IP Library Granted Patent US 12,380,205
Granted Patent B2
US 12,380,205 · App. 18/283,325 · Granted Aug 5, 2025

Secure workflows that enhance data security

Inventors: Gang Wang (Frederick, MD); Nikolaus Rath (Harpenden, GB)
Assignee: Google LLC
G06F21/53G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,380,205
App. No.
18/283,325
Granted
Aug 5, 2025
Kind
B2
Abstract

Methods, systems, and apparatus, including medium-encoded computer program products, for secure workflows that enhance data security are described. In one aspect, a digital component request is received. In response to receiving the digital component request, a multi-stage workflow for selecting a digital component is identified, and can include customizable stages. The execution of workflow stages includes: (A) identifying a given customizable stage; (B) for the stage: (i) identifying, a customization specific to the stage that generates an output for use in selecting the digital component; (ii) initiating an isolated execution environment for each customization; (iii) executing, within each isolated execution environment, the customization for which the isolated execution environment was initiated; and (iv) obtaining the output generated by the code of each isolated execution environment; and (C) executing a final stage to select a digital component based on the outputs. The selected digital component is sent to the client device.

Claims (66)

1. A computer-implemented method comprising:

receiving, from a client device, a digital component request comprising a set of data;

in response to receiving the digital component request:

identifying a multi-stage workflow for selecting a digital component from candidate digital components of multiple content platforms based on the set of data, wherein the multi-stage workflow comprises one or more customizable stages;

executing each stage of the multi-stage workflow in a sequence defined by the multi-stage workflow, the executing comprising:

identifying a given customizable stage in the multi-stage workflow;

for the given customizable stage:

identifying, for each of the multiple content platforms, a customization specific to the given stage provided by the content platform, wherein each customization comprises computer-executable code that generates an output for use in selecting the digital component;

initiating an isolated execution environment for each customization;

executing, within each isolated execution environment, the computer-executable code of the customization for which the isolated execution environment was initiated; and

obtaining the output generated by the computer-executable code of each isolated execution environment; and

executing a final stage to select a digital component based on the obtained outputs; and

sending the selected digital component to the client device.

2. The computer-implemented method of claim 1 , further comprising providing a set of one or more input values for use by the computer-executable code.

3. The computer-implemented method of claim 2 , wherein at least a subset of the set of the one or more input values is provided as key, value pairs.

4. The computer-implemented method of claim 1 , wherein each isolated environment comprises a virtual machine.

5. The computer-implemented method of claim 1 , further comprising:

determining an operational metric resulting from executing at least one stage of the multi-stage workflow;

evaluating the operational metric against a constraint; and

in response to determining that operational metric satisfies the constraint, terminating execution of the at least one stage.

6. The computer-implemented method of claim 5 , wherein the operational metrics is Central Processing Unit use.

7. The computer-implemented method of claim 1 , further comprising:

receiving, from a content provider, code that implements a stage of the multi-stage workflow.

8. The computer-implemented method of claim 7 , wherein the code is encrypted.

9. The computer-implemented method of claim 1 , wherein the multi-stage workflow is defined by a workflow specification.

10. The computer-implemented method of claim 9 , wherein the workflow specification includes default code for at least one stage of the multi-stage workflow.

11. The computer-implemented method of claim 10 , wherein the default code for the at least one stage of the multi-stage workflow cannot be overridden.

12. One or more non-transitory computer-readable storage media storing instructions that when executed by one or more computers cause the one or more computers to perform operations comprising:

receiving, from a client device, a digital component request comprising a set of data;

in response to receiving the digital component request:

identifying a multi-stage workflow for selecting a digital component from candidate digital components of multiple content platforms based on the set of data, wherein the multi-stage workflow comprises one or more customizable stages;

executing each stage of the multi-stage workflow in a sequence defined by the multi-stage workflow, the executing comprising:

identifying a given customizable stage in the multi-stage workflow;

for the given customizable stage:

identifying, for each of the multiple content platforms, a customization specific to the given stage provided by the content platform, wherein each customization comprises computer-executable code that generates an output for use in selecting the digital component;

initiating an isolated execution environment for each customization;

executing, within each isolated execution environment, the computer-executable code of the customization for which the isolated execution environment was initiated; and

obtaining the output generated by the computer-executable code of each isolated execution environment; and

executing a final stage to select a digital component based on the obtained outputs; and

sending the selected digital component to the client device.

