IP Library › Granted Patent US 12,348,374
Granted Patent B2
US 12,348,374 · App. 18/488,539 · Granted Jul 1, 2025

Container based limit enforcement

Inventors: Tomer Shachar (Beer-Sheva, IL); Yevgeni Gehtman (Modi'in, IL); Ophir Jehoshua Buchman (Raanana, IL)
Assignee: Dell Products L.P.
H04L41/0895H04L41/0826
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,374
App. No.
18/488,539
Granted
Jul 1, 2025
Kind
B2
Abstract

Methods and systems for managing operation of endpoint devices are disclosed. The operation of the endpoint devices may be managed by deploying containers to the endpoint devices. The containers may include applications and/or other components. The applications may provide various desired services. The containers may also limit use of host endpoint devices based on activity profiles for the requestors of services provided by the applications and the services provided by the applications. The activity profiles may be used on historical information regarding similar requestors and similar services. At least some of the containers may be nested and may separately apply different sets of limits.

Claims (59)

1. A method for managing operation of endpoint devices of edge infrastructure, the method comprising:

obtaining a container definition for a containerized service requested by a requestor;

instantiating a first container based on a first portion of the container definition, the first portion of the container definition being based on a requestor activity profile for the requestor, the requestor activity profile being based on at least two measured activity profiles of users classified as having a same persona, the requestor being one of the users, and the at least two measured activity profiles specify characteristics of the users of corresponding endpoint devices of the endpoint devices used to provide other instances of the containerized service to the users;

instantiating a second container hosted by the first container to obtain an instance of the containerized service, the second container being based on a second portion of the container definition; and

providing computer implemented services using the containerized service hosted by an endpoint device of the endpoint devices.

2. The method of claim 1 , wherein providing the computer implemented services comprises:

activating a function of an application hosted by the second container; and

preventing, by the first container, at least a first portion of the function from being completed by the second container.

3. The method of claim 2 , wherein the second container is adapted to enforce at least one selected from a group consisting of:

a limit on use of a processor core of the endpoint device; and

a limit on use of memory of the endpoint device.

4. The method of claim 2 , wherein providing the computer implemented services further comprises:

preventing, by the second container, at least a second portion of the function from being completed.

5. The method of claim 4 , wherein the second container is adapted to enforce at least one selected from a group consisting of:

a limit on accessing data stored in directories of the endpoint device; and

a limit on access to network endpoints through the endpoint device.

6. The method of claim 1 , wherein the requestor activity profile specifies a first set of limits on use of the endpoint device by the requestor and the first set of limits comprises:

a first limit on use of hardware resources of the endpoint device;

a second limit on use of applications hosted or that can be hosted by the endpoint device;

a third limit on use of portions of data hosted or that can be hosted by the endpoint device; and

a fourth limit on distribution, by the requestor, of the data hosted by the endpoint device.

7. The method of claim 1 , wherein the second portion of the container definition is based on a service activity profile that specifies a second set of limits on use of the endpoint device by at least one application that provides, at least in part, the containerized service.

8. The method of claim 7 , wherein the first container is adapted to enforce the first set of limits and the second container is adapted to enforce the second set of limits.

9. The method of claim 7 , wherein the second set of limits comprising:

a maximum quantity of computing resources of the endpoint device usable to provide the containerized service;

a network connectivity limit for the containerized service;

a network reachability limit for the containerized service; and

a storage area access limit for the containerized service.

10. The method of claim 7 , wherein the service activity profile is based on the at least two measured activity profiles of the users classified as having the same persona, and the at least two measured activity profiles further specifying characteristics of applications used to provide other instances of the containerized service.

11. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing operation of endpoint devices of edge infrastructure, the operations comprising:

obtaining a container definition for a containerized service;

instantiating a first container based on a first portion of the container definition, the first portion of the container definition being based on a requestor activity profile for the requestor, the requestor activity profile being based on at least two measured activity profiles of users classified as having a same persona, the requestor being one of the users, and the at least two measured activity profiles specify characteristics of the users of corresponding endpoint devices of the endpoint devices used to provide other instances of the containerized service to the users;

instantiating a second container hosted by the first container to obtain an instance of the containerized service, the second container being based on a second portion of the container definition; and

providing computer implemented services using the containerized service hosted by an endpoint device of the endpoint devices.

