Trusted Server Orchestration Framework
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- GOOGLE LLC
- Filing Date
- 2023-10-17
- Publication Date
- 2026-07-30
Smart Images

Figure 0007897951000001 
Figure 0007897951000002 
Figure 0007897951000003
Abstract
Description
Technical Field
[0005] ,
[0001] This specification relates to securely executing a computing workflow in a way that enhances data security and data privacy.
Background Art
[0002] In computing systems connected to a public network such as the Internet, data security is of utmost importance. Computing systems are often protected from unauthorized access and data breaches using network security technologies such as firewalls.
[0003] A virtual machine provides an emulated version of a computing system. A virtual machine can include an emulated processing unit (e.g., a central processing unit (CPU)), memory, a network interface, and / or other computing components.
Summary of the Invention
[0004] This specification describes techniques related to securely executing a workflow that prevents other parties from accessing customizations, enables non-disclosure of workflow stages, and otherwise allows for unique customizations. A workflow is a set of executable steps through which units of work pass from start to completion. These techniques include executing the workflow in a separate environment such as a virtual machine and / or a trusted execution environment (TEE) that provides a secure sandbox while still supporting a fully functional workflow. The technology can further include applying constraints to inputs to and / or outputs from the workflow or a part thereof to maintain user privacy, prevent access to confidential customizations, and improve system integrity.
[0005] In general, one innovative aspect of the subject matter described herein is embodied by a method including the following operation: receiving a digital component request, including a set of data, from a client device and by a secure delivery system; and, in response to receiving the digital component request, the customization orchestrator of the secure delivery system identifying a multi-stage workflow for selecting a digital component from candidate digital components of a given content platform based on the set of data, wherein the multi-stage workflow includes a sequence of customization modules that are communicably coupled to each other by a common data bus, and each customization module includes a set of worklets, including one or more customized worklets provided by a given content platform, and one or more standard worklets used in the customization modules of a multiple content platform, and the secure delivery system defines the multi-stage workflow for selecting a digital component. Executing each customization module of a multi-stage workflow in a defined sequence, the execution of which includes, for each customization module, providing each customization module with a set of input data via a common data bus by the customization orchestrator, executing each worklet of the customization module in a sequence defined by the customization module to generate a set of output data, and transmitting the output data via the common data bus by the customization orchestrator, wherein the output data for a particular customization module in the sequence of customization modules includes data indicating a given digital component selected by a particular customization module based on the set of input data provided to that particular customization module, and causing a client device to present a given digital component.Other embodiments of this aspect include corresponding devices, systems, and computer programs encoded in a computer storage device and configured to perform an aspect of the method.
[0006] These and other embodiments may optionally include one or more of the following functions: Some embodiments include receiving each candidate digital component from a multi-stage workflow of a multiple content platform, including a given digital component from a multi-stage workflow of a given content platform, from a common data bus, and selecting a given digital component from the candidate digital components by a digital component selection module.
[0007] In some embodiments, each worklet in each set of worklets contains an operation defined by a portion of code configured to process data. The portion of code for the operation associated with each customized worklet is a customized portion of code provided by a given content platform. The portion of code for the operation associated with each standard worklet is a portion of code defined by an entity that manages the operations of the secure delivery system.
[0008] In some embodiments, the customization orchestrator transforms a set of input data into a defined set of inputs associated with a customization module.
[0009] In some embodiments, the customization orchestrator transforms output data into a defined set of outputs associated with a customization module. Each customization module may further include a policy engine. The policy engine can determine whether a set of input data and output data conform to a set of data policies. Based on whether the set of input data conforms to a set of data policies, the policy engine can determine whether the set of input data is provided to the customization module by the customization orchestrator. Based on whether the output data conforms to a set of data policies, the policy engine can determine whether the output data is sent to a common data bus by the customization orchestrator.
[0010] In some embodiments, a common data bus is a common data bus that includes one or more data channels. Each of the one or more data channels may be a user data channel, a candidate data channel, a context data channel, or an auxiliary data channel.
[0011] In some embodiments, each customization module includes a local data bus. The set of worklets in each customization module may be coupled together in a communicative manner by the local data bus. Each customization module may include an operations orchestrator configured to transfer data between sets of worklets via the local data bus.
[0012] In some embodiments, one or more customization modules reside within a trusted execution environment on a secure distribution system, and one or more customization modules reside on a client device.
[0013] In some embodiments, the secure delivery system executes each customization module of a multi-stage workflow in a sequence defined by the multi-stage workflow to select digital components, which includes executing one or more customization modules simultaneously.
[0014] In some embodiments, the operation orchestrator executing each worklet of the customization module in a sequence defined by the customization module to generate a set of output data includes executing one or more worklets simultaneously.
[0015] Certain embodiments of the subject matter described herein can be implemented to achieve one or more of the following advantages: Using the techniques described herein, digital components can be selected from various content providers (e.g., content platforms) while protecting user privacy. Furthermore, the technique enables such digital components to be provided by the content platform while maintaining the confidentiality and integrity of the technology and proprietary logic used by the content platform. As further described below, the system can perform the workflow stages used to select digital components, and stages involving sensitive user data and / or confidential technology and / or logic may be performed in an isolated environment, such as within the TEE and / or on a server in a virtual machine. Executing code in the TEE protects the privacy of content requesters (e.g., users) because the TEE can restrict access to information about the requester. Executing code in a virtual machine protects the content platform that supplied the code. This is because the virtual machine ensures that the customization of the content platform remains isolated, preventing other content platforms from accessing the customization of the content platform. The technique may include encrypting the code for customization, thereby ensuring the security, confidentiality, and integrity of the code.
[0016] In addition, the system can implement customization of workflow stages using customization modules. Customization modules enable the content platform to utilize user devices and / or trusted server resources of the secure delivery system, enabling a high level of usability and operability. Furthermore, this technology can be used to ensure that the data generated by the workflow stages meets certain criteria, such as criteria defining the inputs and outputs of each customization module. Such criteria can further protect the privacy of requesters by ensuring that each stage provides other stages and / or the content platform with only data that satisfies data constraints. By running customization modules containing customized code in worklet format within a trusted server (e.g., the secure delivery system) that provides an isolated execution environment, digital components can be selected quickly, accurately, and efficiently, and the security of user data and the sensitive customized code of the content platform can be securely protected. The described system and techniques also enable the selection and delivery process of such digital components to be performed with better debuggability and using fewer resources (e.g., CPU cycles) compared to approaches using standard TEEs.
[0017] Details of one or more embodiments of the subject matter described herein are shown in the accompanying drawings and the following description. Other features, aspects and advantages will become apparent from the description, drawings and claims. [Brief explanation of the drawing]
[0018] [Figure 1] This illustrates an exemplary environment in which a secure delivery system delivers digital components to client devices in a privacy-preserving manner. [Figure 2] Figure 1 shows an example of components in a secure delivery system. [Figure 3] Shows an exemplary multi - stage workflow. [Figure 4] Shows an exemplary customization module coupled to a common data bus. [Figure 5] Shows an exemplary data flow of a customization module. [Figure 6] Shows an exemplary data flow between customization modules of a multi - stage workflow. [Figure 7] Shows an example of concurrent execution of customization modules by a secure delivery system. [Figure 8] Shows an exemplary delivery of a customization module between a secure delivery system and a client device. [Figure 9] It is a flow diagram of an exemplary process for executing a secure workflow for selecting digital components. [Figure 10] It is a flow diagram of an exemplary process for executing a secure workflow for selecting digital components. [Figure 11] It is a block diagram of an exemplary computer system.
Best Mode for Carrying Out the Invention
[0019] In various drawings, like reference numerals and signs refer to like elements.
[0020] Generally, this document describes systems and techniques for selecting and presenting digital components on a user's client device in a way that protects the user's privacy and the content platform's confidential data. A secure delivery system can include one or more computers (e.g., servers) configured to perform a customized digital component selection process that uses confidential user data so that the user data is not provided to other entities. The secure delivery system can host and execute selection logic (which can be in code form) for various content platforms when selecting digital components and / or generating selection parameters for digital components based on user data, to ensure that other entities do not have access to the content platform's selection logic. In this way, both the user's data and the content platform's logic are kept secure.
