Secure device to device communication channel
One embodiment provides a data processing system on a communal electronic device, the data processing system comprising a memory device to store instructions; one or more processors to execute the instructions stored on the memory device, the instructions to cause the one or more processors to provide a virtual assistant to receive commands at the communal electronic device, wherein the virtual assistant, via the one or more processors, is to receive a command at the communal electronic device; determine whether the command is to access personal data of a user associated with the communal electronic device; and in response to a determination that the command is to access personal data of the user, send a request to a personal electronic device of the user to process at least a portion of the command.
1 . A data processing system comprising:
a memory device to store instructions;
one or more processors to execute the instructions stored on the memory device, the instructions to cause the one or more processors to enable an encrypted data channel between electronic devices, the one or more processors to:
receive, from an account server, a list of devices that are registered to a family of associated cloud services accounts, wherein a first electronic device is registered to a first account of the family of associated cloud services accounts, a second electronic device of user is registered to a second account of the family of associated cloud services accounts, the first electronic device and the second electronic device each includes a virtual assistant;
determine that a communication session is to be established between the first electronic device and the second electronic device based on the list of devices;
establish a peer-to-peer data connection between the first electronic device and the second electronic device;
verify a trust relationship between the first electronic device and the second electronic device;
establish an encrypted communication session between the first electronic device and the second electronic device after verification of the trust relationship; and
exchange data between the first electronic device and the second electronic device over the encrypted communication session.
2 . The data processing system as in claim 1 , the one or more processors to establish the peer-to-peer data connection over a direct wireless connection between the first electronic device and the second electronic device.
3 . The data processing system as in claim 1 , the one or more processors to establish the encrypted communication session via a network layer protocol over a wireless network connection, wherein to establish the encrypted communication session, the first electronic device is to compare a persistent identifier of the first electronic device with a persistent identifier of the second electronic device and initiate the connection with the second electronic device in response to a determination that the persistent identifier of the first electronic device is lower than the persistent identifier of the second electronic device.
4 . The data processing system as in claim 1 , wherein to verify the trust relationship between the first electronic device and the second electronic device includes to verify a previously established trust relationship.
5 . The data processing system as in claim 4 , the previously established trust relationship established via one or more of:
an exchange of credentials between the first electronic device and the second electronic device over a short-range wireless connection; and
an exchange of credentials via the cloud services account to which the first electronic device and the second electronic device are registered, the credentials to enable mutual authentication between the first electronic device and the second electronic device.
6 . The data processing system as in claim 1 , the one or more processors additionally to:
determine that the communication session is to be established between the first electronic device and the second electronic device in response to discovery of the second electronic device at the first electronic device via a device discovery protocol; and
establish the peer-to-peer data connection between the first electronic device and the second electronic device after discovery of the second electronic device.
7 . The data processing system as in claim 1 , the one or more processors additionally to:
discover the second electronic device at the first electronic device via a device discovery protocol;
establish the peer-to-peer data connection between the first electronic device and the second electronic device after discovering the second electronic device; and
exchange data between the virtual assistant of the first electronic device and the virtual assistant of the second electronic device via the encrypted communication session.
8 . The data processing system as in claim 1 , one or more processors additionally to:
discover the second electronic device at the first electronic device via a device discovery protocol; and
establish the peer-to-peer data connection between the first electronic device and the second electronic device after discovering the second electronic device.
9 . The data processing system as in claim 1 , the first electronic device to establish a trust relationship with the second electronic device before the first electronic device is enabled to send a request for a data exchange to the second electronic device.
