Secure and private hyper-personalization system and method

By storing and processing user data in a secure virtual container that isolates the operating system on a computing device, and generating inference values, the privacy and data security issues of users receiving highly personalized experiences are resolved, achieving secure highly personalized experiences and anomaly detection.

CN114270316BActive Publication Date: 2026-04-14MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
MICROSOFT TECHNOLOGY LICENSING LLC
Filing Date
2020-06-12
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Users are required to provide private data to service providers when receiving highly personalized experiences, and the machine learning models used by these providers are often kept secret, leading to concerns among users about data security and privacy protection.

Method used

By maintaining secure virtual containers on computing devices, isolating the operating system, and storing and processing user data within them, machine learning models are used to generate inference values ​​without leaking user data. This leverages the isolation of secure virtual containers from the operating system and the confidentiality of machine learning models to deliver a highly personalized experience.

Benefits of technology

It enables users to maintain ownership and control of their privacy data while receiving a highly personalized experience, protects the confidentiality of machine learning models, detects abnormal behavior, and provides automatic remedial measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114270316B_ABST
    Figure CN114270316B_ABST
Patent Text Reader

Abstract

A secure virtual container is enabled to securely store personal data corresponding to a user, where such data is inaccessible to processes running outside the secure virtual container. The secure virtual container can also include an execution environment for machine learning models, in which the models are securely stored and inaccessible. The personal data can be feature engineered and provided to a machine learning model for training purposes and / or to generate inference values corresponding to the user data. The inference values can then be relayed by a proxy application from the secure virtual container to an application outside the container. The application can perform hyper-personalized operations based at least in part on the received inference values. The proxy application can enable the external application to subscribe to notifications regarding availability of inference values. The proxy can also provide inference values in response to queries.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Products and services are increasingly marketed and sold in a variety of ways facilitated by computing devices. For example, businesses today often operate through e-commerce platforms, which consumers access using browsers or other applications from personal computers, smartphones, tablets, etc. Business analytics have shown that personalized e-commerce experiences can drive sales and generate brand loyalty. Historically, this personalization has been driven by aggregating customer data (age, location, purchase history, etc.) to identify similar groups of people, and then treating each member of a given group as having a persona for that group. Decisions about how to personalize the e-commerce experience and / or the market for a particular individual are then made based on the persona assigned to that person, thus personalizing the experience at least to that individual.

[0002] Hyperpersonalization attempts to achieve the same goal as the personalized experiences described above, but in a way that is specifically tailored to that individual based on their customer data. Delivering hyperpersonalized experiences to customers typically involves applying a user's private data (e.g., purchase history, usage information, financial information, demographics, biometrics, relationships / social connections) to sophisticated machine learning algorithms.

[0003] E-commerce suppliers and other service providers typically invest heavily in creating and training machine learning models, which can then implement a great deal of proprietary business intelligence. For this reason, these models are kept strictly confidential. That is, suppliers simply cannot trust that their models will not be misused, and therefore choose not to distribute them.

[0004] Therefore, in order to receive a highly personalized experience based on the output of such machine learning models, users must typically be willing to provide all their private data to the provider / service provider so that they can apply the data to their models. Unfortunately, this means that users simply must trust that the service provider will not misuse their personal data (e.g., by selling access to their data to third parties) and that the service provider is willing and able to protect the data (i.e., prevent hackers from stealing it). Summary of the Invention

[0005] This summary is provided to introduce, in a simplified form, some concepts further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter.

[0006] This document describes methods, systems, and computer program products that enable users to receive hyper-personalized experiences while maintaining ownership and control over all their private data. Furthermore, service providers are enabled to deliver hyper-personalized experiences while maintaining the confidentiality of proprietary machine learning models. Additional embodiments can advantageously allow the detection of anomalous user behavior (e.g., through online service providers) and anomalous machine behavior (i.e., detection of malware, viruses, worms, rootkits, etc.), and provide predictions for device failures as well as automated remediation to address the same issues.

[0007] In one example, a secure virtual container is maintained on a computing device, where the secure virtual container is isolated from the operating system running on the computing device. The secure virtual container and the operating system can each run in parallel via a shared hypervisor, the virtualization features of which are isolated from the underlying hardware implementation. In an alternative embodiment, the secure container can be implemented in a hardware container completely separate from the computing device (i.e., not virtualized on the computing device).

[0008] In another aspect, a secure virtual container is enabled to securely store user-specific personal data, which is inaccessible to processes running outside the secure virtual container. This data may include, in part or in part, features and / or feature vectors suitable for use with machine learning models. A set of features corresponding to an inference category can be selected from the data, and inference values ​​for that category can be generated. This generation can be accomplished in various ways, such as through an appropriately trained machine learning model. Information regarding the availability of one or more inference values ​​for various inference categories can then be published to an agent outside the secure virtual container. For example, the agent may include an application running in an operating system separate and isolated from the secure virtual container. The application can then query the agent for the availability of one or more inference values ​​corresponding to a specific inference category and, upon receiving such inference values, perform hyper-personalized operations based at least in part on the inference values.

[0009] Further features and advantages, as well as the structure and operation of various examples, will be described in detail below with reference to the accompanying drawings. Note that the concepts and techniques are not limited to the specific examples described herein. The examples presented herein are for illustrative purposes only. Based on the teachings contained herein, additional examples will be apparent to those skilled in the art. Attached Figure Description

[0010] The accompanying drawings, which are incorporated herein and form part of the specification, illustrate embodiments of the present application and, together with the description, further serve to explain the principles of the embodiments and enable those skilled in the art to make and use these embodiments.

[0011] Figure 1An example computing device, including a protected personalized system, is depicted according to an embodiment.

[0012] Figure 2 A protected example of a personalized system according to an embodiment is described.

[0013] Figure 3 A stacked view of an example computing device, including a protected personalized system, is depicted according to an embodiment.

[0014] Figure 4 A flowchart is depicted for an example method for providing secure hyperpersonalization in a computing device, according to an embodiment.

[0015] Figure 5 Depicting, according to embodiments, of Figure 4 An improved flowchart of the flowchart, used to provide updated inference values ​​when providing secure hyper-personalization.

[0016] Figure 6 An example artificial neuron suitable for use in a deep neural network (“DNN”) is depicted according to an embodiment.

[0017] Figure 7 An example DNN composed of artificial neurons, according to an embodiment, is described.

[0018] Figure 8 This is a block diagram of an example mobile device that can implement the embodiments described herein.

[0019] Figure 9 This is a block diagram of an example computer system in which embodiments can be implemented.

[0020] The features and advantages of the embodiments will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings (in which the same reference numerals identify corresponding elements throughout). In the drawings, the same reference numerals generally refer to the same, functionally similar, and / or structurally similar elements. The first appearance of an element in the drawing is indicated by the leftmost numeral(s) of the corresponding reference numeral(s). Detailed Implementation

[0021] I. Introduction

[0022] This specification and accompanying drawings disclose one or more embodiments incorporating the features of the present invention. The scope of the invention is not limited to the disclosed embodiments. The disclosed embodiments are merely illustrative of the invention, and modifications to the disclosed embodiments are also covered by the invention. The various embodiments of the invention are defined by the appended claims.

[0023] References to "an embodiment," "embodiment," "example embodiment," etc., in the specification indicate that the described embodiment may include a particular feature, structure, or characteristic; however, each embodiment may not necessarily include that particular feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Additionally, when a particular feature, structure, or characteristic is described in connection with an embodiment, whether explicitly described or not, implementing that feature, structure, or characteristic in conjunction with other embodiments is considered to be within the knowledge of those skilled in the art.

[0024] Furthermore, it should be understood that the spatial descriptions used herein (e.g., "above", "below", "up", "left", "right", "down", "top", "bottom", "vertical", "horizontal", etc.) are for illustrative purposes only, and the actual implementation of the structures described herein can be arranged in space in any orientation or manner.

[0025] In this discussion, unless otherwise stated, adjectives such as “substantially” and “approximately” describing the conditional or relational characteristics of one or more features of embodiments of this disclosure should be understood to mean that the condition or characteristic is limited to an acceptable tolerance for operation of the embodiment for its intended application.

