Privacy Protection Data Processing for Content Distribution
By leveraging unidentifiable user data and shared storage on client devices, the system addresses the challenge of content delivery without third-party cookies, ensuring privacy and effective content selection.
Patent Information
- Application Number
- JP2024535285
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-04-24
- Publication Date
- 2025-06-12
- Estimated Expiration
- 2043-04-24
AI Technical Summary
The exclusion of third-party cookies in browsers and device platforms has hindered the ability of computing systems to collect and utilize user data for personalized content delivery, leading to a gap in predicting user interests and attributes.
A method and system for generating and processing unidentifiable user data to select and deliver digital content to client devices, utilizing a shared storage on the client device to accumulate and update user attribute data, and generating aggregated user attribute reports without relying on third-party cookies.
This approach enables the effective utilization of user attribute data to guide content selection and delivery, ensuring privacy protection and overcoming the limitations imposed by the exclusion of third-party cookies.
Smart Images

Figure 2025517848000001_ABST
Abstract
Description
Technical Field
[0001] This specification generally relates to data processing, data privacy, and data security.
Background Art
[0002] In systems and devices connected to a public network such as the Internet, data security and user privacy are extremely important. With the strengthening of user privacy, many developers have changed the way they handle user data. For example, some browsers plan to discourage the use of third-party cookies.
Summary of the Invention
[0003] This specification describes a method, computer system, and apparatus for generating and processing unidentifiable user data to select and provide digital content to a client device in a privacy-protecting manner, including a computer program encoded in a computer storage medium.
[0004] In an innovative aspect, this specification describes a method for delivering digital components to a client device. The method can be implemented by a system including one or more computers.
[0005] For each of a plurality of client devices, the system receives a digital component request from an application running on the user's client device. The system identifies one or more user attributes of the user based on the digital component request. The system sends a digital component response to the application, which includes (i) one or more digital components and (ii) attribute data including one or more user attributes of the user. In response to receiving the attribute data, the application is configured to update the accumulated user attribute data stored in the shared storage of the client device based on the one or more user attributes. The system retrieves the user attribute data accumulated in the shared storage of each client device from the shared storage of the plurality of client devices. The system generates an aggregated user attribute report for one or more aggregation keys, which includes obtaining an aggregated data profile generated by aggregating the user attribute data accumulated from a subset of the plurality of client devices that accessed an electronic resource or digital component identified by the aggregation key for each of the one or more aggregation keys. The system adjusts one or more delivery parameters for delivering the digital component to the client device in response to the digital component request based on the aggregated data profile. The system delivers the digital component to the client device based on the delivery parameters. Other embodiments of this aspect include corresponding apparatuses, systems, and computer programs configured to execute the aspects of the method, encoded on a computer storage device.
[0006] These and other embodiments may each optionally include one or more of the following features. In some embodiments, to generate an aggregated user attribute report, the system sends an aggregation request to a secure aggregation system that includes the accumulated user attribute data obtained from each of the client devices and one or more aggregation keys, and receives from the secure aggregation system an aggregated data profile generated in response to the aggregation request. The accumulated user attribute data received from each client device may be encrypted by the client device using an encryption key of the secure aggregation system.
[0007] In some embodiments, the digital component request includes context data related to the environment in which one or more digital components are to be displayed on the client device. The environment can include an electronic resource, and the context data can include one or more of a resource locator of the electronic resource on which one or more digital components are to be displayed on the client device, and / or a topic of the content of the electronic resource.
[0008] In some embodiments, one or more user attributes are identified using a prediction model configured to predict attributes of a user who accessed a topic of an electronic resource or content of an electronic resource. In response to receiving the user attributes identified using the prediction model, the application determines whether the stored user attribute data stored in the shared storage of the client device includes keyed entries for one or more user attributes, generates a new keyed entry in the stored user attribute data in response to the stored user attribute data not including keyed entries, assigns an entry value to the new keyed entry based on the one or more user attributes identified using the prediction model, and updates the current entry value of the keyed entry of the stored user attribute data based on the one or more user attributes identified using the prediction model in response to the stored user attribute data including keyed entries. To update the current entry value of the keyed entry, the application can be configured to increment or decrement the current entry value of the keyed entry in response to the stored user attribute data including the keyed entry.
[0009] In some embodiments, a user subscribes to an electronic resource using a user identifier, and one or more user attributes are identified using a user profile associated with the user identifier. In response to receiving user attributes identified using a prediction profile, an application determines whether accumulated user attribute data stored in a shared storage of a client device includes keyed entries for one or more user attributes, generates new keyed entries in the accumulated user attribute data in response to determining that the aggregated user attribute data does not include keyed entries, assigns entry values to the new keyed entries based on one or more user attributes identified using the user profile, and updates the entry values of the keyed entries of the accumulated user attribute data based on one or more user attributes identified using the user profile in response to determining that the accumulated user attribute data includes keyed entries. A user interface of the electronic resource can include code for causing the application to update the accumulated user attribute data based on one or more user attributes in response to receiving the user attributes.
[0010] In some embodiments, an aggregation profile for an aggregation key includes one or more metrics of an electronic resource or digital component identified by the aggregation key. The one or more metrics can include a reach metric that measures the number of unique users in a subset of client devices that have accessed the electronic resource or digital component identified by the aggregation key.
[0011] In some embodiments, to aggregate user attribute data from a subset of client devices, the system adds random noise to the user attribute data of each of the subset of client devices before aggregating.
[0012] Certain embodiments of the subject matter described herein can be implemented to realize one or more of the following advantages. A content delivery system can utilize user attribute data of a set of users, such as users who have accessed a particular electronic resource (such as a website) or digital component (such as a video / audio clip, image, text, etc.), to guide the selection and delivery of content to other users, for example, to deliver content that is optimal for the interests and needs of the users.
