Privacy-preserving data processing for content distribution
By aggregating privacy-preserving user attribute data from client devices, the system addresses the challenge of third-party cookie elimination, enabling effective and secure content delivery based on user interests without compromising privacy.
Patent Information
- Application Number
- JP2024535285
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-04-24
- Publication Date
- 2025-11-19
- Estimated Expiration
- 2043-04-24
AI Technical Summary
The elimination of third-party cookies poses challenges for content delivery systems in predicting user interests and delivering relevant content, as they can no longer collect and utilize data for enhancing online experiences, leading to a loss of data availability for guiding content selection.
A system that retrieves and aggregates privacy-preserving user attribute data from shared storage on client devices, generating aggregated user attribute reports to guide content delivery without relying on third-party cookies, ensuring user privacy and security through secure data handling and anonymization techniques.
Enables effective content delivery systems to leverage user attribute data across multiple sessions and devices, providing personalized content recommendations while protecting user privacy and maintaining data security.
Smart Images

Figure 0007773649000001 
Figure 0007773649000002 
Figure 0007773649000003
Abstract
Description
[Technical Field]
[0001] This specification relates generally to data processing, data privacy, and data security. [Background technology]
[0002] Data security and user privacy are of paramount importance for systems and devices connected to public networks such as the Internet. Increased user privacy has led many developers to change how they handle user data. For example, some browsers plan to deprecate the use of third-party cookies. Summary of the Invention
[0003] This specification describes methods, computer systems, and apparatus for generating and processing de-identified user data to select and provide digital content to client devices in a privacy-preserving manner, including computer programs encoded in computer storage media.
[0004] In one innovative aspect, this specification describes a method for delivering a digital component to a client device, the method being implementable by a system including one or more computers.
[0005] The system receives, for each of a plurality of client devices, a digital component request from an application running on the user's client device. The system identifies one or more user attributes of the user based on the digital component request. The system sends a digital component response to the application, including (i) one or more digital components and (ii) attribute data including one or more user attributes of the user. In response to receiving the attribute data, the application is configured to update accumulated user attribute data stored in the shared storage of the client device based on the one or more user attributes. The system retrieves the accumulated user attribute data from the shared storage of each of the plurality of client devices. The system uses the retrieved accumulated user attribute data to generate an aggregated user attribute report for one or more aggregation keys, including, for each of the one or more aggregation keys, obtaining an aggregated data profile generated by aggregating accumulated user attribute data from a subset of the plurality of client devices that accessed the electronic resource or digital component identified by the aggregation key. The system adjusts one or more delivery parameters for delivering the digital component to the client device in response to the digital component request based on the aggregated data profile. The system delivers the digital component to the client device based on the delivery parameters. Other implementations of this aspect include corresponding apparatus, systems, and computer programs encoded on computer storage devices and configured to perform aspects of the methods.
[0006] Each of these and other embodiments may optionally include one or more of the following features: In some embodiments, to generate an aggregated user attribute report, the system sends an aggregation request to a secure aggregation system that includes accumulated user attribute data obtained from each of the client devices and one or more aggregation keys, and receives from the secure aggregation system an aggregate data profile generated in response to the aggregation request. The accumulated user attribute data received from each client device may be encrypted by the client device using an encryption key of the secure aggregation system.
[0007] In some embodiments, the digital component request includes contextual data related to an environment in which the one or more digital components are displayed on the client device. The environment can include electronic resources, and the contextual data can include one or more of resource locators of the electronic resources in which the one or more digital components are displayed on the client device and / or topics of content of the electronic resources.
[0008] In some embodiments, one or more user attributes are identified using a predictive model configured to predict attributes of users who access the electronic resource or a topic of content of the electronic resource. In response to receiving the user attributes identified using the predictive model, the application may be configured to: determine whether accumulated user attribute data stored on the client device's shared storage includes a keyed entry for the one or more user attributes; generate a new keyed entry in the accumulated user attribute data and assign an entry value to the new keyed entry based on the one or more user attributes identified using the predictive model in response to the accumulated user attribute data not including the keyed entry; and update a current entry value of the keyed entry in the accumulated user attribute data based on the one or more user attributes identified using the predictive model in response to the accumulated user attribute data including the keyed entry. To update the current entry value of the keyed entry, the application may be configured to increment or decrement the current entry value of the keyed entry in response to the accumulated user attribute data including the keyed entry.
[0009] In some embodiments, a user is subscribed to an electronic resource using a user identifier, and one or more user attributes are identified using a user profile associated with the user identifier. In response to receiving the user attributes identified using the predictive profile, the application may be configured to: determine whether accumulated user attribute data stored in the shared storage of the client device includes a keyed entry for the one or more user attributes; in response to the aggregated user attribute data not including the keyed entry, generate a new keyed entry in the accumulated user attribute data and assign an entry value to the new keyed entry based on the one or more user attributes identified using the user profile; and in response to the accumulated user attribute data including the keyed entry, update the entry value of the keyed entry in the accumulated user attribute data based on the one or more user attributes identified using the user profile. The user interface of the electronic resource may include code for causing the application to update the accumulated user attribute data based on the one or more user attributes in response to receiving the user attributes.
[0010] In some embodiments, the aggregate profile for an aggregation key includes one or more metrics for the electronic resource or digital component identified by the aggregation key. The one or more metrics may include a reach metric that measures the number of unique users in a subset of client devices that accessed the electronic resource or digital component identified by the aggregation key.
[0011] In some implementations, to aggregate user attribute data from a subset of client devices, the system adds random noise to the user attribute data of each of the subset of client devices before aggregating.
[0012] Particular embodiments of the subject matter described herein can be implemented to achieve one or more of the following advantages: A content delivery system can leverage user attribute data of one set of users, such as users who have accessed a particular electronic resource (e.g., a website) or digital component (e.g., video / audio clips, images, text, etc.), to guide the selection and delivery of content to other users, e.g., to deliver content that best suits the user's interests and needs.