13. A system comprising:

one or more processors; and

one or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, from a client device, a digital component request comprising a set of data;

in response to receiving the digital component request:

identifying a multi-stage workflow for selecting a digital component from candidate digital components of multiple content platforms based on the set of data, wherein the multi-stage workflow comprises one or more customizable stages;

executing each stage of the multi-stage workflow in a sequence defined by the multi-stage workflow, the executing comprising:

identifying a given customizable stage in the multi-stage workflow;

for the given customizable stage:

identifying, for each of the multiple content platforms, a customization specific to the given stage provided by the content platform, wherein each customization comprises computer-executable code that generates an output for use in selecting the digital component;

initiating an isolated execution environment for each customization;

executing, within each isolated execution environment, the computer-executable code of the customization for which the isolated execution environment was initiated; and

obtaining the output generated by the computer-executable code of each isolated execution environment; and

executing a final stage to select a digital component based on the obtained outputs; and

sending the selected digital component to the client device.

14. The system of claim 13 , wherein the operations comprise providing a set of one or more input values for use by the computer-executable code.

15. The system of claim 14 , wherein at least a subset of the set of the one or more input values is provided as key, value pairs.

16. The system of claim 13 , wherein each isolated environment comprises a virtual machine.

17. The system of claim 13 , wherein the operations comprise:

determining an operational metric resulting from executing at least one stage of the multi-stage workflow;

evaluating the operational metric against a constraint; and

in response to determining that operational metric satisfies the constraint, terminating execution of the at least one stage.

18. The system of claim 17 , wherein the operational metrics is Central Processing Unit use.

19. The system of claim 13 , wherein the operations comprise:

receiving, from a content provider, code that implements a stage of the multi-stage workflow.

20. The system of claim 19 , wherein the code is encrypted.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2023
From: WANG, GANG; RATH, NIKOLAUS
To: GOOGLE LLC
Reel/Frame 065202/0235 →
Continuity (2)
Provisional Application 63421830 · Nov 2, 2022
Related Publication 20250077643A1 · Mar 6, 2025
References Cited (18)
US 9003355B2 · Meda et al. · 2015 [cited by applicant]
US 9032066B1 · Erdmann · 2015 [cited by examiner]
US 9135292B1 · Tsun · 2015 [cited by examiner]
US 9596132B1 · Erdmann · 2017 [cited by applicant]
US 9679112B2 · Brust et al. · 2017 [cited by applicant]
US 10019570B2 · Wang · 2018 [cited by examiner]
US 10984128B1 · Hoffer · 2021 [cited by applicant]
US 10997265B1 · Tsun et al. · 2021 [cited by applicant]
US 11366681B2 · Liguori et al. · 2022 [cited by applicant]
US 20100241990A1 · Gabriel et al. · 2010 [cited by applicant]
US 20140181817A1 · Muller et al. · 2014 [cited by applicant]
US 20180293375A1 · Wang et al. · 2018 [cited by applicant]
US 20210132982A1 · Thakkar et al. · 2021 [cited by applicant]
US 20250086268A1 · Rath · 2025 [cited by examiner]
US 20250094613A1 · Wang · 2025 [cited by examiner]
WO WO2020198539 · 2020 [cited by applicant]
Haidri et al., “Cost effective deadline aware scheduling strategy for workflow applications on virtual machines in cloud computing,” Journal of King Saud University—Computer and Information Sciences, Jul. 1, 2020, 32(6)… [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2022/052534, mailed on Apr. 5, 2023, 11 pages. [cited by applicant]
Cited By (1)
US 12,475,245