IP Library › Granted Patent US 12,401,502
Granted Patent B2
US 12,401,502 · App. 17/919,566 · Granted Aug 26, 2025

Flexible content selection processes using secure multi-party computation

Inventors: Gang Wang (Frederick, MD); Marcel M. Moti Yung (New York, NY)
Assignee: Google LLC
H04L9/085H04L2209/466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,502
App. No.
17/919,566
Granted
Aug 26, 2025
Kind
B2
Abstract

This document relates to using secure MPC to select digital components in ways that preserve user privacy and protects the security of data of each party that is involved in the selection process. In one aspect, a method includes receiving, by a first server of a secure MPC system from a client device, a digital component request. The first server identifies, for each digital component in a set, a selection value and a priority tier. For each tier, the first server determines, using a secure MPC process in collaboration with one or more second servers of the secure MPC system, a first secret share of a winner parameter for each digital component in the priority tier. The first server identifies a highest tier for which a given digital component has a winner parameter that indicates that the given digital component is a winning digital component.

Claims (76)

1. A computer-implemented method comprising:

receiving, by a first server of a secure multi-party computation (MPC) system and from a client device, a digital component request;

identifying, for each digital component in a set of digital components, a selection value for the digital component and a priority tier for the digital component;

identifying a selection value floor established by a publisher of an electronic resource for which the digital component request was received;

filtering, from the set of digital components, one or more digital components having a selection value that is less than the selection value floor;

for each of a plurality of priority tiers:

determining, using a secure MPC process in collaboration with one or more second servers of the secure MPC system, a first secret share of a winner parameter for each digital component in the priority tier, comprising:

determining, for each digital component in the priority tier, a first secret share of a candidate parameter that indicates whether the digital component is a candidate for selection; and

determining the first secret share of the winner parameter for each digital component in the priority tier based on (i) the first secret share of a value of the candidate parameter for each digital component in the priority tier, (ii) one or more second secret shares of the candidate parameter for each digital component in the priority tier, and the selection value for each digital component in the priority tier;

identifying a highest priority tier of the plurality of priority tiers for which a given digital component of the set of digital components has a winner parameter that indicates that the given digital component is a winning digital component for the tier; and

generating a first secret share of a selection result identifying the given digital component; and

providing the first secret share of the selection result to the client device.

2. The computer-implemented method of claim 1 , wherein determining, using the secure MPC process in collaboration with one or more second servers of the secure MPC system, the first secret share of the winner parameter for each digital component in the priority tier comprises determining the first secret share of the winner parameter for each digital component in each priority tier in parallel.

3. The computer-implemented method of claim 1 , wherein determining, using the secure MPC process in collaboration with one or more second servers of the secure MPC system, the first secret share of the winner parameter for each digital component in the priority tier comprises determining the first secret share of the winner parameter for each digital component in each priority tier in a sequence from a highest priority tier to a lowest priority tier.

4. The computer-implemented method of claim 1 , wherein determining, for each digital component in the priority tier, a first secret share of a candidate parameter that indicates whether the digital component is a candidate for selection comprises determining, in collaboration with each of the one or more second servers, the first secret share of the candidate parameter for a particular digital component based on secret shares for one or more conditions for the particular digital component.

5. The computer-implemented method of claim 1 , wherein identifying, for each digital component in the set of digital components, the selection value for the digital component comprises:

identifying, for a given content platform, a boost established by a publisher of an electronic resource for which the digital component request was received or a content platform for the publisher; and

adjusting the selection value for each digital component of the content platform using the boost.

6. The computer-implemented method of claim 1 , wherein determining a secret share of the winner parameter for each digital component in the priority tier comprises:

ordering the digital components in the priority tier based on the selection value for each digital component in the priority tier;

determining, a first secret share of an accumulated value for each digital component in the tier based at least on the order and the first secret share of the candidate parameter for each digital component in the priority tier, wherein the accumulated value for a digital component indicates a quantity of candidate digital components in the priority tier having a higher selection value than the digital component; and

for each digital component in the priority tier, determining the first secret share of the winner parameter for the digital component based on the first secret share of the candidate parameter for the digital component, each of the one or more second secret shares of the candidate parameter for the digital component, and the accumulated value for the digital component.

