Method for executing a secure copy-paste of content between run-time environment, RTE, runnables

The method and system for secure content sharing between RTE runnables use references to content for robust security and granular access control, addressing vulnerabilities and complexity in open execution environments, ensuring efficient and reliable content handling.

WO2025214570A1PCT designated stage Publication Date: 2025-10-16HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/059479
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-08
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

Existing methods for secure content sharing between Run-Time Environments (RTEs) are prone to security vulnerabilities, complexity, and lack flexibility, particularly in open execution environments with diverse security profiles and health conditions, making them susceptible to adversarial attacks and errors.

Method used

A method and system for secure content sharing between RTE runnables that utilize references to content instead of the actual data, enforcing access control through existing APIs and infrastructure, ensuring robust security and granular access management, while maintaining a familiar user experience.

Benefits of technology

This approach provides robust security, granular access control, and efficient content sharing by leveraging existing APIs, reducing vulnerabilities and maintaining user experience, while ensuring secure and reliable content handling in open execution environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024059479_16102025_PF_FP_ABST
    Figure EP2024059479_16102025_PF_FP_ABST
Patent Text Reader

Abstract

A method for executing a secure copy-paste of content between a first Run-Time Environment, RTE, runnable (104, 204, 304, 404, 604) and a second RTE runnable (106, 206, 306, 406, 606) being executed in a Run-Time Environment (112) is provided. The content is stored in a content provider (110, 210, 310, 410). The method includes the first RTE runnable for receiving a copy-command for at least a portion of the content (614), generating a reference (502, 610) to the portion of the content, and storing the reference as a copy-entry in a third RTE runnable (108, 208, 308, 408, 608) executing in the Run-Time Environment. The method includes the second RTE runnable for receiving a paste-command, retrieving a copy-entry from the third RTE runnable, and determining that the copy-entry comprises a reference and in response thereto regenerate the portion of content according to the reference by retrieving the portion of content from the content provider utilizing the reference.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD FOR EXECUTING A SECURE COPY-PASTE OF CONTENT BETWEEN RUN-TIME ENVIRONMENT, RTE, RUNNABLES

[0002] TECHNICAL FIELD

[0003] The disclosure relates generally to a secure copy-paste of content between Run-Time Environment, RTE, runnables, and more particularly, the disclosure relates to a method for executing a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment. Moreover, the disclosure relates to a computer system arranged to execute a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment.

[0004] BACKGROUND

[0005] Modem information technology (IT) workloads are often split across several operational environments (e.g., an endpoint / device and a cloud) and applications (e.g., Paint and PowerPoint). An open execution environment is defined by the split of the business logic between several independent applications, services, etc. However, in a cross-domain cloud operation environment, services are typically migrated to an endpoint, which may introduce security vulnerabilities due to uncontrolled client-side operations. While the endpoint device executes local workloads, heavy or IP-sensitive operations are offloaded to the cloud, aiming to enhance privacy and performance. Nonetheless, adversarial actors (e.g., a client machine owner, local malware, etc . ) may exploit these vulnerabilities to hij ack content exposed on an end client device and transmit it to unauthorized parties. The lack of server-side control by local operating systems or administrators makes it challenging to enforce expected operational flows reliably.

[0006] A data processor may exhibit diverse security profiles and health conditions, as it may be managed by various administrators. The responsibility for ensuring end-to-end security in such a heterogeneous environment typically rests with multiple data or process owners. For example, when an authorized employee within an organization opens a classified document and selectively copies portions into a WhatsApp® conversation or a remote console, the enterprise IT administrator may remain unaware of the potential data breach, as WhatsApp® is legally enabled for chatting with customers.

[0007] The end-to-end security in multi-party content processing scenarios typically hinges on the proficiency and dedication of IT administration to adhere to security guidelines and best practices. Additionally, it relies on the security profile and operational health condition of both the endpoint / device and the collaborating parties. A relaxed security approach is prone to errors and presents challenges in maintenance. Furthermore, the absence of comprehensive visibility into end-to-end security and the availability of trustworthy information regarding the security profile and operational health conditions of processing entities exacerbate the complexity of the situation, heightening uncertainty and intensifying the overall challenge.

[0008] An existing approach maintains end-to-end security administratively by enabling a responsible operator to follow security guidelines. However, the disadvantage of this method is that it is inherently complex and susceptible to errors due to human intervention. Moreover, it is unreliable and easily circumvented by adversarial users, posing significant drawbacks. Another existing approach employs an operating system (OS) that enforces access restrictions per application through installed tools (such as firmware, antivirus, etc.) that enforce pre-defmed policies. Nevertheless, a notable disadvantage of this approach is that compromised software or firmware can compromise security measures. Additionally, a rogue administrator may potentially disable or bypass these tools, undermining the effectiveness of the security framework.

[0009] Another existing approach encrypts content before it is copied outside a secured environment (e.g. a secure browser) and permits a third party to decrypt the encrypted content with a pre-provisioned key. However, the disadvantage of this approach is that it is inherently complex and susceptible to vulnerabilities in key management, potentially compromising the security of the encrypted data. Moreover, it lacks flexibility in terms of access control, limiting the ability to adjust permissions dynamically. Additionally, in this solution, the encryption key itself becomes a valuable asset, introducing additional attack surfaces and potentially compromising security. As a result, rather than enhancing security, this method may lead to increased obscurity and susceptibility to exploitation.

[0010] Another existing solution involves running processing operations within an isolated environment. This ensures that secure content cannot be pasted outside of this secure execution environment, such as within a secure browser. However, a drawback of this approach is its limited applicability, as it is primarily suitable for specific environments, such as thin client setups or secure web offices.

[0011] Therefore, there arises a need to address the aforementioned technical problem / drawbacks for providing a secure copy-paste in open environments.

[0012] SUMMARY

[0013] It is an object of the disclosure to provide a method for executing a secure copy-paste of content between a first Run-Time Environment, RTE, runnable, and a second RTE runnable being executed in a Run-Time Environment and a computer system arranged to execute a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment while avoiding one or more disadvantages of prior art approaches.

[0014] This object is achieved by the features of the independent claims. Further, implementation forms are apparent from the dependent claims, the description, and the figures.