[0021] Ensuring the privacy of personal data is a requirement for many computing systems, especially those connected to public networks such as the Internet. Additionally, some jurisdictions have regulations for protecting privacy. Such privacy assurances can include not only how data is stored but also the processes for controlling the sharing of data with third parties.
[0022] However, some data sharing can provide utility to the user, especially when a digital component provider attempts to customize the digital component selection process for the user. For example, if the user approves such use of their user data, private data, including aggregated private data, can be used to find both relevant and interesting content for the user. Without information about the user, such as the user's interests, it can be difficult for the system to provide relevant content.
[0023] In addition, executing code from multiple content platforms can raise issues of policy compliance and the risk of content platform data leaks to others. For example, one content platform might attempt to share data with another content platform that does not adhere to certain data policies, such as privacy-related policies or user age restriction policies. In another example, a content platform might use its code to determine how another content platform's code behaves, which could violate certain privacy and / or confidentiality policies of the content platform. Therefore, there is a need to ensure the integrity and customizability of the system as a whole, while still allowing proprietary, undisclosed code to operate on sensitive data.
[0024] This specification describes a workflow system that enables a content platform to have code for each stage of a workflow, or a subset of stages of a workflow, which runs in a Trusted Execution Environment (TEE), or in another secure or sandboxed environment of the Secure Delivery System. The result of the workflow may be content presented to the user's client device, such as digital components. As will be described in more detail below, the workflows of the content platform can be implemented using customization modules, each containing one or more worklets, at least some of which may be created or customized by the content platform.
[0025] To protect user privacy, the system can ensure that each customization module is only permitted to access data that does not violate data policies, and that the output data generated by each customization module conforms to the policies, for example, by being a defined set. Furthermore, the system can run each customization module separately and / or simultaneously. By running customization modules separately from the TEE, these valuable data assets are protected. In addition, the TEE ensures the integrity of customized worklets and / or other customized code in the content platform by ensuring that such customizations are not tampered with.
[0026] Figure 1 is a block diagram of an exemplary environment 100 in which a secure distribution system 120 distributes digital components to client devices 110 in a privacy-preserving manner. Environment 100 includes a data communication network 105, such as a local area network (LAN), wide area network (WAN), the internet, a mobile network, or a combination thereof. The data communication network 105 connects the client devices 110 to the secure distribution system 120, and connects the secure distribution system 120 to content platforms such as a supply-side platform (SSP) 140 and / or a demand-side platform (DSP) 150. The network 105 may also interconnect various content platforms and / or connect to a digital component provider 160, for example, a server of the digital component provider 160.
[0027] A client device 110 is an electronic device that can request and receive online resources via the network 105. Exemplary client devices 110 include personal computers, game devices, mobile communication devices, digital assistant devices, augmented reality devices, virtual reality devices, and other devices that can send and receive data via the network 105. While a client device 110 typically includes a user application such as a web browser to facilitate data transmission and reception via the network 105, native applications (other than browsers) running on the client device 110 can also facilitate data transmission and reception via the network 105.
[0028] A gaming device is a device that allows a user to participate in a game application. For example, a user can control one or more characters, avatars, or other rendered content displayed in the game application. A gaming device typically includes a computer processor, a memory device, and a controller interface (physically or visually rendered) that enables user control over the content rendered by the game application. A gaming device can run a game application that is stored and executed locally, or a game application that is stored and / or served at least partially by a cloud server (such as an online game application). Similarly, a gaming device can interface with a game server that runs a game application and "streams" the game application to the gaming device. A gaming device may be a tablet device, a mobile communication device, a computer, or any other device that performs functions other than running a game application.
[0029] Digital assistant devices include devices that include a microphone and a speaker. Digital assistant devices are generally capable of receiving input via voice, responding with content using audible feedback, and presenting other audible information. In some situations, digital assistant devices also include or communicate with a visual display (e.g., via a wireless or wired connection). Where a visual display is present, it can also provide feedback or other information visually. In some situations, digital assistant devices may control other devices such as lighting, locks, cameras, room temperature control devices, alarm systems, and other devices registered with the digital assistant device.
[0030] The client device 110 may include applications 112, such as a web browser and / or a native application, to facilitate the sending and receiving of data over the network 105. A native application is an application developed for a specific platform or a specific device (such as a mobile device with a specific operating system). While operations may be described as being performed by the client device 110, such operations may also be performed by applications 112 running on the client device 110.
[0031] Application 112 can present, for example, display, electronic resources such as web pages, application pages, or other application content to the user of client device 110. Electronic resources may include digital component slots for displaying digital components containing the content of the electronic resource. A digital component slot is an area of the electronic resource (such as a web page or application page) for displaying digital components. A digital component slot may also refer to a portion of an audio stream and / or video stream (another example of an electronic resource) for playing the digital components.
[0032] Electronic resources are also referred to as resources in this specification for brevity. For the purposes of this document, resources may refer to web pages, application pages, application content presented by native applications, electronic documents, audio streams, video streams, or other appropriate types of electronic resources on which digital components may be presented.
[0033] As used throughout this specification, the term “digital component” refers to a distinct unit of digital content or digital information (such as a video clip, audio clip, multimedia clip, image, text, or other content unit). A digital component can be stored electronically in a physical memory device as a single file or as a collection of files, and a digital component can include advertising information in the form of a video file, audio file, multimedia file, image file, or text file; therefore, an advertisement is a type of digital component. For example, a digital component may be content intended to supplement the content of a web page or other resource presented by application 112. More specifically, a digital component may include digital content related to resource content (for example, a digital component may relate to the same or related topics as the web page content). Thus, by providing digital components, the content of a web page or application can be supplemented and improved overall.
[0034] When application 112 loads a resource containing a digital component slot, application 112 can generate a digital component request 125-a that requests a digital component to be presented in the digital component slot. In some embodiments, the digital component slot and / or resource may contain code (such as a script) that causes application 112 to request a digital component from the secure distribution system 120.
[0035] A digital component request 125-a transmitted by the client device 110 may include data that can be used to select a digital component to present to the user of the client device 110. For example, a digital component request 125-a may include sensitive user data related to the user of the client device 110, and / or non-sensitive data, such as contextual data. Sensitive user data may include, for example, data that identifies user groups that include the user as a member. User groups may include interest-based groups. Each interest-based group may include topics of interest and a set of members that have been identified (e.g., determined or predicted) to be interested in those topics. User groups may also include, for example, a group of users who have performed a particular action on the publisher's electronic resources (e.g., a website or native application). For example, a user group may include users who have visited a website, users who have requested further information about an item, users who have interacted with (e.g., selected) a particular digital component, and / or users who have added an item to a virtual cart with the potential to acquire the item. User data may also include topics of interest to the user, user profile data, user attributes (e.g., demographic attributes), and / or data indicating resources the user has visited or viewed.
[0036] In addition to the overall description in this document, the user may be provided with controls (e.g., user interface elements that the user can interact with) that allow the user to make choices about both whether and when the systems, programs, or functions described herein may enable the collection of user information (e.g., information about the user's social networks, social actions, or activities, occupation, user preferences, or user location), and whether content or communications are transmitted from the server to the user. Furthermore, certain data may be processed in one or more ways so that personally identifiable information is removed before it is stored or used. For example, a user's identity may be processed in such a way that personally identifiable information cannot be determined, or a user's geographic location may be generalized so that the user's specific location cannot be determined if location information is obtained (e.g., down to the city, zip code, or state level). Thus, the user may have control over what information is collected about them, how that information is used, and what information is provided to them.
[0037] The context data of the digital component request 125-a can relate to, for example, the environment in which the selected digital component is presented, and can describe it. The context data may include, for example, rough location information indicating the approximate location of the client device 110 that sent the digital component request 125-a, data indicating the resource (e.g., a website or native application) or native application in which the selected digital component is presented, keywords or topics of the resource, queries presented to the search engine by the client device 110, the voice language settings of application 112 or the client device 110, the number of digital component slots in which the digital component is presented with the resource, the type of digital component slot, and / or other appropriate context information.
