IP Library › Granted Patent US 12,309,260
Granted Patent B2
US 12,309,260 · App. 18/664,809 · Granted May 20, 2025

Aggregating encrypted network values

Inventors: Gang Wang (Frederick, MD); Marcel M. Moti Yung (New York, NY)
Assignee: Google LLC
H04L9/0825H04L9/008H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,260
App. No.
18/664,809
Granted
May 20, 2025
Kind
B2
Abstract

Methods, systems, and apparatus, including a method for determining network measurements. In some respects, a method includes receiving, by a first aggregation server and from each of multiple client devices, encrypted impression data. A second aggregation server received from each of at least a portion of the multiple client devices, conversion data that includes, for each conversion recorded by the client device, encrypted conversion value data. The first aggregation server and the second aggregation server perform a multi-party computation process to decrypt the encrypted impression data and the encrypted conversion data.

Claims (67)

1. A computer-implemented method, comprising:

receiving, by a first aggregation server and from each of multiple client devices, impression data that includes, for each impression of a digital component recorded by the client device, (i) a first join key that is based on a unique identifier associated with the impression, and (ii) encrypted impression data for the impression;

encrypting, by the first aggregation server, the first join key for each impression;

providing, by the first aggregation server and to a second aggregation server, a first tuple of data for each impression, wherein the first tuple of data for an impression comprises the encrypted first join key and the encrypted impression data for the impression;

receiving, by the first aggregation server and from the second aggregations server, a second tuple of data for each conversion for which the second aggregation server received encrypted conversion data, wherein the second tuple of data for a conversion comprises an encrypted second join key and the encrypted conversion data for the conversion, wherein each encrypted second join key is based on a unique identifier associated with the conversion;

determining, by the first aggregation server and for each of multiple digital components, an impression count based on a number of encrypted first tuples that include encrypted impression data corresponding to an impression of the digital component;

determining, by the first aggregation server and for each of the multiple digital components, a conversion count based on a number of encrypted second tuples that include encrypted conversion data corresponding to a conversion of the digital component; and

sending, by the first aggregation server and to a recipient, data indicating the impression count and the conversion count.

2. The method of claim 1 , wherein the unique identifier associated with each impression comprises one of (i) an identifier of a client device at which the impression occurred, (ii) an identifier of a user that viewed the digital component of the impression, (iii) a cryptographic hash of an e-mail address of the user, (iv) a cryptographic hash of a phone number of the user, or (v) a cryptographic hash of sign in credentials of the user.

3. The method of claim 1 , wherein the unique identifier associated with each conversion comprises one of (i) an identifier of a client device at which the conversion occurred, (ii) an identifier of a user that completed the conversion, (iii) a cryptographic hash of an e-mail address of the user, (iv) a cryptographic hash of a phone number of the user, or (v) a cryptographic hash of sign in credentials of the user.

4. The method of claim 1 , further comprising:

identifying, using the first join keys and the second join keys, pairs of first tuples of data and second tuples of data for which the first join key of the first tuple of data matches the second join key of the second tuple of data; and

identifying, for a given pair of a first tuple of data and a second tuple of data, each other pair for which the encrypted impression data and the encrypted conversion data of the first tuple of data and the second tuple of data matches the encrypted impression data and the encrypted conversion data of the given pair; and

identifying a number of unique first join keys across the given pair and each other pair; and

providing, as cross conversion data, the number of unique join keys.

5. The method of claim 4 , further comprising, prior to providing the cross conversion data:

comparing the number of unique first join keys to a k-anonymity threshold; and

providing, to a reporting system, the cross conversion data in response to determining that number of unique first join keys satisfies the k-anonymity threshold.

6. The method of claim 1 , further comprising:

comparing the impression count for each digital component of the multiple digital components to a k-anonymity threshold; and

providing each impression count that satisfies the k-anonymity threshold to a reporting system.

7. The method of claim 1 , further comprising:

comparing the conversion count for each digital component of the multiple digital components to a k-anonymity threshold; and

providing each conversion count that satisfies the k-anonymity threshold to a reporting system.

8. The method of claim 1 , wherein the encrypted conversion data for each conversion comprises a thrice-encrypted conversion value that is encrypted first using a probabilistic homomorphic additive public key encryption technique, encrypted second using a public key of the second aggregation server, and encrypted third using a public key of the first aggregation server.