[0026] Several exemplary embodiments are described below. Note that any section / subsection headings provided herein are not intended to be limiting. Various embodiments are described throughout this document, and embodiments of any type may be included under any section / subsection. Furthermore, embodiments disclosed in any section / subsection may be combined in any way with any other embodiments described in the same section / subsection and / or different sections / subsections.

[0027] II. Example Implementation

[0028] In one embodiment, secure and private hyperpersonalization is enabled by applying an obfuscation process to user-specific data, whereby the user's data is, for example, hashed, normalized, and / or feature-engineered, and subsequently provided to applications and / or operating system services in digest form. In another embodiment, the obfuscation process may include applying the user data to a machine learning model. The user data is thus fed into the system for hyperpersonalization.

[0029] This user data can, for example, be stored in a protected data repository that is not directly accessible to the operating system or applications of the computing device. Similarly, the obfuscation process can run within a protected personalization container that includes the protected data repository. For example, a machine learning model can be securely transferred to the protected personalization container and made operable to perform operations on usage data stored in the protected data repository (note that such operations do not expose user data outside the container). The output of the machine learning model can include user data in the form of a digest of the hash / normalization / feature design described above, which can be provided to the operating system and / or applications. Using a protected personalization container in this way protects both the user data and the machine learning model operating on the data. Various types of user data that can be used by embodiments will now be described.

[0030] User data can be collected in various ways (e.g., via multiple direct or indirect sensors) and can subsequently be processed and / or stored in various ways (e.g., in the form of a graph, e.g., using a graph database system). This graph can be constructed in a logically layered manner. For example, the first layer may include a policy layer that implements policies, rules, values, and / or other fundamental operational principles of the system with minimal changes. For example, a highly personalized work environment may operate in part based on security rules set by the company. These rules may be based on user preferences, risk profiles, social profiles, etc. Company machines implementing embodiments of the protected personalized system described herein can be configured with certain company rules and exclusion principles relating to the use of the machine. These rules may be very fine-grained and targeted interpretations of company policies implemented by system configuration (“SCCM”) or mobile device management (“MDM”) tools. For example, SCCM / MDM rules may disable USB ports on the device, prevent the sending of emails with any attachments, and / or block or restrict screenshots.

[0031] In an embodiment, the second layer may include a knowledge graph. The knowledge graph contains slowly changing knowledge about the user. The knowledge layer can be considered a "warm" data layer because this data changes slowly over time (e.g., on a timescale greater than one day). For example, the knowledge graph may reflect a user's risk profile, financial profile, application usage profile (multiple) and / or personalization data (e.g., preferences), habits, relationships, demographics, psychological information, health, education, hobbies, commitments, and basic social and / or professional networks. Demographic information may include, for example, recent facial images, skin color, hair color, eye color, name, age, income, occupation, home location, office location, resume information, musical tastes, Wi-Fi name, password, family member details, etc. The knowledge graph may also include information about the computing devices being used, such as the brand and model of the computer or mobile device, machine / equipment health status, and identification of available sensors. As mentioned above, the information in the knowledge layer changes relatively infrequently, and embodiments may use batch processing algorithms to update this information during nighttime / idle hours.

[0032] The embodiments may also implement the third layer described herein as a transient layer. A transient layer typically includes data created and / or updated over a recent predetermined time interval (e.g., a timescale less than one day). For example, an embodiment may create a transient layer by processing a rolling 20-minute signal window captured by sensors and running basic processing to obtain a basic view of the usage status of a personal computer. Examples include usage status, presence, user flow, dwell time, interaction, engagement, atmosphere, and system status. Transient layer information may also include the locked status of the computing device, the identification of at least one user of the computing device, the location of the computing device, policy violations on the computing device, the identification of a person physically present with at least one user of the computing device, tasks being performed on the computing device, alerts, SMS (Short Message Service) or MMS (Multimedia Messaging Service) messages, emails, memory and / or file access signals, application status, and application-specific data.

[0033] The data in the transient layer may also include data corresponding to a predetermined time period in the future. For example, the transient layer may include sensor and other data tracking for 20 minutes, as well as data about events that, for example, will occur in the near future. In embodiments, such future-focused transient layer data may be collected at least in part from the user's calendar and / or busy / free data, and thus reflect recent time commitments or other commitments made via email, social networks, etc. Alternatively, embodiments may learn user habits over time and predict the user's likely near-term actions, and include these in the transient layer.

[0034] Transient layer data can include temporary / temporary data, as certain types of data are useless outside a finite time frame. For example, many useful types of data are only of interest in real time (e.g., temperature or location). However, transient layer data does not have to be entirely temporary. For example, some transient layer data can be persistently stored in the second layer mentioned above. For instance, user-related activity and / or usage data may be of interest not only at the current moment (as reflected by the transient layer) but also over a longer time frame to determine general usage patterns over time. In addition to these data layers, the graph may also include a service / management layer, which includes functionality for managing, updating, and querying the data layers, as discussed in more detail below.

[0035] Therefore, in this embodiment, the transient layer will have a constantly changing data graph, the data being about who the user is, who else can be with them, where the user is, whether it is a public location (i.e., whether it is a protected location), whether the user is moving or resting, and how fast the user is moving. Thus, the transient layer can be viewed as "hot" data that changes rapidly with the user's state.

[0036] In this embodiment, each of the layers described above may correspond to one or more processing layers. For example, the "hot path" processing of transient layer data collected from sensors may be cached, and this data may be available via API (Application Programming Interface) calls. Similarly, information in the knowledge layer may be processed via a batch processing layer, which may create analytical outputs (in the form of predictions), classifications, and generated data about users and environments of the types discussed in detail above.

[0037] Hyper-personalized services are described below in the context of a specific example. In particular, consider a computer operating system configured to provide a hyper-personalized user interface and hyper-personalized services to applications running on the operating system. However, it should be understood that the described computer and operating system are merely exemplary, and embodiments can be readily implemented on other types of computing devices such as mobile devices / smartphones, as discussed further below.

[0038] In this embodiment, and as described above, enabling hyper-personalization requires user consent to the collection and use of information about the user. When users consent to enabling hyper-personalization, they agree that the system can collect and process information for internal device-level consumption only, and not for sharing with third parties. For example, granting this permission allows a laptop or desktop computer operating in hyper-personalized mode to connect to any of the various data collection devices, such as: cameras, microphones, game consoles (e.g., Microsoft game consoles), mobile phones, TVs, monitors, printers, Bluetooth peripherals, and any other devices accessible by the operating system. Various types of data can be collected, such as audio, video, radio signals, images, ambient light readings, motion, position, vibration, speed, acceleration, inertial sensor readings, magnetism, pressure, temperature, voltage, current, humidity, and / or any other sensor information accessible / received by the computer.

[0039] When users attach peripheral devices to a computer, they typically expect a near-"plug-and-play" experience. That is, the computer will have the necessary access to the devices to connect and activate them using driver software. Similarly, a protected personalization system running on a personal computer can act as a user agent, activating desired peripheral devices and / or sensors at varying time intervals, and collecting information about the user's state and local environment. For example, embodiments of a protected personalization system can be strictly user-aware through conventional identification and authentication mechanisms (i.e., the system customizes operations based on who logs into the machine). Other embodiments of a protected personalization system can be configured to automatically identify the user via sensors.

[0040] Regardless of whether the implementation functions through login dialogue or sensor-based automatic identification, it should be understood that the hyper-personalized experience can vary for the same user. That is, the implementation can track multiple personas for each individual, where each persona corresponds to a specific usage context. For example, a user might use their office computer at home and in the office. In a user's "office" persona, the user is mostly seated at a desk, and a camera can capture the background and items around the user to detect location (other methods of location detection are possible in the implementation, such as Global Positioning System (GPS), etc.). Furthermore, people often wear certain types of clothing in their "office" or "workplace" personas. For example, they might wear hats and shirts with company logos, surgical gowns, a certain hairstyle, use different glasses, wear more or less makeup, etc. Workplaces will also typically have relatively unique visual and auditory characteristics (at least compared to a home environment). For example, workplace infrastructure / furniture, such as cubicles, desks, counters, chairs, etc., is often different from home infrastructure / furniture.

