Securing information access in online interactions
By utilizing the user group request system and employing k-anonymity and encryption technologies, user privacy is protected while reducing the computational and network burden on the content platform. This resolves the conflict between user privacy protection and the content selection process, achieving efficient user privacy protection and content selection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-20
- Publication Date
- 2026-04-14
AI Technical Summary
While existing technologies can protect user privacy, they are insufficient to effectively prevent content platforms from accessing user information, which may negatively impact user experience.
A user group request system is adopted, in which the trusted party maintains the user group membership data. Through k-anonymity, encryption, batch processing and buffering technologies, it is ensured that the user group identifier is not directly exposed to the content platform during the content selection process, thereby reducing the computational and network burden and protecting user privacy.
It effectively protects user privacy, reduces the impact of the content selection process on user experience, lowers the computational burden and network bandwidth consumption of the content platform, and improves the timeliness and accuracy of content delivery.
Smart Images

Figure CN114651254B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims priority to Israel Application No. 277641, filed on September 29, 2020. The disclosure of the aforementioned application is incorporated herein by reference in its entirety. Technical Field
[0003] This manual relates to data processing. Background Technology
[0004] This specification relates to data processing and the maintenance of user privacy, as well as protecting access to information of other entities when analyzing user data.
[0005] k-anonymity is used to ensure that the data of each member in a group is anonymous. For data with the k-anonymity attribute, a member's data cannot be distinguished from the data of the other k-1 members in the group. Summary of the Invention
[0006] Generally, an innovative aspect of the subject matter described in this specification can be embodied in a method comprising receiving a content request from a client device, the content request including a set of request signals specifying user group identifiers, each user group identifier identifying a user group whose members include a user of the client device. One or more user group identifiers satisfying a first k-anonymity process are identified. A selection parameter request including at least one or more of the user group identifiers is sent to each of one or more first content platforms. Selection parameter elements are received from the one or more first content platforms. Each selection parameter request includes data indicating a corresponding digital component and selection parameters for the corresponding digital component. At least a portion of the selection parameters, and for each selection parameter, data identifying the first content platform from which the selection parameter was received, is sent to a second content platform. Data specifying a given first content platform selected based on the selection parameters is received from the second content platform. Data indicating a digital component provided by the given first content platform and selection parameters for the digital component provided by the given first content platform are sent to the client device. Other embodiments of this aspect include corresponding apparatus, systems, and computer programs configured to perform aspects of this method and encoded on a computer storage device.
[0007] These and other implementations can each optionally include one or more of the following features. In some aspects, identifying one or more user group identifiers includes selecting each user group identifier that has been received from a client device, including the client device, at least a threshold number of times during a specified time period as the one or more user group identifiers. Request signals may include context signals. Some aspects may include identifying one or more context signals that satisfy a corresponding k-anonymity procedure and providing the one or more context signals together with a selection parameter request.
[0008] In some respects, sending a selection parameter request, including at least one or more of the user group identifiers, to each of the one or more first content platforms includes: sending a separate selection parameter request to each of the one or more first content platforms for each of the one or more user group identifiers.
[0009] In some aspects, sending at least a portion of the selection parameters to the second content platform includes: identifying a set of selection parameters that satisfy the second k-anonymity process, and sending the set of selection parameters that satisfy the second k-anonymity process as at least a portion of the selection parameters.
[0010] In some respects, the client device sends a second content request to a second content platform. The result of the second content request may include adjusted selection parameters and context signals for each selected digital component. The second platform may select a given digital component from a set of digital components to be presented at the client device, the set of digital components including each selected digital component and one or more additional digital components identified based on context signals independent of any user group identifier.
[0011] In some aspects, each selection parameter element includes a creative element, which includes data indicating the corresponding digital component of the selection parameter element. Each creative element may include one or more categories of the content of the corresponding digital component, a unique identifier of the digital component provider that publishes the corresponding digital component, and a digital signature generated by the second content platform for the creative element. Sending at least a portion of the selection parameters to the second content platform can include selecting a set of digital components based on one or more categories of each creative element, and sending selection parameters for the selected set of digital components as at least a portion of the selection parameters. Selecting a set of digital components based on one or more categories of each creative element can include comparing one or more categories of each creative element with a set of exclusion categories of the electronic resources of the publisher of the requested content for it, and selecting each digital component whose one or more categories do not match any exclusion category in the set of exclusion categories to be included in the set of digital components.
[0012] The subject matter described in this specification can be implemented in specific embodiments to achieve one or more of the following advantages: Adding a user group request computation system operated by a trusted party to a content distribution ecosystem allows user group membership data to be used to select content for users in a privacy-preserving manner, while preventing access to the technology used by the content platform to select or serve content to users, thereby protecting the confidentiality of all entities without negatively impacting the user experience. Instead of maintaining user group memberships on the content platform, such membership data can be securely maintained on the user's client device to protect user privacy regarding membership data. The client device can provide group membership data (e.g., a user group identifier identifying a user group that includes the user as a member) to the user group request system along with the content request, rather than to the content platform.
[0013] To protect user privacy relative to content platforms, the user group request system performs k-anonymization on each user group identifier before providing it to the content platform, preventing the content platform from associating user group identifiers with individual users. Because the user group request system is maintained by a trusted party, all user group identifiers can be sent to the system in a single request, rather than one at a time. This reduces the computational burden on the user group request system and the network bandwidth consumed in sending requests. The use of the user group request system also prevents user group-based requests from directly reaching the content platform. This prevents requests from transmitting any unauthorized target-locking signals to the content platform, such as first-party cookies from browsers or Internet Protocol (IP) addresses from client devices.
[0014] The user group request system can further protect group membership data by sending batch requests to the content platform for multiple client devices, preventing the association of individual requests with individual users based on the timing of the requests. The user group request system can also employ buffering and time delays to further prevent such associations. Furthermore, the user group request system can perform k-anonymization on selection parameters to prevent the content platform from tracking users based on uncommon selection parameters provided for content requests that include a specific set of request signals.
[0015] The user group request system also protects access to the content selection logic used by the content platform (e.g., a provider-side platform (SSP)) when selecting content by enabling content selection to occur on the content platform rather than on the client device. By maintaining and protecting the privacy of user group membership data through the user group request system, user privacy is protected without moving the selection process to the client device, which could expose the content platform's selection logic. Selection parameters can be encrypted by the content platform, such as a demand-side platform (DSP), to prevent other entities from accessing these parameters.
[0016] The user group request system can store creative elements of digital components locally, such as in a cache, to further protect user privacy, reduce latency in providing digital components, reduce the computational burden on the content platform, such as a DSP, and reduce network bandwidth consumption. For example, if the DSP previously provided creative elements and corresponding selection parameters (e.g., bids) for a specific set of request signals (e.g., for a specific user group identifier), the user group request system can cache the creative elements and selection parameters and use the cached data for subsequent content requests with the same request signals. This prevents the provision of request signals to the DSP (e.g., using group identifiers), which protects user privacy, while reducing the number of requests sent to the DSP, which reduces the computational burden on the DSP, reduces network bandwidth consumption, and reduces latency in providing content in response to requests that would otherwise be caused by requesting selection parameters from the DSP. Furthermore, by batching requests delivered to the content platform, user privacy is protected as described above, the computational burden on the DSP is reduced by decreasing the number of requests processed by the DSP in each time period, and network bandwidth consumption is reduced by decreasing the number of requests sent over the network. Reducing content delivery latency also reduces the number of errors occurring on the user's device while waiting for such content to arrive. Since content typically needs to be delivered to wirelessly connected mobile devices within milliseconds, reducing the latency of selecting and delivering content is crucial for preventing errors and minimizing user frustration.