[0038] The secure distribution system 120 can be configured to select and provide digital components in response to digital component requests 125-a received from client devices 110. The secure distribution system 120 can be implemented using one or more server computers (or other suitable computing devices) that may be distributing to multiple locations. Generally, the secure distribution system 120 receives digital component requests 125-a from client devices 110, selects digital components based on the data contained in the digital component requests 125-a, and sends the selected digital components to the client devices 110. As will be described in more detail below, some functions of the secure distribution system 120 can be implemented on the client devices 110 in some embodiments.
[0039] Since the secure distribution system 120 receives confidential user data, it may be operated and maintained by an independent and trusted party, such as a party different from the user of the client device, the party operating the SSP 140 and DSP 150, and the digital component provider 160. For example, the secure distribution system 120 may be operated by an industry association or a government organization. In another example, the secure distribution system 120 may be operated by a content platform or another entity, and the code executed by the secure distribution system 120, such as non-customizable code, may be audited by a trusted third party.
[0040] As will be described in more detail below, the secure distribution system 120 can select one or more digital components from a set of digital components stored in the digital component repository 130 and / or from a set of digital components received from one or more content platforms, for example from the SSP 140. The digital component repository 130 stores digital components received from content platforms (for example from the SSP 140 and / or DSP 150) and additional data (e.g., metadata) for each digital component.
[0041] The metadata for a digital component may include, for example, delivery criteria that define the conditions under which a digital component is eligible to be supplied to a client device 110 in response to a digital component received from the client device 110, and / or selection parameters that indicate the amount given to the issuer when the digital component is displayed and / or presented with the issuer's resources and interacted with by a user. For example, the delivery criteria for a digital component may include location information indicating a geographical location eligible to present the digital component, user group membership data that identifies a user group eligible to present the digital component, resource data that identifies a resource eligible to present the electronic resource, topics of interest, and / or other appropriate delivery criteria. The delivery criteria may also include negative criteria, such as criteria that indicate a situation under which a digital component is not eligible (e.g., a specific resource or a specific location). Other data that can be used to select a digital component may also be stored in the digital component repository along with references to that digital component (e.g., as a link or metadata).
[0042] SSP140 is a hardware and / or software-implemented technology platform that automates the process of acquiring the digital components of a resource. Resource issuers can use SSP140 to manage the process of acquiring the digital components of the digital component slots of their resources. Each issuer may have a corresponding SSP140 or multiple SSP140s. Some issuers may use the same SSP140.
[0043] DSP150 is a hardware and / or software-implemented technology platform that automates the process of delivering digital components for presentation using resources and / or applications. DSP150 can interact with multiple supply-side platforms (SSPs) on behalf of a digital component provider (DSP) (160) to provide digital components for presentation using resources from multiple different publishers. The DSP150 can create (or otherwise publish) digital components to be presented in the digital component slots of the publisher's resources.
[0044] In this example, user data does not cross a trust boundary 107 that isolates the client device 110, the secure distribution system 120, and the digital component repository from the SSP 140, DSP 150, and the digital component provider 160. In this way, entities other than the client device 110 and the secure distribution system 120 do not receive the user data contained in the digital component request 125-a, at least in an unencrypted form. This protects user privacy and data security, in particular, compared to technologies that transmit user data over the internet using third-party cookies.
[0045] To select digital components, the secure distribution system 120 can execute secure workflows for multiple content platforms, such as multiple DSPs 150. Each DSP 150's secure workflow can include customized code that selects candidate digital components based on user data from a digital component request 125-a. In this way, candidate digital components can be selected based on user data and sensitive content platform logic without providing user data to the content platform.
[0046] An exemplary process for selecting and providing digital components to be presented on client device 110 is shown in stages A to I, which illustrate the flow of data between components in environment 100.
[0047] In stage A, application 112 sends a digital component request 125-a to the secure distribution system 120. As described above, application 112 can send a digital component request 125-a to request a digital component for presentation in the digital component slot of the resource presented by application 112. The digital component request 125-a may include user data and / or context data.
[0048] In stage B, the secure delivery system 120 sends a context-based digital component request 125-b to the SSP 140. The context-based digital component request 125-b may include context data from the digital component request 125-a received from application 112. However, the context-based digital component request 125-b does not include any user data. The secure delivery system 120 may temporarily store user data while waiting for a response from the SSP 140. The server 120 may send the context-based digital component request 125-b to the SSP 140 to the issuer of the resource presented or about to be presented by application 112. The secure delivery system 120 can generate a new context-based digital component request 125-b that includes context data, or it can remove user data from the digital component request 125-a and forward the digital component request 125-a without user data to the SSP 140.
[0049] In stage C, SSP140 forwards the context-based digital component request 125-b to one or more DSPs 150. In stage D, each DSP 150 sends to SSP140 one or more digital components, for example, one or more selection parameters for digital components stored in the digital component repository 130. For example, a DSP 150 can select a digital component based on the context data of the context-based digital component request 125-b and determine the selection parameters for the digital component based on the context data. A DSP 150 can also provide digital components and selection parameters for digital components, for example, digital components not stored in the digital component repository 130. Each DSP 150 can send to SSP140 one or more selection parameters, along with data indicating the digital component to which the selection parameter applies. Each DSP 150 can also send to SSP140 one or more digital components and data indicating the selection parameters for each digital component.
[0050] In stage E, the SSP 140 sends a digital component response 129 containing the digital component and / or selection parameters to the secure delivery system 120. In some embodiments, the SSP 140 can filter the digital component and / or selection parameters before sending them to the secure delivery system 120 in the response 129. For example, the SSP 140 can filter the digital component and / or selection parameters based on publisher controls specified by the publisher of the resource presented by the application 112. In a particular example, the publisher of a web page for a specific event may define, as a publisher control, that digital components related to another event will not be presented on this web page. The SSP 140 can filter based on rules or other data provided by the publisher.
[0051] In some embodiments, stages B to E are optional selection stages for obtaining additional digital components as candidates for presentation to the user in response to a digital component request 125-a. In such embodiments, the secure distribution system 120 can select digital components from those whose metadata is stored in the digital component repository 130.
[0052] In stage F, the secure delivery system 120 queries the digital component repository 130 for a set of digital components selected based on the user data of the digital component request 125-a. For example, the server 120 may present a query that defines the user data of the digital component request 125-a as the query condition. In some embodiments, the query may also include context-based conditions. For example, the query may request the retrieval of digital components that include a specific user group and / or a specific geographical location as the delivery criterion. As shown after stages B to E, the secure delivery system 120 may query the digital component repository 130 in parallel with these stages to reduce latency in selecting and providing digital components to the application 112.
[0053] In stage G, server 120 receives one or more user-based digital components (or data identifying digital components) and selection parameters for each digital component from the digital component repository 130. This set of digital components may include those with delivery criteria that match the query conditions.
[0054] In stage H, the secure distribution system 120 selects digital components to provide to application 112 for presentation in the digital component slot. The secure distribution system 120 can select digital components from a set of candidate digital components, including digital components received from SSP 140 and digital components received from the digital component repository 130. The secure distribution system 120 can select digital components from two sets based on the selection parameters of each digital component in the two sets. For example, the secure distribution system 120 can select the digital component with the best selection parameters. In another example, for each candidate digital component, the secure distribution system 120 can select a digital component using a score based on a combination of the candidate digital component's selection parameters and its predicted performance (e.g., predicted user interaction rate).
[0055] As will be described in more detail below, the secure delivery system 120 can execute a secure workflow of the content platform to select candidate digital components to include in a set of candidate digital components that the secure delivery system 120 will provide to the client device 110. The secure workflow can be executed in addition to querying the digital component repository, or instead of querying the digital component repository 130. For example, the secure workflow of the content platform can be used to select a digital component from multiple digital components retrieved from the digital component repository 130, and / or to determine the selection parameters of the digital component retrieved from the digital component repository 130.
