Trusted Server Orchestration Framework

The system addresses privacy and integrity challenges by executing workflows in a TEE or virtual machine, using customization modules to securely select digital components based on user data without exposing it, ensuring efficient and secure execution.

JP2025540547AActive Publication Date: 2025-12-16GOOGLE LLC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024555197
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-10-17
Publication Date
2025-12-16
Estimated Expiration
2043-10-17

AI Technical Summary

Technical Problem

Existing computing systems face challenges in securely executing workflows that protect user privacy and content platform integrity while allowing proprietary customization, particularly in environments connected to public networks like the Internet, where unauthorized access and data breaches are a concern.

Method used

The system executes workflows in a trusted execution environment (TEE) or virtual machine, applying constraints to inputs and outputs to maintain privacy and integrity, using customization modules and worklets to select digital components based on user data without exposing it to unauthorized parties.

Benefits of technology

This approach ensures user privacy and content platform security by executing customization modules in isolated environments, protecting sensitive data and logic, while enabling efficient and secure selection of digital components with reduced resource usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025540547000001_ABST
    Figure 2025540547000001_ABST
Patent Text Reader

Abstract

Methods, systems, and apparatuses, including computer program products encoded on a medium, are described for secure workflows that enhance data security. In one aspect, the method includes receiving, by a secure delivery system and from a client device, a digital component request including a set of data. In response to receiving the digital component request, a customization orchestrator of the secure delivery system identifies a multi-stage workflow for selecting a digital component from candidate digital components of a given content platform based on the set of data. The multi-stage workflow includes a sequence of customization modules communicatively coupled to each other by a common data bus. Each customization module includes a set of worklets, including one or more customized worklets provided by the given content platform and one or more standard worklets used in customization modules of multiple content platforms.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This specification relates to securely executing computing workflows in a manner that enhances data security and data privacy. [Background technology]

[0002] In computing systems connected to public networks such as the Internet, data security is of paramount importance. Computer systems are often protected from unauthorized access and data breaches using network security technologies such as firewalls.

[0003] A virtual machine provides an emulated version of a computer system and may include an emulated processing unit (e.g., a central processing unit (CPU)), memory, network interfaces, and / or other computing components. Summary of the Invention

[0004] Described herein are techniques related to securely executing workflows that enable non-disclosure and otherwise proprietary customization of workflow stages in a manner that prevents other parties from accessing the customizations. A workflow is a set of executable stages that a unit of work goes through from initiation to completion. These techniques include executing the workflow in an isolated environment, such as a virtual machine and / or a trusted execution environment (TEE), that provides a secure sandbox while still supporting a full-featured workflow. The techniques can further include applying constraints to inputs to and / or outputs from a workflow or portions thereof to maintain user privacy, prevent access to sensitive customizations, and improve system integrity.

[0005] In general, one innovative aspect of the subject matter described herein is embodied by a method that includes the following acts: receiving, by a secure delivery system and from a client device, a digital component request including a set of data; and, in response to receiving the digital component request, identifying, by a customization orchestrator of the secure delivery system, a multi-stage workflow for selecting a digital component from candidate digital components of a given content platform based on the set of data, the multi-stage workflow including a sequence of customization modules communicatively coupled to one another by a common data bus, each customization module including a set of worklets including one or more customized worklets provided by the given content platform and one or more standard worklets used in the customization modules of multiple content platforms; and identifying, by the secure delivery system, a multi-stage workflow for selecting a digital component from candidate digital components of a given content platform based on the set of data, the multi-stage workflow including a sequence of customization modules communicatively coupled to one another by a common data bus, each customization module including a set of worklets including one or more customized worklets provided by the given content platform and one or more standard worklets used in the customization modules of multiple content platforms. executing each customization module of the multi-stage workflow in a defined sequence, where the executing includes, for each customization module, providing, by the customization orchestrator, a set of input data to each customization module via a common data bus; executing each worklet of the customization module in a sequence defined by the customization module to generate a set of output data; transmitting, by the customization orchestrator, the output data to the common data bus, where the output data for a particular customization module of the sequence of customization modules includes data indicating a given digital component selected by the particular customization module based on the set of input data provided to the particular customization module; and causing the client device to present the given digital component.Other implementations of this aspect include corresponding apparatus, systems, and computer programs encoded on computer storage devices and configured to perform aspects of the methods.

[0006] Each of these and other embodiments may optionally include one or more of the following features: Some aspects include receiving, from a common data bus, respective candidate digital components from the multi-stage workflows of the multiple content platforms that include a given digital component from the multi-stage workflow of the given content platform, and selecting, by a digital component selection module, the given digital component from among the candidate digital components.

[0007] In some aspects, each worklet in each set of worklets includes an operation defined by a portion of code configured to process data. The portion of code for the operation associated with each customized worklet is a customized portion of code provided by a given content platform. The portion of code for the operation associated with each standard worklet is a portion of code defined by an entity that manages the operation of the secure delivery system.

[0008] In some aspects, the customization orchestrator transforms a set of input data into a set of defined inputs associated with a customization module.

[0009] In some aspects, the customization orchestrator transforms the output data into a set of defined outputs associated with the customization module. Each customization module can further include a policy engine. The policy engine can determine whether the set of input data and the output data comply with a set of data policies. The policy engine can determine whether the set of input data is provided to the customization module by the customization orchestrator based on whether the set of input data complies with the set of data policies. The policy engine can determine whether the output data is sent to the common data bus by the customization orchestrator based on whether the output data complies with the set of data policies.

[0010] In some aspects, the common data bus is a common data bus that includes one or more data channels, each of which may be a user data channel, a candidate data channel, a contextual data channel, or an auxiliary data channel.

[0011] In some aspects, each customization module includes a local data bus. The sets of worklets of each customization module can be communicatively coupled to one another by the local data bus. Each customization module can include an operations orchestrator configured to transfer data between the sets of worklets via the local data bus.

[0012] In some aspects, one or more of the customization modules are located within a trusted execution environment on a secure delivery system, and one or more of the customization modules are located on a client device.

[0013] In some aspects, executing, by the secure delivery system, each customization module of the multi-stage workflow in a sequence defined by the multi-stage workflow to select a digital component includes executing one or more customization modules simultaneously.

[0014] In some aspects, executing, by the operations orchestrator, each worklet of the customization module in a sequence defined by the customization module to generate a set of output data includes executing one or more worklets concurrently.

[0015] Particular embodiments of the subject matter described herein can be implemented to achieve one or more of the following advantages: The techniques described herein can be used to select digital components from various content providers (e.g., content platforms) while protecting user privacy. Furthermore, the techniques enable such digital components to be provided by a content platform while maintaining the confidentiality and integrity of the technology and proprietary logic used by the content platform. As described further below, the system can execute workflow steps used to select a digital component, and steps involving sensitive user data and / or sensitive technology and / or logic can be executed in an isolated environment, such as within a TEE and / or on a server within a virtual machine. Executing code in a TEE protects the privacy of content requesters (e.g., users) because the TEE can limit access to information about the requester. Executing code in a virtual machine protects the content platform that provided the code. This is because the virtual machine can ensure that content platform customizations remain isolated, such that other content platforms cannot access the content platform customizations. The techniques can include encrypting the code for the customizations, thereby ensuring the security, confidentiality, and integrity of the code.

[0016] Additionally, the system can implement workflow stage customization using a customization module. The customization module enables the content platform to utilize user device and / or trusted server resources in the secure delivery system, enabling a high level of usability and operability. The technology can also be used to ensure that data generated by a workflow stage meets specific criteria, such as criteria defining the customization module's respective inputs and outputs. Such criteria can further protect the requester's privacy by ensuring that a stage only provides data that meets data constraints to other stages and / or the content platform. By executing a customization module containing customized code in the form of a worklet within a trusted server (e.g., a secure delivery system) that provides an isolated execution environment, digital components can be selected quickly, accurately, and efficiently, while also securely protecting the security of user data and the content platform's sensitive customized code. The described systems and techniques also enable such digital component selection and delivery processes to be performed using fewer resources (e.g., CPU cycles) and with better debuggability compared to approaches using standard TEEs.

