Privacy-preserving technologies for content selection and distribution

Through the privacy-preserving selection and counterfactual selection process of the secure multi-party computing system, combined with secret sharing technology and counter variables, the problems of user privacy protection and resource waste are solved, and efficient data transmission and content presentation are achieved.

CN114981813BActive Publication Date: 2025-09-09GOOGLE LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180008029.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-12-13
Filing Date
2021-12-10
Publication Date
2025-09-09
Estimated Expiration
2041-12-10

AI Technical Summary

Technical Problem

Existing secure multi-party computing systems cannot effectively protect user privacy during data transmission and processing, and there are problems of data leakage and resource waste.

Method used

Through the collaboration of a secure multi-party computation (MPC) system, privacy-preserving selection and counterfactual selection processes are adopted, digital components are selected using secret sharing technology, and k-anonymity rules are tracked through counter variables to ensure that user information is not accessible in plain text, while reducing data transmission volume and resource consumption.

Benefits of technology

It achieves the goal of reducing data transmission bandwidth, latency and processing power while ensuring user privacy, improving the efficiency of content presentation, and preventing individual users from being targeted and wasting resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114981813B_ABST
    Figure CN114981813B_ABST
Patent Text Reader

Abstract

The present disclosure describes systems and techniques for improving information integrity and protecting information security in content selection and distribution. In one aspect, a method includes receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selection value. In response to receiving the request, the first server collaborates with a second server of the secure MPC system to perform a privacy-preserving selection process and a counterfactual selection process. The first server sends a selection result defining a first winning selection value from the privacy-preserving selection process and a second winning selection value from the counterfactual selection process, and receives a notification from the application on the client device indicating that a digital component corresponding to the winning selection value from the privacy-preserving selection process is presented at the client device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit of priority to Israel Application No. 279406, filed on December 13, 2020, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This specification relates to data security, data integrity, and cryptography. Background Art

[0004] Secure multi-party computation (MPC) is a family of cryptographic protocols that prevents access to data by distributing computation among multiple parties so that no single party can access another party's data. MPC computing systems use secret sharing of data to perform computations. Summary of the Invention

[0005] In general, one innovative aspect of the subject matter described herein can be embodied in a method comprising: receiving, by a first server of a secure multi-party computation (MPC) system, a request for a selection value from an application on a client device, and in response to receiving the request, by the first server of the secure MPC system: collaborating with a second server of the secure MPC system, performing a privacy-preserving selection process to select a first winning selection value from a set of selection values ​​by applying each rule of a set of selection rules including a privacy-preserving anonymity enforcement rule; and collaborating with the second server of the secure MPC system, performing a counterfactual selection process to select a first winning selection value from a set of selection values ​​by applying each rule of the set of selection rules excluding the privacy-preserving anonymity enforcement rule. the first server of the secure MPC system transmitting a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process; the first server of the secure MPC system receiving a notification from an application on a client device, the notification including data indicating that a digital component corresponding to the winning selection value from the privacy-preserving selection process is presented at the client device; and the first server of the secure MPC system updating a privacy-preserving data structure for determining whether the digital component satisfies a privacy-preserving anonymity enforcement rule for maintaining a first value of a privacy-preserving characteristic corresponding to the second winning selection value from the counterfactual selection process.

[0006] These and other embodiments may optionally include one or more of the following features: In some embodiments, performing the privacy-preserving selection process and performing the counterfactual selection process are performed in parallel.

[0007] In some implementations, the notification includes a variable indicating whether the first server of the secure MPC system should increment the value of the privacy-preserving data structure.

[0008] In some embodiments, the privacy-preserving anonymity enforcement rule is a k-anonymity rule.

[0009] In some embodiments, sending the winning selection value from the privacy-preserving selection process includes: sending a first secret share of the winning selection value from the privacy-preserving selection process to the client device through a first server of the secure MPC system; sending a second secret share of the winning selection value from the privacy-preserving selection process to the client device through a second server of the secure MPC system; and wherein sending the winning selection value from the counterfactual selection process includes: sending the first secret share of the winning selection value from the counterfactual selection process to the client device through the first server of the secure MPC system; and sending the second secret share of the winning selection value from the counterfactual selection process to the client device through the second server of the secure MPC system.

[0010] In some embodiments, a privacy-preserving data structure includes a set of counter variables; wherein each counter variable is mapped to an aggregate identifier, wherein each aggregate identifier is mapped to one or more selection values ​​and a specific numeric component, and wherein performing a privacy-preserving selection process to select a first winning selection value from the set of selection values ​​by applying each rule of a set of selection rules including a privacy-preserving anonymity enforcement rule comprises: for each selection value: comparing the value of the counter variable mapped to the aggregate identifier mapped to the selection value with a threshold; and discarding the selection value if the counter variable value is less than the threshold. In some embodiments, updating the privacy-preserving data structure is performed asynchronously and at specified time intervals.

[0011] Other embodiments of this aspect include corresponding systems, apparatus, and computer programs encoded on computer storage devices configured to perform the actions of the method.

[0012] The subject matter described in this specification can be implemented in specific embodiments to realize one or more of the following advantages.

[0013] A secure MPC process performed by two or more MPC servers operated by different parties is used to select digital components based on a secret share of user information, ensuring that the MPC server or another party cannot access the user information in plaintext or cleartext without unauthorized collusion between the MPC servers. The MPC process is used to implement privacy protection measures such as satisfying k-anonymity within a publication of data, or satisfying anonymity to the extent that the information of each user in the publication is indistinguishable from the information of at least k-1 other users in the publication, or satisfying k-anonymity within at least k different applications (such as Internet browsers).

[0014] The MPC cluster can send secret shares identifying the results of selected digital components that were selected by the MPC cluster using a secure MPC process. By sending secret shares of the results of only the selected digital components, rather than information for all or a large group of digital components, the bandwidth, latency, processing power, and battery power consumed in sending and receiving the results are similarly reduced. By limiting the number of digital components whose information is provided to the client device, the potential leakage of confidential information of the content platform that submits the selected values ​​of the digital components to the MPC cluster is also reduced. The described technology provides a simplified process for maintaining a high level of privacy. By implementing a segmented process via MPC technology, the system provides a high threshold for user privacy without requiring extensive changes from the demand-side platform.

[0015] The proposed structure introduces a counterfactual selection process that ignores the k-anonymity rule to determine the phantom user group candidate selection criteria. If the candidate criteria meet all the rules for determining candidate eligibility except the k-anonymity rule, the phantom candidate selection criteria are eligible to win the selection process. In addition to the actual user group candidate selection criteria that are known to meet the k-anonymity rule, the phantom user group candidate selection criteria are provided for selection in the client-side selection process performed by the client-side application. After the client-side selection process is completed, the client-side application provides an update notification to the MPC cluster to dedupe the phantom user group candidate selection criteria to help the MPC cluster correctly maintain a counter that tracks the compliance of the k-anonymity rule. Based on the counter value, the MPC cluster updates the selection process eligibility of the cached user group selection criteria. This enables the MPC cluster to track the number of times a digital component corresponding to the phantom user group candidate selection criteria will be displayed at the client device and use this number to determine whether the digital component meets the k-anonymity requirement. Without these techniques, the MPC system may be unable to distribute new digital components because they will not be eligible to be provided. The counterfactual selection process enables the MPC cluster to determine whether the digital component, if eligible for the privacy-preserving selection process, would have been revealed enough times to satisfy k-anonymity. Using k-anonymity prevents individual users from being targeted and prevents entities from being able to determine which user groups include the user as a member.

[0016] In addition, data cached locally at a particular computing system reduces the latency of future requests for any cached data. Reducing latency in content presentation also reduces the number of errors that occur on client devices while waiting for such content to arrive. Since content typically needs to be provided within hundreds of milliseconds and is provided to mobile devices connected via a wireless network, reducing latency in selecting and providing content is crucial for preventing errors and reducing user frustration. In addition, reducing the need to send data reduces the amount of bandwidth consumed by sending information, reduces latency in sending information, and reduces the amount of processing power required to send information and the associated battery power for devices that rely on batteries (e.g., mobile devices).

[0017] Various features and advantages of the aforementioned subject matter are described below with reference to the accompanying drawings. Additional features and advantages are apparent from the subject matter described herein and from the claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 is a block diagram of an environment in which an MPC cluster performs a secure MPC process to select digital components for distribution to client devices.

[0019] Figure 2 is a swim lane diagram of an example process for selecting a digital component for display at or distribution to a client device.

[0020] Figure 3 is a flow diagram illustrating an example process for selecting a digital component for distribution to a client device.

[0021] Figure 4 is a block diagram of an example computer system.

[0022] The same reference numbers and names in different drawings represent the same elements. DETAILED DESCRIPTION

[0023] In general, this disclosure describes systems and techniques for improving information integrity and protecting information security in content selection and distribution. An MPC cluster of server computers can perform a secure MPC process to select digital components based on user information, without any MPC server being able to access the user information in plain text without unauthorized collusion. User information can be sent to the MPC cluster using probabilistic data structures to reduce the data size of the information sent over the network and maintain information security during transmission.

[0024] Figure 11 is a block diagram of an environment 100 in which an MPC cluster performs a secure MPC process to select digital components for distribution to a client device 110. The example environment 100 includes a data communications network 105, such as a local area network (LAN), a wide area network (WAN), the Internet, a mobile network, or a combination thereof. The network 105 connects the client devices 110, secure MPC clusters 130, publishers 140, websites 142, content platforms, such as a supply-side platform (SSP) 170, and a demand-side platform DSP (150). The example environment 100 may include many different client devices 110, secure MPC clusters 130, publishers 140, websites 142, DSPs 150, and SSPs 170.

[0025] The client device 110 is an electronic device capable of communicating over the network 105. Example client devices 110 include personal computers, mobile communication devices (e.g., smart phones), and other devices that can send and receive data over the network 105. The client device may also include a digital assistant device that accepts audio input through a microphone and outputs audio output through a speaker. When the digital assistant detects a "hot word" or "hot phrase" that activates the microphone to accept audio input, the digital assistant can be placed in listening mode (e.g., ready to accept audio input). The digital assistant device may also include a camera and / or a display to capture images and visually present information. The digital assistant can be implemented in different forms of hardware devices, including wearable devices (e.g., watches or glasses), smart phones, speaker devices, tablet devices, or other hardware devices. The client device may also include a digital media device, for example, a streaming device that plugs into a television or other display to stream video to a television, game console, or virtual reality system.

[0026] The client device 110 typically includes applications 112, such as a web browser and / or native applications, to facilitate sending and receiving data over the network 105. Native applications are applications developed for a specific platform or a specific device (e.g., a mobile device with a specific operating system). In some embodiments, the application 112 can be a program such as an operating system. The publisher 140 can develop and provide native applications to the client device 110, for example, making them available for download. The web browser can request a resource 145 from a web server hosting a website 142 of the publisher 140, for example, in response to a user of the client device 110 entering a resource address of the resource 145 in the address bar of the web browser or selecting a link that references the resource address. Similarly, a native application can request application content from a publisher's remote server.

