein conducting the privacy-preserving selection process and conducting the counterfactual selection process are performed in parallel.

3. The method of claim 1 , wherein sending the selection result comprises sending, by the first computer and to the client device, a first secret share of data indicating the first digital component.

4. The method of claim 3 , wherein the second computer sends, to the client device, a second secret share of the data indicating the first digital component.

5. The method of claim 3 , wherein:

the selection result comprises a first share of data indicating the second digital component; and

the second computer sends, to the client device, a second secret share of the data indicating the second digital component.

6. The method of claim 1 , wherein updating, by the first computer, a privacy-preserving data structure to indicate that the second digital component was selected by the counterfactual selection process comprises updating a count of a number of times the second digital component has been selected by counterfactual selection processes.

7. The method of claim 6 , further comprising updating the privacy-preserving anonymity enforcement rule for the second digital component to indicate that the second digital component is eligible for subsequent privacy-preserving selection processes in response to the count satisfying a threshold.

8. The method of claim 1 , wherein updating, by the first computer, a privacy-preserving data structure to indicate that the second digital component was selected by the counterfactual selection process comprises updating a count of a number of users for which the second digital component has been selected by counterfactual selection processes performed to select digital components for the users.

9. The method of claim 8 , further comprising updating the privacy-preserving anonymity enforcement rule for the second digital component to indicate that the second digital component is eligible for subsequent privacy-preserving selection processes in response to the count satisfying a threshold.

10. A system comprising:

a first computer comprising one or more processors; and

one or more memory elements including instructions that, when executed, cause the one or more processors to perform operations including:

receiving, by the first computer and from an application of a client device, a request for a digital component;

in response to receiving the request:

conducting, by the first computer in collaboration with a second computer, a privacy-preserving selection process using a secure multi-party computation (MPC) protocol to select a first digital component from among a set of digital components by evaluating each rule of a set of selection rules for each digital component, including a privacy-preserving anonymity enforcement rule for each digital component; and

conducting, by the first computer in collaboration with the second computer, a counterfactual selection process using the secure MPC protocol to select a second digital component from among the set of digital components by evaluating each rule of the set of selection rules for each digital component, except for the privacy-preserving anonymity enforcement rule for each digital component;

sending, by the first computer and to the client device, a selection result defining the first digital component; and

updating, by the first computer, a privacy-preserving data structure to indicate that the second digital component was selected by the counterfactual selection process.

11. The system of claim 10 , wherein conducting the privacy-preserving selection process and conducting the counterfactual selection process are performed in parallel.

12. The system of claim 10 , wherein sending the selection result comprises sending, by the first computer and to the client device, a first secret share of data indicating the first digital component.

13. The system of claim 12 , wherein the second computer sends, to the client device, a second secret share of the data indicating the first digital component.

14. The system of claim 13 , wherein:

the selection result comprises a first share of data indicating the second digital component; and

the second computer sends, to the client device, a second secret share of the data indicating the second digital component.

15. The system of claim 10 , wherein updating, by the first computer, a privacy-preserving data structure to indicate that the second digital component was selected by the counterfactual selection process comprises updating a count of a number of times the second digital component has been selected by counterfactual selection processes.

16. The system of claim 15 , wherein the operations comprise updating the privacy-preserving anonymity enforcement rule for the second digital component to indicate that the second digital component is eligible for subsequent privacy-preserving selection processes in response to the count satisfying a threshold.

17. The system of claim 10 , wherein updating, by the first computer, a privacy-preserving data structure to indicate that the second digital component was selected by the counterfactual selection process comprises updating a count of a number of users for which the second digital component has been selected by counterfactual selection processes performed to select digital components for the users.

18. The system of claim 17 , wherein the operations comprise updating the privacy-preserving anonymity enforcement rule for the second digital component to indicate that the second digital component is eligible for subsequent privacy-preserving selection processes in response to the count satisfying a threshold.

19. A non-transitory computer storage medium encoded with instructions that when executed by a first computer cause the first computer to perform operations comprising:

receiving, by the first computer and from an application of a client device, a request for a digital component;

in response to receiving the request:

conducting, by the first computer in collaboration with a second computer, a privacy-preserving selection process using a secure multi-party computation (MPC) protocol to select a first digital component from among a set of digital components by evaluating each rule of a set of selection rules for each digital component, including a privacy-preserving anonymity enforcement rule for each digital component; and

conducting, by the first computer in collaboration with the second computer, a counterfactual selection process using the secure MPC protocol to select a second digital component from among the set of digital components by evaluating each rule of the set of selection rules for each digital component, except for the privacy-preserving anonymity enforcement rule for each digital component;

sending, by the first computer and to the client device, a selection result defining the first digital component; and

updating, by the first computer, a privacy-preserving data structure to indicate that the second digital component was selected by the counterfactual selection process.