[0017] The various features and advantages of the foregoing subject matter are described below with reference to the accompanying drawings. Additional features and advantages will be apparent from the subject matter and claims described herein. Attached Figure Description
[0018] Figure 1 It is a block diagram of the environment in which content is distributed to client devices.
[0019] Figure 2 This is a swimlane diagram illustrating an example process for selecting content and providing it to a client device.
[0020] Figure 3 This is a flowchart illustrating an example process for selecting content and providing it to a client device.
[0021] Figure 4 This is a block diagram of an example computer system.
[0022] The same reference numerals and names in different figures denote the same elements. Detailed Implementation
[0023] Generally, this document describes systems and technologies for maintaining user privacy and preventing access to information of other entities, such as content platforms, resource publishers, and content providers, when analyzing user data. User group request systems can be used to maintain this privacy and information protection while still allowing content platforms to select and serve content based on a user's user group membership, ensuring that the user experience is not negatively impacted. User group request systems and content platforms can use a combination of k-anonymity, encryption, batch processing, and / or buffering techniques, which, when used together as described below, provide a synergistic effect of maintaining privacy and protecting access to information of each entity involved in the content selection and distribution process.
[0024] Figure 1 This is a block diagram of an environment 100 in which content is distributed to client device 110. Example environment 100 includes a data communication network 105, such as a local area network (LAN), wide area network (WAN), the Internet, a mobile network, or a combination thereof. Network 105 connects client device 110, user group request system 130, demand-side platform (DSP) 150, supplier-side platform (SSP) 170, publisher 140, and website 142. Example environment 100 may include many different client devices 110, user request system 130, DSP 150, SSP 170, publisher 140, and website 142.
[0025] Client device 110 is an electronic device capable of communicating via network 105. Example client device 110 includes a personal computer, a mobile communication device such as a smartphone, and other devices capable of delivering and receiving data via network 105. The client device may also include a digital assistant device that accepts audio input via a microphone and outputs audio via a speaker. When the digital assistant detects a “hotword” or “hotphrase” that activates the microphone to accept audio input, the digital assistant can be put into listening mode (e.g., ready to accept audio input). The digital assistant device may also include a camera and / or display to capture images and visually present information. The digital assistant can be implemented in various forms of hardware devices, including wearable devices (e.g., watches or glasses), smartphones, speaker devices, tablet devices, or other hardware devices. The client device may also include a digital media device, such as a streaming device that plugs into a television or other display to stream video to the television.
[0026] Client device 110 typically includes applications 112, such as web browsers and / or native applications, to facilitate the delivery and reception of data over network 105. Native applications are applications developed for a specific platform or device (e.g., a mobile device with a specific operating system). Publisher 140 is able to develop and provide native applications to client device 110, for example, making them available for download. A web browser can request resource 145 from a web server hosting website 142 of publisher 140, for example, in response to a user of client device 110 entering the resource address of resource 145 in the web browser's address bar or selecting a link referencing the resource address. Similarly, native applications can request application content from a publisher's remote server.
[0027] Some resources, application pages, or other application content can include digital component slots for presenting digital components along with resource 145 or application pages. As used throughout this document, the phrase "digital component" refers to a discrete unit of digital content or digital information (e.g., a video clip, audio clip, multimedia clip, image, text, or another unit of content). Digital components can be stored electronically on a physical storage device as a single file or a collection of files, and can take the form of video files, audio files, multimedia files, image files, or text files, and may include advertising information, making advertising a type of digital component. For example, a digital component can be content designed to complement the content of a webpage or other resource presented by application 112. More specifically, a digital component can include digital content related to the resource content (e.g., a digital component can relate to the same topic as the webpage content, or a related topic). Therefore, the provision of digital components can complement and often enhance webpage or application content.
[0028] When application 112 loads resources (or application content) that include one or more digital component slots, application 112 can request digital components for each slot. In some implementations, the digital component slot can include code (e.g., a script) that causes application 112 to request digital components from a digital component distribution system, which selects digital components and provides them to application 112 for presentation to the user of client device 110.
[0029] Some publishers 140 use SSP 170 to manage the process of acquiring digital components for their resources and / or applications' digital component slots. SSP 170 is a hardware and / or software-implemented technology platform that automates the process of acquiring digital components for resources and / or applications. SSP 170 can interact with one or more DSPs 150 to obtain information that can be used to select digital components for digital component slots. As described in more detail below, this information can include selection parameters representing the amount a digital component provider 160 is willing to offer to publishers 140 for presenting digital components to digital component provider 160. For example, the selection parameter could be a bid. Each publisher 140 may have a corresponding SSP 170 or multiple SSPs 170. Some publishers 140 may use the same SSP 170.
[0030] Digital component provider 160 is capable of creating (or otherwise publishing) digital components that are rendered in digital component slots within the resources and applications of a publisher. Digital component provider 160 can use DSP 150 to manage the provision of its digital components for rendering in the digital component slots. DSP 150 is a hardware and / or software-implemented technology platform that automates the process of distributing digital components for rendering with resources and / or applications. DSP 150 can interact on behalf of digital component provider 160 with multiple SSPs 170 to provide digital components for rendering with resources and / or applications of multiple different publishers 140. Typically, DSP 150 can receive requests for digital components (e.g., directly from SSP 170 or via a switch), generate (or select) selection parameters for one or more digital components created by one or more digital component providers based on the request, and provide data related to the digital component (e.g., the digital component itself) and the selection parameters to SSP 170.
[0031] The way the SSP 170 selects digital components and the way the DSP 150 distributes digital components (e.g., generating selection parameters and / or the selection parameters themselves) typically involves information that should not be shared with other parties. The techniques described in this document protect this information from being shared or disclosed to other parties. The SSP 170 and DSP 150 can also be referred to as content platforms.
[0032] In some cases, receiving digital components related to web pages, application pages, or other electronic resources that a user has previously visited and / or interacted with is beneficial to the user. To distribute such digital components to users, users can be assigned to user groups when they access a specific resource or perform a specific action on that resource (e.g., interacting with a specific item presented on a web page or adding that item to a virtual shopping cart). User groups can be generated by the digital component provider 160. That is, when a user accesses an electronic resource provided by the digital component provider 160, each digital component provider 160 can assign the user to their respective user group.
[0033] To protect user privacy, user group memberships can be maintained at the user's client device 110, for example, by one of the applications 112 (or the device operating system or another trusted program), rather than by the digital component provider, content platform, or other party. In a specific example, a web browser or operating system can maintain a list of user group identifiers ("user group list") for users using the web browser or another application. The user group list can include group identifiers for each user group to which the user has been added. The digital component provider 160 that creates the user groups can assign user group identifiers to their user groups. The user group identifier can be a description of the group (e.g., a gardening group) or a code representing the group (e.g., a non-descriptive alphanumeric sequence). The user's user group list can be stored in secure storage at the client device 110, and / or can be encrypted at storage to prevent others from accessing the list.