[0027] Some resources, application pages or other application content may include digital component slots for presenting digital components together with resources 145 or application pages. As used throughout this disclosure, the phrase "digital component" refers to a discrete unit of digital content or digital information (e.g., a video clip, an audio clip, a multimedia clip, an image, text, or other content unit). A digital component may be electronically stored in a physical memory device as a single file or a collection of files, and the digital component may take the form of a video file, an audio file, a multimedia file, an image file, or a text file, and include advertising information, such that an advertisement is a type of digital component. For example, a digital component may be content that is intended to supplement the content of a web page or other resource presented by application 112. More particularly, a digital component may include digital content related to resource content (e.g., a digital component may be related to the same topic as the web page content, or to a related topic). Therefore, the provision of a digital component may supplement and generally enhance web page or application content.

[0028] When application 112 loads a resource (or application content) that includes one or more digital component slots, application 112 can request a digital component for each slot. In some embodiments, a digital component slot can include code (e.g., a script) that causes application 112 to request a digital component from a digital component distribution system, which selects the digital component and provides it to application 112 for presentation to a user of client device 110. As described below, application 112 can request a digital component from MPC cluster 130 and / or one or more SSPs 170.

[0029] Some publishers 140 use an SSP 170 to manage the process of obtaining digital components for digital component slots for their resources and / or applications. An SSP 170 is a technology platform implemented in hardware and / or software that automates the process of obtaining digital components for resources and / or applications. Each publisher 140 may have a corresponding SSP 170 or multiple SSPs 170. Several publishers 140 may use the same SSP 170.

[0030] Digital component providers 160 can create (or otherwise publish) digital components for presentation in digital component slots of publishers' resources and applications. Digital component providers 160 can use DSPs 150 to manage the provision of their digital components for presentation in digital component slots. DSPs 150 are technology platforms implemented in hardware and / or software that automate the process of distributing digital components for presentation with resources and / or applications. DSPs 150 can interact with multiple supply-side platforms (SSPs) on behalf of digital component providers 160 to provide digital components for presentation with resources and / or applications from multiple different publishers 140. Generally, DSPs 150 can receive requests for digital components (e.g., from SSPs), generate (or select) selection values ​​for one or more digital components created by one or more digital component providers based on the requests, and provide data related to the digital components (e.g., the digital components themselves) and selection parameters to the SPPs. The selection value can indicate the amount that the digital component provider 160 is willing to provide for presentation or user interaction with the digital component. The SSP may then select a digital component for presentation at the client device 110 and provide the client device 110 with data that causes the client device 110 to present the digital component.

[0031] In some cases, it is beneficial for users to receive digital components related to web pages, application pages, or other electronic resources that the user has previously visited and / or interacted with. In order to distribute such digital components to users, when a user accesses a specific resource or performs a specific action at the resource (e.g., interacting with a specific product presented on a web page or adding a product to a virtual shopping cart), the user can be assigned to a user group, such as a user interest group, a group of similar users, or other group categories involving similar user data. The user group can be generated by the digital component provider 160. That is, each digital component provider 160 can assign a user to its user group when the user accesses the electronic resources of the digital component provider 160. The user group can also be created by the content platform (e.g., by the DSP 150 and / or the SSP 170).

[0032] To protect user privacy, a user's group memberships may be maintained at the user's client device 110, for example, by one of the applications 112 or the operating system of the client device 110, rather than by the digital component provider, content platform, or other party. In a specific example, a trusted program (e.g., a web browser or operating system) may maintain a list of user group identifiers ("user group list") for users using the web browser or other application (e.g., for users logged into the browser, application, or client device 110). The user group list may include a group identifier for each user group that includes the user as a member. The digital component provider 160 that creates a user group may specify a user group identifier for its user group. The user group identifier for a user group may be a description of the group (e.g., a gardening group) or a code representing the group (e.g., a non-descriptive alphanumeric sequence). The user's user group list may be stored in a secure storage device at the client device 110 and / or may be encrypted when stored to prevent others from accessing the list.

[0033] When application 112 presents a resource or application content related to digital component provider 160 or a web page on website 142, the resource may request application 112 to add one or more user group identifiers to the user group list. In response, application 112 may add the one or more user group identifiers to the user group list and securely store the user group list.

[0034] The MPC cluster 130 may use the user's user group membership to select digital components or other content that may be of interest to the user or that may otherwise benefit the user / client device. For example, such digital components or other content may include data that improves the user experience, improves the operation of the client device, or benefits the user or client device in some other way. However, the user group identifiers of the user's user group lists may be provided and used to select digital components in a manner that prevents the computing systems MPC1 and MPC2 of the MPC cluster 130 from accessing the user group identifiers in plain text, thereby protecting the user's privacy when using user group membership data to select digital components. Plain text is text, including binary files, that is not computationally marked, specially formatted, or written in code or data, and is in a form that can be viewed or used without a key or other decryption device or other decryption process.

[0035] Secure MPC cluster 130 includes two computing systems, MPC1 and MPC2 (e.g., server computers), that execute a secure MPC process to select digital components for distribution to a user's client device based on the user's group membership, without accessing the group membership information in plain text. Although the example MPC cluster 130 includes two computing systems, more computing systems may be used as long as MPC cluster 130 includes more than one computing system. For example, MPC cluster 130 may include three computing systems, four computing systems, or another suitable number of computing systems. Using more computing systems in MPC cluster 130 may provide greater security, but may also increase the complexity of the MPC process.

[0036] Computing systems MPC1 and MPC2 can be operated by different entities. In this way, each entity cannot access the user's group membership in clear text. For example, one of computing systems MPC1 or MPC2 can be operated by a trusted party different from the user, publisher 140, DSP 150, SSP 170, and digital component provider 160. For example, an industry group, a government group, or a browser developer can maintain and operate one of computing systems MPC1 and MPC2. The other computing system can be operated by a different one of these groups, so that a different trusted party operates each computing system MPC1 and MPC2. Preferably, the different parties operating different computing systems MPC1 and MPC2 have no incentive to collude to compromise user privacy. In some embodiments, computing systems MPC1 and MPC2 are architecturally separated and monitored so that they do not communicate with each other outside of executing the secure MPC process described in this disclosure.

[0037] In addition to the description throughout this disclosure, controls (e.g., user interface elements with which the user can interact) can be provided to the user to allow the user to choose whether and when the systems, programs, or features described herein can collect user information (e.g., information about the user's social network, social actions or activities, occupation, the user's preferences, or the user's current location) and whether to send content or communications from a server to the user. In addition, certain data can be processed in one or more ways before it is stored or used to remove personally identifiable information. For example, the user's identity can be processed so that personally identifiable information about the user cannot be determined, or the user's geographic location, if location information is available, can be generalized (e.g., to a city, zip code, or state level) so that the user's specific location cannot be determined. Thus, the user can control what information is collected about the user, how that information is used, and what information is provided to the user.

[0038] Figure 2is a swim lane diagram of an example process 200 for selecting digital components for display at or distribution to a client device. The operations of process 200 may be implemented, for example, by application 112 on client device 110, computing systems MPC1 and MPC2 of MPC cluster 130, and DSP 150. The operations of process 200 may also be implemented as instructions stored on one or more computer-readable media that may be non-transitory, and execution of the instructions by one or more data processing devices may cause the one or more data processing devices to perform the operations of process 200. Although process 200 and other processes are described below with respect to an MPC cluster 130 having two computing systems, an MPC cluster having more than two computing systems may also be used to perform similar processes. Furthermore, the operations of process 200 may be implemented by SSP 170.

[0039] The MPC cluster performs a secure MPC process to select a digital component based on characteristic information (such as user group information) in the digital component request. The user group information can be provided using secret sharing, for example, so that MPC1 obtains a secret share of the user group information and MPC2 obtains a second share of the user group information. The user group information can identify one or more user groups of which the user of the client device sending the request is a member. The digital component selection can include using a first-level lookup key to identify eligible selection values ​​for the digital component in the two-level lookup tables of the computing systems MPC1 and MPC2. This can also include, for example, identifying the selection value of the digital component as a candidate for selection based on the digital component having a user group identifier that matches one of the user group identifiers of the user. This can also include selecting the digital component from the candidate digital components based on the selection value of the digital component. All of this can be performed without the computing system MPC1 or MPC2 having access to the user group identifier in plain text.

[0040] Computing systems MPC1 and MPC2 can use secure MPC techniques to identify candidate selection values ​​using secret sharing, so that neither computing system MPC1 nor MPC2 knows which digital components are candidates or the user group that includes the user as a member. To this end, computing system MPC1 calculates a first share of candidate parameters for each digital component in a set of digital components. Similarly, computing system MPC2 calculates a second share of candidate parameters for each digital component in a set of digital components. The candidate parameter can be a Boolean value (e.g., zero or one) that indicates whether the selection value of the digital component linked to the user group identifier is a candidate. That is, the candidate parameter indicates whether the digital component is linked to an allocation criterion that indicates the eligibility of the digital component for allocation to a user in the user group identified by the user group identifier.

[0041] Computing systems MPC1 and MPC2 may use secure MPC techniques to compute a secret share of the outcome of the selection process with one or more round trips between the computing systems. That is, computing systems MPC1 and MPC2 may determine a secret share of the winning selection value and / or its corresponding digital components.

[0042] Once sharing is complete, MPC1 and MPC2 can each return one of the shares of the selection result to the client device. The client device can then reconstruct the selection result in plaintext using the two secret shares. The selection result can include the corresponding digital component or a reference to the corresponding digital component, such as a link to download the corresponding digital component.

[0043] The process begins with the DSP 150 providing a selection value for a digital component to the MPC cluster 130, typically via the SSP 170 (Phase 1). As described above, the selection value may indicate the amount that the digital component provider 160 is willing to provide for presentation or user interaction with the digital component. The MPC cluster 130 may store the selection value for future digital component requests received from the client device 110. For each digital component, the DSP 150 may also upload additional data for the digital component, such as metadata. The additional data for the digital component may include a user group identifier for the user group corresponding to the digital component (e.g., the user group to which the digital component is eligible for distribution). For example, the DSP 150 may manage activities in which the digital component is distributed to client devices 110 of users who are members of the user group.

[0044] The data for the digital component may include a contextual selection signal that indicates a context for which the digital component is eligible, such as the location of the client device 110, the spoken language selected for the application 112, a universal resource locator (URL) of a resource with which the digital component can be presented. The data for the digital component may also identify the digital component, such as using a unique identifier, a domain from which the digital component can be obtained, and / or other appropriate data for the digital component.

[0045] MPC cluster 130 caches or otherwise stores the selection value of the digital component provided to MPC cluster 130 for future digital component requests. In this example, the context signal and the selection value of the digital component may include the context signal included in the digital component request.