[0015] The disclosure provides a method for executing a secure copy-paste of content between a first Run-Time Environment, RTE, runnable, and a second RTE runnable being executed in a Run-Time Environment and a computer system arranged to execute a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment.

[0016] According to a first aspect, there is provided a method for executing a secure copy-paste of content between a first Run-Time Environment, RTE, runnable, and a second RTE runnable being executed in a Run-Time Environment. The content is stored in a content provider. The method includes the first RTE runnable for receiving a copy command for at least a portion of the content, generating a reference to the portion of the content, and storing the reference as a copy-entry in a third RTE runnable executing in the Run-Time Environment. The method includes the second RTE runnable for receiving a paste-command, retrieving a copy-entry from the third RTE runnable, determining that the copy-entry comprises a reference, and in response thereto regenerating the portion of content according to the reference by retrieving the portion of content from the content provider utilizing the reference. The method includes the content provider, checking the access rights of the second RTE runnable and if the second RTE runnable has access rights to the content, the method includes providing the portion of the content as per the reference. The method includes the second RTE runnable furthermore for inserting the portion of the content.

[0017] The method ensures robust security for content-sharing operations within the open execution environment. The method provides granular access control policies, allowing for precise assignment and effortless revocation of access rights as needed. By leveraging existing application programming interfaces (APIs) and access control infrastructure, the method seamlessly integrates with the system's original architecture, enhancing content protection and security. The method provides a simple, practical, and secure solution for content owners and service providers while maintaining a familiar user experience (UX). The method maintains strict control of the content handling in the remote open execution environment. With client-side operations under control, the method helps to protect their internet protocol (IP) and enforce proper operational flows. Additionally, the method facilitates content sharing through reference, supported by a robust reference structure that enables resilient retrieval of referenced fragments, enhancing the overall efficiency and reliability of the process.

[0018] The method controls the open execution environment to share only the reference to the portion of the content (i.e. not a copy of the original content) with third parties (e.g. the second RTE runnable). The method enforces the third party to engage with the computing system and undergo thorough authentication, authorization, etc. before getting access to the content. The method requires the second RTE runnable / third-party applications to provide additional details (such as an application identifier (ID), a user ID, a machine ID, OS Type, etc.) to determine whether access to the content can be granted. The reference to the content may support retrieval of the content even if the content is changed during sharing without adding server-side complexity and additional vulnerabilities.

[0019] Optionally, the reference to the portion of the content includes an integrity check for the portion of content. The method includes the second RTE runnable furthermore for determining an integrity check for the retrieved portion of content, determining that the integrity checks for the reference corresponds to the integrity check for the retrieved content, and in response thereto inserting the portion of the content. Optionally, the method further includes the second RTE runnable for determining that the integrity check for the reference does not correspond to the integrity check for the retrieved content and in response thereto rejecting the retrieved content.

[0020] Optionally, the method further includes the second RTE runnable for determining that the integrity checks for the reference does not correspond to the integrity check for the retrieved content and in response thereto indicates that there is an error in the retrieved content. Determining the integrity check may include calculating a checksum. Determining the integrity check may include calculating a hash.

[0021] Optionally, the reference to the portion of the content includes a link to the content and an indicator for the portion of the content. Optionally, the indicator for the portion of the content includes a starting marker for the piece of content and an end marker for the portion of content. Optionally, the starting marker is an indicator for a first character, and the end marker is an indicator for a last character of the portion of content. Optionally, the starting marker is an indicator for a first pixel and the end marker is an indicator for a last pixel of the portion of content. Optionally, the indicator for the portion of the content includes a start and an end offset for an image.

[0022] Optionally, the indicator for the portion of the content includes a User Identifier, a Token, and / or user credentials. Optionally, the indicator for the portion of the content includes an RTE runnable Identifier, an RTE runnable Token, and / or RTE runnable Credentials. Optionally, the indicator for the portion of the content includes a Machine Identifier, a Machine Token, and / or Machine Credentials.

[0023] Optionally, the link to the content includes a Uniform Resource Locator. The third RTE runnable may be a clipboard RTE runnable. Optionally, the first RTE runnable is a browser RTE runnable and the content displayed is content for a web page. The indicator for the portion of the content may include a reference to the coding for the web page. Optionally, the method further includes the first RTE runnable displaying the content on a display. A RTE runnable may relate to an application. The Run-Time Environment may relate to an operating system.

[0024] According to a second aspect, there is provided a method for executing a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment. The content is stored in a content provider. The method includes the first RTE runnable for receiving a copy command for at least a portion of the content, generating a reference to the portion of the content, and storing the reference as a copy-entry in a third RTE runnable executing in the RunTime Environment. According to a third aspect, there is provided a method for executing a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment. The content is stored in a content provider. The method includes the first RTE runnable for receiving a copy command for at least a portion of the content, generating a reference to the portion of the content, and storing the reference as a copy-entry in a third RTE runnable executing in the RunTime Environment. The method includes the second RTE runnable for receiving a paste command, retrieving a copy-entry from the third RTE runnable, determining that the copy-entry includes a reference to the portion of the content, and in response thereto regenerating the portion of content according to the reference by retrieving the portion of content from the content provider utilizing the reference, thereby causing the content provider to check the access rights of the second RTE runnable, and if so inserting the portion of the content.

[0025] According to a fourth aspect, there is provided a computer system arranged to execute a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment. The content is stored in a content provider. The computer system includes a controller. The controller is configured to (i) receive a copy command for at least a portion of the content in the first RTE runnable, (ii) generate a reference to the portion of the content, (iii) store the reference as a copy-entry in a third RTE runnable executing in the Run-Time Environment, (iv) receive a paste-command in the second RTE runnable, (v) retrieve a copy-entry from the third RTE runnable, and (vi) determine that the copy-entry includes a reference and in response thereto regenerate the portion of content according to the reference by retrieving the portion of content from the content provider utilizing the reference. The content provider is caused to check the access rights of the second RTE runnable and if the second RTE runnable has access rights to the content, provide the portion of the content as per the reference. The controller of the system is further configured to insert the portion of the content in the second RTE runnable.