[0013] Historically, third-party cookies (e.g., cookies from a domain different from the resource rendered by the client device) have been used to collect data from client devices on the Internet. For example, a third-party cookie can be a script file from a website other than the one currently accessed by the client device, typically used to track user behavior and / or provide digital content to the user. Due to growing concerns about user privacy and data protection, some browsers and device platforms block the use of third-party cookies, and third-party cookies are becoming less popular, thereby preventing data collection using third-party cookies. This creates challenges when attempting to utilize collected data to enhance online browsing experiences, such as selecting relevant content for users based on data collected using third-party cookies. In other words, without the use of third-party cookies, much of the data previously collected is no longer available, preventing computing systems from using such data to predict user interests or attributes, improve a user's online experience, and / or present relevant content to users based on the user's activities on particular web pages or other resources.
[0014] The techniques described herein can overcome obstacles that may arise from the elimination of third-party cookies. In particular, this specification describes techniques for retrieving privacy-preserving user attribute data from shared storage on client devices. The shared storage on the client devices maintains accumulated user attribute data characterizing the attributes and / or interests of users of the client devices and updates the accumulated user attribute data based on user attribute signals received from a content distribution or content serving system. A computer system, such as a secure server, can collect the cumulative user attribute data from client devices without the use of third-party cookies. The computer system can generate aggregated user attribute reports from the user attribute data, and the content distribution system can use the aggregated user attribute reports to guide the delivery of digital components.
[0015] Using these technologies, content delivery systems can effectively leverage user attribute data for user groups to guide content selection and delivery to specific users without using third-party cookies. Instead of using third-party cookies, we describe techniques for maintaining and using privacy-preserving user attribute data using shared storage on client devices. Shared storage provides a framework that allows data to be shared across multiple sessions and / or multiple instances of accessing an electronic resource, such as a website, and / or across different electronic resources. Shared storage can also be implemented with measures to protect the security and privacy of the stored data. These technologies also provide user privacy protection during the user attribute data collection process by preventing the collection and use of sensitive user information (such as personally identifiable information) without the user's consent.
[0016] The details of one or more embodiments of the subject matter described herein are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages of the subject matter will become apparent from the description, drawings, and claims. [Brief explanation of the drawings]
[0017] [Figure 1] 1 is a block diagram of an example environment in which a digital component delivery system delivers digital components to client devices. [Figure 2] FIG. 1 is a swim lane diagram of an example process for delivering a digital component for display on a client device. [Figure 3] FIG. 1 is a flow diagram of an exemplary process for delivering a digital component for viewing on a client device. [Figure 4] FIG. 1 is a block diagram of an exemplary computer system. DETAILED DESCRIPTION OF THE INVENTION
[0018] Like reference symbols and designations in the various drawings indicate like elements.
[0019] Generally, this specification describes systems and techniques for providing digital content, e.g., digital components, to client devices in a manner that preserves user privacy. A server can be configured to retrieve accumulated user attribute data from the client devices and generate aggregated user attribute reports using the retrieved user attribute data. A digital component delivery system can use the aggregated user attribute reports to adjust delivery parameters for delivering the digital components to the client devices in response to digital component requests.
[0020] In addition to the descriptions throughout this literature, users may be provided with controls (e.g., user interface elements with which the user can interact) that allow them to exercise choice regarding both whether and when the systems, programs, or functionality described herein may enable the collection of user information (e.g., information regarding the user's social network, social actions or activities, occupation, user preferences, or the user's current location), as well as whether content or communications are sent from the server to the user. Furthermore, certain data may be processed in one or more ways such that personally identifiable information is removed before it is stored or used. For example, the user's identity may be processed such that personally identifiable information about the user cannot be determined, or if location information is obtained (e.g., to the city, zip code, or state level), the user's geographic location may be generalized such that the user's specific location cannot be determined. Thus, users may control what information is collected about them, how that information is used, and what information is provided to them.
[0021] 1 is a block diagram of an exemplary environment 100 in which a digital component distribution system 150 distributes digital components to client devices 110. The environment 100 includes a data communications network 105, such as a local area network (LAN), a wide area network (WAN), the Internet, a mobile network, or a combination thereof. The data communications network 105 connects the client devices 110 to the digital component distribution system 150. The network 105 may also connect the digital component distribution system 150 to digital component providers (e.g., 160-1, 160-2, and 160-3).
[0022] A website 140 is one or more electronic resources associated with a domain name and hosted by one or more servers. An exemplary website is a collection of HTML-formatted web pages that can include text, images, multimedia content, and programming elements such as scripts. Each website 140 is maintained by a publisher 130, which is an entity that controls, manages, and / or owns the website 140.
[0023] Electronic resources are also referred to herein as resources for brevity. As used herein, resources may include HTML pages, word processing documents, and portable document format (PDF) documents, images, videos, feed sources, and the like. Resources may include content such as words, phrases, images, and audio, which may include embedded information (e.g., meta-information in hyperlinks) and / or embedded instructions (e.g., scripts). Resources may be identified by a resource address, such as a universal resource locator (URL), associated with the resource.
[0024] Client devices 110 are electronic devices capable of communicating over network 105. Exemplary client devices 110 include personal computers, server computers, mobile communication devices such as smartphones and / or tablet computers, and other devices capable of sending and receiving data over network 105. Client devices may also include digital assistant devices that accept audio input through a microphone and output audio output through a speaker. When the digital assistant detects a "hot word" or "hot phrase" that activates the microphone and accepts voice input, the digital assistant can be placed in listening mode (e.g., ready to accept voice input). Digital assistant devices may also include a camera and / or display for capturing images and visually displaying information. Digital assistants can be implemented in various forms of hardware devices, such as wearable devices (e.g., watches or glasses), smartphones, speaker devices, tablet devices, or other hardware devices. Client devices may also include digital media devices, such as streaming devices that connect to a television or other display and stream video to the television, gaming devices, or virtual reality systems.