[0046] In some embodiments, each computing system MPC1 and MPC2 uses a two-level lookup table (LUT) to store selection values ​​for digital components. The first level can be key-encrypted by a user group request key. The user group request key can be a composite message based on a set of context signals, such as a set of context signals requested by the digital component (e.g., URL, location, language, etc.) or a set of context signals for which the digital component is eligible for distribution. In other words, the first-level LUT can be key-encrypted based on the set of context signals. The second-level LUT can be key-encrypted based on a combination of the user group request key and the user group identifier in the first-level LUT. In some embodiments, the second-level LUT can be replaced with a simple table without a lookup key. Each row in the second-level LUT can be a specific selection value for a specific digital component. For example, the DSP 150 can submit different selection values ​​for the same digital component, each selection value targeting a different set of context signals and / or a different user group identifier. Thus, the selection value of a digital component can vary depending on the context.

[0047] DSP 150 or digital component provider 160 may optionally associate (e.g., link or map) a digital component to a user group to which DSP 150 or digital component provider wishes to present the digital component. For example, DSP 150 may wish to provide a digital component associated with a DIY birdhouse building kit for display at a client device to users who have expressed an interest in DIY, birds, and / or garden decor. In this example, DSP 150 may provide data to MPC cluster 130 indicating that the digital component corresponds to a user group identifier for a user group that includes users who have expressed an interest in DIY, birds, and / or garden decor. Additionally, the same DSP 150 or digital component provider 160 may optionally associate (e.g., link or map) the same digital component to other conditions under which DSP 150 or digital component provider wishes to present the digital component, such as a specific pacing condition.

[0048] In some embodiments, the key for a row in the second-level LUT can be a hash or code generated based on a combination of a user group request key UG_Request_Key and a user group identifier for the digital component of the row. For example, the key can be a combined hash-based message authentication code (HMAC), which can be expressed as HMACSHA256(UG_Request_Key, ug_id). The user group identifier ug_id can be based on a combination of an internal user group identifier for the user group and the domain of the owner of the user group (e.g., the domain of the DSP, SSP, or digital component provider that owns the user group). For example, the user group identifier ug_id can be an HMAC of the eTLD+1 of the owner's domain and the digital digest of the internal user group identifier of the owner of the user group, or a combination thereof. eTLD+1 is the effective top-level domain (eTLD) plus one level more than the public suffix. An example eTLD+1 is "example.com," where ".com" is the top-level domain. ug_id can be truncated to 16 bytes or other appropriate data size.

[0049] The value of each row of the second-level LUT can include a selection value for a digital component and other data about the digital component, such as metadata identifying the digital component or a network location from which the digital component can be downloaded. This value can be a digital component information element, which can be a byte array containing the selection value and metadata. The second-level LUT maps the selection value to a specific digital component. In some embodiments, the second-level LUT also optionally maps a specific user group identifier to a specific set of context signals defined by the first-level search key. By doing so, the second-level LUT indicates the specific context for which the digital component's selection value qualifies for the digital component slot. This allows the DSP 150 or digital component provider 160 to specify different selection values ​​for the same digital component for different contexts defined by the context signals (and optionally, the user's group membership or other conditions for content delivery). When a digital component request is received indicating that the user to whom the digital component will be presented is a member of a specific user group identified by a specific user group identifier, and that the digital component will be presented in a specific context defined by the context signals of the first-level search key, any selection value in the second-level LUT with a matching user group identifier and a matching first-level search key is a candidate for selection for distribution in response to the request.

[0050] Client device 110 receives content (stage 2). For example, client device 110 may receive an electronic resource (e.g., a web page) for presentation by a web browser, or application content for presentation by a native application. The content may include one or more digital component slots, each of which includes computer-readable code (e.g., a script) that, when executed, causes client device 110 to request a digital component for each slot. Client device 110 may render the content on a display of client device 110.

[0051] The client device 110 generates a request for one or more digital components based on the received content (stage 3). The request includes data indicating the characteristics of the content and the context in which the digital component will be presented. For example, the request may include one or more categories of the received content (DIY, Birds, Nature Conservation), the user groups of which the user is a member, the location and / or size of the digital component slot, the length of time the digital component will be displayed, and other characteristics. As described above, the user group identifier can be sent as a secret share to prevent any MPC computing system from accessing the user's membership information in plain text. If the resource in which the content is to be displayed includes multiple digital component slots, the client device 110 can request a corresponding digital component for each slot from the MPC cluster 130 and SSP 170. The request can also include an identifier of a specific distribution opportunity and / or a digital component slot in which the selected digital component is to be displayed.

[0052] Client device 110 then sends a request for the digital component to MPC cluster 130 (stage 4). For example, client device 110 may send the request for the digital component directly to MPC cluster 130. In some implementations, client device 110 may send the request for the digital component to SSP 170 (or DSP 150), and SSP 170 (or DSP 150) may forward the request to MPC cluster 130. In some implementations, the request may not include user group information.

[0053] Based on the request, MPC cluster 130 performs a privacy-preserving selection process to select the winning digital component with a specified selection value (stage 5a). For example, the selection process can take the form of an auction, where an auction is held to select the eligible digital component with the highest selection value that meets a threshold (e.g., k-anonymity) specified by MPC cluster 130 or client device 110. In order for a digital component to be eligible for the selection process, it must meet certain distribution requirements. For example, the digital component must meet specific rules specified by one or more digital component providers 160, client device 110, the user of client device 110, and / or MPC cluster 130 itself. The rules can include restrictions and guidelines on how or how often the digital component can be distributed, among other factors. Rules include frequency control, muting, budget, and consumption control limits. The privacy-preserving selection process includes an additional rule—a privacy-preserving rule that enforces the anonymity of a specific user's data. For example, the privacy-preserving rule is implemented as a k-anonymity rule.

[0054] First, computing systems MPC1 and MPC2 determine, based on data provided in a digital component request from client device 110 , whether a particular cached selection value and its corresponding digital component qualify as a candidate for the privacy-preserving selection process being performed.

[0055] Each selected value x is associated with an aggregate identifier (denoted as aggregate_id), and MPC cluster 130 will enforce k-anonymity on the aggregate identifier. For example, the aggregate identifier can be a numeric digest of the numeric components (e.g., SHA256). MPC cluster 130 also implements the function aggregate_id to extract the aggregate identifier from the selected value x. For example, MPC cluster 130 can apply aggregate_id(x) to determine the value of aggregate_id for the selected value x.

[0056] MPC cluster 130 uses the variable satisfy_k_anonymity x Determines the k-anonymity eligibility of a numeric component mapped to a specific aggregate_id and mapped to one or more selected values, using the variable satisfy_k_anonymity x Indicates whether the selected value x of the digital component satisfies k-anonymity. If and only if x satisfies k-anonymity, the variable satisfy_k_anonymity x = 1. Otherwise, the variable satisfy_k_anonymity x = 0. By passing the variable counter aggregate_id(x) The value of the counter represented by is compared with the k-anonymity threshold k to calculate satisfy_k_anonymity xFor example, the computing system MPC1 can use the following equation to calculate the satisfaction_k_anonymity in the secret sharing: x Secret sharing of the value of .

[0057] [satisfy_k_anonymity aggregate_id(x),1 ]=[counter aggregate_id(x),1 ]>k

[0058] Equation (1)

[0059] The computing system MPC2 can calculate the satisfaction_k_anonymity in the secret sharing using an equation similar to the following x Secret sharing of the value of:

[0060] [satisfy_k_anonymity aggregate_id(x),2 ]=[counter aggregate_id(x),2 ]>k

[0061] Equation (2)

[0062] As described in further detail below with respect to stage 10, the MPC cluster 130 may generate a counter variable based on the counter. aggregate_id(x) Update the value of satisfaction_k_anonymity x The value of .

[0063] The concept of k-anonymity ensures that the data of a particular user is indistinguishable from the data of a threshold number k of other users. The system can enforce k-anonymity rules, for example, by ensuring that a particular digital component is delivered to a client device 110 in response to a request for one or more digital components, and that the same digital component may have been or has been presented to a group of at least k users or by at least k browsers within a specific time period. In some embodiments, each of the k browsers to which the digital component may have been or has been delivered must be for a different user.

[0064] The system implements k-anonymity through the use of a privacy-preserving data structure. The distribution of a particular digital component can be tracked within the privacy-preserving data structure (such as a counter of the number of times the digital component has been selected for distribution or display, for example, to different users or using different browsers). As described in further detail below with respect to Stage 8, when a digital component is selected through a privacy-preserving selection process and subsequently distributed to a client device, a counter can be incremented for that digital component. The counter tracks, for example, the number of browsers or users that may have seen or have seen the particular digital component over a period of time. For example, the counter can count the number of browsers that may have seen or have seen the particular digital component in the last 12 hours. Because the counter tracks this information over a recent period of time, it increments when data indicates that the digital component has been or may have been presented and decrements over time. For example, the counter can automatically decrement when each presentation or potential presentation passes a specified time period. The counter can track, for example, the time period that has elapsed since the presentation or potential presentation was added to the counter's total. In some embodiments, the counter can store a timestamp of when each presentation or potential presentation was added to the counter's total. When a specified time period elapses, a counter may automatically decrement the number of expired presentations or potential presentations.

[0065] Furthermore, users generally do not like being repeatedly presented with the same third-party content as they navigate across multiple different websites. Consequently, continuously distributing the same third-party content to the same user across multiple different websites results in a waste of computing resources that are used to distribute content that the user does not want to see and may ignore. One approach to limiting the number of times a particular user is exposed to the same third-party content is to utilize frequency control techniques, which prevent the same user from being exposed to the same third-party content more than a specified number of times within a period of time.

[0066] The system allows further user input by receiving information from the user to mute the digital component or prevent the digital component from being presented to them for a period of time. For example, the user may choose to mute a particular digital component that has been presented to them for a period of five days. In some embodiments, the time period may be specified by the client device 110, MPC cluster 130, DSP 150, digital content provider 160, or SSP 170 based on other factors such as the type of content item and / or the type of feedback provided by the user.

[0067] The distribution of content can also be controlled by input from the digital component provider 160 through budget and consumption control techniques. The digital component provider can specify a total threshold for the selection value within a time period to implement measures to ensure that the resources of the campaign including the digital component are not exhausted early in the campaign period. For example, the digital component provider 160 can specify that the selection value of the selected digital component or the sum of the selection values ​​of a particular digital component from the digital component provider 160 over the course of a week is limited to a maximum of 8,000 units. Once the maximum sum of selection values ​​is reached, the particular digital component to which the maximum value is applied will no longer be eligible for selection to be distributed to the client device 110 until the end of the time period (one week).

[0068] The digital component provider may also specify a rate or consumption at which a threshold value for a selected digital component or a selected value for a particular digital component is reached from the digital component provider 160. For example, the digital component provider 160 may specify that a maximum threshold of 6,000 units must be reached over the course of a month at a consumption of less than 250 units per day. Once the daily total of the selected value is reached, the digital component provided by the digital component provider 160 for which consumption control is applied will no longer be eligible for the selection process to be distributed to the client device 110 until the end of that period (that day).

