Using Secure MPC and Vector Computation to Protect Access to Information in Content Distribution
Through secure multi-party computing processes and vector computing, the problems of low user privacy protection and information transmission efficiency in MPC systems are solved, and efficient and secure digital component selection and distribution are achieved.
Patent Information
- Application Number
- CN202280002639.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-01-10
- Filing Date
- 2022-01-06
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-01-06
AI Technical Summary
In the prior art, multi-party computing (MPC) systems cannot effectively protect user privacy when selecting and distributing digital components, and have low information transmission efficiency and high bandwidth and processing power consumption.
The secure multi-party computing (MPC) process is adopted, and the client device cooperates with the MPC cluster to select digital components using probability data structures and vector calculations to ensure that user information is not accessed in plain text and reduce the amount of information transmission.
It realizes that while protecting user privacy, it reduces the consumption of information transmission bandwidth, delay and processing power, and improves information transmission efficiency and security.
Smart Images

Figure CN115088005B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to cryptography and data security. Background Art
[0002] Secure multi-party computation (MPC) is a family of cryptographic protocols that prevent access to data by distributing computations across multiple parties such that no individual party can access the data or intermediate computed values of another party while the output is only released to designated parties. MPC computing systems typically use secret shares of data to perform computations and sometimes perform computations on encrypted data. Summary of the Invention
[0003] Generally, an innovative aspect of the subject matter described in this specification can be embodied in methods that include: receiving, from a client device and by a first computing system in a multi-party computation (MPC) system, a digital component request that includes a first secret share of data identifying a user group of which the user of the client device is a member and a set of context signals; transmitting, by the first computing system, a context digital component request to a content platform; receiving, by the first computing system and from the content platform, selection data for a plurality of digital components, wherein the selection data includes first vector data that defines a context-based vector of values selected at least in part based on the set of context signals; obtaining, by the first computing system and for each of the digital components, second vector data that defines a user-group-based vector of values selected at least in part based on the corresponding user group associated with the digital component; determining, by the first computing system, a selected value for each digital component based on the first vector data and the second vector data; for each digital component, determining a candidate parameter indicating whether the corresponding user group identifier associated with the digital component matches the user group of which the user is a member; generating, based on the selected value and the candidate parameter, a first secret share of a selection result that identifies a given digital component having the highest selected value from among a plurality of candidate digital components, wherein each candidate digital component is a digital component for which the candidate parameter corresponding to the selected value indicates that a second user group identifier corresponding to the selected value matches the user group of which the user is a member; and transmitting, to the client device, the first secret share of the selection result identifying the given digital component. Other implementations of this aspect include corresponding apparatuses, systems, and computer programs encoded on a computer storage device and configured to perform aspects of the methods.
[0004] These and other implementations can each optionally include one or more of the following features. In some aspects, determining, by the first computing system, a selected value for each digital component based on the first vector data and the second vector data includes determining a dot product of the context-based vector of values of the digital component and the user-group-based vector of values.
[0005] In some aspects, the first vector data includes a first secret share of a context-based vector of values and the second vector data includes a first secret share of a user-group-based vector of values. Determining a selected value for each digital component by the first computing system based on the first vector data and the second vector data can include collaborating with one or more second computing systems in a plurality of MPC systems to perform a secure MPC process to determine a dot product of the context-based vector of values and the user-group-based vector of values of the digital component.
[0006] In some aspects, the selected value for each digital component is based on a user's user profile. Determining a selected value for each digital component by the first computing system based on the first vector data and the second vector data can include determining a dot product of the context-based vector of the digital component, the user-group-based vector of the digital component, and the user profile vector of the user's user profile.
[0007] In some aspects, determining a first secret share of a candidate parameter for each selected value includes determining a first secret share of a candidate parameter for each selected value. In some aspects, generating a first secret share of a selection result includes: generating an order of the selected values based on the magnitude of each selected value; determining a first secret share of a cumulative value of each selected value based on the order of the selected values and the candidate parameter of each selected value; for each selected value, determining a first secret share of a winner parameter based on (i) the candidate parameter of the selected value and (ii) the result of an equality test indicating whether the cumulative value of the selected value is a specified value; and for each selected value, determining a first secret share of the sum of the product of the winner parameter of the selected value and the digital component information element of the selected value as the first secret share of the selection result.
[0008] In some aspects, determining a first secret share of a cumulative value of each selected value includes: for each individual selected value, determining a quantity of selected values including the highest selected value and the individual selected value between the highest selected value and the individual selected value, the quantity of selected values having a candidate parameter indicating that a second user group identifier corresponding to the selected value matches at least one of one or more first user group identifiers.
[0009] The subject matter described in this specification can be implemented in particular embodiments so as to achieve one or more of the following advantages. Using a secure MPC process performed by two or more MPC servers operated by different parties to select digital components based on secret shares of user information ensures that user information cannot be accessed in plaintext by the MPC servers or another party in the absence of unauthorized collusion between the MPC servers.
[0010] During the digital component selection process, the MPC server can select from eligible digital components that meet one or more eligibility criteria while preventing parties from accessing user information in plain text. The eligibility criteria can include restrictions and guidelines on the manner or frequency of distribution of digital components, as well as other factors. These criteria can include user group membership, frequency control, muting, budget, k-anonymity, and / or pacing constraints.
[0011] The user's client device can generate a probabilistic data structure, such as a cuckoo filter, representing user groups of which the user is a member, and generate distributed point functions, one for each user group of which the user is a member. The distributed point functions are secret shares that cryptographically represent whether the user is a member of the user group. Using the probabilistic data structure and / or distributed point functions in this way protects user privacy by preventing access to the user's group membership and reduces the size of the information provided to the MPC cluster. This reduction in data size reduces the amount of bandwidth consumed in transmitting the information, reduces the latency in transmitting the information, and reduces the amount of processing power and associated battery power required for a device operating on battery (e.g., a mobile device) to transmit the information.
[0012] The MPC cluster can transmit the secret shares identifying the results of the selected digital components selected by the MPC cluster using a secure MPC process. By only sending the secret shares of the results of the selected digital components, rather than sending information about all digital components or a large set of digital components, the bandwidth, latency, processing power, and battery power consumed in transmitting and receiving the results are similarly reduced. This also reduces the potential leakage of confidential information of the content platform that submits the selected values of the digital components to the MPC cluster by restricting the number of digital components providing information to the client device.
[0013] The selected values and information about their corresponding digital components can be stored in a data structure using a set of context signals as keys for each selected value. However, this can result in a large number of keys for selected values that are eligible only in very specific contexts. For example, a content platform may want to use different selected values for each of many different contexts. Using vectors of values generated based on context signals and vectors of values generated for user groups to determine the selected values of digital components, vector calculations can be used to significantly reduce the amount of data stored in the data structure, thereby reducing the data storage requirements for storing many different selected values for many different contexts. Vector calculations also achieve more flexibility in accurately specifying selected values for various digital components in context, while also enabling the enforcement of publisher controls on which digital components can be presented with the publisher's content. Secret sharing can be used to perform the vector calculations such that vectors of values based on the user profile can be used to determine the selected values without exposing the user information to the MPC cluster or other parties.
[0014] Details of one or more embodiments of the subject matter described in this specification are set forth in the following figures and description. Other features, aspects, and advantages of the subject matter will become apparent from the specification, the figures, and the claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is a block diagram of an environment in which an MPC cluster performs a secure MPC process to select digital components for distribution to client devices.
[0016] Figure 2 illustrates Figure 1 an example data flow within the environment of.
[0017] Figure 3 is a swimlane diagram of an example process for selecting digital components for presentation at a client device.
[0018] Figure 4 is a swimlane diagram of an example process for selecting digital components for distribution to client devices.
[0019] Figure 5 is a flowchart illustrating an example process for selecting digital components for distribution to client devices.
[0020] Figure 6 is a block diagram of an example computer system.
[0021] Like reference numerals and names in the various figures indicate like elements. DETAILED DESCRIPTION
[0022] Generally, this document describes secure systems and techniques for protecting information in content selection and distribution. An MPC cluster of a server computer is capable of performing a secure MPC process to select digital components based on user information without any MPC server being able to access the user information in plaintext without unauthorized collusion. A probabilistic data structure (such as a cuckoo filter) can be used to send user information to the MPC cluster to reduce the data size of the information transmitted over the network and to keep the information secure during transmission.
[0023] The MPC cluster can use vector computations (such as vector dot product computations) to determine a selection value for a digital component. For example, the MPC cluster can determine a selection value for a digital component by determining the dot product between a vector of values generated for a user group for the digital component and a vector of values generated for the digital component presentation environment based on context signals. The selection value can indicate the amount that a digital component provider is willing to provide for presentation or user interaction with the digital component.
[0024] Figure 1FIG. is a block diagram of an environment 100 in which an MPC cluster performs a secure MPC process to select digital components for distribution to client devices 110. Example environment 100 includes a data communication network 105, such as a local area network (LAN), a wide area network (WAN), the Internet, a mobile network, or a combination thereof. Network 105 connects client devices 110, a secure MPC cluster 130, a publisher 140, a website 142, a content platform, such as a supply-side platform (SSP) 170, and a demand-side platform DSP (150). Example environment 100 may include a number of different client devices 110, secure MPC clusters 130, publishers 140, websites 142, DSPs 150, and SSPs 170.
[0025] Client device 110 is an electronic device capable of communicating via network 105. Example client devices 110 include personal computers, mobile communication devices, such as smart phones, and other devices capable of sending and receiving data via network 105. The client device can also include a digital assistant device that accepts audio input via a microphone and outputs audio output via a speaker. When the digital assistant detects a "hot word" or "hot phrase" that activates the microphone to accept audio input, the digital assistant can be placed in a listening mode (e.g., ready to accept audio input). The digital assistant device can also include a camera and / or a display to capture images and visually present information. The digital assistant can be implemented in different forms of hardware devices, including wearable devices (e.g., watches or glasses), smart phones, speaker devices, tablet devices, or another hardware device. The client device can also include a digital media device, such as a streaming device that plugs into a television or other display to stream video to the television, a gaming system, or a virtual reality system.
[0026] Client device 110 generally includes an application 112, such as a web browser and / or a native application, to facilitate sending and receiving data via network 105. A native application is an application developed for a specific platform or a specific device (e.g., a mobile device with a specific operating system). Publisher 140 can develop and provide (e.g., make available for download) a native application to client device 110. For example, in response to a user of client device 110 entering the resource address of resource 145 in the address bar of a web browser or selecting a link that references the resource address, the web browser can request resource 145 from a web server of website 142 that hosts publisher 140. Similarly, a native application can request application content from a remote server of the publisher.
[0027] Some resources, application pages, or other application content can include digital component slots for presenting digital components together with Resource 145 or the application page. As used throughout this document, the phrase "digital component" refers to discrete units of digital content or digital information (e.g., video clips, audio clips, multimedia clips, images, text, or another content unit). Digital components can be stored electronically in a physical memory device as a single file or as a collection of files, and digital components can take the form of video files, audio files, multimedia files, image files, or text files, and include advertising information such that an advertisement is a type of digital component. For example, a digital component can be content that is intended to supplement the content of a web page or other resource presented by Application 112. More specifically, a digital component can include digital content related to the resource content (e.g., the digital component can relate to the same topic as the web page content or a related topic). Thus, the provision of digital components can supplement and generally enhance web page or application content.
[0028] When Application 112 loads a resource (or application content) that includes one or more digital component slots, Application 112 can request digital components for each slot. In some embodiments, the digital component slot can include code (e.g., a script) that causes Application 112 to request a digital component from a digital component distribution system that selects a digital component and provides the digital component to Application 112 for presentation to a user of Client Device 110. As described below, Application 112 can request digital components from MPC Cluster 130 and / or one or more SSPs 170.
[0029] Some Publishers 140 use SSP 170 to manage the process of obtaining digital components for the digital component slots of their resources and / or applications. SSP 170 is a technology platform implemented in hardware and / or software that automates the process of obtaining digital components for resources and / or applications. Each Publisher 140 can have a corresponding SSP 170 or multiple SSPs 170. Some Publishers 140 can use the same SSP 170.
[0030] The digital component provider 160 can create (or otherwise publish) digital components that are presented in the digital component slots of the publisher's resources and applications. The digital component provider 160 can use the DSP 150 to manage the provision of its digital components for presentation in the digital component slots. The DSP 150 is a technology platform implemented in hardware and / or software that automates the process of distributing digital components for presentation with resources and / or applications. The DSP 150 can interact with multiple supply-side platforms SSPs on behalf of the digital component provider 160 to provide digital components for presentation with the resources and / or applications of multiple different publishers 140. Generally, the DSP 150 can receive a request for a digital component (e.g., from an SSP), generate (or select) a selection value for one or more digital components created by one or more digital component providers based on the request, and provide data related to the digital component (e.g., the digital component itself) and selection parameters to the SSP. The selection value can indicate the amount that the digital component provider 160 is willing to provide for the presentation or user interaction with the digital component. The SSP can then select the digital component to be presented at the client device 110 and provide the client device 110 with the data that causes the client device 110 to present the digital component.