[0025] A gaming device is a device that allows a user to participate in a gaming application. For example, a user can control one or more characters, avatars, or other rendered content displayed in the gaming application. A gaming device typically includes a computer processor, a memory device, and a controller interface (physical or visually rendered) that allows user control over content rendered by the gaming application. A gaming device can store and execute gaming applications locally, or execute gaming applications that are at least partially stored and / or provided by a cloud server (e.g., online gaming applications). Similarly, a gaming device can execute gaming applications and interface with a gaming server that "streams" the gaming application to the gaming device. A gaming device may be a tablet device, a mobile communication device, a computer, or other device that performs functions other than running gaming applications.
[0026] Client device 110 may include applications 112, such as a web browser and / or native applications, to facilitate sending and receiving data over network 105. Native applications are applications developed for a particular platform or device (e.g., a mobile device with a particular operating system). Although operations may be described as being performed by client device 110, such operations may be performed by applications 112 running on client device 110.
[0027] An application 112 can present electronic resources, such as web pages, application pages, or other application content, to a user of the client device 110. An electronic resource can include a digital component slot for displaying a digital component that includes the content of the electronic resource. A digital component slot is an area of an electronic resource (such as a web page or application page) for displaying a digital component. A digital component slot can also refer to a portion of an audio and / or video stream (another example of an electronic resource) for playing the digital component.
[0028] As used throughout this specification, a "digital component" refers to a discrete unit of digital content or information (e.g., a video clip, an audio clip, a multimedia clip, an image, text, or other content unit). A digital component can be stored electronically on a physical memory device as a single file or as a collection of files, and a digital component can take the form of a video file, an audio file, a multimedia file, an image file, or a text file and include advertising information; thus, an advertisement is a type of digital component. For example, a digital component may be content intended to supplement the content of a web page or other resource presented by application 112. More specifically, a digital component may include digital content related to the resource content (e.g., the digital component may be related to the same topic as the web page content or to a related topic). Thus, providing a digital component can supplement and overall improve the content of a web page or application.
[0029] When an application 112 loads a resource that includes a digital component slot, the application 112 can generate a digital component request to request the digital component for display in the digital component slot. In some embodiments, the digital component slot and / or resource can include code (e.g., a script) that causes the application 112 to request the digital component from the digital component distribution system 150.
[0030] The digital component request may include contextual data, which is not typically considered sensitive. The contextual data may describe the environment in which the selected digital component will be presented. The contextual data may include, for example, coarse location information indicating the general location of the client device 110 that sent the digital component request, the resource (e.g., a website or native application) in which the selected digital component will be presented (e.g., by including a resource locator such as a URI or URL of the resource), the audio language setting of the application 112 or client device 110, the number of digital component slots in which the digital component will be presented with the resource, the type of digital component slot, and / or other suitable contextual information.
[0031] As described in more detail below, the digital component delivery system 150 can identify, e.g., predict, user attributes of a user of the client device 110 that received the digital component request based on data (e.g., contextual data) included in the digital component request. In response to the digital component response, the digital component delivery system 150 can send attribute data to the client device 110 that identifies the user attributes identified from the digital component request.
[0032] The application 112 maintains shared storage 114, which stores a set of data that the application 112 can access and update. The data stored in shared storage 114 can have any suitable data format, depending on the particular application, preferences, and / or protocols. The data stored in shared storage 114 can be shared across multiple sessions and / or multiple instances of the application 112. For example, the stored data can be shared by all instances of an electronic resource (e.g., a website) running in different tabs or windows of the application 112. In some embodiments, the data stored in shared storage 114 can be shared across multiple electronic resources, e.g., multiple websites accessed by the application.
[0033] Several measures can be taken to protect the security and privacy of data stored on shared storage 114. For example, in some embodiments, shared storage 114 may reside in a separate portion of the storage space of application 112. In some embodiments, a separate thread of application 112 manages and provides access to shared storage 114. The separate thread can isolate shared storage 114 from being accessed by other components of application 112 and / or from being accessed by unauthorized websites, such as websites with which the user has not interacted. In some embodiments, the application can encrypt data stored on shared storage 114 before transmitting the data over network 105 to another system.
[0034] To provide information in guiding content selection and delivery to users, the data stored on shared storage 114 may include accumulated user attribute data characterizing users of client devices 110. The accumulated user attribute data may include data characterizing the user's interests (such as topics of interest or hobbies) and / or data characterizing the user's non-identifying demographic attributes. As described in more detail below, application 112, e.g., a separate thread of application 112, is configured to update the accumulated user attribute data based on attribute data received from digital component delivery system 150.
[0035] Secure aggregate reporting system 120 is configured to receive accumulated user attribute data from shared storage 114 of multiple client devices 110 and use the accumulated user attribute data to generate aggregated user attribute reports for a set of aggregation keys. System 120 may be a secure server implemented using one or more computers (or other suitable computing devices), which may be distributed across multiple locations. Secure system 120 may be operated and maintained by digital component distribution system 150 or an independent trusted party, such as a party different from users of client devices, the party operating digital component distribution system 150, and digital component providers 160. For example, secure system 120 may be operated by an industry association or a governmental entity.
[0036] In some embodiments, secure system 120 implements a shared storage worklet 122 configured to access the shared storage 114 of the secure environment, i.e., client device 110, to receive accumulated user attribute data, and to process the accumulated user attribute data to generate aggregate reports. To provide further security and privacy for user data, shared storage worklet 122 can be a dedicated process or thread running in secure system 120 that is separate from other processes or threads of secure system 120.
[0037] Shared storage worklet 122 includes an aggregation key selection engine 124 and a data aggregation engine 126. Aggregation key selection engine 124 is configured to select an aggregation key from a list of aggregation keys, and data aggregation engine 126 is configured to generate an aggregate data profile by aggregating accumulated user attribute data from a subset of multiple client devices that accessed the electronic resource or digital component identified by the aggregation key.
[0038] The digital component delivery system 150 can identify a set of digital components eligible for presentation to the client device 110 from among a collection of digital components available from the content platform 150. For example, the digital component delivery system 150 can select one or more digital components from a set of digital components stored in a digital component repository and / or received from a digital component provider 160.