[0069] In addition to enforcing digital component eligibility according to content distribution rules, the privacy-preserving selection process protects user privacy and improves user experience by preserving the k-anonymity of users (or browsers) such that any component selected is provided to at least k other users (or browsers). By ensuring that a particular digital component is provided to a threshold number of other users, the system can prevent a form of user targeting known as microtargeting, which narrowly targets users to an extent that some users may feel uncomfortable with. For example, a digital component that is targeted and distributed to only a few users may feel overly personal, and users may feel isolated or uncomfortable with the specificity of the digital component. The privacy-preserving selection process can ensure that digital components are distributed to a wide enough audience that users feel comfortable with the digital components they receive and the size of the target audience for the digital components.

[0070] The computing system of the MPC cluster 130 can use the Boolean variable is_candidate x The variable is_candidate is a candidate if and only if x satisfies all the distribution rules applied in the privacy-preserving selection process. x = 1. Otherwise, the variable is_candidate x =0.

[0071] Next, each computing system in MPC cluster 130 determines an order of selected values ​​that qualify as candidates for the privacy-preserving selection process. For example, each computing system MPC1 and MPC2 can determine an order of eligible selected values ​​in its second-level LUT. This order can include all eligible selected values ​​in the second-level LUT, including candidate selected values. In some embodiments, this order can include selected values ​​that are not candidates. The order can be from highest selected value to lowest selected value. In some embodiments, the selected values ​​used for this order can be, for example, the values ​​provided to the publisher of the resource after any sharing with DSP 150 and / or SSP 170, with which the selected digital component will be presented. Because the selected values ​​are in plain text, computing systems MPC1 and MPC2 do not need to perform any round-trip computations to sort the selected values. Instead, each computing system MPC1 and MPC2 can independently sort the selected values ​​in its second-level LUT.

[0072] The structure of MPC cluster 130 allows for additive secret sharing, which involves breaking a secret into fragments that add up to the original secret. Once broken into fragments, each fragment is distributed to a different participant, and no single participant has sufficient information to reconstruct the secret. To reconstruct the secret, all fragments must be brought together to reveal the original secret. If the selected values ​​are stored as secret shares at each computing system MPC1 and MPC2, where each computing system MPC1 and MPC2 has a corresponding secret share for each selected value, computing systems MPC1 and MPC2 can perform a secure MPC process using round-trip computation to sort the selected values.

[0073] Once the choice values ​​have been sorted, the MPC cluster 130 completes the privacy-preserving selection process by selecting a winner. For example, the MPC cluster 130 calculates the variable is_pp_winner for each candidate choice value cached by the MPC cluster 130. x The value of is used to determine the winner.

[0074] is_pp_candidate x =is_candidate x ×satisfy_k_anonymity x Equation (3)

[0075] variable satisfy_k_anonymity x Is a Boolean variable that indicates whether the candidate selection value x satisfies k-anonymity. In equation (3), is_candidate x and satisfy_k_anonymity xBoth must be true or 1 in order for is_pp_candidatex to be true.

[0076] In this example, equation 3 is written in a multiplication manner. Conceptually, equation 3 can be executed using a logical AND operation. In some embodiments, the logical expression can be executed directly without converting to a multiplication operation.

[0077] In one example, MPC1 calculates [is_pp_candidate x,1 ].

[0078] [is_pp_candidate x ]=[is_candidate x,1 ]×[satsify_k_anonymity x,1 Equation (4)

[0079] Among them, the parameters appearing in brackets, such as [is_pp_candidate x,1 ], indicating the secret sharing of the variables in the brackets. For example, [is_pp_candidate x,1 ] represents the first secret share of is_pp_candidatex that is known only to MPC1. Computing the secret share of the bracketed parameters may require round-trip remote procedure calls (RPCs) between the computing systems of the MPC cluster 130.

[0080] MPC2 uses a similar equation to calculate [is_pp_candidate x,2 ].

[0081] [is_pp_candidate x ]=[is_candidate x,2 ]×[satsify_k_anonymity x,2 Equation (5)

[0082] The computations represented by equations (4) and (5) are performed simultaneously as part of a secure 2PC protocol. Furthermore, these computations are particularly efficient because the × (multiplication) operation requires only one round of communication between computing systems MPC1 and MPC2, whereas the == (equal to) operation requires three rounds of communication between computing systems MPC1 and MPC2, and the > (greater than) operation requires more than three rounds of communication between computing systems MPC1 and MPC2. For example, computing systems MPC1 and MPC2 can participate in multiple rounds of computation, e.g., multiple RPCs, as part of a secure MPC process to perform equality comparisons. At the end of the process, for each selected value, computing system MPC1 has one secret share of the result, and for each selected value, computing system MPC2 has another secret share of the result. The computations represented by equations (4) and (5) reduce the amount of communication required between computing systems MPC1 and MPC2 relative to performing the operations using comparison operations (such as equality or greater than operations), thereby reducing the amount of transmission traffic and the total computing resources required to complete the computations.

[0083] Conceptually, the accumulated value of a given selection value of a digital component represents the total number of candidate selection values ​​from the top of the sequence to the given selection value. For example, the MPC cluster 130 calculates the accumulated value pp_acc using the following equation x , accumulated value pp_acc x It represents the total number of eligible candidate selection values ​​that precede the selection value x in the privacy-preserving selection process.

[0084] pp_acc x =∑is_pp_candidate b Equation (6)

[0085] The variable b represents the candidate selection value b that is ranked before the selection value x based on the selection value. Because is_pp_candidate has been calculated for each eligible selection value b before b , so the computation of equation (6) does not require communication between computing systems MPC1 and MPC2 but simply requires a summation, assuming that an appropriate secret sharing algorithm is employed.

[0086] Once the choice values ​​have been sorted, the MPC cluster 130 completes the privacy-preserving selection process by selecting a winner. The MPC cluster can determine the variable is_pp_winner for each cached eligible candidate choice value using the following equation: x The value of is used to calculate the result of the privacy-preserving selection process.

[0087]

[0088] The variable is_pp_winner is present if and only if x is the winner of the privacy-preserving selection process.x = 1. Otherwise, the variable is_pp_winner x = 0. Due to pp_acc x has been calculated, so by using the variable pp_acc in equation (7) x , the MPC cluster 130 may use a simple operation to determine whether a particular cached selected value is the winner.

[0089] Computing system MPC1 holds [is_pp_winner x,1 ]. The computing system MPC2 holds [is_pp_winner x,2 ]. [is_pp_winner x,1 ] and [is_pp_winner x,2 ] represents the secret sharing of the variable is_pp_winnerx.

[0090] MPC cluster 130 performs the counterfactual selection process (stage 5b). The counterfactual selection process can be performed in parallel with or before the privacy-preserving selection process. MPC cluster 130 can, for example, perform both selection processes in parallel in batch mode without increasing the number of RPCs between computing systems MPC1 and MPC2. The result of the counterfactual selection process is_winner x The MPC cluster 130 is allowed to update the privacy-preserving data structure to determine whether the selected value x satisfies the k-anonymity rule. However, the final selection process performed by the client device 110 only considers the values ​​with is_pp_winner x The selection value x with a value of 1 is the winner of the privacy-preserving selection process.

[0091] The counterfactual selection process can have the same form as the privacy-preserving selection process, and in order for a digital component to be eligible for the selection process, the digital component must meet certain distribution requirements. The counterfactual selection process measures what would happen if the k-anonymity rule were not applied by applying all the distribution rules applied by the privacy-preserving selection process (except the privacy-preserving rule). Because the counterfactual selection process does not apply privacy-preserving rules, digital components that would otherwise be eligible for selection and provision to a client device but have not yet been distributed to other client devices at least a threshold number of times can be selected during the counterfactual selection process. This process is particularly advantageous because it allows the system to track the selection rate, for example, for newly provided digital components that have not been previously distributed, or have not met the threshold number of distributions, and are therefore ineligible for distribution to users during the privacy-preserving selection process. Without the counterfactual selection process, such digital components may never become eligible for selection in the privacy-preserving selection process and, therefore, in the final selection process, and may never be provided to client devices.

[0092] The counterfactual selection process allows the system to determine whether a particular digital component would be eligible for distribution if it had already met the anonymity rules. As described above with respect to the privacy-preserving selection process, this potential distribution can be tracked within a privacy-preserving data structure (such as a counter of the number of times the digital component was selected for distribution). As described in further detail below with respect to Stage 8, the counter can be incremented for a digital component even if the digital component was not selected by the privacy-preserving selection process and subsequently distributed to the client device, but was instead selected by the counterfactual selection process.

[0093] The concept of k-anonymity ensures that a particular user's data is indistinguishable from the data of a threshold number k of other users. By incrementing a counter for a particular digital component when it would have won the final selection process and been distributed to the client device if not for the privacy protection rules, the system solves the problem of not being able to distribute a digital component when the digital component has no chance of being distributed to the threshold number of people and is able to continue to enforce k-anonymity for other digital components.

[0094] As described above with respect to the privacy-preserving selection process, the MPC cluster 130 performs the same secure MPC process to select digital components based on the characteristic information in the digital component request.

[0095] Conceptually, the cumulative value of a given selection value of a digital component represents the total number of candidate selection values ​​from the top of the sequence to the given selection value. For example, each of the computing systems MPC1 and MPC2 can calculate the accumulator. x ,acc x is the number of eligible choices based on these values ​​that precede the choice x during the selection process.

[0096] Once the selected values ​​have been sorted, the MPC cluster 130 completes the privacy-preserving selection process by selecting a winner. The MPC cluster can determine the variable is_winner for each cached selected value. x The value of is used to calculate the selection process results.

[0097] is_winner x =is_candidate x ×(acc x = = 0) Equation (8)

[0098] The variable is_winner is present if and only if x is the winner of the privacy-preserving selection process. x = 1. Otherwise, the variable is_winner x =0.

[0099] In some embodiments, acc x The calculation of is inclusive calculation including the selected value x, so equation (8) will use acc x ==1.

[0100] Computing system MPC1 holds [is_winner x,1 The computing system MPC2 holds [is_winner x,2 ]. [is_winner x,1 ] and [is_winner x,2 Each of the ] represents the variable is_winner x Secret sharing.

[0101] In some embodiments, with is_pp_winner x =1 and is_winner x = 1 can be the same digital component. However, with is_pp_winner x The numeric components of the selection values ​​for is_winnerx=1 and is_winnerx=1 are typically different numeric components.

[0102] MPC cluster 130 provides the privacy-preserving selection process winner to client device 110 and provides the counterfactual selection process winner to client device 110 (stage 6).

[0103] In response to the digital component request sent from client device 110 to MPC cluster 130 in stage 3, MPC cluster 130 provides the winner or selection results of the privacy-preserving selection process and the counterfactual selection process to client device 110. Computing system MPC1 may return a first share of the selection results to client device 110. Similarly, computing system MPC2 may return a second share of the selection results to client device 110.