[0056] In stage I, the secure distribution system 120 provides the selected digital components to application 112. Then, application 112 can present the resources presented by application 112 to the digital components.
[0057] Figure 2 shows exemplary components of the secure delivery system 120 of Figure 1. Generally, the secure delivery system 120 can securely execute a multi-stage workflow that receives a digital component request 125-a from a client device 110, selects a digital component, and / or generates selection parameters for the digital component, and can deliver the digital component 127 to the client device 110. The secure delivery system 120 may include an interface engine 210, a TEE 205 on which the multi-stage workflow 215 is executed, and a customization orchestrator 230. Each workflow 215 can run on a common TEE, or each workflow 215 can run on its own dedicated TEE. For example, the secure delivery system 120 may include a separate TEE 205 for each workflow 215, and separate TEE 205s for each workflow 215, which are different from each other's TEE 205s. In some embodiments, each workflow 215 runs on a VM, which can be started and executed by the TEE 205. In some embodiments, individual worklets or customization modules 220 run on a VM, which can be started and executed by the TEE205.
[0058] The interface engine 210 is configured to receive digital component requests 125 and, in response to a digital component request 125, can provide a digital component 127 and / or a reference to the digital component 127. The reference to the digital component may include an identifier for the digital component or a resource locator, such as a Uniform Resource Locator (URL) or Universal Resource Identifier (URI), which allows the client device 110 to download the referenced digital component 127 from a server connected to the network 105.
[0059] The interface engine 210 may include an application programming interface (API) configured to accept data (digital component requests 125) provided to the secure distribution system 120 and / or to provide data (e.g., digital components 127) to other components of the environment 100 in Figure 1. Other types of interfaces may also be used to send and receive data.
[0060] Generally, when a digital component request 125 is received, the interface engine 210 can provide the digital component request 125, or data extracted from the digital component request 125, to the customization orchestrator 230. Similarly, if a digital component 127 is selected using the multi-stage workflow 230 of the content platform, the customization orchestrator 230 can provide the interface engine 210 with the selected digital component or a reference to the digital component 127, which can then be provided to the client device 210.
[0061] A customization orchestrator 215, which can be implemented in the software and / or hardware of the secure distribution system 120, is configured to manage the execution of a secure multi-stage workflow 215 of the content platform to obtain a set of candidate digital components, and / or to manage the execution of a secure workflow for selecting digital components from the set of candidate digital components. Although shown outside of the TEE 205, the customization orchestrator 230 can run inside the TEE 205 in some embodiments.
[0062] As will be described in more detail below, each workflow 215 may include customization modules 220, which are coupled to a common data bus 225 that allows the customization modules 220 to transfer data to each other. The combination of customization modules 220 and the common data bus 225 for a multi-stage workflow 215 can be called a workflow unit. The customization orchestrator 215 is configured to manage the transfer of data between the customization modules 220 using the common data bus 225 and to manage the execution of worklets in the customization modules 220.
[0063] The content platform, for example, the digital component selection process of DSP150, may have multiple stages defined by a multi-stage workflow 215. In some embodiments, the overall sequence of stages can be made rigid so as not to be customized by the content platform. In some embodiments, the content platform can be customized so that the stages are executed in different orders or some are executed simultaneously.
[0064] Processes performed in several stages can be customized by the content platform using the customization module 220. For example, the digital component selection process may have a stage in which the digital component request 125 is processed to extract data from the digital component request 125. This stage may be a default stage in which default code that cannot be customized by the content platform, such as a standard worklet, is used by the customization orchestrator 215.
[0065] Subsequent steps may include selecting candidate digital components and generating corresponding selection parameters. At this stage, the customization orchestrator 215 can execute customized worklets of the customization module 220 provided by the content platform to select candidate digital components and generate corresponding selection parameters.
[0066] Since the logic provided by the content platform is typically considered confidential, the customization module 220 can be securely stored by the secure distribution system 120 and executed in an isolated environment such as TEE205. Other standard or default code can be executed outside of the isolated environment. In this way, this other code can be executed faster and more efficiently than if the code were executed in TEE205, which may include encryption and other security measures.
[0067] The customization orchestrator 230 can execute a multi-stage workflow 215 of a multiple content platform, such as a DSP 150, to obtain a set of candidate digital components. Each multi-stage workflow 215 can output one or more candidate digital components and, for each candidate digital component, corresponding selection parameters. These candidate digital components and their selection parameters can be determined based on user data, as they are executed in a secure environment.
[0068] The customization orchestrator 230 can also receive candidate digital components from the content platform. For example, the customization orchestrator 230 can receive candidate digital components selected based on contextual data, for example, using steps B to E in Figure 1 as described above. The set of candidate digital components from which digital components are selected for the client device 110 can include candidate digital components output by the secure workflow 215 and candidate digital components received from the content platform.
[0069] Next, the secure distribution system 120 can select a digital component from candidate digital components in various ways. For example, TEE205 can select a digital component based on the selection value of the candidate digital component. In another example, a customization orchestrator can execute a customization module 220 or workflow 215 of SSP140 corresponding to the resource where the digital component has been selected in order to select the digital component. In this example, the custom logic of SSP140 can be executed within a secure environment provided by the secure distribution system 120 in order to select the digital component.
[0070] As will be described in more detail below, the secure workflow 215 and / or the customization module 220 of workflow 215 can be executed by the secure delivery system 120 and / or the client device 110. For example, the workflow 215 or customization module(s) 220 used to select a digital component from candidate digital components can be executed by either the secure delivery system 120 or the client device 110, depending on the embodiment. This protects user privacy and eliminates the need for observers outside the trust boundary 107 to learn about the user.
[0071] For example, if a digital component is selected without using the secure distribution system 120 or TEE, the digital component will be exposed outside the trust boundary 107. For instance, a malicious DSP 150 could set up a repository within the trust boundary 107 that contains only digital components eligible for distribution to a user who likes dogs. Even a single encrypted digital component, if returned outside the trust boundary 107 and information about the digital component cannot be gathered from the data itself, could allow an observer outside the trust boundary 107 to know that the user likes dogs because the digital component was returned from a repository containing only digital components for a user who likes dogs. Such learning about the user's interests is prevented by performing the selection using the TEE 205 and / or client device 110.
[0072] Figure 3 shows an exemplary multi-stage workflow 215. Generally, the multi-stage workflow 215 includes multiple customization modules 220 that are connected to each other in a communicative manner by a common data bus 225. The common data bus 225 can be implemented in hardware and / or software. For example, a software data bus may include one or more data communication channels that facilitate communication between software modules, for example, between customization modules 220. The customization modules 220 are configured to read data from each of the data channels and write data back to the data channels of the common data bus 225, as will be described in more detail below with reference to Figures 4 and 5.
[0073] In some embodiments, the common data bus 225 may include multiple channels for different types of data. For example, the common data bus 225 may include a user data channel for transferring user data between customization modules 220. The customization orchestrator 230 can extract user data from a digital component request 225-a and send the user data to one or more of the customization modules 220 via the user data channel. The customization modules 220 can also use the user data channel to transfer user data to each other. For example, one customization module 220 may provide user data to another customization module 220 configured to select candidate digital components based on the user data and generate selection parameters for the candidate digital components.
[0074] The common data bus 225 may include candidate data channels for transferring data about candidate digital components between customization modules 220. Continuing from the previous example, customization module 220 can provide data identifying candidate digital components to other customization modules 220 configured to generate selection parameters. In another example, customization orchestrator 230 may receive a response 129 containing candidate digital components selected based on non-sensitive data, for example, based on contextual data. Customization orchestrator 230 can provide data identifying these candidate digital components to customization modules 230 via the candidate data channels.
[0075] The common data bus 225 may include context data channels for transferring context data between customization modules 220. For example, a customization orchestrator 230 can extract context data from a digital component request 125-a and send it to one or more customization modules 220 via the context data channels. Similarly, one customization module 220 can send context data to another customization module 220 via the context data channels.