[0041] Beyond visual cues, the audio differs at each location, and the signatures within each location can be identifiable. For example, a workplace with the hissing of computers and fans, low-frequency voice transmissions through walls, telephone rings, elevator noise, printers, drawers, coffee makers, industrial refrigerators, air conditioners, etc., all emit sounds different from those typically present in a home environment. In addition to audio and visual cues, other signals exist, such as the use of docking stations, Wi-Fi, keyboards and mice, printer connections, etc., which can also tell us about a user's location and the role he or she might be playing at any given time. All of these differences can be detected and stored (typically in a transient layer), specifying which user role should manage the hyper-personalized experience.

[0042] Enabling a secure personalization system to collect and store the aforementioned user information, and obfuscating this information within a secure modeling environment, can be achieved in several ways. For example, Figure 1 An example computing device 102, including a protected personalization system 110 according to an embodiment, is depicted. (e.g.) Figure 1 As shown, computing device 102 includes application 104 and a protected personalization system 110. Application 104 includes a GUI 106, which includes personalized content / features 108. Based on information regarding... Figure 1 The following discussion of the computing device 102 described herein, other structural and operational embodiments will be apparent to those skilled in the art.

[0043] Embodiments of computing device 102 may include any type of mobile computer or computing device, such as a handheld device (e.g., Equipment, RIM Devices, personal digital assistants (PDAs), laptops, notebook computers, tablets (e.g., Apple iPads) TM Microsoft Surface TM Netbooks, mobile phones (e.g., smartphones such as Apple iPhones and Google Android phones), etc. TM Telephone, Microsoft Telephones, etc.), wearable devices (e.g., virtual reality glasses, helmets and masks, watches (e.g., Apple watches) Other types of mobile devices. In another embodiment, computing device 102 may be a fixed computer or computing device, such as a desktop computer.

[0044] In an embodiment, the protected personalization system 110 is configured to securely store user information of the type described herein and securely process such information to produce the user information in the form of a summary. For example, the protected personalization system 110 may be configured to accept a suitably trained machine learning model capable of receiving user information (whether in its raw form or preprocessed into appropriate features) and generating inference 112 from it. Inference 112 may include, for example, a score representing the probability that a given proposition about a user is true based on the user information securely provided to the model. For example, inference 112 may include the probability that the user is in the office, the probability that the user likes a particular show or show type, the probability that the user has purchased a particular type of product in the past 6 months, or the probability that the user belongs to a particular demographic group. Note that the example inference 112 described above is merely exemplary, and inference 112 can in practice include any type of inference that can be modeled based on available user information.

[0045] There are multiple ways to implement the protected personalized system 110 and interface the protected personalized system 110 with the operating system and / or applications. For example, Figure 2 An example protected personalization system 110 according to an embodiment is depicted. The protected personalization system 110 includes a personalization agent 202 and a protected personalization container 204. The personalization container 204 includes a personalization data processor 206 and a personal data repository 210. The personalization data processor 206 includes a machine learning (“ML”) engine 208. Based on information regarding... Figure 2 The following discussion of the protected personalization system 110 shown will reveal other structural and operational embodiments to those skilled in the art.

[0046] At a higher level, embodiments of the protected personalization system 110 can be configured to receive and store user data 220 (i.e., all user data of the aforementioned types) within the policy layer, knowledge layer, and transient data layer of the personal data repository 210 of the protected personalization container 204. The protected personalization container 204 prevents compromised applications or operating system components from directly accessing the user data 220 stored in the personal data repository 210, and instead requires all access to be routed through the personalization agent 202. The personalization agent 202 is configured to securely interface with the personalization data processor 206 to perform this indirect access to the user data 220.

[0047] Personalized data processor 206 can be configured to select features and / or labels from user data 220 stored in personal data repository 210 to train machine learning modules residing in ML engine 208. Alternatively, a pre-trained ML model can be received and stored by personalized data processor 206 for subsequent processing of features selected or generated from personalized data processor 206 and / or personal data repository 210 based on user data 220 stored in personal data repository 210. The features to be selected can be determined at least in part based on which model(s) are present in ML engine 208 (since different models typically generate different inferences) and depends on the different types of underlying user data 220. These general operations of the protected personalization system 110 and the components contained therein are now described in more detail.

[0048] In embodiments, ML engine 208 can interoperate with, or employ, various machine learning frameworks, converters, runtimes, compilers, and visualizers known to those skilled in the art. For example, ML engine 208 can be configured to include and / or operate models in the Open Neural Network Exchange (“ONNX”) format. ONNX is an open format for machine learning models that allows models to be shared and adapted for use with various ML frameworks and tools. For example, Microsoft… ML allows for the rapid integration of pre-trained machine learning models into a variety of applications, and the implementation can be tailored. ML is used within the aforementioned security container. This is in accordance with adjustments made by companies such as Microsoft. As an alternative or supplement to the ML framework, an alternative implementation can instantiate short-lived data packets and access protocols, enabling the ONNX model to be used on short-lived data of user data 220. An example machine learning model will be combined below. Figure 6 and Figure 7 This was discussed in further detail.

[0049] In one embodiment, the protected personalization container 204 comprises a virtual container isolated from the operating system running the user's system and applications. This isolation even prevents the operating system from accessing the user data 220, thereby preventing any malicious programs running therefrom from accessing such data. In another embodiment, the protected personalization container 204 may include a container such as a virtual sandbox that runs in the context of the operating system but is sufficiently hardened to prevent the operating system from directly accessing the user data 220 stored in the personal data repository 210.

[0050] Alternatively, and as described in more detail below, the protected personalization container 204 may include a virtualized container that runs in parallel with and is completely isolated from the operating system. Examples of such containers may include a Virtual Secure Mode (“VSM”) container in Windows 10 Enterprise, an Intel Clear container, a Kata container, and / or a Google gVisor container. Embodiments of the protected personalization container 204 may be configured to incorporate a personal data repository 210 and a personalization data processor 206 into the scope of the container, thereby securely separating the processes running in the personalization data processor 206 and the user data 220 stored in the personal data repository 210 from the operating system.

[0051] Embodiments of the personalized data processor 206 are configured to act as an interface between user data 220 stored in the personal data repository 210 and systems and processes existing outside the protected personalization container 204. The personalized data processor 206 is configured to support data obfuscation operations via the ML engine 208. Specifically, the ML engine 208 is configured to include, receive, and merge a machine learning model that extracts user data 220 retrieved from the personal data repository 210 to produce the aforementioned inference value 112, and provides this inference value 112a to the personalization agent 202 for relaying the inference value 112b to an external consumer.

[0052] Personalization data processor 206 can also be configured to track various types or categories of inference that can be accessed through personalization agent 202 and provide inference category 214 to personalization agent 202. Personalization agent 202 is then configured to publish inference category 214 to entities outside the protected personalization system 110 that may wish to retrieve such inference to build hyper-personalized experiences for users. Personalization agent 202 can also be configured to accept inference queries / subscriptions 218 from external entities. Inference queries / subscriptions 218 may include one or more direct queries to personalization agent 202 to obtain desired inference values, and may also include one or more subscriptions. In embodiments, inference values ​​may be logically grouped together into topics. For example, a topic may include a category or type of inference values ​​that may be of interest. For example, inference values ​​related to a user's hobbies may be logically grouped into the "Hobbies" topic. Interested entities may subscribe to the "Hobbies" topic and then be notified of any new or changed inference values ​​that have been tagged as part of the "Hobbies" topic.

[0053] As described above, the user data 220 stored in the personal data repository 210 is subject to change over time. In the case of transient layer data, this information can change rapidly. Similarly, the inference based on this information must therefore change over time. The inference subscription allows external entities to instruct the personalization agent 202 to automatically detect changes to the inference of interest and send one or more notifications 216 when the updated inference value 112a is available. Alternatively, the personalization agent 202 can be configured to operate in push mode, whereby the inference value 112b is automatically pushed to the subscriber when the personalization data processor 206 makes a change to this inference, either alone or in conjunction with the ML engine 208.

