IP Library › Granted Patent US 12,052,227
Granted Patent B2
US 12,052,227 · App. 17/794,146 · Granted Jul 30, 2024

Privacy-preserving techniques for content selection and distribution

Inventors: Gang Wang (Jersey City, NJ); Marcel M. Moti Yung (New York, NY)
Assignee: Google LLC
H04L63/0421G06F21/6254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,227
App. No.
17/794,146
Granted
Jul 30, 2024
Kind
B2
Abstract

This document describes systems and techniques for improving the integrity and protecting the security of information in content selection and distribution. In one aspect, a method includes receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selection value. In response to receiving the request, the first server conducts, in collaboration with a second server of the secure MPC system, a privacy-preserving selection process and a counterfactual selection process. The first server transmits a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process and receives, from the application on the client device, a notification indicating that a digital component corresponding to the winning selection value from the privacy-preserving selection process was presented at the client device.

Claims (77)

1. A computer-implemented method comprising:

receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selection value;

in response to receiving the request and by the first server of the secure MPC system:

conducting, in collaboration with a second server of the secure MPC system, a privacy-preserving selection process to select a first winning selection value from among a set of selection values by applying each rule of a set of selection rules, including a privacy-preserving anonymity enforcement rule; and

conducting, in collaboration with the second server of the secure MPC system, a counterfactual selection process to select a second winning selection value from among the set of selection values by applying each rule of the set of selection rules, except for the privacy-preserving anonymity enforcement rule;

transmitting, by the first server of the secure MPC system, a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process;

receiving, by the first server of the secure MPC system and from the application on the client device, a notification comprising data indicating that a digital component corresponding to the winning selection value from the privacy-preserving selection process was presented at the client device; and

updating, by the first server of the secure MPC system, a privacy-preserving data structure for determining whether digital components satisfy the privacy-preserving anonymity enforcement rule that maintains a first value for a privacy-preserving characteristic corresponding to the second winning selection value from the counterfactual selection process.

2. The method of claim 1 , wherein conducting the privacy-preserving selection process and conducting the counterfactual selection process are performed in parallel.

3. The method of claim 1 , wherein the notification further comprises a variable that indicates whether the first server of the secure MPC system should increment a value of the privacy-preserving data structure.

4. The method of claim 1 , wherein the privacy-preserving anonymity enforcement rule is a k-anonymity rule.

5. The method of claim 1 , wherein transmitting the winning selection value from the privacy-preserving selection process comprises:

transmitting, by the first server of the secure MPC system, a first secret share of the winning selection value from the privacy-preserving selection process to the client device;

transmitting, by the second server of the secure MPC system, a second secret share of the winning selection value from the privacy-preserving selection process to the client device; and

wherein transmitting the winning selection value from the counterfactual selection process comprises:

transmitting, by the first server of the secure MPC system, a first secret share of the winning selection value from the counterfactual selection process to the client device; and

transmitting, by the second server of the secure MPC system, a second secret share of the winning selection value from the counterfactual selection process to the client device.

6. The method of claim 1 , wherein the privacy-preserving data structure comprises a set of counter variables;

wherein each counter variable is mapped to an aggregate identifier,

wherein each aggregate identifier is mapped to one or more selection values and a particular digital component, and

wherein conducting the privacy-preserving selection process to select a first winning selection value from among a set of selection values by applying each rule of a set of selection rules, including a privacy-preserving anonymity enforcement rule comprises:

for each selection value:

comparing a counter variable value that is mapped to an aggregate identifier that is mapped to the selection value to a threshold; and

discarding the selection value if the counter variable value is less than the threshold.

7. The method of claim 6 , wherein updating the privacy-preserving data structure is performed asynchronously and at a specified time interval.

8. A system comprising:

one or more processors; and

one or more memory elements including instructions that, when executed, cause the one or more processors to perform operations including:

receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selection value;

in response to receiving the request and by the first server of the secure MPC system:

conducting, in collaboration with a second server of the secure MPC system, a privacy-preserving selection process to select a first winning selection value from among a set of selection values by applying each rule of a set of selection rules, including a privacy-preserving anonymity enforcement rule; and

conducting, in collaboration with the second server of the secure MPC system, a counterfactual selection process to select a second winning selection value from among the set of selection values by applying each rule of the set of selection rules, except for the privacy-preserving anonymity enforcement rule;

transmitting, by the first server of the secure MPC system, a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process;

receiving, by the first server of the secure MPC system and from the application on the client device, a notification comprising data indicating that a digital component corresponding to the winning selection value from the privacy-preserving selection process was presented at the client device; and

updating, by first server of the secure MPC system, a privacy-preserving data structure for determining whether digital components satisfy the privacy-preserving anonymity enforcement rule that maintains a first value for a privacy-preserving characteristic corresponding to the second winning selection value from the counterfactual selection process.

9. The system of claim 8 , wherein conducting the privacy-preserving selection process and conducting the counterfactual selection process are performed in parallel.

