Methods, apparatuses, and articles of manufacture to process data
By using secure enclave computing devices and virtual machine technology in the entrusted computing process, the problem of lack of trust between the client and the computing entity is solved, data and computing resources are securely protected, and the integrity and privacy of the computing results are ensured.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ARM IP
- Filing Date
- 2020-09-03
- Publication Date
- 2026-05-08
AI Technical Summary
In the process of commissioned computing, the lack of a trust framework between the commissioning party and the computing entity makes it difficult to guarantee the security of sensitive data and proprietary parameters, and poses a risk of leakage and unauthorized access.
By employing a secure enclave computing device as the root of trust, programs and data are hosted in a secure processing environment through virtual machines. Encryption technology and authentication processes are used to ensure the security and integrity of data transmission, preventing unauthorized access and attacks.
It provides protection for data and computing resources during the delegated computing process, ensuring that data is not disclosed and computing resources are not damaged, establishing a foundation of trust among multiple parties, and preventing eavesdropping and attacks.
Smart Images

Figure CN114503110B_ABST
Abstract
Description
Technical Field
[0001] This disclosure generally relates to computing resources that can be used to provide secure computing resources for computing clients. Background Technology
[0002] There are strong economic, practical, and / or technological incentives for deferring and / or delegating various computational tasks among multiple parties. For example, such computational delegation could include delegating computation to the “cloud”—where a cloud server acts as the delegator, providing the computational service. Other examples could include, for instance, pedigree testing services (such as 23andMe) that provide computational services and / or perform computations, for example, on genetic data extracted from cheek swabs provided by clients. As the number of software- and / or computation-based services offered increases, the amount of computational delegation will inevitably increase as well. Summary of the Invention
[0003] According to a first aspect of this disclosure, a method for data processing is provided, the method comprising: transmitting one or more messages to at least one program input provider entity, the one or more messages including a first cryptographic attribute of at least a portion of system code on at least one computing device, the system code including an implementation of a virtual machine capable of hosting a program to be provided by the at least one program input provider entity; and receiving one or more messages transmitted from the at least one program input provider entity, the one or more messages including a program to be hosted by the virtual machine, the one or more messages having been transmitted by the at least one program input provider entity at least in part in response to a comparison of the first cryptographic attribute with a first cryptographic expression, wherein the system code is used to prevent code of the program from being exposed outside a secure processing environment (SPE).
[0004] According to a second aspect of this disclosure, an apparatus for data processing is provided, the apparatus comprising: a transceiver device for transmitting messages to and receiving messages from a physical transmission medium; and one or more processors for: initiating, via the transceiver device, the transmission of one or more messages to at least one program input provider entity, the one or more transmitted messages including a first cryptographic attribute of at least a portion of system code on the at least one computing device, the system code including an implementation of a virtual machine capable of hosting a program to be provided by the at least one program input provider entity; and obtaining one or more messages received at the transceiver device and transmitted from the at least one program input provider entity, the one or more messages including signal and / or status representation codes of a program hosted by the virtual machine, the one or more messages having been transmitted by the at least one program input provider entity at least in part in response to a comparison of the first cryptographic attribute with a first cryptographic expression, wherein the system code is used to prevent code of the program from being exposed outside a secure processing environment (SPE).
[0005] According to a third aspect of this disclosure, an article of manufacture for data processing is provided, the article of manufacture comprising: a non-transitory storage medium including computer-readable instructions stored thereon, the computer-readable instructions being executable by a computing device to: initiate the transmission of one or more messages to at least one program input provider entity, the one or more messages including a first cryptographic attribute of at least a portion of system code on the at least one computing device, the system code including an implementation of a virtual machine capable of hosting a program to be provided by the at least one program input provider entity; and receive and transmit one or more messages from the at least one program input provider entity, the one or more messages including signal and / or status representation codes of a program hosted by the virtual machine, the one or more messages having been transmitted by the at least one program input provider entity at least in part in response to a comparison of the first cryptographic attribute with a first cryptographic expression, wherein the system code is used to prevent code of the program from being exposed outside a secure processing environment (SPE). Attached Figure Description
[0006] The claimed subject matter is specifically pointed out and clearly claimed at the end of this specification. However, regarding the organization and / or methods of operation, as well as their objects, features, and / or advantages, a better understanding can be obtained by referring to the following detailed description, in conjunction with the accompanying drawings, wherein:
[0007] Figure 1 This is a schematic diagram of an exemplary system for computing resources for a computing client, according to an implementation scheme;
[0008] Figures 2 to 4 This is an exemplary message flow diagram illustrating the exchange of messages between and / or within entities according to a specific implementation scheme to provide computing resources for computing clients;
[0009] Figures 5 to 7 This is a flowchart of an exemplary process to be performed by the participating entities according to a specific implementation scheme, the computation taking place in a delegated computing environment; and
[0010] Figure 8 This is a schematic diagram illustrating a specific implementation of an exemplary computing environment associated with facilitating multi-party and / or commissioned computing processes, according to an implementation scheme. Detailed Implementation
[0011] The accompanying drawings, which form part of the description, are referenced in the following detailed description. Throughout the description, similar numerals may denote similar parts that are corresponding and / or similar. It should be understood that the drawings are not necessarily drawn to scale, such as for simplification and / or clarity. For example, the dimensions of some aspects may be enlarged relative to others. Furthermore, it should be understood that other embodiments may be utilized. Additionally, structural and / or other changes may be made without departing from the claimed subject matter. The term "claimed subject matter" as used throughout this specification refers to the subject matter intended to be covered by one or more claims or any part thereof, and is not necessarily intended to refer to the entire set of claims, a particular combination of claims (e.g., method claims, apparatus claims, etc.), or a particular claim. It should also be noted that directions and / or references (e.g., such as above, below, top, bottom, etc.) are used to facilitate discussion of the drawings and are not intended to limit the application of the claimed subject matter. Therefore, the following detailed description should not be construed as limiting the claimed subject matter and / or equivalents.
[0012] Throughout this specification, references to a particular embodiment, an embodiment, an implementation, an implementation, etc., mean that a particular feature, structure, characteristic, etc., described with respect to a particular embodiment and / or implementation is included in at least one embodiment and / or implementation of the claimed subject matter. Therefore, the frequent appearance of such phrases, for example, throughout this specification, is not necessarily intended to refer to the same embodiment and / or implementation or any particular embodiment and / or implementation. Furthermore, it should be understood that the described particular features, structures, characteristics, etc., can be combined in various ways in one or more embodiments and / or implementations, and are therefore within the contemplated scope of the claims. Of course, in general, as is always the case with respect to the specification of a patent application, these and other issues are susceptible to variation in a particular context of use. In other words, throughout this disclosure, the specific context of the description and / or use provides helpful guidance regarding reasonable reasoning to be derived; however, similarly, "in that context" generally refers, without further limitation, at least to the context of this patent application.
[0013] Currently, commissioned computations may rely on sharing secret and / or proprietary parameters with the commissioning party. The commissioning party (e.g., an agent who appoints the commissioning party to perform computations on their behalf) may allocate and / or otherwise acquire some secret and / or proprietary parameters to perform such computations. This may require the commissioning party to meet certain minimum trust thresholds to satisfy the commissioning party's requirements. For relatively low-value computations commissioned to major cloud providers such as Amazon, Google, or Microsoft, this threshold may be easily met, for example, because major cloud providers are unlikely to risk reputational damage by monitoring or caching the results of their clients' computations. For more sensitive computations—such as those related to health, finance, commerce, or even national security—the minimum trust threshold may also be more difficult to meet, if possible. In particular, health departments possess vast amounts of valuable records that can be mined by stakeholders to extract knowledge often considered important to the wider society (e.g., pharmaceutical companies developing new drugs, demographers conducting population-scale studies, think tanks formulating public policy—to name just three examples). The openness of such records could lead to significant social progress.
[0014] However, given the risk of unintentionally disclosing records and public hostility towards the idea of record sharing, health departments and other guardians of sensitive records conservatively choose not to share them. Instead, they may act as repositories, stockpiling records. However, forming record repositories may be entirely justifiable for one or more of the following reasons:
[0015] 1. Even in other circumstances where computational delegation may be expected to meet some acceptable minimum trust thresholds, accidental disclosure of secrets and / or proprietary parameters can frequently occur. While reputational damage can often be a strong incentive for a company to "do the right thing," it may still remain unexplained as an unfortunate accident, malfeasance, and / or criminal intent by an entity in order to gain access to secrets and / or proprietary parameters.
[0016] 2. The social, legal, and / or business environment in which a computational commission exists may change. Therefore, a computational commission may be coerced and / or induced to share and / or sell such secret and / or proprietary parameters to third parties without establishing control by the founders of the secret and / or proprietary parameters in order to maximize profits, unless special care is taken to prevent this from happening. A computational commission considered trustworthy today may not be trustworthy tomorrow, but sharing secret and / or proprietary parameters may be inherently an irreversible act, as once released, the secret and / or proprietary parameters may become difficult to control, manage, and / or track.
[0017] 3. The value and / or sensitivity of shared secrets and / or proprietary parameters may only become apparent after such secrets and / or proprietary parameters have been shared. For example, the true value and insights that can be extracted from a particular set of secrets and / or proprietary parameters may not yet be fully understood by the public and / or experts. Furthermore, the ability to derive value and / or insights from a particular proprietary parameter may continue to increase. A particular set of secrets and / or proprietary parameters that has low perceived value today may become extremely valuable tomorrow.
[0018] 4. Seemingly reasonable anonymization methods used for sensitive sets of secrets and / or proprietary parameters (such as removing obviously identifiable fields like names) may not be entirely effective. This is especially true if an adversary has the ability to cross-reference entries across multiple sets of secrets and / or proprietary parameters, resulting in multiple instances of deanonymization within the so-called anonymized secrets and / or proprietary parameters. Furthermore, it can be difficult to estimate which fields in the proprietary parameter set might be useful for deanonymization before release. For example, one study found that 87% of the U.S. population can be uniquely identified by their zip code, gender, and date of birth. In another prominent example, the anonymized proprietary parameters released by Netflix still contained enough attributes to easily link entries to individuals.
[0019] Therefore, it is clear that there is a risk of sharing secrets and / or proprietary parameters that should not have been shared in hindsight. Similarly, it is clear that there is a risk of previously shared secrets and / or proprietary parameters being unintentionally disclosed.
[0020] There can be a fundamental tension between delegation, the sharing of secret and / or proprietary parameters, and strong guarantees of privacy. While privacy itself can be sold as a de facto social benefit, note that the motivations for privacy can be more specific, as it can be an economic impetus that allows value and insights to be released from repositories of records that might otherwise be locked away. Strong, verifiable privacy guarantees allow custodians of repositories of records to share the contents of their respective records while maintaining control over who has access to such records and how. Furthermore, under confidentiality guarantees, custodians of sensitive records are free to delegate the handling of secret and / or proprietary parameters to other parties, knowing that these secret and / or proprietary parameters cannot be shared intentionally or unintentionally—even if the custodian's circumstances and / or business model change. In this sense, privacy can include the means of asserting ownership and control over secret and / or proprietary parameters.
[0021] In implementations of secure delegated computing paradigms, multiple distinct parties (e.g., computing entities, program input provider entities, and / or program provider entities) may lack an established framework of mutual trust. In practice, a computing entity may maintain hardware and / or software resources to perform computing services for a client entity, for example, under a contractual arrangement. For instance, a program input provider entity may own and / or control various sets of secret and / or proprietary parameters to be processed by hardware and / or software resources owned and / or controlled by such a computing entity. Furthermore, a computing entity may perform services to process the program input provider entity's secret and / or proprietary parameter sets according to computer-readable instructions and / or code provided by the program input provider entity (e.g., under separate contractual arrangements with the computing entity and / or program input provider entity).
[0022] In specific implementations, the program provider entity may own and / or control the proprietary program "π" (e.g., expressed as code and / or computer-readable instructions stored as signals and / or states on a non-transitory storage medium), which includes trade secrets (e.g., processing techniques and / or algorithms) to be hidden from other parties (such as, for example, a computing entity (e.g., to execute π) and / or the client program input provider entity). The program input provider may own and / or control certain secrets and / or proprietary parameters that can be processed in a certain way according to the proprietary program π. D (For example, stored as signals and / or states representing an array of machine words). Additionally, the computing entity (which may be different from the one that owns and / or controls) D The program input provider and the program provider that owns and / or controls π may at least partially base their operations on... D To perform π to provide the calculation result π( D ).
[0023] In specific scenarios, provideD The program input provider may be concerned about disclosing it to other parties. D And / or π(D), the other party including the program provider entity that owns and / or controls π and / or will execute π to determine π( D The computational entity. Provided D The program input provider may also be concerned that the program provider that owns and / or controls π provides the computational entity that needs to calculate π(D) with the correct program (e.g., the correct and / or latest version, not an alternative program). Additionally, the program provider entity that owns and / or controls π may be concerned about providing, for example, the program that provides... D The program input provider and / or to perform π to calculate π ( D The entity that calculates π discloses details and / or proprietary secrets regarding the content of π. Furthermore, it has been agreed that the calculation of π (…) D The computational entity of ) may be concerned about determining π by performing π( D This could potentially damage hardware and / or software computing resources.