[0017] The details of one or more embodiments of the subject matter described herein are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages will become apparent from the description, drawings, and claims. [Brief explanation of the drawings]

[0018] [Figure 1] 1 illustrates an exemplary environment in which a secure delivery system delivers digital components to client devices in a privacy-preserving manner. [Figure 2] 2 illustrates exemplary components of the secure delivery system of FIG. 1. [Figure 3] 1 illustrates an exemplary multi-step workflow. [Figure 4] 1 illustrates an exemplary customization module coupled to a common data bus. [Figure 5] 1 illustrates an exemplary data flow for a customization module. [Figure 6] 1 illustrates an exemplary data flow between customization modules of a multi-stage workflow. [Figure 7] 1 illustrates an example of concurrent execution of customization modules with a secure delivery system. [Figure 8] 1 illustrates an exemplary distribution of a customization module between a secure distribution system and a client device. [Figure 9] FIG. 1 is a flow diagram of an example process for executing a secure workflow for selecting a digital component. [Figure 10] FIG. 1 is a flow diagram of an example process for executing a secure workflow for selecting a digital component. [Figure 11] FIG. 1 is a block diagram of an exemplary computer system. DETAILED DESCRIPTION OF THE INVENTION

[0019] Like reference numbers and designations in the various drawings indicate like elements.

[0020] Generally, this document describes systems and techniques for selecting and presenting digital components on a user's client device in a manner that protects the user's privacy and the content platform's sensitive data. The secure delivery system can include one or more computers (e.g., servers) configured to execute a customized digital component selection process that uses sensitive user data so that the user data is not provided to other entities. The secure delivery system can host and execute various content platform selection logic (which can be in code form) when selecting digital components and / or generating digital component selection parameters based on user data to ensure that other entities cannot access the content platform's selection logic. In this way, both the user's data and the content platform's logic are kept secure.

[0021] Ensuring the privacy of personal data is a requirement for many computing systems, especially those connected to public networks such as the Internet. In addition, some jurisdictions have regulations that protect privacy. Such privacy guarantees may include processes that control not only how data is stored, but also the sharing of data with third parties.

[0022] However, some data sharing may provide utility to users, especially if digital component providers seek to customize the digital component selection process for users. For example, private data, including aggregated private data, may be used to find content that is both relevant and of interest to the user, if the user authorizes such use of the user data. Without information about the user, such as the user's interests, it may be difficult for the system to provide relevant content.

[0023] Additionally, executing code from multiple content platforms can raise policy compliance issues and the risk of content platform disclosure to others. For example, one content platform may attempt to share data with another content platform that does not comply with certain data policies, such as policies related to privacy or user age restrictions. In another example, a content platform may attempt to use its code to determine how another content platform's code operates, potentially violating certain policies related to privacy and / or confidentiality of the content platform. Thus, a need exists to ensure the integrity and customizability of the overall system while allowing undisclosed proprietary code to operate on confidential data.

[0024] This specification describes a workflow system that enables a content platform to have the code for each stage of a workflow, or the code for a subset of stages, executed in a trusted execution environment (TEE) or other secure or sandbox environment of a secure delivery system. The result of the workflow can be content, e.g., a digital component, that is presented to a user's client device. As described in more detail below, the content platform's workflows can be implemented using customization modules, each of which contains one or more worklets, at least some of which can be created or customized by the content platform.

[0025] To protect user privacy, the system can ensure that each customization module is only permitted to access data that does not violate data policies, and that the output data generated by each customization module complies with the policies, for example, by a defined set. Furthermore, the system can execute each customization module separately and / or concurrently. By executing the customization modules separately from the TEE, these valuable data assets are protected. Additionally, the TEE ensures the integrity of customized worklets and / or other customized code of the content platform by ensuring that such customizations are not subject to tampering.

[0026] 1 is a block diagram of an exemplary environment 100 in which a secure delivery system 120 delivers digital components to client devices 110 in a privacy-preserving manner. The environment 100 includes a data communications network 105, such as a local area network (LAN), a wide area network (WAN), the Internet, a mobile network, or a combination thereof. The data communications network 105 connects the client devices 110 to the secure delivery system 120 and connects the secure delivery system 120 to content platforms, such as a supply-side platform (SSP) 140 and / or a demand-side platform (DSP) 150. The network 105 may also interconnect various content platforms and / or connect to digital component providers 160, such as servers of the digital component providers 160.

[0027] Client devices 110 are electronic devices that can request and receive online resources over network 105. Exemplary client devices 110 include personal computers, gaming devices, mobile communication devices, digital assistant devices, augmented reality devices, virtual reality devices, and other devices that can send and receive data over network 105. Client devices 110 typically include a user application, such as a web browser, to facilitate sending and receiving data over network 105, although native applications (other than a browser) executed by client devices 110 can also facilitate sending and receiving data over network 105.

[0028] A gaming device is a device that allows a user to participate in a gaming application. For example, a user may control one or more characters, avatars, or other rendered content displayed in the gaming application. A gaming device typically includes a computer processor, a memory device, and a controller interface (physical or visually rendered) that allows user control over content rendered by the gaming application. A gaming device may store and execute gaming applications locally, or execute gaming applications that are at least partially stored and / or provided by a cloud server (e.g., online gaming applications). Similarly, a gaming device may execute gaming applications and interface with a gaming server that "streams" the gaming application to the gaming device. A gaming device may be a tablet device, a mobile communication device, a computer, or other device that performs functions other than running gaming applications.

[0029] Digital assistant devices include devices that include a microphone and a speaker. Digital assistant devices are generally capable of receiving input via voice and can respond with content using audible feedback and present other audible information. In some situations, the digital assistant device also includes a visual display or is in communication with a visual display (e.g., via a wireless or wired connection). If a visual display is present, feedback or other information can also be provided visually. In some situations, the digital assistant device can control other devices, such as lights, locks, cameras, room temperature control devices, alarm systems, and other devices registered with the digital assistant device.

[0030] Client device 110 may include applications 112, such as a web browser and / or native applications, to facilitate sending and receiving data over network 105. Native applications are applications developed for a particular platform or device (e.g., a mobile device with a particular operating system). Although operations may be described as being performed by client device 110, such operations may be performed by applications 112 running on client device 110.

[0031] The application 112 can present, e.g., display, electronic resources, such as web pages, application pages, or other application content, to a user of the client device 110. The electronic resources can include digital component slots for displaying digital components that include the content of the electronic resource. A digital component slot is an area of ​​an electronic resource (e.g., a web page or application page) for displaying a digital component. A digital component slot can also refer to a portion of an audio and / or video stream (another example of an electronic resource) for playing the digital component.

[0032] Electronic resources are also referred to herein as resources for brevity. For the purposes of this document, a resource may refer to a web page, an application page, application content presented by a native application, an electronic document, an audio stream, a video stream, or any other suitable type of electronic resource in which a digital component may be presented.

[0033] As used throughout this specification, the phrase “digital component” refers to a discrete unit of digital content or information (e.g., a video clip, an audio clip, a multimedia clip, an image, text, or other content unit). A digital component can be stored electronically on a physical memory device as a single file or as a collection of files, and a digital component can take the form of a video file, an audio file, a multimedia file, an image file, or a text file and include advertising information; thus, an advertisement is a type of digital component. For example, a digital component can be content intended to supplement the content of a web page or other resource presented by application 112. More specifically, a digital component can include digital content related to the resource content (e.g., the digital component can be related to the same topic as the web page content or to a related topic). Thus, providing a digital component can supplement and overall improve the content of a web page or application.

[0034] When an application 112 loads a resource that includes a digital component slot, the application 112 can generate a digital component request 125-a that requests a digital component for presentation in the digital component slot. In some embodiments, the digital component slot and / or resource can include code (e.g., a script) that causes the application 112 to request the digital component from the secure delivery system 120.

[0035] The digital component request 125-a sent by the client device 110 may include data that can be used to select a digital component to present to the user of the client device 110. For example, the digital component request 125-a may include sensitive user data and / or non-sensitive data, e.g., contextual data, associated with the user of the client device 110. Sensitive user data may include, for example, data identifying user groups that include the user as a member. User groups may include interest-based groups. Each interest-based group may include a topic of interest and a set of members identified (e.g., determined or predicted) as being interested in that topic. User groups may also include, for example, groups of users who performed a particular action on a publisher's electronic resource (e.g., a website or native application). For example, user groups may include users who visited a website, requested more information about an item, interacted with (e.g., selected) a particular digital component, and / or added the item to a virtual cart with the potential to acquire the item. The user data for a user may also include data indicative of the user's topics of interest, user profile data, attributes of the user (eg, demographic attributes), and / or resources visited or viewed by the user.