7. The computer-implemented method of claim 6 , further comprising determining a second selection value corresponding to a second value selection process, comprising:

determining, for each priority tier, a first secret share of a winning tier parameter that represents whether the given digital component is included in the priority tier;

determining, for each digital component in the set of digital components, a first secret share of a second selection value parameter that represents whether the selection value for the digital component might be second highest selection value among a set of candidate digital components; and

identifying, as the second selection value, a selection value for a digital component for which (i) the candidate parameter for the digital component indicates that the digital component is a candidate for selection, (ii) the winning tier parameter indicates that the given digital component is included in the winning tier, and (iii) the second selection value parameter that indicates that the selection value for the digital component might be second highest selection value among a set of candidate digital components.

8. A system comprising:

a first server comprising one or more processors; and

one or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, by the first server of a secure multi-party computation (MPC) system and from a client device, a digital component request;

identifying, for each digital component in a set of digital components, a selection value for the digital component and a priority tier for the digital component;

identifying a selection value floor established by a publisher of an electronic resource for which the digital component request was received;

filtering, from the set of digital components, one or more digital components having a selection value that is less than the selection value floor;

for each of a plurality of priority tiers:

determining, using a secure MPC process in collaboration with one or more second servers of the secure MPC system, a first secret share of a winner parameter for each digital component in the priority tier, comprising:

determining, for each digital component in the priority tier, a first secret share of a candidate parameter that indicates whether the digital component is a candidate for selection; and

determining the first secret share of the winner parameter for each digital component in the priority tier based on (i) the first secret share of a value of the candidate parameter for each digital component in the priority tier, (ii) one or more second secret shares of the candidate parameter for each digital component in the priority tier, and the selection value for each digital component in the priority tier;

identifying a highest priority tier of the plurality of priority tiers for which a given digital component of the set of digital components has a winner parameter that indicates that the given digital component is a winning digital component for the tier; and

generating a first secret share of a selection result identifying the given digital component; and

providing the first secret share of the selection result to the client device.

9. The system of claim 8 , wherein determining, using the secure MPC process in collaboration with one or more second servers of the secure MPC system, the first secret share of the winner parameter for each digital component in the priority tier comprises determining the first secret share of the winner parameter for each digital component in each priority tier in parallel.

10. The system of claim 8 , wherein determining, using the secure MPC process in collaboration with one or more second servers of the secure MPC system, the first secret share of the winner parameter for each digital component in the priority tier comprises determining the first secret share of the winner parameter for each digital component in each priority tier in a sequence from a highest priority tier to a lowest priority tier.

11. The system of claim 8 , wherein determining, for each digital component in the priority tier, a first secret share of a candidate parameter that indicates whether the digital component is a candidate for selection comprises determining, in collaboration with each of the one or more second servers, the first secret share of the candidate parameter for a particular digital component based on secret shares for one or more conditions for the particular digital component.

12. The system of claim 8 , wherein identifying, for each digital component in the set of digital components, the selection value for the digital component comprises:

identifying, for a given content platform, a boost established by a publisher of an electronic resource for which the digital component request was received or a content platform for the publisher; and

adjusting the selection value for each digital component of the content platform using the boost.

13. The system of claim 8 , wherein determining a secret share of the winner parameter for each digital component in the priority tier comprises:

ordering the digital components in the priority tier based on the selection value for each digital component in the priority tier;

determining, a first secret share of an accumulated value for each digital component in the tier based at least on the order and the first secret share of the candidate parameter for each digital component in the priority tier, wherein the accumulated value for a digital component indicates a quantity of candidate digital components in the priority tier having a higher selection value than the digital component; and

for each digital component in the priority tier, determining the first secret share of the winner parameter for the digital component based on the first secret share of the candidate parameter for the digital component, each of the one or more second secret shares of the candidate parameter for the digital component, and the accumulated value for the digital component.

14. The system of claim 13 , wherein the operations comprise determining a second selection value corresponding to a second value selection process, comprising:

determining, for each priority tier, a first secret share of a winning tier parameter that represents whether the given digital component is included in the priority tier;

determining, for each digital component in the set of digital components, a first secret share of a second selection value parameter that represents whether the selection value for the digital component might be second highest selection value among a set of candidate digital components; and

identifying, as the second selection value, a selection value for a digital component for which (i) the candidate parameter for the digital component indicates that the digital component is a candidate for selection, (ii) the winning tier parameter indicates that the given digital component is included in the winning tier, and (iii) the second selection value parameter that indicates that the selection value for the digital component might be second highest selection value among a set of candidate digital components.