[0024] As mentioned above, providing D The program input provider entity, the program provider entity that provides π, and / or the execution entity that performs π to calculate π ( D The computational entities involved may lack an established framework of mutual trust. Furthermore, any primary party may assume that the other two parties are actively cooperating to harm the primary party. Nevertheless, in order to achieve the computational result π ( D All three parties may wish to cooperate. In addition to the concerns mentioned above, the aforementioned entities may also be concerned that other parties may be eavesdropping and / or launching proactive attacks, such as through observation and / or caching of information provided. D The program input provider entity, the program provider entity that provides π, and / or the execution entity that performs π to calculate π ( D Plaintext messages transmitted between and / or within computing entities.
[0025] According to the implementation plan, calculate π( D The computing entities can employ one or more secure enclave computing devices as part of a secure processing environment (SPE) to collectively participate in computing π. D When calculating π, a root of trust is provided among the parties. D The authentication reports transmitted between and / or among the participants provide at least some guarantees, namely, that details and / or proprietary secrets regarding the content of π will not be disclosed, and that secrets and / or proprietary parameters will be protected. D It will not be disclosed that the program provider entity that owns and / or controls π provides the correct program, and / or guarantees that the computing resources owned and / or controlled by the computing entity will not be used in attempts to compute π. D It was damaged during the calculation of π( ). In the implementation scheme, π( ) is calculated.D The computational entity of π can employ one or more secure enclave computing devices to at least partially perform π to determine π( D ). Providers of one or more such secure enclave computing devices may include neutral and / or trusted parties to verify and / or authenticate the computation of π ( D The authentication report transmitted between and / or among the participants during the collective participation calculation of π ( D This provides a root of trust among all parties.
[0026] For simplicity, the above description refers to the procedure π to be provided by a unilateral party / entity, and the secrets and / or proprietary parameters to be provided by a unilateral party / entity. D To be used to calculate the result π in SPE ( D In a specific implementation, components of program π may be supplied by multiple different parties for integration into the SPE. For example, multiple different program provider entities may provide component modules to be linked and / or compiled at the computing device within the SPE to execute as a single program. Additionally, secret and / or proprietary parameters... D Input can be provided by multiple different program input provider entities for processing in the SPE to determine the result π. D ).
[0027] Figure 1 This is a schematic diagram of an exemplary system 100 including computing resources for computing clients according to an embodiment. According to the embodiment, a program provider entity 120 (e.g., providing program π), a program input provider entity 110 (e.g., secrets and / or proprietary parameters) D (the provider) and computing entity 130 (e.g., calculating π( D )) can exchange messages through a communication network to at least partially process secret and / or proprietary parameters to provide calculation results (e.g., π( D In the implementation scheme, the program input provider entity 110 may transmit secret and / or proprietary parameters (e.g., D The program provider entity 120 may maintain the program (e.g., for determining how to handle secret and / or proprietary parameters) as signals and / or states stored in storage device 119, and the computing entity 130 may include a secure enclave computing device 132 to execute the program provided by the program provider entity 120 to determine the calculation result (e.g., to calculate π). D )).
[0028] As mentioned above, although Figure 1A single program input provider entity 110 and a single program provider entity 120 are shown, but it should be understood that a particular implementation may include multiple different program input provider entities (e.g., providing different parts to be processed to determine secret and / or proprietary parameters to determine the computation result) and / or multiple different program provider entities (e.g., providing different modules to be linked and compiled at the SPE to execute to provide the computation result).
[0029] In this context, as referred to herein, a “secure enclave computing device” means a combination of software and hardware features integrated to provide an isolated computing environment within a larger computing environment, thereby providing one or more guarantees for applications executing within the secure enclave computing device. In a particular embodiment, a secure enclave computing device may include a processing environment within a larger computing system, wherein 1) memory, 2) cryptographic keys, and / or 3) instruction sets are maintained separate from the computing resources of such larger computing system. For example, a secure enclave computing device may include a processor that executes separately from the processor controlling the larger computing system, and may include memory that cannot be accessed by the operating system of the larger computing system (e.g., physically separate memory and / or control encryption of signals and / or states stored in shared memory). In an exemplary embodiment, a secure enclave computing device may include computing resources to perform at least partially according to Intel... ® Software Protection Extensions (Intel) ® Computer-readable instructions formatted in SGX format. However, it should be understood that this is merely an example of how computer-readable instructions can be formatted for execution by computing resources in a secure enclave computing device, and the subject matter for which protection is claimed is not limited in this respect.
[0030] According to the implementation, transport server 134 and transport clients 114 and 124 may establish and / or maintain a transport layer infrastructure (e.g., TCP / IP) suitable for exchanging messages between and / or among program provider entities 120 using communication formats at a higher level of abstraction (e.g., HTTP, MQTT, COaP, LoRa, WiSUN, Zigbee, etc.). According to the implementation, secure enclave computing device 132 may include a transport security entity 136 capable of establishing secure message exchange with program input provider entities 110 and / or program provider entities 120 via transport clients 114 and 124 through the transport layer infrastructure established and / or maintained between and / or among transport servers 134 and transport clients 114 and 124. For example, transport server 134 and transport clients 114 and 124 may establish secure sessions according to specific cryptographic communication protocols (such as, for example, Transport Layer Security (TLS), to name just one).
[0031] According to the implementation scheme, the secure enclave computing device 132 may include computing resources (e.g., processor, bus, memory, and / or executable instructions) to establish a virtual machine 139 to perform computations (e.g., providing π( D The calculation results, etc. In this context, as referred to herein, a "virtual machine" means simulating one or more aspects of a computer system to host the execution of one or more programs (e.g., represented as signals and / or states stored in a non-transitory computer-readable medium). In one exemplary embodiment, a virtual machine may simulate the behavior of one or more aspects of a computer architecture (e.g., dedicated hardware and / or software) to provide the functionality of a physical computing device. In another exemplary embodiment, a virtual machine may provide functionality that enables the execution of an entire operating system. However, it should be understood that these are merely exemplary aspects of virtual machines, and the claimed subject matter is not limited thereto.
[0032] As described above, computational entity 130 may be concerned about executing a program (e.g., π) provided by program provider entity 120 to process secret and / or proprietary parameters (e.g., π) provided by program input provider entity 110. D ) to provide calculation results (e.g., π( DThe virtual machine 139 may damage the computing resources owned and / or maintained by computing entity 130 during the process of [the process]. Such damage may include or arise from, for example, modifications to other programs via rowhammer attacks, disclosure of files or records of other programs via side-channel attacks, garbage loading of the host hard drive, disclosure of signals and / or states stored on the disk, etc. In an embodiment, virtual machine 139 may protect computing resources from both "physical" (e.g., Rowhammer) and "logical" (e.g., virus-like behavior) attacks. According to an embodiment, virtual machine 139 may include an executable image (e.g., including executable instructions maintained as signals and / or states in memory (not shown)) to emulate one or more aspects of a computing system capable of executing instructions of a program provided by program provider entity 120 for processing secret and / or proprietary parameters provided by program input provider entity 110. According to an embodiment, virtual machine 139 may not emulate all aspects and / or functions of a particular computing system to be emulated. For example, virtual machine 139 may not emulate specific aspects and / or functions of a computing system that could corrupt the computing system hardware and / or software, and / or expose the instructions of the program to be executed, the input parameters of such program, intermediate computation results, and / or the final computation results. In one exemplary embodiment, the executable image of virtual machine 139 may include a subset of compiler operation code that is omitted at least in part during the execution of one or more omitted operation codes based on at least one vulnerability in the computing resources (e.g., a corrupting vulnerability as described above). For example, the bytecode for the executable image of virtual machine 139 may include a sufficient set of operation code (e.g., arithmetic, logic, control flow, data movement) to host the execution of a program of broad interest, including, for example, machine learning algorithms, genomic or genetic algorithms, and / or other similar pure functions from machine word arrays to machine word arrays, to name just a few. In a particular implementation, the bytecode forming the executable image for virtual machine 139 may include a subset of machine instructions and / or bytecode selected from commercial compilers and / or interpreters (such as Arm Limited compilers and / or WebAssembly compilers), or a subset of machine instructions and / or bytecode selected from proprietary compilers and / or interpreters and / or just-in-time compilers and / or interpreters, to name just a few examples.
[0033] According to the implementation scheme, the source code of the executable image maintained by the virtual machine 139 and / or the source code of the entire software system code to be installed on the secure enclave computing device 132 (e.g., including source code for the virtual machine 139) can be used by the program provider entity 120 and / or the program input provider entity 110 to enable verification of the correctness of the implementation of the virtual machine 139 on the secure enclave computing device 132. Here, a partial trust can be established between the program provider entity 120 and the program input provider entity 110, namely, that the executable image maintained by the virtual machine provides the expected computational result to faithfully compute the result (e.g., π). D Additionally, program input provider entity 110 can at least partially ensure that virtual machine 139 does not cache and / or decrypt (e.g., by using "print file" statements and / or opening sockets to allow untrusted third-party access) secrets and / or proprietary parameters provided by program input provider entity 110. Furthermore, program provider entity 120 can at least partially ensure that virtual machine 139 does not cache and / or decrypt programs provided by program provider entity 120. For example, software system code including code for virtual machine 139 may be made available for inspection / verification by, for example, program input provider entity 110 and / or program provider entity 120 (e.g., to ensure that secrets and / or proprietary parameters and / or program details are not disclosed without authorization).
[0034] According to the implementation, the secure enclave computing device 132 executing the virtual machine 139 may embed an untrusted server host and / or the like, including a transport server 134. For example, the transport server 134 may accept, for example, connections between the secure enclave computing device 132 and program provider entity 120 or program input provider entity 110 and / or forward messages. In specific implementations, additional security measures implemented, at least in part in the transport security entity 136, may prevent computing entity 130 and / or third parties from observing and / or caching the content (e.g., plaintext messages) transmitted between the secure enclave computing device 132 and program provider entity 120 or program input provider entity 110. Furthermore, specific implementations may prevent and / or mitigate controlled side-channel attacks and / or other potential compromises to privacy guarantees implemented within the secure enclave computing device 132. According to the implementation, the computation result (e.g., π) may be determined, at least in part, according to a policy such as a policy published by computing entity 130. D Access to the computation result (e.g., π(D)) can be restricted. Such policies may be agreed upon by the program provider entity 120, the program input provider entity 110, and / or the computation entity 130 before the computation is performed to determine the result. For example, a specific implementation of the policy governing access to the computation result can prevent the computation entity 130 from making unauthorized access to the computation result (e.g., π(D)).
[0035] According to the implementation scheme, program provider entity 120 or program input provider entity 110 may establish key pairs for any of several asymmetric encryption techniques (such as, for example, RSA, Diffie-Helman, elliptic curve cryptography, proposed post-quantum cryptography algorithms, to name just a few examples). For example, program input provider entity 110 may establish key pairs represented as follows: Ka and Ka -1 The public and private keys. Similarly, program provider entity 120 can establish [a system / mechanism] represented as [a specific key]. Kb and Kb -1 The public and private keys. The cryptographic representation of an object θ (e.g., θ = D or π) based on any public key Kx is: public key pair Ka / Ka -1 and private key pair Kb / Kb -1 The coherence conditions according to the following expressions (1) and (2) can be satisfied:
[0036] (1)
[0037] (2)
[0038] Figure 2 This is a message flow diagram illustrating the exemplary exchange of messages between and / or among entities including program input provider entity 210, program provider entity 220, computing entity 230, and secure enclave computing device 232. In a particular implementation, program input provider entity 210, program provider entity 220, computing entity 230, and secure enclave computing device 232 may include the above-referenced... Figure 1 The description includes one or more features of each of the program input provider entity 110, program provider entity 120, computing entity 130, and secure enclave computing device 132. For example, secure enclave computing device 232 may include one or more computing devices residing in an SPE and installed by a trusted manufacturer and / or integrator of the hardware and / or software resources constituting secure enclave computing device 232. Public key pairs may be established for input provider entity 210 and program provider entity 220 respectively before transmitting message 240. Ka / Ka -1 and private key pair Kb / Kb -1 In a specific implementation, the key pair Ka / Ka -1 and Kb / Kb -1The expressions (1) and (2) above are satisfied, and the signals and / or states are maintained in the memories of the input provider entity 210 and the program provider entity 220, respectively. Additionally, the program input provider entity 210 and the program provider entity 220 may have each established a self-signed digital certificate Cert. a and Cert b In the implementation plan, Cert a and Cert b This may include electronic documents, which can be used to verify and / or validate input provider entity 210 public keys, respectively. Ka Ownership and program provider entity 220 pairs of public keys Kb Ownership. For example, Cert. a It may include one or more parameters, including Cert. a The unique identifier associated with input provider entity 210 in the main body, and Cert a The signature part is based on the private key Ka -1 The calculated cryptographic hash of the unique identifier associated with input provider entity 210. Similarly, Cert... b It may include one or more parameters, including Cert. b The unique identifier associated with the program provider entity 220 in the main body, and Cert b The signature part is based on the private key Kb -1 The calculated cryptographic hash of the unique identifier associated with program provider entity 220.
