IP Library › Granted Patent US 12,386,686
Granted Patent B2
US 12,386,686 · App. 18/141,681 · Granted Aug 12, 2025

Multi-tenant data protection in edge computing environments

Inventors: Kshitij Arun Doshi (Tempe, AZ); Ned M. Smith (Beaverton, OR); Francesc Guim Bernat (Barcelona, ES); Timothy Verrall (Pleasant Hill, CA)
Assignee: Intel Corporation
G06F9/544G06F8/443G06F9/44594G06F9/5016G06F9/505G06F9/5072G06F9/5077G06F11/3433G06F16/1865G06F21/602H04L9/008H04L9/0637H04L9/0822H04L9/0825H04L9/0866H04L41/0893H04L41/0894H04L41/0895H04L41/0896H04L41/142H04L41/145H04L41/5009H04L41/5025H04L41/5051H04L43/08H04L47/822H04L63/0407H04L63/0428H04L63/108H04L63/1408H04L63/20H04L67/1008H04L67/12H04L67/141G06F9/3836G06F9/45533G06F9/4881G06F9/5038G06F11/1004G06F12/1408G06F16/2322G06F2209/509G16Y40/10H04L9/3297H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,686
App. No.
18/141,681
Granted
Aug 12, 2025
Kind
B2
Abstract

Various approaches for implementing multi-tenant data protection are described. In an edge computing system deployment, a system includes memory and processing circuitry coupled to the memory. The processing circuitry is configured to obtain a workflow execution plan that includes workload metadata defining a plurality of workloads associated with a plurality of edge service instances executing respectively on one or more edge computing devices. The workload metadata is translated to obtain workload configuration information for the plurality of workloads. The workload configuration information identifies a plurality of memory access configurations and service authorizations identifying at least one edge service instance authorized to access one or more of the memory access configurations. The memory is partitioned into a plurality of shared memory regions using the memory access configurations. A memory access request for accessing one of the shared memory regions is processed based on the service authorizations.

Claims (56)

1. A system comprising:

memory; and

processing circuitry coupled to the memory, the processing circuitry to:

partition the memory into a plurality of shared memory regions associated with a plurality of memory address ranges using a plurality of memory access configurations, the plurality of shared memory regions of the memory configured for shared access among a plurality of edge computing devices based at least on a mapping between the plurality of memory address ranges and identification information of the plurality of edge computing devices;

configure a shared memory region of the plurality of shared memory regions of the memory for shared access by the plurality of edge computing devices based on data in a memory access configuration of the plurality of memory access configurations, the data including the mapping and identifying a memory address range of the plurality of memory address ranges for an edge computing device of the plurality of edge computing devices, the memory address range configured in the shared memory region;

configure the shared memory region of the plurality of shared memory regions for a raw mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the raw mode access, the shared memory region includes an encrypted memory portion storing encrypted data, the encrypted memory portion specified by an encrypted address range, and the encrypted memory portion enabled for read and write access by the at least two edge computing devices;

process a memory access request for accessing the shared memory region in accordance with the memory access configuration, the memory access request received via a communication network from an edge computing device of the plurality of edge computing devices; and

complete processing of the memory access request based on granting the edge computing device access to the memory address range configured in the shared memory region.

2. The system of claim 1 , wherein the processing circuitry is to:

configure the shared memory region of the plurality of shared memory regions for a protected mode access by an edge computing device of the plurality of edge computing devices, wherein during the protected mode access, the shared memory region stores data of the edge computing device, and the data being isolated in a trusted execution environment within the shared memory region.

3. The system of claim 1 , wherein the processing circuitry is to:

configure the shared memory region of the plurality of shared memory regions for a shared plain mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the shared plain mode access, the shared memory region stores data enabled for secure shared access among the at least two edge computing devices or by applications executing on the at least two edge computing devices.

4. The system of claim 3 , wherein the processing circuitry is to:

configure the shared memory region of the plurality of shared memory regions for a shared homomorphic protected mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the shared homomorphic protected mode access, the shared memory region stores data enabled for the secure shared access among the at least two edge computing devices or by applications executing on the at least two edge computing devices and the data is encrypted using homomorphic encryption.

5. The system of claim 1 , wherein the processing circuitry is to:

obtain a plurality of device identifications of devices authorized to access the plurality of shared memory regions using the plurality of memory access configurations, the plurality of device identifications corresponding to the plurality of edge computing devices.