20. The non-transitory computer storage medium claim 19 , wherein conducting the privacy-preserving selection process and conducting the counterfactual selection process are performed in parallel.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2024
From: WANG, GANG; YUNG, MARCEL M. MOTI
To: GOOGLE LLC
Reel/Frame 068088/0903 →
Priority Claims (1)
IL 279406 · Dec 13, 2020 · national
Continuity (2)
Continuation 17794146
Related Publication 20240414136A1 · Dec 12, 2024
References Cited (33)
US 9679314B1 · Wang · 2017 [cited by examiner]
US 10078656B1 · Carl · 2018 [cited by examiner]
US 12052227B2 · Wang · 2024 [cited by examiner]
US 20040225681A1 · Chaney · 2004 [cited by examiner]
US 20120011538A1 · Yarvis et al. · 2012 [cited by applicant]
US 20180365043A1 · Kaufman · 2018 [cited by examiner]
US 20200311300A1 · Callcut et al. · 2020 [cited by applicant]
CN 111125736 · 2020 [cited by applicant]
CN 112041811 · 2020 [cited by applicant]
JP 2013140510 · 2013 [cited by applicant]
JP 2016517069 · 2016 [cited by applicant]
JP 2016157454 · 2016 [cited by applicant]
JP 2017054539 · 2017 [cited by applicant]
KR 1020200019061 · 2020 [cited by applicant]
KR 1020200121106 · 2020 [cited by applicant]
WO WO2007101973 · 2007 [cited by applicant]
WO WO2018124729 · 2018 [cited by applicant]
WO WO2020144768 · 2020 [cited by applicant]
Shang et al., “A privacy-preserving approach to policy-based content dissemination”, 2010 IEEE 26th International Conference on Data Engineering (ICDE 2010), Date of Conference: Mar. 1-6, 2010. [cited by examiner]
Guerriero et al., “Defining, Enforcing and Checking Privacy Policies In Data-Intensive Applications”, 2018 ACM/IEEE 13th International Symposium on Software Engineering for Adaptive and Self-Managing Systems, pp. 172-18… [cited by examiner]
Notice of Allowance in Korean Appln. No. 10-2022-7021324, mailed on Dec. 5, 2024, 5 pages (with English translation). [cited by applicant]
Breaux et al., “Analyzing Regulatory Rules for Privacy and Security Requirements” IEEE Transactions On Software Engineering, vol. 34, No. 1, Jan./Feb., Jan./Feb. 2008, 5-20. [cited by applicant]
Extended European Search Report in European Appln. No. 22182700.9, mailed on Aug. 3, 2022, 8 pages. [cited by applicant]
Helsloot et al., “Badass: Preserving privacy in behavioural advertising with applied secret sharing.” 12th International Conference on Provable Security, Aug. 14, 2018, 1-23. [cited by applicant]
IBM, “Method for selecting advertisements respecting user privacy” May 8, 2009, 7 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2021/062880, mailed on Jun. 22, 2023, 9 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2021/062880, mailed on Mar. 25, 2022, 15 pages. [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2022-540742, mailed on Feb. 19, 2024, 5 pages (with English translation). [cited by applicant]
Office Action in Israel Appln. No. 279406, mailed on May 4, 2023, 4 pages. [cited by applicant]
Office Action in Japanese Appln. No. 2022-540742, mailed on Oct. 23, 2023, 13 pages (with English translation). [cited by applicant]
Wikipedia.org [online], “Private information retrieval”, Nov. 2004, retrieved on Oct. 3, 2022, retrieved from URL <https://en.wikipedia.org/wiki/Private_information_retrieval>, 4 pages. [cited by applicant]
Office Action in Indian Appln. No. 202227031951, mailed on Feb. 17, 2025, 6 pages (with English translation). [cited by applicant]
Office Action in Chinese Appln. No. 202180008029.2, mailed on Apr. 27, 2025, 10 pages (with English translation). [cited by applicant]