[0039] The memory maintained by input provider entity 210 and / or program provider entity 220 may also store signals and / or states representing the cryptographic expression M, which may include a cryptographic hash and / or cryptographic digest of a portion of system code that can be used to derive an executable image of a virtual machine installed on the secure enclave computing device 232 (e.g., Figure 1 The executable image of the virtual machine 139 in the secure enclave computing device 232). In an exemplary embodiment, such system code for exporting the executable image of the virtual machine installed on the secure enclave computing device 232 may include, for example, system code that is publicly available as open source. Thus, the cryptographic expression M may include a cryptographic hash and / or cryptographic digest of at least a portion of such publicly available system code. Furthermore, the program input provider entity 210 may maintain cryptographic values of at least a portion of the code constituting the program that will be provided by the program provider entity 220 (e.g., π) and hosted on the virtual machine of the secure enclave computing device 232 to process secret and / or proprietary parameters (e.g., provided by the program input provider entity 210) that will be provided by the program input provider entity 210. DThis cryptographic value may include a hash of at least a portion of the code of the program expected to be provided by program provider entity 220, and may be represented as a "hash (π)" and stored as a signal and / or state in memory at program input provider entity 210. In an embodiment, the cryptographic value including the hash of at least a portion of the code of the program expected to be provided by program provider entity 220 may be obtained from publicly available sources and / or directly from program provider entity 220. Furthermore, computation entity 230 may use the public key... Ka and Kb and digital certificates Cert a and Cert b It is maintained in memory as a signal and / or state.
[0040] Computing entity 230 may transmit messages 240, including digital certificate Cert, to secure enclave computing device 232. a and Cert b The program input provider entity 210 may transmit one or more messages to the secure enclave computing device 232 to initiate authentication process 244, and the program provider entity 220 may transmit one or more messages to the secure enclave computing device 232 to initiate authentication process 246. (See the following text for further details.) Figure 3 As discussed in the specific implementation, authentication processes 244 and 246 may include exchanging messages to establish a public key for the secure enclave computing device 232. Ke The trust is established, and it is confirmed and / or verified that the secure enclave computing device 232 will use the specific executable image as intended to process the secret and / or proprietary parameters provided by the input provider entity 210. In the implementation, the public key may be established at least in part by a hardware and / or software manufacturer and / or integrator who has contracted with computing entity 230 to include the secure enclave computing device 232. Ke Trust. In a particular implementation discussed below, authentication processes 244 and 246 may include exchanging messages with a trusted provider (not shown) of the secure enclave computing device 232 to at least partially verify that the secure enclave computing device 232 will use the specific executable image as intended to process secrets and / or proprietary parameters provided by the program input provider entity 210.
[0041] After verification via authentication process 246, process 248 may include exchanging messages between program provider entity 220 and secure enclave computing device 232 to load a program (e.g., π) to be hosted on a virtual machine (e.g., virtual machine 139) installed on secure enclave computing device 232. Here, secure transmission process 250 may include exchanging messages between program provider entity 220 and secure enclave computing device 232 to at least partially establish a trust and secure channel for transmitting messages containing signals and / or status of code (such as a program (e.g., π)) to be hosted on a virtual machine installed on secure enclave computing device 232. In a particular implementation, for example, it may be according to the discussion below. Figure 4 The secure transfer process 250 is performed using one or more aspects of the message flow shown. Following the secure transfer process 250, the program provider entity 220 may transmit message 252, which includes signals and / or states indicating program code to be hosted on a virtual machine installed on the secure enclave computing device 232. Upon receiving message 252, the secure enclave computing device 232 may load the program into the virtual machine (e.g., load a program such as π into a virtual machine such as virtual machine 139) based at least in part on the signals and / or states obtained from message 252, and transmit message 256 to the program provider entity 220, thereby confirming that the intended program π has been loaded.
[0042] Process 258 may include exchanging messages between program input provider entity 210 and secure enclave computing device 232, at least in part based on signals and / or states representing the program loaded into the virtual machine at box 254 and secret and / or proprietary parameters to be provided by program input provider entity 210 (e.g., D The calculation result is determined. Here, the secure transmission process 260 may include exchanging messages between the input provider entity 210 and the secure enclave computing device 232 to establish trust and establish a secure channel for transmitting messages containing secret and / or proprietary parameters (e.g., ...) indicating that the input provider entity 210 will provide such parameters. D The signal and / or status of ). In a particular implementation, for example, it may be based on Figure 4One or more aspects of the message flow shown are used to perform the secure transfer process 260. Following the secure transfer process 260, the input provider entity 210 may transmit message 262 requesting a hash of at least a portion of the code of the program loaded at box 254. Upon receiving message 262, the secure enclave computing device 232 may calculate a hash, denoted as H', of at least a portion of the code of the program (e.g., π) received at message 252 (from program provider entity 220) and loaded into the virtual machine at box 254. The secure enclave computing device 232 may then transmit message 266 to the input provider entity 210, which contains signals and / or states representing h'. The program input provider entity 210 may then compare the value of h' with a password value (e.g., a password hash (π)) at box 268 to confirm that the correct program has been loaded into the virtual machine installed at the secure enclave computing device 232 (e.g., at box 254). At least a partial response at box 268 confirms that the correct program has been loaded into the virtual machine installed at the secure enclave computing device 232. The input provider entity 210 can transmit message 272 to the secure enclave computing device 232, which includes secret and / or proprietary parameters indicating that the program loaded at box 254 will be processed (e.g., ...). D The signal and / or status of ). At box 274, the secure enclave computing device 232 can compute results (e.g., π) by, for example, executing a program hosted on a virtual machine installed on the secure enclave computing device 232 (e.g., loaded at box 254). D The secure enclave computing device 232 can transmit message 276 to the program input providing entity 210, which includes signals and / or statuses indicating the computation results obtained at block 274. In an alternative embodiment, message 276 may be transmitted to program provider entity 220 or other parties (not shown) based on a strategy agreed upon between the participants (e.g., after a secure transmission process different from secure transmission processes 250 or 260).
[0043] Figure 3 This is a message flow diagram of a specific implementation of an exemplary authentication process 300 according to the implementation scheme. The exemplary authentication process 300 may include authentication processes 244 and / or 246 implemented according to the implementation scheme. Figure 2In an exemplary embodiment, computing entity 330 may include a specific implementation of computing entities 130 and / or 230. Similarly, secure enclave computing device 332 may include a specific implementation of secure enclave computing devices 132 and / or 232. Secure enclave computing device provider 340 may include entities and / or parties that provide hardware and / or software for the secure enclave computing device 332 to operate in the SPE. For example, secure enclave computing device provider 340 may include a party that has contracted with computing entity 330 to become a manufacturer and / or integrator of hardware and / or software resources to include secure enclave computing device 332. In an embodiment, secure enclave computing device provider 340 may be trusted by program input provider entity 210 and / or program provider entity 220. In a particular exemplary embodiment, among other things, process 300 may provide authentication to challenge entity 320, i.e., including for implementing virtual machines (e.g., Figure 1 The expected system code of the virtual machine 139 shown is installed on the secure enclave computing device 332.
[0044] In a specific implementation, the interrogating entity 320 may include the program input provider entity 210 (e.g., such as...). Figure 2 The specific implementation of the authentication process 244 shown may include a program provider entity 220 (e.g., such as...). Figure 2 (In a specific implementation of the authentication process 264 shown). The challenging entity 320 may transmit an authentication request message 342 including the identifier "challenge", which may be forwarded as message 344 to the secure enclave computing device 332 via the computing entity 330. In at least a partial response to receiving message 344, the secure enclave computing device 332 may compute the cryptographic attribute M' of the system code implemented on the secure enclave computing device 332, which will include a virtual machine for hosting programs provided by a program provider entity (e.g., such as program provider entities 120 and / or 220, which will be loaded at box 254). According to an implementation, for example, the secure enclave computing device provider 340 may provide a private authentication key, which will be maintained within and applied by the secure enclave computing device 332 and cannot be accessed by the computing entity 330. In a particular implementation, the cryptographic attribute M' This may include, for example, a cryptographic hash and / or cryptographic digest calculated using a suitable cryptographic hashing technique, such as SHA-256. The secure enclave computing device 332 at box 346 can compute, including... M’ , Ke , Sign ( M’ challenge Ke The challenge response report r_challenge, where Sign( M’challenge Ke Including at least partly based on M’ challenge Ke The cryptographic expression is calculated based on the private authentication key provided by the secure enclave computing device provider 340. The secure enclave computing device 332 can then transmit a message 347 including a challenge response report r_challenge and the identifier “challenge”, which can be forwarded by the computing entity 330 to the challenging entity 320 in message 348.
[0045] The challenging entity 320 may forward the challenge response report r_challenge (obtained in received message 348) to the secure enclave computing device provider 340. In an alternative implementation, the challenge response report r_challenge may be forwarded to a different party, such as, for example, a network service entity (not shown). The secure enclave computing device provider 340 may then apply a private authentication key provided by the secure enclave computing device provider 340 to the Sign(s) in r_challenge. M’ challenge Ke ), to restore M’ challenge Ke The value is received, and at least one recovery value for "challenge" is forwarded to the challenger entity 320 in message 352. The challenger entity 320 can then compare the recovery value for "challenge" received in message 352 with the value provided in message 342 for "challenge" to confirm the value calculated in the authentication response report r_challenge (received in message 348). M’ This is based on the latest system code installed on the secure enclave computing device 332. A "pass" determination instructs analysis of the identifier "challenge" to confirm the computation in the authentication response report r_challenge. M’ It is based on the latest system code installed on the secure enclave computing device 332, and indicates the public key in r_challenge to the challenging entity 320. Ke (Received in message 348) Originating from secure enclave computing device 332. At least in part in response to determining that the authentication response report r_challenge (received in message 348) is based on the latest system code installed on secure enclave computing device 332, the challenge entity 320 at box 354 can provide password attributes. M’ (Obtained from r_challenge in message 350) and signature M The signature was compared. MIt may include a cryptographic hash and / or hash digest of at least a portion of publicly available system code (e.g., open source), which is intended to be installed on a secure enclave computing device 332 (e.g., including a virtual machine intended to host a program that will be loaded at box 254), as discussed above.
[0046] If the challenging entity 320 includes program input provider entity 210, then determining a match at box 354 provides at least some guarantee that the virtual machine installed at the secure enclave computing device 332 will prevent the disclosure of secret and / or proprietary parameters (e.g., provided at message 272) where such secrets and / or proprietary parameters will be processed by a program hosted by the virtual machine. Similarly, if the challenging entity 320 includes program provider entity 220, determining a match at box 354 provides at least some guarantee that the virtual machine installed at the secure enclave computing device 332 will prevent the disclosure of secrets and / or details about a program provided to the secure enclave computing device (e.g., at message 252) for processing secret and / or proprietary parameters (e.g., provided by program input provider entity 210).
[0047] Figure 4 This is a flowchart of an exemplary process 400 for establishing a secure communication channel according to an embodiment. Exemplary process 400 may include aspects of implementing secure transmission process 250 to establish a secure communication channel between secure enclave computing device 232 and application provider entity 220, and / or aspects of implementing secure transmission process 260 to establish a secure communication channel between secure enclave computing device 232 and application provider entity 220. In the currently shown embodiment, initiating entity 415 may attempt to establish a secure communication channel with secure enclave computing device 432. According to the embodiment, secure enclave computing device 432 may include one or more aspects of secure enclave computing device 232, while initiating entity 415 may include one or more aspects of application provider entity 220 (e.g., in a specific implementation of secure transmission process 250) and / or one or more aspects of input provider entity 210 (e.g., in a specific implementation of secure transmission process 260).
[0048] At box 422, initiating entity 415 may determine a random number r1 and then transmit message 424 to secure enclave computing device 432, including, for example, signals and / or states representing the random number r1, an identifier of a transport security technology (e.g., a version of the TLS or SSL protocol), a list of cipher suites, and / or a list of compression methods. In response to receiving message 424, secure enclave computing device 432 may transmit an acknowledgment message 426 back to initiating entity 415. Based at least in part on the random number r1 obtained from receiving message 424, secure enclave computing device 432 may determine a random number r2 at box 428 and select cipher suite CS and compression method COMP from the available cipher suites and compression methods identified in message 424. Secure enclave computing device 432 may then transmit message 430 to initiating entity 425, which includes signals and / or states representing CS, COMP, r2, and mutually supporting transport security technologies (e.g., candidate transport security technologies identified in message 424).