[0054] As described above, the protected personalization system 110 and the protected personalization container 204 can be configured in various ways. For example, Figure 3 A stacked view of an example computing device 102 including a protected personalization system according to an embodiment is depicted. The computing device 102 includes a host operating system 308, a protected personalization container 204, a hypervisor 310, and hardware 312. Based on information regarding... Figure 3 The following discussion of the computing device 102 shown, other structural and operational embodiments will be apparent to those skilled in the art(s).

[0055] In this embodiment, the host OS 308 and the protected personalized container 204 are each virtual machines running on a hypervisor 310, which in turn runs on and abstracts the underlying hardware 312. The host OS 308 includes a kernel 304 that performs operating system functions and provides an application environment in which applications 104 and the personalization agent 202 can execute. The protected personalized container 204 also includes its own kernel 306, which provides not only system functions specific to the protected personalized container 204 (e.g., retrieving data from the personal data repository 210) but also an operating environment in which the personalized data processor 206 can execute. The hypervisor 310 is configured to prevent processes in the host OS 308 and the protected personalized container 204 from directly accessing another resource. In operation, the personalization agent 202 of the host OS 308 can be configured to communicate with the protected personalization container 204 via, for example, a network connection, thereby enabling the inference value 112b to be transferred from the protected personalization container 204 to the host OS 308. Based on the teachings of this document, it will become clear to those skilled in the art(s) related to this matter that other techniques can be employed to enable communication between isolated containers.

[0056] Continue to refer to Figure 3The computing device 102, with its personalization agent 202 running in the host OS 308, can be configured to accept inference value 112a and relay it to an application (e.g., application 104) or operating system component running elsewhere in the host OS 308. This application and / or operating system component can be configured to perform personalization operations, at least in part, based on inference value 112b. For example, application 104 can be configured to customize the user interface associated with it. This customization can be performed based on, for example, inference value 112b, which indicates a high probability that the user is currently at work and in a specific location within the work area (i.e., by displaying notifications of events near the user).

[0057] Alternatively, components of the host OS 308 can be configured to perform customized operations based on inference value 112b. For example, the host OS 308 can be configured to: based on a) the time of day; and b) inference value 112b, which indicates a high probability that the user's environment currently has reduced ambient lighting; and c) where other inference values ​​112b indicate a high probability that the user has a configuration preference or setting habit for low blue light display settings in low ambient lighting at night, to change display output characteristics to reduce blue light output. It should be noted that these examples are far from exhaustive, and the various inference categories and values ​​are limited only by the availability of machine learning models(s) appropriately configured to generate the desired inference values, and the availability of sufficient user data(s)220 for use by such models(s).

[0058] Figure 1 The computing device 102 and Figure 2 The protected personalized system 110's other operational aspects will now be combined Figure 4 Explained, Figure 4 A flowchart 400 depicts an example method for providing secure hyperpersonalization in a computing device according to an embodiment. Flowchart 400 continues to be referenced. Figure 2 and Figure 3 To describe. However, based on about Figure 4 Flowchart 400 and Figure 2 The following discussion of the protected personalized system 110, other structural and operational embodiments will be apparent to those skilled in the art(s).

[0059] Flowchart 400 begins at step 402. At step 402, the feature data is stored in a secure virtual container running on the computing device, which operates in parallel with and is isolated from the operating system running on the computing device. For example, and referring to... Figure 2The protected personalization system 110, and the personal data repository 210 within the protected personalization container 204 (i.e., the "secure virtual container"), can be configured to store characteristic data, such as personal user data 220 as described above. Also, as in conjunction with the above... Figure 2 and Figure 3 As described in the specification, the protected personalized container 204 may include a virtual container executing on a computing device, which runs in parallel and is isolated from the operating system executing on that device. Specifically, and referring to... Figure 3 The protected personalized container 204 can be configured to run on the hypervisor 310, running in parallel with and isolated from the host OS 308. Figure 4 The flowchart 400 continues at step 404.

[0060] In step 404, a first feature set is selected from the stored feature data. For example, in an embodiment, this is done in the manner described in detail above, and continuing to refer to... Figure 2 and Figure 3 The protected personalization system 110. More specifically, normalized or other feature-designed versions of user data 220 can be retrieved from the personal data repository 210 and subsequently provided to the ML engine 208 for processing. The selection of such features depends on the specific data required for a given model to generate specific inferences. Furthermore, although a given model may be able to generate multiple inferences, external consumers may not be interested in all of these inferences at any given time, and therefore, there is no need to select and retrieve the corresponding features. Figure 4 The flowchart 400 continues at step 406.

[0061] In step 406, a first inference value for a first inference category is generated in the secure virtual container, at least in part based on the first feature set. For example, and continuing to refer to... Figure 2 and Figure 3 In the protected personalization system 110, in an embodiment, the ML engine 208 can be configured to include a properly trained machine learning model that is configured to accept feature data retrieved from the personal data repository 210 (i.e., feature-processed user data 220) and generate one or more inference values ​​in the manner described in detail above. Flowchart 400 continues at step 408.

[0062] At step 408, the agent outside the secure virtual container is notified of the availability of the first inference value corresponding to the first inference category. For example, and continuing to refer to... Figure 2 and Figure 3In the protected personalization system 110, in an embodiment, the personalization data processor 206 can be configured to: generate a notification 216 in response to inference values ​​generated by the ML engine 208, and send the notification 216 to the personalization agent 202 in the general manner described above. Figure 2 In the illustrated embodiment, the personalized data processor 206 (and the ML engine 208, which is part of the personalized data processor 206) is included in a protected personalization container 204, while the personalization agent 202 is outside the secure virtual container (i.e., the protected personalization container 204). Flowchart 400 continues at step 410.

[0063] At step 410, the first inferred value from the secure virtual container is received at the agent. For example, and continue to refer to... Figure 2 and Figure 3 In the protected personalization system 110, in an embodiment, the personalization agent 202 is configured to accept inference 112 relayed from the protected personalization container 204 after the ML engine 208 of the personalization data processor 206 generates such inference in the same general manner as described in detail above. Flowchart 400 ends at step 412.

[0064] At step 412, the first inferred value is provided by the agent to at least one running process in the operating system, wherein the at least one running process is configured to perform personalized operations based at least in part on the first inferred value. For example, and continuing to refer to Figure 2 and Figure 3 The protected personalization system 110, where the personalization agent 202 receives inference value 112a from the personalization data processor 206 of the protected personalization container 204, can provide it as inference value 112b to a process outside the protected personalization system 110. For example, the personalization data processor 206 within the protected personalization container 204 can be configured to transfer inference value 112a from the protected personalization container 204 to the personalization agent 202 executing in the context of the host OS 208, whereby the personalization agent 202 in turn transfers inference value 112b to application 104 (also running on the host OS 308). As described above, application 104 can be configured to customize the user experience at least in part based on the inference value 112b received from the personalization agent 202.

[0065] In the foregoing discussion of steps 402 to 412 of flowchart 400, it should be understood that sometimes such steps may be performed in a different order, or even simultaneously with other steps. Other embodiments of operation will be apparent to those skilled in the art(s). It should also be noted that the foregoing general description of the operation of the protected personalization system 110 is provided for illustrative purposes only, and embodiments of the protected personalization system 110 may include different hardware and / or software and may operate in a manner different from that described above. In fact, the steps of flowchart 400 may be performed in various ways.

[0066] For example, Figure 5 A flowchart 500 depicts an additional example method for generating event suggestions according to an embodiment, and wherein the flowchart 500 includes methods for, for example Figure 4 The method steps of flowchart 400 depicted in the flowchart are improved or added. Therefore, Figure 5 Flowchart 500 will also continue to be referenced. Figure 2 The protected personalized system 110, and Figure 2 and Figure 3 The personalization agent 202, the protected personalization container 204, the personalization data processor 206, and the ML engine 208 are described. However, based on the following discussion of flowchart 500, other structural and operational embodiments will be apparent to those skilled in the art(s).

[0067] In step 502, after receiving the feature data, additional feature data is received at the secure virtual container. This additional feature data at least reflects changes to the first feature set. For example, and continuing to refer to... Figure 2 and Figure 3 The protected personalization system 110, as described above, continuously collects information corresponding to the user and / or the user's operating environment over time. Therefore, user data 220 is continuously transmitted to the personal data repository 210 for storage. This user data 220 includes additional feature data, as it undergoes normalization or other feature design operations known in the art. Flowchart 500 continues at step 504.