[0036] In addition to the descriptions throughout this document, users may be provided with controls (e.g., user interface elements with which the user can interact) that allow them to exercise choice regarding both whether and when the systems, programs, or functionality described herein may enable the collection of user information (e.g., information regarding the user's social networks, social actions or activities, occupation, user preferences, or the user's current location), as well as whether content or communications are sent from the server to the user. Additionally, certain data may be processed in one or more ways such that personally identifiable information is removed before it is stored or used. For example, the user's identity may be processed such that personally identifiable information about the user cannot be determined, or if location information is obtained (such as to the city, zip code, or state level), the user's geographic location may be generalized such that the user's specific location cannot be determined. Thus, users may control what information is collected about them, how that information is used, and what information is provided to them.

[0037] The contextual data of the digital component request 125-a may relate to, e.g., describe, the environment in which the selected digital component will be presented. The contextual data may include, for example, general location information indicating the general location of the client device 110 that sent the digital component request 125-a, data indicating the resource (e.g., a website or native application) or native application in which the selected digital component will be presented, keywords or topics of the resource, a query submitted to a search engine by the client device 110, the speech language setting of the application 112 or client device 110, the number of digital component slots in which the digital component will be presented with the resource, the type of digital component slot, and / or other suitable contextual information.

[0038] Secure delivery system 120 can be configured to select and provide digital components in response to digital component requests 125-a received from client device 110. Secure delivery system 120 can be implemented using one or more server computers (or other suitable computing devices), which may be distributing to multiple locations. Generally, secure delivery system 120 receives digital component requests 125-a from client device 110, selects digital components based on data included in digital component requests 125-a, and transmits the selected digital components to client device 110. As described in more detail below, some functionality of secure delivery system 120 can, in some implementations, be implemented on client device 110.

[0039] Because secure delivery system 120 receives sensitive user data, secure delivery system 120 may be operated and maintained by an independent, trusted party, such as a party different from the user of the client device, the party operating SSP 140 and DSP 150, and digital component provider 160. For example, secure delivery system 120 may be run by an industry or government organization. In another example, secure delivery system 120 may be operated by a content platform or another entity, and code executed by secure delivery system 120, e.g., non-customizable code, may be audited by a trusted third party.

[0040] As described in more detail below, secure delivery system 120 can select one or more digital components from a set of digital components stored in digital component repository 130 and / or from a set of digital components received from one or more content platforms, such as from SSP 140. Digital component repository 130 stores digital components received from content platforms (e.g., from SSP 140 and / or DSP 150) and additional data (e.g., metadata) for each digital component.

[0041] The metadata for a digital component may include, for example, distribution criteria that define circumstances in which the digital component is eligible to be provided to a client device 110 in response to receiving the digital component from the client device 110, and / or selection parameters that indicate an amount to be awarded to a publisher if the digital component is displayed with the publisher's resource and / or interacted with by a user when presented. For example, the distribution criteria for a digital component may include location information that indicates eligible geographic locations for presenting the digital component, user group membership data that identifies eligible user groups for presenting the digital component, resource data that identifies eligible resources for presenting the electronic resource, topics of interest, and / or other suitable distribution criteria. The distribution criteria may also include negative criteria, e.g., criteria that indicate circumstances (such as specific resources or specific locations) for which the digital component is not eligible. Other data that can be used to select a digital component may also be stored in the digital component repository along with a reference to the digital component (e.g., as a link or metadata).

[0042] SSP 140 is a technology platform implemented in hardware and / or software that automates the process of acquiring digital components of a resource. Issuers of resources can use SSP 140 to manage the process of acquiring digital components for digital component slots of that resource. Each issuer can have a corresponding SSP 140 or multiple SSPs 140. Some issuers may use the same SSP 140.

[0043] DSP 150 is a technology platform implemented in hardware and / or software that automates the process of delivering digital components for presentation using resources and / or applications. DSP 150 can interact with multiple supplying platforms (SSPs) on behalf of digital component providers 160 to provide digital components for presentation using resources from multiple different publishers. Digital component providers 160 can create (or otherwise publish) digital components to be presented in digital component slots of publisher resources.

[0044] In this example, user data does not cross trust boundary 107, which separates client device 110, secure delivery system 120, and digital component repository from SSP 140, DSP 150, and digital component provider 160. In this way, no entity other than client device 110 and secure delivery system 120 receives the user data included in digital component request 125-a, at least in unencrypted form. This protects user privacy and data security, especially when compared to techniques that use third-party cookies to transmit user data over the Internet.

[0045] To select digital components, the secure delivery system 120 can execute secure workflows for multiple content platforms, e.g., multiple DSPs 150. The secure workflow for each DSP 150 can include customized code that selects candidate digital components based on user data in the digital component request 125-a. In this manner, candidate digital components can be selected based on user data and sensitive content platform logic without providing the user data to the content platform.

[0046] An exemplary process for selecting and providing digital components for presentation on client device 110 is shown in stages AI, which illustrate the flow of data between components of environment 100.

[0047] In stage A, application 112 sends digital component request 125-a to secure delivery system 120. As described above, application 112 can send digital component request 125-a to request a digital component for presentation in a digital component slot of a resource being presented by application 112. Digital component request 125-a can include user data and / or context data.

[0048] In phase B, the secure delivery system 120 sends a context-based digital component request 125-b to the SSP 140. The context-based digital component request 125-b may include the context data of the digital component request 125-a received from the application 112. However, the context-based digital component request 125-b does not include any user data. The secure delivery system 120 may temporarily store the user data while waiting for a response from the SSP 140. The server 120 may send the context-based digital component request 125-b to the SSP 140 for the issuer of the resource being or to be presented by the application 112. The secure delivery system 120 may generate a new context-based digital component request 125-b that includes the context data, or may remove the user data from the digital component request 125-a and forward the digital component request 125-a without the user data to the SSP 140.

[0049] In stage C, the SSP 140 forwards the context-based digital component request 125-b to one or more DSPs 150. In stage D, each DSP 150 sends to the SSP 140 one or more selection parameters for one or more digital components, e.g., digital components stored in the digital component repository 130. For example, the DSP 150 can select digital components based on the context data of the context-based digital component request 125-b and determine selection parameters for the digital components based on the context data. The DSP 150 can also provide digital components and selection parameters for the digital components, e.g., digital components not stored in the digital component repository 130. Each DSP 150 can send to the SSP 140 one or more selection parameters along with, for each selection parameter, data indicating the digital components to which the selection parameter applies. Each DSP 150 can also send to the SSP 140 one or more digital components and data indicating the selection parameters for each digital component.

[0050] In stage E, SSP 140 sends digital component response 129, including the digital component and / or selection parameters, to secure delivery system 120. In some implementations, SSP 140 can filter the digital component and / or selection parameters before sending them to secure delivery system 120 in response 129. For example, SSP 140 can filter the digital component and / or selection parameters based on publisher controls specified by the publisher of the resource being presented by application 112. In a particular example, the publisher of a web page related to a particular event may define as a publisher control that digital components related to another event are not presented on this web page. SSP 140 can filter based on rules or other data provided by the publisher.

[0051] In some implementations, stages B-E are optional stages for obtaining additional digital components as candidates for presentation to the user in response to digital component request 125-a. In such implementations, secure delivery system 120 may select digital components from those whose metadata is stored in digital component repository 130.

[0052] In stage F, the secure delivery system 120 queries the digital component repository 130 for a set of digital components selected based on the user data of the digital component request 125-a. For example, the server 120 may submit a query that defines the user data of the digital component request 125-a as a condition of the query. In some implementations, the query may also include context-based conditions. For example, the query may request retrieval of digital components that include a particular user group and / or a particular geographic location as delivery criteria. While shown after stages B-E, the secure delivery system 120 may query the digital component repository 130 in parallel with these stages to reduce latency in selecting and providing digital components to the application 112.