[0034] When application 112 presents resources or application content related to web pages on digital component provider 160 or website 142, the resource may request application 112 to add one or more user group identifiers to the user group list. In response, application 112 may add one or more user group identifiers to the user group list and securely store the user group list.
[0035] User group request system 130 enables the use of user group membership when selecting content to be provided to client device 110, while maintaining the privacy of membership data and protecting access to data on DSP 150 and SSP 170. User group request system 130 can be implemented using one or more computing systems maintained by a trusted third party, such as a trusted third party other than the user, SSP 170, DSP 150, publisher 140, and digital component provider 160. For example, industry groups, government groups, or browser developers can maintain and operate user group request system 130.
[0036] User group request system 130 can perform several functions to maintain privacy and protect access to entity information. For example, user group request system 130 can interact with DSP 150 and SSP 170 to select digital components based on user group identifiers using techniques that prevent DSP 150 and SSP 170 from associating users with their user group memberships. To this end, user group request system 130 can perform k-anonymization on the user group identifier before providing it to DSP 150 for selecting digital components and their selection parameters. By doing so, SSP 170 can perform its content selection process itself, rather than moving these processes to client device 110, which could potentially expose its confidential selection process logic. User group request system 130 can also perform k-anonymization on the selection parameters provided by DSP 150 to prevent DSP 150 from using uncommon selection parameters for a particular set of request signals to track the users whose request signals are provided to DSP 150. (See below for further details.) Figure 2 Describe these features in more detail.
[0037] To obtain digital components for the digital component slot, application 112 can be configured to split a content request into two separate requests. Application 112 can deliver a first content request to user group request system 130. This content request can be for digital components selected based on the user's user group membership. The content request can include a user group identifier for the user group to which the user is a member. As described in more detail below, user group request system 130 can interact with DSP 150 and SSP 170 to select one or more digital components for application 112 based on the user group identifier. User group request system 130 can provide application 112 with creative elements and adjusted selection parameters for each selected digital component. The creative elements and adjusted selection parameters are described below.
[0038] Then, application 112 can deliver a second content request to SSP 170. Application 112 can deliver this content request to the SSP 170 of the publisher 140 of the electronic resource for which the requested content is located. This content request can be directed to digital components that will ultimately be presented along with the electronic resource. That is, application 112 may not immediately present the digital components of the creative elements received from the user group request system 130. Instead, these digital components may be candidates provided to SSP 170 for the final selection process.
[0039] The second content request can include adjusted selection parameters for one or more creative elements received from the user group request system 130 in response to the first content request, and context signals that can be used by the DSP 150 to select digital components. The SSP 170 can interact with the DSP 150 to obtain selection parameters for the digital components selected based on the context signals. In this selection, the DSP 150 may not have access to user group membership data. That is, the DSP 150 can select digital components and their corresponding selection parameters based on context signals independent of user group membership.
[0040] SSP 170 can use its content selection logic to select digital components for application 112 from a set of digital components, including one or more digital components selected based on a user group identifier in response to a first content request and digital components selected based on context signals in response to a second content request. SSP 170 can then provide the selected digital components (or data identifying the digital component, or data that can be used to obtain and present the digital component) to application 112 for presentation to the user.
[0041] In some implementations, application 112 may provide a user interface that enables a user to manage the user groups to which the user is assigned. For example, the user interface may enable a user to remove a user group identifier, preventing all or specific resources, publishers, digital component providers, digital component switches, and / or DSP 150 from adding the user to the user group (e.g., preventing entities from adding the user group identifier to the list of user group identifiers maintained by application 112). This provides the user with greater transparency and control.
[0042] Throughout this document, the descriptions may include controls that allow users to make choices regarding whether and when the systems, programs, or features described herein can collect user information (e.g., information about a user's social networks, social actions or activities, occupation, user preferences, or current location), and whether to deliver content or communications to the user from a server. Furthermore, certain data may be processed in one or more ways before being stored or used to remove personally identifiable information. For example, a user's identity may be processed so that personally identifiable information about the user cannot be determined, or the user's geographic location may be generalized (e.g., to a city, zip code, or state level) if location information is available, so that the user's specific location cannot be determined. Therefore, users can control what information about themselves is collected, how that information is used, and what information is provided to them.
[0043] Figure 2This is a swimlane diagram illustrating an example process 200 for selecting content and providing content to client device 110. The operation of process 200 can be implemented, for example, by client device 110, user group request system 130, one or more DSPs 150 and SSPs 170. The operation of process 200 can also be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause one or more data processing devices to perform the operation of process 200.
[0044] In this example, SSP 170 is an SSP used by a specific publisher whose content will be presented along with an electronic resource. That is, SSP 170 is an SSP that manages the process of obtaining digital components for the publisher's resources and / or application's digital component slots, and client device 110 requests content in response to client device 110's application loading the publisher's electronic resources (e.g., a web page or a local application).
[0045] SSP 170 is capable of inspecting digital components before they can be provided for presentation with a publisher's electronic resources, wherein SSP 170 acquires digital components for the publisher's electronic resources. For example, SSP 170 can inspect the content and format of the digital component to ensure it meets various criteria, such as excluding specific types of content, meeting data and / or display size requirements, etc. Each SSP 170 is capable of inspecting and approving / rejecting digital components for its respective publisher.
[0046] If SSP 170 approves a digital component, it can generate a signed creative element for that digital component. The signed creative element can include a content set and a digital signature generated based on that content set. For example, the content set can include creative fragments, a digital component provider identifier (or provider account identifier) that uniquely identifies the provider who created and / or published the digital component (this allows SSP 170 to determine the corresponding DSP 150 for the digital component), creative metadata, the resource locator of SSP 170, and / or the expiration date of the digital signature (e.g., requiring the DSP to periodically resubmit the digital component for revalidation).
[0047] Creative snippets can include the digital component itself (or a resource locator or a link to a server from which the digital component can be downloaded). Creative snippets can also include computer-executable code for rendering the digital component, such as Hypertext Markup Language (HTML) snippets and / or scripts for downloading the digital component from the server and rendering it in a digital component slot. Creative snippets can also include computer-executable code for sending information about the rendering of the digital component to a reporting server, for example, scripts that cause a client device to send information to a reporting server.
[0048] The resource locator for SSP 170 can be the eTLD+1 of the domain used for SSP 170. eTLD+1 is the effective top-level domain (eTLD) plus one more level than the public suffix. An example of eTLD+1 is "example.com", where ".com" is the top-level domain.
[0049] Metadata can include a set of attributes that allow the user group request system 130 to perform publisher-defined exclusions of digital components or DSPs. For example, a publisher may not allow digital components with specific attributes (e.g., content associated with a specific category) to be rendered with its resources. Metadata can include a list of prohibited categories, topics, or other attributes of the digital components that the publisher prohibits.
[0050] In some implementations, SSP 170 is capable of encrypting each attribute and including each encrypted attribute in the creative element of the signature. For example, SSP 170 can encrypt each attribute using a symmetric deterministic encryption algorithm with its own secret key. Thus, only SSP 170 can access the plaintext value of each attribute using the same symmetric encryption algorithm with the same secret key. While asymmetric public / private key encryption / decryption can be used instead of symmetric encryption, this is likely not necessary.