[0026] The computer system ensures robust security for content-sharing operations within the open execution environment. The computer system provides granular access control policies, allowing for precise assignment and effortless revocation of access rights as needed. By leveraging existing application programming interfaces (APIs) and access control infrastructure, the computer system seamlessly integrates with the system's original architecture, enhancing content protection and security. The computer system provides a simple, practical, and secure solution for content owners and service providers while maintaining a familiar user experience (UX). The computer system maintains strict control of the content handling in the remote open execution environment. With client-side operations under control, the computer system helps to protect their internet protocol (IP) and enforce proper operational flows. Additionally, the computer system facilitates content sharing through reference, supported by a robust reference structure that enables resilient retrieval of referenced fragments, enhancing the overall efficiency and reliability of the process.

[0027] According to a fourth aspect, there is provided a computer program product including program instructions for performing the above described, when executed by one or more processors in a computer system.

[0028] Therefore, in contradistinction to the existing solutions, the method ensures robust security for content-sharing operations within the open execution environment. The method provides granular access control policies, allowing for precise assignment and effortless revocation of access rights as needed. By leveraging existing application programming interfaces (APIs) and access control infrastructure, the method seamlessly integrates with the system's original architecture, enhancing content protection and security. The method provides a simple, practical, and secure solution for content owners and service providers while maintaining a familiar user experience (UX). The method maintains strict control of the content handling in the remote open execution environment. With client-side operations under control, the method helps to protect their internet protocol (IP) and enforce proper operational flows. Additionally, the method facilitates content sharing through reference, supported by a robust reference structure that enables resilient retrieval of referenced fragments, enhancing the overall efficiency and reliability of the process. These and other aspects of the disclosure will be apparent from the implementation s) described below.

[0029] BRIEF DESCRIPTION OF DRAWINGS

[0030] Implementations of the disclosure will now be described, by way of example only, with reference to the accompanying drawings, in which:

[0031] FIG. 1 is a block diagram that illustrates a computer system arranged to execute a secure copy-paste of content between a first Run-Time Environment, RTE, runnable and a second RTE runnable being executed in a Run-Time Environment in accordance with an implementation of the disclosure;

[0032] FIG. 2 illustrates an exemplary implementation of a computer system arranged to execute a secure copy-paste of content between a first Run-Time Environment, RTE, runnable, and a second RTE runnable being executed in a Run-Time Environment in accordance with an implementation of the disclosure;

[0033] FIG. 3 is an exemplary illustration of a computer system arranged to execute a secure copy-paste of content between a first Run-Time Environment, RTE, runnable, and a second RTE runnable being executed in a Run-Time Environment in accordance with an implementation of the disclosure;

[0034] FIG. 4 illustrates an interaction diagram of a computer system arranged to execute a secure copy-paste of content between a first Run-Time Environment, RTE, runnable and a second RTE runnable being executed in a Run-Time Environment in accordance with an implementation of the disclosure;

[0035] FIG. 5 illustrates an exemplary reference to a portion of content generated in a first Run-Time Environment, RTE, in accordance with an implementation of the disclosure;

[0036] FIG. 6 illustrates a use case for illustrating a computer system for executing a secure copy-paste of content between a first RunTime Environment, RTE, runnable and a second RTE runnable being executed in a Run-Time Environment in accordance with an implementation of the disclosure;

[0037] FIGS. 7A-7B are flow diagrams that illustrate a method for executing a secure copy-paste of content between a first Run-Time Environment, RTE, runnable, and a second RTE runnable being executed in a Run-Time Environment in accordance with an implementation of the disclosure; and

[0038] FIG. 8 is an illustration of a computer system in which the various architectures and functionalities of the various previous implementations may be implemented.

[0039] DETAILED DESCRIPTION OF THE DRAWINGS

[0040] Implementations of the disclosure provide a method for executing a secure copy-paste of content between a first Run-Time Environment, RTE, runnable, and a second RTE runnable being executed in a Run-Time Environment and a computer system arranged to execute a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment.

[0041] To make solutions of the disclosure more comprehensible for a person skilled in the art, the following implementations of the disclosure are described with reference to the accompanying drawings.

[0042] Terms such as "a first", "a second", "a third", and "a fourth" (if any) in the summary, claims, and foregoing accompanying drawings of the disclosure are used to distinguish between similar objects and are not necessarily used to describe a specific sequence or order. It should be understood that the terms so used are interchangeable under appropriate circumstances, so that the implementations of the disclosure described herein are, for example, capable of being implemented in sequences other than the sequences illustrated or described herein. Furthermore, the terms "include" and "have" and any variations thereof, are intended to cover a non-exclusive inclusion. For example, a process, a method, a system, a product, or a device that includes a series of steps or units, is not necessarily limited to expressly listed steps or units but may include other steps or units that are not expressly listed or that are inherent to such process, method, product, or device.

[0043] FIG. 1 is a block diagram that illustrates a computer system 100 arranged to execute a secure copy-paste of content between a first Run-Time Environment, RTE, runnable 104, and a second RTE runnable 106 being executed in a Run-Time Environment 112 in accordance with an implementation of the disclosure. The content is stored in a content provider 110. The computer system 100 includes a controller 102. The controller 102 is configured to (i) receive a copy-command for at least a portion of the content in the first RTE runnable 104, (ii) generate a reference to the portion of the content, (iii) store the reference as a copy-entry in a third RTE runnable 108 executing in the Run-Time Environment 112, (iv) receive a paste-command in the second RTE runnable 108, (v) retrieve a copy-entry from the third RTE runnable 108, and (vi) determine that the copy-entry includes a reference and in response thereto regenerate the portion of content according to the reference by retrieving the portion of content from the content provider 110 utilizing the reference. The content provider 110 is caused to check the access rights of the second RTE runnable 106 and if the second RTE runnable 106 has access rights to the content, provide the portion of the content as per the reference. The controller 102 of the computer system 100 is further configured to insert the portion of the content in the second RTE runnable 106.