6. The system of claim 5 , wherein the plurality of memory access configurations further identify particular one or more edge computing devices of the plurality of edge computing devices authorized to access each memory region of the plurality of memory regions.

7. The system of claim 1 , wherein the processing circuitry is to:

detect data is stored in the shared memory region of the plurality of shared memory regions, the data being shared between one or more edge computing devices of the plurality of edge computing devices.

8. The system of claim 7 , wherein the processing circuitry is to:

replicate the data into a virtual memory region, the virtual memory region associated with at least one additional virtual memory region of the one or more edge computing devices, wherein replicating the data into the virtual memory region causes replication of the data from the virtual memory region to the at least one additional virtual memory region of the one or more edge computing devices.

9. A method comprising:

partitioning a memory into a plurality of shared memory regions associated with a plurality of memory address ranges using a plurality of memory access configurations, the plurality of shared memory regions of the memory configured for shared access among a plurality of edge computing devices based at least on a mapping between the plurality of memory address ranges and identification information of the plurality of edge computing devices;

configuring a shared memory region of the plurality of shared memory regions of the memory for shared access by the plurality of edge computing devices based on data in a memory access configuration of the plurality of memory access configurations, the data including the mapping and identifying a memory address range of the plurality of memory address ranges for an edge computing device of the plurality of edge computing devices, the memory address range configured in the shared memory region;

configuring the shared memory region of the plurality of shared memory regions for a raw mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the raw mode access, the shared memory region includes an encrypted memory portion storing encrypted data, the encrypted memory portion specified by an encrypted address range, and the encrypted memory portion enabled for read and write access by the at least two edge computing devices;

processing a memory access request for accessing the shared memory region in accordance with the memory access configuration, the memory access request received via a communication network from an edge computing device of the plurality of edge computing devices; and

completing the processing of the memory access request based on granting the edge computing device access to the memory address range configured in the shared memory region.

10. The method of claim 9 , further comprising:

configuring the shared memory region of the plurality of shared memory regions for a protected mode access by an edge computing device of the plurality of edge computing devices, wherein during the protected mode access, the shared memory region stores data of the edge computing device, and the data being isolated in a trusted execution environment within the shared memory region.

11. The method of claim 9 , further comprising:

configuring the shared memory region of the plurality of shared memory regions for a shared plain mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the shared plain mode access, the shared memory region stores data enabled for secure shared access among the at least two edge computing devices or by applications executing on the at least two edge computing devices.

12. The method of claim 11 , further comprising:

configuring the shared memory region of the plurality of shared memory regions for a shared homomorphic protected mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the shared homomorphic protected mode access, the shared memory region stores data enabled for the secure shared access among the at least two edge computing devices or by applications executing on the at least two edge computing devices and the data is encrypted using homomorphic encryption.

13. The method of claim 9 , further comprising:

decoding the plurality of memory access configurations to obtain a plurality of device identifications of devices authorized to access the plurality of shared memory regions, the plurality of device identifications corresponding to the plurality of edge computing devices,

wherein the plurality of memory access configurations further identify particular one or more edge computing devices of the plurality of edge computing devices authorized to access each shared memory region of the plurality of shared memory regions.

14. The method of claim 9 , further comprising:

detecting data is stored in the shared memory region of the plurality of shared memory regions, the data being shared between one or more edge computing devices of the plurality of edge computing devices; and

replicating the data into a virtual memory region, the virtual memory region associated with at least one additional virtual memory region of the one or more edge computing devices, wherein replicating the data into the virtual memory region causes replication of the data from the virtual memory region to the at least one additional virtual memory region of the one or more edge computing devices.

15. A non-transitory computer-readable storage medium that stores instructions for execution by one or more processors of a computing device to cause the computing device to perform operations comprising:

partitioning a memory into a plurality of shared memory regions associated with a plurality of memory address ranges using a plurality of memory access configurations, the plurality of shared memory regions of the memory configured for shared access among a plurality of edge computing devices based at least on a mapping between the plurality of memory address ranges and identification information of the plurality of edge computing devices;

configuring a shared memory region of the plurality of shared memory regions of the memory for shared access by the plurality of edge computing devices based on data in a memory access configuration of the plurality of memory access configurations, the data including the mapping and identifying a memory address range of the plurality of memory address ranges for an edge computing device of the plurality of edge computing devices, the memory address range configured in the shared memory region;

configuring the shared memory region of the plurality of shared memory regions for a raw mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the raw mode access, the shared memory region includes an encrypted memory portion storing encrypted data, the encrypted memory portion specified by an encrypted address range, and the encrypted memory portion enabled for read and write access by the at least two edge computing devices;

processing a memory access request for accessing the shared memory region in accordance with the memory access configuration, the memory access request received via a communication network from an edge computing device of the plurality of edge computing devices; and

completing the processing of the memory access request based on granting the edge computing device access to the memory address range configured in the shared memory region.

16. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

configuring the shared memory region of the plurality of shared memory regions for one of:

a protected mode access by an edge computing device of the plurality of edge computing devices, wherein during the protected mode access, the shared memory region stores data of the edge computing device, and the data being isolated in a trusted execution environment within the shared memory region;

a shared plain mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the shared plain mode access, the shared memory region stores data enabled for secure shared access among the at least two edge computing devices or by applications executing on the at least two edge computing devices; and

a shared homomorphic protected mode access by at least two edge computing devices of the plurality of edge computing devices, wherein during the shared homomorphic protected mode access, the shared memory region stores data enabled for the secure shared access among the at least two edge computing devices or by applications executing on the at least two edge computing devices and the data is encrypted using homomorphic encryption.

17. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

decoding the plurality of memory access configurations to obtain a plurality of device identifications of devices authorized to access the plurality of shared memory regions, the plurality of device identifications corresponding to the plurality of edge computing devices,

wherein the plurality of memory access configurations further identify particular one or more edge computing devices of the plurality of edge computing devices authorized to access each shared memory region of the plurality of shared memory regions.

18. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

detecting data is stored in the shared memory region of the plurality of shared memory regions, the data being shared between one or more edge computing devices of the plurality of edge computing devices; and

replicating the data into a virtual memory region, the virtual memory region associated with at least one additional virtual memory region of the one or more edge computing devices, wherein replicating the data into the virtual memory region causes replication of the data from the virtual memory region to the at least one additional virtual memory region of the one or more edge computing devices.