[0049] In the implementation plan, the secure enclave computing device 432 can generate a self-signed digital certificate Cert. s It can be used to verify and / or authenticate 432 pairs of public keys for secure enclave computing devices. Ks Ownership. In specific implementation, Cert s This may include an electronic document that includes one or more parameters, such as, for example, Cert. s The unique identifier associated with the secure enclave computing device 432 in the main body, and Cert s The signature part is based on the private key Ks -1 The cryptographic hash of the unique identifier associated with the secure enclave computing device 432 is calculated. The secure enclave computing device 432 can transmit message 434 to the initiating entity 415, the message including an identifier representing Cert. s The initiating entity 415 receives the signal and / or status, and then transmits message 436 to the initiating entity 415, which requests a client certificate. Following this, message 438 is transmitted to the initiating entity 415, indicating the end of the transmission of initial parameters from the secure enclave computing device 432. The initiating entity 415 may transmit message 440 to the secure enclave computing device 432, indicating receipt of messages 430, 434, 436, and 438. The initiating entity 415 can then verify the server digital certificate received in message 434 (e.g., using the server's public key) at box 442. Ks ), generate the premaster secret "pms", using pms, r1 and r2 and {pms} Ks To calculate the master secret "ms".
[0050] According to the implementation plan, Entity 415 initiated the pair of self-signed digital certificates Cert. s Dependencies can be at least partially achieved through authentication processes (such as...) Figure 3 The authentication process 300 shown is used to achieve this. For example, the verification of r_challenge by the secure enclave computing device provider 340 allows the initiating entity 415 to rely on the self-signed server certificate provided at message 434. As described above, the challenging entity 320 can obtain the public key in message 352. Ke The content of r_challenge (e.g., after processing r_challenge according to the private authentication key provided by the secure enclave computing device provider 340). Therefore, the secure enclave computing device 432 includes a specific implementation of the secure enclave computing device 332 (e.g., Ks = Ke In a specific implementation, the initiating entity 415 trusts the public key. Ks For use in validating Cert s And indicate the public key in r_challenge to the challenging entity 320. Ke (Received in message 348) Originating from secure enclave computing device 332.
[0051] Initiating entity 415 may transmit message 444 to secure enclave computing device 432, the message including a self-signed client certificate (e.g., Certificate if initiating entity 415 is program input provider entity 110 and / or 210). a And / or if the initiating entity 415 is a program provider entity 120 and / or 220, then it is a Cert. b At box 446, the secure enclave computing device 432 can compare a self-signed client certificate obtained from the received message 444 with an expected client certificate (e.g., an expected client certificate obtained during the startup process according to a mutually agreed policy). The initiating entity 415 can also transmit message 448 to the secure enclave computing device 432, which includes a representation of {pms} as calculated at box 442. Ks Signals and / or states. At box 450, by applying the private key. Ks -1 The secure enclave computing device 432 can be based on the {pms} received in message 448. Ks Determine pms as {{pms} Ks} Ks -1Initiating entity 415 may transmit message 452 at box 442 indicating verification of the server certificate, and secure enclave computing device 432 may at box 454 verify the server certificate provided in message 452 based at least in part on the client certificate received in message 444. Here, message 452 may be signed with a private key associated with the public key in the client certificate received in message 444. Message 456 may include an indication of a cryptographic change, and message 458 may indicate that initiating entity 415 has completed the process. Message 460 from secure enclave computing device 432 may indicate confirmation of receipt of messages 456 and 458, and message 462 from secure enclave computing device 432 may indicate a reversal of the cryptographic change proposed in message 456.
[0052] Figure 5 According to the implementation plan, the secure enclave computing device in the SPE (such as, for example, secure enclave computing device 132) will be used. Figure 1 ) and / or 232 ( Figure 2 The flowchart of an exemplary process 500 performed is shown below. Box 502 may include, for example, transmitting one or more messages to a program input provider entity, such as, for example, program input provider entities 110 and / or 210. In this context, "input provider entity" as used herein refers to a party that owns and / or controls secret and / or proprietary parameters, and / or acts on behalf of a party that owns and / or controls such secret and / or proprietary parameters. Furthermore, in this context, "secret and / or proprietary parameters" as used herein refers to signals and / or states that represent content valuable to a party (e.g., a program input provider entity) for limiting and / or preventing disclosure. Such content represented by secret and / or proprietary parameters may include, for example, parameters, values, sign bits, elements, characters, numbers, numerals, measurements, text, formulas, images, and / or records. However, it should be understood that these are merely examples of content that may be represented by secret and / or proprietary parameters, and the claimed subject matter is not limited in this respect. The message transmitted at box 502 may include, for example, message 346, which includes r_challenge to include parameters. M’ 、Ke、Sign( M’ challenge Ke ) and the identifier "challenge", in which M’Cryptographic attributes include at least a portion of the system code loaded into secure enclave computing devices 132 and / or 232. As used herein, “system code” refers to signals and / or states representing rules, instructions, actions, and / or operations to at least partially control the execution of the computing device. In one example, system code may include an operating system (e.g., to control the runtime execution of applications and input / output operations involving peripheral devices, etc.), diagnostics, etc. In a particular embodiment, system code may at least partially include representations of rules, instructions, actions, and / or operations to implement a virtual machine on one or more computing devices. However, it should be understood that these are merely exemplary embodiments of system code, and the claimed subject matter is not limited thereto. As used herein, “cryptographic expression” refers to content that has been at least partially transformed by an application key. In examples, embodiments of a cryptographic expression may include “cryptographic attributes” to include specific portions of a content object that have been at least partially transformed by an application key. In a particular embodiment, such cryptographic attributes may include signals and / or states. As described above, the parameters provided in r_challenge can at least partially assure the receiving program input provider entity that the system code installed on the secure enclave computing device includes a virtual machine (e.g., virtual machine 139) capable of hosting the execution of a program provided by a third party (such as, for example, program provider entities 120 and / or 220). For example, such a virtual machine may include a set of operational codes and / or instructions that prevent secret and / or proprietary parameters from being revealed due to the virtual machine hosting the execution of such a program (e.g., through caching, printing to a file, etc.).
[0053] As described above, the program input provider entities 110 and / or 210 may exchange messages with the secure enclave computing device provider 340 to determine the verification of the identifier "challenge", and then the password attributes. M’ With the cryptographic expression described above M Compare (e.g., at box 354).
[0054] Box 504 may include receiving one or more messages transmitted from program input provider entities 110 and / or 210, the one or more messages including secret and / or proprietary parameters to be processed by a third-party program. Here, execution of such a third-party program may at least partially transform all or a portion of the secret and / or proprietary parameters to provide computational results represented as signals and / or states, which are stored in non-transitory memory and / or transmitted in a transmission medium. Such messages received from program input provider entities 110 and / or 210 may have already been at least partially responded to by program input provider entities 110 and / or 210 in response to a comparison of a first cryptographic attribute with a first signature (e.g., the cryptographic attribute shown in box 354). M’ With signatureM (Comparison) transmission. For example, password attributes. M' With cryptographic expressions M Such comparisons may include determining password attributes. M’ Whether one or more features are related to the cryptographic expression M One or more features match. Box 504 may include, for example, receiving message 272 from program input provider entities 110 and / or 210, which includes secret and / or proprietary parameters to be processed according to the program loaded at box 254. As described above, the program loaded at box 254 may be hosted by a virtual machine to include a virtual machine that can prevent the disclosure of secret and / or proprietary parameters received in message 272 by, for example, restricting and / or preventing the execution of specific instructions of the hosted program, which may disclose secret and / or proprietary parameters or at least in part based on their computational results.
[0055] Figure 6 This is a flowchart of process 600 performed by a program input provider entity (such as, for example, program input provider entities 110 and / or 210). In a particular implementation, block 602 may include, for example, the exchange of messages between program input provider entities 110 and / or 210 and secure enclave computing devices 132 and / or 232 operating within the SPE to at least partially authenticate the implementation of specific system code on the computing device. As referred to herein, an SPE refers to a partition of a larger computing system that can be executed concurrently with the execution of other operations (e.g., operating systems and / or applications) in a larger computing system outside that partition. Furthermore, such partitions of the SPE may define isolated regions of a larger computing system, thereby guaranteeing: 1) the non-disclosure and integrity of system code (e.g., including virtual machines and / or programs hosted on virtual machines) for execution within the partition, 2) the non-disclosure of input parameters to be processed within the partition, 3) the non-disclosure of output processing results, and 4) the disclosure of intermediate processing results. In an embodiment, the message exchange at block 602 may include the exchange of messages between a challenging entity 320 and a secure enclave computing device 332. In this context, "attestation" and / or "to attest," as used herein, refers to verifying and / or proving a condition based at least in part on the observation of one or more pieces of evidence. Here, this may be at least in part in response to the cryptographic properties shown in box 354. M’ With cryptographic expressions M The comparison and authentication system code (including executable instructions for implementing virtual machines (such as virtual machine 139)) is installed on the secure enclave computing device 332.
[0056] Box 604 may include, for example, the transmission of one or more messages by program input provider entities 110 and / or 210 to secure enclave computing devices 132 and / or 232, the one or more messages including proprietary and / or secret parameters. For example, box 604 may include the transmission of message 272 from program input provider entities 110 and / or 210, the information including keys and / or proprietary parameters to be processed according to the program loaded at box 254. As described above, the program loaded at box 254 may be hosted by a virtual machine that can prevent the disclosure of secret and / or proprietary parameters received in message 272 by, for example, restricting and / or preventing the execution of specific instructions of the hosted program, which may disclose the secret and / or proprietary parameters or calculation results based on them.
[0057] Figure 7 This is a flowchart of process 700 performed by a program provider entity (such as, for example, program provider entities 120 and / or 220). Box 602 may include, for example, the exchange of messages between program provider entities 120 and / or 220 and secure enclave computing devices 132 and / or 232 to at least partially authenticate the implementation of specific system code on the computing device. For example, such message exchange at box 702 may include the exchange of messages between a challenging entity 320 and secure enclave computing device 332. In an embodiment, the cryptographic attributes shown in box 354 may be at least partially responsive. M’ With cryptographic expressions M The comparison and authentication system code (including executable instructions for implementing virtual machines (such as virtual machine 139)) is installed on the secure enclave computing device 332.
[0058] Box 704 may include, for example, the transmission of one or more messages by program provider entities 120 and / or 220 to secure enclave computing devices 132 and / or 232, the one or more messages including signals and / or states representing code of a program to be hosted by a virtual machine. For example, box 704 may include the transmission of message 252 from program provider entities 120 and / or 220, which will be loaded at box 254 for execution by the virtual machine.
[0059] In the context of this patent application, the terms "connector," "component," and / or similar terms are intended to be physical, but not necessarily tangible. Therefore, whether these terms refer to tangible subject matter can vary in a particular context of use. For example, a tangible connection and / or tangible connection path can be formed, such as by a tangible electrical connection (e.g., a conductive path comprising a metal or other conductor) capable of conducting current between two tangible components. Similarly, a tangible connection path can be at least partially influenced and / or controlled such that, as is typically the case, a tangible connection path may sometimes be opened or closed due to the influence of one or more externally derived signals (e.g., external current and / or voltage for an electrical switch). Non-limiting examples of electrical switches include transistors, diodes, etc. However, in a particular context of use, "connection" and / or "component" can also be intangible (albeit physical), such as a connection between a client and a server over a network (particularly a wireless network), which typically refers to the ability of the client and server to transmit, receive, and / or exchange communications, as discussed in more detail later.
[0060] Therefore, in specific contexts of use (such as the specific context of discussing tangible components), the terms “coupled” and “connected” are used in a way that makes these terms unambiguous. Similar terms may also be used in a way that expresses a similar intent. Thus, “connected” is used to indicate, for example, two or more tangible components that are in tangible direct physical contact. Thus, using the previous example, two tangible components that are electrically connected are physically connected via a tangible electrical connection, as previously described. However, “coupled” is used to mean that two or more tangible components are potentially in tangible direct physical contact. Nevertheless, “coupled” is also used to mean that two or more tangible components are not necessarily in tangible direct physical contact, but are capable of cooperating, communicating, and / or interacting, such as through “optical coupling.” Similarly, the term “coupled” is also understood to mean an indirect connection. It should also be noted that, in the context of this patent application, since memories such as memory components and / or memory states are intended to be non-transitory, the term “physical” (at least if used relative to memory) necessarily means that such memory components and / or memory states (continuing with the example) are tangible.