[0068] In step 504, the additional feature data is combined with the first feature set to provide a second feature set. For example, and continuing to refer to... Figure 2 and Figure 3The protected personalization system 110, personal data repository 210, may already contain user data 220, which was previously collected by the system and received by the personal data repository 210 for storage. As described above, as new user data 220 is collected and transferred to the personal data repository 210 for storage, this user data 220 must be reconciled or merged with existing data. For example, suppose... Figure 1 An embodiment of computing device 102 is configured to send the lock state of computing device 102 to personal data repository 210 for storage. In this case, the current lock state should always be maintained, but previous lock states and their associated timestamps may be useful for determining usage patterns of computing device 102. Therefore, historical lock state information can be maintained and subsequently supplemented with new lock state information (when it is received at personal data repository 210). Furthermore, when user data 220 has changed, embodiments of personal data repository 210 and / or personalized data processor 206 can generate or receive updated features (i.e., a "second feature set") based on the characteristics of such changed user data 220. Flowchart 500 continues at step 506.

[0069] In step 506, a second feature set is provided to a first inference generation model, which is included in a secure virtual container and configured to generate a second inference value based at least in part on the second feature set. For example, as described above... Figure 4 As described in step 406 of flowchart 400, in this embodiment, ML engine 208 may be configured to include a properly trained machine learning model configured to: receive feature data (i.e., feature-engineered user data 220) retrieved from personal data repository 210, and generate one or more inferred values ​​in the manner described in detail above. ML engine 208 of personalized data processor 206 may also be configured to: generate additional inferred values ​​as new or altered user data 220 is received and stored in personal data repository 210. Flowchart 500 ends at step 508.

[0070] In step 508, in response to a request received from the agent for an inference value corresponding to the first inference category, and after the receipt of the additional feature data, a second inference value is provided to the agent. For example, and continuing to refer to... Figure 2 and Figure 3The protected personalization system 110, in embodiments, can operate as described above, wherein the personalization data processor 206 can be configured to generate and send notifications to external applications and / or components regarding changes or availability of inference values ​​corresponding to one or more inference categories. More specifically, and also as described above, entities outside the protected personalization system 110 can subscribe via the personalization agent 202 to receive notifications regarding one or more inference values ​​or inference categories, and the personalization data processor 206 can be configured to generate such notifications in response to changes in features / categories of interest. Alternatively, the personalization data processor 206 can also be configured to push updated inference values ​​directly to subscribed components, wherein the updated inference values ​​themselves serve as notifications.

[0071] In the foregoing discussion of steps 502 to 508 of flowchart 500, it should be understood that sometimes such steps may be performed in a different order, or even simultaneously with other steps. Other embodiments of operation will be apparent to those skilled in the art(s). It should also be noted that the foregoing general description of the operation of the protected personalization system 110 is provided for illustrative purposes only, and embodiments of the protected personalization system 110 may include different hardware and / or software and may operate in a different manner than described above.

[0072] As described above, embodiments may include and / or utilize various machine learning platforms and algorithms. For example, an ONNX model or other types of available or generated machine learning models may be adapted to generate inference 112 from user data 220. For example, a deep neural network (“DNN”) may be constructed to generate one or more inferences 112 based on user data 220. A DNN is a type of artificial neural network that conceptually consists of artificial neurons. For example, Figure 6 An example artificial neuron 600 suitable for use in a DNN is depicted according to an embodiment. Neuron 600 includes an activation function 602, a constant input CI 604, input In1 606, input In2 608, and an output 610. Figure 6 The 600 neurons are merely exemplary and based on... Figure 6 The following discussion of the neuron 600 will make other structural or operational embodiments apparent to those skilled in the art(s).

[0073] Neuron 600 operates by performing activation function 602 on weighted versions of inputs CI 604, In1 606, and In2 608 to produce output 610. The inputs to activation function 602 are weighted according to weights b 612, W1 614, and W2 616. For example, inputs In1 606 and In2 608 may include normalized or otherwise feature-processed data corresponding to user data 220. Activation function 602 is configured to accept a single number based on all inputs (i.e., in this example, a linear combination of weighted inputs) and perform a fixed operation. As known in the art, such an operation may include, for example, a sigmoid unit operation, tanh, or rectified linear unit operation. Input CI 604 includes a constant value that can typically be set to 1, the purpose of which will be discussed further below.

[0074] A single neuron typically accomplishes very little, and useful machine learning models often involve the combined computational work of a large number of neurons working together. For example, Figure 7 An example deep neural network (“DNN”) 700, comprising neurons 600, is depicted according to an embodiment. The DNN 700 includes multiple neurons 600 assembled in layers and connected in a cascaded manner. Such layers include an input layer 700, a first hidden layer 704, a second hidden layer 706, and an output layer 708. The DNN 700 depicts the output of each neuron in each layer, which is weighted according to weights 710 and then used individually as the input to neurons in the next layer. However, it should be understood that other interconnection strategies are possible in other embodiments and are as known in the art.

[0075] Neurons 600 of the input layer 702 (labeled Ni1, Ni2, and Ni3) can each be configured to receive normalized or otherwise feature-designed or processed data corresponding to user data 220, as described above. Figure 6The neurons 600 described in the input layer 702 are weighted according to the weights 710 corresponding to specific output edges, and then applied as input to each neuron 600 of the first hidden layer 704. It should be noted that each edge depicted in the DNN 700 corresponds to an independent weight; for clarity, the label for such weights for each edge is omitted. In the same manner, the output of each neuron 600 of the first hidden layer 704 is weighted according to its corresponding edge weights and provided as input to neurons 600 in the second hidden layer 706. Finally, the output of each neuron 600 of the second hidden layer 706 is weighted and provided as input to the neurons of the output layer 708. One or more outputs of neurons 600 of the output layer 708 comprise the output of the model. In the context described above, such output comprises inference 112. Note that although the output layer 708 comprises two neurons 600, the embodiment may instead have only a single output neuron 600, and therefore only a single discrete output. Also note that... Figure 7 The DNN 700 depicts a simplified topology, and generating useful inference from a DNN like the DNN 700 typically requires far more layers, and each layer has far more neurons. Therefore, the DNN 700 should only be considered a simplified example.

[0076] The construction of the aforementioned DNN 700 involves beginning to generate a useful machine learning model. The accuracy of the inference generated by this DNN requires selecting an appropriate activation function and then adjusting each weight in the entire model to provide accurate output. This process of adjusting these weights is called "training." Training a DNN or other type of neural network requires a collection of training data with known characteristics. For example, when a DNN aims to predict the probability that an input image of a piece of fruit is an apple or a pear, the training data will include many different fruit images, typically including not only apples and pears but also plums, oranges, and other types of fruit. Training requires preprocessing the image data corresponding to each image according to normalization and / or feature extraction techniques known in the art to produce input features for the DNN, which are then fed into the network. In the example above, these features are fed into the neurons of the input layer 702.

[0077] Subsequently, each neuron 600 of the DNN 700 performs its corresponding activation function operation, and the output of each neuron 600 is weighted and fed forward to the next layer, and so on, until the output layer 708 generates the output. Afterward, the output(s) of the DNN can be compared with known or expected values. The output of the DNN can then be compared with the expected values, and the differences can be fed back through the network to modify the weights contained therein according to backpropagation algorithms known in the art. Using the model including the modified weights, the same image features can be input into the model again (e.g., neuron 600 of the input layer 702 of the DNN 700 described above) and generate new outputs. Training involves iterating the model over the body of training data and updating the weights at each iteration. Once the model output achieves sufficient accuracy (or the output has otherwise converged and the weight changes have little effect), the model is said to have been trained. The trained model can then be used to evaluate arbitrary input data whose properties are unknown beforehand and which the model has not previously considered (e.g., a new picture of a piece of fruit) and output the expected inference (e.g., the probability that the image is an image of an apple).