[0031] In some cases, it is beneficial for the user to receive digital components related to a web page, application page, or other electronic resource that the user has previously visited and / or interacted with. To distribute such digital components to the user, when the user accesses a specific resource or performs a specific action on the resource (e.g., interacts with a specific item presented on a web page or adds the item to a virtual shopping cart), the user can be assigned to a user group, such as a user interest group, a group of similar users, or other group types involving similar user data. The user group can be generated by the digital component provider 160. That is, each digital component provider 160 can assign the user to their user group when the user accesses the electronic resource of the digital component provider 160. The user group can also be created by a content platform, such as by the DSP 150 and / or the SSP 170.
[0032] To protect user privacy, user group membership can be maintained at the user's client device 110, e.g., by one of the applications 112 or the operating system of the client device 110, rather than by the digital component provider, content platform, or other parties. In a particular example, a trusted program (e.g., a web browser or operating system) can maintain a list of user group identifiers ("user group list") for a user using a web browser or another application (e.g., a user logged into the browser, application, or client device 110). The user group list can include the group identifier for each user group that the user is a member of. The digital component provider 160 that creates user groups can assign user group identifiers to their user groups. The user group identifier of a user group can describe the group (e.g., gardening group) or be a code representing the group (e.g., a non - descriptive alphanumeric sequence). The user's user group list can be stored in a secure storage at the client device 110 and / or can be encrypted when stored to prevent others from accessing the list.
[0033] When the application 112 presents a resource related to the digital component provider 160 or application content or a web page on the website 142, the resource can request the application 112 to add one or more user group identifiers to the user group list. In response, the application 112 can add one or more user group identifiers to the user group list and securely store the user group list.
[0034] The MPC cluster 130 can use the user's user group membership to select digital components or other content that the user may be interested in or that is otherwise beneficial to the user / user device. For example, such digital components or other content can include data that improves the user experience, improves the operation of the user device, or benefits the user or user device in some other way. However, the user group identifiers of the user's user group list can be provided and used in a way that prevents the computing systems MPC1 and MPC2 in the MPC cluster 130 from accessing the user's user group identifiers in plain text when selecting digital components, thus protecting user privacy when using user membership data to select digital components. Plain text is text that is not computationally marked, specially formatted, or written in code or data (including binary files) in a form that can be viewed or used without a key or other decryption device or other decryption process.
[0035] The secure MPC cluster 130 includes two computing systems MPC1 and MPC2 (e.g., server computers) that perform secure MPC processes to select digital components for distribution to client devices of users based on user group membership, but do not access the membership information in plain text. Although the example MPC cluster 130 includes two computing systems, more computing systems can also be used as long as the MPC cluster 130 includes more than one computing system. For example, the MPC cluster 130 can include three computing systems, four computing systems, or other appropriate numbers of computing systems. Using more computing systems in the MPC cluster 130 can provide more security, but can also increase the complexity of the MPC process.
[0036] The computing systems MPC1 and MPC2 can be operated by different entities. In this way, each entity may not be able to access the complete user profile in plain text. For example, one of the computing systems MPC1 or MPC2 can be operated by a trusted party different from the user, publisher 140, DSP 150, SSP 170, and digital component provider 160. For example, an industry group, a government group, or a browser developer can maintain and operate one of the computing systems MPC1 and MPC2. Other computing systems can be operated by a different one of these groups such that different trusted parties operate each of the computing systems MPC1 and MPC2. Preferably, the different parties operating the different computing systems MPC1 and MPC2 have no incentive to collude to compromise user privacy. In some embodiments, the computing systems MPC1 and MPC2 are architecturally separated and are monitored to not communicate with each other except for performing the secure MPC processes described herein.
[0037] Each of the computing systems MPC1 and MPC2 can store a vector of values for determining selection values of digital components. For example, as part of a previous digital component selection process, the computing systems MPC1 and MPC2 can cache vectors previously received from the SSP 170 and / or DSP 150. In this way, the MPC cluster 130 can use the vectors to select digital components for distribution to the client device 110 in response to future user group-based digital component requests received from the client device 110.
[0038] The computing systems MPC1 and MPC2 can store a user group-based vector V of values of digital components (e.g., digital components to be provided to users who are members of a user group) ug . The values can be floating-point values or values in different computer number formats. Such a user group-based vector V ug can be used to determine selection values of digital components for use in a digital component selection process in order to select digital components to be distributed for presentation to users in a user group. The user group-based vector Vug can include multiple elements across two or more dimensions and each element can represent a specific characteristic of a digital component presentation opportunity. For example, a user-group-based vector V of values ug can include elements for: a geographical location or region, a spoken language, an age or age range, a specific URL of a web page or other electronic resource, a specific product or service, whether a digital component slot is above or below the fold, the type of digital component slot, the size of the digital component slot, the number of digital component slots on an electronic resource, the time of day, a web property identifier, and / or other suitable characteristics of the digital component presentation opportunity. In some implementations (such as those employing neural networks), the user-group-based vector V ug can be an embedding of the user group in some abstract vector space.
[0039] The value of each element can reflect the amount by which the selection value of the digital component is to be increased or decreased based on the current digital component presentation opportunity having the characteristic corresponding to that element. For example, if DSP 150 wants to present a digital component to users in Atlanta rather than Dallas, the value of the element for Atlanta can be a positive value greater than one, while the value of the element for Dallas can be a positive value less than one (e.g., zero) or a negative value. As described in more detail below, these values can be part of a vector dot product calculation that determines the selection value of the digital component.
[0040] In some embodiments, each of the computations MPC1 and MPC2 uses a two-level look-up table (LUT) to store the user-group-based vector V of values of the digital component ug . Using a two-level LUT can provide some performance advantages, but other suitable data structures can also be used. The first level can be keyed by a user-group request key (UG_Request_Key). The UG_Request_Key can be a composite message based on a set of context signals, such as a set of context signals for a digital component request (e.g., URL, location, language, etc.) or a set of context signals for which the digital component is eligible for distribution. That is, the first-level LUT can be keyed based on a set of context signals. The key of the first level can be a hash of the UG_Request_Key, for example, using a hash function such as SHA256. The key can be truncated to a specified number of bits, such as 16 bits, 32 bits, or other suitable number of bits. The value of each key UG_Request_Key in the first-level LUT can indicate the row of a second-level LUT that contains data for digital component requests that include the digital component eligible for the context signals including the UG_Request_Key. An example first-level LUT is shown in Table 1 below.
[0041] Key Value SHA256(UG_Request_Key) Line… … Line…
[0042] Table 1
[0043] The second - level LUT can be keyed based on a combination of the user - group request key UG_Request_Key and the user - group identifier in the first - level LUT. Each row in the second - level LUT can be used for a specific selection value of a specific digital component. For example, DSP 150 can submit different selection values for the same digital component, where each selection value is for a different set of context signals and / or different user - group identifiers. Thus, the selection value of a digital component can vary based on context and other factors.
[0044] DSP 150 or the digital - component provider 160 can associate (e.g., link or map) a digital component to the user group to which DSP 150 or the digital - component provider wants to present the digital component. For example, DSP 150 may want to present digital components related to men's basketball shoes to males who have shown an interest in basketball and / or shoes. In this example, DSP 150 can provide data to the MPC cluster 130 indicating a user - group identifier for the user group corresponding to the digital component that includes males who have shown an interest in basketball and / or shoes.
[0045] In some embodiments, the key for a row in the second - level LUT can be a hash or code generated based on a combination of the user - group request key UG_Request_Key and the user - group identifier of the digital component for that row. For example, the key can be a hash - based message authentication code (HMAC) of the combination, which can be represented as HMAC SHA256 (UG_Request_Key, ug_id). The user - group identifier ug_id can be based on a combination of the internal user - group identifier of the user group and the domain of the owner of the user group (e.g., the DSP, SSP, or digital - component provider that owns the user group). For example, the user - group identifier ug_id can be the HMAC of the eTLD + 1 of the owner domain and the internal user - group identifier of the owner of the user group. The eTLD + 1 is the effective top - level domain (eTLD) plus one level more than the public suffix. An example of eTLD + 1 is “example.com”, where “.com” is the top - level domain. The ug_id can be truncated to 16 bytes or other appropriate data size.
[0046] Continuing with the example of the men's basketball shoes, the second-level lookup key for the row containing information about the digital component to be presented to the users in the men's basketball shoes group can be the combination of the user group request key UG_Request_Key and the user group identifier ug_id of the men's basketball shoes group. Since the digital component can be presented in different contexts, the second-level lookup table can include multiple rows of digital components associated with the user group identifier ug_id of the men's basketball shoes group, each row having a different user group request key UG_Request_Key and a different value.
[0047] The value of each row of the second-level LUT can be the user-group-based vector V of the digital component ug and other data of the digital component, for example, metadata that identifies the digital component or the network location from which the digital component can be downloaded, etc. An example second-level LUT is shown in Table 2 below.
[0048] Key Value HMAC(UG_Request_Key,UG_ID) <![CDATA[{V ug , metadata}]]> … …
[0049] Table 2
[0050] The second-level LUT maps the user-group-based vector V ug to a specific digital component, to a specific user group identifier ug_id, and to a specific set of context signals defined by the first-level lookup key UG_Request_Key. By doing so, the second-level LUT indicates the specific context of the digital component slot for which the user-group-based vector V ug is eligible. Since the user-group-based vector V ug defines the selection value based on a combination of potentially numerous characteristics of the digital component presentation opportunity, the number of context signals of the first-level lookup key UG_Request_Key can be minimized, for example, to specify a specific resource with which the digital component can be presented. This reduces the number of rows in the table required to specify a specific selection value for a specific context.
[0051] When a digital component request indicating that the user to whom the digital component will be presented is a member of a specific user group identified by a specific user group identifier ug_ig and the digital component will be presented in a specific context defined by the context signals of the first-level lookup key is received, any digital component with a matching user group identifier and a matching first-level lookup key is a candidate for selection for distribution in response to that request. Although a two-level LUT is used in this example, other suitable data structures can also be used.
[0052] In addition to the description throughout this document, controls (e.g., user interface elements with which a user can interact) can be provided to the user to allow the user to select whether and when the systems, programs, or features described in this document can enable the collection of user information (e.g., information about the user's social network, social actions or activities, occupation, user preferences, or user's current location), and whether to send content or communications to the user from a server. Additionally, before storing or using certain data, it can be disposed of in one or more ways such that personally identifiable information is removed. For example, the user's identity can be disposed of such that the user's personally identifiable information cannot be determined, or the user's geographical location can be generalized (e.g., to a city, zip code, or state level) when location information is obtained such that the user's specific location cannot be determined. Thus, the user can control what information about the user is collected, how that information is used, and what information is provided to the user.
[0053] Figure 2 Shows Figure 1 An example data stream 200 within the environment of. In phase A, application 112 transmits a digital component request to MPC cluster 130. The digital component request can be for a digital component to be presented in a digital component slot of the content to be presented by application 112.
[0054] The request can include data about the user's user group membership of the user using application 112, such as in the secret shares described below, and context signals for the digital component slot. The context signals can describe the digital component presentation opportunity by including signals such as: the geographical location of client device 110, the spoken language used by application 112, the URL of the content including the digital component slot, whether the digital component is above or below the first screen, the type and / or size of the digital component slot, the current time of day at the location of client device 110, the web property identifier of the content, and / or other appropriate features.
[0055] If application 112 supports cookies, the request can also include first-party cookies of the publisher of the content including the digital component slot. This can enable SSP 170 and / or DSP 150 to use additional user data when selecting digital components for consideration for presentation in the digital component slot.
[0056] If supported by application 112, the request can also include a group identifier of a user group that includes the user of application 112 as a member. This group identifier is a low-entropy (e.g., 16 - 20 bits) identifier of a group of users determined to have similar cross-domain browsing patterns at each device without sharing information from the device. This can enable SSP 170 and / or DSP 150 to infer additional information about the user of application 112.
[0057] In stage B, the MPC cluster 130 transmits a contextual digital component request to the SSP 170 for a publisher that includes the content of the digital component slot. This request can include a contextual signal, a first-party cookie, and / or a group identifier. This request does not include user membership data.
[0058] In stage C, the SSP 170 sends the contextual digital component request to one or more DSPs 150. In stage D, the DSP 150 generates digital component selection data and transmits it to the SSP 170. This selection data can include a context-based vector V generated by the DSP 150 based on the information included in the contextual digital component request (e.g., based on the contextual signal) and using the information obtained or inferred based on the first-party cookie and / or group identifier. context 。
[0059] For each DSP 150, its context-based vector V context can have the structure of its user-group-based vector V stored by the MPC cluster 130. This enables the MPC cluster 130 to perform a dot product calculation to determine, for each user-group-based vector V of the DSP 150 ug the selection value of the digital component corresponding to that user group. For example, the context-based vector V of the DSP 150 ug can have the same dimensions and features as each of its user-group-based vectors V context However, the DSP 150 can determine the value of the context-based vector V ug based on the information in the contextual digital component request to generate a customized selection value for the digital component request. For a given contextual digital component request, each DSP 150 can provide a single context-based vector V context to be used in determining the selection value of each of its digital components for which the user-group-based vector V context is stored at the MPC cluster 130. ug
[0060] In addition to providing the context-based vector V context the DSP 150 can also provide one or more conditional selection values or vectors to be stored at the MPC cluster 130 for current or future digital component requests. For example, the DSP 150 can piggyback a new or updated user-group-based vector V ug to be stored at the MPC cluster 130 onto the response. With each user-group-based vector V ug, the DSP 150 can provide other data to be stored at the MPC cluster 130, such as the user group request key UG_Request_Key of the vector and / or the metadata of the vector. The vector can be split into secret shares and / or digital signatures by the DSP 150 before being sent to the SSP 170 to protect user privacy, protect trade secret information, prevent the computing systems MPC1 and MPC2 from accessing the information in plaintext, and / or prevent man-in-the-middle attacks or eavesdropping (e.g., between the DSP 150 and the SSP 170 or between other collaborators in between, but not shown in Figure 2 ).