[0061] Unless otherwise specified, in the context of this patent application, when used for a list of related terms such as A, B, or C, the term "or" is intended to be used herein in an inclusive sense to mean A, B, and C, and herein in an exclusive sense to mean A, B, or C. According to this understanding, "and" is used in an inclusive sense and is intended to mean A, B, and C; while "and / or" may be used cautiously so that all the foregoing meanings are contemplated, although such use is not necessary. Furthermore, the terms "one or more" and / or similar terms are used to describe any feature, structure, characteristic, etc., in the singular form, and "and / or" is also used to describe multiple and / or some other combinations of features, structures, characteristics, etc. Similarly, the terms "based on" and / or similar terms are understood to be not necessarily intended to convey an exhaustive list of factors, but rather to allow for the presence of additional factors that are not necessarily explicitly described.
[0062] Furthermore, for specific implementations of the claimed subject matter and subject to tests, measurements, and / or specifications regarding degree, the specific situation is intended to be understood in the following manner. For example, in a given situation, suppose the value of a physical property will be measured. If a person skilled in the art could reasonably conceive of alternative reasonable methods for testing, measuring, and / or specifying degree (at least with respect to the property, continuing with this example), then, at least for the purposes of specific implementation, the claimed subject matter is intended to cover those alternative reasonable methods, unless otherwise expressly stated. For example, if a graph of measured values is generated over a certain region and the specific implementation of the claimed subject matter refers to the measurement of the slope over that region, but there are multiple reasonable and alternative techniques for estimating the slope over that region, then, unless otherwise expressly stated, the claimed subject matter is intended to cover those reasonable alternative techniques.
[0063] Where the subject matter protected by the claims relates to one or more specific measurements, such as physical properties that can be physically measured, such as, but not limited to, temperature, pressure, voltage, current, electromagnetic radiation, etc., it is believed that the subject matter protected by the claims does not fall under the judicial exception of the abstract concept of statutory subject matter. Conversely, it is claimed that physical measurement is not a mental step, and is also not an abstract concept.
[0064] Nevertheless, it should be noted that the typical measurement model employed is that one or more measurements may each comprise the sum of at least two components. Thus, for a given measurement, for example, one component may include a deterministic component, which ideally may include physical values (e.g., sought via one or more measurements) typically in the form of one or more signals, signal samples, and / or states, and another component may include a random component, which may have various sources that are potentially difficult to quantify. Sometimes, for example, a lack of measurement precision can affect a given measurement. Therefore, for the subject matter protected by the claims, in addition to deterministic models, statistical or stochastic models may also be used as methods for identifying and / or predicting one or more measurements that may be relevant to the subject matter protected by the claims.
[0065] For example, a relatively large number of measurements can be collected to better estimate the deterministic components. Similarly, if measurements vary (which is often the case), it is possible that some portions of the variance can be interpreted as deterministic components, while other portions can be interpreted as random components. Generally, it is desirable, if feasible, that the random variance associated with the measurements be relatively small. That is, it is generally preferred that the reasonable portion of the measurement variation be accounted for in a deterministic manner rather than as a random factor used as an aid to identification and / or predictability.
[0066] Following these principles, various techniques have been employed to process one or more measurements to better estimate the fundamental deterministic components, and potentially the stochastic components. These techniques can vary depending on the details surrounding a given situation. However, more complex problems often involve the use of more sophisticated techniques. In this regard, as mentioned above, one or more measurements of physical performance can be deterministically and / or stochastically modeled. Employing a model allows for the potential identification and / or processing of the collected measurements, and / or potentially allows for the estimation and / or prediction of the fundamental deterministic components, for example, relative to later measurements to be performed. A given estimate may not be a perfect estimate; however, in general, averaging one or more estimates is expected to better reflect the fundamental deterministic components, for example, if the stochastic components that may be included in one or more of the obtained measurements are taken into account. In practice, it is desirable to be able to generate physically meaningful models, such as through estimation methods, of the processes that influence the measurements to be performed.
[0067] However, in some cases, as noted, the potential impact can be complex. Therefore, seeking to understand the appropriate factors to consider can be particularly challenging. Thus, it is not uncommon to employ heuristics relative to generating one or more estimates in such situations. Heuristics refers to the use of experience-related methods that reflect the implemented process and / or the implemented results, such as the use of historical measurements. For example, heuristics may be employed where more analytical methods might be too complex and / or nearly intractable. Therefore, for the purposes of the claims, innovative features may include heuristics that can be used, for example, to estimate and / or predict one or more measurements in the exemplary embodiments.
[0068] It should also be noted that when the terms "type" and / or "class," such as when used with a feature, structure, property, etc., using "optical" or "electrical" as a simple example, mean at least partially possessing and / or relating to that feature, structure, property, etc., the existence of minor variations, or even variations that might otherwise not be considered completely identical to that feature, structure, property, etc., generally does not prevent the feature, structure, property, etc. from being called a "type" and / or "class" (such as "optical type" or "optical class"), if the minor variation is small enough that the feature, structure, property, etc., will still be considered substantially present in cases where such variations also exist. Therefore, continuing with this example, the terms optical type and / or optical class characteristics are necessarily intended to include optical characteristics. Similarly, as another example, the terms electrical type and / or electrical class characteristics are necessarily intended to include electrical characteristics. It should be noted that the specification of this patent application provides only one or more illustrative examples, and the claimed subject matter is not intended to be limited to one or more illustrative examples; then, similarly, the context described and / or used, as is always present in the specification of the patent application, provides helpful guidance on the reasonable reasoning to be derived.
[0069] For example, with technological advancements, distributed computing and / or communication methods have become more typical, in which a portion of a process (such as signal processing of signal samples) can be distributed among various devices, including one or more client devices and / or one or more server devices, via a computing and / or communication network. For instance, a network may include two or more devices such as network devices and / or computing devices, and / or devices that can be coupled, such as network devices and / or computing devices, such that signal communication, such as in the form of signal packets and / or signal frames (e.g., including one or more signal samples), can be exchanged, for example, between server devices and / or client devices, as well as other types of devices, including between wired and / or wireless devices coupled via wired and / or wireless networks.
[0070] In the context of this patent application, the term "network device" refers to any device capable of communicating via and / or as part of a network, and may include computing devices. While network devices may be capable of transmitting signals (e.g., signal packets and / or frames) such as via wired and / or wireless networks, in various embodiments they are also capable of performing operations associated with computing devices, such as arithmetic and / or logical operations, such as processing and / or storage operations in memory as a tangible physical memory state (e.g., storing signal samples), and / or operating, for example, as server devices and / or client devices. Network devices capable of operating as server devices, client devices, and / or otherwise may include, for example, dedicated rack-mounted servers, desktop computers, laptop computers, set-top boxes, tablet computers, netbooks, smartphones, wearable devices, integrated devices combining two or more features of the foregoing devices, and any combination thereof. As mentioned, signal packets and / or frames may be exchanged, for example, between server devices and / or client devices and other types of devices, including, for example, between wired and / or wireless devices coupled via wired and / or wireless networks, or any combination thereof. It should be noted that the terms server, server equipment, server computing equipment, server computing platform, and / or similar terms are used interchangeably. Similarly, the terms client, client equipment, client computing equipment, client computing platform, and / or similar terms are also used interchangeably. Although in some cases these terms may be used in the singular for ease of description, such as by referring to “client equipment” or “server equipment,” this description is intended to cover one or more client equipment and / or one or more server equipment as needed. In a similar manner, references to “database” are understood to refer to one or more databases and / or portions thereof as needed.
[0071] It should be understood that, for ease of description, network devices (also referred to as networking devices) may be implemented and / or described in accordance with computing devices, and vice versa. However, it should also be understood that this specification should in no way be construed as limiting the claimed subject matter to one implementation, such as computing devices only and / or network devices only, but rather, on the contrary, it may be implemented as a variety of devices or combinations thereof, including, for example, one or more illustrative examples.
[0072] For example, a network may also include arrangements, derivatives, and / or improvements known now and / or developed thereafter, including, for example, past, present, and / or future high-capacity storage devices such as network-attached storage devices (NAS), storage area networks (SANs), and / or other forms of device-readable media. A network may include a portion of the Internet, one or more local area networks (LANs), one or more wide area networks (WANs), wired connections, wireless connections, other connections, or any combination thereof. Therefore, the scope and / or extended area of a network can be worldwide. Similarly, subnetworks, such as those employing different architectures and / or those substantially compatible with and / or substantially compatible with different protocols such as network computing and / or communication protocols (e.g., network protocols), may interoperate within a larger network.
[0073] In the context of this patent application, when the term subnetwork and / or similar terms are used, for example, in relation to a network, they refer to a network and / or a portion thereof. A subnetwork may also include links such as physical links, connections, and / or coupling nodes to enable the transmission of signal packets and / or frames between devices including specific nodes via wired links, wireless links, or combinations thereof. Various types of devices, such as network devices and / or computing devices, may be available, enabling device interoperability and / or being apparent in at least some cases. In the context of this patent application, when used in relation to devices within a network, the term "transparent" refers to devices communicating via a network, wherein these devices are capable of communicating via one or more intermediate devices (such as one or more intermediate nodes), but the communicating device does not necessarily specify the one or more intermediate nodes and / or one or more intermediate devices of the one or more intermediate nodes, and / or may therefore include devices within the network communicating via the one or more intermediate nodes and / or one or more intermediate devices among the one or more intermediate nodes, but may participate in signaling communication as if not necessarily involving such intermediate nodes and / or intermediate devices. For example, a router may provide links and / or connections between other separate and / or independent LANs.
[0074] In the context of this patent application, "private network" refers to a specific finite set of devices, such as network devices and / or computing devices, capable of communicating with other devices, such as network devices and / or computing devices, such as via signaling packets and / or signaling frames, without requiring rerouting and / or redirecting signaling communications. A private network may include a standalone network; however, a private network may also include a subset of a larger network, such as, but not limited to, all or part of the Internet. Thus, for example, a private network "in the cloud" may refer to a private network that includes a subset of the Internet. Although signaling packets and / or frame communications (e.g., signaling communication) may employ intermediate devices at intermediate nodes to exchange signaling packets and / or signaling frames, those intermediate devices may not necessarily be included in the private network because, for example, they are not the source or designated destination of one or more signaling packets and / or signaling frames. It should be understood that, in the context of this patent application, a private network may direct outgoing signaling communications to devices not within the private network, but devices outside the private network may not necessarily be able to direct inbound signaling communications to devices included within the private network.
[0075] The Internet refers to a distributed, global network of interoperable networks conforming to the Internet Protocol (IP). It should be noted that several versions of the Internet Protocol exist. The terms Internet Protocol, IP, and / or similar terms are intended to refer to any version now known and / or to be developed in the future. The Internet includes, for example, Local Area Networks (LANs), Wide Area Networks (WANs), Wireless Networks, and / or long-distance public networks that allow communication of signal packets and / or frames between LANs. The terms World Wide Web (WWW or Web) and / or similar terms may also be used, but they refer to a portion of the Internet conforming to the Hypertext Transfer Protocol (HTTP). For example, network devices may participate in an HTTP session by exchanging appropriate, substantially compatible, and / or substantially compatible signal packets and / or frames. It should be noted that several versions of the Hypertext Transfer Protocol exist. The terms Hypertext Transfer Protocol, HTTP, and / or similar terms are intended to refer to any version now known and / or to be developed in the future. It should also be noted that in many places throughout this document, the term Internet may be used interchangeably with the term World Wide Web (“Web”) without significantly departing from its meaning, and therefore may be understood in this manner if statements would remain correct under such substitutions.
[0076] Throughout this document, the terms "electronic document" and / or "electronic file" refer to a collection of stored memory states and / or physical signals that are associated in some way, thereby forming a file (e.g., an electronic document) and / or an electronic file. That is, this does not imply an implicit reference to a particular syntax, format, and / or method used, for example, with respect to the associated collection of memory states and / or the associated collection of physical signals. If, for example, a particular type of file storage format and / or syntax is anticipated, then that file storage format and / or syntax is explicitly referenced. It should also be noted that the association of memory states can be, for example, logical and not necessarily tangible physical. Therefore, although the signal and / or state components of a file and / or electronic file will be logically associated, for example, in one embodiment, the storage of such signal and / or state components may, for example, reside in one or more different locations in tangible physical memory.
[0077] For example, Hypertext Markup Language (“HTML”) can be used to specify digital content and / or its format, such as in the form of electronic files and / or electronic documents, such as web pages, websites, etc. In one embodiment, Extensible Markup Language (“XML”) can also be used to specify digital content and / or its format, such as in the form of electronic files and / or electronic documents, such as web pages, websites, etc. Of course, HTML and / or XML are merely examples of “markup” languages provided as a non-limiting illustration. Furthermore, HTML and / or XML are intended to refer to any version of these languages now known and / or to be developed hereafter. Similarly, the claimed subject matter is not intended to be limited to the examples provided as illustrations.