[0013] Heretofore, third-party cookies (such as cookies from a domain different from the resource rendered by the client device) have been used to collect data from client devices on the Internet. For example, a third-party cookie can be a script file from a website other than the website currently being accessed by the client device, and is typically used for the purpose of tracking a user's actions and / or providing digital content to the user. Due to the increasing concerns about user privacy and data protection, some browsers and device platforms block the use of third-party cookies, and third-party cookies are being used less and less, thereby preventing data collection using third-party cookies. Therefore, when attempting to enhance the online browsing experience by leveraging the collected data, such as selecting content relevant to the user based on data collected using third-party cookies, problems arise. That is, without using third-party cookies, much of the previously collected data becomes unavailable, and thus computing systems cannot use the data to predict a user's interests or attributes, improve the user's online experience, and / or present relevant content to the user based on the activities performed by the user on a particular web page or other resource.
[0014] The technology described in this specification can solve the obstacles that can arise from the exclusion of third - party cookies. In particular, this specification describes a method for obtaining user - attribute data that protects privacy from the shared storage of a client device. The shared storage of a client device maintains accumulated user - attribute data that characterizes the attributes and / or interests of the user of the client device, and updates the accumulated user - attribute data based on user - attribute signals received from a content - delivery system or a content - supply system. A computer system, such as a secure server, can collect cumulative user - attribute data from a client device without using third - party cookies. The computer system can generate a user - attribute report aggregated from the user - attribute data, and the content - delivery system can use the aggregated user - attribute report to guide the delivery of digital components.
[0015] By using these technologies, a content - delivery system can effectively utilize the user - attribute data of a user group without using third - party cookies to guide the selection and delivery of content to specific users. Instead of using third - party cookies, a method for maintaining and utilizing user - attribute data that protects privacy using the shared storage of a client device will be described. The shared storage provides a framework that enables sharing data between multiple sessions and / or multiple instances accessing an electronic resource such as a website, and / or sharing data between different electronic resources. The shared storage can also be implemented with measures to protect the security and privacy of the stored data. These technologies also provide user - privacy protection in the process of collecting user - attribute data by preventing the collection and use of a user's confidential information (such as information that can identify an individual) without the user's consent.
[0016] The details of one or more embodiments of the subject matter described in this specification are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages of the subject matter will become apparent from the description, the drawings, and the claims.
Brief Description of the Drawings
[0017]
Figure 1
Figure 2
Figure 3
Figure 4
Best Mode for Carrying Out the Invention
[0018] Like reference symbols and designations in the various drawings refer to like elements.
[0019] Generally, this specification describes systems and techniques for providing digital content, such as digital components, to client devices in a manner that protects a user's privacy. A server can be configured to obtain user attribute data accumulated from a client device and use the obtained user attribute data to generate an aggregated user attribute report. A digital component delivery system can use the aggregated user attribute report to adjust delivery parameters for delivering digital components to a client device in response to a digital component request.
[0020] In addition to the description of this entire document, with respect to both whether the systems, programs, or functions described in this specification can enable the collection of user information (e.g., information regarding the user's social network, social actions or activities, occupation, user preferences, or the user's current location), and when they can enable it, as well as whether content or communications are sent from the server to the user, controls (e.g., user interface elements with which the user can interact) can be provided to the user to enable the user to make selections. Further, certain data can be processed in one or more ways such that information that can identify an individual is removed before the data is stored or used. For example, the user's identity can be processed so as not to be able to determine information that can identify the individual user, or, when location information is obtained (such as at the city, zip code, or state level), the user's geographical location can be generalized so as not to be able to determine the user's specific location. Thus, the user can control what information is collected about the user, how that information is used, and what information is provided to the user.
[0021] FIG. 1 is a block diagram of an exemplary environment 100 in which a digital component delivery system 150 delivers digital components to a client device 110. Environment 100 includes a data communication network 105 such as a local area network (LAN), wide area network (WAN), the Internet, a mobile network, or a combination thereof. The data communication network 105 connects the client device 110 to the digital component delivery system 150. The network 105 can also connect the digital component delivery system 150 to digital component providers (e.g., 160-1, 160-2, and 160-3).
[0022] Website 140 is one or more electronic resources associated with a domain name and hosted by one or more servers. An exemplary website can be a collection of web pages in HTML format that can include programming elements such as text, images, multimedia content, and scripts. Each website 140 is maintained by an issuer 130, which is an entity that controls, manages, and / or owns the website 140.
[0023] Electronic resources are also referred to as resources herein for brevity. As used herein, a resource can include HTML pages, word processor documents, and Portable Document Format (PDF) documents, images, videos, and feed sources. A resource may contain content such as words, phrases, images, and audio, and such content may contain embedded information (such as meta information within a hyperlink) and / or embedded instructions (such as a script). A resource can be identified by a resource address such as a Universal Resource Locator (URL) associated with the resource.
[0024] Client device 110 is an electronic device that can communicate via network 105. Exemplary client devices 110 include personal computers, server computers, mobile communication devices such as smartphones and / or tablet computers, and other devices that can send and receive data via network 105. The client device may also include a digital assistant device that accepts audio input via a microphone and outputs audio output via a speaker. When the digital assistant detects a "hot word" or "hot phrase" that activates the microphone to accept voice input, the digital assistant can be set to a listening mode (such as being ready to accept voice input). The digital assistant device may also include a camera and / or a display for capturing images and visually displaying information. The digital assistant can be implemented on various forms of hardware devices such as wearable devices (such as watches and glasses), smartphones, speaker devices, tablet devices, or other hardware devices. The client device may also include digital media devices such as a streaming device that connects to a television and other displays to stream video to the television, a gaming device, or a virtual reality system.
[0025] A game device is a device that enables a user to participate in a game application. For example, a user can control one or more characters, avatars, or other rendered content displayed in the game application. A game device typically includes a computer processor, a memory device, and a controller interface (physically or visually rendered) that enables user control of the content rendered by the game application. A game device can store and execute the game application locally, or execute a game application (such as an online game application) that is at least partially stored and / or provided by a cloud server. Similarly, a game device can interface with a game server that executes the game application and "streams" the game application to the game device. A game device can be a tablet device, a mobile communication device, a computer, or other device that performs functions other than executing a game application.