[0078] In embodiments, the ML engine 208, as described above, can be configured to enable the generation and training of machine learning models, such as deep neural networks as described above. Various platforms, such as Deep Learning (“Keras”) or TensorFlow, can allow the construction of untrained DNNs suitable for use with the ML engine 208, and subsequently train such models using user data 220. Alternatively, a pre-trained machine learning model (e.g., a DNN with optimal or near-optimal weights for a given problem) can be imported into the ML engine 208, which then accepts user data 220 as input for generating inference 112.

[0079] III. Example Mobile Device Implementation

[0080] Figure 8 This is a block diagram of an exemplary mobile device 802 that can implement the embodiments described herein. For example, mobile device 802 can be used to implement a protected personalization system 110, a protected personalization container 204, a personalization data processor 206, an ML engine 208, a personal data repository 210, and / or a personalization agent 202, and / or any components described therein and / or any steps in any flowchart 400 and / or flowchart 500. Figure 8As shown, mobile device 802 includes a variety of optional hardware and software components. Any component of mobile device 802 can communicate with any other component, although not all connections are shown for illustration purposes. Mobile device 802 can be any various computing device (e.g., cellular phone, smartphone, handheld computer, personal digital assistant (PDA), etc.) and can allow wireless two-way communication with one or more mobile communication networks 804 (such as cellular or satellite networks) or with a local area network or wide area network. Mobile device 802 can also be any various wearable computing device (e.g., smartwatch, augmented reality headset, etc.).

[0081] Mobile device 802 may include a controller or processor 810 (e.g., a signal processor, microprocessor, ASIC, or other control and processing logic circuitry device) for performing tasks such as signal encoding, data processing, input / output processing, power control, and / or other functions. Operating system 812 may control the allocation and use of components of mobile device 802 and provide support for one or more applications 814 (also referred to as "applications" or "apps"). Applications 814 may include common mobile computing applications (e.g., email applications, calendars, contact managers, web browsers, messaging applications) and any other computing applications (e.g., word processing applications, mapping applications, media player applications).

[0082] Mobile device 802 may include memory 820. Memory 820 may include non-removable memory 822 and / or removable memory 824. Non-removable memory 822 may include RAM, ROM, flash memory, hard disk, or other known memory devices or technologies. Removable memory 824 may include flash memory or a Subscriber Identity Module (SIM) card (which is known in GSM communication systems) or other known memory devices or technologies, such as a "smart card". Memory 820 may be used to store data and / or code for running operating system 812 and application 814. Example data may include web pages, text, images, sound files, video data, or other data to be sent to and / or received from one or more web servers or other devices via one or more wired or wireless networks. Memory 820 may be used to store subscriber identifiers such as International Mobile Subscriber Identity (IMSI) and device identifiers such as International Mobile Equipment Identity (IMEI). Such identifiers may be transmitted to a web server to identify users and devices.

[0083] Mobile device 802 may support one or more input devices 830 such as touchscreen 832, microphone 834, camera 836, physical keyboard 838, and / or trackball 840, and one or more output devices 850 such as speaker 852 and display 854. Other possible output devices (not shown) may include piezoelectric or other haptic output devices. Some devices may provide more than one input / output function. For example, touchscreen 832 and display 854 may be combined into a single input / output device. Input device 830 may include a Natural User Interface (NUI).

[0084] Multiple wireless modems 860 may be coupled to multiple antennas (not shown) and may support bidirectional communication between processor 810 and external devices, as well as is well understood in the art. Multiple modems 860 are generally shown and may include a cellular modem 866 for communicating with mobile communication network 804 and / or other radio-based modems (e.g., Bluetooth 864 and / or Wi-Fi 862). At least one of the multiple wireless modems 860 is generally configured to communicate with one or more cellular networks, such as a GSM network for data and voice communication within a single cellular network, between cellular networks, or between a mobile device and the Public Switched Telephone Network (PSTN).

[0085] The mobile device 802 may also include at least one input / output port 880, a power supply 882, a satellite navigation system receiver 884 such as a Global Positioning System (GPS) receiver, an accelerometer 886, and / or a physical connector 880 (which may be a USB port), an IEEE 1594 (FireWire) port, and / or an RS-232 port. The illustrated components of the mobile device 802 are not essential or exhaustive; as those skilled in the art will understand, any component can be removed and others can be added.

[0086] In this embodiment, the mobile device 802 is configured to implement the protected personalization system 110, the protected personalization container 204, the personalization data processor 206, the ML engine 208, the personal data repository 210, and / or the personalization agent 202, and / or any of the foregoing features of any component described therein and / or any step in any flowchart 400 and / or flowchart 500. The computer program logic for performing the functions of these devices may be stored in memory 820 and executed by processor 810.

[0087] IV. Example Computer System Implementation

[0088] Each of the protected personalization system 110, the protected personalization container 204, the personalization data processor 206, the ML engine 208, the personal data repository 210 and / or the personalization agent 202, and the flowcharts 400 and / or 500 can be implemented in hardware or in hardware combined with software and / or firmware. For example, the protected personalization system 110, the protected personalization container 204, the personalization data processor 206, the ML engine 208, the personal data repository 210 and / or the personalization agent 202, and the flowcharts 400 and / or 500 can be implemented as computer program code / instructions configured to be executed in one or more processors and stored in a computer-readable storage medium. Alternatively, the protected personalization system 110, the protected personalization container 204, the personalization data processor 206, the ML engine 208, the personal data repository 210 and / or the personalization agent 202, and the flowcharts 400 and / or 500 can be implemented as hardware logic / circuit devices.

[0089] For example, in an embodiment, one or more of the protected personalization system 110, the protected personalization container 204, the personalization data processor 206, the ML engine 208, the personal data repository 210, and / or the personalization agent 202, as well as flowcharts 400 and / or 500, can be implemented together in an SoC in any combination. The SoC may include an integrated circuit chip that includes a processor (e.g., a central processing unit (CPU), a microcontroller, a microprocessor, a digital signal processor (DSP), one or more graphics processing units (GPUs), etc.), memory, one or more communication interfaces, and / or other circuitry, and may optionally execute received program code and / or include embedded firmware to perform functions.

[0090] also, Figure 9 Exemplary implementations of a computing device 900 in which various embodiments may be implemented are depicted. For example, user equipment 138 and servers(s)140 may be implemented in one or more computing devices similar to computing device 900 in static or mobile computer embodiments, including one or more features and / or alternative features of computing device 900. The description of computing device 900 provided herein is provided for illustrative purposes only and is not intended to be limiting. Embodiments may be implemented in other types of computer systems as known to those skilled in the art(s).

[0091] like Figure 9As shown, computing device 900 includes one or more processors (referred to as processor circuitry 902), system memory 904, and a bus 906 coupling various system components, including system memory 904, to processor circuitry 902. Processor circuitry 902 is implemented as a central processing unit (CPU), microcontroller, microprocessor, and / or other physical hardware processor circuitry using one or more physical hardware electronic circuitry device elements and / or integrated circuit devices (semiconductor material chips or dies). Processor circuitry 902 can execute program code stored in a computer-readable medium, such as program code for operating system 930, application program 932, other programs 934, etc. Bus 906 represents one or more bus structures from a variety of bus architectures, including memory buses or memory controllers, peripheral buses, accelerated graphics ports, and processor or local buses using any of the various bus architectures. System memory 904 includes read-only memory (ROM) 908 and random access memory (RAM) 910. Basic input / output system 912 (BIOS) is stored in ROM 908.

[0092] The computing device 900 also includes one or more of the following drives: a hard disk drive 914 for reading and writing to a hard disk, a disk drive 916 for reading or writing to a removable disk 918, and an optical disc drive 920 for reading or writing to a removable optical disc 922 such as a CD-ROM, DVD-ROM, or other optical media. The hard disk drive 914, disk drive 916, and optical disc drive 920 are connected to the bus 906 via a hard disk drive interface 924, a disk drive interface 926, and an optical disc drive interface 928, respectively. These drives, along with their associated computer-readable media, provide a non-volatile storage for computer-readable instructions, data structures, program modules, and other data. While hard disks, removable disks, and removable optical discs have been described, other types of hardware-based computer-readable storage media, such as flash memory cards, digital video discs, RAM, ROM, and other hardware storage media, can also be used to store data.