[0053] In stage G, server 120 receives a set of one or more user-based digital components (or data identifying the digital components), and selection parameters for each digital component, from digital component repository 130. This set of digital components can include those with delivery criteria that match the terms of the query.

[0054] In Phase H, the secure delivery system 120 selects a digital component to provide to the application 112 for presentation in the digital component slot. The secure delivery system 120 may select the digital component from a set of candidate digital components that includes digital components received from the SSP 140 and digital components received from the digital component repository 130. The secure delivery system 120 may select the digital component from the two sets based on selection parameters for each digital component in the two sets. For example, the secure delivery system 120 may select the digital component with the highest selection parameter. In another example, the secure delivery system 120 may select the digital component using a score for each candidate digital component that is based on a combination of the candidate digital component's selection parameters and the candidate digital component's predicted performance (e.g., predicted user interaction rate).

[0055] As described in more detail below, the secure delivery system 120 may execute a content platform secure workflow to select candidate digital components for inclusion in a set of candidate digital components from which the secure delivery system 120 selects digital components to provide to the client device 110. The secure workflow may be executed in addition to querying the digital component repository 130 or instead of querying the digital component repository 130. For example, the content platform secure workflow may be used to select a digital component from a plurality of digital components retrieved from the digital component repository 130 and / or to determine selection parameters for a digital component retrieved from the digital component repository 130.

[0056] In Phase I, the secure delivery system 120 provides the selected digital component to the application 112. The application 112 can then present the resources being presented by the application 112 to the digital component.

[0057] 2 illustrates exemplary components of the secure delivery system 120 of FIG. 1. Generally, the secure delivery system 120 can receive a digital component request 125-a from a client device 110, securely execute a multi-stage workflow that selects a digital component and / or generates selection parameters for the digital component, and provide the digital component 127 to the client device 110. The secure delivery system 120 can include an interface engine 210, a TEE 205 in which the multi-stage workflow 215 executes, and a customization orchestrator 230. Each workflow 215 can execute in a common TEE, or each workflow 215 can execute in its own dedicated TEE. For example, the secure delivery system 120 can include a respective TEE 205 for each workflow 215, and the TEEs 205 for each workflow 215 can be distinct and isolated from each other's workflows 215. In some implementations, each workflow 215 executes in a VM, which can be initiated and executed by the TEE 205. In some embodiments, individual worklets or customization modules 220 execute in VMs, which can be started and executed by the TEE 205.

[0058] The interface engine 210 is configured to receive the digital component request 125 and, in response to the digital component request 125, may provide a digital component 127 and / or a reference to a digital component 127. The reference to the digital component may include an identifier, or resource locator, for the digital component, such as a uniform resource locator (URL) or a universal resource identifier (URI), that enables the client device 110 to download the referenced digital component 127 from a server connected to the network 105.

[0059] The interface engine 210 can include an application programming interface (API) configured to accept data (digital component request 125) provided to the secure delivery system 120 and / or to provide data (e.g., digital component 127) to other components of the environment 100 of Figure 1. Other types of interfaces can also be used to send and receive data.

[0060] Generally, when a digital component request 125 is received, the interface engine 210 can provide the digital component request 125, or data extracted from the digital component request 125, to the customization orchestrator 230. Similarly, when a digital component 127 is selected using the content platform's multi-stage workflow 230, the customization orchestrator 230 can provide the selected digital component or a reference to the digital component 127 to the interface engine 210 to provide to the client device 210.

[0061] The customization orchestrator 215, which may be implemented in software and / or hardware of the secure delivery system 120, is configured to manage the execution of the content platform's secure multi-stage workflow 215 to obtain a set of candidate digital components and / or manage the execution of a secure workflow for selecting a digital component from the set of candidate digital components. Although shown outside the TEE 205, the customization orchestrator 230 may, in some embodiments, execute inside the TEE 205.

[0062] As described in more detail below, each workflow 215 can include a customization module 220, which is coupled to a common data bus 225 that enables the customization modules 220 to transfer data with each other. The combination of the customization modules 220 and the common data bus 225 for a multi-stage workflow 215 can be referred to as a workflow unit. The customization orchestrator 215 is configured to manage the transfer of data between the customization modules 220 and manage the execution of the worklets of the customization modules 220 using the common data bus 225.

[0063] The digital component selection process of a content platform, e.g., DSP 150, can have multiple stages defined by a multi-stage workflow 215. In some implementations, the overall sequence of stages can be rigid such that there is no customization by the content platform. In some implementations, the content platform can customize the stages to be performed in a different order, or to have some performed simultaneously.

[0064] The processes performed in some stages can be customized by the content platform using the customization module 220. For example, the digital component selection process can have a stage where the digital component request 125 is processed to extract data from the digital component request 125. This stage can be a default stage where default code, e.g., a standard worklet, that cannot be customized by the content platform is used by the customization orchestrator 215.

[0065] A later stage may include selecting candidate digital components and generating corresponding selection parameters, at which stage the customization orchestrator 215 may execute customized worklets of the customization module 220 provided by the content platform to select candidate digital components and generate corresponding selection parameters.

[0066] Because logic provided by the content platform is typically considered sensitive, the customization module 220 can be securely stored by the secure delivery system 120 and executed in an isolated environment, such as the TEE 205. Other standard or default code can be executed outside of the isolated environment. In this way, this other code can be executed faster and more efficiently than if the code were executed in the TEE 205, which may include encryption and other security measures.

[0067] The customization orchestrator 230 can execute multi-stage workflows 215 of multiple content platforms, such as the DSP 150, to obtain a set of candidate digital components. Each multi-stage workflow 215 can output one or more candidate digital components and, for each candidate digital component, corresponding selection parameters. These candidate digital components and their selection parameters can be determined based on user data because they are executed in a secure environment.

[0068] The customization orchestrator 230 can also receive candidate digital components from the content platform. For example, the customization orchestrator 230 can receive candidate digital components to be selected based on the context data, for example, using stages B-E of FIG. 1 as described above. The set of candidate digital components from which digital components are selected for the client device 110 can include the candidate digital components output by the secure workflow 215 and the candidate digital components received from the content platform.

[0069] The secure delivery system 120 can then select a digital component from the candidate digital components in various ways. For example, the TEE 205 can select a digital component based on the selection values ​​of the candidate digital components. In another example, the customization orchestrator can execute the customization module 220 or workflow 215 of the SSP 140 corresponding to the resource from which the digital component is being selected to select the digital component. In this example, the custom logic of the SSP 140 can execute within the secure environment provided by the secure delivery system 120 to select the digital component.

[0070] As described in more detail below, the secure workflow 215 and / or the customization module 220 of the workflow 215 may be executed by the secure delivery system 120 and / or the client device 110. For example, the workflow 215 or customization module(s) 220 used to select a digital component from candidate digital components may be executed by either the secure delivery system 120 or the client device 110, depending on the implementation. This protects the privacy of the user and avoids the need for observers from outside the trust boundary 107 to learn about the user.

[0071] For example, if a digital component is selected without using the secure delivery system 120 or the TEE, the digital component will be exposed outside the trust boundary 107. To illustrate, a malicious DSP 150 may set up a repository within the trust boundary 107 that has only digital components that are eligible for delivery to users who like dogs. If even a single encrypted digital component is returned outside the trust boundary 107 and information about the digital component cannot be gleaned from the data itself, an observer from outside the trust boundary 107 may be able to tell that the user likes dogs because the digital component was returned from a repository that contains only digital components for users who like dogs. Performing the selection using the TEE 205 and / or the client device 110 prevents such learning about the user's interests.

[0072] 3 illustrates an exemplary multi-stage workflow 215. Generally, multi-stage workflow 215 includes multiple customization modules 220 communicatively coupled to one another by a common data bus 225. Common data bus 225 may be implemented in hardware and / or software. For example, a software data bus may include one or more data communication channels that facilitate communication between software modules, such as customization modules 220. Customization modules 220 are configured to read data from each of the data channels and write data back to the data channels of common data bus 225, as described in further detail below with reference to FIGS. 4 and 5.

[0073] In some implementations, common data bus 225 may include multiple channels for different types of data. For example, common data bus 225 may include a user data channel for transferring user data between customization modules 220. Customization orchestrator 230 may extract user data from digital component request 225-a and send the user data to one or more of customization modules 220 via the user data channel. Customization modules 220 may also transfer user data between each other using the user data channel. For example, a customization module 220 may provide the user data to another customization module 220 configured to select candidate digital components based on the user data and generate selection parameters for the candidate digital components.

