IP Library › Granted Patent US 12,530,446
Granted Patent B2
US 12,530,446 · App. 18/560,759 · Granted Jan 20, 2026

Secure workflows that enhance data security using sandboxes hosted by trusted execution environments

Inventor: Nikolaus Rath (Harpenden, GB)
Assignee: Google LLC
G06F21/53G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,530,446
App. No.
18/560,759
Granted
Jan 20, 2026
Kind
B2
Abstract

Methods, systems, and apparatus, including medium-encoded computer program products for secure workflows that enhance data security using sandboxes hosted by trusted execution environments. A digital component (DC) request can be received, and in response, multi-stage workflows can be identified. Each multi-stage workflow (i) being configured to select DCs of multiple content platforms and (ii) including customizable stages. A trusted execution environment of the server can initiate a sandbox environment for executing stages of the workflow, which can be executed within the sandbox environment, preventing the code of the workflow from transmitting user data from the server. Output data can be received from the workflow by the server and from the trusted execution environment. A DC can be selected by the server based on at least a portion of the output data from the workflows. The DC can be provided to the client device for presentation to a user.

Claims (81)

1 . A computer-implemented method comprising:

receiving, by a server and from a client device, a digital component request comprising a set of data;

in response to receiving the digital component request:

identifying one or more multi-stage workflows, each multi-stage workflow of the one or more multi-stage workflows (i) being configured to select digital components from candidate digital components of one or more content platforms and (ii) comprising one or more customizable stages;

for each particular multi-stage workflow of the one or more multi-stage workflows:

initiating, by a trusted execution environment (TEE) of the server, one or more sandbox environments for executing one or more stages of the particular multi-stage workflow;

executing, by the TEE, the one or more stages of the particular multi-stage workflow, wherein each sandbox environment prevents code of the multi-stage workflow from transmitting user data from the server, and wherein the code of each customizable stage is executed in a separate sandbox environment; and

receiving, by the server and from the TEE, output data from the particular multi-stage workflow;

selecting, by the server, a digital component based on at least a portion of the output data from each particular multi-stage workflow; and

providing, by the server, the digital component to the client device for presentation to a user of the client device.

2 . The computer-implemented method of claim 1 , wherein executing the one or more stages of the particular multi-stage workflow further comprises:

for each customizable stage of the particular multi-stage workflow:

initiating, by the trusted execution environment, a corresponding sandbox environment in which code of the stage is executed to generate output data for use in one or more other stages of the multi-stage workflow;

executing, within the sandbox environment, the code of the stage; and

receiving, by the server and from the trusted execution environment, the output data from each customizable stage.

3 . The computer-implemented method of claim 1 , further comprising, for at least one stage of a particular multi-stage workflow of the one or more multi-stage workflow, wherein the particular multi-stage workflow is of a particular content platform:

determining, for a stage of the at least one stage of the particular multi-stage workflow, a reference to a location that contains code implementing the stage; and

requesting, by the server and from the content platform, at least in part using the reference, code comprising the at least one stage, wherein executing, within the sandbox environment, the particular multi-stage workflow comprises executing the code.

4 . The computer-implemented method of claim 1 , wherein the sandbox environment comprises a virtual machine.

5 . The computer-implemented method of claim 1 , further comprising: providing, by the TEE, a signature of the code for the TEE.

6 . The computer-implemented method of claim 5 , further comprising:

obtaining, by a particular content platform, the signature;

obtaining, by the particular content platform, a known signature of the TEE;

determining that signature matches the known signature; and

in response to determining that the signature matches the known signature:

determining that the trusted execution environment is verified; and

providing at least one customization to the trusted execution environment.

7 . The computer-implemented method of claim 1 , wherein the output data comprises one or more selection parameters that describe a relevance of the digital component to the digital component request.

8 . The computer-implemented method of claim 1 , further comprising:

identifying in the multi-stage workflow at least one stage that is not customizable, and in response, executing the at least one stage outside the trusted execution environment.