15. A non-transitory computer readable storage medium carrying instructions that, when executed by one or more processors of a first server, cause the one or more processors to perform operations comprising:

receiving, by a first server of a secure multi-party computation (MPC) system and from a client device, a digital component request;

identifying, for each digital component in a set of digital components, a selection value for the digital component and a priority tier for the digital component;

identifying a selection value floor established by a publisher of an electronic resource for which the digital component request was received;

filtering, from the set of digital components, one or more digital components having a selection value that is less than the selection value floor;

for each of a plurality of priority tiers:

determining, using a secure MPC process in collaboration with one or more second servers of the secure MPC system, a first secret share of a winner parameter for each digital component in the priority tier, comprising:

determining, for each digital component in the priority tier, a first secret share of a candidate parameter that indicates whether the digital component is a candidate for selection; and

determining the first secret share of the winner parameter for each digital component in the priority tier based on (i) the first secret share of a value of the candidate parameter for each digital component in the priority tier, (ii) one or more second secret shares of the candidate parameter for each digital component in the priority tier, and the selection value for each digital component in the priority tier;

identifying a highest priority tier of the plurality of priority tiers for which a given digital component of the set of digital components has a winner parameter that indicates that the given digital component is a winning digital component for the tier; and

generating a first secret share of a selection result identifying the given digital component; and

providing the first secret share of the selection result to the client device.

16. The non-transitory computer readable storage medium of claim 15 , wherein determining, using the secure MPC process in collaboration with one or more second servers of the secure MPC system, the first secret share of the winner parameter for each digital component in the priority tier comprises determining the first secret share of the winner parameter for each digital component in each priority tier in parallel.

17. The non-transitory computer readable storage medium of claim 15 , wherein determining, using the secure MPC process in collaboration with one or more second servers of the secure MPC system, the first secret share of the winner parameter for each digital component in the priority tier comprises determining the first secret share of the winner parameter for each digital component in each priority tier in a sequence from a highest priority tier to a lowest priority tier.

18. The non-transitory computer readable storage medium of claim 15 , wherein determining, for each digital component in the priority tier, a first secret share of a candidate parameter that indicates whether the digital component is a candidate for selection comprises determining, in collaboration with each of the one or more second servers, the first secret share of the candidate parameter for a particular digital component based on secret shares for one or more conditions for the particular digital component.

19. The non-transitory computer readable storage medium of claim 15 , wherein identifying, for each digital component in the set of digital components, the selection value for the digital component comprises:

identifying, for a given content platform, a boost established by a publisher of an electronic resource for which the digital component request was received or a content platform for the publisher; and

adjusting the selection value for each digital component of the content platform using the boost.

20. The non-transitory computer readable storage medium of claim 15 , wherein determining a secret share of the winner parameter for each digital component in the priority tier comprises:

ordering the digital components in the priority tier based on the selection value for each digital component in the priority tier;

determining, a first secret share of an accumulated value for each digital component in the tier based at least on the order and the first secret share of the candidate parameter for each digital component in the priority tier, wherein the accumulated value for a digital component indicates a quantity of candidate digital components in the priority tier having a higher selection value than the digital component; and