[0061] The DSP 150 can also provide an unconditional selection value (e.g., not conditional on user group membership and other sensitive information not present in phases B and C) and data for a digital component that is considered to be a digital component selected to be presented at the client device 110 in response to a digital component request. Such a digital component can be provided only for the current digital component request and not stored by the MPC cluster 130 for future digital component requests.
[0062] In phase E, the SSP 170 transmits the vector and / or selection value received from the DSP 150 to the MPC cluster 130. As described in more detail below, the SSP 170 can apply publisher controls to the vector and / or selection value before transmitting the vector and / or selection value to the MPC cluster 130. In some implementations, the SSP 170 can modify the vector and / or selection value to account for the sharing arrangement before sending the vector and / or selection value to the MPC cluster 130.
[0063] In phase F, the MPC cluster 130 performs a digital component selection process and transmits the selection result to the application 112. An example selection process is illustrated in Figure 4 and described below. The MPC cluster 130 can also store the user group-based vector V ug and the associated metadata / keys related to the corresponding digital components for use in subsequent digital component selection processes.
[0064] In phase G, the application 112 transmits a notification to the MPC cluster 130. The notification can identify the digital component presented by the application and / or include data indicating whether the digital component has been user-interacted with (e.g., selected) by the application 112. In some implementations, the notification in phase G can be piggybacked on the digital component request in phase A in the near future. This piggybacking reduces the number of requests sent by the application 112 and can reduce the network and battery consumption of the application 112.
[0065] Figure 3FIG. 0 is a swimlane diagram of an example process 300 for selecting digital components for rendering at a client device. Operations of process 300 can be implemented, for example, by client device 110, computing systems MPC1 and MPC2 in MPC cluster 130, and DSP 150. Operations of process 300 can also be implemented as instructions stored on one or more computer-readable media, which can be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operations of process 300. Although process 300 and other processes below are described in terms of two computing systems in MPC cluster 130, MPC clusters with more than two computing systems can also be used to perform similar processes. Additionally, operations of process 300 can be implemented by SSP 170.
[0066] DSP 150 provides user-group-based vector V of digital components to MPC cluster 130 (302) ug . For example, the DSP can provide user-group-based vector V of digital components to MPC cluster 130 via SSP 170 ug . As described above, DSP 150 can provide user-group-based vector V together with context-based vector V context (e.g., piggybacked on a response that includes context-based vector V context ). However, user-group-based vector V ug can be one of two inputs for a dot product calculation for a future digital component request, while context-based vector V ug is one of two inputs for a dot product calculation for a current digital component request. MPC cluster 130 can store user-group-based vector V context together with the corresponding digital components and / or their associated metadata for future digital component requests received from client device 110. In another example, DSP150 can provide user-group-based vector V of digital components outside of a digital component request, for example, based on generating a new or updated user-group-based vector V ug . ug . ug .
[0067] For each digital component, the DSP 150 is also capable of uploading additional data for the digital component, such as metadata. The additional data for the digital component can include a user group identifier for a user group corresponding to the digital component. The data for the digital component can also include a set of user group request keys UG_Request_Key for a context selection signal based on a context (e.g., the location of the client device 110, the spoken language selected for the application 112, the uniform resource locator (URL) of a resource with which the digital component can be presented) indicating for which the digital component is eligible. The MPC cluster 130 caches or otherwise stores a user group-based vector V of digital components provided to the MPC cluster 130 for future digital component requests ug . As described above, data can be stored in a two-level LUT or other suitable data structure.
[0068] The client device 110 receives content (304). For example, the client device 110 can receive an electronic resource (e.g., a web page) for rendering by a web browser or application content for rendering by a native application. The content can include one or more digital component slots that include computer-readable code, such as a script, that, when executed, causes the client device 110 to request a digital component for each slot. The client device 110 can render the content on a display of the client device 110.
[0069] The client device 110 identifies a set of user group identifiers (306). The set of user group identifiers can be user group identifiers for user groups of which the user is a member. For example, the set of user group identifiers can be user group identifiers in a user group list. The application 112 that presents the content or the trusted program can identify the set of user group identifiers, for example, by accessing a user group list from secure storage of the client device 110.
[0070] To protect the user's privacy such that the computing systems of the MPC cluster 130 cannot access the user's user group identifiers, the application 112 can send a corresponding secret share of the user group identifier to each computing system of the MPC cluster 130. In this example, the application 112 sends a distributed point function representing the secret share of the user identifier. However, other suitable secret sharing techniques can be used, including sending a cuckoo filter to the MPC cluster 130 as described below.
[0071] Application 112 or a trusted program can use a set of user group identifiers to generate a probabilistic data structure (308). In some embodiments, the probabilistic data structure is a cuckoo filter with a table using two hash functions F1 and F2. Cuckoo hashing is a hashing method that uses two (or more) tables with a total of (1 + ε)N entries to store N items, such as user group identifiers, such that each entry will contain at most one item. Additionally, each item, such as a user group identifier, will appear in one of two entries defined by one of the two hash functions F1 and F2, whose output is the set [(1 + ε)N]. The item associated with key k will appear at position F1(k) in the first table or position F2(k) in the second table. For a reasonably large number of N items (e.g., N ≥ 1000), using ε = 0.1 is sufficient, meaning that N items can be hashed using cuckoo hashing with a combined table size of 1.1N. In these expressions, ε can be referred to as the load factor.
[0072] To construct a sparse private information retrieval data structure using a cuckoo filter, up to N user group identifiers are hashed into two (or more) tables using cuckoo hashing, which have a combined size of 1.1N or another appropriate size. All empty entries can be replaced with 0-bit strings. To query the user group identifier associated with key k, the user group identifier (if it exists in the data structure) will appear at entry F1(k) in the first table or F2(k) in the second table. Using a table size C = 1.1N will result in 1 ≤ F1(ug_id), F2(ug_id) ≤ C.
[0073] Client device 110 can generate a cuckoo filter by computing two possible positions for each user group identifier in the set of user group identifiers using both hash functions F1 and F2. If at least one of the two possible positions is empty, client device 110 can insert the element into the empty position, which can be in either table, to complete the insertion process for that user group identifier. If both positions are occupied, client device 110 randomly selects a position and swaps the item currently in that position with the item to be inserted. Client device 110 can then recompute the two hash functions F1 and F2 and attempt the insertion again. This process is repeated until the insertion is successful for each user group identifier in the set of user group identifiers or too many attempts fail. After constructing the cuckoo filter, each user group identifier ug_id is stored at a specific index in the table.
[0074] The client device 110 generates a distributed point function (310). The application 112 or a trusted program can use the point function and the cuckoo filter table to generate the distributed point function. The distributed point function represents a secret share of the point function. Generally, a point function is a function f i :[N][N], where f(x) = 0 when x!= i and f(i) = 1. The point function f i has a secret sharing that is two functions g i :[N]->[N] and h i :[N]->[N], such that for all x in the set [N], f i (x) = g i (x) + h i (x). Additionally, given the specification of either function h i or g i (but not both), it is impossible to recover the original function f i .
[0075] For each ug_id, a point function G ug_id is required, which can be split into distributed point functions g ug_id,1 and g ug_id,2 such that for the following relations 1 and 2 are satisfied.
[0076] If i = F1(ug_id), then G ug_id (i) = g ug_id,1 (i) + g ug_id,2 (i) = ug_id, (1)
[0077] Otherwise G ug_id (i) = g ug_id,1 (i) + g ug_id,2 (i) = 0, (2)
[0078] Similarly, a point function H ug_id is required, which can be split into distributed point functions h ug_id,1 and h ug_id,2 such that for the following relations 3 and 4 are satisfied.
[0079] If i = F2(ug_id), then H ug_id (i) = h ug_id,1 (i) + h ug_id,2 (i) = ug_id (3)
[0080] Otherwise H ug_id (i) = h ug_id,1 (i) + h ug_id,2 (i) = 0 (4)
[0081] That is, a distributed point function that can evaluate a specific point function at multiple possible points (e.g., multiple possible user group identifiers), but the result is always zero except for the user group identifier ug_id of the user group that includes the user as a member and for which the distributed point function is generated. The distributed point function has a very small data size, which can be transmitted over the network without using too much bandwidth and with low latency compared to sending other encrypted forms of the user group identifier.
[0082] For a given user group identifier ug_id, a corresponding first table of the point function F1 and the cuckoo filter, the client device 110 generates a distributed point function g for the computing system MPC1 ug_id,1 and a distributed function g for the computing system MPC2 ug_id,2 . Similarly, for a given user group identifier ug_id, a corresponding second table of the point function F2 and the cuckoo filter, the client device 110 generates a distributed point function h for the computing system MPC1 ug_id,1 and a distributed point function h for the computing system MPC2 ug_id,2 .
[0083] The client device 110 transmits a digital component request (312) to the MPC cluster 130. The digital component request can include a distributed point function. The client device 110 can transmit to the computing system MPC1 a digital component request that includes each distributed point function g ug_id,1 and each distributed point function h ug_id,1 . The digital component request can include a first-level lookup key, such as SHA256(UG_Request_Key). The client device 110 can generate the first-level lookup key based on the context signal of the digital component request. For example, the client device 110 can generate the first-level lookup key by generating a composite message that includes context signals such as the URL of the resource with which the selected digital component will be presented, the location of the client device 110 that submits the digital component request, the spoken language of the application 112 that will present the selected digital component, etc. The client device 110 can then apply a hash function, such as the SHA256 function, to the composite message to generate the first-level lookup key.
[0084] Similarly, the client device 110 can transmit to the computing system MPC2 a digital component request that includes each distributed point function g ug_id,2 and each distributed point function h ug_id,2Digital component requests. The digital component requests can also include a first-level lookup key, such as SHA256(UG_Request_Key). Since the context signals are the same, the first-level lookup key can be the same for digital component requests sent to two computing systems MPC1 and MPC2 in the MPC cluster 130.
[0085] The computing system MPC1 can create a vector of additive secret shares [M1] = [m 1,1 ,…m C,1 , where for 1 ≤ i ≤ C, m i,1 = g ug_id,1 (i). Brackets are used herein to denote the secret shares of the secret. Similarly, the computing system MPC2 can create a vector of additive secret shares [M2] = [m 1,2 ,…m C,2 , where for 1 ≤ i ≤ C, m i,2 = g ug_id,2 (i). In this example, the secret shares [m i,1 and [m i,2 are additive secret shares of G ug_id (i), and [M1] and [M2] are two additive secret shares of M, i.e., vectors of dimension C, where M i = G ug_id (i). Shamir's secret sharing or another suitable secret sharing technique can be used to generate the secret shares. The computing systems MPC1 and MPC2 can generate similar vectors for the point functions h ug_id,1 (i) and h ug_id,1 (i).
[0086] The digital component requests sent to at least one of the computing systems MPC1 and / or MPC2 can include context digital component requests. As described above, the context digital component requests can include context signals for digital component presentation opportunities, first-party cookies, and / or group identifiers. In this case, the context signals can include the URL of the electronic resource containing the content, the location of the client device 110, the spoken language of the application 112, etc.
[0087] The MPC cluster 130 transmits a context digital component request (314) to the SSP 170. The SSP 170 transmits a context digital component request (316) to one or more DSPs 150. The DSP 150 can generate a context-based vector V context based on the information included in the context digital component request and transmit to the SSP 170 a context-based vector V contextresponse (318). As described above, DSP 150 is also capable of providing a new or updated user group-based vector V ug for the current digital component selection process and / or to be stored at MPC cluster 130 for future digital component selection processes.
[0088] In some implementations, the response from DSP 150 can include unconditional selection values for digital components selected based on context signals and / or other information included in the context digital component request. This can be in addition to or instead of the context-based vector V context . For example, these digital components can be selected for the current digital component request rather than being cached at MPC cluster 130.
[0089] SSP 170 transmits the response (320) from DSP 150 to MPC cluster 130. In some implementations, SSP170 can enforce publisher controls on the response before transmitting it to MPC cluster 130. If a digital component has features that have been excluded by the publisher of the content, such publisher controls can filter the digital component from consideration. Such publisher controls can also filter digital components received from digital component providers that have been excluded by the publisher.