Continuity (4)
Continuation 16723358 · Dec 20, 2019
Provisional Application 62939303 · Nov 22, 2019
Provisional Application 62907597 · Sep 28, 2019
Related Publication 20230267004A1 · Aug 24, 2023
References Cited (100)
US 8656189B2 · Orsini et al. · 2014 [cited by applicant]
US 8719590B1 · Faibish et al. · 2014 [cited by applicant]
US 10083193B2 · Meng · 2018 [cited by examiner]
US 10142342B2 · Seligson et al. · 2018 [cited by applicant]
US 10389746B2 · Sakalanaga et al. · 2019 [cited by applicant]
US 10521360B1 · Gibson · 2019 [cited by examiner]
US 11087006B2 · Feroz et al. · 2021 [cited by applicant]
US 11425111B2 · Smith et al. · 2022 [cited by applicant]
US 11669368B2 · Doshi et al. · 2023 [cited by applicant]
US 11757795B2 · Grunwald et al. · 2023 [cited by applicant]
US 12206552B2 · Guim Bernat et al. · 2025 [cited by applicant]
US 20030065933A1 · Hashimoto · 2003 [cited by examiner]
US 20070067644A1 · Flynn · 2007 [cited by examiner]
US 20070245104A1 · Lindemann · 2007 [cited by examiner]
US 20080115135A1 · Behnen et al. · 2008 [cited by applicant]
US 20090249014A1 · Obereiner · 2009 [cited by examiner]
US 20100100604A1 · Fujiwara · 2010 [cited by examiner]
US 20110264920A1 · Rieffel · 2011 [cited by examiner]
US 20110296019A1 · Ferris et al. · 2011 [cited by applicant]
US 20120072669A1 · Nishiguchi · 2012 [cited by examiner]
US 20120303818A1 · Thibeault et al. · 2012 [cited by applicant]
US 20140237550A1 · Anderson et al. · 2014 [cited by applicant]
US 20140304297A1 · Lian · 2014 [cited by examiner]
US 20140365549A1 · Jenkins · 2014 [cited by applicant]
US 20140379928A1 · Song et al. · 2014 [cited by applicant]
US 20150067353A1 · Hui · 2015 [cited by examiner]
US 20150271169A1 · Seligson et al. · 2015 [cited by applicant]
US 20150310026A1 · Chen · 2015 [cited by examiner]
US 20160203102A1 · Meng · 2016 [cited by examiner]
US 20160267051A1 · Metzler et al. · 2016 [cited by applicant]
US 20160359854A1 · Bhargava · 2016 [cited by examiner]
US 20160359955A1 · Gill et al. · 2016 [cited by applicant]
US 20170010839A1 · Masuda · 2017 [cited by examiner]
US 20170249460A1 · Lipton · 2017 [cited by examiner]
US 20170324813A1 · Jain et al. · 2017 [cited by applicant]
US 20170366606A1 · Ben-Shaul et al. · 2017 [cited by applicant]
US 20180115522A1 · Gleichauf · 2018 [cited by applicant]
US 20180165218A1 · Parker · 2018 [cited by examiner]
US 20180189087A1 · Palermo et al. · 2018 [cited by applicant]
US 20180285009A1 · Guim Bernat et al. · 2018 [cited by applicant]
US 20190004703A1 · Johri et al. · 2019 [cited by applicant]
US 20190036678A1 · Ahmed · 2019 [cited by applicant]
US 20190042315A1 · Smith et al. · 2019 [cited by applicant]
US 20190044703A1 · Smith · 2019 [cited by applicant]
US 20190286572A1 · Gschwind · 2019 [cited by examiner]
US 20190288934A1 · Chakra · 2019 [cited by examiner]
US 20190356743A1 · Park et al. · 2019 [cited by applicant]
US 20200014633A1 · You et al. · 2020 [cited by applicant]
US 20200134207A1 · Doshi et al. · 2020 [cited by applicant]
US 20200159415A1 · Neelakantam · 2020 [cited by examiner]
US 20210125083A1 · Ogawa et al. · 2021 [cited by applicant]
US 20210144517A1 · Guim Bernat et al. · 2021 [cited by applicant]
US 20210373537A1 · Wei et al. · 2021 [cited by applicant]
US 20220141761A1 · Cai et al. · 2022 [cited by applicant]
CN 102340533B · 2017 [cited by applicant]
CN 106911814A · 2017 [cited by applicant]
CN 114026834A · 2022 [cited by applicant]
DE 112020000054T5 · 2021 [cited by applicant]
JP 7612419B2 · 2024 [cited by applicant]
WO WO2020226979A2 · 2020 [cited by applicant]
WO WO2020226979A8 · 2020 [cited by applicant]
“European Application Serial No. 20801584.2, Partial Supplementary European Search Report mailed May 17, 2023”, 14 pgs. [cited by applicant]
Cheol-Ho, Hong, “qCon: QoS-Aware Network Resource Management for Fog Computing”, vol. 18, No. 10,, [Online] Retrieved from the internet:https: pdfs.semanticscholar.org 65d2 7b9576f6e39dda2413ad822a46e33a6055b5,pdf, (Oct… [cited by applicant]
Enas, Ahmad, “Location-Aware, Context-Driven QoS for IoT Applications”, IEEE Systems Journal, IEEE, US, vol. 14, No. 1, (Feb. 12, 2019), 12 pgs. [cited by applicant]
Flathagen, Joakim, “A combined Network Access Control and QoS scheme for Software Defined Networks”, IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), IEEE, (Nov. 27, 2018), 6 p… [cited by applicant]
Gupta, Harshit, “SDFog: A Software Defined Computing Architecture for QoS Aware Service Orchestration over Edge Devices”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 14853, (Sep… [cited by applicant]
Joshua, Boley M, “Adaptive QoS for data transfers using software-defined networking”, IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), IEEE, (Nov. 6, 2016), 6 pgs. [cited by applicant]