[0051] As described below, the user group request system 130 can use attributes (e.g., in encrypted form) to exclude digital components for the publisher. Even if the attributes are encrypted, the user group request system 130 can still perform the exclusion without determining which attributes the publisher excludes, thus protecting the publisher's confidential information.
[0052] The SSP 170 can create digital signatures by signing the content collection using its asymmetric private key. The recipient of the creative element of the signature can verify the digital signature using the asymmetric public key corresponding to the private key used to generate the signature. If any data in the content collection changes after the digital signature is generated, the verification of the digital signature will fail. The SSP 170 can send the creative element of the signature for each digital component to the DSP 150 of the digital component provider 160 that created / published the digital component.
[0053] Client device 110 sends a user group-based content request (202) to user group request system 130. For example, a web browser running on client device 110 can load resources from a publisher that have one or more digital component slots. In another example, a user can launch a publisher's local application, and the content of that application may include one or more digital component slots. Application 112, which includes digital component slots, can send a user group-based content request.
[0054] In this example process 200, application 112 is able to send two separate content requests. Application 112 can first send a user group-based content request to request one or more digital components based on one or more user groups to which the user of client device 110 is assigned, such as groups including the user as a member. Application 112 can then deliver a contextual content request that requests the digital components based on additional contextual information, and if a digital component is obtained using the user group-based content request, the selection parameters for the digital component are selected based on one or more user groups, and optionally, data identifying the DSP that submitted the selection parameters for the digital component (e.g., information not identifying the digital component or the digital component itself). This allows the contextual content selection process to include digital components selected based on one or more user groups, while maintaining user privacy regarding the user groups to which the user is assigned, and protecting access to information about the DSP / SSP used to select the digital component.
[0055] User group-based content requests can include a set of request signals. This set of request signals can include some contextual signals, but fewer than those included in the contextual content requests described below. For example, a user group content request can include a resource locator, such as a Uniform Resource Locator (URL) for a webpage or a Uniform Resource Identifier (URI) for application content. A user group content request can also include language (e.g., the language used by the application rendering the content) and / or coarse geolocation information indicating the coarse location of the client device 110.
[0056] The request signal set can also include user group identifiers to which the user of client device 110 is assigned. In some implementations, application 112 delivers a corresponding user group-based content request for each user group identifier. Since the user group request system 130 is operated by a trusted party, application 112 is able to deliver a single user group-based content request that includes all (or at least multiple) user group identifiers of the user. Delivering a separate request for each user group identifier reduces battery consumption and the computational burden imposed on client device 110.
[0057] Content requests based on user groups can include encrypted user group identifiers to protect user privacy. Application 112 can encrypt each user group identifier in such a way that only the intended DSP 150 can decrypt it. That is, only the DSP 150 of the digital component provider 160 that generated the user group and assigned users to it can decrypt the user group identifier. For example, the application can use the public key of the intended DSP 150 to encrypt each user group identifier.
[0058] To enable user group request system 130 to perform k-anonymity on user group identifiers—that is, for a user group identifier to be used for content selection, at least k users or their applications must belong to a given user group within a given time period—encryption can be deterministic for the duration of the given time period, but probabilistic over longer periods. One way to achieve this is by relying on a deterministic public-key encryption algorithm that utilizes pseudo-random numbers calculated based on quantized timestamps. For example, if the duration of k-anonymity is one week, application 112 can encrypt each user group identifier using the following formula: Encrypt deterministic (User_Group_Identifier||number_of_weeks_since_epoch,DSP_key). In this example, "Encrypt" deterministic The message is a composite message based on a deterministic public-key cryptographic algorithm. "User_Group_Identifier||number_of_weeks_since_epoch" is the user group identifier and the number of weeks since a historically fixed and well-known time (e.g., Unix time). "DSP_key" is the expected public key of the DSP 150. Therefore, in this formula, the composite message is encrypted using a deterministic public-key cryptographic algorithm and the expected public key of the DSP 150.
[0059] User group request system 130 receives user group-based content requests and performs k-anonymization (204) on the request signal. K-anonymization ensures that the request signal for each user for whom the application sends a user group-based content request is shared among at least K users, thus preventing the unique identification of a single user or a small group of users. When k-anonymization is applied to the request signal, the user group content request can be used from request signals received from multiple client devices over a period of time, such as a day, week, month, etc., from client devices of many different users from whom the user group content request is received.
[0060] In some implementations, the user group request system 130 combines other request signals, such as context signals, to perform k-anonymity for each user group identifier. For example, if a user group content request includes user group identifiers A and B, the user group request system 130 is able to compare the combination of identifier A and the context signal with other combinations including the identifier and the context signal. If at least K unique applications 112 (or unique client devices) have delivered requests including the same combination of identifier A and the context signal, then the combination of identifier A and the context signal satisfies k-anonymity. In this example, the user group request system 130 is able to deliver user group identifier A and the request signal to the DSP 150 of user group identifier A, as described below.
[0061] In some implementations, the user group request system 130 performs k-anonymity for each user group identifier and each request signal. In this example, the user group request system 130 is able to determine the number of applications 112 (or client devices) that deliver content requests with user group identifier A within a time period. If at least k unique applications or client devices deliver requests including identifier A during that time period, then user group identifier A satisfies k-anonymity and can be provided to the DSP 150 for user group identifier A. If the geographic location of the client device also satisfies k-anonymity, then the user group request system 130 can also deliver the geographic location along with each user group identifier that satisfies k-anonymity. If another context signal does not satisfy k-anonymity, then that request signal may not be provided to the DSP 150.
[0062] As mentioned above, user group identifiers can be encrypted. In this example, the user group request system is able to compare the encrypted result of each user group identifier with other encrypted results received from other client devices to determine the number of unique applications or client devices that delivered the user group identifiers.
[0063] User group request system 130 can also ignore user group-based content requests for specific resource locators. For example, user group request system 130 can maintain a list of resource locators (e.g., a list of web pages, websites, or applications that can be presented to users of client device 110), whose content is not selected based on user group identifiers. These resource locators may be for rare and / or sensitive resources; rare resources may be, for example, new resources created for fraudulent purposes, and sensitive resources may be, for example, resources for specific medical conditions.
[0064] User group request system 130 checks content (206) in a cache (or other local storage). The cache may include previous creative elements and corresponding selection parameters provided by DSP 150 for previous content requests. For example, if the DSP provides creative element C and selection parameter P for a request including user group identifier A, user group request system 130 can cache the mapping (or other link or association) between creative element C and its selection parameter P and user group identifier A.
[0065] User group request system 130 can check in a cache for each signal or signal group that satisfies k-anonymity. If a match is found, user group system 130 can use the previous creative element and selection parameter from the cache without sending a selection parameter request to DSP 150, which previously provided the creative element and selection parameter. Continuing the previous example, if a user group-based content request includes a user group identifier A, and user group identifier A satisfies k-anonymity, then user group request system 130 can use creative element C and its selection parameter P in subsequent steps of process 200 without requesting the selection parameter from DSP 150, which previously provided creative element C.
[0066] User group request system 130 sends selection parameter requests (208) to one or more DSPs 150. For each user group identifier that satisfies k-anonymity, user group request system 130 can send a selection parameter request to the DSP 150 of that user group identifier. However, if creative elements and selection parameters already exist in the cache for a given user group identifier and applicable request signals, a selection parameter request may not be delivered for that user group identifier. The selection parameter request delivered to a given DSP 150 can include the user group identifier of that DSP 150 and the request signal that satisfies k-anonymity.