[0104] The selection result of the privacy-preserving and counterfactual selection process may be in the form of a byte array comprising information about the selected digital components corresponding to the actual value or the imaginary value. To perform a computation in the secret share, the computing system MPC1 obtains all cached selected values ​​and multiplies the digital component information elements of the selected values ​​(which may be in plain text) by the first secret share of the winner parameter, e.g., [is_pp_winner x,1 ] or [is_winner x,1 ]. Computing system MPC1 may then determine the sum of these products and return the sum to the client device 110 that submitted the digital component request. Computing system MPC2 may perform a similar calculation to determine a second share of the result.

[0105] For example, the selection result may be a byte array including the value of the digital component in the second LUT, e.g., the selected value of the digital component and metadata of the digital component. To prevent the computing systems MPC1 and MPC2 from knowing the selected digital component, the computing systems MPC1 and MPC2 may be prevented from sharing a secret share of their selection results with each other.

[0106] MPC cluster 130 provides a selection result for zero or one cached selection values ​​that were presented at client device 110 and were the winners of the privacy-preserving selection process. If MPC cluster 130 provides a winner of the privacy-preserving selection process, the selection value complies with all rules, such as frequency control, muting, budget, consumption control, and k-anonymity. This winner is the selection value x for which is_pp_winnerx = 1, and this is the only selection value used by client device 110 in its final selection process. This winner is called the actual value.

[0107] The MPC cluster 130 also provides a selection result for zero or one cached selection values ​​of the winner of the counterfactual selection process. If the MPC cluster 130 provides the winner of the counterfactual selection process, the selection value meets all rules except the k-anonymity rule. The winner is the selection value x for which is_winnerx=1, and the client device 110 does not use this selection value in its final selection process. The winner is called a virtual value. Because the client device will never present the digital components mapped to the virtual value to the user or allow the user to interact with the digital components mapped to the virtual value, the MPC cluster 130 can optionally strip off the code (e.g., Javascript) and assets (e.g., HTML, CSS, JPG) embedded in the virtual value that are necessary to render the virtual value and enable the user to interact with the virtual value, thereby reducing battery and bandwidth consumption of the mobile device.

[0108] In some embodiments, each of the actual and virtual values ​​selected for a particular distribution opportunity can indicate the distribution opportunity in response to which the actual and virtual values ​​were selected. For example, an identifier for the distribution opportunity can be included within each of the actual and virtual values, or sent along with the actual and virtual values ​​to client device 110. In some embodiments, the identifier for the distribution opportunity can be mapped to the is_winner and is_pp_winner variables for each selected value. In other embodiments, the identifier for the distribution opportunity can be mapped to each selected value.

[0109] The client device 110 can then reconstruct the selection result in plain text using the secret share. For example, the application 112 can reconstruct the selection result by determining the sum of the secret shares. If the selection result has a value of zero, the MPC cluster 130 does not recognize the digital component of the user group that includes the user as a member.

[0110] Client device 110 performs a final selection process (stage 7) that includes the winning selection criteria it received from MPC cluster 130 .

[0111] In some embodiments, client device 110 may request digital components from MPC cluster 130 based on user group membership. Client device 110 may also request digital components from SSP 170 based on contextual signals. These contextual signals may include the same contextual information described above, as well as optional additional contextual signals, such as the number of digital component slots for the resource, the type of digital component slots, the types and / or formats of digital components that can be presented with the resource, and the like. SSP 170 may select one or more digital components based on the contextual signals and the selection values ​​of the digital components, and provide one or more of the selected digital components (or data identifying the digital components) and the selection values ​​of the digital components to client device 110. Client device 110 may then select the digital components to be presented with the content at client device 110 from a set of digital components, including the actual values ​​of the digital components received from MPC cluster 130 and the digital components selected by SSP 170. For example, in addition to the selection values ​​received from MPC cluster 130, client device 110 may also use a selection value cached at client device 110 to perform the final selection process. In some implementations, client device 110 may receive winning selection values ​​from more than one MPC cluster 130 , more than one SSP 170 , and / or more than one DSP 150 .

[0112] Although the MPC cluster 130 provides winning selections from both the privacy-preserving selection process and the counterfactual selection process, the client device 110 only considers the winner of the privacy-preserving selection process, the selected value x where is_pp_winnerx = 1, or the actual value. By accepting both the actual and virtual values ​​but only considering the actual values, the MPC cluster 130 provides a high level of privacy for the user by enforcing k-anonymity for the digital components selected for distribution, while allowing digital components that have not yet met the k-anonymity requirement to be tracked and have their corresponding k-anonymity counts increased, giving digital components a chance to meet the k-anonymity requirement. In some embodiments, the final selection process can have additional rules. For example, the final selection process can include additional rules regarding the frequency with which a particular digital component corresponding to the selected value can be displayed.

[0113] The application 112 of the client device 110 performs the final selection process according to a method similar to the process described with respect to the privacy-preserving and counterfactual selection process. For example, the web browser 112 installed on the client device 110 can perform the final selection process by sorting and ranking the candidate selection values. The web browser 112 then selects the top-ranked selection value as the winner of the final selection process.

[0114] Client device 110 determines the digital component corresponding to the winner of the final selection process and presents the digital component (stage 8). For each selection result, client device 110 receives two secret shares from computing systems MPC1 and MPC2, from which client device 110 can determine the selection result. For example, using an additional secret sharing library, client device 110 can add the two secret shares of the selection result together to obtain the selection result in plaintext. This allows client device 110 to access the selection value of the digital component and metadata for the digital component, such as the identity of the digital component, the location from which client device 110 can download the digital component, etc. If the selection result is non-zero, the selection result has a value equal to the digital component information element, then application 112 can parse the digital component information element to obtain the selection value and metadata for the digital component. Application 112 can then present the digital component along with the received content at client device 110. For example, application 112 can cause the digital component and content to be displayed on a display of client device 110.

[0115] If and only if the actual value (selection value x with is_pp_winnerx=1) is the winning candidate selection value of the final selection process performed by client device 110, client device 110 provides update data to MPC cluster 130 (stage 9). For example, application 112 on client device 110 can send a notification containing information about the winning candidate selection value and the k-anonymity eligibility of the actual value (which is the winning candidate selection value) and the virtual value provided with the actual value. Update data is provided to MPC cluster 130 only if the actual value is the winning candidate selection value of the final selection process, because the digital component mapped to the selection value is only present at client device 110 when the selection value is the winning candidate selection value of the final selection process.

[0116] Application 112 on client device 110 sends a notification containing information about the winning candidate selection value and the digital component associated with the candidate selection value to MPC cluster 130. The notification indicates that the winning candidate selection value from the final selection process is the actual value provided by MPC cluster 130 and the digital component associated with the winning candidate selection value is presented at client device 110, e.g., rendered at client device 110.

[0117] Because notifications are sent only when the actual value is the winning candidate selection value, MPC cluster 130 will receive information about the winner of its own privacy-preserving and counterfactual selection process. Notifications can identify, for example, the winning candidate selection value by an identifier such as aggregate_id or other information specific to the selection value. Notifications can be triggered by various actions associated with the presentation of a digital component linked to the winning candidate selection value, including rendering of the digital component by application 112, inserting the digital component into content to be presented at application 112, and other actions.

[0118] The notification allows application 112 to provide deduplication functionality by including two Boolean values. The first variable, is_distinct_phantom_value, is true if and only if, when application 112 is triggered to send the notification, this is the first time application 112 has received a dummy value during a specified recent time period as a dummy value that will not be used in the final selection process. For example, if the system's specified time period is four hours when application 112 receives the dummy value, is_distinct_phantom_value is true if this is the first time application 112 has received the dummy value within the past four hours. The variable is_distinct_phantom_value allows the application to ensure that a counter of the number of times a numeric component associated with the dummy value has been distributed is not incremented during repeated final selection processes where the same dummy value wins a previous counterfactual selection process when the selection processes are too close in time. When the selection processes are too close in time and for the same application 112 of the client device 110, the counter of the number of times the digital component associated with the virtual value is distributed is not necessarily incremented, as this may indicate a situation where the digital component associated with the virtual value will not be distributed due to frequency control rules or other content distribution restrictions.

[0119] Furthermore, because the k-anonymity used herein is applied to k different browsers, if the period of time during which the counter looks back on the k-anonymity is 2 days, for example, during this period, the browser will at most request the MPC cluster 130 to increment the k-anonymity counter for a particular digital component once. Furthermore, because this process is performed using secret sharing, the MPC cluster 130 will not be able to detect whether the virtual value and the actual value are the same for a particular digital component request; the browser will request the MPC cluster to increment the counter associated with either the randomly selected virtual value or the actual value.

[0120] A second variable, is_distinct_actual_value, is true if and only if, when application 112 is triggered to send a notification, this is the first time during a specified time period that application 112 has taken an action related to rendering a digital component associated with an actual value, and the actual value differs from the virtual value. For example, when application 112 renders a digital component for presentation at client device 110, if the system's specified time period is a day and this is the first time application 112 has rendered a digital component for presentation at client device 110 within the past day, then is_distinct_actual_value is true. The variable is_distinct_actual_value allows the system to determine, for example, whether the winners of the privacy-preserving selection process and the counterfactual selection process correspond to the same digital component. Each of computing systems MPC1 and MPC2 in MPC cluster 130 only holds a share of each winner's identifier and, therefore, cannot determine whether the winners correspond to the same digital component. However, client device 110 holds the winner in plain text and can notify MPC cluster 130 of any duplication via this variable.

[0121] For example, if a particular digital component is selected to be presented to the same application 112 fifty times in a row, the client device 110 will include in the notification to the MPC cluster 130 information that the digital component's k-anonymity counter will be incremented only once (because it was displayed to the same browser within a short period of time), but other characteristics (such as budgeting, consumption control, frequency control, and muting) will be incremented and tracked normally.

[0122] By providing an update including a request to update the k-anonymity counter, the browser provides deduplication functionality to the MPC cluster 130 and its record keeping. This notification allows the MPC cluster to maintain the integrity of its records and ensure that a particular numeric component meets the k-anonymity requirements without inflating the number due to the same numeric component being provided to the same browser's counting process multiple times within a short period of time. For example, if the client device 110 requests more than one numeric component in the same request, the notification information allows the MPC cluster 130 to attribute only one of the numeric components for the purpose of k-anonymity counting because the browser is targeting the same user.

[0123] In some embodiments, the MPC cluster 130 may include additional logic to deduplicate selections of specific digital components by the same user across different client devices and applications. For example, the system may perform a credential check to determine whether the same user is associated with different client devices and applications, and may deduplicate different browsers or devices where the same user has entered credentials identifying themselves. For example, if a user logs into a browser on their smartphone and logs into a browser on their laptop, the system may determine that the same user is logged in based on the user's credentials using a synchronization mechanism between the browsers.