10. The system of claim 8 , wherein the notification further comprises a variable that indicates whether the first server of the secure MPC system should increment a value of the privacy-preserving data structure.

11. The system of claim 8 , wherein the privacy-preserving anonymity enforcement rule is a k-anonymity rule.

12. The system of claim 8 , wherein transmitting the winning selection value from the privacy-preserving selection process comprises:

transmitting, by the first server of the secure MPC system, a first secret share of the winning selection value from the privacy-preserving selection process to the client device;

transmitting, by the second server of the secure MPC system, a second secret share of the winning selection value from the privacy-preserving selection process to the client device; and

wherein transmitting the winning selection value from the counterfactual selection process comprises:

transmitting, by the first server of the secure MPC system, a first secret share of the winning selection value from the counterfactual selection process to the client device; and

transmitting, by the second server of the secure MPC system, a second secret share of the winning selection value from the counterfactual selection process to the client device.

13. The system of claim 8 , wherein the privacy-preserving data structure comprises a set of counter variables;

wherein each counter variable is mapped to an aggregate identifier,

wherein each aggregate identifier is mapped to one or more selection values and a particular digital component, and

wherein conducting the privacy-preserving selection process to select a first winning selection value from among a set of selection values by applying each rule of a set of selection rules, including a privacy-preserving anonymity enforcement rule comprises:

for each selection value:

comparing a counter variable value that is mapped to an aggregate identifier that is mapped to the selection value to a threshold; and

discarding the selection value if the counter variable value is less than the threshold.

14. The system of claim 13 , wherein updating the privacy-preserving data structure is performed asynchronously and at a specified time interval.

15. A non-transitory computer storage medium encoded with instructions that when executed by a distributed computing system cause the distributed computing system to perform operations comprising:

receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selection value;

in response to receiving the request and by the first server of the secure MPC system:

conducting, in collaboration with a second server of the secure MPC system, a privacy-preserving selection process to select a first winning selection value from among a set of selection values by applying each rule of a set of selection rules, including a privacy-preserving anonymity enforcement rule; and

conducting, in collaboration with the second server of the secure MPC system, a counterfactual selection process to select a second winning selection value from among the set of selection values by applying each rule of the set of selection rules, except for the privacy-preserving anonymity enforcement rule;

transmitting, by the first server of the secure MPC system, a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process;

receiving, by the first server of the secure MPC system and from the application on the client device, a notification comprising data indicating that a digital component corresponding to the winning selection value from the privacy-preserving selection process was presented at the client device; and

updating, by first server of the secure MPC system, a privacy-preserving data structure for determining whether digital components satisfy the privacy-preserving anonymity enforcement rule that maintains a first value for a privacy-preserving characteristic corresponding to the second winning selection value from the counterfactual selection process.

16. The non-transitory computer storage medium of claim 15 , wherein conducting the privacy-preserving selection process and conducting the counterfactual selection process are performed in parallel.

17. The non-transitory computer storage medium of claim 15 , wherein the notification further comprises a variable that indicates whether the first server of the secure MPC system should increment a value of the privacy-preserving data structure.

18. The non-transitory computer storage medium of claim 15 , wherein the privacy-preserving anonymity enforcement rule is a k-anonymity rule.

19. The non-transitory computer storage medium of claim 15 , wherein transmitting the winning selection value from the privacy-preserving selection process comprises:

transmitting, by the first server of the secure MPC system, a first secret share of the winning selection value from the privacy-preserving selection process to the client device;

transmitting, by the second server of the secure MPC system, a second secret share of the winning selection value from the privacy-preserving selection process to the client device; and

wherein transmitting the winning selection value from the counterfactual selection process comprises:

transmitting, by the first server of the secure MPC system, a first secret share of the winning selection value from the counterfactual selection process to the client device; and

transmitting, by the second server of the secure MPC system, a second secret share of the winning selection value from the counterfactual selection process to the client device.

20. The non-transitory computer storage medium of claim 15 , wherein the privacy-preserving data structure comprises a set of counter variables;

wherein each counter variable is mapped to an aggregate identifier,

wherein each aggregate identifier is mapped to one or more selection values and a particular digital component, and

wherein conducting the privacy-preserving selection process to select a first winning selection value from among a set of selection values by applying each rule of a set of selection rules, including a privacy-preserving anonymity enforcement rule comprises:

for each selection value:

comparing a counter variable value that is mapped to an aggregate identifier that is mapped to the selection value to a threshold; and

discarding the selection value if the counter variable value is less than the threshold.

21. The non-transitory computer storage medium of claim 20 , wherein updating the privacy-preserving data structure is performed asynchronously and at a specified time interval.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2022
From: WANG, GANG; YUNG, MARCEL M. MOTI
To: GOOGLE LLC
Reel/Frame 060638/0907 →
Priority Claims (1)
IL 279406 · Dec 13, 2020 · national
Continuity (1)
Related Publication 20230072957A1 · Mar 9, 2023
Cited By (1)
US 12,438,850