-
公开(公告)号:US12224991B1
公开(公告)日:2025-02-11
申请号:US18067533
申请日:2022-12-16
Applicant: Amazon Technologies, Inc.
Inventor: Sachin P. Joglekar , Temesghen Kahsai Azene , Kadirvel Chockalingam Vanniarajan , Firas Azrai , Charles Ward , David M. Wheeler
Abstract: Systems, devices, and methods are provided for cloud-based privacy controls. User content is encrypted using a content encryption key (CEK). The CEK may be double-encrypted by the data producer—the inner envelope is encrypted using keys associated with privacy domains that are authorized to access the user content. The outer envelope is encrypted using a cloud privacy control's public key. When a data consumer requests access the user content, the cloud privacy control evaluates privacy policies and determine whether access should be permitted. If permitted, the cloud privacy control decrypts the outer envelope and provides the inner envelope with CEK to the requestor. Upon receiving the inner envelope, the data consumer may then decrypt the inner envelope with its privacy domain private key to obtain the CEK. The CEK may then be used to perform a decryption and obtain the user content.
-
公开(公告)号:US10567346B2
公开(公告)日:2020-02-18
申请号:US14853769
申请日:2015-09-14
Applicant: Amazon Technologies, Inc.
Inventor: Sachin P. Joglekar , Peter S. Vosshall , Jonathan A. Jenkins
IPC: H04L29/06 , H04L12/911
Abstract: A browsing process is directed to the generation and management of a browse session at a network computing provider. A client computing device transmits secure requests for network resources to a network computing provider. The network computing provider comprises one or more virtual network computing providers for processing secure communications between a client computing device and a content source. A virtual network computing provider handles the secure communications, decrypting and processing the communications while preventing third parties from accessing the unencrypted communication data. The virtual network computing provider may determine a browse configuration identifying processing actions to perform on the request content. The virtual network computing provider may retrieve the requested content, perform a first set of processing actions to generate a processing result, and provide the processing result to the client computing device, which may perform a second set of processing actions, including display.
-
公开(公告)号:US20160006697A1
公开(公告)日:2016-01-07
申请号:US14853769
申请日:2015-09-14
Applicant: Amazon Technologies, Inc.
Inventor: Sachin P. Joglekar , Peter S. Vosshall , Jonathan A. Jenkins
IPC: H04L29/06
CPC classification number: H04L63/0272 , H04L47/70 , H04L63/0236 , H04L63/0442 , H04L63/061 , H04L63/10 , H04L63/20
Abstract: A browsing process is directed to the generation and management of a browse session at a network computing provider. A client computing device transmits secure requests for network resources to a network computing provider. The network computing provider comprises one or more virtual network computing providers for processing secure communications between a client computing device and a content source. A virtual network computing provider handles the secure communications, decrypting and processing the communications while preventing third parties from accessing the unencrypted communication data. The virtual network computing provider may determine a browse configuration identifying processing actions to perform on the request content. The virtual network computing provider may retrieve the requested content, perform a first set of processing actions to generate a processing result, and provide the processing result to the client computing device, which may perform a second set of processing actions, including display.
Abstract translation: 浏览过程针对在网络计算提供商处的浏览会话的生成和管理。 客户计算设备向网络计算提供商传送网络资源的安全请求。 网络计算提供商包括用于处理客户端计算设备和内容源之间的安全通信的一个或多个虚拟网络计算提供者。 虚拟网络计算提供者处理安全通信,解密和处理通信,同时防止第三方访问未加密的通信数据。 虚拟网络计算提供者可以确定识别要在请求内容上执行的处理动作的浏览配置。 虚拟网络计算提供商可以检索所请求的内容,执行第一组处理动作以生成处理结果,并将处理结果提供给客户端计算设备,该客户端计算设备可以执行包括显示在内的第二组处理动作。
-
-