IP Library Granted Patent US 12,340,255
Granted Patent B2
US 12,340,255 · App. 17/581,802 · Granted Jun 24, 2025

Edge device service enclaves

Inventors: David Dale Becker (Seattle, WA); Maxim Baturin (Sammamish, WA)
Assignee: Oracle International Corporation
G06F9/5077G06F9/455G06F9/5005G06F11/3409G06F11/3414G06F11/3433G06F11/3457G06F2009/45562G06F2009/45587H04L41/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,340,255
App. No.
17/581,802
Granted
Jun 24, 2025
Kind
B2
Abstract

Techniques are described for implementing a secure enclave within an edge device (e.g., an edge device of a computing cluster of edge devices). In some embodiments, a service enclave comprising a plurality of services can be implemented. The plurality of services can be implemented within respective containers and communicatively connected to one another via a virtual substrate network of the cloud-computing edge device. The virtual substrate network may be dedicated to network traffic between services of the plurality of services. A first service of the enclave may generate and transmit a message to a second service of the enclave for processing. One or more operations may be executed by the second service based on reception of the message.

Claims (37)

1. A computer-implemented method, comprising:

implementing, by a plurality of cloud-computing edge devices, a plurality of distributed computing clusters that operate as respective isolated computing clusters that individually lack a network connection to a cloud-provider network, each of the plurality of distributed computing clusters implementing a respective distributed service enclave comprising a plurality of services that are implemented within respective containers and communicatively connected to one another, according to a manifest, by an intra-node switch and by a distributed virtual substrate network, the distributed virtual substrate network being dedicated to network traffic of the plurality of services and distributed across a set of cloud-computing edge devices corresponding to the respective distribute service enclave, each respective distribute service enclave implementing a respective distributed control plane that manages infrastructure components and services of a respective distributed computing cluster, a network topology of each respective distributed service enclave being predefined by the manifest;

generating, by a first service of the respective distributed service enclave, a message comprising data related to cloud-computing operations;

transmitting, by the first service of the respective distributed service enclave, the message comprising the data related to cloud-computing operations;

receiving, by the first service from a second service of the plurality of services, an additional message via the distributed virtual substrate network; and

executing, by the first service, one or more operations based at least in part on receiving the additional message via the distributed virtual substrate network.

2. The computer-implemented method of claim 1 , wherein the network traffic between the plurality of services of the respective distributed service enclave is unencrypted, and wherein external network traffic between a plurality of distributed service enclaves is encrypted.

3. The computer-implemented method of claim 1 , wherein the plurality of services comprise a gateway service that enables communication between a client device and the plurality of services.

4. The computer-implemented method of claim 1 , further comprising encrypting the message prior to transmitting the message from a first cloud-computing edge device of the plurality of cloud-computing edge devices to a second cloud-computing edge device of the plurality of cloud-computing edge devices.

5. The computer-implemented method of claim 1 , wherein each of the plurality of cloud-computing edge devices comprise a security module that is configured to encrypt traffic between the plurality of cloud-computing edge devices.

6. The computer-implemented method of claim 1 , wherein a first cloud-computing edge device of the respective distributed control plane performs operations related to managing the infrastructure components and services of a second cloud-computing edge device of the plurality of cloud-computing edge devices.

7. The computer-implemented method of claim 1 , wherein a single cloud-computing edge device of an isolated computing cluster is configured to connect with a client device, and wherein the single cloud-computing edge device is further configured to propagate data received from the client device to at least one additional cloud-computing edge device of the isolated computing cluster.

8. A computing cluster, comprising:

an intra-node switch;

a plurality of cloud-computing edge devices communicatively connected to one another via the intra-node switch, the plurality of cloud-computing edge devices individually comprising one or more processors and one or more memories storing computer-executable instructions that, when executed with the one or more processors, cause a cloud-computing edge device to:

implement, by a plurality of distributed computing clusters comprising the computing cluster that operate as respective isolated computing clusters that individually lack a network connection to a cloud-provider network, each of the plurality of distributed computing clusters implementing a respective distributed service enclave comprising a plurality of services that are implemented within respective containers and communicatively connected to one another, according to a manifest, by the intra-node switch and by a distributed virtual substrate network, the distributed virtual substrate network being dedicated to network traffic of the plurality of services and distributed across a set of cloud computing services corresponding to the respective distributed service enclave, each respective distribute service enclave implementing a respective distributed control plane that manages infrastructure components and services of a respective distributed computing cluster, a network topology of each respective distributed service enclave being predefined by the manifest;

generate, by a first service of the respective distributed service enclave, a message comprising data related to cloud-computing operations;

transmit, by the first service of the respective distributed service enclave, the message comprising the data related to cloud-computing operations;

receive, by the first service from a second service of the plurality of services, an additional message via the distributed virtual substrate network; and

execute, by the first service, one or more operations based at least in part on receiving the additional message via the distributed virtual substrate network.