[0026] Client device 110 can include an application 112, such as a web browser and / or a native application, to facilitate the sending and receiving of data via network 105. A native application is an application developed for a specific platform or a specific device (such as a mobile device with a specific operating system). Although operations can be described as being performed by client device 110, such operations can be performed by application 112 operating on client device 110.
[0027] Application 112 can present electronic resources such as web pages, application pages, or other application content to the user of client device 110. The electronic resources can include digital component slots for displaying digital components that include the content of the electronic resource. A digital component slot is an area of an electronic resource (such as a web page or application page) for displaying a digital component. A digital component slot may also refer to a part of an audio stream and / or video stream (another example of an electronic resource) for playing a digital component.
[0028] As used throughout this specification, "digital component" refers to an individual unit of digital content or digital information (such as a video clip, audio clip, multimedia clip, image, text, or other content unit). A digital component can be electronically stored on a physical memory device as a single file or as a collection of files, and a digital component can take the form of a video file, audio file, multimedia file, image file, or text file and can include advertising information, so an advertisement is a type of digital component. For example, a digital component may be content intended to supplement the content of a web page or other resource presented by Application 112. More specifically, a digital component may include digital content related to the resource content (e.g., a digital component may be related to the same topic or a related topic as the web page content). Thus, by providing digital components, the content of a web page or application can be supplemented and overall improved.
[0029] When application 112 loads a resource that includes a digital component slot, application 112 can generate a digital component request that requests a digital component for display in the digital component slot. In some embodiments, the digital component slot and / or the resource can include code (such as a script) that causes application 112 to request a digital component from digital component delivery system 150.
[0030] A digital component request may include context data that is typically considered non-confidential. The context data can describe the environment in which the selected digital component is presented. The context data can include, for example, approximate location information indicating the approximate location of the client device 110 that sent the digital component request, the resource (such as a website or native application) in which the selected digital component is presented (such as by including a resource locator such as a URI or URL of the resource), the language settings of application 112 or client device 110, the number of digital component slots in which the digital component is presented with the resource, the type of digital component slot, and / or other appropriate context information.
[0031] As will be described in more detail below, based on the data (such as context data) included in the digital component request, digital component delivery system 150 can identify, for example predict, the user attributes of the user of client device 110 that received the digital component request. In response to the response of the digital component, digital component delivery system 150 can send attribute data identifying the user attributes identified from the digital component request to client device 110.
[0032] Application 112 maintains a shared storage 114 that stores a set of data that Application 112 can access and update. The data stored in shared storage 114 can have any suitable data format depending on the particular application, preference, and / or protocol. The data stored in shared storage 114 can be shared among multiple sessions and / or multiple instances of Application 112. For example, the stored data can be shared by all instances of an electronic resource (such as a website) running in different tabs or windows of Application 112. In some embodiments, the data stored in shared storage 114 can be shared among multiple electronic resources, e.g., multiple websites accessed by an application.
[0033] To protect the security and privacy of the data stored in shared storage 114, several measures can be taken. For example, in some embodiments, shared storage 114 may be located in a separate portion of the storage space of Application 112. In some embodiments, a separate thread of Application 112 manages shared storage 114 and provides access to shared storage 114. The separate thread can isolate shared storage 114 from being accessed by other components of Application 112 and / or by unpermitted websites, e.g., websites the user has not interacted with. In some embodiments, the application can encrypt the data stored in shared storage 114 before transmitting the data to another system via network 105.
[0034] To provide data for guiding the selection and delivery of content to a user, the data stored in the shared storage 114 may include accumulated user attribute data characterizing the user of the client device 110. The accumulated user attribute data may include data characterizing the user's interests (such as topics of interest or hobbies), and / or data characterizing the user's non-identifying demographic attributes. As will be described in more detail below, the application 112, for example, a separate thread of the application 112, is configured to update the accumulated user attribute data based on the attribute data received from the digital component delivery system 150.
[0035] The secure aggregation reporting system 120 is configured to receive the accumulated user attribute data from the shared storage 114 of a plurality of client devices 110 and use the accumulated user attribute data to generate an aggregated user attribute report for a set of aggregation keys. The system 120 can be a secure server implemented using one or more computers (or other suitable computing devices) that may be distributed in multiple locations. The secure system 120 can be operated and maintained by a party different from the digital component delivery system 150 or an independent trusted party, such as the user of the client device, the party operating the digital component delivery system 150, and the digital component provider 160. For example, the secure system 120 can be operated by an industry group or a government group.
[0036] In some embodiments, the secure system 120 implements a shared storage worklet 122 configured to receive user attribute data stored by accessing the shared storage 114 of the client device 110 in a secure environment, i.e., a secure environment, and to process the stored user attribute data to generate an aggregated report. To provide further security and privacy for user data, the shared storage worklet 122 can be a dedicated process or thread executed in the secure system 120 that is separated from other processes or threads of the secure system 120.
[0037] The shared storage worklet 122 includes an aggregation key selection engine 124 and a data aggregation engine 126. The aggregation key selection engine 124 is configured to select an aggregation key from a list of aggregation keys, and the data aggregation engine 126 is configured to generate an aggregated data profile by aggregating user attribute data stored from a subset of client devices that have accessed an electronic resource or digital component identified by the aggregation key.
[0038] The digital component delivery system 150 can identify a set of digital components eligible for presentation to the client device 110 from among a set of digital components available from the content platform 150. For example, the digital component delivery system 150 can select one or more digital components from the digital components stored in the digital component repository and / or from the set of digital components received from the digital component provider 160.
[0039] The digital component repository can store in a database the digital components received from digital component providers and additional data (such as metadata) for each digital component. The metadata of a digital component can include, for example, distribution criteria that define the circumstances under which the digital component is eligible to be supplied to the client device 110 in response to a digital component request received from the client device 110, and / or selection parameters indicating the amount to be given to the originator when the digital component is displayed and / or presented together with the originator's resources and / or interacted with by the user. The distribution criteria and selection parameters can be characterized by one or more distribution parameters.