[0074] The common data bus 225 may include a candidate data channel for transferring data regarding candidate digital components between customization modules 220. Continuing with the previous example, a customization module 220 may provide data identifying the candidate digital components to other customization modules 220 configured to generate selection parameters. In another example, the customization orchestrator 230 may receive a response 129 including candidate digital components selected based on the non-sensitive data, e.g., based on the contextual data. The customization orchestrator 230 may provide data identifying these candidate digital components to the customization modules 230 via the candidate data channel.

[0075] The common data bus 225 may include a context data channel for transferring context data between the customization modules 220. For example, the customization orchestrator 230 may extract context data from the digital component request 125-a and send the context data to one or more customization modules 220 via the context data channel. Similarly, a customization module 220 may send context data to another customization module 220 via the context data channel.

[0076] The common data bus 225 may include an auxiliary data channel for transferring auxiliary data between the customization modules 220. The auxiliary data may include data obtained from the content platform of the workflow 215 via an auxiliary API. In some implementations, the auxiliary data is immutable.

[0077] In general, the candidate data channel, the contextual data channel, and the auxiliary data bus may include data specific to the content platform on which the workflow 215 executes. Thus, the common data bus of each workflow 215 may not be connected to other workflows of other content platforms. For example, each workflow 215 may execute in a separate, isolated environment, such as a separate TEE 205.

[0078] Using multiple data channels reduces the amount of processing performed by components of secure delivery system 120. For example, some components of secure delivery system 120 may be configured to process only some types of data. By using different channels for different types of data, these components do not waste resources processing other types of data. For example, as described below with reference to FIG. 4, secure delivery system 120 may include a policy engine 405 that can evaluate user data before providing it to customization module 220 and / or before allowing data from customization module 220 to be output on common data bus 225. By including the user data in a dedicated user data channel, policy engine 405 can enforce correct use of the user data while processing only the data on the user data channel.

[0079] Each customization module 220 can be configured to perform one or more tasks of the workflow 215, such as one or more tasks of a given stage of the workflow 215. For example, one customization module 220 can be configured to select one or more candidate digital components based on user data, contextual data, and / or other data, while another customization module 220 can be configured to generate selection parameters for each candidate digital component. Another customization module 220 can be configured to filter the candidate digital components based on eligibility criteria, such as resource availability to meet the selection parameters, content platforms that enable / disable the candidate digital components, publisher requirements, etc. Another customization module 220 can be configured to expand the candidate digital components into multiple variations of the same candidate digital component with different visual characteristics (e.g., different layouts or content) and then select from these variations.

[0080] Each customization module 220 may include one or more worklets 305 and a local data bus 310 that communicatively couples the worklets 305 of the customization module 220. The worklets may communicate data among themselves via the local data bus 310. The local data bus 310 may be implemented in a manner similar to the common data bus 225.

[0081] Each worklet 305 may include code for performing a subtask of the customization module 220. For example, a task of the customization module 220 may be to select candidate digital components whose delivery criteria are satisfied by the data of the digital component request 125-a. A worklet 305 of this customization module 220 may include code for comparing keywords of the context data of the digital component request 125-a with keywords of the delivery criteria of a set of digital components to identify candidate digital components having contextual delivery criteria that are satisfied by the context data of the digital component request. Another worklet 305 of this customization module 220 may be configured to compare user data of the digital component request 125-a with user parameters of the delivery criteria of the digital components to identify candidate digital components having user-based delivery criteria that are satisfied by the user data of the digital component request 125-a.

[0082] The customization module 220 can include one or more standard worklets and / or one or more customized worklets. A standard worklet is a worklet that is provided as part of the secure delivery system 120 and includes code for performing a task, such as default code for performing a task. For example, a standard worklet may not be customizable by the content platform for the worklet, but may be selected for inclusion in the customization module 220 for the content platform's workflow 215.

[0083] A customized worklet is a worklet that can be customized by the content platform. A customized worklet can include any customized code provided by the content platform. For example, a customized worklet can include code that defines a rule set for selecting candidate digital components or code that defines a trained machine learning model that has been trained to select candidate digital components or to generate selection parameters for candidate digital components.

[0084] In another example, the secure delivery system 220 can make customizable worklets available to the content platform. These customizable worklets can include some standard code and portions that can be customized by the content platform to generate customized worklets.

[0085] The content platform can create and / or select worklets 305 for the customization module 220 and generate the customization module 220 by arranging the worklets 205 in a sequence. A sequence of worklets 305 can include worklets 305 that execute simultaneously, as described below with reference to Figure 4. The content platform can also define the types of data that are input and output to and from each worklet 205 and / or exchanged between worklets 305 over the local data bus 310.

[0086] The content platform can also arrange the customization modules 220 in a sequence, which can include customization modules 220 running simultaneously and / or a concurrent sequence of customization modules 220, as described below with reference to Figure 7. The content platform can also define the types of input data 315 and output data 320 for each customization module 220.

[0087] Customization orchestrator 230 is configured to execute customization modules 220 and their worklets 305 based on the arrangement of worklets 305 and customization modules 220 defined by the content platform. Customization orchestrator 230 also controls the input data 315 provided to each customization module 220 and the output data output by each customization module 220 to common data bus 225. For example, if customization module 220 consumes a particular type of data, customization orchestrator 230 can provide that data to customization module 220 via common data bus 225.

[0088] In some implementations, the customization orchestrator 215 can transform the input data 315 for responding to the customization modules 220 into a defined set of inputs based on the provided definitions provided by the corresponding customization modules 220. For example, a particular customization module 220 may have limited access to data associated with a user, and the customization orchestrator 215 can ensure that only qualified user data is provided to the customization module 220.

[0089] In some implementations, as described below, each customization module 220 can include an operations orchestrator 403 (FIG. 4) that executes and manages operations performed within worklets 305. Similar to the customization orchestrator 215, the operations orchestrator can manage the delivery of data to and from the worklets 305 of the customization module 220 via a local data bus 225.

[0090] After executing a sequence of worklets 305, a customization module 220 can generate output data 320. The customization orchestrator 215 can then send the output data 320 to another customization module 220 using a common data bus 225. In some examples, similar to defining inputs 315, the customization orchestrator 215 can transform the output data 320 corresponding to a customization module 220 into a set of defined outputs based on the definitions of the corresponding customization module 220.

[0091] In this manner, the customization orchestrator 215 can execute each of the customization modules 220 to select one or more candidate digital components, expand the candidate digital components into multiple variations, filter the candidate digital components based on eligibility criteria, and / or generate selection parameters for each candidate digital component. The final customization module 220 of the workflow 215 can generate this data and provide it to the customization orchestrator 215.

[0092] 4 illustrates an example customization module 220 coupled to a common data bus 225. This example customization module 220 includes two standard worklets 305-a and 305-d and two customized worklets 305-b and 305-c that execute simultaneously. Although not shown, each worklet 305a-305d is communicatively coupled to a local data bus 310.

[0093] The operations orchestrator 403 of the customization module 220 can execute each of the worklets 305-a-305-d in an order defined by the customization module 220. For example, the operations orchestrator 403 can provide a defined set of inputs from the input data 315 to the standard worklet 305-a. The operations orchestrator 403 can execute the standard worklet 305-a and provide the output of the standard worklet 305-a to the customized worklets 305-b and 305-c using the local data bus 310.

[0094] The operations orchestrator 403 can execute customized worklet 305-b and customized worklet 305-c simultaneously (e.g., in parallel), whereby each worklet 305-b and 305-c processes the output of standard worklet 305-a as input and generates a corresponding output related to the operation of the customized worklet. The operations orchestrator 405 can then execute standard worklet 305-d by providing the outputs of both customized worklet 305-b and customized worklet 305-c as inputs to standard worklet 305-d, and the operations orchestrator 403 can provide the output of standard worklet 305-d to the local data bus 310. The customization orchestrator can then transform the output of standard worklet 305-d into a defined set of output data 320. The customization orchestrator 403 can provide the output data 320 to the common data bus 225.