9. The computing cluster of claim 8 , wherein the network traffic between the plurality of services of the respective distributed service enclave is unencrypted, and wherein external network traffic between a plurality of distributed service enclaves is encrypted.

10. The computing cluster of claim 8 , wherein the plurality of services comprise a gateway service that enables communication between a client device and the plurality of services.

11. The computing cluster of claim 8 , wherein executing the computer-executable instructions further causes the one or more processors to encrypt the message prior to transmitting the message from a first cloud-computing edge device of the plurality of cloud-computing edge devices to a second cloud-computing edge device of the plurality of cloud-computing edge devices.

12. The computing cluster of claim 8 , wherein each of the plurality of cloud-computing edge devices comprise a security module that is configured to encrypt traffic between the plurality of cloud-computing edge devices.

13. The computing cluster of claim 8 , wherein a first cloud-computing edge device of the respective distributed control plane performs operations related to managing the infrastructure components and services of a second cloud-computing edge device of the plurality of cloud-computing edge devices.

14. The computing cluster of claim 8 , wherein a single cloud-computing edge device of an isolated computing cluster is configured to connect with a client device, and wherein the single cloud-computing edge device is further configured to propagate data received from the client device to at least one additional cloud-computing edge device of the isolated computing cluster.

15. A non-transitory computer-readable storage medium comprising computer-executable instructions that, when executed by one or more processors of a cloud-computing edge device, causes the cloud-computing edge device to:

implement, by the plurality of distributed computing clusters that operate as respective isolated computing clusters that individually lack a network connection to a cloud-provider network, each of the plurality of distributed computing clusters implementing a respective distributed service enclave comprising a plurality of services that are implemented within respective containers and communicatively connected to one another, according to a manifest, by an intra-node switch and by a distributed virtual substrate network, the distributed virtual substrate network being dedicated to network traffic of the plurality of services and distributed across a set of cloud computing services corresponding to the respective distributed service enclave, each respective distribute service enclave implementing a respective distributed control plane that manages infrastructure components and services of a respective distributed computing cluster, a network topology of each respective distributed service enclave being predefined by the manifest;

generate, by a first service of the respective distributed service enclave, a message comprising data related to cloud-computing operations;

transmit, by the first service of the respective distributed service enclave, the message comprising the data related to cloud-computing operations;

receive, by the first service from a second service of the plurality of services, an additional message via the distributed virtual substrate network; and

execute, by the first service, one or more operations based at least in part on receiving the additional message via the distributed virtual substrate network.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the network traffic between the plurality of services of the respective distributed service enclave is unencrypted, and wherein external network traffic between a plurality of distributed service enclaves is encrypted.

17. The non-transitory computer-readable storage medium of claim 15 , wherein executing the computer-executable instructions further causes the one or more processors to encrypt the message prior to transmitting the message from a first cloud-computing edge device of a plurality of cloud-computing edge devices to a second cloud-computing edge device of the plurality of cloud-computing edge devices.

18. The non-transitory computer-readable storage medium of claim 15 , wherein each of the cloud-computing edge device comprises a security module that is configured to encrypt traffic between the cloud-computing edge device and a plurality of cloud-computing edge devices.

19. The non-transitory computer-readable storage medium of claim 15 , wherein a first cloud-computing edge device of the respective distributed control plane performs operations related to managing the infrastructure components and services of a second cloud-computing edge device of a plurality of cloud-computing edge devices.

