IP Library Granted Patent US 12,587,451
Granted Patent B2
US 12,587,451 · App. 17/944,226 · Granted Mar 24, 2026

Automating secured deployment of containerized workloads on edge devices

Inventors: Erol Aygar (Maynard, MA); Margaret Natasha Drew (San Francisco, CA); Mark Peek (Anacortes, WA); Daniel Beveridge (Valrico, FL); Raunak Ravindra Singwi (Pune, IN); Nilanjan Daw (Bangalore, IN); Pranay Pareek (Sunnyvale, CA); Sairam Veeraswamy (Coimbatore, IN); Amarnath Raghunathan (San Jose, CA)
Assignee: Velocloud Networks, LLC
H04L41/40H04L41/0894H04L41/342H04L43/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,451
App. No.
17/944,226
Granted
Mar 24, 2026
Kind
B2
Abstract

Computer-implemented methods, media, and systems for automating secured deployment of containerized workloads on edge devices are disclosed. One example computer-implemented method includes receiving, by a software defined wide area network (SD-WAN) edge device and from a remote manager, resource quotas for a compute service to be enabled at the SD-WAN edge device. Pre-deployment sanity checks are performed by confirming availability of resources satisfying the resource quotas, where the resources are at the SD-WAN edge device. In response to the confirmation of the availability of resources satisfying the resource quotas, one or more security constructs are set up to isolate SD-WAN network functions at the SD-WAN edge device from the compute service at the SD-WAN edge device. The compute service is attached to a SD-WAN network by the SD-WAN edge device. An acknowledgement that the compute service is enabled at the SD-WAN edge device is sent to the remote manager.

Claims (39)

1 . A computer-implemented method, comprising:

receiving, by a software defined wide area network (SD-WAN) edge device and from a remote manager, resource quotas dictating a limit on resources of the SD-WAN edge device for allocating to a compute service to be enabled at the SD-WAN edge device;

performing, by the SD-WAN edge device, pre-deployment checks including confirming availability of the resources for the compute service at the SD-WAN device satisfying the resource quotas beyond resources dedicated to core services of the SD-WAN device, wherein the pre-deployment checks comprise determining that a buffer size for SD-WAN network function virtualization (NFV) at the SD-WAN edge device is larger than a memory limit specified in the resource quotas;

in response to confirming the availability of resources satisfying the resource quotas, setting up, by the SD-WAN edge device, one or more security constructs to isolate SD-WAN network functions (NFs) at the SD-WAN edge device from the compute service at the SD-WAN edge device, the one or more security constructs to enable the compute service to deploy one or more containerized workloads in isolation from the core services;

attaching, by the SD-WAN edge device, the compute service to a SD-WAN to enable availability of the one or more containerized workloads on the SD-WAN; and

sending, by the SD-WAN edge device and to the remote manager, an acknowledgement that the compute service is enabled at the SD-WAN edge device;

after sending the acknowledgement to the remote manager, updating, by the SD-WAN edge device, one or more firewall policies at the SD-WAN edge device based on one or more firewall policy updates from the remote manager.

2 . The computer-implemented method according to claim 1 , wherein the resource quotas are received via a heartbeat mechanism between the remote manager and the SD-WAN edge device, and wherein the heartbeat mechanism comprises message sharing between the remote manager and the SD-WAN edge device at a predefined frequency.

3 . The computer-implemented method according to claim 1 , wherein the one or more security constructs comprise at least one of one or more transport layer security (TLS) certificates, one or more TLS keys, a plurality of firewall settings, a plurality of network address translation (NAS) parameters, a plurality of internet protocol (IP) values, a plurality of egress parameters, a plurality of ingress parameters, or a plurality of definitions for authorization and authentication data flows.

4 . The computer-implemented method according to claim 1 , wherein before attaching the compute service to the SD-WAN network, the method further comprises:

setting up, by the SD-WAN edge device, a container orchestration platform based compute infrastructure to handle life cycle management of the compute service.

5 . The computer-implemented method according to claim 1 , wherein after updating the one or more firewall policies at the SD-WAN edge device, the method further comprises:

monitoring, by the SD-WAN edge device, health of the compute service based on telemetry data collected by a management daemon (MGD) at the SD-WAN edge device.

6 . A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations, the operations comprise:

receiving, by a software defined wide area network (SD-WAN) edge device and from a remote manager, resource quotas dictating a limit on resources of the SD-WAN edge device for allocating to a compute service to be enabled at the SD-WAN edge device;

performing, by the SD-WAN edge device, pre-deployment checks including confirming availability of the resources for the compute service at the SD-WAN device satisfying the resource quotas beyond resources dedicated to core services of the SD-WAN device, wherein the pre-deployment checks comprise determining that a buffer size for SD-WAN network function virtualization (NFV) at the SD-WAN edge device is larger than a memory limit specified in the resource quotas;

in response to confirming the availability of resources satisfying the resource quotas, setting up, by the SD-WAN edge device, one or more security constructs to isolate SD-WAN network functions (NFs) at the SD-WAN edge device from the compute service at the SD-WAN edge device, the one or more security constructs to enable the compute service to deploy one or more containerized workloads in isolation from the core services;

attaching, by the SD-WAN edge device, the compute service to a SD-WAN to enable availability of the one or more containerized workloads on the SD-WAN; and

sending, by the SD-WAN edge device and to the remote manager, an acknowledgement that the compute service is enabled at the SD-WAN edge device;

after sending the acknowledgement to the remote manager, updating, by the SD-WAN edge device, one or more firewall policies at the SD-WAN edge device based on one or more firewall policy updates from the remote manager.