9. A system comprising:

a first aggregation server comprising one or more processors; and

one or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, by the first aggregation server and from each of multiple client devices, impression data that includes, for each impression of a digital component recorded by the client device, (i) a first join key that is based on a unique identifier associated with the impression, and (ii) encrypted impression data for the impression;

encrypting, by the first aggregation server, the first join key for each impression;

providing, by the first aggregation server and to a second aggregation server, a first tuple of data for each impression, wherein the first tuple of data for an impression comprises the encrypted first join key and the encrypted impression data for the impression;

receiving, by the first aggregation server and from the second aggregations server, a second tuple of data for each conversion for which the second aggregation server received encrypted conversion data, wherein the second tuple of data for a conversion comprises an encrypted second join key and the encrypted conversion data for the conversion, wherein each encrypted second join key is based on a unique identifier associated with the conversion;

determining, by the first aggregation server and for each of multiple digital components, an impression count based on a number of encrypted first tuples that include encrypted impression data corresponding to an impression of the digital component;

determining, by the first aggregation server and for each of the multiple digital components, a conversion count based on a number of encrypted second tuples that include encrypted conversion data corresponding to a conversion of the digital component; and

sending, by the first aggregation server and to a recipient, data indicating the impression count and the conversion count.

10. The system of claim 9 , wherein the unique identifier associated with each impression comprises one of (i) an identifier of a client device at which the impression occurred, (ii) an identifier of a user that viewed the digital component of the impression, (iii) a cryptographic hash of an e-mail address of the user, (iv) a cryptographic hash of a phone number of the user, or (v) a cryptographic hash of sign in credentials of the user.

11. The system of claim 9 , wherein the unique identifier associated with each conversion comprises one of (i) an identifier of a client device at which the conversion occurred, (ii) an identifier of a user that completed the conversion, (iii) a cryptographic hash of an e-mail address of the user, (iv) a cryptographic hash of a phone number of the user, or (v) a cryptographic hash of sign in credentials of the user.

12. The system of claim 9 , wherein the operations comprise:

identifying, using the first join keys and the second join keys, pairs of first tuples of data and second tuples of data for which the first join key of the first tuple of data matches the second join key of the second tuple of data; and

identifying, for a given pair of a first tuple of data and a second tuple of data, each other pair for which the encrypted impression data and the encrypted conversion data of the first tuple of data and the second tuple of data matches the encrypted impression data and the encrypted conversion data of the given pair; and

identifying a number of unique first join keys across the given pair and each other pair; and

providing, as cross conversion data, the number of unique join keys.

13. The system of claim 12 , wherein the operations comprise, prior to providing the cross conversion data:

comparing the number of unique first join keys to a k-anonymity threshold; and

providing, to a reporting system, the cross conversion data in response to determining that number of unique first join keys satisfies the k-anonymity threshold.

14. The system of claim 9 , wherein the operations comprise:

comparing the impression count for each digital component of the multiple digital components to a k-anonymity threshold; and

providing each impression count that satisfies the k-anonymity threshold to a reporting system.

15. The system of claim 9 , wherein the operations comprise:

comparing the conversion count for each digital component of the multiple digital components to a k-anonymity threshold; and

providing each conversion count that satisfies the k-anonymity threshold to a reporting system.

16. The system of claim 9 , wherein the encrypted conversion data for each conversion comprises a thrice-encrypted conversion value that is encrypted first using a probabilistic homomorphic additive public key encryption technique, encrypted second using a public key of the second aggregation server, and encrypted third using a public key of the first aggregation server.

17. A non-transitory computer readable storage medium carrying instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, by a first aggregation server and from each of multiple client devices, impression data that includes, for each impression of a digital component recorded by the client device, (i) a first join key that is based on a unique identifier associated with the impression, and (ii) encrypted impression data for the impression;

encrypting, by the first aggregation server, the first join key for each impression;

providing, by the first aggregation server and to a second aggregation server, a first tuple of data for each impression, wherein the first tuple of data for an impression comprises the encrypted first join key and the encrypted impression data for the impression;

receiving, by the first aggregation server and from the second aggregations server, a second tuple of data for each conversion for which the second aggregation server received encrypted conversion data, wherein the second tuple of data for a conversion comprises an encrypted second join key and the encrypted conversion data for the conversion, wherein each encrypted second join key is based on a unique identifier associated with the conversion;

determining, by the first aggregation server and for each of multiple digital components, an impression count based on a number of encrypted first tuples that include encrypted impression data corresponding to an impression of the digital component;

determining, by the first aggregation server and for each of the multiple digital components, a conversion count based on a number of encrypted second tuples that include encrypted conversion data corresponding to a conversion of the digital component; and

sending, by the first aggregation server and to a recipient, data indicating the impress ion count and the conversion count.