[0076] The common data bus 225 may include auxiliary data channels for transferring auxiliary data between customization modules 220. The auxiliary data may include data retrieved from the content platform of the workflow 215 via an auxiliary API. In some embodiments, the auxiliary data is immutable.
[0077] Generally, candidate data channels, context data channels, and auxiliary data buses can contain data specific to the content platform on which workflow 215 is executed. Therefore, the common data bus of each workflow 215 may not connect to other workflows on other content platforms. For example, each workflow 215 can run in a separate, isolated environment, such as a separate TEE205.
[0078] By using multiple data channels, the amount of processing performed by the components of the secure distribution system 120 is reduced. For example, some components of the secure distribution system 120 can be configured to process only certain types of data. By using different channels for different types of data, these components do not waste resources that would otherwise be used to process other types of data. For example, as described below with reference to Figure 4, the secure distribution system 120 may include a policy engine 405 that can evaluate user data before providing it to the customization module 220 and / or before allowing data from the customization module 220 to be output to the common data bus 225. By including user data in a dedicated user data channel, the policy engine 405 can enforce the correct use of user data while processing only the data on the user data channel.
[0079] Each customization module 220 can be configured to perform one or more tasks in the workflow 215, for example, one or more tasks at a given stage of the workflow 215. For example, one customization module 220 may be configured to select one or more candidate digital components based on user data, context data, and / or other data, while another customization module 220 may be configured to generate selection parameters for each candidate digital component. Another customization module 220 may be configured to filter candidate digital components based on eligibility criteria, such as the availability of resources to satisfy the selection parameters, the content platform for enabling / disabling the candidate digital components, and the publisher's requirements. Another customization module 220 may be configured to expand the candidate digital components into multiple variations of the same candidate digital component having different visual characteristics (e.g., different layouts or content), and then select from these variations.
[0080] Each customization module 220 may include one or more worklets 305 and a local data bus 310 that connects the worklets 305 of the customization module 220 in a communicative manner. The worklets can communicate data with each other via the local data bus 310. The local data bus 310 may be implemented in a similar manner to the common data bus 225.
[0081] Each worklet 305 may contain code to perform a subtask of the customization module 220. For example, a task in the customization module 220 might be to select candidate digital components whose delivery criteria are satisfied by the data of digital component request 125-a. Worklet 305 of this customization module 220 may contain code to identify candidate digital components that have contextual delivery criteria satisfied by the contextual data of the digital component request by comparing keywords in the contextual data of the digital component request 125-a with keywords in the delivery criteria of the set of digital components. Another worklet 305 of this customization module 220 may be configured to identify candidate digital components that have user-based delivery criteria satisfied by the user data of the digital component request 125-a by comparing user data in the digital component request 125-a with user parameters in the delivery criteria of the digital components.
[0082] The customization module 220 may include one or more standard worklets and / or one or more customized worklets. A standard worklet is provided as part of the secure delivery system 120 and is a worklet that contains code for performing a task, for example, default code for performing a task. For example, a standard worklet may not be customizable by the content platform for the worklet, but may be selected for inclusion in the customization module 220 for the content platform's workflow 215.
[0083] A customized worklet is a worklet that can be customized by the content platform. A customized worklet can contain any customized code provided by the content platform. For example, a customized worklet may contain code that defines a set of rules for selecting candidate digital components, or code that defines a trained machine learning model that is trained to select candidate digital components or to generate selection parameters for candidate digital components.
[0084] In another example, the secure distribution system 220 can make customizable worklets available to the content platform. These customizable worklets may include several standard codes and components that can be customized by the content platform to generate the customized worklets.
[0085] The content platform can generate the customization module 220 by creating and / or selecting worklets 305 for the customization module 220 and arranging the worklets 205 in sequence. The sequence of worklets 305 may include worklets 305 that are executed simultaneously, as described below with reference to Figure 4. The content platform can also define the types of data that are input to and output from each worklet 205, and / or exchanged between worklets 305 via the local data bus 310.
[0086] The content platform can also arrange the customization modules 220 in sequence, which may include customization modules 220 running simultaneously and / or a simultaneous sequence of customization modules 220, as described below with reference to Figure 7. The content platform can also define the types of input data 315 and output data 320 for each customization module 220.
[0087] The customization orchestrator 230 is configured to execute the customization modules 220 and their worklets 305 based on the arrangement of the worklets 305 and customization modules 220 defined by the content platform. The customization orchestrator 230 also controls the input data 315 provided to each customization module 220 and the output data output to the common data bus 225 by each customization module 220. For example, if a customization module 220 consumes a particular type of data, the customization orchestrator 230 can provide that data to the customization module 220 via the common data bus 225.
[0088] In some embodiments, the customization orchestrator 215 can convert input data 315 to respond to the customization module 220 into a defined set of inputs based on the definitions provided by the corresponding customization module 220. For example, a particular customization module 220 may have restricted access to user-related data, and the customization orchestrator 215 can ensure that only eligible user data is provided to the customization module 220.
[0089] In some embodiments, as described below, each customization module 220 may include an operations orchestrator 403 (Figure 4) that executes and manages operations performed within the worklet 305. Similar to the customization orchestrator 215, the operations orchestrator can manage the distribution of data to and from the worklet 305 of the customization module 220 via the local data bus 225.
[0090] After executing the sequence of worklet 305, the customization module 220 can generate output data 320. The customization orchestrator 215 can then send the output data 320 to another customization module 220 using the common data bus 225. In some examples, as with defining input 315, the customization orchestrator 215 can convert the output data 320 corresponding to a customization module 220 into a defined set of outputs based on the definition of the corresponding customization module 220.
[0091] In this way, the customization orchestrator 215 can execute each of the customization modules 220 to select one or more candidate digital components, expand the candidate digital components into multiple variations, filter the candidate digital components based on eligibility criteria, and / or generate selection parameters for each candidate digital component. The final customization module 220 of the workflow 215 can generate this data and provide it to the customization orchestrator 215.
[0092] Figure 4 shows an exemplary customization module 220 coupled to a common data bus 225. This exemplary customization module 220 includes two standard worklets 305-a and 305-d, as well as two customized worklets 305-b and 305-c that run concurrently. Although not shown, each worklet 305a-305d is communicably coupled to a local data bus 310.
[0093] The operation orchestrator 403 of the customization module 220 can execute each of the worklets 305a to 305-d in the order defined by the customization module 220. For example, the operation orchestrator 403 may provide a defined set of inputs from input data 315 to the standard worklet 305-a. The operation orchestrator 403 can execute the standard worklet 305-a and use the local data bus 310 to provide the output of the standard worklet 305-a to the customized worklets 305-b and 305-c.
[0094] The operation orchestrator 403 can execute customized worklets 305-b and 305-c simultaneously (e.g., in parallel), so that each worklet 305-b and 305-c processes the output of standard worklet 305-a as input and generates a corresponding output related to the operation of the customized worklet. The operation orchestrator 405 can then execute standard worklet 305-d by providing the outputs of both customized worklet 305-b and customized worklet 305-c as input to standard worklet 305-d, and the operation orchestrator 403 can provide the output of standard worklet 305-d to the local data bus 310. The customization orchestrator can then convert the output of standard worklet 305-d into a defined set of output data 320. The customization orchestrator 403 can provide the output data 320 to the common data bus 225.
[0095] In some examples, the customization module 220 is coupled to the policy engine 405. The policy engine 405 can determine whether the input data 315, the output data 320, or both conform to a set of data policies.
[0096] Based on whether the input 315, the output 320, or both conform to a set of data policies, the policy engine 405 can decide whether to provide the input data 315 to the customization module 220, send the output data 320 to the common data bus 225, or both.
[0097] A set of data policies can be defined by entities operating the content platform and / or the secure delivery system 120. For example, input 315 may violate a data policy related to user privacy, and the policy engine 405 may determine that input 315 violates a data policy and refrain from providing input 315 to the customization module 220.