[0067] During a small time window, such as 100 milliseconds (ms) or some other suitable time window, numerous applications running on many client devices can deliver multiple user group content requests to the user group request system 130, all of which are directed to the same DSP 150. In some implementations, the user group request system 130 is capable of generating batch requests for each DSP 150, which include multiple selection parameter requests (or multiple selection parameter requests for data) to the DSP 150. By delivering batch requests, the amount of bandwidth consumed and the computational burden imposed on the DSP 150 can be reduced. This also prevents timing-based attacks by making it difficult for the DSP 150 to associate multiple requests with a given client device or its user.
[0068] In some implementations, the user group request system 130 can delay the delivery of selected parameters for received user group-based content requests by a delay period, which can vary from request to request. This can further reduce the likelihood of a successful time-based attack.
[0069] Each DSP 150 that receives a selection parameter request selects content and determines the selection parameters for the content (210). For example, DSP 150 is capable of receiving a selection parameter request for a user-based content request and identifying the user group identifier and any context signals included in the selection parameter request. DSP 150 is capable of selecting one or more digital components based on the user group identifier and context signals. DSP 150 is also capable of generating or selecting selection parameters for digital components based on the user group identifier and / or context data.
[0070] Each DSP 150 can quantile its determined selection parameter (212). For example, each DSP 150 can maintain a set of quantiles and compare the determined selection parameter with a range of values for each quantile. The DSP 150 can then determine the quantized selection parameter. That is, the DSP 150 can replace the determined selection parameter with the value of a matching quantile that represents the determined selection parameter. For example, if the value of the selection parameter is 9, and there exists a quantile in the range of 7-10 with a quantized value of 8.5, then the DSP can replace the selection parameter with the quantized value of 8.5.
[0071] This quantile technique reduces the number of different selection parameters submitted by DSP 150 to user group request system 130. This makes DSP 150 more likely to submit at least a threshold number, such as k identical selection parameters in a k-anonymity process, ensuring the selection parameters satisfy k-anonymity, as described below. The size of each quantile of DSP 150 can be selected based on the number of times DSP 150 submits selection parameters to user group request system 130. For example, if DSP 150 delivers a large number of selection parameters, the range of values for each quantile can be small because a large number of requests makes it more likely that various quantiles will have a sufficient number of selection parameters.
[0072] DSP 150 sends a selection parameter element (214) to user group request system 130. The selection parameter request delivered by DSP 150 can include creative elements identifying the selected digital component and selection parameters, which can be quantized and / or encrypted.
[0073] The technology used to protect selection parameters can include multiple layers of protection to safeguard DSP 150 and maintain user privacy. For example, only SSP 170 should know the identity of DSP 150 that submitted the highest selection parameter and the corresponding plaintext highest selection parameter. In other cases, plaintext selection parameters from DSP 150 should generally be kept confidential from all parties under any circumstances. Furthermore, the user group requests system 130 to perform k-anonymization on selection parameters from DSP 150 to prevent micro-targeting of users.
[0074] To protect the identity of the DSP 150 that submitted the highest selection parameter and each selection parameter, each DSP 150 can encrypt its selection parameters using an encryption key shared by DSP 150 and SSP 170. Each DSP 150 can use and confidentially maintain an encryption key different from that of each other DSP 150. This encryption algorithm can be a symmetric encryption algorithm. To enable k-anonymity processing on the encrypted selection parameters, the encryption algorithm can also be deterministic. DSP 150 and SSP 170 can establish a shared encryption key via the Diffie-Hellman key exchange algorithm. An example encryption algorithm that can be used to encrypt selection parameters is the Advanced Encryption Standard (AES). In some implementations, each DSP 150 can use an asymmetric encryption algorithm to encrypt its selection parameters using the public key of SSP 170.
[0075] In some implementations, the selection parameter element delivered by each DSP 150 can include additional information to verify the authenticity of the selection parameters and provide better security and privacy protection. For example, the selection parameter request delivered by DSP 150 can include creative elements of the digital component, encrypted quantized selection parameters, a user group identifier for selecting the digital component and any contextual signals received along with the user group identifier, a timestamp, and a random number.
[0076] User group identifiers and context signals enable user group request system 130 to associate selection parameters with appropriate user group-based content requests. A timestamp and a random number can be delivered from user group request system 130 to DSP 150 along with the selection parameter request. The timestamp indicates the time the selection parameter request was delivered to DSP 150. The timestamp and random number can be used to identify individual requests and prevent replay attacks. For example, if multiple selection parameter requests with the same timestamp and random number are received, DSP 150 can determine that it is a copy of a previous request. If multiple selection parameter elements with the same timestamp and random number are received from the same DSP 150, user group request system 130 can make the same determination. If DSP 150 generates timestamps and random numbers, DSP 150 can encode additional information that may weaken security and privacy protections.
[0077] The DSP 150 can also digitally sign selection parameter elements to protect them from tampering or forgery. For example, the DSP 150 can generate a digital signature by signing the content of the selection parameter element using the DSP 150's private key.
[0078] DSP 150 sends a selection parameter element (214) to user group request system 130. If the selection parameter element is digitally signed, user group request system 130 can verify the digital signature using the public key corresponding to the private key of the DSP used to sign the selection parameter element. If the verification fails, user group request system 130 can ignore the selection parameter element.
[0079] User group request system 130 performs k-anonymity (216) on creative elements and selection parameters. User group request system 130 can perform k-anonymity on the selection parameters of each DSP 150. That is, before a selection parameter submitted by DSP 150 can be used to select content for a client device, the selection parameter must have been received from DSP 150 at least a threshold, such as k unique times. This prevents DSP 150 from micro-targeting users with uncommon selection parameter values, and prevents DSP 150 from colluding with SSP 170 to associate additional contextual signals with the user if the selection parameter is returned to SSP along with a contextual content request. User group request system 130 can compare the number of times the selection parameter is received from DSP 150 within a specified time period. If the number satisfies a threshold, for example, by reaching or exceeding a threshold, user group request system 130 can determine that the selection parameter satisfies k-anonymity.
[0080] User group content request 130 can similarly compare the number of times the DSP 150 has provided creative elements with a threshold, such as k. If the number of times satisfies the threshold, for example by reaching or exceeding the threshold, then user group request system 130 can determine that the creative element satisfies k-anonymity. Performing k-anonymity on creative elements also prevents micro-targeting of specific users using specific digital components. The selection parameters and the threshold for creative elements can be the same or different.
[0081] User group request system 130 sends at least a portion of the selection parameters received for a user group-based content request to SSP 170 (218). User group request system 130 is capable of sending only the selection parameters that satisfy k-anonymity and correspond to creative elements that also satisfy k-anonymity. For each selection parameter, user group request system 130 is also capable of sending data identifying the DSP 150 that submitted the selection parameter. In some embodiments, user group request system 130 also delivers the creative element corresponding to the selection parameter along with the selection parameter.
[0082] SSP 170 can select content (220) based on the received selection parameters. As described above, the selection parameters can be encrypted by DSP 150 using an encryption key shared with SSP 170. SSP 170 can decrypt the selection parameters using the corresponding encryption key. SSP 170 can identify the highest selection parameter and select the digital component corresponding to the highest selection parameter.