[0124] Upon receiving the update data, MPC cluster 130 updates the privacy-preserving data structure maintained within a storage medium accessible to MPC cluster 130 (stage 10). The update data may be, for example, an impression notification including the values ​​of is_distinct_phantom_value and is_distinct_actual_value. MPC cluster 130 may update the value of, for example, a counter variable maintained by MPC cluster 130 for tracking k-anonymity. For example, the counter variable may be cached by MPC cluster 130.

[0125] When the impression notification received from the browser indicates that is_distinct_phantom_value is true, the MPC 130 cluster will update the counter of the k-anonymity of the phantom value. In this case, based on the impression notification, the MPC cluster 130 can look up the selected value of is_winnerx=1 from the local storage device or other location of the MPC cluster 130. The impression notification may include an identifier of the distribution opportunity, and the MPC cluster 130 can look up is_winnerx=1 and the selected value mapped to the distribution opportunity identifier. Regardless of the format in which the information is encoded and sent to the MPC cluster 130, the MPC cluster 130 can look up the selected value and update the corresponding counter variable. For example, the computing system MPC1 holds [is_winner x,1 ], and MPC2 holds [is_winner x,2 ]. Thus, each computing system can individually update the corresponding counter variable shared by the selected value. In some embodiments, the MPC cluster 130 will update all counters associated with all eligible digital components, i.e., counter x =counter x +is_winner_x. If is_winner x=0, then the update does not perform an operation. If is_winner_x=1, then the update is equivalent to an increment operation. Therefore, any individual computing system in the MPC cluster 130 cannot access any user information without collusion with other computing systems in the MPC cluster 130.

[0126] In some embodiments, each computing system in MPC cluster 130 has a separate storage device that is inaccessible to other computing systems. This separate storage system reduces the possibility of collusion between computing systems in MPC cluster 130 to compromise user privacy and maintains the integrity of the selection and update processes performed within the system.

[0127] The MPC cluster 130 maintains a list of counters for each possible aggregate_id on all possible cache keys. If is_distinct_actual_value is TRUE, then for any The MPC cluster 130 calculates the is_pp_winner for any selected value x according to the following equation: x The sum of all values ​​increases the counter variable counter aggregate_id , where aggregate_id(x) == aggregate_id.

[0128] ∑ is_pp_winner for any selected value x , where aggregate_id(x) == aggregate_id

[0129] Equation (9)

[0130] In some embodiments, computing system MPC1 may perform this incremental process by iterating through all possible selection values ​​according to the following equation.

[0131] [counter aggregate_id(x),1 ]=[counter aggregate_id(x),1 ]+[is_pp_winner x,1 ]

[0132] Equation (10)

[0133] The computing system MPC2 performs a similar process according to the following equation.

[0134] [counter aggregate_id(x),2 ]=[counter aggregate_id(x),2 ]+[is_pp_wunner x,2 ]

[0135] Equation (11)

[0136] Similarly, upon receiving an impression notification from a browser indicating that is_distinct_phantom_value is true, the MPC cluster can update a counter for the anonymity of the phantom value. In this case, based on the impression notification, the MPC cluster 130 can look up a selected value for is_winnerx=1 from local storage or other locations of the MPC cluster 130. The impression notification can include an identifier for the distribution opportunity, and the MPC cluster 130 can look up is_winnerx=1 and the selected value mapped to the distribution opportunity identifier.

[0137] For any The MPC cluster 130 calculates the is_winner for any selected value x according to the following equation: x The sum of all values ​​increases the counter variable counter aggregate_id , where aggregate_id(x) == aggregate_id.

[0138] ∑ is_pp_wunner for any selected value x , where aggregate_id(x) == aggregate_id

[0139] Equation (12)

[0140] In some embodiments, computing system MPC1 may perform this incremental process by iterating through all possible selection values ​​according to the following equation.

[0141] [counter aggregate_id(x),1 ]=[counter aggregate_id(x),1 ]+[is_pp_winner x,1 ]

[0142] Equation (13)

[0143] The computing system MPC2 performs a similar process according to the following equation.

[0144] [counter aggregate_id(x),2 ]=[counter aggregate_id(x),2 ]+[is_pp_winner x,2 ]

[0145] Equation (14)

[0146] In some embodiments, a vector (in the form of a secret share that protects user privacy) is used to increment a counter stored by the MPC cluster 130. For example, a sparse vector, where only real and imaginary values ​​may have a corresponding vector value of 1 while other values ​​have a corresponding vector value of 0, may be used to update a counter variable.

[0147] In some embodiments, the MPC cluster 130 uses a counter variable to track the k-anonymity eligibility of any cached selection value associated with a particular aggregation_id. For example, the MPC cluster 130 can count the number of times any cached selection value associated with a particular aggregation_id wins the selection process within a given time period and store that value in the counter variable counter for the selection value x. aggregate_id(x) MPC computing systems MPC1 and MPC2 can easily and quickly perform such calculations. However, because MPC cluster 130 is counting the number of times a digital component has won (or potentially won) a selection process, the cluster is unaware of the number of browsers to which the winning cached selection value represented by x or the associated aggregate_id was selected for distribution, and therefore lacks deduplication when incrementing the counter variable. When tracking the k-anonymity eligibility of cached selection values ​​based solely on the MPC cluster 130's count of selection process winners determined by the MPC cluster 130, a particular digital component associated with a particular aggregate_id may receive more counts than actually occurred; for example, all selection process wins may be for the same browser because the digital component is micro-targeting a specific browser. For example, while this approach is simple to implement, if there is a final selection process on the client side at client device 110 that uses the winner of the MPC cluster 130's selection process, the winner of the MPC cluster 130's selection process may not actually be presented for display at client device 110.

[0148] The MPC cluster 130 can update k-anonymity eligibility on a continuous and / or asynchronous basis. Because comparison operations require multiple round trips between MPC computing systems, they are quite expensive. Therefore, the MPC cluster can periodically update k-anonymity eligibility by updating a counter variable to reduce the required computing resources and the amount of processing time required. This allows the system to save communication and transmission costs while minimizing the impact on content distribution and selection. For example, by updating the k-anonymity eligibility counter every minute instead of every millisecond or upon receiving each impression notification, the MPC cluster 130 can reduce traffic between computing systems MPC1 and MPC2 and save transmission costs.

[0149] The counter variable controls eligibility for selection within the system because k-anonymity eligibility is determined using the counter variable. Therefore, if the counter variable is not updated frequently enough, the digital component corresponding to a particular selection value may not be eligible for selection between counter updates even if the k threshold is met. The system operates at such a volume that the impact on regular updates is minimized.

[0150] As mentioned above, the MPC cluster can be aggregate_id(x) Compare with the k-anonymity threshold k to update the flag satisfy_k_anonymity indicating whether the selected value x satisfies k-anonymity x Update flag satisfaction_k_anonymity x This step requires multiple RPCs between MPC1 and MPC2, but because MPC cluster 130 performs the update operation asynchronously, it is not sensitive to latency and remains unaffected by the required processing and communication time.

[0151] Figure 3 is a flow chart illustrating an example process 300 for selecting digital components for distribution to client devices. The operations of process 300 may be implemented, for example, by computing system MPC1 or computing system MPC2 of MPC cluster 130. The operations of process 300 may also be implemented as instructions stored on one or more computer-readable media that may be non-transitory, and execution of the instructions by one or more data processing devices may cause the one or more data processing devices to perform the operations of process 300. For simplicity, process 300 is described as being performed by computing system MPC1 of MPC cluster 130.

[0152] Process 300 begins with a request for selection values ​​being received from an application on a client device by a first server of a secure multi-party computation (MPC) system (302). For example, computing system MPC1 of MPC cluster 130 may receive a request for one or more selection values ​​for a particular digital component slot from client device 110. The request may include information indicating the characteristics of the digital component slot, information about the context of the slot (including the content in which the digital component slot is located), information about content distribution and / or selection rules specified by client device 110 and user-provided information, among other information. In some embodiments, the selection rules are not encoded in the request, but are instead specified directly by the content publisher to SSP 170 or by the content creator to DSP 150.

[0153] In response to receiving the request, process 300 continues as follows: the first server of the secure MPC system collaborates with the second server of the secure MPC system to perform a privacy-preserving selection process to select a first winning selection value from a set of selection values ​​by applying each rule of a set of selection rules including a privacy-preserving anonymity enforcement rule (304). For example, computing system MPC1 of MPC cluster 130 may collaborate with MPC2 to perform the following steps: Figure 2The privacy-preserving selection process described above is described. The MPC cluster 130 applies all selection rules, including the k-anonymity rule as a privacy-preserving anonymity enforcement rule, to all cached selection values ​​matching the UG_Request_Key to determine a set of eligible selection values. The MPC cluster 130 then ranks the eligible selection values ​​and selects the winner of the privacy-preserving selection process.

[0154] In some embodiments, performing the privacy-preserving selection process includes: for each selected value, comparing a value of a counter variable mapped to an aggregate identifier mapped to the selected value with a threshold, and discarding the selected value if the counter variable value is less than the threshold. The selected value is discarded because the selected value is ineligible for the selection process.

[0155] In response to receiving the request, process 300 continues as follows: the first server of the secure MPC system collaborates with the second server of the secure MPC system to perform a counterfactual selection process to select a second winning selected value from a set of selected values ​​that match the UG_Request_Key by applying each rule in a set of selection rules except the privacy-preserving anonymity enforcement rule (306). For example, computing system MPC1 of MPC cluster 130 may collaborate with MPC2 to perform the counterfactual selection process as described in relation to Figure 2 The counterfactual selection process described above is described in detail. The MPC cluster 130 applies all selection rules except the k-anonymity rule to the cached selection values ​​to determine a set of eligible selection values. The MPC cluster 130 then ranks the eligible selection values ​​and selects the winner of the counterfactual selection process.

[0156] As about Figure 2 As described, the privacy-preserving selection process and the counterfactual selection process can be performed in parallel via a batch process, such that the winners of the processes are selected and ready for transmission at the same time.

[0157] Process 300 continues by sending, via a first server of the secure MPC system, the winning selected value from the privacy-preserving selection process and the winning selected value from the counterfactual selection process (308). For example, MPC1 of MPC cluster 130 may provide a secret share of the virtual value, or the winning selected value from the counterfactual selection process, and a secret share of the actual value, or the winning selected value from the privacy-preserving selection process, to client device 110.

[0158] Sending the winning selection value from the privacy preserving selection process and from the counterfactual selection process may include sending a first secret share of the winning selection value to client device 110 via MPC1 of MPC cluster 130 and sending a second secret share of the winning selection value to client device 110 via MPC2 of MPC cluster 130 .

[0159] Process 300 continues by receiving, by a first server of the secure MPC system and from an application on the client device, data indicating that a digital component corresponding to a winning selection value from the privacy-preserving selection process is rendered at the client device (310). For example, MPC1 of MPC cluster 130 may receive an update notification from client device 110 indicating that a digital component for which an actual value is provided is rendered at client device 110.