[0044] The computer system 100 ensures robust security for content sharing operations within the open execution environment. The computer system 100 provides granular access control policies, allowing for precise assignment and effortless revocation of access rights as needed. By leveraging existing application programming interfaces (APIs) and access control infrastructure, the computer system 100 seamlessly integrates with the system's original architecture, enhancing content protection and security. The computer system 100 provides a simple, practical, and secure solution for content owners and service providers while maintaining a familiar user experience (UX). The computer system 100 maintains strict control of the content handling in the remote open execution environment. With client-side operations under control, the computer system 100 enables to protect of their internet protocol (IP) and enforces proper operational flows. Additionally, the computer system 100 facilitates content sharing through reference, supported by a robust reference structure that enables resilient retrieval of referenced fragments, enhancing the overall efficiency and reliability of the process.

[0045] FIG. 2 illustrates an exemplary implementation of a computer system arranged to execute a secure copy-paste of content between a first Run-Time Environment, RTE, runnable 204, and a second RTE runnable 206 being executed in a Run-Time Environment in accordance with an implementation of the disclosure. An RTE runnable (i.e., the first RTE runnable 204, the second RTE runnable 206, and a third RTE runnable 208) may relate to an application. The Run-Time Environment may relate to an operating system, OS. A runnable is a sequence of operations provided by the component that can be started by the runtime environment, RTE. The RTE can be in an operating system, OS, and the runnable can then be targeted at or mapped to an OS task. Examples of runnables include, but are not limited to RTE runnables, tasks, threads, scripts, etc.

[0046] The computer system includes a controller 202. The computer system may be a server 212. The server 212 is a cloud server. The controller 202 receives a copy-command for at least a portion of the content in the first RTE runnable 204. Optionally, the first RTE runnable 204 is a browser RTE runnable. The content displayed is content for a web page (e.g., http: / / 123.com / content, http: / / www. wikipedia. org. etc.). The first RTE runnable 204 may be modified to process appropriately the copy-command / copy request for the at least a portion of the content. The first RTE runnable 204 may include a copy handler 214 and the copy handler 214 further includes a reference encoder 216. The copy handler 214 improves the content copying on the first RTE runnable 204. Optionally, the first RTE runnable 204 displays the content on a display. The content is stored in a content provider 210. The content provider 210 may be a server. The controller 202 generates a reference to the portion of the content.

[0047] Optionally, the reference to the portion of the content includes a link to the content and an indicator for the portion of the content. Optionally, the link to the content includes a Uniform Resource Locator, URL, (e.g., http: / / 123.com / content, http: / / www. wikipedia. org. etc.). The indicator for the portion of the content includes a starting marker for the piece / fragment of content and an end marker for the portion of content. Optionally, the starting marker is an indicator for a first character, and the end marker is an indicator for a last character of the portion of content. Optionally, the starting marker is an indicator for a first pixel and the end marker is an indicator for a last pixel of the portion of content. Optionally, the indicator for the portion of the content includes a start and an end offset for an image.

[0048] Optionally, the indicator for the portion of the content includes a User Identifier, a Token, and / or user credentials. The indicator for the portion of the content may include an RTE runnable Identifier, an RTE runnable Token, and / or RTE runnable Credentials. The indicator for the portion of the content includes a Machine Identifier, a Machine Token, and / or Machine Credentials. The indicator for the portion of the content may include a reference to the coding for the web page.

[0049] The controller 202 stores the reference as a copy-entry in the third RTE runnable 208 (e.g., a clipboard) that is executed in the Run-Time Environment (e.g., an operating system) instead of storing the original content that is copied. The third RTE runnable 208 may be modified to accommodate various methods of handling the reference to the portion of the content during pasting. The third RTE runnable 208 may be a clipboard RTE runnable. The clipboard is a buffer that the computer system provides for short-term storage of the reference and transfer within and between the RTE runnables.

[0050] The controller 202 receives a paste-command in the second RTE runnable 206 and retrieves a copy-entry from the third RTE runnable 208. The controller 202 determines that the copy-entry includes the reference and in response thereto regenerates the portion of content according to the reference by retrieving the portion of content from the content provider 210 by utilizing the reference. The controller 202 may retrieve the indicator (e.g., a user identifier, a token, user credentials, etc.) for the portion of the content along with the link to the content. The controller 202 may validate the indicator before granting access for the required portion of the content in the second RTE runnable 206. The second RTE runnable 206 may include an indicator retriever 222 for retrieving the indicator for the portion of the content. The second RTE runnable 206 uses the retrieved portion of the content during paste operation. The second RTE runnable 206 may include a paste handler 218 that improves the paste operation for the retrieved portion of content.

[0051] The content provider 210 checks the access rights of the second RTE runnable 206 and if the second RTE runnable 206 has access rights to the content, the content provider 210 provides the portion of the content as per the reference. The controller 202 inserts the portion of the content in the second RTE runnable 206.

[0052] Optionally, the reference to the portion of the content includes an integrity check for the portion of content. The second RTE runnable 206 determines that an integrity check for the retrieved portion of content, and determines the integrity check for the reference corresponds to the integrity check for the retrieved content and in response thereto inserting the portion of the content. The second RTE runnable 206 may include a query manager 220 to determine the integrity check for the retrieved portion of content. Optionally, the second RTE runnable 206 determines that the integrity checks for the reference does not correspond to the integrity check for the retrieved content and in response thereto rejects the retrieved content. The second RTE runnable 206 may determine that the integrity checks for the reference does not correspond to the integrity check for the retrieved content and in response thereto indicate that there is an error in the retrieved content. Determining the integrity check may include calculating a checksum and a hash. The second RTE runnable 206 may include a paste formatter 224 that uses the start and end offsets for the image to modify a piece / fragment of the content. The second RTE runnable 206 may further include an on- change policy 226. When errors are detected in the determination of the integrity check for the reference, the paste operation may be aborted, continued with prompt, etc. as specified in the on-change policy 226. The on-change policy 226 may specify the action to perform on fragment change, abort operation, ask for user consent, paste & notify, etc.