[0078] In the context of this patent application, the terms “entry,” “electronic entry,” “document,” “electronic document,” “content,” “digital content,” “item,” and / or similar terms are intended to refer to a signal and / or state in a physical format (such as a digital signal and / or digital state format) that, for example, is perceptible to a user if displayed, played, haptic-generated, and / or otherwise performed by a device such as a digital device (including, for example, a computing device), but (e.g., if in digital format) may not necessarily be easily perceptible to humans. Similarly, in the context of this patent application, digital content provided to a user in a form that allows the user to easily perceive the inner content itself (e.g., content presented in a form that can be consumed by humans, such as hearing audio, feeling tactile sensations, and / or seeing images) is referred to by the user as “consuming” digital content, “consuming” digital content, “consumable” digital content, and / or similar terms. For one or more embodiments, for example, an electronic document and / or electronic file may include web page code (e.g., computer instructions) in a markup language executed by or to be executed by a computing and / or networking device. In another embodiment, an electronic document and / or electronic file may include a portion and / or a region of a web page. However, the subject matter for which protection is sought is not intended to be restricted in these respects.
[0079] Additionally, for one or more embodiments, electronic documents and / or electronic files may include multiple components. As previously stated, in the context of this patent application, components are physical but not necessarily tangible. For example, in one or more embodiments, components referring to electronic documents and / or electronic files may include text in the form of, for example, physical signals and / or physical states (e.g., capable of being physically displayed). Typically, memory states include tangible components, while physical signals are not necessarily tangible, although signals can become tangible, such as if they appear on a tangible display, which is not uncommon. Furthermore, for one or more embodiments, components referring to electronic documents and / or electronic files may include graphic objects and / or sub-objects, such as images like digital images, which include their attributes, again including physical signals and / or physical states (e.g., capable of being tangibly displayed). In one embodiment, digital content may include, for example, text, images, audio, video, and / or other types of electronic documents and / or electronic files, including, for example, portions of electronic documents and / or electronic files.
[0080] Additionally, in the context of this patent application, the terms “parameter” (e.g., one or more parameters), “value” (e.g., one or more values), “symbol” (e.g., one or more symbols), “bit” (e.g., one or more bits), “element” (e.g., one or more elements), “character” (e.g., one or more characters), “number” (e.g., one or more digits), “digit” (e.g., one or more digits), or “measurement” (e.g., one or more measurements) refer to material describing a set of signals, such as in one or more electronic documents and / or electronic files, and existing in the form of physical signals and / or physical states, such as memory states. For example, one or more parameters, values, symbols, bits, elements, characters, numbers, quantities, or measurements (such as referring to one or more aspects of an electronic document and / or electronic file including images) may include, for example, the time of day of the captured image, the latitude and longitude of an image-capturing device such as a camera. In another example, for example, one or more parameters, values, symbols, bits, elements, characters, numbers, quantities, or measurements associated with digital content (such as digital content including a technical paper) may include, for example, one or more authors. The subject matter protected by the claims is intended to cover any meaningful descriptive parameter, value, symbol, bit, element, character, number, quantity, or measurement in any format, provided that one or more of the parameter, value, symbol, bit, element, character, number, quantity, or measurement includes a physical signal and / or state, which may include, as examples of parameters, a set name (e.g., electronic document and / or electronic document identifier name), creation technology, creation purpose, creation time and date, if stored logical path, encoding format (e.g., type of computer instruction, such as markup language), and / or standards and / or specifications used to ensure compatibility with protocols for one or more uses (e.g., the meaning of substantially compatible and / or essentially compatible), etc.
[0081] Signal packet transmission and / or signal frame transmission (or simply "signal packet" or "signal frame") can be transmitted between nodes in a network, where, for example, a node may include one or more network devices and / or one or more computing devices. As an illustrative example, but not a limitation, a node may include one or more sites in a local network address space, employing a local network address. Similarly, devices such as network devices and / or computing devices may be associated with the node. It should also be noted that, in the context of this patent application, the term "transmission" is intended as another term for a type of signal communication that can occur under any of a variety of circumstances. Therefore, it is not intended to imply a particular direction of communication and / or a particular initiating end of the communication path used for "transmission" communication. For example, in the context of this patent application, the mere use of the term itself does not imply a specific meaning relative to the one or more signals being transmitted, such as whether the signal is "transmitted" to a particular device, whether the signal is "transmitted" from a particular device, and / or regarding which end of the communication path can initiate communication, such as whether it is performed in a "push type" or a "pull type" manner for signal transmission. In the context of this patent application, push signal transmission and / or pull signal transmission are distinguished by which end of the communication path initiates the signal transmission.
[0082] Therefore, for example, signaling packets and / or frames may communicate from a site via an access node coupled to the Internet via a communication channel and / or communication path (such as including a portion of the Internet and / or the Web), or vice versa. Similarly, for example, signaling packets and / or frames may be forwarded via a network node to a target site coupled to a local network. Signaling packets and / or frames transmitted via the Internet and / or a network may be routed, for example, via a path including one or more gateways, servers, etc., such as being “pushed” or “pulled,” which may route the signaling packets and / or frames, for example, substantially based on the destination address and / or the availability of the network path from the network node to the destination address and / or the destination address. Although the Internet and / or the Web includes networks of interoperable networks, not all of these interoperable networks are publicly available and / or accessible. According to embodiments, signaling packets and / or frames may include all or part of a “message” transmitted between devices. In specific embodiments, a message may include signals and / or statuses expressing content to be delivered to a receiving device. For example, a message may at least partially include physical signals in a transmission medium modulated by content in a non-transitory storage medium to be stored at the receiving device and subsequently processed.
[0083] In the context of a particular patent application, network protocols (such as those for communication between devices in a network) can be characterized at least partially and substantially according to a layered description (such as a method and / or description of the so-called Open Systems Interconnection (OSI) seven-layer type). Network computing and / or communication protocols (also referred to as network protocols) refer to a set of signaling conventions, such as those used for communication transmissions, for example, as may occur between and / or with devices in a network. In the context of this patent application, the terms “between” and / or similar terms should be understood to include “among” (if applicable) and vice versa. Similarly, in the context of this patent application, the terms “compatible with,” “compliant,” and / or similar terms should be understood to include substantial compatibility and / or substantial compliance, respectively.
[0084] Network protocols, such as those characterized essentially according to the aforementioned OSI description, have several layers. These layers are called the network stack. Various types of communication, such as network communication (e.g., transport), can occur across these layers. The lowest layer in the network stack, such as the so-called physical layer, characterizes how symbols (e.g., bits and / or bytes) are conveyed as one or more signals (and / or signal samples) via a physical medium (e.g., twisted-pair copper wire, coaxial cable, fiber optic cable, wireless air interface, combinations thereof, etc.). As we progress to higher layers in the network protocol stack, additional operations and / or features become available through communication that is substantially compatible and / or substantially compatible with the specific network protocols at these higher layers. For example, higher layers of a network protocol can, for instance, affect device licensing, user licensing, etc.
[0085] In one implementation, the network and / or subnetworks may communicate via signaling packets and / or signaling frames (such as via participating digital devices) and may be substantially compatible with, but not limited to, versions of any of the following network protocol stacks currently known and / or to be developed: ARCNET, AppleTalk, ATM, Bluetooth, DECnet, Ethernet, FDDI, Frame Relay, HIPPI, IEEE 1394, IEEE 802.11, IEEE-488, Internet Protocol Packet, IPX, Myrinet, OSI Packet, QsNet, RS-232, SPX, System Network Architecture, Token Ring, USB, and / or X.25. The network and / or subnetworks may employ versions currently known and / or to be developed, such as TCP / IP, UDP, DECnet, NetBEUI, IPX, AppleTalk, etc. The Internet Protocol (IP) version may include IPv4, IPv6, and / or other versions to be developed.
[0086] Regarding network-related aspects, including communication and / or computing networks, wireless networks can couple devices, including client devices, to the network. Wireless networks can employ standalone networks, self-organizing networks, mesh networks, wireless LAN (WLAN) networks, cellular networks, etc. Wireless networks can also include systems of terminals, gateways, routers, etc., coupled by radio links, which can move freely and randomly and / or organize themselves arbitrarily, allowing the network topology to sometimes change rapidly. Wireless networks can also employ a variety of network access technologies, both currently known and those to be developed in the future, including Long Term Evolution (LTE), WLAN, Wireless Router (WR) networks, and versions of 2G, 3G, or 4G (2G, 3G, or 4G) cellular technologies. For example, network access technologies can achieve wide-area coverage for devices with varying degrees of mobility, such as computing devices and / or network devices.
[0087] Networks can achieve radio frequency and / or other wireless communication via wireless network access technologies and / or air interfaces such as: Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), General Packet Radio Service (GPRS), Enhanced Data GSM Environment (EDGE), 3GPP Long Term Evolution (LTE), LTE Advanced, Wideband Code Division Multiple Access (WCDMA), Bluetooth, Ultra Wideband (UWB), 802.11b / g / n, etc. Wireless networks can include virtually any type of currently known and / or under development wireless communication mechanism and / or wireless communication protocol, through which signals can communicate between devices, between networks, within networks, etc., including, of course, the aforementioned.
[0088] In one exemplary implementation, such as Figure 8 As shown, system implementations may include a local network (e.g., device 804 and media 840) and / or another type of network such as a computing and / or communication network. Therefore, for illustrative purposes, Figure 8 An implementation scheme 800 of a system is shown that can be used to implement any one or both types of networks. Network 808 may include one or more network connections, links, processes, services, applications, and / or resources to facilitate and / or support communications, such as the exchange of communication signals between a computing device (such as 802) and another computing device (such as 806), which may include, for example, one or more client computing devices and / or one or more server computing devices. By way of example and not limitation, network 808 may include wireless and / or wired communication links, telephone and / or telecommunications systems, Wi-Fi networks, Wi-MAX networks, the Internet, local area networks (LANs), wide area networks (WANs), or any combination thereof.
[0089] In the implementation plan, Figure 8The exemplary devices described may include features of, for example, client computing devices and / or server computing devices. It should also be noted that, generally speaking, the term "computing device," whether used as a client and / or as a server or otherwise, refers at least to a processor and memory connected via a communication bus. Likewise, at least in the context of this patent application, this is understood to refer to sufficient structures as referred to in 35 USC § 112(f), and therefore, the use of the term "computing device" and / or similar terms is specifically explicit and does not relate to 35 USC § 112(f); however, if, for some inconspicuous reason, it is determined that the foregoing understanding is not valid, and therefore 35 USC § 112(f) is necessarily implied by the use of the term "computing device" and / or similar terms, then, according to that statutory portion, the corresponding structures, materials, and / or actions for performing one or more functions are understood and interpreted, at least in the text associated with the foregoing figures of this patent application. Figures 3 to 7 As described in the text.
[0090] Now for reference Figure 8 In the implementation scheme, the first device 802 and the third device 806 are capable of presenting, for example, a graphical user interface (GUI) for network devices and / or computing devices, enabling user operators to engage with the system. In this illustration, device 804 could potentially perform a similar function. Similarly, in Figure 8 In this patent application, computing device 802 (“first device” in the figures) can interact with computing device 804 (“second device” in the figures). In one embodiment, the computing device may also include features such as client computing device and / or server computing device. Processor (e.g., processing device) 820 and memory 822, which may include main memory 824 and auxiliary memory 826, can communicate via, for example, a communication bus 815. In the context of this patent application, the term “computing device” refers to a system and / or device, such as a computing device, that includes the ability to process (e.g., perform calculations) and / or store digital content such as electronic files, electronic documents, measurements, text, images, videos, audio, etc., in the form of signals and / or states. Therefore, in the context of this patent application, a computing device may include hardware, software, firmware, or any combination thereof (excluding software). itself (Except for). Figure 8 As shown, computing device 804 is merely an example, and the claimed subject matter is not limited in scope to this particular example. Figure 8The interface may also include a communication interface 830, which may include circuitry and / or devices to facilitate the transmission of messages between a second device 804 and a first device 802 and / or a third device 806 via a network 808, for example, using one or more network communication technologies identified herein. In a particular embodiment, the communication interface 830 may include a transmitter device including devices and / or circuitry to modulate physical signals in a physical transmission medium according to a particular communication format based at least in part on messages intended to be received by one or more receiver devices. Similarly, the communication interface 830 may include a receiver device including devices and / or circuitry for demodulating physical signals in a physical transmission medium to at least in part recover at least a portion of the messages used to modulate physical signals according to a particular communication format. In a particular embodiment, the communication interface may include a transceiver device having circuitry for implementing the receiver device and the transmitter device.
[0091] For one or more embodiments, devices such as computing devices and / or network devices may include any of a wide range of digital electronic devices, including, but not limited to: desktop computers and / or laptops, high-definition televisions, digital versatile optical disc (DVD) and / or other optical disc players and / or video recorders, game consoles, satellite TV receivers, mobile phones, tablet devices, wearable devices, personal digital assistants, mobile audio and / or video playback and / or recording devices, Internet of Things (IoT) type devices, or any combination thereof. Furthermore, unless otherwise specifically stated, processes described in reference flowcharts and / or other ways may also be performed and / or influenced wholly or in part by computing devices and / or network devices. Devices such as computing devices and / or network devices may vary depending on their capabilities and / or characteristics. The claimed subject matter is intended to cover a wide range of potential variations. For example, devices may include limited-function numeric keypads and / or other displays, such as monochrome liquid crystal displays (LCDs) for displaying text. However, in contrast, network-enabled devices may include physical and / or virtual keyboards, mass storage devices, one or more accelerometers, one or more gyroscopes, Global Positioning System (GPS) and / or other location identification capabilities, and / or displays with higher functionality such as touch-sensitive color 5D or 3D displays.