[0039] The digital component repository can store in a database digital components received from digital component providers and additional data (e.g., metadata) for each digital component. The metadata for a digital component can include, for example, delivery criteria that define the circumstances under which the digital component is eligible to be provided to a client device 110 in response to a digital component request received from the client device 110, and / or selection parameters that indicate the amount to be awarded to a publisher if the digital component is displayed with the publisher's resources and / or interacted with by a user when presented. The delivery criteria and selection parameters can be characterized by one or more delivery parameters.
[0040] For example, the distribution parameters for a particular digital component may include distribution keywords that must be matched, such as by terms specified in a request, for the digital component to be eligible for presentation. In another example, the distribution criteria for a digital component may include location information indicating geographic locations eligible for presentation of the digital component, user group membership data identifying user groups eligible for presentation of the digital component, resource data identifying resources eligible for presentation of the electronic resource, and / or other suitable distribution criteria. The distribution criteria may also include negative criteria, e.g., criteria indicating circumstances (such as specific resources or specific locations) for which the digital component is not eligible. The distribution parameters may also specify selection parameters and / or budgets for delivering particular third-party content.
[0041] As described in more detail below, delivery parameters for the digital components can be adjusted based on aggregated user attribute reports for the digital components. The digital component delivery system 150 can identify eligible digital components based on the delivery parameters and data included in the digital component request. The digital component delivery system 150 can then select a digital component from the eligible digital components and provide the selected digital component to the client device 110 for display to the user of the client device 110.
[0042] 2 is a swimlane flow diagram of an exemplary process 200 for delivering digital components for display on client devices. The operations of process 200 may be implemented by, for example, client device 110, secure aggregate reporting system 120, and digital component delivery system 150, one or more publishers 130, and one or more websites 140. The operations of process 200 may also be implemented as instructions stored on a computer-readable medium, which may be non-transitory, where execution of the instructions by a data processing device causes the data processing device to perform the operations of process 200.
[0043] At 212, the client device 110 sends a request for an electronic resource, such as a request for a web page, to the website 140. The request may include a URL for the electronic resource. At 232, the website 140 sends the requested electronic resource to the client device 110.
[0044] After receiving the requested electronic resource, while loading the electronic resource, the client device 110 generates a digital component request to request the digital component to be displayed in the digital component slot of the electronic resource. The digital component request includes contextual data describing the environment in which the selected digital component will be presented. For example, the contextual data may identify the electronic resource (e.g., a website) in which the selected digital component will be presented. In certain examples, the contextual data may include a URL or URI of the electronic resource. The contextual data may include, for example, coarse location information indicating the general location of the client device 110, the spoken language setting of the client device 110, the number of digital component slots in which the digital component will be presented with the resource, the type of digital component slot, and / or other suitable contextual information.
[0045] At 214, the client device 110 sends a digital component request to the digital component delivery system 150. The digital component delivery system 150 selects a digital component based on the digital component request at 251 a and identifies one or more user attributes of the user based on the digital component request at 251 b.
[0046] In some embodiments, the digital component delivery system 150 identifies user attributes using a predictive model (e.g., a trained machine learning model) based on the contextual data in the digital component request. For example, the predictive model can be configured to predict attributes of users who accessed the electronic resource or topics of the content of the electronic resource. The digital component delivery system 150 can use the predictive model to process input specifying the electronic resource and / or the topic of the content of the electronic resource and generate output including predictions of user attributes of the user, such as the user interests (e.g., topics of interest), demographic attributes of the user, and / or other characteristics of users who accessed the electronic resource or the topic of the content of the electronic resource. The user attributes and / or other characteristics predicted by the predictive model can be used to indicate attributes of the user of the client device 110. In some embodiments, the predictive model can further output a numerical value of the likelihood that the user has the predicted user attribute.
[0047] In some other implementations, when a user signs in to an electronic resource using a user identifier, the digital component delivery system 150, with the user's permission, can retrieve user attribute data associated with a user profile identified by the user identifier. For example, the user profile can specify or indicate the user's interests, demographic attributes, and / or other characteristics of the user. The digital component delivery system 150 can identify such information from the user profile.
[0048] At 252, the digital component distribution system 150 sends a response to the client device 110. The response includes the selected digital component and attribute data specifying user attributes of the user, such as user attributes identified based on the output of a predictive model and / or user attributes identified based on a user profile.
[0049] Upon receiving the attribute data, the client device 110 updates 216 the accumulated user attribute data stored in the shared storage of the client device 110 based on the user attributes specified by the attribute data.
[0050] In some implementations, when a user attribute is identified using a predictive model based on context data, the client device 110 can determine whether the accumulated user attribute data stored in the shared storage includes a keyed entry for the identified user attribute. If the accumulated user attribute data does not include the keyed entry, the client device 110 can generate a new keyed entry for the identified user attribute and assign an entry value to the new keyed entry. On the other hand, if the accumulated user attribute data includes the keyed entry, the client device 110 can update the current entry value of the keyed entry based on the user attribute identified using the predictive model. For example, when updating the current entry value of the keyed entry, the client device 110 can increment or decrement the current entry value of the keyed entry.
[0051] In an illustrative example, a first digital component request received from a client device 110 may include context data identifying a first electronic resource as "example.com / / vegetablefertilizer / ." The predictive model may output a 60% prediction that a user accessing this web page is interested in gardening. The client device 110 may generate a keyed entry "Interest in Gardening" and assign the entry a value of 0.6. A second digital component request received from a client device 110 may include context data identifying a second electronic resource as "example.com / gardendesign / ." The predictive model may output an 80% prediction that a user accessing this web page is interested in gardening. The client device 110 may update the value of the keyed entry "Interest in Gardening" by incrementing the entry's value by 0.8. The value of the keyed entry may be updated cumulatively based on predicted user attributes associated with the keyed entry.
[0052] In some other implementations, if user attributes are identified using user profile data associated with a user identifier, client device 110 may generate or update keyed entries for one or more of the identified user attributes. For example, if the user profile data specifies or indicates that the user has an interest in gardening, client device 110 may generate a keyed entry for "Interested in Gardening" and assign the entry a value of 1. If the user profile data specifies or indicates that the user has no interest in gardening, client device 110 may assign the entry for "Interested in Gardening" a value of 0.