[0053] FIG. 3 is an exemplary illustration of a computer system arranged to execute a secure copy-paste of content between a first Run-Time Environment, RTE, runnable 304, and a second RTE runnable 306 being executed in a Run-Time Environment in accordance with an implementation of the disclosure. The computer system includes a controller 302. The computer system may be a server 312. The server 312 is a cloud server. The controller 302 receives a copy-command for at least a portion of the content in the first RTE runnable 304 from a user 314. Optionally, the first RTE runnable 304 is a browser RTE runnable. The content displayed is content for a web page (e.g., http: / / 123.com / contentl). The content is stored in a content provider 310. The content provider 310 is located in the server 312. The controller 302 generates a reference to the portion of the content. Optionally, the reference to the portion of the content includes a link to the content and an indicator for the portion of the content. The link to the content may include a Uniform Resource Locator, URL, (e.g., http: / / 123.com / contentl).

[0054] The controller 302 stores the reference as a copy-entry in a third RTE runnable 308 (e.g., a clipboard) that is executed in the Run-Time Environment (e.g., an operating system) instead of storing the original content that is copied. The controller 302 receives a paste-command in the second RTE runnable 306 from the user 314 and the controller 302 retrieves a copy-entry from the third RTE runnable 308. The controller 302 determines that the copy-entry includes a reference and in response thereto regenerates the portion of content according to the reference by retrieving the portion of content from the content provider 310 by utilizing the reference (e.g., http: / / 123.com / contentl, indicator). The controller 302 retrieves the indicator 316 (e.g., a user ID, a Token, user credentials, an RTE runnable ID, an RTE runnable Token, RTE runnable Credentials, Machine ID, a Machine Token and / or Machine Credentials, etc.) for the portion of the content along with the link to the content. The controller 302 may validate the indicator 316 before granting the access to the required portion of the content in the second RTE runnable 306. The second RTE runnable 306 uses the retrieved portion of the content during paste operation. The content provider 310 checks the access rights of the second RTE runnable 306 and if the second RTE runnable 306 has access rights to the content, the content provider 310 provides the portion of the content as per the reference. The controller 302 inserts the portion of the content in the second RTE runnable 306.

[0055] Optionally, the reference to the portion of the content includes an integrity check for the portion of content. The second RTE runnable 306 determines that an integrity check for the retrieved portion of a content, and determines that the integrity checks for the reference corresponds to the integrity check for the retrieved content and in response thereto inserting the portion of the content.

[0056] FIG. 4 illustrates an interaction diagram of a computer system arranged to execute a secure copy-paste of content between a first Run-Time Environment, RTE, runnable 404, and a second RTE runnable 406 being executed in a Run-Time Environment in accordance with an implementation of the disclosure. The computer system includes a controller 402. The content is stored in a content provider 410. The controller 402 and the content provider 410 may be a server. The server may be a cloud server. A RTE runnable (i.e., the first RTE runnable 404, the second RTE runnable 406, and a third RTE runnable 408) may relate to an application in the computer system. The Run-Time Environment may relate to an operating system. At a step 414, a user 412 uses the first RTE runnable 404, and the user 412 requests for content in the first RTE runnable 404. At a step 416, the controller 402 retrieves the content from the content provider 410 to the first RTE runnable 404. Optionally, the first RTE runnable 404 is a browser RTE runnable. The content displayed is content for a web page (e.g., http: / / 123.com / content, http: / / www. wikipedia. org. etc.). At a step 418, the user 412 uses the content in the first RTE runnable 404 one or more times. At a step 420, the user 412 selects a portion of the content in the first RTE runnable 404. At a step 422, the user 412 copies the portion of the content in the first RTE runnable 404. At a step 424, the controller 402 receives a copy-command from the first RTE runnable 404 for the portion of the content that the user 412 is selected and copied in the first RTE runnable 404. At a step 426, the controller 402 generates a reference to the portion of the content. Optionally, the reference to the portion of the content includes a link to the content and an indicator for the portion of the content. Optionally, the link to the content includes a Uniform Resource Locator, URL, (e.g., http: / / 123.com / content, http: / / www. wikipedia. org. etc.). At a step 428, the controller 402 stores the reference as a copy-entry in the third RTE runnable 408 (e.g., a clipboard) executing in the Run-Time Environment (e.g., an operating system).

[0057] At a step 430, the controller 402 receives a paste-command in the second RTE runnable 406 from the user 412. At a step 432, the controller 402 retrieves a copy-entry from the third RTE runnable 408. At a step 434, the controller 402 checks whether the copy-entry includes a reference or not. At a step 436, if the copy-entry includes a reference, the controller 402 generates an indicator (e.g., a User ID, a Token, user credentials, an RTE runnable ID, an RTE runnable Token, and / or RTE runnable Credentials, etc.) for the portion of the content. At a step 438, the controller 402 regenerates the portion of content according to the reference by retrieving the portion of content from the content provider 410 by utilizing the reference.

[0058] At a step 440, the controller 402 authorizes the portion of content before granting access to the second RTE runnable 406 for the required portion of the content. At a step 442, the content provider 410 checks the access rights of the second RTE runnable 406. At a step 444, if the second RTE runnable 406 has access rights to the content, the content provider 410 provides the portion of the content as per the reference. At a step 446, the second RTE runnable 406 determines an integrity check (i.e., checks for any changes) for the retrieved portion of content and the reference corresponds to the integrity check for the retrieved content. At a step 448, the second RTE runnable 406 determines that the integrity checks for the reference does not correspond to the integrity check for the retrieved content, and in response, the second RTE runnable 406 rejects the retrieved content and indicates / notifies that there is an error in the retrieved content to the first RTE runnable 404. At a step 450, if the integrity check for the reference corresponds to the integrity check for the retrieved content and in response, the controller 402 inserts the portion of the content in the second RTE runnable 406.

[0059] FIG. 5 illustrates an exemplary reference 502 to a portion of the content generated in a first Run-Time Environment, RTE, in accordance with an implementation of the disclosure. The reference 502 to the portion of the content includes a link 504 to the content and an indicator 506 for the portion of the content. Optionally, the link 504 to the content includes a Uniform Resource Locator, URL, (e.g., http: / / 123.com / content, httpV / www.wikipedia.org^ etc.). The indicator 506 for the portion of the content includes a starting marker 508 for the piece / fragment of content and an end marker 510 for the portion of content. Optionally, the starting marker 508 is an indicator 506 for a first character, and the end marker 510 is an indicator 506 for a last character of the portion of content. Optionally, the starting marker 508 is an indicator 506 for a first pixel and the end marker 510 is an indicator 506 for a last pixel of the portion of content. Optionally, the indicator 506 for the portion of the content includes a start and an end offset for an image.