18. The non-transitory computer readable storage medium of claim 17 , wherein the unique identifier associated with each impression comprises one of (i) an identifier of a client device at which the impression occurred, (ii) an identifier of a user that viewed the digital component of the impression, (iii) a cryptographic hash of an e-mail address of the user, (iv) a cryptographic hash of a phone number of the user, or (v) a cryptographic hash of sign in credentials of the user.

19. The non-transitory computer readable storage medium of claim 17 , wherein the unique identifier associated with each conversion comprises one of (i) an identifier of a client device at which the conversion occurred, (ii) an identifier of a user that completed the conversion, (iii) a cryptographic hash of an e-mail address of the user, (iv) a cryptographic hash of a phone number of the user, or (v) a cryptographic hash of sign in credentials of the user.

20. The non-transitory computer readable storage medium of claim 17 , wherein the operations comprise:

identifying, using the first join keys and the second join keys, pairs of first tuples of data and second tuples of data for which the first join key of the first tuple of data matches the second join key of the second tuple of data; and

identifying, for a given pair of a first tuple of data and a second tuple of data, each other pair for which the encrypted impression data and the encrypted conversion data of the first tuple of data and the second tuple of data matches the encrypted impression data and the encrypted conversion data of the given pair; and

identifying a number of unique first join keys across the given pair and each other pair; and