9 . The computer-implemented method of claim 1 , wherein identifying the multi-stage workflows comprises receiving a revised version of a default workflow from a particular content platform, the method further comprising:

executing the revised version of the default workflow using an envelope that provides a limited set of communication Application Programming Interfaces (APIs) that limit communications of the revised version of the workflow with external components.

10 . A system comprising:

one or more processors of a server; and

one or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, by the server and from a client device, a digital component request comprising a set of data;

in response to receiving the digital component request:

identifying one or more multi-stage workflows, each multi-stage workflow of the one or more multi-stage workflows (i) being configured to select digital components from candidate digital components of one or more content platforms and (ii) comprising one or more customizable stages;

for each particular multi-stage workflow of the one or more multi-stage workflows:

initiating, by a trusted execution environment (TEE) of the server, one or more sandbox environments for executing one or more stages of the particular multi-stage workflow;

executing, by the TEE, the one or more stages of the particular multi-stage workflow, wherein each sandbox environment prevents code of the multi-stage workflow from transmitting user data from the server, and wherein the code of each customizable stage is executed in a separate sandbox environment; and

receiving, by the server and from the TEE, output data from the particular multi-stage workflow;

selecting, by the server, a digital component based on at least a portion of the output data from each particular multi-stage workflow; and

providing, by the server, the digital component to the client device for presentation to a user of the client device.

11 . The system of claim 10 , wherein executing the one or more stages of the particular multi-stage workflow further comprises:

for each customizable stage of the particular multi-stage workflow:

initiating, by the trusted execution environment, a corresponding sandbox environment in which code of the stage is executed to generate output data for use in one or more other stages of the multi-stage workflow;

executing, within the sandbox environment, the code of the stage; and

receiving, by the server and from the trusted execution environment, the output data from each customizable stage.

12 . The system of claim 10 , wherein the operations comprise, for at least one stage of a particular multi-stage workflow of the one or more multi-stage workflow, wherein the particular multi-stage workflow is of a particular content platform:

determining, for a stage of the at least one stage of the particular multi-stage workflow, a reference to a location that contains code implementing the stage; and

requesting, by the server and from the content platform, at least in part using the reference, code comprising the at least one stage, wherein executing, within the sandbox environment, the particular multi-stage workflow comprises executing the code.

13 . The system of claim 10 , wherein the sandbox environment comprises a virtual machine.

14 . The system of claim 10 , wherein the operations comprise providing, by the TEE, a signature of the code for the TEE.

15 . The system of claim 14 , wherein the operations comprise:

obtaining, by a particular content platform, the signature;

obtaining, by the particular content platform, a known signature of the TEE;

determining that signature matches the known signature; and

in response to determining that the signature matches the known signature:

determining that the trusted execution environment is verified; and

providing at least one customization to the trusted execution environment.

16 . The system of claim 10 , wherein the output data comprises one or more selection parameters that describe a relevance of the digital component to the digital component request.

17 . The system of claim 10 , wherein the operations comprise:

identifying in the multi-stage workflow at least one stage that is not customizable, and in response, executing the at least one stage outside the trusted execution environment.

18 . The system of claim 10 , wherein identifying the multi-stage workflows comprises receiving a revised version of a default workflow from a particular content platform, the operations further comprising:

executing the revised version of the default workflow using an envelope that provides a limited set of communication Application Programming Interfaces (APIs) that limit communications of the revised version of the workflow with external components.

19 . A non-transitory computer readable medium carrying instructions that, when executed by one or more processors of a server, cause the one or more processors to perform operations comprising:

receiving, by the server and from a client device, a digital component request comprising a set of data;

in response to receiving the digital component request:

identifying one or more multi-stage workflows, each multi-stage workflow of the one or more multi-stage workflows (i) being configured to select digital components from candidate digital components of one or more content platforms and (ii) comprising one or more customizable stages;

for each particular multi-stage workflow of the one or more multi-stage workflows:

initiating, by a trusted execution environment (TEE) of the server, one or more sandbox environments for executing one or more stages of the particular multi-stage workflow;

executing, by the TEE, the one or more stages of the particular multi-stage workflow, wherein each sandbox environment prevents code of the multi-stage workflow from transmitting user data from the server, and wherein the code of each customizable stage is executed in a separate sandbox environment; and

receiving, by the server and from the TEE, output data from the particular multi-stage workflow;

selecting, by the server, a digital component based on at least a portion of the output data from each particular multi-stage workflow; and

providing, by the server, the digital component to the client device for presentation to a user of the client device.