[0060] The format of the reference 502 to the portion of content may include <Reference Marker> {<Element Type> <Source> <Starting Marker> <End Marker> <CRC> <Extensions>} x N. An example of the reference 502 to the portion of content is as follows:

[0061] @CopyReference {

[0062] Type=general,

[0063] Source URL = https: / / www.wikipedia.org,

[0064] Start {

[0065] ID = “ / html / body / div[2] / div / div[3] / main / div[3] / div[3] / div[l] / p[3] / a[5]”, Offset = 6

[0066] }

[0067] End {

[0068] ID = “ / html / body / div[2] / div / div[3] / main / div[3] / div[3] / div[l] / p[3] / a[6]”,

[0069] Offset = 4

[0070] }

[0071] CRC { type: SHA-256,

[0072] Value = “ad9583c3aled714b77e2c0eal2bc41903blfbd583b0fc0052e987848478e6614”

[0073] }

[0074] }

[0075] An example of the reference 502 to an image is as follows:

[0076] “Element Type”: “image”, / / possible values: general / media, “image” will be followed by reference URL.

[0077] “Source”: {

[0078] “url” :“https: / / en.wikipedia.org / wiki / File:Safari_15.png”, / / url of the image

[0079] “hash”: { / / calculated hash on the image

[0080] “type”: “SHA-256”, / / hash type

[0081] “value”:

[0082] “clc6d2c61a0714878ee5bb2939ab613802c56637b95e8b2690175b816da67e78” / / hash value of the image

[0083] }

[0084] }

[0085] FIG. 6 illustrates a use case for illustrating a computer system for executing a secure copy-paste of content between a first RunTime Environment, RTE, runnable 604, and a second RTE runnable 606 being executed in a Run-Time Environment in accordance with an implementation of the disclosure. The computer system includes a controller 602. The computer system may be a cloud server 612. A user uses the first RTE runnable 604 and selects specific content in the first RTE runnable 604 to copy-paste the selected content to the second RTE runnable 606. The controller 602 receives a copy-command for at least a portion of the content 614 (i.e., the selected content) in the first RTE runnable 604 from the user. The first RTE runnable 604 is a browser RTE runnable. The content displayed is content for a web page (e.g., https: / / en.wikipedia.org). The content is stored in a content provider. The content provider is located in the server 612. The controller 602 generates a reference 610 to the portion of the content 614. Optionally, the reference 610 to the portion of the content 614 includes a link to the content and an indicator for the portion of the content 614. The link to the content may include a Uniform Resource Locator, URL, (e.g., https: / / en.wikipedia.org / wiki / Clipboard_(computing)).

[0086] The controller 602 stores the reference 610 as a copy-entry in a third RTE runnable 608 (e.g., a clipboard) that is executed in the Run-Time Environment (e.g., an operating system) instead of storing the original content that is copied. The controller 602 receives a paste-command in the second RTE runnable 606 from the user and the controller 602 retrieves a copy-entry from the third RTE runnable 608. The controller 602 determines that the copy-entry includes a reference 610 and in response thereto regenerates the portion of content 614 according to the reference 610 by retrieving the portion of content 614 from the content provider by utilizing the reference 610. The controller 602 retrieves the indicator (e.g., User ID, a Token, user credentials, an RTE runnable Identifier, an RTE runnable Token, RTE runnable Credentials, Machine ID, a Machine Token and / or Machine Credentials, etc.) for the portion of the content 614 along with the link to the content. The controller 602 may validate the indicator before granting the access to the second RTE runnable 606 for the required portion of the content 614. The second RTE runnable 606 uses the retrieved portion of the content 614 during the paste operation. The content provider checks the access rights of the second RTE runnable 606 and if the second RTE runnable 606 has access rights to the content, the content provider provides the portion of the content 614 as per the reference 610. The controller 602 inserts the portion of the content 614 in the second RTE runnable 606.

[0087] FIGS. 7A-7B are flow diagrams that illustrate a method for executing a secure copy-paste of content between a first Run-Time Environment, RTE, runnable, and a second RTE runnable being executed in a Run-Time Environment in accordance with an implementation of the disclosure. The content is stored in a content provider. At a step 702, a copy-command is received for at least a portion of the content in the first RTE runnable. At a step 704, a reference is generated to the portion of the content in the first RTE runnable. At a step 706, the reference is stored as a copy-entry in a third RTE runnable that is executed in the Run-Time Environment. At a step 708, a paste-command is received in the second RTE runnable. At a step 710, a copy-entry is retrieved from the third RTE runnable in the second RTE runnable. At a step 712, the copy-entry that comprises a reference is determined in the second RTE runnable and in response thereto the portion of content according to the reference is regenerated by retrieving the portion of content from the content provider utilizing the reference. At a step 714, the access rights of the second RTE runnable are checked using the content provider and if the second RTE runnable has access rights to the content, the portion of the content as per the reference is provided. At a step 716, the portion of the content is inserted in the second RTE runnable.

[0088] In an example implementation, a method for executing a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment is provided. The content is stored in a content provider. The method includes the first RTE runnable for receiving a copy-command for at least a portion of the content, generating a reference to the portion of the content, and storing the reference as a copy-entry in a third RTE runnable executing in the RunTime Environment.

[0089] In another example implementation, a method for executing a secure copy-paste of content between a first RTE runnable and a second RTE runnable being executed in a Run-Time Environment is provided. The content is stored in a content provider. The method includes the first RTE runnable for receiving a copy-command for at least a portion of the content, generating a reference to the portion of the content, and storing the reference as a copy-entry in a third RTE runnable executing in the RunTime Environment. The method includes the second RTE runnable for receiving a paste-command, retrieving a copy-entry from the third RTE runnable, determining that the copy-entry includes a reference to the portion of the content and in response thereto regenerating the portion of content according to the reference by retrieving the portion of content from the content provider utilizing the reference, thereby causing the content provider to check the access rights of the second RTE runnable, and if so inserting the portion of the content. Optionally, the reference to the portion of the content includes an integrity check for the portion of content. The method includes the second RTE runnable furthermore for determining an integrity check for the retrieved portion of content, determining that the integrity checks for the reference corresponds to the integrity check for the retrieved content, and in response thereto inserting the portion of the content. Optionally, the method further includes the second RTE runnable for determining that the integrity check for the reference does not correspond to the integrity check for the retrieved content and in response thereto rejecting the retrieved content.

