IP Library › Granted Patent US 12,739,130
Granted Patent B2
US 12,739,130 · App. 18/828,916 · Granted Sep 15, 2026

Extraction of data in a mutually distrustful environment

Inventors: Christian Rudolf Hoermann (Raleigh, NC); Dharma Ganesan (Columbia, MD); Thomas William Keetch (Blackburn with Darwen, GB); David Meibusch (Brisbane City, AU)
Assignee: Oracle International Corporation
H04L9/3247G06F21/6227G06F21/64H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,130
App. No.
18/828,916
Granted
Sep 15, 2026
Kind
B2
Abstract

Techniques for transmitting data within a cloud environment are disclosed. Data is received by a transmission service, which transmits the data to a signature and encryption (SE) service, along with an encryption key. Signed and encrypted data, which is received from the SE service, is (i) encrypted using the encryption key and (ii) signed by the SE service. In an example, the SE service maintains a log of the data. The signed and encrypted data is transmitted to an intermediate zone, to facilitate the intermediate zone to verify a signature of the signed and encrypted data, and allow passage of the signed and encrypted data to a reception service. The transmission and reception services are within a first tenancy and a second tenancy, respectively, of a cloud environment; and the intermediate zone is within one of the first tenancy or a third tenancy of the cloud environment.

Claims (78)

1 . A method comprising:

receiving, by a transmission service, data;

transmitting, from the transmission service, the data to a signature and encryption (SE) service, along with an encryption key;

receiving, by the transmission service from the SE service, (i) signed and encrypted data that is encrypted using the encryption key and signed by the SE service, and (ii) metadata including a value that is calculated based on an amount of source code included within the data; and

transmitting, by the transmission service, the signed and encrypted data and the metadata to an intermediate zone, to facilitate the intermediate zone to verify a signature of the signed and encrypted data, and allow passage of the signed and encrypted data to a reception service.

2 . The method of claim 1 , wherein:

the transmission service is within a first tenancy of a cloud environment; and

the reception service is within a second tenancy of the cloud environment that is different from the first tenancy.

3 . The method of claim 2 , wherein the intermediate zone is within one of (i) the first tenancy of the cloud environment, or (ii) a third tenancy of the cloud environment that is different from each of the first and second tenancies.

4 . The method of claim 1 , further comprising:

subsequent to receiving the data, generating a cleartext form of the data,

wherein transmitting the data to the SE service comprises transmitting the cleartext form of the data to the SE service.

5 . The method of claim 1 , further comprising:

responsive at least in part to the intermediate zone verifying the signature of the signed and encrypted data, receiving, from the intermediate zone, the signed and encrypted data at the reception service.

6 . The method of claim 1 , further comprising:

providing one or more keys to the reception service for decryption of the signed and encrypted data; and

refraining from providing the one or more keys to the intermediate zone for decryption of the signed and encrypted data,

wherein the transmission service does not have access to a signature key used by the SE service to sign the encrypted data.

7 . The method of claim 1 , wherein the value within the metadata indicates whether the amount of the source code included within the data is less than, or greater than a threshold value.

8 . The method of claim 1 , wherein:

the encryption key is a first encryption key;

the value within the metadata is encrypted using a second encryption key that is different from the first encryption key; and

the intermediate zone decrypts at least the section of the metadata, without decrypting the signed and encrypted data.

9 . The method of claim 8 , wherein the value within the metadata that is encrypted is less than one byte.

10 . The method of claim 1 , wherein:

the source code is of a program that is deployable to a plurality of mobile devices or to a cloud-based server; and

the value within the metadata quantifies the amount of the source code included within the data.

11 . The method of claim 1 , wherein the intermediate zone allows passage of the signed and encrypted data to the reception service, responsive at least in part to the amount of the source code included within the data, as indicated by the value within the metadata, being less than a threshold value.

12 . The method of claim 1 , wherein the SE service maintains a log of the data, and the log of the data includes the source code included within the data.

13 . The method of claim 1 , further comprising:

analyzing the source code of a program that is deployable to a plurality of mobile devices;

generating the data that at least in part includes results of analyzing the source code; and

transmitting the data to the transmission service.

14 . The method of claim 1 , wherein the data is first data, wherein the encryption key is a first encryption key, wherein the signed and encrypted data is first signed and encrypted data, and wherein the method further comprises:

transmitting, by the transmission service, second data to the SE service, along with a second encryption key;

receiving, from the SE service, second signed and encrypted data that is (i) encrypted using the second encryption key and (ii) signed by the SE service;

detecting an error condition associated with the second signed and encrypted data;

transmitting, by the transmission service, a request to the intermediate zone;

receiving, by the transmission service, a debug token from the intermediate zone, responsive at least in part to transmitting the request to the intermediate zone;

transmitting, by the transmission service, the debug token to the SE service; and

receiving debug information from the SE service, responsive at least in part to transmitting the debug token to the SE service, the debug information including information associated with debugging the error condition.

15 . The method of claim 14 , further comprising:

transmitting, by the transmission service, the debug information to the intermediate zone for debugging.

16 . The method of claim 14 , further comprising:

transmitting, by the transmission service, the data and the second encryption key to the SE service, along with transmitting the token to the SE service;

receiving, from the SE service, third signed and encrypted data, along with receiving the debug information from the SE service; and

transmitting, by the transmission service, the debug information and the third signed and encrypted data to the intermediate zone for debugging.

17 . The method of claim 14 , further comprising:

transmitting, by the transmission service, the second signed and encrypted data to the intermediate zone, along with transmitting the request to the intermediate zone.

