Trusted-Hardware Cryptographic Content Selection for On-Device Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic techniques for content selection on user devices often compromise user privacy and security by transmitting sensitive data over public networks, leading to latency and bandwidth issues.

Innovation Solution

Utilizing a trusted hardware module with zero-knowledge proofs and ring learning with errors (RLWE) to encrypt and analyze user attributes locally, enabling secure content selection without revealing personal information, thus reducing latency and bandwidth consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user data is transmitted over public networks for content selection, then content personalization can be achieved, but user privacy and security are compromised

Engineering Contradiction:
Improvecontent personalizationVSAvoiduser privacy compromise
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the content selection process from the network environment and moves it to the local trusted hardware module. User attributes remain stored locally in the TEE, and only encrypted selection results are transmitted over the network, effectively separating the sensitive data processing from the public network transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted hardware module (TEE) as an intermediary between user data and the content selection process. This intermediary performs cryptographic operations locally, acting as a secure mediator that prevents direct exposure of user attributes to external systems while still enabling personalized content delivery.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If user data is transmitted over public networks for content selection, then content personalization can be achieved, but latency and bandwidth issues occur

Engineering Contradiction:
Improvecontent personalizationVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-storing user attributes in the trusted hardware module and preparing the cryptographic analysis environment in advance. When content selection is needed, the comparison operation can be performed immediately using pre-loaded data, reducing the time required for personalized content delivery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trusted hardware module performs the content selection process independently using locally stored user attributes and received candidate content information. This self-service approach eliminates the need to transmit user data to remote servers for processing, significantly reducing network latency and bandwidth consumption.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If cryptographic analysis is performed remotely, then content selection can be centralized, but user data security is compromised

Engineering Contradiction:
Improvecentralized content selectionVSAvoiddata security
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

Instead of the conventional approach where remote servers perform cryptographic analysis on transmitted user data, the patent inverts the architecture so that the trusted hardware module performs the cryptographic analysis locally on locally stored data. This inversion fundamentally changes the security model from data-protection-during-transmission to data-never-leaves-device.

Inventive Principle:
Principle #13The other way round (Inversion)

4Object-affected harmful factors

If zero-knowledge proofs are used for content selection, then user privacy is protected, but computational complexity increases

Engineering Contradiction:
Improveuser privacy protectionVSAvoidcryptographic computation
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent replaces complex software-based zero-knowledge proof implementations with hardware-based cryptographic operations in the trusted hardware module. This substitution leverages dedicated cryptographic hardware to perform the computationally intensive operations more efficiently, reducing the practical complexity burden on the overall system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4193277B1Localized cryptographic techniques for privacy protection
Publication Date: 2025.08.20 GOOGLE LLC
  • EP4193277B1 patent drawingFigure 1
  • EP4193277B1 patent drawingFigure 2
  • EP4193277B1 patent drawingFigure 3

AI summary

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for preserving user privacy when selecting content are described. In some aspects, a method includes receiving a data element identifying a set of candidate digital components and, for each candidate digital component, a set of distribution parameters for the candidate digital component. For each candidate digital component, encrypted selection data for the candidate digital component is provided as input to a cryptographic analysis application running in a trusted hardware module of a client device. The encrypted selection data represents the set of distribution parameters for the candidate digital component and is encrypted using a zero-knowledge proof protocol. The cryptographic analysis application is configured to determine a measure of match between the selection data and user attributes of a user of the client device.