[0160] In some embodiments, the notification further includes a variable indicating whether the first server of the secure MPC system should increment the value of the privacy-preserving data structure. For example, the notification may indicate whether, at the time the notification was sent, it was the first time the client device received a winning selection value from the counterfactual selection process as the winning selection value of the counterfactual selection process within a specified time period, and a variable indicating whether, at the time the notification was sent, it was the first time the client device received a winning selection value from the privacy-preserving selection process as the winning selection value of the privacy-preserving selection process within the specified time period, and the winning selection value of the privacy-preserving selection process was different from the winning selection value from the counterfactual selection process.

[0161] In some embodiments, a variable indicates whether MPC cluster 130 should increment a counter to support the k-anonymity rule. For example, application 112 may make a decision based on whether application 112 recently instructed MPC1 to increment a counter for a particular selected value. For example, if the virtual value and the actual value are the same, application 112 will instruct MPC1 to increment a counter for at most one of the two values. In another example, if the browser previously instructed MPC1 to increment a counter for a numeric component when the numeric component was mapped to a virtual value, application 112 may refrain from instructing MPC1 to increment a counter in the near future (i.e., within a specific time period for enforcing k-anonymity) when the numeric component is an actual value.

[0162] In addition, the privacy-preserving data structure also includes a second value of the privacy-preserving characteristic of the digital component corresponding to the winning selection value from the privacy-preserving selection process. For example, the MPC cluster 130 may update a counter variable satisfy_k_anonymity for each selection value x. x The variable satisfaction_k_anonymity x Indicates whether the selected value x satisfies the k-anonymity rule. In addition, as mentioned above Figure 2 As described, the notification may include a variable is_distinct_phantom_value, ie, when the notification is sent, it is the first time that the client device 110 has received a phantom value as the phantom value within a specified time period. The notification may also include a variable is_distinct_actual_value.

[0163] The process 300 continues by updating, by the secure MPC system, a privacy-preserving data structure for determining whether the digital component satisfies the privacy-preserving anonymity enforcement rule for maintaining the value of the privacy-preserving property corresponding to the winning choice value from the counterfactual selection process (312). For example, the MPC cluster 130 may update a counter variable satisfy_k_anonymity for each choice value x. x The variable satisfaction_k_anonymity x Indicates whether the selected value x satisfies the k-anonymity rule.

[0164] Each counter variable satisfy_k_anonymity x is mapped to an aggregate identifier, such as aggregate_id. The aggregate identifier is mapped to, for example, a specific numeric component for which one or more selection values ​​are provided as candidate selection values ​​to be used in the selection process. In addition, the secure MPC system can update the privacy-preserving data structure asynchronously and at specified time intervals. For example, the MPC cluster 130 can update the privacy-preserving data structure by updating the variable counter every two minutes. aggregate_id(x) The value of the counter variable represented by is compared with the k-anonymity threshold k to update the counter variable, so as to save the required transmission and computing resources. In some embodiments, if performance optimization is not required, the secure MPC system can synchronously update the privacy-preserving data structure.

[0165] Figure 4 4 is a block diagram of an example computer system 400 that can be used to perform the operations described above. System 400 includes a processor 410, a memory 420, a storage device 430, and an input / output device 440. Each of components 410, 420, 430, and 440 can be interconnected, for example, using a system bus 450. Processor 410 is capable of processing instructions for execution within system 400. In some embodiments, processor 410 is a single-threaded processor. In another embodiment, processor 410 is a multi-threaded processor. Processor 410 is capable of processing instructions stored in memory 420 or on storage device 430.

[0166] Memory 420 stores information within system 400. In one embodiment, memory 420 is a computer-readable medium. In some embodiments, memory 420 is a volatile memory unit. In another embodiment, memory 420 is a non-volatile memory unit.

[0167] The storage device 430 can provide mass storage for the system 400. In some embodiments, the storage device 430 is a computer-readable medium. In various embodiments, the storage device 430 can include, for example, a hard disk device, an optical disk device, a storage device shared by multiple computing devices over a network (e.g., a cloud storage device), or some other mass storage device.

[0168] Input / output device 440 provides input / output operation for system 400.In some embodiments, input / output device 440 may include one or more of network interface devices, for example, an Ethernet card, a serial communication device (for example, and an RS-232 port) and / or a wireless interface device (for example, and an 802.11 card).In another embodiment, input / output device may include a driver device configured to receive input data and send output data to external device 460 (for example, a keyboard, a printer, and a display device).However, other embodiments may also be used, such as mobile computing devices, mobile communication devices, set-top box television client devices, etc.

[0169] Although already Figure 4 An example processing system is described in the specification, but the subject matter and implementation of the functional operations described in this specification may be implemented in other types of digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or a combination of one or more of them.

[0170] Embodiments of the subject matter and operations described in this specification can be implemented in digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or a combination of one or more thereof. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions, encoded on a computer storage medium (or multiple media), for execution by a data processing device or for controlling the operation of the data processing device. Alternatively or additionally, the program instructions can be encoded on an artificially generated propagated signal, such as a machine-generated electrical, optical, or electromagnetic signal, which is generated to encode information for transmission to a suitable receiver device for execution by the data processing device. A computer storage medium can be or be included in a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination of one or more thereof. Furthermore, while a computer storage medium is not a propagated signal, a computer storage medium can be a source or destination of computer program instructions encoded in an artificially generated propagated signal. A computer storage medium can also be or be included in one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices).

[0171] The operations described in this specification can be implemented as operations performed by a data processing apparatus on data stored on one or more computer-readable storage devices or received from other sources.

[0172] The term "data processing apparatus" encompasses all types of apparatus, equipment, and machines for processing data, including, for example, a programmable processor, a computer, a system on a chip, or a plurality of programmable processors, computers, systems on a chip, or a combination thereof. The apparatus may include dedicated logic circuitry, such as an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit). In addition to hardware, the apparatus may also include code that creates an execution environment for the computer program, such as code constituting processor firmware, a protocol stack, a database management system, an operating system, a cross-platform runtime environment, a virtual machine, or a combination of one or more of these. The apparatus and execution environment may implement a variety of different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.

[0173] A computer program (also referred to as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program can, but need not, correspond to a file in a file system. A program can be stored in a portion of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program, or in multiple coordinated files (e.g., files that store one or more modules, subroutines, or portions of code). A computer program can be deployed to execute on one computer or on multiple computers located at one site or distributed across multiple sites and interconnected by a communications network.

[0174] The processes and logic flows described in this specification can be performed by one or more programmable processors executing one or more computer programs to perform actions by operating on input data and generating output. The processes and logic flows can also be performed by, and apparatus can be implemented as, special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit).

[0175] As an example, the processor suitable for executing a computer program includes both a general-purpose microprocessor and a special-purpose microprocessor. Typically, the processor will receive instructions and data from a read-only memory or a random access memory or both. The essential element of a computer is a processor for performing an action according to an instruction and one or more memory devices for storing instructions and data. Typically, a computer will also include one or more large-capacity storage devices (e.g., magnetic disks, magneto-optical disks, or optical disks) for storing data, or may be operably coupled to one or more large-capacity storage devices to receive data from them, or to send data to them, or both. However, a computer does not necessarily have such a device. In addition, a computer can be embedded in another device, for example, a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device (e.g., a universal serial bus (USB) flash drive) etc. Devices suitable for storing computer program instructions and data include all forms of nonvolatile memory, media, and storage devices, including, for example, semiconductor memory devices (e.g., EPROM, EEPROM, and flash memory devices); magnetic disks (e.g., internal hard disks or removable disks); magneto-optical disks; and CD ROM and DVD-ROM disks. The processor and memory can be supplemented by, or incorporated in, special purpose logic circuitry.

[0176] To provide for interaction with a user, embodiments of the subject matter described in this specification may be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and pointing device (e.g., a mouse or trackball) that the user can use to provide input to the computer. Other kinds of devices may also be used to provide for interaction with the user; for example, feedback provided to the user may be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback; and input from the user may be received in any form, including acoustic, voice, or tactile input. In addition, a computer may interact with a user by sending documents to and receiving documents from a device used by the user; for example, by sending a web page to a web browser on a user's client device in response to a request received from the web browser.

[0177] Embodiments of the subject matter described in this specification can be implemented in a computing system that includes a back-end component (e.g., as a data server), or includes a middleware component (e.g., an application server), or includes a front-end component (e.g., a client computer with a graphical user interface or a web browser through which a user can interact with an implementation of the subject matter described in this specification), or includes any combination of one or more such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include local area networks ("LANs") and wide area networks ("WANs"), interconnected networks (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks).

[0178] A computing system may include a client and a server. The client and the server are generally remote from each other and typically interact via a communication network. The relationship between the client and the server arises by means of computer programs running on respective computers and having a client-server relationship with each other. In some embodiments, the server sends data (e.g., an HTML page) to a client device (e.g., for the purpose of displaying data to a user interacting with the client device and receiving user input from the user interacting with the client device). Data generated at the client device (e.g., the result of the user interaction) can be received from the client device at the server.

[0179] In addition to the above embodiments, the following embodiments are also innovative:

[0180] Embodiment 1 is a method comprising: receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selection value; in response to receiving the request and by the first server of the secure MPC system: collaborating with a second server of the secure MPC system to perform a privacy-preserving selection process to select a first winning selection value from a set of selection values ​​by applying each rule in a set of selection rules including a privacy-preserving anonymity enforcement rule; and collaborating with the second server of the secure MPC system to perform a counterfactual selection process to select a second winning selection value from the set of selection values ​​by applying each rule in a set of selection rules except for the privacy-preserving anonymity enforcement rule; sending, by the first server of the secure MPC system, a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process; receiving, by the first server of the secure MPC system and from the application on the client device, a notification including data indicating that a digital component corresponding to the winning selection value from the privacy-preserving selection process is presented at the client device; and updating, by the first server of the secure MPC system, a privacy-preserving data structure for determining whether the digital component satisfies the privacy-preserving anonymity enforcement rule for maintaining a first value of a privacy-preserving characteristic corresponding to the second winning selection value from the counterfactual selection process.

[0181] Embodiment 2 is the method of embodiment 1, wherein the privacy-preserving selection process and the counterfactual selection process are performed in parallel.

[0182] Embodiment 3 is the method of embodiment 1 or 2, wherein the notification further includes a variable indicating whether the first server of the secure MPC system should increment the value of the privacy-preserving data structure.

[0183] Embodiment 4 is the method of any one of embodiments 1-3, wherein the privacy-preserving anonymity enforcement rule is a k-anonymity rule.

[0184] Embodiment 5 is the method of any one of embodiments 1-4, wherein sending the winning selection value from the privacy-preserving selection process includes: sending a first secret share of the winning selection value from the privacy-preserving selection process to the client device through a first server of the secure MPC system; sending a second secret share of the winning selection value from the privacy-preserving selection process to the client device through a second server of the secure MPC system; and wherein sending the winning selection value from the counterfactual selection process includes: sending the first secret share of the winning selection value from the counterfactual selection process to the client device through the first server of the secure MPC system; and sending the second secret share of the winning selection value from the counterfactual selection process to the client device through the second server of the secure MPC system.