[0093] Multiple program modules may be stored on a hard disk, magnetic disk, optical disk, ROM, or RAM. These programs include an operating system 930, one or more application programs 932, other programs 934, and program data 936. Application programs 932 or other programs 934 may include, for example, computer program logic (e.g., computer program code or instructions) for implementing the protected personalization system 110, the protected personalization container 204, the personalization data processor 206, the ML engine 208, the personal data repository 210, and / or the personalization agent 202, as well as flowcharts 400 and / or 500 (including any appropriate steps of flowcharts 400 and / or 500) and / or other embodiments described herein.

[0094] Users can input commands and information into computing device 900 through input devices such as keyboard 938 and pointing device 940. Other input devices (not shown) may include microphone, joystick, game controller, satellite dish, scanner, touchscreen and / or touch tablet, voice identification system for receiving voice input, gesture identification system for receiving gesture input, etc. These and other input devices are typically connected to processor circuitry 902 via serial port interface 942 coupled to bus 906, but may also be connected via other interfaces such as parallel port, game port, or universal serial bus (USB)

[0095] Display screen 944 is also connected to bus 906 via an interface such as video adapter 946. Display screen 944 may be external to computing device 900 or incorporated within computing device 900. Display screen 944 may display information and serve as a user interface for receiving user commands and / or other information (e.g., via touch, finger gestures, virtual keyboard, etc.). In addition to display screen 944, computing device 900 may also include other peripheral output devices (not shown), such as speakers and printers.

[0096] Computing device 900 is connected to network 948 (e.g., the Internet) via an adapter or network interface 950, modem 952, or other means for establishing communication over the network. The modem 952, which may be internal or external, can be connected to bus 906 via serial port interface 942, such as... Figure 9 As shown, it can also be connected to bus 906 using another interface type that includes a parallel interface.

[0097] As used herein, the terms “computer program medium,” “computer-readable medium,” and “computer-readable storage medium” are used to refer to physical hardware media, such as a hard disk associated with hard disk drive 914, removable disk 918, removable optical disk 922, other physical hardware media such as RAM, ROM, flash memory cards, digital video disks, zip disks, MEM, nanotechnology-based memory devices, and other types of physical / tangible hardware storage media. Such computer-readable storage media are distinct from and do not overlap with communication media (which are not included in communication media). Communication media implement computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves. The term “modulated data signal” means a signal in which one or more characteristics of its properties are set or changed in a manner that encodes information. By way of example and not limitation, communication media include wireless media such as acoustic, RF, infrared, and other wireless media, as well as wired media. Embodiments also relate to such communication media that are distinct from and do not overlap with embodiments relating to computer-readable storage media.

[0098] As noted above, computer programs and modules (including application program 932 and other programs 934) may be stored on a hard disk, magnetic disk, optical disk, ROM, RAM, or other hardware storage medium. Such computer programs may also be received via network interface 950, serial port interface 942, or any other interface type. When executed or loaded by an application, such computer programs enable computer 802 to implement the features of the embodiments described herein. Therefore, such computer programs represent the controller of computer device 900.

[0099] The embodiments also relate to computer program products comprising computer code or instructions stored on any computer-readable medium. Such computer program products include hard disk drives, optical disk drives, memory device packages, memory sticks, memory cards, and other types of physical storage hardware.

[0100] V. Additional Example Implementations

[0101] This paper provides a method for providing secure hyperpersonalization in a computing device. The method includes: storing feature data in a secure virtual container running on the computing device and isolated from an operating system running on the computing device; selecting a first feature set from the stored feature data; generating a first inference value for a first inference category based at least in part on the first feature set; and notifying an agent outside the secure virtual container of the availability of the first inference value corresponding to the first inference category; and in the agent within the computing device: receiving the first inference value from the secure virtual container; and providing the first inference value to at least one running process in the operating system, wherein the at least one running process is configured to perform personalization operations based at least in part on the first inference value.

[0102] In an embodiment of the aforementioned method, the first inference value is generated by a first inference generation model included in the secure virtual container.

[0103] In another embodiment of the aforementioned method, the feature data and the first inference generation model are securely maintained in a manner inaccessible outside the secure virtual container.

[0104] In one embodiment of the aforementioned method, the feature data includes at least one of the following: transient data, personal data of at least one user specific to the computing device, and a policy to be implemented by the computing device.

[0105] In embodiments of the foregoing method, transient data includes short-term operational data collected by the computing device within a predetermined recent time interval. The operational data includes at least one of the following: the lock status of the computing device, the identifier of at least one user of the computing device, the location of the computing device, policy violations on the computing device, the identifier of a person physically present with at least one user of the computing device, tasks being performed on the computing device, alerts, SMS or MMS messages, emails, memory and / or file access signals, application status, and application-specific data.

[0106] In another embodiment of the aforementioned method, the personal data specific to at least one user includes at least one of the following types of data corresponding to at least one user: risk profile, financial profile, habits, hobbies, relationships, demographic data, and application personalization data.

[0107] In one embodiment of the aforementioned method, the first inference generation model includes a properly trained machine learning model configured to output a first inference value.

[0108] In embodiments of the aforementioned method, the secure virtual container and the operating system are each executed via a shared management program.

[0109] In another embodiment of the foregoing method, the method further includes: receiving additional feature data at a secure virtual container at a time after receiving the feature data, the additional feature data reflecting at least changes in a first feature set; merging the additional feature data with the first feature set to provide a second feature set; providing the second feature set to a first inference generation model, the first inference generation model being further configured to: generate a second inference value at least in part based on the second feature set; and providing the second inference value to the agent in response to a request received from the agent for an inference value corresponding to a first inference category, and at a time after receiving the additional feature data.

[0110] This document provides a system for providing secure hyperpersonalization. In one embodiment, the system includes: one or more processor circuits; one or more memory devices connected to the one or more processor circuits, the one or more memory devices storing computer program logic for execution by the one or more processor circuits. In one embodiment, the computer program logic includes: an operating system; a secure virtual container isolated from the operating system; a personalization agent executing in the operating system; a personalization data processor executing in the secure virtual container and configured to: store feature data; select a first feature set from the stored feature data; generate a first inference value for a first inference category based at least in part on the first feature set; and notify the personalization agent of the availability of the first inference value corresponding to the first inference category; and the personalization agent is configured to: receive the first inference value from the personalization data processor; and provide the first inference value to at least one running process in the operating system, wherein the at least one running process is configured to: perform personalization operations based at least in part on the first inference value.

[0111] In another embodiment of the aforementioned system, the first inference value is configured to be generated by a first inference generation model included in the personalized data processor.

[0112] In an additional embodiment of the aforementioned system, the first inference generation model includes a properly trained machine learning model configured to output a first inference value.

[0113] In one embodiment of the aforementioned system, the secure virtual container is further configured to securely maintain the feature data and the first inference generation model such that the feature data and the first inference generation model are each inaccessible outside the secure virtual container.

[0114] In another embodiment of the aforementioned system, the feature data includes at least one of the following: transient data, personal data of at least one user specific to the computing device, and a policy to be implemented by the computing device.

[0115] In an additional embodiment of the aforementioned system, transient data includes short-term operational data collected by the computing device within a predetermined recent time interval. The operational data includes at least one of the following: the lock status of the computing device, the identifier of at least one user of the computing device, the location of the computing device, policy violations on the computing device, the identifier of a person physically present with at least one user of the computing device, tasks being performed on the computing device, alerts, SMS or MMS messages, emails, memory and / or file access signals, application status, and application-specific data.

[0116] In one embodiment of the aforementioned system, personal data specific to at least one user includes at least one of the following types of data corresponding to at least one user: risk profile, financial profile, habits, hobbies, relationships, demographic data, and application personalization data.

[0117] In another embodiment of the aforementioned system, the secure virtual container and the operating system are each configured to execute via a shared management program.

[0118] In an additional embodiment of the aforementioned system, the personalized data processor is further configured to: receive additional feature data at a time after receiving the feature data, the additional feature data reflecting at least changes in the first feature set; merge the additional feature data with the first feature set to provide a second feature set; provide the second feature set to a first inference generation model, the first inference generation model being further configured to generate a second inference value based at least in part on the second feature set; and, in response to a request received from the personalized agent for an inference value corresponding to a first inference category, and at a time after receiving the additional feature data, provide the second inference value to the personalized agent.