12. The non-transitory machine-readable medium of claim 11 , wherein providing the computer implemented services comprises:

activating a function of an application hosted by the second container; and

preventing, by the first container, at least a first portion of the function from being completed by the second container.

13. The non-transitory machine-readable medium of claim 12 , wherein the second container is adapted to enforce at least one selected from a group consisting of:

a limit on use of a processor core of the endpoint device; and

a limit on use of memory of the endpoint device.

14. The non-transitory machine-readable medium of claim 12 , wherein providing the computer implemented services further comprises:

preventing, by the second container, at least a second portion of the function from being completed.

15. The non-transitory machine-readable medium of claim 11 , wherein the second portion of the container definition is based on a service activity profile that specifies a second set of limits on use of the endpoint device by at least one application that provides, at least in part, the containerized service.

16. A management system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing operation of endpoint devices of edge infrastructure, the operations comprising:

obtaining a container definition for a containerized service;

instantiating a first container based on a first portion of the container definition, the first portion of the container definition being based on a requestor activity profile for the requestor, the requestor activity profile being based on at least two measured activity profiles of users classified as having a same persona, the requestor being one of the users, and the at least two measured activity profiles specify characteristics of the users of corresponding endpoint devices of the endpoint devices used to provide other instances of the containerized service to the users;

instantiating a second container hosted by the first container to obtain an instance of the containerized service, the second container being based on a second portion of the container definition; and

providing computer implemented services using the containerized service hosted by an endpoint device of the endpoint devices.

17. The management system of claim 16 , wherein providing the computer implemented services comprises:

activating a function of an application hosted by the second container; and

preventing, by the first container, at least a first portion of the function from being completed by the second container.

18. The management system of claim 17 , wherein the second container is adapted to enforce at least one selected from a group consisting of:

a limit on use of a processor core of the endpoint device; and

a limit on use of memory of the endpoint device.

19. The management system of claim 17 , wherein providing the computer implemented services further comprises:

preventing, by the second container, at least a second portion of the function from being completed.

20. The management system of claim 16 , wherein the second portion of the container definition is based on a service activity profile that specifies a second set of limits on use of the endpoint device by at least one application that provides, at least in part, the containerized service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2023
From: SHACHAR, TOMER; GEHTMAN, YEVGENI; BUCHMAN, OPHIR JEHOSHUA
To: DELL PRODUCTS L.P.
Reel/Frame 065522/0273 →
Continuity (1)
Related Publication 20250126018A1 · Apr 17, 2025
References Cited (24)
US 10015132B1 · Qin · 2018 [cited by examiner]
US 10732962B1 · Florescu · 2020 [cited by examiner]
US 10943014B2 · Stopel · 2021 [cited by examiner]
US 11868494B1 · Zhuang · 2024 [cited by examiner]
US 20140372382A1 · Hrebicek · 2014 [cited by examiner]
US 20150378709A1 · D'Amico · 2015 [cited by examiner]
US 20160085841A1 · Dorfman · 2016 [cited by examiner]
US 20170197750A1 · Wolf · 2017 [cited by examiner]
US 20170201597A1 · Narasimhan · 2017 [cited by examiner]
US 20170324828A1 · Clavera · 2017 [cited by examiner]
US 20180316725A1 · Mani · 2018 [cited by examiner]
US 20190065278A1 · Jeuk · 2019 [cited by examiner]
US 20190222988A1 · Maes · 2019 [cited by examiner]
US 20190332421A1 · Kozlowski · 2019 [cited by examiner]
US 20190372850A1 · Fandli · 2019 [cited by examiner]
US 20200065085A1 · Talbert · 2020 [cited by examiner]
US 20200162472A1 · Zadeh · 2020 [cited by examiner]
US 20220198034A1 · Rodriguez · 2022 [cited by examiner]
US 20220217181A1 · Viswanathan · 2022 [cited by examiner]
US 20240086522A1 · Grover · 2024 [cited by examiner]
EP 3455775B1 · 2022 [cited by examiner]
WO WO2021242160A1 · 2021 [cited by examiner]
WO WO2022165347A1 · 2022 [cited by examiner]
WO WO2024206146A1 · 2024 [cited by examiner]