[0092] As previously mentioned, communication between computing devices and / or network devices and wireless networks may be based on known and / or developing network protocols, including, for example, Global System for Mobile Communications (GSM), Enhanced Data Rate GSM Evolution (EDGE), 802.11b / g / n / h, and / or Global Microwave Access Interoperability (WiMAX). Computing devices and / or network devices may also have a Subscriber Identity Module (SIM) card, which may include, for example, a removable or embedded smart card capable of storing a user's subscription content and / or a contact list. However, it should be noted that the SIM card may also be an electronic card, meaning it can simply be stored in a specific location within the memory of the computing device and / or network device. A user may own the computing device and / or network device, or may otherwise become a user, such as a primary user. Addresses may be assigned to devices by wireless network operators, wired network operators, and / or Internet service providers (ISPs). For example, an address may include a domestic or international telephone number, an Internet Protocol (IP) address, and / or one or more other identifiers. In other embodiments, the computing and / or communication network may be implemented as a wired network, a wireless network, or any combination thereof.
[0093] Computing and / or network devices may include and / or be capable of executing a variety of now-known and / or to-be-developed operating systems, their derivatives, and / or versions, including computer operating systems such as Windows, iOS, and Linux, and mobile operating systems such as iOS, Android, and Windows Mobile. Computing and / or network devices may include and / or be capable of executing a variety of possible applications, such as client software applications that enable communication with other devices. For example, one or more messages (e.g., content) may be conveyed via one or more protocols now-known and / or to be developed for conveying email, short message service (SMS), and / or multimedia messaging service (MMS), including via networks such as social networks formed at least in part by a computing and / or communication network, including but not limited to Facebook, LinkedIn, Twitter, Flickr, and / or Google+, to name just a few. Computing and / or network devices may also include executable computer instructions for processing and / or conveying digital content such as text content, digital multimedia content, etc. Computing and / or networking devices may also include executable computer instructions for performing a variety of possible tasks such as browsing, searching, playing various forms of digital content (including locally stored video and / or streaming video) and / or games (such as, but not limited to, Fantasy Sports League). The foregoing is provided merely to illustrate that the claimed subject matter is intended to include a broad range of possible features and / or capabilities.
[0094] exist Figure 8In this context, computing device 802 can provide one or more sources of executable computer instructions in the form of, for example, physical states and / or signals (e.g., states stored in memory). For instance, computing device 802 can communicate with computing device 804 via a network connection, such as via network 808. As previously mentioned, while the connection is physical, it may not necessarily be tangible. Although... Figure 8 The computing device 804 illustrates various tangible physical components, but the claimed subject matter is not limited to a computing device having only these tangible components, as other specific embodiments and / or implementations may include alternative arrangements that may include, for example, additional tangible components or fewer tangible components that perform different functions while achieving similar results. Rather, the examples provided are illustrative only and are not intended to limit the claimed subject matter to the scope of illustrative examples.
[0095] Memory 822 may include any non-transitory storage mechanism. Memory 822 may include, for example, main memory 824 and auxiliary memory 826, and may use additional memory circuitry, mechanisms, or combinations thereof. Memory 822 may include, for example, random access memory, read-only memory, etc., and may take the form of one or more storage devices and / or systems, such as disk drives including, for example, optical disc drives, magnetic tape drives, solid-state memory drives, etc., to name just a few.
[0096] Memory 822 may be used to store programs that execute computer instructions. For example, processor 820 may fetch executable instructions from memory and continue executing the fetched instructions. Memory 822 may also include a memory controller for accessing device-readable medium 840, which may carry and / or form accessible digital content, including, for example, code and / or instructions executable by processor 820 and / or some other device (such as a controller) capable of executing computer instructions. Under the guidance of processor 820, non-transitory memory (such as memory cells storing physical states (e.g., memory states) including programs that execute computer instructions may be executed by processor 820 and may generate signals to be transmitted via a network, for example, as described above. The generated signals may also be stored in memory, or in the previously suggested memory.
[0097] Memory 822 may store electronic files and / or electronic documents, such as those associated with one or more users, and may also include a computer-readable medium that can carry and / or form accessible content, including, for example, code and / or instructions executable by processor 820 and / or other devices (such as controllers) capable of executing computer instructions. As previously stated, the terms electronic file and / or electronic document, as used throughout this document, refer to a set of stored memory states and / or physical signals that are associated in some way, thereby forming an electronic file and / or electronic document. That is, this does not imply an implicit reference to, for example, a particular syntax, format, and / or method used with respect to the associated set of memory states and / or the associated set of physical signals. It should also be noted that the association of memory states may be, for example, logical and not necessarily tangible physical. Thus, although the signal and / or state components of electronic files and / or electronic documents will be logically associated, in one embodiment, the storage of these signal and / or state components may, for example, reside in one or more different locations in tangible physical memory.
[0098] Algorithm descriptions and / or symbolic representations are examples of techniques used by those skilled in the art of signal processing and / or related fields to communicate the substance of their work to others skilled in the art. In the context of this patent application, an algorithm is considered, and generally is considered, a self-consistent sequence of operations and / or similar signal processing that leads to a desired result. In the context of this patent application, operations and / or processing involve the physical manipulation of physical quantities. Typically, although not required, such quantities may take the form of electrical and / or magnetic signals and / or states that can be stored, transmitted, combined, compared, processed, and / or otherwise manipulated, for example, as electronic signals and / or states constituting components of various forms of digital content, such as signal measurements, text, images, video, audio, etc.
[0099] Primarily for common use, it has sometimes proven convenient to refer to such physical signals and / or physical states as bits, values, elements, parameters, symbols, characters, terms, numbers, quantities, measures, contents, etc. However, it should be understood that all such and / or similar terms will be associated with appropriate physical quantities and are merely convenient labels. Unless otherwise specifically stated, it is evident from the foregoing discussion that throughout this specification, the use of terms such as “processing,” “calculating,” “determining,” “establishing,” “obtaining,” “identifying,” “selecting,” “generating,” etc., can refer to the actions and / or processes of specific devices such as dedicated computers and / or similar dedicated computing devices and / or network devices. Therefore, in the context of this specification, dedicated computers and / or similar dedicated computing and / or network devices are capable of processing, manipulating, and / or transforming signals and / or states, typically in the form of physical electronic and / or magnetic quantities, within the memory, registers, and / or other storage devices, processing devices, and / or display devices of dedicated computers and / or similar dedicated computing and / or network devices. In the context of this particular patent application, as mentioned, the term "specific device" therefore includes general computing and / or networking devices, such as general-purpose computers, which, once programmed, perform specific functions such as in accordance with program software instructions.
[0100] In some cases, state changes in memory devices, such as from binary one to binary zero or vice versa, may include transitions, such as physical transitions. For certain types of memory devices, such physical transitions may include the physical transformation of an article into a different state or thing. For example, but not limited to, for some types of memory devices, state changes may involve the accumulation and / or storage of charge or the release of stored charge. Similarly, in other memory devices, state changes may include physical changes, such as a change in magnetic orientation. Likewise, physical changes may include a change in molecular structure, such as from a crystalline form to an amorphous form, or vice versa. In other memory devices, changes in physical states may involve quantum mechanical phenomena, such as superposition, entanglement, etc., which may involve, for example, qubits (quantum bits). The above is not intended to be an exhaustive list of all examples where state changes in memory devices, such as from binary one to binary zero or vice versa, may include transitions, such as physical but non-transient transitions. Rather, the above is intended as illustrative examples.
[0101] Refer again Figure 8Processor 820 may include one or more circuits, such as digital circuits, to perform at least a portion of computational steps and / or processes. By way of example and not limitation, processor 820 may include one or more processors, such as controllers, microprocessors, microcontrollers, application-specific integrated circuits, digital signal processors, programmable logic devices, field-programmable gate arrays, etc., or any combination thereof. In various specific embodiments and / or implementations, processor 820 may generally perform signal processing, such as manipulating signals and / or states, constructing signals and / or states, etc., based on acquired executable computer instructions, wherein signals and / or states generated in such a manner will be communicated and / or stored in memory.
[0102] Figure 8 Device 804 is also shown as including component 832 that can operate with input / output devices, for example, enabling signals and / or states to be appropriately communicated between devices, such as between device 804 and input devices and / or between device 804 and output devices. Users may utilize input devices such as computer mice, styluses, trackballs, keyboards, and / or any other similar devices capable of receiving user actions and / or movements as input signals. Similarly, for devices with speech-to-text capabilities, users may speak to the device to generate input signals. Users may utilize output devices such as monitors, printers, etc., and / or any other devices capable of providing signals to users and / or generating stimuli such as visual stimuli, audio stimuli, and / or other similar stimuli.
[0103] The implementation scheme described herein relates to a method, which includes:
[0104] The method involves exchanging messages with at least one computing device operating within a Secure Processing Environment (SPE) to authenticate implementations of system code on the at least one computing device, the system code including an implementation of a virtual machine capable of hosting the execution of a program provided by one or more third parties; and transmitting one or more messages to the at least one computing device, at least in part, in response to authenticating the implementation of the system code on the at least one computing device, the one or more messages including proprietary and / or secret parameters that will be processed by the execution of the program provided by the one or more third parties while hosted on the virtual machine, wherein the virtual machine is configured to prevent code executing the program from revealing the proprietary and / or secret parameters outside the SPE. In a particular embodiment, the SPE is embedded within an untrusted host server. In another particular embodiment, the method further includes comparing cryptographic attributes of at least a portion of the system code in the one or more messages transmitted by the at least one computing device with a predetermined cryptographic expression to authenticate the implementation of the system code on the at least one computing device. In another specific embodiment, the method further includes receiving one or more messages from the at least one computing device, the one or more messages including a cryptographic attribute of at least a portion of the code of the program hosted by the virtual machine; and transmitting one or more messages to the at least one computing device, the one or more messages including the secret and / or proprietary parameters, at least in part in response to a comparison of the cryptographic attribute with a password. In another specific embodiment, exchanging messages with the at least one computing device further includes: transmitting a challenge message to the at least one computing device, the challenge message including a challenge value; and receiving one or more messages from the at least one computing device including an authentication report, the authentication report including one or more cryptographic expressions at least in part based on the challenge value, and wherein the method further includes: transmitting one or more verification request messages to a secure enclave computing device provider, the one or more verification request messages including at least one cryptographic expression of the one or more cryptographic expressions; and obtaining a verification status indication from a verification response message received from the secure enclave computing device provider, the verification status indication having been determined at least in part by the at least one cryptographic expression of the one or more cryptographic expressions.
[0105] Other embodiments described herein relate to an apparatus comprising: a transceiver device for transmitting and receiving messages to and from a physical transmission medium; and one or more processors for: exchanging messages via the transceiver device with at least one computing device operating within a Secure Processing Environment (SPE) to authenticate implementations of system code on the at least one computing device, the system code including implementations of a virtual machine capable of hosting the execution of a program provided by one or more third parties; and, at least in part in response to authenticating the implementation of the system code on the at least one computing device, initiating, via the transceiver device, the transmission of one or more messages to the at least one computing device, the one or more messages including proprietary and / or secret parameters to be processed by the execution of the program provided by the one or more third parties while hosted on the virtual machine, wherein the virtual machine is configured to prevent code executing the program from revealing the proprietary and / or secret parameters outside the SPE.
[0106] Other embodiments described herein relate to an article of manufacture comprising: a non-transitory storage medium including computer-readable instructions stored thereon, the computer-readable instructions being executable by a computing device to: exchange messages with at least one computing device operating within a secure processing environment (SPE) to authenticate implementation of system code on the at least one computing device, the system code including implementation of a virtual machine capable of hosting the execution of a program provided by one or more third parties; and, at least in part in response to authenticating the implementation of the system code on the at least one computing device, initiating the transmission of one or more messages to the at least one computing device, the one or more messages including proprietary and / or secret parameters, the proprietary and / or secret parameters being processed by the execution of the program provided by the one or more third parties while hosted on the virtual machine, wherein the virtual machine is configured to prevent code executing the program from revealing the proprietary and / or secret parameters outside the SPE.