[0040] For example, the distribution parameters of a specific digital component can include distribution keywords that must be matched by terms specified in the request, etc., for the digital component to be eligible for presentation. In another example, the distribution criteria of a digital component can include location information indicating a geographical location eligible to present the digital component, user group membership data identifying a user group eligible to present the digital component, resource data identifying a resource eligible to present an electronic resource, and / or other appropriate distribution criteria. The distribution criteria may also include negative criteria, such as criteria indicating circumstances under which the digital component is not eligible (such as a specific resource or a specific location). The distribution parameters can also specify selection parameters and / or budgets for delivering specific third-party content.
[0041] As will be described in more detail below, the delivery parameters of digital components can be adjusted based on the aggregated user attribute reports of the digital components. The digital component delivery system 150 can identify eligible digital components based on the delivery parameters and data included in the digital component requests. The digital component delivery system 150 then selects a digital component from the eligible digital components and can supply the selected digital component to the client device 110 for display to the user of the client device 110.
[0042] Figure 2 is a swimlane flowchart of an exemplary process 200 for delivering digital components for display on a client device. The operations of process 200 can be implemented, for example, by the client device 110, the secure aggregation reporting system 120, and the digital component delivery systems 150, one or more issuers 130, and one or more websites 140. The operations of process 200 can also be implemented as instructions stored on a non-transitory computer-readable medium, and the execution of the instructions by a data processing apparatus can cause the data processing apparatus to perform the operations of process 200.
[0043] At 212, the client device 110 sends a request for an electronic resource, such as a request for a web page, to the website 140. The request can include the URL of the electronic resource. At 232, the website 140 sends the requested electronic resource to the client device 110.
[0044] After receiving the requested electronic resource and while loading the electronic resource, client device 110 generates a digital component request for the digital components to be displayed in the digital component slots of the electronic resource. The digital component request includes context data that describes the environment in which the selected digital components are to be presented. For example, the context data can identify the electronic resource (such as a website) in which the selected digital components are to be presented. In a particular example, the context data may include the URL or URI of the electronic resource. The context data can include, for example, approximate location information indicating a general location of client device 110, the voice language setting of client device 110, the number of digital component slots in which the digital components are to be presented with the resource, the type of digital component slots, and / or other suitable context information.
[0045] At 214, client device 110 transmits the digital component request to digital component delivery system 150. Digital component delivery system 150 selects digital components based on the digital component request at 251a and identifies one or more user attributes of the user based on the digital component request at 251b.
[0046] In some embodiments, the digital component delivery system 150 identifies user attributes using a prediction model (e.g., a trained machine learning model) based on context data within a digital component request. For example, the prediction model can be configured to predict the attributes of a user who accessed an electronic resource or the topic of the content of an electronic resource. The digital component delivery system 150 uses the prediction model to process an input that specifies an electronic resource and / or the topic of the content of the electronic resource, and generates an output that includes a prediction of the user's user attributes, such as the user's user interests (e.g., topics of interest), the user's demographic attributes, and / or other characteristics of the user who accessed the electronic resource or the topic of the content of the electronic resource. The user attributes and / or other characteristics predicted by the prediction model can be used to indicate the attributes of the user of the client device 110. In some embodiments, the prediction model can further output a numerical value of the likelihood that the user has the predicted user attributes.
[0047] In some other embodiments, when a user signs in to an electronic resource using a user identifier, the digital component delivery system 150 can obtain user attribute data associated with the user profile identified by the user identifier, if the user permits. For example, in the user profile, the user's interests, demographic attributes, and / or other characteristics of the user can be specified or indicated. The digital component delivery system 150 can identify such information from the user profile.
[0048] At 252, the digital component delivery system 150 transmits a response to the client device 110. The response includes the selected digital component and attribute data that specifies the user's user attributes, such as user attributes identified based on the output of the prediction model and / or user attributes identified based on the user profile.
[0049] When receiving the attribute data, at 216, the client device 110 updates the stored user attribute data stored in the shared storage of the client device 110 based on the user attributes specified by the attribute data.
[0050] In some embodiments, when user attributes are identified using a prediction model based on context data, the client device 110 can determine whether the stored user attribute data stored in the shared storage includes a keyed entry for the identified user attribute. If the stored user attribute data does not include a keyed entry, the client device 110 can generate a new keyed entry for the identified user attribute and assign an entry value to the new keyed entry. On the other hand, if the stored user attribute data includes a keyed entry, the client device 110 can update the current entry value of the keyed entry based on the user attribute identified using the prediction model. For example, when updating the current entry value of the keyed entry, the client device 110 can increment or decrement the current entry value of the keyed entry.
[0051] In an exemplary example, the first digital component request received from the client device 110 may include context data that identifies the first electronic resource as "example.com / / vegetablefertilizer / ". The prediction model can predict and output with a 60% probability that a user accessing this web page is likely to be interested in gardening. The client device 110 can generate an entry with the key "interest in gardening" and assign a value of 0.6 to that entry. The second digital component request received from the client device 110 may include context data that identifies the second electronic resource as "example.com / gardendesign / ". The prediction model can predict and output with an 80% probability that a user accessing this web page is likely to be interested in gardening. The client device 110 can update the value of the keyed entry "interest in gardening" by incrementing the value of the entry by 0.8. The value of the keyed entry can be updated cumulatively based on the predicted user attributes associated with the keyed entry.
[0052] In some other embodiments, when user attributes are identified using user profile data associated with a user identifier, the client device 110 can generate or update keyed entries for one or more of the identified user attributes. For example, if the user profile data specifies or indicates that the user is interested in gardening, the client device 110 can generate a keyed entry "interested in gardening" and assign a value of 1 to that entry. If the user profile data specifies or indicates that the user is not interested in gardening, the client device 110 can assign a value of 0 to the entry "interest in gardening".
[0053] In some embodiments, when an electronic resource is presented to the client device 110, the user interface for presenting the electronic resource includes script code for causing an application on the client device 110 to update the stored user attribute data based on user attributes identified using the user profile.