[0095] In some examples, the customization module 220 is coupled to a policy engine 405. The policy engine 405 can determine whether the input data 315, the output data 320, or both, conform to a set of data policies.

[0096] Based on whether the input 315, the output 320, or both, conform to a set of data policies, the policy engine 405 can determine whether to provide the input data 315 to the customization module 220, whether to send the output data 320 to the common data bus 225, or both.

[0097] The set of data policies may be defined by the content platform and / or an entity operating the secure delivery system 120. For example, the input 315 may violate a data policy related to a user's privacy, and the policy engine 405 may determine that the input 315 violates the data policy and refrain from providing the input 315 to the customization module 220.

[0098] 5 illustrates an example data flow for the customization module 220. Generally, the operations orchestrator 403 can use the local data bus 310 to execute each worklet 305 in a sequence of worklets 305 for the customization module 220. The operations orchestrator 403 can read data from and write data to the local data bus 310 and execute each worklet 305.

[0099] In particular, the operations orchestrator 403 can execute the standard worklet 305-a and the customized worklet 305-b by providing inputs to each of the worklets, which can be data read from a particular data channel of the local data bus 310. The local data bus 310 can be an internal data bus for the operations of the customization module 220.

[0100] Additionally, the operations orchestrator 403 may provide the outputs of the executed standard worklet 305-a and the executed customized worklet 305-b to subsequent worklets 305 in the sequence of worklets 305 using the local data bus 310. The operations orchestrator 403 may write data associated with the outputs to a particular data channel of the local data bus 310. The operations orchestrator 403's operation to write data to the local data bus 310 may, in some examples, persist across the customization module 220 based on the set of defined outputs of the customization module 220.

[0101] For example, the operations orchestrator 403 can execute the standard worklet 305-a as the first worklet in a sequence of worklets. For example, the operations orchestrator 403 can provide data associated with a set of inputs defined for the customization module 220 to the standard worklet 305-a. The standard worklet 305-a can process the data and generate an output. The operations orchestrator 403 can provide the output of the standard worklet 305-a to the local data bus 310. In particular, the operations orchestrator can write the data associated with the output to data channel 505 and data channel 510 of the local data bus 310. The data channel 505 can be associated with the set of outputs defined for the customization module 220, and the data associated with the data channel 505 can persist across the customization module 220. The data channel 510 can be associated with any data provided by a content provider, and any data may not persist across the customization module 220.

[0102] The operations orchestrator 403 can then execute the customized worklet 305-b by reading data from the data channel 505 and providing the data from the data channel 505 as input to the customized worklet 305-b. The customized worklet 305-b can process the input to generate output. The operations orchestrator 403 can write the output to the data channel 515, which can be associated with a set of defined outputs for the customization module 220.

[0103] The operations orchestrator 403 can read data on data channel 510 (e.g., any data from a content provider) and data on data channel 515 (e.g., the output of customized worklet 305-b) and provide the data as input to standard worklet 305-c. In some examples, standard worklet 305-c can process the input and generate output for the customization module 220.

[0104] 6 illustrates an exemplary data flow between customization modules 220 of a multi-stage workflow 215. Generally, a customization orchestrator 230 executes the customization modules 220 of a secure workflow 215 and can exchange data between the customization modules 220 using a common data bus 225. The customization orchestrator 230 can read data from the customization modules 220 and write data to the common data bus 225 for use in subsequent executions of the customization modules 220.

[0105] In particular, customization orchestrator 230 can execute each of the customization modules 220 by providing input to each of the customization modules 220 in secure workflow 215. The input can include data from the output of a previous customization module 220 in secure workflow 215 and / or other input data defined for the customization module 220. Customization orchestrator 230 can read the data read from a particular data channel of common data bus 225. The operation of customization orchestrator 230 to write data can, in some examples, persist across customization modules 220 based on the set of defined outputs of the customization modules 220.

[0106] For example, the customization orchestrator 230 can provide a set of inputs to the customization module 220-a. The operations orchestrator 403-a of the customization module 220-a can execute the worklets 305-a of the customization module 220-a by reading data from the local data bus 310-a and providing the data as input to the worklets 305-a. The worklets 305-a can process the inputs and generate outputs. The operations orchestrator 403-a of the customization module 220-a can write outputs to the data channel 510 of the local data bus 310-a and to the data channel 505-a of the local data bus 310-a. The data channel 510 can be associated with any data from a content provider, and the data channel 505-a can be associated with a defined set of outputs of the customization module 220-a. As described herein, other types of data channels can also be used.

[0107] The customization orchestrator 230 can then write the data from the data channel 505-a to a data channel 605 of the local data bus. The data channel 605 can be a user data channel, a candidate data channel, a contextual data channel, or an auxiliary data channel. In some examples, the customization orchestrator 230 can convert the data from the data channel 505-a into a set of output data based on a definition corresponding to the customization module 220-a.

[0108] Customization orchestrator 230 can read data from data channel 605 and provide the data as input to customization module 220-b. In some examples, customization orchestrator 230 can transform the data from data channel 605 into a set of inputs based on definitions corresponding to customization module 220-b.

[0109] Customization orchestrator 230 can write data to data channel 505-b of local data bus 310-b, and operations orchestrator 403-b of customization module 220-b can provide the data as input to worklet 305-b. Data channel 505-b and data channel 505-c can both be associated with a defined set of outputs of customization module 220-b.

[0110] 7 illustrates an example of concurrent execution of customization modules 220 by secure delivery system 120. Generally, customization orchestrator 230 can simultaneously execute multiple customization modules 220 of secure workflow 215 based on multiple concurrent execution paths 705, e.g., execution paths 705-a and 705-b.

[0111] The customization orchestrator 230 can execute multiple concurrent execution paths 705, where each concurrent execution path 705 can include a sequence of one or more customization modules 220. For example, the customization orchestrator 230 can split an execution path into two concurrent execution paths 705. The customization orchestrator 230 can simultaneously execute the customization modules 220 of a first concurrent execution path 705-a and the customization modules 220 of a second concurrent execution path 705-b.

[0112] Customization orchestrator 230 can execute customization module 220-a corresponding to concurrent execution path 705-a, followed by customization module 220-b, while executing customization module 220-c corresponding to concurrent execution path 705-b. Customization orchestrator 230 can then use common data bus 225 to merge the data output by customization modules 220 of concurrent execution paths 705-a and 705-b after each execution of the corresponding customization modules 220.

[0113] 8 illustrates an exemplary distribution of customization modules 220 between a secure delivery system and a client device 110. In this example, some customization modules 220 of a secure workflow 215 execute on the client device 110, while other customization modules 220 of the workflow 215 execute on the secure delivery system 120.

[0114] Customization orchestrator 230 can execute one or more customization modules 220 on client device 110, and customization orchestrator 230 can execute one or more customization modules 220 on secure delivery system 120 using a corresponding common data bus 225. Customization orchestrator 230 can exchange data in the form of inputs and outputs from common data bus 225 on client device 110 and secure delivery system 120, respectively.

[0115] For example, client device 110 can be associated with first common data bus 225-a, and client device 110 can include first customization module 220-a and second customization module 220-b. Customization orchestrator 230 can execute customization module 220-a and customization module 220-b using each customization module's 220's respective operation orchestrator and execute each customization module's 220's respective worklet 305 using each local data bus 310. Customization orchestrator 230 can provide input and output to customization modules 220 using common data bus 225-a, where the input and output can be based on data from server 120's common data bus 225-b. In particular, the customization orchestrator 230 can execute the customization module 220-c using the operations orchestrator 403 to execute the worklet 305 using the local data bus 310-c. The customization orchestrator 230 can provide input to the customization module 220-c from the common data bus 225-c, where the input can be associated with data from the common data bus 225-a of the client device 110.

[0116] 9 is a flow diagram of an exemplary process 900 for performing a secure workflow for content selection. For convenience, process 900 is described as being performed by a system for performing a secure workflow for content selection, e.g., secure delivery system 120 of FIGS. 1 and 2, which is suitably programmed to perform the process. The operations of process 900 may also be embodied as instructions stored on one or more computer-readable media, which may be non-transitory, such that execution of the instructions by one or more data processing devices causes the one or more data processing devices to perform the operations of process 900. One or more other components described herein may perform the operations of process 900.