[0090] In some implementations, SSP 170 can also adjust the vector and / or selection values based on a shared protocol between the publisher, SSP 170, and / or DSP 150 before sending the vector and / or selection values to MPC cluster 130. The result of doing so is the final amount of the selection values that will be provided to the publisher from the digital component provider 160 for presentation or user interaction with the digital component. In one example, SSP 170 can multiply the user group-based vector V ug by the value (1 - share) to obtain a resulting vector V ug '. The parameter share can represent the percentage of the selection values calculated using the vector V ug to be provided to SSP 170 and / or DSP 150. The parameter share can vary across digital components based on the protocol between the provider and SSP 170 and / or DSP 150. In this example, the resulting vector V ug ' can be stored by computing systems MPC1 and MPC2 and can be used multiple times as long as the stored vector and its digital components remain active for the digital component selection process.
[0091] In another example, SSP 170 can multiply the context vector V context by (1 - share) to obtain a resulting vector V context’. In this example, the result vector can be stored by computing systems MPC1 and MPC2 and used for the current digital component selection process. However, since the context vector is specific to the current digital component selection process, it may not be used for future digital component selection processes. In another example, the parameter share of each digital component can be stored by computing systems MPC1 and MPC2 and reused for future digital component selection processes, e.g., to compute result vectors V ug ’ and V context ’.
[0092] MPC cluster 130 performs a digital component selection process in response to a digital component request to select a digital component (322) to distribute to client device 110. This can include using a first-level lookup key to identify eligible digital components in a two-level lookup table of computing systems MPC1 and MPC2. This can also include identifying digital components as alternative candidates based on digital components having a user group identifier that matches one of the user group identifiers of the user. This can also include selecting a digital component from the candidate digital components based on the selection value of the digital component. This can all be performed in cases where computing systems MPC1 or MPC2 cannot access the user group identifier and / or other user data in plaintext. In Figure 4 is illustrated and described below an example process for selecting digital components using secure MPC processes.
[0093] MPC cluster 130 transmits a secret share (324) of the selection result to client device 110. The selection result can be in the form of a byte array including information about the selected digital component. For example, the selection result can be a byte array including the value of the digital component in the second LUT (e.g., the selection value of the digital component and the metadata of the digital component). Computing systems MPC1 and MPC2 can use secure MPC processes to determine the secret share of the selection result, as described in more detail below. Computing system MPC1 can transmit a first secret share of the selection result to client device 110, and computing system MPC2 can send a second secret share of the selection result to client device 110. To prevent computing systems MPC1 and MPC2 from knowing the selected digital component, it can be prevented for computing systems MPC1 and MPC2 to share the secret shares of their selection results with each other, e.g., by encrypting their secret shares using the public key of an application (e.g., a browser).
[0094] When using a cuckoo filter with two tables, the MPC cluster 130 is able to provide secret shares of two selection results, one for each table. However, retrieving the list selection values of two user groups for two digital components contributes to selection value abandonment. To reduce this risk, the MPC cluster 130 is able to use another secure MPC technique to return at most one selection result with the highest selection value, as described below.
[0095] The client device 110 determines the digital component (326) corresponding to the selection result. For each selection result for which the client device 110 receives two secret shares from the computing systems MPC1 and MPC2, the client device 110 is able to determine the selection result from the two secret shares. For example, using an additive secret sharing library described in more detail below, the client device 110 is able to add the two secret shares of the selection result together to obtain the selection result in plaintext. This enables the client device 110 to access the selection value of the digital component and the metadata of the digital component, such as the identity of the digital component, the location from which the client device 110 can download the digital component, etc.
[0096] The client device 110 is able to present the digital component (328). For example, the application 112 is able to present the digital component with the content received in step 204. In some embodiments, the client device 110 is able to present the digital component of the selection result. If two selection results are received, the client device 110 (e.g., the application 112) is able to select the digital component with the highest selection value and present the selected digital component.
[0097] If the resource includes multiple digital component slots, the client device 110 is able to request the corresponding digital components for each slot from the MPC cluster 130 and from the SSP 170. To reduce the consumed bandwidth and latency, the client device 110 is able to transmit the distributed point function of the user group identifier for all digital component slots at once.
[0098] Although the steps for generating the cuckoo filter and the distributed point function are shown in Figure 3 to be executed after receiving the content, the client device 110 is able to generate the cuckoo filter and the distributed point function before receiving the content. For example, the client device 110 is able to generate and cache the cuckoo filter and the distributed point function periodically or in response to the user's user group membership being updated.
[0099] Figure 4is a swimlane diagram of an example process 400 for selecting digital components for distribution to client devices. Operations of process 400 can be implemented, for example, by computing systems MPC1 and MPC2 in MPC cluster 130. Operations of process 400 can also be implemented as instructions stored on one or more computer-readable media, which can be non-transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operations of process 400.
[0100] Computing systems MPC1 and MPC2 use a user-group-based vector V associated with each cached digital component ug and a context vector V received in response to a digital component request received from client device 110 context to determine a selection value for the digital component (402). Computing systems MPC1 and MPC2 can determine the selection value for each digital component stored by computing systems MPC1 and MPC2 in, for example, a two-level LUT, and any vectors received from SSP 170 in response to a digital component request received from client device 110, as described above with reference to Figure 3 the description.
[0101] To determine the selection value for the digital component, computing systems MPC1 and MPC2 can determine the stored vector V associated with the digital component ug and a context-based vector V received from DSP 150 for the digital component (and other digital components of DSP 150) in response to the digital component request context of the dot product. In some implementations, computing systems MPC1 and MPC2 determine the dot product of one of the vectors (e.g., V context ) and the result (e.g., V ug ’) of the other vector after sharing (e.g., after multiplying by (1 - share)), depending on how the sharing is processed. The result of the dot product is the selection value for the digital component requested for the corresponding digital component request. If a parameter share is provided to the MPC cluster 130 for the digital component, the value obtained from the dot product calculation can be multiplied by (1 - share).
[0102] In some implementations, computing systems MPC1 and MPC2 can determine three vectors (the context vector V of the digital component context , the user-group-based vector V of the digital component ug and a user vector V of a user profile representing the user of client device 110 from which the digital component request is received user) The dot product of (...) is used as the selection value for the digital component. Each vector can have the same dimension and the same elements representing the same features. However, each vector can have different element values, depending on the weight of the feature represented by the element. For example, the value of the location element for Austin in the user profile vector can be positive if the user is in Austin or negative or zero if the user is not in Austin; the value of the same location element in the context vector can be positive if the publisher content currently shown to the user is highly relevant to Austin; the value of the same location element in the user group-based vector of the digital component is positive if the digital component is relevant to Austin. To calculate the dot product of three vectors, the computing systems MPC1 and MPC2 first perform element-wise multiplication between the corresponding elements (one for each of the three vectors), and then sum the results. For example, assume the three vectors are V1 = {v 1,1 ...v 1,n}, V2 = {v 2,1 ...v 2,n}, and V3 = {v 3,1 ...v 3,n}, the dot product between the three vectors will be
[0103] Application 112 can generate a user profile for the user based on, for example, the feature vectors received from SSP 170 or DSP 150. Application 112 can accumulate the user profile over time and provide corresponding secret shares of the user profile to each of the computing systems MPC1 and MPC2.
[0104] In some implementations, the computing systems MPC1 and MPC2 can limit the selection value determined using two (or three) vectors. In this way, the resulting selection value is not higher than a first threshold or lower than a second threshold. For example, the computing systems MPC1 and MPC2 can use a cap function to output a selection value within a range between a specified minimum value and a specified maximum value for the digital component, e.g., specified by DSP 150 for the digital component.
[0105] In some implementations, for example, if a user profile is not used, computing systems MPC1 and MPC2 use plaintext vectors to compute a selected value in plaintext. In some implementations, computing systems MPC1 and MPC2 use a secure MPC process to compute the selected value using secret shares of each vector. For example, SSP 170 or DSP 150 can split a vector derived from sensitive user information into secret shares and provide the corresponding secret shares of the vector to each of the computing systems MPC1 and MPC2. After the computing systems MPC1 and MPC2 compute the secret shares of each selected value, the computing systems MPC1 and MPC2 can reconstruct the selected value in plaintext, for example, by adding together the secret shares of the selected value (if the secret shares are additive secret shares). In implementations that include a user profile vector in the dot product calculation, as described below, a secure MPC process is used to protect user privacy by preventing computing system MPC1 or MPC2 from accessing the user profile in plaintext.
[0106] Computing system MPC1 identifies eligible digital components (404). As described above, for each user interface group of which a user including a client device is a member, a digital component request can include a distributed dot function g generated by client device 110 using hash function F1 for user interface group identifier ug_id. ug_id,1 If a two-table cuckoo filter is used, the digital component request can also include a distributed dot function h generated by client device 110 using hash function F2 for user interface group identifier ug_id. ug_id,1 The digital component request can also include a first-level lookup key generated based on a context signal of the digital component request, such as SHA256(UG_Request_Key).
[0107] Computing system MPC1 can use the first-level lookup key of the digital component request to identify eligible user-group-based vectors of the digital component. Computing system MPC1 can access the first-level LUT and use the first-level lookup key to identify information about user-group-based vectors in the second-level LUT that include digital components eligible for presentation for the set of context signals represented by the first-level lookup key (e.g., for which a user-group-based vector has been received). For example, as described above, each row of the second-level LUT includes information about a digital component and a second-level lookup key based on a set of context signals. Thus, computing system MPC1 can use the first-level lookup key to identify the rows of the second-level LUT that have a set of context signals that match the set of context signals defined by the first-level lookup key received in the digital component request. These rows include information about digital components that are eligible to be presented or have eligible user-group-based vectors for the context defined by the first-level lookup key received in the digital component request.
[0108] The computing system MPC2 identifies eligible user-group-based vectors (406). The computing system MPC2 is capable of identifying eligible user-group-based vectors for digital component requests received from the client device 110. For each user interface group that includes the user of the client device as a member, the digital component request can include a distributed dot function g generated by the client device 110 using a hash function F1 for the user interface group identifier ug_id ug_id,2 If a cuckoo filter using two tables is used, the digital component request can also include a distributed dot function h generated by the client device 110 using a hash function F2 for the user interface group identifier ug_id ug_id,2 The digital component request can also include a first-level lookup key generated based on the context signal of the digital component request, such as SHA256(UG_Request_Key).
[0109] The first-level lookup key of the digital component request received by the computing system MPC2 can be the same as the first-level lookup key received by the computing system MPC1. Each distributed dot function g ug_id,2 can be generated based on the same distributed dot function G as the corresponding distributed dot function received by the computing system MPC1 ud_id That is, for the user group identifier ud_id of the user group that includes the user as a member, the client device 110 can use the hash function F1 to generate the distributed function g of the digital component request ug_id,1 and g ug_id,2 . Similarly, for the user group identifier ud_id of the user group that includes the user as a member, the client device 110 can use the hash function F2 to generate the distributed function h of the digital component request ug_id,1 and h ug_id,2 .
[0110] For simplicity, the remaining steps of process 400 are described based on the digital components selected for distribution to the client device 110 in response to the digital component request for the distributed dot function according to the hash function F1. However, the same steps can be performed on the distributed dot function of the hash function F2. This can result in two selected digital components, and the MPC cluster 130 can perform additional operations to select one of the two digital components, as described below
[0111] Computing system MPC2 can identify eligible user-group-based vectors using the first-level lookup key requested by a digital component. Computing system MPC2 can access the first-level LUT and use the first-level lookup key to identify a row in the second-level LUT that includes information about digital components (e.g., for which a selection value has been received) that are eligible to be presented for the set of context signals represented by the first-level lookup key. As described above, each of computing systems MPC1 and MPC2 can maintain a corresponding two-level LUT that includes the same information.
[0112] For each eligible selection value, computing systems MPC1 and MPC2 determine (408), in response to a digital component request, whether the selection value and its digital component are candidates for selection for distribution to client device 110. A candidate user-group-based vector is an eligible user-group-based vector of digital components having a user-group identifier that matches the user-group identifier of the user (e.g., the user-group identifier of a user group that includes the user as a member). As described above, each digital component can be mapped to one or more user groups that include members to whom DSP 150 or the digital component provider 160 indicates the digital component should be presented. As described above, this information is part of the second-level lookup key of the second-level LUT.
[0113] The digital components in a row of the second-level LUT are candidate selections if their user-group identifier ug_id, which is part of the second-level lookup key for that row, matches one of the user-group identifiers of the user. Conceptually, to use a cuckoo filter to determine whether a digital component is a candidate to represent a user's group membership, where the cuckoo filter allows an element to be inserted into one of two (or more) possible locations, the computing system can determine whether the user-group identifier ug_id of the second-level lookup key matches one of two (or more) tags in one of two (or more) cuckoo filter locations.
[0114] In addition to this user-group-based condition, MPC cluster 130 can also apply other conditions, frequency control, muting, budgeting, k-anonymity, and / or pacing constraints. For example, to be a candidate in the digital component selection process, a digital component can be required to meet one or more conditions of eligibility during the digital component selection process. These conditions can include, for example, whether the user group associated with the digital component matches the user group of the user to whom the digital component will be provided; whether the digital component meets a frequency control condition that prevents the same user from being exposed to the same digital component more than a specified number of times within a period of time; whether the digital component meets a muting condition that prevents the digital component from being presented to a user who has selected to be muted; whether the digital component meets a k-anonymity condition; and / or whether the activity including the digital component meets a pacing eligibility condition that paces the distribution of the digital component in the activity.