[0054] In 221, the secure aggregation reporting system 120 obtains user attribute data stored from the shared storage of the client device 110. The above processes including 212, 232, 214, 251a, 251b, 252, and 216 can be repeatedly executed for a plurality of client devices 110, and the secure aggregation reporting system 120 obtains user attribute data stored from each of the plurality of client devices 110.
[0055] In 222, the secure aggregation reporting system 120 uses the obtained stored user attribute data to generate an aggregated user attribute report including respective aggregated data profiles for each set of selected aggregation keys.
[0056] System 120 can select an aggregation key based on context signals such as a specific resource locator, a specific digital component, a specific geographic region, and / or a specific type of device. For example, the aggregation key can be in the form of <URL, Region, Device Type>. In another example, the aggregation key can be in the form of <Digital component identifier, Region, Device Type>. Other suitable signals can also be used. The aggregation key can include a combination of context signals, topics, and / or other suitable signals. In a specific example, the aggregation key can be <example.com / flowers, Canada, smartphone>. The aggregated profile of this key includes data related to a subset of users who accessed example.com / flowers from a smartphone in Canada.
[0057] System 120 can select an aggregation key from a list of aggregation key candidates. The list of aggregation key candidates can be composed of various entities such as the digital component distribution system 150 and / or the digital content originator 130. The digital component distribution system 150 and / or the originator 130 can supply the system 120 with configuration data that defines the list of aggregation key candidates. In the configuration data, for each aggregation key candidate, it is also possible to define the type of data to be included in the aggregated profile of the aggregation key. For example, in the configuration data, it can be specified that the aggregated profile of the aggregation key candidate includes, for each of a plurality of user attributes, a count of the number or proportion of users whose data with that user attribute is aggregated. The aggregated profile can include a combination of many data types.
[0058] When an aggregation key is selected, system 120 can identify a subset of client devices for which the accumulated user attributes are used to generate an aggregation profile for the selected aggregation key. For example, the subset of client devices may be client devices that accessed an electronic resource or digital component identified by the aggregation key. The selection of the subset of client devices can also be based on the user's permissions settings. As described above, for each client device, the user can provide controls (such as user interface elements with which the user can interact) and can select whether, when, and how such a system, program, or function can collect user information and how such information will be used.
[0059] In some embodiments, before and / or during generating an aggregation profile using accumulated user attribute data from a subset of client devices, system 120 can apply privacy protection techniques to the accumulated user attribute data. These techniques include, for example, removing any user identifiers from the data, applying k-anonymity techniques, and / or applying differential privacy techniques to the aggregated data to anonymize each user's data.
[0060] System 120 generates an aggregated profile by aggregating the accumulated user attribute data obtained from a subset of the identified client devices for each selected aggregation key. As described above, the aggregated profile of an aggregation key can include various types of aggregated user data regarding the users whose data is aggregated for the aggregation key. For example, the aggregated profile of an aggregation key can include a count of the number of users or a percentage of users in a subset of client devices having a particular attribute. In a specific example, the aggregated profile <example.com / flowers,Canada,smartphone> of an aggregation key can specify the percentage of female users, the percentage of users interested in the topic of gardening, and / or the percentage of users who speak English in a subset of the identified client devices.
[0061] In some embodiments, the aggregated profile of an aggregation key may include metrics calculated by System 120. For example, the aggregated profile can include a reach metric that characterizes the total number of unique users within a set of users who accessed a particular electronic resource, or the total number of unique users to whom a particular digital component was supplied. In another example, the aggregated profile can include a frequency metric that represents the number of times the same user was supplied with a particular digital component. In another example, the aggregated profile can include an attribution metric that quantifies the number of digital component impressions that led to a particular action (e.g., conversion), such as user interaction, user sign-up, purchase, etc., with the supplied digital component for a subset of client devices to which the particular digital component was supplied.
[0062] In 224a, the system 120 sends an aggregated user attribute report to the digital component delivery system 150. The system 120 can further send at least a portion of the aggregated user attribute report to the originator 130 or the website 140 (224b). For example, the system 120 can send an aggregated profile generated for a particular resource locator (such as a URL) to the corresponding website 140 or the originator 130 of the resource.
[0063] In 254, the digital component delivery system 150 can use the aggregated data profiles in the report to adjust the delivery parameters for delivering digital components.
[0064] In an exemplary example, for an aggregation key that specifies a particular resource locator, such as example.com / flowers, the aggregated profile can include the percentage of users in a particular group of interest, for example, a group whose interest topic is "gardening". The delivery system 150 can determine whether the percentage of users exceeds a predefined value, and if the percentage exceeds the predefined value, the delivery system 150 can add the relevant group of interest to the list of a particular digital component or a group of related digital components to be eligible for presentation.
[0065] In some other examples, the delivery system 150 can adjust the delivery parameters based on the metrics included in the report aggregation profile. In an exemplary example, if the aggregated data profile includes reach metrics for a particular digital component in a particular geographical region, the delivery system 150 can determine whether the reach metric exceeds a predefined threshold, and if the reach metric exceeds the predefined threshold, the delivery system 150 can decide to remove the particular geographical region from the list of geographical regions for the particular digital component or related digital components to be supplied. In another exemplary example, if the reach metric for a particular digital component exceeds a particular threshold and / or if the frequency metric for a particular digital component exceeds a particular threshold for users in a particular group of interest, the delivery system 150 can decide to add the group of interest related to the list of groups for the particular digital component or related digital components to be eligible for presentation. In another exemplary example, if the reach metric for a particular digital component exceeds a particular threshold and / or if the frequency metric for a particular digital component exceeds a particular threshold, the delivery system 150 can decide to increase or decrease the selection parameters and / or budget for delivering the particular digital component or related digital components.
[0066] At 256, the digital component delivery system 150 delivers digital components to the client device 110 based on delivery parameters. In particular, the delivery system 150 can select the digital components to be delivered to the client device 110 in response to receiving a digital component request from the client device according to the delivery parameters adjusted at 254. The system 150 can then supply the selected digital components to the client device 110 according to the updated delivery parameters. Then, at 216, the client device 110 can present the supplied digital components, for example, by an application of the client device 110.