10 . A non-transitory machine-readable medium storing instructions to cause one or more processors to perform operations comprising:
receiving, from an account server, a list of devices that are registered to a family of cloud services accounts, wherein a first electronic device is registered to a first account of the family of cloud services accounts, or a second electronic device is registered to a second account of the family of cloud services accounts, the first electronic device and the second electronic device each including a virtual assistant;
determining that a communication session is to be established between the first electronic device and the second electronic device based on the list of devices;
establishing a peer-to-peer data connection between the first electronic device and the second electronic device;
verifying a trust relationship between the first electronic device and the second electronic device;
establishing an encrypted communication session between the first electronic device and the second electronic device after verifying the trust relationship; and
exchanging data between the first electronic device and the second electronic device over the encrypted communication session.
11 . The non-transitory machine-readable medium as in claim 10 , the operations additionally comprising establishing the peer-to-peer data connection over a direct wireless connection between the first electronic device and the second electronic device.
12 . The non-transitory machine-readable medium as in claim 10 , the operations additionally comprising establishing the encrypted communication session via a network layer protocol over a wireless network connection, wherein to establish the encrypted communication session, the first electronic device is to compare a persistent identifier of the first electronic device with a persistent identifier of the second electronic device and initiate the connection with the second electronic device in response to a determination that the persistent identifier of the first electronic device is lower than the persistent identifier of the second electronic device.
13 . The non-transitory machine-readable medium as in claim 10 , wherein verifying the trust relationship between the first electronic device and the second electronic device includes verifying a previously established trust relationship.
14 . The non-transitory machine-readable medium as in claim 13 , the previously established trust relationship established via operations including one or more of:
exchanging credentials between the first electronic device and the second electronic device over a short-range wireless connection; and
exchanging credentials via the cloud services account to which the first electronic device and the second electronic device are registered, the credentials to enable mutual authentication between the first electronic device and the second electronic device.
15 . The non-transitory machine-readable medium as in claim 10 , the operations additionally comprising:
determining that the communication session is to be established between the first electronic device and the second electronic device in response to discovery the second electronic device at the first electronic device via a device discovery protocol; and
establishing the peer-to-peer data connection between the first electronic device and the second electronic device after discovering the second electronic device.
16 . The non-transitory machine-readable medium as in claim 10 , the operations additionally comprising:
discovering the second electronic device at the first electronic device via a device discovery protocol;
establishing the peer-to-peer data connection between the first electronic device and the second electronic device after discovering the second electronic device; and
exchanging data between the virtual assistant of the first electronic device and the virtual assistant of the second electronic device via the encrypted communication session.
17 . The non-transitory machine-readable medium as in claim 10 , the operations additionally comprising:
discovering the second electronic device at the first electronic device via a device discovery protocol; and
establishing the peer-to-peer data connection between the first electronic device and the second electronic device after discovering the second electronic device.
18 . The non-transitory machine-readable medium as in claim 10 , the first electronic device to establish a trust relationship with the second electronic device before the first electronic device is enabled to send a request for a data exchange to the second electronic device.
19 . A method comprising:
receiving, from an account server a list of devices that are registered to a family of associated cloud services accounts to which at least one of a first electronic device of a user or a second electronic device are registered to a cloud services account of the family of associated cloud services accounts, the first electronic device and the second electronic device each including a virtual assistant, the first electronic device being a communal electronic device associated with a plurality of users;
determining that a communication session is to be established between the first electronic device and the second electronic device based on the list of devices;
establishing a peer-to-peer data connection between the first electronic device and the second electronic device via a wireless radio device;
verifying a trust relationship between the first electronic device and the second electronic device, wherein verifying the trust relationship between the first electronic device and the second electronic device includes verifying a previously established trust relationship;
establishing an encrypted communication session between the first electronic device and the second electronic device via a network layer protocol over a wireless network connection, the encrypted communication session established after verifying the trust relationship; and
exchanging data between the first electronic device and the second electronic device over the encrypted communication session to synchronize device data between the first electronic device and the second electronic device, the device data associated with the cloud services account.
20 . The method as in claim 19 , additionally comprising:
discovering the second electronic device at the first electronic device via a device discovery protocol; and
establishing the peer-to-peer data connection between the first electronic device and the second electronic device after discovering the second electronic device.