[0115] Computing systems MPC1 and MPC2 are able to identify candidate user-group-based vectors using secure MPC techniques leveraging secret shares, such that neither computing system MPC1 nor MPC2 knows which digital components are candidates or user groups that include the user as a member. To do so, computing system MPC1 computes a first share of the candidate parameter is_dc_a_candidate for each cached digital component associated with the user-group identifier ug_id. Similarly, computing system MPC2 computes a second share of the candidate parameter is_dc_a_candidate for each cached digital component associated with the user-group identifier ug_id. The candidate parameter is_dc_a_candidate can be a boolean value (e.g., zero or one) indicating whether the user-group-based vector linked to the cached digital component is a candidate. If the user-group-based vector of a digital component is a candidate, its corresponding selection value computed using the user-group-based vector is a candidate and the corresponding digital component.
[0116] The first share of the candidate parameter is_dc_a_candidate can be represented as [is_dc_a_candidate dc,1 and the second share of the candidate parameter is_dc_a_candidate can be represented as [is_dc_a_candidate dc,2 . The first secret share of the candidate parameter for the digital component dc of the cache associated with the user-group identifier ug_id is equal to the boolean ug_id,1 secret share of ug_id == [g (F1(ug_id))]. The second secret share of the candidate parameter for the digital component dc of the cache associated with the user-group identifier ug_id is equal to the boolean ug_id,2 secret share of ug_id == [g (F1(ug_id))]. The symbol "==" represents an equality test, which is true (or 1) if the two values are equal or false (or 0) if the values are not equal.
[0117] Computing systems MPC1 and MPC2 are able to use secure MPC techniques to compute the secret shares [is_dc_a_candidate dc,1 and [is_dc_a_candidate dc,2 for the hash function F1 in one or more round-trips between computing systems MPC1 and MPC2 to evaluate ug_id == [g ug_id,1 (F1(ug_id))] and ug_id == [g ug_id,2The equality expression of (F1(ug_id)). That is, the computing systems MPC1 and MPC2 can, for each user group identifier received from the client device 110 as part of a digital component request, determine, based on the distributed point functions g ug_id,1 and g ug_id,2 the secret shares [is_dc_a_candidate dc,1 and [is_dc_a_candidate dc,2 of the digital component dc of each cache associated with the user group identifier ug_id.
[0118] The computing systems MPC1 and MPC2 can use secret sharing techniques or secret sharing libraries that support the operations shown in Table 3 below. An example secret sharing technique that supports these operations is Security by Private Information Aggregation (SEPIA).
[0119]
[0120] Table 3
[0121] The computing system MPC1 determines the order (410) of the selection values calculated based on the user group-based vector and the context vector. Similarly, the computing system MPC2 determines the order (412) of the selection values based on the user group-based vector and the context vector. Each of the computing systems MPC1 and MPC2 can determine the order of the selection values associated with the digital components of the cache that match the UG_Request_Key in its second-level LUT. This order can include all the selection values calculated for all the digital components cached in the second-level LUT that match the UG_Request_Key, including the selection values for the candidate digital components that are eligible for the digital component selection process and the selection values for the digital components that are not candidates and are thus ineligible. The order can be from the highest calculated selection value to the lowest calculated selection value. In some implementations, the selection values for the order can be, for example, the values of the resources that will be provided to the publisher of the digital component with which the selection will be presented after any sharing with the DSP 150 and / or SSP 170. Since the selection values are in plaintext, the computing systems MPC1 and MPC2 do not have to perform any round-trip calculations to sort the selection values. Instead, each of the computing systems MPC1 and MPC2 can independently sort the selection values of its second-level LUT. If the selection values are stored as secret shares at each of the computing systems MPC1 and MPC2, where each of the computing systems MPC1 and MPC2 has the corresponding secret share of each selection value, the computing systems MPC1 and MPC2 can use round-trip calculations to perform a secure MPC process to sort the selection values.
[0122] Computing systems MPC1 and MPC2 determine secret shares (414) of the cumulative value of each candidate selection value associated with the digital components of the cache. Conceptually, the cumulative value of a given selection value of a digital component represents the total number of candidate selection values from the top of the order to the given selection value (including the given selection value if the given selection value is a candidate). This concept is shown in Table 4 below.
[0123] Sorted selection values is_dc_a_candidate Cumulative value (acc) Does the cumulative value equal 1? Highest 0 0 0 Second highest 1 1 1 Third highest 0 1 1 Fourth highest 1 2 0 … … … …
[0124] Table 4
[0125] In some implementations, the cumulative value of a given selection value of a digital component represents the total number of candidate selection values from the top of the order to the given selection value (excluding the given selection value if the given selection value is a candidate). In this example, the fourth column would indicate whether the cumulative value is equal to zero rather than one. In either case, the cumulative value of each selection value indicates the position of the selection value in the ranking order of the candidate selection values, where the candidate selection values are candidates for selection based on the association of the selection value with a user group identifier that matches the user group identifier of the user.
[0126] In Table 4, for each selection value with a candidate parameter is_dc_a_candidate equal to one, the cumulative value (acc) increases as it progresses from the top of the order to the bottom of the order. For example, the cumulative value acc of the highest selection value associated with the digital components of the cache is zero because the candidate parameter is_dc_a_candidate of the digital component with the highest selection value is equal to zero. The cumulative value acc of the digital component with the second highest selection value is one because the candidate parameter is_dc_a_candidate of the digital component with the second selection value is equal to one and no digital component higher than the digital component with the second highest selection value has a candidate parameter is_dc_a_candidate equal to one. Moving down the order, the candidate parameter is_dc_a_candidate of the digital component with the third highest selection value is zero, so the cumulative value acc of the digital component with the third highest selection value does not increase from the cumulative value acc of the digital component with the second highest selection value. Since the candidate parameter is_dc_a_candidate of the digital component with the fourth highest selection value is one, the cumulative value acc of the digital component with the fourth highest selection value increases by one from the cumulative value acc of the digital component with the third highest selection value. Thus, the cumulative value acc of the digital component with the fourth highest selection value is equal to two because there are two selection values with the candidate parameter is_dc_a_candidate from the highest selection value to the fourth highest selection value (including the highest selection value and the fourth highest selection value).
[0127] In some implementations, the cumulative value of a given digital component represents the total number of candidate digital components from the top of the order to the given digital component (excluding the given digital component). In this example, the fourth column will indicate whether the cumulative value is equal to zero rather than one. In either case, the cumulative value of each digital component indicates the position of the digital component in the ranking order of candidate digital components, where the candidate digital components are candidates for selection based on being associated with a user group identifier that matches the user group identifier of the user.
[0128] Using Table 4, computing systems MPC1 and MPC2 will select the digital component corresponding to the selection parameter with the candidate parameter is_dc_a_candidate having a value of one and the cumulative value acc having a value of one for distribution to client device 110, as indicated in the fourth column of Table 4. This represents the digital component with the highest ranked selection value having the candidate parameter is_dc_a_candidate having a value of one. Since the candidate parameter is_dc_a_candidate is in the secret share so that computing systems MPC1 and MPC2 maintain user privacy and ensure no leakage of user data, computing systems MPC1 and MPC2 determine the secret share of the cumulative value acc for each selection value and use a round-trip calculation to determine which selection value has a cumulative value acc equal to one and a candidate parameter is_dc_a_candidate equal to one.
[0129] Computing systems MPC1 and MPC2 are able to independently determine the secret share of the cumulative value acc for each of their digital components without any round-trip calculation. For example, computing system MPC1 can determine the first share [acc dc,1 of the cumulative value acc for each digital component dc by traversing all the selection values in order from highest to lowest and summing the candidate parameter is_dc_a_candidate of the digital component in order along the way, as described above with reference to Table 4. Similarly, computing system MPC2 can determine the second share [acc dc,2 of the cumulative value acc for each digital component dc by traversing all the selection values in order from highest to lowest and summing the candidate parameter is_dc_a_candidate of the digital component in order along the way.
[0130] Computing systems MPC1 and MPC2 determine the secret share (416) of the result indicating whether the cumulative value acc has a specified value for each selection value associated with the digital component dc. The specified value can be the value one, as shown in the 3rd and 4th columns of Table 4, or zero in other implementations. As described above, the digital component with a cumulative value of one and a candidate parameter is_dc_a_candidate of one is the digital component with the highest selection value among the candidate selection values.
[0131] The computing systems MPC1 and MPC2 are capable of participating in multiple rounds of computations that are part of a secure MPC process, such as multiple remote procedure calls (RPCs), to compute the equality operation acc based on the secret shares of each digital component. dc == 1. At the end of this process, the computing system MPC1 has the secret share of the result [acc dc,1 == 1 for each digital component dc, while the computing system MPC2 has another secret share of the result [acc dc,2 == 1 for each digital component dc.
[0132] The computing systems MPC1 and MPC2 determine a selection result (418). The computing systems MPC1 and MPC2 are capable of determining the selection result for each digital component dc based on the secret shares of acc dc == 1 and the secret share of the candidate parameter is_dc_a_candidate dc . To do so, the computing systems MPC1 and MPC2 are capable of computing the winner parameter is_dc_the_winner for each digital component dc based on the secret shares. dc The winner parameter is_dc_the_winner dc can be a boolean value (e.g., zero or one, or true or false) indicating whether the digital component dc is the winner of the selection process (e.g., whether the corresponding digital component is selected for distribution to the client device 110 in response to a digital component request).
[0133] The winner parameter is_dc_the_winner of the digital component dc can be based on the candidate parameter is_dc_a_candidate of the digital component dc and whether the cumulative value acc of the digital component is equal to a specified value, e.g., equal to one or zero depending on how the fourth column of Table 4 is determined as described above. In the following example, the MPC cluster 130 can determine the product of these two parameters for each digital component. Other techniques can also be used to determine whether the candidate parameter is_dc_a_candidate dc is true or one and whether the cumulative value is equal to the specified value, e.g., using the truth table described below.
[0134] Each of the computing systems MPC1 and MPC2 can perform a secret share multiplication protocol to compute the winner parameter is_dc_the_winner for each digital component dc based on the secret shares. dc == (is_dc_a_candidate dc × (acc dc==1)). Depending on the secure MPC process used, this may require computing an RPC between computing systems MPC1 and MPC2 to multiply the two secret shares. At the end of this MPC process, computing system MPC1 has a secret share of the result is_dc_the_winner for each digital component dc, denoted as [is_dc_the_winner dc = [is_dc_a_candidate dc,1 x ([acc dc,1 == 1). Similarly, computing system MPC2 has another secret share of the result is_dc_the_winner for each digital component dc, denoted as [is_dc_the_winner dc,1 = [is_dc_a_candidate dc x ([acc dc,2 == 1). Note that for all digital components, at most one digital component has a winner parameter is_dc_the_winner equal to one, which corresponds to the digital component selected for distribution to client device 110. All other digital components will be equal to zero. dc,2 x ([acc dc,2 == 1). Note that for all digital components, at most one digital component has a winner parameter is_dc_the_winner equal to one, which corresponds to the digital component selected for distribution to client device 110. All other digital components will be equal to zero. dc that corresponds to the digital component selected for distribution to client device 110. All other digital components will be equal to zero.
[0135] Computing systems MPC1 and MPC2 can compute the selection result based on the winner parameter of the digital component and the digital component information element dc_information_element of the digital component. As described above, the digital component information element dc_information_element of the digital component can include the selection value of the digital component and other data of the digital component, for example, in the form of a byte array with a digital sequence.
[0136] Computing systems MPC1 and MPC2 can use the following relation 5 to compute the selection result as result F1 .
[0137]
[0138] In this example, the selection result result F1 will have a value of zero in the absence of a digital component in the cache with a user group identifier that matches the user group identifier of the user or will have the value of the digital component information element dc_information_element of the selected digital component with a winner parameter is_dc_the_winner equal to one. dc that matches the selection of the digital component with a winner parameter is_dc_the_winner equal to one.
[0139] To perform computations on the secret shares, computing system MPC1 takes all the cached digital component information elements and, for each digital component dc, multiplies the digital component information element dc that can be the plaintext by the first secret share of the winner parameter [is_dc_the_winner dc,1 . Computing system MPC1 can then determine the sum of these products and return that sum to client device 110 that submitted the digital component request. That is, computing system MPC1 can determine the first share that is the result of the summation using relation 6 below
[0140]
[0141] Computing system MPC2 can perform a similar computation to determine the second share of the result using relation 7 below
[0142]
[0143] Computing system MPC1 can return the first share of the selection result to client device 110. Similarly, computing system MPC2 can return the second share of the selection result to client device 110. Application 112 can then use the two secret shares and to reconstruct the selection result result F1 in plaintext, for example by determining the sum of the secret shares in the case of an additive secret sharing algorithm. If the selection result result F1 has a value of zero, MPC cluster 130 does not identify a digital component for any user group that includes the user as a member. Otherwise, if the selection result result F1 has a value equal to that of the digital component information element dc_information_element, application 112 can parse the digital component information element dc_information_element to obtain the selection value and metadata of the digital component. As described above, application 112 can then display the digital component or use the digital component and other digital components received from SSP 170 to perform the selection process.