[0053] In some embodiments, when an electronic resource is presented on a client device 110, the user interface for presenting the electronic resource includes script code that causes an application on the client device 110 to update stored user attribute data based on user attributes identified using the user profile.
[0054] At 221, secure aggregate reporting system 120 retrieves accumulated user attribute data from the shared storage of client devices 110. The above process, including 212, 232, 214, 251a, 251b, 252, and 216, can be repeated for multiple client devices 110, with secure aggregate reporting system 120 retrieving accumulated user attribute data from each of the multiple client devices 110.
[0055] At 222, the secure aggregate reporting system 120 uses the obtained accumulated user attribute data to generate an aggregated user attribute report including a respective aggregate data profile for each set of selected aggregation keys.
[0056] The system 120 can select an aggregation key based on context signals such as a particular resource locator, a particular digital component, a particular geographic region, and / or a particular type of device.<URL, Region, Device Type> In another example, the aggregation key is<Digital component identifier, Region, Device Type> Other suitable signals may also be used. The aggregation key may include a combination of context signals, topics, and / or other suitable signals. In a particular example, the aggregation key is<example.com / flowers, Canada, smartphone> The aggregated profile for this key contains data related to the subset of users who visited example.com / flowers from smartphones located in Canada.
[0057] The system 120 can select an aggregation key from a list of candidate aggregation keys. The list of candidate aggregation keys can be configured by various entities, such as the digital component distribution system 150 and / or the digital content publisher 130. The digital component distribution system 150 and / or the publisher 130 can provide configuration data to the system 120 that defines the list of candidate aggregation keys. The configuration data can also define, for each candidate aggregation key, the type of data to include in the aggregation key's aggregation profile. For example, the configuration data can specify that the candidate aggregation key's aggregation profile includes, for each of multiple user attributes, a count of the number or percentage of users whose data for the aggregation key has that user attribute. The aggregated profile can include many combinations of data types.
[0058] Once an aggregation key is selected, the system 120 can identify a subset of client devices whose accumulated user attributes are used to generate an aggregate profile for the selected aggregation key. For example, the subset of client devices can be client devices that accessed the electronic resource or digital component identified by the aggregation key. The selection of the subset of client devices can also be based on user permission settings. As mentioned above, for each client device, the user can provide controls (e.g., user interface elements with which the user can interact) to allow the user to select whether and when a system, program, or feature may enable the collection of user information and how such information is used.
[0059] In some embodiments, before and / or during generation of the aggregated profile using the accumulated user attribute data from the subset of client devices, system 120 may apply privacy preservation techniques to the accumulated user attribute data, including, for example, removing any user identifiers from the data, applying k-anonymity techniques, and / or applying differential privacy techniques to the aggregated data to anonymize each user's data.
[0060] For each selected aggregation key, the system 120 generates an aggregate profile by aggregating accumulated user attribute data obtained from the identified subset of client devices. As previously described, the aggregate profile for an aggregate key can include various types of aggregated user data about the users for whom the data for the aggregation key is aggregated. For example, the aggregate profile for an aggregate key can include a count of the number of users or a percentage of users of the subset of client devices that have a particular attribute. In a particular example, the aggregate profile for an aggregate key can include:<example.com / flowers,Canada,smartphone> can specify the percentage of female users of the identified subset of client devices, the percentage of users interested in gardening topics, and / or the percentage of English-speaking users.
[0061] In some implementations, the aggregate profile of an aggregate key may include metrics calculated by system 120. For example, the aggregated profile may include a reach metric that characterizes the total number of unique users in a user set who accessed a particular electronic resource or the total number of unique users to whom a particular digital component was provided. In another example, the aggregated profile may include a frequency metric that represents the number of times the same user was provided with a particular digital component. In another example, the aggregated profile may include an attribution metric that quantifies, for a subset of client devices to which the particular digital component was provided, the number of digital component impressions that led to a particular action (e.g., conversion), such as user interaction with the provided digital component, user signup, or purchase.
[0062] At 224a, system 120 transmits the aggregated user attribute report to digital component distribution system 150. System 120 may further transmit (224b) at least a portion of the aggregated user attribute report to publisher 130 or website 140. For example, system 120 may transmit an aggregate profile generated for a particular resource locator (e.g., a URL) to the corresponding website 140 or resource publisher 130.
[0063] At 254, the digital component delivery system 150 can use the aggregated data profile in the report to adjust delivery parameters for delivering the digital component.
[0064] In an illustrative example, for an aggregation key that specifies a particular resource locator, e.g., example.com / flowers, the aggregated profile may include the percentage of users that belong to a particular interest group, e.g., a group whose topic of interest is “gardening.” Delivery system 150 may determine whether the percentage of users exceeds a predefined value, and if so, delivery system 150 may add the associated interest group to a list of the particular digital component or group of related digital components that are eligible for presentation.
[0065] In some other examples, the distribution system 150 can adjust distribution parameters based on metrics included in the report's aggregate profile. In an illustrative example, if the aggregated data profile includes reach metrics for a particular digital component in a particular geographic region, the distribution system 150 can determine whether the reach metrics exceed a predetermined threshold. If the reach metrics exceed a predetermined threshold, the distribution system 150 can decide to remove the particular geographic region from a list of geographic regions for which the particular digital component or related digital components are served. In another illustrative example, if the reach metrics for a particular digital component exceed a certain threshold and / or the frequency metrics for a particular digital component exceed a certain threshold for users of a particular interest group, the distribution system 150 can decide to add the related interest group to a list of groups for the particular digital component or related digital components to be eligible for presentation. In another illustrative example, if the reach metrics for a particular digital component exceed a certain threshold and / or the frequency metrics for a particular digital component exceed a certain threshold, the distribution system 150 can decide to increase or decrease selection parameters and / or budgets for delivering the particular digital component or related digital components.