7 . The non-transitory, computer-readable medium according to claim 6 , wherein the resource quotas are received via a heartbeat mechanism between the remote manager and the SD-WAN edge device, and wherein the heartbeat mechanism comprises message sharing between the remote manager and the SD-WAN edge device at a predefined frequency.

8 . The non-transitory, computer-readable medium according to claim 6 , wherein the one or more security constructs comprise at least one of one or more transport layer security (TLS) certificates, one or more TLS keys, a plurality of firewall settings, a plurality of network address translation (NAS) parameters, a plurality of internet protocol (IP) values, a plurality of egress parameters, a plurality of ingress parameters, or a plurality of definitions for authorization and authentication data flows.

9 . The non-transitory, computer-readable medium according to claim 6 , wherein before attaching the compute service to the SD-WAN network, the operations further comprise:

setting up, by the SD-WAN edge device, a container orchestration platform based compute infrastructure to handle life cycle management of the compute service.

10 . The non-transitory, computer-readable medium according to claim 6 , wherein after updating the one or more firewall policies at the SD-WAN edge device, the operations further comprise:

monitoring, by the SD-WAN edge device, health of the compute service based on telemetry data collected by a management daemon (MGD) at the SD-WAN edge device.

11 . A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations, the one or more operations comprise:

receiving, by a software defined wide area network (SD-WAN) edge device and from a remote manager, resource quotas dictating a limit on resources of the SD-WAN edge device for allocating to a compute service to be enabled at the SD-WAN edge device;

performing, by the SD-WAN edge device, pre-deployment checks including confirming availability of the resources for the compute service at the SD-WAN device satisfying the resource quotas beyond resources dedicated to core services of the SD-WAN device, wherein the pre-deployment checks comprise determining that a buffer size for SD-WAN network function virtualization (NFV) at the SD-WAN edge device is larger than a memory limit specified in the resource quotas;

in response to confirming the availability of resources satisfying the resource quotas, setting up, by the SD-WAN edge device, one or more security constructs to isolate SD-WAN network functions (NFs) at the SD-WAN edge device from the compute service at the SD-WAN edge device, the one or more security constructs to enable the compute service to deploy one or more containerized workloads in isolation from the core services;

attaching, by the SD-WAN edge device, the compute service to a SD-WAN to enable availability of the one or more containerized workloads on the SD-WAN; and

sending, by the SD-WAN edge device and to the remote manager, an acknowledgement that the compute service is enabled at the SD-WAN edge device;

after sending the acknowledgement to the remote manager, updating, by the SD-WAN edge device, one or more firewall policies at the SD-WAN edge device based on one or more firewall policy updates from the remote manager.

12 . The computer-implemented system according to claim 11 , wherein the resource quotas are received via a heartbeat mechanism between the remote manager and the SD-WAN edge device, and wherein the heartbeat mechanism comprises message sharing between the remote manager and the SD-WAN edge device at a predefined frequency.

13 . The computer-implemented system according to claim 11 , wherein the one or more security constructs comprise at least one of one or more transport layer security (TLS) certificates, one or more TLS keys, a plurality of firewall settings, a plurality of network address translation (NAS) parameters, a plurality of internet protocol (IP) values, a plurality of egress parameters, a plurality of ingress parameters, or a plurality of definitions for authorization and authentication data flows.

14 . The computer-implemented system according to claim 11 , wherein before attaching the compute service to the SD-WAN network, the one or more operations further comprise:

setting up, by the SD-WAN edge device, a container orchestration platform based compute infrastructure to handle life cycle management of the compute service.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: VMWARE, LLC
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 072326/0693 →
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2022
From: AYGAR, EROL; DREW, MARGARET NATASHA; PEEK, MARK; BEVERIDGE, DANIEL; SINGWI, RAUNAK RAVINDRA; DAW, NILANJAN; PAREEK, PRANAY; VEERASWAMY, SAIRAM; RAGHUNATHAN, AMARNATH
To: VMWARE, INC.
Reel/Frame 061084/0630 →
Continuity (1)
Related Publication 20240039804A1 · Feb 1, 2024
References Cited (70)
US 6760306B1 · Pan · 2004 [cited by examiner]
US 6775701B1 · Pan · 2004 [cited by examiner]
US 7065042B1 · Pan · 2006 [cited by examiner]
US 7606146B1 · Pan · 2009 [cited by examiner]
US 8806605B1 · Chickering · 2014 [cited by examiner]
US 9350704B2 · Chickering · 2016 [cited by examiner]
US 10078537B1 · Nanda · 2018 [cited by examiner]
US 10171313B2 · Diaz · 2019 [cited by applicant]
US 10924429B1 · Gupta · 2021 [cited by applicant]
US 10938717B1 · Sundararajan · 2021 [cited by applicant]
US 11089092B1 · Seibel · 2021 [cited by applicant]
US 11290328B1 · Singhal · 2022 [cited by applicant]
US 11381474B1 · Kumar · 2022 [cited by applicant]
US 11422865B2 · Fong · 2022 [cited by examiner]
US 11444871B1 · Nainar · 2022 [cited by applicant]
US 11595264B1 · Singh · 2023 [cited by applicant]
US 11637753B1 · Wang · 2023 [cited by applicant]
US 11792086B1 · Singwi · 2023 [cited by applicant]
US 20030123392A1 · Ruutu · 2003 [cited by examiner]
US 20070091902A1 · Stewart · 2007 [cited by examiner]
US 20150372878A1 · Ganesan · 2015 [cited by applicant]
US 20180083845A1 · Chan · 2018 [cited by applicant]
US 20180255150A1 · Williams · 2018 [cited by examiner]
US 20190173802A1 · Xia · 2019 [cited by applicant]
US 20200014663A1 · Chen · 2020 [cited by applicant]
US 20200142735A1 · Maciocco · 2020 [cited by applicant]
US 20200167186A1 · Zhong · 2020 [cited by examiner]
US 20200167205A1 · Guim Bernat · 2020 [cited by applicant]
US 20200314022A1 · Vasseur · 2020 [cited by applicant]
US 20200319925A1 · Clampitt, III · 2020 [cited by examiner]
US 20200322226A1 · Mishra · 2020 [cited by examiner]
US 20200322230A1 · Natal · 2020 [cited by applicant]
US 20200351172A1 · Vasseur · 2020 [cited by applicant]
US 20210021484A1 · Sood · 2021 [cited by applicant]
US 20210021485A1 · Guim Bernat · 2021 [cited by applicant]
US 20210117241A1 · Xia · 2021 [cited by examiner]
US 20210168125A1 · Vemulpali · 2021 [cited by applicant]
US 20210176122A1 · Bregman · 2021 [cited by examiner]
US 20210218849A1 · Cai · 2021 [cited by examiner]
US 20210226849A1 · Malhotra · 2021 [cited by applicant]
US 20210232439A1 · Fong et al. · 2021 [cited by applicant]
US 20210281491A1 · Yelahanka Raghuprasad · 2021 [cited by applicant]
US 20210314385A1 · Pande · 2021 [cited by applicant]
US 20210326167A1 · Yang · 2021 [cited by examiner]
US 20220027197A1 · Tang · 2022 [cited by applicant]
US 20220083398A1 · Ravindran · 2022 [cited by applicant]
US 20220129156A1 · Twohig · 2022 [cited by examiner]
US 20220206772A1 · Akiona et al. · 2022 [cited by applicant]
US 20220294730A1 · Vasseur · 2022 [cited by applicant]
US 20220329495A1 · Xie · 2022 [cited by examiner]
US 20220329499A1 · Smith · 2022 [cited by applicant]
US 20220346160A1 · Agrawal · 2022 [cited by applicant]
US 20220358220A1 · Smith · 2022 [cited by examiner]
US 20230028646A1 · Nainar · 2023 [cited by applicant]
US 20230080537A1 · Ramanathan · 2023 [cited by applicant]
US 20230107735A1 · Wang · 2023 [cited by examiner]
US 20230125491A1 · Gordon · 2023 [cited by applicant]
US 20230171190A1 · Jean-Philippe · 2023 [cited by applicant]
US 20230362236A1 · Nair · 2023 [cited by examiner]
US 20230376344A1 · Jutzi · 2023 [cited by examiner]
US 20230409415A1 · McVeigh · 2023 [cited by examiner]
WO 2022056292 · 2022 [cited by applicant]
Dobbelaere, Julie, “International Search Report & Written Opinion”, International Application No. PCT/US2023/011563, mailed May 3, 2023, 12 pages. [cited by applicant]
Office Action (Final Rejection) dated Apr. 7, 2025 for U.S. Appl. No. 18/488,744 (pp. 1-10). [cited by applicant]
Office Action (Non-Final Rejection) dated Oct. 22, 2024 for U.S. Appl. No. 18/488,744 (pp. 1-6). [cited by applicant]
Office Action (Notice of Allowance and Fees Due (PTOL-85)) dated Jun. 8, 2023 for U.S. Appl. No. 17/945,199 (pp. 1-7). [cited by applicant]
U.S. Appl. No. 17/945,181, Final Office Action dated Jan. 4, 2024, 32 pages. [cited by applicant]
U.S. Appl. No. 17/945,181, Non-Final Office Action dated Jul. 19, 2023, 32 pages. [cited by applicant]
U.S. Appl. No. 17/945,199, Notice of Allowance dated Jun. 8, 2023, 32 pages. [cited by applicant]
Action (Non-Final Rejection) dated Nov. 6, 2025 for U.S. Appl. No. 18/488,744 (pp. 1-12). [cited by applicant]