[0144] In the double-table cuckoo filter implementation, application 112 can receive two selection results, one for each hash function F1 and F2. In this example, application 112 can select a digital component from the set of digital components that includes both these digital components and any digital components received from SSP 170.
[0145] In some implementations, the application 112 can perform a final verification, i.e., the user group of digital components selected by the MPC cluster 130 matches the user group that includes the user as a member. For example, the digital component information element dc_information_element of each digital component can include the user group identifier of the digital component. The application 112 can compare the user group identifier of the digital component information element dc_information_element with the user group list of the user. If there is no match, the application 112 can exclude the digital component from the selection process. If there is a match, the application 112 can include the digital component in the selection process.
[0146] As described above, receiving two selection results from the MPC cluster 130 can facilitate selection value conflicts. To reduce this risk, the MPC cluster 130 can perform a process that returns only one selection result.
[0147] In a single-table cuckoo filter implementation, each user group identifier ug_id can appear in two (or more) places where its indices are F1(ug_id) and F2(ug_id). Let M denote the single-table cuckoo filter and M i denote the value of the i-th element in the table. If or then the candidate parameter is_dc_a_candidate of the selection value of the digital component with the user group identifier ug_id dc is true. This MPC cluster 130 can use the following relational expressions 8 or 9 to calculate the candidate parameter is_dc_a_candidate of the digital component dc associated with the user group identifier ug_id for the selection value dc .
[0148]
[0149]
[0150] Relational expression 8 can involve two equality tests that can be performed in parallel. Relational expression 9 can involve one equality test and one multiplication. When using secure MPC processes to perform these operations on secret shares, multiplication requires less computation and one round-trip, but equality tests can require more computation and four round-trips in probabilistic solving. Therefore, relational expression 8 can require one less round-trip but more computation than relational expression 9.
[0151] The computing system MPC1 can calculate a candidate parameter is_dc_a_candidate of a digital component dc associated with a user group identifier ug_id on secret shares based on relation 8 using the following relation 10 dc .
[0152] [is_dc_a_candidate dc,1 = (ug_id == [g ug_id,1 (F1(ug_id))]) + (ug_id == [g ug_id,1 (F2(ug_id))]) (10)
[0153] Similarly, the computing system MPC2 can calculate a candidate parameter is_dc_a_candidate of a digital component dc associated with a user group identifier ug_id on secret shares based on relation 9 using the following relation 11 dc .
[0154] [is_dc_a_candidate dc,2 = (ug_id == [gu g_id,2 (F1(ug_id))]) + (ug_id == [g ug_id,2 (F2(ug_id))]) (11)
[0155] The computing system MPC1 can calculate a candidate parameter is_dc_a_candidate of a digital component dc associated with a user group identifier ug_id on secret shares based on relation 9 using the following relation 12 dc .
[0156] [is_dc_a_candidate dc,1 = (ug_id - [g ug_id,1 (F1(ug_id))]) × (ug_id - [g ug_id,1 (F2(ug_id))]) (12)
[0157] The computing system MPC2 can calculate a candidate parameter is_dc_a_candidate of a digital component dc associated with a user group identifier ug_id on secret shares based on relation 10 using the following relation 13 dc .
[0158] [is_dc_a_candidate dc,2 = (ug_id - [g ug_id,2 (F1(ug_id))]) × (ug_id - [g ug_id,2(F2(ug_id))]) (13)
[0159] The MPC cluster 130 can then use a process similar to the process 300 of Figure 3 to calculate the secret shares of the selection result result. In particular, the computing systems MPC1 and MPC2 can calculate the secret shares of the cumulative value acc, [acc dc,1 , and [acc dc,2 , respectively, for each digital component dc based on the order of the selection values of the digital components and the candidate parameters of the digital components.
[0160] The computing systems MPC1 and MPC2 can calculate the secret shares of the winner parameter is_dc_the_winner, [is_dc_the_winner dc,1 , and [is_dc_the_winner dc,2 , respectively, for each digital component dc based on the candidate parameters of the digital component dc and whether the cumulative value of the digital component dc is equal to one.
[0161] The computing systems MPC1 and MPC2 can use the following relational expressions 14 and 15 to calculate the secret shares [result1] and [result2] of the selection result result.
[0162] [result1] = ∑ dc ([is_dc_the_winner dc,1 × dc_information_element dc ) (14)
[0163] [result2] = ∑ dc ([is_dc_the_winner dc,2 × dc_information_element dc ) (15)
[0164] The computing system MPC1 can return the first share of the selection result [result1] to the application 112, and the computing system MPC2 can return the second share of the selection result [result2] to the application 112. As described above, the application 112 can then use the two secret shares to reconstruct the selection result result.
[0165] In some implementations, instead of using a distributed point function, it is possible to send the cuckoo filter itself to the MPC cluster 130. In this example, the application 112 can use a pseudorandom function (PRF) parameterized by either a user group identifier or an identifier from a set of blocked identifiers and one of two random variables generated by the application 112. For example, assume that the three random variables generated by the application 112 are rand_var1a, rand_var1b, and rand_var2. Also assume that each item in the bucket is a k-bit integer. In some implementations, the application 112 and the MPC cluster 130 agree in advance on the PRF, where k is the number of bits in each item in the bucket of the cuckoo filter. Each item in the bucket of the cuckoo filter can be occupied by a user group identifier or a blocked identifier, or be empty. For example, the application 112 can generate a cuckoo filter table whose items are PRF(ug_id,rand_var1a), PRF(blocked_id,rand_var1b), or 0, where ug_id is the identifier of the user group generated by applying HMAC on the label of the user group (e.g., the user group identifier) based on the domain of the content provider and 0 represents an empty item. This process is repeated for all user group identifiers and blocked identifiers.
[0166] The application 112 can generate a vector B based on the cuckoo filter table generated for the user group identifier and the blocked identifier. Each value B in the vector B i can be represented as B i =(A i _PRF(rand_var2, i)) mod p, where A is the cuckoo filter table and i is the index of the vector B and the cuckoo filter table A. When the application 112 initiates a request for a digital component for a digital component slot, the application transmits rand_var1a, rand_var1b, and rand_var2 as parameters of the request to the computing system MPC1. The application 112 also transmits the vector B, rand_var1a, and rand_var1b as parameters of the request to the computing system MPC2. PRF(rand_var2,i) and B i are two additive secret shares in A i in Z p held by the computing systems MPC1 and MPC2 respectively. Since neither of the computing systems MPC1 and MPC2 can access these two secret shares, neither computing system can reproduce the cuckoo filter table, thus preserving user privacy.
[0167] The computing system MPC1 determines whether each candidate selection value is associated with the user group specified in the request. The computing system MPC1 receives an equivalent of an array of secret shares of the cuckoo filter table M, denoted by [M1]. Each user group identifier present in M will be in one of N possible positions.
[0168] The computing system MPC1 calculates the user-group based candidate parameter [is_dc_a_candidate x,1 according to relation 16 below:
[0169]
[0170] where Π represents the multiplication of multiple terms. Here, ug_id(x) is a function for retrieving the user group identifier ug_id associated with the selection value x, {F1,…F N} is a set of hash functions for calculating the possible indices of the entries within the cuckoo filter table A, and rand_val1a is a random value received in the digital component request. [M x,1 is the x-th element in the array [M1]. == is an equality test between a plaintext integer and the secret share of a secret integer. The result of == is the secret share of a secret integer that is either 0 (not equal) or 1 (equal). Here, the value of [M i,1 = [PRF(rand_val2a,i)1].
[0171] Similarly, the computing system MPC2 calculates the user-group based candidate parameter [is_dc_a_candidate x,2 according to relation 17 below:
[0172]
[0173] Here, the value of [M i,2 = B i .
[0174] The above description relates the multiplication between secret shares of a secret integer having a value of 0 or 1 to computer logic AND. The above description also relates 1 minus the secret share of a secret integer having a value of 0 or 1 to computer logic NOT. In some implementations, alternative solutions can be employed to evaluate logical expressions regarding secret shares. For example, to compute the logical AND of additive secret shares of a secret integer having a value of 0 or 1, the MPC server can compare the sum of those additive secret shares with the number of secret shares. For another example, to compute any logical expression having secret shares as inputs, the MPC server can adopt a truth table method, i.e., the computing system MPC1 can construct a truth table having one row for each possible combination of the input secret shares held by MPC2. The computing system MPC1 randomly selects a secret share for the result represented as [result1]. For each row, the computing system MPC1 can combine its input secret shares and the hypothesized input secret shares held by MPC2 to reconstruct the input of the logical expression in plaintext and then evaluate the result of the logical expression. For each row, the computing system MPC1 splits the result into two secret shares, one of which is [result1] and the other is [result2]. The computing system MPC1 then writes [result2] to the row in the truth table. After the computing system MPC1 finishes constructing the truth table, the computing system MPC2 can initiate an oblivious transfer extension (OTe) to extract the row in the truth table corresponding to the input secret shares held by MPC2. The extraction result is [result2]. At the end of the above process, the computing systems MPC1 and MPC2 respectively hold [result1] and [result2], which are secret shares of the result of the logical expression. The computing system MPC1 does not know the value of [result2], while the computing system MPC2 does not know the value of [result1]. In some implementations, the computing systems MPC1 and MPC2 can evaluate the logical expression by constructing a garbled circuit to determine is_dc_a_candidate sv,1 and is_dc_a_candidate sv,2 .
[0175] Figure 5 FIG. is a flowchart illustrating an example process 500 for selecting digital components for distribution to client devices. The operations of process 500 can be implemented, for example, by the computing system MPC1 or the computing system MPC2 of the MPC cluster 130. The operations of process 500 can also be implemented as instructions stored on one or more computer-readable media that can be non-transitory, and the execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operations of process 500. For simplicity, process 500 is described as being executed by the computing system MPC1.
[0176] The computing system MPC1 receives a digital component request (502) from the client device 110. The digital component request can include secret shares of data identifying one or more first user groups of which the user of the client device 110 is a member. For example, the digital component request can include one or more cuckoo filters or other suitable probabilistic data structures and / or distributed point functions. Each distributed point function can represent a secret share of a point function that indicates whether the user of the client device is a member of the corresponding first user group identified by the corresponding first user group identifier. For example, the digital component request received by the computing system MPC1 can include a distributed point function g for each user group of which the user of the client device 110 is a member ug_id,1 . As described above, the digital component request can also include context signals, first-party cookies, and / or group identifiers.
[0177] The digital component request can also include a lookup key. For example, the digital component request can include a UG_Request_Key, which can be a composite message based on a set of context signals (e.g., the set of context signals of the digital component request). Similar digital component requests can be sent to one or more additional MPC systems (e.g., the computing system MPC2), which will cooperate with the computing system MPC1 in a secure MPC process to select digital components to provide to the client device 110 in response to the digital component request. For each distributed point function of the digital component request, each other digital component request can include a corresponding distributed point function generated using the same point function for the same user group identifier. For example, the computing system MPC2 will receive a corresponding distributed point function g for each distributed point function g received by the computing system MPC1 ug_id,1 receive a corresponding distributed point function g ug_id,2 .
[0178] The computing system MPC1 transmits a context digital component request (504) to the content platform. For example, the computing system MPC1 can transmit a context digital component request to the SSP 170. The context digital component request can include context signals, first-party cookies, and the group identifier of the received digital component request.
[0179] The computing system MPC1 receives selection data (506) for each of a plurality of digital components. The selection data for a digital component can include first vector data that defines a context-based vector V of values selected at least in part based on a set of context signals context . For example, the selection data for a digital component can include an array of first secret shares of a context-based vector or values of a context-based vector.
[0180] The computing system MPC1 obtains second vector data for each of a plurality of digital components, the second vector data defining a user group-based vector V that is at least partially based on values selected by a corresponding user group associated with the digital component ug (508). For example, the computing system MPC1 can store the user group-based vector V ug of the first secret share of the user group-based vector V ug .
[0181] The computing system MPC1 determines a selection value for each digital component based on the first vector data and the second vector data (510). For example, the computing system MPC1 can determine the dot product of two vectors V ug and V context . If the vectors are transmitted and stored in secret shares, the computing system MPC1 can collaborate with the computing system MPC2 to determine the secret share of the dot product of the vectors V ug and V context . In some implementations, as described above, the computing system MPC1 uses the vectors V ug , V context and the user profile vector of the user's user profile to determine the selection value of the digital component
[0182] The computing system MPC1 collaborates with one or more second computing systems in a plurality of MPC systems to use a secure MPC process to determine candidate parameters for each digital component (512). The candidate parameter is_dc_a_candidate can indicate whether the digital component meets one or more conditions of eligibility in the digital component selection process. These conditions can include, for example, whether the user group associated with the digital component matches the user group of the user to whom the digital component will be provided; whether the digital component meets a frequency control condition that prevents the same user from being exposed to the same digital component more than a specified number of times within a period of time; whether the digital component meets a mute condition that prevents the digital component from being presented to a user who has selected to be muted; whether the digital component meets a k-anonymity condition; and / or whether the activity including the digital component meets a pacing eligibility condition for pacing the distribution of the digital component in the activity
[0183] For example, the candidate parameter is_dc_a_candidate can indicate whether a second user group identifier corresponding to a digital component matches at least one of one or more first user group identifiers. That is, in this example, the candidate parameter is_dc_a_candidate of the digital component indicates whether the user group identifier of the digital component matches the user group identifier of the user group that includes the user of the client device 110 as a member. If so, the digital component is a candidate digital component as a candidate to be selected. As described above, the computing system MPC1 can use a secure MPC process to cooperate with one or more additional MPC systems including the computing system MPC2 to obtain a first secret share of the candidate parameter is_dc_a_candidate for each selected value.