[0119] A computer program product is provided herein, comprising a computer-readable storage device having computer program logic recorded thereon, the computer program logic, when executed by at least one processor of a computing device, causing the at least one processor to perform operations for providing secure hyper-personalization to a user, the operations including: executing a personalization agent in an operating system running on the computing device; executing a secure virtual container on the computing device, the secure virtual container being isolated from the operating system, the secure virtual container being configured to: store feature data; select a first feature set from the stored feature data; generate a first inference value for a first inference category based at least in part on the first feature set; and notify the personalization agent of the availability of the first inference value corresponding to the first inference category; and the personalization agent being configured to: receive the first inference value from the secure virtual container; and provide the first inference value to at least one running process in the operating system, wherein the at least one running process is configured to: perform personalization operations based at least in part on the first inference value.

[0120] In another embodiment of the aforementioned computer program product, the secure virtual container is further configured to: receive additional feature data at a time after receiving feature data, the additional feature data reflecting at least a change in the first feature set; combine the additional feature data with the first feature set to provide a second feature set; generate a second inference value for a first inference category based at least in part on the second feature set; and, in response to a request received from the personalization agent for an inference value corresponding to the first inference category, provide the second inference value to the personalization agent at a time after receiving the additional feature data.

[0121] VI. Conclusion

[0122] Although various embodiments of the disclosed subject matter have been described above, it should be understood that they are presented by way of example only and not limitation. Those skilled in the art will understand that various changes in form and detail may be made without departing from the spirit and scope of the embodiments as defined in the appended claims. Therefore, the breadth and scope of the disclosed subject matter should not be limited by any of the exemplary embodiments described above, but should be limited only by the appended claims and their equivalents.

Claims

1. A method for providing secure hyperpersonalization in a computing device, comprising: In a secure virtual container running on the computing device and isolated from the operating system running on the computing device: The storage includes feature data that includes policy data for the use of the computing device and status data representing the current use of the computing device. Select a first feature set from the stored feature data; At least in part based on the first feature set, a first inference value is generated for a first inference category, the first inference value representing the probability that a proposition about the user of the computing device is true; as well as The agent outside the secure virtual container is notified of the availability of the first inference value corresponding to the first inference category; as well as In the agent in the computing device: Receive the first inference value from the secure virtual container; as well as The first inference value is provided to at least one running process in the operating system, wherein the at least one running process is configured to perform personalized operations based at least in part on the first inference value.

2. The method of claim 1, wherein the first inference value is generated by a first inference generation model included in the secure virtual container.

3. The method of claim 2, wherein the feature data and the first inference generation model are securely maintained so that they are each inaccessible outside the secure virtual container.

4. The method of claim 1, wherein the feature data further comprises at least one of the following: transient data, or personal data specific to at least one user of the computing device.

5. The method of claim 4, wherein the transient data includes short-term operational data collected by the computing device within a predetermined recent time interval, the short-term operational data including at least one of the following: the lock status of the computing device, the identifier of the at least one user of the computing device, the location of the computing device, policy violations on the computing device, the identifier of a person physically present with the at least one user of the computing device, tasks being performed on the computing device, alerts, SMS or MMS messages, emails, memory and / or file access signals, application status, and application-specific data.

6. The method of claim 4, wherein the personal data specific to at least one user includes at least one of the following: risk profile, financial profile, habits, hobbies, relationships, demographic data, and application-specific data.

7. The method of claim 2, wherein the first inference generation model comprises a properly trained machine learning model configured to output the first inference value.

8. The method of claim 1, wherein the secure virtual container and the operating system are each executed through a shared hypervisor.

9. The method according to claim 2, further comprising: After receiving the feature data, additional feature data is received at the secure virtual container, the additional feature data reflecting at least the changes in the first feature set; The additional feature data is combined with the first feature set to provide a second feature set; The second feature set is provided to the first inference generation model, and the first inference generation model is further configured to generate a second inference value based at least in part on the second feature set; as well as In response to a request received from the agent for a second inference value corresponding to the first inference category, and at a time after the receipt of the additional feature data, the second inference value is provided to the agent.

10. A system comprising: One or more processor circuits; One or more memory devices are connected to the one or more processor circuits, the one or more memory devices storing computer program logic for execution by the one or more processor circuits, the computer program logic including: operating system; Secure virtual container, isolated from the operating system; The personalized data processor, executed within the secure virtual container, is configured to: The storage includes feature data that includes policy data for the use of computing devices and status data representing the current use of the computing devices. Select a first feature set from the stored feature data; At least in part based on the first feature set, a first inference value is generated for a first inference category, the first inference value representing the probability that a proposition concerning the user of the computing device is true; and Notify the availability of the first inference value corresponding to the first inference category; and The personalized agent executes in the operating system and is configured as follows: Receive the first inference value from the personalized data processor; and The first inference value is provided to at least one running process in the operating system, wherein the at least one running process is configured to perform personalized operations based at least in part on the first inference value.

11. The system of claim 10, wherein the first inference value is configured to be generated by a first inference generation model included in the personalized data processor.

12. The system of claim 11, wherein the first inference generation model comprises a properly trained machine learning model configured to output the first inference value.

13. The system of claim 11, wherein the secure virtual container is further configured to: securely maintain the feature data and the first inference generation model such that the feature data and the first inference generation model are each inaccessible outside the secure virtual container.

14. The system of claim 10, wherein the feature data further comprises at least one of the following: transient data, or personal data specific to at least one user of the computing device.

15. The system of claim 14, wherein the transient data includes short-term operational data collected by the computing device within a predetermined recent time interval, the short-term operational data including at least one of the following: the lock status of the computing device, the identifier of the at least one user of the computing device, the location of the computing device, policy violations on the computing device, the identifier of a person physically present with the at least one user of the computing device, tasks being performed on the computing device, alerts, SMS or MMS messages, emails, memory and / or file access signals, application status, and application-specific data.

16. The system of claim 14, wherein the personal data specific to at least one user includes at least one of the following: risk profile, financial profile, habits, hobbies, relationships, demographic data, and application-specific data.

17. The system of claim 10, wherein the secure virtual container and the operating system are each configured to execute via a shared hypervisor.

18. The system of claim 11, wherein the personalized data processor is further configured to: After receiving the feature data, additional feature data is received, which at least reflects changes in the first feature set; The additional feature data is combined with the first feature set to provide a second feature set; The first inference generation model is provided with the second feature set, and the first inference generation model is further configured to generate a second inference value based at least in part on the second feature set; and In response to a request received from the personalized agent for a second inference value corresponding to the first inference category, and at a time after the receipt of the additional feature data, the second inference value is provided to the personalized agent.

19. A computer program product comprising a computer-readable storage device having computer program logic recorded thereon, the computer program logic causing the at least one processor of a computing device to perform operations, the operations including: A secure virtual container is executed on the computing device, the secure virtual container being isolated from the operating system running on the computing device, and the secure virtual container is configured to: The storage includes feature data that includes policy data for the use of the computing device and status data representing the current use of the computing device. Select a first feature set from the stored feature data; At least in part based on the first feature set, a first inference value is generated for a first inference category, the first inference value representing the probability that a proposition about the user of the computing device is true; as well as Notify the availability of the first inference value corresponding to the first inference category; as well as A personalized agent that runs in the operating system, the personalized agent being configured as follows: Receive the first inference value from the secure virtual container; as well as The first inference value is provided to at least one running process in the operating system, wherein the at least one running process is configured to perform personalized operations based at least in part on the first inference value.

20. The computer program product of claim 19, wherein the secure virtual container is further configured to: After receiving the feature data, additional feature data is received, which at least reflects changes in the first feature set; The additional feature data is combined with the first feature set to provide a second feature set; At least in part based on the second feature set, a second inference value is generated for the first inference category; and In response to a request received from the personalized agent for a second inference value corresponding to the first inference category, and at a time after the receipt of the additional feature data, the second inference value is provided to the personalized agent.

Citation Information

Patent Citations

  • User profile selection using contextual authentication

    US20170180363A1