providing, as cross conversion data, the number of unique join keys.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2024
From: WANG, GANG; YUNG, MARCEL M. MOTI
To: GOOGLE LLC
Reel/Frame 067580/0965 →
Priority Claims (1)
IL 272520 · Feb 6, 2020 · national
Continuity (2)
Continuation 17418469
Related Publication 20240297783A1 · Sep 5, 2024
References Cited (63)
US 9565020B1 · Camenisch et al. · 2017 [cited by applicant]
US 9641332B1 · Yung et al. · 2017 [cited by applicant]
US 10565524B2 · Bellala · 2020 [cited by examiner]
US 20140095297A1 · O'Reilly · 2014 [cited by applicant]
US 20140115321A1 · Isshiki · 2014 [cited by examiner]
US 20160094540A1 · Camenisch et al. · 2016 [cited by applicant]
US 20170353855A1 · Joy · 2017 [cited by examiner]
US 20180276661A1 · Van Wingerden · 2018 [cited by examiner]
US 20180316495A1 · Wall · 2018 [cited by examiner]
US 20180337899A1 · Becker · 2018 [cited by examiner]
US 20180373882A1 · Veugen · 2018 [cited by applicant]
US 20190013950A1 · Becker · 2019 [cited by examiner]
US 20190205568A1 · Veugen · 2019 [cited by applicant]
US 20200151356A1 · Rohloff · 2020 [cited by examiner]
US 20200403781A1 · Gentry et al. · 2020 [cited by applicant]
US 20220376900A1 · Wang · 2022 [cited by examiner]
CN 108965230 · 2018 [cited by applicant]
CN 110612696 · 2019 [cited by applicant]
EP 3455995 · 2019 [cited by applicant]
EP 3506547 · 2019 [cited by applicant]
EP 3506547A1 · 2019 [cited by examiner]
EP 3506550 · 2019 [cited by applicant]
JP 2015517163 · 2015 [cited by applicant]
KR 101677803 · 2016 [cited by applicant]
WO WO2015025916 · 2015 [cited by applicant]
WO WO2017194469 · 2017 [cited by applicant]
WO WO2017194469A1 · 2017 [cited by examiner]
WO WO2019020830 · 2019 [cited by applicant]
WO WO2019020830A1 · 2019 [cited by examiner]
Form keys to databases—Real world application of secure multi party computing (Year: 2018). [cited by examiner]
Archer et al., “From keys to databases—real-world applications of secure multi-party computation,” International Association For Cryptologic Research, Nov. 2018, 61(12):1-32. [cited by applicant]
Data Tracker.ietf.org [online], “Oblivious Pseudorandom Functions (OPRFs) using Prime-Order Groups,” Mar. 2018, retrieved on Jun. 30, 2021, retrieved from URL<https://datatracker.ietf.org/doc/draft-sullivan-cfrg-voprf/>… [cited by applicant]
Gajek et al., “Trustless, Censorship-Resilient and Scalable Votings in the Permission-based Blockchain Model,” International Association For Cryptologic Research, Jun. 2019, 24 pages. [cited by applicant]
GitHub.com [online], “Attribution Reporting API with Aggregate Reports,” Aug. 2019, retrieved on Jun. 30, 2021, retrieved from URL<https://github.com/WICG/conversion-measurement-api/blob/main/AGGREGATE.md>, 13 pages. [cited by applicant]
GitHub.com [online], “Attribution Reporting API,” Jul. 2020, retrieved on Jun. 30, 2021, retrieved from URL<https://github.com/WICG/conversion-measurement-api/blob/main/README.md#conversion-registration>, 3 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2020/064839, mailed on Aug. 18, 2022, 10 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2020/064839, mailed on Mar. 31, 2021, 17 pages. [cited by applicant]
Ion et al., “On Deploying Secure Computing Commercially: Private Intersection-Sum Protocols and their Business Applications” IACR Cryptol. ePrint Arch, Jan. 2019, 48 pages. [cited by applicant]
Li et al., “Provably private data anonymization: Or, k-anonymity meets differential privacy,” CoRR, abs/1101.2604, Jan. 2011, 49(55):1-12. [cited by applicant]
Libert et al., “Linearly homomorphic structure-preserving signatures and their applications,” Designs, Codes and Cryptography, Dec. 2015, 77(2):1-31. [cited by applicant]
Liu et al., “Towards Private and Efficient Ad Impression Aggregation in Mobile Advertising” 2019 IEEE International Conference on Communications, May 2019, 6 pages. [cited by applicant]
Notice of Allowance in Chinese Appln. No. 202080009404.0 mailed on May 22, 2023, 8 pages (with English translation). [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2021-540866, mailed on Sep. 5, 2022, 5 pages (with English translation). [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2022-161054, mailed on Nov. 13, 2023, 5 pages (with English translation). [cited by applicant]
Notice of Allowance in Korean Appln. No. 10-2021-7020668, mailed on Aug. 29, 2023, 4 pages (with English translation). [cited by applicant]
Oauth.net [online], “An open protocol to allow secure authorization in a simple and standard method from web, mobile and desktop applications,” Jan. 2020, retrieved on Jun. 30, 2021, retrieved from URL<https://oauth.net… [cited by applicant]
Office Action in Chinese Appln. No. 202080009404.0, mailed on Oct. 27, 2022, 24 pages (with English translation). [cited by applicant]
Office Action in Indian Appln. No. 202127027875, mailed on Sep. 9, 2022, 6 pages (with English translation). [cited by applicant]
Office Action in Israel Appln. No. 272520, mailed on Sep. 5, 2022, 3 pages. [cited by applicant]
Office Action in Korean Appln. No. 10-2021-7020668, mailed on Mar. 20, 2023, 8 pages (with English translation). [cited by applicant]
Sako et al., “Semantic Security,” Encyclopedia of Cryptography and Security, 2011, 1176-1177. [cited by applicant]
Support.google.com [online], “Sync your account settings,” 2021, retrieved on Jun. 30, 2021, retrieved from URL<https://support.google.com/chromebook/answer/2914794?hl-en>, 2 pages. [cited by applicant]
Veugen et al., “Efficient coding for secure computing with additively-homomorphic encrypted data,” Int. J. Applied Cryptography, May 2019, 10:1-15. [cited by applicant]
Wikipedia.org [online], “Commutative property,” Jul. 2019, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Commutative_property>, 10 pages. [cited by applicant]
Wikipedia.org [online], “Differential Privacy,” Feb. 2020, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Differential_privacy>, 11 pages. [cited by applicant]
Wikipedia.org [online], “Diffie-Hellman key exchange,” Aug. 2020, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exchange>, 11 pages. [cited by applicant]
Wikipedia.org [online], “Homomorphic encryption,” Sep. 2020, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Homomorphic_encryption>, 12 pages. [cited by applicant]
Wikipedia.org [online], “Paillier cryptosystem,” Dec. 2014, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Paillier_cryptosystem>, 5 pages. [cited by applicant]
Wikipedia.org [online], “Secret sharing,” Jan. 2019, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Secret_sharing>, 8 pages. [cited by applicant]
Wikipedia.org [online], “Secure multi-party computation,” Feb. 2019, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Secure_multi- party_computation>, 11 pages. [cited by applicant]
Wikipedia.org [online], “Sybil attack,” Dec. 2018, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Sybil_attack>, 6 pages. [cited by applicant]
Wikipedia.org [online], “Threshold Cryptosystem,” Apr. 2012, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Threshold_cryptosystem>, 3 pages. [cited by applicant]
Wikipedia.org [online], “Variance,” Apr. 2020, retrieved on Jun. 30, 2021, retrieved from URL<https://en.wikipedia.org/wiki/Variance>, 21 pages. [cited by applicant]