[0083] The selection parameters provided by DSP 150 can be in the form of a total amount that the digital component provider is willing to provide for the presentation of the digital component, or in the form of a publisher amount that the publisher will receive for the presentation of the digital component. For example, the total amount can be divided among the publisher, DSP 150, and / or SSP 170.
[0084] If DSP 150 needs to provide a publisher amount, SSP 170 can select the highest publisher amount, i.e., the highest selection parameter. However, if DSP 150 needs to provide a total amount, SSP 170 can determine the publisher amount based on various rules and / or selection logic. For example, SSP 170 can look up rules that define how much of the total amount is allocated to that publisher for a particular combination of publisher and DSP 150. In other words, SSP 170 can use the selection parameter sharing protocol between DSP 150 and the publisher to determine the publisher amount for each total amount received from DSP 150. SSP 170 can then select the highest publisher amount. SSP 170 can determine the publisher based on the resource location (e.g., domain or URL) of the resource for which it selects content. The information used to determine the publisher amount is generally confidential. The use of user group request system 130 in environment 100 allows this information to be used at SSP 170 instead of at client device 110, which prevents information leakage.
[0085] In some implementations, SSP 170 can apply exclusions to exclude certain selection parameters of DSP 150 from the content selection process. For example, a publisher may not want content from a particular DSP 150 or digital component provider 160 to be presented along with its electronic resources. Each publisher 140 can provide SSP 170 with data identifying excluded (or included) DSP 150s and / or digital component providers. SSP 170 can apply exclusions based on the resource locator of the resource for which it selects content.
[0086] Publishers may not allow digital components with specific attributes (e.g., content related to a specific category) to be presented with their assets. Publishers' SSP 170 allows defining a set of digital component attributes to support creative exclusion. Such attributes can be represented as a finite discrete set: P = {P1, P2, ..., P...} n SSP 170 can optionally use the SSP's secret encryption key to encrypt these properties using a deterministic symmetric encryption algorithm, similar to how properties can be encrypted to be included in the creative elements of a signature.
[0087] SSP 170 is able to store the set of properties for each publisher locally, such as in a cache.
[0088] For example, SSP 170 can maintain data structures similar to those in Table 1 below.
[0089] Resource Locator Creative exclusion example.com / mainpage <![CDATA[P1,P 41 ,P 90 ]]> example.com / secondpage <![CDATA[P7]]>
[0090] Table 1
[0091] In this table, each attribute (e.g., P1, P...) 41 (etc.) can be the content category of the digital component, the object depicted by the digital component, or other attributes of the digital component. For each resource locator, the set of attributes in the Creative Exclusion column indicates attributes that, if assigned to a digital component, should not be provided for rendering along with the resource corresponding to that resource locator.
[0092] To apply creative exclusion to a selection parameter element, SSP 170 can obtain the set of attributes included in the metadata of the signed creative element from the signed creative element. SSP 170 can then calculate the intersection of the attribute set of the signed creative element and the set of attributes for creative exclusion defined as a resource locator included in the selection parameter element's request identifier. If the intersection is empty, the digital component of the signed creative element is eligible to be rendered with the resource corresponding to that resource locator. Otherwise, SSP 170 can ignore the creative element and its selection parameters.
[0093] SSP 170 requests system 130 to send data (222) indicating the selected content. For example, SSP 170 can send data identifying the DSP 150 that submitted the highest selection parameter, such as the DSP 150 corresponding to the highest publisher amount. SSP 170 may not send the selection parameter in plaintext to maintain the confidentiality of the selection parameter. Instead, only SSP 170 and DSP 150 can access the selection parameter in plaintext form.
[0094] User group request system 130 identifies creative elements corresponding to the selected content and provides these creative elements to application 112 (224) that submitted the user group-based content request. User group request system 130 can also deliver encrypted selection parameters to application 112. For example, user group request system 130 can deliver a user group content response to the user group-based content request. The user group content response can include creative elements and encrypted selection parameters for the creative elements. The user group content response can also include data identifying the DSP that submitted the selection parameters for the creative elements.
[0095] The user group content response can also include a digital signature of the selection parameter element submitted by DSP 150 in response to the selection parameter request. By including this signature, if the digital component of DSP 150 is ultimately selected for presentation by application 112, application 112 can include the digital signature in one or more reports delivered by application 112 to report the presentation of the digital component or user interaction with the digital component. In this way, DSP 150 or its reporting system can verify the signature to ensure that the presentation or user interaction is valid.
[0096] In some implementations, SSP 170 can select multiple digital components in response to a user group-based content request based on selection parameters. In this example, user group request system 130 can send a user group content response to the application, which includes creative elements for each selected digital component and encrypted selection parameters for each selected digital component.
[0097] Application 112 sends a context content request (226) to SSP 170. The context content request can include at least a portion of information from the user group content response and context data. For example, the context content request can include encrypted selection parameters from the user group content response and an identifier of the DSP 150 that submitted the highest selection parameter, i.e., the DSP 150 that provided the creative element to application 112. In some implementations, the context content request does not include data identifying the selected content or any user group identifier. Instead, in this example, SSP 170 will only have access to the highest selection parameter and optionally, access to the DSP 150 that submitted the highest selection parameter.
[0098] Contextual data for contextual content requests can include the same contextual data as for user group-based content requests, plus additional contextual data such as the number of digital component slots included in the resource, the location of the digital component slots within the resource (e.g., above a fold, below a fold, on the side of the page, etc.), the size of the digital component slots, and the type of digital component slots.
[0099] SSP 170 delivers context content requests (228) to one or more DSPs 150. These context content requests may include context data of the context content request received from application 112, but may not include information from the user group content response that was previously included in the context content request.
[0100] For at least some DSPs 150, this would be a second request received by DSP 150 for the same potential content presentation at application 112. By batch processing requests to DSP 150 with user group identifiers from multiple client devices and / or caching or delaying those requests, it becomes difficult for DSP 150 to associate the additional context data provided for the same user with the user group identifier of a previously provided user. Furthermore, implementing k-anonymity on user group identifiers, request signals, and selection parameters prevents DSP 150 from micro-targeting specific users based on uncommon user group identifiers, request signals, and / or selection parameters. For example, without these techniques, DSP 150 would be able to provide very rare selection parameters for user group-based content requests that include user group identifiers specific to a particular user. If SSP 170 colludes with DSP 150, SSP 170 would be able to inform DSP 150 that the highest selection parameter is very rare and provide DSP 150 with additional context signals for the context content request. At this point, DSP 150 is able to associate all additional context data and user group identifiers with the user. Therefore, even when the SSP 170 and DSP 150 are in tandem, the combination of batch processing, random delay, and k-anonymity techniques described in this document can protect user privacy relative to the SSP 170 and DSP 150.
[0101] Each DSP 150 can send selection parameters (230) to the SSP 170. For example, each DSP 150 can select one or more digital components on behalf of the digital component provider represented by the DSP 150 based on context data. For each digital component, the DSP 150 can also generate or select selection parameters for the digital component. The DSP 150 can then send the selection parameters and data of the digital component (e.g., the creative element of the signature, the digital component itself, or the resource locator of the digital component) to the SSP 170.
[0102] SSP 170 selects content (232). SSP 170 is capable of selecting content based at least in part on selection parameters received from DSP 150 and selection parameters of digital components selected by user group request system 130, i.e., selection parameters of context content request. Since the selection parameters can be encrypted, SSP 170 is capable of decrypting the selection parameters using an encryption key shared with DSP 150.