20. The non-transitory computer-readable storage medium of claim 15 , wherein a single cloud-computing edge device of an isolated computing cluster is configured to connect with a client device, and wherein the single cloud-computing edge device is further configured to propagate data received from the client device to at least one additional cloud-computing edge device of the isolated computing cluster.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2022
From: BECKER, DAVID DALE; BATURIN, MAXIM
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 058810/0553 →
Continuity (2)
Provisional Application 63173244 · Apr 9, 2021
Related Publication 20220329578A1 · Oct 13, 2022
References Cited (56)
US 10880743B1 · Berzin et al. · 2020 [cited by applicant]
US 11050781B2 · Samuel · 2021 [cited by examiner]
US 11201789B1 · Keane · 2021 [cited by examiner]
US 11582027B1 · Lawton · 2023 [cited by applicant]
US 20040252717A1 · Solomon et al. · 2004 [cited by applicant]
US 20160266922A1 · Brandwine · 2016 [cited by examiner]
US 20170201455A1 · Amulothu et al. · 2017 [cited by applicant]
US 20180004953A1 · Smith, II · 2018 [cited by examiner]
US 20180054490A1 · Wadhwa · 2018 [cited by examiner]
US 20190138294A1 · Smith et al. · 2019 [cited by applicant]
US 20190253262A1 · Smith · 2019 [cited by examiner]
US 20190327312A1 · Gupta et al. · 2019 [cited by applicant]
US 20200097274A1 · Sarkar et al. · 2020 [cited by applicant]
US 20200103888A1 · Sayyarrodsari et al. · 2020 [cited by applicant]
US 20200153623A1 · Asanghanwa et al. · 2020 [cited by applicant]
US 20200213227A1 · Pianigiani et al. · 2020 [cited by applicant]
US 20200293477A1 · Lefebvre · 2020 [cited by examiner]
US 20200296138A1 · Crabtree · 2020 [cited by examiner]
US 20200344847A1 · Nardini et al. · 2020 [cited by applicant]
US 20200351380A1 · Fedorov et al. · 2020 [cited by applicant]
US 20210014113A1 · Guim Bernat · 2021 [cited by examiner]
US 20210112034A1 · Sundararajan et al. · 2021 [cited by applicant]
US 20210132976A1 · Chandrappa · 2021 [cited by examiner]
US 20210168203A1 · Parulkar · 2021 [cited by examiner]
US 20210256824A1 · Wyseur et al. · 2021 [cited by applicant]
US 20210314423A1 · Rolando · 2021 [cited by examiner]
US 20220019422A1 · Anderson · 2022 [cited by applicant]
US 20220051762A1 · Sharma et al. · 2022 [cited by applicant]
US 20220083245A1 · Kant · 2022 [cited by examiner]
US 20220100182A1 · Mehrotra et al. · 2022 [cited by applicant]
US 20220329628A1 · Zayats · 2022 [cited by examiner]
US 20220334725A1 · Mertes · 2022 [cited by examiner]
US 20220405157A1 · Bender · 2022 [cited by applicant]
US 20220413974A1 · Wang · 2022 [cited by examiner]
US 20230254943A1 · Nardini · 2023 [cited by examiner]
US 20230283517A1 · Maheshwari · 2023 [cited by examiner]
US 20240171391A1 · Ananthanarayanan · 2024 [cited by examiner]
CN 112543429B · 2022 [cited by applicant]
EP 2369782 · 2011 [cited by applicant]
EP 3391588 · 2018 [cited by applicant]
WO 2016069638 · 2016 [cited by applicant]
WO 2019236181 · 2019 [cited by applicant]
WO 2020052322 · 2020 [cited by applicant]
AWS Snowball Edge Developer Guide AWS Snowball Edge, Available Online at: https://docs.aws.amazon.com/snowball/latest/developer-guide/AWSSnowball-dg.pdf#UsingCluster, 2021, 227 pages. [cited by applicant]
Cisco SD-WAN Design Guide, Available Online at: https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-design-guide.html, Sep. 2020, 102 pages. [cited by applicant]
Device Update APT Manifest, Available Online at: https://docs.microsoft.com/en-us/azure/iot-hub-device-update/device-update-apt-manifest, Feb. 17, 2021, 2 pages. [cited by applicant]
Encrypting Traffic Between Nodes with IPsec, Available Online at: https://docs.openshift.com/container-platform/3.11/admin_guide/ipsec.html, Accessed from Internet on May 21, 2021, 8 pages. [cited by applicant]
NSX-T Data Center, Available Online at: https://docs.vmware.com/en/VMware-NSX-T-Data-Center/2.5/nsxt_25_install.pdf, Jul. 31, 2020, 276 pages. [cited by applicant]
Software Installation and Upgrade for vEdge Routers, Available Online at: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/hardware-and-software-installation.html, 2021, 2 pages. [cited by applicant]
Upgrade an Edge Cluster, Available Online at: https://partners-intl.aliyun.com/help/doc-detail/154532.htm, 2021, 4 pages. [cited by applicant]
Upgrade NSX Edge Cluster, Available Online at: https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.1/nsxt_31_upgrade.pdf, 2021, pp. 1-57. [cited by applicant]
Akesson et al., How to Build a Resilient Over-the-Air Update Solution, Available Online at: https://techcommunity.microsoft.com/t5/internet-of-things/how-to-build-a-resilient-over-the-air-update-solution/ba-p/2163991, M… [cited by applicant]
Asif et al., Prototype Implementation of Edge Encryption in IoT Architecture, 10th International Conference on Computing, Communication and Networking Technologies, Jul. 6-8, 2019, 7 pages. [cited by applicant]
Pavlik, Managing Thousands of Edge Kubernetes Clusters with GitOps, Available Online at: https://www.volterra.io/resources/blog/managing-thousands-of-edge-kubernetes-clusters-with-gitops, Dec. 18, 2019, 8 pages. [cited by applicant]
U.S. Appl. No. 17/549,859, Non-Final Office Action mailed on Oct. 16, 2023, 16 pages. [cited by applicant]
U.S. Appl. No. 17/549,859, “Final Office Action”, mailed Jul. 5, 2024, 12 pages. [cited by applicant]