[0184] This determination of the candidate parameter of the digital component can be performed after filtering the digital component based on context, for example, using the user group request key UG_Request_Key. For example, the MPC cluster 130 can use the candidate parameter is_dc_a_candidate to perform two sequential stage filtering operations, one based on the request key and the other based on one or more conditions.
[0185] The computing system MPC1 generates a first secret share (514) of the selection result. The computing system MPC1 can cooperate with one or more additional MPC systems including the computing system MPC2 to generate the selection result. Generally, the selection result identifies the candidate digital component with the highest selected value. As described above, the MPC system can sort the selected values, determine the cumulative value of each selected value, and determine a secret share of the winner parameter is_dc_the_winner for each digital component associated with the selected value. The MPC systems can then cooperate to determine a secret share of the sum of the product of the winner parameter of the selected value and the digital component information element of the selected value as the secret share of the selection result for each selected value. For example, the MPC system can use the relationship 5 shown above to determine the secret share of the sum of the products.
[0186] The computing system MPC1 provides the client device 110 with a first secret share (516) of the selection result that identifies a given digital component. As described above, the selection result identifies the selected digital component and the selected value of the digital component. The client device 110 can also receive the corresponding secret share of the selection result from each of one or more additional MPC systems. As described above, the client device 110 can use the secret shares to reconstruct the selection result.
[0187] In some cases, the context vector V context can be considered sensitive information for the DSP. In such cases, the DSP can provide the context vector V in the secret share, for example.context An encrypted version. For example, the DSP 150 can provide the context vector V to the computing system MPC1 context with the first secret share and provide the context vector V to MPC2 context with the second secret share. In this example, the computing systems MPC1 and MPC2 can determine the digital component with the highest selected value and thus are the selected digital components using the secure MPC process, such that the computing systems cannot access the vector or the selected value in plaintext. This process can be used instead of the above cumulative value-based sorting.
[0188] The computing systems MPC1 and MPC2 can then perform a secure MPC process to compute the dot product of the vectors (e.g., user group vector, context vector, and user vector). The result of this computation is two arrays of secret shares [V1] = {[v 1,1 , … [v N,1} and [V2] = {[v 1,2 , … [v N,2}. In these representations, N is the dimension of the array and the second subscript represents the secret share of the element. For example, the first = 1 and the second = 2.
[0189] Each element in the array can correspond to the selected value of the digital component. For example, [v 1,1 and [v 1,2 can be the two secret shares of the element for the selected value of the digital component. In some implementations, each element in the array includes a composite message (e.g., byte array) of the digital component. As described above, the byte array can include the selected value obtained from the dot product calculation and information of the digital component.
[0190] Assume that both computing systems MPC1 and MPC2 can access the same list of plaintext items {Item1, … Item N} corresponding to the element array. The function reconstruct can be used to reconstruct the value v i,1 of the item in the array represented by the secret shares [v i,2 and [v i . That is, v i = reconstruct([v i,1 , [v i,2 ).
[0191] The computing systems MPC1 and MPC2 can return the maximum value and the corresponding item in the array without leaking any information in plaintext to the computing system MPC1 or MPC2. To do so, the computing system MPC1 should return the secret share pair {[max_v1], [max_element1]} and the computing system MPC2 should return the secret share pair {[max_v2], [max_element2]} such that reconstruct([max_v1], [max_v2]) = reconstruct([v max_i,1 ,[v max_i,1 ) and reconstruct([max_element1], [max_element2]) = Item max_i . In this example, the maximum value corresponds to the highest selected value and the maximum element corresponds to the digital component with the maximum value. The maximum element can include a composite message, such as a byte array of the digital component.
[0192] One way to determine the maximum value and the element with the maximum value in the secret shares is to perform pairwise secret share comparisons between any secret share pairs. For example, for any i ≤ i < j ≤ N, the computing systems MPC1 and MPC2 can cooperate to perform a secret share comparison. The computing system MPC1 obtains [m i,j,1 = [v i,1 > [v j,1 and the computing system MPC2 obtains [m i,j,2 = [v i,2 > [v j,2 . The comparison parameter m i,j = reconstruct([m i,j,1 , [m i,j,2 ) is one if v i > v j and zero otherwise. The secret shares [m i,j and [m i,j,1 of the parameter m i,j,2 can be additive secret shares in Z M where M ≥ N.
[0193] To find the maximum element, the computing system MPC1 locally counts how many other values are greater than v i for each i ∈ [1, N], i.e., Similarly, the computing system MPC2 locally counts how many other values are greater than v i for each i ∈ [1, N], i.e., The computing systems MPC1 and MPC2 then cooperate to test count for each i ∈ [1, N]i equal to 0, i.e., the computing system MPC1 has [is_max_element i,1 = ([count i,1 == 0) and the computing system MPC2 has [is_max_element i,2 = ([count i,2 == 0). Note that [is_max_element i,1 and [is_max_element i,2 can be additive secret shares in Z2.
[0194] The computing system MPC1 can calculate [max_v1] through [max_v1] = ∑ i [v i,1 × [is_max_element i,1 . The computing system MPC1 can also calculate [max_element1] through [max_element1] = ∑ i ([element i,1 × [is_max_element i,1 ).
[0195] Similarly, the computing system MPC2 can calculate [max_v1] through [max_v2] = ∑ i [v i,2 × [is_max_element i,2 . The computing system MPC2 can also calculate [max_element2] through [max_element2] = ∑ i ([element i,2 × [is_max_element i,2 ).
[0196] To improve the efficiency of these comparison operations, the MPC cluster 130 can use a divide-and-conquer algorithm. To do so, the MPC cluster 130 can divide the elements of the array into groups, e.g., into groups, where each group contains elements. Without using divide-and-conquer, solving may require six rounds of communication between the computing systems MPC1 and MPC2. The comparison test phase may require comparisons of secret share pairs. The equality test phase may require N equality tests.
[0197] Using The divide-and-conquer of each group can solve each simpler problem through a total of six rounds of three-round comparison tests and three-round equality tests. The results of each simpler problem can be combined into another simpler problem of size that can be solved through a total of six rounds of three-round comparison tests and three-round equality tests.
[0198] As described above, based on three vectors: the context vector V of the digital component context , the user group-based vector V of the digital component ug , and the user vector V of the user profile representing the user user , the selection value of the digital component can be determined. The group identifier can be calculated by the application 112 using an algorithm selected by the application developer (e.g., browser developer) for the entire digital component distribution industry. The group identifier algorithm cannot be customized by individual content platforms or digital component providers. In this example, the MPC cluster 130 can use the three vectors to calculate the selection value of the digital component, such as selection value = Cap(V ug ·V context ·V user , max sv , min sv ), where max sv is the maximum selection value and min sv is the minimum selection value, such that the resulting selection value is between the maximum and minimum values. The dot product between the three vectors can be calculated as ∑ i (V ug,i1 ×V context,i ×V user,i ), where i is the index of the vector.
[0199] In some cases, the publisher amount after sharing is considered privacy-sensitive. For example, if the amount is derived from the cross-domain user profile as described above using the user vector V user . In such cases, it may be desirable to prevent each server of the MPC cluster 130 from accessing the publisher amount in plaintext. Without the plaintext amount, the MPC cluster 130 may not be able to sort the selection values as described above. In this example, to determine whether a digital component is a candidate, the computing system MPC1 can receive an equivalent of an array of secret shares of the cuckoo filter table M represented by [M1]. Each user group identifier ug_id will be in one of N possible positions if it exists in M.
[0200] Define ug_id(dc) as the function for retrieving the user group identifier ug_id corresponding to the digital component dc whose information is stored by the MPC cluster 130. Also define {F1,...F N} is defined as a function for calculating the possible indices of the items in the cuckoo filter table A.
[0201] The computing system MPC1 computes [match_ug dc,1,i as where i ∈ [1, N]. Similarly, the computing system MPC2 computes [match_ug dc,2,i as where i ∈ [1, N]. Note that [M i,2 = PRF(nonce secret share,i ), where nonce secret_share is a parameter in the digital component request received from the client device 110 and is encrypted by the public key of the computing system MPC2. The secret shares [match_ug dc,1,i and [match_ug dc,1,i are 0 or 1, where match_ug dc,i = [match_ug dc,1,i bitwise_xor [match_ug dc,2,i is 1 when the user group identifier of the digital component dc matches the i-th possible position in the cuckoo filter, and 0 otherwise. Additionally, note that match_ug dc = match_ug dc,1 or match_ug dc,2… or match_ug dc,N is true if and only if the digital component dc corresponds to the user interest group identifier of the user group that includes the user as a member (where the high probability depends on the length of the tags in the cuckoo filter).
[0202] It is also possible to modify the above techniques to support recency and other per-user-group-level signals. The recency of the interest group, i.e., how recently the user was added to the user group, can be an important signal for deciding on the selection value. For example, if the user was added to the remarketing list more than eight hours ago, the value of distributing the digital component using the user membership can be halved. To achieve precise selection values based on recency without weakening the security and privacy guarantees, the above cryptographic techniques can be modified such that each content platform bucketizes the recency into a small number of buckets, e.g., four time-period-based buckets. For each bucket, the content platform can define a vector for the above dot product calculation.
[0203] When generating a digital component request for the MPC cluster 130, the application 112 can combine the recency bucket information with the user group identifier for each user group of which the user is a member to create an augmented user group identifier, e.g., HMAC(ug_id,recency_bucket_id), where recency_bucket_id is the identifier of the recency bucket corresponding to when the user was added to the user group ug_id. For example, if the user was added to the user group two hours ago, the augmented user group identifier can be the identifier of the recency bucket based on the time period of 1 - 3 hours before the current time. The application then inserts the augmented user group identifier instead of the original user group identifier into the cuckoo filter. The application 112 then splits the cuckoo filter into two secret shares for each of the two servers in the MPC cluster 130.
[0204] Upon receiving the context response, for each cached digital component and each valid recency bucket identifier, the MPC cluster 130 uses the dot product technique described above to compute the publisher amount in plaintext. The MPC cluster 130 then inserts the digital component and the computed publisher amount into a list. The MPC cluster 130 also inserts any selection values received along with the context response in the same list and sorts the list based on the publisher amount from highest to lowest. The list size is proportional to the average cardinality of the recency buckets. For example, if there are 1,000 cached digital components and on average each cached digital component has four recency buckets, this will create a list of publisher amounts of size 4,000.
[0205] The MPC cluster 130 computes the corresponding augmented user group identifier and then relies on the secret share equality test algorithm to check if the augmented user group identifier is in the cuckoo filter to determine if the cached digital component and the corresponding selection value (e.g., publisher amount) are eligible for the selection process.
[0206] Similarly, the same method can support other low - entropy per - user - group user - level signals. For example, if the user group is about users who leave an electronic device in a shopping cart, the user - level signal can be the bucketized value of the electronic device, e.g., low / medium / high amount.
[0207] Figure 6FIG. 600 is a block diagram of an example computer system capable of performing the above operations. System 600 includes a processor 610, a memory 620, a storage device 630, and an input / output device 640. Each of the components 610, 620, 630, and 640 can be interconnected, for example, using a system bus 650. The processor 610 is capable of processing instructions for execution within the system 600. In some embodiments, the processor 610 is a single-threaded processor. In another embodiment, the processor 610 is a multi-threaded processor. The processor 610 is capable of processing instructions stored in the memory 620 or the storage device 630.
[0208] The memory 620 stores information within the system 600. In one embodiment, the memory 620 is a computer-readable medium. In some embodiments, the memory 620 is a volatile memory unit. In another embodiment, the memory 620 is a non-volatile memory unit.
[0209] The storage device 630 can provide mass storage for the system 600. In some embodiments, the storage device 630 is a computer-readable medium. In various different embodiments, the storage device 630 can include, for example, a hard disk device, an optical disk device, a storage device shared by multiple computing devices over a network (e.g., a cloud storage device), or some other mass storage device.
[0210] The input / output device 640 provides input / output operations for the system 600. In some embodiments, the input / output device 640 can include one or more of the following: a network interface device, such as an Ethernet card, a serial communication device, such as an RS-232 port, and / or a wireless interface device, such as an 802.11 card. In another embodiment, the input / output device can include a drive device configured to receive input data and send output data to an external device 660 (e.g., a keyboard, a printer, and a display device). However, other embodiments can also be used, such as mobile computing devices, mobile communication devices, set-top box TV client devices, etc.