[0117] The system can receive a digital component request (905). The system can be a secure delivery system, and the system can receive the digital component request from a client device. The digital component request includes a set of data. The set of data can include user data and / or context data, as described herein.

[0118] The system may identify a multi-stage workflow for selecting a digital component to provide to the client device in response to the digital component request (910). The system may identify multi-stage workflows defined by one or more content platforms, as described in further detail below with reference to FIG. 10. Each workflow may be configured to select one or more candidate digital components to be added to a set of candidate digital components from which a digital component is selected for presentation at the client device in response to the digital component request.

[0119] The system can execute multi-stage workflows for multiple content platforms 915. The system can execute each multi-stage workflow by executing a sequence of customization modules as described herein.

[0120] The system can receive respective candidate digital components from multi-stage workflows of multiple content platforms 920. The system can include a candidate digital component from each workflow in a set of candidate digital components from which the digital component is selected for presentation at the client device in response to the digital component request.

[0121] The system may select a given digital component (925). In particular, the system may select the given digital component from the candidate digital components based on a selection parameter of the digital component. For example, the system may select the digital component with the highest value of the selection parameter. The system may cause a client device to present the given digital component, for example, by providing the digital component to the client device.

[0122] 10 is a flow diagram of an exemplary process for executing a secure workflow for selecting a digital component. For convenience, process 1000 is described as being performed by a system for executing a secure workflow for content selection, e.g., secure delivery system 120 of FIGS. 1 and 2, which is suitably programmed to perform the process. The operations of process 1000 may also be implemented as instructions stored on one or more computer-readable media, which may be non-transitory, and execution of the instructions by one or more data processing devices may cause the one or more data processing devices to perform the operations of process 1000. One or more other components described herein may perform the operations of process 1000.

[0123] The system can receive a digital component request 1005. The system can be a secure delivery system, and the system can receive a digital component request from a client device. The digital component request includes a set of data, for example, user data and / or context data.

[0124] The system can identify 1010 multi-stage workflows for selecting a digital component. The system can use a customization orchestrator to identify each multi-stage workflow for selecting a digital component from a set of candidate digital components associated with a content platform of the multiple content platforms. In particular, the multi-stage workflow includes a sequence of customization modules communicatively coupled to one another by a common data bus. Each customization module can include a set of worklets. The worklets can be customized worklets provided by the content platform or standard worklets used in customization worklets of the multiple content platforms.

[0125] In some examples, some of the customization modules (e.g., one or more customization modules) are located in a trusted execution environment on a secure delivery system, and some customization modules are located on the client device.

[0126] The system can execute the multi-stage workflow for each content platform of the one or more content platforms 1015. The system can execute each customization module of each multi-stage platform to select the digital component.

[0127] In particular, for each customization module, the system can use a customization orchestrator to provide a set of input data to the customization module over a common data bus (1020). The customization orchestrator can transform the set of input data into a set of defined inputs associated with the customization module.

[0128] In some examples, the system includes a policy engine that determines whether the output data complies with a set of data policies. The policy engine determines whether to provide the set of input data to the customization module based on whether the set of input data complies with the set of data policies.

[0129] The system can execute each worklet of the customization module (1025). In particular, the system can use an operations orchestrator to execute each worklet in a sequence defined by the customization module to generate a set of output data. In some examples, the customization module includes a local data bus, and the set of worklets are communicatively coupled to each other by the local data bus. In this case, the operations orchestrator provides data to each worklet via the local data bus. In some examples, the system executes the worklets in a concurrent (e.g., parallel) manner.

[0130] The system can transmit output data to the common data bus (1030). The system can transmit the output data using a customization orchestrator. The output data includes data indicative of a given digital component selected by the customization module based on a set of input data provided to the customization module. In some examples, the customization orchestrator can transform the output data into a set of defined outputs associated with the customization module.

[0131] In some examples, the system includes a policy engine that determines whether the output data complies with a set of data policies, and the policy engine determines whether the output data is sent to a common data bus based on whether the output data complies with the set of data policies.

[0132] The system can then cause the client device to present the digital component (1035). If the customization module is executed on the secure delivery system, the secure delivery system can provide the digital component to the client device for presentation. If some of the customization module and / or the final selection of the digital component is executed on the client device, the client device can present the digital component after selection.

[0133] 11 is a block diagram of an exemplary computer system 1100 that can be used to perform the operations described above. The system 1100 includes a processor 1110, a memory 1120, a storage device 1130, and an input / output device 1140. Each of the components 1110, 1120, 1130, and 1140 can be interconnected using, for example, a system bus 1150. The processor 1110 can process instructions for execution within the system 1100. In one embodiment, the processor 1110 is a single-threaded processor. In another embodiment, the processor 1110 is a multi-threaded processor. The processor 1110 can process instructions stored in the memory 1120 or the storage device 1130.

[0134] Memory 1120 stores information within system 1100. In one embodiment, memory 1120 is a computer-readable medium. In one embodiment, memory 1120 is a volatile memory unit. In another embodiment, memory 1120 is a non-volatile memory unit.

[0135] Storage device 1130 can provide mass storage for system 1100. In one embodiment, storage device 1130 is a computer-readable medium. In various different embodiments, storage device 1130 can include, for example, a hard disk device, an optical disk device, a storage device shared over a network by multiple computing devices (e.g., a cloud storage device), or some other mass storage device.

[0136] The input / output device 1140 provides input / output operations for the system 400. In one embodiment, the input / output device 1140 may include one or more of a network interface device, such as an Ethernet card, a serial communication device, such as an RS-232 port, and / or a wireless interface device, such as an 802.11 card. In another embodiment, the input / output device may include a driver device configured to receive input data and send output data to other devices, such as keyboards, printers, displays, and other peripheral devices 1160. However, other implementations, such as mobile computing devices, mobile communication devices, set-top boxes, television client devices, etc., may also be used.

[0137] Although FIG. 11 illustrates an exemplary processing system, implementations of the subject matter and functional operations described herein can be implemented in other types of digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed herein and structural equivalents thereof, or in one or more combinations thereof.

[0138] An electronic document (for simplicity we will simply call it a document) does not necessarily correspond to a file: a document may be stored as part of a file that holds other documents, in a single file dedicated to that document, or in multiple linked files.

[0139] Embodiments of the subject matter and functional operations described herein can be implemented in digital electronic circuitry, computer software, firmware, or hardware, including the structures disclosed herein and structural equivalents thereof, or in one or more combinations thereof. Embodiments of the subject matter described herein can be implemented using one or more modules of computer program instructions encoded on a computer-readable medium for execution by or to control the operation of a data processing apparatus. The computer-readable medium can be a computer system hard drive, an optical disc sold through retail channels, or a manufactured product such as an embedded system. The computer-readable medium can be obtained separately and later encoded with one or more modules of computer program instructions, such as by delivery of one or more modules of computer program instructions over a wired or wireless network. The computer-readable medium can be a machine-readable storage device, a machine-readable storage substrate, a memory device, or one or more combinations thereof.

[0140] The term "data processing apparatus" encompasses all apparatus, devices, and machines for processing data, including, by way of example, a programmable processor, a computer, or multiple processors or computers. In addition to hardware, an apparatus may also include code that creates an execution environment for such computer programs, such as code that constitutes processor firmware, a protocol stack, a database management system, an operating system, a runtime environment, or one or more combinations thereof. Additionally, an apparatus may use a variety of different computing model infrastructures, such as web services, distributed computing, and grid computing infrastructures.

[0141] A computer program (also known as a program, software, software application, script, or code) can be written in any suitable form of programming language, including compiled or interpreted, declarative or procedural, and can be deployed in any suitable form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program does not necessarily correspond to a file in a file system. A program can be stored in part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program, or in multiple associated files (e.g., files storing one or more modules, subprograms, or portions of code). A computer program can be deployed to be executed on one computer or on multiple computers that are located at one site or distributed across multiple sites and interconnected by a communications network.

[0142] The processes and logic flows described herein may be performed by one or more programmable processors executing one or more computer programs to perform functions by operating on input data and generating output. The processes and logic flows may also be performed by, and apparatus may be implemented as, special purpose logic circuitry, such as an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit).