Slavica, Tomovic, “An Architecture for QoS-aware Service Deployment in Software-Defined IoT Networks”, 20th International Symposium on Wireless Personal Multimedia Communications (WPMC), IEEE, (Dec. 17, 2017), 7 pgs. [cited by applicant]
“European Application Serial No. 20801584.2, Extended European Search Report mailed Aug. 18, 2023”, 12 pgs. [cited by applicant]
“European Application Serial No. 20181908.3, Summons to Attend Oral Proceedings mailed Sep. 1, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 17/119,785, Non Final Office Action mailed Sep. 29, 2023”, 12 pgs. [cited by applicant]
“Indian Application Serial No. 202047055252, Response filed Jul. 17, 2023 to First Examination Report mailed Jan. 16, 2023”, w English Claims, 26 pgs. [cited by applicant]
Calcote, Lee, “Container Networking: A Breakdown, Explanation and Analysis—The New Stack”, [Online] Retrieved from the internet:https: thenewstack.io container-networking-breakdown-explanationanalysis , (Sep. 14, 2016),… [cited by applicant]
Eguro, Ken, “FPGAs for trusted cloud computing”, Field Programmable Logic and Applications (FPL), 22nd International Conference on, IEEE, (Aug. 29, 2012), 63-70. [cited by applicant]
Sven, Akkermans, “Software Technologies for Multi-Tenant Internet of Things Platforms”, Ku Leuven, (Apr. 2019), 222 pgs. [cited by applicant]
Yu, Hong, “A Group Key Distribution Scheme for Wireless Sensor Networks in the Internet of Things Scenario”, International Journal of Distributed Sensor Networks, (2012), 12 pgs. [cited by applicant]
“U.S. Appl. No. 17/119,785, Response filed Dec. 7, 2023 to Non Final Office Action mailed Sep. 29, 2023”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 17/119,785, Final Office Action mailed Feb. 15, 2024”, 17 pgs. [cited by applicant]
“European Application Serial No. 20801584.2, Response filed Feb. 28, 2024 to Extended European Search Report mailed Aug. 18, 2023”, 16 pgs. [cited by applicant]
“U.S. Appl. No. 16/723,358, Examiner Interview Summary mailed Dec. 7, 2022”, 3 pgs. [cited by applicant]
“U.S. Appl. No. 16/723,358, Final Office Action mailed Sep. 8, 2022”, 20 pgs. [cited by applicant]
“U.S. Appl. No. 16/723,358, Non Final Office Action mailed Apr. 6, 2022”, 20 pgs. [cited by applicant]
“U.S. Appl. No. 16/723,358, Notice of Allowability mailed Apr. 26, 2023”, 3 pgs. [cited by applicant]
“U.S. Appl. No. 16/723,358, Notice of Allowance mailed Jan. 25, 2023”, 18 pgs. [cited by applicant]
“U.S. Appl. No. 16/723,358, Preliminary Amendment filed Dec. 20, 2019”, 10 pgs. [cited by applicant]
“U.S. Appl. No. 16/723,358, Response filed Jul. 6, 2022 to Non Final Office Action mailed Apr. 6, 2022”, 16 pgs. [cited by applicant]
“U.S. Appl. No. 16/723,358, Response filed Dec. 2, 2022 to Final Office Action mailed Sep. 8, 2022”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 17/119,785, Preliminary Amendment filed”, 7 pgs. [cited by applicant]
“European Application Serial No. 20181908.3, Communication Pursuant to Article 94(3) EPC mailed Jun. 30, 2022”, 10 pgs. [cited by applicant]
“European Application Serial No. 20181908.3, Extended European Search Report mailed Jan. 19, 2021”, 10 pgs. [cited by applicant]
“European Application Serial No. 20181908.3, Response filed Jun. 21, 2021 to Extended European Search Report mailed Jan. 19, 2021”, 25 pgs. [cited by applicant]
“European Application Serial No. 20181908.3, Response filed Nov. 10, 2022 to Communication Pursuant to Article 94(3) EPC mailed Jun. 30, 2022”, 30 pgs. [cited by applicant]
“Indian Application Serial No. 202047055252, First Examination Report mailed Jan. 16, 2023”, w/English Translation, 6 pgs. [cited by applicant]
“International Application Serial No. PCT/US2020/030554, International Preliminary Report on Patentability mailed Nov. 11, 2021”, 8 pgs. [cited by applicant]
“International Application Serial No. PCT/US2020/030554, International Search Report mailed Jan. 15, 2021”, 5 pgs. [cited by applicant]
“International Application Serial No. PCT/US2020/030554, Written Opinion mailed Jan. 15, 2021”, 6 pgs. [cited by applicant]
Ashkan, Yousefpour, et al., “All One Needs to Know about Fog Computing and Related Edge Computing Paradigms: A Complete Survey”, arxiv.org, Cornell University Library, 201 Olin Library Cornell University Ithaca, NY 1485… [cited by applicant]
Guangshun, Li, et al., “Method of Resource Estimation Based on QoS in Edge Computing, Published in: Hindawi Wireless Communications and Mobile Computing”, (Jan. 22, 2018), 10 pgs. [cited by applicant]
Hesham, El-Sayed, et al., “Edge of Things: The Big Picture on the Integration of Edge, IoT and the Cloud in a Distributed Computing Environment”, (Feb. 14, 2018), 12 pgs. [cited by applicant]
Sangster, Paul, et al., “Virtualized Trusted Platform Architecture Specification”, Specification Version 1.0 Revision 0.26. TCG Published, (Sep. 27, 2011), 60 pgs. [cited by applicant]