[0098] Figure 5 shows an exemplary data flow for the customization module 220. Generally, the operation orchestrator 403 can use the local data bus 310 to execute each worklet 305 in the sequence of worklets 305 of the customization module 220. The operation orchestrator 403 can read data from the local data bus 310, write data to the local data bus 310, and execute each worklet 305.
[0099] In particular, the operation orchestrator 403 can execute standard worklet 305-a and customized worklet 305-b by providing inputs to each worklet. The inputs may be data read from a specific data channel of the local data bus 310. The local data bus 310 may be an internal data bus for the operation of the customization module 220.
[0100] Furthermore, the operation orchestrator 403 may use the local data bus 310 to provide the outputs of the executed standard worklet 305-a and the executed customized worklet 305-b to subsequent worklets 305 in the sequence of worklets 305. The operation orchestrator 403 may write data related to the output to a specific data channel of the local data bus 310. The operation orchestrator 403's operation to write data to the local data bus 310 may, in some examples, persist throughout the customization module 220 based on a defined set of outputs in the customization module 220.
[0101] For example, the operation orchestrator 403 can execute standard worklet 305-a as the first worklet in a sequence of worklets. For example, the operation orchestrator 403 can provide standard worklet 305-a with a defined set of inputs and associated data for the customization module 220. Standard worklet 305-a can process the data and produce an output. The operation orchestrator 403 can provide the output of standard worklet 305-a to the local data bus 310. In particular, the operation orchestrator can write the output and associated data to data channels 505 and 510 of the local data bus 310. Data channel 505 can be associated with a defined set of outputs for the customization module 220, and the data associated with data channel 505 can persist across the customization module 220. Data channel 510 can be associated with any data provided by a content provider, and any data may not persist across the customization module 220.
[0102] Next, the operation orchestrator 403 can execute the customized worklet 305-b by reading data from the data channel 505 and providing the data from the data channel 505 as input to the customized worklet 305-b. The customized worklet 305-b can process the input to generate an output. The operation orchestrator 403 can write the output to the data channel 515, which can then be associated with a defined set of outputs for the customization module 220.
[0103] The operation orchestrator 403 can read data from data channel 510 (e.g., arbitrary data from a content provider) and data from data channel 515 (e.g., the output of a customized worklet 305-b) and provide the data as input to a standard worklet 305-c. In some examples, the standard worklet 305-c can process the input and generate the output of the customization module 220.
[0104] Figure 6 shows an exemplary data flow between customization modules 220 in a multi-stage workflow 215. Generally, the customization orchestrator 230 can execute the customization modules 220 of the secure workflow 215 and exchange data between the customization modules 220 using the common data bus 225. The customization orchestrator 230 can read data from the customization modules 220 and write data to the common data bus 225 for use in subsequent executions of the customization modules 220.
[0105] In particular, the customization orchestrator 230 can execute each of the customization modules 220 by providing inputs to each of the customization modules 220 in the secure workflow 215. The inputs can include data from the output of the previous customization module 220 in the secure workflow 215, and / or other input data defined for the customization module 220. The customization orchestrator 230 can read data read from a specific data channel of the common data bus 225. Operations of the customization orchestrator 230 to write data can, in some examples, persist throughout the customization module 220 based on a defined set of outputs for the customization module 220.
[0106] For example, the customization orchestrator 230 can provide a set of inputs to the customization module 220-a. The operation orchestrator 403-a of the customization module 220-a can execute the worklet 305-a of the customization module 220-a by reading data from the local data bus 310-a and providing the data as input to the worklet 305-a. The worklet 305-a can process the inputs and generate outputs. The operation orchestrator 403-a of the customization module 220-a can write outputs to the data channel 510 of the local data bus 310-a and to the data channel 505-a of the local data bus 310-a. The data channel 510 can be associated with any data from a content provider, and the data channel 505-a can be associated with a defined set of outputs of the customization module 220-a. Other types of data channels can also be used, as described herein.
[0107] Next, the customization orchestrator 230 can write data from data channel 505-a to data channel 605 of the local data bus. Data channel 605 can be a user data channel, a candidate data channel, a context data channel, or an auxiliary data channel. In some examples, the customization orchestrator 230 can convert the data from data channel 505-a into a set of output data based on the definitions corresponding to the customization module 220-a.
[0108] The customization orchestrator 230 can read data from the data channel 605 and provide the data as input to the customization module 220-b. In some examples, the customization orchestrator 230 can transform the data from the data channel 605 into a set of inputs based on the definitions corresponding to the customization module 220-b.
[0109] The customization orchestrator 230 can write data to data channel 505-b of the local data bus 310-b, and the operation orchestrator 403-b of the customization module 220-b can provide data as input to worklet 305-b. Both data channels 505-b and 505-c can be associated with a defined set of outputs of the customization module 220-b.
[0110] Figure 7 shows an example of simultaneous execution of customization modules 220 by the secure distribution system 120. Generally, the customization orchestrator 230 can simultaneously execute multiple customization modules 220 of the secure workflow 215 based on multiple concurrent execution paths 705, for example, execution paths 705-a and 705-b.
[0111] The customization orchestrator 230 can execute multiple concurrent execution paths 705, each of which can contain a sequence of one or more customization modules 220. For example, the customization orchestrator 230 can split an execution path into two concurrent execution paths 705. The customization orchestrator 230 can simultaneously execute the customization module 220 of the first concurrent execution path 705-a and the customization module 220 of the second concurrent execution path 705-b.
[0112] The customization orchestrator 230 can execute customization module 220-a, corresponding to concurrent execution path 705-a, and then customization module 220-b, while simultaneously executing customization module 220-c, corresponding to concurrent execution path 705-b. Next, the customization orchestrator 230 can use the common data bus 225 to merge the data output by the customization modules 220 of concurrent execution paths 705-a and 705-b after each corresponding customization module 220 has been executed.
[0113] Figure 8 shows an exemplary delivery of customization modules 220 between the secure delivery system and the client device 110. In this example, some customization modules 220 of the secure workflow 215 are executed on the client device 110, while other customization modules 220 of the workflow 215 are executed on the secure delivery system 120.
[0114] The customization orchestrator 230 can run one or more customization modules 220 on the client device 110, and the customization orchestrator 230 can run one or more customization modules 220 on the secure distribution system 120 using the corresponding common data bus 225. The customization orchestrator 230 can exchange data in the form of inputs and outputs from the client device 110 and the common data bus 225 on the secure distribution system 120, respectively.
[0115] For example, client device 110 can be associated with a first common data bus 225-a, and client device 110 can include a first customization module 220-a and a second customization module 220-b. Customization orchestrator 230 can execute customization modules 220-a and 220-b using the respective operation orchestrators for each customization module 220, and execute the respective worklets 305 of each customization module 220 using each local data bus 310. Customization orchestrator 230 can provide inputs and outputs to customization modules 220 using the common data bus 225-a, where the inputs and outputs may be based on data from the common data bus 225-b of server 120. In particular, the customization orchestrator 230 can execute the customization module 220-c using the operation orchestrator 403 to execute the worklet 305 using the local data bus 310-c. The customization orchestrator 230 can provide input to the customization module 220-c from the common data bus 225-c, where the input may be associated with data from the common data bus 225-a of the client device 110.
[0116] Figure 9 is a flowchart of an exemplary process 900 for executing a secure workflow for content selection. For convenience, process 900 is described as being executed by a system for executing a secure workflow for content selection, such as the secure distribution system 120 of Figures 1 and 2, which is appropriately programmed to execute the process. The operation of process 900 can also be performed as instructions stored in one or more computer-readable media, which may be non-temporary, and the execution of instructions by one or more data processing devices can cause one or more data processing devices to execute the operation of process 900. One or more other components described herein can execute the operation of process 900.
[0117] The system can receive digital component requests (905). The system can be a secure delivery system, and the system can receive digital component requests from client devices. A digital component request includes a dataset. The dataset may include user data and / or context data, as described herein.