[0103] During this selection process, the set of digital components selected by SSP 170 can include at least one digital component selected based on the user's membership, such as the digital component selected in step 220. However, SSP 170 does not know the identity of the digital component(s) selected based on the user's membership, only the selection parameters and optionally the DSP that submitted the selection parameters. The set of digital components can also include one or more digital components selected based on context signals, such as the digital component(s) for which DSP 150 provides selection parameters in step 230. SSP 170 can select the digital component with the highest selection parameters from these digital components, such as the digital component with the highest publisher amount.
[0104] Then, SSP 170 can send the selected digital component and / or the creative elements of the selected digital component to client device 110 (234). If the selected digital component is a digital component selected based on the user's membership, for example, if SSP 170 does not recognize data for a digital component selected based on the user's membership, then SSP 170 can deliver data indicating that the digital component selected based on the membership is a digital component selected by SSP 170. Conversely, application 112 can present the selected digital component along with the publisher's resources (236).
[0105] Figure 3 This is a flowchart illustrating an example process 300 for selecting content and providing it to a client device. The operation of process 300 can be implemented, for example, by a user group request system 130. The operation of process 300 can also be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices can cause one or more data processing devices to perform the operation of process 300.
[0106] Receive a content request from the client device (302). The content request may include a set of request signals, similar to the user group-based content request described above. The request signals may include user group identifiers, each identifying a user group that includes the user of the client device as a member. The request signals may also include contextual signals, such as the resource locator of the electronic resource to which the selected content will be presented, the human (e.g., spoken) language of the application that submitted the content request, and / or the geographic location of the client device that sent the content request.
[0107] One or more user group identifiers (304) that satisfy the first k-anonymity process for the user group are identified. The first k-anonymity process can include comparing the number of times each user group identifier has been received from a unique client device within a specified time period, the unique client device including the client device that sent the content request. This can include selecting each user group identifier that has received content requests from the client device at least a threshold number of times within the specified time period as the one or more user group identifiers. As described above, k-anonymity can also be performed on each request signal.
[0108] A selection parameter request, including at least one or more of the user group identifiers, is sent to each of one or more first content platforms (306). Each first content platform may be a DSP. For each user group identifier that satisfies k-anonymity, a selection parameter request is delivered to the first content platform for that user group identifier. The selection parameter request delivered to a given first content platform can include the user group identifier of DSP 150 and a request signal that satisfies k-anonymity.
[0109] Receive selection parameter elements (308) from one or more first content platforms. Each selection parameter element can include data indicating a corresponding digital component and selection parameters for that digital component. For example, a selection parameter element can include a creative element selected by the first content platform and encrypted selection parameters, as described above.
[0110] At least a portion of the selection parameters are sent to a second content platform (310). The second content platform may be an SSP. In addition to the selection parameters, data identifying the first content platform from which the selection parameters are received may be provided to the SSP.
[0111] The portion of the selection parameters delivered to the second content platform may include only the selection parameters that satisfy the second k-anonymity process. In some implementations, for the second parameter to be delivered to the second content platform, the creative element corresponding to the selection parameter must also satisfy the third k-anonymity process.
[0112] (312) Receives data from a second content platform specifying a given first content platform selected based on selection parameters. For example, the second content platform can select one or more digital components based on the received selection parameters. The selected digital component can be one or more digital components with the highest selection parameter(s). The second content platform can provide data specifying the first content platform that provided the selected digital component and / or data specifying the digital component itself.
[0113] Data indicating the digital components provided by the given first content platform is provided to the client device (314). Furthermore, selection parameters for the digital components provided by the given first content platform can also be provided to the client device, for example, in encrypted form. As described above, the client device can present content or deliver a second content request, such as a contextual content request, to a second content platform.
[0114] Figure 4 This is a block diagram of an example computer system 400 that can be used to perform the operations described above. System 400 includes a processor 410, memory 420, storage device 430, and input / output device 440. Each of components 410, 420, 430, and 440 can be interconnected, for example, using a system bus 450. Processor 410 is capable of processing instructions for execution within system 400. In some embodiments, processor 410 is a single-threaded processor. In another embodiment, processor 410 is a multi-threaded processor. Processor 410 is capable of processing instructions stored in memory 420 or storage device 430.
[0115] Memory 420 stores information within system 400. In one embodiment, memory 420 is a computer-readable medium. In some embodiments, memory 420 is a volatile memory cell. In another embodiment, memory 420 is a non-volatile memory cell.
[0116] Storage device 430 provides mass storage for system 400. In some embodiments, storage device 430 is a computer-readable medium. In various embodiments, storage device 430 may include, for example, a hard disk drive, an optical disk drive, a storage device shared by multiple computing devices over a network (e.g., a cloud storage device), or some other mass storage device.
[0117] Input / output device 440 provides input / output operations for system 400. In some embodiments, input / output device 440 may include one or more network interface devices, such as an Ethernet card, a serial communication device such as an RS-232 port, and / or a wireless interface device such as an 802.11 card. In another embodiment, input / output device may include a driver device configured to receive input data and deliver output data to an external device 360, such as a keyboard, printer, and display device. However, other embodiments, such as mobile computing devices, mobile communication devices, set-top box television client devices, etc., may also be used.
[0118] Despite Figure 4An example processing system is described herein, but implementations of the subject matter and functional operations described herein can be implemented in other types of digital electronic circuits, or in computer software, firmware, or hardware, including the structures disclosed herein and their structural equivalents, or in combinations thereof.
[0119] The embodiments of the subject matter and operations described in this specification can be implemented in digital electronic circuits, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or in combinations thereof. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more computer program instruction modules encoded on a computer storage medium (or media) for execution by or control of the operation of a data processing device. Alternatively or additionally, program instructions can be encoded on artificially generated propagated signals, such as machine-generated electrical, optical, or electromagnetic signals, generated to encode information for transmission to a suitable receiver device for execution by the data processing device. The computer storage medium can be or is included in a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination thereof. Furthermore, although the computer storage medium is not a propagated signal, it can be a source or destination of computer program instructions encoded in artificially generated propagated signals. The computer storage medium can also be or be included in one or more separate physical components or media (e.g., multiple CDs, discs, or other storage devices).
[0120] The operations described in this specification can be implemented as operations performed by a data processing apparatus on data stored on one or more computer-readable storage devices or received from other sources.
[0121] The term "data processing apparatus" encompasses all kinds of devices, apparatuses, and machines used for processing data, including, for example, programmable processors, computers, systems-on-a-chip, or a combination thereof. Apparatus may include special-purpose logic circuitry, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits). In addition to hardware, apparatus may also include code that creates an execution environment for the computer program in question, such as code constituting processor firmware, protocol stacks, database management systems, operating systems, cross-platform runtime environments, virtual machines, or combinations thereof. Apparatus and execution environments can implement a variety of different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.
[0122] A computer program (also known as a program, software, software application, script, or code) can be written in any programming language, including compiled or interpreted languages, declarative or procedural languages, and can be deployed in any form, including as a standalone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may, but does not need to, correspond to a file in a file system. A program can be stored as a portion of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), as a single file dedicated to the program in question, or as multiple collaborative files (e.g., a file storing one or more modules, subroutines, or code sections). A computer program can be deployed to execute on a single computer or on multiple computers located in one place or distributed across multiple locations and interconnected via a communication network.
