Patents by Inventor John Tobler

John Tobler has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260172246
    Abstract: The techniques disclosed herein provide a secure control plane (SCP), which in turn provides an isolated secure execution environment for a data plane (DP). Any arbitrary business logic can execute within the DP, and all sensitive data traversing the SCP and entering the DP is encrypted. Split keys generated outside the DP are assembled within, and only within, the DP, where they are used to decrypt sensitive data, enabling the business logic to perform computations using the sensitive data within the secure execution environment. The DP also provides attestation for the business logic executing within the DP, enabling outside parties to verify that the deployed business logic matches published logic. In the event of proprietary logic that is not published, techniques are also disclosed herein that enable verification that proprietary business logic deployed on the DP adheres to security policies.
    Type: Application
    Filed: February 4, 2026
    Publication date: June 18, 2026
    Inventors: Carlos Cela, John Tobler, Brian Burdick, Branton Horsley, Mayank Patel, Chanda Patel, Asela Gunawardana
  • Patent number: 12567961
    Abstract: The techniques disclosed herein provide a secure control plane (SCP), which in turn provides an isolated secure execution environment for a data plane (DP). Any arbitrary business logic can execute within the DP, and all sensitive data traversing the SCP and entering the DP is encrypted. Split keys generated outside the DP are assembled within, and only within, the DP, where they are used to decrypt sensitive data, enabling the business logic to perform computations using the sensitive data within the secure execution environment. The DP also provides attestation for the business logic executing within the DP, enabling outside parties to verify that the deployed business logic matches published logic. In the event of proprietary logic that is not published, techniques are also disclosed herein that enable verification that proprietary business logic deployed on the DP adheres to security policies.
    Type: Grant
    Filed: February 15, 2023
    Date of Patent: March 3, 2026
    Assignee: GOOGLE LLC
    Inventors: Carlos Cela, John Tobler, Brian Burdick, Branton Horsley, Mayank Patel, Chanda Patel, Asela Gunawardana
  • Publication number: 20260050690
    Abstract: One or more servers send, to a user device executing a software application, a tagging snippet to be provided in the software application along with a content software application requested from a content provider and auxiliary content the software application received from an auxiliary content provider. The tagging snippet, in response to a user interacting with the auxiliary content via the software application, causes the software application to: (i) obtain a public key, (ii) encrypt, using the public key, personally identifiable information associated with the user, and (iii) send the encrypted personally identifiable information to a collection endpoint associated with a trusted execution environment (TEE) implemented in a cloud computing platform.
    Type: Application
    Filed: October 4, 2024
    Publication date: February 19, 2026
    Inventors: Chanda Patel, John Tobler, Quaseer Mujawar
  • Publication number: 20250342270
    Abstract: Server(s) can implement a method for managing privacy budgets. The method includes receiving a request to analyze a dataset associated with a privacy budget representing a number of times the dataset can be analyzed. The method also includes transmitting a first request to a first server implementing a first privacy budget service to verify whether there is sufficient privacy budget to analyze the dataset, and transmitting a second request to a second server implementing a second privacy budget service to verify whether there is sufficient privacy budget to analyze the dataset, the second privacy budget service independent from the first privacy budget service. The method further includes receiving, from the first server, a first response indicating whether there is sufficient privacy budget: receiving, from the second server, a second response indicating whether is sufficient privacy budget; and processing, based on the first response and the second response, the dataset.
    Type: Application
    Filed: December 29, 2023
    Publication date: November 6, 2025
    Inventors: Carlos Cela, John Tobler, Chanda Patel, Esfandiar Manii, Shobhit Saxena, Vikas Kumar Singh, Paul Revere, Eugene Goh
  • Publication number: 20250211432
    Abstract: One or more servers implement a method for managing privacy budgets. The method includes receiving a plurality of datasets, each of the datasets including respective encrypted data and respective metadata; sorting the plurality of datasets into one or more groups of datasets based on the respective metadata; and executing a query to determine, for a group included in the one or more groups, whether there is sufficient privacy budget to store results of analyzing the group, wherein the privacy budget for the group corresponds to a number of times the group can be analyzed.
    Type: Application
    Filed: December 29, 2023
    Publication date: June 26, 2025
    Inventors: Carlos Cela, John Tobler, Chanda Patel, Esfandiar Manii, Shobhit Saxena, Vikas Kumar Singh, Paul Revere, Eugene Goh
  • Publication number: 20250094561
    Abstract: To performing a join operation, a module executing in a trusted execution environment (TEE) receives a first dataset including personal identifiable information (PII) data and non-PII data from a first-party (1P) data source. The module pre-processes the PII data to generate first formatted PII data, the first formatted PII data conforming to a predefined format: matches, in the TEE, the first formatted PII data to second formatted PII data included in a second dataset: performs a join operation between the first dataset and the second dataset based on the matching, to generate a joined dataset: and provides, to a data service operating independently of the 1P data source, the joined dataset.
    Type: Application
    Filed: July 24, 2023
    Publication date: March 20, 2025
    Inventors: Carlos Cela, John Tobler, Eugene Shaphir, Chanda Patel, Quaseer Mujawar, Farshid Shariatzadeh, Dina Kurman, Minh Hoang
  • Publication number: 20240291650
    Abstract: The techniques disclosed herein provide a secure control plane (SCP), which in turn provides an isolated secure execution environment for a data plane (DP). Any arbitrary business logic can execute within the DP, and all sensitive data traversing the SCP and entering the DP is encrypted. Split keys generated outside the DP are assembled within, and only within, the DP, where they are used to decrypt sensitive data, enabling the business logic to perform computations using the sensitive data within the secure execution environment. The DP also provides attestation for the business logic executing within the DP, enabling outside parties to verify that the deployed business logic matches published logic. In the event of proprietary logic that is not published, techniques are also disclosed herein that enable verification that proprietary business logic deployed on the DP adheres to security policies.
    Type: Application
    Filed: February 15, 2023
    Publication date: August 29, 2024
    Inventors: Carlos Cela, John Tobler, Brian Burdick, Branton Horsley, Mayank Patel, Chanda Patel, Asela Gunawardana