[0066] At 256, the digital component delivery system 150 delivers the digital component to the client device 110 based on the delivery parameters. In particular, the delivery system 150 can select a digital component to deliver to the client device 110 in response to receiving a digital component request from the client device according to the delivery parameters adjusted at 254. The system 150 can then provide the selected digital component to the client device 110 according to the updated delivery parameters. The client device 110 can then present the provided digital component at 216, for example, via an application on the client device 110.
[0067] 3 is a flow diagram of an exemplary process 300 for delivering digital components for display on client devices. The operations of process 300 may be performed by one or more computer systems located at one or more locations, such as a server, such as digital component delivery system 150, and / or the secure aggregate reporting system 120 described with reference to FIG. 1, suitably programmed in accordance with this specification, may perform process 300. The operations of process 300 may also be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, such that execution of the instructions by one or more data processing devices causes the one or more data processing devices to perform the operations of process 300. For convenience and without loss of generality, process 300 will be described as being performed by a data processing device, e.g., a computer system.
[0068] At 310, the data processing device receives, for each of a plurality of client devices, a digital component request from an application executing on the user's client device. The digital component request may include contextual data related to an environment in which one or more digital components are displayed on the client device. For example, the environment may include an electronic resource and the contextual data. The contextual data may include a resource locator (e.g., a URL) of the electronic resource in which one or more digital components are displayed on the client device and / or a topic of content of the electronic resource.
[0069] At 320, the data processing device identifies user attributes for the user for each client device based on the digital component request.
[0070] In some embodiments, user attributes are identified using a predictive model based on contextual data of the digital component request. For example, the predictive model can be configured to predict attributes of users who access the electronic resource or topics of the content of the electronic resource.
[0071] In some implementations, a user is subscribed to an electronic resource using a user identifier, and user attributes are identified using a user profile associated with the user identifier.
[0072] At 330, the data processing device sends a digital component response to the application of each client device. The digital component response includes (i) one or more digital components and (ii) attribute data specifying user attributes of the user. In response to receiving the attribute data, each client device is configured to update accumulated user attribute data stored in the client device's shared storage based on the user attributes in the attribute data.
[0073] In some implementations, when a user attribute is identified using a predictive model based on the context data, the application can determine whether accumulated user attribute data stored on the shared storage of the client device includes a keyed entry for the user attribute. If the accumulated user attribute data does not include the keyed entry, the application can generate a new keyed entry in the accumulated user attribute data and assign an entry value to the new keyed entry based on the user attribute identified using the predictive model. If the accumulated user attribute data includes the keyed entry, the application can update a current entry value for the keyed entry in the accumulated user attribute data based on the user attribute identified using the predictive model. For example, to update the current entry value for the keyed entry, the application can increment or decrement the current entry value for the keyed entry.
[0074] In some implementations, if a user attribute is identified using a user profile associated with a user identifier, the application can determine whether accumulated user attribute data stored on the shared storage of the client device includes a keyed entry for the user attribute. If the aggregated user attribute data does not include the keyed entry, the application can generate a new keyed entry in the accumulated user attribute data and assign an entry value to the new keyed entry based on the user attribute identified using the user profile. If the accumulated user attribute data includes the keyed entry, the application can update (e.g., replace) the entry value for the keyed entry in the accumulated user attribute data based on the user attribute identified using the user profile. In one example, a user interface of an electronic resource can include script code for an application to update the accumulated user attribute data based on the user attribute in response to receiving the user attribute.
[0075] At 340, the data processing device retrieves the accumulated user attribute data from the shared storage of each client device.
[0076] At 350, the data processing device uses the obtained accumulated user attribute data to generate an aggregated user attribute report for the set of aggregation keys. In particular, for each aggregation key, the data processing device generates an aggregated data profile by aggregating the accumulated user attribute data from a subset of client devices that accessed the electronic resource or digital component identified by the aggregation key.
[0077] In some embodiments, the aggregate profile of an aggregation key includes one or more metrics for the electronic resource or digital component identified by the aggregation key. For example, the metrics may include a reach metric that measures the number of unique users within a subset of client devices that accessed the electronic resource or digital component identified by the aggregation key.
[0078] In some embodiments, before and / or during generation of the aggregated profile using the accumulated user attribute data from the subset of client devices, the data processor may apply privacy-preserving techniques to the accumulated user attribute data to ensure data security and privacy. These techniques may include, for example, removing any user identifiers from the data, applying k-anonymity techniques, and / or applying differential privacy techniques to the aggregated data to anonymize each user's data. For example, to apply a differential privacy process, the data processor may add random noise to the user attribute data of each of the subset of client devices before aggregating it.
[0079] In some embodiments, to improve data security and data privacy, aggregated user attribute reports can be generated by a secure aggregation system. The secure aggregate reporting system can be a computing system separate from the digital component distribution system or a computing system that is part of the digital component distribution system. If the secure aggregate reporting system is a computing system separate from the digital component distribution system, the digital component distribution system can send an aggregation request to the secure aggregate reporting system. The aggregation request includes the accumulated user attribute data received from each client device and a set of aggregation keys. The accumulated user attribute data received from the client devices can be encrypted at the client device using an encryption key of the secure aggregation system. Once the aggregated user attribute report is generated by the secure aggregate reporting system, the digital component distribution system can receive an aggregated data profile from the secure aggregation system.
[0080] At 360, the data processing device adjusts one or more delivery parameters for delivering the digital component to the client device in response to the digital component request based on the estimated metric. For example, the data processing device may adjust keywords that must be matched, a list of geographic locations to which the digital component is eligible to be served, a list of user groups to which the digital component is eligible to be served, parameters characterizing resources to which the digital component is eligible to be presented, and / or other suitable delivery parameters based on the estimated metric.
[0081] At 370, the data processing device delivers the digital component to the client device based on the delivery parameters.
[0082] 4 is a block diagram of an exemplary computer system 400 that can be used to perform the operations described above. System 400 includes a processor 410, a memory 420, a storage device 430, and an input / output device 440. Each of the components 410, 420, 430, and 440 can be interconnected using, for example, a system bus 450. Processor 410 can process instructions for execution within system 400. In some embodiments, processor 410 is a single-threaded processor. In other embodiments, processor 410 is a multi-threaded processor. Processor 410 can process instructions stored in memory 420 or storage device 430.
