IP Library Granted Patent US 12695633
Granted Patent B2
US 12695633 · App. 18/531,845 · Granted Jul 28, 2026

Systems and methods for supporting network-based computing services

Inventors: Xu Li (Kanata, CA); Hang Zhang (Kanata, CA)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L9/40G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695633
App. No.
18/531,845
Granted
Jul 28, 2026
Kind
B2
Abstract

A method of implementing a computing service on edge nodes of a communication network, where the computing service is made from a plurality of service functions, each of which is connected to another service function by a communication routine. Service functions and routines can be deployed on edge nodes and communication between any two service functions can be performed via a routine and a privacy router, with coordination from a routine manager. Service functions and routines can be grouped into tasks, which can be coordinated with task managers. Tasks can be grouped into works, which can be coordinated with work managers. Because a privacy router can perform encryption on routine communications, any of the entities implementing the computing service can be deployed on edge nodes of a communication network, and a service manager can interface with external entities.

Claims (66)

1 . A system operative to execute a computing service, the computing service comprising at least one routine and at least one service function, each routine associated with a routine server function and a routine client function, the system comprising:

(i) at least one routine manager operative to execute a routine and configured for:

receiving a synchronization requirement associated with the routine;

inviting a first routine client, according to the synchronization requirement, the first routine client being associated with an instance of the routine client function, to perform a first data communication with a routine server, the routine server being an instance of the routine server function; and

inviting a second routine client, according to the synchronization requirement, the second routine client being associated with an instance of the routine client function, to perform a second data communication with the routine server;

the at least one routine manager further operative to co-ordinate the execution of the routine including:

sending a first notification to a privacy router configured for processing data related to routine execution, the processing comprising performing proxy re-encryption on the data by using a re-encryption key related to a receiver of the data and forwarding re-encrypted data from the routine, and

forwarding a second notification to an instance of a routine server function, wherein the first notification includes:

information identifying the computing service and

information identifying the routine;

sending a third notification to a privacy router configured for processing the data related to routine execution, the processing comprising performing proxy re-encryption on the data by using a re-encryption key related to the receiver of the data and forwarding re-encrypted data from the routine; and

forwarding a fourth notification to an instance of a routine client function, wherein the third notification includes:

information identifying the computing service and

information identifying the routine;

wherein at least one privacy router is further configured to initiate a communication between the instance of a routine server function and the instance of a routine client function, in accordance with communication instructions; and

wherein processing the data related to routine execution is performed in accordance with communication instructions; and

(ii) at least one first said privacy router being operative to forward data traffic associated with the first data communication between the routine server and the first routine client; and

(iii) at least one second said privacy router being operative to forward data traffic associated with the second data communication between the routine server and the second routine client.

2 . The system of claim 1 wherein:

the synchronization requirement is for sequential communication, and

the second data communication occurs after completion of the first data communication.

3 . The system of claim 1 wherein:

the synchronization requirement is for parallel communications, and

inviting the second routine client to perform the second data communication with the routine server, occurs prior to the completion of the first data communication.

4 . The system of claim 1 wherein:

the synchronization requirement is for parallel communication, and

the second data communication occurs prior to the completion of the first data communication.

5 . The system of claim 1 , wherein the at least one privacy router receives, from the routine manager, instructions indicating to perform proxy re-encryption on the data traffic, and performs accordingly.

6 . The system of claim 1 , wherein the first privacy router and the second privacy router are a same entity.

7 . The system of claim 1 , wherein at least one of the first routine client and the second routine client is a terminal device.

8 . A method of executing a computing service, comprising:

coordinating, by a routine manager, the execution of a routine which forms the computing service in accordance with a respective synchronization requirement; wherein the execution of the routine includes a process of:

performing proxy re-encryption on data from the routine,

and forwarding the data from the routine; and

wherein coordinating the execution of a routine includes triggering the execution of a routine, which comprises:

sending a first notification to a privacy router configured for processing the data related to routine execution, the processing comprising performing proxy re-encryption on the data by using a re-encryption key related to the receiver of the data and forwarding re-encrypted data from the routine, and

forwarding a second notification to an instance of a routine server function, wherein the first notification includes: information identifying the computing service and information identifying the routine;

sending a third notification to a privacy router configured for processing the data related to routine execution, the processing comprising performing proxy re-encryption on the data by using a re-encryption key related to the receiver of the data and forwarding re-encrypted data from the routine; and

forwarding a fourth notification to an instance of a routine client function, wherein the third notification includes: information identifying the computing service and information identifying the routine;

wherein at least one privacy router is further configured to initiate a communication between the instance of a routine server function and the instance of a routine client function, in accordance with communication instructions; and

wherein processing the data related to routine execution is performed in accordance with communication instructions.