[0090] Optionally, the method further includes the second RTE runnable for determining that the integrity checks for the reference does not correspond to the integrity check for the retrieved content and in response thereto indicates that there is an error in the retrieved content. Optionally, determining the integrity check includes calculating a checksum. Optionally, determining the integrity check includes calculating a hash.

[0091] Optionally, the reference to the portion of the content includes a link to the content and an indicator for the portion of the content. Optionally, the indicator for the portion of the content includes a starting marker for the piece of content and an end marker for the portion of content. Optionally, the starting marker is an indicator for a first character, and the end marker is an indicator for a last character of the portion of content. Optionally, the starting marker is an indicator for a first pixel and the end marker is an indicator for a last pixel of the portion of content. Optionally, the indicator for the portion of the content includes a start and an end offset for an image.

[0092] Optionally, the indicator for the portion of the content includes a User Identifier, a Token, and / or user credentials. Optionally, the indicator for the portion of the content includes an RTE runnable Identifier, an RTE runnable Token, and / or RTE runnable Credentials. Optionally, the indicator for the portion of the content includes a Machine Identifier, a Machine Token, and / or Machine Credentials. Optionally, the link to the content includes a Uniform Resource Locator. The third RTE runnable may be a clipboard RTE runnable.

[0093] Optionally, the first RTE runnable is a browser RTE runnable and the content displayed is content for a web page. The indicator for the portion of the content may include a reference to the coding for the web page. Optionally, the method further includes the first RTE runnable displaying the content on a display. An RTE runnable may relate to an application. The Run-Time Environment may relate to an operating system.

[0094] FIG. 8 is an illustration of a computer system in which the various architectures and functionalities of the various previous implementations may be implemented. As shown, the computer system 800 includes at least one processor 804 that is connected to a bus 802, wherein the computer system 800 may be implemented using any suitable protocol, such as PCI (Peripheral Component Interconnect), PCI-Express, AGP (Accelerated Graphics Port), Hyper Transport, or any other bus or point-to-point communication protocol (s). The computer system 800 also includes a memory 806.

[0095] Control logic (software) and data are stored in the memory 806 which may take a form of random-access memory (RAM). In the disclosure, a single semiconductor platform may refer to a sole unitary semiconductor-based integrated circuit or chip. It should be noted that the term single semiconductor platform may also refer to multi-chip modules with increased connectivity which simulate on-chip modules with increased connectivity which simulate on-chip operation, and make substantial improvements over utilizing a conventional central processing unit (CPU) and bus implementation. Of course, the various modules may also be situated separately or in various combinations of semiconductor platforms per the desires of the user.

[0096] The computer system 800 may also include a secondary storage 810. The secondary storage 810 includes, for example, a hard disk drive and a removable storage drive, representing a floppy disk drive, a magnetic tape drive, a compact disk drive, digital versatile disk (DVD) drive, recording device, universal serial bus (USB) flash memory. The removable storage drive at least one of reads from and writes to a removable storage unit in a well-known manner.

[0097] Computer programs, or computer control logic algorithms, may be stored in at least one of the memory 806 and the secondary storage 810. Such computer programs, when executed, enable the computer system 800 to perform various functions as described in the foregoing. The memory 806, the secondary storage 810, and any other storage are possible examples of computer-readable media.

[0098] In an implementation, the architectures and functionalities depicted in the various previous figures may be implemented in the context of the processor 804, a graphics processor coupled to a communication interface 812, an integrated circuit (not shown) that is capable of at least a portion of the capabilities of both the processor 804 and a graphics processor, a chipset (namely, a group of integrated circuits designed to work and sold as a unit for performing related functions, and so forth).

[0099] Furthermore, the architectures and functionalities depicted in the various previous-described figures may be implemented in a context of a general computer system, a circuit board system, a game console system dedicated for entertainment purposes, an application-specific system. For example, the computer system 800 may take the form of a desktop computer, a laptop computer, a server, a workstation, a game console, an embedded system.

[0100] Furthermore, the computer system 800 may take the form of various other devices including, but not limited to a personal digital assistant (PDA) device, a mobile phone device, a smart phone, a television, and so forth. Additionally, although not shown, the computer system 800 may be coupled to a network (for example, a telecommunications network, a local area network (LAN), a wireless network, a wide area network (WAN) such as the Internet, a peer-to-peer network, a cable network, or the like) for communication purposes through an I / O interface 808.

[0101] It should be understood that the arrangement of components illustrated in the figures described are exemplary and that other arrangement may be possible. It should also be understood that the various system components (and means) defined by the claims, described below, and illustrated in the various block diagrams represent components in some systems configured according to the subject matter disclosed herein. For example, one or more of these system components (and means) may be realized, in whole or in part, by at least some of the components illustrated in the arrangements illustrated in the described figures.

[0102] In addition, while at least one of these components are implemented at least partially as an electronic hardware component, and therefore constitutes a machine, the other components may be implemented in software that when included in an execution environment constitutes a machine, hardware, or a combination of software and hardware.

[0103] Although the disclosure and its advantages have been described in detail, it should be understood that various changes, substitutions, and alterations can be made herein without departing from the spirit and scope of the disclosure as defined by the appended claims.

