IP Library › Granted Patent US 12,250,246
Granted Patent B2
US 12,250,246 · App. 17/483,656 · Granted Mar 11, 2025

Perform edge processing by selecting edge devices based on security levels

Inventors: Sarbajit K. Rakshit (Kolkata, IN); Venkata Vara Prasad Karri (Visakhapatnam, IN); Subha Kiran Patnaikuni (Visakhapatnam, IN); Saraswathi Sailaja Perumalla (Visakhapatnam, IN); Sri Harsha Varada (Vizianagaram, IN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/20G06N20/00H04L63/102H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,246
App. No.
17/483,656
Granted
Mar 11, 2025
Kind
B2
Abstract

Provided are techniques for performing edge processing by selecting edge devices based on security levels. A security policy is identified for a job to determine a security level for the data. A number of the edge devices that are to be included in a participating group to execute the job is identified. A subset of edge devices that meet the security level are identified by comparing security data of each of the edge devices with the security level. In response to determining that the subset of edge devices includes that number of edge devices, the edge devices from the subset are added to the participating group. The job is executed using the edge devices in the participating group and the one or more cloud nodes, while maintaining the security level in processing the data and in communications across the edge devices and the one or more cloud nodes.

Claims (70)

1. A computer-implemented method, comprising operations for:

determining that a job that uses one or more cloud nodes and uses edge devices to process data from one or more data sources is to be executed, wherein each of the edge devices comprises security data;

identifying a security level for the job from a security policy stored at a cloud node of the one or more cloud nodes;

determining a desired number of the edge devices that are to be included in a participating group to execute the job;

comparing the security data of each of the edge devices with the security level of the security policy defined at the cloud node;

determining that a subset of the edge devices meet the security level based on the comparing;

adding the subset of the edge devices that meet the security level to the participating group;

determining that the participating group does not include the desired number of the edge devices;

installing a security update at one or more other edge devices that did not meet the security level to move the one or more other edge devices to the security level and to reach the desired number of the edge devices;

adding the one or more other edge devices to the participating group; and

executing the job using the participating group and the one or more cloud nodes.

2. The computer-implemented method of claim 1 , wherein installing the security update further comprises operations for:

sending the security update to one or more edge devices that are not in the participating group; and

receiving confirmation that the security update has been installed at the one or more edge devices.

3. The computer-implemented method of claim 2 , further comprising operations for:

in response to determining that the edge devices in the participating group have completed edge processing, uninstalling the security update from the one or more other edge devices.

4. The computer-implemented method of claim 1 , wherein the security level changes, and further comprising:

modifying the edge devices that are in the participating group.

5. The computer-implemented method of claim 1 , further comprising operations for:

classifying the data using a machine learning model; and

determining whether to send the data to a particular edge device in the participating group based on the classification of the data.

6. The computer-implemented method of claim 1 , wherein identifying the subset of the edge devices that meet the security level uses a machine learning model.

7. The computer-implemented method of claim 1 , wherein a Software as a Service (SaaS) is configured to perform the operations of the method.

8. A computer program product, the computer program product comprising a computer readable storage medium having program code embodied therewith, the program code executable by at least one processor to perform operations for:

determining that a job that uses one or more cloud nodes and uses edge devices to process data from one or more data sources is to be executed, wherein each of the edge devices comprises security data;

identifying a security level for the job from a security policy for the job stored at a cloud node of the one or more cloud nodes;

determining a desired number of the edge devices that are to be included in a participating group to execute the job;

comparing the security data of each of the edge devices with the security level of the security policy defined at the cloud node;

determining that a subset of the edge devices meet the security level based on the comparing;

adding the subset of the edge devices that meet the security level to the participating group;

determining that the participating group does not include the desired number of the edge devices;

installing a security update at one or more other edge devices that did not meet the security level to move the one or more other edge devices to the security level and to reach the desired number of the edge devices;

adding the one or more other edge devices to the participating group; and

executing the job using the participating group and the one or more cloud nodes.

9. The computer program product of claim 8 , wherein the program code for installing the security update is executable by the at least one processor to perform further operations for:

sending the security update to one or more edge devices that are not in the participating group; and

receiving confirmation that the security update has been installed at the one or more edge devices.

10. The computer program product of claim 8 , wherein the program code is executable by the at least one processor to perform operations for:

in response to determining that the edge devices in the participating group have completed edge processing, uninstalling the security update from the one or more other edge devices.

11. The computer program product of claim 8 , wherein the security level changes, and wherein the program code is executable by the at least one processor to perform operations for:

modifying the edge devices that are in the participating group.

12. The computer program product of claim 8 , wherein the program code is executable by the at least one processor to perform operations for:

classifying the data using a machine learning model; and

determining whether to send the data to a particular edge device in the participating group based on the classification of the data.

13. The computer program product of claim 8 , wherein identifying the subset of the edge devices that meet the security level uses a machine learning model.

14. The computer program product of claim 8 , wherein a Software as a Service (SaaS) is configured to perform the operations of the computer program product.

15. A computer system, comprising:

one or more processors, one or more computer-readable memories and one or more computer-readable, tangible storage devices; and

program instructions, stored on at least one of the one or more computer-readable, tangible storage devices for execution by at least one of the one or more processors via at least one of the one or more computer-readable memories, to perform operations comprising:

determining that a job that uses one or more cloud nodes and uses edge devices to process data from one or more data sources is to be executed, wherein each of the edge devices comprises security data;

identifying a security level for the job from a security policy stored at a cloud node of the one or more cloud nodes;

determining a desired number of the edge devices that are to be included in a participating group to execute the job;

comparing the security data of each of the edge devices with the security level of the security policy defined at the cloud node;

determining that a subset of the edge devices meet the security level based on the comparing;

adding the subset of the edge devices that meet the security level to the participating group;

determining that the participating group does not include the desired number of the edge devices;

installing a security update at one or more other edge devices that did not meet the security level to move the one or more other edge devices to the security level and to reach the desired number of the edge devices;

adding the one or more other edge devices to the participating group; and

executing the job using the participating group and the one or more cloud nodes.

