TEE Sandbox Workflows for Confidential Digital Component Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to protect user privacy and maintain the confidentiality and integrity of proprietary logic used by content platforms while selecting and distributing digital components, leading to potential data leaks and unauthorized access.

Innovation Solution

Implementing secure workflows within trusted execution environments (TEEs) and sandboxes to execute stages of digital component selection processes, ensuring that user data remains confidential and proprietary logic is isolated, using encryption and cryptographic signatures to verify and control data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If workflows are executed in traditional virtual machines, then full-function workflows are supported, but user privacy and data confidentiality cannot be guaranteed

Engineering Contradiction:
Improvedata confidentialityVSAvoidexecution environment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the execution environment into distinct layers: a traditional virtual machine layer for general computation and a TEE-based sandbox layer for secure workflow execution. This segmentation allows workflows to be divided between untrusted code execution and trusted data processing, resolving the contradiction between functionality and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a TEE-based sandbox as an intermediary between the untrusted workflow code and the trusted user data. The sandbox acts as a mediator that allows code execution while preventing direct access to sensitive data, thus maintaining confidentiality without sacrificing workflow functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If proprietary logic is made accessible for verification, then third-party trust can be established, but confidentiality of the proprietary logic is compromised

Engineering Contradiction:
Improvethird-party verificationVSAvoidproprietary logic confidentiality
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by providing different levels of transparency to different entities. Third parties can verify the TEE implementation and its security properties, while the actual proprietary workflow logic remains confidential within the TEE. This localized transparency resolves the contradiction between verification and confidentiality.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent creates a verifiable copy or representation of the TEE's security properties and execution behavior that can be inspected by third parties, without exposing the actual proprietary logic. This allows verification of trustworthiness while maintaining the confidentiality of the underlying algorithms and data processing methods.

Inventive Principle:
Principle #26Copying

3Reliability

If sandboxes are used to isolate workflow execution, then user privacy is protected, but workflow functionality may be limited

Engineering Contradiction:
Improveuser privacy protectionVSAvoidworkflow functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent designs the TEE-based sandbox to be multi-functional, supporting a wide range of workflow operations including data processing, computation, and output generation while maintaining security. The sandbox provides universal interfaces that allow diverse workflow functionalities to execute securely, resolving the contradiction between privacy protection and functional versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12530446B2Secure workflows that enhance data security using sandboxes hosted by trusted execution environments
Publication Date: 2026.01.20 GOOGLE LLC
  • US12530446B2 patent drawing
  • US12530446B2 patent drawing
  • US12530446B2 patent drawing

AI summary

Methods, systems, and apparatus, including medium-encoded computer program products for secure workflows that enhance data security using sandboxes hosted by trusted execution environments. A digital component (DC) request can be received, and in response, multi-stage workflows can be identified. Each multi-stage workflow (i) being configured to select DCs of multiple content platforms and (ii) including customizable stages. A trusted execution environment of the server can initiate a sandbox environment for executing stages of the workflow, which can be executed within the sandbox environment, preventing the code of the workflow from transmitting user data from the server. Output data can be received from the workflow by the server and from the trusted execution environment. A DC can be selected by the server based on at least a portion of the output data from the workflows. The DC can be provided to the client device for presentation to a user.