[0118] The system can identify multi-stage workflows for selecting digital components to provide to a client device in response to a digital component request (910). The system can identify multi-stage workflows defined by one or more content platforms, as will be further described below with reference to Figure 10. Each workflow may be configured to select one or more candidate digital components to be added to a set of candidate digital components from which the digital component to be presented on the client device will be selected in response to a digital component request.
[0119] The system can execute multi-stage workflows on a multiple content platform (915). The system can execute each multi-stage workflow by executing a sequence of customization modules, as described herein.
[0120] The system can receive candidate digital components from each step of a multi-stage workflow of a multiple content platform (920). The system can include candidate digital components from each workflow of a set of candidate digital components, which are selected to be presented on the client device in response to a digital component request.
[0121] The system can select a given digital component (925). In particular, the system can select a given digital component from candidate digital components based on the selection parameters of the digital component. For example, the system can select a digital component having the highest selection parameter value. The system can cause a client device to present a given digital component by, for example, providing the digital component to the client device.
[0122] Figure 10 is a flowchart illustrating an exemplary process for executing a secure workflow for selecting digital components. For convenience, process 1000 is described as being executed by a system for executing a secure workflow for content selection, such as the secure distribution system 120 of Figures 1 and 2, which is appropriately programmed to execute the process. The operation of process 1000 can also be implemented as instructions stored in one or more computer-readable media, which may be non-temporary, and the execution of instructions by one or more data processing devices can cause one or more data processing devices to execute the operation of process 1000. One or more other components described herein can execute the operation of process 1000.
[0123] The system can receive digital component requests (1005). The system can be a secure distribution system, and the system can receive digital component requests from client devices. A digital component request includes a set of data, e.g., user data and / or context data.
[0124] The system can identify multi-stage workflows for selecting digital components (1010). The system can use a customization orchestrator to identify each multi-stage workflow for selecting a digital component from a set of candidate digital components associated with a content platform among multiple content platforms. In particular, a multi-stage workflow includes a sequence of customization modules coupled together so as to be able to communicate with each other by a common data bus. Each customization module may include a set of worklets. Worklets can be customized worklets provided by the content platform or standard worklets used in the customization worklets of the multiple content platform.
[0125] In some cases, some of the customization modules (e.g., one or more customization modules) reside in a trusted execution environment on a secure delivery system, while some of the customization modules reside on client devices.
[0126] The system can execute a multi-stage workflow for each content platform of one or more content platforms (1015). The system can execute each customization module of each multi-stage platform to select digital components.
[0127] In particular, for each customization module, the system can use a customization orchestrator to provide a set of input data to the customization module via a common data bus (1020). The customization orchestrator can then convert the set of input data into a defined set of inputs associated with the customization module.
[0128] In some examples, the system includes a policy engine that determines whether the output data conforms to a set of data policies. Based on whether the input data conforms to a set of data policies, the policy engine determines whether to provide the input data to the customization module.
[0129] The system can execute each worklet of the customization module (1025). In particular, the system can use an operations orchestrator to execute each worklet in a sequence defined by the customization module to generate a set of output data. In some examples, the customization module includes a local data bus, and the set of worklets are coupled together so that they can communicate with each other via the local data bus. In this case, the operations orchestrator provides data to each worklet via the local data bus. In some examples, the system executes the worklets concurrently (e.g., in parallel).
[0130] The system can send output data to a common data bus (1030). The system can also send output data using a customization orchestrator. The output data includes data indicating a given digital component selected by the customization module based on a set of input data provided to the customization module. In some examples, the customization orchestrator can convert the output data into a defined set of outputs associated with the customization module.
[0131] In some examples, the system includes a policy engine that determines whether the output data conforms to a set of data policies. Based on whether the output data conforms to the set of data policies, the policy engine determines whether the output data is sent to a common data bus.
[0132] The system can then cause the client device to present the digital components (1035). If the customization module is executed in the secure delivery system, the secure delivery system can provide the digital components to the client device for presentation. If the final selection of some customization modules and / or digital components is performed in the client device, the client device can present the digital components after the selection.
[0133] Figure 11 is a block diagram of an exemplary computer system 1100 that can be used to perform the operations described above. System 1100 includes a processor 1110, memory 1120, storage device 1130, and input / output device 1140. Each of components 1110, 1120, 1130, and 1140 can be interconnected, for example, using a system bus 1150. The processor 1110 can process instructions to be executed within system 1100. In one embodiment, the processor 1110 is a single-threaded processor. In another embodiment, the processor 1110 is a multi-threaded processor. The processor 1110 can process instructions stored in memory 1120 or storage device 1130.
[0134] The memory 1120 stores information within the system 1100. In one embodiment, the memory 1120 is a computer-readable medium. In one embodiment, the memory 1120 is a volatile memory unit. In another embodiment, the memory 1120 is a non-volatile memory unit.
[0135] The storage device 1130 can provide high-capacity storage to the system 1100. In one embodiment, the storage device 1130 is a computer-readable medium. In various different embodiments, the storage device 1130 may include, for example, a hard disk device, an optical disk device, a storage device shared over a network by multiple computing devices (e.g., a cloud storage device), or some other high-capacity storage device.
[0136] The input / output device 1140 provides input / output operations for the system 400. In one embodiment, the input / output device 1140 may include one or more of the following: a network interface device, e.g., an Ethernet card; a serial communication device, e.g., an RS-232 port; and / or a wireless interface device, e.g., an 802.11 card. In another embodiment, the input / output device may include a driver device configured to receive input data and transmit output data to other devices, e.g., a keyboard, printer, display, and other peripheral devices 1160. However, other embodiments such as mobile computing devices, mobile communication devices, and set-top box television client devices may also be used.
[0137] While Figure 11 illustrates an exemplary processing system, the subjective and functional operational embodiments described herein can be implemented in other types of digital electronic circuits, or in computer software, firmware, or hardware, or a combination of one or more thereof, including the structures disclosed herein and their structural equivalents.
[0138] Electronic documents (simply called documents for brevity) do not necessarily correspond to files. A document can be part of a file that holds other documents, a single file dedicated to that document, or multiple linked files.
[0139] Embodiments of subject matter and functional operation described herein can be implemented in digital electronic circuits, computer software, firmware, or hardware including structures disclosed herein and their structural equivalents, or in combination of one or more thereof. Embodiments of subject matter described herein can be implemented using one or more modules of computer program instructions encoded on a computer-readable medium for execution by a data processing device or for controlling the operation of a data processing device. The computer-readable medium may be a hard drive of a computer system, or an optical disc sold through retail channels, or a manufactured product such as an embedded system. The computer-readable medium may be acquired separately and subsequently encoded with one or more modules of computer program instructions, for example, by delivery of one or more modules of computer program instructions over a wired or wireless network. The computer-readable medium may be a machine-readable storage device, a machine-readable storage substrate, a memory device, or a combination of one or more thereof.
[0140] The term "data processing device" encompasses all devices, machines, and equipment for processing data, including, for example, programmable processors, computers, or multiple processors or computers. In addition to hardware, a device may also include code that creates the execution environment for the computer program in question, such as processor firmware, protocol stacks, database management systems, operating systems, runtime environments, or code comprising one or more of these. Furthermore, a device may utilize a variety of different computing model infrastructures, including web services, distributed computing, and grid computing infrastructures.
[0141] A computer program (also known as a program, software, software application, script, or code) can be written in any preferred programming language, including compiled or interpreted languages, declarative or procedural languages, and can be deployed in any preferred form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program does not necessarily correspond to a file in a file system. A program can be stored in a single file dedicated to it, in part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), or in multiple collaborative files (e.g., a file that stores one or more modules, subprograms, or parts of code). A computer program can be deployed to run on one computer, or on multiple computers located in one location or distributed across multiple locations and interconnected by a communication network.
[0142] The processes and logic flows described herein may be executed by one or more programmable processors running one or more computer programs, performing functions by acting on input data and generating outputs. Process and logic flows may also be executed by special-purpose logic circuits, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits), and devices may also be implemented as these special-purpose logic circuits.