16. The computer system of claim 15 , wherein the operations for installing the security update further comprise:

sending the security update to one or more edge devices that are not in the participating group; and

receiving confirmation that the security update has been installed at the one or more edge devices.

17. The computer system of claim 15 , wherein the operations further comprise:

in response to determining that the edge devices in the participating group have completed edge processing, uninstalling the security update from the one or more other edge devices.

18. The computer system of claim 15 , wherein the security level changes, and wherein the operations further comprise:

modifying the edge devices that are in the participating group.

19. The computer system of claim 15 , wherein the operations further comprise:

classifying the data using a machine learning model; and

determining whether to send the data to a particular edge device in the participating group based on the classification of the data.

20. The computer system of claim 15 , wherein a Software as a Service (SaaS) is configured to perform the operations of the computer system.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT UPDATE THE ASSIGNOR'S DATA PREVIOUSLY RECORDED ON REEL 57821 FRAME 499. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 31, 2025
From: RAKSHIT, SARBAJIT K.; PATNAIKUNI, SUBHA KIRAN; PERUMALLA, SARASWATHI SAILAJA; VARADA, SRI HARSHA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 070076/0477 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: RAKSHIT, SARBAJIT K.; PATNAIKUNI, SUBHA KIRAN; PERUMALLA, SARASWATHI SAILAJA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057821/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: IBM INDIA PRIVATE LIMITED
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057821/0846 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: KARRI, VENKATA VARA PRASAD
To: IBM INDIA PRIVATE LIMITED
Reel/Frame 058589/0732 →
Continuity (1)
Related Publication 20230090200A1 · Mar 23, 2023
References Cited (32)
US 10462171B2 · Weingarten et al. · 2019 [cited by applicant]
US 11153175B2 · Bijavara Aswathanarayana Rao · 2021 [cited by examiner]
US 11210578B2 · Scheidegger · 2021 [cited by examiner]
US 11347970B2 · Anghel · 2022 [cited by examiner]
US 11443132B2 · Yellin · 2022 [cited by examiner]
US 20030177386A1 · Cuomo · 2003 [cited by examiner]
US 20060271658A1 · Beliles · 2006 [cited by examiner]
US 20070157307A1 · Katoh · 2007 [cited by examiner]
US 20070280211A1 · Malueg · 2007 [cited by examiner]
US 20130101291A1 · Wittenschlaeger · 2013 [cited by examiner]
US 20170060574A1 · Malladi · 2017 [cited by examiner]
US 20170063905A1 · Muddu · 2017 [cited by examiner]
US 20170235603A1 · Baughman · 2017 [cited by examiner]
US 20190392328A1 · Gil Bulacio · 2019 [cited by examiner]
US 20220292221A1 · Sohail · 2022 [cited by examiner]
CN 107770263 · 2019 [cited by applicant]
CN 111459665 · 2020 [cited by applicant]
CN 107959708 · 2020 [cited by applicant]
CN 112306673 · 2021 [cited by applicant]
WO WO2017066936 · 2017 [cited by applicant]
WO 2020068238 · 2020 [cited by applicant]
WO 2021036265 · 2021 [cited by applicant]
Yu, Wei, et al. “A survey on the edge computing for the Internet of Things.” IEEE access 6 (2017): 6900-6919. (Year: 2017). [cited by examiner]
B. R. Kandukuri, R. P. V. and A. Rakshit, “Cloud Security Issues,” 2009 IEEE International Conference on Services Computing, Bangalore, India, 2009, pp. 517-520, doi: 10.1109/SCC.2009.84. (Year: 2009). [cited by examiner]
Zhang, Yanyong, et al. “Impact of workload and system parameters on next generation cluster scheduling mechanisms.” IEEE Transactions on Parallel and Distributed Systems 12.9 (2001): 967-985. (Year: 2001). [cited by examiner]
Gao et al. “A Light-weight Trust Mechanism for Cloud-Edge Collaboration Framework” dated Oct. 31, 2019, 2019 IEEE 27th International Conference on Network Protocols (ICNP), Total 6 pages. [cited by applicant]
J. Deal, “NXP Launches Flexible IoT Cloud Platform to Securely Manage and Connect Edge Devices” dated Feb. 3, 2021, NXP Semiconductors Press Release, Total 3 pages. [cited by applicant]
Xu et al., “A Collaborative Cloud-Edge Computing Framework in Distributed Neural Network” dated Oct. 26, 2020, EURASIP Journal on Wireless Communications and Networking vol. 2020, Total 17 pages. [cited by applicant]
L. Eliot “Edge Computing And The Cloud Are Perfect Pairing For Autonomous Vehicles” dated Mar. 30, 2021, (online) retrieved from the Internet at URL>Edge Computing And The Cloud Are Perfect Pairing For Autonomous Vehicl… [cited by applicant]
“Role of Edge Computing in Connected and Autonomous Vehicles” dated Jan. 24, 2020, (online) retrieved from the Internet at URL>https://www.einfochips.com/blog/role-of-edge-computing-in-connected-and-autonomous-vehicles/… [cited by applicant]
Mell et al., “Effectively and Securely Using the Cloud Computing Paradigm” dated Oct. 7, 2009, NIST, Information Technology Laboratory, 80 pp. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing” dated Sep. 2011, Recommendations of the National Institute of Standards and Technology, 7 pp. [cited by applicant]