[0067] FIG. 3 is a flow diagram of an exemplary process 300 for delivering digital components for display on a client device. The operations of process 300 may be performed by a system of one or more computers located at one or more locations, such as a server such as digital component delivery system 150, and / or the secure aggregation reporting system 120 described with reference to FIG. 1, appropriately programmed according to this specification, can execute process 300. The operations of process 300 can also be implemented as instructions stored on one or more computer-readable media, which may or may not be transitory, and execution of the instructions by one or more data processing devices can cause the one or more data processing devices to perform the operations of process 300. For convenience, and without loss of generality, process 300 will be described as being performed by a data processing device, such as a computer system.
[0068] At 310, the data processing device receives, for each of a plurality of client devices, a digital component request from an application running on the user's client device. The digital component request may include context data related to an environment in which one or more digital components are to be displayed on the client device. For example, the environment may include electronic resources and context data. The context data may include a resource locator (e.g., a URL) of an electronic resource on which one or more digital components are to be displayed on the client device, and / or a topic of the content of the electronic resource.
[0069] At 320, the data processing device identifies the user attributes of the user for each client device based on the digital component request.
[0070] In some embodiments, the user attributes are identified using a prediction model based on the context data of the digital component request. For example, the prediction model can be configured to predict the attributes of users who access an electronic resource or the topic of the content of the electronic resource.
[0071] In some embodiments, the user subscribes to an electronic resource using a user identifier, and the user attributes are identified using a user profile associated with the user identifier.
[0072] At 330, the data processing device transmits a digital component response to the application of each client device. The digital component response includes (i) one or more digital components and (ii) attribute data specifying the user attributes of the user. In response to receiving the attribute data, each client device is configured to update the stored user attribute data stored in the shared storage of the client device based on the user attributes of the attribute data.
[0073] In some embodiments, when user attributes are identified using a prediction model based on context data, the application can determine whether the stored user attribute data stored in the shared storage of the client device includes a keyed entry for the user attribute. If the stored user attribute data does not include a keyed entry, the application can generate a new keyed entry in the stored user attribute data and assign an entry value to the new keyed entry based on the user attributes identified using the prediction model. If the stored user attribute data includes a keyed entry, the application can update the current entry value of the keyed entry in the stored user attribute data based on the user attributes identified using the prediction model. For example, to update the current entry value of the keyed entry, the application can increment or decrement the current entry value of the keyed entry.
[0074] In some embodiments, when user attributes are identified using a user profile associated with a user identifier, the application can determine whether the stored user attribute data stored in the shared storage of the client device includes a keyed entry for the user attribute. If the aggregated user attribute data does not include a keyed entry, the application can generate a new keyed entry in the stored user attribute data and assign an entry value to the new keyed entry based on the user attributes identified using the user profile. If the stored user attribute data includes a keyed entry, the application can update (e.g., replace) the entry value of the keyed entry in the stored user attribute data based on the user attributes identified using the user profile. In one example, the user interface of the electronic resource can include script code for the application to update the stored user attribute data based on the user attributes in response to receiving the user attributes.
[0075] At 340, the data processing device obtains user attribute data accumulated from the shared storage of each client device.
[0076] At 350, the data processing device uses the obtained accumulated user attribute data to generate an aggregated user attribute report for a set of aggregation keys. In particular, the data processing device generates an aggregated data profile by aggregating the user attribute data accumulated from a subset of client devices that accessed the electronic resource or digital component identified by the aggregation key for each aggregation key.
[0077] In some embodiments, the aggregated profile of the aggregation keys includes one or more metrics of the electronic resource or digital component identified by the aggregation key. For example, the metrics can include reach metrics that measure the number of unique users within a subset of client devices that accessed the electronic resource or digital component identified by the aggregation key.
[0078] In some embodiments, before and / or during generating the aggregated profile using the user attribute data accumulated from a subset of client devices, the data processing device can apply privacy protection techniques to the accumulated user attribute data for data security and privacy. These techniques include, for example, removing any user identifiers from the data, applying k-anonymity techniques, and / or applying differential privacy techniques to the aggregated data to anonymize each user's data. For example, to apply a differential privacy process, the data processing device can add random noise to each user attribute data of the subset of client devices before aggregation.
[0079] In some embodiments, to improve data security and data privacy, an aggregated user attribute report can be generated by a secure aggregation system. The secure aggregation report system can be a computing system separate from the digital component delivery system or a computing system that is part of the digital component delivery system. When the secure aggregation report system is a computing system separate from the digital component delivery system, the digital component delivery system can send an aggregation request to the secure aggregation report system. The aggregation request includes a set of accumulated user attribute data received from each client device and an aggregation key. The accumulated user attribute data received from the client device can be encrypted at the client device using the encryption key of the secure aggregation system. When the secure aggregation report system generates an aggregated user attribute report, the digital component delivery system can receive the aggregated data profile from the secure aggregation system.
[0080] In 360, the data processing device adjusts one or more delivery parameters for delivering a digital component to a client device in response to a digital component request based on an estimated metric. For example, the data processing device can adjust keywords that need to match, a list of geographical locations eligible to receive the digital component, a list of user groups eligible to receive the digital component, parameters characterizing resources eligible to present the digital component, and / or other appropriate delivery parameters based on the estimated metric.
[0081] In 370, the data processing device delivers the digital component to the client device based on the delivery parameters.
[0082] FIG. 4 is a block diagram of an exemplary computer system 400 that can be used to execute the operations described above. System 400 includes a processor 410, a memory 420, a storage device 430, and input / output devices 440. Each component 410, 420, 430, and 440 can be interconnected using, for example, a system bus 450. The processor 410 can process instructions for execution within the system 400. In some embodiments, the processor 410 is a single-threaded processor. In another embodiment, the processor 410 is a multi-threaded processor. The processor 410 can process instructions stored in the memory 420 or the storage device 430.