18 . A non-transitory computer-readable medium including instructions that when executed by one or more processors, cause the one or more processors to perform operations including:

transmitting, by a transmission service, data to a signature and encryption (SE) service, along with an encryption key;

receiving, from the SE service, signed and encrypted data that is (i) encrypted using the encryption key and (ii) signed by the SE service;

detecting an error condition associated with the signed and encrypted data;

transmitting, by the transmission service, a request to an intermediate zone;

receiving, by the transmission service, a debug token from the intermediate zone, responsive at least in part to transmitting the request to the intermediate zone;

transmitting, by the transmission service, the debug token to the SE service;

receiving debug information from the SE service, responsive at least in part to transmitting the debug token to the SE service, the debug information including information associated with debugging the error condition; and

transmitting, by the transmission service, the debug information to the intermediate zone, for debugging the error condition.

19 . The non-transitory computer-readable medium of claim 18 , wherein:

the transmission service is within a first tenancy of a cloud environment; and

the intermediate zone is within a second tenancy of the cloud environment that is different from the first tenancy.

20 . The non-transitory computer-readable medium of claim 18 , wherein the signed and encrypted data is first signed and encrypted data, and wherein the operations further include:

transmitting, by the transmission service, the data and the encryption key to the SE service, along with transmitting the token to the SE service;

receiving, from the SE service, second signed and encrypted data, along with receiving the debug information from the SE service; and

transmitting, by the transmission service, the second signed and encrypted data to the intermediate zone, along with transmitting the debug information to the intermediate zone.

21 . The non-transitory computer-readable medium of claim 18 , wherein the operations further include:

transmitting, by the transmission service, the data to the intermediate zone, along with transmitting the second signed and encrypted data and the debug information to the intermediate zone.

22 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions, which, when executed by the system, cause the system to perform a set of actions including:

receiving, by a transmission service, data;

transmitting, from the transmission service, the data to a signature and encryption (SE) service, along with an encryption key;

receiving, by the transmission service from the SE service, signed and encrypted data that is (i) encrypted using the encryption key and (ii) signed by the SE service, wherein the SE service maintains a log of the data; and

transmitting, by the transmission service, the signed and encrypted data to an intermediate zone, to facilitate the intermediate zone to verify a signature of the signed and encrypted data, and allow passage of the signed and encrypted data to a reception service.

23 . The system of claim 22 , wherein:

the transmission service is within a first tenancy of a cloud environment;

the reception service is within a second tenancy of the cloud environment that is different from the first tenancy; and

the intermediate zone is within one of (i) the first tenancy of the cloud environment, or (ii) a third tenancy of the cloud environment that is different from each of the first and second tenancies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2024
From: HOERMANN, CHRISTIAN RUDOLF; GANESAN, DHARMA; KEETCH, THOMAS WILLIAM; MEIBUSCH, DAVID
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 068639/0831 →
Continuity (3)
Provisional Application 63659243 · Jun 12, 2024
Provisional Application 63659241 · Jun 12, 2024
Related Publication 20250384165A1 · Dec 18, 2025
References Cited (32)
US 8639989B1 · Sorenson, III · 2014 [cited by examiner]
US 9710617B2 · Oxford · 2017 [cited by applicant]
US 10341321B2 · Kumar et al. · 2019 [cited by applicant]
US 10981306B1 · Weinstein et al. · 2021 [cited by applicant]
US 11153283B2 · Graber et al. · 2021 [cited by applicant]
US 11165592B2 · Barreto · 2021 [cited by applicant]
US 11251959B2 · Wentz · 2022 [cited by applicant]
US 11488147B2 · Sheng et al. · 2022 [cited by applicant]
US 11531783B2 · Hamel · 2022 [cited by examiner]
US 11784985B2 · Graber et al. · 2023 [cited by applicant]
US 12341902B2 · Kim et al. · 2025 [cited by applicant]
US 12348649B1 · Kaplan · 2025 [cited by examiner]
US 12425203B2 · Chang et al. · 2025 [cited by applicant]
US 12609836B2 · Hoermann · 2026 [cited by examiner]
US 20190199692A1 · Atta et al. · 2019 [cited by applicant]
US 20200412548A1 · Allen · 2020 [cited by examiner]
US 20230246845A1 · Peddada · 2023 [cited by examiner]
CN 105227565A · 2016 [cited by examiner]
CN 114721634A · 2022 [cited by examiner]
CN 115225399A · 2022 [cited by examiner]
CN 120034336A · 2025 [cited by examiner]
CN 121169539A · 2025 [cited by examiner]
GB 2604337A · 2022 [cited by examiner]
JP 2023137873A · 2023 [cited by examiner]
WO WO2025259537A1 · 2025 [cited by examiner]
WO WO2025259538A1 · 2025 [cited by examiner]
Zhao. English translation of CN 115225399 A. (Year: 2022). [cited by examiner]
Cai et al., “LightSCA: Lightweight Side-Channel Attack via Discrete Cosine Transform and Residual Networks,” 2022 IEEE 24th Int Conf on High Performance Computing & Communications; 8th Int Conf on Data Science & Systems… [cited by applicant]
International Search Report & Written Opinion notified Oct. 13, 2025 for PCT Patent Application No. PCT/US2025/032519. [cited by applicant]
International Search Report & Written Opinion notified Sep. 1, 2025 for PCT Patent Application No. PCT/US2025/032521. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/828,919 notified Nov. 24, 2025. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/828,919 notified Mar. 6, 2026. [cited by applicant]