Claims

CLAIMS1. A method for executing a secure copy-paste of content between a first Run-Time Environment, RTE, runnable (104, 204, 304, 404, 604) and a second RTE runnable (106, 206, 306, 406, 606) being executed in a Run-Time Environment (112), wherein the content is stored in a content provider (110, 210, 310, 410), wherein the method comprises the first RTE runnable receiving a copy-command for at least a portion of the content, generating a reference (502, 610) to the portion of the content (614), and storing the reference as a copy-entry in a third RTE runnable (108, 208, 308, 408, 608) executing in the Run-Time Environment, wherein the method comprises the second RTE runnable receiving a paste-command, retrieving a copy-entry from the third RTE runnable, and determining that the copy-entry comprises a reference and in response thereto regenerate the portion of content according to the reference by retrieving the portion of content from the content provider utilizing the reference, wherein the method comprises the content provider checking the access rights of the second RTE runnable and if the second RTE runnable has access rights to the content, providing the portion of the content as per the reference, wherein the method comprises the second RTE runnable furthermore inserting the portion of the content.

2. The method according to claim 1, wherein the reference to the portion of the content comprises an integrity check for the portion of content, and wherein the method comprises the second RTE runnable furthermore determining an integrity check for the retrieved portion of content, determining that the integrity check for the reference corresponds to the integrity check for the retrieved content and in response thereto inserting the portion of the content.

3. The method according to claim 2, wherein the method further comprises the second RTE runnable determining that the integrity check for the reference does not correspond to the integrity check the retrieved content and in response thereto rejecting the retrieved content.

4. The method according to claim 3, wherein the method further comprises the second RTE runnable determining that the integrity check for the reference does not correspond to the integrity check for the retrieved content and in response thereto indicate that there is an error in the retrieved content.

5. The method according to any of claims 2 to 4, wherein determining the integrity check comprises calculating a checksum.

6. The method according to any of claims 2 to 5, wherein determining the integrity check comprises calculating a hash.

7. The method according to any preceding claim, wherein the reference (502, 610) to the portion of the content comprises a link (504) to the content and an indicator (316, 506) for the portion of the content.

8. The method according to any preceding claim, wherein the indicator for the portion of the content comprises a starting marker (508) for the piece of content and an end marker (510) for the portion of content.

9. The method according to claim 8, wherein the starting marker is an indicator for a first character, and the end marker is an indicator for a last character of the portion of content.

10. The method according to claim 8, wherein the starting marker is an indicator for a first pixel and the end marker is an indicator for a last pixel of the portion of content.

11. The method according to any preceding claim, wherein the indicator for the portion of the content comprises a start and an end offset for an image.

12. The method according to any preceding claim, wherein the indicator for the portion of the content comprises a User Identifier, a Token, and / or user credentials.

13. The method according to any preceding claim, wherein the indicator for the portion of the content comprises an RTE runnable Identifier, an RTE runnable Token, and / or RTE runnable Credentials.

14. The method according to any preceding claim, wherein the indicator for the portion of the content comprises a Machine Identifier, a Machine Token and / or Machine Credentials.

15. The method according to any preceding claim, wherein the link to the content comprises a Uniform Resource Locator.

16. The method according to any preceding claim, wherein the third RTE runnable is a clipboard RTE runnable.

17. The method according to any preceding claim, wherein the first RTE runnable is a browser RTE runnable and the content displayed is content for a web page, wherein the indicator for the portion of the content comprises a reference to the coding for the web page.

18. The method according to any preceding claim, wherein the method further comprises the first RTE runnable displaying the content on a display.

19. The method according to any preceding claim, wherein an RTE runnable relates to an application.

20. The method according to any preceding claim, wherein the Run-Time Environment relates to an operating system.

21. A method for executing a secure copy-paste of content between a first RTE runnable (104, 204, 304, 404, 604) and a second RTE runnable (106, 206, 306, 406, 606) being executed in a Run-Time Environment (112), wherein the content is stored in a content provider (110, 210, 310, 410), wherein the method comprises the first RTE runnable receiving a copy-command for at least a portion of the content, generating a reference (502, 610) to the portion of the content, and storing the reference as a copy-entry in a third RTE runnable (108, 208, 308, 408, 608) executing in the Run-Time Environment.

22. A method for executing a secure copy-paste of content between a first RTE runnable (104, 204, 304, 404, 604) and a second RTE runnable (106, 206, 306, 406, 606) being executed in a Run-Time Environment (112), wherein the content is stored in a content provider (110, 210, 310, 410), wherein the method comprises the first RTE runnable receiving a copy-command for at least a portion of the content, generating a reference (502, 610) to the portion of the content (614), and storing the reference as a copy-entry in a third RTE runnable (108, 208, 308, 408, 608) executing in the Run-Time Environment, wherein the method comprises the second RTE runnable receiving a paste-command, retrieving a copy-entry from the third RTE runnable, determining that the copy-entry comprises a reference to the portion of the content and in response theretoregenerating the portion of content according to the reference by retrieving the portion of content from the content provider utilizing the reference, thereby causing the content provider to check the access rights of the second RTE runnable, and if so inserting the portion of the content.

23. A computer system (100) arranged to execute a secure copy-paste of content between a first RTE runnable (104, 204, 304, 404, 604) and a second RTE runnable (106, 206, 306, 406, 606) being executed in a Run-Time Environment (112), wherein the content is stored in a content provider (110, 210, 310, 410), wherein the system comprises a controller (102, 202, 302, 402, 602) configured to: receive a copy-command for at least a portion of the content in the first RTE runnable, generate a reference (502, 610) to the portion of the content (614), and store the reference as a copy-entry in a third RTE runnable (108, 208, 308, 408, 608) executing in the Run-Time Environment, receive a paste-command in the second RTE runnable, retrieve a copy-entry from the third RTE runnable, determine that the copy-entry comprises a reference and in response thereto regenerate the portion of content according to the reference by retrieving the portion of content from the content provider utilizing the reference, wherein the content provider is caused to: check the access rights of the second RTE runnable and if the second RTE runnable has access rights to the content, provide the portion of the content as per the reference, wherein the controller of the system is further configured to: insert the portion of the content in the second RTE runnable.

24. A computer program product comprising program instructions for performing the method according to any of claims 1 to 22, when executed by one or more processors in a computer system.

Citation Information

Patent Citations

  • Sharing contents between applications

    US20170242983A1

  • Systems and methods for providing data loss prevention via an embedded browser

    US20220245272A1

  • Techniques for performing clipboard-to-file paste operations

    US20230101774A1