[0083] Memory 420 stores information within system 400. In one embodiment, memory 420 is a computer-readable medium. In some embodiments, memory 420 is a volatile memory unit. In another embodiment, memory 420 is a non-volatile memory unit.
[0084] Storage device 430 can provide mass storage for system 400. In some embodiments, storage device 430 is a computer-readable medium. In various different embodiments, storage device 430 can include, for example, a hard disk device, an optical disk device, a storage device shared over a network by multiple computing devices (e.g., a cloud storage device), or some other mass storage device.
[0085] The input / output device 440 provides input and output operations for the system 400. In some embodiments, the input / output device 440 may include one or more of a network interface device, such as an Ethernet card, a serial communication device, such as an RS-232 port, and / or a wireless interface device, such as an 802.11 card. In another embodiment, the input / output device may include a driver device configured to receive input data and send output data to an external device 460, such as a keyboard, a printer, a display device, etc. However, other implementations, such as a mobile computing device, a mobile communication device, a set-top box, a television client device, etc., may also be used.
[0086] Although FIG. 4 illustrates an exemplary processing system, implementations of the subject matter and functional operations described herein can be implemented in other types of digital electronic circuitry, or computer software, firmware, or hardware, including the structures disclosed herein and structural equivalents thereof, or one or more combinations thereof.
[0087] Embodiments of the subject matter and operations described herein can be implemented in digital electronic circuitry, or computer software, firmware, or hardware, including the structures disclosed herein and their structural equivalents, or one or more combinations thereof. Embodiments of the subject matter described herein can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions, encoded on a computer storage medium (or media) for execution by or to control the operation of a data processing apparatus. Alternatively, or additionally, the program instructions can be encoded in an artificially generated propagated signal, such as a machine-generated electrical, optical, or electromagnetic signal, that is generated to encode information for transmission to a suitable receiving device for execution by the data processing apparatus. A computer storage medium can be, or can be included in, a computer-readable storage device, a computer-readable storage substrate, or a random or serial access memory array or device, or one or more combinations thereof. Furthermore, while a computer storage medium is not a propagated signal, a computer storage medium can be a source or destination of computer program instructions encoded in an artificially generated propagated signal. A computer storage medium may also be, or may be included in, one or more separate physical components or media (such as multiple CDs, disks, or other storage devices).
[0088] The operations described herein may be implemented as operations performed by a data processing apparatus on data stored in one or more computer-readable storage devices or data received from other sources.
[0089] The term "data processing apparatus" encompasses all kinds of apparatuses, devices, and machines for processing data, including, by way of example, a programmable processor, a computer, a system on a chip, or a plurality or combination thereof. An apparatus can include special-purpose logic circuitry, such as an FPGA (field-programmable gate array) or an ASIC (application-specific integrated circuit). In addition to hardware, an apparatus also includes code that creates an execution environment for the computer program, such as code comprising processor firmware, a protocol stack, a database management system, an operating system, a cross-platform runtime environment, a virtual machine, or one or more combinations thereof. The apparatus and execution environment can implement a variety of different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.
[0090] A computer program (also known as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted, declarative or procedural, and can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may, but need not, correspond to a file in a file system. A program can be stored in a portion of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program, or in multiple associated files (e.g., files storing one or more modules, subprograms, or portions of code). A computer program can be deployed to be executed on one computer or on multiple computers located at one site or distributed across multiple sites and interconnected by a communications network.
[0091] The processes and logic flows described herein may be performed by one or more programmable processors executing one or more computer programs to perform actions by operating on input data and generating output. The processes and logic flows may also be performed by, and apparatus may be implemented as, special purpose logic circuitry, such as an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit).
[0092] Processors suitable for executing computer programs include, for example, both general-purpose and special-purpose microprocessors. Generally, a processor receives instructions and data from a read-only memory, a random-access memory, or both. The essential elements of a computer are a processor that performs actions in accordance with the instructions and one or more memory devices for storing instructions and data. Typically, a computer also includes one or more mass storage devices for storing data, such as magnetic, magneto-optical, or optical disks, or is operatively coupled to receive data from or transfer data to them, or both. However, a computer need not include such devices. Furthermore, a computer may be incorporated into other devices, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device (such as a universal serial bus (USB) flash drive). Suitable storage devices for storing computer program instructions and data include all types of non-volatile memory, media, and memory devices, including, by way of example, semiconductor memory devices such as EPROM, EEPROM, and flash memory devices, magnetic disks such as internal hard disks and removable disks, magneto-optical disks, and CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special purpose logic circuitry.
[0093] To interact with a user, embodiments of the subject matter described herein may be implemented in a computer that has a display device, such as a CRT (cathode ray tube) or LCD (liquid crystal display) monitor, for displaying information to the user, and a keyboard and pointing device, such as a mouse or trackball, by which the user can provide input to the computer. Other types of devices may also be used to provide interaction with the user. For example, feedback provided to the user may be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback, and input from the user may be acoustic, verbal, or tactile input. Additionally, a computer may interact with a user by sending and receiving documents to a device used by the user, for example, by sending a web page to a web browser on the user's client device in response to a request received from the web browser.
[0094] Embodiments of the subject matter described herein can be implemented in a computing system that includes back-end components, e.g., a data server, or includes middleware components, e.g., an application server, or includes a front-end component, e.g., a client computer having a graphical user interface or web browser through which a user can interact with an implementation of the subject matter described herein, or any combination of one or more such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication, e.g., a communications network. Examples of communications networks include local area networks ("LANs") and wide area networks ("WANs"), internetworks (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks).
[0095] A computing system may include clients and servers. Clients and servers are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and by virtue of the client-server relationship to each other. In some embodiments, a server sends data (e.g., HTML pages) to client devices (e.g., for the purpose of displaying the data to and receiving user input from a user interacting with the client device). Data generated at the client device (e.g., the results of user interaction) can be received from the client device by the server.
