Multi-Stage Digital Component Selection with Isolated Virtual Machines
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems face challenges in securely selecting and distributing digital components while preserving user privacy and maintaining the confidentiality and integrity of proprietary content platform logic, as they often expose sensitive user data and risk unauthorized access to proprietary code.
Innovation Solution
A secure distribution system executes stages of the workflow in isolated virtual machines, encrypts customizations, and ensures that each stage only accesses data within privacy constraints, using separate virtual machines for different content platforms to protect user data and proprietary logic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary customization code is executed in isolated virtual machines to protect confidentiality, then system security and data privacy are improved, but device complexity and processing overhead increase
Solution Approach 1:
The system segments the workflow into multiple independent stages (filtering, selection, rendering, packaging), with each stage executed in separate virtual machine instances. This segmentation isolates proprietary code from different content platforms, preventing cross-contamination of data while maintaining individual security boundaries. Each VM instance processes only its designated stage, reducing the attack surface and complexity of securing the entire system.
Solution Approach 2:
The patent introduces an intermediary workflow management system that coordinates between multiple virtual machine instances. This intermediary layer handles the complexity of inter-VM communication, data passing, and workflow orchestration, shielding the proprietary customization code from direct interaction with other platforms' code while maintaining system-wide coherence and security.
2Measurement precision
If user data is shared with content platforms for digital component selection, then component selection accuracy is improved, but user privacy is compromised
Solution Approach 1:
The system extracts and isolates user data within the trusted execution environment of the workflow system, preventing its exposure to external content platforms. Proprietary customization code operates on user data within controlled VM instances, extracting only the necessary selection results without accessing or exposing the underlying user information. This extraction approach maintains selection accuracy while preserving user privacy.
Solution Approach 2:
The patent creates an inert, controlled execution environment using virtual machines with strict access controls. User data resides in this protected environment where proprietary code can process the data according to distribution directives without the ability to exfiltrate or misuse the information. The VM architecture provides an atmospheric barrier that maintains data integrity and privacy while enabling accurate component selection.
3Adaptability or versatility
If proprietary customization code is shared with the workflow system, then workflow functionality is improved, but vulnerability to unauthorized access increases
Solution Approach 1:
The system segments proprietary customization code into isolated virtual machine instances, where each content platform's code runs in its own secure container. This segmentation allows the workflow system to incorporate diverse proprietary functionality from multiple platforms while preventing any single piece of code from accessing or affecting other platforms' code, thereby reducing unauthorized access risk.
Solution Approach 2:
The patent employs virtual machine instances as flexible protective shells around proprietary customization code. These VM shells provide the necessary isolation and security boundaries while allowing the proprietary code to maintain its full functionality and adaptability. The thin film of virtualization overhead enables secure code execution without significantly impacting the code's operational capabilities.
4Measurement precision
If distribution directives are applied to control digital component delivery, then delivery precision is improved, but processing time increases
Solution Approach 1:
The system performs preliminary actions by pre-configuring distribution directives and filtering criteria before the actual digital component selection process. Proprietary customization code is pre-loaded into virtual machine instances with pre-established security contexts and access controls. This preliminary setup enables the workflow to execute distribution directives efficiently during runtime without incurring significant processing overhead, as the complex security and filtering logic has already been prepared.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for securely executing customized computing workflows for selecting digital components are described. In one aspect, a method includes receiving a request for a digital component for presentation by a client device. In response to receiving the request, a pool of candidate digital components is retrieved from a repository of digital components, and each stage of a multi-stage workflow for selecting a digital component from the pool of digital components is executed in a sequence defined by the multi-stage workflow, including a filtering stage, a selection stage, and a rendering stage. After the rendering stage has been executed, a selected and packaged digital component is transmitted for receipt by the client device.