[0123] The processes and logic flows described in this specification can be executed by one or more programmable processors that execute one or more computer programs to perform actions by manipulating input data and generating outputs. The processes and logic flows can also be executed by dedicated logic circuits, and the devices can be implemented as dedicated logic circuits, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits).
[0124] For example, processors suitable for executing computer programs include both general-purpose microprocessors and special-purpose microprocessors. Typically, a processor receives instructions and data from read-only memory or random access memory, or both. The basic components of a computer are a processor for performing actions according to instructions and one or more memory devices for storing instructions and data. Typically, a computer will also include one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, or operatively coupled to said mass storage devices to receive data from or transfer data to them, or both. However, a computer does not need to have such devices. Furthermore, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device (e.g., a universal serial bus (USB) flash drive), etc. Devices suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and storage devices, including, for example, semiconductor storage devices such as EPROM, EEPROM, and flash memory devices; magnetic disks, such as internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM discs. The processor and memory can be supplemented or incorporated by dedicated logic circuitry.
[0125] To provide interaction with the user, embodiments of the subject matter described in this specification can be implemented on a computer having a display device for displaying information to the user, such as a CRT (cathode ray tube) or LCD (liquid crystal display) monitor, and a keyboard and pointing device, such as a mouse or trackball, that the user can use to provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback, such as visual, auditory, or tactile feedback; and input from the user can be received in any form, including sound, speech, or tactile input. Furthermore, the computer can interact with the user by delivering documents to and receiving documents from the device used by the user; for example, by delivering a webpage to a web browser on the user's client device in response to a request received from a web browser.
[0126] Embodiments of the subject matter described in this specification can be implemented in a computing system that includes, for example, a backend component as a data server, or a middleware component as an application server, or a frontend component as a client computer having, for example, a graphical user interface or a web browser, through which a user can interact with embodiments of the subject matter described in this specification, or any combination of one or more such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium, such as a communication network. Examples of communication networks include local area networks (“LANs”) and wide area networks (“WANs”), the Internet (e.g., the Internet), and peer-to-peer networks (e.g., self-organizing peer-to-peer networks).
[0127] A computing system can include clients and servers. Clients and servers are typically geographically separated and usually interact via a communication network. The client-server relationship arises from computer programs running on respective computers and having a client-server relationship with each other. In some embodiments, the server sends data (e.g., HTML pages) to the client device (e.g., to display data to a user interacting with the client device and to receive user input from that user). Data generated at the client device (e.g., the result of user interaction) can be received from the client device at the server.
[0128] While this specification contains numerous specific implementation details, these should not be construed as limiting the scope of any invention or the scope that may be claimed, but rather as descriptions of features characteristic of particular embodiments of a particular invention. Some features described in this specification in the context of independent embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented individually or in any suitable sub-combination in multiple embodiments. Furthermore, although features may be described above as functioning in certain combinations, and even initially claimed in this way, one or more features from a claimed combination can be removed from that combination in some cases, and the claimed combination may be for sub-combinations or variations thereof.
[0129] Similarly, although operations are described in a specific order in the accompanying drawings, this should not be construed as requiring these operations to be performed in the specific order shown or sequentially, or requiring all shown operations to be performed, in order to obtain the desired result. In some cases, multitasking and parallel processing can be advantageous. Furthermore, the separation of various system components in the above embodiments should not be construed as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.
[0130] Therefore, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the following claims. In some cases, the actions described in the claims can be performed in a different order and the desired result can still be obtained. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some implementations, multitasking and parallel processing can be advantageous.
Claims
1. A computer-implemented method for providing digital components, comprising: Receive content requests from client devices, the content requests comprising a set of request signals specifying user group identifiers, each user group identifier identifying a user group that includes a user of the client device as a member; Identify one or more user group identifiers that satisfy the first k-anonymity process; Send a selection parameter request to each of one or more first content platforms, including at least one of one or more user group identifiers that satisfy the first k-anonymity process; Receive selection parameter elements from the one or more first content platforms, each selection parameter element including data indicating a corresponding digital component and selection parameters for that corresponding digital component; Send one or more of the selection parameters to the second content platform, and for each selection parameter, send data to the second content platform identifying the first content platform from which the selection parameter was received; Receive data from the second content platform, specifying a given first content platform selected based on one or more selection parameters; as well as Send data indicating digital components provided by the given first content platform and selection parameters for the digital components provided by the given first content platform to the client device.
2. The computer-implemented method for providing digital components according to claim 1, wherein, Identifying one or more user group identifiers includes: selecting each user group identifier that has been received from a client device including the client device at least a threshold number of times during a specified time period as the one or more user group identifiers.
3. The computer-implemented method for providing digital components according to claim 1 or 2, wherein, The request signal also includes a context signal, and the method further includes: Identify one or more context signals that satisfy the corresponding k-anonymity process; as well as The one or more context signals are provided together with the selection parameter request.
4. The computer-implemented method for providing digital components according to claim 1, wherein, Sending a selection parameter request, comprising at least one of one or more user group identifiers satisfying a first k-anonymity process, to each of the one or more first content platforms includes: sending a separate selection parameter request to each of the one or more user group identifiers.
5. The computer-implemented method for providing digital components according to claim 1, wherein, Sending one or more selection parameters to the second content platform includes: Identify the set of selection parameters that satisfy the second k-anonymity process; as well as Send the set of selection parameters that satisfy the second k-anonymity process as one or more selection parameters.
6. The computer-implemented method for providing digital components according to claim 1, wherein: The client device sends a second content request to the second content platform; The second content request includes selection parameters and context signals for each selected digital component; and The second content platform selects a given digital component from a set of digital components to be presented at the client device, the set of digital components including each selected digital component and one or more additional digital components identified based on contextual signals independent of any user group identifier.
7. The computer-implemented method for providing digital components according to claim 1, wherein, Each selection parameter element includes a creative element, which includes data indicating a corresponding digital component of the selection parameter element, wherein each creative element further includes: One or more categories of the content of the corresponding digital component; The unique identifier of the digital component provider that publishes the corresponding digital component; and A digital signature generated by a second content platform for the creative element.
8. The computer-implemented method for providing digital components according to claim 7, wherein, Sending one or more of the selected parameters to a second content platform includes: A collection of digital components is selected based on one or more categories for each creative element; as well as Send selection parameters for the set of selected digital components as one or more selection parameters.
9. The computer-implemented method for providing digital components according to claim 8, wherein, The set of digital components selected based on one or more categories for each creative element includes: Compare one or more categories of each creative element with the set of excluded categories of the electronic resources of the publishers who are requesting the content for them; as well as Select each digital component whose one or more categories do not match any of the exclusion categories in the set of exclusion categories to include it in the set of digital components.
10. A system for providing digital components, comprising: One or more processors; and A storage device for storing one or more instructions, which, when executed by one or more processors, cause the one or more processors to perform the method of any one of claims 1 to 9.
11. A computer-readable medium carrying instructions that, when executed by one or more processors, cause the one or more processors to perform the method of any one of claims 1 to 9.
12. A computer program product comprising instructions that, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Associating anonymous information to personally identifiable information in a non-identifiable manner
US20160142379A1