9 . The method of claim 8 , wherein the communication instructions are included in a notification to a privacy router.

10 . The method of claim 8 , where the re-encryption key is pre-configured in the privacy router, or is received from the routine manager as part of the communication instructions.

11 . The method of claim 8 , further comprising receiving, by the routine manager, from the instance of a routine server function or the instance of a routine client function, a notification that a data communication is completed.

12 . The method of claim 9 , wherein coordinating the execution of a routine includes:

sending, by the routine manager to a first instance of a service function, a first invitation message;

sending, by the routine manager to a second instance of a service function, a second invitation message;

receiving, by the routine manager from the first instance of a service function, a first accept message that includes security material for performing proxy re-encryption of the routine's data; and

receiving, by the routine manager from the second instance of a service function, a second accept message that includes security material for performing proxy re-encryption of the routine's data;

wherein the sending of each message is facilitated with a privacy router.

13 . The method of claim 12 , wherein one or more of the first invitation message and the second invitation message further includes one or more of:

information identifying the computing service,

information identifying a routine,

information identifying a routine execution.

14 . The method of claim 12 , wherein sending the first or second invitation message further comprises sending an outer message that includes the invitation message and routing information related to a privacy router.

15 . The method of claim 8 , wherein coordinating the execution of a routine includes:

receiving a notification, by the routine manager, from a task manager having obtained information associated with a service profile of the computing service, to execute the routine;

sending an acknowledgment, from the routine manager to the task manager;

sending an invitation, from the routine manager to an instance of a routine server function, to contribute to the routine execution;

sending an invitation, from the routine manager to at least one instance of a routine client function, to contribute to at least one routine execution;

executing, by the routine manager, a routine communication procedure with each instance of a routine client function.

16 . The method of claim 15 , wherein coordinating the execution of a routine further includes:

executing at least one routine, by at least one routine manager including the routine manager, based on data obtained by a task manager, including data allowing the selection of the at least one routine manager; routine data associated with the at least one routine; task data associated to a task; compute plane data related to a task; and a request from a work manager, to trigger the task that includes the at least one routine.

17 . The method of claim 16 , wherein the work manager is selected by a service manager and operative to receive a work order from the service manager, receive work data associated with the work, receive information as to how to execute the work, and receive at least one execution condition.

18 . An apparatus of executing a computing service, the apparatus comprising a processor coupled with a memory storing instructions, which, when executed by the processor, configure the apparatus to coordinate the execution of a routine that forms the computing service, in accordance with a synchronization requirement; wherein the execution of a routine includes a process of:

performing proxy re-encryption on data from the routine, and forwarding the data from the routine; and wherein coordinating the execution of a routine includes triggering the execution of a routine, which comprises: sending a first notification to a privacy router configured for processing the data related to routine execution, the processing comprising performing proxy re-encryption on the data by using a re-encryption key related to the receiver of the data and forwarding re-encrypted data from the routine, and forwarding a second notification to an instance of a routine server function, wherein the first notification includes: information identifying the computing service and information identifying the routine; sending a third notification to a privacy router configured for processing the data related to routine execution, the processing comprising performing proxy re-encryption on the data by using a re-encryption key related to the receiver of the data and forwarding re-encrypted data from the routine; and forwarding a fourth notification to an instance of a routine client function, wherein the third notification includes: information identifying the computing service and information identifying the routine; wherein at least one privacy router is further configured to initiate a communication between the instance of a routine server function and the instance of a routine client function, in accordance with communication instructions; and wherein processing the data related to routine execution is performed in accordance with communication instructions.