[0083] The memory 420 stores information within the system 400. In one embodiment, the memory 420 is a computer-readable medium. In some embodiments, the memory 420 is a volatile memory unit. In another embodiment, the memory 420 is a non-volatile memory unit.
[0084] The storage device 430 can provide large-capacity storage for the system 400. In some embodiments, the storage device 430 is a computer-readable medium. In various different embodiments, the storage device 430 can include, for example, a hard disk device, an optical disk device, a storage device shared on a network by a plurality of computing devices (e.g., a cloud storage device), or some other large-capacity storage device.
[0085] The input / output device 440 provides input / output operations for the system 400. In some embodiments, the input / output device 440 may include one or more of a network interface device, such as an Ethernet card, a serial communication device, such as an RS-232 port, and / or a wireless interface device, such as an 802.11 card. In another embodiment, the input / output device may include a driver device configured to receive input data and transmit output data to an external device 460, such as a keyboard, a printer, a display device, etc. However, other embodiments, such as mobile computing devices, mobile communication devices, set-top box television client devices, etc., may also be used.
[0086] Although an exemplary processing system has been described with reference to FIG. 4, embodiments of the subject matter and the functional operations described herein may be implemented in other types of digital electronic circuits, or in computer software, firmware, or hardware, including the structures disclosed herein and their structural equivalents, or combinations of one or more of them.
[0087] Embodiments of the subject matter and the operations described in this specification can be implemented in digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or combinations of one or more of them. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., as one or more modules of computer program instructions, encoded on a computer storage medium (or media) for execution by, or to control the operation of, a data processing apparatus. Alternatively, or in addition, the program instructions can be encoded in an artificially generated propagated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal, that is generated to encode information to be sent to an appropriate receiver apparatus for execution by a data processing apparatus. A computer storage medium can be, or can include, a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination of one or more of them. Further, a computer storage medium is not a propagated signal, but a computer storage medium can be the source or destination of computer program instructions encoded in an artificially generated propagated signal. A computer storage medium can also be, or can include, one or more separate physical components or media (such as multiple CDs, disks, or other storage devices).
[0088] The operations described in this specification can be implemented as operations performed by a data processing apparatus on data stored on one or more computer-readable storage devices or received from other sources.
[0089] The term "data processing apparatus" includes, by way of example, any kind of apparatus, device, and machine for processing data, including programmable processors, computers, systems on a chip, or multiple ones thereof or combinations thereof. The apparatus can include special-purpose logic circuits, such as FPGAs (field-programmable gate arrays) or ASICs (application-specific integrated circuits). The apparatus can also include, in addition to the hardware, code for creating an execution environment for the computer program, such as processor firmware, protocol stacks, database management systems, operating systems, cross-platform runtime environments, virtual machines, or code constituting one or more combinations thereof. The apparatus and the execution environment can implement various different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.
[0090] A computer program (also known as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and it can be deployed in any form, including as a stand-alone program or in the form of a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may or may not correspond to a file in a file system. The program can be stored in a part of a file that holds other programs or data (e.g., one or more scripts stored in a document of a markup language), in a single file dedicated to the program of interest, or in multiple related files (e.g., files that store one or more modules, subprograms, or portions of code). A computer program can be deployed to be executed on one computer or on multiple computers located in one place or distributed across multiple places and interconnected by a communication network.
[0091] The processes and logic flows described herein can be executed by one or more programmable processors executing one or more computer programs to perform actions by operating on input data to generate output. The processes and logic flows can also be executed by special-purpose logic circuits, such as FPGAs (field programmable gate arrays) or ASICs (application specific integrated circuits), and the apparatus can also be implemented as those special-purpose logic circuits.
[0092] Processors suitable for the execution of a computer program include, for example, both general-purpose microprocessors and special-purpose microprocessors. Generally, a processor receives instructions and data from a read-only memory, a random access memory, or both. Essential elements of a computer are a processor that executes actions according to instructions and one or more memory devices for storing instructions and data. Generally, a computer also includes or is coupled to operate for receiving data from, transferring data to, or both, one or more mass storage devices such as magnetic disks, magneto-optical disks, or optical disks for storing data. However, a computer does not require such devices. Further, a computer can also be incorporated into other devices such as mobile phones, personal digital assistants (PDAs), mobile audio or video players, game consoles, global positioning system (GPS) receivers, or portable storage devices (such as universal serial bus (USB) flash drives). Storage devices suitable for storing computer program instructions and data include, by way of example, semiconductor memory devices such as EPROM, EEPROM, and flash memory devices, magnetic disks such as internal hard disks and removable disks, magneto-optical disks, and all forms of non-volatile memories, media, and memory devices including CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, dedicated logic circuitry.
[0093] To interact with a user, embodiments of the subject matter described herein can be implemented on a computer having a display device for displaying information to the user, such as a CRT (cathode ray tube) or LCD (liquid crystal display) monitor, and a keyboard and a pointing device, such as a mouse or trackball, by which the user can input to the computer. Other types of devices can also be used to provide interaction with the user. For example, the feedback provided to the user can be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback, and the input from the user can be acoustic, speech language, or tactile input. Further, the computer can interact with the user by sending and receiving documents to and from the devices used by the user, such as by sending a web page to a web browser on the user's client device in response to a request received from a web browser.
[0094] Embodiments of the subject matter described in this specification can be implemented in a computing system that includes a back-end component, such as a data server, or a middleware component, such as an application server, or a front-end component, such as a graphical user interface or a web browser by which a user can interact with an embodiment of the subject matter described in this specification, or any combination of one or more such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication, such as by a communication network. Examples of communication networks include local area networks ("LANs"), and wide area networks ("WANs"), Internet networks (such as the Internet), and peer-to-peer networks (such as ad hoc peer-to-peer networks).
[0095] A computing system can include a client and a server. The client and the server are generally far apart from each other and typically interact through a communication network. The relationship between the client and the server is created by computer programs operating on respective computers and by the client and the server having a relationship with each other. In some embodiments, the server transmits data (e.g., an HTML page) to the client device (for the purpose of, e.g., displaying the data to a user interacting with the client device and receiving user input from the user). Data generated at the client device (e.g., as a result of user interaction) can be received at the server from the client device.