[0107] Other embodiments described herein relate to a method comprising: exchanging messages with at least one computing device operating within a secure processing environment (SPE) to authenticate implementations of system code on the at least one computing device, the system code including implementations of virtual machines; and transmitting one or more messages to the at least one computing device, at least in part, in response to authenticating the implementation of the system code on the at least one computing device, the one or more messages including signals and / or states indicating code of a program to be hosted by the virtual machine to process parameters, wherein the system code is used to prevent the code of the program from being exposed outside the SPE. In one particular embodiment, the SPE is embedded within an untrusted host server. In another particular embodiment, the method further includes comparing cryptographic attributes of at least a portion of the system code in the one or more messages transmitted by the at least one computing device with a predetermined cryptographic expression to authenticate the implementation of the system code on the at least one computing device. In yet another specific embodiment, the method further includes receiving one or more messages from the at least one computing device, the one or more messages including a cryptographic attribute of at least a portion of the code of the program hosted by the virtual machine; and transmitting one or more messages to the at least one computing device at least in part in response to a comparison of the cryptographic attribute with a password, the one or more messages including a signal and / or state representing the code of the program. In yet another specific embodiment, exchanging messages with the at least one computing device further includes: transmitting a challenge message to the at least one computing device, the challenge message including a challenge value; and receiving one or more messages from the at least one computing device including an authentication report, the authentication report including one or more cryptographic expressions at least in part based on the challenge value, and wherein the method further includes: transmitting one or more verification request messages to a secure enclave computing device provider, the one or more verification request messages including at least one cryptographic expression of the one or more cryptographic expressions; and obtaining a verification status indication from a verification response message received from the secure enclave computing device provider, the verification status indication having been determined at least in part by the at least one cryptographic expression of the one or more cryptographic expressions.
[0108] Other embodiments described herein relate to an apparatus comprising: a transceiver device for transmitting and receiving messages to and from a physical transmission medium; and one or more processors for: exchanging messages via the transceiver device with at least one computing device operating within a Secure Processing Environment (SPE) to authenticate implementations of system code on the at least one computing device, the system code including implementations of virtual machines; and, at least in part in response to authenticating the implementations of the system code on the at least one computing device, initiating, via the transceiver device, the transmission of one or more messages to the at least one computing device, the one or more messages including signals and / or states indicating code of a program to be hosted by the virtual machine to process parameters, wherein the system code is used to prevent the code of the program from being exposed outside the SPE.
[0109] Other embodiments described herein relate to an article of manufacture comprising: a non-transitory storage medium including computer-readable instructions stored thereon, the computer-readable instructions being executable by a computing device to: exchange messages with at least one computing device operating within a secure processing environment (SPE) to authenticate implementation of system code on the at least one computing device, the system code including implementation of a virtual machine; and, at least in part in response to authenticating implementation of the system code on the at least one computing device, the one or more messages including signals and / or states indicating code of a program to be hosted by the virtual machine to process parameters, wherein the system code is used to prevent the code of the program from being exposed outside the SPE.
[0110] In the foregoing description, various aspects of the claimed subject matter have been described. For purposes of explanation, details such as quantity, system, and / or configuration have been set forth as examples. In other instances, well-known features have been omitted and / or simplified to avoid obscuring the claimed subject matter. While certain features have been illustrated and / or described herein, many modifications, alternatives, variations, and / or equivalents will now occur to those skilled in the art. Therefore, it should be understood that the appended claims are intended to cover all modifications and / or variations falling within the claimed subject matter.
Claims
1. A method for data processing, the method comprising: One or more messages are transmitted to at least one program input provider entity, the one or more messages including a first cryptographic attribute of at least a portion of system code on at least one computing device, the system code including an implementation of a virtual machine capable of hosting a program to be provided by the at least one program input provider entity; as well as Receive one or more messages transmitted from the at least one program input provider entity, the one or more messages including a program to be hosted by the virtual machine, the one or more messages being transmitted by the at least one program input provider entity in at least part of response to a comparison of the first cryptographic attribute with the first cryptographic expression. The system code is used to prevent the program's code from being leaked outside the Secure Processing Environment (SPE).
2. The method according to claim 1, further comprising: Transmit one or more messages to at least one program input provider entity, the one or more messages including a second cryptographic attribute of at least a portion of the code of a program to be executed by the virtual machine; as well as Receive one or more messages transmitted from the at least one program input provider entity, the one or more messages including secrets and / or proprietary parameters to be processed by the program, the one or more messages having been transmitted by the at least one program input provider entity at least in part in response to a comparison of the second cryptographic attribute with the second cryptographic expression. The virtual machine is used to prevent the execution of the program's code from revealing the secrets and / or proprietary parameters outside the secure processing environment (SPE).
3. The method according to claim 2, further comprising: Load the code of the program that will be hosted by the virtual machine; One or more messages are transmitted to the at least one program input provider entity, the one or more messages including a second cryptographic expression of at least a portion of the code of the program to be executed by the virtual machine; as well as Signals and / or states representing the secret and / or proprietary parameters are obtained from one or more messages transmitted from the at least one program input provider entity, the one or more messages being transmitted by the at least one program input provider entity in at least part response to a comparison of the second cryptographic expression with the second cryptographic attribute of the at least a portion of the code of the loaded program.
4. The method according to claim 1 or claim 2, further comprising: Receive one or more messages transmitted from the at least one program input provider entity in a transport layer security session.
5. The method of claim 1 or claim 2, wherein the virtual machine includes a subset of compiler operation code, the virtual machine omitting one or more operation codes in the compiler operation code at least in part based on at least one vulnerability of the at least one computing device, to execute the omitted one or more operation codes of the compiler.
6. The method according to claim 1 or claim 2, further comprising: One or more challenge messages are transmitted to a secure enclave computing device embedded in the secure processing environment (SPE), the one or more challenge messages including challenge values; as well as One or more messages including the first cryptographic attribute are received from the secure enclave computing device, wherein the one or more messages including the first cryptographic attribute from the secure enclave computing device have been transmitted at least in part in response to the receipt of the one or more challenge messages.
7. The method according to claim 1 or claim 2, wherein the first cryptographic attribute comprises a cryptographic hash and / or hash digest of the at least a portion of the system code.
8. The method according to claim 1 or claim 2, wherein, The first password attribute is compared with the first password expression to confirm that the version of the system code has been installed in the secure processing environment to at least partially implement the virtual machine.
9. An apparatus for data processing, the apparatus comprising: A transceiver device for transmitting messages to and receiving messages from a physical transmission medium; and One or more processors, said one or more processors being used for: The transceiver device initiates the transmission of one or more messages to at least one program input provider entity, the one or more transmitted messages including a first cryptographic attribute of at least a portion of system code on the at least one computing device, the system code including an implementation of a virtual machine capable of hosting a program provided by the at least one program input provider entity; as well as Receive one or more messages received at the transceiver device and transmitted from the at least one program input provider entity, the one or more messages including signal and / or status representation codes of a program hosted by the virtual machine, the one or more messages being transmitted by the at least one program input provider entity at least in part in response to a comparison of the first cryptographic attribute with the first cryptographic expression. The system code is used to prevent the program's code from being leaked outside the Secure Processing Environment (SPE).
10. The apparatus of claim 9, wherein the one or more processors are further configured to: The transceiver device initiates the transmission of one or more messages to at least one program input provider entity, the one or more messages including a second cryptographic attribute of at least a portion of the code of the program hosted by the virtual machine; and Obtain one or more messages transmitted from the at least one program input provider entity and received at the transceiver device, the one or more messages including secrets and / or proprietary parameters to be processed by the program executed by the virtual machine, the one or more messages having been transmitted by the at least one program input provider entity at least in part in response to a comparison of the second cryptographic attribute with the second cryptographic expression. The virtual machine is used to prevent the execution of the program's code from revealing the secrets and / or proprietary parameters outside the secure processing environment (SPE).
11. The apparatus of claim 10, wherein the one or more processors are further configured to: Load the code of the program that will be hosted by the virtual machine and provided by the at least one program input provider entity; The transceiver device initiates the transmission of one or more messages to the at least one program input provider entity, the one or more messages including a second cryptographic expression of at least a portion of the code of the program hosted by the virtual machine; as well as From one or more messages received at the transceiver device and transmitted from the at least one program input provider entity, signals and / or states representing secret and / or proprietary parameters are obtained, said one or more messages being transmitted by the at least one program input provider entity in at least part response to a comparison of the second cryptographic expression with a cryptographic value of said at least a portion of the code of the loaded program.
12. The apparatus according to any one of claims 9 to 11, wherein the one or more processors are further configured to: Obtain the one or more messages received at the transceiver device and transmitted from the at least one program input provider entity in a transport layer security session.
13. The apparatus of any one of claims 9 to 11, wherein the virtual machine includes a subset of compiler operation code, the virtual machine omitting one or more operation codes of the compiler operation code at least in part based on at least one vulnerability of the at least one computing device, to execute the omitted one or more operation codes of the compiler.
14. The apparatus according to any one of claims 9 to 11, wherein the one or more processors are further configured to: Initiate the transmission of one or more challenge messages to a secure enclave computing device embedded in the Secure Processing Environment (SPE), wherein the one or more challenge messages include a challenge value; and One or more messages including the first cryptographic attribute received from the secure enclave computing device are obtained, wherein the one or more messages including the first cryptographic attribute from the secure enclave computing device have been transmitted at least in part in response to the receipt of the one or more challenge messages.
15. The apparatus according to any one of claims 9 to 11, wherein the first cryptographic attribute comprises a cryptographic hash and / or hash digest of the at least portion of the system code.
16. The apparatus according to any one of claims 9 to 11, wherein, The first password attribute is compared with the first password expression to confirm that the version of the system code has been installed in the secure processing environment to at least partially implement the virtual machine.
17. An article of manufacture for data processing, the article of manufacture comprising: A non-transitory storage medium, the non-transitory storage medium including computer-readable instructions stored thereon, the computer-readable instructions being executable by a computing device to: Initiating the transmission of one or more messages to at least one program input provider entity, the one or more messages including a first cryptographic attribute of at least a portion of system code on the at least one computing device, the system code including an implementation of a virtual machine capable of hosting a program to be provided by the at least one program input provider entity; as well as Receive one or more messages received and transmitted from the at least one program input provider entity, the one or more messages including signal and / or status representation codes of the program hosted by the virtual machine, the one or more messages being transmitted by the at least one program input provider entity in at least part of response to a comparison of the first cryptographic attribute with the first cryptographic expression. The system code is used to prevent the program's code from being leaked outside the Secure Processing Environment (SPE).
18. The article of manufacture according to claim 17, wherein the instructions are further executable by the computing device to: Initiating the transmission of one or more messages to at least one program input provider entity via a transceiver device, said one or more messages including a second cryptographic attribute of at least a portion of the code of a program to be executed by the virtual machine; and Obtain one or more messages transmitted from the at least one program input provider entity and received at the computing device, the one or more messages including secrets and / or proprietary parameters to be processed by the program, the one or more messages having been transmitted by the at least one program input provider entity at least in part in response to a comparison of the second cryptographic attribute with the second cryptographic expression. The virtual machine is used to prevent the execution of the program's code from revealing the secrets and / or proprietary parameters outside the secure processing environment (SPE).
19. The article of manufacture according to claim 17, wherein the instructions are further executable by the computing device to: Load the code of the program that will be hosted by the virtual machine; Initiate the transmission of one or more messages to the at least one program input provider entity, the one or more messages including a cryptographic expression of at least a portion of the code of the program hosted by the virtual machine; as well as From one or more messages received from the at least one program input provider entity, signals and / or states representing secret and / or proprietary parameters are obtained, said one or more messages being transmitted by the at least one program input provider entity in at least part response to a comparison of the cryptographic expression with a cryptographic value of said at least a portion of the code of the loaded program.
20. The article of manufacture according to any one of claims 17 to 19, wherein the instructions are further executable by the computing device to: Obtain the one or more messages transmitted from the at least one program input provider entity in a transport layer security session.
21. The article of manufacture according to any one of claims 17 to 19, wherein the virtual machine includes a subset of compiler operation code, the virtual machine omitting one or more operation codes of the compiler operation code at least in part based on at least one vulnerability of the at least one computing device, to execute the omitted one or more operation codes of the compiler.
22. The article of manufacture according to any one of claims 17 to 19, wherein the instructions are further executable by the computing device to: Initiate the transmission of one or more challenge messages to a secure enclave computing device embedded in the Secure Processing Environment (SPE), wherein the one or more challenge messages include a challenge value; and One or more messages including the first cryptographic attribute received from the secure enclave computing device are obtained, wherein the one or more messages including the first cryptographic attribute from the secure enclave computing device have been transmitted at least in part in response to the receipt of the one or more challenge messages.
23. The article of manufacture according to any one of claims 17 to 19, wherein the first cryptographic attribute comprises a cryptographic hash and / or hash digest of the at least portion of the system code.
24. The article of manufacture according to any one of claims 17 to 19, wherein, The first password attribute is compared with the first password expression to confirm that the version of the system code has been installed in the secure processing environment to at least partially implement the virtual machine.
Citation Information
Patent Citations
Mutually assured data sharing between distrusting parties in a network environment
US20140283098A1