for each digital component in the priority tier, determining the first secret share of the winner parameter for the digital component based on the first secret share of the candidate parameter for the digital component, each of the one or more second secret shares of the candidate parameter for the digital component, and the accumulated value for the digital component.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2023
From: WANG, GANG; YUNG, MARCEL M. MOTI
To: GOOGLE LLC
Reel/Frame 063416/0811 →
Priority Claims (1)
IL 281328 · Mar 8, 2021 · national
Continuity (1)
Related Publication 20230171091A1 · Jun 1, 2023
References Cited (48)
US 9577829B1 · Roth · 2017 [cited by examiner]
US 9679314B1 · Wang · 2017 [cited by applicant]
US 10635824B1 · Triandopoulos · 2020 [cited by examiner]
US 11023595B1 · Allen · 2021 [cited by examiner]
US 20170264531A1 · Mahyar · 2017 [cited by examiner]
US 20180109612A1 · Zhong et al. · 2018 [cited by applicant]
US 20190205568A1 · Veugen · 2019 [cited by examiner]
US 20190311138A1 · Harris · 2019 [cited by examiner]
US 20200126143A1 · Chen et al. · 2020 [cited by applicant]
US 20210067315A1 · Mitchell et al. · 2021 [cited by applicant]
US 20210203492A1 · Soares de Resende · 2021 [cited by examiner]
US 20210406386A1 · Ortiz · 2021 [cited by examiner]
US 20240022392A1 · Wang et al. · 2024 [cited by applicant]
CN 106209366 · 2016 [cited by applicant]
CN 109359957 · 2019 [cited by applicant]
JP 2000057157 · 2000 [cited by applicant]
JP 2008518570 · 2008 [cited by applicant]
JP 2010146269 · 2010 [cited by applicant]
JP 2011519080 · 2011 [cited by applicant]
JP 2012033088 · 2012 [cited by applicant]
JP 2014534546 · 2014 [cited by applicant]
JP 2015532737 · 2015 [cited by applicant]
JP 2016510912 · 2016 [cited by applicant]
JP 2019527427 · 2019 [cited by applicant]
WO WO2018135334 · 2018 [cited by applicant]
WO WO2019063503 · 2019 [cited by applicant]
WO WO2020159591 · 2020 [cited by applicant]
Office Action in Israel Appln. No. 281329, dated Jun. 27, 2023, 3 pages. [cited by applicant]
Office Action in Israel Appln. No. 281328, mailed on Aug. 9, 2023, 4 pages. [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2022-556203, mailed on Dec. 25, 2023, 5 pages (with English translation). [cited by applicant]
Notice of Allowance in Japanese Appln. No. 2022-570376, mailed on Jan. 22, 2024, 5 pages (with English translation). [cited by applicant]
Office Action in Japanese Appln. No. 2022-556203, mailed on Nov. 27, 2023, 4 pages (with English translation). [cited by applicant]
Takashi Nishide others—the [ with the structure of an automatic tie breaker ]—a M+ univalent rank code auction system and 2014 Code, collection [ of information security symposium summaries ], Japan, Institute of Electr… [cited by applicant]
Alvarez et al., “Comprehensive survey on privacy-preserving protocols for sealed-bid auctions.” Computers & Security 88, Apr. 3, 2019, 14 pages. [cited by applicant]
Ardian Poernomo, “Dovekey” Submitted on Sep. 23, 2020, <https://github.com/google/ads-privacy/tree/master/proposals/dovekey>, 7 pages. [cited by applicant]
Garay et al., “A little honesty goes a long way.” Theory of Cryptography Conference. Springer, Berlin, Heidelberg, Mar. 2015, 134-158. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2022/019169, dated Jun. 13, 2022, 14 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2022/019171, dated Jun. 15, 2022, 14 pages. [cited by applicant]
Kikuchi et al., “Distributed auction servers resolving winner and winning bid without revealing privacy of bids.” Proceedings Seventh International Conference on Parallel and Distributed Systems: Workshops. IEEE, Jul. 4… [cited by applicant]
Kikuchi, “(M+ 1) st-price auction protocol.” IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences 85.3, Mar. 2002, 676-683. [cited by applicant]
Lindell, “Secure multiparty computation.” Communications of the ACM 64.1, Dec. 17, 2020, 86-96. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2022/019169, mailed on Sep. 21, 2023, 8 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2022/019171, mailed on Sep. 21, 2023, 8 pages. [cited by applicant]
Extended European Search Report in European Appln. No. 24195469.2, mailed on Oct. 31, 2024, 7 pages. [cited by applicant]
Office Action in Chinese Appln. No. 202280003163.8, mailed on Dec. 20, 2024, 15 pages (with English translation). [cited by applicant]
Office Action in Indian Appln. No. 202227059806, mailed on Mar. 24, 2025, 8 pages (with English translation). [cited by applicant]
Office Action in Chinese Appln. No. 202280004253.9, mailed on May 29, 2025, 11 pages (with English translation). [cited by applicant]
Office Action in Korean Appln. No. 10-2022-7039722, mailed on May 15, 2025, 14 pages (with English translation). [cited by applicant]