[0096] Although this specification contains many details of specific embodiments, these should not be construed as limiting the scope of any invention or of what is patentable, but rather as descriptions of features specific to particular embodiments of a particular invention. The specific features described in the context of individual embodiments herein can also be implemented in combination within a single embodiment. Conversely, the various features of the invention described in the context of a single embodiment can also be provided separately or in any suitable sub-combination in a plurality of embodiments. Furthermore, where features are described above as functioning in a particular combination and are initially claimed as such, one or more features from the claimed combination may in some cases be excised from the combination, and the claimed combination may be directed to a sub-combination or variation of a sub-combination.
[0097] Similarly, although operations are shown in the drawings in a particular order, this should not be understood as requiring that the operations be performed in that particular order or in a sequential order shown, or that all of the operations shown be performed, to obtain a desirable result. In certain circumstances, multitasking and parallel processing may be advantageous. Further, the separation of the various system components in the above embodiments should not be understood as requiring such separation in all embodiments, and the described program components and systems can generally be integrated into a single software product or packaged into multiple software products.
[0098] Thus, particular embodiments of the invention have been described. Other embodiments are within the scope of the following claims. In some cases, different orders of performing the actions recited in the claims may still result in desirable outcomes. Further, the processes shown in the accompanying figures do not necessarily require being in the particular or sequential order shown to obtain a desirable result. In certain embodiments, multitasking and parallel processing may be advantageous.
Claims
1. A computer-implemented method comprising: for each of a plurality of client devices, receiving, from an application executing on the user's client device, a digital component request; identifying one or more user attributes of the user based on the digital component request; and sending to the application a digital component response comprising (i) one or more digital components and (ii) attribute data including the one or more user attributes of the user, wherein the application is configured to update accumulated user attribute data stored in the shared storage of the client device based on the one or more user attributes in response to receiving the attribute data; obtaining, from the shared storage of each of the plurality of client devices, the accumulated user attribute data stored in the shared storage of each client device; generating, using the obtained accumulated user attribute data, an aggregated user attribute report for one or more aggregation keys, the generating including obtaining, for each of the one or more aggregation keys, an aggregated data profile generated by aggregating the accumulated user attribute data from a subset of the plurality of client devices that accessed an electronic resource or digital component identified by the aggregation key; adjusting, based on the aggregated data profile, one or more delivery parameters for delivering a digital component to a client device in response to a digital component request; and delivering the digital component to the client device based on the delivery parameters. A method as described above.
2. The generating of the aggregated user attribute report comprises: sending to a secure aggregation system an aggregation request comprising the accumulated user attribute data obtained from each of the plurality of client devices and the one or more aggregation keys; and receiving from the secure aggregation system the aggregated data profile generated in response to the aggregation request. The method of claim 1, including the above steps.
3. The method according to claim 2, wherein the accumulated user attribute data received from each client device is encrypted by the client device using an encryption key of the secure aggregation system.
4. The method according to any one of claims 1 to 3, wherein the digital component request includes context data related to an environment in which the one or more digital components are to be displayed on the client device.
5. The environment includes electronic resources, The method according to claim 4, wherein the context data includes one or more of a resource locator of the electronic resource on which the one or more digital components are to be displayed on the client device, or a topic of the content of the electronic resource.
6. The method according to any one of claims 1 to 5, wherein the one or more user attributes are identified using a prediction model configured to predict attributes of a user who has accessed the electronic resource or the topic of the content of the electronic resource.
7. In response to the application receiving the user attributes identified using the prediction model, determining whether the accumulated user attribute data stored in the shared storage of the client device includes keyed entries for the one or more user attributes, in response to the accumulated user attribute data not including the keyed entries, generating new keyed entries in the accumulated user attribute data and assigning entry values to the new keyed entries based on the one or more user attributes identified using the prediction model, and in response to the accumulated user attribute data including the keyed entries, updating current entry values of the keyed entries in the accumulated user attribute data based on the one or more user attributes identified using the prediction model, The method according to claim 6, wherein the method is configured to perform the above steps.
8. Updating the current entry value of the keyed entry includes in response to the accumulated user attribute data including the keyed entry, incrementing or decrementing the current entry value of the keyed entry. The method according to claim 7.
9. The user subscribes to the electronic resource using a user identifier, and the one or more user attributes are identified using a user profile associated with the user identifier. The method according to any one of claims 1 to 5.
10. In response to the application receiving the user attributes identified using the user profile, determining whether the stored user attribute data stored in the shared storage of the client device includes keyed entries for the one or more user attributes, in response to the aggregated user attribute data not including the keyed entry, generating a new keyed entry in the stored user attribute data and assigning an entry value to the new keyed entry based on the one or more user attributes identified using the user profile, and in response to the stored user attribute data including the keyed entry, updating the entry value of the keyed entry in the stored user attribute data based on the one or more user attributes identified using the user profile, The method according to claim 9, configured to perform.
11. The user interface of the electronic resource includes code for causing the application to update the stored user attribute data based on the one or more user attributes in response to receiving the user attributes. The method according to claim 10.
12. The aggregation profile for the aggregation key includes one or more metrics of the electronic resource or the digital component identified by the aggregation key. The method according to any one of claims 1 to 11.
13. The one or more metrics include a reach metric that measures the number of unique users in a subset of client devices that have accessed the electronic resource or the digital component identified by the aggregation key. The method according to claim 12.
14. Aggregating the user attribute data from a subset of the client devices includes adding random noise to the user attribute data of each of the subset of the client devices before aggregating, the method according to any one of claims 1 to 13.
15. A system comprising one or more computers, and one or more storage devices storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the operations of each of the methods according to any one of claims 1 to 14. A system comprising.
16. One or more computer-readable storage media storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the operations of each of the methods according to any one of claims 1 to 14.
Citation Information
Patent Citations
Communication distribution of service contents by multiple operators
JP2008535079A
System and Method for Creating Anonymous User Profiles from a Mobile Data Network
US20090247193A1