[0211] Although an example processing system has been described Figure 6 herein, embodiments of the subject matter and functional operations described in this specification can be implemented in other types of digital electronic circuits, or in computer software, firmware, or hardware (including the structures disclosed in this specification and their structural equivalents), or in a combination of one or more of them.
[0212] Embodiments of the subject matter and the operations described in this specification can be implemented in digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or in a combination of one or more of them. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions, encoded on a computer storage medium (or media) for execution by, or to control the operation of, a data processing apparatus. Alternatively or additionally, the program instructions can be encoded on an artificially generated propagated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal, generated to encode information for transmission to an appropriate receiver apparatus for execution by the data processing apparatus. A computer storage medium can be a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination or subset of one or more of them. Moreover, although a computer storage medium is not a propagated signal, a computer storage medium can be the source or destination of computer program instructions encoded in an artificially generated propagated signal. A computer storage medium can also be one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices) or a combination or subset of one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices).
[0213] The operations described in this specification can be implemented as operations performed by a data processing apparatus on data stored on one or more computer-readable storage devices or received from other sources.
[0214] The term “data processing apparatus” encompasses all kinds of apparatus, devices, and machines for processing data, including, by way of example, a programmable processor, a computer, a system on a chip, or multiple or combinations of the foregoing. The apparatus can include dedicated logic circuitry, such as an FPGA (field programmable gate array) or an ASIC (application specific integrated circuit). In addition to hardware, the apparatus can also include code that creates an execution environment for the computer programs being discussed, e.g., code that constitutes processor firmware, a protocol stack, a database management system, an operating system, a cross-platform runtime environment, a virtual machine, or a combination of one or more of them. The apparatus and the execution environment can implement various different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.
[0215] A computer program (also known as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may or may not correspond to a file in a file system. The program can be stored in a portion of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program in question, or in multiple cooperating files (e.g., files that store one or more modules, subroutines, or portions of code). A computer program can be deployed to execute on one computer or on multiple computers located at one site or distributed across multiple sites and interconnected by a communication network.
[0216] The processes and logical flows described in this specification can be performed by one or more programmable processors executing one or more computer programs to perform actions by operating on input data and generating output. The processes and logical flows can also be performed by special-purpose logic circuitry, and the apparatus can also be implemented as special-purpose logic circuitry, such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit).
[0217] By way of example, processors suitable for executing a computer program include both general and special purpose microprocessors. Generally, a processor will receive instructions and data from a read only memory or a random access memory or both. The basic elements of a computer are a processor for performing actions in accordance with the instructions and one or more memory devices for storing the instructions and data. Generally, a computer will also include or be operatively coupled to one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, to receive data from or transfer data to the mass storage device, or both. However, a computer need not have such devices. In addition, a computer can be embedded in another device, for example, a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a Global Positioning System (GPS) receiver, or a portable storage device (e.g., a Universal Serial Bus (USB) flash drive), etc. Devices suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, including, for example, semiconductor memory devices such as EPROM, EEPROM, and flash memory devices; magnetic disks, such as internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special-purpose logic circuitry.
[0218] To provide for interaction with a user, embodiments of the subject matter described in this specification can be implemented on a computer having a display device for displaying information to the user, such as a CRT (cathode ray tube) or LCD (liquid crystal display) monitor, and a keyboard and a pointing device by which the user can provide input to the computer, such as a mouse or a trackball. Other types of devices can also be used to provide for interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback; and input from the user can be received in any form, including sound, voice, or tactile input. In addition, the computer can interact with the user by sending documents to and receiving documents from the devices used by the user; for example, by sending a web page to a web browser on a client device of the user in response to a request received from the web browser.
[0219] Embodiments of the subject matter described in this specification can be implemented in a computing system that includes a backend component (such as a data server), or includes a middleware component (such as an application server), or includes a frontend component (such as a client computer having a graphical user interface or a web browser through which a user can interact with an implementation of the subject matter described in this specification), or includes any combination of one or more such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (such as a communication network). Examples of communication networks include local area networks (“LANs”) and wide area networks (“WANs”), the Internet (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks).
[0220] The computing system can include clients and servers. The clients and servers are typically located remotely from each other and typically interact through a communication network. The relationship between a client and a server arises from computer programs running on the respective computers and has a client-server relationship with each other. In some embodiments, the server sends data (e.g., an HTML page) to a client device (e.g., to display the data to a user interacting with the client device and to receive user input from the user). Data generated at the client device (e.g., the result of a user interaction) can be received at the server from the client device.
[0221] Although this specification contains many specific implementation details, these should not be construed as limitations on the scope of any invention or of what may be claimed, but rather as descriptions of features specific to particular embodiments of a particular invention. Certain features that are described in this specification in the context of separate embodiments can also be implemented in combination within a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although the features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be deleted from the combination, and the claimed combination may refer to a sub-combination or a variant of a sub-combination.
[0222] Similarly, although operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In some cases, multitasking and parallel processing may be advantageous. In addition, the separation of various system components in the foregoing embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.
[0223] Accordingly, particular embodiments of the subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve desirable results. In addition, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve desirable results. In certain implementations, multitasking and parallel processing may be advantageous.
Claims
1. A computer-implemented method, comprising: Receiving, from a client device and by a first computing system among a plurality of multi-party computing (MPC) systems, a digital component request that includes a first secret share of data identifying a user group of which the user of the client device is a member and a set of context signals; Transmitting, by the first computing system, a context digital component request to a content platform; Receiving, by the first computing system and from the content platform, selection data for a plurality of digital components, wherein the selection data includes first vector data that defines a context-based vector of values selected at least in part based on the set of context signals; Obtaining, by the first computing system and for each of the plurality of digital components, second vector data that defines a user-group-based vector of values selected at least in part based on a corresponding user group to which the digital component corresponds; Determining, by the first computing system, a selection value for each digital component based on the first vector data and the second vector data, wherein determining the selection value for each digital component includes determining a dot product of the context-based vector of values of the digital component and the user-group-based vector of values; For each digital component, determining a candidate parameter indicating whether a corresponding user group identifier corresponding to the digital component matches the user group of which the user is a member; Generating, based on the selection value and the candidate parameter, a first secret share of a selection result that identifies a given digital component having the highest selection value from among a plurality of candidate digital components, wherein each candidate digital component is a digital component for which the candidate parameter of the selection value corresponding to the digital component indicates that the corresponding user group identifier corresponding to the selection value matches the user group of which the user is a member; and Transmitting, to the client device, the first secret share of the selection result that identifies the given digital component.
2. The computer-implemented method according to claim 1, wherein, The first vector data includes a first secret share of the context-based vector of values and the second vector data includes a first secret share of the user-group-based vector of values.
3. The computer-implemented method according to claim 2, wherein, Determining, by the first computing system, the selection value for each digital component based on the first vector data and the second vector data includes collaborating with one or more second computing systems among the plurality of MPC systems to perform a secure MPC process to determine a dot product of the context-based vector of values of the digital component and the user-group-based vector of values.
4. The computer-implemented method according to claim 1, wherein, The selection value for each digital component is based on the user's user profile.
5. The computer-implemented method according to claim 4, wherein, Determining, by the first computing system, the selection value for each digital component based on the first vector data and the second vector data includes determining a dot product of the context-based vector of the digital component, the user-group-based vector of the digital component, and a user profile vector of the user's user profile.
6. The computer-implemented method according to claim 1, wherein, Determining the candidate parameter for each selection value includes determining a first secret share of the candidate parameter for each selection value.
7. The computer-implemented method according to claim 1, wherein, Generating the first secret share of the selection result includes: Generate an order of the selection values based on the magnitude of each selection value; Determine a first secret share of the cumulative value of each selection value based on the order of the selection values and the candidate parameters of each selection value; For each selection value, determine a first secret share of the winner parameter based on (i) the candidate parameter of the selection value and (ii) the result of an equality test indicating whether the cumulative value of the selection value is a specified value; For each selection value, determine the product of the winner parameter of the selection value and the digital component information element of the selection value, and determine a first secret share of the sum of the products as the first secret share of the selection result; 8. The computer-implemented method according to claim 7, wherein, Determining the first secret share of the cumulative value of each selection value includes: For each individual selection value, determine a certain amount of selection values between the highest selection value and the individual selection value, including the highest selection value and the individual selection value, where the certain amount of selection values have candidate parameters indicating that the corresponding user group identifier associated with the selection value matches the user group including the user as a member; 9. A system, comprising: A first computing system including one or more processors; And One or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations including the following: Receive, from a client device and by the first computing system in a plurality of multi-party computing (MPC) systems, a digital component request, the digital component request including a first secret share of data identifying a user group including the user of the client device as a member and a set of context signals; Transmit, by the first computing system, a context digital component request to a content platform; Receive, by the first computing system and from the content platform, selection data for a plurality of digital components, where the selection data includes first vector data that defines a context-based vector of values selected at least in part based on the set of context signals; Obtain, by the first computing system and for each of the plurality of digital components, second vector data that defines a user-group-based vector of values selected at least in part based on the corresponding user group associated with the digital component; Determine, by the first computing system, a selection value for each digital component based on the first vector data and the second vector data, where determining the selection value for each digital component includes determining the dot product of the context-based vector of the value of the digital component and the user-group-based vector of the value; For each digital component, determine a candidate parameter indicating whether the corresponding user group identifier associated with the digital component matches the user group including the user as a member; Generate a first secret share of a selection result based on the selected value and the candidate parameter, the selection result identifying a given digital component having the highest selected value from a plurality of candidate digital components, wherein each candidate digital component is a digital component for which the candidate parameter of the selected value corresponding to the digital component indicates that the corresponding user group identifier corresponding to the selected value matches the user group including the user as a member; and Transmit the first secret share of the selection result identifying the given digital component to the client device.
10. The system according to claim 9, wherein, The first vector data includes a first secret share of a context-based vector of values and the second vector data includes a first secret share of a user-group-based vector of values.
11. The system according to claim 10, wherein Determining, by the first computing system, the selected value for each digital component based on the first vector data and the second vector data includes collaborating with one or more second computing systems in the plurality of MPC systems to perform a secure MPC process to determine a dot product of the context-based vector of values and the user-group-based vector of values of the digital component.
12. The system according to claim 9, wherein, The selected value for each digital component is based on the user's user profile.
13. The system according to claim 12, wherein, Determining, by the first computing system, the selected value for each digital component based on the first vector data and the second vector data includes determining a dot product of the context-based vector of the digital component, the user-group-based vector of the digital component, and the user profile vector of the user's user profile.
14. The system according to claim 9, wherein, Determining the candidate parameter for each selected value includes determining a first secret share of the candidate parameter for each selected value.
15. The system according to claim 9, wherein Generating the first secret share of the selection result includes: Generating an order of the selected values based on the magnitude of each selected value; Determining a first secret share of a cumulative value for each selected value based on the order of the selected values and the candidate parameter for each selected value; For each selected value, determining a first secret share of a winner parameter based on (i) the candidate parameter of the selected value and (ii) the result of an equality test indicating whether the cumulative value of the selected value is a specified value; For each selected value, determining the product of the winner parameter of the selected value and the digital component information element of the selected value, and determining a first secret share of the sum of the products as the first secret share of the selection result.
16. The system according to claim 15, wherein, Determining the first secret share of the cumulative value for each selected value includes: For each individual selected value, determining a certain number of selected values between the highest selected value and the individual selected value, including the highest selected value and the individual selected value, the certain number of selected values having candidate parameters indicating that the corresponding user group identifier corresponding to the selected value matches the user group including the user as a member.
17. A non-transitory computer storage medium encoded with instructions that, when executed by a first computing system, cause the first computing system to perform operations including the following: Receiving, from a client device and by a first computing system among a plurality of multi-party computing (MPC) systems, a digital component request that includes a first secret share of data identifying a user group of which a user including the client device is a member and a set of context signals; Transmitting, by the first computing system, a context digital component request to a content platform; Receiving, by the first computing system and from the content platform, selection data for a plurality of digital components, wherein the selection data includes first vector data that defines a context-based vector of values selected at least in part based on the set of context signals; Obtaining, by the first computing system and for each of the plurality of digital components, second vector data that defines a user-group-based vector of values selected at least in part based on a corresponding user group to which the digital component corresponds; Determining, by the first computing system, a selection value for each digital component based on the first vector data and the second vector data, wherein determining the selection value for each digital component includes determining a dot product of the context-based vector of values of the digital component and the user-group-based vector of values; For each digital component, determining a candidate parameter indicating whether a corresponding user group identifier corresponding to the digital component matches the user group including the user as a member; Generating, based on the selection value and the candidate parameter, a first secret share of a selection result that identifies a given digital component having the highest selection value from among a plurality of candidate digital components, wherein each candidate digital component is a digital component for which the candidate parameter of the selection value corresponding to the digital component indicates that the corresponding user group identifier corresponding to the selection value matches the user group including the user as a member; and Transmitting, to the client device, the first secret share of the selection result identifying the given digital component.
Citation Information
Patent Citations
Multimodal transmission of packetized data
CN108541312A
Improving opt-out compliance
CN110622159A