20 . The non-transitory computer readable medium of claim 19 , wherein executing the one or more stages of the particular multi-stage workflow further comprises:

for each customizable stage of the particular multi-stage workflow:

initiating, by the trusted execution environment, a corresponding sandbox environment in which code of the stage is executed to generate output data for use in one or more other stages of the multi-stage workflow;

executing, within the sandbox environment, the code of the stage; and

receiving, by the server and from the trusted execution environment, the output data from each customizable stage.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2023
From: RATH, NIKOLAUS
To: GOOGLE LLC
Reel/Frame 065623/0187 →
Continuity (1)
Related Publication 20250086268A1 · Mar 13, 2025
References Cited (36)
US 7210009B2 · Gulick et al. · 2007 [cited by applicant]
US 7222062B2 · Goud et al. · 2007 [cited by applicant]
US 8082551B2 · Ibrahim et al. · 2011 [cited by applicant]
US 8086852B2 · Bade et al. · 2011 [cited by applicant]
US 8117642B2 · Covey et al. · 2012 [cited by applicant]
US 8250520B2 · Hao et al. · 2012 [cited by applicant]
US 8832452B2 · Johnson et al. · 2014 [cited by applicant]
US 8856291B2 · Bartlett et al. · 2014 [cited by applicant]
US 8935746B2 · Vetillard · 2015 [cited by applicant]
US 9003355B2 · Meda et al. · 2015 [cited by applicant]
US 9032066B1 · Erdmann · 2015 [cited by examiner]
US 9189653B2 · Thom et al. · 2015 [cited by applicant]
US 9594927B2 · Zimmer et al. · 2017 [cited by applicant]
US 9596132B1 · Erdmann · 2017 [cited by applicant]
US 9679112B2 · Brust et al. · 2017 [cited by applicant]
US 10366237B2 · Zimmer et al. · 2019 [cited by applicant]
US 10984128B1 · Hoffer · 2021 [cited by applicant]
US 11366681B2 · Liguori et al. · 2022 [cited by applicant]
US 11823145B2 · Wong · 2023 [cited by examiner]
US 20100107218A1 · Kurien et al. · 2010 [cited by applicant]
US 20100241990A1 · Gabriel et al. · 2010 [cited by applicant]
US 20140173596A1 · Ng et al. · 2014 [cited by applicant]
US 20140181817A1 · Muller et al. · 2014 [cited by applicant]
US 20160036826A1 · Pogorelik et al. · 2016 [cited by applicant]
US 20190005228A1 · Singh et al. · 2019 [cited by applicant]
US 20200228880A1 · Iyer · 2020 [cited by examiner]
US 20210132982A1 · Thakkar et al. · 2021 [cited by applicant]
US 20220172183A1 · Wong et al. · 2022 [cited by applicant]
US 20250077643A1 · Wang · 2025 [cited by examiner]
EP 3736718 · 2020 [cited by applicant]
WO WO2020198539 · 2020 [cited by applicant]
Haidri et al., “Cost effective deadline aware scheduling strategy for workflow applications on virtual machines in cloud computing,” Journal of King Saud University—Computer and Information Sciences, Jul. 1, 2020, 32(6)… [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2022/054358, mailed on Jul. 28, 2023, 9 pages. [cited by applicant]
Wikipedia.org [online], “Trusted execution environment,” available on or before Dec. 22, 2023, via Internet Archive: Wayback Machine URL<https://web.archive.org/web/20231222041422/https://en.wikipedia.org/wiki/Trusted_e… [cited by applicant]
Extended European Search Report in European Appln. No. 25176180.5, mailed on Jun. 10, 2025, 8 pages. [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/US2022/054358, mailed on Jul. 10, 2025, 9 pages. [cited by applicant]