[0096] While this specification contains many specific implementation details, these should not be construed as limiting the scope or patentable content of any invention, but rather as descriptions of features specific to particular embodiments of a particular invention. Certain features described herein in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features of the invention that are described in the context of a single embodiment can also be provided in multiple embodiments separately or in any suitable subcombination. Furthermore, even if features may be described above as functioning in a particular combination and originally claimed as such, one or more features from a claimed combination may, in some cases, be deleted from the combination, and the claimed combination may be directed to subcombinations or variations of the subcombination.
[0097] Similarly, while acts are shown in a particular order in the figures, this should not be understood as requiring that such acts be performed in the particular order or sequential order shown, or that all of the acts shown be performed, to achieve desirable results. In certain situations, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system components in the above embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems may generally be integrated into a single software product or packaged into multiple software products.
[0098] Thus, specific embodiments of the present invention have been described. Other embodiments are within the scope of the following claims. In some cases, the actions recited in the claims may be performed in a different order and still achieve desirable results. Furthermore, the processes depicted in the accompanying figures do not necessarily require the particular order shown, or sequential order, to achieve desirable results. In certain implementations, multitasking and parallel processing may be advantageous.
Claims
1. 1. A computer-implemented method comprising: For each of multiple client devices, a digital component delivery system receiving a digital component request from an application running on said client device of a user; the digital component delivery system identifying one or more user attributes of the user based on the digital component request; and the digital component delivery system sending a digital component response to the application including (i) one or more digital components and (ii) attribute data including the one or more user attributes of the user, the application being configured to update accumulated user attribute data stored in shared storage of the client device based on the one or more user attributes in response to receiving the attribute data; a secure aggregation system acquiring, from the shared storage of each of the plurality of client devices, the accumulated user attribute data stored in the shared storage of each client device; generating, by the secure aggregation system, an aggregated user attribute report for one or more aggregation keys using the obtained accumulated user attribute data, the generating including obtaining, for each of the one or more aggregation keys, an aggregate data profile generated by aggregating the accumulated user attribute data from a subset of the plurality of client devices that accessed an electronic resource or digital component identified by the aggregation key; the digital component delivery system adjusting, based on the aggregated data profile, one or more delivery parameters for delivering the digital component to the client device in response to the digital component request; and the digital component delivery system delivering the digital component to the client device based on the delivery parameters; A method comprising:
2. generating the aggregated user attribute report includes: sending an aggregation request to the secure aggregation system, the aggregation request including the accumulated user attribute data obtained from each of the plurality of client devices and the one or more aggregation keys; and receiving from the secure aggregation system the aggregated data profile generated in response to the aggregation request; The method of claim 1 , comprising:
3. The method of claim 2 , wherein the accumulated user attribute data received from each client device is encrypted by the client device using an encryption key of the secure aggregation system.
4. The method of claim 1 , wherein the digital component request includes contextual data related to an environment in which the one or more digital components are displayed on the client device.
5. the environment includes electronic resources; 5. The method of claim 4, wherein the contextual data includes one or more of a resource locator of an electronic resource on which the one or more digital components are displayed on the client device, or a topic of content of the electronic resource.
6. 6. The method of claim 5, wherein the one or more user attributes are identified using a predictive model configured to predict attributes of users who accessed the electronic resource or the topic of the content of the electronic resource.
7. The application, in response to receiving the user attributes identified using the predictive model, determining whether the accumulated user attribute data stored on the shared storage of the client device includes a keyed entry for the one or more user attributes; responsive to the stored user attribute data not including the keyed entry, generating a new keyed entry in the stored user attribute data and assigning an entry value to the new keyed entry based on the one or more user attributes identified using the predictive model; and responsive to the accumulated user attribute data including the keyed entry, updating a current entry value for the keyed entry in the accumulated user attribute data based on the one or more user attributes identified using the predictive model; The method of claim 6 , configured to:
8. Updating the current entry value of the keyed entry comprises:
8. The method of claim 7, further comprising incrementing or decrementing the current entry value of the keyed entry in response to the accumulated user attribute data including the keyed entry.
9. the user is subscribed to the electronic resource using a user identifier; The method of claim 1 , wherein the one or more user attributes are identified using a user profile associated with the user identifier.
10. The application, in response to receiving the user attributes identified using the user profile, determining whether the accumulated user attribute data stored on the shared storage of the client device includes a keyed entry for the one or more user attributes; responsive to the aggregated user attribute data not including the keyed entry, generating a new keyed entry in the accumulated user attribute data and assigning an entry value to the new keyed entry based on the one or more user attributes identified using the user profile; and responsive to the stored user attribute data including the keyed entry, updating the entry value of the keyed entry in the stored user attribute data based on the one or more user attributes identified using the user profile; The method of claim 9 , configured to:
11. 11. The method of claim 10, wherein the user interface of the electronic resource includes code for causing the application to update the accumulated user attribute data based on the one or more user attributes in response to receiving the user attributes.
12. The method of claim 1 , wherein the aggregate data profile for an aggregation key includes one or more metrics of the electronic resource or the digital component identified by the aggregation key.
13. 13. The method of claim 12, wherein the one or more metrics include a reach metric that measures the number of unique users in the subset of client devices that accessed the electronic resource or digital component identified by the aggregation key.
14. 2. The method of claim 1, wherein aggregating the user attribute data from the subset of client devices includes adding random noise to the user attribute data of each of the subset of client devices before aggregating.
15. 1. A system comprising: one or more computers; and one or more storage devices storing instructions that, when executed by said one or more computers, cause said one or more computers to perform the operations of the respective method of any one of claims 1 to 14; Including, the system.
16. One or more computer-readable storage media storing instructions that, when executed by the one or more computers, cause the one or more computers to perform the respective method operations of any one of claims 1 to 14.
Citation Information
Patent Citations
Communication distribution of service contents by multiple operators
JP2008535079A
System and Method for Creating Anonymous User Profiles from a Mobile Data Network
US20090247193A1