[0143] Processors suitable for executing computer programs include, for example, special-purpose microprocessors. Generally, processors receive instructions and data from read-only memory, random-access memory, or both. The basic elements of a computer are a processor for executing instructions, and one or more memory devices for storing instructions and data. Generally, a computer also includes one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, or is operablely coupled to them for receiving data from them, transferring data to them, or both. However, a computer does not require such devices. Furthermore, a computer can be incorporated into another device, for example, a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a Global Positioning System (GPS) receiver, or a portable storage device (such as a Universal Serial Bus (USB) flash drive). Suitable storage devices for storing computer program instructions and data include, for example, semiconductor memory devices such as EPROM (erasable programmable read-only memory), EEPROM (electrically erasable programmable read-only memory), and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks, encompassing all forms of non-volatile memory, media, and memory devices. Processors and memory may be complemented by or incorporated into dedicated logic circuits.
[0144] In this specification, the term “engine” is used broadly to refer to a software-based system, subsystem, or process programmed to perform one or more specific functions. Generally, an engine is implemented as one or more software modules or components and installed on one or more computers in one or more locations. In some cases, one or more computers are dedicated to a particular engine, while in other cases, multiple engines may be installed and run on the same one or more computers.
[0145] To provide user interaction, embodiments of the subject matter described herein may be implemented on a computing device capable of providing information to the user. Information can be provided to the user in any sensory form, including visual, auditory, tactile, or a combination thereof. The computing device may be coupled to a display device, such as an LCD (liquid crystal display) display device, an OLED (organic light-emitting diode) display device, another monitor, a head-mounted display device, etc., to display information to the user. The computing device may be coupled to an input device. Input devices may include touchscreens, keyboards, and pointing devices, such as a mouse or trackball, through which the user can provide input to the computing device. Other types of devices can also be used to provide user interaction. For example, feedback provided to the user may be any preferred form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback, and input from the user may be received in any preferred form, such as acoustic input, voice input, or tactile input.
[0146] A computing system may include clients and servers. Clients and servers are generally geographically distant from each other and typically interact through a communication network. The client-server relationship arises from computer programs running on each computer that have a client-server relationship with each other. Embodiments of the subject matter described herein can be implemented in a computing system which includes backend components, e.g., a data server, or middleware components, e.g., an application server, or frontend components, e.g., a client computer having a graphical user interface or web browser on which a user can interact with embodiments of the subject matter described herein, or any combination of one or more such backend, middleware, or frontend components. The components of the system can be interconnected by any preferred form or medium of digital data communication, e.g., a communication network. Examples of communication networks include local area networks ("LANs") and wide area networks ("WANs"), internetworks (such as the Internet), and peer-to-peer networks (such as ad-hoc peer-to-peer networks).
[0147] While this specification provides details of many specific embodiments, these should not be construed as limitations on the scope of what is claimed or may be claimed, but rather as descriptions of features specific to particular embodiments of the disclosed subject matter. Certain features described herein in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features of the present invention described in the context of a single embodiment may be implemented separately or in any preferred subcombination in multiple embodiments. Furthermore, features may be described above as functioning in a particular combination, and even if initially claimed as such, one or more features from the claimed combination may be removed from the combination, and the claimed combination may cover subcombinations or variations of subcombinations. Therefore, unless expressly stated otherwise, or unless the knowledge of those skilled in the art clearly indicates otherwise, any of the features of the embodiments described above may be combined with any of the other features of the embodiments described above.
[0148] Similarly, while operations are shown in a specific order in the drawings, this should not be understood as requiring that such operations be performed in a specific or sequential order shown, or that all shown operations be performed, in order to obtain the desired results. In certain situations, multitasking and / or parallel processing may be advantageous. Furthermore, the separation of various system components in the embodiments described above should not be understood as requiring such separation in all embodiments, and the described program components and systems should be understood as generally being able to be integrated into a single software product or packaged into multiple software products.
[0149] Specific embodiments of the present invention have been described in this manner. Other embodiments are within the scope of the following claims. For example, the desired results can still be obtained by performing the actions described in the claims in a different order.
Claims
1. A computer implementation method, The secure distribution system receives digital component requests, including sets of data, from client devices. Upon receiving the aforementioned digital component request, The customization orchestrator of the secure distribution system identifies a multi-stage workflow for selecting a digital component from candidate digital components of a given content platform based on the set of data, wherein the multi-stage workflow includes a sequence of customization modules that are communicably coupled to each other by a common data bus, and each customization module includes a set of worklets containing one or more customized worklets provided by the given content platform, and one or more standard worklets used in the customization modules of multiple content platforms. The secure distribution system executes each customization module of the multi-stage workflow in a sequence defined by the multi-stage workflow in order to select the digital components, For each customization module, The customization orchestrator provides a set of input data to each customization module via the common data bus, The process involves executing each worklet of the customization module in the sequence defined by the customization module to generate a set of output data, The customization orchestrator transmits the output data to another customization module of the given content platform using the common data bus, wherein the output data for a particular customization module in a sequence of the customization modules includes data indicating a given digital component selected by the particular customization module based on the set of input data provided to the particular customization module. This includes, To cause the client device to present the given digital component Computer implementation methods, including those mentioned above.
2. Receiving candidate digital components from the multi-stage workflow of a given content platform, including the given digital components from the multi-stage workflow of the given content platform, from the common data bus, The digital component selection module selects the given digital component from among the candidate digital components. The computer implementation method according to claim 1, including the method described in claim 1.
3. Each worklet in each set of worklets contains operations defined by a portion of code configured to process data. The portion of the code for the operation associated with each customized worklet is a customized portion of the code provided by the given content platform. The portion of the code for the operation associated with each standard worklet is a portion of the code defined by the entity that manages the operation of the secure delivery system. The computer implementation method according to claim 1.
4. The computer implementation method according to claim 1, wherein the customization orchestrator converts the set of input data into a defined set of inputs associated with the customization module.
5. The computer implementation method according to claim 1, wherein the customization orchestrator converts the output data into a defined set of outputs associated with the customization module.
6. Each customization module further includes a policy engine, The computer implementation method according to claim 5, wherein the policy engine determines whether the set of input data and the output data conform to a set of data policies.
7. The computer implementation method according to claim 6, wherein the policy engine determines whether the set of input data is provided to the customization module by the customization orchestrator based on whether the set of input data conforms to the set of data policies.
8. The computer implementation method according to claim 6, wherein the policy engine determines whether the output data is transmitted to the common data bus by the customization orchestrator based on whether the output data conforms to the set of data policies.
9. The aforementioned common data bus is a common data bus that includes one or more data channels, Each of the one or more data channels is a user data channel, a candidate data channel, a context data channel, or an auxiliary data channel. The computer implementation method according to claim 1.
10. Each customization module further includes a local data bus, The set of worklets in each customization module are coupled together so as to be able to communicate with each other via the local data bus. The computer implementation method according to claim 1.
11. The computer implementation method according to claim 10, wherein each customization module includes an operations orchestrator configured to transfer data between the set of worklets via the local data bus.
12. The computer implementation method according to claim 1, wherein one or more of the customization modules are located in a trusted execution environment on the secure distribution system, and one or more of the customization modules are located on the client device.
13. The computer implementation method according to claim 1, further comprising the secure distribution system executing each customization module of the multi-stage workflow in the sequence defined by the multi-stage workflow for selecting the digital components, or executing one or more of the customization modules simultaneously.
14. The computer implementation method according to claim 11, further comprising the operation orchestrator executing each worklet of the customization module in a sequence defined by the customization module to generate a set of output data, by executing one or more worklets simultaneously.
15. A system comprising one or more computers and one or more storage devices for storing instructions, wherein when an instruction is executed by the one or more computers, the system causes the one or more computers to perform the method according to any one of claims 1 to 14.
16. One or more computer-readable storage media that, when executed by one or more computers, stores instructions causing one or more computers to perform the method according to any one of claims 1 to 14.
17. A computer program that, when executed by a computer, includes instructions causing the computer to perform the method described in any one of claims 1 to 14.