[0185] Embodiment 6 is the method of any one of embodiments 1-5, wherein the privacy-preserving data structure comprises a set of counter variables; wherein each counter variable is mapped to an aggregate identifier, wherein each aggregate identifier is mapped to one or more selection values ​​and a specific numeric component, and wherein performing a privacy-preserving selection process to select a first winning selection value from a set of selection values ​​by applying each rule in a set of selection rules including a privacy-preserving anonymity enforcement rule comprises: for each selection value: comparing the counter variable value mapped to the aggregate identifier mapped to the selection value with a threshold; and discarding the selection value if the counter variable value is less than the threshold.

[0186] Embodiment 7 is the method of any one of embodiments 1-6, wherein updating the privacy-preserving data structure is performed asynchronously and at specified time intervals.

[0187] Embodiment 8 is a system comprising: one or more processors; and one or more memory elements comprising instructions that, when executed, cause the one or more processors to perform the method of any one of embodiments 1 to 7.

[0188] Embodiment 9 is a computer storage medium encoded with instructions that, when executed by a distributed computing system, cause the distributed computing system to perform the method of any one of embodiments 1 to 7.

[0189] Although this specification contains many specific implementation details, these should not be interpreted as limiting the scope of any invention or that may be claimed, but rather as descriptions of features specific to particular embodiments of particular inventions. Certain features described in this specification in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented in multiple embodiments individually or in any suitable subcombination. Furthermore, although features may be described above as functioning in certain combinations and even initially claimed as such, one or more features from a claimed combination may be removed from the combination in some cases, and a claimed combination may refer to a subcombination or a variation of a subcombination.

[0190] Similarly, although operations are depicted in a particular order in the accompanying drawings, this should not be understood as requiring that the operations be performed in the particular order shown or in sequential order, or that all of the illustrated operations be performed to achieve the desired result. In some cases, multitasking and parallel processing can be advantageous. Furthermore, the separation of various system components in the above-described embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.

[0191] Thus, specific embodiments of the subject matter have been described. Other embodiments are also within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the particular order shown or sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing may be advantageous.

Claims

1. A computer-implemented method comprising: receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selected value; In response to receiving the request and passing through the secure MPC system, the first server: performing, in cooperation with a second server of the secure MPC system, a privacy-preserving selection process to select a first winning selected value from a set of selected values ​​by applying each rule of a set of selection rules including a privacy-preserving anonymity enforcement rule; and performing, in cooperation with the second server of the secure MPC system, a counterfactual selection process to select a second winning selected value from the set of selected values ​​by applying each rule of the set of selection rules except the privacy-preserving anonymity-enforcing rule; sending, by the first server of the secure MPC system, a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process; receiving, by the first server of the secure MPC system and from the application on the client device, a notification including data indicating that a digital component corresponding to the first winning selection value from the privacy-preserving selection process is presented at the client device, wherein the digital component comprises a discrete unit of digital content or digital information; as well as Updating, by the first server of the secure MPC system, a privacy-preserving data structure for determining whether a digital component satisfies the privacy-preserving anonymity enforcement rule for maintaining a first value of a privacy-preserving property corresponding to the second winning selection value from the counterfactual selection process.

2. The method according to claim 1, wherein The privacy-preserving selection process and the counterfactual selection process are performed in parallel.

3. The method according to claim 1 or 2, wherein: The notification also includes a variable indicating whether the first server of the secure MPC system should increment the value of the privacy preserving data structure.

4. The method according to claim 1, wherein The privacy-preserving anonymity enforcement rule is a k-anonymity rule.

5. The method according to claim 1, wherein Sending the first winning selection value from the privacy preserving selection process includes: sending, by the first server of the secure MPC system, a first secret share of the first winning selection value from the privacy-preserving selection process to the client device; sending, by the second server of the secure MPC system, a second secret share of the first winning selection value from the privacy-preserving selection process to the client device; and Wherein, sending the second winning selection value from the counterfactual selection process comprises: sending, by the first server of the secure MPC system, a first secret share of the second winning selection value from the counterfactual selection process to the client device; and A second secret share of the second winning selection value from the counterfactual selection process is sent to the client device by the second server of the secure MPC system.

6. The method according to claim 1, wherein The privacy-preserving data structure includes a set of counter variables; where each counter variable is mapped to an aggregate identifier, where each aggregate identifier maps to one or more selected values ​​and a specific numeric component, and Wherein, performing the privacy-preserving selection process to select a first winning selected value from a set of selected values ​​by applying each rule in a set of selection rules including a privacy-preserving anonymity enforcement rule comprises: For each select value: comparing a value of a counter variable mapped to the aggregate identifier mapped to the selected value to a threshold value; and If the counter variable value is less than the threshold, the selected value is discarded.

7. The method according to claim 6, wherein: Updating the privacy preserving data structure is performed asynchronously and at specified time intervals.

8. A system for content selection and distribution, comprising: one or more processors; and One or more memory elements including instructions that, when executed, cause the one or more processors to perform operations comprising: receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selected value; In response to receiving the request and passing through the secure MPC system, the first server: performing, in cooperation with a second server of the secure MPC system, a privacy-preserving selection process to select a first winning selected value from a set of selected values ​​by applying each rule of a set of selection rules including a privacy-preserving anonymity enforcement rule; and performing, in cooperation with the second server of the secure MPC system, a counterfactual selection process to select a second winning selected value from the set of selected values ​​by applying each rule of the set of selection rules except the privacy-preserving anonymity-enforcing rule; sending, by the first server of the secure MPC system, a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process; receiving, by the first server of the secure MPC system and from the application on the client device, a notification including data indicating that a digital component corresponding to the first winning selection value from the privacy-preserving selection process is presented at the client device, wherein the digital component comprises a discrete unit of digital content or digital information; and Updating, by a first server of the secure MPC system, a privacy-preserving data structure for determining whether a digital component satisfies the privacy-preserving anonymity enforcement rule for maintaining a first value of a privacy-preserving property corresponding to the second winning selection value from the counterfactual selection process.

9. The system according to claim 8, wherein: The privacy-preserving selection process and the counterfactual selection process are performed in parallel.

10. The system according to claim 8 or 9, wherein: The notification also includes a variable indicating whether the first server of the secure MPC system should increment the value of the privacy preserving data structure.

11. The system according to claim 8, wherein The privacy-preserving anonymity enforcement rule is a k-anonymity rule.

12. The system according to claim 8, wherein: Sending the first winning selection value from the privacy preserving selection process includes: sending, by the first server of the secure MPC system, a first secret share of the first winning selection value from the privacy-preserving selection process to the client device; sending, by the second server of the secure MPC system, a second secret share of the first winning selection value from the privacy-preserving selection process to the client device; and Wherein, sending the second winning selection value from the counterfactual selection process comprises: sending, by the first server of the secure MPC system, a first secret share of the second winning selection value from the counterfactual selection process to the client device; and A second secret share of the second winning selection value from the counterfactual selection process is sent to the client device by the second server of the secure MPC system.

13. The system according to claim 8, wherein: The privacy-preserving data structure includes a set of counter variables; where each counter variable is mapped to an aggregate identifier, where each aggregate identifier maps to one or more selected values ​​and a specific numeric component, and Wherein, performing the privacy-preserving selection process to select a first winning selected value from a set of selected values ​​by applying each rule in a set of selection rules including a privacy-preserving anonymity enforcement rule comprises: For each select value: comparing a value of a counter variable mapped to the aggregate identifier mapped to the selected value to a threshold value; and If the counter variable value is less than the threshold, the selected value is discarded.

14. The system according to claim 13, wherein: Updating the privacy preserving data structure is performed asynchronously and at specified time intervals.

15. A computer storage medium encoded with instructions that, when executed by a distributed computing system, cause the distributed computing system to perform operations comprising: receiving, by a first server of a secure multi-party computation (MPC) system and from an application on a client device, a request for a selected value; In response to receiving the request and passing through the secure MPC system, the first server: performing, in cooperation with a second server of the secure MPC system, a privacy-preserving selection process to select a first winning selected value from a set of selected values ​​by applying each rule of a set of selection rules including a privacy-preserving anonymity enforcement rule; and performing, in cooperation with the second server of the secure MPC system, a counterfactual selection process to select a second winning selected value from the set of selected values ​​by applying each rule of the set of selection rules except the privacy-preserving anonymity-enforcing rule; sending, by the first server of the secure MPC system, a selection result defining the first winning selection value from the privacy-preserving selection process and the second winning selection value from the counterfactual selection process; receiving, by the first server of the secure MPC system and from the application on the client device, a notification including data indicating that a digital component corresponding to the first winning selection value from the privacy-preserving selection process is presented at the client device, wherein the digital component comprises a discrete unit of digital content or digital information; as well as Updating, by the first server of the secure MPC system, a privacy-preserving data structure for determining whether a digital component satisfies the privacy-preserving anonymity enforcement rule for maintaining a first value of a privacy-preserving property corresponding to the second winning selection value from the counterfactual selection process.

16. The computer storage medium of claim 15, wherein: The privacy-preserving selection process and the counterfactual selection process are performed in parallel.

17. The computer storage medium of claim 15 or 16, wherein: The notification also includes a variable indicating whether the first server of the secure MPC system should increment the value of the privacy preserving data structure.

18. The computer storage medium of claim 15, wherein: The privacy-preserving anonymity enforcement rule is a k-anonymity rule.

19. The computer storage medium of claim 15, wherein: Sending the first winning selection value from the privacy preserving selection process includes: sending, by the first server of the secure MPC system, a first secret share of the first winning selection value from the privacy-preserving selection process to the client device; sending, by the second server of the secure MPC system, a second secret share of the first winning selection value from the privacy-preserving selection process to the client device; and Wherein, sending the second winning selection value from the counterfactual selection process comprises: sending, by the first server of the secure MPC system, a first secret share of the second winning selection value from the counterfactual selection process to the client device; and A second secret share of the second winning selection value from the counterfactual selection process is sent to the client device by the second server of the secure MPC system.

20. The computer storage medium of claim 15, wherein: The privacy-preserving data structure includes a set of counter variables; where each counter variable is mapped to an aggregate identifier, where each aggregate identifier maps to one or more selected values ​​and a specific numeric component, and Wherein, performing the privacy-preserving selection process to select a first winning selected value from a set of selected values ​​by applying each rule in a set of selection rules including a privacy-preserving anonymity enforcement rule comprises: For each select value: comparing a value of a counter variable mapped to the aggregate identifier mapped to the selected value to a threshold value; and If the counter variable value is less than the threshold, the selected value is discarded.

21. The computer storage medium of claim 20, wherein: Updating the privacy preserving data structure is performed asynchronously and at specified time intervals.

Citation Information

Patent Citations

  • Pathogenic gene detection method based on privacy protection intersection calculation protocol

    CN111125736A

  • Determining action selection policies of an execution device

    CN112041811A