[0143] Processors suitable for executing computer programs include, for example, special-purpose microprocessors. Generally, a processor receives instructions and data from a read-only memory, a random-access memory, or both. The basic elements of a computer are a processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer also includes, or is operatively coupled to receive data from, transfer data to, or both of, one or more mass storage devices for storing data, such as, for example, magnetic, magneto-optical, or optical disks. However, a computer need not include such devices. Furthermore, a computer can be incorporated into another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device (such as a universal serial bus (USB) flash drive), to name just a few. Suitable storage devices for storing computer program instructions and data include all types of non-volatile memory, media, and memory devices, including, by way of example, semiconductor memory devices such as EPROM (erasable programmable read-only memory), EEPROM (electrically erasable programmable read-only memory), and flash memory devices, magnetic disks such as internal hard disks and removable disks, magneto-optical disks, and CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special purpose logic circuitry.

[0144] The term "engine" is used broadly herein to refer to a software-based system, subsystem, or process that is programmed to perform one or more specific functions. Generally, an engine is implemented as one or more software modules or components and installed on one or more computers in one or more locations. In some cases, one or more computers are dedicated to a particular engine, and in other cases, multiple engines may be installed and running on the same computer or computers.

[0145] To provide interaction with a user, embodiments of the subject matter described herein may be implemented on a computing device that can provide information to a user. The information can be provided to the user in any form of sensory format, including visual, auditory, tactile, or a combination thereof. The computing device may be coupled to a display device, such as an LCD (liquid crystal display) display device, an OLED (organic light-emitting diode) display device, another monitor, a head-mounted display device, etc., to display information to the user. The computing device may be coupled to an input device. The input device may include a touchscreen, a keyboard, and a pointing device, such as a mouse or trackball, by which a user can provide input to the computing device. Other types of devices may also be used to provide interaction with a user. For example, feedback provided to the user may be any suitable form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback, and input from the user may be received in any suitable form, such as acoustic input, speech input, or tactile input.

[0146] A computing system may include clients and servers. Clients and servers are generally remote from each other and typically interact through a communications network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. Embodiments of the subject matter described herein may be implemented in a computing system that includes back-end components, e.g., a data server, or middleware components, e.g., an application server, or front-end components, e.g., a client computer having a graphical user interface or a web browser through which a user can interact with an implementation of the subject matter described herein, or any combination of one or more such back-end, middleware, or front-end components. The components of the system may be interconnected by any suitable form or medium of digital data communication, e.g., a communications network. Examples of communications networks include a local area network (“LAN”), a wide area network (“WAN”), an internetwork (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network).

[0147] Although many specific implementation details are described herein, these should not be construed as limitations on the scope of what is or can be claimed, but rather as descriptions of features specific to particular embodiments of the disclosed subject matter. Certain features described herein in the context of individual embodiments can also be implemented in combination in a single embodiment. Conversely, various features of the invention that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable subcombination. Furthermore, even if features may be described above as functioning in a particular combination and originally claimed as such, one or more features from the claimed combination may, in some cases, be deleted from the combination, and the claimed combination may be directed to a subcombination or variation of the subcombination. Thus, unless expressly stated otherwise or unless the knowledge of one of ordinary skill in the art clearly dictates otherwise, any feature of the above-described embodiments can be combined with any other feature of the above-described embodiments.

[0148] Similarly, while operations are shown in a particular order in the figures, this should not be understood as requiring that such operations be performed in the particular order or sequential order shown, or that all of the shown operations be performed, to achieve desirable results. In certain situations, multitasking and / or parallel processing may be advantageous. Furthermore, the separation of various system components in the above embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems may generally be integrated into a single software product or packaged into multiple software products.

[0149] Thus, while specific embodiments of the present invention have been described, other embodiments are within the scope of the following claims. For example, the actions recited in the claims can be performed in a different order and still achieve desirable results.

Claims

1. 1. A computer-implemented method comprising: receiving, by a secure delivery system and from a client device, a digital component request including a set of data; In response to receiving the digital component request, identifying, by a customization orchestrator of the secure delivery system, a multi-stage workflow for selecting a digital component from candidate digital components of a given content platform based on the set of data, the multi-stage workflow including a sequence of customization modules communicatively coupled to each other by a common data bus, each customization module including a set of worklets including one or more customized worklets provided by the given content platform and one or more standard worklets used in customization modules of multiple content platforms; executing, by the secure delivery system, each customization module of the multi-stage workflow in a sequence defined by the multi-stage workflow to select the digital component, wherein said executing includes: For each customization module, providing, by the customization orchestrator, a set of input data to each customization module via the common data bus; Executing each worklet of the customization module in a sequence defined by the customization module to generate a set of output data; transmitting, by the customization orchestrator, the output data to the common data bus, the output data for a particular customization module of the sequence of customization modules including data indicative of a given digital component selected by the particular customization module based on the set of input data provided to the particular customization module; said performing comprising: causing the client device to present the given digital component; The computer-implemented method includes:

2. receiving, from the common data bus, respective candidate digital components from the multi-stage workflows of multiple content platforms that include the given digital component from the multi-stage workflow of the given content platform; selecting, by the digital component selection module, the given digital component from among the candidate digital components; The computer-implemented method of claim 1 , comprising:

3. Each worklet in each set of worklets includes an operation defined by a portion of code configured to process data; the portion of code for the operation associated with each customized worklet is a customized portion of code provided by the given content platform; the portion of the code for the operation associated with each standard worklet is a portion of code defined by an entity that manages the operation of the secure delivery system.

3. The computer-implemented method of claim 1 or 2.

4. The computer-implemented method of claim 1 , wherein the customization orchestrator transforms the set of input data into a set of defined inputs associated with the customization module.

5. The computer-implemented method of claim 1 , wherein the customization orchestrator transforms the output data into a set of defined outputs associated with the customization module.

6. Each customization module further includes a policy engine; The computer-implemented method of claim 5 , wherein the policy engine determines whether the set of input data and the output data comply with a set of data policies.

7. 7. The computer-implemented method of claim 6, wherein the policy engine determines whether the set of input data is to be provided by the customization orchestrator to the customization module based on whether the set of input data complies with the set of data policies.

8. 7. The computer-implemented method of claim 6, wherein the policy engine determines whether the output data is to be sent by the customization orchestrator to the common data bus based on whether the output data complies with the set of data policies.

9. the common data bus is a common data bus including one or more data channels; each data channel of the one or more data channels is a user data channel, a candidate data channel, a context data channel, or an auxiliary data channel; A computer-implemented method according to any one of claims 1 to 8.

10. each customization module further includes a local data bus; the set of worklets of each customization module are communicatively coupled to one another by the local data bus; A computer-implemented method according to any one of claims 1 to 9.

11. The computer-implemented method of claim 10 , wherein each customization module includes an operations orchestrator configured to transfer data between the set of worklets via the local data bus.

12. 12. The computer-implemented method of claim 1, wherein one or more of the customization modules are located in a trusted execution environment on the secure delivery system and one or more of the customization modules are located on the client device.

13. 13. The computer-implemented method of claim 1, wherein executing, by the secure delivery system, each customization module of the multi-stage workflow in the sequence defined by the multi-stage workflow to select the digital component further comprises executing the one or more customization modules simultaneously.

14. 14. The computer-implemented method of claim 1, wherein executing, by the operations orchestrator, each worklet of the customization module in a sequence defined by the customization module to generate a set of output data further comprises executing the one or more worklets concurrently.

15. 1. A system including one or more computers and one or more storage devices storing instructions, The system, wherein the instructions, when executed by the one or more computers, cause the one or more computers to perform the respective operations of the method of any one of claims 1 to 14.

16. One or more computer-readable storage media storing instructions that, when executed by one or more computers, cause the one or more computers to perform the respective operations of the method of any one of claims 1 to 14.

17. A computer program product comprising instructions which, when executed by a computer, cause said computer to perform the steps of the method according to any one of claims 1 to 14.

Citation Information

Patent Citations

  • Distributed processing system, distributed processing method and distributed processing program

    JP2019035996A

  • Secured integration of third-party logic in electronic transaction processing

    US20220172183A1

  • System for updating a set of instantiated content providers based on changes in content provider directory without interruption of a network information services

    US6516349B1

  • Advertising auction system

    US8983860B1

  • Privacy preserving cross-domain machine learning

    WO2022197304A1