IP Library › Granted Patent US 10,341,351
Granted Patent B2
US 10,341,351 · App. 15/941,560 · Granted Jul 2, 2019

Differentiated containerization and execution of web content based on trust level and other attributes

Inventors: Hong C. Li (El Dorado Hills, CA); John B. Vicente (Roseville, CA); Prashant Dewan (Hillsboro, OR)
Assignee: Intel Corporation
H04L63/101G06F21/51G06F21/53G06F2221/2119H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,351
App. No.
15/941,560
Granted
Jul 2, 2019
Kind
B2
Abstract

Systems and methods may provide for receiving web content and determining a trust level associated with the web content. Additionally, the web content may be mapped to an execution environment based at least in part on the trust level. In one example, the web content is stored to a trust level specific data container.

Claims (46)

1. A computing system comprising:

network circuitry;

a storage device including instructions; and

processor circuitry associated with a local execution environment, the processor circuitry to execute the instructions to:

store data of a first type in a first container associated with the local execution environment;

store data of a second type in a second container associated with the local execution environment, the second type different from the first type;

determine whether to provide content to a remote execution environment separate from the local execution environment based on whether the content is unverified; and

provide the content to the remote execution environment when the content is determined to be unverified.

2. The computing system of claim 1 , wherein the processor circuitry is to determine whether the content is unverified based on a blacklist.

3. The computing system of claim 1 , wherein the processor circuitry is to determine whether the content is unverified based on a whitelist.

4. The computing system of claim 1 , wherein the content includes hypertext markup language (HTML) content.

5. The computing system of claim 4 , wherein the network circuitry is to receive the HTML content.

6. The computing system of claim 1 , wherein the processor circuitry is further to receive a result associated with the content from the remote execution environment.

7. At least one computer readable storage device comprising instructions that, when executed, cause at least one processor associated with a local execution environment to at least:

store data of a first type in a first container associated with the local execution environment;

store data of a second type in a second container associated with the local execution environment, the second type different from the first type;

determine whether to provide content to a remote execution environment separate from the local execution environment based on whether the content is unverified; and

provide the content to the remote execution environment when the content is determined to be unverified.

8. The at least one computer readable storage device of claim 7 , wherein the instructions, when executed, cause the at least one processor to determine whether the content is unverified based on a blacklist.

9. The at least one computer readable storage device of claim 7 , wherein the instructions, when executed, cause the at least one processor to determine whether the content is unverified based on a whitelist.

10. The at least one computer readable storage device of claim 7 , wherein the content includes hypertext markup language (HTML) content.

11. The at least one computer readable storage device of claim 10 , wherein the instructions, when executed, cause the at least one processor to receive the HTML content via network circuitry.

12. The at least one computer readable storage device of claim 7 , wherein the instructions, when executed, further cause the at least one processor to receive a result associated with the content from the remote execution environment.

13. A system comprising:

networking means for communicating with a network;

processing means for processing data associated with a local execution environment, the processing means to:

store data of a first type in a first container associated with the local execution environment;

store data of a second type in a second container associated with the local execution environment, the second type different from the first type;

determine whether to provide content to a remote execution environment separate from the local execution environment based on whether the content is unverified; and

provide the content to the remote execution environment when the content is determined to be unverified; and

storage means for storing instructions accessible by the processing means.

14. The system of claim 13 , wherein the processing means is to determine whether the content is unverified based on a blacklist.

15. The system of claim 13 , wherein the processing means is to determine whether the content is unverified based on a whitelist.

16. The system of claim 13 , wherein the content includes hypertext markup language (HTML) content.

17. The system of claim 16 , wherein the networking means is to receive the HTML content.

18. The system of claim 13 , wherein the processing means is further to receive a result associated with the content from the remote execution environment.

19. A method comprising

storing data of a first type in a first container associated with a local execution environment;

storing data of a second type in a second container associated with the local execution environment, the second type different from the first type;

determining, by executing an instruction with at least one processor associated with the local execution environment, whether to provide content to a remote execution environment separate from the local execution environment based on whether the content is unverified; and

providing, by executing an instruction with the at least one processor, the content to the remote execution environment when the content is determined to be unverified.

20. The method of claim 19 , further including determining whether the content is unverified based on a blacklist.

21. The method of claim 19 , further including determining whether the content is unverified based on a whitelist.

22. The method of claim 19 , wherein the content includes hypertext markup language (HTML) content.

23. The method of claim 22 , further including receiving the HTML content via network circuitry.

24. The method of claim 19 , further including receiving a result associated with the content from the remote execution environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2018
From: LI, HONG C.; VICENTE, JOHN B.; DEWAN, PRASHANT
To: INTEL CORPORATION
Reel/Frame 046810/0842 →
Continuity (3)
Continuation 15722336 · Oct 2, 2017
Continuation 13830634 · Mar 14, 2013
Related Publication 20180227309A1 · Aug 9, 2018